Integrated Assurance

One audit plan. Four lines of defence. Zero gaps.

Coordinate internal audit and combined assurance across your organisation, linked directly to risks, controls, and corrective actions, so every line of defence operates from the same picture of what needs assurance.

Download: Brochure (PDF)

IIA StandardsISO 19011King VPFMA
v5.xgrc.cloud · Integrated Assurance
Integrated Assurance dashboard

What is Integrated Assurance?

Integrated assurance software helps organisations coordinate assurance activities, internal audits, control testing, findings and corrective actions across multiple lines of defence.

Organisations typically adopt Integrated Assurance when internal audit findings are raised but never closed against the risk register, combined assurance maps live in outdated slide decks, and nobody has a consolidated view of assurance coverage. Integrated Assurance links assurance activities directly to risks, controls, actions and compliance evidence within XGRC® Software.

The challenge

What breaks without Integrated Assurance.

Audit findings that do not close risks

Internal audit operates independently from the risk register. Findings are raised, management responds, risks stay open.

Combined assurance maps in PowerPoint

Outdated the moment they are presented. Nobody knows who is providing assurance over which risks until the board asks.

Coverage gaps and duplication

High-risk areas receive no audit attention. Low-risk areas audited three times by different lines. Nobody has a consolidated view.

Reactive audit planning

Annual plans built from intuition and last year's plan, not from the current risk landscape. Emerging risks go unaudited.

What it does

How Integrated Assurance works.

XGRC® Integrated Assurance manages the complete internal audit lifecycle, from risk-based planning and fieldwork through findings management, corrective actions, and board reporting, with a combined assurance matrix that maps every assurance provider to the risks they cover.

See it in action →
4 Lines of defence
Risk-based Audit planning
Live Assurance matrix
What's included

Everything in Integrated Assurance.

Core capabilities are configured to your requirements, with the flexibility to expand as your needs grow.

Planning

Risk-Based Audit PlanningAnnual Audit ScheduleResource & Capacity PlanningScope Definition

Fieldwork

Audit Programme ManagementEvidence CaptureInterview & Testing RecordsWorking Papers

Findings & Actions

Finding Ratings & ClassificationManagement Response TrackingCorrective Action PlansFollow-up & Closure

Combined Assurance

Four Lines of Defence MapCombined Assurance MatrixAssurance Coverage AnalyticsBoard & Audit Committee Reporting
Set the record straight

What Integrated Assurance is not.

Integrated Assurance is not a standalone audit-management tool disconnected from risk. It maintains a live combined assurance matrix mapping every assurance provider to the risks they cover, so coverage gaps and duplication are visible, not discovered at the board meeting.

Frequently asked

Common questions.

Which standards does Integrated Assurance align to?

Integrated Assurance is aligned to IIA Standards, ISO 19011, King V and the PFMA for public sector organisations.

Does Integrated Assurance replace our internal audit team?

No. It gives your internal audit function risk-based planning, fieldwork and findings-tracking tools, the audit team still does the work, with better data and less manual reconciliation.

What is a combined assurance matrix?

It's a live map of every assurance provider, internal audit, risk, compliance, external audit, against the risks they cover, so coverage gaps and duplication are visible in real time, not just at year-end.

Can Integrated Assurance connect to our risk register?

Yes. Findings, corrective actions and audit coverage all link directly to the same risk register used in XGRC® ERM.

ISO 27001:2022 Platform certified by BSI
IIA Standards · ISO 19011 · King V · PFMA Aligned frameworks
Audit-ready Every record traceable
Internal Audit & Combined Assurance

See Integrated Assurance running in your environment.

Talk to an XGRC® specialist about how Integrated Assurance fits your organisation's specific compliance and governance requirements.

[email protected] · +27 (0)87 802 0179