🎉 Celebrating 25 YEARS of helping organisations confidently take risk 🎉

Audit and Risk Committee Effectiveness: 9 Governance Failure Lessons

Audit and Risk Committee effectiveness lessons from seven major governance failures

Audit and Risk Committee Effectiveness: Lessons from Nine Major Governance Failures

An Audit and Risk Committee (ARC) can have an approved charter, qualified members, regular meetings and comprehensive reports – and still fail to see a major problem developing. Audit and Risk Committee effectiveness is different to Audit and Risk Committee compliance.

History shows that governance failure rarely results from the absence of formal structures alone. More commonly, the structures exist but don’t work as intended. Information is incomplete. Warning signs are normalised. Remediation is repeatedly deferred. Audit and Risk Committee members can become too accepting of management explanations. Risks that do not immediately affect financial performance or have a material regulatory or stakeholder impact, often receive insufficient attention.

Our research does not suggest that an Audit and Risk Committee was solely responsible for each governance failure in this publication. Management owns risk, the board remains accountable, and regulators, auditors and assurance functions also play important roles. However, the cases presented here demonstrate what can happen if audit and risk oversight does not provide the independent challenge, escalation and accountability an organisation needs.

Throughout this article, ‘ARC’ refers to any committee responsible for audit and risk oversight. This includes a standalone audit committee, risk committee, combined audit and risk committee, or audit, risk and improvement committee (ARIC) for NSW local government.

What is audit and risk committee effectiveness?

Audit and Risk Committee effectiveness is not well defined. There is no one definition of what Audit and Risk Committee effectiveness is.

Looking at a number of credible ARC guidelines from the Auditing and Assurance Standards Board, Australian Institute of Company Directors, Institute of Internal Auditors-Australia as well as state based Audit Office publications, we define Audit and Risk Committee effectiveness as follows:

the committee’s ability to provide high-quality independent assurance, oversight of governance and informed and constructive advice that enhances an organisation’s governance, risk management, compliance, internal control, and financial reporting frameworks that support the organisation to achieve its objective.

Audit and Risk Committee effectiveness is not a static state but a multi-dimensional measure of how well a committee fulfils its mandate to protect stakeholder interests and support organisational objectives. Also, the range of advice the ARC provides can vary and should be included in the Audit and Risk Committee Charter.

Five elements of audit committee effectiveness

In 2020, the Queensland Audit Office undertook an audit of the effectiveness of audit committees in state government entities.  As part of the audit, the Auditor-General identified a continuous cycle built on five elements that impacted audit committee effectiveness.

Audit and risk committee effectiveness

Source: Queensland Audit Office

  1. Engaged leadership:  Without visible support and engagement from the chief executive officer or governing body, an audit committee loses relevance and becomes less effective, no matter how skilled or experienced its members are.
  2. A focused role: A committee can only direct its limited time to where it matters most if it has a clear view of the maturity of the entity’s governance, risk and control systems, rather than spreading its attention evenly across every item in its charter.
  3. The right members: Independence, external perspective and relevant subject matter, technical and sector expertise are what allow a committee to ask difficult questions and test management’s assumptions rather than simply endorse them.
  4. Valuable meetings: If members are overwhelmed with volume (500 page ARC meeting papers) rather than given targeted, decision-useful information, meetings become an exercise in processing paper rather than in genuine oversight and discussion.
  5. Continuous improvement: A committee that skips its annual self-assessment, 3 year external ARC performance review or leaves new members without induction training has no reliable way of knowing whether it is still performing its role effectively.

Learning from failure

These nine governance failures presented here are real, and the organisations and individuals involved lived through their consequences. But their inclusion here does not imply that the ARC involved was ineffective, nor that these nine cases are representative of Audit and Risk Committees generally – the vast majority of ARCs operate every year without ever appearing in a royal commission or public inquiry report.

An inactive or under-resourced ARC does not, by itself, guarantee a poor outcome. But where it coincides with other warning signs e.g. a weak organisational culture, under-developed internal controls, or broader governance gaps, the combined risk of a serious failure rises sharply. In several of the cases below, it is difficult to say which came first: the compromised ARC or the conditions that compromised it. Both are usually symptoms of the same underlying weakness.

