Audit Committee Charter: What Should Be Included?
A Practical Guide to Building an Effective Audit Committee Charter
An Audit Committee Charter is one of the most important documents in an organization's corporate governance framework.
It establishes the committee's purpose, authority, responsibilities, membership requirements, and relationship with the Board of Directors, management, Internal Audit, and external auditors.
Yet many organizations treat the Audit Committee Charter as an administrative document rather than a critical entity-level internal control.
A charter may be formally approved, posted on the organization's website, and reviewed annually while providing little practical guidance concerning the committee's responsibilities.
The real question is not whether an organization has an Audit Committee Charter.
The question is whether the charter establishes the authority, independence, information access, and accountability necessary for the committee to perform effective oversight.
1. Purpose and Mission of the Audit Committee
The charter should begin with a clear statement of purpose.
The Audit Committee generally assists the Board in overseeing matters such as:
Financial reporting integrity
Internal control effectiveness
External auditor independence and performance
Internal Audit effectiveness
Fraud risk and whistleblower reporting
Regulatory compliance
Risk management responsibilities assigned by the Board
The charter should explain that the committee provides oversight rather than assuming management's operational responsibilities.
Management owns the organization's internal control system. The Audit Committee oversees the responsibilities assigned to it by the Board and applicable requirements.
This distinction should be explicit.
2. Authority Granted by the Board
An effective Audit Committee needs sufficient authority to perform its responsibilities.
The charter should address the committee's authority to:
Obtain relevant information from management.
Meet directly with the CFO and other executives.
Communicate independently with internal and external auditors.
Request investigations of significant concerns.
Obtain advice from independent legal, accounting, or other professionals.
Escalate unresolved matters to the full Board.
Review management's responses to significant findings.
For covered SEC-listed companies, certain authority and funding provisions are established by Exchange Act Rule 10A-3.
For other organizations, the appropriate provisions depend on applicable law and governance arrangements.
An Audit Committee cannot provide meaningful oversight if management controls what information the committee is permitted to receive.
3. Membership, Independence, and Financial Expertise
The charter should establish requirements for committee membership.
These may include:
Independence: Members should be sufficiently independent of management to exercise objective judgment.
Financial literacy: Members should be capable of understanding financial statements, accounting estimates, and internal control issues.
Financial expertise: The committee should have access to appropriate accounting and financial reporting expertise.
Appointment and removal: The charter should identify how members are selected and replaced.
Terms of service: Membership terms and rotation practices should be defined.
Conflicts of interest: Members should disclose relevant conflicts and follow applicable recusal procedures.
Requirements vary among SEC-listed companies, private organizations, financial institutions, nonprofits, and governmental entities.
The charter should reflect the requirements applicable to the organization rather than adopting generic language without modification.
4. Financial Reporting Oversight
Financial reporting oversight should be a central charter responsibility.
The committee should be assigned appropriate responsibilities for reviewing:
Annual financial statements
Interim financial reporting
Significant accounting policies
Material accounting estimates
Significant unusual transactions
Material adjustments and corrections
Financial reporting deficiencies
Going-concern and liquidity considerations
Significant financial statement disclosures
The charter should establish how and when management communicates these matters to the committee.
For organizations with annual regulatory filings, it may be appropriate to require management to provide draft financial reports and explain significant adjustments before submission or Board approval.
A financial reporting oversight responsibility is ineffective if the committee has no established opportunity to examine significant financial reports.
5. Internal Control Oversight
The charter should address oversight of management's internal control framework.
The COSO Internal Control—Integrated Framework provides a useful reference.
Its five components are:
Control Environment
Risk Assessment
Control Activities
Information and Communication
Monitoring Activities
The committee should receive information sufficient to understand significant control risks and deficiencies.
Charter responsibilities may include:
Reviewing management's internal control assessments.
Understanding significant control deficiencies.
Reviewing management's corrective action plans.
Monitoring remediation of high-risk findings.
Evaluating significant changes affecting internal controls.
Understanding controls over financial reporting and compliance.
The charter should also establish procedures for escalating unresolved control deficiencies to the Board.
6. Internal Audit Oversight
A strong Audit Committee Charter should clearly define its relationship with Internal Audit.
Under the IIA's Global Internal Audit Standards, the Board plays an important role in authorizing, positioning, and overseeing the internal audit function.
Depending on the governance structure, the Audit Committee may carry out significant portions of these responsibilities.
Important charter provisions include:
Reviewing and approving the Internal Audit Charter.
Reviewing and approving the risk-based internal audit plan.
Reviewing Internal Audit's budget and resource needs.
Supporting the Chief Audit Executive's organizational independence.
Participating in decisions concerning appointment, removal, and evaluation of the Chief Audit Executive.
Receiving significant internal audit reports.
Monitoring management's corrective actions.
Meeting privately with the Chief Audit Executive.
Reviewing Internal Audit's quality assurance and improvement program.
The charter should establish direct communication between Internal Audit and the committee.
Internal Audit should be able to report significant concerns without inappropriate management interference.
7. External Auditor Oversight
For SEC-listed companies subject to applicable requirements, the Audit Committee has specific responsibilities concerning the independent external auditor.
These include oversight of the auditor's appointment, compensation, retention, independence, and work.
