# One audit plan, four lines of defence, one picture for the board.

XGRC® coordinates internal audit and combined assurance across your organisation, linking every finding to the risk it relates to and the controls meant to manage it. Every line of defence works from the same assurance map.

**Frameworks:** King V, Combined Assurance, IIA Standards, ISO 19011, COSO, ISO 31000, Three Lines Model

## Disconnected assurance activity leaves real coverage gaps.

When internal audit, risk, and compliance each work from their own plan, nobody has a consolidated view of what is actually being assured — or what is not being assured at all.

- Audit plans built from intuition rather than the current risk register
- Combined assurance maps kept in PowerPoint and outdated within weeks
- High-risk areas go unaudited while low-risk areas are checked repeatedly
- Audit findings raised without a clear link back to risk or forward to closure

## A structured, risk-based assurance process.

- Define the four lines of defence and assign assurance providers
- Build the annual audit plan from the current risk register
- Execute fieldwork using structured programmes and evidence capture
- Rate findings and obtain documented management responses
- Map assurance coverage against the full risk universe
- Report combined assurance status to the audit committee and board

## How it works

- Risk-based audit planning linked to the live risk register
- Structured fieldwork, evidence capture, and working papers
- Findings classification and management response tracking
- A combined assurance matrix mapping every risk to its assurance providers
- Real-time dashboards and board-ready reporting

## On the platform

**One assurance map, always current** — XGRC® maintains a live combined assurance matrix that shows exactly which risks are covered, by which line of defence, and where the gaps or duplication sit. Audit findings link directly to risks, controls, and corrective actions.

## The same assurance activity, without the coverage gaps.

| Manual approach | With XGRC® |
| --- | --- |
| Audit plans disconnected from the risk register | Risk-based audit planning |
| Assurance maps in static PowerPoint decks | A live, auditable combined assurance matrix |
| Coverage gaps and duplication go unnoticed | Coverage gaps and duplication surfaced automatically |
| Manual, periodic board reporting | Real-time dashboards and board reporting |

## One platform across every line of defence.

- Internal audit
- Risk management assurance
- Compliance assurance
- External and regulatory assurance

## Frequently asked questions

### What is integrated assurance software?

Integrated assurance software coordinates internal audit and combined assurance across every line of defence, linking each finding back to the risk it relates to so the board sees one consolidated assurance picture instead of separate reports from separate functions.

### Does XGRC® build the audit plan from the actual risk register?

Yes. The annual audit plan is built from the current risk register, so audit effort is directed at the highest-risk areas rather than repeating the same checks a spreadsheet-based plan defaults to.

### How current is the combined assurance matrix?

The combined assurance matrix is live, not a static document, so coverage gaps and duplication across lines of defence are visible continuously rather than discovered when someone next updates a slide deck.

### Which standards does integrated assurance align to?

Integrated assurance aligns to King V, IIA Standards, ISO 19011, COSO and ISO 31000, reflecting the lines of defence model most assurance functions report against.

## Related solution

- [Integrated Assurance](https://xgrcsoftware.com/integrated-assurance)

---

Source: https://xgrcsoftware.com/use-cases/integrated-assurance
