{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-38","description":"For every material risk and each applicable enterprise-risk-management activity — identify, assess, manage, monitor, and report — the organization assigns a named first-line owner accountable for risk decisions and responses, a second-line role providing specialist support, monitoring, and challenge, and an independent third-line assurance role where warranted. External providers are classified according to the role performed for the activity rather than the function that engaged them. Assignments are documented at activity level, acknowledged by the assigned parties, approved by the appropriate governance authority, and reviewed at least annually and upon significant organizational or responsibility changes. The review identifies missing ownership, incompatible duties, duplicate coverage, and self-assurance. Outsourcing does not transfer management or board accountability.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[{"propositionId":"IIA-POS-ERM-01","propositionTitle":"Board, Management, and Internal Audit Accountabilities","source":"iia-pos-2026-erm","sourcePages":"ERM pp. 3, 7–9","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"},{"propositionId":"IIA-POS-ERM-02","propositionTitle":"ERM Activity and Service Boundaries","source":"iia-pos-2026-erm","sourcePages":"ERM pp. 8, 11","sourceTitle":"The Role of the Internal Audit Function in Enterprise Risk Management"},{"propositionId":"IIA-POS-TLM-01","propositionTitle":"Activity-Level Three Lines Responsibilities","source":"iia-pos-2026-three-lines","sourcePages":"Three Lines pp. 3–5, 13–19","sourceTitle":"Three Lines Model: Assurance and Advice in Support of Effective Governance"}],"members":[],"statement":"For every material risk and each applicable enterprise-risk-management activity — identify, assess, manage, monitor, and report — the organization assigns a named first-line owner accountable for risk decisions and responses, a second-line role providing specialist support, monitoring, and challenge, and an independent third-line assurance role where warranted. External providers are classified according to the role performed for the activity rather than the function that engaged them. Assignments are documented at activity level, acknowledged by the assigned parties, approved by the appropriate governance authority, and reviewed at least annually and upon significant organizational or responsibility changes. The review identifies missing ownership, incompatible duties, duplicate coverage, and self-assurance. Outsourcing does not transfer management or board accountability.","title":"Assign and maintain Three Lines accountability by risk activity","unified_id":"UC-GOV-38"},"id":"uc:UC-GOV-38","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-38","sourceIds":["iia-pos-2026-erm","iia-pos-2026-three-lines"],"sourceUrl":null,"title":"UC-GOV-38 — Assign and maintain Three Lines accountability by risk activity","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1889e1064f89088e03dd6aa659e4c9423282a6569b34c5524edfd3940b55072b","properties":{"rationale":"Activity-level Three Lines accountability assigns named risk decision-makers, challenge, and independent assurance, directly countering execution drift caused by unclear role ownership.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","sourceId":"uc:UC-GOV-38","targetDetailPath":"/data/v1/records/risk-strategic-misalignment-execution-d9c0675b.json","targetId":"risk:strategic-misalignment-execution","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:424aa1d6be0feea8c3eff42b7f991ace14ed70b42933cf65e9c22040a2be720b","properties":{"control_id":"IIA-POS-TLM-01","coverage":"guidance","delta":null,"framework":"iia-pos-2026-three-lines","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Three Lines pp. 3–5, 13–19","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","sourceId":"uc:UC-GOV-38","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-three-lines-iia-pos-tlm-01-2ee41e40.json","targetId":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-01","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4926845441ec44ba26ca61f03aa59b3cc26fd9322b26be564e62c304d11488d3","properties":{},"sourceDetailPath":"/data/v1/records/wf-g4-a265153d.json","sourceId":"wf:G4","targetDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","targetId":"uc:UC-GOV-38","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6d345a1c2d22a56c7395a702b683dfd5f0474b5d9fb0b05577f6bfaf04af9443","properties":{"control_id":"IIA-POS-ERM-01","coverage":"guidance","delta":null,"framework":"iia-pos-2026-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"ERM pp. 3, 7–9","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","sourceId":"uc:UC-GOV-38","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-01-6f73f46d.json","targetId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-01","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:747356fdac6fa018a60214212b3f0e42631af892f6eab2220b5e18bd69bb0d1c","properties":{"rationale":"Documented, governance-approved Three Lines accountability makes risk ownership and retained board and management responsibility transparent, supporting stakeholder trust.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","sourceId":"uc:UC-GOV-38","targetDetailPath":"/data/v1/records/risk-reputational-stakeholder-trust-23d21e70.json","targetId":"risk:reputational-stakeholder-trust","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cb987e37171a9d9fbca514ecd492988fff1913a767ea997db1e4f516735a0e5a","properties":{},"sourceDetailPath":"/data/v1/records/wf-g2-bd9bee15.json","sourceId":"wf:G2","targetDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","targetId":"uc:UC-GOV-38","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d972f93de535219262d85640e50744e0492fa413875d8b8eee0557274b978e30","properties":{"control_id":"IIA-POS-ERM-02","coverage":"guidance","delta":null,"framework":"iia-pos-2026-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"ERM pp. 8, 11","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-38-0167bec0.json","sourceId":"uc:UC-GOV-38","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-erm-iia-pos-erm-02-1e6dc74e.json","targetId":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-02","type":"informed_by"}],"schemaVersion":1}
