The major responsibility of Audit Committee

Auditing is an indispensable element of every management system, including of risk management and of internal control. The fact that auditors are responsible for assessing the soundness and adequacy of an entity’s accounting, operating, and administrative functions as well as its day-to-day management controls, makes them and their work the cornerstone of good governance.

Audit reports must be clear, unambiguous, and well documented. They should be presented not only to the Audit Committee but to all members of the board, the CEO, and senior executives, identifying defects which must be remedied sys- tematically and promptly. Follow-up audits should describe:

● Weaknesses which are not yet remedied, and

● Recommendations not yet implemented.

In the United States, the Federal Reserve instructs its examiners under its author- ity that they should review documents, taking into account the reporting process followed by the auditor. This permits them to subsequently evaluate in a firm manner the nature and efficiency of the tasks internal auditing has performed.

The central bank’s examiners also look into whether or not:

● Internal auditors have been given the authority necessary to carry out a dependable job, and

● If they have free access to any records needed for the proper conduct of their investigation.

These are issues the Audit Committee should always keep in mind. A sound way of looking at auditing is as a meta-layer (higher-up level) of day-to-day manage- ment control functions. As we have already seen, internal control is focused on daily ongoing activities, while auditing is responsible for the independent exam- ination function, which must tell if financial reporting is reliable in all its aspects.

Because auditing procedures are an indispensable supplement in the ongoing evaluation provided by internal controls, it is important for the auditor to con- duct his or her activities in a way permitting evaluation of:

● The way in which top management directives are being issued, and fol- lowed, and

● Whether compliance with designated laws, regulations, and internal bylaws is part of corporate culture.

Eventually this information will be part and parcel of the Audit Committee’s watch. After World War II until about two decades ago, board members were prac- tically immune from prosecution, and CEOs from firing. Stockholder activism, particularly from institutional investors, has changed that. Even if the company buys an insurance policy for legal protection for members of its board and its top brass, juries can award awfully big compensation and there is also the company’s and the individual’s reputation at stake. This is one more reason why all employ- ees must be subject to internal control and auditing. Even if they have no finan- cial responsibilities, they must be accountable for their actions.

As Chapter 16 brought to the reader’s attention, a good system of internal control has significant impact on how the business is planned, conducted, and con- trolled. Moreover, everybody should contribute to internal control. The question is not whether each individual is honest, but rather whether situations exist that:

● Might permit an intentional error or bias to be concealed, or

● Make it possible for errors and biases to remain undetected, and hence unknown to top management.

Both points speak volumes about the internal and external directors’ accounta- bility. Authority is delegated, responsibility never. On the other hand, a person can really be accountable for something if he or she knows and understands the subject on which decisions are taken. Parkinson’s Law says that, at board meet- ings, time spent to reach a decision is universally proportional to the importance this decision has for the company. Yet,

● The board will have many ‘experts’ on coffee brands, and discussions on which to choose for the cafeteria can take hours.

● But there are very few members who understand changes in the risk and return curve for the portfolio of derivatives, and the need to develop differ- ent risk estimates for different time brackets, instruments, and counterpar- ties, and thus decisions concerning risk and return may be made on the fly.

As far as a credit institution’s or other financial company’s survival is concerned, decisions concerning risk are more than six orders of magnitude more important than the choice of a new brand of coffee.

On several occasions, the board’s Audit Committee and Technology Committee will need to work together. A rigorous approach to auditing, risk management, and internal control would pay full attention to the information technology

being used: from networks and databases, to datamining, models, and interactive reporting, through visualization (turning tables into graphs).

Not only must the channels of communication operate in real time and the mod- elling of all types of exposure be effectively done, but also market-related para- meters have to be adjusted immediately to changing financial conditions and/or board decisions with an impact on the management of risk. Risk figures derived from risk-based auditsmust be continuously compared with actual market data, as well as trends indicating a change in direction.

The effectiveness of auditing, internal control, and risk management depends a great deal on understanding the business and the people, and this is one of the fundamental duties of the board. ‘Problems arise when people at the top do not understand the professionals working for them, and therefore they can neither guide them nor control them,’ suggested Brandon Davies, formerly treasurer of Barclays Bank. Institutions are very reliant on the expertise of a few people: the traders, financial analysts, and some other professionals, but:

● Quite often senior management makes no effort to comprehend how these people think and work, and

● Misunderstandings significantly diminish what can be done through man- agement control, even if there is transparency in reporting.

Let me add this remark: ‘The role of bank managers is not only to assure the proper functioning of their institution, but also to see to it that auditors obtain a consistent and coherent image of status and results,’ said Alain Coune of the International Monetary Fund (IMF), adding that: ‘This is true of the quantifica- tion side of internal control and of audit.’ The qualification aspects, particularly those concerning internal controls, have not been till now tightly coupled to audit, but as we have seen this is changing.

* * * * *

Whether misrepresentations in financial accounting are due to omission or com- mission, they end by costing dear not only to the company but also its senior exec- utives and members of the board. Mid-August 2005, the Securities and Exchange Commission (SEC) brought civil charges against Charles Conaway, former chief executive, and John McDonald, former chief financial officer, of Kmart. They were accused of trying to cover up a ‘reckless’ purchase of $850 million in inventory in

2001.4The pair are the most senior former directors at the retailer to face action in SEC’s investigation into fraud stemming from Kmart’s bankruptcy in 2002. And this is only one example. Increasingly, the corporate executives’ and independent direc- tors’ everyday lives are measured against good governance principles. Therefore, I am often amazed by the bad judgment of top management people, including the chairman, president, and director of auditing when:

● Denunciations of malpractices are thrown in the wastepaper basket.

● Problems are covered up, to avoid disturbing the status quo, and

● Due investigations are not undertaken for fear that they will find the facts.

I have recently had such an experience which left me flabbergasted. The object of concern was malpractice to a client’s disfavour at a major private banking institution.5The letter which I wrote to the bank’s top management was factual and fully documented. The answer I received was neither based on facts, nor did it reflect the results of an investigation of malpractice. Yet, available evidence suggested a great deal of operational risk, as well as conflict of interest. Internal control it seemed had leave of absence.

In conclusion, a common mission of rigorous accounting, auditing, risk manage- ment, and internal control is to assure that those who have something to conceal receive no mercy. The value of all control activities lies in their ability to probe into the secret placesof operations. Only on rare occasions should management control be outwitted in its examination, and one of the basic functions of the Audit Committee is to ensure that wrong-doers receive no mercy. The chairman and members of the Audit Committee should heed the advice of an Athenian senator in Shakespeare’s Timon of Athens: ‘Nothing emboldens sin so much as mercy’. But is anybody listening?


