Use Case · Integrated Assurance

One audit plan, four lines of defence, one picture for the board.

XGRC® coordinates internal audit and combined assurance across your organisation, linking every finding to the risk it relates to and the controls meant to manage it. Every line of defence works from the same assurance map.

Book a demo
The problem

Disconnected assurance activity leaves real coverage gaps.

When internal audit, risk, and compliance each work from their own plan, nobody has a consolidated view of what is actually being assured — or what is not being assured at all.

Audit plans built from intuition rather than the current risk register

Combined assurance maps kept in PowerPoint and outdated within weeks

High-risk areas go unaudited while low-risk areas are checked repeatedly

Audit findings raised without a clear link back to risk or forward to closure

The XGRC® approach

A structured, risk-based assurance process.

01

Define the four lines of defence and assign assurance providers

02

Build the annual audit plan from the current risk register

03

Execute fieldwork using structured programmes and evidence capture

04

Rate findings and obtain documented management responses

05

Map assurance coverage against the full risk universe

06

Report combined assurance status to the audit committee and board

How it works

Built for audit teams. Visible to the board.

  • Risk-based audit planning linked to the live risk register
  • Structured fieldwork, evidence capture, and working papers
  • Findings classification and management response tracking
  • A combined assurance matrix mapping every risk to its assurance providers
  • Real-time dashboards and board-ready reporting

One assurance map, always current

XGRC® maintains a live combined assurance matrix that shows exactly which risks are covered, by which line of defence, and where the gaps or duplication sit. Audit findings link directly to risks, controls, and corrective actions.

From manual to XGRC®

The same assurance activity, without the coverage gaps.

Manual approach
  • Audit plans disconnected from the risk register
  • Assurance maps in static PowerPoint decks
  • Coverage gaps and duplication go unnoticed
  • Manual, periodic board reporting
XGRC® approach
  • Risk-based audit planning
  • A live, auditable combined assurance matrix
  • Coverage gaps and duplication surfaced automatically
  • Real-time dashboards and board reporting
Free resource

Integrated Assurance Checklist

  • Assurance framework and governance
  • Risk-based audit planning
  • Combined assurance mapping
  • Fieldwork and evidence
  • Findings and management response
  • Coverage analytics and reporting
PDF · Combined assurance aligned · v1.0
Standards and frameworks

Assure against the frameworks that matter.

  • King V
  • Combined Assurance
  • IIA Standards
  • ISO 19011
  • COSO
  • ISO 31000
  • Three Lines Model
Scope of application

One platform across every line of defence.

  • Internal audit
  • Risk management assurance
  • Compliance assurance
  • External and regulatory assurance
Frequently asked

Common questions.

What is integrated assurance software?

Integrated assurance software coordinates internal audit and combined assurance across every line of defence, linking each finding back to the risk it relates to so the board sees one consolidated assurance picture instead of separate reports from separate functions.

Does XGRC® build the audit plan from the actual risk register?

Yes. The annual audit plan is built from the current risk register, so audit effort is directed at the highest-risk areas rather than repeating the same checks a spreadsheet-based plan defaults to.

How current is the combined assurance matrix?

The combined assurance matrix is live, not a static document, so coverage gaps and duplication across lines of defence are visible continuously rather than discovered when someone next updates a slide deck.

Which standards does integrated assurance align to?

Integrated assurance aligns to King V, IIA Standards, ISO 19011, COSO and ISO 31000, reflecting the lines of defence model most assurance functions report against.

See combined assurance as one coordinated process, not four.

Book a demo to see how XGRC® connects audit planning, fieldwork, findings, and combined assurance reporting on one platform.

Book a demo