Internal Audit and Combined Assurance

Internal audit functions are expected to provide assurance over increasingly complex organisations. At the same time, risk, compliance, control and external assurance teams may be reviewing many of the same areas.
Without coordination, organisations can experience duplicated testing, assurance gaps and inconsistent reporting.
Internal audit transformation and combined assurance address both the quality of assurance and the way it is coordinated.
Modernise audit planning
Annual audit plans can become outdated when risks change quickly.
Planning should draw on:
⦁ Enterprise risk assessments.
⦁ Regulatory developments.
⦁ Incidents and losses.
⦁ Control failures.
⦁ Transformation programmes.
⦁ Cyber and technology risks.
⦁ Previous findings.
A connected audit universe should link business units, processes, risks, controls and prior assurance results.
Use data and technology
Data analytics can support scoping, sample selection, anomaly detection, testing and trend analysis.
AI can assist with reviewing documents, comparing controls, summarising evidence, drafting workpapers and identifying recurring themes.
These tools should improve coverage and efficiency, but professional judgement remains essential.
Coordinate assurance providers
Combined assurance begins with the organisation’s most significant risks.
For each material risk, leadership should understand:
⦁ Who owns it.
⦁ Which controls manage it.
⦁ Who monitors those controls.
⦁ Which assurance activities are planned.
⦁ What findings remain open.
⦁ Whether coverage is sufficient.
An assurance map can identify gaps, duplication and areas requiring independent review.
Improve reporting
Boards need more than a list of completed audits.
Reporting should show material weaknesses, repeated findings, delayed actions, assurance gaps and emerging themes.
The Falconry approach
Falconry Solutions helps internal audit and assurance functions improve both operating efficiency and strategic relevance.
Our support can include audit operating-model design, risk-based planning, audit methodology, combined assurance, data analytics, AI use cases, quality assessment and report enhancement.
Falconry360 can connect the audit universe, risks, controls, workpapers, evidence, findings and remediation. FalconryX can support evidence analysis, workpaper preparation and thematic reporting.
What differentiates Falconry is the connection between internal audit and the broader governance environment. Audit does not operate as an isolated module; it is linked to enterprise risk, compliance, controls and issues.
Falconry can also provide co-sourced or managed internal audit support and build practitioner capability through Falconry Academy.
The result is a more responsive, technology-enabled assurance function with clearer coverage and stronger board relevance.