Assurance mapping is a critical governance tool for ensuring assurance efforts are coordinated, targeted and aligned to organisational priorities.
Organisations invest significant time and resources into various assurance activities including compliance monitoring, internal audit, and regulatory reviews.
However, key questions that Boards and management often ask are whether they are receiving enough assurance coverage? Whether this is being directed in the right areas and focuses on risks that matter the most? Whether there is an appropriate overview with respect to how these are being coordinated across the business?
Assurance mapping can help organisations answer these questions by providing greater visibility and clarity of assurance coverage across the business.
What is Assurance Mapping?
Assurance mapping is a structured process of identifying and mapping the main sources and types of assurance in an organisation using “The Institute of Internal Auditors’ Three Lines Model” and coordinating them to best effect.
The assurance mapping process covers the following:
- A comprehensive view of assurance activities across an organisation.
- An evidence-based exercise that identifies potential gaps and duplications of assurance coverage areas. For example, an area where excessive assurance coverage is already provided may not require additional coverage from internal audit, management and/or other external reviews in great detail, and vice versa a functional area where insufficient assurance coverage is provided may require more focus from internal audit, management and/or other external review coverage.
- Coordination of assurance activities between the business and external assurance providers. This also assists organisations in ensuring that its resources are used in the most efficient and effective way.
An assurance map is the resulting document or visual representation once the mapping exercise has been undertaken.
What are the key attributes of Assurance Mapping?
The Three Lines Model provides the foundation for assurance mapping by defining the respective roles of management, risk and compliance functions, internal audit and governing bodies in managing risks, providing oversight and the protection of organisational value.
Key attributes under these governing principles that the assurance mapping process highlights include:
- The first line (management): represents the baseline operational controls and risks owned by management (e.g. policies, procedures, guidelines, systems, delegations, training, controls, etc.).
- The second line (management): represents management’s monitoring, reviewing and support functions (e.g. risk management, compliance, legal).
- The third line (internal audit): provides independent assurance on the governance, risk and control environment.
- Other external assurance: provides other independent assurance across key functions and activities (e.g. regulators, accreditations, external consultants, etc.). These may not always be mandatory and may be implemented at the discretion of the organisation to complement other assurance sources.
It is also important that the assurance map links to the organisation’s risk profile, key functions / service areas and structure.
Practical example
An organisation may receive extensive assurance over its finance function through various means such as external audit, internal audit, management reviews. However, the organisation may be receiving minimal or no assurance over other areas such as AI governance or its people and culture function. An assurance map makes this visible, helping the Board and management identify these imbalances, and inform future assurance priorities.
Changes in the Assurance Mapping Landscape – the growing importance
The operating environment and risks faced by organisations are becoming increasingly complex. Businesses are finding it challenging to manage a number of emerging and evolving risks, as well as meeting increased compliance requirements. This includes areas such as artificial intelligence and automation, ESG, cyber security, privacy, data governance, third-party security, psychosocial health and wellbeing.
These risks often involve a number of stakeholders and assurance providers. The absence of formalised and structured coordination means businesses may find it difficult to determine whether they are being provided with sufficient assurance coverage with respect to these and other risk areas. The need to apply a coordinated approach is even more important considering how a number of organisations are investing a substantial amount of time and resources in assurance activities.
Benefits of Assurance Mapping
Assurance mapping provides great insight into an organisation’s assurance coverage and is a powerful Board and management tool if utilised effectively.
Some of the key benefits include:
- Improved Governance Oversight: Boards, Audit and Risk Committees and management have better visibility of where assurance is being provided and where assurance shortfalls exist. The assurance map also establishes clear roles, responsibilities and parameters across the businesses’ functional areas and risk exposure areas.
- Minimising Duplication: With better visibility of where assurance coverage is being provided, organisations can coordinate more effectively and minimise assurance provision being duplicated across a number of activities. In turn, reducing time, effort and resources.
- Improved Internal Audit Planning: An assurance map can be utilised as part of internal audit planning, to guide internal audit focus areas based on the current assurance coverage environment where little to no assurance coverage exists.
- Better Allocation of Resources: Assurance resources can be directed towards high-risk areas and genuine coverage gaps, supporting more efficient and risk-informed investment.
- Enhanced Risk Management: The assurance map becomes an important organisation-wide tool and sits within the overarching risk management framework. For example, the mapping exercise enables management to test whether risk treatments and controls are being reviewed at an appropriate level.
It is also important to highlight that an assurance map is not, by itself, assurance. An assurance map depicts coverage visually and does not determine effectiveness.
Further, it is imperative that organisations utilise, maintain and update the visual assurance map on a regular basis, given the assurance map reflects the exercise undertaken at a point in time, and the map can only be effective when it is up-to-date and relevant.
Most organisations do not lack assurance activity. What they often lack is a consolidated view of whether that activity is focused on the right risks. An assurance map’s value does not lie simply in documenting who reviews what. It’s value lies in enabling better governance decisions.
How can HLB help?
HLB Mann Judd can support organisations to develop or refresh assurance maps, evaluate assurance coverage and integrate the results into risk management, governance reporting and strategic internal audit planning.
Get in touch with your local HLB Mann Judd contact to learn how we can assist you further.
