top of page
Search

Audit Committee Responsibilities for Internal Audit: A Practical Guide to Effective Oversight

18 hours ago
8 min read

Why the Audit Committee Is Essential to Internal Audit Independence and Effectiveness


An organization may have an Internal Audit Department, a Chief Audit Executive, an approved Internal Audit Charter, and an annual audit plan.


But none of these elements guarantees that Internal Audit is independent, adequately resourced, or effective.


An essential safeguard is the oversight provided by the Board of Directors, often through its Audit Committee.


Under the Institute of Internal Auditors' (IIA) Global Internal Audit Standards, effective January 9, 2025, the Board has important responsibilities for authorizing, positioning, and overseeing the internal audit function.


Where the Board delegates these responsibilities to its Audit Committee, the committee becomes a critical component of the organization's governance framework.


The Audit Committee should do more than receive Internal Audit reports. It should help ensure that Internal Audit has the authority, independence, resources, and organizational support necessary to fulfill its mandate.


1. Understand the IIA's Global Internal Audit Standards

The Global Internal Audit Standards organize professional internal auditing into five domains:

Domain

Subject

I

Purpose of Internal Auditing

II

Ethics and Professionalism

III

Governing the Internal Audit Function

IV

Managing the Internal Audit Function

V

Performing Internal Audit Services

Domain III is especially relevant to Audit Committees.


It establishes three principles:

  • Principle 6 — Authorized by the Board: The Board establishes, approves, and supports the internal audit mandate.

  • Principle 7 — Positioned Independently: The Board establishes and protects the internal audit function's independence.

  • Principle 8 — Overseen by the Board: The Board provides oversight to ensure the internal audit function is effective.


These principles are supported by specific standards addressing the internal audit mandate, charter, Board and senior management support, organizational independence, Chief Audit Executive qualifications, Board interaction, resources, quality, and external quality assessment.


Although the standards refer to the Board, an Audit Committee may carry out delegated oversight responsibilities, subject to the organization's governance arrangements.


2. Approve and Periodically Review the Internal Audit Charter

The Internal Audit Charter is the foundational document establishing the internal audit function's authority, mandate, organizational position, and responsibilities.


The Audit Committee should review the charter and recommend or approve it as authorized by the Board.


The charter should address:

  • The purpose and mandate of Internal Audit.

  • The authority to access records, personnel, and physical property.

  • Organizational independence and reporting relationships.

  • The scope of internal audit services.

  • The responsibilities of the Chief Audit Executive.

  • The relationship with the Board and senior management.

  • Commitment to the Global Internal Audit Standards.


The charter should be reviewed periodically and updated when organizational circumstances or professional standards change.


A charter is not effective simply because it has been approved. It must provide the authority necessary for Internal Audit to perform its responsibilities without inappropriate interference.


3. Protect Internal Audit Independence

One of the Audit Committee's most important responsibilities is protecting the organizational independence of Internal Audit.


The Chief Audit Executive should have direct access to the Board or Audit Committee and be able to communicate significant concerns without management interference.


The committee should evaluate whether:

  • Management can improperly restrict audit scope.

  • Internal Audit has unrestricted access to relevant information.

  • The Chief Audit Executive can report significant findings directly.

  • Internal Audit is assigned operational responsibilities that impair objectivity.

  • Budget or staffing decisions could compromise independence.

  • Management influences or suppresses audit conclusions.


The Audit Committee should meet privately with the Chief Audit Executive when appropriate.


Private meetings create an opportunity to discuss sensitive concerns that may not be raised in the presence of management.


Internal Audit cannot provide independent assurance if management controls what it may examine or report.


4. Oversee the Appointment and Performance of the Chief Audit Executive

The Audit Committee should have an appropriate role in the selection, evaluation, compensation, and removal of the Chief Audit Executive.


The precise authority depends on the organization's governance structure.


Responsibilities may include:

  • Reviewing qualifications and professional certifications.

  • Participating in candidate interviews.

  • Evaluating professional competence.

  • Assessing independence and objectivity.

  • Reviewing annual performance.

  • Providing input on compensation.

  • Reviewing proposed removal or reassignment.


The Chief Audit Executive must possess the competencies necessary to manage the internal audit function.


These include knowledge of internal auditing, governance, risk management, internal controls, communication, and organizational leadership.


The committee should also evaluate whether the Chief Audit Executive has sufficient authority within the organization to perform the role effectively.


