
Blog Post
The Second Line Cannot Challenge What It Cannot Evaluate
August 24, 2026
The three lines model rests on an assumption that holds well in financial risk and poorly in cyber. It assumes the second line can evaluate the first line's work independently, which requires the second line to understand that work at least as well as the people doing it.
In model risk management at a bank, that assumption is satisfied by staffing. The independent review function employs people who can re-derive a model's output and disagree with it on technical grounds. In cyber, the expertise sits almost entirely in the first line, and the risk function is rarely equipped to judge whether a control was rated correctly.
Challenge Degrades Into Evidence Collection
Where the second line cannot assess the substance, it falls back on what it can verify. Was an assessment performed, was it signed, is there a document, did the date fall inside the window.
All of that is worth doing and none of it is challenge. A control rated as effective by the team that operates it, reviewed by a function that cannot evaluate the rating, produces a governance record with no independent judgment anywhere in it. The examination happens, the paperwork exists, and nobody has genuinely disagreed with anything.
Everyone Involved Knows
This is rarely a secret inside the organization. First line teams describe second line review as a documentation exercise, second line staff describe their position as asking questions they cannot evaluate the answers to, and both are correct. Naming it is more productive than the alternative, which is a governance structure everyone privately discounts.
Give the Second Line Something Disputable
The resolution is not to hire security engineers into the risk function, which is expensive and tends to recreate the first line. It is to express the first line's conclusions in a form that can be argued with by someone who is not a security engineer.

A control maturity rating of three is an expert judgment. Disagreeing with it requires equivalent expertise, which is exactly what the second line lacks. A modeled exposure figure is a different object, because it decomposes into assumptions that are separately arguable.
What Becomes Available to Argue With
Whether the asset value used reflects what the business would lose. Whether the assumed frequency is consistent with the organization's own incident history. Whether two scenarios treated as independent share a dependency. Whether the peer comparison uses a sensible cohort. None of those requires knowing how a firewall rule is written, and all of them can materially change the output.
Disagreement Becomes Recordable
An argument about an assumption produces something a third line can later examine, which an argument about a maturity rating does not. The record shows what was contested, what the first line answered and whether the figure changed, which is the evidence that challenge occurred rather than an assertion that it did. Directors reading an oversight pack look for exactly that record. A register built for decisions holds that exchange rather than only the conclusion.
Where the Lines Blur in Practice
Three structural situations recur, and each weakens independence in a different way.
- The Security Function Reports Into Technology: First and second line then share an executive, so an uncomfortable finding travels up a single chain.
- Operations Sits in Both: A security operations team detecting incidents is first line, and the same team reporting on control performance is acting as second.
- One Team Writes and Tests: Where the group defining a control standard also assesses conformance to it, the assessment measures agreement with itself.
None of these is unusual and all are survivable, provided the arrangement is documented and compensated for rather than described as three independent lines on an organization chart. An examiner will identify the reporting structure before examining any assessment, and where GRC programs break down operationally covers the wider pattern.
The Third Line Has the Same Problem, Compounded
Internal audit is expected to provide independent assurance over both lines, and cyber expertise in internal audit functions is scarcer still. The common resolution engages an external specialist, which supplies technical capability and reintroduces a dependency on somebody outside the organization's own assurance chain.

Auditing a Number Requires the Methodology
Assurance over a quantified figure is achievable without deep security expertise provided the model is transparent about its inputs and its versions. An auditor can test whether stated assumptions match documented reality, whether changes between periods were methodology or environment, and whether the same inputs reproduce the same output. The work is ordinary audit practice applied to an unfamiliar subject, and it is considerably more tractable than auditing an opinion. Model stability is the property that makes reproduction a fair test.
Making It Work Without Reorganizing
Reporting lines are rarely within a risk function's gift to change. Four adjustments work inside an imperfect structure.
Express first line conclusions in a form the second line can contest, which is the change that does the most work. Document the dependency explicitly where lines share an executive, so the limitation is visible rather than implied. Create an escalation route that reaches a body outside the shared chain, and record escalations whether or not they changed anything, since a record of rejected challenges is stronger evidence of a functioning mechanism than an absence of disagreement. Separating the standard-setting activity from the assessment activity completes it, even where one function holds both, so that at least the timing and the individuals differ.
