Combined Assurance
Combined Assurance Gap Analysis
Significant risks with no assurance, single-source assurance or duplicated coverage across providers.
Why Map Combined Assurance Gaps
King IV expects a combined assurance model that gives the audit committee confidence every significant risk is covered, without wasteful duplication. In practice some risks attract three overlapping assurance providers while others have none, and only a deliberate gap analysis exposes the imbalance. AuditPro Core maps each significant risk to its assurance providers and flags the unassured, single-source and duplicated cases so coverage can be rebalanced.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Significant risks
62
No assurance
9
blind spots
Single-source
21
fragile
Over-assured
7
duplicated
Risks by assurance depth
Unassured significant risks
| Risk | Owner | Rating | Assurance gap |
|---|---|---|---|
| Revenue completeness | CFO | Extreme | No 3rd line |
| ICT obsolescence | CIO | High | No assurance |
| Talent attrition | HR head | High | No assurance |
| Water losses | Eng. director | Extreme | 1st line only |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
The Combined Assurance Idea
Combined assurance coordinates management, internal audit, external audit and other providers so their work complements rather than collides. The goal is complete coverage of significant risks at the lowest sensible cost.
The Three Failure Modes
Coverage fails in three ways: a significant risk with no assurance at all, reliance on a single fragile source, and several providers duplicating effort on the same risk. Each is a different problem with a different fix.
Unassured Risks Are the Priority
A significant risk with zero assurance is the most dangerous gap because the audit committee has no independent basis for comfort. These cases should be closed before duplication is trimmed.
Mapping to the Three Lines
Combined assurance sits naturally on the three-lines model, with management, oversight functions and independent audit each contributing. Mapping providers to lines clarifies who is relied on for what.
How AuditPro Core Bridges the Gap
- Coverage mapping: every significant risk is linked to its assurance providers, exposing no-assurance, single-source and duplicated cases at a glance.
- Gap prioritisation: unassured significant risks are flagged first so the most dangerous blind spots close before duplication is trimmed.
- Exception workflow: uncovered risks route to the assurance coordinator for assignment with a tracked plan.
- Audit-ready export: produce the combined assurance plan and coverage map the audit committee relies on under King IV.
Key Takeaways
- Combined assurance aims for full coverage of significant risks at the lowest sensible cost.
- Coverage fails three ways: no assurance, single-source, and wasteful duplication.
- Unassured significant risks are the priority — close them before trimming overlap.
- Mapping providers to the three lines clarifies who is relied on for what.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
