Combined assurance provides a coordinated view of the assurance available over material risks and controls. Different providers may include business control teams, risk, compliance, information security, quality, internal audit, external audit and specialist reviewers. Their work can overlap, use different ratings and leave other important areas uncovered.
The purpose is not to merge the independent roles or remove challenge. It is to map scope, frequency, quality and reliance so that management and the Board understand where assurance is strong, partial, duplicated or absent. The process should connect directly to the enterprise risk and control universe.
This article explains how to create an assurance map and use it for planning, reporting and follow-up.
Management question: For each material risk and key control, what assurance exists, how reliable is it, what duplication occurs and where is additional coverage required?
Why combined assurance framework matters#
Boards may receive many reports without a clear view of overall assurance. Several providers can test the same accessible controls while complex or cross-cutting risks remain weakly covered. Combined assurance supports better planning and can reduce burden on business teams, but only if differences in scope, timing, method and independence are visible.
This topic is closely connected to Central Control Library: How to Build and Govern an Enterprise Control Inventory and Enterprise Risk Dashboard for CROs: Metrics, Design and Decision Use.
Core principles#
Start from risks and controls#
Map assurance to the material enterprise risk and key-control universe rather than to organisational functions alone. The practical test is whether the organisation can apply this principle consistently when information is incomplete, ownership is distributed and decisions must be made within a defined governance timetable. In combined assurance framework, a rule that exists only in a policy document is not enough. The rule should be translated into named data fields, accountable roles, review evidence and a clear exception path. Teams should be able to explain what was decided, who reviewed it, what information supported the conclusion and when the matter must be reconsidered. That discipline turns start from risks and controls from an administrative statement into an operating control.
Preserve provider independence#
Coordination should clarify roles and reliance without weakening statutory or professional responsibilities. This element should be designed around the decision it is intended to support rather than around the convenience of a template. A sound approach defines the minimum information required, the acceptable source of that information, the person responsible for maintaining it and the reviewer who can challenge it. For Boards, Audit Committees, CROs, compliance and internal audit leaders, the most useful outcome is not a larger volume of data; it is a reliable line of sight from the underlying risk condition to the management response. Where the condition changes, the record should show the new assessment, the reason for the change and any resulting action.
Assess quality as well as presence#
Consider scope, method, evidence, competence, independence, timing and unresolved findings. In practice, this requires both standardisation and room for judgement. Standardisation ensures that comparable risks are treated in comparable ways, while judgement allows context, materiality and emerging information to be considered. The balance is achieved through defined criteria, evidence expectations, approval thresholds and periodic review. Without those safeguards, combined assurance framework can become either mechanically rigid or inconsistently subjective. A mature process makes the judgement visible and reviewable without pretending that every risk decision can be reduced to a single number.
Identify duplication and gaps#
Compare providers and periods to reveal repeated testing, inconsistent conclusions and uncovered exposure. The design should also anticipate failure modes. Records may become stale, owners may change, thresholds may be interpreted differently and actions may remain open after their original rationale has expired. Controls therefore need due dates, reminders, escalation logic, independent review and closure evidence. For Boards, Audit Committees, CROs, compliance and internal audit leaders, this is especially important because a weak follow-through process can create a false impression of control. The objective is to make unresolved exposure visible early enough for management to intervene.
Use the map in planning#
Adjust risk, compliance and audit plans and report material gaps and reliance decisions to governance forums. The practical test is whether the organisation can apply this principle consistently when information is incomplete, ownership is distributed and decisions must be made within a defined governance timetable. In combined assurance framework, a rule that exists only in a policy document is not enough. The rule should be translated into named data fields, accountable roles, review evidence and a clear exception path. Teams should be able to explain what was decided, who reviewed it, what information supported the conclusion and when the matter must be reconsidered. That discipline turns use the map in planning from an administrative statement into an operating control.
A practical operating model#
1. Define assurance universe#
Identify material risks, key controls, obligations, entities and important business services. In practice, this requires both standardisation and room for judgement. Standardisation ensures that comparable risks are treated in comparable ways, while judgement allows context, materiality and emerging information to be considered. The balance is achieved through defined criteria, evidence expectations, approval thresholds and periodic review. Without those safeguards, combined assurance framework can become either mechanically rigid or inconsistently subjective. A mature process makes the judgement visible and reviewable without pretending that every risk decision can be reduced to a single number.
2. Inventory providers and activities#
Record scope, owner, frequency, methodology, evidence, rating and reporting forum. The design should also anticipate failure modes. Records may become stale, owners may change, thresholds may be interpreted differently and actions may remain open after their original rationale has expired. Controls therefore need due dates, reminders, escalation logic, independent review and closure evidence. For Boards, Audit Committees, CROs, compliance and internal audit leaders, this is especially important because a weak follow-through process can create a false impression of control. The objective is to make unresolved exposure visible early enough for management to intervene.
3. Map and rate coverage#
Assess full, partial, limited or no assurance and the quality and recency of the work. The practical test is whether the organisation can apply this principle consistently when information is incomplete, ownership is distributed and decisions must be made within a defined governance timetable. In combined assurance framework, a rule that exists only in a policy document is not enough. The rule should be translated into named data fields, accountable roles, review evidence and a clear exception path. Teams should be able to explain what was decided, who reviewed it, what information supported the conclusion and when the matter must be reconsidered. That discipline turns map and rate coverage from an administrative statement into an operating control.