The value in looking closely at these failures is to ask, as an ARC member: what would I need to see, hear or challenge to ensure this doesn’t happen in my organisation, or on my watch? Read this way, the lessons that follow are recurring patterns worth testing against your own committee’s practice – not proof that a particular committee caused a particular failure, but a prompt to examine whether the same conditions could be quietly forming in your own oversight environment.

HIH Insurance: Expertise without effective challenge

HIH Insurance entered provisional liquidation in March 2001. By August 2001, the estimated deficiency across the group was between $3.6 billion and $5.3 billion, making it Australia’s largest corporate failure at the time.

The HIH Royal Commission concluded that the primary reason for the collapse was a failure to provide adequately for future insurance claims. This was not simply a technical actuarial problem. It reflected mismanagement, poor strategic decisions, inadequate oversight and a corporate culture in which unpleasant information was too readily filtered or disregarded.

HIH’s board wasn’t short on expertise. It had insurance professionals, accountants and lawyers around the table – even a former Big Four audit partner on the audit committee itself. None of it was enough. Management largely controlled what the board saw, directors rarely pushed back hard enough on the assumptions underneath the numbers, and the board never established real independence from the CEO.

If you’re on an ARC today, the uncomfortable question HIH raises isn’t “do we have the right qualifications in the room”, it’s “when was the last time someone in this room asked a question management didn’t want to answer?”

The lesson for Audit and Risk Committee effectiveness is clear: qualifications and experience are valuable, but they do not compensate for weak information, excessive reliance on management or an unwillingness to pursue difficult questions.

Read the Australian Treasury’s summary of the HIH collapse.

National Australia Bank: Warning signs that did not reach the right forum

In January 2004, National Australia Bank announced losses of $360 million from unauthorised foreign-currency options trading. Four traders had exploited weaknesses in systems and processes, concealed losses through false transactions and continued breaching risk limits.

The subsequent investigation identified failures in management supervision, back-office monitoring, escalation, risk management and financial controls. It also found a culture in which staff suppressed bad news rather than escalating it.

The committee-level findings are particularly instructive. NAB’s Principal Board Risk Committee held its first meeting in November 2003, but the desk’s repeated limit breaches never reached it. Instead, management reassured the committee that the broader Markets Division was operating within its limits. The Audit Committee had received reports containing indications of control weaknesses, but further probing may have exposed the seriousness of the breakdowns.

This was not a case where warning signs did not exist. Limit breaches, internal audit findings, market concerns and regulatory correspondence were all present. The governance system failed to connect the dots and escalate them.

For enhanced Audit and Risk Committee effectiveness, aggregate reporting can be particularly dangerous when it masks a material problem within one business unit, project, portfolio or control environment.

See NAB’s 2004 Annual Report containing a number of disclosures and references to the unauthorised foreign-currency options trading transactions.

Commonwealth Bank: Financial success masked non-financial risk

APRA’s 2018 Prudential Inquiry into the Commonwealth Bank found significant weaknesses in governance, culture and accountability, particularly in relation to operational, compliance and conduct risks.

The Inquiry found inadequate oversight and challenge by the Board and its gatekeeper committees, unclear accountability for key risks, weaknesses in issue escalation and a lack of urgency in resolving identified problems. It described an operational risk framework that worked better on paper than in practice.

CBA’s sustained financial success contributed to complacency. It reduced the perceived urgency of non-financial risks and allowed overdue audit and risk issues to be tolerated. A highly collegial culture also made constructive criticism and individual accountability more difficult.

The lesson is that strong financial performance is not evidence of a strong control environment. It may, in fact, make weaknesses harder to recognise.

To improve Audit and Risk Committee effectiveness, look beyond financial results and ask whether complaints, incidents, regulatory breaches, technology failures, control deficiencies and conduct issues reveal a deteriorating risk profile.

Read APRA’s CBA Prudential Inquiry Final Report.

The Hayne Royal Commission: Responsibility remains with boards and management

The 2019 Financial Services Royal Commission placed primary responsibility for industry misconduct on the entities concerned and those who managed and controlled them – their boards and senior management.

The Commission connected misconduct with organisational culture, governance and remuneration. It also drew heavily on the CBA Prudential Inquiry, asking whether boards and their gatekeeper committees provided adequate oversight and challenge of emerging non-financial risks.

The findings demonstrated that conduct risk cannot be treated as a narrow compliance matter. Remuneration, product design, customer treatment, complaints, breach reporting and management accountability can all create material governance risks.

