Learning Objectives

By the end of this lesson, learners should be able to:

  • Define an audit committee and explain its purpose.
  • Explain the role and responsibilities of the audit committee.
  • Distinguish between internal audit and external audit.
  • Explain the relationship between the board, audit committee, management and auditors.
  • Examine the importance of auditor independence.
  • Explain how external audit supports financial governance.
  • Evaluate the role of the audit committee in financial reporting and risk oversight.
  • Identify common weaknesses that can undermine audit effectiveness.

1. Introduction to Audit Committees and External Audit

Financial governance requires reliable financial information and effective independent oversight.

The board cannot personally examine every transaction, accounting record or financial control within an organization. It therefore relies on specialized governance mechanisms to provide assurance and oversight.

Two important mechanisms are:

  • Audit committees.
  • External audit.

The audit committee operates as a committee of the board, while the external auditor provides an independent examination of the organization’s financial statements and related financial reporting.

The relationship can be illustrated as:

Board of Directors → Audit Committee → Oversight of Financial Reporting, Audit and Controls

Management → Prepares Financial Information

External Auditor → Independently Examines Financial Statements

Internal Audit → Provides Independent Assurance Within the Organization

Effective coordination among these functions strengthens financial governance.

2. Meaning of an Audit Committee

An audit committee is a committee established by the board to provide specialized oversight of matters relating to:

  • Financial reporting.
  • Internal controls.
  • Internal audit.
  • External audit.
  • Risk management.
  • Compliance.
  • Financial integrity.

The audit committee does not replace the board.

Instead, it helps the board perform its oversight responsibilities more effectively.

A properly functioning audit committee should provide independent challenge and informed scrutiny of significant financial and control matters.

3. Purpose of the Audit Committee

The fundamental purpose of an audit committee is to strengthen the board’s oversight of financial integrity and assurance.

Its purposes may include:

  • Reviewing financial reporting.
  • Monitoring the integrity of financial statements.
  • Overseeing internal controls.
  • Supporting auditor independence.
  • Monitoring internal audit activities.
  • Overseeing the external audit process.
  • Reviewing significant financial risks.
  • Monitoring compliance with financial requirements.
  • Investigating significant financial concerns.
  • Reporting important matters to the board.

The audit committee therefore serves as an important link between the board and the organization’s assurance functions.

4. Audit Committee and the Board

The audit committee operates under authority delegated by the board.

However, the board retains ultimate responsibility for governance.

The relationship can be understood as:

Board → Delegates specialized oversight → Audit Committee

Audit Committee → Reviews and challenges → Management and assurance functions

Audit Committee → Reports significant matters → Board

The committee should therefore have sufficient authority, access to information and independence to perform its responsibilities effectively.

5. Composition of the Audit Committee

An effective audit committee should generally contain directors with appropriate independence, competence and financial understanding.

Relevant qualities may include:

  • Financial literacy.
  • Accounting knowledge.
  • Risk-management knowledge.
  • Governance experience.
  • Independence.
  • Professional judgment.
  • Understanding of the organization’s operations.

The precise composition depends on applicable law, governance codes and organizational circumstances.

A committee consisting entirely of individuals closely connected to management may have difficulty providing objective challenge.

6. Financial Literacy

Financial literacy is particularly important for audit committee members.

Members should be able to understand and critically assess matters such as:

  • Financial statements.
  • Accounting policies.
  • Revenue recognition.
  • Assets and liabilities.
  • Cash flows.
  • Financial risks.
  • Audit findings.
  • Internal controls.
  • Significant accounting judgments.

Financial literacy does not necessarily mean that every committee member must be a professional accountant.

However, the committee collectively should possess sufficient expertise to understand complex financial matters and challenge management appropriately.

7. Responsibilities of the Audit Committee

The responsibilities of an audit committee commonly include oversight of:

Financial Reporting

The committee reviews whether financial information is complete, accurate and appropriately presented.

Internal Control

The committee considers whether effective systems exist to protect organizational resources and reduce financial risks.

Internal Audit

The committee oversees the internal audit function and considers significant internal audit findings.

