KITE 2025 New Product Award — Local IT | SACEEC

What is Combined Assurance? The Three Lines Model Explained

Combined assurance coordinates everyone who provides assurance so the board gets one coherent picture, with less duplication and fewer gaps.

Free PDF GuideDownload this guide as a PDF

In most organisations, several different teams independently check that risks are being managed: line managers, the risk function, compliance, internal audit, and external auditors. Left uncoordinated, they trip over each other on some risks while ignoring others entirely, and the board receives a confusing patchwork of assurance. Combined assurance fixes this by coordinating all those assurance providers into a single, coherent view. This guide explains the model, how the players fit together, how to build a combined assurance map, and the King IV context that makes it a governance expectation in South Africa.

Watch: what combined assurance is and the three lines model Watch: Combined assurance explained (short overview)
i

What You'll Learn

By the end of this guide you will understand what combined assurance is, the three lines model that underpins it, how management, risk and compliance, and internal and external audit coordinate, how to build a combined assurance map and plan, the benefits of doing so, and how King IV frames combined assurance for South African organisations.

What Combined Assurance Is

Combined assurance is the coordination of all the assurance activities across an organisation so that, together, they give the board and management a complete and consistent picture of how well risks are being managed. The word "combined" is the key. The individual assurance providers already exist; combined assurance is about making them work as a coherent whole rather than in isolation.

The goal is captured in a simple idea. For every material risk in your risk register, the board should be able to ask "how do we know this risk is under control?" and receive a clear answer showing which assurance providers have looked at it, what they found, and where the gaps are. Combined assurance turns a scattered set of activities into that single answer.

i

Pro Tip

Combined assurance is a coordination discipline, not a new department. You are not creating another team that provides assurance; you are orchestrating the teams you already have so their coverage adds up to something the board can rely on.

The Three Lines Model

The most common way to organise assurance providers is the three lines model (historically called the three lines of defence). It groups everyone who contributes to risk management and assurance into three distinct roles, each with a different relationship to the risk.

Line Who Role
First line Operational management and staff Own and manage risk directly; run the day-to-day controls
Second line Risk, compliance, and similar functions Set frameworks, oversee, challenge, and support the first line
Third line Internal audit Provide independent, objective assurance over the first two lines

External auditors and regulators sit outside the three lines as additional, independent assurance providers. They are an important part of the combined picture but are not part of the internal structure, because their independence comes precisely from being external.

Why the lines must stay distinct

The model only works if the lines keep their separate roles. If internal audit helps design the controls it later audits, its independence is compromised. If the second line takes over running controls, nobody is left to challenge them. The value of the model is in the separation of duties, which is why combined assurance coordinates the lines without blurring them.

Want the full framework with worked examples?

How the Players Coordinate

Coordination is where combined assurance earns its keep. Each line contributes a different kind of assurance, and the trick is to align them around the same risks so coverage is complete without being wasteful.

First line: management's own assurance

Operational managers provide the most immediate assurance simply by running and monitoring their controls. Their self-assessments, control checks, and KRIs, the kind described in monitoring risks over time, are the foundation everything else builds on.

Second line: oversight and challenge

The risk and compliance functions set the frameworks, define the scoring scales, and independently challenge whether the first line's view is realistic. They aggregate risk across the organisation and are usually the natural owner of the combined assurance process itself.

Third line: independent audit

Internal audit provides objective assurance that the first and second lines are actually working as intended. A risk-based internal audit plan deliberately targets the highest risks, which is exactly where combined assurance wants audit effort concentrated.

External providers

External audit, regulatory inspections, and specialist assessments (such as certification audits) add independent assurance on specific areas. Mapping their coverage alongside the internal lines prevents both duplication and blind spots.

!

Important

Coordination does not mean assurance providers share conclusions or soften their findings to agree. Each must reach its own judgement independently. Combined assurance aligns what they look at and how findings are reported. It never compromises the independence that makes each line valuable.

Building a Combined Assurance Map

The central tool of combined assurance is the assurance map: a matrix that plots your material risks against your assurance providers, showing who covers what. It makes duplication and gaps visible at a glance.

Risk 1st Line (Mgmt) 2nd Line (Risk/Compliance) 3rd Line (Internal Audit) External
Cyber breach Control self-assessment Security policy oversight Annual IT audit Penetration test
Financial misstatement Reconciliations Finance compliance review Controls audit External audit
Regulatory breach Obligation tracking Compliance monitoring Compliance audit Regulator inspection
Supplier failure Vendor management Third-party risk review None this cycle None

Read down the columns and across the rows. The supplier failure row above immediately reveals a thinner layer of independent assurance than the others, a gap the board may want to close. A row where all four columns are full might signal over-assurance, where effort could be reallocated to a riskier area.

Steps to build the map

  1. Start from your material risks. List the significant risks from your risk register as the rows.
  2. List your assurance providers as the columns, grouped by line.
  3. Plot existing coverage. For each risk, record what each provider does and how often.
  4. Spot gaps and overlaps. Highlight risks with little independent assurance and those with redundant effort.
  5. Build a combined assurance plan. Reallocate and schedule activities so coverage matches risk, then have the board or audit committee approve it.
Example

Closing a gap the map revealed

A mid-sized insurer mapped its top fifteen risks. The map showed that data privacy risk had strong first and second line coverage but had never been independently audited, while a low-priority procurement risk was being checked by three separate providers. The audit committee reallocated effort: internal audit added a privacy audit to next year's plan and dropped two redundant procurement reviews. Same total assurance budget, far better coverage of what mattered.

