Combined Assurance

Boards increasingly ask a simple question and get an incomplete answer: who is assuring what? Internal audit covers some things, external audit others, regulators and management self assessments the rest, and nobody has laid the picture out on one page. Combined assurance does that, and it usually reveals both duplication and areas nobody is looking at.

1

Identify

Every assurance provider

2

Map

Coverage against risk

3

Analyse

Gaps and overlaps

4

Rationalise

Reallocate effort

5

Report

Board level view

How We Map It

01

Identifying Assurance Providers

More parties provide assurance than most organisations count. Beyond internal and external audit there are regulators, quality functions, health and safety inspections, external certifications and management self assessments, all producing assurance nobody consolidates.

02

Mapping Coverage to Risk

Each provider coverage is mapped against the organisational risk register, so the board can see which risks are assured, by whom, and how recently. This is the artefact King IV expects and most organisations lack.

03

Gap and Duplication Analysis

Two findings recur almost universally: several parties testing the same well controlled area, and significant risks nobody has examined in years. Both are expensive in different ways.

04

Rationalisation

We propose reallocation, which usually means internal audit stepping back where external assurance is already reliable and redirecting that capacity to the uncovered areas. That requires agreement between providers, not just a recommendation.

05

Committee Support and Reporting

We produce the reporting the committee needs to discharge its mandate, and refresh charters where they have drifted or were never properly drafted.

What You Receive

Indicative Timeline

A first combined assurance exercise takes three to five weeks. Obtaining scope information from external providers is normally the constraint rather than the mapping itself.

Assurance Providers We Map

Assurance arrives from more directions than the audit function alone, and all of it counts.

Internal Audit

Risk based coverage of controls and processes, reporting to the audit committee.

External Audit

Financial statement assurance and, in the public sector, compliance and performance reporting.

Regulators

Sector inspections and statutory reviews that provide genuine assurance the board can rely on.

Certification Bodies

ISO and similar certification, where the certified scope actually covers the risk in question.

Management Assurance

Self assessment, monitoring controls and management review, the first line that is routinely omitted.

Specialist Reviews

Technical assessments such as ICT audit, health and safety, and environmental compliance.

Frequently Asked Questions

Principle 15 expects the governing body to ensure an effective combined assurance arrangement that enables an effective control environment. In practice that means the board can see who assures which risks and can conclude the coverage is adequate.

No. Smaller organisations often benefit more, because they have fewer assurance resources and can least afford duplication. The map is simpler but the reallocation is usually more valuable.

It may redirect it. Where external assurance is genuinely reliable, internal audit can reduce coverage there and redeploy to uncovered areas. Total effort often stays similar while coverage improves materially.

Only where the certified scope covers the risk you are relying on it for. Scope statements are frequently narrower than assumed, which is why we verify rather than accept the certificate at face value.

Usually internal audit maintains it and the audit committee owns it. What matters is that somebody keeps it current, because a map two years old misrepresents coverage rather than describing it.

Annually alongside the audit plan, and whenever a significant new risk or assurance provider appears. The two exercises inform each other and are best run together.

Related Services

This sits inside our Internal Audit practice. Related work: Risk Based Audit Planning, which combined assurance directly informs, and Business Advisory for wider King IV governance support.

Discuss combined assurance