Strategic Business Leader · Internal control and management reporting
Audit Committee and Risk Monitoring for ACCA SBL
Updated 11 October 2026 · Fact-checked
An audit committee is a board committee of independent non-executive directors. It oversees financial reporting, internal control, risk monitoring, internal audit and the external auditor, and reports to the board. To answer exam questions, state the duty, apply it to the scenario's weakness, and recommend a specific action.
Understand Audit Committee and Risk Monitoring
A board has a duty to protect shareholders, but executives run the business day to day. That creates a gap. Executives prepare the numbers and design the controls, so someone independent must check them. The audit committee fills that gap.
It is a board committee, normally made up of independent non-executive directors (NEDs). At least one member usually needs recent and relevant financial experience. Independence matters because the committee reviews the work of executives and must not be influenced by them. Many governance codes recommend such a committee, often for listed companies. Check the rules in the scenario rather than assuming one country's code.
The committee does not run the controls. Management owns the controls and risk management. The committee oversees and challenges. Its main areas are:
- Financial reporting: reviewing the integrity of the financial statements and key judgements and estimates.
- Internal control and risk: reviewing the effectiveness of internal control and risk management systems, and the information it receives about risks.
- Internal audit: approving its plan, reviewing its reports, checking its resources and independence, and supporting the appointment or removal of the head of internal audit. Internal audit should have a direct reporting line to the committee.
- External audit: recommending appointment and fees, assessing independence and effectiveness, and agreeing the policy on non-audit services.
- Whistleblowing and fraud: reviewing arrangements for staff to raise concerns in confidence.
The audit committee versus risk committee question comes up often. The audit committee focuses on assurance: are controls and reports reliable? A risk committee focuses on the risks themselves: what risks the company faces, its risk appetite and strategy for managing them. Some companies combine the two, or give risk to the audit committee. Many codes let the audit committee cover risk where no separate committee exists. In the exam, say which structure the scenario shows and whether it works.
For risk monitoring, the committee asks for regular reports from management, internal audit and the risk function. It looks for new risks, breaches of limits, control failures and whether actions are completed. It then reports to the board, which keeps overall responsibility for risk and internal control.
Key rules to remember
- Audit committee composition (typical code position)
- Independent NEDs only; at least one with recent and relevant financial experience
- Exact numbers vary by code. Use the scenario's code if one is given, and do not quote a number you cannot support.
- Oversight chain
- Management designs and operates controls → internal audit tests them → audit committee reviews and challenges → board is responsible
- Use this to show who does what. The board is always ultimately responsible.
- Core responsibilities (memory aid)
- Reporting, Controls and risk, Internal audit, External audit, Whistleblowing
- Five headings to structure any answer on the committee's role.
- Audit committee vs risk committee
- Audit committee = assurance over controls and reporting; Risk committee = risk strategy, appetite and exposure
- Overlap is common. Say so in the answer, and judge it against the company's situation.
How to solve Audit Committee and Risk Monitoring questions
Use this method for any question on the audit committee, internal control oversight or risk monitoring.
- 1Read the requirement and note the verb: explain, evaluate, advise or recommend. This sets the depth of your answer.
- 2Underline the facts in the scenario: who sits on the board, whether a committee exists, how internal audit reports, and any failures or warnings.
- 3State the relevant duty of the committee in one line, such as reviewing internal control effectiveness.
- 4Link the duty to the scenario fact. Say what is wrong or missing, such as an executive on the committee, or internal audit reporting to the finance director.
- 5Give a specific recommendation: change membership, set up direct reporting, require regular risk reports, or review non-audit fees.
- 6Explain the benefit in terms of the scenario: stronger independence, earlier detection of fraud, or greater shareholder confidence.
- 7Add a short balancing point if the verb is evaluate, such as cost, or the risk of the committee becoming a box-ticking exercise.
- 8Check that your answer is written to the right reader, such as a letter or briefing note, to earn professional skills marks.
Quickest way: Duty, fact, fix
When to use it: Use this when time is short and you need a structured answer in a few minutes.
- Write the five duty headings down the page: reporting, controls and risk, internal audit, external audit, whistleblowing.
- Tick the ones the scenario touches.
- For each ticked heading, write one sentence of weakness from the facts and one sentence of fix.
- Close with one line on how the committee reports to the board.
- Spend any spare time on the professional skills requirement, such as a clear opening and a firm recommendation.
Common mistakes in Audit Committee and Risk Monitoring
Saying the audit committee is responsible for the internal control system.
Students mix up oversight with ownership.
Fix: Say management designs and operates controls, the committee reviews their effectiveness, and the board is ultimately responsible.
Listing duties without applying them to the scenario.
Students learn the role as a list and recite it.
Fix: Link each duty to a named fact in the case, then recommend an action.
Treating audit committee and risk committee as the same thing in every case.
They overlap and some firms combine them.
Fix: State the difference in focus: assurance versus risk strategy and appetite. Then note when combining them is acceptable.
Ignoring independence.
Students focus on tasks and forget who performs them.
Fix: Always comment on membership. Executives, or a chair who was recently the finance director, weaken the committee's independence.
