Assurance tests whether those expectations deserve confidence.

NewEra helps organisations look across critical risks, controls, verification and operational reality to understand where protection is strong, where uncertainty remains and where attention is needed most.

Assurance is more than checking compliance.

An organisation can have:

Critical risks defined.

Bowties developed.

Critical controls identified.

Performance standards documented.

Verification completed.

Dashboards reporting green.

And still have uncertainty about whether people are protected.

Critical Risk Assurance asks a different question:

How confident should we be?

Not simply:

Is the framework in place?

But:

Is the framework producing effective protection in the work?

Start with what matters most.

Assurance effort shouldn't be spread evenly across everything.

Some risks deserve deeper attention.

Some controls carry greater reliance.

Some areas contain more uncertainty.

Some operating conditions create greater exposure.

NewEra uses three questions to shape assurance:

RISK

What could happen?

Consider the potential severity of the serious-harm pathway and the nature of exposure.

RELIANCE

How much are we depending on this?

Understand how important particular controls are to preventing or mitigating the pathway and whether genuinely independent protection exists.

UNCERTAINTY

How much do we actually know?

Consider the quality, consistency and recency of evidence about control effectiveness.

Assurance follows risk, reliance and uncertainty.

Verification and assurance are connected.

They aren't the same thing.

VERIFICATION

Is this control effective?

Verification gathers evidence about defined performance requirements and the state of the control.

It operates close to the control and the work.

ASSURANCE

How confident should we be in the protection?

Assurance looks across the wider body of evidence.

It challenges whether:

The right risks have been identified.

The right controls have been selected.

Performance expectations are appropriate.

Verification provides meaningful evidence.

Control states are understood.

Degradation is acted upon.

Learning changes the system.

Governance has an accurate picture.

Verification contributes evidence.

Assurance challenges the confidence built from it.

Assurance should follow the risk.

Traditional assurance programs can become calendar-led.

Annual audit.

Quarterly review.

Monthly inspection.

Scheduled verification.

Those rhythms can be useful.

But risk doesn't follow a calendar.

Exposure changes.

Work changes.

Controls degrade.

Projects enter different phases.

Equipment changes.

Incidents reveal new information.

Verification identifies uncertainty.

Assurance should respond to those signals.

Look deeper when the risk gives you a reason to.

Depth should reflect uncertainty.

Not every assurance activity needs the same level of scrutiny.

NewEra considers three dimensions.

DEPTH

How far do we need to look?

Document review?

Interviews?

Data analysis?

Field observation?

Technical testing?

Independent validation?

FREQUENCY

How often do we need confidence?

The answer should reflect exposure, control demand, variability, degradation and the consequences of failure.

COVERAGE

Where do we need to look?

Which sites?

Which activities?

Which controls?

Which operating conditions?

Which parts of the organisation?

The objective isn't maximum assurance.

It's enough assurance to support the decisions being made.

Follow the pathway from system to exposure.

Critical Risk Assurance should be able to trace the logic all the way through.

CRITICAL RISK

Is the serious-harm event or exposure clearly understood?