The three lines model
Institute of Internal Auditors · 2013Who owns a risk, who oversees it, and who independently checks both — kept as three distinct roles.
The first line owns and manages risk in the work itself; the second sets policy and monitors; the third gives independent assurance to the governing body. The point is separation: assurance given by the people who would have to report their own failure is not assurance, whatever it is called.
- Reach for it when
- When setting up how risk and assurance are organised, and when it is unclear who is actually responsible for a control.
- Where it stops
- Read as an org chart it produces bureaucracy and a first line that believes risk is someone else’s department. The 2020 revision exists largely because of that.
Institute of Internal Auditors, “The Three Lines of Defense in Effective Risk Management and Control”, position paper, 2013; The IIA’s Three Lines Model, 2020.
ISO 31000 risk management
International Organization for Standardization · 2009A common set of principles and a process for identifying, assessing, treating and monitoring risk.
It gives a vocabulary and a cycle rather than a checklist, and deliberately is not certifiable. Its most useful contribution to ordinary practice is the insistence that risk is defined against objectives — which means you cannot assess risk at all until someone has said what the organisation is trying to do.
- Reach for it when
- When building a risk process from nothing, or when everyone in the room means something different by the word risk.
- Where it stops
- It is a framework for process, not a source of judgement. It will not tell you what your risks are or how much of them to accept.
ISO 31000, Risk management — Guidelines, International Organization for Standardization, 2009; revised 2018.
COSO Enterprise Risk Management
Committee of Sponsoring Organizations of the Treadway Commission · 2004Also known as COSO ERM
Risk treated as part of setting and carrying out strategy, overseen by the board, rather than as a list kept by a specialist.
The first version extended internal control to risk across the whole enterprise; the 2017 revision went further and tied risk explicitly to strategy and performance, with governance and culture as its starting point. Its useful claim is that the largest risk is often the strategy itself — the chance that the chosen direction does not fit the organisation’s purpose or its appetite for risk.
- Reach for it when
- When the board receives a risk register every quarter and nothing in it has ever changed a decision.
- Where it stops
- It is broad and demanding, and easily reduced to a heat map that satisfies the auditors. It offers structure, not judgement about which risks are worth taking.
Committee of Sponsoring Organizations of the Treadway Commission, Enterprise Risk Management — Integrated Framework, 2004; Enterprise Risk Management — Integrating with Strategy and Performance, 2017. COSO is named here only to refer to its published work.
Agency theory
Michael C. Jensen & William H. Meckling · 1976Also known as The principal–agent problem
Those who run a company and those who own it want different things, and governance exists largely to manage the gap.
Owners delegate to managers who know more and have their own interests, so owners bear costs to monitor them, managers bear costs to reassure owners, and some value is lost anyway. Boards, audits, incentive pay and disclosure rules can all be read as attempts to shrink that loss — which is also a way of asking whether any of them actually does.
- Reach for it when
- When designing a board, an incentive scheme or a reporting line, and when management and owners seem to be pulling in different directions without anyone saying so.
- Where it stops
- It assumes people are narrowly self-interested, and designs built only on that assumption can crowd out the loyalty and professionalism they fail to count. It also says little about owners who want more than returns.
Michael C. Jensen & William H. Meckling, “Theory of the Firm: Managerial Behavior, Agency Costs and Ownership Structure”, Journal of Financial Economics, 1976.
These are other people’s models, named here so you can go to the source and use them properly. The Omnigoal is not affiliated with their authors and is not endorsed by them; nothing of theirs is reproduced here — no canvas, no diagram, no wording. Each is described in our own words, with the originator credited, because the framework is a place to put thinking, not a replacement for the people who did it. Model names and trademarks belong to their respective owners and are used here only to refer to the work itself.