Is Your Audit Committee Really Providing Effective Oversight?
- John Blackshire
- Aug 22
- 8 min read
Why Board Members, Audit Committee Members and Internal Audit Leaders Should Revisit Audit Committee Best Practices
An organization can have an Audit Committee charter, regularly scheduled meetings, detailed agendas, financial reports, Internal Audit presentations and an external auditor—and still have weak governance.
The existence of an Audit Committee does not establish that the Audit Committee is effective.
The more important questions are:
Does the Audit Committee understand the organization's most significant risks?
Does it challenge management when necessary?
Does it receive independent assurance about whether critical controls actually work?
Does Internal Audit have direct and unrestricted access to the committee?
Does the committee know what questions it should be asking?
These questions are why The Accountware Group believes Audit Committee effectiveness deserves continuing attention from boards, management and Internal Audit.
Corporate Compliance Seminars will present its Best Practices: Audit Committee CPE program twice during the remainder of 2026:
Tuesday, August 25, 2026
Tuesday, October 27, 2026
The two-hour program provides 2 CPE credits in Auditing and focuses on financial reporting, risk management, ICFR, external and Internal Audit, governance controls, special investigations, ethics and Audit Committee reporting responsibilities.
The Audit Committee Is an Entity-Level Control
Internal Auditors spend considerable time evaluating transaction-level controls.
Someone approves a purchase order.
Someone reviews a journal entry.
Someone reconciles a bank account.
Someone reviews system access.
Those controls matter.
An effective Audit Committee influences the organization's:
Control Environment
Tone at the Top
Financial Reporting
Risk Management
Internal Audit
External Audit
Ethics and Compliance
Fraud Oversight
That makes the Audit Committee itself an important entity-level governance control.
If this control is weak, weaknesses can cascade throughout the organization.
Governance Is Not Management
Audit Committees sometimes struggle with the distinction between oversight and management.
Management should manage the organization.
Management owns the risks.
Management designs and operates the controls.
Management is responsible for achieving organizational objectives.
The Audit Committee provides governance oversight.
That requires the committee to ask:
What are management's most significant objectives?
What could prevent management from achieving them?
What controls address those risks?
How does management know those controls are effective?
What independent assurance does the board receive?
The CCS program specifically addresses the committee's fiduciary oversight responsibilities for financial reporting, risk management, ICFR, external auditors, Internal Audit, governance controls and investigations.
Start With the Audit Committee Charter
One of the first documents Internal Audit should examine when evaluating governance is the Audit Committee Charter.
The charter should not merely establish meeting dates and membership requirements.
It should clearly establish:
Purpose
Authority
Responsibilities
Access to Information
Relationship With Management
Relationship With Internal Audit
Relationship With External Audit
Reporting Responsibilities
The CCS agenda specifically includes Audit Committee purpose, boards and subcommittees, Audit Committee charters and good corporate governance.
The charter establishes what the committee is supposed to do.
But there is another question:
Does the committee actually do what its charter says?
That distinction makes the Audit Committee charter an excellent subject for Internal Audit review.
Audit Committee Effectiveness Can Be Audited
Internal Audit departments frequently audit every major function except one:
Governance itself.
Why shouldn't Internal Audit periodically evaluate whether important governance controls are appropriately designed?
An Audit Committee governance review could examine whether the charter appropriately addresses significant responsibilities and compare actual committee practices with those responsibilities.
The review might consider:
Meeting frequency and attendance
Agenda coverage
Information provided to members
Financial-reporting oversight
Risk oversight
Internal Audit reporting
External auditor communications
Fraud and ethics matters
Corrective-action monitoring
Executive sessions
Committee self-assessment
That is not Internal Audit telling the Audit Committee how to govern.
It is providing independent assurance over an important entity-level control.
Financial Reporting Requires More Than Receiving Financial Statements
An Audit Committee can receive a financial package every quarter without providing meaningful financial-reporting oversight.
The CCS program addresses financial-statement review, materiality, misstatements and financial-statement estimates.
Effective committee members should understand where management judgment materially affects financial reporting.
They should be prepared to ask:
Where are our most significant accounting estimates?
Which assumptions have the greatest effect on reported results?
Where did management exercise significant judgment?
What concerns did the external auditor identify?
Were there disagreements between management and the auditor?
Were significant adjustments proposed?
The committee doesn't perform the audit.
But it needs enough knowledge to challenge the people who do.
Internal Control Over Financial Reporting Deserves Attention
The CCS program also specifically addresses Internal Control over Financial Reporting (ICFR), COSO, weak controls and financial-statement risk.
This is where Audit Committee members need to understand an important distinction:
A control existing is not the same as a control being effective.
A manager can sign a reconciliation every month.
That doesn't necessarily mean the review is capable of identifying a material error.
A policy can exist.
That doesn't mean employees follow it.
A system can require approval.
That doesn't necessarily mean management cannot override it.
Effective governance requires understanding whether critical controls are appropriately designed and operating effectively.
Tone at the Top Is a Governance Issue
The CCS agenda specifically includes tone at the top as part of its discussion of risk, fraud and internal control.
This is significant.
Corporate culture is not simply an HR issue.
It affects whether employees:
Follow controls.
Report problems.
Challenge questionable decisions.
Tell Internal Audit the truth.
Use whistleblower mechanisms.
Escalate bad news.
A board can approve an excellent Code of Conduct while management behavior communicates an entirely different message.
The Audit Committee should pay attention to both.
Fraud Risk Requires Skeptical Governance
Audit Committee members should never assume:
“Fraud cannot happen here.”
The better governance question is:
“If someone wanted to commit fraud here, how could they circumvent our controls?”
