Skip to main content
Category: Internal Audit and Assurance

Governance, Risk, and Control Assurance

Also known as: GRC (in the assurance context)
Simply put

Governance, risk, and control assurance refers to the combined activities an organization uses to set direction and oversight (governance), identify and manage the things that could affect its objectives (risk), and gain confidence that its policies and controls are actually working (assurance). While governance is about establishing policies, frameworks, responsibilities, and oversight processes, assurance is a distinct activity focused on independently confirming that those controls operate as intended. These terms are related but describe separate functions, and how they are structured typically varies by organization, sector, and jurisdiction.

Formal definition

Governance, risk, and control assurance describes the interrelated but distinct capabilities through which an organization directs and oversees its activities, manages risk to objectives, and obtains evidence-based confidence over the design and operating effectiveness of its controls. Governance encompasses the policies, frameworks, allocation of responsibilities, and oversight processes, typically an accountability of the board and its committees, with implementation by management. Assurance, by contrast, is a separate activity aimed at evaluating and confirming that controls are appropriately designed and functioning, often delivered by internal audit or other independent functions. Practitioners should note that this framing overlaps with, but is not identical to, the broader 'GRC' (Governance, Risk, and Compliance) concept described in the evidence, and that specific roles, ownership, and the balance between binding requirements and voluntary frameworks depend on the entity type, sector, and jurisdiction. This entry is educational and not legal, audit, or compliance advice.

Why it matters

Boards and senior management are increasingly held accountable not just for having policies on paper, but for demonstrating that those policies and controls actually function. Governance, risk, and control assurance matters because it closes the gap between intent and reality: governance sets direction and allocates responsibility, risk management identifies what could interfere with objectives, and assurance independently confirms whether the controls meant to address those risks are designed well and operating as intended. Treating these as a single blurred activity is a common source of oversight failure, because the function that owns a control should not be the sole party attesting that it works.

The distinction between establishing controls and confirming them is central. As practitioners frequently observe, governance focuses on establishing the policies, frameworks, responsibilities, and oversight processes, while assurance focuses on evaluating and confirming that those controls operate effectively. A board that receives only management's self-reporting, without independent assurance, may believe it has visibility that it does not. Conversely, assurance activity that is not anchored in a clear governance structure and a defined understanding of risk to objectives can become a checklist exercise disconnected from what actually threatens the organization.

How this is structured varies significantly. The balance between binding requirements, such as statutes, regulations, and listing rules, and voluntary frameworks or codes depends on the entity type, sector, and jurisdiction. Because of this variation, organizations should be deliberate about which activities are legally required, which reflect adopted best practice, and where the answer depends on their own facts and judgment rather than assuming a single universal model applies.

Who it's relevant to

Boards and board committees
Directors carry oversight accountability for governance and for confirming that risk is managed and controls function. This concept is relevant to boards and audit or risk committees because it clarifies why independent assurance, rather than management self-reporting alone, supports informed oversight, while keeping the board's role distinct from management's operational ownership of controls.
Internal audit and assurance functions
Assurance is often delivered by internal audit or other independent functions tasked with evaluating whether controls are appropriately designed and operating effectively. This entry helps such functions articulate how their evidence-based work is distinct from the governance and risk-management activities owned by management.
Chief risk and compliance officers
Risk and compliance leaders identify and help manage the things that could affect objectives and are frequently responsible for control design and monitoring. The framing here is useful for distinguishing their activities from independent assurance and from the board's oversight role, and for recognizing where the broader GRC concept overlaps with, but differs from, assurance specifically.
General counsel and governance professionals
Those advising on structure and accountability benefit from a clear separation of governance, risk, and assurance roles, and from attention to how the mix of binding requirements and voluntary frameworks varies by entity type, sector, and jurisdiction rather than following one universal model.
Senior management
Management implements governance, owns the controls addressing risk to objectives, and is subject to independent assurance over those controls. This entry is relevant for understanding where operational ownership sits and why an independent view of control effectiveness is treated as separate from management's own reporting.

Inside Governance, Risk, and Control Assurance

Three Lines Model
A widely used framework (updated by the IIA in 2020 from the earlier 'three lines of defence' concept) distinguishing management functions that own and manage risk (first line), risk and compliance oversight functions that support and monitor (second line), and internal audit as independent assurance (third line). It clarifies accountability rather than mandating a rigid structure, and the model is guidance, not a legal requirement.
Assurance Mapping
The exercise of identifying which functions provide assurance over which risks and controls, typically to reveal gaps and duplication across first, second, and third line activities. Ownership of the map generally sits with a coordinating function such as internal audit or a risk function, but responsibility varies by entity.
Control Design vs. Operating Effectiveness
Two distinct assessment questions: whether a control is designed appropriately to address a risk, and whether it operated as intended over a period. Assurance activities generally test both; a well-designed control can still fail on operating effectiveness, and vice versa.
Inherent and Residual Risk
Inherent risk is the exposure before considering controls; residual risk is what remains after controls operate. Assurance work typically evaluates whether residual risk aligns with the board-approved risk appetite, though the terms are not interchangeable and depend on how the organisation defines its assessment methodology.
Independence and Objectivity
A defining feature of third-line assurance (internal audit) is independence from the activities it reviews, generally supported by a reporting line to the audit committee. Second-line functions provide monitoring and oversight but are typically not independent in the same sense, since they may participate in designing or operating controls.
Board and Committee Oversight
The board, often through an audit or risk committee, is generally responsible for overseeing the adequacy of assurance arrangements and the effectiveness of the control environment. Management is responsible for designing and operating controls. This oversight-versus-operational distinction is central and should not be blurred.
Supporting Frameworks
Frameworks such as COSO Internal Control - Integrated Framework, COSO ERM, ISO 31000, and IIA standards inform assurance practice. Some become effectively expected through listing rules or regulatory reference in certain jurisdictions (for example, controls-related requirements associated with Sarbanes-Oxley for in-scope issuers), but no single framework is universally mandatory.

