Audit and Risk Committees: Do you need one?

Audit and Risk Committees: Do you need one?

An audit and risk committee can be a valuable governance tool for a not-for-profit organisation, but not every organisation needs one.

For some boards, an Audit and Risk Committee helps provide deeper oversight of financial reporting, audit processes, internal controls and risk management. For others, creating a separate committee may add more structure than the organisation can realistically support.

The question is not simply, “Should we have a committee?”

The better question is, “Does our board have the right level of financial and risk oversight for the size, complexity and responsibilities of our organisation?”

A small volunteer-run association may not need a formal Audit and Risk Committee. A larger charity with staff, grants, government funding, multiple programs, complex reporting obligations or an annual audit may benefit from one.

This article explains what an Audit and Risk Committee does, when a not-for-profit might need one, when it may not be necessary, and what practical alternatives smaller organisations can use.

What is an Audit and Risk Committee?

An Audit and Risk Committee is a subcommittee of the board that focuses on financial reporting, audit, risk management and internal controls.

It does not replace the board. It helps the board by doing more detailed work in areas that need closer attention.

For example, the committee may review financial reports in more detail before they go to the full board. It may meet with the auditor, review audit findings, check whether internal controls are working, and monitor key organisational risks.

The committee usually makes recommendations to the board. The board remains responsible for final decisions and overall governance.

In plain English:

  • the board remains accountable
  • the committee does deeper review
  • management provides information and implements actions
  • the auditor or external adviser provides independent assurance where required

For not-for-profit boards, this can be especially useful when financial reports, audit requirements or risks are becoming too complex for the full board to examine properly during ordinary board meetings.

What does an Audit and Risk Committee do?

The role of an Audit and Risk Committee depends on the organisation’s size, structure and needs.

In many not-for-profits, the committee’s work covers four broad areas:

  • financial reporting
  • audit oversight
  • risk management
  • internal controls

Some organisations also include compliance, insurance, fraud prevention, cyber risk or workplace health and safety within the committee’s scope.

The committee should have a clear terms of reference that explains what it is responsible for, what authority it has, who sits on it, how often it meets and how it reports back to the board.

Financial reporting oversight

Financial reporting is one of the most important areas for an Audit and Risk Committee.

The committee may review whether financial reports are accurate, timely and useful for decision-making.

This may include reviewing:

  • profit and loss reports
  • balance sheets
  • cash flow reports or forecasts
  • budget versus actual reports
  • restricted funds or grant reports
  • financial risk summaries
  • annual financial statements
  • management commentary on key variances

The committee should not simply check whether the reports exist. It should ask whether the reports help the board understand what is happening.

Useful questions include:

  • Are reports prepared on time?
  • Are major variances explained clearly?
  • Is cash flow visible?
  • Are restricted funds tracked properly?
  • Are financial risks highlighted early?
  • Do reports support board decisions?
  • Are the annual financial statements consistent with regular board reporting?

If your board is still refining its reporting pack, our board reporting checklist for NFPs explains what should usually be included in a useful board financial pack.

Audit oversight

Audit oversight is another common responsibility of an Audit and Risk Committee.

Some not-for-profits are required to have their financial statements audited or reviewed because of their size, structure, funding agreements, governing rules or ACNC obligations.

For registered charities, ACNC requirements depend on charity size. Medium charities must have their annual financial report reviewed or audited. Large charities must have their annual financial report audited.

An Audit and Risk Committee may help oversee:

  • appointment or recommendation of the auditor
  • audit planning
  • audit timing
  • information requested by the auditor
  • draft annual financial statements
  • audit findings
  • management letters
  • internal control recommendations
  • follow-up actions from previous audits

The committee may also meet with the auditor without management present, where appropriate. This gives the auditor an opportunity to raise concerns directly with board representatives.

An audit should not be treated as a once-a-year compliance event. It can provide useful insight into reporting quality, financial controls and governance processes.

Risk management oversight

Risk management is broader than financial risk.

For a not-for-profit, risks may include:

  • funding uncertainty
  • cash flow pressure
  • fraud or financial misuse
  • cybersecurity and payment scams
  • staffing and key person dependency
  • program delivery risk
  • regulatory or compliance risk
  • workplace health and safety risk
  • reputation risk
  • service quality risk
  • governance or board capability risk

An Audit and Risk Committee does not remove risk from the organisation. Its role is to help the board understand whether key risks have been identified, assessed and managed.

The committee may review:

  • the risk register
  • new or emerging risks
  • risk ratings and controls
  • actions assigned to management
  • insurance coverage
  • incident reports
  • significant compliance matters
  • risk implications of major decisions

For smaller organisations, this does not need to be complicated. A simple risk register reviewed regularly can be more useful than a complex framework that no one updates.

Internal controls oversight

Internal controls are the checks and processes that help protect an organisation’s money, records and assets.

An Audit and Risk Committee may review whether these controls are suitable and working in practice.

Important controls may include:

  • clear approval limits
  • two-person payment approval
  • bank reconciliations
  • separation of duties
  • credit card review
  • supplier bank detail checks
  • payroll approvals
  • restricted fund tracking
  • system access controls
  • fraud prevention processes

The committee does not need to inspect every transaction. Instead, it should ask whether the organisation has reasonable controls for its size and risk.

