CORAA
Resources · Assurance Mapping

Three lines assurance map.

A three-lines assurance map helps the CAE, internal audit partner or Audit Committee see who owns each risk, who monitors it, what independent assurance exists and which high-risk areas are still uncovered. It is the bridge between governance theory and the annual internal audit plan.

Build annual planReview charter
Downloads

Assurance map workbook workbook

Download the Excel/PDF pack for risk ownership, first-line controls, second-line monitoring, third-line coverage, reliance tests, duplication, gaps and Audit Committee summary.

Roles

Who does what in the three lines does

Board / Audit Committee

Approves mandate, receives assurance, challenges unresolved risk and decides whether coverage is sufficient.

Senior management

Owns the risk-management system, allocates responsibility, funds controls and resolves cross-functional gaps.

First line

Owns and manages risk in day-to-day processes: operations, finance, HR, procurement, sales, IT and site teams.

Second line

Supports, monitors and challenges: risk, compliance, legal, information security, finance control, quality and HSE teams.

Third line

Internal audit gives independent assurance and advice after evaluating mandate, evidence, objectivity and coverage.

External assurance providers

Statutory auditors, certification bodies and specialists may provide assurance work, but reliance needs scope, evidence and objectivity evaluation.

External risk inputs

Regulatory findings, insurer surveys, customer audits and consultant reports can inform risk assessment, but should not be treated as assurance without evaluation.

Assurance map fields

What the map should capture capture

The map should be specific enough to affect the annual plan. A generic line saying "compliance reviews this" is not enough for reliance. Record the period, population, evidence and exception treatment.

Risk / process

Use audit-universe language: P2P, O2C, R2R, treasury, ITGC, AI governance, data privacy or third-party risk.

Risk owner

Name the accountable first-line executive or process owner, not only the department.

Second-line coverage

Record compliance, risk, legal, finance control, InfoSec, quality or HSE monitoring actually performed.

Internal audit coverage

Map completed reviews, planned reviews, monitoring rules, deferred areas and open scope limitations.

Reliance basis

Evaluate provider, competence, objectivity, scope, timing, testing depth, evidence retained, exceptions and limitation impact.

Coverage conclusion

Mark covered, partly covered, duplicated, uncovered or not relied upon, with the effect on the annual plan.

Reliance gates

Before internal audit relies on another team rely

Competence

Does the assurance provider have the skill, methodology and reviewer depth to cover the risk?

Objectivity

Is the provider sufficiently independent from the activity, target or control owner being assessed?

Scope alignment

Does their work cover the same risk, period, population, locations and systems internal audit cares about?

Evidence quality

Are source files, testing logic, sample basis, exception review and conclusion trail available for review?

Timing

Is the work recent enough to support current assurance, or does internal audit need refresh testing?

Exception follow-up

Were exceptions resolved, escalated, accepted as risk or left open without ownership?

Planning value

Gaps the assurance map should expose avoid

Second-line dashboard treated as assurance

Monitoring can support internal audit planning, but a dashboard alone is not independent assurance.

Duplicate testing across teams

Risk, compliance and internal audit all test the same controls while high-risk areas remain untouched.

No named risk owner

A committee owns the topic on paper, but no executive owns remediation, funding or escalation.

Reliance without workpaper access

Internal audit relies on compliance or consultant work without reviewing scope, testing and exceptions.

Annual plan ignores assurance map

The audit plan is built from last year plus requests, not from true coverage gaps.

Board pack hides assurance gaps

The Audit Committee sees green dashboards without knowing which risks were not independently covered.

Authority anchors

Sources to verify before issuing cite

IIA Three Lines Model Statement of Position

Use the IIA model to define board, management, first-line, second-line and third-line responsibilities before mapping assurance coverage.

IIA Global Internal Audit Standards

Anchor reliance and coordination to strategic planning, stakeholder communication, engagement work and board oversight expectations.

IIA Coordination and Reliance Guidance

Use IIA guidance on working with other assurance providers when deciding whether second-line or external work can reduce, reshape or only inform internal audit coverage.

ICAI SIA 220, 230, 310, 330, 350 and 370

Use ICAI SIAs for overall planning, objectives, assignment planning, internal control evaluation, review and supervision, and internal audit reporting.

Companies Act Section 138 and Rule 13

For Indian companies, connect the assurance map to the approved scope, functioning, periodicity and methodology of internal audit.

Product reuse

Website resource now, product workflow later later

The public resource can become specification input for the separate Internal Audit product build: assurance universe, reliance decisioning, duplicate coverage alerts, coverage-gap routing and Audit Committee reporting.

Assurance universe

Risk dashboard: Risk, process, owner, inherent rating, assurance providers, coverage conclusion.

Provider register

Governance setup: First-line owner, second-line monitor, third-line reviewer, external assurance input.

Reliance decision

Planning workflow: Competence, objectivity, scope, evidence, timing, exception follow-up, reliance decision.

Coverage gap log

Annual plan builder: Uncovered risk, duplicate testing, deferred coverage, scope limitation, next review date.

Committee summary

Board reporting: Top uncovered risks, duplicated effort, reliance caveats, required management decisions.

Related resources

Use the map in planning and reporting next

Internal Audit Charter & Mandate

Confirm reporting line, authority and evidence access before relying on other assurance work.

Internal Audit Annual Plan Generator

Convert uncovered risks and duplicated coverage into the next audit plan.

Internal Audit Dashboard KPIs

Use assurance-map outputs in committee dashboards and coverage metrics.

Internal Audit Annual Report & Assurance Opinion

Disclose coverage gaps and reliance caveats before giving annual assurance.

Internal Audit Maturity Assessment

Treat missing assurance maps and weak reliance criteria as maturity gaps.

Internal Audit Resource Capacity Planner

Use coverage gaps to justify internal capacity, specialist support or co-sourcing.

FAQs

Assurance map questions answered

What is a three-lines assurance map?

A three-lines assurance map shows who owns a risk, who monitors or challenges it, who provides independent internal audit assurance, what external assurance exists and where coverage gaps or duplication remain.

Can internal audit rely on second-line compliance or risk work?

Internal audit can use second-line work as an input only after evaluating competence, objectivity, scope, timing, evidence quality and exception follow-up. Second-line monitoring does not automatically become internal audit assurance.

Why should the Audit Committee see the assurance map?

The Audit Committee needs to see not only completed internal audits, but also major risks with no independent coverage, areas covered only by management monitoring, duplicated testing and reliance caveats affecting assurance.

How does an assurance map improve the annual audit plan?

It turns the audit universe into a coverage decision: keep high-risk gaps in scope, reduce duplicated work, plan reliance testing, add specialist reviews and explain deferred areas before the plan is approved.