Combined Assurance
Boards increasingly ask a simple question and get an incomplete answer: who is assuring what? Internal audit covers some things, external audit others, regulators and management self assessments the rest, and nobody has laid the picture out on one page. Combined assurance does that, and it usually reveals both duplication and areas nobody is looking at.
1
Identify
Every assurance provider
2
Map
Coverage against risk
3
Analyse
Gaps and overlaps
4
Rationalise
Reallocate effort
5
Report
Board level view
How We Map It
01
Identifying Assurance Providers
More parties provide assurance than most organisations count. Beyond internal and external audit there are regulators, quality functions, health and safety inspections, external certifications and management self assessments, all producing assurance nobody consolidates.
- Internal and external audit coverage
- Regulatory inspections and statutory reviews
- Certification bodies and their actual scope
- Management self assessment and monitoring controls
02
Mapping Coverage to Risk
Each provider coverage is mapped against the organisational risk register, so the board can see which risks are assured, by whom, and how recently. This is the artefact King IV expects and most organisations lack.
- Coverage mapped provider by provider against each risk
- Recency of the most recent assurance per risk
- Depth of coverage, not merely presence
- Reliance placed on each provider work
03
Gap and Duplication Analysis
Two findings recur almost universally: several parties testing the same well controlled area, and significant risks nobody has examined in years. Both are expensive in different ways.
- Risks with no assurance coverage identified
- Areas covered by multiple providers
- Assessment of whether duplication is justified
- Effort quantified against coverage achieved
04
Rationalisation
We propose reallocation, which usually means internal audit stepping back where external assurance is already reliable and redirecting that capacity to the uncovered areas. That requires agreement between providers, not just a recommendation.
- Proposed coverage model by provider
- Reliance protocols between assurance providers
- Internal audit plan adjusted accordingly
- Agreement with each provider on the revised split
05
Committee Support and Reporting
We produce the reporting the committee needs to discharge its mandate, and refresh charters where they have drifted or were never properly drafted.
- Combined assurance report for the board
- Audit committee charter and terms of reference
- Reporting calendar aligned to the committee cycle
- Standing agenda and papers template
What You Receive
- Inventory of every assurance provider and their scope
- Coverage map against the organisational risk register
- Gap and duplication analysis with quantified effort
- Proposed rationalised coverage model
- Audit committee charter and reporting templates
- Combined assurance report for the board
Indicative Timeline
A first combined assurance exercise takes three to five weeks. Obtaining scope information from external providers is normally the constraint rather than the mapping itself.
- Provider identification and scoping: one week
- Coverage mapping against the risk register: one to two weeks
- Gap analysis and rationalisation proposals: one week
- Reporting and committee presentation: one week
Assurance Providers We Map
Assurance arrives from more directions than the audit function alone, and all of it counts.
Internal Audit
Risk based coverage of controls and processes, reporting to the audit committee.
External Audit
Financial statement assurance and, in the public sector, compliance and performance reporting.
Regulators
Sector inspections and statutory reviews that provide genuine assurance the board can rely on.
Certification Bodies
ISO and similar certification, where the certified scope actually covers the risk in question.
Management Assurance
Self assessment, monitoring controls and management review, the first line that is routinely omitted.
Specialist Reviews
Technical assessments such as ICT audit, health and safety, and environmental compliance.
Frequently Asked Questions
What does King IV require on combined assurance?
Principle 15 expects the governing body to ensure an effective combined assurance arrangement that enables an effective control environment. In practice that means the board can see who assures which risks and can conclude the coverage is adequate.
Is this only for large organisations?
No. Smaller organisations often benefit more, because they have fewer assurance resources and can least afford duplication. The map is simpler but the reallocation is usually more valuable.
Will this reduce our internal audit work?
It may redirect it. Where external assurance is genuinely reliable, internal audit can reduce coverage there and redeploy to uncovered areas. Total effort often stays similar while coverage improves materially.
Can we rely on a supplier ISO certificate as assurance?
Only where the certified scope covers the risk you are relying on it for. Scope statements are frequently narrower than assumed, which is why we verify rather than accept the certificate at face value.
Who owns the combined assurance map?
Usually internal audit maintains it and the audit committee owns it. What matters is that somebody keeps it current, because a map two years old misrepresents coverage rather than describing it.
How often should it be refreshed?
Annually alongside the audit plan, and whenever a significant new risk or assurance provider appears. The two exercises inform each other and are best run together.
Related Services
This sits inside our Internal Audit practice. Related work: Risk Based Audit Planning, which combined assurance directly informs, and Business Advisory for wider King IV governance support.
