
Serving on an audit committee can be challenging because of the sheer breadth of corporate functions the committee is required to oversee. Still, an effective audit committee plays an essential role in helping the company stay within the boundaries of regulatory obligations and avoid fines, penalties, and loss of trust from stakeholders.
One day you may be overseeing financial reporting, and the next, you’re participating in an internal investigation. Whatever the day brings, it’s important to know these six critical auditing areas that will help the company maintain its integrity and keep moving in the right direction:
Let’s take a closer look at each of these critical areas of focus for audit committees, why they matter, and what audit committee members need to focus on as they examine each space.
First, all directors on the audit committee should understand the financial reporting process, including:
The committee also needs to review actual filings and approve the earnings release.
Audit committees need to be actively engaged in reviewing non-GAAP (generally accepted accounting principles) measures.
Their main job is to understand how, when, and why management uses these measures in performance evaluation, financial reporting, and internal decision-making.
The audit committee should also work to understand tax fundamentals, including how the tax group is organized, who it reports to, and how it functions with other parts of the company. Additionally, the committee should know how tax addresses competing priorities, strategic business changes, transformation efforts, talent management, and third-party resources when special expertise is needed.
To get the most out of an internal audit, the audit committee needs to ensure that:
The person in this CAO role should also be part of any appropriate management leadership committees, and management should be held accountable for implementing internal audit recommendations in a timely fashion. Finally, all reporting lines should encourage and promote objectivity to ensure the internal audit’s success.
The external auditor’s role is to help ensure integrity in the company’s financial reporting. The audit committee is responsible for appointing, compensating, and overseeing the external auditor’s work.
For this reason, it’s vital that the audit committee build a strong working relationship with the external auditor by:
The audit committee also needs to ensure that its proxy statement disclosures include information about how it assesses external auditor performance and fulfills its oversight role.
Today’s companies face a wide range of business risks. Though risk management oversight is the job of the audit committee, it’s important for the entire board to be involved and bring their diverse skills and backgrounds to the table.
Beyond that, good risk management should always be viewed from the perspective of various stakeholders and assessed in line with the company’s long-term strategy.
As companies face uncertainty, it’s critical that the board and audit committees have a firm grasp on:
With cyber threats rising and 75% of U.S. CEOs concerned about it, audit committees need to be focused as intensely on data breach response as they are on prevention. A few tips to help audit committees accomplish that goal include:
No matter who takes on the task of cybersecurity oversight, enlist the help and advice of experts who can properly assess the effectiveness of your program and ensure maximum protection throughout the business.
ESG concerns are more than just a hot news topic. Large institutional investors are now starting to make critical decisions based on corporate transparency. Regulators are also entering the conversation to discuss how to hold companies accountable for their sustainability efforts.
As audit committees and boards figure out how to draft investor-grade ESG enclosures, they must develop ESG metrics that are value drivers for the company and material to its operations and performance. The audit committee’s financial reporting expertise can help determine whether the company’s internal controls are good enough to ensure data accuracy.
The audit committee should also consider the most appropriate method for making ESG disclosures. As the committee inquires about management’s ESG-related procedures, it’s important to discover the company’s current ESG risks and opportunities, the frameworks or standards being used, and the way the company responds to the requests of key stakeholders and regulators.
To properly handle an internal investigation or unexpected crisis, the audit committee needs to know whether the issue is serious enough to warrant an investigation or coordinated response. If so, the committee should take the following actions:
Once the investigation is complete, the committee should consider its remediation plan to reduce the chances that the same type of incident will occur in the future.
Audit committees are indeed responsible for a lot. Financial reporting, internal and external audits, risk management, cybersecurity, ESG reporting, and crisis response are all critical areas that can make or break a company.
In dealing with it all, the audit committee must understand the company’s current processes, get the information it needs to make tough decisions, and maintain open lines of communication with investors and key players. While it will never be an easy job, keeping those goals front and center will help committee members maximize their effectiveness and do the best job of keeping the company on track.
Fill out the email request form to learn more about our approach.