Audit or finance committees that work: roles,
skills and practical agendas under King V™

A committee with effective oversight over the independent review or audit and other financial matters is one of the board’s most reliable guardrails. When it is well composed, clear on its mandate, and disciplined in execution, it strengthens trust in reporting, risk oversight and controls, and frees the board to focus on strategy and performance. Usually organisations constitutes an Audit Committee or a Finance Committee.

King V™ raises the bar on stakeholder outcomes, combined assurance and technology oversight. South African boards that recalibrate their Audit Committee now, in line with the Companies Act and current governance expectations, will be better placed to navigate scrutiny, cyber risk and fast-changing reporting demands.

This guide distils what works in practice. It clarifies the Audit Committee’s remit visa vis Risk and Social and Ethics Committees, maps the skills that matter, and offers a one year agenda and reporting templates you can adopt tomorrow.

Start with proportionality: the same outcomes, different structures

Good governance should scale with the organisation. The desired outcomes remain consistent across companies of different sizes: reliable financial information, effective controls, appropriate assurance, responsible technology use, visible management of fraud and misconduct risk, and clear accountability for corrective action. What changes is the structure through which those outcomes are achieved.

A company should begin by establishing whether an Audit Committee is legally required under the Companies Act, its Memorandum of Incorporation, a shareholders’ agreement, financing arrangements or another regulatory framework. It should then consider the company’s Public Interest Score, ownership model, stakeholder exposure, funding structure, operating complexity, geographical reach, use of technology, susceptibility to fraud and dependence on key individuals.

For a smaller company, proportionality must not become an excuse for informality. The absence of a separate Audit Committee or internal audit department does not remove the board’s responsibility for reliable reporting, appropriate controls and responsible oversight. It means that the organisation must allocate those responsibilities deliberately, document who performs them, obtain independent expertise where internal capability is insufficient, and create an escalation path when concerns arise.

For a larger or more complex organisation, the opposite danger applies. The existence of multiple functions, committees and reports can create the appearance of assurance without producing genuine insight. Proportional governance therefore requires every organisation to ask three questions: what must be assured, who is sufficiently competent and independent to provide that assurance, and how will the board know that material concerns have been addressed?

What effective audit oversight looks like at different scales

 

Governance feature

Large or complex company

Medium-sized or growing company

Small or owner-managed company

Typical oversight structure

A dedicated Audit Committee, often supported by separate Risk and Social and Ethics Committees.

A dedicated Audit Committee where required or justified; alternatively, a combined Audit and Risk Committee with a clearly defined mandate.

Where an Audit Committee is not legally required, we recommend a Finance Committee as a practical first-step structure. It is easier to establish where the company does not yet have independent non-executive directors and helps a first-time committee build a disciplined rhythm of financial oversight, reporting and action tracking.

Membership

Usually three to five independent non-executive directors with a broad mix of financial, assurance, technology, sector and regulatory expertise.

Usually three suitably skilled non-executive members, supplemented by external advisers for specialist matters.

The board should identify at least one financially competent person and consider an independent adviser or non-executive member where the directors are operationally involved in the business.

Internal audit

A permanent internal audit function led by a Chief Audit Executive, with a risk-based plan and direct access to the committee chair.

A small internal audit team, co-sourced service or outsourced programme focused on the most material risks and controls.

No permanent internal audit function may be necessary. The company can commission targeted reviews of cash, payroll, procurement, inventory, cyber controls, regulatory compliance or other priority areas.

Risk function

A Chief Risk Officer or dedicated risk team maintains the enterprise risk framework and coordinates assurance.

Risk responsibility may sit with the CFO, company secretary, compliance lead or another executive, supported by advisers where required.

The CEO, finance lead or board member may maintain a concise risk and control register, provided ownership, review dates and escalation triggers are clear.

Financial leadership

A CFO and financial reporting team prepare board-level reporting, technical papers and control attestations.

A finance executive or financial manager may be supported by external technical accounting and tax specialists.

A bookkeeper, accountant or finance manager may maintain records, while an independent external accounting professional assists with financial statements, tax, reviews and control improvement.

External assurance

Statutory audit, specialist assurance and regulatory reviews, coordinated through a formal combined assurance model.

Statutory audit or independent review as legally required, supplemented by targeted assurance over priority risks.

Independent review, compilation or audit as legally required, with additional assurance commissioned when lenders, investors, customers or the risk profile justify it.

Technology and cyber oversight

Formal IT governance, cyber reporting, data governance, access reviews, resilience testing and specialist assurance.

Periodic technology risk assessments, outsourced security reviews and management reporting on incidents, access and recovery testing.

Basic but disciplined controls: secure backups, tested recovery, multifactor authentication, restricted system access, payment verification and prompt escalation of incidents.

