Internal audit teams face a structural question as AI systems proliferate: which defense line is responsible for validating, monitoring, and governing these models? The traditional three lines of defense model wasn't designed for technologies that learn, drift, and require continuous oversight. Your challenge isn't just adding AI to existing workflows, it's deciding where accountability sits.
The Decision You're Facing
You need to determine how AI model governance fits into your three lines of defense framework. This isn't a theoretical exercise. Your first line (business units and model owners) wants to deploy faster. Your second line (risk and compliance) is building new oversight capabilities. Your third line (internal audit) needs to evaluate both. The wrong allocation creates gaps where model risks slip through or duplicates effort where three teams validate the same thing.
The core question: Does AI model governance strengthen your existing defense structure, or does it require a fundamental redesign?
Key Factors That Affect Your Choice
Model criticality and risk tier. High-risk AI systems under the EU AI Act or models material to financial decisions under SR 11-7 demand different oversight intensity than low-risk automation. Your defense allocation should match the risk profile.
Technical capability distribution. If your first line lacks data science expertise, pushing model validation responsibilities there creates paper compliance without substance. Conversely, if second-line risk teams don't understand model architectures, they can't provide effective challenge.
Regulatory expectations. ISO/IEC 42001 requires defined roles and responsibilities across the AI lifecycle. The NIST AI RMF Govern function explicitly calls for accountability structures. Your regulator may expect internal audit to independently verify AI governance controls, which constrains how you distribute first- and second-line duties.
Speed of model deployment. Organizations deploying dozens of models monthly need first-line controls that scale. Those deploying a handful of high-stakes systems can afford more centralized second-line review.
Path A: Strengthen Traditional Boundaries
Choose this path when your AI deployment is limited, your models fit established risk categories, and your existing defense lines have sufficient technical depth.
First line owns: Model development, initial validation, deployment approval, and operational monitoring. Business units document model limitations and use restrictions, maintain model inventories, and execute ongoing performance reviews.
Second line owns: Independent model risk policy, risk tiering frameworks, validation standards, and periodic compliance reviews. Risk teams challenge first-line validation evidence, assess vendor model risk, and escalate material model changes.
Third line owns: Audit of governance effectiveness, control testing, and assurance that first- and second-line responsibilities are properly executed.
This works when you're extending model risk management practices you already use for traditional statistical models. If you have mature SR 11-7 programs for credit or market risk models, applying the same three-line structure to AI models maintains consistency.
When this path fails: Your first line deploys a foundation model through an API, and nobody knows which defense layer should assess the provider's post-market monitoring. Or your second line reviews model cards but can't evaluate whether the training data introduces prohibited bias. The traditional boundaries assume static, interpretable models, not systems that require continuous algorithmic auditing.
Path B: Create AI-Specific Hybrid Accountability
Choose this path when AI models introduce risks your traditional defense structure can't handle, or when technical expertise doesn't align with your current line assignments.
First line owns: Business requirements, use case definition, instructions for use, and operational incident response. They're accountable for outcomes but not for validating the model's internal mechanics.
Second line owns: End-to-end AI model governance, including validation, approval, ongoing monitoring, and vendor due diligence. This becomes a specialized risk function with data science capability, not a policy-writing team.
Third line owns: Governance process audits and independent testing of high-risk systems, potentially using external AI audit specialists.
This path recognizes that effective model validation requires technical depth most first-line business units don't have. You're centralizing AI-specific expertise in the second line while keeping business accountability in the first.
Implementation specifics: Your second line builds or acquires capabilities in adversarial simulation, bias mitigation assessment, and reproducibility testing. They maintain the AI system impact assessment process required by ISO/IEC 42005. They own the General-Purpose AI Code of Practice compliance review if you're using foundation models.
When this path fails: Your second line becomes a bottleneck. Every model deployment waits for centralized review, slowing time-to-value. Or the second line lacks authority to block deployments, turning governance into advisory theater.
Path C: Distributed Governance with Clear Escalation
Choose this path when you're deploying AI at scale across multiple business units, each with varying technical maturity and risk appetites.
First line owns: Model development, initial validation using standardized templates, and Tier 1/2 model approvals (low and moderate risk). They execute validation evidence collection per ISO/IEC 5338 lifecycle processes and maintain system cards.
Second line owns: Validation framework and standards, Tier 3/4 model approvals (high risk and systemic risk), vendor model risk assessment, and challenge of first-line validation for material models. They define what constitutes adequate validation evidence and when independent review is required.
Third line owns: Audit of the tiering framework itself, testing whether first-line validations meet second-line standards, and independent assessment of your highest-risk AI systems.
This path scales governance by pushing routine oversight to the first line while reserving second-line capacity for complex, high-stakes models. It requires robust model risk tiering criteria and clear escalation triggers.
Critical success factor: Your tiering framework must be specific. "High-risk AI" isn't enough, you need defined thresholds. For example: models processing personal data of more than 10,000 individuals, models influencing credit decisions above $1M, or any General-Purpose AI Model with Systemic Risk as defined in the EU AI Act.
When this path fails: First-line teams game the tiering system to avoid second-line review. Or your escalation criteria are so broad that everything gets flagged as high-risk, collapsing back into Path B's bottleneck.
Summary Matrix
| Factor | Path A: Traditional | Path B: Hybrid | Path C: Distributed |
|---|---|---|---|
| Best for | Limited AI deployment, mature model risk programs | High technical complexity, centralized expertise | Scale deployment, varying business unit maturity |
| First-line capability requirement | High (full validation) | Low (business context only) | Moderate (templated validation) |
| Second-line role | Policy and challenge | End-to-end governance | Standards and high-risk approval |
| Scalability | Low | Moderate | High |
| Control strength | Depends on first-line skill | High if properly staffed | Moderate with strong tiering |
| Regulatory fit | SR 11-7 for traditional models | ISO/IEC 42001, EU AI Act high-risk systems | NIST AI RMF with risk-based approach |
Your choice isn't permanent. Many organizations start with Path B to build capability, then migrate to Path C as first-line teams mature. What you can't do is leave the question unanswered, ambiguity about which line owns AI model validation is itself a material control gap.
The three lines of defense model still works for AI. But only if you're explicit about where technical accountability sits, what triggers escalation, and how internal audit independently verifies the whole structure holds.



