Three Lines, COSO or ISO 37301: which model, when

A recurring confusion in compliance is treating the major frameworks as rival products, as if you had to pick the Three Lines Model or COSO or ISO 37301 and commit. You do not, and the choice is a category error. These three are not competitors. They answer different questions, and a serious compliance programme quietly uses all three, each where it fits. The skill is not choosing one. It is knowing which question you are trying to answer, and reaching for the model built for it.

00.20.50.811Three Lines:who owns it1COSO: doesthe control1ISO 37301:is the
Each framework answers a different question. They stack, they do not compete. Indicative. Source: compliance-framework practice

The three questions, kept separate

The Three Lines Model answers a question about responsibility: for this risk, who owns it, who oversees it, and who independently assures it. It is about roles. COSO answers a question about a control: does this specific control actually work, given the environment, the risk, the information and the monitoring around it. It is about effectiveness. ISO 37301 answers a question about the whole thing: is our compliance system complete and self-improving, from knowing our obligations to feeding lessons back in. It is about the system. Responsibility, effectiveness, completeness. Three different jobs.

The solution, as a decision guide

Reach for the model that fits the question

When you are asking...Reach forBecause it is built for
Who is actually responsible for this risk?Three Lines ModelAssigning ownership, oversight and assurance
Does this control actually work?COSOThe five conditions a control needs to hold
Is our whole compliance system sound?ISO 37301The full loop from obligations to improvement
How much risk should we take here?Risk appetite (ISO 31000)Setting boundaries people can act within
Why did this specific thing fail?Root cause and bowtieTracing cause and mapping barriers

How they stack in practice

In a real programme these layer neatly. ISO 37301 gives you the shape of the whole system. Inside it, the Three Lines Model tells you who does what. Inside each control, COSO tells you whether it will actually hold. And a clear risk appetite sets how far people can go before any of it is triggered. They are not five competing philosophies. They are five tools for five parts of one job, and reaching for the wrong one, using COSO to settle a question of ownership, or the Three Lines to judge whether a control works, is how people end up frustrated with frameworks that were never meant to answer that question.

The trap: adopting a model as an identity

The failure mode is treating a framework as a badge rather than a tool. An organisation announces it "follows COSO" or "has implemented the Three Lines", and then judges everything through that one lens, including the questions it was never designed for. Frameworks are instruments, not identities. The mature stance is to hold all of them lightly, know what each is for, and pick up whichever answers the question in front of you. That is how experienced practitioners actually work, and it is far more useful than loyalty to a single model.

Questions to pick the right model

  • What question am I actually trying to answer, ownership, effectiveness or completeness?
  • Am I forcing one framework to answer a question it was not built for?
  • Do we treat a model as a tool, or as an identity we defend?
  • For this problem, which single model gets me the cleanest answer?
  • Are the frameworks we use stacking together, or competing for the same job?

You never had to choose between the Three Lines Model, COSO and ISO 37301, any more than a builder chooses between a level, a saw and a tape measure. Each answers a different question: who is responsible, does the control work, is the system whole. Learn the question each one is built for, keep them all in the box, and reach for the right one when the moment comes. That is the difference between someone who has adopted a framework and someone who actually understands compliance.

Notes and sources

  1. The IIA Three Lines Model, COSO Internal Control framework and ISO 37301 compliance management systems, three complementary references. Overview via ISO. Link. ↩
Cover of Compliance

From the book

Key Compliance Models

Fifty-eight models of governance, risk and compliance, each explained in plain language and anchored to a real, sourced case.

View on Amazon →

← Back to Writing