Internal Audit
Three Reviews Do Not Mean Your Risk Is Covered
An assurance map should show what your reviews actually establish, not just who touched the risk. Start with the business question nobody has answered.
By Eric Kennedy · Thu Sep 17 2026 · 9 min read
Assurance mapping connects important business risks to the work that has actually examined them. A useful map shows the question each review answered, the evidence behind its conclusion, and what remains untested. It does not turn three department names beside a risk into three layers of protection.
For a CFO or chief audit executive, the payoff is a better choice about where the next review belongs. Before adding another audit, find out whether the existing work answers the question the business needs answered.
Start with the question, not the list of reviewers
Consider this illustrative scenario, constructed for this article rather than drawn from a KRG client engagement.
A manufacturer depends on a specialist component. The risk register says “supplier disruption,” and the assurance column lists procurement, compliance, and internal audit. That looks reassuring until someone asks whether the backup supplier can deliver before available inventory runs out.
Procurement has confirmed the supplier file is complete. Compliance has confirmed required checks are complete. Internal audit has tested onboarding approvals. All three activities can be useful. None, in this scenario, tested the backup supplier's capacity, qualification lead time, or delivery capability.
Three reviews. One unanswered question.
The graphic's “onboarding covered” label is deliberately narrow. It means the stated onboarding activities were reviewed, not that every onboarding control works or that supplier disruption is controlled. “Still untested” belongs beside the delivery question, even if the other reviews reported no exceptions.
The right next step is not automatically a fourth review of the supplier file. Operations needs to establish whether the alternate source can meet the required delivery window. The CAE can then decide what independent challenge or testing is warranted, considering the exposure and the evidence operations provides.
This is the distinction between counting reviewers and understanding coverage. Count evidence, not reviewers. If the underlying exposure is unclear, start with the business consequences described in vendor risk as financial exposure, then decide which questions assurance needs to address.
What an assurance map does, and what it does not
A risk register records exposures, ownership, and responses. An assurance map adds a different view: what supports management's confidence that those responses will work?
The IIA's Global Internal Audit Standards, Standard 9.5 requires the CAE to coordinate with other assurance providers and consider reliance on their work. When internal audit relies on another provider, the CAE must document the basis and remains responsible for internal audit's conclusions. The implementation guidance describes an assurance map as one way to identify coverage and duplication. It does not require a particular mapping template.
HM Treasury's Orange Book, Part II, sections 9.7 to 9.13 likewise allows different mapping approaches rather than prescribing one format. This is UK government guidance, not a requirement for US private companies. Its discussion is useful context for adapting the method to a mid-market business.
The approach below is KRG's practical recommendation, not a standards checklist. It focuses on the question a decision-maker is trying to resolve. A company does not need to adopt government terminology or build an elaborate combined-assurance program to use it.
The map also does not transfer risk ownership to audit. Management still decides and acts. Assurance examines the basis for confidence. Keep that boundary visible, especially when a lean team supports both functions. The separate question of internal audit's role in ERM needs its own safeguards.
Replace the tick mark with a conclusion you can defend
Start with a handful of exposures that could materially disrupt the operating plan. For each, write a question specific enough to test.
“Cybersecurity” is a topic. “Can the acquired business restore its order-processing system within the interruption the business can tolerate?” is a question. “Revenue risk” is a topic. “Are discounts outside delegated authority being identified before contracts are signed?” gives a reviewer something concrete to examine.
Then ask the person listed as a source of assurance to provide the relevant report, test result, or review record. Do not begin by asking them to rate their own coverage as red, amber, or green. Ask what they did and what they concluded.
Before you count a risk as covered, ask what the evidence actually supports:
- 01 Scope: Does it answer the risk question?
- 02 Evidence: Was performance tested?
- 03 Timing: Is it still current?
- 04 Objectivity: Who checked whose work?
The performance question matters when you are claiming a control actually works. A design review can establish whether a proposed control is sensible without testing its operation. That is useful evidence for a design decision. It is not the same conclusion as “the control operated throughout the period.”
Timing is more than the report date. Work completed recently may examine an old system or exclude a newly acquired operation. Record the period and business perimeter tested. An older review of an unchanged, stable process may be more relevant than a new report on the wrong scope.
Objectivity needs similar care. An operating manager's review can be valuable without being independent assurance. Label it accurately. A checklist signed by the person who performed the work should not silently become “independently verified” when it reaches the board.
The IIA's implementation guidance for Standard 9.5 also addresses provider competence, objectivity, independence, work quality, and the evidence supporting reliance. These four executive questions are a starting point, not a substitute for that fuller evaluation.
