Combined Assurance
Combined assurance is an approach to coordinating the different groups that provide assurance about an organization's risks and controls, such as internal audit and other assurance providers, so their work is aligned rather than duplicated or fragmented. The goal is to give the board, typically through the audit committee, a clearer and more complete picture of how key risks are being managed. It is generally treated as a governance practice or framework rather than a legal requirement.
Combined assurance refers to the integration and alignment of assurance activities across multiple assurance providers so that assurance is planned, delivered, and reported in a coordinated manner relative to an organization's identified risks. In practice it seeks to align internal audit with other assurance providers to reduce gaps and duplication, improve risk and governance oversight, and achieve control efficiencies, with results generally reported to the board through the audit committee. It is risk-based, meaning coverage is driven by the organization's identified risks. Combined assurance is typically implemented as a voluntary governance framework or maturity practice; its specific structure, scope, and the roles assigned to management, assurance functions, and the board vary by organization, sector, and jurisdiction. This entry is educational and not legal, audit, or compliance advice.
Why it matters
Large organizations typically rely on multiple providers of assurance, internal audit, compliance monitoring, risk management functions, external audit, and various specialist reviewers. Without coordination, these providers can duplicate effort over some risks while leaving others with little or no coverage. Combined assurance matters because it seeks to reduce this fragmentation and give the board, generally through the audit committee, a more coherent view of whether key risks are actually being managed rather than a patchwork of separate, sometimes contradictory reports.
For boards and audit committees, the value lies in improved oversight quality. When assurance is planned and reported against the organization's identified risks, directors are better positioned to see where assurance is strong, where it is thin, and where reliance is being placed on unverified management representations. It can also produce control efficiencies, because aligning the work of internal audit with other assurance providers can reduce overlap and the 'assurance fatigue' that arises when business units face repeated, uncoordinated reviews of the same processes.
It is important to understand what combined assurance is not. It is generally a voluntary governance practice or maturity framework rather than a legal requirement, and its structure varies by organization, sector, and jurisdiction. It does not replace the distinct responsibilities of management for controls, of assurance functions for independent evaluation, or of the board for oversight; rather, it aims to coordinate how those parties' assurance activities fit together. Whether and how to adopt it remains a matter of each organization's own judgment.
Who it's relevant to
Inside CA
Common questions
Answers to the questions practitioners most commonly ask about CA.