IIA Three Lines Model Assurance Mapping Training Course
| Course code | SD-A-072 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Auditing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Boards, audit committees and executives need a defensible view of whether material risks are covered by reliable assurance—not simply a list of control owners, compliance reports and audit plans. In many organisations, first-line management, risk, compliance, quality, information security and internal audit perform overlapping reviews while significant risks receive little independent challenge. This course addresses the practical work of identifying assurance providers, testing the nature and reliability of their work, and presenting risk coverage gaps in a form that supports audit planning and governance decisions.
Participants apply the IIA Three Lines Model to distinguish management accountability, second-line expertise and monitoring, and internal audit’s independent assurance role. They build a risk-to-assurance universe, define assurance activities and reliance criteria, assess coverage, duplication and independence, and create an assurance map and heat map. The course also covers stakeholder interviews, evidence requests, assurance maturity scoring, reporting to the audit committee, and using mapping results to refresh a risk-based internal audit plan without taking ownership of management controls.
Delivery combines instructor-led technical sessions with a running corporate case involving operational, financial, regulatory and technology risks. Teams use structured worksheets to map assurance sources, challenge ambiguous line assignments, rate assurance quality and develop recommendations for rationalising activity or closing gaps. Each participant leaves with a completed assurance-mapping pack: a risk-and-assurance matrix, provider inventory, coverage assessment, reliance criteria, reporting dashboard and a 90-day implementation plan that can be adapted for their own organisation.
The programme is designed for experienced audit, risk and assurance professionals who need to coordinate assurance across functions while preserving clear accountabilities and internal audit independence.
Course objectives
By the end of this course, participants will be able to:
- Apply the IIA Three Lines Model to assign governance, management, second-line and internal audit assurance responsibilities
- Construct a risk-and-assurance universe linking material risks, controls, assurance providers and reporting recipients
- Inventory assurance activities using a structured provider questionnaire and evidence-request schedule
- Assess assurance quality using criteria for scope, competence, independence, methodology, evidence and reporting
- Create an assurance map and heat map showing coverage, duplication, gaps and over-reliance on self-assessment
- Evaluate when internal audit may place reliance on second-line testing without compromising independence
- Facilitate stakeholder interviews that clarify assurance mandates, escalation routes and control ownership
- Produce an audit-committee assurance report and 90-day action plan based on mapping findings
Benefits of attending
For you
- Gain a repeatable method for turning fragmented assurance activity into a board-ready coverage view
- Build credibility when challenging duplicate testing, weak self-assessment and unclear assurance mandates
- Strengthen risk-based audit planning by identifying risks requiring independent audit attention
- Develop practical criteria for assessing whether second-line assurance can be relied upon
- Leave with a reusable assurance-mapping pack for leading cross-functional workshops in your organisation
For your organisation
- Reduces blind spots by identifying material risks with insufficient or low-quality assurance coverage
- Limits duplicated reviews by revealing overlapping testing performed by audit, risk, compliance and specialist teams
- Improves audit committee reporting through traceable links between risk appetite, assurance sources and residual gaps
- Protects internal audit independence by clarifying advisory boundaries and management accountability under the Three Lines Model
- Supports more targeted audit-plan and assurance-resource decisions using documented coverage and reliance assessments
Target competencies
Who should attend
- Heads of Internal Audit — who need to align risk-based audit planning with the wider assurance landscape
- Internal Audit Managers — who coordinate audit coverage and evaluate reliance on other assurance functions
- Risk Managers — who need to connect enterprise risk reporting with credible assurance evidence
- Compliance Managers — who must demonstrate where compliance monitoring complements or duplicates other reviews
- Governance, Risk and Compliance Leaders — who design assurance coordination and reporting for senior management
- Audit Committee Secretaries — who prepare clear assurance coverage information for board and committee agendas
Requirements and prerequisites
Participants should have practical experience in internal audit, enterprise risk management, compliance, control testing or assurance reporting. They should understand risk registers, control objectives, audit planning, audit evidence and the distinction between management controls and independent assurance. Familiarity with the IIA Three Lines Model and a basic working knowledge of spreadsheets are helpful, but prior assurance-mapping experience is not required. Participants do not need audit software, data analytics expertise, statistical sampling knowledge or a formal internal audit qualification. The course assumes confidence discussing risks and controls with operational and second-line stakeholders.