Common questions

Answers to the questions practitioners most commonly ask about Governance, Risk, and Control Assurance.

Are governance, risk management, and control assurance just three names for the same activity?
No. Although they are closely related and often coordinated, they are distinct disciplines with different owners and objectives. Governance generally refers to the structures, processes, and oversight by which an entity is directed and held accountable, typically led by the board and its committees. Risk management is the ongoing process, usually owned by management, of identifying, assessing, and treating uncertainty against defined objectives, often structured around frameworks such as COSO ERM or ISO 31000. Control assurance is the activity of evaluating whether controls are designed appropriately and operating effectively, which may be performed by management (first and second lines) or by independent assurance functions such as internal audit (third line). Conflating them tends to obscure where accountability actually sits. This entry is educational and not legal, audit, or compliance advice.
Does obtaining control assurance mean the board can treat a risk as eliminated?
Not typically. Assurance addresses whether controls are designed and operating as intended; it does not remove the underlying risk. Even where controls operate effectively, residual risk generally remains after their application, and that residual risk should be evaluated against the entity's risk appetite and tolerance. Assurance also has inherent limitations, it is usually based on samples, point-in-time or period testing, and professional judgment, and it cannot provide absolute certainty. The board's oversight role generally involves understanding these limitations rather than assuming assurance converts a risk to zero. The specifics depend on the facts, the framework applied, and the assurance provider's own judgment.
How should responsibilities for governance, risk, and control assurance typically be divided across the lines of defense?
Under many three-lines models, operational management owns and manages risks and the related controls (first line); risk and compliance functions provide oversight, expertise, and monitoring (second line); and internal audit provides independent assurance (third line). The board and its committees sit above these lines in an oversight capacity rather than an operational one. The precise allocation varies by entity size, sector, and jurisdiction, and the model is a guiding framework rather than a universal legal mandate. Entities should document who owns each risk, who monitors it, and who provides independent assurance to avoid gaps or duplication.
What is the difference between assessing control design and control operating effectiveness, and why does the order matter?
Assessing control design generally asks whether a control, if operating as intended, would adequately address the risk it is meant to mitigate. Assessing operating effectiveness generally asks whether the control actually functioned as designed over a defined period. The order typically matters because a control that is poorly designed cannot be relied upon regardless of how consistently it operates, so design is usually evaluated first. A common implementation pitfall is testing operation without first confirming design adequacy, which can produce false comfort. The evidence and testing approach depend on the nature of the control and the professional judgment of those performing the work.
How can assurance activities be prioritized when resources are limited?
Prioritization is generally risk-based. Many entities focus assurance effort on areas of higher inherent risk, higher residual risk relative to appetite, or greater significance to strategic objectives, financial reporting, or regulatory obligations. This typically involves coordination between the risk function's assessments and the assurance plan so that effort is directed where it adds most value. Risk appetite, tolerance, and the entity's own risk capacity generally inform where the line is drawn. The appropriate prioritization depends on the entity's facts, sector, and applicable requirements, and remains a matter of professional judgment rather than a fixed formula.
How can duplication or gaps between risk monitoring and independent assurance be reduced?
Coordination mechanisms often include a shared understanding of the risk universe, combined assurance mapping that plots which functions cover which risks, and regular dialogue among management, the risk and compliance functions, and internal audit. The aim is generally to identify risks that are over-assured, under-assured, or unassured, while preserving the independence of the third line. Governance frameworks and codes may encourage such coordination, but the specific approach is typically an internal design choice rather than a prescribed legal requirement. Care should be taken that coordination does not compromise the objectivity of independent assurance providers.

Common misconceptions

The three lines are three separate departments, and assurance means each simply does its own checks.
The model describes distinct roles and accountabilities, not necessarily three separate teams. First-line management owns and manages risk, the second line provides oversight and support, and the third line provides independent assurance. Coordination across the lines, not siloed checking, is the point, and the structure can be adapted to the size and nature of the entity.
If a control is well designed, assurance over it is complete.
Design adequacy and operating effectiveness are separate questions. A control can be soundly designed yet fail in practice because it was not consistently performed. Assurance generally requires evidence that the control operated as intended over the relevant period, not just that it exists on paper.
Internal audit is responsible for the effectiveness of controls.
Management owns and is accountable for designing and operating controls. Internal audit provides independent assurance about whether those controls are effective; it does not own them. Attributing control effectiveness to the assurance function confuses oversight and independent evaluation with operational responsibility.

Best practices

Prepare and periodically refresh an assurance map that links key risks to the functions providing assurance, so the board can identify coverage gaps and unnecessary duplication across the lines.
Test both control design and operating effectiveness explicitly, and document the period and evidence supporting any conclusion on operating effectiveness rather than relying on design alone.
Preserve the independence of the third line by maintaining a reporting relationship to the audit committee, and avoid assigning internal audit operational responsibilities that would compromise its objectivity.
Clarify in writing which functions sit in the first, second, and third lines and where accountability for each risk and control resides, adapting the model to the entity's size, sector, and jurisdiction rather than imposing a rigid structure.
Express assurance conclusions in relation to the board-approved risk appetite and tolerance, distinguishing inherent from residual risk so oversight bodies understand what exposure remains after controls.
Select and apply recognised frameworks such as COSO, ISO 31000, or IIA standards deliberately, documenting which are used and why, and recognising that requirements and expectations differ by jurisdiction, sector, and entity type.