Audit Committee | Pillar 4: Board Committees
Audit Committee
Composition, Duties, Relationship with External and Internal Auditors
First: Introduction
The audit committee is among the most important, most sensitive, and most regulated committees in corporate governance. It is the committee responsible for overseeing financial integrity, the soundness of financial statements, the effectiveness of internal control system, the independence of external and internal audit, and regulatory compliance. The financial scandals that hit global markets — from Enron and WorldCom in the early 2000s to recent crises — have all revealed the importance of audit committees. Strong audit committees are an essential line of defense against fraud and material errors.
In the Saudi system, the audit committee is mandatory in every listed company without exception. The Corporate Governance Regulations precisely detail its composition, duties, and operating standards. This focus reflects the legislator’s awareness of the committee’s importance in protecting shareholders and capital market integrity. This article reviews the audit committee in depth: composition, qualifications, duties, relationships with auditors and management, challenges, and best practices.
| 💡 Key Insight The audit committee is the guardian of financial integrity. Its primary role is not to do the audit itself but to ensure that audit (internal and external) is conducted with the highest standards of independence and quality, and that financial statements reflect economic reality accurately. A strong audit committee makes investors trust the company’s numbers. |
Second: Regulatory Framework
1. Saudi Companies Law
The Companies Law provides for the existence of an audit committee in listed joint-stock companies and specifies its general powers.
2. Corporate Governance Regulations
The regulations detail audit committee provisions in articles 54-57, specifying:
- Mandatory Formation: In every listed company.
- Composition: 3-5 members.
- Independence: All members non-executive, majority independent, independent chair.
- Financial Expertise: At least one member with financial and accounting expertise.
- Authorities: Detailed in the law.
- Disclosure: Mandatory in annual report.
3. International Standards
The audit committee draws on multiple international standards:
- US Sarbanes-Oxley Act (SOX): Pioneer model for committee oversight.
- UK Corporate Governance Code: Detailed best practices.
- EU Audit Directive.
- IFAC Standards.
- PCAOB Guidance.
Third: Committee Composition
1. Member Count
The Corporate Governance Regulations specify member count between 3 and 5:
- 3 members: Suitable for small companies.
- 5 members: Suitable for large companies with audit complexity.
2. Member Types
2.1 Independent Members
- Must constitute the majority of members.
- Committee chair must be independent.
- Bring complete objectivity to discussions.
2.2 Non-Executive Members
- Acceptable to be non-independent (such as major shareholder representatives).
- Provide diverse perspectives.
- All must be non-executive in the company.
2.3 Executive Members
- Prohibited from membership.
- Important for committee independence.
- Avoids self-oversight conflict.
3. External Members
In some Saudi systems, audit committee may include members from outside the board:
- Provides additional specialization (such as a specialized retired auditor).
- Permitted if the articles of association provide for it.
- Must meet same competence and independence conditions.
Fourth: Required Member Qualifications
1. Required Member
At least one member must have:
- Financial accounting expertise.
- Ability to understand and analyze financial statements.
- Knowledge of accounting standards (IFRS).
- Auditing experience or specialty (CPA preferred).
2. Other Members
Other members should possess at least:
- Basic understanding of financial statements.
- Ability to read financial reports.
- Capacity to ask substantive questions.
- Awareness of risks and control.
3. Required Personal Qualities
- Integrity: Absolute necessity.
- Objectivity: In handling sensitive information.
- Sufficient Time: Audit committee work is heavy.
- Courage: To raise difficult questions.
- Independence of Thought: Even within independence.
4. Continuous Training
Audit committee members need continuous training in:
- Updates in accounting standards.
- New audit standards.
- Regulatory developments.
- Emerging risks (especially cyber).
- New audit techniques.
Fifth: Main Committee Duties
1. Oversight of Financial Statements
1.1 Reviewing Quarterly and Annual Statements
- Reviewing financial statements before publication.
- Discussing significant changes.
- Verifying disclosure of all required information.
- Recommending board approval (or amendment).
1.2 Following Up Accounting Standards Application
- Following up updates in IFRS.
- Verifying their correct application.
- Reviewing complex accounting estimates.
- Discussing significant accounting choices.
1.3 Following Up Material Disclosures
- Reviewing periodic disclosures to Tadawul.
- Verifying their accuracy.
- Following up on related party transactions.
- Reviewing analyst presentations.
2. Oversight of External Audit
2.1 External Auditor Selection
- Recommending auditor selection to the board.
- Reviewing auditor independence.
- Evaluating reputation and competence.
- Considering fees.
- Periodic rotation (per regulations).