5. Review and Approve the Risk-Based Internal Audit Plan

The annual internal audit plan should be based on an assessment of the organization's significant risks.


Under the Global Internal Audit Standards, the Chief Audit Executive is responsible for developing a risk-based internal audit plan and communicating it to the Board for approval.


The Audit Committee should evaluate whether the plan addresses the organization's principal risks.


Important questions include:

  • Has the organization established an appropriate audit universe?

  • Are significant financial, operational, compliance, and technology risks included?

  • Does the plan address changes in the business?

  • Are fraud risks appropriately considered?

  • Are high-risk areas receiving sufficient audit coverage?

  • Are planned engagements aligned with available resources?

  • Are significant changes to the plan explained?


The committee should challenge plans that appear to emphasize routine audits while overlooking significant emerging risks.


An Internal Audit plan should reflect the organization's risk profile—not simply repeat the prior year's schedule.


6. Evaluate Internal Audit Resources

The Audit Committee should understand whether Internal Audit has adequate resources to fulfill its responsibilities.


Resource considerations include:

  • Staffing: Is the department sufficiently staffed to complete the approved plan?

  • Competency: Do auditors possess the necessary technical knowledge?

  • Technology: Does Internal Audit have appropriate audit software, data analytics capabilities, and access to information?

  • Specialists: Can the department obtain cybersecurity, information technology, valuation, or other specialized expertise when necessary?

  • Budget: Are financial resources sufficient to perform the approved work?


The committee should understand the consequences of resource limitations.


For example, a department may have a well-designed risk-based audit plan but lack sufficient staffing to complete the highest-priority engagements.


In that situation, the committee should ensure that the Board understands the resulting limitations in assurance coverage.


7. Monitor Internal Audit Performance

The Audit Committee should periodically review the internal audit function's performance.


Relevant measures may include:

  • Completion of the approved audit plan.

  • Coverage of significant risks.

  • Timeliness of engagement reporting.

  • Quality of audit findings.

  • Management's acceptance of recommendations.

  • Timeliness of corrective actions.

  • Stakeholder feedback.

  • Internal audit quality assessment results.


Performance measures should not focus exclusively on the number of audits completed.


A department that completes many low-risk engagements while failing to examine critical risks may not be providing effective assurance.


Internal Audit performance should be evaluated based on the quality, relevance, and impact of its work.


8. Review Significant Audit Findings

The Audit Committee should receive timely reports concerning significant internal audit findings.


These may involve:

  • Material weaknesses or significant deficiencies in internal controls.

  • Fraud or suspected misconduct.

  • Regulatory compliance failures.

  • Significant cybersecurity exposures.

  • Financial reporting weaknesses.

  • Ineffective risk management processes.

  • Significant operational inefficiencies.


The committee should understand the underlying causes of findings and the potential consequences for the organization.


Management should explain its proposed corrective actions, responsible personnel, and completion dates.


The committee should also consider whether findings indicate broader weaknesses in the organization's control environment.


9. Hold Management Accountable for Corrective Actions

Internal Audit identifies and evaluates risks and control deficiencies.


Management is responsible for correcting those deficiencies.


The Audit Committee should oversee management's response to significant findings.


An effective corrective action monitoring process should identify:

Element

Audit Committee consideration

Audit finding

What risk or control deficiency was identified?

Root cause

Why did the deficiency occur?

Risk rating

How serious is the exposure?

Management action

What corrective action is planned?

Responsible owner

Who is accountable for implementation?

Target date

When should remediation be completed?

Current status

Is the action completed, overdue, or in progress?

Validation

Has Internal Audit verified the corrective action where appropriate?


The committee should pay particular attention to overdue high-risk findings and repeated deficiencies.


Management should not be permitted to close significant findings merely by asserting that corrective action has occurred.


Appropriate evidence should support closure.


10. Oversee Internal Audit's Quality Assurance and Improvement Program

The Global Internal Audit Standards require a Quality Assurance and Improvement Program (QAIP).


The Audit Committee should receive information about the function's conformance with professional standards and its efforts to improve performance.


Important elements include:

  • Ongoing monitoring of audit quality.

  • Periodic internal assessments.

  • Performance measurement.

  • External quality assessments.

  • Corrective action plans addressing assessment findings.


Under the Global Internal Audit Standards, an external quality assessment must be conducted at least once every five years by a qualified, independent assessor or assessment team.


