top of page
Search

Audit Committee Charter: What Should Be Included?

2 days ago
7 min read

A Practical Guide to Building an Effective Audit Committee Charter

An Audit Committee Charter is one of the most important documents in an organization's corporate governance framework.


It establishes the committee's purpose, authority, responsibilities, membership requirements, and relationship with the Board of Directors, management, Internal Audit, and external auditors.


Yet many organizations treat the Audit Committee Charter as an administrative document rather than a critical entity-level internal control.


A charter may be formally approved, posted on the organization's website, and reviewed annually while providing little practical guidance concerning the committee's responsibilities.


The real question is not whether an organization has an Audit Committee Charter.


The question is whether the charter establishes the authority, independence, information access, and accountability necessary for the committee to perform effective oversight.


1. Purpose and Mission of the Audit Committee

The charter should begin with a clear statement of purpose.


The Audit Committee generally assists the Board in overseeing matters such as:

  • Financial reporting integrity

  • Internal control effectiveness

  • External auditor independence and performance

  • Internal Audit effectiveness

  • Fraud risk and whistleblower reporting

  • Regulatory compliance

  • Risk management responsibilities assigned by the Board


The charter should explain that the committee provides oversight rather than assuming management's operational responsibilities.


Management owns the organization's internal control system. The Audit Committee oversees the responsibilities assigned to it by the Board and applicable requirements.


This distinction should be explicit.


2. Authority Granted by the Board

An effective Audit Committee needs sufficient authority to perform its responsibilities.


The charter should address the committee's authority to:

  • Obtain relevant information from management.

  • Meet directly with the CFO and other executives.

  • Communicate independently with internal and external auditors.

  • Request investigations of significant concerns.

  • Obtain advice from independent legal, accounting, or other professionals.

  • Escalate unresolved matters to the full Board.

  • Review management's responses to significant findings.


For covered SEC-listed companies, certain authority and funding provisions are established by Exchange Act Rule 10A-3.


For other organizations, the appropriate provisions depend on applicable law and governance arrangements.


An Audit Committee cannot provide meaningful oversight if management controls what information the committee is permitted to receive.


3. Membership, Independence, and Financial Expertise

The charter should establish requirements for committee membership.


These may include:

  • Independence: Members should be sufficiently independent of management to exercise objective judgment.

  • Financial literacy: Members should be capable of understanding financial statements, accounting estimates, and internal control issues.

  • Financial expertise: The committee should have access to appropriate accounting and financial reporting expertise.

  • Appointment and removal: The charter should identify how members are selected and replaced.

  • Terms of service: Membership terms and rotation practices should be defined.

  • Conflicts of interest: Members should disclose relevant conflicts and follow applicable recusal procedures.


Requirements vary among SEC-listed companies, private organizations, financial institutions, nonprofits, and governmental entities.


The charter should reflect the requirements applicable to the organization rather than adopting generic language without modification.


4. Financial Reporting Oversight

Financial reporting oversight should be a central charter responsibility.


The committee should be assigned appropriate responsibilities for reviewing:

  • Annual financial statements

  • Interim financial reporting

  • Significant accounting policies

  • Material accounting estimates

  • Significant unusual transactions

  • Material adjustments and corrections

  • Financial reporting deficiencies

  • Going-concern and liquidity considerations

  • Significant financial statement disclosures


The charter should establish how and when management communicates these matters to the committee.


For organizations with annual regulatory filings, it may be appropriate to require management to provide draft financial reports and explain significant adjustments before submission or Board approval.


A financial reporting oversight responsibility is ineffective if the committee has no established opportunity to examine significant financial reports.


5. Internal Control Oversight

The charter should address oversight of management's internal control framework.


The COSO Internal Control—Integrated Framework provides a useful reference.


Its five components are:

  1. Control Environment

  2. Risk Assessment

  3. Control Activities

  4. Information and Communication

  5. Monitoring Activities


The committee should receive information sufficient to understand significant control risks and deficiencies.


Charter responsibilities may include:

  • Reviewing management's internal control assessments.

  • Understanding significant control deficiencies.

  • Reviewing management's corrective action plans.

  • Monitoring remediation of high-risk findings.

  • Evaluating significant changes affecting internal controls.

  • Understanding controls over financial reporting and compliance.


The charter should also establish procedures for escalating unresolved control deficiencies to the Board.


6. Internal Audit Oversight

A strong Audit Committee Charter should clearly define its relationship with Internal Audit.


Under the IIA's Global Internal Audit Standards, the Board plays an important role in authorizing, positioning, and overseeing the internal audit function.


Depending on the governance structure, the Audit Committee may carry out significant portions of these responsibilities.


Important charter provisions include:

  • Reviewing and approving the Internal Audit Charter.

  • Reviewing and approving the risk-based internal audit plan.

  • Reviewing Internal Audit's budget and resource needs.

  • Supporting the Chief Audit Executive's organizational independence.

  • Participating in decisions concerning appointment, removal, and evaluation of the Chief Audit Executive.

  • Receiving significant internal audit reports.

  • Monitoring management's corrective actions.

  • Meeting privately with the Chief Audit Executive.

  • Reviewing Internal Audit's quality assurance and improvement program.


The charter should establish direct communication between Internal Audit and the committee.


Internal Audit should be able to report significant concerns without inappropriate management interference.


7. External Auditor Oversight

For SEC-listed companies subject to applicable requirements, the Audit Committee has specific responsibilities concerning the independent external auditor.


These include oversight of the auditor's appointment, compensation, retention, independence, and work.


