Skip to content
Patrick M. Hayes

Integrated Assurance

The business operates as one system. Assurance should understand it that way.

Organizations usually divide responsibility across cybersecurity, technology, operations, governance, risk, compliance, audit and other functions. Those boundaries help organize the business, but they can also fragment how risk is understood.

Integrated Assurance provides an operating model for bringing those perspectives together without eliminating the expertise or accountability of the functions themselves. The objective is to make assurance part of how the enterprise governs, designs, operates and makes decisions.

Capable functions can still produce a fragmented view of the business.

Individual functions may have mature processes, experienced people and useful information while the organization still struggles to understand how risk crosses the boundaries between them.

Integrated Assurance addresses that fragmentation by connecting governance, architecture, engineering, operations, risk, compliance, audit, measurement and culture around a more coherent understanding of the enterprise.

Origins

Built from enterprise architecture outward

Patrick M. Hayes became a Zachman Enterprise Architect in 2000. His work in enterprise and security architecture reinforced the importance of understanding an organization as an interconnected system rather than through the perspective of a single function.

More than two decades of work across cybersecurity, operations, governance, risk, assurance and executive leadership expanded that thinking into Integrated Assurance. The model addresses a recurring problem: organizations can become increasingly capable within individual disciplines while the relationships between those disciplines remain difficult to see and govern.

The operating model

Assurance becomes an enterprise capability

Integrated Assurance extends across six organizational domains. It is not simply a cybersecurity model or a collection of risk functions. It reaches into how the enterprise governs, designs, operates, measures and collaborates.

  1. Governance
  2. Architecture & Engineering
  3. IT & Engineering Operations
  4. Risk, Compliance & Audit
  5. Metrics & Reporting
  6. Culture & Collaboration
Six domains, one operating model. Each domain is connected to every other.

Integrated Assurance Maturity Model

Maturity is measured across the enterprise, not with a single score

The Integrated Assurance Maturity Model, or IAMM, provides a way to understand how assurance currently operates across the six domains and how deeply it has become part of the organization’s operating model.

  1. Level 1

    Fragmented

    Assurance activities largely operate independently, with limited shared governance, inconsistent integration and isolated measures.

  2. Level 2

    Defined

    Policies, frameworks and basic practices exist, but integration and cross-functional application remain inconsistent.

  3. Level 3

    Aligned

    Cross-functional practices begin to emerge. Ownership becomes clearer, shared information improves and assurance activities become more coordinated.

  4. Level 4

    Embedded

    Assurance becomes integrated into governance, engineering, operational processes, measurement and decision-making.

  5. Level 5

    Institutionalized

    Assurance functions as an enterprise capability and is embedded in strategic planning, governance, culture and continuous decision-making.

Each of the six domains is assessed against the five maturity levels
Domain1 · Fragmented2 · Defined3 · Aligned4 · Embedded5 · Institutionalized
Governance
Architecture & Engineering
IT & Engineering Operations
Risk, Compliance & Audit
Metrics & Reporting
Culture & Collaboration

Maturity is assessed domain by domain. An organization may be Aligned in one domain and Fragmented in another.

IAMM Self-Assessment

Where is your organization today?

Take the IAMM Self-Assessment for an indicative view of maturity across governance, architecture, operations, risk, measurement and culture.

18 questions · About 5 minutes

From assessment to implementation

Knowing where you are is different from knowing what to do next

IAMM establishes the current maturity of Integrated Assurance. The implementation methodology provides a practical path for moving the organization forward.

  1. Stage 1

    Define Strategic Intent and Organizational Alignment

  2. Stage 2

    Baseline Capabilities and Identify Friction Points

  3. Stage 3

    Execute Targeted Pilots and Codify Patterns

  4. Stage 4

    Operationalize Assurance at Scale

  5. Stage 5

    Institutionalize Assurance as an Enterprise Capability

Institutionalized assurance changes how the enterprise operates.

At the highest level of maturity, assurance is no longer an activity performed around the business. It becomes part of how the business governs, designs, operates, measures and makes decisions.

Leadership owns and understands risk. Assurance information influences enterprise decisions. Architecture and engineering incorporate assurance into design. Operational teams internalize risk ownership. Metrics demonstrate business impact. Culture reinforces shared responsibility.

Integrated Assurance supports Business Survivability

Business Survivability asks whether the organization can continue operating when the assumptions, systems, people and dependencies it relies upon stop behaving as expected.

Integrated Assurance helps expose and manage those conditions across the enterprise before disruption forces leadership to discover them.

Understand where your organization is today

An Integrated Assurance Assessment uses the IAMM to examine maturity across the six domains, identify fragmentation and friction, and establish the next meaningful steps toward a more integrated operating model.