For example, a small charity may not have enough people for full segregation of duties, but it can still require two-person payment approval and Treasurer review of bank reconciliations.

For a practical breakdown of simple controls, see internal controls for charities.

Does an Audit and Risk Committee make decisions for the board?

Usually, an Audit and Risk Committee recommends rather than decides.

The board may delegate certain tasks to the committee, such as reviewing audit findings or monitoring the risk register. But the full board remains responsible for governance and final approval of major matters.

For example, the committee may recommend that the board:

  • approve annual financial statements
  • accept the audit report
  • adopt a revised risk framework
  • approve a new financial delegations policy
  • increase reserves
  • strengthen payment controls
  • address an audit finding

The board should receive clear reports from the committee so all board members understand what has been reviewed, what issues were identified and what decisions are required.

This matters because the existence of a committee does not remove board financial responsibilities. The board still needs to engage with financial reports, risks and major governance decisions.

When might a not-for-profit need an Audit and Risk Committee?

A not-for-profit may benefit from an Audit and Risk Committee when the organisation has grown beyond what the full board can comfortably oversee in ordinary meetings.

Signs that a committee may be useful include:

  • the organisation has an annual audit or review
  • financial reports are complex
  • the organisation manages significant grants or restricted funds
  • there are multiple programs, locations or entities
  • cash flow and reserves need closer monitoring
  • the organisation has staff, payroll and employment obligations
  • risk management is becoming more important
  • board meetings do not allow enough time for detailed finance and risk discussion
  • audit findings need regular follow-up
  • funders or stakeholders expect stronger governance structures
  • the organisation is going through growth, change or financial pressure

The committee can give the board a more disciplined way to monitor financial oversight and risk without turning every board meeting into a detailed finance review.

When might an Audit and Risk Committee not be necessary?

Not every not-for-profit needs a separate Audit and Risk Committee.

For smaller organisations, a committee may be unnecessary if:

  • the organisation has low financial complexity
  • there are few transactions
  • there are no staff or payroll obligations
  • the board can review finances and risks properly during ordinary meetings
  • there is no audit or review requirement
  • there are not enough suitably skilled people to form a committee
  • a committee would create more administration than value

A committee should not be created just because it sounds like good governance. It should solve a real oversight need.

If a small organisation creates a committee but no one has time to prepare papers, attend meetings or follow up actions, the structure may not improve governance.

Good governance is not about having more committees. It is about having the right oversight for the organisation’s size and risk.

Practical alternatives for smaller organisations

Smaller not-for-profits can still strengthen audit and risk oversight without forming a formal committee.

Practical alternatives include the following.

Add a finance and risk item to every board agenda

The board can include a standing finance and risk item at every meeting.

This item may cover:

  • financial report review
  • cash flow position
  • major variances
  • restricted funds
  • key risks
  • internal control issues
  • compliance deadlines
  • decisions required

This keeps finance and risk visible without creating a separate committee.

Hold a quarterly finance and risk review

Even if the board reviews financial reports at each meeting, it may benefit from a deeper quarterly review.

Quarterly discussion could focus on:

  • year-to-date performance
  • cash flow forecast
  • funding pipeline
  • reserves
  • risk register
  • policy exceptions
  • internal controls
  • upcoming reporting obligations

This can be a practical middle ground for boards that do not need a formal committee but want more disciplined oversight.

Use a Treasurer and Chair review process

Some smaller organisations use a Treasurer and Chair review process before board meetings.

For example, the Treasurer and Chair may meet with management or the bookkeeper to review reports, ask initial questions and identify matters that need board attention.

This can help make board discussions more focused.

However, this should not mean the rest of the board becomes passive. The full board should still receive clear reports and ask questions.

Bring in external support when needed

Smaller organisations may not have the internal skills to review audit findings, controls or financial systems.

In that case, external accounting or governance support can help.

For example, an adviser may assist with:

  • reviewing board financial reports
  • preparing for audit or review
  • responding to audit findings
  • improving internal controls
  • setting approval limits
  • building cash flow reports
  • reviewing financial policies
  • creating a simple risk register

For organisations without an internal finance function, an outsourced finance team can help create the reporting and review processes that support board oversight.

What should be in an Audit and Risk Committee terms of reference?

If the board decides to create an Audit and Risk Committee, it should document the committee’s role clearly.

A terms of reference may include:

  • purpose of the committee
  • scope of responsibilities
  • membership and skills required
  • chairing arrangements
  • meeting frequency
  • quorum
  • reporting to the board
  • authority to seek external advice
  • relationship with management
  • relationship with external auditors
  • review process for the committee’s effectiveness

The terms of reference should be approved by the board and reviewed regularly.

It should also be clear whether the committee has decision-making authority or only makes recommendations to the board.

Who should sit on an Audit and Risk Committee?

The committee should include people with enough financial, governance or risk knowledge to add value.

This may include:

  • board members with finance experience
  • the Treasurer
  • board members with governance or risk experience
  • independent committee members with relevant skills
  • the Chair, depending on the organisation’s structure

Management may attend committee meetings to provide reports and answer questions, but the committee should still be able to exercise independent oversight.

