Skip to content
Patrick M. Hayes
Cover of Integrated Assurance: Unified Risk Strategy by Patrick Hayes, showing a gold cube of business and risk symbols

Security, Audit and Leadership Series

Integrated Assurance

Unified Risk Strategy

The foundational argument for treating assurance as one coordinated activity rather than a set of separate functions reporting on the same business.

Where to find it

  • CRC Press · Publisher edition, hardcover and ebook
  • Major booksellers · Available through most academic and professional retailers

Published by CRC Press, Taylor & Francis Group.

Overview

Integrated Assurance sets out the case that most organizations do not suffer from a shortage of assurance work. They suffer from assurance work that has been divided so thoroughly that no one can assemble it into a view of the business.

The book describes how fragmentation forms, why it persists even in well governed organizations, and what changes when security, technology, operations, governance, resilience and risk are coordinated around one shared understanding of what the business depends on.

It is written for the people who receive assurance reporting as well as the people who produce it, with attention to the structural reasons integration tends to fail.

Who the book is for

  • Executives and directors who receive risk and assurance reporting they cannot reconcile
  • CIOs, CISOs and technology leaders working across organizational boundaries
  • Risk, audit, governance and compliance leaders carrying overlapping mandates
  • Advisors and architects responsible for designing assurance across a enterprise

Key ideas

Fragmentation is structural

Separate budgets, frameworks and reporting lines reliably produce separate and partially contradictory views of the same organization.

One model of the business

Integration depends on a shared description of what the organization requires to operate, maintained as a living reference rather than a project artifact.

Assurance as an operating model

Coordination is achieved by changing how existing work is scoped, related and reported, not by consolidating teams.

Reporting in business terms

Assurance becomes useful to leadership when findings are expressed as consequences for operations rather than counts of controls.

Where it sits in the work

This is the book where the framework behind much of Patrick's later work is established. Business Survivability, Decision Debt and Operational Trust all rely on the ability to see risk across boundaries that Integrated Assurance sets out.

Continue with the book

The full case for treating assurance as one coordinated view of the business.

More books

Cover of Relevant Impact: A Field Guide to Integrated Assurance by Patrick M. Hayes, showing a gold sphere assembled from cubes

Relevant Impact

A Field Guide to Integrated Assurance

Cover of Can We Insure This? Second Edition by Patrick M. Hayes, showing a processor chip marked with a skull on scattered currency

Can We Insure This?

A Business Leader's Guide to Cyber Risk, AI, Insurance, and Business Survivability