The Three Lines of Defense model for compliance and risk management, where internal audit is positioned as an independent function in the third line of defense, is considered a good practice to enhance oversight over a company’s control environment. It describes the interaction among operating units that manage risks (the first line), departments that provide oversight (the second line), and groups that provide independent assurance (third line). Internal audit not only provides independent assurance that risks are managed at acceptable levels; it also provides assurance that second-line oversight functions work as desired.