
A recurring confusion in compliance is treating the major frameworks as rival products, as if you had to pick the Three Lines Model or COSO or ISO 37301 and commit. You do not, and the choice is a category error. These three are not competitors. They answer different questions, and a serious compliance programme quietly uses all three, each where it fits. The skill is not choosing one. It is knowing which question you are trying to answer, and reaching for the model built for it.
The three questions, kept separate
The Three Lines Model answers a question about responsibility: for this risk, who owns it, who oversees it, and who independently assures it. It is about roles. COSO answers a question about a control: does this specific control actually work, given the environment, the risk, the information and the monitoring around it. It is about effectiveness. ISO 37301 answers a question about the whole thing: is our compliance system complete and self-improving, from knowing our obligations to feeding lessons back in. It is about the system. Responsibility, effectiveness, completeness. Three different jobs.
The solution, as a decision guide
Reach for the model that fits the question
| When you are asking... | Reach for | Because it is built for |
|---|---|---|
| Who is actually responsible for this risk? | Three Lines Model | Assigning ownership, oversight and assurance |
| Does this control actually work? | COSO | The five conditions a control needs to hold |
| Is our whole compliance system sound? | ISO 37301 | The full loop from obligations to improvement |
| How much risk should we take here? | Risk appetite (ISO 31000) | Setting boundaries people can act within |
| Why did this specific thing fail? | Root cause and bowtie | Tracing cause and mapping barriers |
How they stack in practice
In a real programme these layer neatly. ISO 37301 gives you the shape of the whole system. Inside it, the Three Lines Model tells you who does what. Inside each control, COSO tells you whether it will actually hold. And a clear risk appetite sets how far people can go before any of it is triggered. They are not five competing philosophies. They are five tools for five parts of one job, and reaching for the wrong one, using COSO to settle a question of ownership, or the Three Lines to judge whether a control works, is how people end up frustrated with frameworks that were never meant to answer that question.
The trap: adopting a model as an identity
The failure mode is treating a framework as a badge rather than a tool. An organisation announces it "follows COSO" or "has implemented the Three Lines", and then judges everything through that one lens, including the questions it was never designed for. Frameworks are instruments, not identities. The mature stance is to hold all of them lightly, know what each is for, and pick up whichever answers the question in front of you. That is how experienced practitioners actually work, and it is far more useful than loyalty to a single model.
Questions to pick the right model
- What question am I actually trying to answer, ownership, effectiveness or completeness?
- Am I forcing one framework to answer a question it was not built for?
- Do we treat a model as a tool, or as an identity we defend?
- For this problem, which single model gets me the cleanest answer?
- Are the frameworks we use stacking together, or competing for the same job?
You never had to choose between the Three Lines Model, COSO and ISO 37301, any more than a builder chooses between a level, a saw and a tape measure. Each answers a different question: who is responsible, does the control work, is the system whole. Learn the question each one is built for, keep them all in the box, and reach for the right one when the moment comes. That is the difference between someone who has adopted a framework and someone who actually understands compliance.
Notes and sources
From the book
Key Compliance ModelsFifty-eight models of governance, risk and compliance, each explained in plain language and anchored to a real, sourced case.