4. Coordinate plans#
Resolve unnecessary overlap, agree reliance, schedule complementary work and assign gap coverage. This element should be designed around the decision it is intended to support rather than around the convenience of a template. A sound approach defines the minimum information required, the acceptable source of that information, the person responsible for maintaining it and the reviewer who can challenge it. For Boards, Audit Committees, CROs, compliance and internal audit leaders, the most useful outcome is not a larger volume of data; it is a reliable line of sight from the underlying risk condition to the management response. Where the condition changes, the record should show the new assessment, the reason for the change and any resulting action.
5. Report and refresh#
Provide Board and committee views of coverage, findings, contradiction and unresolved gaps and update for change. In practice, this requires both standardisation and room for judgement. Standardisation ensures that comparable risks are treated in comparable ways, while judgement allows context, materiality and emerging information to be considered. The balance is achieved through defined criteria, evidence expectations, approval thresholds and periodic review. Without those safeguards, combined assurance framework can become either mechanically rigid or inconsistently subjective. A mature process makes the judgement visible and reviewable without pretending that every risk decision can be reduced to a single number.
Practical example#
A bank maps assurance over privileged access. Technology control teams perform monthly monitoring, compliance reviews access to regulatory-reporting systems, internal audit tests selected applications annually and external audit covers financial-reporting systems. The map reveals repeated testing of one system but no assurance over service accounts used by a critical payments platform. Future plans are coordinated to close the gap, and internal audit decides where it can rely on second-line testing after reviewing its quality.
The example is deliberately simple, but it illustrates an important point: a useful ERM process does not stop when a score has been produced. It connects the assessment to ownership, evidence, thresholds, actions, review and reporting. The resulting record should be capable of supporting management discussion without requiring the risk team to reconstruct the history from emails and spreadsheets.
Measures that show whether the process is working#
- Material-risk coverage: Top risks with full, partial, limited or no assurance.
- Key-control coverage: Key controls tested by an appropriate provider within the required period.
- Assurance duplication: Controls or areas reviewed repeatedly with materially overlapping scope.
- Coverage gaps: Material risks or controls without adequate assurance and assigned response.
- Conflicting conclusions: Providers reaching different ratings over the same control or risk.
- Reliance effectiveness: Planned reliance supported by review of provider quality and evidence.
Metrics should be interpreted together. A high completion rate can coexist with weak challenge, poor evidence or overdue remediation. Conversely, a temporary increase in identified issues may indicate that the organisation is becoming more transparent rather than less controlled. Management should therefore consider direction, materiality and the quality of response, not only the absolute number of exceptions.
Common implementation mistakes#
- Counting reports as assurance: A report may not cover the material risk, current period or control operation.
- Mapping at a broad function level: Specific key controls and cross-cutting risks remain unclear.
- Assuming all assurance is equal: Independence, evidence, methodology and timing differ across providers.
- Eliminating overlap without quality review: Necessary challenge may be removed before reliance is justified.
- Updating the map annually only: Material incidents, change and new providers can make coverage obsolete.
These mistakes are avoidable when the operating model is designed before technology configuration begins. The organisation should agree terminology, ownership, approval thresholds, evidence expectations and reporting logic first. Technology can then enforce the agreed method rather than becoming the place where unresolved policy questions are hidden.
Implementation checklist#
- Define material risks and key controls.
- Inventory assurance providers and activities.
- Record scope, timing, evidence and rating.
- Assess coverage quality and recency.
- Identify duplication, gaps and conflicts.
- Agree reliance and plan changes.
- Assign owners for uncovered areas.
- Report to management and the Board.
- Refresh for material change and findings.
How Vilfora ERM can support the process#
Vilfora's Assurance Map can connect enterprise risks and controls to internal audit and other assurance activities, while shared issues and control results preserve findings and status. Board Intelligence can present coverage gaps, duplication and conflicting conclusions with drill-down to source evidence.
Suggested product screenshot: Vilfora Assurance Map showing material risks, key controls, assurance providers, coverage level, findings and gaps.
The screenshot should use anonymised demonstration data and should not expose personal information, credentials, confidential client information or internal environment details. Use a clear crop that shows the relevant workflow, status indicators and drill-down structure. Add a short caption explaining the management decision supported by the screen rather than merely naming the menu.
Frequently asked questions#
Is combined assurance the same as the three lines model?#
The three lines model clarifies roles in governance, risk and assurance. Combined assurance coordinates and maps the work performed across those roles and other providers while preserving their responsibilities.
Can internal audit rely on compliance testing?#
It may rely after evaluating competence, objectivity, scope, methodology, evidence and quality. The reliance decision should be documented and consistent with internal audit standards and policy.
How often should an assurance map be updated?#
At least annually for planning, with updates for material risk change, incidents, new assurance work, significant findings or changes in provider scope.
Related reading#
- Central Control Library: How to Build and Govern an Enterprise Control Inventory
- Enterprise Risk Dashboard for CROs: Metrics, Design and Decision Use
- Issue and Action Management: How to Close Findings Effectively and Prevent Repeat Issues
- Internal Audit Management: From Risk-Based Planning to Validated Closure
Final perspective#
A combined assurance framework gives the Board a clearer view than a collection of separate reports. Mapping risks and controls to the quality and timing of assurance reveals where confidence is strong, where work is duplicated and where material gaps remain. Coordination improves coverage and efficiency without removing independent challenge.





