How We Used AI in the Review of an Entity-Level Control: Lessons From a Governance Review of an Audit Committee Charter
- John C. Blackshire, Jr.

- Aug 16
- 9 min read
An Audit Committee Charter Is More Than a Document
An Audit Committee Charter may look like a relatively simple governance document.
But it can function as one of the organization’s most important entity-level controls.
The charter defines how the Audit Committee is expected to oversee areas such as:
Financial reporting
Internal control
Internal Audit
External Audit
Fraud risk
Compliance
Risk management
Corrective action
Communication with management
Escalation of significant issues
That means reviewing an Audit Committee Charter should not be treated as a proofreading exercise.
The real question is:
Is the charter designed well enough to support effective governance and oversight?
In a recent governance project, we used an AI tool as part of a structured review of an
Audit Committee Charter.
The objective was not to let AI decide whether the charter was adequate.
The objective was to use AI to help us analyze the document more systematically, compare provisions, identify potential gaps, challenge our conclusions, and improve the communication of the findings.
The experience produced several important lessons for auditors, Audit Committee members, governance professionals, and organizations considering how AI can support control design reviews.
Start With the Control Objective
Before reviewing individual charter provisions, we first needed to define what the control was supposed to accomplish.
For an Audit Committee Charter, the fundamental objective is not:
“Have an approved charter.”
The objective is much broader.
The charter should create a governance framework that enables the Audit Committee to exercise appropriate oversight over the areas assigned to it.
That may include ensuring that the Committee has sufficient:
Authority
Independence
Information
Access
Responsibility
Escalation mechanisms
Accountability
That distinction is critical.
An organization can have a formally approved charter and still have a poorly designed governance control.
We Treated the Charter as an Entity-Level Control
The review therefore focused on the charter as part of the organization's control environment.
Instead of asking only:
“Does the document contain the right language?”
we asked:
“If the organization follows this charter exactly as written, will the Audit Committee have the authority and responsibilities necessary to provide effective oversight?”
That is a design-effectiveness question.
The approach is the same one an auditor might use when reviewing a transactional control:
Objective
↓
Risk
↓
Control
↓
Design Effectiveness
The difference is that the control operates at the governance level.
Why AI Was Useful
AI was particularly useful in several parts of the review.
It helped us:
Extract and organize charter responsibilities
Group provisions by governance area
Compare related responsibilities
Identify ambiguous wording
Identify possible omissions
Generate questions for further review
Challenge preliminary findings
Rewrite technical observations for an executive audience
But AI did not determine the final conclusions.
The auditor still had to decide:
What criteria were appropriate
Whether a gap actually existed
How significant the issue was
Whether the evidence supported the finding
What corrective action was reasonable
That distinction is fundamental.
AI accelerated the analysis. Professional judgment controlled the conclusion.
Audit Committee Oversight Needs Specificity
One major area of review was whether the charter clearly described the Committee's responsibilities.
Vague language can create weak governance.
For example:
“The Committee will oversee internal controls.”
Sounds reasonable.
But what does that actually mean?
Does the Committee:
Review significant control deficiencies?
Monitor remediation?
Receive reports from Internal Audit?
Discuss material weaknesses with the external auditor?
Review management's assessment of internal control?
Escalate unresolved issues?
A strong charter should provide enough specificity that Committee members understand what they are expected to do.
Internal Audit Oversight Is a Critical Charter Area
The Audit Committee Charter should clearly define its relationship with Internal Audit.
Questions we considered included:
Does the Committee approve or review the Internal Audit Charter?
Does it review the risk-based audit plan?
Does it receive significant audit findings?
Does it monitor corrective actions?
Does it have direct access to the Chief Audit Executive?
Does the CAE have direct access to the Committee?
Can the Committee meet privately with the CAE?
These provisions are important because Audit Committee oversight can be a major safeguard of Internal Audit independence.
If the charter is vague about those responsibilities, the governance design may be weaker than management assumes.
External Audit Responsibilities Also Need Clarity
The Audit Committee generally has significant responsibilities involving the external auditor.
The charter should clearly address areas such as:
Appointment or recommendation of the external auditor
Independence
Audit scope
Significant audit findings
Management disagreements
Internal-control deficiencies
Audit results
Private meetings with the external auditor
Again, the question is not simply whether the word “external audit” appears.
The question is:
Does the charter create an effective oversight mechanism?
Financial Reporting Oversight Should Be Explicit
Another major governance area involves financial reporting.
