Back to InsightsExecutive Brief

The Three Lines Model, Instrumented for AI — Executive Brief

By James WaddellApril 9, 20265 min

The Three Lines Model, Instrumented for AI — Executive Brief

Three Converging Pressures on Audit Committees

Audit committees face a convergence of three pressures in 2026 that put AI governance on the fiduciary plate:

  1. EU AI Act Enforcement (phased from 2025): High-risk AI systems carry binding obligations — risk management, human oversight, documentation, logging, and transparency (Articles 9, 14, 26). The Act stops short of mandating an independent second-line governance body, but it pushes hard in that direction. Extraterritorial scope means US and global companies deploying AI in Europe, or affecting EU residents, can be in scope.

  2. SEC Disclosure Expectations: The SEC has signaled that existing materiality-based disclosure obligations already apply to AI-related risks — compliance, bias, regulatory, and operational. A dedicated AI-disclosure rule currently exists only as a rulemaking petition, not an adopted or proposed rule.

  3. Caremark Duty (Delaware courts): Directors can face liability where they make no good-faith effort to establish oversight of material, "mission-critical" risks (Marchand, 2019; Boeing, 2021). Whether AI meets that threshold is company-specific and fact-intensive — but for many boards it increasingly does.

Together, these forces raise the expectation that boards maintain credible oversight of material AI risk.

Mapping the Three Lines to AI Risk

First Line: Operational Management

  • AI teams own performance, monitoring, explainability
  • Daily model management, drift detection, logging
  • Cognitive Corp BAGI alignment: Operational scorecard (accuracy, latency, uptime)

Second Line: Risk & Compliance Oversight

  • Compliance team owns regulatory alignment, bias review, data governance
  • Quarterly or semi-annual governance reviews
  • Direct escalation for violations
  • Cognitive Corp BAGI alignment: Governance index (compliance, fairness, transparency)

Third Line: Internal Audit

  • Audit function tests controls, validates models, assesses governance process
  • Annual or semi-annual independent audit
  • Cognitive Corp BAGI alignment: Audit readiness and findings follow-up

The Cognitive Corp Governance Stack: Building Constitution

Cognitive Corp's Building Constitution operationalizes the Three Lines across three pillars:

| Pillar | First Line | Second Line | Third Line | |--------|-----------|------------|-----------| | XAI (Explainable AI) | Model interpretation, feature importance | Compliance explanation requirements | Audit readiness for explanations | | HITL (Human-in-the-Loop) | Human sign-off protocols | Policy compliance review | Governance of escalation paths | | Bias Mitigation | Fairness monitoring | Bias review threshold | Bias testing and follow-up |

This framework closes the second-line collapse by making compliance, transparency, and fairness explicit governance responsibilities.

Five Concrete Next Steps for Audit Committees

Q2 2026:

  1. Inventory AI Applications: Map all operational AI systems. Classify by risk level (high, medium, low) using EU AI Act criteria.
  2. Appoint Second-Line Owner: Name a Chief Risk Officer or Chief Compliance Officer with explicit AI governance responsibility.

Q3 2026: 3. Implement Risk Register: Deploy the 7-column risk register (see separate brief). Baseline assessment of all high-risk systems. 4. Establish Governance Cadence: Quarterly second-line AI governance review to the audit committee.

Q4 2026: 5. Align with Regulatory Timeline: Map EU AI Act enforcement phases to your disclosure calendar. Prepare for AI disclosure if material risk exists.

Why This Matters: The Fiduciary Picture

For many boards, doing nothing on AI governance is now the harder position to defend.

A board that knows AI is material to the company and makes no good-faith effort to oversee it is on weaker ground under the Caremark line of cases (Marchand, Boeing). This is a company-specific, fact-intensive standard — not an automatic rule — but the direction of Delaware law, together with EU and SEC expectations, points toward stronger internal oversight of AI.

Boards that act now build a documented record of oversight. Boards that delay have less to show if the question is ever asked.

Quick-Start Governance Checklist

  • [ ] AI applications inventory completed
  • [ ] Second-line owner appointed with explicit AI responsibility
  • [ ] Risk register deployed and populated
  • [ ] Quarterly reporting cadence established
  • [ ] EU AI Act timeline mapped
  • [ ] SEC disclosure risk assessment completed
  • [ ] Board oversight policy updated to include AI

This brief reflects BoardSight's analysis and is not legal advice.

Reading time: 5 minutes

B
BoardSight

The AI Oversight Practice from Cognitive Corp.

Standards

NIST AI RMF 1.0ISO/IEC 42001:2023EU AI ActCOSO ERM

BoardSight provides independent, board-ready oversight evidence and advisory support. It does not provide legal opinions, regulatory certification, statutory audit assurance, or a guarantee that an AI system is safe or compliant.

© 2026 Cognitive Corp. All rights reserved.

BoardSight · AI Governance · Three Lines for AI