Skip to main content
Category: Board Committees and Governance

Audit Committee

Simply put

An audit committee is a committee formed by a company's or organization's board of directors to oversee how the entity handles its financial reporting and related disclosures. It provides an independent layer of oversight over the audit process and, in many organizations, over compliance matters, helping promote transparency and integrity in the numbers the entity reports. The committee oversees these functions on behalf of the board rather than performing the day-to-day financial or accounting work itself.

Formal definition

An audit committee is a committee of an organization's board of directors that is delegated authority to oversee the financial reporting and disclosure process, typically including oversight of the external audit and, depending on the entity, related compliance and internal control processes. As a board-level oversight body, its role is distinct from management, which owns the preparation of financial statements and the operation of controls, and from assurance functions that perform audit work; the committee provides accountability and independent oversight rather than executing operational tasks. Its specific composition, authority, and mandated responsibilities vary by jurisdiction, sector, and entity type (for example, listed companies versus nonprofits), and may be shaped by applicable listing rules, statutes, or governance frameworks not detailed in this evidence.

Why it matters

The audit committee sits at the center of an organization's accountability structure for financial reporting, providing a layer of independent oversight that is distinct from the management team responsible for preparing the numbers. Because the committee oversees the financial reporting and disclosure process on behalf of the full board, it helps promote the transparency and integrity of the information an entity puts before investors, regulators, funders, and other stakeholders. Where financial reporting failures occur, questions about the quality of board-level oversight frequently follow, which is why the committee's role is treated as a cornerstone of good governance.

The committee's value comes precisely from what it does not do: it does not prepare financial statements, operate controls, or execute audit procedures. Those responsibilities belong to management and to assurance functions. Instead, the committee provides accountability and independent oversight, creating a check on management's assertions and a channel through which concerns about financial reporting and, in many organizations, compliance and internal control matters can be surfaced and addressed. This separation of oversight from execution is what gives the committee its credibility.

The committee's specific composition, authority, and mandated responsibilities vary considerably by jurisdiction, sector, and entity type. A listed company's audit committee may be shaped by listing rules and statutes, while a nonprofit may establish either a standing committee or a task force to serve a comparable oversight function. Because these requirements differ, boards should confirm what applies to their own entity rather than assuming a single universal model. This entry is educational and not legal, audit, or compliance advice.

Who it's relevant to

Board members and directors
Directors establish the audit committee and delegate authority to it, and they rely on its oversight to discharge the board's collective accountability for financial reporting. Understanding the committee's scope helps the wider board distinguish oversight that has been delegated to the committee from matters the full board retains.
Audit committee members
Members need clarity on the boundaries of their mandate: overseeing the financial reporting, disclosure, and, in many organizations, compliance and internal control processes, while not taking on management's operational duties or the execution of audit work. Their responsibilities may be shaped by applicable listing rules, statutes, or governance frameworks depending on the entity.
General counsel and compliance officers
In many organizations the committee's oversight extends to compliance matters, making its scope relevant to those responsible for the compliance program. The committee provides an independent board-level channel for oversight, distinct from the day-to-day operation of compliance activities by management.
Management and finance leadership
Management owns the preparation of financial statements and the operation of controls, and interacts with the audit committee as the body that oversees those processes. Recognizing this division of responsibility helps management engage with the committee appropriately without confusing oversight with execution.
Internal auditors and assurance functions
Assurance functions perform audit work, whereas the committee provides oversight of the financial reporting process and the audit relationship. The distinction clarifies reporting lines and reinforces the independence of the oversight the committee provides.
Nonprofit boards
Nonprofits may establish either a standing committee or a task force given authority by the board to provide accountability over financial reporting, compliance, and audit processes. This flexibility means the committee's form and scope should be defined to fit the organization rather than copied from a listed-company model.

Inside Audit Committee

Financial Reporting Oversight
The audit committee typically oversees the integrity of the entity's financial statements and the related reporting process, reviewing significant accounting judgments, estimates, and disclosures with management and the external auditor. This is an oversight role; management remains responsible for preparing the financial statements.
External Auditor Relationship
In many jurisdictions and under various listing rules, the committee is responsible for recommending or overseeing the appointment, remuneration, independence, and performance of the external auditor. The specific scope of this authority varies by jurisdiction, sector, and entity type.
Internal Control and Financial Reporting Controls
The committee generally monitors the effectiveness of internal controls over financial reporting, drawing on assurance from internal audit and management. This involves considering both control design and operating effectiveness, though the committee oversees rather than operates these controls.
Internal Audit Oversight
Where an internal audit function exists, the committee typically oversees its mandate, resourcing, and independence, and reviews its findings. Internal audit generally serves as a third-line assurance function reporting functionally to the committee.
Composition and Independence
Audit committees are commonly composed of non-executive or independent directors, often with a requirement or expectation of financial literacy or relevant financial expertise. Specific independence and qualification requirements depend on applicable listing rules, statutes, and governance codes.
Whistleblowing and Concerns Channels
In many frameworks the committee has responsibility for overseeing arrangements by which staff can raise concerns about financial reporting or related matters. The precise obligation varies by jurisdiction and entity type.

