Audit and assurance committee handbook

Guidance on the principles and best practise for the organisation of Audit and Assurance committees.


Annex I: Risk Control Framework

The Risk Control Framework, as updated in the May 2023 revision of the Orange Book, provides a structured approach to assessing and reporting on the effectiveness of governance, risk management and control arrangements across public sector organisations. Audit and Assurance Committees should ensure that their annual reporting reflects the principles and expectations set out in this framework.

Annual Reporting Requirements

The Audit and Assurance Committee’s Annual Report should provide a clear and evidence-based opinion on the following:

  • the effectiveness of governance, risk management and control arrangements, including the organisation’s compliance with the updated Orange Book and its embedded Risk Control Framework
  • the comprehensiveness of assurances in meeting the needs of the AO and Board
  • the reliability and integrity of the assurances received
  • whether the assurance available is sufficient to support the AO and Board in their decision-making and accountability obligations
  • the implications of these assurances for the overall management of risk within the organisation
  • any issues the committee considers pertinent to the Governance Statement, including long-term matters that should be brought to the attention of the AO and/or Board
  • the quality of financial reporting for the year
  • the quality and effectiveness of both internal and external audit functions and their approach to fulfilling their responsibilities
  • the committee’s own effectiveness, including any recommendations for improvement or development

Group and Shared Service Considerations

Where risks span across a group of organisations or shared service arrangements, related Audit and Assurance Committees may be required to produce coordinated Annual Reports. These should be timed to support the production of any overarching governance or assurance reports and should reflect the collective risk and control environment.

Bilateral Communications

To support effective oversight and assurance, there should be mutual rights of access between the Chair of the Audit and Assurance Committee, the AO, the Head of Internal Audit, the Risk Manager (where this is a distinct function), and the External Auditor. Periodic bilateral discussions—at least annually—should be held outside of the formal committee structure to ensure expectations are aligned and there is a shared understanding of current risks and emerging issues.

Contact

Email: DIAABusinessSupportHub@gov.scot

Back to top