Forgetting the external auditor link.
Students think only of internal audit.
Fix: Include auditor appointment, fees, independence and the policy on non-audit services.
Giving generic advice such as 'improve controls'.
Students run short of time and write safe, vague points.
Fix: Name the action, who does it and how often, for example quarterly risk reports to the committee.
Worked examples
Example 1
Zenith Retail plc has an audit committee of three members: two NEDs and the finance director. The head of internal audit reports to the finance director and has not attended a committee meeting in two years. Evaluate the weaknesses in the committee's arrangements and recommend improvements. (8 marks)
Show the solution
- Weakness 1: the finance director sits on the committee. The committee reviews financial reporting and controls that the finance director is responsible for. This is a self-review problem and weakens independence.
- Weakness 2: internal audit reports to the finance director. Its findings can be filtered or softened, so the committee may not see problems with finance or controls.
- Weakness 3: the head of internal audit has no access to the committee. The committee cannot properly review internal audit's plan, resources or findings.
- Recommendation 1: restrict membership to independent NEDs. Appoint at least one with recent and relevant financial experience. The finance director may attend by invitation.
- Recommendation 2: give the head of internal audit a direct reporting line to the committee chair, with regular meetings, including some without management present.
- Recommendation 3: the committee should approve the internal audit plan and review its reports. This improves oversight of controls and risk.
- Balance: the changes may cost more through added NED time and internal audit resources. The benefit is more reliable reporting and greater investor confidence.
Answer: The committee lacks independence because the finance director is a member, and internal audit has no direct access to it. Zenith should use independent NEDs only, with financial expertise, and give internal audit a direct reporting line to the committee chair. The committee should approve the internal audit plan and review its reports. The extra cost is justified by better oversight and investor confidence.
Example 2
The board of Orion Foods has no risk committee. The audit committee receives a risk register once a year from management. A major supplier failure last month caused a stockout that was not on the register. Explain how the audit committee should improve risk monitoring. (6 marks)
Show the solution
- Identify the problem: risk reporting is annual and comes only from management. It is too infrequent and lacks independent challenge. The supplier risk was missed, so the process did not identify emerging risks.
- Improvement 1: require risk reports at every meeting, or at least quarterly, covering new risks, changes in risk levels and breaches of risk limits.
- Improvement 2: obtain input from internal audit, which can test whether the register is complete and whether controls over key suppliers work.
- Improvement 3: ask management to include supplier dependency and key third-party risks, with named owners and actions.
- Improvement 4: challenge management and check that mitigating actions are completed on time.
- Improvement 5: report to the board on the effectiveness of risk monitoring. Consider with the board whether a separate risk committee is needed given the company's risk profile.
- Link to scenario: these steps would give earlier warning of supplier problems and allow contingency plans, such as alternative suppliers.
Answer: The audit committee should move from annual to regular risk reporting, use internal audit to test the risk register, require supplier and third-party risks to be included with owners and actions, and challenge management on mitigation. It should report to the board and advise whether a separate risk committee is warranted. This would give earlier warning of failures like the supplier stockout.
Exam tips
- Always comment on the independence and expertise of the committee members when the scenario gives details of the membership.
- Tie every point to a scenario fact, then make a specific recommendation. Generic lists earn few marks.
- When asked about audit versus risk committee, state the difference in focus, then say whether combining them is acceptable for this company.
- Remember the external auditor: comment on independence, fees and non-audit services where the scenario hints at a conflict.
- Use the format asked for, such as a report to the board, and write a clear conclusion to earn professional skills marks.
Practice questions from Internal control and management reporting
- At Alder Pharma, one finance officer raises purchase orders, receives goods into the system, approves supplier invoices and releases payment…
- Marlow Pharma's internal audit report on a regional plant found weak authorisation of purchases. Management have accepted the finding but ha…
- Dorne Plc's audit committee is reviewing the annual report before board approval. Which activity falls squarely within the committee's role …
- Pelham Pharma is deciding between an in-house internal audit team and outsourcing. The company operates in a highly specialised regulated ar…
- Kestrel Foods plc has no internal audit function. Its board is considering outsourcing internal audit to a professional firm. The board want…
Audit Committee and Risk Monitoring in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Audit Committee and Risk Monitoring: frequently asked questions
What is the main role of the audit committee in ACCA SBL?
It oversees financial reporting, internal control, risk monitoring, internal audit and the external auditor on behalf of the board. It is made up of independent NEDs. It reports to the board, which keeps ultimate responsibility.
What is the difference between an audit committee and a risk committee?
The audit committee focuses on assurance over reporting and controls. A risk committee focuses on the risks the company faces, its risk appetite and its strategy for managing them. Some companies combine the two, so check the scenario.
Who should sit on an audit committee?
Governance codes generally expect independent non-executive directors, with at least one who has recent and relevant financial experience. Executives should not be members, although they may attend by invitation.
Does the audit committee manage internal audit?
No. It oversees internal audit by approving its plan, reviewing its reports and checking its resources and independence. Internal audit should have a direct reporting line to the committee so that it can report freely.