Mandate
The Audit and Risk Committee has been established by the Chief Executive of the Australian Financial Security Authority (the Agency) in compliance with section 45 of the Public Governance, Performance and Accountability Act 2013 (PGPA Act) and section 17 of the Public Governance, Performance and Accountability Rule 2014 (PGPA Rule). It has the authority of the Chief Executive to carry out the activities prescribed in this Charter.
Role
The objective of the Audit and Risk Committee is to provide independent advice to the Chief Executive on the appropriateness of the Agency's financial and performance reporting, system of risk oversight and management, and system of internal control.
Functions
In accordance with Subsection 17(2) of the PGPA Rule, the Chief Executive has determined that the functions of the Agency’ Audit and Risk Committee are to review and give independent advice about the appropriateness of the Agency's financial reporting, performance reporting, systems of risk oversight and management and systems of internal control.
Financial reporting [PGPA Rule 17(2)(a)]
Including providing written advice to the Chief Executive as to whether:
- The annual financial statements, in the committee's view, comply with the PGPA Act, the PGPA Rules, the Accounting Standards and supporting guidance;
- Information (other than financial statements) required by the Department of Finance for the purpose of preparing the Australian Government consolidated financial statements (including the supplementary reporting package);
- The Agency's financial reporting as a whole is appropriate, with reference to any specific areas of concern or suggestions for improvement.
Performance reporting [PGPA Rule 17(2)(b)]
Including providing written advice to the Chief Executive as to whether:
- The approach to developing performance information is appropriate, including compliance with mandatory requirements of the PGPA Act and PGPA Rule;
- Performance information included in the Portfolio Budget Statements is appropriate;
- Performance information included in the Corporate Plan is appropriate;
- Annual performance statements are appropriate and comply with the PGPA Act and Rule; and
- Performance reporting as a whole is appropriate, with reference to any specific areas of concern or suggestions for improvement.
System of risk oversight and management [PGPA Rule 17(2)(c)]
Including providing written advice to the Chief Executive as to whether:
- The Agency's systems for risk oversight and risk management as a whole, including the approach to managing key risks, project and program risks, regulatory risk, procurement and contract management and workplace health and safety, are appropriate, with reference to the Commonwealth Risk Management Policy and any specific areas of concern or suggestions for improvement; and
- The Agency's fraud and corruption control arrangements are appropriate, and the Agency has implemented appropriate processes and systems to detect, capture and effectively respond to fraud risks consistent with the Commonwealth Fraud and Corruption Control Framework.
System of internal control [PGPA Rule 17(2)(d)]
Including providing written advice to the Chief Executive in relation to the appropriateness of the Agency's systems for internal control, with reference to any specific areas of concern or suggestions for improvement. This would consider:
- The Agency’s overall control environment, as reflected in its governance, risk management, and assurance arrangements, including whether relevant processes and policies are in place;
- The Agency’s arrangements to ensure legislative and policy compliance;
- Compliance with the requirements of the Protective Security Policy Framework;
- Internal audit resourcing and coverage in relation to the Agency's key risks, and recommending approval of the internal audit charter, and Annual Internal Audit Work Program by the Chief Executive;
- Internal and external audit reports, providing advice to the Chief Executive about significant issues identified, and monitoring the implementation of agreed actions;
- Providing advice on the appropriateness of internal audit services delivered and in compliance with the Institute of Internal Auditor’s International Professional Practices Framework.
- Business continuity planning arrangements including whether business continuity and disaster recovery plans are appropriate and periodically updated and tested;
- Controls for the access, security and provision of ICT services, including cyber security controls;
- Steps taken by management to embed a culture of ethical and lawful behaviour; and
- Mechanisms to review relevant Australian National Audit Office, Parliamentary Committee and external reviews and reports and recommendations from these.
As far as is practicable, the Audit and Risk Committee should indicate which matters it will consider during any given year in a forward plan, noting that it may consider other or additional matters in response to changes in the Agency's operating environment.
Authority
The Audit and Risk Committee is directly accountable to the Chief Executive for the performance of its functions.
The Chief Executive authorises the Audit and Risk Committee, in performing its functions, to:
- Obtain any information it needs from any official or external party (subject to their legal obligation to protect information);
- Discuss any matters with the external auditor, internal audit service provider or other external parties (subject to confidentiality considerations);
- Request the attendance of any official, including the Chief Executive, at Audit and Risk Committee meetings;
- request internal or external legal or other professional advice (e.g. external advisors or other parties), subject to approval by the appropriate Agency delegate and at the Agency's expense.
The Audit and Risk Committee has no executive powers in relation to the operations of the Agency. The Audit and Risk Committee may only review the appropriateness of aspects of those operations consistent with its functions, and advise the Chief Executive accordingly.
Responsibility for the appropriateness of the Agency's financial reporting, performance reporting, system of risk oversight and management, and system of internal control rests with the Chief Executive and officials of the Agency.
Membership and Expertise on the Committee
In accordance with Subsection 17(3) and Subsection 17(4) of the PGPA Rule, The Audit and Risk Committee will consist of at least three independent members appointed by the Chief Executive.
