Eight-person rowing team moves in sync across calm water

How coordinated assurance strengthens risk oversight

As assurance activity matures, a coordinated assurance approach strengthens reliance and risk oversight across the enterprise.


In brief
  • Coordinated assurance helps organizations align assurance activities, reduce duplication and improve visibility into risk coverage.
  • Through risk-based reliance, internal audit can leverage assurance performed by other functions while maintaining independence.
  • Organizations adopting coordinated assurance approaches gain clearer risk insight, greater efficiency and a stronger basis for decision-making.

More assurance isn’t always reassuring. In an increasingly nonlinear, accelerated, volatile and interconnected (NAVI) world where risks overlap and intertwine, many organizations have scaled their assurance efforts to keep pace. Yet this increase in activity does not always create decision clarity, and counterintuitively, may introduce risks of its own.

Compliance, controls and internal audit functions often lack consistent coordination, shared ways of working and a common understanding of risk across the enterprise — so as activity increases, so too can fragmentation and duplication. Organizations may spend more time, effort and money on assurance activity without gaining visibility into risk coverage. Left with conflicting inputs and no synchronized picture of risk, leadership may hesitate to act or defer decision-making altogether.

 

This challenge becomes more pressing as external risk conditions intensify. As geopolitical conflict, tariff and trade volatility, and profound technological change drive demand for cyber, regulatory and operational assurance, leadership may consider how better coordination and alignment of these activities, rather than simply increasing their volume, can create value in risk-informed oversight. By bringing fragmented assurance activity into closer alignment, leadership can see risk exposure more clearly across the enterprise, align resources to strategic imperatives, preserve independence across the lines of defense, and use technology-enabled monitoring and risk sensing to make faster, risk-informed decisions in response to today’s challenges.

The problem: fragmentation, duplication and exhaustion

Executives understand that the lines of defense are intentionally separated to maintain independence. However, this separation can introduce fragmentation as functions naturally develop their own processes, reporting-line structures, governance forums and planning cycles. Especially in large or heavily regulated organizations, bringing these efforts together is not always a primary focus, making alignment more difficult to achieve.

Given the nature of assurance work, some degree of duplication can be expected, particularly across the second and third lines of defense. For instance, financial control frameworks are often tested by the second line and tested again by internal audit or another provider, creating duplication and increasing the control burden on the organization. It’s also common for internal audit to test core transactional and operational controls, such as those in HR, including payroll. These same controls may also be reviewed by second-line compliance teams or other assurance providers.

Without a coordinated assurance approach, organizations may experience:

  • Fragmented or inconsistent assessments of risk severity and control effectiveness
  • Piecemeal reports to various panels — to audit committees or management committees, for example — that do not represent an organizational view of risk
  • Business fatigue and saturation, where stakeholders experience repeated requests and overlapping reviews, reducing engagement and effectiveness
  • Gaps where no function has full accountability for coverage
  • Duplication of effort across assurance providers

In other words, assurance activity is robust, yet clarity regarding risk coverage (and, just as importantly, risk exposure) is not. The organization may have more information but trust itself less to make key decisions.

Understanding the importance of this trust, the organization may find it is easier to secure buy-in for a coordinated assurance approach than to implement the practical frameworks needed to achieve it.

The shift: introducing a coordinated and reliant assurance approach

Both coordination and reliance are fundamental elements of assurance quality. According to Standard 9.5 from the Institute of Internal Auditors, “The chief audit executive must coordinate with internal and external providers of assurance services and consider relying upon their work. Coordination of services minimizes duplication of efforts, highlights gaps in coverage of key risks, and enhances the overall value added by providers.”1

Coordinated assurance — also referred to as combined assurance or integrated assurance — introduces a structured approach for collaboration across all providers, including first-line management, second-line functions and internal audit. The objective is to align assurance efforts so that risks are covered effectively with independence and objectivity, not duplication. A key component of this coordination is reliance, where one assurance provider considers the work of other providers as part of the overall approach.

 

Reliance is not a static concept: it factors in the risk level and the quality of assurance that other functions provide. This concept is most effective in areas where assurance activities are mature and aligned with the organization’s risk profile, and where internal audit, or another provider, has previously validated its effectiveness. Conversely, for higher-risk areas or where escalation is required, internal audit may consider whether a greater level of independent assurance is required.

