Audit and assurance committee handbook

Guidance on the principles and best practise for the organisation of Audit and Assurance committees.


Annex G: Key Questions for an Audit and Assurance Committee to Ask

This list of questions is not intended to be exhaustive or restrictive nor should it be treated as a checklist substituting for detailed consideration of the issues it raises. Rather it is intended to act as a set of “prompts” to help the committee ensure that their work is comprehensive.

On the strategic processes for risk, control and governance, how do we know:

  • the risk management culture is appropriate
  • there is a comprehensive process for identifying and evaluating risk, and for deciding what levels of risk are tolerable
  • the risk register is an accurate reflection of the risks facing the organisation.
  • appropriate ownership of risk is in place
  • risk management is carried out in a way that really benefits the organisation or is it treated as a box ticking exercise
  • the organisation as a whole is aware of the importance of risk management and of the organisation's risk priorities
  • management has an appropriate view of how effective internal control is
  • the system of internal control and effective risk identification and management will provide indicators of things that may be going wrong or off track
  • the AO's annual governance statement is meaningful, and is underpinned by appropriate evidence
  • the governance statement appropriately discloses action to deal with material problems
  • the Board is appropriately considering the results of the effectiveness review underpinning the governance statement

On risk management processes, how do we know:

  • how senior management (and Ministers where appropriate) support and promote effective risk management
  • how well people are equipped and supported to manage risk well
  • there is a clear risk strategy and policies
  • the arrangements in place for identification and mitigation of risks are effective
  • the organisation’s risk appetite has been articulated
  • there are effective arrangements for managing risks with partners
  • the organisation's processes incorporate effective risk management
  • key strategic risks can be change quickly, scenario planning and stress testing can be carried out and “bubbling under” risks captured
  • external and emerging risks are considered
  • financial’ risks and “non-financial” risks are reviewed
  • risk management contributes to achieving outcomes
  • management are regularly reviewing top risks, including the effectiveness of mitigating actions

On the planned activity and results of both internal and external audit, how do we know:

  • the Internal Audit strategy is appropriate for delivery of an informed assurance opinion on the whole of risk, control and governance
  • the internal audit plan will achieve the objectives of the Internal Audit strategy, and in particular is it adequate to facilitate a positive, reasonable assurance on the key risks facing the organisation
  • Internal Audit has appropriate resources, including skills, to deliver its objectives
  • Internal Audit takes appropriate account of other assurance activity, especially in the first and second line (and that this assurance is understood and owned by management)
  • Internal Audit recommendations that have been agreed by management are timeously implemented
  • any issues arising from line management not accepting Internal Audit recommendations are appropriately escalated for consideration
  • the quality of Internal Audit work is adequate. What does application of the Internal Audit Quality Assessment process tell us about the quality of the Internal Audit service
  • there is appropriate access to both Internal and External Audit to discuss the organisations/Non-Executives assurance questions and concerns privately
  • there is appropriate co-operation between the internal and external auditors
  • External Audit’s plan will provide sufficient scrutiny of the organisation’s financial statements and assurance that resources have been discharged properly, effectively and efficiently
  • the AO and Board have taken all necessary steps to make themselves aware of any relevant information and that auditors are aware of that information

On the accounting policies, the accounts, and the annual report of the organisation, how do we know:

  • how effective and accurate budgeting and in-year forecasting is
  • if the finance function is fit for purpose
  • what the “hidden” financial risks are, relating to (inter alia):
    • HR
    • VAT
    • overruns
    • sudden loss of funding/revenue
  • the accounting policies comply with relevant requirements, particularly the HMT Financial Reporting Manual
  • there has been due process in preparing the accounts and annual report and is that process robust
  • the accounts and annual report have been subject to sufficient review by management and by the Board and AO
  • when new or novel accounting issues arise, appropriate advice on accounting treatment is sought and provided
  • there is an appropriate anti-fraud policy in place and losses are suitably recorded
  • suitable processes are in place to ensure accurate financial records are kept in line with legislative and organisational requirements
  • suitable processes are in place to ensure fraud is guarded against, and regularity and propriety is achieved
  • financial control, including the structure of delegations, enables the organisation to achieve its objectives with good value for money
  • if there are any issues likely to lead to qualification of the accounts
  • if the accounts have been qualified, that appropriate action is being taken to deal with the reason for qualification
  • issues raised by the External Auditors are given appropriate attention

On the adequacy of management response to issues identified by audit activity, how do we know:

  • the implementation of recommendations is monitored and followed up
  • there are suitable resolution procedures in place for cases when management reject audit recommendations which the auditors stand by as being important

On assurances relating to the corporate governance requirements for the organisation, how do we know:

  • corporate governance arrangements operate effectively and are clear to the whole organisation
  • the AO’s Governance Statement is meaningful, and that robust evidence underpins it
  • the Governance Statement appropriately discloses action to deal with material problems
  • the Board/Executive is appropriately considering the results of the effectiveness review underpinning the annual Governance Statement
  • the range of assurances available is sufficient to facilitate the drafting of a meaningful annual Governance Statement
  • those producing the assurances understand fully the scope of the assurance they are being asked to provide, and the purpose to which it will be put
  • effective mechanisms are in place to ensure that assurances are reliable and adequately evidenced
  • assurances are “positively” stated (i.e. – premised on sufficient relevant evidence to support them)
  • the assurances draw appropriate attention to material weaknesses or losses which should be addressed
  • the annual Governance Statement realistically reflects the assurances on which it is premised

On the work of the committee itself, how do we know:

  • we are being effective in achieving our terms of reference and adding value to corporate governance and control systems of the organisation
  • we have the appropriate skills mix
  • we have an appropriate level of understanding of the purpose and work of the organisation
  • we understand all of the sources of assurance available to the organisation
  • we have sufficient time to give proper consideration to our business
  • our individual members are avoiding any conflict of interest
  • we are avoiding “group think”
  • what impact we are having on an organisation

On the risk of cyber security, how do we know that:

  • there is sufficient assurance that the organisation is properly managing its cyber risk, including having appropriate risk mitigation - does the committee have responsibility for review of the draft strategies
  • the organisation has properly identified and evaluated the cyber security risk
  • there are proper governance arrangements and controls to protect from, detect and respond to cyber security attacks/incidents (for example there is board member (or equivalent) with a specific security remit
  • government expectations and standards relating to cyber security are considered and implemented within the organisation
  • the organisation has suitably skilled and experienced staff, or access to such staff to deal with incidents
  • there is suitable awareness and ongoing training within the organisation on the risk from cyber-attack

Contact

Email: DIAABusinessSupportHub@gov.scot

Back to top