top of page
Search

How We Used AI in the Review of an Entity-Level Control: Lessons From a Governance Review of an Audit Committee Charter

An Audit Committee Charter Is More Than a Document


An Audit Committee Charter may look like a relatively simple governance document.


But it can function as one of the organization’s most important entity-level controls.


The charter defines how the Audit Committee is expected to oversee areas such as:

  • Financial reporting

  • Internal control

  • Internal Audit

  • External Audit

  • Fraud risk

  • Compliance

  • Risk management

  • Corrective action

  • Communication with management

  • Escalation of significant issues


That means reviewing an Audit Committee Charter should not be treated as a proofreading exercise.


The real question is:

Is the charter designed well enough to support effective governance and oversight?

In a recent governance project, we used an AI tool as part of a structured review of an

Audit Committee Charter.


The objective was not to let AI decide whether the charter was adequate.


The objective was to use AI to help us analyze the document more systematically, compare provisions, identify potential gaps, challenge our conclusions, and improve the communication of the findings.


The experience produced several important lessons for auditors, Audit Committee members, governance professionals, and organizations considering how AI can support control design reviews.


Start With the Control Objective

Before reviewing individual charter provisions, we first needed to define what the control was supposed to accomplish.


For an Audit Committee Charter, the fundamental objective is not:

“Have an approved charter.”

The objective is much broader.


The charter should create a governance framework that enables the Audit Committee to exercise appropriate oversight over the areas assigned to it.


That may include ensuring that the Committee has sufficient:

  • Authority

  • Independence

  • Information

  • Access

  • Responsibility

  • Escalation mechanisms

  • Accountability


That distinction is critical.


An organization can have a formally approved charter and still have a poorly designed governance control.


We Treated the Charter as an Entity-Level Control

The review therefore focused on the charter as part of the organization's control environment.


Instead of asking only:

“Does the document contain the right language?”

we asked:

“If the organization follows this charter exactly as written, will the Audit Committee have the authority and responsibilities necessary to provide effective oversight?”

That is a design-effectiveness question.


The approach is the same one an auditor might use when reviewing a transactional control:

Objective

Risk

Control

Design Effectiveness


The difference is that the control operates at the governance level.


Why AI Was Useful

AI was particularly useful in several parts of the review.


It helped us:

  • Extract and organize charter responsibilities

  • Group provisions by governance area

  • Compare related responsibilities

  • Identify ambiguous wording

  • Identify possible omissions

  • Generate questions for further review

  • Challenge preliminary findings

  • Rewrite technical observations for an executive audience


But AI did not determine the final conclusions.


The auditor still had to decide:

  • What criteria were appropriate

  • Whether a gap actually existed

  • How significant the issue was

  • Whether the evidence supported the finding

  • What corrective action was reasonable


That distinction is fundamental.

AI accelerated the analysis. Professional judgment controlled the conclusion.

Audit Committee Oversight Needs Specificity

One major area of review was whether the charter clearly described the Committee's responsibilities.


Vague language can create weak governance.


For example:

“The Committee will oversee internal controls.”

Sounds reasonable.


But what does that actually mean?


Does the Committee:

  • Review significant control deficiencies?

  • Monitor remediation?

  • Receive reports from Internal Audit?

  • Discuss material weaknesses with the external auditor?

  • Review management's assessment of internal control?

  • Escalate unresolved issues?


A strong charter should provide enough specificity that Committee members understand what they are expected to do.


Internal Audit Oversight Is a Critical Charter Area

The Audit Committee Charter should clearly define its relationship with Internal Audit.


Questions we considered included:

  • Does the Committee approve or review the Internal Audit Charter?

  • Does it review the risk-based audit plan?

  • Does it receive significant audit findings?

  • Does it monitor corrective actions?

  • Does it have direct access to the Chief Audit Executive?

  • Does the CAE have direct access to the Committee?

  • Can the Committee meet privately with the CAE?


These provisions are important because Audit Committee oversight can be a major safeguard of Internal Audit independence.


If the charter is vague about those responsibilities, the governance design may be weaker than management assumes.


External Audit Responsibilities Also Need Clarity

The Audit Committee generally has significant responsibilities involving the external auditor.


The charter should clearly address areas such as:

  • Appointment or recommendation of the external auditor

  • Independence

  • Audit scope

  • Significant audit findings

  • Management disagreements

  • Internal-control deficiencies

  • Audit results

  • Private meetings with the external auditor


Again, the question is not simply whether the word “external audit” appears.


The question is:

Does the charter create an effective oversight mechanism?

Financial Reporting Oversight Should Be Explicit

Another major governance area involves financial reporting.


