Institute for Operational Assurance

Category boundaries

Operational Assurance complements established disciplines.

It does not replace GRC, Internal Audit, Compliance, Risk Management, Quality Assurance, Process Mining, Change Management or AI Governance.

Comparison of Operational Assurance with related disciplines
DisciplineTypical focusTimingRelationship to Operational Assurance
GRCGovernance, risk and compliance structuresPlanning, oversight and monitoringProvides policies, controls, risks and obligations that Operational Assurance helps connect to execution.
Internal AuditIndependent assurance over governance, risk and controlPrimarily retrospective and periodicProvides independent challenge and evidence; Operational Assurance strengthens visibility during work.
ComplianceAdherence to laws, regulation and policyPreventative and detectiveDefines requirements; Operational Assurance helps make compliant behaviour more achievable in context.
Risk ManagementIdentification and treatment of uncertaintyAcross planning and operationFrames material exposure and appetite; Operational Assurance supports execution within those boundaries.
Quality AssuranceConformance and quality of outputs or processesBefore, during and after deliveryShares an interest in reliable outcomes; Operational Assurance connects wider organisational intent and behaviour.
Process MiningEvidence of system-recorded process flowsRetrospective and near-real-time analysisProvides valuable visibility; Operational Reality Mapping adds human, informal and cross-system context.
Change ManagementAdoption and transitionDuring organisational changeSupports adoption; Operational Assurance continuously examines behaviour and execution after programmes conclude.
AI GovernanceResponsible design and oversight of AIAcross the AI lifecycleDefines governance for AI; Operational Assurance examines agent action within real enterprise workflows.