The board report says controls are in place. The manager says issues are being monitored. But when an incident is reviewed, no one can show who owned the control, who challenged it, or who independently tested it.
If assurance lines blur, governance becomes reassurance instead of evidence.
The three lines of defense model is widely referenced in governance documents, yet it often breaks down in community-based services. Roles overlap, managers step into delivery, and assurance becomes informal. Providers need a practical model that separates delivery, oversight, and independent testing while remaining realistic in day-to-day operations.
This work aligns closely with board governance and accountability and risk ownership and assurance lines, where leaders must show how risk is owned, challenged, and independently tested. The Leadership, Governance & Organisational Capability Knowledge Hub supports this by connecting governance theory to practical organisational control.
This is where assurance either becomes defensible—or stays symbolic.
Why the three lines model breaks down in practice
The model fails when organizations misunderstand separation. The first line owns delivery and applies controls. The second line checks, challenges, and supports improvement. The third line independently tests whether the first two lines are working.
In community services, these boundaries can collapse quickly. Managers cover shifts, quality teams help fix records, and leaders accept verbal assurance because teams are under pressure.
That may solve today’s problem, but it weakens governance evidence.
Operational Example 1: First-line ownership at shift level
A provider identifies repeated gaps in visit completion, medication prompts, and welfare checks. The issue is not that controls do not exist. The issue is that no named person owns them during each shift.
The provider assigns a shift lead for every service period. The shift lead owns first-line confirmation of critical controls before handover.
Required fields must include: shift lead, visit completion status, missed controls, incidents, escalation decisions, and unresolved risks.
The process cannot proceed without: confirmation that each critical control has been completed, escalated, or recorded as unresolved.
The supervisor receives the shift confirmation and reviews exceptions before the next operational cycle.
Auditable validation must confirm: first-line controls are actively owned at shift level and exceptions are visible before they drift.
This prevents responsibility from diffusing across the team. It also gives managers real evidence rather than informal reassurance.
Operational Example 2: Second-line management challenge without taking over delivery
A program manager notices that missed-control logs are increasing. In weaker systems, the manager fixes the issue directly—rewriting notes, chasing staff, or completing corrections themselves.
A stronger second-line process keeps the manager in challenge mode. The manager reviews trends weekly and requires the first-line owner to correct gaps, explain causes, and confirm completion.
Required fields must include: trend reviewed, risk rating, challenge raised, action owner, deadline, and follow-up decision.
Cannot proceed without: evidence that the first line has responded to the challenge and completed the corrective action.
The manager records whether the issue reflects workload pressure, unclear guidance, training gaps, or poor compliance.
Auditable validation must confirm: second-line review challenges patterns and tracks correction without replacing first-line ownership.
This protects assurance integrity. Management oversight remains visible, but delivery responsibility does not disappear.
This is where assurance becomes challenge, not rescue.
Operational Example 3: Third-line independent testing for board confidence
A board receives positive summaries about safeguarding escalation, but incident reviews suggest that some concerns were escalated late. Leadership commissions a targeted internal audit.
The audit team selects a sample of safeguarding cases and tests whether first-line controls occurred, whether second-line challenge identified gaps, and whether corrective actions were completed.
Required fields must include: audit scope, sample selected, evidence reviewed, findings, rating, and board-level action required.
The audit cannot proceed without: independence from the service area being tested and direct reporting to senior leadership or the board.
The audit identifies that managers reviewed incidents but did not consistently challenge delayed escalation. The board requires revised escalation reporting and follow-up testing within the next quarter.
Auditable validation must confirm: third-line testing independently verifies whether first and second-line controls are working.
Without this layer, boards rely on management self-report. With it, they can evidence informed oversight.
System and regulator expectations
Boards are expected to demonstrate separation between control ownership, management oversight, and independent assurance. This does not require bureaucracy, but it does require clarity.
Regulators and funders will look for evidence that assurance includes challenge and correction. Compliance statements alone are weak if they are not backed by records, testing, and follow-up.
Making the model usable in community services
The three lines of defense model only works if it fits service reality. Providers do not need complex structures for every risk, but they do need clear rules for who owns controls, who challenges performance, and who independently tests reliability.
Good assurance should help services see risk earlier, not add paperwork after failure.
Conclusion
The three lines of defense model is valuable only when it works in practice. In community services, that means making ownership visible at shift level, ensuring managers challenge without taking over, and giving boards independent evidence that controls are reliable.
The strongest providers use the model to protect clarity. They can show who delivered, who challenged, who tested, and what changed when gaps appeared.
When assurance lines are clear, governance becomes evidence. When they blur, risk hides behind reassurance.