Article

Differences Between Internal Audit, Compliance, and Internal Control: who does what

The Three Lines Model explained with a comparison table and a step-by-step practical example.

"That's already covered by Compliance." "That's an Internal Control matter." "I thought Internal Audit handled that." If you have ever heard or said any of these phrases in a meeting, you are not alone. It is probably the most widespread source of confusion among those who start working around risk management in an organization, and it persists even among experienced professionals when the three functions coexist without a clear boundary. This article settles once and for all who does what, why three separate functions exist rather than one, and what happens when those boundaries blur.

The root of the confusion: three functions that speak of risk but play different roles

Internal Audit, Compliance, and Internal Control share a common vocabulary: risk, control, finding, action plan. That makes them look, from the outside, like three versions of the same thing. But the right question is not what words they use, but what question each one answers:

  • Internal Control answers: "What controls have we designed to manage this risk day to day?"
  • Compliance answers: "Are we meeting the regulations and internal policies applicable to this risk?"
  • Internal Audit answers: "Do those controls and that compliance actually work, independently of whoever designed them?"

The key to never confusing them again lies in that last word: independence. It is the axis that separates Internal Audit from the other two functions, and understanding it resolves the majority of questions that arise in practice.

The Three Lines Model: the framework that organizes everything

The IIA formalized a framework that has become the standard reference for understanding this distribution of roles: the Three Lines Model. It is not an abstract theory; it is the most direct way to explain why these three functions exist separately and cannot be merged without losing something important along the way.

First line: those who manage risk directly

This is the operational staff: those who sell, buy, serve the customer, or run the machinery. They are responsible for applying controls in their day-to-day work, because risk originates there, in operations. A relationship manager who verifies a customer's identity before opening an account is acting in the first line.

Second line: those who design and oversee control

This is where Internal Control and Compliance live, alongside functions such as Risk Management or Information Security. Their work is to design the policies, procedures, and controls that the first line must apply, and to monitor on an ongoing basis that they are being executed correctly. They do not run the operation, but they build the rules of the game and supervise their compliance closely.

Third line: those who provide independent assurance

Internal Audit is, by definition, the third line. Its role is not to design controls or monitor them on an ongoing basis, but to independently and objectively assess whether the entire system (first and second lines together) works as expected. This independence is structural: Internal Audit cannot audit with objectivity something it has itself designed or executed.

AT A GLANCE

1st line (Operations): applies the control day to day.
2nd line (Internal Control and Compliance): designs the control and monitors that it is applied.
3rd line (Internal Audit): independently evaluates whether both previous lines are actually working well.

What Internal Control is and who executes it

Definition and scope

Internal Control is the set of policies, procedures, and mechanisms designed to provide reasonable assurance that the organization will achieve its operational, reporting, and compliance objectives. It is not exclusively a department; it is above all a system that runs across the entire organization. Many organizations do however have a specific Internal Control function responsible for designing the methodology, maintaining the risk and control matrix, and coordinating control self-assessments.

Who is responsible for Internal Control within the organization

Here lies one of the most common misconceptions: ultimate responsibility for Internal Control does not rest with a department, but with Management and with each process owner. The Internal Control function (where it exists as a specific area) acts as a facilitator and coordinator of the methodology, but it is not who executes the control day to day; that falls to the first line.

What Compliance is and how it differs from Internal Control

Definition and scope

Compliance is the function responsible for identifying the regulatory and legal obligations affecting the organization, translating them into internal policies, and monitoring that they are met. Its typical scope includes anti-money laundering, data protection, anti-corruption, competition law, and sector-specific regulations.

Why Compliance sits in the second line, not the third

It is common for someone new to risk management to assume that Compliance "audits" regulatory compliance and should therefore sit in the same position as Internal Audit. This is not the case: Compliance designs the policy, trains employees, monitors alerts, and actively and continuously reports non-compliance. That closeness to day-to-day operations, and the fact that Compliance participates in designing the regulatory control system itself, is precisely what places it in the second line. Internal Audit, by contrast, evaluates afterward, independently, whether that Compliance system is actually working as expected.

What Internal Audit is and why its independence is the key

Definition and scope

Internal Audit is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It evaluates the effectiveness of governance, risk management, and control processes, expressly including the systems designed by Internal Control and Compliance.

Independence as a differentiating feature, not an optional one

Internal Audit's independence is not an organizational preference; it is a normative requirement set out in the Global Internal Audit Standards. This translates into a very concrete rule: Internal Audit should not design controls, perform Compliance tasks, or take on management responsibilities that it would subsequently need to evaluate. When this happens, the function loses the objectivity that justifies its very existence as the third line.

