
Security, Audit and Leadership Series
Integrated Assurance
Unified Risk Strategy
The foundational argument for treating assurance as one coordinated activity rather than a set of separate functions reporting on the same business.
Where to find it
- CRC Press · Publisher edition, hardcover and ebook
- Major booksellers · Available through most academic and professional retailers
Published by CRC Press, Taylor & Francis Group.
Overview
Integrated Assurance sets out the case that most organizations do not suffer from a shortage of assurance work. They suffer from assurance work that has been divided so thoroughly that no one can assemble it into a view of the business.
The book describes how fragmentation forms, why it persists even in well governed organizations, and what changes when security, technology, operations, governance, resilience and risk are coordinated around one shared understanding of what the business depends on.
It is written for the people who receive assurance reporting as well as the people who produce it, with attention to the structural reasons integration tends to fail.
Who the book is for
- Executives and directors who receive risk and assurance reporting they cannot reconcile
- CIOs, CISOs and technology leaders working across organizational boundaries
- Risk, audit, governance and compliance leaders carrying overlapping mandates
- Advisors and architects responsible for designing assurance across a enterprise
Key ideas
Fragmentation is structural
Separate budgets, frameworks and reporting lines reliably produce separate and partially contradictory views of the same organization.
One model of the business
Integration depends on a shared description of what the organization requires to operate, maintained as a living reference rather than a project artifact.
Assurance as an operating model
Coordination is achieved by changing how existing work is scoped, related and reported, not by consolidating teams.
Reporting in business terms
Assurance becomes useful to leadership when findings are expressed as consequences for operations rather than counts of controls.
Where it sits in the work
This is the book where the framework behind much of Patrick's later work is established. Business Survivability, Decision Debt and Operational Trust all rely on the ability to see risk across boundaries that Integrated Assurance sets out.
Continue with the book
The full case for treating assurance as one coordinated view of the business.
Related ideas
Related writing
- Introducing the Integrated Assurance Maturity Model (IAMM)
September 18, 2025
- The Ten Things I Didn’t Expect on the Road to Publishing Integrated Assurance
October 21, 2025
More books

Relevant Impact
A Field Guide to Integrated Assurance

Can We Insure This?
A Business Leader's Guide to Cyber Risk, AI, Insurance, and Business Survivability