Some organisations invite external advisers or auditors to attend for specific agenda items.

The board should also consider independence and conflicts of interest. For example, a person involved in preparing the accounts should not be the only person reviewing them for governance purposes.

How often should an Audit and Risk Committee meet?

The right meeting frequency depends on the organisation.

Many Audit and Risk Committees meet quarterly, with additional meetings around audit preparation, annual financial statements or major risk matters.

A practical rhythm might include:

  • quarterly review of financial reports, risk register and controls
  • pre-audit meeting to review audit plan and timing
  • post-audit meeting to review findings and management responses
  • annual review of financial policies and delegations
  • additional meetings during major change, financial stress or significant risk events

The committee should meet often enough to provide useful oversight, but not so often that it creates unnecessary administrative burden.

For broader reporting rhythm, see how often should a board review financial reports?

What should the committee report back to the board?

An Audit and Risk Committee should report clearly to the full board after each meeting.

The report does not need to be long, but it should highlight:

  • what the committee reviewed
  • key findings or concerns
  • audit or review updates
  • financial reporting issues
  • risk matters requiring board attention
  • internal control issues
  • policy breaches or exceptions
  • recommendations for board decision
  • actions assigned to management

This helps the full board stay informed and accountable.

A committee can do detailed work, but it should not become a place where important issues disappear from full board visibility.

Common mistakes with Audit and Risk Committees

An Audit and Risk Committee can improve governance, but only if it is set up and used well.

Mistake 1: Creating a committee without a clear purpose

A committee should have a clear reason for existing.
If the board does not define the committee’s role, it may duplicate board discussion or create confusion about who is responsible for what.

Mistake 2: Assuming the committee replaces board accountability

The full board remains accountable for governance.
The committee can review, question and recommend, but the board still needs to understand major financial and risk matters.

Mistake 3: Focusing only on the audit

Audit is important, but risk and controls matter throughout the year.
A committee that only meets around annual financial statements may miss opportunities to improve reporting, controls and risk oversight earlier.

Mistake 4: Not following up on audit findings

Audit or review findings should lead to action.
The committee should track management responses, due dates and completion of agreed improvements.

Mistake 5: Making the committee too technical

The committee should not become so technical that it disconnects from the board’s practical governance needs.
Its role is to help the board understand financial reporting, audit and risk matters clearly.

Mistake 6: Not having the right skills

An Audit and Risk Committee needs people who can read financial reports, ask useful questions and understand risk.
If the committee lacks these skills, it may need training, external support or independent members.

A practical checklist: Do you need an Audit and Risk Committee?

Use this checklist to help your board decide whether a committee may be useful.

You may need one if:

  • your organisation is required to have an audit or review
  • financial reports are becoming more complex
  • the board does not have enough time for detailed finance and risk review
  • you manage significant grants or restricted funds
  • you have multiple programs, locations or funding streams
  • you have staff, payroll or complex compliance obligations
  • audit findings need structured follow-up
  • risk management needs more attention
  • internal controls need regular monitoring
  • funders or stakeholders expect stronger governance oversight

You may not need one if:

  • your organisation is small and low-risk
  • financial reports are simple and well understood
  • the full board has time to review finance and risk properly
  • there is no audit or review requirement
  • there are not enough skilled people to form a useful committee
  • a committee would add administration without improving oversight

Practical alternatives may include:

  • a standing finance and risk agenda item
  • quarterly deeper finance and risk reviews
  • Treasurer and Chair pre-meeting reviews
  • external adviser support
  • a simple risk register
  • clear financial delegations and internal controls

How an Audit and Risk Committee supports stronger governance

A well-run Audit and Risk Committee can strengthen not-for-profit governance by giving financial and risk matters more focused attention.

It can help the board:

  • understand financial reports more clearly
  • prepare for audit or review
  • respond to audit findings
  • monitor financial risks
  • improve internal controls
  • track compliance obligations
  • review policies and delegations
  • make decisions based on better information

The committee should help the board see the bigger picture. It should not make governance more complicated than necessary.

For many organisations, the goal is not more paperwork. The goal is clearer oversight, better accountability and stronger decision-making.

Final thoughts

An Audit and Risk Committee can be highly useful for a not-for-profit organisation with complex finances, audit obligations, significant risks or growing governance demands.

But it is not automatically necessary for every organisation.

Smaller NFPs may achieve strong oversight through regular board reporting, quarterly finance and risk reviews, clear approval limits and practical internal controls. Larger or more complex organisations may benefit from a formal committee that can give audit, risk and financial reporting matters closer attention.

The right structure depends on the organisation’s size, complexity, risks and board capability.

If your board is unsure whether it needs an Audit and Risk Committee, or whether a simpler finance and risk review process would be more practical, Hopscotch can help you assess your current reporting, controls and governance rhythm so the board has the clarity it needs to make confident decisions.

More insights...

Treasurer's responsibilities in an incorporated association
Restricted-funds-explained-for-charities-and-not-for-profits
Governance Standard 5 explained in plain English