Comparison table: the three functions side by side

Aspect Internal Control Compliance Internal Audit
Line of defense Second line Second line Third line
Question it answers What controls have we designed? Are we meeting regulations and policies? Is the whole system actually working?
Relationship with risk Designs and coordinates the control matrix Identifies obligations and monitors compliance Independently evaluates the whole system
Frequency of action Continuous, integrated into the process Continuous, with active monitoring Periodic, through planned engagements
Reports primarily to CEO or Risk Committee CEO and, depending on the case, the Board Board of Directors or Audit Committee
Can be reviewed by Internal Audit Internal Audit External Quality Assessment (external body)
Example activity Designing the payment approval procedure Training employees on the anti-corruption policy Verifying whether that policy is effectively applied

One risk, three different roles: a practical example

The best way to fix this distinction is to follow a single risk through all three functions. Take the risk of money laundering in account opening at a financial institution.

RISK: MONEY LAUNDERING IN ACCOUNT OPENING

First line (commercial network): the branch manager requests identification documents from the customer, completes the know-your-customer form, and applies the verification procedure defined by the organization.

Second line (Compliance): designed that know-your-customer procedure, defines what documentation is valid depending on the customer's risk level, trains commercial staff, and continuously monitors alerts generated by the transaction system to detect suspicious patterns.

Third line (Internal Audit): does not design the procedure or review alerts day to day. Instead, it selects a sample of accounts opened in recent months and evaluates whether the Compliance procedure was correctly followed in practice, whether generated alerts were managed within the required timeframe, and whether the Compliance monitoring system itself has design weaknesses that should be corrected.

Note the key difference: if Internal Audit started reviewing transaction alerts day to day, it would be doing Compliance's job, not evaluating it. And if Compliance stopped reviewing alerts to limit itself to quarterly sampling of already-closed cases, it would be abandoning its second-line role to become, in effect, a parallel audit function without the independence needed to be one.

Common mistakes that create conflict between the three functions

  • Internal Audit executes controls it must subsequently review. If the audit team participates in designing a Compliance procedure, it cannot evaluate it afterward with the objectivity its role requires.
  • Compliance takes on assurance functions that belong to Internal Audit. When Compliance begins certifying internally that "everything is in order" with the same language and authority that should belong to an audit report, a confusing duplication arises over who actually provides independent assurance.
  • Internal Control becomes diluted without a clear owner. In organizations without a well-defined Internal Control function, each area designs its own controls without coordination, making it harder for both Compliance and Internal Audit to work from a common, consistent base.
  • Compliance reports to an area it should itself be supervising. If the Compliance function reports hierarchically to the business area whose compliance it must oversee, a conflict of interest arises that weakens its ability to act firmly when it detects a breach.

How the three functions should collaborate without overlapping

A clear distinction of roles does not mean the three functions should work in silos. Quite the opposite: when they collaborate in a coordinated way without losing their respective independence, the result is what is often called combined assurance.

  • Share risk maps, not conclusions. Compliance and Internal Control can share their own risk maps and control matrices with Internal Audit, helping prioritize the audit plan without Internal Audit losing its independent judgment about what and how to evaluate.
  • Coordinate calendars to avoid duplicating testing on the same control. If Compliance has already reviewed a specific control in depth this quarter, Internal Audit can use that evidence as an input, without giving up independently validating its reliability before relying on it.
  • Communicate findings cross-functionally where appropriate. An Internal Audit finding about a control designed by Compliance should be communicated constructively, as an improvement opportunity, not as a personal challenge to the Compliance team's work.

Key control point: if nobody in your organization can clearly explain why a particular control is reviewed by Compliance, another by Internal Control, and a third by Internal Audit, there is likely no combined assurance map in place, and it is time to build one.

An audit management and GRC platform that centralizes the organization's risk and control map allows all three lines to work from a shared base, avoiding duplicated testing on the same control and leaving clear traceability of which function has evaluated what, and when.

Checklist to diagnose whether your organization has clearly defined roles

  1. Is there a document or charter that clearly defines the scope of each of the three functions?
  2. Does Internal Audit report to an independent body (Audit Committee or Board), separate from the one overseeing Compliance or Internal Control?
  3. Does Compliance participate in designing controls without also taking on the role of independently evaluating them?
  4. Is there a shared risk and control map that prevents each function from working in isolation?
  5. Are Internal Audit findings about Compliance or Internal Control controls managed through a formal action plan, just like any other finding?
  6. Is any one of the three functions performing tasks that should belong to another, creating overlap or a responsibility gap?

Conclusion

Internal Control, Compliance, and Internal Audit are not three different names for the same function, nor three redundant layers of bureaucracy. They are three lines of defense with complementary purposes: one designs the control, another monitors regulatory compliance closely, and the third evaluates, from an independent position, whether the first two are actually working. Understanding this distinction is not a theoretical exercise: it is what allows each function to act with the authority and objectivity its specific role requires, and what prevents a significant risk from going uncovered simply because everyone assumed someone else was looking after it.