Meeting rhythm

Four or more formal meetings annually, with additional sessions around reporting cycles and material events.

Three or four focused meetings annually, aligned to reporting, audit, risk and control milestones.

Two to four structured board or committee discussions annually, with financial and control oversight also embedded in regular board meetings.

Reporting style

Detailed committee packs, dashboards, assurance maps, technical papers and formal private sessions with assurance providers.

Concise dashboards, issue trackers and exception reports, supported by specialist papers when necessary.

A short financial pack, cash-flow view, key control checklist, risk register and action tracker focused on material exceptions and decisions.

Principal governance risk

Fragmentation, duplication and over-reliance on complex assurance structures.

Capability gaps, unclear mandates and insufficient challenge as the business grows.

Excessive dependence on the founder, weak segregation of duties, informal approvals and limited independent challenge.


A practical assurance model when there is no Chief Audit Executive

A business without a Chief Audit Executive can still establish credible assurance by combining management ownership, independent review and board challenge.

  • First line: operational ownership. Process owners should maintain the controls embedded in finance, sales, procurement, payroll, information technology and operations. In a small business, this may involve only a few people, which makes documented approvals and visible review especially important.
  • Second line: monitoring and specialist support. The finance lead, compliance adviser, company secretary, outsourced accountant or technology provider may monitor selected risks and requirements. Their roles should be clear, and the board should remain alert to conflicts where a provider both designs and assesses the same control.
  • Independent assurance. The external auditor, independent reviewer or targeted specialist can provide assurance over defined areas. External audit should not automatically be treated as a substitute for internal audit, because its principal purpose and scope differ. However, its findings can inform the board’s view of financial reporting and control risk.
  • Board oversight. The board or Audit Committee should integrate these different sources, identify gaps, challenge management’s conclusions and require corrective action. The goal is not to create a complex assurance map for its own sake; the goal is to ensure that every material risk has an owner, an appropriate control, a source of assurance and a clear escalation route.


Mandate and positioning under King V™ and the Companies Act

The Companies Act, 2008 requires certain companies to appoint an Audit Committee and sets minimum duties relating to financial reporting and auditor independence. King V broadens this with outcomes-focused, apply-and-explain guidance. In practice, the Audit Committee’s core purpose is to safeguard the integrity of financial reporting and the effectiveness of internal control and combined assurance, with specific oversight of external and internal audit, technology risks that affect reporting and controls, and whistleblowing channels.

When is an Audit Committee required?

The starting point is the Companies Act, but the inquiry should not end there. A company must consider its legal form, its constitutional documents and the wider regulatory and commercial environment in which it operates. The requirement is clear for some organisations and contextual for others.

  1. Public companies. A public company must appoint an Audit Committee at each annual general meeting.
  2. State-owned companies. A state-owned company must appoint an Audit Committee, subject also to any applicable public-sector legislation and any exemption lawfully granted.
  3. Requirement in the Memorandum of Incorporation. A private, personal-liability or non-profit company must appoint an Audit Committee where its Memorandum of Incorporation requires one.
  4. Other binding requirements. An Audit Committee may also be required by sector-specific legislation, listing requirements, a licence condition, a shareholders’ agreement, a financing arrangement or an investor covenant.
  5. Voluntary establishment. Even where no legal obligation applies, a board may establish an Audit Committee where the organisation’s scale, complexity, funding structure, stakeholder exposure or risk profile warrants dedicated and independent oversight.

 

Audit requirement versus Audit Committee requirement

These two requirements should not be conflated. A private, personal-liability or non-profit company may be required to have its annual financial statements audited because of its Public Interest Score, the manner in which its financial statements are prepared, or another applicable requirement, without automatically being required to establish a statutory Audit Committee. The Public Interest Score helps determine the appropriate level of financial reporting assurance; it does not, on its own, determine whether an Audit Committee must exist.

A practical first step: establish a Finance Committee

Where a company is not legally required to appoint an Audit Committee, we recommend that it consider establishing a Finance Committee as a proportionate and practical first step. Smaller and growing companies do not always have independent non-executive directors available to satisfy the composition requirements of a statutory Audit Committee, and a Finance Committee can therefore provide a more accessible structure through which the board builds financial discipline, strengthens oversight and develops confidence in committee-based governance.

A Finance Committee should not be presented as a statutory Audit Committee, nor should it assume powers that legislation reserves for such a committee. Its mandate can instead focus on management accounts, budgets, cash flow, working capital, funding, tax and statutory obligations, financial controls, related-party transactions, significant expenditure and the implementation of audit or independent-review findings. Its members may include directors, executives and appropriately skilled advisers, with responsibilities and conflicts of interest addressed clearly in its terms of reference.

