An assurance map records who examines which controls, how, and how often. Its value is that it exposes two problems simultaneously: areas being tested by four different parties, and areas nobody has looked at in three years. Most organisations have both and can see neither.
Why duplication happens
Nobody designs it. It accumulates:
- An ISO 27001 auditor tests access management.
- A SOC 2 auditor tests access management.
- Internal audit tests access management.
- A major customer's security review tests access management.
- A regulator asks about access management.
Each is reasonable in isolation. Together they consume the same team five times for substantially the same evidence - while, say, physical security at your secondary site has never been examined by anyone.
The result is audit fatigue in the wrong places. Control owners come to see assurance as harassment, which degrades cooperation precisely where testing is most valuable.
What goes on the map
A simple grid: your controls or risk areas down one axis, assurance providers across the other. For each intersection record:
- Who provides the assurance - external auditor, internal audit, second line, an automated check, a customer assessment.
- What they examine - full test, sample, documentation review, self-assessment.
- When - frequency and last performed.
- Strength - independent testing outranks self-assessment, which outranks a policy read.
See coverage across every framework at once
GRC Copilot maps your controls across all the frameworks you report against and shows which are evidenced, which are over-tested, and which nobody covers.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
What the map reveals
- Over-assured areas. Access control, change management and backups typically appear in every column. Once visible, you can reuse evidence across engagements rather than regenerating it.
- Assurance gaps. Physical security, HR security, supplier oversight and disaster recovery are commonly examined by nobody - each usually because everyone assumed someone else covered it.
- Weak assurance dressed as strong. An area "covered" only by annual self-assessment is not assured in any meaningful sense.
- Timing clashes. Three engagements landing in the same six weeks, entirely avoidably.
Acting on it
- Reuse evidence across engagements. The same access review export serves ISO, SOC 2 and a customer review - if it is stored once and mapped to all three.
- Redirect internal audit away from areas external auditors already cover thoroughly, toward the gaps. This is the single biggest efficiency gain available to a small internal audit function.
- Rely on external work where legitimate. Internal audit can often rely on external testing rather than repeating it - subject to independence and quality judgement.
- Sequence engagements so they do not collide.
- Offer a completed pack to customer assessors instead of answering the same questions bespoke each time.
Combined assurance
The mature version is combined assurance: the lines of defence coordinate their activity so coverage is deliberate and the board receives one integrated view rather than several partial ones. In practice this means internal audit, second line and external auditors agree annually who covers what.
The board-level benefit is significant. Instead of three reports that each cover part of the estate with unclear overlap, leadership sees a single coverage picture with genuine gaps identified.
Starting small
You do not need a formal programme. A single spreadsheet with your top twenty control areas and every assurance source from the last two years typically reveals the pattern within an hour - and the gaps it surfaces usually justify the exercise immediately.
Frequently asked questions
Can internal audit rely on external audit work?
Often yes, with judgement about scope, timing, independence and quality. Documenting that reliance decision is what makes it defensible rather than a gap.
Does this reduce audit cost?
It reduces internal effort substantially through evidence reuse and better sequencing. External fees are driven by scope, so savings there depend on scope decisions rather than mapping.
Who owns the assurance map?
Usually the second line - risk or compliance - with input from internal audit. In smaller organisations, whoever coordinates audits.
How often should it be updated?
Annually as part of audit planning, and whenever a new framework or major customer assessment enters the picture.
Key takeaways
- Duplication accumulates without anyone designing it.
- The map exposes over-tested areas and unexamined ones at the same time.
- Redirecting internal audit toward gaps is the biggest single gain.
- A spreadsheet and an hour is enough to start.