Integrated Assurance
The business operates as one system. Assurance should understand it that way.
Organizations usually divide responsibility across cybersecurity, technology, operations, governance, risk, compliance, audit and other functions. Those boundaries help organize the business, but they can also fragment how risk is understood.
Integrated Assurance provides an operating model for bringing those perspectives together without eliminating the expertise or accountability of the functions themselves. The objective is to make assurance part of how the enterprise governs, designs, operates and makes decisions.
Capable functions can still produce a fragmented view of the business.
Individual functions may have mature processes, experienced people and useful information while the organization still struggles to understand how risk crosses the boundaries between them.
Integrated Assurance addresses that fragmentation by connecting governance, architecture, engineering, operations, risk, compliance, audit, measurement and culture around a more coherent understanding of the enterprise.
Origins
Built from enterprise architecture outward
Patrick M. Hayes became a Zachman Enterprise Architect in 2000. His work in enterprise and security architecture reinforced the importance of understanding an organization as an interconnected system rather than through the perspective of a single function.
More than two decades of work across cybersecurity, operations, governance, risk, assurance and executive leadership expanded that thinking into Integrated Assurance. The model addresses a recurring problem: organizations can become increasingly capable within individual disciplines while the relationships between those disciplines remain difficult to see and govern.
The operating model
Assurance becomes an enterprise capability
Integrated Assurance extends across six organizational domains. It is not simply a cybersecurity model or a collection of risk functions. It reaches into how the enterprise governs, designs, operates, measures and collaborates.
- Governance
- Architecture & Engineering
- IT & Engineering Operations
- Risk, Compliance & Audit
- Metrics & Reporting
- Culture & Collaboration
Integrated Assurance Maturity Model
Maturity is measured across the enterprise, not with a single score
The Integrated Assurance Maturity Model, or IAMM, provides a way to understand how assurance currently operates across the six domains and how deeply it has become part of the organization’s operating model.
Level 1
Fragmented
Assurance activities largely operate independently, with limited shared governance, inconsistent integration and isolated measures.
Level 2
Defined
Policies, frameworks and basic practices exist, but integration and cross-functional application remain inconsistent.
Level 3
Aligned
Cross-functional practices begin to emerge. Ownership becomes clearer, shared information improves and assurance activities become more coordinated.
Level 4
Embedded
Assurance becomes integrated into governance, engineering, operational processes, measurement and decision-making.
Level 5
Institutionalized
Assurance functions as an enterprise capability and is embedded in strategic planning, governance, culture and continuous decision-making.
| Domain | 1 · Fragmented | 2 · Defined | 3 · Aligned | 4 · Embedded | 5 · Institutionalized |
|---|---|---|---|---|---|
| Governance | |||||
| Architecture & Engineering | |||||
| IT & Engineering Operations | |||||
| Risk, Compliance & Audit | |||||
| Metrics & Reporting | |||||
| Culture & Collaboration |
Maturity is assessed domain by domain. An organization may be Aligned in one domain and Fragmented in another.
IAMM Self-Assessment
Where is your organization today?
Take the IAMM Self-Assessment for an indicative view of maturity across governance, architecture, operations, risk, measurement and culture.
18 questions · About 5 minutes
From assessment to implementation
Knowing where you are is different from knowing what to do next
IAMM establishes the current maturity of Integrated Assurance. The implementation methodology provides a practical path for moving the organization forward.
Stage 1
Define Strategic Intent and Organizational Alignment
Stage 2
Baseline Capabilities and Identify Friction Points
Stage 3
Execute Targeted Pilots and Codify Patterns
Stage 4
Operationalize Assurance at Scale
Stage 5
Institutionalize Assurance as an Enterprise Capability
Institutionalized assurance changes how the enterprise operates.
At the highest level of maturity, assurance is no longer an activity performed around the business. It becomes part of how the business governs, designs, operates, measures and makes decisions.
Leadership owns and understands risk. Assurance information influences enterprise decisions. Architecture and engineering incorporate assurance into design. Operational teams internalize risk ownership. Metrics demonstrate business impact. Culture reinforces shared responsibility.
Integrated Assurance supports Business Survivability
Business Survivability asks whether the organization can continue operating when the assumptions, systems, people and dependencies it relies upon stop behaving as expected.
Integrated Assurance helps expose and manage those conditions across the enterprise before disruption forces leadership to discover them.
Understand where your organization is today
An Integrated Assurance Assessment uses the IAMM to examine maturity across the six domains, identify fragmentation and friction, and establish the next meaningful steps toward a more integrated operating model.