Methodology

We asked 14 governance standards one question about the second line

Every standard a board can pull today talks about AI governance. We wanted to know a narrower thing: how many of them actually require the independent second line — the function that challenges AI risk before a failure reaches the board. This page shows exactly how we checked, and how you can replicate it.

Reviewed

14 board-available standards

Reference model

IIA Three Lines Model

Test

One question, asked of each

Result

1 of 14 require an independent second line

What we asked

The Institute of Internal Auditors’ Three Lines Model describes three roles in any control system: a first line that operates the activity and owns its risk, a second line that independently challenges and monitors that risk, and a third line that provides independent assurance to the board.

We put one question to each of 14 board-available standards: does it require an independent second line for AI — a risk, compliance, or validation function that is separate from the people building or operating the system, separate from internal audit, and empowered to challenge or constrain what the first line ships?

We scored functions, not job titles. A standard passes if it clearly requires that independent challenge — even without the words “second line.” It does not pass for defining roles in general, for encouraging good practice, or for relying on the operators’ own risk process or on an outside auditor.

How we scored

There is no composite index and no weighting here — deliberately. Each standard gets exactly one of three verdicts, and each verdict is tied to a specific clause, article, or principle you can open and read yourself:

  • Requires — the text mandates an independent second-line function (e.g. “validation independent of development”).
  • Optional — it defines roles, risk management, or oversight, but leaves the independent second line to management’s discretion.
  • Silent — it addresses only high-level principles or disclosure, and says nothing about internal oversight structure.

Because the verdict is binary and every call is cited, anyone can pull the same 14 documents, apply the same question, and check us line by line. That is the point: the finding should survive a skeptical reader, not depend on trusting our arithmetic.

The result

Of the 14 board-available standards we reviewed, this is how many require an independent second line for AI.

1 / 14

7% of standards reviewed

Explicitly require an independent second line

Only SR 11-7 — and it is a 2011 banking rule, not an AI standard.

10 / 14

71% of standards reviewed

Leave it to management’s discretion

They define roles or reference the model, but never require a function independent of the builders.

3 / 14

21% of standards reviewed

Silent on internal oversight structure

High-level principles or disclosure only.

Put plainly: 13 of the 14 standards a board can obtain today do not require an independent second line for AI — and the one that does was written for bank models in 2011, long before generative AI. Nearly every standard is explicit about who operates the AI, and most address independent assurance. The independent challenge in the middle is the line the guidance leaves optional. That is the gap BoardSight is built to close.

Standard by standard

Every one of the 14, with the verdict and the specific provision behind it. These are not interchangeable instruments — a binding regulation, a voluntary framework, and director guidance do different jobs — so we label each by what it is.

1. SR 11-7 — Model Risk Management

US Federal Reserve / OCC, 2011 · Supervisory guidance

Requires

Mandates "validation independent of development" and "effective challenge" by parties who do not own or use the model.

View the source · § IV — Model Validation / “effective challenge”

2. NIST AI Risk Management Framework 1.0

NIST, 2023 · Voluntary framework

Optional

Defines governance roles; MEASURE 1.3 encourages independent assessors as a best practice, not a requirement.

View the source · GOVERN 2–4; MEASURE 1.3

3. ISO/IEC 42001:2023

ISO/IEC, 2023 · AI management-system standard

Optional

Clause 5.3 assigns roles; the only independent check it requires is internal audit (9.2) — the third line, not the second.

View the source · Clause 5.3 (roles); Clause 9.2 (internal audit)

4. ISO/IEC 23894:2023

ISO/IEC, 2023 · AI risk-management guidance

Optional

Guidance only (no "shall"); recommends a risk owner but not a function independent of the builders.

View the source · Clauses 4–6 (guidance, no “shall”)

5. ISO/IEC 38507:2022

ISO/IEC, 2022 · AI governance guidance for the board

Optional

Addresses governing-body oversight above the three lines and delegates implementation without prescribing a second line.

