Loading Events

« All Events

Enhancing the Effectiveness of Board Audit and Risk Committees: Strengthening Oversight, Governance and Strategic Risk Management

October 19 @ 8:00 AM - October 23 @ 5:00 PM
$3500

Background

Board Audit and Risk Committees occupy a position of direct consequence within the governance structure of an organisation. Their responsibilities extend beyond the review of financial statements, internal audit reports and periodic risk schedules. They are required to determine whether management has established adequate systems for preserving assets, producing reliable financial and non-financial information, complying with applicable obligations and maintaining risks within approved limits. Failures in these areas are rarely caused by the complete absence of policies. They commonly arise from weak committee enquiry, incomplete reporting, poor escalation, fragmented assurance responsibilities, untested management assumptions and insufficient attention to the conditions underlying reported results.

 

The quality of committee oversight depends upon the precision with which members interpret financial reporting judgements, risk concentrations, control deficiencies, audit findings, capital exposures, liquidity pressures, contractual obligations, technology dependencies and management conduct. Audit Committees must distinguish accounting compliance from faithful financial representation, while Risk Committees must determine whether risk appetite, capital capacity, strategic ambition and operating practice remain properly connected. Where these committees operate separately, their mandates must still converge around significant matters such as impairment, provisioning, fraud, cyber exposure, third-party dependence, regulatory breaches, business continuity, misconduct, major investments and the reliability of management information.

 

Therefore, this global programme is designed to provide a rigorous examination of the authorities, methods, information requirements and decision processes required for effective Audit and Risk Committee performance. It addresses committee composition, mandate design, financial reporting oversight, internal and external audit, enterprise risk governance, control assurance, technology risk, crisis preparedness, conduct, capital protection and committee accountability. The programme participants will work with committee papers, risk reports, audit findings, financial disclosures, assurance maps, scenario results and escalation records in order to test whether the evidence presented to the Board is sufficient, accurate, timely and capable of supporting defensible decisions.

 

Target Audience

  • Board and Committee Leadership
  • Board Chairpersons
  • Independent Non-Executive Directors
  • Executive Directors
  • Audit Committee Chairpersons and Members
  • Board Risk Committee Chairpersons and Members
  • Combined Audit and Risk Committee Members
  • Finance, Investment and Compliance Committee Members

 

  • Senior Executive Management
  • Chief Executive Officers and Managing Directors
  • Deputy Managing Directors
  • Chief Operating Officers
  • Chief Financial Officers
  • Chief Risk Officers
  • Chief Audit Executives
  • Chief Compliance Officers
  • Chief Information and Technology Officers
  • Chief Information Security Officers
  • Company Secretaries and Heads of Board Governance
  • External Audit Partners and Senior Assurance Professionals

 

 

Learning Outcomes

At the end of the programme, participants will be able to:

  • Evaluate the adequacy of Audit and Risk Committee mandates, membership, information flows and decision processes against the organisation’s governance obligations and risk profile.
  • Interrogate financial statements, audit findings, risk reports, control assessments and management representations with greater technical precision.
  • Assess whether enterprise risks, internal controls, assurance arrangements, capital resources and recovery capabilities are sufficient to support the organisation’s strategic commitments.
  • Direct corrective action, escalation, independent investigation and Board reporting where financial, operational, regulatory, technology or conduct concerns exceed acceptable limits.

 

Learning Objectives

The programme is designed to enable participants to:

  • Examine the legal, fiduciary and governance responsibilities assigned to Board Audit and Risk Committees across different organisational structures.
  • Apply structured methods for reviewing financial reporting judgements, internal controls, audit quality, risk appetite, capital exposure and regulatory compliance.
  • Determine the reliability, completeness and decision value of information submitted by management, internal audit, external audit and specialist assurance functions.
  • Establish clear procedures for addressing control failures, management override, unresolved audit matters, significant risk events and weaknesses in executive accountability.
  • Develop practical Committee Effectiveness Plans supported by work programmes, reporting standards, escalation rules, performance measures and periodic independent evaluation.

