Skip to main content
Category: Internal Audit and Assurance

Assurance Map

Also known as: Assurance Mapping, Combined Assurance Map
Simply put

An assurance map is a structured tool that lays out where an organization gets assurance over its key risks and who provides it, so gaps and overlaps become visible. It helps different assurance providers coordinate their work, reduce duplicated effort, and improve overall coverage. It is generally a voluntary practice used to increase transparency rather than a legal requirement.

Formal definition

An assurance map is a structured means of identifying and mapping the main sources and types of assurance across an organization's lines of defence, typically to reveal coverage of key risks, expose gaps and duplication, and enable coordination and reliance among assurance providers. It is a common internal audit practice used in many organizations to provide insight into coverage delivered by other assurance functions; some frameworks describe it across three lines while others reference a four-lines-of-defence model, so the specific structure depends on the framework and organization adopting it. As a coordination tool it does not itself perform assurance activities, and its use, scope, and format vary by organization; it is generally a leading practice rather than a mandated requirement.

Why it matters

In most organizations, assurance over key risks is delivered by many different providers: management controls, risk and compliance functions, internal audit, and external assurance sources. When these providers work in silos, boards and audit committees can be left with an incomplete picture, some risks may be covered several times over while others receive little or no attention. An assurance map addresses this by making coverage visible, so that gaps and duplication across the lines of defence become apparent rather than hidden.

The practical value lies in coordination and efficiency. By laying out who provides assurance over which risks, an assurance map allows different providers to plan their work with awareness of one another, reduce duplicated effort, and enable one function to place reliance on another where appropriate. It is generally treated as a leading practice that increases transparency rather than a legal requirement, so organizations adopt it to strengthen governance and inform assurance planning, not to satisfy a specific mandate.

Because the format and scope of an assurance map vary by organization and framework, some describe it across three lines of defence while others reference a four-lines model, its usefulness depends on how well it reflects the organization's actual risks and assurance sources. The map itself does not perform assurance; it is a tool for seeing and coordinating assurance that others deliver. Its value therefore rests on the quality and honesty of the underlying information and on management and the board acting on the gaps it reveals.

Who it's relevant to

Chief Audit Executives and Internal Audit
Assurance mapping is commonly an internal audit practice, and the CAE often owns or coordinates the map to plan audit work, avoid duplicating the efforts of other providers, and identify where internal audit can rely on assurance delivered elsewhere. It helps internal audit demonstrate to stakeholders how coverage over key risks is achieved across the organization.
Audit Committees and the Board
The board and its audit committee are consumers of the insight an assurance map provides. It gives them a clearer view of where assurance over key risks sits, whether coverage is adequate, and where gaps or overlaps exist, information that supports their oversight of the organization's assurance arrangements. The map informs oversight but does not shift assurance responsibilities onto the board itself.
Risk and Compliance Functions
As assurance providers within the lines of defence, risk and compliance functions appear on the map and benefit from seeing how their work fits alongside that of other providers. This can support coordination, reduce duplicated effort, and clarify which function is providing assurance over which risks.
Management
Management, as an operator of controls and a source of assurance over risks it owns, is reflected in the map's coverage of key risks. The map can help management understand where assurance over its areas comes from and where coverage may be thin, though acting on identified gaps generally requires coordination with the relevant assurance providers and oversight bodies.

Inside Assurance Map

Assurance sources (lines of defense)
A mapping typically identifies which parties provide assurance over a given risk or control area, often organized by the three lines model: operational management (first line), risk and compliance functions (second line), and internal audit (third line). External assurance providers, such as external auditors or regulators, are sometimes recorded as a separate source.
Key risks or objectives
The map is generally anchored to the organization's significant risks, control objectives, or areas of regulatory obligation, so that assurance activity can be assessed against what matters most rather than against activity volume.
Coverage and gaps
A core purpose is to show where assurance exists, where it is duplicated across multiple providers, and where material risks receive little or no independent assurance. Highlighting under- and over-covered areas is typically the analytical output.
Nature and level of assurance
Entries often distinguish the type of assurance provided (for example, self-assessment versus independent review) and its relative depth or reliability, since not all assurance sources carry equal weight.
Ownership and reporting lines
The map generally records who owns each risk and control and to whom assurance results are reported, clarifying where accountability sits and how findings reach the board or its committees, such as the audit or risk committee.

Common questions

Answers to the questions practitioners most commonly ask about Assurance Map.