The committee should review the results and monitor necessary improvements.


A quality assessment should evaluate the internal audit function's actual performance, not simply the existence of policies and procedures.


11. Maintain Effective Communication with the Chief Audit Executive

The Audit Committee should establish regular communication with the Chief Audit Executive.


Communication should address:

  • Significant changes in organizational risks.

  • Internal audit plan progress.

  • Emerging control deficiencies.

  • Significant audit findings.

  • Management's corrective action status.

  • Resource limitations.

  • Restrictions on audit activities.

  • Quality assurance results.

  • Matters requiring Governing Board attention.


The committee should also establish procedures for urgent reporting.


Significant fraud allegations, inappropriate management interference, or major control failures should not wait until the next scheduled quarterly meeting.


12. Understand the Relationship Between Internal Audit and Management

The Audit Committee should maintain a clear understanding of the different responsibilities of management and Internal Audit.


Management owns the organization's risk management and internal control processes.

Internal Audit provides independent assurance and advisory services concerning those processes.


The Audit Committee oversees the internal audit function and the governance responsibilities delegated to it.


This distinction is consistent with the IIA's Three Lines Model.


First Line: Management functions responsible for delivering products and services and managing risks.


Second Line: Functions providing expertise, support, monitoring, and challenge concerning risk-related matters.


Third Line: Internal Audit, providing independent and objective assurance and advice.

Governing Body: The Board and its committees oversee organizational governance and accountability.


The Audit Committee should avoid assigning Internal Audit responsibility for designing or operating the controls it will subsequently evaluate.


Such assignments can impair independence and objectivity.


13. Common Audit Committee Oversight Weaknesses

Common governance weaknesses include:

  • Approving an Internal Audit Charter without periodically reviewing it.

  • Failing to protect the Chief Audit Executive's independence.

  • Accepting an audit plan without evaluating risk coverage.

  • Ignoring staffing or resource limitations.

  • Receiving audit reports without discussing significant findings.

  • Failing to monitor overdue corrective actions.

  • Allowing management to restrict audit scope.

  • Failing to review Internal Audit quality assessment results.

  • Evaluating Internal Audit only by the number of audits completed.

  • Failing to establish direct communication with the Chief Audit Executive.


These weaknesses can significantly reduce the value of the internal audit function.


14. A Practical Audit Committee Oversight Checklist

Audit Committee members should periodically ask:

  1. Is the Internal Audit Charter current and appropriately approved?

  2. Does Internal Audit have sufficient organizational independence?

  3. Can the Chief Audit Executive communicate directly with the committee?

  4. Has the committee evaluated the Chief Audit Executive's qualifications and performance?

  5. Has the committee reviewed the risk-based audit plan?

  6. Does the plan cover the organization's significant risks?

  7. Are Internal Audit's resources adequate?

  8. Are significant findings reported promptly?

  9. Are overdue corrective actions being monitored?

  10. Are restrictions on audit scope disclosed?

  11. Is the QAIP operating effectively?

  12. Has the required external quality assessment been completed?

  13. Does the committee meet privately with the Chief Audit Executive?

  14. Are significant unresolved issues escalated to the Board?


The answers provide a useful starting point for evaluating whether the committee is exercising effective oversight.


The Bottom Line

An Audit Committee's responsibility for Internal Audit extends far beyond receiving periodic audit reports.


The committee should help establish and protect the internal audit function's mandate, independence, resources, performance, and quality.


It should review the risk-based audit plan, evaluate significant findings, monitor management's corrective actions, and ensure that important concerns reach the Board.


Most importantly, it should establish a governance environment in which Internal Audit can perform its responsibilities without inappropriate interference.


An effective Audit Committee does not manage Internal Audit engagements. It ensures that Internal Audit is independent, competent, adequately resourced, and accountable for delivering meaningful assurance.


Organizations that treat Audit Committee oversight as a continuous governance responsibility are better positioned to identify risks, strengthen internal controls, and improve accountability.


 
 
 

Recent Posts

See All
Audit Committee Charter: What Should Be Included?

A Practical Guide to Building an Effective Audit Committee Charter An Audit Committee Charter is one of the most important documents in an organization's corporate governance framework. It establishes

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

​

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

​

National Registry of CPE Sponsors ID #108983

​

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366; davem@cseminars.com) and/ or John Blackshire (479-200-4373; johnb@cseminars.com)

 

​

bottom of page