 

Programme Focused Areas

 

Legal Authority, Fiduciary Duties and Committee Mandate Architecture

  • Board delegation, reserved matters and committee decision rights
  • Fiduciary duties of care, loyalty, diligence and good faith
  • Differences between Audit, Risk and combined committee mandates
  • Committee authority to obtain information, advice and independent assurance
  • Relationship between committee recommendations and full Board responsibility
  • Regulatory expectations across listed, regulated and public-interest entities
  • Personal exposure arising from neglect, acquiescence or uninformed approval
  • Management attendance, executive access and private committee sessions
  • Committee charter design, annual review and mandate sufficiency
  • Treatment of conflicts of interest and related-party matters
  • Documentation standards for challenge, dissent and resolution
  • Conditions requiring direct reporting to regulators or shareholders

 

Financial Reporting Oversight and the Examination of Management Judgement

  • Audit Committee responsibility for financial statement integrity
  • Revenue recognition and the risk of premature or unsupported income
  • Asset valuation, impairment, provisioning and expected-loss assumptions
  • Fair value measurements and the use of management models
  • Going-concern assessment and material uncertainty disclosures
  • Off-balance-sheet commitments and contingent liabilities
  • Related-party transactions and transfer-pricing concerns
  • Accounting estimates, bias indicators and estimation uncertainty
  • Significant unusual transactions and period-end adjustments
  • Segment reporting and concealment of underperforming operations
  • Non-financial information connected to financial disclosures
  • Committee review of management representation letters

 

External Audit Quality, Independence and Significant Audit Matters

  • Auditor appointment, reappointment, rotation and removal
  • Assessment of competence, industry knowledge and engagement capacity
  • Audit scope, materiality and significant risk determination
  • Auditor independence and prohibited non-audit services
  • Evaluation of proposed audit fees and resource adequacy
  • Key audit matters and unresolved differences with management
  • Treatment of corrected and uncorrected misstatements
  • Review of control deficiencies reported by the external auditor
  • Private sessions between the Committee and the audit partner
  • Assessment of audit evidence and professional scepticism
  • Group audit arrangements and component auditor reliance
  • Annual external audit effectiveness assessment
  • Case study: The Profitable Group with Weak Earnings Quality

 

Internal Control Architecture and Management Accountability

  • Control environment and the influence of executive conduct
  • Entity-level, process-level and transaction-level controls
  • Preventive, detective, corrective and compensating controls
  • Financial, operational, compliance and information controls
  • Delegated authorities and segregation of incompatible duties
  • Management override and senior executive exceptions
  • Control ownership and first-line management responsibility
  • Control documentation, testing and certification
  • Deficiency classification by likelihood, consequence and pervasiveness
  • Recurring control failures and ineffective remediation
  • Internal control statements included in annual reports
  • Committee assessment of material control weaknesses

 

Internal Audit Independence, Planning and Assurance Reliability

  • Functional and administrative reporting arrangements
  • Appointment, appraisal and removal of the Chief Audit Executive
  • Approval of the internal audit charter and annual plan
  • Risk-based audit planning and coverage determination
  • Internal audit access to records, systems, personnel and premises
  • Restrictions imposed by management and their consequences
  • Quality of audit evidence, findings and root-cause analysis
  • Rating of audit issues and management action plans
  • Overdue findings, repeated exceptions and risk acceptance
  • Internal audit resources, specialist skills and technology capability
  • Independent quality assessment of the internal audit function
  • Private communication between the Committee and Internal Audit

 

Assurance Mapping, Control Testing and the Prevention of Assurance Gaps

  • Construction of an enterprise assurance universe
  • Allocation of assurance responsibilities across control functions
  • Identification of duplicate reviews and unexamined risk areas
  • Distinction between management confirmation and independent assurance
  • Evaluation of assurance provider competence and objectivity
  • Assurance coverage of subsidiaries, joint ventures and outsourced operations
  • Use of control self-assessments and management attestations
  • Specialist assurance over models, valuations, technology and sustainability data
  • Consolidation of assurance findings for Committee reporting
  • Assurance ratings and the treatment of conflicting conclusions
  • Periodic integrated assurance planning
  • Board assurance statements and their evidential basis
  • Case Study: The Control Failure that Passed Every Review

