Board / Executive Advisory

The Assurance Gap: What Does the Board Think Is Covered — and What Is Actually Covered?

Multiple assurance providers do not guarantee that material risks are covered. How Boards and Internal Audit can close the gap between perceived and actual assurance.

Board / Executive Advisory7 min readPublished 29 September 2026By DisInnova Editorial Team
DisInnova conceptual illustration of the assurance gap: complete layers of Board expectations above fragmented layers of actual assurance coverage, separated by a visible gap.

Executive summary

Multiple assurance providers do not guarantee that material risks are covered. How Boards and Internal Audit can close the gap between perceived and actual assurance.

The Board receives a lot of assurance — but is it complete?

Most Boards do not suffer from a shortage of assurance. In a typical quarter, the Audit Committee will receive reports from Internal Audit, Risk, Compliance, the external auditor, the information security function and, increasingly, specialist providers covering areas such as data protection, operational resilience or model risk. Each report is prepared with care. Each speaks with authority about its own domain.

The difficulty is that these reports are rarely designed to be read together. They use different risk taxonomies, different rating scales and different reporting cycles. They answer the question each function was asked, not necessarily the question the Board needs answered: are the organisation's most significant risks adequately and independently assured?

This is where the assurance gap emerges. It is the distance between what the Board believes is covered and what is actually covered. It is rarely the product of negligence. More often, it is the natural consequence of assurance activity that has grown function by function, rather than being designed around the organisation's risk profile as a whole.

Where assurance gaps come from

Assurance gaps tend to form at the boundaries — between functions, between lines of defence and between the organisation's historical risk profile and its current one.

Fragmented reporting creates confidence without visibility

When several functions report on overlapping subjects, the Board can reasonably infer that the area is well covered. Yet each provider may be looking at a narrow slice: Compliance at regulatory obligations, Risk at the risk appetite framework, Internal Audit at a specific process in a specific year. The volume of reporting creates a sense of coverage. The absence of an integrated view means no one is positioned to confirm it.

Quantity is not the same as quality

Assurance quantity is measured in reports, reviews and findings. Assurance quality depends on independence, scope, depth of testing, competence of the provider and the currency of the work. A second-line monitoring review and an independent Internal Audit engagement may carry the same subject heading, but they provide very different levels of comfort. A clean management attestation is not equivalent to independently tested evidence. Where these distinctions are not made explicit, the Board may be counting assurance rather than weighing it.

Emerging risks fall between traditional mandates

The most material gaps tend to appear in areas that do not sit neatly within a single function's mandate. Artificial intelligence, cyber risk, third-party and supply-chain dependency, data governance and large transformation programmes all cut across technology, operations, legal, risk and the business. Each function may assume another is providing oversight. Specialist expertise may be thinly spread. The result is that some of the organisation's fastest-moving risks can receive the least coherent assurance.

Plans reflect history rather than the current risk profile

Assurance plans are frequently built incrementally from prior years' coverage. That approach offers continuity, but it can anchor effort to risks that were significant three years ago rather than those that are significant now. A rotation cycle that faithfully revisits established processes may leave a newly launched product, a recent acquisition or a material outsourcing arrangement without meaningful independent review.

Duplication does not equal coverage

One of the less intuitive features of the assurance gap is that it often coexists with duplication. The same well-understood controls — financial reporting, access management, core regulatory processes — may be reviewed by three or four providers in a single year. Management teams experience assurance fatigue. Boards receive repetitive messages about stable areas.

Meanwhile, capacity that could have been directed at genuinely under-assured risks is consumed by overlap. Duplication, in other words, is not simply inefficient. It can actively contribute to gaps by absorbing the time, budget and expertise that the organisation needs elsewhere.

Recognising this changes the conversation. The objective is not more assurance. It is better-allocated assurance: less repetition in areas of stable, well-evidenced control and more depth where risk is high, changing or poorly understood.

What the Board should be asking

The Audit Committee is not expected to perform assurance itself. It is, however, responsible for satisfying itself that the arrangements in place are adequate. That requires an understanding of who provides assurance over each material risk, what kind of assurance it is and how recent it is.

