Coordinating Assurance Coverage and Assurance Mapping
In CIA Part 3, coordinating assurance coverage and assurance mapping are key techniques the chief audit executive (CAE) uses when building a risk-based internal audit plan. Under the IIA Standards (formerly Standard 2050, now Standard 9.5 of the Global Internal Audit Standards), the CAE should shar… In CIA Part 3, coordinating assurance coverage and assurance mapping are key techniques the chief audit executive (CAE) uses when building a risk-based internal audit plan. Under the IIA Standards (formerly Standard 2050, now Standard 9.5 of the Global Internal Audit Standards), the CAE should share information, coordinate activities and consider relying on the work of other internal and external assurance and consulting providers. The goal is to ensure proper coverage and minimize duplication of effort. Assurance providers typically include first-line management self-assessments, second-line functions such as risk management, compliance, quality, health and safety and information security, and third-line internal audit. External providers include external auditors, regulators and specialist consultants. Coordinating with them reduces audit fatigue for the business, lowers costs and gives the board a more complete view of risk. Assurance mapping is the practical tool used to achieve this coordination. It is a matrix or grid that lists the organization's key risks or processes on one axis and the assurance providers on the other. Each cell records who provides assurance, the scope, frequency, last review date, and the level or strength of assurance provided. The map reveals gaps, where significant risks receive little or no assurance, and overlaps, where several providers review the same area unnecessarily. Internal audit can then focus its plan on high-risk gaps and reduce effort where reliable coverage already exists. This approach is often called combined assurance. Before relying on another provider's work, the CAE must evaluate that provider's competence, objectivity and due professional care. The CAE must also assess the scope, objectives and quality of the work performed. Reliance does not transfer responsibility, because internal audit remains accountable for its own conclusions. The CAE should document the basis for reliance, communicate the results to senior management and the board, and update the assurance map as risks and providers change.
Coordinating Assurance Coverage and Assurance Mapping (CIA Part 3: Internal Audit Plan)
Introduction
Coordinating assurance coverage and assurance mapping are core topics in the CIA Part 3 syllabus. They fall under managing the internal audit activity, specifically developing the internal audit plan. These concepts explain how the chief audit executive (CAE) makes sure the organization gets complete, efficient and non-duplicated assurance over its key risks. The internal audit function is only one of several assurance and consulting providers.
Why It Is Important
Organizations get assurance from many sources, including:
• Management and process owners
• Risk management
• Compliance
• Quality assurance
• Health and safety
• Information security
• External auditors
• Regulators
• Third-party specialists
• Internal audit
Without coordination, several problems arise:
• Duplication of effort: several functions test the same controls, which wastes resources and causes audit fatigue for the business.
• Gaps in coverage: significant risks may receive no assurance at all because each provider assumes another is covering them.
• Inconsistent reporting: the board and senior management receive fragmented, conflicting or incomparable information about risk and control.
• Inefficient use of internal audit resources: internal audit may spend time where others already provide reliable assurance instead of focusing on high-risk, under-covered areas.
The IIA's Global Internal Audit Standards (2024) address this directly in Standard 9.5 Coordination and Reliance. Under the former IPPF, the equivalent was Standard 2050 Coordination and Reliance. The CAE should coordinate with internal and external providers of assurance services and consider relying on their work. The aims are to ensure proper coverage and minimize duplication of effort. The three lines model also emphasizes that the activities of all lines should be aligned, communicated and coordinated.
What It Is
Coordinating assurance coverage is the process by which the CAE communicates and collaborates with other assurance providers. Its purpose is to share information, align plans and timing, agree on common risk and control terminology, and determine where reliance can be placed. The goal is comprehensive coverage at an optimal cost.
Assurance mapping is a tool, usually a matrix or chart, that links the organization's significant risks or risk categories to the assurance providers covering them. A typical map records:
• The key risks, objectives or processes, often taken from the risk register or enterprise risk management framework
• Which line or provider gives assurance over each risk (first line, second line, internal audit, external providers)
• The nature, scope, frequency and timing of each provider's work
• The level or strength of assurance, sometimes rated or color-coded
• The gaps and overlaps in coverage
Combined assurance is a closely related concept. It means aligning all assurance processes so that the board and audit committee receive one integrated view of risk and control effectiveness. The assurance map is the main tool used to achieve combined assurance.
How It Works
Step 1: Identify the risk universe. Start with the organization's strategic objectives and key risks, using the ERM risk register and internal audit's own risk assessment.
Step 2: Identify all assurance providers. List them across the three lines:
• First line: management and operational controls, control self-assessment
• Second line: risk management, compliance, information security, quality, health and safety, legal
• Third line: internal audit
• External: external auditors, regulators, certification bodies, consultants
Step 3: Map coverage. For each risk, record who provides assurance, what they do, how often, and what they report and to whom.