That changes the discussion.
The committee should understand risks involving:
Management Override
Related Parties
Conflicts of Interest
Unusual Transactions
Journal Entries
Vendor Relationships
Whistleblower Allegations
Executive Expenses
Financial Estimates
Special Investigations
The CCS program specifically incorporates fraud, weak controls, risk management and special investigations into the committee's oversight responsibilities.
Internal Audit Needs a Direct Relationship With the Audit Committee
This may be one of the most important governance relationships in the organization.
The Chief Audit Executive should be able to communicate with the Audit Committee without management controlling the message.
The CCS agenda addresses why organizations need Internal Audit, what Internal Auditors should do, and how the Audit Committee should manage its relationships with auditors.
An effective Audit Committee should know:
Is Internal Audit sufficiently independent?
Does it have adequate resources?
Does it have the necessary competencies?
Can it audit any area of the organization?
Does it have access to the information it needs?
Is management interfering with its work?
And perhaps most importantly:
Is Internal Audit auditing the risks that matter most?
Completing 100% of an ineffective audit plan isn't a measure of success.
The Audit Committee Should Meet Privately With Internal Audit
An executive session with the Chief Audit Executive can be one of the committee's most valuable governance controls.
Management should not always be in the room.
One simple question can reveal a great deal:
“Is there anything happening in this organization that you believe this committee needs to know but that has not been adequately communicated to us?”
Then listen.
The answer—or hesitation before the answer—may tell the committee something important.
The External Auditor Should Be Challenged Too
Audit Committees also need an effective relationship with the external auditor.
The CCS program addresses management-versus-auditor responsibilities, PCAOB requirements where applicable, evaluating auditor capabilities and audit quality.
The committee should not merely receive the external auditor's presentation.
Members should ask:
What areas involved the greatest audit risk?
Which estimates required the greatest judgment?
What surprised you?
Where was the audit most difficult?
Did management resist any proposed adjustments?
Were there disagreements with management?
What internal-control weaknesses concern you?
If you were sitting on this committee, what would concern you most?
That final question can produce a very different conversation.
Special Investigations Need Governance Before the Crisis
The CCS program specifically identifies special investigations as an Audit Committee oversight responsibility.
Organizations should establish how significant allegations will be handled before an allegation occurs.
Consider what happens when an allegation involves:
The CEO
CFO
Superintendent
Executive Management
Internal Audit Leadership
Financial Reporting
Fraud
Retaliation
Who controls the investigation?
Who selects outside counsel or investigators?
Who receives the report?
Who determines whether the matter is escalated?
How is investigator independence protected?
Those governance questions are much easier to answer before a crisis.
The Audit Committee Should Evaluate Itself
The CCS agenda includes Audit Committee self-assessment.
That is an important control that is frequently reduced to a checklist.
A meaningful self-assessment should ask harder questions:
Do we have the right expertise?
Are we spending time on the right issues?
Do we receive the information we need?
Are materials provided early enough to review?
Do members challenge management?
Are dissenting views encouraged?
Do we understand Internal Audit's concerns?
Are unresolved findings being allowed to age?
Do we follow issues through corrective action?
Is management controlling too much of our agenda?
The objective isn't to prove the committee is effective.
The objective is to identify how it can become more effective.
AI Should Now Be on the Audit Committee Agenda
There is another governance risk that has rapidly become significant:
Artificial Intelligence.
Audit Committees should increasingly ask management:
Where are we using AI?
Who authorized those applications?
What confidential information is being entered into AI systems?
How are AI-generated outputs validated?
What controls exist over AI-assisted financial decisions?
How is cybersecurity addressed?
What regulatory requirements apply?
Has Internal Audit evaluated AI governance?
AI may be new technology.
But the governance issue is familiar:
Objective → Risk → Control → Monitoring → Assurance
The Audit Committee doesn't need to become an AI engineering team.
It does need assurance that management understands and controls material AI risks.
Ten Questions Every Audit Committee Should Ask
A useful way to evaluate Audit Committee effectiveness is to see whether the committee can obtain credible answers to these ten questions:
What are the organization's five most significant risks?
Which of those risks have changed materially during the past year?
What are our most important entity-level controls?
Where does management believe our control environment is weakest?
What concerns Internal Audit most?
What concerns the external auditor most?
Where could management override existing controls?
Which significant audit findings remain unresolved?
Can employees report serious concerns without fear of retaliation?
What should this Audit Committee be discussing that isn't currently on our agenda?
That last question deserves to be asked regularly.
Two Opportunities to Attend in 2026
CCS offers Best Practices: Audit Committee every eight weeks on Tuesdays from 1:00 p.m. to 3:00 p.m. Central Time. It is a Group Internet Based program providing 2 CPE credits in Auditing, with no prerequisites or advance preparation.
For TAG readers, two upcoming opportunities are:
Tuesday, August 25, 2026
and
Tuesday, October 27, 2026
The program is designed for Audit Committee members, board members and directors, senior officers, and advisors responsible for governance and risk oversight.
The Bottom Line: Governance Requires More Than Attendance
An ineffective Audit Committee can have perfect attendance.
It can have detailed minutes.
It can receive hundreds of pages of meeting materials.
It can have a beautifully written charter.
None of those things proves effective governance.
Effective oversight requires something more:
Understand the risk.
Demand evidence.
Challenge assumptions.
Protect auditor independence.
Follow significant issues through resolution.
Ask difficult questions.
And when the answers indicate that something needs to change:
Act.
That is what distinguishes an Audit Committee that exists on an organizational chart from an Audit Committee that functions as an effective entity-level governance control.
Comments