An Audit Committee should understand its responsibilities regarding:

  • Significant accounting issues

  • Financial statement integrity

  • Management judgments

  • Estimates

  • Disclosures

  • Internal control over financial reporting


The charter should help prevent a situation where everyone assumes someone else owns the oversight responsibility.


Ambiguity is a governance risk.


Fraud Risk Should Not Be Buried

Fraud deserves explicit consideration.


The Audit Committee may need visibility into:

  • Fraud risk assessment

  • Significant allegations

  • Whistleblower activity

  • Management override

  • Investigations

  • Corrective action


If fraud-related responsibilities are vague or absent, that may represent a charter-design weakness.


The Committee does not conduct the investigation itself.


But governance should understand whether management has an effective system for detecting, investigating, escalating, and correcting significant fraud risks.


Risk Oversight Needs Boundaries

Audit Committee charters increasingly include risk responsibilities.


That creates another design question:

What risks belong to the Audit Committee, and what risks belong elsewhere?

The Committee may have responsibilities involving:

  • Financial reporting risk

  • Fraud risk

  • Compliance risk

  • Internal control risk

  • Cybersecurity risk


But the charter should avoid creating an impossible mandate where the Audit Committee is nominally responsible for every enterprise risk.


A good governance document should make responsibilities clear enough to prevent both:

Gaps

and

Overlap


Corrective Action Is a Governance Issue

Finding a problem is not enough.


Someone needs to determine whether management fixes it.


The Audit Committee Charter should therefore be evaluated for provisions addressing:

  • Significant findings

  • Management responses

  • Corrective-action status

  • Overdue actions

  • Repeat findings

  • Escalation of unresolved risks


This can be particularly important where management repeatedly delays corrective action.


At some point, the issue moves from operational management into governance.


Escalation Rights Matter

One of the most important questions in a governance review is:

What happens when management and Internal Audit disagree?

Or:

What happens when management refuses to correct a significant risk?

A strong Audit Committee Charter should support escalation of significant unresolved issues.


Otherwise, important risks can remain trapped below the governance level.


The charter should help ensure that the Committee receives information needed to exercise oversight even when the information is uncomfortable.


Private Sessions Can Be an Important Control

The ability of the Audit Committee to meet privately with:

  • Internal Audit

  • External Audit

  • Compliance

  • Other key assurance functions

can be an important entity-level control.


Why?


Because some information may not emerge when management is in the room.


This is particularly relevant when the issue involves:

  • Management override

  • Financial reporting pressure

  • Scope limitations

  • Fraud allegations

  • Auditor independence


Private access helps protect the flow of information to governance.


AI Helped Identify Ambiguity

One useful role for AI was finding language that looked reasonable but was potentially too vague.


Examples of words that may need further analysis include:

  • “Review”

  • “Oversee”

  • “Consider”

  • “Monitor”

  • “As appropriate”


These words are not inherently wrong.


But in a governance document, ambiguity can create questions about accountability.


AI can rapidly flag these areas.


The auditor then determines whether the ambiguity represents a real control-design problem.


AI Can Compare Responsibilities Across the Charter

Another useful capability is identifying inconsistencies.


For example:

One section may say the Audit Committee approves the Internal Audit plan.


Another may say management approves it.


That conflict matters.


AI can help identify inconsistencies across a long governance document much faster than manual review alone.


The professional then determines the significance.


AI Can Be Used as a Red-Team Reviewer

One of the strongest uses of AI came after the initial findings were developed.


Instead of asking AI to support our conclusions, we asked it to challenge them.


A useful prompt might be:

“Assume you are management and strongly disagree with this governance finding. Identify weaknesses in the criteria, evidence, consequence, and proposed corrective action.”

That is valuable because auditors can become attached to their findings.


AI can act as an inexpensive skeptical reviewer.


If the finding survives the challenge, it becomes stronger.


If it does not, revise it.


AI Should Identify Missing Evidence

Another useful prompt is:

“What evidence would be required before concluding that this charter provision represents a governance deficiency?”

This can expose situations where the auditor is relying too heavily on an assumption.


That matters because AI can otherwise make a weak argument sound very persuasive.


The evidence boundary still applies.


The Review Used a Finding Structure

Rather than creating a list of comments, the issues were analyzed using a structured finding approach.

  • Condition: What does the charter currently say?

  • Criteria: What should an effective governance framework require?

  • Cause: Why does the gap exist?

  • Consequence: What governance risk results?

  • Corrective Action: What should be changed?


This structure helps move the review from:

“We don't like the wording.”

to:

“This provision creates a specific governance risk.”

Design Effectiveness Was the Primary Focus

This is important.


The review was primarily about design effectiveness.


