No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Internal Audit

6 Aligned Assurance Strategies for Audit Departments

Audit executives struggle to coordinate assurance work across organizations

by Thomas Teravainen and James Bourke
February 26, 2024
in Internal Audit
six pairs of eyeglasses lined up

Often, when multiple assurance functions exist across organizations, their audits may seem fragmented or even contradictory. Thomas Teravainen and James Bourke of Gartner’s audit research team share methods for aligning assurance strategies.

In response to growing organizational complexity and a rapidly changing risk landscape, there has been a rapid growth in assurance, with the number of distinct assurance functions (e.g., risk, privacy, information security and quality) nearly doubling in most organizations. Each function often uses different rationales and language in providing assurance, and yet they often interview the same managers and report to the same executive committees and the board.

Having multiple, uncoordinated assurance teams can lead to multiple views of the truth for the board and senior management, duplication and gaps in assurance coverage, and assurance fatigue. An uncoordinated approach also heightens the risk of noncompliance, and it can make leadership unnecessarily risk-averse and delay decision-making. As a result, many organizations are looking to implement aligned assurance initiatives.

But in doing so, they often experience ownership and coordination challenges and struggle to lay the necessary foundation for these initiatives to be successful. Chief audit executives (CAEs), too, are feeling the pressure of these challenges. According to Gartner research, only 37% of CAEs are confident in their ability to reduce corrections and repetitions of other assurance functions’ work and only 46% are confident in their ability to better align their reporting to the audit committee with other assurance functions.

Given the scale and difficulty of achieving fully aligned assurance, CAEs often struggle to know where to start. Moreover, attempting to build a comprehensive aligned assurance program can be a lengthy process that can be easily eclipsed by urgent priorities. To make progress, CAEs should identify targeted opportunities for aligned assurance in specific areas or projects and build from there, instead of attempting to achieve top-to-bottom alignment.

1. Conduct assurance mapping to improve cross-functional visibility

Identifying opportunities where assurance functions can coordinate their work starts with CAEs understanding what activities are performed by each assurance provider and when. To identify these opportunities and obtain a comprehensive view of the risk landscape, leading organizations leverage assurance maps to share their plans and identify potential assurance partners for key risks and assurance activities.

Sharing information on ongoing and planned assurance activities using one shared map for all assurance functions will help reduce the procedural burden on management and prevent assurance fatigue. This shared information allows audit to adjust risk assessment models and determine the depth of coverage and level of assurance needed for each risk depending on changes in organizational and business priorities.

Assurance maps also help identify areas of residual risk left over after accounting for all assurance activities and the maturity levels of assurance in different functional and risk areas. Having this information available helps streamline the process of updating the map for future activities and determine the depth of coverage required. Assurance mapping does not need to encompass all risks to the organization to be useful, so it is best to make a start on it rather than be put off by the difficulty of achieving a perfect map.

2. Streamline communication by creating a common risk language, risk-rating scales and metrics

To effectively integrate risk management processes and arrive at a consistent view of risk, assurance functions need to develop a common risk language and risk-rating scales. Assurance functions that use their own unique risk language, risk-rating scales and methodologies create confusion around key risks, risk tolerance, mitigation performance and actions required. This can complicate assurance findings and decision-making.

Unfortunately, Gartner found that less than half of audit committee members (46%) report their risk and assurance functions use the same scales when presenting on risks. Establishing a common risk language is key to facilitating meaningful coordination.

3. Collaborate on risk assessment and audit planning

Standard risk assessments involve audit or another assurance function conducting activities (such as surveys, interviews and workshops) to evaluate organizational risks and determine the priorities for plan coverage. When conducted alone, risk assessments are more likely to contain gaps and inaccuracies and/or fail to account for the work of other assurance functions in determining the level of residual risk.

Coordinating risk assessments remains a priority for CAEs, and joint risk assessments allow them to prioritize coverage based on a holistic view of the impact of all assurance functions’ work in mitigating risks.

businesswoman looking at stack of documents for audit
Compliance

Annual Survey: Companies Spending More Time on SOX Compliance

by Staff and Wire Reports
September 15, 2023

Nearly three in four organizations are looking for ways to further enable automation of their SOX compliance processes, according to Protiviti’s 14th annual SOX compliance survey, which also found that 58% said they spent more time on SOX compliance in the past year.

Read moreDetails

4. Solicit input from other assurance functions on engagement scoping

A key efficiency gain from aligned assurance work is the ability to adapt the scope of audit engagements to account for the level of risk coverage and mitigation provided by other assurance functions. By doing so, audit can better “right size” the scope of its engagements and target key risks to meet the organization’s needs. Coordinating engagement scoping with other assurance functions also allows audit to ensure engagements have been updated for any changes in risk early enough in the audit engagement process. Audit can collaborate with other assurance functions in scoping audit engagements by incorporating specific risk information that would not be available if they were acting alone.

5. Deepen assurance coverage by performing joint audits

Joint auditing enables multiple assurance teams to pool resources when planning and conducting joint site visits and interviews. Joint audits decrease the likelihood of duplications in work that may occur when multiple assurance functions review and report on similar risks or controls and increase visibility into potential assurance gaps.

In joint audit scenarios, CAEs can effectively coordinate responsibilities across all assurance functions, which reduces the likelihood of the assurance fatigue that occurs when multiple assurance functions interview business partners separately. Joint audits also provide access to other assurance functions’ specialized knowledge, enhancing the depth of assurance.

6. Provide holistic view of risk across the organization by delivering joint reports

Like joint audits, collaboration between assurance functions through joint reporting helps prevent multiple assurance functions from providing different views on the same risks to the audit committee and board. Assurance functions typically work independently of each other and report separately to the board on the state of the risk and control environment. This can provide the board with information that is both incomplete and in different formats, limiting the board’s ability to make effective decisions.

In fact, 20% of audit committee members agree that getting different information from multiple assurance functions is confusing and about half of them want to see more thematic views of risk across the organization. With coordinated risk reporting, assurance providers provide the board with an integrated, comprehensive view of all risks, enabling better decision making.

CAEs do not need to approach these six activities sequentially but should instead view them as a menu of options and choose the ones that fit best for their organization’s capabilities and context.


Previous Post

4 Audit Angles to Prepare Your HR Team for Rise in EEOC Cases

Next Post

Black Leadership in the Wake of Supreme Court Ruling

Thomas Teravainen and James Bourke

Thomas Teravainen and James Bourke

Thomas Teravainen is a research specialist on Gartner’s audit research team.
James Bourke is a senior principal on Gartner’s audit research team. Before that, he held several roles at Washington International School.

Related Posts

money

CCO Salary Increases Cooling Off

by Staff and Wire Reports
June 6, 2025

35% of executives give boards high marks

overwhelming stacks of documents

Why Contract Management Is No Longer Legal’s Problem

by Matt Lhoumeau
June 6, 2025

As companies eliminate dedicated legal departments, contract ownership is shifting to teams that view agreements as business processes, not just...

surrealist businessmen on platforms doing tug of war

Regulation vs. Innovation: The Tug-of-War Defining Finance’s Future

by Alex Tsepaev
June 6, 2025

AI compliance creates a global patchwork where EU fines reach €35 million while the US encourages growth — leaving financial...

Smarsh AI Copilot Launch

Smarsh Unveils AI Platform Enhancements

by Corporate Compliance Insights
June 5, 2025

Smarsh has announced platform updates including AI-powered compliance tools and expanded API capabilities designed to integrate with existing legal and...

Next Post
us supreme court building

Black Leadership in the Wake of Supreme Court Ruling

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights