unified

UC-GOV-38 — Assign and maintain Three Lines accountability by risk activity

For every material risk and each applicable enterprise-risk-management activity — identify, assess, manage, monitor, and report — the organization assigns a named first-line owner accountable for risk decisions and responses, a second-line role providing specialist support, monitoring, and challenge, and an independent third-line assurance role where warranted. External providers are classified according to the role performed for the activity rather than the function that engaged them. Assignments are documented at activity level, acknowledged by the assigned parties, approved by the appropriate governance authority, and reviewed at least annually and upon significant organizational or responsibility changes. The review identifies missing ownership, incompatible duties, duplicate coverage, and self-assurance. Outsourcing does not transfer management or board accountability.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Governance, Policy & Oversight
type
preventive
category
administrative

Details

unified_id
UC-GOV-38
title
Assign and maintain Three Lines accountability by risk activity
statement
For every material risk and each applicable enterprise-risk-management activity — identify, assess, manage, monitor, and report — the organization assigns a named first-line owner accountable for risk decisions and responses, a second-line role providing specialist support, monitoring, and challenge, and an independent third-line assurance role where warranted. External providers are classified according to the role performed for the activity rather than the function that engaged them. Assignments are documented at activity level, acknowledged by the assigned parties, approved by the appropriate governance authority, and reviewed at least annually and upon significant organizational or responsibility changes. The review identifies missing ownership, incompatible duties, duplicate coverage, and self-assurance. Outsourcing does not transfer management or board accountability.
domain
Governance, Policy & Oversight
control_type
preventive
control_category
administrative
members
    guidance
    • source
      iia-pos-2026-erm
      sourceTitle
      The Role of the Internal Audit Function in Enterprise Risk Management
      propositionId
      IIA-POS-ERM-01
      propositionTitle
      Board, Management, and Internal Audit Accountabilities
      sourcePages
      ERM pp. 3, 7–9
    • source
      iia-pos-2026-erm
      sourceTitle
      The Role of the Internal Audit Function in Enterprise Risk Management
      propositionId
      IIA-POS-ERM-02
      propositionTitle
      ERM Activity and Service Boundaries
      sourcePages
      ERM pp. 8, 11
    • source
      iia-pos-2026-three-lines
      sourceTitle
      Three Lines Model: Assurance and Advice in Support of Effective Governance
      propositionId
      IIA-POS-TLM-01
      propositionTitle
      Activity-Level Three Lines Responsibilities
      sourcePages
      Three Lines pp. 3–5, 13–19

    Source

    No record-specific source URL is provided.

    Connections