The charter should address:
External auditor selection and evaluation
Auditor independence
Audit scope and significant risks
Significant audit findings
Material accounting disagreements
Audit adjustments
Communications required by applicable auditing standards
Non-audit services and preapproval requirements, where applicable
Private meetings with the external auditor
For public company audits, PCAOB AS 1301 — Communications with Audit Committees establishes important auditor communication requirements.
For governmental entities and other organizations, external audit oversight should reflect applicable laws, contracts, and auditing standards.
8. Risk Management and Fraud Oversight
The charter should identify the risks assigned to the Audit Committee for oversight.
These may include:
Financial reporting risks
Fraud and corruption
Cybersecurity
Regulatory compliance
Third-party risk
Liquidity and financial sustainability
Significant operational risks
Artificial intelligence and technology risks
The Board should clarify which risks are overseen by the Audit Committee and which are assigned to other committees or the full Board.
Fraud-related responsibilities may include oversight of whistleblower procedures, significant allegations, investigations involving senior management, and corrective actions.
The committee should also understand how management assesses the risk of management override of controls.
9. Meetings, Reporting, and Communication
The charter should establish the committee's operating procedures.
These include:
Meeting frequency: How often the committee meets and when additional meetings may be called.
Agenda development: How significant issues are placed on the agenda.
Information delivery: When committee members receive financial reports and supporting materials.
Executive sessions: Opportunities to meet privately with Internal Audit, external auditors, and other relevant parties.
Minutes: Documentation of significant discussions, decisions, and recommendations.
Board reporting: Procedures for communicating findings and unresolved concerns to the full Board.
Follow-up: Responsibility for monitoring outstanding matters.
The charter should support timely communication rather than allowing significant information to be withheld until after decisions have been made.
10. Audit Committee Member Orientation and Training
An effective charter should address how new committee members become familiar with their responsibilities.
Orientation may cover:
The organization's business model and principal risks
Financial reporting requirements
Internal control framework
Audit Committee Charter
Internal Audit Charter
External audit arrangements
Significant outstanding audit findings
Regulatory obligations
Current financial condition
Prior committee minutes and significant decisions
Ongoing education should also be considered.
Audit Committee members need to understand changing risks, accounting standards, cybersecurity threats, fraud schemes, and governance expectations.
A committee cannot exercise effective oversight of risks its members do not understand.
11. Annual Charter Review and Committee Evaluation
The charter should require periodic review.
An annual review is a common governance practice.
The committee should evaluate whether its charter remains appropriate given changes in:
Organizational structure
Regulatory requirements
Financial reporting risks
Internal Audit responsibilities
External audit requirements
Technology
Governance expectations
The committee should also evaluate its own performance.
A useful self-assessment asks whether the committee actually fulfilled its assigned responsibilities.
For example:
Charter responsibility | Performance question |
Financial reporting | Did the committee receive significant financial reports in time for meaningful review? |
Internal controls | Were significant control deficiencies discussed and monitored? |
Internal Audit | Did the committee approve and oversee the risk-based audit plan? |
External Audit | Were audit scope, findings, and independence adequately addressed? |
Risk oversight | Were significant emerging risks communicated? |
Fraud | Were significant allegations and corrective actions appropriately reviewed? |
Board communication | Were material concerns promptly escalated? |
Training | Did members receive appropriate orientation and education? |
The evaluation should identify specific opportunities for improvement.
12. Common Audit Committee Charter Deficiencies
Charters frequently contain weaknesses such as:
Vague descriptions of committee authority.
No explicit right to obtain information.
Unclear responsibilities for financial reporting.
Inadequate Internal Audit independence provisions.
No process for escalating unresolved findings.
No requirements for private meetings with auditors.
Limited attention to fraud and whistleblower matters.
No defined process for reviewing significant financial filings.
No member orientation or continuing education.
No performance evaluation requirement.
Responsibilities that are assigned but never monitored.
A charter can be legally compliant yet still provide an inadequate foundation for effective governance.
13. A Practical Audit Committee Charter Checklist
Before approving or revising a charter, the Board should ask:
Is the committee's purpose clearly defined?
Does the charter establish appropriate authority and independence?
Are membership qualifications addressed?
Are financial reporting responsibilities sufficiently detailed?
Does the committee receive timely information about significant accounting matters?
Are internal control oversight responsibilities clear?
Is Internal Audit's independence appropriately protected?
Are external auditor oversight responsibilities defined?
Are fraud, compliance, and risk oversight responsibilities addressed?
Are meeting, reporting, and escalation procedures established?
Is orientation and ongoing education addressed?
Does the charter require periodic review and performance evaluation?
These questions help determine whether the charter supports meaningful oversight.
The Bottom Line
An Audit Committee Charter should be more than a list of responsibilities copied from another organization's website.
It should establish a practical governance structure that enables the committee to perform its assigned oversight responsibilities.
The charter must define authority, independence, access to information, relationships with auditors, reporting responsibilities, and accountability.
Most importantly, the organization must implement the processes necessary for the committee to fulfill those responsibilities.
An Audit Committee Charter is not effective because the Board approved it. It is effective when the committee has the authority, information, and independence necessary to carry out its duties.

Comments