Is an assurance map the same thing as a risk register?
No. A risk register catalogs risks along with their assessment (such as likelihood and impact) and often the controls and owners associated with each. An assurance map is a different tool: it plots the sources of assurance across an organization against key risks or objectives, showing which functions provide assurance over what and where assurance is duplicated or missing. The two are complementary and frequently drawn from overlapping data, but the assurance map answers the question 'who gives us confidence over this risk, and how robust is that confidence?' rather than simply recording the risks themselves. In practice, an organization typically maintains both, using the risk register as an input to the assurance map.
Does building an assurance map mean internal audit is now responsible for all assurance activity?
No. Assurance across an organization is generally provided by multiple parties spanning what many frameworks describe as the three lines: operational management and its own controls, risk and compliance oversight functions, and independent internal audit, alongside external assurance providers. Internal audit often coordinates or facilitates the mapping exercise because of its independent, enterprise-wide vantage point, but facilitating the map does not transfer ownership of first- or second-line assurance to internal audit. Management retains accountability for the controls it operates, oversight functions retain their monitoring role, and the board or audit committee typically oversees the overall assurance picture. The map is intended to clarify these responsibilities, not to consolidate them.
How should an organization decide what to place along the axes of an assurance map?
There is no single prescribed format, and the design generally depends on the organization's purpose for the map. Many organizations plot key risks, strategic objectives, or principal risk categories down one axis and the available sources of assurance across the other, distinguishing between the different lines or between internal and external providers. Some map to a control framework or to the risk register to maintain traceability. The choice typically reflects what the board or audit committee wants to see and the level of granularity that is useful; too fine a breakdown can obscure the overall picture, while too coarse a view can hide gaps. This is a matter of judgment rather than a fixed rule.
How do you interpret gaps and overlaps once the map is complete?
A gap indicates a risk or objective over which little or no assurance is currently provided, while an overlap indicates multiple functions providing assurance over the same area. Neither is automatically a problem. A gap may be acceptable if the risk falls within appetite or is low priority, and some overlap may be intentional where a risk is significant enough to warrant layered coverage. The map is a prompt for informed discussion rather than a scorecard: management and the relevant oversight functions typically assess whether the coverage is proportionate to the risk, and whether any duplication represents efficient reinforcement or wasteful effort. Conclusions depend on the organization's risk appetite and its own judgment.
How often should an assurance map be refreshed?
There is no universal frequency, and the appropriate cadence generally reflects how quickly the organization's risk profile, structure, and assurance arrangements change. Many organizations revisit the map at least annually, often aligned to the audit planning cycle or the board's risk review, and update it on an event-driven basis when significant changes occur, such as a major reorganization, a new regulatory obligation, or an emerging risk. The map is most useful when treated as a living tool rather than a one-time deliverable, though the effort involved should be proportionate to the value it provides.
What is the role of the board or audit committee in relation to the assurance map?
The board, typically through its audit or risk committee, generally uses the assurance map as an oversight tool to satisfy itself that key risks are subject to adequate and appropriately independent assurance, and to understand where reliance is being placed. The board oversees rather than operates the mapping process: it does not build or run the underlying assurance activities but reviews the resulting picture, challenges apparent gaps or unjustified overlaps, and considers whether the balance of assurance is appropriate. Where the map informs a broader statement on the effectiveness of risk management and internal control, its use may connect to governance code expectations in some jurisdictions, though the specific obligations vary by jurisdiction and entity type.

Common misconceptions

An assurance map is the same as internal audit's audit plan.
An assurance map is generally broader. It seeks to capture assurance from across all sources, including first- and second-line functions and external providers, not only the work internal audit performs. The audit plan may be informed by the map, but the two serve different purposes and are typically owned differently.
More lines of assurance over a risk always means the risk is well managed.
Multiple assurance sources over the same area can indicate duplication and inefficiency rather than strength, while other significant risks may go uncovered. The map is intended to help evaluate whether coverage is appropriately targeted, not simply to maximize the number of providers.
The board owns and maintains the assurance map as an operational task.
Preparing and maintaining a map is typically a management or assurance-function activity, often coordinated by internal audit or a risk or compliance function. The board and its committees generally use the map for oversight rather than producing it, and accountability for the underlying risks remains with management.

Best practices

Anchor the map to the organization's significant risks or control objectives rather than to functional activity, so coverage is assessed against what matters most.
Distinguish the type and relative reliability of each assurance source, avoiding treating self-assessment and independent review as equivalent.
Explicitly flag both gaps in coverage and areas of duplication, and use these findings to inform, rather than replace, the internal audit plan and management's own assurance activities.
Clarify ownership for each risk and control and confirm how assurance results are reported to the relevant board committee, keeping oversight and operational responsibilities separate.
Review and refresh the map on a defined cycle and when the risk profile changes, since a static map can quickly misrepresent actual coverage.
Treat the map as a decision-support tool that depends on professional judgment and organizational context, and validate its conclusions with the relevant functions rather than relying on it in isolation.