Expectations from Audit Committee and Those Charged With Governance

“Governance is not tested in the calm of routine meetings. It is tested in the one conversation no one wanted to have.”
Consider an Audit Committee that meets every quarter. It has the right composition — independent chair, financially literate members, proper quorum. The statutory and internal auditors present findings. Management responds. The committee notes the discussion. Minutes are drafted, signed, and filed.
On paper, this committee has done everything right.
But ask a different question — did this committee ask a single question this year that management did not already have a prepared answer for? — and the answer, more often than we would like to admit, is no.
That gap — between a committee that functions and a committee that governs — is where this article begins.
I. The Changing Role of the Audit Committee
The Audit Committee’s traditional mandate, which centers on financial reporting, audit findings, and regulatory compliance, has not diminished in any way. It is simply no longer sufficient on its own. Committees today are expected to oversee a far broader and more interconnected risk landscape that includes cybersecurity, fraud, data governance, ESG, business resilience, and the rapid adoption of artificial intelligence. Each of these areas carries financial reporting implications, but each also carries reputational, operational, and strategic consequences that extend well beyond the financial statements.
As responsibilities have expanded, many committees respond by seeking more reports, more presentations, and larger board packs. Yet governance does not improve with information volume. It improves with questioning quality.
A committee that asks, “What is the one thing we should be discussing today that is not on this agenda?” will learn more in one answer than fifty pages of pre-circulated notes. The committee’s greatest value lies not in reviewing what has already happened, but in challenging whether management’s responses remain aligned to strategy, risk appetite, and reporting obligations.
The quality of oversight is rarely determined by the information a committee receives. It is determined by the questions the committee chooses to ask.
This calls for a genuine shift in mindset, moving from reviewing the past to anticipating emerging risk, from receiving conclusions to challenging assumptions, and from merely noting information to actively exercising judgement.
II. Building a Culture of Escalation
A culture of escalation does not emerge by accident. It is built when an Audit Committee makes it clear — through action, not charter — that difficult issues must travel upward unfiltered, undiluted, and on time.
An Audit Committee’s role extends beyond reviewing reports. Its deeper responsibility is to create an environment where difficult issues are surfaced early, challenged openly, and resolved transparently. A simple test illustrates the point: when an auditor flags a significant concern, does it reach the committee as a concern — or as a footnote in a fifty-page board pack that no one interrogates? The answer tells you more about governance quality than any committee charter ever will.
The strongest governance cultures are those where disagreement between the auditor and management is not suppressed but constructively resolved — with the audit committee in the room. This is why private sessions matter. The committee should meet the statutory auditor and the internal auditor separately, without management present. Not as a formality. As a discipline. These are where the real temperature check happens — where an auditor can say what cannot be said with the CFO in the room, where the committee can ask the one question that matters: what are you not being allowed to tell us?
Equally critical is the auditor’s direct access to the Committee Chair — not routed through the CFO, not channelled through the Company Secretary, not subject to management acting as gatekeeper. And the committee must actively seek out what is not being reported. Silence in governance is rarely a sign that nothing is wrong. It is almost always a sign that something is not being said.
An effective Audit Committee Chair creates trust with management, independence with auditors, and openness to challenge. This cannot be mandated through a charter. It must be demonstrated — meeting after meeting — until it becomes the way the organization operates, not just the way it reports.
The expectation from the audit committee is clear: create an environment where bad news travels faster than good news.
The true test of governance is not what reaches the minutes of the meeting, but what reaches the table before it becomes a crisis.
III. Those Charged With Governance (TCWG)
Standards on Auditing require the auditor to identify “Those Charged With Governance” — the persons or bodies responsible for overseeing the entity’s financial reporting process and strategic direction. In practice, this identification is rarely treated as a judgment call. The Audit Committee is assumed to be TCWG, and the assumption is seldom revisited.
A scenario exposes the risk. An auditor identifies a material related-party transaction that raises questions about management integrity. The auditor reports it to the Audit Committee. But the Audit Committee includes members who are themselves related parties to the transaction — or who lack the authority to act on it independently. The matter is noted, discussed briefly, and filed. It never reaches the full Board.
This is not a failure of audit procedure. It is a failure of routing. The auditor communicated to a forum that lacked the independence, the authority, or the willingness to act. The information reached a governance body — but not the right one. And because the auditor treated the Audit Committee as TCWG by default, the question of whether a more appropriate forum existed was never asked.
The lesson is direct: TCWG is not a label to be assumed. It is a judgment to be made — engagement by engagement, matter by matter. The auditor must evaluate whether the forum receiving a significant finding has the mandate to act on it, the independence to challenge management, and the authority to escalate when the matter demands it. Where the gravity of a concern exceeds what the Audit Committee can address — whether due to conflicts of interest, limitations of mandate, or the sheer significance of the issue — the full Board must be informed directly.
IV. The National Financial Reporting Authority (NFRA) Signal
The January 2026 Circular from the National Financial Reporting Authority (NFRA) is the regulatory response to exactly the kind of failures described above. The Circular did not create new obligations. It exposed how poorly the existing ones were being met.
NFRA found that auditors were routinely defaulting to the Audit Committee as TCWG — without evaluating the company’s governance structure, without assessing whether the sub-group had the authority to act, and without considering whether the nature or gravity of a matter demanded that the full Board be informed directly. In some cases, discussions with management executives were being treated as TCWG communication — a practice NFRA called fundamentally inconsistent with the Standards on Auditing. Documentation was perfunctory, and substantial audit matters were being discussed in too little time for meaningful dialogue or course correction.
The Circular’s expectations are precise: communicate early, not at year-end. Escalate to the right forum, not the convenient one. Document a genuine two-way dialogue, not a presentation met with silence. And ensure auditors can reach the Board directly — without management controlling the message.
It also calls on Boards to institutionalize a formal communication framework — moving governance communication from a periodic event to a continuous discipline. The signal is unmistakable: the distance between what the standards require and what practice delivers is now being measured, documented, and enforced.
V. Demonstrate Governance, Do Not Merely Document It
If this article must leave the reader with one takeaway, let it be this:
Documentation should not merely prove that a meeting took place. It should demonstrate that meaningful oversight was exercised. That is the difference between governance and administration.
Five expectations from the Audit Committee and Those Charged With Governance:
- Build and renew your own competence — the landscape changes faster than any induction, and you cannot challenge what you do not understand.
- Ask better questions, not for more reports.
- Make bad news travel faster than good news.
- Guard the auditor’s independence and direct access.
- Documentation should prove that assumptions were challenged and actions followed through — not merely that a meeting took place.
A Reflection
As expectations from regulators and stakeholders continue to evolve, every Audit Committee and every governance body may benefit from asking itself one honest question:
If the most significant matter under our oversight became public tomorrow, could we prove — not merely claim — that it was genuinely challenged, and not simply discussed? That question is not about compliance. It is about confidence — the quiet assurance, that when the difficult question is finally asked, our answer will reflect not just a process that was followed, but a purpose that was served.
[The author can be reached at jinitadharod@gmail.com]