Three Lines Model for Procurement Governance Training Course

5 days Procurement Certificate on completion
Course codeSD-P-034
Duration5 days
LevelIntermediate to Advanced
CategoryProcurement
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Procurement decisions are increasingly examined for fairness, delegated authority, conflict management, contract compliance, supplier risk and evidence of challenge. Yet many procurement teams operate with blurred ownership: buyers approve exceptions they later administer, category managers own controls without independent testing, and internal audit is engaged only after a disputed award or supplier failure. The Three Lines Model provides a practical way to separate management accountability, risk and compliance oversight, and independent assurance without creating unnecessary approval layers.

This course applies the Institute of Internal Auditors’ Three Lines Model directly to procurement governance. Participants define first-line procurement control ownership, second-line policy and risk oversight, and third-line internal-audit assurance roles. They build procurement risk-control matrices, map delegation-of-authority controls, distinguish preventive from detective controls, establish escalation routes, and design assurance testing for sourcing, supplier onboarding, contract variation and payment governance. The programme also addresses RACI design, evidence retention, control exceptions, conflicts of interest and reporting to procurement leadership and audit committees.

Instruction combines facilitated analysis with realistic procurement scenarios, including a contested tender award, a high-risk supplier onboarding case and uncontrolled contract changes. Participants work from templates used in class, review control evidence, challenge weak governance designs and receive structured feedback from the instructor. Each participant leaves with a procurement Three Lines operating model pack: a line-of-defence role map, RACI, risk-control matrix, assurance calendar, escalation workflow and a 90-day implementation plan for their organisation.

The course is suited to experienced procurement, supply chain, compliance, risk and internal-audit professionals who need to make governance responsibilities explicit and defensible. It is particularly valuable where an organisation is strengthening procurement controls after audit findings, regulatory scrutiny, rapid growth, decentralisation or a major procurement-system implementation.

Course objectives

By the end of this course, participants will be able to:

  • Apply the IIA Three Lines Model to define first-, second- and third-line responsibilities across the procurement lifecycle
  • Construct a procurement risk-control matrix covering sourcing, supplier onboarding, contracting, purchasing and supplier management
  • Design a procurement governance RACI that separates decision rights, control ownership, oversight and assurance
  • Map delegation-of-authority controls for tender awards, waivers, contract changes and supplier approvals
  • Evaluate procurement controls as preventive, detective or corrective and identify evidence required for testing
  • Develop a second-line monitoring and escalation framework for policy exceptions, conflicts and supplier risk
  • Plan risk-based third-line assurance reviews using control objectives, test procedures and reporting criteria
  • Produce a 90-day Three Lines implementation roadmap for a defined procurement governance gap

Benefits of attending

For you

  • Gain a defensible method for explaining who owns procurement risks, controls and assurance activities
  • Build confidence challenging unclear tender approvals, policy waivers and contract-change decisions
  • Create governance artefacts that demonstrate readiness for senior procurement, compliance or risk roles
  • Learn to translate audit findings into control ownership and practical remediation actions
  • Strengthen credibility when presenting procurement governance issues to executives and audit committees

For your organisation

  • Clarify accountability for procurement controls, reducing duplicated reviews and unmanaged control gaps
  • Improve the quality and traceability of award, waiver, supplier-approval and contract-variation decisions
  • Establish risk-based second-line monitoring before issues become audit findings or supplier failures
  • Give internal audit a clearer basis for independent procurement assurance planning and testing
  • Produce an implementable governance roadmap aligned to procurement policy, risk appetite and delegated authority

Target competencies

Three Lines designProcurement control mappingGovernance RACI developmentRisk-based assuranceAuthority control designException escalation

Who should attend

  • Procurement Managers — who own purchasing controls and need clear accountability across their teams
  • Category Managers — who lead sourcing and supplier decisions requiring defensible governance
  • Head of Procurement — who must establish scalable oversight without slowing commercial delivery
  • Procurement Compliance Managers — who monitor policy adherence, waivers and control exceptions
  • Supply Chain Risk Managers — who need to connect supplier risk monitoring with procurement decision rights
  • Internal Auditors — who assess procurement controls and require an independent assurance framework

Requirements and prerequisites

Participants should have practical experience in procurement, sourcing, contract management, supplier management, compliance, risk or internal audit. They should understand the basic procurement lifecycle, including requisitioning, tendering, evaluation, award, contracting and supplier performance management, and be familiar with terms such as delegation of authority, conflict of interest, policy exception and audit evidence. Experience using an ERP or source-to-pay system is helpful but not essential. No prior internal-audit qualification, formal risk-management certification, statistical expertise or specialist governance software is required; course templates are supplied.

Training methodology

The programme uses short instructor-led briefings followed by guided application to procurement cases and participants’ own operating contexts. Teams analyse tender, supplier-risk and contract-variation evidence; build risk-control matrices; assign Three Lines responsibilities; and test whether proposed controls can be evidenced and assured. Facilitated peer challenge focuses on practical tensions between commercial speed, control ownership and independent review. Daily outputs are progressively assembled into a procurement governance pack, and the final session converts this work into a prioritised 90-day application plan.

