# XGRC® Integrated Assurance

_Internal Audit & Combined Assurance_

**One audit plan. Four lines of defence. Zero gaps.**

Coordinate internal audit and combined assurance across your organisation, linked directly to risks, controls, and corrective actions, so every line of defence operates from the same picture of what needs assurance.

## What it is

Integrated assurance software helps organisations coordinate assurance activities, internal audits, control testing, findings and corrective actions across multiple lines of defence.

## Overview

XGRC® Integrated Assurance manages the complete internal audit lifecycle, from risk-based planning and fieldwork through findings management, corrective actions, and board reporting, with a combined assurance matrix that maps every assurance provider to the risks they cover.

## When organisations use it

Organisations typically adopt Integrated Assurance when internal audit findings are raised but never closed against the risk register, combined assurance maps live in outdated slide decks, and nobody has a consolidated view of assurance coverage. Integrated Assurance links assurance activities directly to risks, controls, actions and compliance evidence within XGRC® Software.

## What it is not

Integrated Assurance is not a standalone audit-management tool disconnected from risk. It maintains a live combined assurance matrix mapping every assurance provider to the risks they cover, so coverage gaps and duplication are visible, not discovered at the board meeting.

## Challenges it addresses

- **Audit findings that do not close risks** — Internal audit operates independently from the risk register. Findings are raised, management responds, risks stay open.
- **Combined assurance maps in PowerPoint** — Outdated the moment they are presented. Nobody knows who is providing assurance over which risks until the board asks.
- **Coverage gaps and duplication** — High-risk areas receive no audit attention. Low-risk areas audited three times by different lines. Nobody has a consolidated view.
- **Reactive audit planning** — Annual plans built from intuition and last year's plan, not from the current risk landscape. Emerging risks go unaudited.

## Modules

- **Planning:** Risk-Based Audit Planning, Annual Audit Schedule, Resource & Capacity Planning, Scope Definition
- **Fieldwork:** Audit Programme Management, Evidence Capture, Interview & Testing Records, Working Papers
- **Findings & Actions:** Finding Ratings & Classification, Management Response Tracking, Corrective Action Plans, Follow-up & Closure
- **Combined Assurance:** Four Lines of Defence Map, Combined Assurance Matrix, Assurance Coverage Analytics, Board & Audit Committee Reporting

## Standards & frameworks

- IIA Standards
- ISO 19011
- King V
- PFMA

## Frequently asked questions

### Which standards does Integrated Assurance align to?

Integrated Assurance is aligned to IIA Standards, ISO 19011, King V and the PFMA for public sector organisations.

### Does Integrated Assurance replace our internal audit team?

No. It gives your internal audit function risk-based planning, fieldwork and findings-tracking tools, the audit team still does the work, with better data and less manual reconciliation.

### What is a combined assurance matrix?

It's a live map of every assurance provider, internal audit, risk, compliance, external audit, against the risks they cover, so coverage gaps and duplication are visible in real time, not just at year-end.

### Can Integrated Assurance connect to our risk register?

Yes. Findings, corrective actions and audit coverage all link directly to the same risk register used in XGRC® ERM.

## Related solutions

- [Enterprise Risk Management](https://xgrcsoftware.com/erm)
- [MSX®](https://xgrcsoftware.com/msx)
- [MSXCyber®](https://xgrcsoftware.com/msxcyber)

---

Source: https://xgrcsoftware.com/integrated-assurance
