unified
UC-GOV-38 — Assign and maintain Three Lines accountability by risk activity
For every material risk and each applicable enterprise-risk-management activity — identify, assess, manage, monitor, and report — the organization assigns a named first-line owner accountable for risk decisions and responses, a second-line role providing specialist support, monitoring, and challenge, and an independent third-line assurance role where warranted. External providers are classified according to the role performed for the activity rather than the function that engaged them. Assignments are documented at activity level, acknowledged by the assigned parties, approved by the appropriate governance authority, and reviewed at least annually and upon significant organizational or responsibility changes. The review identifies missing ownership, incompatible duties, duplicate coverage, and self-assurance. Outsourcing does not transfer management or board accountability.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-38
- title
- Assign and maintain Three Lines accountability by risk activity
- statement
- For every material risk and each applicable enterprise-risk-management activity — identify, assess, manage, monitor, and report — the organization assigns a named first-line owner accountable for risk decisions and responses, a second-line role providing specialist support, monitoring, and challenge, and an independent third-line assurance role where warranted. External providers are classified according to the role performed for the activity rather than the function that engaged them. Assignments are documented at activity level, acknowledged by the assigned parties, approved by the appropriate governance authority, and reviewed at least annually and upon significant organizational or responsibility changes. The review identifies missing ownership, incompatible duties, duplicate coverage, and self-assurance. Outsourcing does not transfer management or board accountability.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- guidance
- source
- iia-pos-2026-erm
- sourceTitle
- The Role of the Internal Audit Function in Enterprise Risk Management
- propositionId
- IIA-POS-ERM-01
- propositionTitle
- Board, Management, and Internal Audit Accountabilities
- sourcePages
- ERM pp. 3, 7–9
- source
- iia-pos-2026-erm
- sourceTitle
- The Role of the Internal Audit Function in Enterprise Risk Management
- propositionId
- IIA-POS-ERM-02
- propositionTitle
- ERM Activity and Service Boundaries
- sourcePages
- ERM pp. 8, 11
- source
- iia-pos-2026-three-lines
- sourceTitle
- Three Lines Model: Assurance and Advice in Support of Effective Governance
- propositionId
- IIA-POS-TLM-01
- propositionTitle
- Activity-Level Three Lines Responsibilities
- sourcePages
- Three Lines pp. 3–5, 13–19
Source
No record-specific source URL is provided.
Connections
- UC-GOV-38 — Assign and maintain Three Lines accountability by risk activity mitigates Strategic misalignment and execution failure
- strength
- primary
- rationale
- Activity-level Three Lines accountability assigns named risk decision-makers, challenge, and independent assurance, directly countering execution drift caused by unclear role ownership.
- UC-GOV-38 — Assign and maintain Three Lines accountability by risk activity informed_by IIA-POS-TLM-01 — Activity-Level Three Lines Responsibilities
- framework
- iia-pos-2026-three-lines
- control_id
- IIA-POS-TLM-01
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- 2026
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Three Lines pp. 3–5, 13–19
- Enterprise Risk Register Lifecycle operates UC-GOV-38 — Assign and maintain Three Lines accountability by risk activity
- UC-GOV-38 — Assign and maintain Three Lines accountability by risk activity informed_by IIA-POS-ERM-01 — Board, Management, and Internal Audit Accountabilities
- framework
- iia-pos-2026-erm
- control_id
- IIA-POS-ERM-01
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- 2026
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- ERM pp. 3, 7–9
- UC-GOV-38 — Assign and maintain Three Lines accountability by risk activity mitigates Stakeholder trust and social-license erosion
- strength
- related
- rationale
- Documented, governance-approved Three Lines accountability makes risk ownership and retained board and management responsibility transparent, supporting stakeholder trust.
- Combined Assurance Mapping tests UC-GOV-38 — Assign and maintain Three Lines accountability by risk activity
- UC-GOV-38 — Assign and maintain Three Lines accountability by risk activity informed_by IIA-POS-ERM-02 — ERM Activity and Service Boundaries
- framework
- iia-pos-2026-erm
- control_id
- IIA-POS-ERM-02
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- 2026
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- ERM pp. 8, 11