An Audit Committee should understand its responsibilities regarding:
Significant accounting issues
Financial statement integrity
Management judgments
Estimates
Disclosures
Internal control over financial reporting
The charter should help prevent a situation where everyone assumes someone else owns the oversight responsibility.
Ambiguity is a governance risk.
Fraud Risk Should Not Be Buried
Fraud deserves explicit consideration.
The Audit Committee may need visibility into:
Fraud risk assessment
Significant allegations
Whistleblower activity
Management override
Investigations
Corrective action
If fraud-related responsibilities are vague or absent, that may represent a charter-design weakness.
The Committee does not conduct the investigation itself.
But governance should understand whether management has an effective system for detecting, investigating, escalating, and correcting significant fraud risks.
Risk Oversight Needs Boundaries
Audit Committee charters increasingly include risk responsibilities.
That creates another design question:
What risks belong to the Audit Committee, and what risks belong elsewhere?
The Committee may have responsibilities involving:
Financial reporting risk
Fraud risk
Compliance risk
Internal control risk
Cybersecurity risk
But the charter should avoid creating an impossible mandate where the Audit Committee is nominally responsible for every enterprise risk.
A good governance document should make responsibilities clear enough to prevent both:
Gaps
and
Overlap
Corrective Action Is a Governance Issue
Finding a problem is not enough.
Someone needs to determine whether management fixes it.
The Audit Committee Charter should therefore be evaluated for provisions addressing:
Significant findings
Management responses
Corrective-action status
Overdue actions
Repeat findings
Escalation of unresolved risks
This can be particularly important where management repeatedly delays corrective action.
At some point, the issue moves from operational management into governance.
Escalation Rights Matter
One of the most important questions in a governance review is:
What happens when management and Internal Audit disagree?
Or:
What happens when management refuses to correct a significant risk?
A strong Audit Committee Charter should support escalation of significant unresolved issues.
Otherwise, important risks can remain trapped below the governance level.
The charter should help ensure that the Committee receives information needed to exercise oversight even when the information is uncomfortable.
Private Sessions Can Be an Important Control
The ability of the Audit Committee to meet privately with:
Internal Audit
External Audit
Compliance
Other key assurance functions
can be an important entity-level control.
Why?
Because some information may not emerge when management is in the room.
This is particularly relevant when the issue involves:
Management override
Financial reporting pressure
Scope limitations
Fraud allegations
Auditor independence
Private access helps protect the flow of information to governance.
AI Helped Identify Ambiguity
One useful role for AI was finding language that looked reasonable but was potentially too vague.
Examples of words that may need further analysis include:
“Review”
“Oversee”
“Consider”
“Monitor”
“As appropriate”
These words are not inherently wrong.
But in a governance document, ambiguity can create questions about accountability.
AI can rapidly flag these areas.
The auditor then determines whether the ambiguity represents a real control-design problem.
AI Can Compare Responsibilities Across the Charter
Another useful capability is identifying inconsistencies.
For example:
One section may say the Audit Committee approves the Internal Audit plan.
Another may say management approves it.
That conflict matters.
AI can help identify inconsistencies across a long governance document much faster than manual review alone.
The professional then determines the significance.
AI Can Be Used as a Red-Team Reviewer
One of the strongest uses of AI came after the initial findings were developed.
Instead of asking AI to support our conclusions, we asked it to challenge them.
A useful prompt might be:
“Assume you are management and strongly disagree with this governance finding. Identify weaknesses in the criteria, evidence, consequence, and proposed corrective action.”
That is valuable because auditors can become attached to their findings.
AI can act as an inexpensive skeptical reviewer.
If the finding survives the challenge, it becomes stronger.
If it does not, revise it.
AI Should Identify Missing Evidence
Another useful prompt is:
“What evidence would be required before concluding that this charter provision represents a governance deficiency?”
This can expose situations where the auditor is relying too heavily on an assumption.
That matters because AI can otherwise make a weak argument sound very persuasive.
The evidence boundary still applies.
The Review Used a Finding Structure
Rather than creating a list of comments, the issues were analyzed using a structured finding approach.
Condition: What does the charter currently say?
Criteria: What should an effective governance framework require?
Cause: Why does the gap exist?
Consequence: What governance risk results?
Corrective Action: What should be changed?
This structure helps move the review from:
“We don't like the wording.”
to:
“This provision creates a specific governance risk.”
Design Effectiveness Was the Primary Focus
This is important.
The review was primarily about design effectiveness.
We were asking:
If the Audit Committee follows this charter exactly as written, is the charter capable of producing effective governance?