Step 4: Evaluate reliance. Before relying on another provider's work, the CAE should assess that provider's:
• Independence and objectivity, including potential conflicts of interest
• Competence, qualifications and experience
• Due professional care and the methodology used, such as planning, supervision and documentation
• Scope, objectives and results, to confirm they meet internal audit's needs
Relying on another provider's work does not transfer responsibility. Internal audit remains accountable for its own conclusions and opinions.
Step 5: Identify gaps and overlaps. Gaps (high risk with little or no assurance) feed into the risk-based internal audit plan as priorities. Overlaps (multiple providers on the same risk) are opportunities to streamline, rely on others, or agree a division of work.
Step 6: Coordinate and agree. Hold regular meetings, share plans and reports, agree a common risk language and rating scale, coordinate timing to reduce business disruption, and establish information-sharing protocols that respect confidentiality.
Step 7: Report to the board. Present the assurance map or combined assurance report to the audit committee. This gives the board a holistic picture of where assurance is strong, weak or missing, and supports its oversight role.
Step 8: Update periodically. The map should change as risks, the organization, and the assurance landscape change. Typically it is updated alongside the annual or rolling audit plan.
Benefits of Assurance Mapping
• Gives a visual, holistic view of assurance over key risks
• Highlights gaps and duplications
• Supports a risk-based internal audit plan and efficient allocation of resources
• Reduces audit fatigue and cost
• Strengthens board oversight and governance
• Improves communication among the three lines
Limitations and Challenges
• It takes time and resources to build and maintain.
• Other providers may resist sharing information or be unwilling to align.
• Providers may use different terminology and rating scales.
• The map can give false comfort if the quality of others' assurance is not evaluated.
• Confidentiality constraints apply, for example to regulator or legal work.
Role of the CAE vs. the Board
The CAE leads coordination and decides whether to rely on others' work. Senior management supports cooperation among the functions. The board or audit committee oversees the overall assurance framework and uses the map to judge whether coverage is adequate. The CAE should explain to the board the basis for any reliance and communicate significant gaps.
Exam Tips: Answering Questions on Coordinating Assurance Coverage and Assurance Mapping
1. Know the purpose words. Correct answers usually mention ensuring proper coverage, minimizing duplication of effort, identifying gaps, or providing a holistic view to the board. Be wary of answers saying coordination is meant to reduce internal audit's independence, or to let internal audit control other functions.
2. Reliance does not mean transfer of responsibility. A common trap states that if internal audit relies on another provider, that provider becomes responsible for internal audit's opinion. This is wrong. The CAE remains responsible for internal audit's conclusions.
3. Evaluate before relying. If a question asks what the CAE should do first or before relying on another provider's work, choose the answer about assessing competence, objectivity or independence, and due professional care. Do not choose answers that rely on the work automatically or that re-perform all of it.
4. Gaps go into the audit plan. When a scenario shows a high risk with no assurance coverage, the best response is usually to prioritize it in the risk-based audit plan or to raise it with senior management and the board. Simply noting it is not enough.
5. Overlaps signal efficiency opportunities. When several functions test the same area, the best answer usually involves coordinating, agreeing scope, or placing reliance. Eliminating the other functions is rarely correct.
6. Link to the three lines model. Be able to place each provider in its line. Internal audit provides independent assurance and does not perform management's responsibilities. Second-line functions are not fully independent of management.
7. External auditors. Coordination with external auditors usually involves sharing work papers and plans, coordinating timing, and avoiding duplication. Internal audit does not direct the external auditor, and the external auditor's work does not replace internal audit's risk-based plan.
8. Board perspective. If asked who benefits most from an assurance map, or what its primary output is, think of the board or audit committee gaining a consolidated view of assurance over significant risks.
9. Common terminology. Choose answers that promote a common risk language and consistent rating criteria. These are key success factors for combined assurance.
10. Read for best versus acceptable. CIA questions often have several plausible answers. Prefer the one that is risk-based, collaborative, and preserves internal audit's independence while maximizing coverage and efficiency.
Sample Question
A CAE discovers that the compliance function, the information security function and internal audit are all testing access controls over the same ERP system. Meanwhile, no provider is reviewing third-party vendor risk, which has been rated high. What is the CAE's most appropriate action?
A. Stop internal audit testing of access controls immediately and let the other functions continue.
B. Prepare an assurance map, coordinate with the other providers to allocate coverage, evaluate whether their work can be relied upon, and reallocate internal audit resources to vendor risk.
C. Report the compliance and information security functions to the board for inefficiency.
D. Continue the current plan, since internal audit must remain independent of other functions.
Answer: B. It addresses both the overlap and the gap, applies the reliance evaluation, and follows the risk-based planning principle.
Key Takeaways
• Coordination and reliance are required by the IIA Standards.
• The assurance map links key risks to the assurance providers covering them, revealing gaps and overlaps.
• Evaluate competence, objectivity and due care before relying on other providers.
• Reliance never removes the CAE's responsibility for internal audit's conclusions.
• The results feed the risk-based audit plan and give the board an integrated view of assurance.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!