For a company establishing formal committees for the first time, this creates a manageable pathway: begin with a focused agenda, establish a regular reporting rhythm, record decisions and actions, and deepen independent challenge as the business grows. The board should review the arrangement periodically and transition to a properly constituted Audit Committee when the law requires it, when the company’s risk and complexity justify it, or when investors, lenders and other stakeholders expect a higher level of independent assurance.

 

Minimum requirements where a statutory Audit Committee is required

  • The committee must comprise at least three members.
  • Its members must be elected by shareholders at the annual general meeting, subject to the limited arrangements that apply to an initial committee or a vacancy.
  • Each member must be a director of the company and must satisfy the statutory independence criteria.
  • A member may not be involved in the day-to-day management of the company, may not have served as a prescribed officer or full-time employee during the preceding three financial years, and may not have a material supplier or customer relationship that could reasonably compromise independent judgement.
  • A member may not be related to a person whose position or relationship would disqualify that person from membership.
  • The committee must collectively possess the prescribed knowledge and experience in areas such as financial reporting, internal financial controls, external and internal audit, risk management, sustainability reporting and governance.
  • The company must provide adequate resources and permit the committee to obtain independent advice where reasonably necessary to perform its duties.
  • The committee must perform its statutory responsibilities, including nominating the external auditor, assessing auditor independence, determining the nature and extent of permissible non-audit services, reviewing financial reporting and internal financial controls, addressing relevant complaints and reporting to shareholders.

The legal requirement establishes the minimum; effective governance asks a further question: what degree of oversight will enable this organisation to protect trust, strengthen accountability and respond intelligently to its particular risks? For a smaller business that is not required to have an Audit Committee, the answer may be a focused Finance Committee supported by targeted external assurance. This creates a practical entry point for a company without independent non-executive directors and allows first-time committee members to build discipline, confidence and capability before the governance structure becomes more complex. For a larger or more complex organisation, the appropriate response will ordinarily be a properly constituted Audit Committee supported by deeper specialist capability.

Relationship to other committees:

  • Risk Committee: oversees the enterprise risk framework and risk appetite. The Audit Committee focuses on the adequacy of controls and assurance over material risks, financial and reporting risks, and fraud. In many entities the two committees hold joint sessions for combined assurance, cyber and business continuity topics.
  • Social and Ethics Committee: oversees ethics, conduct, social and environmental matters. The Audit Committee tests whether ethics-related controls and reporting (including fraud, tip-offs, misconduct metrics and related party transactions) are reliable and fairly presented.

Composition, independence and size

Independence and financial literacy are non-negotiable. Typically:

  • Membership: three to five independent non-executive directors, one as chair. The Companies Act expects independence for public and some private companies that require an Audit Committee.
  • Attendance: CFO, CEO, Chief Audit Executive, Chief Risk Officer, external audit partner and company secretary attend by invitation. Only members vote.
  • Expertise: at least one Chartered Accountant (SA) or equivalent with recent and relevant financial reporting experience; the chair should be independent, financially literate and experienced in leading assurance dialogues.
  • Tenure and refresh: stagger terms to balance continuity with fresh perspective; assess independence annually and after role or relationship changes.
    Who needs an Audit Committee? Public companies, state owned companies and other entities that meet thresholds in legislation or by memorandum of incorporation, and any organisation whose scale or complexity warrants independent assurance oversight.

How many members should it have? Three is a practical minimum; four or five offers resilience for absences and complex workloads.

The Audit Committee skills matrix

Build a matrix and recruit or co-opt to close gaps. Priority capabilities include:

  • Financial reporting and IFRS, JSE and Companies Act literacy
  • Internal control and internal audit methodology
  • External audit, auditor independence, and professional scepticism
  • Combined assurance and assurance mapping
  • Technology, data, AI and cyber risk as these affect reporting, controls and resilience
  • Regulatory compliance affecting reporting (tax, iXBRL, anti-money laundering)
  • Industry economics and business model understanding
  • Ethics, whistleblowing and fraud risk
  • Integrated reporting and ESG data integrity where material to investors and lenders

The 5 C’s that often describe effective audit work are also useful for member behaviour: Competence, Curiosity, Courage, Collaboration and Communication.

