Audit and assurance committee handbook

Guidance on the principles and best practise for the organisation of Audit and Assurance committees.


Foreword

At its simplest, corporate governance helps make sure an organisation is achieving its objectives in the best way it can. The scale, variety and nature of risks which the public sector is navigating, including fiscal challenges, cyber threats, digital disruption and geopolitical uncertainty, demands robust and effective governance. In this context, the role of the Audit and Assurance Committee* is more important than ever.

The role is a challenging one. It needs independent and objective members with an appropriate range of skills and experience. Audit and Assurance Committees must provide insight and effective, constructive challenge.

Since the Handbook** was last reviewed in 2023, the Global Internal Audit Standards (GIAS) have come into effect, replacing the Public Sector Internal Audit Standards. The GIAS, as they apply to internal audit functions in the public sector in the UK, introduced mandatory requirements for Audit and Assurance Committees in relation to their role in enabling an effective internal audit function.

This revision of the Handbook sets out to support Audit and Assurance Committee effectiveness by clarifying the fundamental principles relating to the role, membership and work of Audit and Assurance Committees in those organisations to which the Scottish Public Finance Manual (SPFM) is directly applicable. It can also be used as a good practice guide for organisations in which the SPFM is not directly applicable.

A degree of flexibility, pragmatism and proportionality will be needed in applying the guidance in this Handbook to individual organisations. For example, the use of the term “Board” referred to in chapter four should be interpreted in the context of the “On Board” Guidance (January 2023), which defines the differences between Statutory and Management Advisory Boards. Subject to these caveats, any significant non-compliance with the principles in this Handbook should be explained and reported in the annual Governance Statement.

The Handbook emphasises the sources of assurance available to Audit and Assurance Committees in addition to internal and external audit. We encourage all organisations within the Scottish Government family to define their assurance needs, map their various sources of assurance and develop an integrated approach to assurance which will secure best value for the public purse and embed best practice principles within their organisation.

We commend this Handbook to you.

Joe Griffin

Permanent Secretary

Jennifer Inglis-Jones

Director of Internal Audit and Assurance

* Alternatively referred to as the Audit Committee / Audit and Risk Committee / Audit and Risk Assurance Committee. For the purposes of this Handbook - the term Audit and Assurance Committee will be used in a generic context.

**The Scottish Government Audit and Assurance Committee Handbook draws on, and is consistent with, generally accepted principles concerning corporate governance and the role of audit and assurance committees. Relevant source publications include:

Contact

Email: DIAABusinessSupportHub@gov.scot

Back to top