2-2 Short Paper: Roles and Responsibilities of Oversight Committee
"An auditor commission's major function is to offer monitoring on the accounting for the
company,, the audit method, the firm's internal controls framework, and compliance with laws
and regulations" (CFA Institute, 2015). Yet, as new rules have been enacted, the role of audit
committees has shifted throughout time. The relationship between audit committees and risk
management is an important aspect of this. Risk management is defined as "the process through
which management identifies, assesses, monitors, and mitigates hazards confronting the firm"
(Lorsch & Simpson, 2009). When those two indicators are compared, both risk management and
audit committees appear to share some responsibility for ensuring that a company's job is done
correctly, both in terms of profitability and injury prevention. In the end, they both serve to
defend the firm and its resources.
The notion of internal auditors did not take off until the SEC proposed in the 1970s that
"public corporations form an audit committee in order to strengthen their financial reporting"
(Lorsch & Simpson, 2009). The 1987 Treadway Commission, whose purpose was to decrease
fraud via greater governance, expanded the function of audit committees dramatically. The panel
suggested that audit committees create formal charters outlining their enlarged responsibilities.
SEC Chairman Arthur Levitt requested "increased oversight" in September 1998 to address
concerns about the implications of earnings management on financial accounting, which
culminated in the formation of the Blue Ribbon Committee on Enhancing the Performance of
Business Internal Auditors. In its 1999 assessment, the advisory board advised that external
auditors resolve the ambiguities surrounding the reporting process by " promoting measures that
encourage responsibility" Lorsch and Simpson (2009).
The audit commission's obligations grew even more in the 2000s. The primary worry
regarding risk management was at the heart of this obligation. Companies were obliged to realize
the relationship among "... financial information risk oversight and crisis management" (Lorsch
& Simpson, 2009). Because of the greater responsibility and monitoring, the accompanying rules
and regulations were enacted: Sections 205, 302, and 404 of the Sarbanes-Oxley Act of 2002
NYSE Regulation 303A.06-07 SEC Rule 10A-3 SEC Risk Factor Disclosure on Forms 10-K and
10-Q.
The internal auditors must describe its goal, functions, and obligations not only because it
is required by law, but also because it offers a framework for the committee to understand how it
should operate and what its accountability and obligations are. By identifying this, the committee
may better grasp the risks for which they are accountable. "...if an audit committee is resolved to
be rigorous in its oversight duty... the specifics of how any audit committee does its work should
be self-decided," according to the Blue Ribbon group (Lorsch & Simpson, 2009).
The laws and regulations affecting oversight committees regarding what is expected of
them, the minimums required to operate, and how they should proceed with legal documentation,
such as audit filings, are the most important factors that would influence how a committee would
define its activities moving forward. There is still a significant gap in who is responsible for
overseeing financial reporting and regulatory compliance issues. "According to a KPMG survey
of approximately 2,000 directors, independent review panel members, and senior executives,
35% believe the audit committee should be solely in charge of oversight of accounting
information and compliance related risks, while 30% believe the committee should be
responsible for oversight of all major risks confronting the firm" (Lorsch & Simpson, 2009).
References
CFA Institute. (2015). Audit Committee Role and Practices. CFA Institute.
https://www.cfainstitute.org/en/advocacy/issues/audit-committee-role-practices
Lorsch, J. W., & Simpson, K. A. (2009, June 23). The Role of the Audit Committee in Risk
Oversight. Retrieved from 409016-PDF-ENG (2).pdf