External Audit

The committee oversees the external audit process and monitors auditor independence and performance.

Risk

The committee may review significant financial and reporting risks.

Compliance

The committee may monitor compliance with relevant financial reporting and regulatory requirements.

8. Oversight of Financial Reporting

One of the most important responsibilities of the audit committee is oversight of financial reporting.

Management is responsible for preparing financial statements.

The audit committee should not prepare the financial statements itself.

Instead, it should critically review the reporting process.

Questions may include:

  • Are the financial statements complete?
  • Are accounting policies appropriate?
  • Are significant judgments properly supported?
  • Are material risks appropriately disclosed?
  • Are there unusual transactions?
  • Are there significant changes from previous periods?
  • What issues did the auditors identify?
  • Are there unresolved accounting disagreements?

This oversight helps strengthen confidence in financial information.

9. Management’s Responsibility

Management remains primarily responsible for:

  • Preparing financial statements.
  • Maintaining accounting records.
  • Establishing internal controls.
  • Managing organizational resources.
  • Identifying and managing financial risks.
  • Providing information to auditors.
  • Correcting identified weaknesses.

The audit committee should not assume management’s responsibilities.

This distinction is essential.

Management → Prepares and manages

Audit Committee → Oversees and challenges

External Auditor → Independently examines and provides assurance

Board → Ultimately oversees governance

10. Meaning of External Audit

An external audit is an independent examination of an organization’s financial statements and related financial information by an external auditor.

The objective is generally to provide an independent opinion on whether the financial statements are prepared, in all material respects, in accordance with the applicable financial reporting framework.

External audit provides an important layer of assurance to users of financial statements.

These users may include:

  • Shareholders.
  • Investors.
  • Creditors.
  • Regulators.
  • Lenders.
  • Government institutions.
  • Other stakeholders.

11. Objectives of External Audit

External audit seeks to provide reasonable assurance that financial statements are not materially misstated.

A material misstatement may arise because of:

  • Error.
  • Fraud.
  • Incorrect accounting treatment.
  • Omission.
  • Misclassification.
  • Inadequate disclosure.

The auditor gathers evidence and evaluates whether the financial statements provide a reliable representation within the applicable reporting framework.

12. Reasonable Assurance

External audit does not normally provide absolute assurance.

Instead, an audit provides reasonable assurance.

This distinction is important.

An audit cannot guarantee that:

  • Every fraud will be detected.
  • Every error will be identified.
  • Every transaction will be examined.
  • The organization will never fail.
  • Management will always act ethically.

Auditors use professional judgment, risk assessment, sampling and other procedures.

Therefore:

Audit Assurance ≠ Absolute Guarantee

13. Internal Audit Versus External Audit

Internal audit and external audit are different functions.

Internal Audit

External Audit

Operates within or on behalf of the organization

Independent external professional function

Provides assurance and advisory services

Provides an independent audit opinion

Examines controls, risks and processes

Primarily examines financial statements and related matters

Reports through organizational governance structures

Reports to shareholders or other legally appropriate stakeholders, with governance interaction

Can conduct reviews throughout the year

Usually performs an annual financial statement audit, though engagement activities occur throughout the reporting cycle

Both functions can contribute significantly to effective governance.

14. Internal Audit

Internal audit provides independent and objective assurance designed to help an organization evaluate and improve its:

  • Risk management.
  • Governance.
  • Internal controls.
  • Operational processes.

Internal auditors may examine:

  • Procurement.
  • Payroll.
  • Information systems.
  • Financial controls.
  • Inventory.
  • Compliance.
  • Cybersecurity.
  • Operational efficiency.

Internal audit therefore has a broader organizational perspective than external financial statement audit.

15. External Auditor Independence

Auditor independence is fundamental to credible external audit.

An auditor should be able to perform the audit objectively without inappropriate influence from:

  • Management.
  • Directors.
  • Major shareholders.
  • Personal relationships.
  • Financial interests.
  • Commercial pressure.

If an auditor becomes excessively dependent on the organization being audited, the credibility of the audit may be weakened.

