Governance
Combined Assurance Gaps
When management, internal audit and external assurance all assume someone else is covering a risk, that risk ends up covered by no one — and that blind spot is where the next major failure incubates.
Why Combined Assurance Gaps Matter
King IV Principle 15 requires the governing body to ensure a combined assurance model that covers significant risks across the lines of defence, giving the audit committee comfort that the control environment is adequately assured. A significant risk with no effective assurance is precisely the exposure the AGSA and audit committee most want surfaced. AuditPro Core maps significant risks against assurance coverage across the three lines of defence so uncovered risks are visible rather than assumed away.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Significant risks
46
Adequately assured
71%
▲ 8%
Assurance gaps
13
No coverage
4
Assurance coverage by risk theme
Uncovered significant risks
| Risk | Rating | Providers |
|---|---|---|
| Cyber breach of billing system | High | 0 |
| Water revenue losses | High | 1 |
| Third-party fraud | High | 0 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
The three lines of defence
Management owns and controls risk as the first line, risk and compliance functions oversee it as the second, and internal and external audit independently assure it as the third. Combined assurance coordinates all three.
Coverage over duplication
Without coordination, low-glamour risks go unassured while popular areas are assured several times over. Mapping coverage exposes both the gaps and the wasteful overlaps.
Significance weighting
Not every risk needs every line. The model targets assurance at significant risks, so the gap that matters is a high-impact risk with no effective assurance, not an immaterial one.
Quality of assurance, not just presence
A box ticked as assured by a weak or outdated review is a false comfort. Effective combined assurance assesses whether the assurance is reliable, not merely whether it exists.
How AuditPro Core Bridges the Gap
- Coverage mapping: significant risks are matched to assurance providers across all three lines to expose gaps.
- Gap flagging: high-significance risks with no effective assurance surface as exceptions for the audit committee.
- Overlap visibility: duplicated assurance is identified so effort can be redirected to uncovered areas.
- Audit-ready evidence: the coverage map exports as proof that Principle 15 combined assurance was applied.
Key Takeaways
- Combined assurance coordinates management, oversight functions and audit across the three lines of defence.
- Mapping coverage exposes both unassured gaps and wasteful duplication.
- The gap that matters is a significant risk with no effective assurance.
- Assurance presence is not enough; its reliability must be assessed too.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