Reliance is also most impactful when the organization can set a defensible basis for when test evidence is strong enough to be reused by other providers. Internal audit should play a central role in defining this basis, weighing the source of the evidence, the competence of the preparer, its recency, how it was sampled and when re-performance is required.

Once that standard is agreed, a control tested once could be relied upon across internal audit, SOX, compliance and the first and second lines, rather than checked again by each. In addition to reducing duplication, a shared standard supports an enterprise-wide view of risk. Technology-enabled monitoring and risk sensing draw on that view, giving leadership the time and information to respond to risk more quickly and decisively.

To follow the above example of financial controls, internal audit can draw upon the work of other functions to better focus on principal and strategic risks where independent assurance can add objective-aligned value and strengthen decision-making. The third line gives assurance on the second line’s approach and methodology, and resulting findings strengthen future assurance activities.

Overall principles of coordinated assurance include:

  • Delivering aligned assurance plans and activities
  • Sharing methodologies, findings and risk insights
  • Ensuring consistent coverage and messaging of key risks
  • Providing a basis for coordinated reporting

This does not remove accountability for each function to maintain an independent view of risk management and effectiveness. Rather, it provides a structured basis for determining when other assurance activities are sufficient and delivering the consistency needed for a comprehensive, trusted view of risk. More broadly, this approach supports leaders in making decisions, rather than merely describing risk after the fact.

The foundations of effective coordinated assurance

Practical, actionable first steps include establishing a common risk taxonomy, mapping existing assurance activity across the second and third lines, and identifying exactly where reliance can reduce duplication without weakening independent oversight.

Backed by strong sponsorship, six foundational conditions enable assurance providers to work together consistently. Without these principles, different functions will continue to interpret risk differently, assurance outputs cannot be accurately compared, and reliance decisions become inconsistent and difficult to defend.


Scaling it: risk-based reliance and the path to better outcomes

As noted, reliance is calibrated based on the level of risk and confidence in other assurance providers, determined by factors such as:

  • Alignment and understanding of risk taxonomy
  • Skill and competence of assurance providers
  • Strength and evidence of outcomes
  • Scope and depth of coverage
  • Track record and consistency
  • Use of consistent methodologies

An effective coordinated assurance model refines how assurance providers communicate on an ongoing basis, as they adapt to evolving ways of working, collaboration protocols and reliance mechanisms. Further, coordination should not seek to merely standardize every assurance activity, but rather reduce duplication through a pragmatic, balanced approach. Different providers bring different perspectives and responsibilities, and that independent judgment should be preserved where it adds value.

When structured correctly, coordinated assurance and reliance expand risk coverage and efficiency. But perhaps just as importantly, leaders strengthen confidence in their decisions and actions. The result is not just better coverage, but faster, more confident action — fewer pauses for clarification, fewer redundant reviews, and greater capacity to scale automation and AI into core operations. A NAVI world demands it.

Thank you to the following contributors, who assisted in the development of this content: Courtney Adler, Principal, Technology Risk, Ernst & Young LLP; Helen L. Bateman, Senior Manager, Risk Consulting, Ernst & Young LLP; and Ben Parsons, Manager, Risk Consulting, Ernst & Young LLP.


Summary 

As assurance activity expands across organizations, fragmented reviews and overlapping testing can reduce confidence rather than strengthen it. Coordinated assurance helps organizations align assurance activities, establish a common view of risk and reduce duplication. Through coordinated assurance practices and risk-based reliance, internal audit can leverage the work of other functions while focusing independent assurance where it adds the greatest value.

About this article

Authors

Contributors

Related articles

How will AI redefine resilience for risks not yet imagined?

AI’s speed, scale and insight drives resilient growth in today’s complex risk environment. Learn more.

Ten plays to strengthen your internal audit function

Enhance your internal audit effectiveness with 10 innovative strategies focused on leveraging technology and improving risk management practices.

Five steps internal audit can take to unlock strategic value

The risk landscape is changing. Here are five steps internal audit can take to unlock value and improve risk strategy.