What to record in the working map
Keep the executive view short, but retain enough detail behind it for someone else to follow the conclusion. The following fields are a practical starting point, not a prescribed template.
| Field | What it should establish |
|---|---|
| Risk question and owner | The business outcome at risk, the question to answer, and the management owner. |
| Source and role | Who performed the work and whether it was an operating review, specialist oversight, or independent assurance. |
| Scope and period | The locations, systems, transactions, and dates included, with material exclusions. |
| Evidence and conclusion | What was examined, what the results support, and a link or reference to the underlying record. |
| Remaining question | What is not established, whether it matters for the next decision, and why. |
| Next action | The required test, monitoring, or explicit coverage decision, with a named owner and due date. |
Do not force a single “covered” status over conflicting evidence. If management's monitoring shows a control working but an independent test identifies failures, show the disagreement and the follow-up. Averaging those results into amber hides the information the committee needs.
Turn a gap into a choice, not another spreadsheet
Return to the illustrative supplier scenario. The map has done its job when it changes the next action.
A weak action would be “add supply chain to next year's audit plan.” That may be appropriate eventually, but it does not answer the delivery question before the next production commitment.
A more useful action is specific: the operations owner obtains evidence of alternate-source capacity and qualification requirements, tests the delivery assumption where practical, and brings the remaining uncertainty to the decision-maker before committing to the plan. Internal audit determines whether its own work is needed and how much reliance it can place on the evidence.
The conclusion may be uncomfortable: there is no qualified backup within the required window. That is not a failed assurance exercise. It is a useful finding. Management can now evaluate inventory, production, customer commitments, or another response with the constraint visible.
Be equally precise when you find overlap. Two reviews are not duplicates merely because they sit beside the same risk. One may test how approvals are designed while another tests whether people followed them. Another may cover a different plant, period, or failure mode.
Only consider reducing work after comparing the questions, scope, methods, timing, and required level of independence. A busy process owner may reasonably want fewer requests, but fewer requests are not the objective if they leave an important question unanswered.
What the audit committee should see
The committee does not need a wall of ticks. It needs a concise account of where confidence is warranted and where a decision remains.
For each significant gap, state the business question, the evidence available, what that evidence does not establish, and the proposed next action. Put the management owner and decision date next to it. If resources are insufficient, show what will remain unexamined under the proposed plan.
Avoid presenting “not audited” as a synonym for “unmanaged.” A risk may have strong operating controls and relevant specialist monitoring without a recent internal audit. Equally, an audit may have been completed while significant problems remain unresolved. Coverage, control effectiveness, and residual risk are different judgments.
For the supplier example, the committee's message is simple: onboarding has been reviewed; alternate delivery capability has not been established; operations owns the evidence-gathering action; the open question affects the next production commitment. That is more useful than “three assurance providers, green.”
The existing board-ready risk reporting guide addresses how to present the broader risk picture. The map supplies one part of it: how much confidence the available evidence justifies.
When more mapping is not the answer
There is a point at which a map becomes an administrative project. If the team spends weeks reconciling hundreds of low-value controls before addressing an obvious gap in a major exposure, stop expanding it.
Use the smallest scope that can change the current decision. Add detail when it helps distinguish an important gap from a harmless difference in terminology.
A blank cell does not automatically justify an engagement. Management and the committee may reasonably prioritize another exposure, accept limited assurance for a period, or rely on proportionate operating monitoring. Record the choice and its rationale instead of turning every blank into an urgent audit.
Nor should an annual mapping exercise freeze the picture. Revisit relevant entries when systems change, acquisitions alter the perimeter, tests fail, or a decision depends on evidence that may no longer apply. The map is useful only while its conclusions remain usable.
Where to Start
Take one major risk from the next board pack. Ask the named reviewers which business question their work answered and what they did not examine. If the answers do not support the confidence shown in the report, correct the report before commissioning more work.
For a broader check of whether your risk reporting supports board decisions, start with KRG's Board-Ready Risk Reporting Scorecard.
Take the Board-Reporting Scorecard
Frequently Asked Questions
What is assurance mapping?
Assurance mapping connects business risks to the reviews and evidence that examine them. A useful map identifies the question tested, provider, scope, period, conclusion, and remaining uncertainty. It helps leaders decide where additional work is warranted.
How is an assurance map different from a risk register?
A risk register tracks exposures, owners, and responses. An assurance map shows what evidence supports confidence in those responses. The two should connect, but a risk owner and a completed review do not by themselves prove that the response works.
Does every risk need an internal audit?
No. The appropriate work depends on the exposure, existing evidence, available resources, and the need for independent assurance. Operating reviews and specialist monitoring may be useful. Any decision to leave an important question unexamined should be explicit rather than hidden by a coverage label.