No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Featured

Audit’s Increasingly Critical Role in GRC

by Malcolm Murray
October 13, 2017
in Featured, Risk
woman working with binder and calculator in foreground

The Need for Aligned Assurance

Today’s changing risk landscape has put increased pressure on assurance functions to simplify their requirements and to provide the board, senior management and other key stakeholders with a complete risk and assurance picture. To do so requires coordinating on the risk universe, risk terminology and ratings. Malcolm Murray and Rafael Go discuss how, in light of this mandate to the board and companywide remit, internal audit is best placed to kick-start and champion these aligned assurance efforts.

with co-author Rafael Go

In recent years, both the size and scope of the risk landscape has changed dramatically. These changes are driven by the reality that organizations are becoming larger, more complex and more geographically dispersed. Add that to the number of third parties (now including fourth and fifth parties) rapidly proliferating and the increase in digitization efforts that are requiring more robust protection from cyberattacks and data breaches. And, along with all of this, companies are under increased competitive pressure from more digitized competitors.

Despite an increased focus on these new challenges, assurance functions are faced with stagnant resources, having to provide more comprehensive assurance with less. Most organizations’ assurance functions tend to work independently, which adversely affects operations and strategy by lengthening decision-making, slowing down corporate clock speed and increasing the procedural burden. According to research from CEB, now Gartner, 43 percent of compliance executives report that internal partners sometimes avoid the compliance process and 77 percent of business leaders have indicated becoming more risk averse. This leads to a 48 percent reduction in potential top-line growth from foregone corporate opportunities and new projects.

Having separate groups report independently to the board and senior management also means they get an incomplete or, at worst, contradictory picture of the risk landscape. In order to provide comprehensive risk guidance to the business, assurance functions must increase their efforts at aligning their work.

Enter Aligned Assurance

Aligned assurance brings about formalized collaboration and coordination between assurance functions to share risk information, assign risk coverage and synchronize assessment and reporting efforts. In doing so, assurance functions can provide the organization with a clear view of the current risk environment, offer better assurance, minimize redundancies and identify and mitigate new risks. Providing a unified voice to the board also allows assurance functions to increase executive accountability.

In order to successfully implement aligned assurance, participants need to take the following steps:

  • Identify and align the needs of assurance partners. Fostering discussion and open communication among all relevant assurance functions is crucial to the success of aligned assurance. This can be done in the form of an aligned assurance project groups or steering committees. To be effective, these discussions need to have input from all participants to address their concerns and generate buy-in. The group also needs to assess the organization’s current control environment and the strengths and weaknesses of each function in order to find optimal areas for collaboration and allocate resources effectively.
  • Jointly establish a framework. Bringing together team members from different assurance functions yields diverse insights that are central to the success of the project. To ensure productive communication and coordination, stakeholders must build formal structures into the process, including a common risk language and/or register and an assurance map.
  • Execute aligned assurance activities. Synchronizing activities among assurance providers combines their expertise and resources and eases the compliance burden on the business. Successful organizations coordinate their assessments and audits to happen simultaneously or they conduct them together. In doing this, stakeholders gain a broader view of the risk and control environment and it becomes easier to provide a clear and unified view of the organization’s risks to senior management and the board.
  • Review and assess the aligned assurance model. Constant maintenance and regular check-ups ensure the longevity of machines. The same principle applies to the aligned assurance model. Continually discussing the program with stakeholders can highlight inefficiencies that can be addressed, thereby improving the process. Furthermore, by actively engaging with the business and increasing awareness of aligned assurance, the model becomes embedded in the company culture, enabling more effective cooperation among stakeholders in the future.

What Audit Should Know About Aligned Assurance

In a recent CEB, now Gartner, survey of 130+ audit departments globally, 76 percent cite aligning assurance efforts as an important or critically important priority for 2018. However, only 41 percent currently have an aligned assurance model. The remaining 59 percent of audit departments must take the lead in this area, as audit is the best-suited function to initiate or push it forward.

As the only function with a direct mandate to the board, audit is the most equipped to lead cross-functional efforts on aligning assurance. Further, with its companywide remit and unparalleled knowledge of the entire control environment, audit is best placed to spot gaps and redundancies in assurance efforts. Audit also stands to gain significantly from these efforts, as a successful aligned assurance model can lead to audit not having to do full-scale audits in areas covered by the second line.

Conclusion

Given today’s frenetic pace of change and new threats in the risk landscape, it is imperative that assurance functions increase their collaboration to keep organizations on top of these complex risks. Aligned assurance provides assurance functions a valuable framework to guide their efforts at coordination in order to manage their resources more effectively and provide more comprehensive assurance to the business, and audit should take the lead at making it a reality.

Previous Post

Infographic: Data Protection and Privacy Regulations

Next Post

Identification of “Red Flags” for Possible Violations of Key U.S. Laws for Companies Operating Overseas

Malcolm Murray

Malcolm Murray

Malcolm Murray is Research VP and Fellow at Gartner. He works with heads of Audit at Fortune 500 companies to better leverage data analytics, automation and other assurance functions to drive actionable change within their organizations. A Chartered Financial Analyst, originally from Stockholm, Sweden, Malcolm holds an M.Sc. in Business and Economics from the Stockholm School of Economics, an MBA from INSEAD and a Master of International Management from HEC in Paris.

Related Posts

GRC News Roundup Cover

GRC News Roundup: Agiloft, Redgate Software MIND, LinkSquares & More

by Corporate Compliance Insights
July 30, 2026

GRC technology is one of the fastest-growing segments in enterprise software, and compliance professions are rapidly evolving. Here’s the latest...

news roundup_062124

Activist Investors Significantly Increase M&A Sale Pushes

by Staff and Wire Reports
July 30, 2026

Massive data security confidence comes with high data security concerns.

us doj building with flag

Once You’ve Decided to Self-Disclose, Here’s How to Do It Right

by Sean M. Farrell and Thomas F. Rybarczyk
July 29, 2026

Deciding to self-disclose is one thing; doing it well is another, and the difference often shapes whether a company earns...

normandy invasion monument

What a D-Day Weather Forecast Teaches About Decision-Making Under Pressure

by Jim DeLoach
July 28, 2026

Two forecasters, two methods and a go or no-go call with thousands of lives at stake, the D-Day story holds...

Next Post
Red flags in a row

Identification of "Red Flags" for Possible Violations of Key U.S. Laws for Companies Operating Overseas

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights