AI Governance Institute
All governance templates →How do we apply a three lines of defense model to AI risk?

Implementation Kit

AI Three Lines of Defense RACI and Audit Templates

Applying the three-lines model to AI risk without the second line rubber-stamping what it cannot evaluate. A RACI across the lines, a second-line technical literacy assessment, a risk committee reporting template, and a third-line audit program.

Who this is for: The risk or audit leader mapping AI risk onto an existing three-lines structure.

Download the kit (Markdown) ↓4 artifacts. Every table also copies as CSV.

1. Three lines of defense RACI for AI

Spreadsheet

Each governance activity assigned across first line (owns and manages), second line (oversees and challenges), and third line (independent assurance).

Template

ActivityFirst line (business / product)Second line (risk / compliance)Third line (internal audit)
AI system inventory and classificationR/AC (challenge tiering)I (test completeness)
Model risk assessmentRA (set method, review)I
Bias and performance testingR (run)A (standard, review results)I (re-perform sample)
Human oversight operationR/ACI
Vendor AI riskRAI
Incident responseRCI
Regulatory obligation trackingCR/AI
Governance reporting to the boardCRA (opinion on the program)

Worked example

The contested calls, with the reasoning.

ActivityFirst lineSecond lineThird line
Bias testingruns it in the model pipelineowns the methodology; reviews every high-risk result pre-shipre-performs on a sample of models each year
Regulatory trackingconsulted on which systems are affectedR/A (compliance owns it)tests coverage
Board reportingconsulteddrafts the reportindependent opinion on whether the program is effective, not just present

Acceptance criteria

  • Every activity has one accountable line, and the second line's role is challenge, not execution.
  • Third line has an independent assurance role on every activity, including the program itself.
  • Role labels match the organization's actual functions.

2. Second-line AI technical literacy assessment

Spreadsheet

Confirms the oversight function can actually evaluate what it signs off. Oversight without competence is theatre.

Template

CapabilityNeeded to overseeCurrent stateGap action
Read and question a model card and eval reportmodel risk sign-off
Interpret a disparate-impact and subgroup analysisbias oversight
Assess whether a human oversight design is meaningfuloversight review
Evaluate a red-team report and residual risksecurity sign-off
Understand agentic autonomy and containment conceptsagent deployments
Read a monitoring dashboard and judge a drift responseongoing oversight

Worked example

CapabilityCurrent stateGap action
Question a model card / eval1 of 4 risk staff comfortabletraining + a technical advisor embedded
Interpret disparate-impact analysis2 of 4workshop with DS; a checklist aid
Judge human oversight designstrongnone
Evaluate a red-team reportweakpair with Security on the next two reviews
Agentic conceptsnonebring in external training Q4
Read monitoring dashboardsmoderateshadow the ML on-call review monthly

Acceptance criteria

  • Each capability is rated against a real standard, not self-declared confidence.
  • Gaps have a concrete action (training, advisor, pairing), not "upskill".
  • The assessment is repeated as the second line takes on new AI risk types.

3. AI risk committee reporting template

Document

The second line's standing report to the risk committee: posture, movement, and what needs a decision.

Template

One to two pages, standing agenda item.

  • AI risk posture: systems by tier; high-risk systems with an open control gap; overdue reviews
  • Movement since last meeting: new systems, retired systems, tier changes, closed and opened gaps
  • Incidents and near-misses: count by severity, status, lessons
  • Second-line challenges raised: where oversight pushed back on first line, and the outcome
  • Regulatory: obligations approaching, readiness
  • Third-line findings: open audit findings and remediation status
  • Decisions requested

Worked example

  • Posture: 47 systems (3 High, 12 Limited, 32 Minimal). 1 High-tier gap (resume-screener oversight design). 4 overdue reviews, down from 7.
  • Movement: 2 new (both Limited); support-copilot moved Minimal to Limited; F-1 gap closed.
  • Incidents: 0 Sev-1, 2 Sev-2 (both closed with fixes).
  • Second-line challenges: blocked a fraud-model deploy pending an updated bias eval; resolved in 5 days.
  • Regulatory: CA ADMT product work at risk; escalated.
  • Third-line: 2 open findings from the H1 audit, both on track.
  • Decisions requested: approve Q1 budget for ADMT tooling.

Acceptance criteria

  • The report shows movement, not just a snapshot.
  • It records where the second line challenged the first line and what happened.
  • Third-line findings and their status appear every cycle.

4. Third-line AI audit program

Spreadsheet

What internal audit tests to give an independent opinion on the governance program, not just individual systems.

Template

Audit areaWhat is testedMethodFrequency
Inventory completenessis every AI system actually captured?independent discovery, compare to the registerannual
Classification accuracyare tiers assigned correctly and consistently?re-classify a sampleannual
Control operationdo documented controls actually run?test a sample against system behaviour, not just policyannual
Second-line effectivenessdoes oversight have competence and independence?review challenge logs; competence assessmentannual
Incident handlingwere incidents classified, notified, and remediated per policy?trace a sample end to endannual
Board reporting accuracydoes the board picture match reality?reconcile a past report to source dataannual

Worked example

H1 audit summary.

Audit areaResult
Inventory completenessindependent discovery found 2 systems not in the register (both Minimal); onboarding checkpoint not consistently applied
Classification accuracyre-classified 10; 1 disagreement (borderline Limited/High), resolved to High
Control operationtested 8 controls on 6 systems; 2 "documented not enforced" (monitoring alerting, low-score review)
Second-line effectivenesschallenge log healthy; competence gap on red-team evaluation noted
Overall opinioneffective, with improvements needed on control enforcement and onboarding discipline

Acceptance criteria

  • Audit uses independent testing (re-discovery, re-classification, behaviour testing), not self-reported status.
  • The program tests the second line and the board reporting, not only first-line systems.
  • It produces an overall opinion on program effectiveness.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

MGV-004
MGV-004

The RACI and third-line program are the continuous AI assurance function design.

BRD-005
BRD-005

The third-line opinion and any maturity grid feed the governance maturity assessment.

BRD-002
BRD-002

The three-lines RACI clarifies committee decision rights and escalation.

HOC-007
HOC-007

The risk committee reporting template is board and committee risk reporting.

MGV-003
MGV-003

Audit findings become governance-program milestones.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →