IIA Three Lines Model Assurance Mapping Training Course

5 days Auditing Certificate on completion
Course codeSD-A-072
Duration5 days
LevelIntermediate to Advanced
CategoryAuditing
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Boards, audit committees and executives need a defensible view of whether material risks are covered by reliable assurance—not simply a list of control owners, compliance reports and audit plans. In many organisations, first-line management, risk, compliance, quality, information security and internal audit perform overlapping reviews while significant risks receive little independent challenge. This course addresses the practical work of identifying assurance providers, testing the nature and reliability of their work, and presenting risk coverage gaps in a form that supports audit planning and governance decisions.

Participants apply the IIA Three Lines Model to distinguish management accountability, second-line expertise and monitoring, and internal audit’s independent assurance role. They build a risk-to-assurance universe, define assurance activities and reliance criteria, assess coverage, duplication and independence, and create an assurance map and heat map. The course also covers stakeholder interviews, evidence requests, assurance maturity scoring, reporting to the audit committee, and using mapping results to refresh a risk-based internal audit plan without taking ownership of management controls.

Delivery combines instructor-led technical sessions with a running corporate case involving operational, financial, regulatory and technology risks. Teams use structured worksheets to map assurance sources, challenge ambiguous line assignments, rate assurance quality and develop recommendations for rationalising activity or closing gaps. Each participant leaves with a completed assurance-mapping pack: a risk-and-assurance matrix, provider inventory, coverage assessment, reliance criteria, reporting dashboard and a 90-day implementation plan that can be adapted for their own organisation.

The programme is designed for experienced audit, risk and assurance professionals who need to coordinate assurance across functions while preserving clear accountabilities and internal audit independence.

Course objectives

By the end of this course, participants will be able to:

  • Apply the IIA Three Lines Model to assign governance, management, second-line and internal audit assurance responsibilities
  • Construct a risk-and-assurance universe linking material risks, controls, assurance providers and reporting recipients
  • Inventory assurance activities using a structured provider questionnaire and evidence-request schedule
  • Assess assurance quality using criteria for scope, competence, independence, methodology, evidence and reporting
  • Create an assurance map and heat map showing coverage, duplication, gaps and over-reliance on self-assessment
  • Evaluate when internal audit may place reliance on second-line testing without compromising independence
  • Facilitate stakeholder interviews that clarify assurance mandates, escalation routes and control ownership
  • Produce an audit-committee assurance report and 90-day action plan based on mapping findings

Benefits of attending

For you

  • Gain a repeatable method for turning fragmented assurance activity into a board-ready coverage view
  • Build credibility when challenging duplicate testing, weak self-assessment and unclear assurance mandates
  • Strengthen risk-based audit planning by identifying risks requiring independent audit attention
  • Develop practical criteria for assessing whether second-line assurance can be relied upon
  • Leave with a reusable assurance-mapping pack for leading cross-functional workshops in your organisation

For your organisation

  • Reduces blind spots by identifying material risks with insufficient or low-quality assurance coverage
  • Limits duplicated reviews by revealing overlapping testing performed by audit, risk, compliance and specialist teams
  • Improves audit committee reporting through traceable links between risk appetite, assurance sources and residual gaps
  • Protects internal audit independence by clarifying advisory boundaries and management accountability under the Three Lines Model
  • Supports more targeted audit-plan and assurance-resource decisions using documented coverage and reliance assessments

Target competencies

Assurance mappingThree Lines applicationRisk coverage analysisReliance assessmentAssurance reportingStakeholder facilitation

Who should attend

  • Heads of Internal Audit — who need to align risk-based audit planning with the wider assurance landscape
  • Internal Audit Managers — who coordinate audit coverage and evaluate reliance on other assurance functions
  • Risk Managers — who need to connect enterprise risk reporting with credible assurance evidence
  • Compliance Managers — who must demonstrate where compliance monitoring complements or duplicates other reviews
  • Governance, Risk and Compliance Leaders — who design assurance coordination and reporting for senior management
  • Audit Committee Secretaries — who prepare clear assurance coverage information for board and committee agendas

Requirements and prerequisites

Participants should have practical experience in internal audit, enterprise risk management, compliance, control testing or assurance reporting. They should understand risk registers, control objectives, audit planning, audit evidence and the distinction between management controls and independent assurance. Familiarity with the IIA Three Lines Model and a basic working knowledge of spreadsheets are helpful, but prior assurance-mapping experience is not required. Participants do not need audit software, data analytics expertise, statistical sampling knowledge or a formal internal audit qualification. The course assumes confidence discussing risks and controls with operational and second-line stakeholders.

Training methodology

The instructor uses short technical briefings to establish the IIA Three Lines Model, followed by guided construction of an assurance map from a multi-function corporate case. Participants work in teams with risk registers, assurance-provider profiles, testing samples and audit-committee reporting requirements. They conduct simulated interviews, score assurance reliability against defined criteria, debate reliance decisions and present findings to a mock audit committee. Daily exercises build one connected mapping pack; the final session converts that pack into an organisation-specific implementation plan with stakeholders, milestones and governance actions.

Course outline

Day 1: Positioning assurance under the IIA Three Lines Model

  • Purpose and principles of the IIA Three Lines Model
  • Governing body accountability and oversight expectations
  • First-line management ownership of risk and control
  • Second-line monitoring, expertise and challenge functions
  • Internal audit independence, assurance and advisory boundaries
  • Distinguishing assurance, monitoring, control operation and management reporting
  • Defining the assurance-mapping objective and scope

Workshop: Participants analyse a corporate operating model and produce a draft Three Lines responsibility map for its key risk functions.

Day 2: Building the risk and assurance universe

  • Translating enterprise risk registers into mapping populations
  • Selecting material risks, risk themes and control domains
  • Designing an assurance-provider inventory
  • Classifying internal and external assurance sources
  • Capturing assurance activity scope, frequency and reporting routes
  • Stakeholder interview planning and evidence-request design
  • Creating a risk-to-assurance matrix in Microsoft Excel

Workshop: Participants build a risk-to-assurance matrix and provider inventory for the case organisation using supplied risk and assurance data.

Day 3: Assessing assurance quality and reliance

  • Criteria for assurance scope, competence and objectivity
  • Evaluating methodology, testing depth and evidence quality
  • Assessing independence from operational control ownership
  • Reliance considerations for second-line monitoring
  • Rating assurance maturity and reliability
  • Documenting limitations, qualifications and residual uncertainty
  • Applying Global Internal Audit Standards to assurance coordination

Workshop: Participants score three assurance providers against a reliance assessment template and produce documented reliance conclusions.

Day 4: Mapping coverage, gaps and duplication

  • Coverage scoring across risk, control and assurance dimensions
  • Creating assurance heat maps and gap analyses
  • Identifying duplicated testing and inefficient assurance demand
  • Recognising false assurance from self-assessment and narrow scope
  • Analysing assurance coverage against COSO ERM risk categories
  • Prioritising actions using impact, urgency and assurance reliability
  • Facilitating cross-functional challenge sessions

Workshop: Participants create an assurance coverage heat map, identify priority gaps and duplication, and agree corrective actions in a facilitated workshop.

Day 5: Reporting and embedding assurance mapping

  • Designing audit committee assurance dashboards
  • Writing concise coverage, gap and reliance narratives
  • Linking mapping outcomes to risk-based internal audit planning
  • Escalating unresolved gaps and unclear accountabilities
  • Establishing assurance coordination governance and review cycles
  • Measuring implementation progress and map refresh triggers
  • Developing a 90-day assurance-mapping implementation roadmap

Workshop: Participants present a board-style assurance report and complete a 90-day implementation roadmap for applying the method in their own organisation.

Tools & standards covered

IIA Three Lines Model, Global Internal Audit Standards, COSO Enterprise Risk Management Framework, Microsoft Excel

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should be comfortable with risk registers, controls, audit evidence and assurance reporting, gained through audit, risk, compliance or related work. You do not need prior experience of formal assurance mapping, but the course is not intended as an introduction to basic auditing.

A laptop with Microsoft Excel is recommended for the mapping templates and exercises. No specialist audit-management platform is required; the course focuses on a method that can later be configured in your organisation’s existing GRC or audit tool.

It is best suited to internal audit, risk, compliance and assurance leaders who need a joined-up view of risk coverage across multiple functions. It is particularly valuable where audit committees receive numerous reports but lack a clear view of assurance gaps and overlaps.

Audit planning courses focus primarily on selecting and scheduling internal audit engagements. This course examines the entire assurance ecosystem, including first-line evidence, second-line monitoring, specialist assurance and internal audit, then uses that view to inform planning and governance reporting.

You can begin with a defined risk area, such as financial reporting, cyber security or regulatory compliance, rather than attempting an enterprise-wide map immediately. The supplied pack provides a provider inventory, risk-and-assurance matrix, reliability assessment and reporting structure for a practical pilot.

You leave with completed templates for assurance-provider profiling, risk-to-assurance mapping, reliance assessment, coverage heat mapping and audit-committee reporting. You also create a 90-day implementation plan identifying stakeholders, pilot scope, evidence needs and escalation points.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Auditing

5 Days Certificate

Advanced Forensic Audit Investigation and Interviewing Training Course

Suspected fraud, financial misconduct, and control override require more than routine audit testing. Investigators must turn an allegation, …

5 Days Certificate

ISACA ITAF Audit Framework Application Training Course

Technology audit teams are expected to produce work that is defensible to audit committees, regulators, external auditors and senior managem…

5 Days Certificate

ACL Analytics Continuous Auditing Techniques Training Course

Continuous auditing fails when audit teams rely on periodic spreadsheet extracts, undocumented tests, and exception reports that cannot be r…

5 Days Certificate

Manufacturing Inventory Audit Controls Training Course

Manufacturing inventory is vulnerable to errors and loss at every hand-off: goods receipt, put-away, production issue, scrap booking, subcon…