View the source · Scope; governing-body guidance

6. EU AI Act — Regulation (EU) 2024/1689

European Union, 2024 · Binding regulation

Optional

Art. 9 lets the risk system be "part of, or combined with" existing procedures; the independent check is external notified-body assessment.

View the source · Arts. 9, 14, 17, 26; conformity assessment

7. NIST Cybersecurity Framework 2.0

NIST, 2024 · Voluntary framework

Optional

The new GOVERN function requires roles and oversight outcomes but is deliberately agnostic about organizational structure.

View the source · GOVERN function (GV.RR, GV.OV)

8. COSO Enterprise Risk Management

COSO, 2017 · Enterprise-risk framework

Optional

References the three-lines model but leaves the operating structure to management’s discretion.

View the source · Governance & Culture, Principle 2

9. COSO Internal Control — Integrated Framework

COSO, 2013 · Internal-control framework

Optional

Requires operating structures and monitoring; the explicit three-lines articulation came later, and not as a requirement.

View the source · Principle 3; Monitoring (Prin. 16–17)

10. IIA Three Lines Model

Institute of Internal Auditors, 2020 · Reference model

Optional

The 2020 update places first- and second-line roles under management and states they "may be blended or separated."

View the source · 2020 model — first/second-line roles

11. COBIT 2019

ISACA, 2019 · IT governance framework

Optional

Assigns risk as an integrated management practice (APO12); does not require it to be independent of operations.

View the source · APO12; EDM03; MEA domain

12. OECD AI Principles

OECD, 2019 / 2024 · Intergovernmental principles

Silent

Values-based; the accountability principle names no internal oversight structure.

View the source · Principle 1.5 (Accountability)

13. NACD Cyber-Risk Oversight Handbook

NACD / ISA, 2023 · Director guidance

Silent

Directs the board to expect management to build a framework; prescribes no second-line function.

View the source · 2023 edition — Principle 4

14. SEC Cybersecurity Disclosure Rule

US SEC, 2023 · Disclosure regulation

Silent

Requires disclosure of governance processes "if any"; mandates no control structure.

View the source · Reg S-K Item 106 (disclosure)

Limitations

  • The test is deliberately strict: a standard scores “requires” only if it mandates a function independent of the people who build or operate the AI — not merely defined roles or an encouraged best practice.
  • Reasonable reviewers may code borderline cases differently. NIST’s AI framework, for example, comes closest to “requires” without crossing the line; we show our reasoning for each call so you can disagree with any one of them.
  • This measures what the guidance requires — not any organization’s implementation, maturity, or legal compliance.
  • A standard can require operational ownership (first line) or independent assurance (third line) and still score “optional” here, because we are testing one thing: the independent second line.
  • Standards and regulations change. SR 11-7 is model-risk guidance written for banks, and several of these instruments are being revised.
  • The review does not establish market prevalence, causation, or that any single standard is deficient for its own purpose.

Every standard above links directly to its primary source, with the specific clause behind each verdict. The full coding guide and the scored crosswalk — our reasoning for every call — are also available on request. We treat this as versioned research and welcome corrections, additional standards, and independent replication using the published criteria.

Request the source register & coding guide

This methodology is independent governance research. It does not constitute legal advice, regulatory certification, statutory audit assurance, or a guarantee that an AI system or governance program is compliant, effective, or safe.

See where your board stands

Request a Briefing
B
BoardSight

The AI Oversight Practice from Cognitive Corp.

Standards

NIST AI RMF 1.0ISO/IEC 42001:2023EU AI ActCOSO ERM

BoardSight provides independent, board-ready oversight evidence and advisory support. It does not provide legal opinions, regulatory certification, statutory audit assurance, or a guarantee that an AI system is safe or compliant.

© 2026 Cognitive Corp. All rights reserved.

BoardSight · AI Governance · Three Lines for AI