For ARCs, the critical question is not merely whether an activity is legally permitted. It is also whether the activity is appropriate, consistent with organisational values and likely to produce fair and sustainable outcomes.

Read Volume 1 of the Royal Commission’s Final Report.

ASX: When financial priorities overtake stewardship

ASIC’s March 2026 final report into ASX found long-standing and deeply embedded shortcomings in governance, capability, culture and risk management.

The Inquiry concluded that ASX had become disconnected from its stewardship role as an operator of critical market infrastructure. Short-term financial objectives had too often taken precedence over investment in technology, systems, people and operational resilience.

The report found that governance arrangements did not provide sufficient focus on individual ASX licensees and their infrastructure responsibilities. It also identified complex risk and compliance frameworks, blurred accountability across the three lines, weaknesses in control testing and a reactive approach to incidents and remediation.

ASX operated a combined Audit and Risk Committee until June 2025, when separate Risk and Audit and Supervision Committees were established. The Inquiry welcomed the increased board-level focus on risk but emphasised the need for clearer accountability and timely action when risks move outside tolerance.

The lesson is clear: an ARC must test whether strategic and capital decisions serve the organisation’s purpose, obligations and long-term resilience. Near-term financial targets are not enough.

Read ASIC’s Inquiry into the ASX Group Final Report.

Carillion: An assurance system that did not reveal the underlying reality

UK construction and services group Carillion entered compulsory liquidation in January 2018 with liabilities of nearly £7 billion and only £29 million in cash.

A UK parliamentary inquiry concluded that the board had failed to challenge executives effectively and that aggressive accounting practices presented an overly positive picture of the company’s position. It also strongly criticised the external auditor, internal audit provider and regulators.

The failure was not confined to one committee or one assurance provider. It involved the wider governance and assurance ecosystem: management reporting, board challenge, accounting judgements, internal audit, external audit and regulatory oversight.

Carillion demonstrates why an ARC cannot assume that the presence of multiple assurance providers means the organisation is adequately assured. The committee must understand what each provider has examined, where assurance gaps remain and whether different sources of evidence tell a consistent story.

Read the UK Parliament’s findings on Carillion.

Wirecard: Oversight structures arrived too late

Wirecard collapsed in 2020 after reporting that billions of Euros supposedly held in trust accounts probably did not exist. The company also questioned whether its previous descriptions of its third-party acquiring business were accurate.

The scandal exposed one of Europe’s largest corporate frauds, revealing €1.9 billion in fictitious assets and years of inflated revenue created through forged bank letters and sham third-party processors.

The governance structure itself was a warning sign. Wirecard had not established separate supervisory board committees while its board remained relatively small. Audit and Risk and Compliance Committees were only created in the first quarter of 2019, despite the company’s rapid growth and increasing international complexity.

Wirecard also departed from the German Corporate Governance Code recommendation that the Supervisory Board Chair should not simultaneously chair the Audit Committee.

The scandal ultimately exposed failures across management, supervisory governance, external audit and the German financial-reporting enforcement system. The European Securities and Markets Authority (ESMA) later identified deficiencies in the regulatory examination of Wirecard’s financial reports, including insufficient professional scepticism and inadequate attention to media and whistleblower allegations.

The lesson for Audit and Risk Committee effectiveness is that governance arrangements must evolve with organisational scale, complexity and risk. A committee structure that may have been adequate for a smaller organisation can become dangerously insufficient as operations expand.

Read ESMA’s findings on regulatory supervision.

Central Coast Council: Information quality & escalation of financial risks

Central Coast Council’s 2020 financial crisis demonstrates that an ARIC cannot effectively oversee risks it is not shown. Council’s unrestricted cash position had become negative, but this was not highlighted in investment reports provided to councillors. The Public Inquiry found that the ARIC, which met four to five times annually and had a broad agenda, was not briefed on Council’s deteriorating financial position until June 2020.

Importantly, the Inquiry did not find that the ARIC had a central or peripheral role in causing the financial crisis. Instead, the case highlights a wider governance weakness: critical financial information did not reach the governing body or its assurance committee early enough or clearly enough. Following the crisis, Council expanded the ARIC Charter to provide greater oversight of financial performance and the controls introduced by Council.