Training methodology
The instructor uses short technical briefings to establish the IIA Three Lines Model, followed by guided construction of an assurance map from a multi-function corporate case. Participants work in teams with risk registers, assurance-provider profiles, testing samples and audit-committee reporting requirements. They conduct simulated interviews, score assurance reliability against defined criteria, debate reliance decisions and present findings to a mock audit committee. Daily exercises build one connected mapping pack; the final session converts that pack into an organisation-specific implementation plan with stakeholders, milestones and governance actions.
Course outline
Day 1: Positioning assurance under the IIA Three Lines Model
- Purpose and principles of the IIA Three Lines Model
- Governing body accountability and oversight expectations
- First-line management ownership of risk and control
- Second-line monitoring, expertise and challenge functions
- Internal audit independence, assurance and advisory boundaries
- Distinguishing assurance, monitoring, control operation and management reporting
- Defining the assurance-mapping objective and scope
Workshop: Participants analyse a corporate operating model and produce a draft Three Lines responsibility map for its key risk functions.
Day 2: Building the risk and assurance universe
- Translating enterprise risk registers into mapping populations
- Selecting material risks, risk themes and control domains
- Designing an assurance-provider inventory
- Classifying internal and external assurance sources
- Capturing assurance activity scope, frequency and reporting routes
- Stakeholder interview planning and evidence-request design
- Creating a risk-to-assurance matrix in Microsoft Excel
Workshop: Participants build a risk-to-assurance matrix and provider inventory for the case organisation using supplied risk and assurance data.
Day 3: Assessing assurance quality and reliance
- Criteria for assurance scope, competence and objectivity
- Evaluating methodology, testing depth and evidence quality
- Assessing independence from operational control ownership
- Reliance considerations for second-line monitoring
- Rating assurance maturity and reliability
- Documenting limitations, qualifications and residual uncertainty
- Applying Global Internal Audit Standards to assurance coordination
Workshop: Participants score three assurance providers against a reliance assessment template and produce documented reliance conclusions.
Day 4: Mapping coverage, gaps and duplication
- Coverage scoring across risk, control and assurance dimensions
- Creating assurance heat maps and gap analyses
- Identifying duplicated testing and inefficient assurance demand
- Recognising false assurance from self-assessment and narrow scope
- Analysing assurance coverage against COSO ERM risk categories
- Prioritising actions using impact, urgency and assurance reliability
- Facilitating cross-functional challenge sessions
Workshop: Participants create an assurance coverage heat map, identify priority gaps and duplication, and agree corrective actions in a facilitated workshop.
Day 5: Reporting and embedding assurance mapping
- Designing audit committee assurance dashboards
- Writing concise coverage, gap and reliance narratives
- Linking mapping outcomes to risk-based internal audit planning
- Escalating unresolved gaps and unclear accountabilities
- Establishing assurance coordination governance and review cycles
- Measuring implementation progress and map refresh triggers
- Developing a 90-day assurance-mapping implementation roadmap
Workshop: Participants present a board-style assurance report and complete a 90-day implementation roadmap for applying the method in their own organisation.
Tools & standards covered
IIA Three Lines Model, Global Internal Audit Standards, COSO Enterprise Risk Management Framework, Microsoft Excel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Auditing
Advanced Forensic Audit Investigation and Interviewing Training Course
Suspected fraud, financial misconduct, and control override require more than routine audit testing. Investigators must turn an allegation, …
ISACA ITAF Audit Framework Application Training Course
Technology audit teams are expected to produce work that is defensible to audit committees, regulators, external auditors and senior managem…
ACL Analytics Continuous Auditing Techniques Training Course
Continuous auditing fails when audit teams rely on periodic spreadsheet extracts, undocumented tests, and exception reports that cannot be r…
Manufacturing Inventory Audit Controls Training Course
Manufacturing inventory is vulnerable to errors and loss at every hand-off: goods receipt, put-away, production issue, scrap booking, subcon…