2.2 Periodic Auditor Communication
- Pre-audit meetings to discuss plan and scope.
- Post-audit meetings to discuss results.
- Private discussion with auditor (without management).
- Receiving direct communications.
2.3 Reviewing Audit Results
- Reviewing audit report.
- Discussing significant observations.
- Following up auditor recommendations.
- Ensuring response to observations.
2.4 Auditor Independence
- Periodic review of independence.
- Approval of additional services from auditor.
- Limiting permissible additional services.
- Disclosure of additional fees.
3. Oversight of Internal Audit
3.1 Appointing Head of Internal Audit
- Recommending head appointment to the board.
- Annual performance evaluation.
- Approving compensation.
- Recommending dismissal if necessary.
3.2 Approving Audit Plan
- Annual review of plan.
- Verifying scope adequacy.
- Verifying resource adequacy.
- Periodic plan amendment if needed.
3.3 Receiving Audit Reports
- Periodic reports on findings.
- Discussing fundamental observations.
- Following up management response.
- Discovered fraud reports.
3.4 Evaluating Function Effectiveness
- Function effectiveness assessment.
- Function independence.
- Resources and budget.
- Continuous improvement.
4. Oversight of Internal Control
- Assessing internal control system effectiveness.
- Reviewing identified weaknesses.
- Following up improvement plans.
- Communication with risk function.
- Coordination with risk committee.
5. Oversight of Regulatory Compliance
- Following up CMA disclosure requirements.
- Reviewing tax and Zakat compliance.
- Following up sectoral regulations.
- Reviewing identified violations.
- Coordination with governance committee.
6. Oversight of Related Party Transactions
- Reviewing all transactions before approval.
- Verifying fair pricing.
- Verifying compliance with disclosure procedures.
- Reporting to the board and assembly.
7. Receiving Whistleblower Reports
- Approving whistleblowing policy.
- Receiving direct reports.
- Investigating reports.
- Protecting whistleblowers.
- Following up corrective actions.
| 📌 Note The audit committee’s duties are wide-ranging and complex. Carrying them out requires significant time investment from members — often more time than any other committee. Companies should be realistic in expectations and provide audit committee members with appropriate compensation reflecting this workload. |
Sixth: Relationship with External Auditor
1. Importance of the Relationship
The relationship between audit committee and external auditor is the cornerstone of audit integrity:
- Auditor reports directly to the committee.
- Committee is auditor’s protection from management pressure.
- Communication is regular and open.
- Confidentiality respected from both sides.
2. Periodic Meetings
- Before annual audit: Discussing plan and scope.
- After half-year audit: Discussing initial findings.
- Before publishing annual statements: Discussing final results.
- Quarterly meetings: Following up periodic reviews.
- Private session: In each meeting, without management.
3. Topics for Discussion
- Audit scope and approach.
- Identified risks and how to address them.
- Significant observations.
- Disagreements with management.
- Application of accounting standards.
- Complex accounting estimates.
- Internal control weaknesses.
- Frauds discovered or suspected.
- Auditor independence.
4. Auditor Independence Test
The committee periodically tests auditor independence:
- Reviewing services provided by auditor.
- Verifying absence of conflict.
- Verifying compliance with rotation requirements.
- Reviewing partners and personal interests.
5. Auditor Change
Auditor change is a sensitive matter requiring caution:
- Justifying the change.
- Avoiding change due to disagreement on accounting matters.
- Disclosure of change reasons.
- Communication with new auditor for smooth transition.
Seventh: Relationship with Internal Audit
1. Reporting Line
Head of internal audit reports primarily to the audit committee, not management:
- Functional reporting to committee.
- Administrative reporting may be to CEO or chairman.
- Committee appoints and dismisses the head.
- Committee approves compensation.
- Committee evaluates performance.
2. Annual Audit Plan
The committee approves the annual plan:
- Comprehensive coverage of significant operations.
- Risk-based prioritization.
- Sufficient resources for execution.
- Flexibility for emerging changes.
3. Periodic Reports
The committee receives:
- Detailed reports on each audit task.
- Identified observations.
- Risk assessment.
- Management response.
- Implementation follow-up.
4. Periodic Function Evaluation
- Function effectiveness.
- Personnel competence.
- Resource adequacy.
- Compliance with international standards.
Eighth: Relationship with Executive Management
1. Open Cooperation
The committee needs CFO, CEO, and other officials cooperation:
- Attending meetings as needed.
- Providing requested information.
- Answering questions transparently.
- Implementing approved recommendations.
2. Limits of Cooperation
Cooperation does not mean loss of independence:
- Committee meets in closed session without management.