16. Threats to Auditor Independence

Potential threats may include:

Self-Interest Threat

The auditor has a financial or other interest that could influence professional judgment.

Self-Review Threat

The auditor is required to evaluate work previously performed by the same firm or individual.

Familiarity Threat

A close relationship with management reduces professional skepticism.

Advocacy Threat

The auditor promotes the client’s interests in a manner inconsistent with independence.

Intimidation Threat

The auditor feels pressured or threatened by management or other powerful individuals.

Appropriate safeguards should be used to manage such threats.

17. Appointment of External Auditors

The appointment process depends on applicable law, organizational structure and governance requirements.

A strong governance process should seek to ensure that:

  • The auditor is appropriately qualified.
  • Independence is assessed.
  • Conflicts of interest are considered.
  • Audit quality is evaluated.
  • Fees are appropriately reviewed.
  • The auditor has access to necessary information.

The audit committee often plays an important role in recommending or overseeing the appointment of the external auditor.

18. Audit Committee and External Auditor Relationship

The audit committee should maintain an appropriate relationship with the external auditor.

The committee may meet with the auditor to discuss:

  • Audit strategy.
  • Significant risks.
  • Audit findings.
  • Accounting judgments.
  • Internal control weaknesses.
  • Management disagreements.
  • Auditor independence.
  • Audit fees.
  • Uncorrected misstatements.
  • Significant unusual transactions.

The audit committee should also have opportunities to communicate with the external auditor without management present when appropriate.

19. Auditor Communication with the Audit Committee

External auditors may communicate significant matters to those charged with governance.

These may include:

  • Significant audit risks.
  • Major accounting judgments.
  • Significant difficulties encountered during the audit.
  • Material control deficiencies.
  • Significant misstatements.
  • Disagreements with management.
  • Concerns regarding financial reporting.
  • Matters affecting auditor independence.

Such communication allows the audit committee to exercise informed oversight.

20. Audit Evidence

Auditors do not simply accept management’s statements without examination.

They obtain audit evidence through procedures such as:

  • Inspection.
  • Observation.
  • Confirmation.
  • Recalculation.
  • Analytical procedures.
  • Inquiry.
  • Examination of supporting documents.

For example, if an organization reports a significant receivable, auditors may examine supporting documentation and obtain confirmations where appropriate.

The objective is to obtain sufficient appropriate audit evidence to support the audit opinion.

21. Materiality

Materiality is an important concept in auditing.

Information is considered material if its omission, misstatement or obscuring could reasonably be expected to influence decisions made by users of the financial statements.

Not every error has the same significance.

For example:

A small accounting error may have little effect on financial statement users.

A significant undisclosed liability could materially affect their decisions.

Auditors therefore assess both quantitative and qualitative aspects of materiality.

22. Fraud and External Audit

Fraud is a significant governance concern.

Examples include:

  • Falsifying financial records.
  • Misappropriating assets.
  • Creating fictitious transactions.
  • Manipulating revenue.
  • Concealing liabilities.
  • Unauthorized payments.

Management has primary responsibility for preventing and detecting fraud through appropriate controls.

External auditors consider the risk of material misstatement due to fraud and perform procedures designed to respond to identified risks.

However:

External Audit ≠ Guarantee That All Fraud Will Be Detected

23. Audit Committee Oversight of Fraud Risk

The audit committee should understand the organization’s exposure to fraud risk.

Questions may include:

  • Where could fraud occur?
  • Who has access to organizational resources?
  • Are duties appropriately segregated?
  • Are unusual transactions monitored?
  • Are whistleblowing mechanisms functioning?
  • Have previous fraud incidents been addressed?
  • Are management override risks considered?

The committee should encourage a culture in which employees can report suspected misconduct without inappropriate retaliation.

24. Internal Controls and Audit

Auditors consider relevant internal controls when planning and performing their work.

Examples include:

  • Authorization controls.
  • Segregation of duties.
  • Access controls.
  • Reconciliations.
  • Approval procedures.
  • Physical controls.
  • IT controls.