That is different from asking whether the Committee actually performs its responsibilities.
That second question involves operating effectiveness.
For example: The charter may require quarterly review of significant audit findings.
Design question:
Is quarterly review an appropriate governance control?
Operating question:
Did the Committee actually perform the quarterly reviews?
Both matter.
But they are separate audit questions.
A Perfect Charter Does Not Prove Effective Governance
This is one of the biggest lessons from the project.
An organization can create an excellent charter and still have poor governance.
The Committee may:
Fail to challenge management
Ignore repeat findings
Accept weak explanations
Receive incomplete information
Spend insufficient time on major risks
That means charter review is only one part of governance assessment.
The charter provides the design.
Committee behavior provides the operation.
The Charter Should Reflect the Real Organization
Another important point is that a charter should not simply copy a template.
The organization should consider:
Size
Complexity
Industry
Regulatory environment
Risk profile
Internal Audit structure
External Audit relationships
Governance model
A generic charter may omit responsibilities that matter greatly to a particular organization.
That is why customization matters.
AI Can Help With Benchmarking, But Criteria Must Be Controlled
AI can help compare a charter against:
Professional standards
Governance frameworks
Model charters
Regulatory requirements
But the auditor should control the criteria.
Do not simply ask:
“Is this a good charter?”
Instead:
“Compare this charter with these specific criteria and identify provisions that are missing, ambiguous, or inconsistent.”
That produces a much more defensible result.
Audit Committee Members Should Understand the Findings
Governance reviews should not end with management receiving a marked-up document.
The Audit Committee itself should understand:
What gaps were identified
Why they matter
Which responsibilities are changing
What authority the Committee is accepting
What new information it should expect to receive
The people who will operate the control need to understand the design.
Use a Governance Dashboard
One useful output from this type of review is a governance dashboard summarizing issues by:
Priority
Finding
Governance area
Risk
This allows Audit Committee members to focus on the most important governance gaps rather than working through pages of detailed edits.
Detailed support can remain behind the dashboard.
That is a better executive communication model.
AI Can Improve the Final Report
Once findings are validated, AI can help improve how they are communicated.
For example, it can help:
Reduce excessive words
Improve structure
Convert technical language to governance language
Create executive summaries
Develop alternative finding titles
Build summary tables
But the rule remains:
AI may improve the communication. It does not own the conclusion.
What We Learned From the Project
The project reinforced several important principles:
1. Start with the control objective.
Do not begin with the document wording.
2. Treat the Audit Committee Charter as an entity-level control.
Evaluate whether it creates effective oversight.
3. Separate design from operation.
A good charter and an effective Audit Committee are related but not identical.
4. Use AI to accelerate analysis—not replace judgment.
The auditor still owns the finding.
5. Use AI to challenge conclusions.
Red-team review can improve quality.
6. Focus findings on governance risk.
Do not reduce the project to wordsmithing.
7. Communicate findings at the Audit Committee level.
Governance needs executive-level clarity.
The Broader Lesson for Auditors
This project illustrates a much broader principle.
AI can be extremely valuable during a control-design review when used correctly.
A practical workflow might look like:
Define Objective
↓
Identify Criteria
↓
Provide Controlled Source Documents
↓
Use AI to Extract and Compare
↓
Identify Potential Gaps
↓
Validate With Professional Judgment
↓
Develop Findings
↓
Use AI to Red-Team Findings
↓
Prepare Executive Communication
That is a disciplined use of AI.
It is far more sophisticated than:
“AI, tell me whether this charter is good.”
The Bottom Line
An Audit Committee Charter is not just a document.
It is part of the organization's governance control environment.
The right review asks whether the charter provides enough:
Authority
Independence
Oversight
Information
Escalation
Accountability
to allow the Audit Committee to perform its responsibilities effectively.
AI can make that review faster, more systematic, and more challenging.
But the professional still has to answer the most important question:
Is this charter designed well enough to support effective governance?
That is where audit methodology and AI work best together.
Use the AI to analyze.
Use it to compare.
Use it to challenge.
Use it to improve communication.
But keep the judgment where it belongs:
With the auditor.
The TUSD Audit Committee Charter was reviewed using AI as the starting point for comparing the Approved Charter to established standards. From that initial review the various sections of the below TUSD Audit Committee Charter Review were created by an AI tool and then reviewed by a 50 plus year audit and corporate governance expert. Total time from start to finish about 6 hours. Can a human alone be that productive?
Comments