{"title":"Internal Audit, DPO and the adjustment of Three-Lines-of-Defense-Modell","authors":"Thomas Kahler","doi":"10.5771/9783748921561-163","DOIUrl":null,"url":null,"abstract":"Internal audit usually follows the Three-Lines-of-Defense-Modell (T-LoD).1 Within this modell the 1LoD is the business line – like sales and marketing. The 2LoD is checking whether the 1LoD adheres to internal policies, external law and adequately manages the risk. Risk management and compliance function are part of the 2LoD. The 3LoD is internal audit which has the oversight over both the 1LoD and similarly the 2LoD. But the T-LoD-modell fails when the DPO is defined as 2LoD. That derives from the independent position of DPO.","PeriodicalId":326055,"journal":{"name":"Turning Point in Data Protection Law","volume":"7 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-10-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Turning Point in Data Protection Law","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.5771/9783748921561-163","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Internal audit usually follows the Three-Lines-of-Defense-Modell (T-LoD).1 Within this modell the 1LoD is the business line – like sales and marketing. The 2LoD is checking whether the 1LoD adheres to internal policies, external law and adequately manages the risk. Risk management and compliance function are part of the 2LoD. The 3LoD is internal audit which has the oversight over both the 1LoD and similarly the 2LoD. But the T-LoD-modell fails when the DPO is defined as 2LoD. That derives from the independent position of DPO.