The COSO Internal Control – Integrated Framework (the Framework) outlines the components, principles, and factors necessary for an organization to effectively manage its risks through the implementation of internal control. However, it is largely silent regarding who is responsible for specific duties outlined in the Framework.
The Three Lines of Defense (the Model) addresses how specific duties related to risk and control could be assigned and coordinated within an organization, regardless of its size or complexity.