Audit Committee
Definition
A sub-committee of the board of directors composed principally of independent non-executive directors, responsible for overseeing financial reporting, internal controls, and the internal and external audit functions. The forensic auditor's primary reporting line in most corporate governance frameworks.
- Position
- Sub-committee of the board of directors
- Composition
- Principally independent non-executive directors
- Oversees
- Financial reporting, internal controls, audit functions
- Role for forensic auditor
- Primary reporting line
Common questions
Why does a forensic auditor report to the audit committee rather than to management?+
Reporting to a committee composed mainly of independent directors preserves the independence of the finding, particularly important when the investigation concerns senior management, since reporting through the ordinary management chain could create a conflict of interest.
What is the practical difference between the audit committee and the external auditor?+
The audit committee is an internal governance body drawn from the board that oversees both internal and external audit work, while the external auditor is an independent firm engaged to opine on the financial statements; the committee typically appoints and liaises with the external auditor.
Does every organisation have an audit committee?+
Publicly listed companies in most jurisdictions are required to maintain one under stock exchange or corporate governance rules, while smaller private companies may combine the function into full board oversight or omit a formal committee entirely.
Related terms
- Attorney-Client Privilege (Legal Professional Privilege)
- A legal protection that prevents compelled disclosure of confidential communications between a lawyer and their client. In forensic audit engagements structured as...
- CISO (Chief Information Security Officer)
- The senior executive responsible for developing and maintaining the information security programme. The CISO reports to the board or a board committee...
- First-Line Controls
- Controls owned and operated by the business units and IT functions that process or store information. The first line is accountable for...
- Flash Report (Preliminary Oral Briefing)
- An interim communication to the audit committee or board during an active investigation, before the formal written report is ready. Used when...
- Management Override
- The circumvention of established internal controls by members of senior management. A key fraud risk in any organisation because those who set...
- Second-Line Oversight
- The risk management and compliance functions, including the CISO office and the risk function, that set policy, monitor control effectiveness across the...
- Security Steering Committee
- A cross-functional management body, typically chaired by the CISO or Chief Risk Officer, that coordinates security priorities across business units, approves major...
- Three Lines of Defence
- A governance model that separates security responsibility into three distinct layers: operational management that owns controls (first line), risk and compliance functions...
- Whistleblower Channel
- A mechanism for individuals to report suspected misconduct to the audit committee or board directly, bypassing management. Required under SOX in the...
- Work-Product Doctrine
- A rule protecting materials prepared by or for an attorney in anticipation of litigation. It is broader than attorney-client privilege and covers...
Explained in these topics
- Presenting Findings to Management and Audit Committees
- Security Governance Structures and RolesA sub-committee of the board, composed largely of independent non-executive directors, that oversees financial reporting, internal controls, and risk managemen...