Combined Assurance
Three-lines-of-defence coverage at a glance.
A three-lines-of-defence heat-map mapping every significant risk to first-line controls, second-line oversight and third-line audit assurance — surfacing where assurance is missing or duplicated.
What you get
- Assurance heat-map
- Control detail
- Drives the plan
Why it matters
See where assurance is missing, duplicated or thin.
Combined assurance is King IV Principle 15 made operational: the deliberate coordination of all assurance providers so that significant risks are covered once, properly, rather than three times in some places and not at all in others. The model maps every significant risk across the three lines of defence — first-line management controls, second-line oversight functions, and third-line audit assurance — to reveal where assurance is missing, duplicated or simply inadequate.
Without this view, assurance is accidental. Internal audit, risk, compliance and external audit each do their own thing, leadership assumes the gaps are someone else's coverage, and a material risk sits unassured until it materialises. The Audit Committee, which must give the board comfort on the control environment, has no defensible basis for that comfort — and AGSA's assurance-coverage discussion exposes the holes.
A combined-assurance heat-map turns that into a single, drillable picture. Cells shade by assurance adequacy across the three lines; you drill into control owners, monitoring frequency and last-tested dates; and the coverage gaps feed the annual internal-audit plan so the next cycle targets exactly what is under-assured.
Capabilities
What Combined Assurance does.
Assurance heat-map
Cells shaded by assurance adequacy across the three lines.
Control detail
Drill in to owners, monitoring frequency and last-tested date.
Drives the plan
Coverage gaps feed the annual internal-audit plan.
Outcomes
What changes for your team.
Tangible improvements an entity sees once Combined Assurance replaces the spreadsheet.
How it works
From data to defensible signal.
Want to see Combined Assurancerunning on your entity's own data?
Enquire nowWho it's for
- Audit Committee
- Chief Audit Executive and Chief Risk Officer
- Compliance Officer
- External Audit (AGSA) for the assurance-coverage discussion
Legislative basis
- King IV Principle 15 — combined assurance model
- IIA Standard 2050 — coordination and reliance among assurance providers
- National Treasury Combined Assurance Framework Guideline — public-sector coordination
FAQ
Questions teams ask before they sign up.
How does this support the assurance discussion with AGSA?
The heat-map shows, risk by risk, which lines of defence provide assurance and how adequate it is — exactly the coverage picture AGSA discusses. Gaps are visible rather than assumed away.
Does it actually drive the audit plan?
Yes. Risks shaded as under-assured feed directly into the internal-audit plan and the audit universe, so the next cycle covers what is genuinely exposed.
Who maintains the map?
The CAE, Chief Risk Officer and Compliance Officer maintain it together and review it with the Audit Committee at each meeting, keeping the coverage view current.
Want to know more about Combined Assurance?
Tell us about your entity and we'll be in touch with a walkthrough, pricing and next steps — everything you see is traceable to source.
