Skip to main content
Category: Internal Audit and Assurance

Combined Assurance

Also known as: CA, Combined Assurance Model, Combined Assurance Framework
Simply put

Combined assurance is an approach to coordinating the different groups that provide assurance about an organization's risks and controls, such as internal audit and other assurance providers, so their work is aligned rather than duplicated or fragmented. The goal is to give the board, typically through the audit committee, a clearer and more complete picture of how key risks are being managed. It is generally treated as a governance practice or framework rather than a legal requirement.

Formal definition

Combined assurance refers to the integration and alignment of assurance activities across multiple assurance providers so that assurance is planned, delivered, and reported in a coordinated manner relative to an organization's identified risks. In practice it seeks to align internal audit with other assurance providers to reduce gaps and duplication, improve risk and governance oversight, and achieve control efficiencies, with results generally reported to the board through the audit committee. It is risk-based, meaning coverage is driven by the organization's identified risks. Combined assurance is typically implemented as a voluntary governance framework or maturity practice; its specific structure, scope, and the roles assigned to management, assurance functions, and the board vary by organization, sector, and jurisdiction. This entry is educational and not legal, audit, or compliance advice.

Why it matters

Large organizations typically rely on multiple providers of assurance, internal audit, compliance monitoring, risk management functions, external audit, and various specialist reviewers. Without coordination, these providers can duplicate effort over some risks while leaving others with little or no coverage. Combined assurance matters because it seeks to reduce this fragmentation and give the board, generally through the audit committee, a more coherent view of whether key risks are actually being managed rather than a patchwork of separate, sometimes contradictory reports.

For boards and audit committees, the value lies in improved oversight quality. When assurance is planned and reported against the organization's identified risks, directors are better positioned to see where assurance is strong, where it is thin, and where reliance is being placed on unverified management representations. It can also produce control efficiencies, because aligning the work of internal audit with other assurance providers can reduce overlap and the 'assurance fatigue' that arises when business units face repeated, uncoordinated reviews of the same processes.

It is important to understand what combined assurance is not. It is generally a voluntary governance practice or maturity framework rather than a legal requirement, and its structure varies by organization, sector, and jurisdiction. It does not replace the distinct responsibilities of management for controls, of assurance functions for independent evaluation, or of the board for oversight; rather, it aims to coordinate how those parties' assurance activities fit together. Whether and how to adopt it remains a matter of each organization's own judgment.

Who it's relevant to

Audit Committees and Boards
Combined assurance is typically designed to serve the board, most often through the audit committee, by consolidating assurance results into a clearer view of how key risks are managed. Directors can use it to test whether assurance coverage aligns with the risks they consider most significant and to identify areas of over- or under-assurance, while retaining their oversight role rather than assuming operational responsibility.
Chief Audit Executives and Internal Audit
Internal audit is frequently central to combined assurance, as the approach seeks to align internal audit with other assurance providers to deliver deeper insight and reduce duplication. Chief audit executives may help coordinate planning and reporting, while preserving internal audit's independence and its distinct evaluative role relative to management's ownership of controls.
Risk and Compliance Functions
Risk management and compliance monitoring functions are often among the assurance providers whose work combined assurance seeks to coordinate. Aligning their activities with internal audit and others can reduce gaps and overlap, though each function retains its own separate mandate and accountability.
Executive Management
Management typically owns the risks and controls that assurance activities examine, and is generally responsible for the underlying processes being assured. Combined assurance can affect how management experiences and responds to assurance work, potentially reducing repeated, uncoordinated reviews, without transferring oversight responsibility to management.
Governance Professionals in SMEs and Other Sectors
The evidence indicates combined assurance has been explored beyond large listed companies, including as a potential integrated governance option for medium-sized enterprises and in sectors such as higher education. Because it is generally a voluntary framework whose structure varies by organization and jurisdiction, professionals in these settings would need to tailor any model to their own context and judgment.

Inside CA

Coordinated Assurance Providers
Combined assurance typically brings together the assurance activities of multiple providers, commonly organized along the three lines model: operational management and control functions (first line), risk and compliance oversight functions (second line), and internal audit (third line), and may also incorporate external assurance sources such as external auditors or regulators. Each provider retains its distinct mandate and accountability.
Assurance Mapping
A central component is the mapping of assurance activities against the organization's key risks or objectives, generally to identify where assurance is duplicated, where gaps exist, and where coverage is adequate. This mapping supports coordination but does not merge the responsibilities of the different functions.
Governance and Oversight Structure
Combined assurance is generally overseen by the board or a relevant committee (such as an audit or risk committee), while management is typically responsible for executing and coordinating assurance activities day to day. The oversight role and the operational role remain distinct.
Risk-Based Prioritization
Assurance effort is typically directed toward areas of greatest significance, often informed by the organization's risk assessment, risk appetite, and risk tolerance. This helps focus limited assurance resources, though it does not alter the underlying ownership of specific risks or controls.
Reporting and Communication
Combined assurance generally involves consolidated or coordinated reporting to those charged with governance, intended to give a more holistic view of the effectiveness of risk management and control. Reporting arrangements vary by framework, jurisdiction, sector, and entity type.