Six core functions that deliver results

In practice, six functions anchor a high performing Audit Committee:

  1. Financial reporting integrity: oversee accounting policies, significant judgements, going concern assessments, liquidity disclosures, and fair presentation in annual and interim reports.
  2. Internal controls: evaluate management’s control attestations, monitor remediation of material control deficiencies, and test the effectiveness of key entity level and process controls.
  3. Combined assurance: approve the combined assurance plan, ensure an integrated, risk based approach across the Three Lines Model, and prevent duplication or blind spots.
  4. External audit oversight: recommend appointment, independence and fees, approve scope and materiality, monitor quality, and review key audit matters and findings resolution.
  5. Internal audit oversight: approve the internal audit charter, plan and budget, assess independence and skills, and track issue closure to target dates.
  6. Technology and cyber considerations: understand how IT general controls, data governance, AI use, cybersecurity and business continuity affect financial reporting, fraud risk and resilience; coordinate with the Risk Committee where mandates intersect.

Sample 12 month agenda

Quarter 1

  • Annual planning session, committee self-assessment actions, and skills refresh plan
  • Approve internal audit charter and risk based plan; confirm combined assurance map and roles
  • External audit strategy and materiality; independence and prohibited services check
  • Review control environment and prior year findings closure status

Quarter 2

  • Interim results review; accounting policy updates and significant estimates
  • Cyber and data risk deep dive focused on IT general controls and fraud risk
  • Internal audit progress; high risk findings and remediation timetables
  • Whistleblowing trend analysis and ethics control themes

Quarter 3

  • Pre year end readiness: going concern indicators, liquidity and covenant monitoring
  • Auditor quality and independence evaluation; fee review and rotation planning
  • Assurance on key non-financial metrics used in remuneration or financing
  • Legal, tax and regulatory updates affecting disclosures, including iXBRL

Quarter 4

  • Annual financial statements and integrated report sections within remit
  • Review of key audit matters, unadjusted differences and representation letters
  • Internal control effectiveness statement; combined assurance outcome statement
  • Committee effectiveness review, updated TORs and work plan for the year ahead

Board ready reporting templates

Concise, decision useful packs improve board oversight. Use:

  • Audit Committee chair’s report: one page summary of material matters, decisions, and recommendations.
  • Issue tracker: heat map of significant deficiencies, owner, target date and status.
  • Combined assurance statement: mapping of top risks to assurance providers, coverage, and residual risk confidence level.
  • External audit independence confirmation: services, fees, rotation horizon, and safeguards.
  • Technology and cyber dashboard: control maturity ratings, incidents, recovery metrics and remediation progress.

Red flags from recent South African governance trends

  • Weak going concern and liquidity oversight, especially where off balance sheet or complex financing structures exist.
  • Auditor dependence on management prepared models without robust challenge.
  • ESG and sustainability metrics used in remuneration or funding without control assurance.
  • Cyber incidents that expose gaps in IT general controls, access management and backup discipline.
  • Related party transactions lacking transparent approval trails and disclosure.
  • Skills erosion on committees, with limited technology literacy and overreliance on a single financial expert.

FAQs

  • What does an Audit Committee do? It safeguards financial reporting integrity, oversees internal control and combined assurance, and provides independent oversight of external and internal audit, technology risks that affect controls, and fraud and whistleblowing themes.
  • Who are the members? Independent non-executive directors, typically three to five, with invitees such as the CFO, CEO, Chief Audit Executive, CRO, external auditor and the company secretary.
  • How many members are needed? Three at minimum; four to five is common for resilience and workload.
  • What skills are required? Financial reporting, internal control, external and internal audit, combined assurance, technology and cyber, regulatory literacy, ethics and fraud risk, and sector knowledge.
  • What are the six functions? Financial reporting oversight, internal controls, combined assurance, external audit, internal audit, and technology and cyber considerations.
  • What are the 5 C’s of audit? Competence, Curiosity, Courage, Collaboration and Communication.
  • Who needs an Audit Committee? Public and state owned companies under the Companies Act and entities whose scale or stakeholder expectations warrant independent assurance oversight.
  • What is the main function? To protect the integrity of reporting and the effectiveness of internal control through independent, skilled oversight.

Where FluidRock can help

If you need fit‑for‑purpose committee terms of reference, board evaluations or independence assessments, engage FluidRock Advisory. For CPD‑accredited upskilling of committee members and chairs, the FluidRock Governance Academy offers practical programmes aligned with King V™ and ISO 37000.

Explore our corporate governance advisory services to strengthen committee mandates and evaluation practices, and keep abreast of corporate governance in South Africa through our insights and training.

Summary and next steps

An Audit Committee that is independent, financially literate and technology‑aware can materially improve trust, resilience and decision quality. Clarify the mandate, appoint the right mix of skills, run a disciplined 12‑month plan, and report to the board with sharp, decision‑oriented insights. If you would like help to refresh your TORs, evaluate your committee, or upskill members for King V™ application, contact FluidRock to tailor a practical governance response.

Copyright and trademarks pertaining to the King Reports are owned by the Institute of Directors in South Africa NPC and all of its rights are reserved.

Shopping Cart
Scroll to Top