To better understand the key challenges and concerns facing audit committees, boards, and their companies, KPMG's Audit Committee Institute surveyed more than 800 audit committee members in 42 countries.
The survey findings offer insights that audit committees around the world can use to sharpen their focus, benchmark responsibilities and practices, and strengthen oversight.
While audit committees continue to express confidence in financial reporting and audit quality, the results highlight ongoing concerns about risk management, legal and regulatory compliance, cyber security risk, and managing the control environment in the company's extended organization.
The report offers six key takeaways:
Risk management is a top concern for audit committees. The effectiveness of risk management programs generally, as well as legal/regulatory compliance, cyber security risk, and the company’s controls around risks, topped the list of issues that survey participants view as posing the greatest challenges to their companies. It’s hardly surprising that risk is top of mind for audit committees—and very likely, the full board—given the volatility, uncertainty, and rapid pace of change in the business and risk environment. More than 40 percent of audit committee members think their risk management program and processes “require substantial work,” and a similar percentage say that it is increasingly difficult to oversee those major risks.
Internal audit can maximize its value to the organization by focusing on key areas of risk and the adequacy of the company’s risk management processes generally. The survey results show that audit committees are looking to internal audit to focus on the critical risks to the business, including key operational risks (e.g., cyber security and technology risks) and related controls—and not just compliance and financial reporting risks. They also want the audit plan to be flexible and adjust to changing business and risk conditions.
Tone at the top, culture, and short-termism are major challenges—and may need more attention. A significant number of audit committee members—roughly one in four—ranked tone at the top and culture as a top challenge, and nearly one in five cited short-term pressures and aligning the company’s short- and long-term priorities as a top challenge. Meanwhile, nearly the same percentage of audit committee members said they are not satisfied that their committee agenda is properly focused on those issues.
CFO succession planning and bench strength in the finance organization continue to be weak spots. Forty-four percent of audit committees are not satisfied that their agenda is properly focused on CFO succession planning, and another 46 percent are only somewhat satisfied. In addition, few are satisfied with the level of focus on talent and skills in the finance organization. Given the increasing demands on the finance organization and its leadership—financial reporting and controls, risk management, analyzing mergers and acquisitions (M&A) and other growth initiatives, shareholder engagement, and more—audit committees want to devote more time to the finance organization, including the talent pipeline, training, and resources, as well as succession planning for the CFO and other key finance executives.
Two key financial reporting issues may need a more prominent place on audit committee agendas: Implementation of new accounting standards and non-GAAP financial measures. Few audit committees say their companies have clear implementation plans for two major accounting changes on the horizon—the new revenue recognition and lease accounting standards. Given the scope and complexity of those implementation efforts and their impact on the business, systems, controls, and resource requirements, those efforts should be a key area of focus. In addition, audit committees ought to consider whether to increase attention to any non-GAAP financial measures, which are an area of significant attention and comment by the SEC staff. Nearly a quarter of those surveyed say their role with respect to the presentation of those metrics is very limited.
Audit committee effectiveness hinges on understanding the business. Audit committee members say a better understanding of the business and the company’s key risks would most improve their oversight effectiveness. They also view additional expertise in technology/cyber security as being key to greater effectiveness, since it would strengthen their ability to oversee those risks.