The charter should address:

  • External auditor selection and evaluation

  • Auditor independence

  • Audit scope and significant risks

  • Significant audit findings

  • Material accounting disagreements

  • Audit adjustments

  • Communications required by applicable auditing standards

  • Non-audit services and preapproval requirements, where applicable

  • Private meetings with the external auditor


For public company audits, PCAOB AS 1301 — Communications with Audit Committees establishes important auditor communication requirements.


For governmental entities and other organizations, external audit oversight should reflect applicable laws, contracts, and auditing standards.


8. Risk Management and Fraud Oversight

The charter should identify the risks assigned to the Audit Committee for oversight.


These may include:

  • Financial reporting risks

  • Fraud and corruption

  • Cybersecurity

  • Regulatory compliance

  • Third-party risk

  • Liquidity and financial sustainability

  • Significant operational risks

  • Artificial intelligence and technology risks


The Board should clarify which risks are overseen by the Audit Committee and which are assigned to other committees or the full Board.


Fraud-related responsibilities may include oversight of whistleblower procedures, significant allegations, investigations involving senior management, and corrective actions.


The committee should also understand how management assesses the risk of management override of controls.


9. Meetings, Reporting, and Communication

The charter should establish the committee's operating procedures.


These include:

  • Meeting frequency: How often the committee meets and when additional meetings may be called.

  • Agenda development: How significant issues are placed on the agenda.

  • Information delivery: When committee members receive financial reports and supporting materials.

  • Executive sessions: Opportunities to meet privately with Internal Audit, external auditors, and other relevant parties.

  • Minutes: Documentation of significant discussions, decisions, and recommendations.

  • Board reporting: Procedures for communicating findings and unresolved concerns to the full Board.

  • Follow-up: Responsibility for monitoring outstanding matters.


The charter should support timely communication rather than allowing significant information to be withheld until after decisions have been made.


10. Audit Committee Member Orientation and Training

An effective charter should address how new committee members become familiar with their responsibilities.


Orientation may cover:

  • The organization's business model and principal risks

  • Financial reporting requirements

  • Internal control framework

  • Audit Committee Charter

  • Internal Audit Charter

  • External audit arrangements

  • Significant outstanding audit findings

  • Regulatory obligations

  • Current financial condition

  • Prior committee minutes and significant decisions


Ongoing education should also be considered.


Audit Committee members need to understand changing risks, accounting standards, cybersecurity threats, fraud schemes, and governance expectations.


A committee cannot exercise effective oversight of risks its members do not understand.


11. Annual Charter Review and Committee Evaluation

The charter should require periodic review.


An annual review is a common governance practice.


The committee should evaluate whether its charter remains appropriate given changes in:

  • Organizational structure

  • Regulatory requirements

  • Financial reporting risks

  • Internal Audit responsibilities

  • External audit requirements

  • Technology

  • Governance expectations


The committee should also evaluate its own performance.


A useful self-assessment asks whether the committee actually fulfilled its assigned responsibilities.


For example:

Charter responsibility

Performance question

Financial reporting

Did the committee receive significant financial reports in time for meaningful review?

Internal controls

Were significant control deficiencies discussed and monitored?

Internal Audit

Did the committee approve and oversee the risk-based audit plan?

External Audit

Were audit scope, findings, and independence adequately addressed?

Risk oversight

Were significant emerging risks communicated?

Fraud

Were significant allegations and corrective actions appropriately reviewed?

Board communication

Were material concerns promptly escalated?

Training

Did members receive appropriate orientation and education?

The evaluation should identify specific opportunities for improvement.


12. Common Audit Committee Charter Deficiencies

Charters frequently contain weaknesses such as:

  • Vague descriptions of committee authority.

  • No explicit right to obtain information.

  • Unclear responsibilities for financial reporting.

  • Inadequate Internal Audit independence provisions.

  • No process for escalating unresolved findings.

  • No requirements for private meetings with auditors.

  • Limited attention to fraud and whistleblower matters.

  • No defined process for reviewing significant financial filings.

  • No member orientation or continuing education.

  • No performance evaluation requirement.

  • Responsibilities that are assigned but never monitored.


A charter can be legally compliant yet still provide an inadequate foundation for effective governance.


13. A Practical Audit Committee Charter Checklist

Before approving or revising a charter, the Board should ask:

  1. Is the committee's purpose clearly defined?

  2. Does the charter establish appropriate authority and independence?

  3. Are membership qualifications addressed?

  4. Are financial reporting responsibilities sufficiently detailed?

  5. Does the committee receive timely information about significant accounting matters?

  6. Are internal control oversight responsibilities clear?

  7. Is Internal Audit's independence appropriately protected?

  8. Are external auditor oversight responsibilities defined?

  9. Are fraud, compliance, and risk oversight responsibilities addressed?

  10. Are meeting, reporting, and escalation procedures established?

  11. Is orientation and ongoing education addressed?

  12. Does the charter require periodic review and performance evaluation?


These questions help determine whether the charter supports meaningful oversight.


The Bottom Line

An Audit Committee Charter should be more than a list of responsibilities copied from another organization's website.


It should establish a practical governance structure that enables the committee to perform its assigned oversight responsibilities.


The charter must define authority, independence, access to information, relationships with auditors, reporting responsibilities, and accountability.


Most importantly, the organization must implement the processes necessary for the committee to fulfill those responsibilities.


An Audit Committee Charter is not effective because the Board approved it. It is effective when the committee has the authority, information, and independence necessary to carry out its duties.


 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

​

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

​

National Registry of CPE Sponsors ID #108983

​

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366; davem@cseminars.com) and/ or John Blackshire (479-200-4373; johnb@cseminars.com)

 

​

bottom of page