Board Audit Committee: Duties, Auditor Oversight, and Liability

The audit committee of a board of directors is the group of independent directors responsible for overseeing a public company’s financial reporting, its relationship with the outside auditor, its internal controls, and the channels employees use to report accounting concerns. Federal law requires every company listed on a U.S. national securities exchange to maintain one, and the committee’s responsibilities are set by statute, SEC rule, and exchange listing standards rather than left to the company’s discretion.

Which Companies Must Have an Audit Committee

Section 301 of the Sarbanes-Oxley Act directs the SEC to prohibit national securities exchanges from listing any company that lacks a compliant audit committee.1Office of the Law Revision Counsel. 15 U.S. Code 78j-1 – Audit Requirements In practice, that means every company trading on the NYSE or Nasdaq. The SEC put the mandate into effect through Rule 10A-3, which sets the baseline standards for independence, complaint procedures, and committee authority that exchanges enforce through their own listing rules.2GovInfo. 17 CFR 240.10A-3 – Listing Standards Relating to Audit Committees

Private companies and smaller non-listed issuers are not subject to these requirements. Many still adopt audit committees voluntarily as a governance practice, but the responsibilities described here apply as legal obligations only to public, listed companies.

Who Can Serve on the Committee

Every member of the audit committee must be an independent director. Federal law defines independence with two prohibitions: a committee member cannot accept any consulting, advisory, or other compensatory fee from the company beyond board compensation, and cannot be an affiliated person of the company or its subsidiaries.1Office of the Law Revision Counsel. 15 U.S. Code 78j-1 – Audit Requirements An “indirect acceptance” rule extends those prohibitions to a member’s spouse, minor children, and any entity where the member holds a leadership role.2GovInfo. 17 CFR 240.10A-3 – Listing Standards Relating to Audit Committees

The exchanges add more. The NYSE requires at least three members on the committee.3U.S. Securities and Exchange Commission. NYSE Section 303A.07 Audit Committee Additional Requirements Nasdaq disqualifies anyone employed by the company within the past three years, anyone whose family member served as an executive officer in that period, or anyone who received more than $120,000 in compensation from the company during any twelve consecutive months of the preceding three years, excluding board fees and certain retirement benefits.4Nasdaq Listing Center. Nasdaq Rule 5600 Series

The Financial Expert Designation

Companies must disclose whether at least one audit committee member qualifies as a “financial expert,” and if none does, explain why. The SEC ties the designation to whether the person has, through education or experience, an understanding of generally accepted accounting principles and financial statements, hands-on experience preparing or auditing comparable financial statements, familiarity with internal accounting controls, and an understanding of audit committee functions.5Office of the Law Revision Counsel. 15 U.S.C. 7265 – Disclosure of Audit Committee Financial Expert People typically bring this background from roles as chief financial officer, controller, or public accounting partner.

Overseeing Financial Reporting

The committee reviews the company’s major public financial filings before they reach the SEC, including the annual Form 10-K and the quarterly Form 10-Q. PCAOB standards require the external auditor to communicate significant issues found during interim reviews to the committee before the company files its quarterly report.6Public Company Accounting Oversight Board. AS 4105 – Reviews of Interim Financial Information During these reviews, the committee discusses the selection of accounting methods, significant estimates and adjustments, and whether the numbers consistently reflect the company’s actual financial position.

Committees look for consistency in how revenue and expenses are recognized across periods and flag anything that suggests the financial picture is being dressed up. Catching an aggressive revenue recognition or a questionable accrual before a filing goes out is very different from restating it after the fact. Restatements are expensive, often trigger enforcement investigations, and can pull executive pay back through the clawback rule described below.

The Annual Proxy Statement Report

Every year, the audit committee must publish a formal report in the company’s proxy statement. SEC regulations specify what the report must state: that the committee reviewed and discussed the audited financial statements with management, discussed required matters with the independent auditors, received written disclosures from the auditors about their independence, and, based on all of this, recommended that the board include the audited financial statements in the Form 10-K.7GovInfo. 17 CFR 229.407 – Corporate Governance Every committee member signs by name. The disclosure creates a public record of accountability.

Managing the External Auditor

The committee holds direct, exclusive authority over the company’s external auditor. Federal law makes it responsible for appointing, compensating, and overseeing the outside accounting firm, and requires the auditor to report to the committee rather than to company executives.1Office of the Law Revision Counsel. 15 U.S. Code 78j-1 – Audit Requirements Before Sarbanes-Oxley, auditors often reported to the CFO whose numbers they were checking. The current structure severs that line.

Pre-Approving Non-Audit Services

The committee must pre-approve any non-audit work the external auditor performs for the company, such as tax compliance or certain consulting engagements. Several categories are prohibited outright. External auditors cannot provide bookkeeping services, design financial information systems, perform appraisals or valuations, provide actuarial services, outsource internal audit work, take on management functions, serve as a broker or dealer, provide legal services, or offer expert opinions unrelated to the audit.8U.S. Securities and Exchange Commission. Commission Adopts Rules Strengthening Auditor Independence The rule is that an auditor cannot objectively evaluate work it performed itself.

