Best Practices for Bank Audit Committees
Strengthen Board Oversight of Risk, Internal Audit, Financial Reporting, Cybersecurity, Fraud, and Regulatory Compliance
Bank Audit Committees operate in an environment of heightened regulatory scrutiny, rapidly evolving technology, sophisticated fraud schemes, liquidity pressures, cybersecurity threats, and increasing expectations for effective Board governance.
The Best Practices for Bank Audit Committees CPE training event provides Audit Committee members, bank directors, Internal Audit leaders, risk professionals, and financial institution executives with practical guidance for fulfilling their oversight responsibilities.
This four-CPE-credit program examines how an effective Bank Audit Committee should oversee financial reporting, Internal Audit, External Audit, enterprise risk management, internal controls, regulatory examinations, fraud risk, cybersecurity, artificial intelligence, BSA/AML compliance, third-party risk, and management corrective actions.
The program emphasizes a fundamental governance principle:
The Board governs. Management manages the business and owns the risks. Internal Audit provides independent assurance. The Audit Committee provides focused and independent oversight.
The course is based on banking regulatory expectations, recognized governance frameworks, and practical experience working with executives, Boards of Directors, Internal Audit departments, and regulated financial institutions.
Details on Event Presentation
Offered every eight weeks on Tuesdays at 10:00 a.m. to 2:30 p.m. Central Time in four CPE-Credit event.
We can schedule private events on your timetable for two or more attendees.
NASBA Program Disclosure
Program Level of Understanding: Basic
Prerequisites: None
Advance Preparation: None
Delivery Format: Seminar (Group Internet Based)
NASBA Field(s) of Study: Auditing, Information Technology
CPE Credits: 4, based on 50 minutes of instruction per hour
CPE Event Highlights
Participants will examine the expanding responsibilities of Bank Audit Committees and learn how to provide effective oversight without becoming involved in management’s day-to-day responsibilities.
The program addresses:
- Bank Board and Audit Committee governance responsibilities
- The distinction between Board oversight and management execution
- Audit Committee charter requirements and regulatory expectations
- The Three Lines Model for governance, risk management, and assurance
- Internal Audit independence and functional reporting
- Oversight of External Audit quality and independence
- Financial reporting and internal control oversight
- COSO internal control and enterprise risk management concepts
- Risk appetite, residual risk, and enterprise risk reporting
- Bank regulatory examinations and corrective action plans
- Matters Requiring Attention and unresolved regulatory findings
- Credit quality and loan portfolio risk
- Deposit growth, liquidity, and funding risk
- Interest-rate risk and capital adequacy
- Fraud risk management and financial crime
- Cybersecurity and ransomware governance
- Artificial intelligence governance
- Third-party and technology vendor risk
- BSA/AML and OFAC compliance
- Bank Call Reports and regulatory financial information
- Whistleblower programs and ethics oversight
- Business continuity and organizational resilience
- Audit Committee meeting agendas, minutes, and executive sessions
- Tracking repeat findings and overdue corrective actions
- Audit Committee self-assessment and continuing education
The underlying course materials emphasize enterprise governance, management accountability, COSO, risk-based oversight, Internal Audit independence, and emerging bank risks.
Learning Objectives
By the end of this CPE event, participants should be able to:
- Explain the role of the Bank Audit Committee.
Distinguish the responsibilities of the Board, Audit Committee, management, Risk Management, Compliance, Internal Audit, and External Audit. - Apply the Three Lines Model.
Evaluate whether risk ownership, risk oversight, and independent assurance responsibilities are clearly assigned throughout the financial institution. - Assess Audit Committee effectiveness.
Determine whether the committee’s charter, meeting practices, reporting structure, agendas, minutes, and executive sessions support effective governance. - Evaluate Internal Audit independence.
Assess whether Internal Audit has appropriate organizational authority, resources, access, competence, and direct functional reporting to the Audit Committee. - Provide effective External Audit oversight.
Evaluate auditor independence, audit scope, industry expertise, audit quality, significant accounting issues, management letter comments, and communications with the Audit Committee. - Oversee enterprise risk management.
