A three-lines assurance map helps the CAE, internal audit partner or Audit Committee see who owns each risk, who monitors it, what independent assurance exists and which high-risk areas are still uncovered. It is the bridge between governance theory and the annual internal audit plan.
Download the Excel/PDF pack for risk ownership, first-line controls, second-line monitoring, third-line coverage, reliance tests, duplication, gaps and Audit Committee summary.
Approves mandate, receives assurance, challenges unresolved risk and decides whether coverage is sufficient.
Owns the risk-management system, allocates responsibility, funds controls and resolves cross-functional gaps.
Owns and manages risk in day-to-day processes: operations, finance, HR, procurement, sales, IT and site teams.
Supports, monitors and challenges: risk, compliance, legal, information security, finance control, quality and HSE teams.
Internal audit gives independent assurance and advice after evaluating mandate, evidence, objectivity and coverage.
Statutory auditors, certification bodies and specialists may provide assurance work, but reliance needs scope, evidence and objectivity evaluation.
Regulatory findings, insurer surveys, customer audits and consultant reports can inform risk assessment, but should not be treated as assurance without evaluation.
The map should be specific enough to affect the annual plan. A generic line saying "compliance reviews this" is not enough for reliance. Record the period, population, evidence and exception treatment.
Use audit-universe language: P2P, O2C, R2R, treasury, ITGC, AI governance, data privacy or third-party risk.
Name the accountable first-line executive or process owner, not only the department.
Record compliance, risk, legal, finance control, InfoSec, quality or HSE monitoring actually performed.
Map completed reviews, planned reviews, monitoring rules, deferred areas and open scope limitations.
Evaluate provider, competence, objectivity, scope, timing, testing depth, evidence retained, exceptions and limitation impact.
Mark covered, partly covered, duplicated, uncovered or not relied upon, with the effect on the annual plan.
Does the assurance provider have the skill, methodology and reviewer depth to cover the risk?
Is the provider sufficiently independent from the activity, target or control owner being assessed?
Does their work cover the same risk, period, population, locations and systems internal audit cares about?
Are source files, testing logic, sample basis, exception review and conclusion trail available for review?
Is the work recent enough to support current assurance, or does internal audit need refresh testing?
Were exceptions resolved, escalated, accepted as risk or left open without ownership?
Monitoring can support internal audit planning, but a dashboard alone is not independent assurance.
Risk, compliance and internal audit all test the same controls while high-risk areas remain untouched.
A committee owns the topic on paper, but no executive owns remediation, funding or escalation.
Internal audit relies on compliance or consultant work without reviewing scope, testing and exceptions.
The audit plan is built from last year plus requests, not from true coverage gaps.
The Audit Committee sees green dashboards without knowing which risks were not independently covered.
The public resource can become specification input for the separate Internal Audit product build: assurance universe, reliance decisioning, duplicate coverage alerts, coverage-gap routing and Audit Committee reporting.
Risk dashboard: Risk, process, owner, inherent rating, assurance providers, coverage conclusion.
Governance setup: First-line owner, second-line monitor, third-line reviewer, external assurance input.
Planning workflow: Competence, objectivity, scope, evidence, timing, exception follow-up, reliance decision.
Annual plan builder: Uncovered risk, duplicate testing, deferred coverage, scope limitation, next review date.
Board reporting: Top uncovered risks, duplicated effort, reliance caveats, required management decisions.
A three-lines assurance map shows who owns a risk, who monitors or challenges it, who provides independent internal audit assurance, what external assurance exists and where coverage gaps or duplication remain.
Internal audit can use second-line work as an input only after evaluating competence, objectivity, scope, timing, evidence quality and exception follow-up. Second-line monitoring does not automatically become internal audit assurance.
The Audit Committee needs to see not only completed internal audits, but also major risks with no independent coverage, areas covered only by management monitoring, duplicated testing and reliance caveats affecting assurance.
It turns the audit universe into a coverage decision: keep high-risk gaps in scope, reduce duplicated work, plan reliance testing, add specialist reviews and explain deferred areas before the plan is approved.