The Benefits

When assurance providers coordinate around a shared map, the organisation gains on several fronts:

  • Less duplication: Multiple teams stop independently checking the same low-risk areas, freeing effort for higher-priority work.
  • Fewer gaps: Risks that fall between providers' remits become visible and get covered.
  • A coherent board view: Leadership receives one integrated picture rather than several disconnected reports, strengthening the board risk report.
  • Reduced audit fatigue: Business units are not subjected to wave after wave of overlapping reviews from different teams.
  • Better use of assurance budget: Effort is directed by risk, so scarce audit and compliance resources go where they matter most.
  • Stronger governance evidence: The map is concrete proof to regulators and stakeholders that assurance is deliberate and complete.

Combined Assurance and King IV

In South Africa, combined assurance is not just good practice. It is an explicit governance expectation. The King IV Report on Corporate Governance makes combined assurance one of its principles, recommending that the governing body ensure assurance services and functions are arranged so they enable an effective control environment and support the integrity of information used for decision-making and reporting.

King IV broadens the idea beyond the traditional three lines, encouraging organisations to think of all assurance providers, including external assurance and even the board's own oversight, as contributing to a single combined assurance model. In practice, King IV expects the audit committee to oversee the combined assurance arrangements and to satisfy itself that significant risks are adequately covered.

i

Pro Tip

If your organisation applies King IV, an up-to-date combined assurance map is among the most useful artefacts you can bring to the audit committee. It directly evidences the principle and turns an abstract governance requirement into a concrete, reviewable document.

Even outside South Africa, the principle travels well. Frameworks such as ISO 31000 and the broader practice of enterprise risk management assume that assurance over risk is coordinated rather than fragmented, making combined assurance a natural fit for any mature risk programme.

Common Mistakes to Avoid

1. Blurring the lines

Letting internal audit help build the controls it later audits, or letting the second line run first-line controls, destroys the independence the model depends on. Keep the roles distinct.

2. Treating combined assurance as a report, not a process

A one-off map produced for the audit committee and never updated adds little. Combined assurance is an ongoing coordination process, refreshed as risks and coverage change.

3. Mapping only internal audit

A map that ignores first-line self-assessment and external assurance overstates the gaps and understates real coverage. Include every provider across all lines.

4. Coordinating activities but not findings

If providers align what they review but never compare what they found, contradictions and themes go unnoticed. Bring findings together as well as plans.

5. Ignoring the gaps the map reveals

Building a map that exposes under-assured risks and then doing nothing wastes the exercise. The point of the map is to drive reallocation of assurance effort.

6. Pursuing total coverage

Trying to give every risk four layers of assurance burns resources. Match the depth of assurance to the level of the risk, accepting lighter coverage on minor risks.

Key Takeaways

Summary

  • Combined assurance coordinates all assurance providers so the board gets one coherent picture
  • The three lines model separates risk owners (first), oversight (second), and independent audit (third)
  • External audit and regulators add independent assurance from outside the three lines
  • An assurance map plots material risks against providers to reveal duplication and gaps at a glance
  • Benefits include less duplication, fewer gaps, a coherent board view, and better use of assurance budget
  • King IV makes combined assurance an explicit governance principle overseen by the audit committee

Frequently Asked Questions

What is the difference between combined assurance and the three lines model?

The three lines model is a way of organising assurance providers into roles: risk owners, oversight functions, and independent audit. Combined assurance is the broader discipline of coordinating all of those providers, plus external assurance, so their coverage adds up to a complete, consistent picture for the board. The three lines model is one of the building blocks of combined assurance.

What are the three lines of defence?

The first line is operational management, who own and manage risk through day-to-day controls. The second line is risk, compliance, and similar functions that set frameworks and provide oversight and challenge. The third line is internal audit, which provides independent, objective assurance that the first two lines are working. The model is increasingly called simply the "three lines model".

What is a combined assurance map?

A combined assurance map is a matrix that plots your material risks against your assurance providers, recording who provides what assurance over each risk. It makes duplication and gaps immediately visible, which lets you reallocate assurance effort so coverage matches the importance of each risk. It is the central working tool of combined assurance.

Who owns the combined assurance process?

The second line, usually the risk or compliance function, typically coordinates the combined assurance process, because it already aggregates risk across the organisation. Oversight of the arrangements, however, rests with the audit committee on behalf of the board, which is responsible for satisfying itself that significant risks are adequately covered.

Does combined assurance reduce the cost of assurance?

It usually improves the value you get for a given budget rather than slashing cost outright. By cutting duplication on low-risk areas and redirecting that effort to under-assured high risks, you get better coverage of what matters without necessarily spending more. It also reduces audit fatigue in the business by avoiding overlapping reviews.

Is combined assurance required by King IV?

King IV is an apply-and-explain code rather than hard law, but combined assurance is one of its principles. Organisations applying King IV are expected to arrange their assurance providers into a combined assurance model and to have the audit committee oversee it. In practice, a maintained combined assurance map is strong evidence of applying the principle.

Save this guide for later

Download the PDF version to read offline or share with your team.

Co-Founder & ERM Practitioner

An enterprise risk management practitioner with experience across healthcare, public sector, and regulated environments. Phumi focuses on translating ERM frameworks into practical, decision-relevant processes.

Co-Founder & ERM Practitioner

Specialises in enterprise risk management through risk assessments, data analysis, and mitigation planning. Contributes to compliance oversight, risk reporting, and monitoring of key risk indicators.