Common questions

Answers to the questions practitioners most commonly ask about CA.

Does combined assurance mean the internal audit function coordinates and controls all assurance activity across the organization?
Not necessarily. Combined assurance is typically a coordinating approach that maps and aligns assurance from multiple providers, but it does not automatically place internal audit in control of the first and second lines. Under many three-lines models, management (first line) owns and manages risks and controls, risk and compliance functions (second line) provide oversight and monitoring, and internal audit (third line) provides independent assurance. Combined assurance seeks to align these efforts without eroding the independence of internal audit or blurring accountability. Who convenes or facilitates the exercise varies by organization; it may be internal audit, a risk function, or a governance office, and this should not be assumed. This entry is educational and not audit or compliance advice.
Is combined assurance a mandatory requirement that organizations must implement?
In most contexts it is not a universal legal requirement. Combined assurance is generally described in governance codes, professional standards, and best-practice frameworks rather than mandated by statute for all entities. In certain jurisdictions or sectors, corporate governance codes may recommend or expect it, often on a comply-or-explain basis, and some regulated sectors may have more specific expectations. Whether it applies, and in what form, depends on jurisdiction, sector, entity type, and the framework an organization chooses to adopt. Organizations should confirm the specific obligations and guidance relevant to their circumstances; this entry is educational and not legal advice.
How can an organization begin mapping its existing assurance activities?
A common starting point is to build an assurance map that sets out the organization's significant risks and identifies which providers give assurance over each, distinguishing first-line management activities, second-line risk and compliance oversight, and third-line independent audit, along with any external assurance. This mapping can help surface gaps where a material risk lacks coverage, and duplication where multiple providers assure the same area. The map is generally a tool to inform coordination and prioritization rather than a compliance document in itself, and its usefulness depends on the quality and honesty of the underlying inputs.
How does combined assurance relate to the board and its committees?
Combined assurance is typically intended to give the board, and often the audit and risk committees, a more coherent view of how risks are being assured across the organization, supporting their oversight role. It generally does not transfer operational responsibility for controls to the board or its committees; management usually retains that responsibility. Committees may receive reporting on assurance coverage, gaps, and reliance placed on different providers. The precise allocation of these responsibilities depends on the organization's governance structure, applicable frameworks, and any relevant codes or listing rules.
What practical challenges commonly arise when implementing combined assurance?
Frequently cited challenges include inconsistent risk taxonomies and rating scales across providers, protecting the independence and objectivity of internal audit while coordinating with other functions, avoiding over-reliance on assurance whose scope or rigor differs, and maintaining clear accountability so that coordination does not dilute ownership of risks and controls. Cultural and data-sharing barriers between functions can also arise. How significant each challenge is, and how it is addressed, depends on the organization's size, maturity, and structure, and on the professional judgment of those involved.
How might an organization assess whether it can place reliance on another function's assurance work?
Reliance decisions generally consider factors such as the competence, objectivity, and independence of the provider, the scope and rigor of the work performed, and the extent to which its findings address the specific risk in question. Distinguishing control design from operating effectiveness can matter here, as assurance over one does not automatically cover the other. Internal audit and other providers typically retain professional judgment over how much reliance is appropriate and whether additional work is needed. These are judgment-based determinations that depend on the facts and on applicable professional standards; this entry is educational and not audit advice.

Common misconceptions

Combined assurance merges the three lines of defense into a single function.
Combined assurance coordinates the activities of separate assurance providers; it does not eliminate their distinct mandates or accountabilities. Internal audit generally retains its independence, and second-line risk and compliance functions remain separate from first-line management responsibilities.
Adopting combined assurance is a binding legal requirement.
Combined assurance is generally a governance practice or expectation associated with certain codes and frameworks rather than a universal statutory obligation. Whether, and to what extent, it applies depends on jurisdiction, sector, listing requirements, and entity type, and in many settings it is a recommended practice rather than binding law.
Combined assurance transfers responsibility for risks and controls to internal audit or the assurance function.
Ownership of risks and controls typically remains with management (the first line). Assurance functions provide evaluation and reporting on the effectiveness of those controls; coordinating their work does not shift accountability for the underlying risks.

Best practices

Develop and maintain an assurance map that links assurance activities to the organization's key risks and objectives, so that duplication, gaps, and coverage can be identified and reviewed periodically.
Preserve the distinct mandates and independence of each assurance provider, particularly internal audit, when coordinating their activities, and document how accountability and reporting lines are maintained.
Clarify in governance documentation that management retains ownership of risks and controls while the board or relevant committee retains oversight, avoiding any drift of operational duties to the board or oversight duties to management.
Prioritize assurance effort using the organization's risk assessment, risk appetite, and risk tolerance, focusing coordinated coverage on the most significant areas.
Establish consolidated or coordinated reporting to those charged with governance that gives a holistic view of control and risk management effectiveness without obscuring the source or scope of each provider's work.
Tailor the combined assurance approach to the organization's jurisdiction, sector, applicable frameworks, and entity type, and treat this guidance as educational rather than a substitute for legal, audit, or compliance advice.