The Chief Executive will appoint the Chair of the Audit and Risk Committee. The Chair of the Committee is authorised to appoint a Deputy Chair, who will act as Chair in the absence of the Chair.
Audit and Risk Committee members will be appointed for an initial period determined by the Chief Executive. Members may be re-appointed after a formal review of their performance for further periods as specified by the Chief Executive.
A phased rotation of committee appointments should be considered to allow for a flow of skills and talent, whilst balancing and preserving development of appropriate levels of experience, knowledge and of relationships.
Consistent with subsection 17(3) of the PGPA Rule the members of the Audit and Risk Committee, taken collectively, will have a broad range of knowledge, skills and experience relevant to the operations of the Agency, including its information technology environment and regulatory purpose.
All members should be conversant with financial management reporting and at least one member of the Audit and Risk Committee should have accounting or related financial management experience and/or qualifications, and a comprehensive understanding of accounting and auditing standards.
Members will be supported by the Chief Audit Executive.
The Chief Audit Executive is required to attend all meetings of the Committee except those meetings consisting of the Committee meeting without observers or advisors (closed meetings) or when the Chair specifically requests that the Chief Audit Executive not attend.
The Chief Audit Executive is not a member of the Committee.
Induction and Clearance
New members will receive relevant information and briefings on their appointment to assist them to meet their Committee responsibilities.
Members will be required to hold a relevant security clearance as determined by the Agency and to sign appropriate confidentiality agreements.
Operation of the Committee
Meeting schedule and details
The Audit and Risk Committee will meet at least four times per year, and more often if required. Special meetings may be held to review the Agency’s annual financial statements and annual performance statements or to meet other specific responsibilities of the Audit and Risk Committee.
The Chair will call a meeting if requested to do so by the Chief Executive, and may call a meeting if requested by another Audit and Risk Committee member.
Quorum
A quorum for any Audit and Risk Committee meeting will be two members.
Observers
The Chief Executive, Chief Operating Officer, Chief Risk Officer, Chief Information Officer, Chief Finance Officer, representatives from the Australian National Audit Office (the ANAO) and internal audit may attend all or part of the meeting to provide advice to the Committee as determined by the Chair, but will not be members of the Committee.
The exception being those meetings consisting of the Committee meeting without observers or advisors (private sessions), as determined by the Chair. These in-camera sessions include annual meetings with the external auditors, internal auditors, and as required with the Chief Executive, Chief Risk Officer or other senior officials.
Secretariat
The Chief Executive will provide resources to provide secretariat support to the Audit and Risk Committee.
The Secretariat will ensure the agenda for each meeting and supporting papers are circulated, after approval of the agenda from the Chair, at least one week before the meeting, and ensure the minutes of the meetings are prepared and maintained.
Any papers requiring a decision between scheduled meetings are only to be circulated out of session with the consent of the Chair. Approval from the Chair must also be sought prior to circulating papers for noting out-of-session (unless previously discussed and agreed at a meeting).
Minutes
Draft minutes must be approved by the Chair and circulated within two weeks of the meeting to each member and observers, as appropriate.
Minutes of the preceding meeting will be confirmed at each meeting, which includes a review of the action items outstanding.
Reporting and Communications
The Chair will report to the Chief Executive after each meeting. Any matter deemed of sufficient importance will be reported to the Chief Executive immediately.
Following each Audit and Risk Committee meeting, a summary of matters discussed will be provided to the Executive Board. This will be developed by the Secretariat drawing from the approved minutes and may also involve a briefing from the Chair of the Committee.
The Audit and Risk Committee will, as often as necessary, and at least once a year, provide a written report to the Chief Executive on its operation and activities during the year.
Information relating to disclosure of the Audit and Risk Committee and its members will be included in the annual report as required under Section 17AG of the PGPA Rule. The Secretariat will Iiaise with members where necessary to obtain this information.
Conflict of Interest Management
To the extent possible, Audit and Risk Committee members should avoid interests that conflict, or could be seen to conflict, with the role and independence of the Audit and Risk Committee.
Once a year, Audit and Risk Committee members will provide written declarations to the Chair for provision to the Chief Executive declaring any potential or actual conflicts of interest they may have in relation to their responsibilities.
Audit and Risk Committee members must declare any conflicts of interest at the start of each meeting or before discussion of the relevant agenda item or topic. Details of any conflicts of interest should be appropriately minuted.
Members with a conflict of interest will notify the Audit and Risk Committee Chair as soon as these issues become apparent. Any member with a conflict of interest will absent themselves from discussions about relevant matters.
Review of Performance
The Chair will initiate a review of the performance of the Audit and Risk Committee at least once every two years. The outcomes of this assessment will be reported to the Chief Executive.
Review of the Charter
At least once a year the Audit and Risk Committee will review this Charter. A review of the Charter may also be initiated at any time by the Chief Executive.
Any changes to the Audit and Risk Committee Charter will be recommended by the Audit and Risk Committee and formally approved by the Chief Executive.