One audit plan, four lines of defence, one picture for the board.
XGRC® coordinates internal audit and combined assurance across your organisation, linking every finding to the risk it relates to and the controls meant to manage it. Every line of defence works from the same assurance map.
Disconnected assurance activity leaves real coverage gaps.
When internal audit, risk, and compliance each work from their own plan, nobody has a consolidated view of what is actually being assured — or what is not being assured at all.
Audit plans built from intuition rather than the current risk register
Combined assurance maps kept in PowerPoint and outdated within weeks
High-risk areas go unaudited while low-risk areas are checked repeatedly
Audit findings raised without a clear link back to risk or forward to closure
A structured, risk-based assurance process.
Define the four lines of defence and assign assurance providers
Build the annual audit plan from the current risk register
Execute fieldwork using structured programmes and evidence capture
Rate findings and obtain documented management responses
Map assurance coverage against the full risk universe
Report combined assurance status to the audit committee and board
Built for audit teams. Visible to the board.
- Risk-based audit planning linked to the live risk register
- Structured fieldwork, evidence capture, and working papers
- Findings classification and management response tracking
- A combined assurance matrix mapping every risk to its assurance providers
- Real-time dashboards and board-ready reporting
One assurance map, always current
XGRC® maintains a live combined assurance matrix that shows exactly which risks are covered, by which line of defence, and where the gaps or duplication sit. Audit findings link directly to risks, controls, and corrective actions.
The same assurance activity, without the coverage gaps.
Integrated Assurance Checklist
- Assurance framework and governance
- Risk-based audit planning
- Combined assurance mapping
- Fieldwork and evidence
- Findings and management response
- Coverage analytics and reporting
Assure against the frameworks that matter.
- King V
- Combined Assurance
- IIA Standards
- ISO 19011
- COSO
- ISO 31000
- Three Lines Model
One platform across every line of defence.
- Internal audit
- Risk management assurance
- Compliance assurance
- External and regulatory assurance
Explore the connected platform.
Integrated Assurance
Internal Audit & Combined Assurance
Explore Integrated Assurance → Use CaseInternal Audit
XGRC® is internal audit software that lets organisations plan, execute and manage audits in a structured, consistent way. It connects audits to risks, controls and actions on a single platform, giving full visibility across the audit lifecycle.
View use case → Use CaseInternal Controls
XGRC® is internal controls software that lets organisations design, implement, test, and assure controls in a structured way. Every control is linked to the risk it mitigates and the assurance provider testing it, so control effectiveness is demonstrable at any time.
View use case → Use CaseRisk Management
XGRC® is risk management software that lets organisations identify, assess and manage risks in a structured, consistent way. It connects risks to controls, actions and assurance activities on a single platform, giving clear visibility of risk exposure across the organisation.
View use case →Common questions.
What is integrated assurance software?
Integrated assurance software coordinates internal audit and combined assurance across every line of defence, linking each finding back to the risk it relates to so the board sees one consolidated assurance picture instead of separate reports from separate functions.
Does XGRC® build the audit plan from the actual risk register?
Yes. The annual audit plan is built from the current risk register, so audit effort is directed at the highest-risk areas rather than repeating the same checks a spreadsheet-based plan defaults to.
How current is the combined assurance matrix?
The combined assurance matrix is live, not a static document, so coverage gaps and duplication across lines of defence are visible continuously rather than discovered when someone next updates a slide deck.
Which standards does integrated assurance align to?
Integrated assurance aligns to King V, IIA Standards, ISO 19011, COSO and ISO 31000, reflecting the lines of defence model most assurance functions report against.
See combined assurance as one coordinated process, not four.
Book a demo to see how XGRC® connects audit planning, fieldwork, findings, and combined assurance reporting on one platform.
Book a demoWhere should we send your download link?
Enter your details and we will email you the link to the checklist.
Your checklist is ready.
Click the button below to download the PDF. We have also sent this link to your email.
Download the checklist (PDF)