For local government ARICs, the lesson is clear: formal oversight is not enough on its own. Committees need timely, exception-based reporting on unrestricted cash, budget performance, and emerging control failures. ARICs must control the meeting plan and agenda.

Read the 2022 Central Coast Council Public Inquiry Report.

Queensland councils: Absent or inactive audit committees

A 2025 Queensland Audit Office review found that 12 local governments did not have an audit committee and a further two had committees that did not meet during the year. The Audit Office assessed nine of the 12 councils as being at high risk of financial unsustainability.

The Audit Office also found that councils without active audit committees or internal audit functions were more likely to finalise financial statements late. They also took longer to resolve significant control deficiencies. The findings show that simply establishing an audit committee is not enough. It must meet regularly, have appropriate independence and expertise, receive unrestricted access to information, and actively monitor how significant issues are resolved.

For smaller and regional councils, resource constraints are real, but that does not remove the need for independent oversight. Joint or shared committee arrangements can provide access to expertise while keeping costs proportionate.

Read the 2025 Queensland Audit Office’s Insights on Audit Committees in Local Government

The questions every ARC should ask

Formal compliance does not necessarily mean effective oversight. An ARC can have an approved charter, experienced members, regular meetings and detailed reports, yet still fall short of providing the challenge and assurance the organisation needs.

A high-performing ARC should periodically step back from its agenda and ask:

  • Are we receiving the information we need, or only the information management chooses to present?
  • Which risks, incidents, control weaknesses or audit findings have recurred despite previous remediation?
  • Are significant matters presented clearly, or concealed by aggregate ratings, optimistic commentary and high-level dashboards?
  • When did we last hear directly from risk owners, internal audit, external audit or frontline management, without unnecessary executive filtering?
  • Do we have the expertise, independence and confidence to challenge emerging financial and non-financial risks?
  • Do we require evidence that significant actions have been implemented and are working before agreeing to closure?
  • Are we measuring our effectiveness by the meetings we hold – or by the risks we help the organisation understand and address?

Frequently asked questions

How should Audit and Risk Committee effectiveness be assessed?

The assessment should examine both how the committee operates and the value it provides. It should consider the quality of meeting papers, coverage of significant risks, member skills and independence, meeting dynamics, the level of challenge applied to management, access to assurance providers, monitoring of agreed actions and the quality of advice provided to the board or governing body.

A robust assessment normally combines document review, confidential interviews or surveys, observation of committee meetings and comparison against the committee’s charter, regulatory requirements and better practice. It should result in practical, prioritised improvement actions – not simply an overall performance rating.

How often should an ARC undertake an independent performance review?

The committee should assess its performance annually and track agreed improvements. For most organisations, an independent review every two to three years is a sensible practice, with an earlier review following significant changes in membership, organisational risk, regulatory scrutiny or a major governance or control failure.

For NSW councils, the governing body must review, or arrange an external review of, ARIC effectiveness at least once every council term – currently every four years. The NSW guidelines allow a suitably qualified external assessor or peer to undertake the review or independently evaluate the governing body’s findings.

What are the warning signs of an ineffective Audit and Risk Committee?

Common warning signs include limited challenge of management, recurring or long-overdue audit findings, excessive reliance on dashboards, little direct engagement with risk owners and assurance providers, weak oversight of non-financial risks, insufficient industry or specialist expertise, poor-quality meeting papers and actions being closed without evidence that the underlying issue has been resolved.

Other indicators include meetings dominated by presentations rather than discussion, consistently optimistic reporting, repeated deferral of difficult matters and an inability to demonstrate how the committee’s work has improved governance, risk management or organisational performance.

These questions can be difficult for a committee to answer objectively. An independent ARC performance review can provide a clearer view of what is working, where oversight may be falling short and what practical changes would strengthen the committee’s contribution.

How we can help

InConsult provides independent ARC performance reviews tailored to your organisation, sector, risk profile and budget. We assess how effectively the committee operates – not just whether it meets formal requirements – and provide practical recommendations to strengthen oversight, challenge, accountability and outcomes. From a digital scorecard or focused health check to a comprehensive review involving confidential interviews and meeting observations, we can help your ARC identify blind spots and operate with greater confidence and impact.

If your ARC is preparing for a regulatory review, has recently changed in composition, is navigating a period of elevated risk, or simply wants an honest external perspective on what is working and what is not, lets talk.