We were asking:

If the Audit Committee follows this charter exactly as written, is the charter capable of producing effective governance?

That is different from asking whether the Committee actually performs its responsibilities.


That second question involves operating effectiveness.


For example: The charter may require quarterly review of significant audit findings.


Design question:

Is quarterly review an appropriate governance control?

Operating question:

Did the Committee actually perform the quarterly reviews?

Both matter.


But they are separate audit questions.


A Perfect Charter Does Not Prove Effective Governance

This is one of the biggest lessons from the project.


An organization can create an excellent charter and still have poor governance.


The Committee may:

  • Fail to challenge management

  • Ignore repeat findings

  • Accept weak explanations

  • Receive incomplete information

  • Spend insufficient time on major risks


That means charter review is only one part of governance assessment.


The charter provides the design.


Committee behavior provides the operation.


The Charter Should Reflect the Real Organization

Another important point is that a charter should not simply copy a template.


The organization should consider:

  • Size

  • Complexity

  • Industry

  • Regulatory environment

  • Risk profile

  • Internal Audit structure

  • External Audit relationships

  • Governance model


A generic charter may omit responsibilities that matter greatly to a particular organization.


That is why customization matters.


AI Can Help With Benchmarking, But Criteria Must Be Controlled

AI can help compare a charter against:

  • Professional standards

  • Governance frameworks

  • Model charters

  • Regulatory requirements


But the auditor should control the criteria.


Do not simply ask:

“Is this a good charter?”

Instead:

“Compare this charter with these specific criteria and identify provisions that are missing, ambiguous, or inconsistent.”

That produces a much more defensible result.


Audit Committee Members Should Understand the Findings

Governance reviews should not end with management receiving a marked-up document.


The Audit Committee itself should understand:

  • What gaps were identified

  • Why they matter

  • Which responsibilities are changing

  • What authority the Committee is accepting

  • What new information it should expect to receive


The people who will operate the control need to understand the design.


Use a Governance Dashboard

One useful output from this type of review is a governance dashboard summarizing issues by:

  • Priority

  • Finding

  • Governance area

  • Risk

This allows Audit Committee members to focus on the most important governance gaps rather than working through pages of detailed edits.


Detailed support can remain behind the dashboard.


That is a better executive communication model.


AI Can Improve the Final Report

Once findings are validated, AI can help improve how they are communicated.


For example, it can help:

  • Reduce excessive words

  • Improve structure

  • Convert technical language to governance language

  • Create executive summaries

  • Develop alternative finding titles

  • Build summary tables


But the rule remains:

AI may improve the communication. It does not own the conclusion.

What We Learned From the Project

The project reinforced several important principles:


1. Start with the control objective.

Do not begin with the document wording.


2. Treat the Audit Committee Charter as an entity-level control.

Evaluate whether it creates effective oversight.


3. Separate design from operation.

A good charter and an effective Audit Committee are related but not identical.


4. Use AI to accelerate analysis—not replace judgment.

The auditor still owns the finding.


5. Use AI to challenge conclusions.

Red-team review can improve quality.


6. Focus findings on governance risk.

Do not reduce the project to wordsmithing.


7. Communicate findings at the Audit Committee level.

Governance needs executive-level clarity.


The Broader Lesson for Auditors

This project illustrates a much broader principle.


AI can be extremely valuable during a control-design review when used correctly.


A practical workflow might look like:

Define Objective

Identify Criteria

Provide Controlled Source Documents

Use AI to Extract and Compare

Identify Potential Gaps

Validate With Professional Judgment

Develop Findings

Use AI to Red-Team Findings

Prepare Executive Communication


That is a disciplined use of AI.


It is far more sophisticated than:

“AI, tell me whether this charter is good.”

The Bottom Line

An Audit Committee Charter is not just a document.


It is part of the organization's governance control environment.


The right review asks whether the charter provides enough:

  • Authority

  • Independence

  • Oversight

  • Information

  • Escalation

  • Accountability

to allow the Audit Committee to perform its responsibilities effectively.


AI can make that review faster, more systematic, and more challenging.


But the professional still has to answer the most important question:

Is this charter designed well enough to support effective governance?

That is where audit methodology and AI work best together.


Use the AI to analyze.


Use it to compare.


Use it to challenge.


Use it to improve communication.


But keep the judgment where it belongs:

With the auditor.

The TUSD Audit Committee Charter was reviewed using AI as the starting point for comparing the Approved Charter to established standards. From that initial review the various sections of the below TUSD Audit Committee Charter Review were created by an AI tool and then reviewed by a 50 plus year audit and corporate governance expert. Total time from start to finish about 6 hours. Can a human alone be that productive?




 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page