- Direct communication with auditors without management mediation.
- Right to engage independent advisors.
- Right to investigate without management permission.
3. Sensitive Cases
- Suspicions of executive management fraud.
- Disclosure of significant accounting errors.
- Disagreements with management on critical accounting matters.
- Whistleblower reports involving management.
Ninth: Audit Committee Charter
1. Importance of Charter
Committee charter is the document detailing all aspects of its work:
- Defines duties and responsibilities.
- Determines authorities and limits.
- Specifies operating mechanism.
- Forms basis for accountability.
- Tool for transparency to shareholders.
2. Charter Components
- Introduction: Background and purpose.
- Composition: Member count, independence, qualifications.
- Duties: Detailed in each area.
- Authorities: What the committee can do.
- Meetings: Frequency, quorum, agenda.
- Reports: To the board, frequency, content.
- Resources: Right to engage advisors, secretarial support.
- Confidentiality: Confidentiality requirements.
- Review: Periodic charter review.
3. Charter Approval
- Drafted by the committee.
- Reviewed by legal advisor.
- Approved by the board.
- Annual or biennial review.
- Disclosed on company website.
Tenth: Common Challenges
1. Information Overload
Audit committee receives huge volumes of information:
- Massive financial statements.
- Detailed audit reports.
- Internal audit reports.
- Regulatory documents.
Treatment:
- Effective executive summaries.
- Reliance on specialized advisors.
- Sufficient time for review.
2. Material Estimates Challenge
Some accounting matters involve significant estimates:
- Goodwill impairment.
- Defined benefit obligations.
- Pricing complex financial instruments.
- Provisions for litigation and contingent liabilities.
Treatment:
- Deep questioning of management.
- Independent expert opinion.
- Comparison with peers.
- Documentation of accepted rationale.
3. Auditor Independence Challenge
Maintaining auditor independence amid pressures:
- Long-standing relationships with management.
- Additional services.
- Fees affected by client relationship.
Treatment:
- Periodic partner rotation.
- Strict limits on additional services.
- Annual independence review.
- Direct committee-auditor relationship.
4. Fraud Challenge
Detecting fraud is among the most difficult tasks:
- Top-management fraud is hardest to detect.
- Anti-fraud controls may be evaded.
- Whistleblowing culture insufficient in some companies.
Treatment:
- Effective whistleblowing system.
- Whistleblower protection.
- Independent investigations.
- Anti-fraud culture from top.
Eleventh: Audit Committee Disclosure
1. Annual Report
Audit committee includes a separate report in annual report covering:
- Committee composition and member experience.
- Number of meetings and attendance.
- Tasks performed during the year.
- Reviewing financial statements.
- Communicating with external auditor.
- Overseeing internal audit.
- Significant findings.
- Performance evaluation.
2. Special Disclosures
- Material changes in accounting policies.
- Significant disagreements with management.
- Whistleblowing system.
- Discovered fraud.
Twelfth: Best Practices
1. At Composition Level
- Independent majority: Beyond regulatory minimum.
- Strong financial expertise: Two members instead of one.
- Distinguished chairmanship: Financial leadership experience.
- Real time: Sufficient for tasks.
2. At Operational Level
- Regular meetings: Quarterly minimum.
- Closed sessions: In every meeting.
- Open communication: With auditors.
- Continuous training: Especially in regulatory updates.
3. At Effectiveness Level
- Specialized secretariat: In financial and audit matters.
- Independent advisors: When needed.
- Annual evaluation: Of committee performance.
- Transparent disclosure: Beyond minimum required.
4. At Cultural Level
- Strong relationship with auditors: Built on trust and respect.
- Active questioning: Of management.
- Constructive skepticism: In accepting estimates.
- Whistleblowing culture: Protected and encouraged.
Conclusion
The audit committee is the guardian of financial integrity and the cornerstone of capital market confidence. A strong, independent, qualified committee makes financial statements reliable, investors confident, and the company a model of governance. A weak, formal, or non-independent committee creates risk for the company and the market as a whole.
