Governance · Enterprise risk · Component

Assurance map

For each principal risk, who manages it, who oversees it and who checks it independently — and when each last did so.

The deliverable

What it is

The Three Lines Model separates those who own and manage a risk, those who set policy and monitor it, and those who give independent assurance to the governing body. An assurance map applies that separation risk by risk, showing where assurance is strong, where it is thin, and where several parties check the same thing.

The testing itself happens elsewhere. Compliance monitoring tests regulatory controls, internal or external audit tests others; the map records what they concluded and when, so the board can judge how much weight each part of the register can bear.

One level in

What it is made of

Each element is a constituent part of the component. Follow one to see the attributes it carries.

  1. Lines per risk

    Who provides first-, second- and third-line coverage for each principal risk, named as roles.

    4 attributes: Risk · First line · Second line · Third line

    Learn
  2. Assurance record

    When each line last reviewed the risk, what it concluded, and how much reliance the board can place on the conclusion.

    3 attributes: Last assured · Reliance · Evidence

    Learn
  3. Gaps and overlaps

    Principal risks that nobody checks independently, and places where several parties check the same thing twice.

    3 attributes: Finding · Priority · Resolved by

    Learn

A principal risk with no independent check is one the board is taking on trust. That may be acceptable, but it should be a decision.