Understand risk appetite, inherent risk, control effectiveness, residual risk, risk heat maps, key risk indicators, and emerging-risk reporting. - Evaluate financial reporting and internal controls.
Apply COSO concepts to financial, operational, compliance, technology, and entity-level controls. - Monitor regulatory examination findings.
Evaluate management’s responses to regulatory findings, Matters Requiring Attention, enforcement concerns, and corrective action commitments. - Identify major banking risks requiring committee attention.
Recognize significant risks involving liquidity, deposits, credit quality, cybersecurity, fraud, BSA/AML, vendors, artificial intelligence, and business continuity. - Ask more effective oversight questions.
Develop questions that help directors challenge assumptions, identify emerging problems, and determine whether management is operating within the Board-approved risk appetite. - Monitor corrective action effectively.
Evaluate the aging, ownership, status, validation, and sustainability of remediation efforts. - Improve Audit Committee reporting to the Board.
Communicate significant risks, findings, unresolved issues, and emerging concerns in a concise and decision-useful format.
- Explain the role of the Bank Audit Committee.
Key Issues on the Agenda
Key Issues Covered
Today's Bank Audit Committee is responsible for much more than reviewing financial statements. Regulators expect committees to provide independent oversight of governance, risk management, internal controls, financial reporting, Internal Audit, External Audit, cybersecurity, fraud, regulatory compliance, and emerging technologies such as Artificial Intelligence.
This course examines the most important responsibilities of an effective Bank Audit Committee, including:
- Board governance and fiduciary responsibilities
- The distinction between Board oversight and management responsibilities
- Audit Committee charter development and best practices
- The Three Lines Model of governance, risk management, and assurance
- Maintaining Internal Audit independence and organizational authority
- Developing and approving risk-based Internal Audit plans
- Oversight of External Audit independence, scope, quality, and communications
- Financial reporting oversight and accounting judgments
- COSO Internal Control Framework and enterprise risk management
- Risk appetite, inherent risk, residual risk, and risk heat maps
- Regulatory examinations, Matters Requiring Attention (MRAs), and corrective action tracking
- Enterprise Risk Management (ERM) reporting to the Board
- Deposit growth, liquidity management, and funding risk
- Credit quality, loan portfolio monitoring, and allowance for credit losses
- Fraud risk management, insider fraud, Business Email Compromise, wire fraud, synthetic identities, and deepfake threats
- Cybersecurity governance, ransomware preparedness, cloud security, and business continuity
- Artificial Intelligence governance, AI risk management, model oversight, data privacy, and acceptable use policies
- BSA/AML, OFAC, Customer Due Diligence, Suspicious Activity Reports, and regulatory compliance oversight
- Third-party and vendor risk management, including cybersecurity and critical service providers
- Whistleblower programs, ethics, and organizational culture
- Regulatory expectations for community banks and financial institutions
- Executive sessions with Internal Audit, External Audit, regulators, and management
- Monitoring corrective actions and identifying repeat audit findings
- Audit Committee self-assessments and continuous improvement
Participants will learn how to ask better governance questions, evaluate management's risk reporting, monitor emerging risks, protect Internal Audit independence, strengthen oversight of financial reporting and internal controls, and improve communication with the Board of Directors.
The course emphasizes practical governance techniques that can be immediately applied to strengthen Board oversight, improve regulatory compliance, enhance enterprise risk management, and support the long-term safety and soundness of financial institutions.
Attendees will also gain a better understanding of current banking regulatory expectations from the Federal Reserve, FDIC, OCC, FFIEC, FinCEN, and other financial institution regulators, while learning proven best practices used by high-performing Audit Committees.
Whether you serve as a Bank Director, Audit Committee member, Chief Audit Executive, Internal Auditor, Chief Risk Officer, Compliance Officer, CFO, Controller, or External Auditor, this program provides practical guidance for improving governance effectiveness, enhancing risk oversight, and protecting the institution from emerging financial, operational, technology, compliance, and reputational risks.
