Products / Combined Assurance
Available

Combined Assurance

Three-lines-of-defence coverage at a glance.

A three-lines-of-defence heat-map mapping every significant risk to first-line controls, second-line oversight and third-line audit assurance — surfacing where assurance is missing or duplicated.

What you get

  • Assurance heat-map
  • Control detail
  • Drives the plan

Why it matters

See where assurance is missing, duplicated or thin.

Combined assurance is King IV Principle 15 made operational: the deliberate coordination of all assurance providers so that significant risks are covered once, properly, rather than three times in some places and not at all in others. The model maps every significant risk across the three lines of defence — first-line management controls, second-line oversight functions, and third-line audit assurance — to reveal where assurance is missing, duplicated or simply inadequate.

Without this view, assurance is accidental. Internal audit, risk, compliance and external audit each do their own thing, leadership assumes the gaps are someone else's coverage, and a material risk sits unassured until it materialises. The Audit Committee, which must give the board comfort on the control environment, has no defensible basis for that comfort — and AGSA's assurance-coverage discussion exposes the holes.

A combined-assurance heat-map turns that into a single, drillable picture. Cells shade by assurance adequacy across the three lines; you drill into control owners, monitoring frequency and last-tested dates; and the coverage gaps feed the annual internal-audit plan so the next cycle targets exactly what is under-assured.

Capabilities

What Combined Assurance does.

Assurance heat-map

Cells shaded by assurance adequacy across the three lines.

Control detail

Drill in to owners, monitoring frequency and last-tested date.

Drives the plan

Coverage gaps feed the annual internal-audit plan.

Outcomes

What changes for your team.

Tangible improvements an entity sees once Combined Assurance replaces the spreadsheet.

Map every significant risk across all three lines of defence
Shade coverage by assurance adequacy to expose gaps and duplication
Drill into control owners, monitoring frequency and last-tested dates
Give the Audit Committee a defensible basis for its assurance comfort
Feed coverage gaps directly into the annual internal-audit plan
Coordinate assurance providers so risks are covered once, properly

How it works

From data to defensible signal.

01
Map
Map each significant risk to its lines of defence.
02
Assess
Shade cells by assurance adequacy.
03
Act
Close gaps through the audit plan and oversight functions.

Want to see Combined Assurancerunning on your entity's own data?

Enquire now

Who it's for

  • Audit Committee
  • Chief Audit Executive and Chief Risk Officer
  • Compliance Officer
  • External Audit (AGSA) for the assurance-coverage discussion

Legislative basis

  • King IV Principle 15 — combined assurance model
  • IIA Standard 2050 — coordination and reliance among assurance providers
  • National Treasury Combined Assurance Framework Guideline — public-sector coordination

FAQ

Questions teams ask before they sign up.

How does this support the assurance discussion with AGSA?

The heat-map shows, risk by risk, which lines of defence provide assurance and how adequate it is — exactly the coverage picture AGSA discusses. Gaps are visible rather than assumed away.

Does it actually drive the audit plan?

Yes. Risks shaded as under-assured feed directly into the internal-audit plan and the audit universe, so the next cycle covers what is genuinely exposed.

Who maintains the map?

The CAE, Chief Risk Officer and Compliance Officer maintain it together and review it with the Audit Committee at each meeting, keeping the coverage view current.

Want to know more about Combined Assurance?

Tell us about your entity and we'll be in touch with a walkthrough, pricing and next steps — everything you see is traceable to source.