The existence of controls does not automatically mean that they are effective.

Auditors may test whether controls:

  • Exist.
  • Are properly designed.
  • Have been implemented.
  • Operate effectively where relevant to the audit.

25. Audit Findings

An audit may identify weaknesses requiring management attention.

Examples include:

  • Weak segregation of duties.
  • Missing documentation.
  • Unauthorized transactions.
  • Inadequate reconciliations.
  • Weak access controls.
  • Inaccurate accounting.
  • Inadequate financial disclosures.

Significant findings should be communicated appropriately to management and the audit committee.

26. Corrective Action

Identifying a weakness is only the beginning.

Management should establish corrective actions that address:

  1. The identified weakness.
  2. The underlying cause.
  3. The responsible person.
  4. The required action.
  5. The implementation deadline.
  6. The monitoring process.

The audit committee should monitor whether significant weaknesses are actually corrected.

Repeated findings may indicate that management is not adequately addressing governance weaknesses.

27. Audit Committee and Risk Management

Financial reporting risk is only one part of organizational risk.

Audit committees may interact with broader risk-management structures concerning:

  • Financial risk.
  • Operational risk.
  • Compliance risk.
  • Cybersecurity risk.
  • Fraud risk.
  • Reputational risk.
  • Strategic risk.

The precise division of responsibilities between the audit committee and other board committees depends on the organization’s governance structure.

28. External Audit and Stakeholder Confidence

Reliable external audit can strengthen stakeholder confidence.

Investors and other users of financial information may have limited access to the organization’s internal operations.

An independent audit provides an additional layer of assurance concerning the financial statements.

This can support:

  • Investor confidence.
  • Credibility of financial reporting.
  • Access to financing.
  • Regulatory confidence.
  • Stakeholder trust.

However, audit is only one component of a broader governance system.

29. Audit Quality

Audit quality depends on several factors, including:

  • Auditor competence.
  • Independence.
  • Professional skepticism.
  • Adequate resources.
  • Appropriate audit procedures.
  • Effective supervision.
  • Strong ethical standards.
  • Effective communication with those charged with governance.

An audit may be formally completed while still being ineffective if auditors fail to exercise sufficient professional judgment and skepticism.

30. Professional Skepticism

Professional skepticism involves maintaining a questioning mind and critically assessing audit evidence.

Auditors should not automatically assume that:

  • Management is dishonest.

Nor should they automatically assume that:

  • Management is completely trustworthy.

Instead, auditors should evaluate evidence objectively.

For example, if management provides an explanation for a significant financial transaction, auditors should consider whether supporting evidence confirms the explanation.

31. Audit Committee Challenges

Audit committees may face several challenges, including:

  • Limited financial expertise.
  • Excessive dependence on management.
  • Insufficient information.
  • Weak board independence.
  • Poor communication.
  • Complex accounting issues.
  • Inadequate time.
  • Conflicts of interest.
  • Failure to follow up audit findings.
  • Excessive reliance on external auditors.

Effective committees need sufficient authority, competence and independence to overcome these challenges.

32. Common Audit Governance Failures

Audit governance can fail when:

  • The audit committee does not challenge management.
  • Directors lack financial understanding.
  • Auditors are not sufficiently independent.
  • Significant audit findings are ignored.
  • Internal controls are weak.
  • Management overrides controls.
  • Conflicts of interest are not disclosed.
  • Financial information is manipulated.
  • Whistleblowing mechanisms are ineffective.

These failures can contribute to serious financial and organizational consequences.

33. Board-Level Questions for the Audit Committee

A strong audit committee should ask questions such as:

  1. Are the financial statements reliable?
  2. What are the most significant accounting judgments?
  3. What are the major financial reporting risks?
  4. What weaknesses have internal auditors identified?
  5. What weaknesses have external auditors identified?
  6. Has management corrected significant control deficiencies?
  7. Is the external auditor independent?
  8. Are there unresolved disagreements between management and auditors?
  9. What fraud risks exist?
  10. Are whistleblowing mechanisms functioning effectively?
  11. Are significant related-party transactions properly disclosed?
  12. What issues should immediately be brought to the full board?