Partner Rotation

The lead audit partner and the concurring review partner must rotate off the engagement after five consecutive years, followed by a five-year cooling-off period before returning. Other significant audit partners rotate after seven years with a two-year timeout.8U.S. Securities and Exchange Commission. Commission Adopts Rules Strengthening Auditor Independence The committee tracks the schedule and manages transitions.

Internal Controls and Risk Oversight

Section 404 of the Sarbanes-Oxley Act requires management, not the audit committee, to assess and report annually on the adequacy of internal controls over financial reporting. For larger companies, the external auditor must independently attest to that assessment.9Office of the Law Revision Counsel. 15 U.S.C. 7262 – Management Assessment of Internal Controls The committee’s role is to oversee the process: monitoring whether controls actually work, reviewing what the auditor finds, and making sure identified weaknesses get fixed.

Committees meet regularly with the internal audit function to review findings and confirm that management has followed through on corrective actions. Enforcement risk for internal control failures is real. In 2024, the SEC charged Entergy Corporation with internal accounting controls violations and imposed a $12 million civil penalty for failing to accurately record surplus materials in its financial statements.10U.S. Securities and Exchange Commission. SEC Charges Utility Company Entergy Corp. with Internal Accounting Controls Violations

Cybersecurity Oversight

SEC rules adopted in 2023 added cybersecurity to what the committee typically watches. Companies must describe their processes for assessing and managing material cybersecurity risks, identify the board committee responsible for overseeing those risks, and explain how the board stays informed about cybersecurity threats.11U.S. Securities and Exchange Commission. Final Rule – Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure Most public companies have placed that oversight with the audit committee.

Whistleblower and Complaint Procedures

Section 301 requires every audit committee to establish formal procedures for receiving, retaining, and acting on complaints about accounting, internal controls, or auditing matters. The committee must also create a channel for employees to submit concerns anonymously and confidentially about questionable accounting or auditing practices.1Office of the Law Revision Counsel. 15 U.S. Code 78j-1 – Audit Requirements This is a listing requirement, not a suggestion. Employees who report potential securities law violations are also protected from retaliation, and the SEC has brought actions against companies that used confidentiality agreements or internal policies to discourage employees from contacting the Commission.12U.S. Securities and Exchange Commission. Whistleblower Protections

Authority, Funding, and Private Meetings

The committee has statutory authority to hire independent legal counsel and other outside advisors whenever it determines they are necessary, without seeking management’s permission. The company must fund whatever the committee needs, including compensation for the external auditor and any advisors the committee retains.1Office of the Law Revision Counsel. 15 U.S. Code 78j-1 – Audit Requirements The committee itself decides what appropriate funding means. A management team that controls the committee’s budget effectively controls the committee, and the statute removes that lever.

Effective committees also hold executive sessions with the internal audit leader or external auditor with no member of management in the room. These meetings give auditors a place to raise concerns they might not voice in front of the CFO. Most well-run committees hold executive sessions at every regular meeting.

Triggering the Executive Compensation Clawback

SEC Rule 10D-1, adopted under the Dodd-Frank Act and effective for listed companies since late 2023, requires every listed company to maintain a written policy for recovering executive compensation awarded on financial results that later turn out to be wrong. If the company restates its financials, whether because of a material error or a smaller correction that would be material if left uncorrected, it must recover the excess incentive-based compensation received by current or former executive officers during the three completed fiscal years before the restatement.13eCFR. 17 CFR 240.10D-1 – Listing Standards Relating to Recovery of Erroneously Awarded Compensation

Recovery is mandatory regardless of whether the executive was personally responsible for the error, and the company cannot indemnify executives against clawback losses or insure them against it.13eCFR. 17 CFR 240.10D-1 – Listing Standards Relating to Recovery of Erroneously Awarded Compensation The compensation committee usually administers the policy, but the audit committee’s oversight of financial reporting is what identifies the restatement that starts the process.

Personal Liability for Committee Members

Serving on an audit committee carries real legal exposure. The SEC does not typically pursue enforcement actions against independent directors just for holding a board seat, but the Commission has charged individual committee members who ignored clear warning signs of fraud or helped conceal financial problems. The threshold is generally willful blindness: repeatedly failing to investigate red flags an attentive director would have noticed.

Past enforcement actions have involved directors who ignored material weakness letters from auditors, failed to act on auditor resignations, disregarded internal complaints about inventory overvaluation, or omitted critical information when reporting to the full board. In one case, audit committee members faced charges for delaying required filings to hide an auditor’s going concern opinion about the company’s viability. The common thread is not a bad judgment call. It is the choice to stop paying attention.

The practical protection for individual members is doing the work: asking hard questions about red flags, documenting discussions, ensuring complaints get investigated, and insisting on private time with the auditors. Committees that treat the role as ceremonial are the ones that end up in enforcement proceedings.