Governance · Enterprise risk · Component
Assurance map
For each principal risk, who manages it, who oversees it and who checks it independently — and when each last did so.
The deliverable
What it is
The Three Lines Model separates those who own and manage a risk, those who set policy and monitor it, and those who give independent assurance to the governing body. An assurance map applies that separation risk by risk, showing where assurance is strong, where it is thin, and where several parties check the same thing.
The testing itself happens elsewhere. Compliance monitoring tests regulatory controls, internal or external audit tests others; the map records what they concluded and when, so the board can judge how much weight each part of the register can bear.
One level in
What it is made of
Each element is a constituent part of the component. Follow one to see the attributes it carries.
Lines per risk
Who provides first-, second- and third-line coverage for each principal risk, named as roles.
4 attributes: Risk · First line · Second line · Third line
LearnAssurance record
When each line last reviewed the risk, what it concluded, and how much reliance the board can place on the conclusion.
3 attributes: Last assured · Reliance · Evidence
LearnGaps and overlaps
Principal risks that nobody checks independently, and places where several parties check the same thing twice.
3 attributes: Finding · Priority · Resolved by
Learn
A principal risk with no independent check is one the board is taking on trust. That may be acceptable, but it should be a decision.
The other components in enterprise risk
Risk appetite statement
How much risk the organisation is prepared to carry in each category, with the tolerances that trigger escalation to the board.
LearnEnterprise risk register
The principal risks across the whole organisation, drawn from every function, assessed on one scale and each with a named owner.
Learn