Effective Challenge Needs Standing, Not Only Scope
A function permitted to raise concerns and not permitted to delay anything performs review rather than challenge. Defining the threshold at which the second line can require remediation before a system proceeds gives the arrangement teeth, and tying that threshold to a stated appetite that can be breached is what makes it a rule rather than a negotiation.
What the Model Was Updated to Say
The framework itself moved on from the rigid separation most cyber programs still cite. The governing body responsible for it reframed the model around coordinated roles and value creation rather than sequential defensive barriers, and de-emphasized strict independence in favor of defined accountability.
Read that way the objective is not three walls but knowing who owns a decision, who reviews it and who assures the arrangement, with the overlaps documented rather than denied. A cyber program that described its real structure, including where lines merge, would be closer to the current model than one presenting a clean diagram nobody recognizes.
Independence Requires Capability
The three lines arrangement fails in cyber less because reporting structures are compromised, though they often are, than because the reviewing function cannot evaluate what it reviews. Structural fixes address the first problem and leave the second untouched. Expressing security conclusions as figures with stated assumptions gives the second line a legitimate basis for disagreement without requiring it to become a second security team, and gives the third line something auditable. Kovrr's cyber risk quantification records assumptions, model versions and peer comparisons alongside each figure, which is what makes the challenge substantive.
To see security conclusions expressed in a form a risk function can genuinely contest, book a demo with our cyber risk experts.
Three Lines Model FAQs
Speak to an ExpertWhy does the three lines model struggle in cybersecurity?
Because it assumes the second line can independently evaluate the first line's work, which requires comparable expertise. In model risk management at a bank that assumption is satisfied by staffing, since the review function employs people who can re-derive a model's output and disagree on technical grounds. In cyber the expertise sits almost entirely in the first line, so the risk function is rarely equipped to judge whether a control was rated correctly, and challenge falls back to verifying that an assessment happened rather than whether it was right.
What does challenge look like when it degrades?
It becomes evidence collection. The second line verifies that an assessment was performed, that it was signed, that a document exists and that the date fell inside the window. All of that is worth doing and none of it is challenge. A control rated effective by the team operating it, reviewed by a function that cannot evaluate the rating, produces a governance record containing no independent judgment. Most people inside the organization already know this, and naming it is more productive than maintaining a structure everyone privately discounts.
How can a second line challenge without security expertise?
By having the first line's conclusions expressed in a form that decomposes into arguable assumptions. A control maturity rating is an expert judgment requiring equivalent expertise to dispute. A modeled exposure figure separates into whether the asset value reflects what the business loses, whether assumed frequency matches the organization's own incident history, whether scenarios treated as independent share a dependency, and whether peer comparison uses a sensible cohort. None of those requires knowing how a firewall rule is written, and each can materially change the output.
Where do the lines blur most often in cyber?
Three situations recur. The security function reporting into technology, so first and second line share an executive and uncomfortable findings travel up one chain. Security operations sitting in both, since a team detecting incidents is first line while the same team reporting on control performance acts as second. And one team both writing a control standard and assessing conformance to it, where the assessment measures agreement with itself. None is unusual and all are survivable if documented and compensated for rather than presented as three independent lines.
How does internal audit assure a quantified figure?
More easily than it assures an expert opinion, provided the model is transparent about inputs and versions. An auditor can test whether stated assumptions match documented reality, whether movement between periods came from methodology changes or from the environment, and whether the same inputs reproduce the same output. The work is ordinary audit practice applied to an unfamiliar subject. Auditing a maturity rating, by contrast, requires the technical judgment internal audit functions usually lack and typically source externally.
What can be improved without changing reporting lines?
Four adjustments work inside an imperfect structure. Express first line conclusions in a contestable form, which does the most work. Document the dependency explicitly where lines share an executive, so the limitation is visible rather than implied. Create an escalation route reaching a body outside the shared chain and record escalations whether or not they changed anything, since rejected challenges evidence a functioning mechanism better than an absence of disagreement. And separate standard-setting from assessment even within one function, so timing and individuals differ.