Saudi companies today, with the developed regulatory framework, possess the basis for building advanced audit committees. Going beyond the regulatory minimum, investing in distinguished competencies, building strong cultures of constructive skepticism and whistleblowing, are factors distinguishing leading companies. Strong audit committees are a long-term investment in corporate sustainability and market integrity, the dividends of which are seen in every financial disclosure and every confidence-building moment.
| 🎯 Essential Points to Remember (1) Audit committee is mandatory in every Saudi listed company. (2) Composition: 3-5 members, all non-executive, majority independent, independent chair. (3) Mandatory financial expertise in at least one member. (4) Main duties: oversight of financial statements, external audit, internal audit, internal control, compliance, related party transactions, whistleblower reports. (5) Audit committee’s relationship with external auditor is the cornerstone — direct, regular, with closed sessions. (6) Head of internal audit functionally reports to the committee. (7) Committee charter is the document detailing all aspects of work. (8) Challenges: information overload, material estimates, auditor independence, fraud. (9) Disclosure: special report in annual report. (10) Best practices: strong competencies, regular meetings, closed sessions, transparent disclosure. |
Frequently Asked Questions
What are the mandatory composition requirements for an audit committee in Saudi listed companies?
Articles 54 to 57 of the CMA Corporate Governance Regulations require every listed company without exception to form an audit committee with three to five members, all of whom must be non-executive, a majority must be independent, and the chair must be independent. Executive members are prohibited from membership to eliminate self-oversight conflict. At least one member must possess financial and accounting expertise defined as the ability to understand and analyze financial statements, deep knowledge of IFRS, and auditing experience with a CPA or equivalent credential preferred. Other members must at minimum be able to read financial reports, ask substantive questions, and understand risk and control concepts. Beyond technical qualifications, every member must possess integrity, objectivity in handling sensitive information, sufficient time given the committee's heavy workload, the courage to raise difficult questions, and genuine independence of thought. The committee chair must not be the board chairman and must hold deep financial leadership experience. Some companies appoint external members from outside the board such as retired specialized auditors where the articles of association permit it, subject to the same competence and independence conditions.
What are the main duties of the audit committee and how does it manage the external auditor relationship?
The audit committee's duties span seven interconnected areas. Financial statement oversight by reviewing quarterly and annual statements before publication, verifying IFRS application including complex accounting estimates, and recommending board approval. External audit oversight by recommending auditor selection, evaluating independence and competence, and approving fees. Internal audit oversight by recommending the head of internal audit appointment, approving the annual plan, receiving periodic reports, and evaluating function effectiveness. Internal control oversight by assessing system effectiveness and following up weaknesses. Regulatory compliance oversight including CMA disclosures, tax and Zakat, and sectoral regulations. Related party transactions review before approval to verify fair pricing and disclosure compliance. Whistleblower management including approving policy, receiving direct reports, and ensuring whistleblower protection. The external auditor relationship is the cornerstone of audit integrity — the auditor reports directly to the committee, not management. The committee meets with the auditor before the annual audit to discuss plan and scope, after mid-year to discuss initial findings, before publishing annual statements to discuss final results, and holds a private closed session in every meeting without management present. The committee annually tests auditor independence by reviewing all services provided, verifying absence of conflict, and ensuring compliance with rotation requirements.
What are the most common challenges facing audit committees in Saudi Arabia and what are best practices for addressing them?
Four challenges recur across Saudi audit committees. Information overload from massive financial statements, detailed audit reports, internal audit findings, and regulatory documents — addressed through effective executive summaries, clear prioritization, reliance on specialized advisors, and allocating sufficient pre-meeting review time. Material accounting estimates such as goodwill impairment, defined benefit obligations, complex financial instrument pricing, and litigation provisions — addressed through deep questioning of management assumptions, obtaining independent expert opinions, benchmarking against peers, and documenting the rationale for accepted estimates. Auditor independence challenged by long-standing management relationships and additional service revenue — addressed through periodic partner rotation, strict limits on permitted additional services, annual independence reviews, and building the committee's direct relationship with the auditor rather than routing communication through management. Fraud detection which is hardest when fraud involves senior management — addressed through an effective protected whistleblowing system, independent investigations free from management interference, and building an anti-fraud culture visible from the top. Best practices that distinguish leading Saudi audit committees include having two members with strong financial expertise rather than the regulatory minimum of one, holding closed sessions with auditors in every single meeting, annual performance evaluation of the committee itself, transparent disclosure beyond the regulatory minimum in the annual report, and a specialized secretariat in financial and audit matters.
References and Sources
- Corporate Governance Regulations issued by the Capital Market Authority — Articles 54-57.
- Saudi Companies Law (Royal Decree M/132).
- Implementing Regulations of the Companies Law for Listed Joint-Stock Companies.
- Sarbanes-Oxley Act (SOX) — US Standards.
- UK Corporate Governance Code — Audit Committee Practices.
- PCAOB Standards — Audit Committee Communications.
- IFAC Standards — Audit Committee Best Practices.
- ICGN Global Governance Principles.
- Deloitte — Audit Committee Effectiveness Guide.
- KPMG / EY / PwC — Audit Committee Reports.