These questions demonstrate active governance rather than passive approval.

34. Relationship Between the Four Key Functions

Effective financial governance can be represented as:

Management

Prepares financial information and operates internal controls.

↓

Internal Audit

Provides independent assurance concerning governance, risk and controls.

↓

Audit Committee

Reviews, challenges and oversees financial reporting and assurance.

↓

External Auditor

Provides an independent audit opinion on the financial statements.

↓

Board of Directors

Retains ultimate governance responsibility.

These functions should complement one another rather than operate in isolation.

35. Practical Example

Consider a company that reports rapidly increasing profits.

The board should not simply celebrate the result.

The audit committee may ask:

  • What caused the increase?
  • Is revenue recognition appropriate?
  • Are there unusual transactions?
  • Have receivables increased significantly?
  • Has cash flow improved?
  • What assumptions were used?
  • What did the external auditor identify?
  • Are internal controls functioning properly?

Suppose management cannot adequately explain a significant increase in revenue while cash collections remain weak.

The audit committee should require further investigation.

This demonstrates the importance of governance challenge.

36. Executive Application Exercise

Audit Governance Assessment

Select an organization you are familiar with and assess its audit governance.

Evaluate:

  1. Audit Committee

Does the organization have an audit committee?

  1. Composition

Does the committee have appropriate expertise and independence?

  1. Financial Reporting

How does the committee oversee financial reporting?

  1. Internal Audit

Does the organization have an effective internal audit function?

  1. External Audit

How is the external auditor appointed and monitored?

  1. Independence

What safeguards exist to protect auditor independence?

  1. Internal Controls

What major controls protect organizational resources?

  1. Fraud Risk

How does the organization identify and respond to fraud?

  1. Audit Findings

How are weaknesses identified by auditors addressed?

  1. Overall Assessment

Identify three strengths and three weaknesses in the organization’s audit governance.

Then recommend three practical improvements.

37. Best Practices for Effective Audit Committees

Organizations should seek to:

  1. Ensure appropriate audit committee independence.
  2. Appoint members with sufficient financial literacy.
  3. Establish clear committee responsibilities.
  4. Provide members with timely and accurate information.
  5. Maintain direct communication with internal and external auditors.
  6. Protect auditor independence.
  7. Review significant financial reporting judgments.
  8. Monitor major internal control weaknesses.
  9. Monitor fraud risks.
  10. Follow up unresolved audit findings.
  11. Encourage confidential reporting of concerns.
  12. Evaluate the effectiveness of the audit committee regularly.
  13. Maintain appropriate records of committee decisions.
  14. Escalate significant concerns to the full board.
  15. Promote a culture of financial integrity.

Lesson Summary

An audit committee is an important committee of the board responsible for specialized oversight of financial reporting, internal controls, audit and related governance matters.

External audit provides an independent examination of an organization’s financial statements and provides reasonable assurance concerning whether those statements are materially misstated.

The major governance relationships are:

Management → prepares financial information

Internal Audit → provides internal assurance

Audit Committee → provides specialized board oversight

External Auditor → provides independent external assurance

Board → retains ultimate governance responsibility

Effective audit governance depends on:

  • Independence.
  • Financial literacy.
  • Professional skepticism.
  • Effective internal controls.
  • Reliable financial reporting.
  • Strong communication.
  • Appropriate oversight.
  • Timely corrective action.
  • Ethical conduct.

The key lesson is that an audit committee should not simply receive audit reports. It should actively question, challenge, understand and follow up on significant matters affecting financial integrity and organizational accountability.

References

  • G20/OECD Principles of Corporate Governance 2023 — OECD
  • International Standards on Auditing — International Auditing and Assurance Standards Board (IAASB)
  • International Professional Practices Framework — The Institute of Internal Auditors (IIA)
  • UK Corporate Governance Code — Financial Reporting Council
  • International Finance Corporation — Corporate Governance Methodology
  • Companies Act and applicable corporate governance requirements in the relevant jurisdiction