Three Lines for AI: A Fiduciary Framework for Board Oversight
Forward-looking analysis and opinion — not a description of current law or a regulatory requirement. Verify against primary sources before relying on it for a board decision.
Three Lines for AI: A Fiduciary Framework for Board Oversight
This article reflects BoardSight's analysis. It is not legal advice. The full standard-by-standard result and coding method are available on request and summarized on our methodology page.
Executive Summary
This review examines 14 governance standards a board can obtain today to outline a practical framework for AI oversight aligned with the IIA's Three Lines Model. Our key finding: of those 14 standards, only one — SR 11-7, a 2011 banking rule — actually requires an independent second line for AI, while nearly all of them are explicit about first-line operational ownership. That asymmetry leaves boards with gaps in exactly the areas — compliance, bias, and regulatory alignment — that draw oversight scrutiny under the Caremark line of Delaware cases.
Methodology: One Question, 14 Board-Available Standards
We reviewed 14 governance standards a board can obtain today — among them NIST AI RMF, ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 38507, the EU AI Act, NIST CSF 2.0, COSO ERM, the IIA Three Lines Model, SR 11-7, and COBIT 2019 — and asked one question of each: does it require an independent second line for AI, separate from the teams building or operating the system and separate from internal audit? Every verdict is tied to a specific cited clause, so any reader can pull the same documents and check us. This is preliminary, versioned research; the full crosswalk is available on request.
The Three Lines Model for AI Governance
First line: operational management. The operational line owns day-to-day AI performance, data quality, and technical control — engineering and data-science teams, monitoring and logging, model-drift detection, and explainability upkeep. Coverage finding: nearly every standard explicitly assigns first-line operational ownership.
Second line: risk & compliance oversight. The second line is the independent check on AI risk — regulatory compliance, bias and fairness review, data governance and privacy, risk-appetite calibration, and the Three Lines structure itself. Coverage finding: only 1 of the 14 standards actually requires an independent second line. Most mention risk oversight but leave the independent challenge function optional, assuming risk ownership sits at the operational level.
Third line: internal audit. Internal audit gives independent assurance on AI risk management and controls — periodic control testing, model validation, governance-process audits, and findings follow-up. Coverage finding: most standards address audit-level assurance — though it inspects, after the fact, what the second line was meant to catch first.
The Second-Line Gap: What the Review Shows
The second-line gap is structural: the field often conflates operational resilience with risk governance. A plant can run smoothly (first-line excellence) while breaching environmental rules (second-line failure). An AI system can score well on accuracy while breaching data-governance policy, introducing bias, or creating regulatory exposure.
The second-line gap means audit committees inherit blind spots in compliance, bias, and regulatory alignment — the very risks that draw oversight scrutiny.
Fiduciary Implications
Delaware's Caremark doctrine (1996) holds that directors can face liability if they fail to make a good-faith effort to establish systems to monitor material risks. Later cases extend it:
- Marchand v. Barnhill (2019): applied Caremark to "mission-critical" risks, not just financial controls.
- Boeing (2021): reinforced that directors must act on clear "red flags."
- SEC disclosure focus on AI (ongoing): the SEC has signaled that existing materiality-based disclosure obligations already apply to AI-related risks. A dedicated AI-governance disclosure requirement currently exists only as a rulemaking petition (SEC File No. 4-882) — not an adopted or proposed rule.
Together, these developments strengthen the expectation that boards maintain credible oversight of material AI risk. Whether a given board's AI use is "mission-critical" is company-specific and fact-intensive; where directors know of material AI deployment and keep no monitoring system at all, they are on weaker ground under the Caremark line. This is our analysis, not legal advice.
Building Second-Line AI Governance
To close the gap, boards should look for: clear second-line ownership of AI compliance, bias review, and risk appetite; measurable coverage of high-risk AI applications; independence from operational teams; a regular reporting cadence to the audit committee; and a defined escalation path for compliance issues and red flags. Cognitive Corp's Building Constitution framework (explainability, human-in-the-loop, bias mitigation) is designed to operationalize these across the three lines.
Regulatory Backdrop: EU AI Act, NIST, ISO/IEC 42001
The EU AI Act applies in phases and sets obligations across the AI value chain. For deployers of high-risk AI, Article 26 requires, among other things: using the system in line with the provider's instructions, assigning human oversight to competent people, monitoring operation and keeping logs, and reporting incidents. A separate fundamental-rights impact assessment applies to certain deployers under Article 27. The Act does not prescribe any single "second-line" org chart; we map its obligations onto the Three Lines model as a practical operating frame. (After the 2025 Digital Omnibus, high-risk obligations for stand-alone Annex III systems apply from December 2027.)
NIST's AI Risk Management Framework and ISO/IEC 42001 similarly treat governance as distinct from technical controls, which supports the case for a real second line — even though, as our review shows, neither requires one.
Recommendations for Boards
- Run a Three Lines maturity check — map current AI oversight to the three lines and find the second-line gaps.
- Name second-line accountability — give a risk or compliance owner explicit AI oversight responsibility.
- Keep an AI risk register — track high-risk AI applications with a second-line review cadence.
- Monitor coverage — report to the audit committee on the share of AI applications with documented second-line review.
- Track regulatory expectations — EU AI Act, SEC, and FCA developments all point toward stronger internal oversight of AI.
Conclusion
The second-line gap is a governance problem, not just an operational one. Boards that close it gain clarity on compliance, bias, and regulatory exposure. Those that don't inherit undocumented risk. The Three Lines Model, applied honestly to AI, is the practical fix.
Claim status: qualified
Facts checked: 2026-07-22
Reviewed by: BoardSight Editorial Review (regulatory)
Scope: EU (AI Act Arts. 26–27) and US (SEC disclosure, Delaware Caremark). Analysis, not legal advice.
Primary sources: EU AI Act — Regulation (EU) 2024/1689: https://eur-lex.europa.eu/eli/reg/2024/1689/ · SEC rulemaking petition, File No. 4-882: https://www.sec.gov/rules-regulations/2026/02/4-882 · SEC statement on disclosure review: https://www.sec.gov/newsroom/speeches-statements/gerding-statement-state-disclosure-review-062424