Course outline

Day 1: Applying the Three Lines Model to procurement

  • Institute of Internal Auditors Three Lines Model principles
  • Procurement lifecycle governance touchpoints
  • Management accountability versus oversight responsibility
  • First-line ownership in sourcing and purchasing
  • Second-line procurement compliance and risk functions
  • Third-line internal audit independence requirements
  • Governance failure patterns in procurement decisions

Workshop: Participants diagnose a contested tender award case and produce an initial Three Lines responsibility map for the decision.

Day 2: Procurement risks, controls and evidence

  • Procurement risk taxonomy and risk appetite
  • Risk-control matrix design methodology
  • Preventive, detective and corrective procurement controls
  • Control objectives for competitive sourcing
  • Supplier onboarding due diligence controls
  • Contract variation and spend-authorisation controls
  • Control evidence, retention and audit trails

Workshop: Participants build a risk-control matrix for a source-to-contract process, including owners, evidence and control classifications.

Day 3: Decision rights and second-line oversight

  • Procurement governance RACI construction
  • Delegation-of-authority matrix design
  • Tender evaluation and award approval gates
  • Single-source and waiver governance
  • Conflict-of-interest declaration controls
  • Second-line monitoring indicators and thresholds
  • Exception logging and escalation workflows

Workshop: Participants redesign a flawed procurement approval workflow and produce a RACI, authority matrix and exception-escalation route.

Day 4: Independent assurance and governance reporting

  • Risk-based procurement assurance planning
  • Internal audit scope and independence boundaries
  • Control testing procedures and sample selection
  • Design effectiveness versus operating effectiveness
  • Issue rating and root-cause analysis
  • Procurement governance dashboards and KRIs
  • Audit committee reporting for procurement risks

Workshop: Participants develop an assurance test plan for supplier onboarding and present findings, ratings and management actions to a mock audit committee.

Day 5: Implementing a workable procurement Three Lines model

  • Target operating model for procurement governance
  • Gap assessment against current control arrangements
  • Stakeholder mapping and change sponsorship
  • Policy, procedure and system-control alignment
  • SAP Ariba workflow and approval-control considerations
  • Assurance calendar and management review cadence
  • Ninety-day implementation roadmap development

Workshop: Participants complete and peer-review a procurement Three Lines operating model pack and a prioritised 90-day implementation roadmap.

Tools & standards covered

IIA Three Lines Model, ISO 31000, COSO Enterprise Risk Management Framework, SAP Ariba

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand how procurement work moves from requirement through sourcing, award, contract and supplier management. Experience in procurement, compliance, risk or internal audit is expected; you do not need a formal audit or risk qualification.

A laptop is recommended for completing the risk-control matrix, RACI and implementation roadmap templates. No live access to SAP Ariba, an ERP or any organisational procurement system is required.

The course is designed for professionals with responsibility for procurement decisions, controls, oversight or assurance. It is especially relevant to procurement managers, category managers, compliance leads, supplier-risk professionals and internal auditors.

This programme uses the Three Lines Model as the organising method for procurement governance rather than teaching policy compliance or audit techniques in isolation. It focuses on assigning ownership, oversight and independent assurance across specific procurement decisions and controls.

You can use the supplied templates to map current procurement responsibilities, identify control gaps and establish escalation and assurance routines. The final 90-day plan is structured to support discussion with procurement leadership, risk, compliance and internal audit.

You will leave with a procurement Three Lines operating model pack tailored to a selected process or governance issue. It includes a role map, RACI, risk-control matrix, assurance calendar, escalation workflow and implementation roadmap.

Upcoming sessions

  • 21 – 25 Sep 2026
    Mombasa · USD 3,200
    Book
  • 28 Sep – 02 Oct 2026
    Dubai · USD 4,500
    Book
  • 12 – 16 Oct 2026
    Live Online · USD 1,500
    Book
  • 12 – 16 Oct 2026
    Dubai · USD 4,500
    Book
  • 12 – 16 Oct 2026
    Kigali · USD 3,500
    Book
  • 19 – 23 Oct 2026
    Live Online · USD 1,500
    Book
  • 19 – 23 Oct 2026
    Dubai · USD 4,500
    Book
  • 26 – 30 Oct 2026
    Nairobi · USD 3,000
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Procurement

5 Days Certificate

Purchase Order Management and Approval Controls Fundamentals Training Course

Purchase orders are a primary control point between an approved buying decision and a financial commitment. When requisitions are converted …

5 Days Certificate

Healthcare Procurement and Medical Supplies Management Training Course

Healthcare procurement teams must secure clinically suitable products at controlled cost while protecting continuity of care. A poorly speci…

5 Days Certificate

NEC4 Procurement and Contracting Strategy Training Course

Procurement teams face difficult choices long before an NEC4 contract is signed: whether to use a framework, single-stage or two-stage tende…

5 Days Certificate

JAGGAER Source-to-Pay Configuration Training Course

JAGGAER Source-to-Pay configurations often evolve through urgent fixes: a field added for one category, an approval rule copied from another…