 

Risk Governance, Risk Appetite and Committee Oversight

  • Risk governance structure and allocation of responsibilities
  • Enterprise risk taxonomy and risk ownership
  • Risk appetite statements and quantitative risk limits
  • Risk capacity, risk tolerance and operating thresholds
  • Alignment of strategy, capital, liquidity and risk appetite
  • Risk acceptance, avoidance, transfer, mitigation and termination
  • Risk limit breaches and escalation procedures
  • Aggregation of risks across subsidiaries and jurisdictions
  • Emerging risk assessment without dependence on speculation
  • Risk culture and management conduct indicators
  • Committee challenge of optimistic management assumptions
  • Periodic review of risk appetite adequacy

 

Strategic Risk, Capital Protection and Business Model Exposure

  • Board distinction between growth, scale, profit and value
  • Strategic concentration by product, customer, geography and supplier
  • Capital allocation and risk-adjusted return analysis
  • Liquidity requirements and funding dependence
  • Acquisition, investment and expansion risk
  • Pricing decisions and margin deterioration
  • Major project and capital expenditure exposure
  • Business model sensitivity to economic and regulatory conditions
  • Scenario analysis and reverse stress testing
  • Management forecasts and assumption challenge
  • Trigger points for strategy revision or withdrawal
  • Post-investment review and benefit realisation accountability

 

Operational Resilience, Technology Risk and Third-Party Dependence

  • Identification of critical business services
  • Maximum tolerable periods of disruption
  • Recovery time and recovery point requirements
  • Technology architecture and single points of failure
  • Cybersecurity governance and information asset protection
  • Identity, access and privileged-user controls
  • Data integrity, confidentiality, availability and recovery
  • Cloud services and outsourced technology arrangements
  • Third-party concentration and subcontractor dependence
  • Incident notification, crisis command and Board communication
  • Business continuity exercises and disaster recovery testing
  • Committee review of unresolved resilience weaknesses
  • Case Study: Expansion Approved Beyond the Organisation’s Risk Capacity

 

Fraud, Misconduct, Whistleblowing and Management Override

  • Fraud risk governance and Committee responsibilities
  • Management override of financial and operational controls
  • Whistleblowing arrangements and reporter protection
  • Investigation authority, independence and evidence preservation
  • Fraud indicators in financial and operational information
  • Related-party abuse and conflict-of-interest concealment
  • Executive expense, procurement and contracting irregularities
  • Retaliation against internal audit, compliance or whistleblowers
  • Use of external investigators and legal advisers
  • Reporting obligations to regulators and law-enforcement bodies
  • Remediation, disciplinary action and recovery of losses
  • Committee oversight of investigation closure and lessons arising

 

Crisis Oversight, Regulatory Breach and Board Escalation

  • Classification of significant incidents and crises
  • Committee authority during emergencies
  • Notification thresholds and escalation routes
  • Preservation of Board independence during management-led response
  • Regulatory breach assessment and notification
  • Financial impact, liquidity impact and disclosure obligations
  • Crisis information requirements and reporting frequency
  • Legal privilege and investigation governance
  • Stakeholder communication and market disclosure control
  • Decision records during periods of incomplete information
  • Recovery monitoring and independent validation
  • Post-incident review and accountability determination

 

Committee Performance, Information Quality and Continuous Accountability

  • Annual Committee work plans and meeting calendars
  • Committee agendas linked to principal risks and reporting obligations
  • Standards for Board papers and executive submissions
  • Information sufficiency, timeliness, accuracy and comparability
  • Use of dashboards, exceptions and trend analysis
  • Recording challenge, dissent, decisions and follow-up actions
  • Tracking of audit findings and risk remediation
  • Committee skills matrix and succession planning
  • Induction and continuing technical education
  • Chairperson effectiveness and member participation
  • Internal and independent Committee evaluation
  • Reporting Committee performance to the full Board and shareholders
  • Case Study: The Whistleblower Report, Regulatory Inquiry and Board Division

 

Executive Experiential Tour

Details

Venue

  • ONLINE