A small number of disciplined questions can surface a great deal:

  • For each principal risk, which function provides assurance, and is that assurance independent of management?
  • When was each material risk last subject to independent testing, and what was its scope?
  • Where do multiple providers review the same area, and is that overlap deliberate?
  • Which emerging risks — AI, cyber, third parties, data, transformation — have no clearly accountable assurance provider?
  • How does the current assurance plan reflect changes in strategy, products and operating model over the past year?

Behind all of these sits one Board-level question that deserves to be asked explicitly and regularly:

"What material risks do we believe are independently assured, and what evidence supports that belief?"

Where that question cannot be answered clearly, the Board has found its assurance gap. Structured Board advisory support can help directors frame these questions and interpret the answers with appropriate challenge.

Internal Audit's role in closing the visibility gap

Internal Audit is well positioned to help, precisely because of its independence and its organisation-wide remit. It sees across functions in a way that individual assurance providers often cannot.

Providing an integrated view without taking ownership

Internal Audit can map assurance activity across the organisation against the principal risk register, showing where coverage is strong, where it is duplicated and where it is weak or absent. This is an advisory and coordinating contribution, consistent with professional standards. It must be delivered without Internal Audit assuming management's responsibility for designing risk frameworks or operating second-line activities. Management continues to own risk; Internal Audit provides clarity about how well that ownership is being assured.

Distinguishing reliance from assumption

Where Internal Audit intends to rely on the work of other providers, it should assess the competence, objectivity and scope of that work. Formal reliance is valuable; informal assumption is not. Making that distinction visible to the Audit Committee is itself a meaningful improvement in assurance quality.

Directing independent effort to the weakest areas

Once overlaps and blind spots are visible, Internal Audit can rebalance its own plan toward areas where independent assurance is limited, and recommend where other providers might adjust their focus. This is a central theme of Internal Audit transformation: moving from a plan inherited from previous cycles to one explicitly aligned with the organisation's current risk profile.

From fragmented assurance to an integrated assurance view

Organisations that address the assurance gap effectively tend to share several characteristics. They maintain a common risk language across assurance providers. They produce a consolidated assurance map that the Audit Committee reviews at least annually. They classify assurance by type and independence rather than treating all coverage as equivalent. And they revisit the map whenever strategy, products or the operating model change materially.

None of this requires a large new framework. It requires coordination, a willingness to be candid about where coverage is thin and an Internal Audit function with the standing and capability to lead the conversation. For many organisations, building that capability is part of a broader transformation of the Internal Audit operating model.

The benefit is not simply fewer surprises. An integrated assurance view allows the Board to make better judgements about risk appetite, investment in control and the allocation of scarce assurance resources.

Final perspective

The presence of many assurance providers is reassuring. It is not, on its own, evidence that the organisation's most important risks are covered. Boards that recognise the difference — between perceived and actual coverage, between assurance quantity and assurance quality — are better placed to direct their oversight where it matters.

Internal Audit has a distinctive contribution to make: not by owning risk, and not by producing more reports, but by giving the Board a clear, independent and current view of where assurance is strong and where it is not. The question for every Audit Committee is whether it currently has that view.

Next step. If your Board or Audit Committee would like a clearer picture of assurance coverage, explore our Internal Audit Transformation and Board Advisory services, or speak with us about an independent perspective.

Key takeaways

  • Volume of assurance reporting is not evidence of complete coverage of material risks.
  • Assurance quality depends on independence, scope, depth and currency, not on the number of reports.
  • Duplication in well-controlled areas can coexist with, and contribute to, material assurance gaps.
  • AI, cyber, third-party, data and transformation risks often fall between traditional assurance mandates.
  • Audit Committees should regularly ask which material risks are independently assured, and what evidence supports that belief.
  • Internal Audit can map overlaps and blind spots and align coverage to the current risk profile without owning risk.

Written by

DisInnova Editorial Team

DisInnova's insights are prepared by a senior practitioner-led advisory firm with credentials across internal audit, IT audit, governance, risk management, controls, fraud examination, strategy, corporate governance and financial services, including CIA, CISA, CFE, CRMA, CRISC and related professional certifications.

This article is general advisory information and does not constitute legal, regulatory, audit, tax, investment or professional assurance advice.

Explore DisInnova advisory services for governance, risk and transformation.

Need support with governance, risk, internal audit or AI transformation?

Our advisory services help Boards, Audit Committees and Executive Management strengthen governance, improve Internal Audit, manage risk and deliver responsible digital transformation.

Explore Our Services