Does your audit and risk committee have the capability it needs?
Financial expertise remains essential as emerging risks demand broader perspectives and a committee culture that encourages curiosity.
Audit and risk committees have traditionally been closely associated with financial reporting, controls and external audit. Those responsibilities remain central, but the committee’s remit now reaches into areas such as cyber risk, climate and supply chain impacts, and geopolitical and trade pressures. These risks may be harder to quantify, cut across several parts of the organisation, and require a wider range of experience and judgement around the table.
The IoD’s Governance diversity in New Zealand report found that finance, accounting and assurance experience was highly visible across the boards examined, while technology and digital, people and culture, and sustainability-related capability appeared much less frequently.
The IoD Director Sentiment Survey has also consistently found that fewer than half of directors say their boards have the skills and capabilities needed to meet increasing business complexity and risk.
Audit and risk committees therefore need to consider whether they have the collective capability and diversity of perspective needed for the risks they oversee.
During the Audit and Risk Shared Interest Group webinar, Building a multi-disciplinary A&R committee: the non-financial skills that matter, experienced audit and risk committee chair Bruce Robertson and director Rachel Reese MInstD discussed what that looks like in practice. Their discussion also showed that broader capability only matters if the committee knows how to use it.
Start with the committee’s purpose
Robertson argued that audit and risk committees can be pulled towards detailed financial material because of the word “audit” in their title.
He described joining a committee where the dominant agenda paper contained extensive financial information that had already been considered by a finance committee. He asked: “Why have I got this? What does it add?”
“Strategic financial risk is something that everybody on a committee should be able to get a grip on,” Robertson said. “They need to understand the fundamentals of strategic risk and financial sustainability, not the minutiae and the detail.”
A committee can process a large volume of material without improving the board’s understanding of its overall risk position. Technical reporting may also disengage members whose experience lies elsewhere, narrowing the discussion.
Robertson’s wider point was that form should follow function. The committee’s structure, agenda and membership should reflect the organisation’s objectives, strategic risks and assurance needs.
He also offered a practical test. In a three-hour meeting, at least an hour should be available for discussion about strategic risk and opportunity. A committee dominated by historical reporting has too little time to look ahead, explore uncertainty and consider the risk appetite required to pursue opportunities.
Look underneath the reporting
Reese emphasised the need to understand the business beneath what is presented to the committee.
“This is not compliance or a tick-box exercise. It’s not affirming a tidy set of financials,” she said. “It’s the looking underneath and it’s about understanding the business you’re governing.”
That understanding allows committee members to assess materiality and consequences, test assumptions and ask the “what if?” questions that may reveal emerging concerns.
Reese noted that people naturally seek information that confirms what they already know. Different perspectives can disrupt groupthink, expose blind spots and expose blind spots that might otherwise go unchallenged.
Robertson challenged the idea that accounting expertise should be a prerequisite for every committee member.
“What really counts are people who understand the business’s context. Do you understand the objectives? Do you have an inquiring mind?”
A major technology programme illustrates the point. Reese observed that boards may focus quickly on appointing technology expertise. Yet the programme may also involve business change, customer impacts, privacy and new ways of working. The committee needs to understand the wider business context, rather than viewing the risk through one technical lens.
Capability requirements can change over time. During major transformation or heightened exposure, a board may need targeted recruitment, an independent committee appointment or external advice. Short-term appointments can also add capability for a defined high-risk area.
Create a committee that is safe and curious
Reese described an effective committee environment as “safe and curious”.
Psychological safety supports open discussion among committee members, executives and others attending the meeting. It allows uncertainty and emerging concerns to be raised before management has developed a complete response.
“You want to ask those curious questions in a way that invites exploration, and open, honest answers,” she said.
“The purpose of the committee is . . . to help the business perform better.”
The committee must challenge management and test whether significant risks are being understood and managed. Effective challenge also depends on management feeling able to bring forward incomplete or uncomfortable information.
Reese suggested a diverse committee can provide a safeguard where strong or charismatic leadership creates blind spots, or where management waits until it has a solution before alerting governors. Different perspectives can help surface those issues earlier.
The chair turns capability into contribution
A broader mix of experience will not automatically improve committee performance. The chair must create the conditions for different perspectives to influence discussion.
Reese encouraged chairs to question inherited agendas and ways of working. Is the committee clear about why it exists? Does the agenda reflect its priorities?
The chair also needs to manage the balance of voices. Reese suggested contacting a member before the meeting when an item relates closely to their expertise, giving them time to prepare. During the meeting, an open question can invite a quieter member into the discussion.
The value of diversity lies in whether different experience, expertise, judgement and lived experience actually influence discussion and decisions.
A committee-level skills matrix is one practical way to assess whether collective capability reflects the committee’s remit and future risk profile. Evaluation can then test how that capability is being used, including whether meeting practices and chairing style enable constructive challenge. The findings should inform development, succession and appointments.
Robertson returned throughout the webinar to one simple question: does the committee add value?