practice

Assurance Map

A single view of which risks are covered by which assurance activity, exposing both the gaps nobody is looking at and the duplication several parties are paying for.

Assurance accumulates independently. Internal audit has a plan, security runs penetration tests, a certification body assesses annually, a regulator inspects, the platform team runs continuous compliance checks, and customers send questionnaires. Each was commissioned for a reason and none was designed against the others.

The map lays risks down one axis and assurance activities across the other. Two patterns emerge immediately. Duplication: the same control tested four times a year by four parties, each requiring evidence gathering from the same engineers. Gaps: risks with no coverage at all, which are usually the ones that fall between functions — third-party concentration, model behaviour, data lineage integrity.

The value is in what it enables. Duplicated coverage can be consolidated by reuse: one well-evidenced control test accepted by several parties, which is the largest available saving in assurance effort. Gaps get an owner and an activity.

It also exposes over-reliance on a single form of assurance — an organisation whose entire coverage of a critical risk is one annual audit has a twelve-month detection window for that risk, which is a statement worth making explicitly to a board.