Common questions

Answers to the questions practitioners most commonly ask about Audit Committee.

Does the audit committee prepare the company's financial statements?
No. Preparing the financial statements is a management responsibility, typically owned by the chief financial officer and the finance function. The audit committee's role is one of oversight: it reviews the financial reporting process, discusses significant judgments and estimates with management and the external auditor, and monitors the integrity of the reporting. Confusing oversight with preparation blurs the line between the board's committee and management, and the specific division of duties can vary by jurisdiction, listing rules, and entity type.
Is the audit committee the same as the internal audit function?
No. These are distinct. Internal audit is generally an assurance function within the organization that provides independent evaluation of governance, risk management, and control processes. The audit committee is a board-level committee that provides oversight, commonly including oversight of the internal audit function itself. In many governance models the internal audit function reports functionally to the audit committee, but the committee does not perform the audit work. The two operate in different lines and should not be treated as interchangeable.
How does an audit committee typically oversee the external auditor?
In many jurisdictions and under various listing rules, the audit committee is responsible for overseeing the relationship with the external auditor, which can include matters such as appointment or recommendation for appointment, remuneration, independence, and the scope of the audit. The committee generally reviews audit findings and significant issues directly with the auditor, often including private sessions without management present. The precise powers depend on the applicable legal framework, listing requirements, and the entity's own charter, so committees should confirm their specific mandate.
What does an audit committee usually consider when evaluating internal controls over financial reporting?
The committee typically reviews information about both the design and the operating effectiveness of controls over financial reporting, drawing on reports from management, internal audit, and the external auditor. Design and operating effectiveness are separate concepts: a control may be well designed but not operating as intended, or vice versa. Committees generally focus on significant deficiencies, material weaknesses, and remediation progress. The depth of this responsibility depends on the applicable framework and requirements, which vary by jurisdiction and entity type; this is educational information and not audit or compliance advice.
How can an audit committee maintain the independence needed to be effective?
Independence is generally supported through committee composition, direct reporting lines, and access. Many governance codes and listing rules call for audit committee members to be independent non-executive or outside directors, and some regimes expect relevant financial expertise. Practical measures often include holding private sessions with the external auditor and the head of internal audit, having authority to obtain external advice, and controlling its own agenda. Specific independence and expertise requirements differ across jurisdictions, sectors, and frameworks, so committees should confirm what applies to them.
How does an audit committee's remit relate to the wider risk oversight of the board?
The audit committee's focus is commonly centered on financial reporting, internal control over financial reporting, external and internal audit, and often compliance-related matters, though scope varies by charter and jurisdiction. Broader enterprise risk oversight may sit with the full board or a separate risk committee, particularly in certain sectors such as financial services. It is important not to assume the audit committee owns all risk oversight; boards should define clearly, usually in committee charters, where responsibility for each category of risk sits to avoid gaps or overlaps.

Common misconceptions

The audit committee prepares the financial statements and performs the audit.
The committee performs an oversight function. Management is responsible for preparing the financial statements and maintaining internal controls, and the external auditor is responsible for the independent audit. The committee oversees these parties rather than doing their work.
The audit committee is responsible for all of the organization's risk.
The committee's remit typically centers on financial reporting, related internal controls, and audit matters. Broader enterprise risk oversight may sit with the full board or a separate risk committee, depending on the entity's structure and applicable requirements. Committee mandates vary by jurisdiction and organization.
Every organization is legally required to have an audit committee structured the same way.
Audit committee requirements depend on the entity type, sector, jurisdiction, and listing status. Some are mandated by statute or listing rules, while for other entities they reflect voluntary governance code expectations or best practice. Composition and duties are not uniform across regimes.

Best practices

Maintain a clear written charter or terms of reference that distinguishes the committee's oversight role from management's operational responsibilities and defines its authority over the external and internal auditors.
Confirm that members meet applicable independence and financial literacy or expertise expectations under the relevant listing rules, statutes, or governance code, and refresh membership periodically.
Hold regular private sessions with the external auditor and with internal audit, separate from management, to surface concerns candidly.
Periodically assess external auditor independence, performance, and where relevant tenure or rotation, consistent with applicable requirements in the jurisdiction.
Review significant accounting judgments, estimates, and disclosures with management and the auditor, focusing on areas of higher judgment and control risk.
Oversee whistleblowing and concerns arrangements and follow up on reported matters relevant to financial reporting, documenting how issues are tracked to resolution.