Audit & Risk Committee Governance
Banking, Insurance and Regulated Financial Institutions
Effective Audit and Risk Committee governance is central to the resilience of banks, insurers and other regulated financial institutions. The board's role is not to manage risk or perform assurance work itself, but to ensure that management, control functions and auditors provide a sufficiently complete, independent and forward-looking view of the institution.
My own board and executive experience spans banking, non-life insurance, export credit and other regulated environments. It includes current responsibilities as an Independent Non-Executive Director at Argenta Bank & Insurance Group and Chair of the Audit and Risk Committees for the insurance activities within the group, as well as international executive leadership in banking and insurance.
The board's role in Audit & Risk
The effectiveness of an Audit or Risk Committee depends less on the volume of information it receives than on whether it receives the right information, at the right level, with sufficient independence and challenge.
A strong committee should be able to determine:
-
whether the financial and risk picture presented to the board is complete and reliable;
-
whether key risks are properly identified, quantified and escalated;
-
whether internal control weaknesses are being addressed at the required pace;
-
whether assurance functions have sufficient independence, authority and resources;
-
whether risk appetite is genuinely influencing business decisions;
-
and whether the board is receiving early warning of emerging issues rather than retrospective explanations.
The committee's task is therefore not simply to review reports. It is to test whether the organisation's governance system is working as intended.
Audit Committee priorities
In a regulated financial institution, the Audit Committee should maintain a clear view of the integrity of financial reporting, the effectiveness of internal controls and the quality of assurance provided by both internal and external audit.
Particular attention should be given to:
Financial reporting and judgement. The committee should understand the principal accounting judgements, estimates and assumptions that materially affect reported results and capital positions.
Internal control effectiveness. Identified weaknesses should be assessed not only individually, but also for patterns that may indicate broader governance or organisational issues.
Internal audit independence. Internal Audit must have unrestricted access to the committee, appropriate resources and sufficient organisational standing to challenge management effectively.
External audit quality. The committee should assess audit quality, independence, professional scepticism and the extent to which significant issues receive adequate attention.
Remediation discipline. Repeated extensions of audit findings or regulatory actions can be an early indicator of weak management ownership or insufficient board attention.
An effective Audit Committee should therefore look beyond compliance with the annual audit cycle and understand whether the institution's broader control environment is improving or deteriorating.
Risk Committee priorities
The Risk Committee should focus on whether the institution's risk framework remains appropriate for its strategy, financial capacity and regulatory obligations.
In banking and insurance, this includes oversight of areas such as:
-
risk appetite and limit frameworks;
-
capital adequacy and solvency;
-
liquidity and funding;
-
credit and underwriting risk;
-
market and investment risk;
-
operational resilience;
-
cyber and technology risk;
-
concentration risk;
-
model risk;
-
compliance and conduct risk;
-
and emerging strategic risks.
Risk appetite is particularly important. It should not exist merely as a formal board document. It should influence pricing, underwriting, credit decisions, investment choices, growth ambitions and management incentives.
The committee should also be alert to situations where individually acceptable risks may combine into a materially different aggregate exposure.
Where Audit and Risk intersect
Audit and Risk are distinct governance responsibilities, but in practice many of the most important board issues sit at their intersection.
Examples include:
-
weaknesses in internal controls that create financial or operational risk;
-
model limitations affecting both risk measurement and financial reporting;
-
cyber incidents with operational, financial and regulatory consequences;
-
compliance weaknesses that develop into reputational or capital risk;
-
and major transformation programmes that create control gaps during implementation.
For this reason, coordination between Audit and Risk Committees is essential, particularly where responsibilities are divided between separate committees.
Boards should avoid both duplication and governance gaps.
In combined Audit and Risk structures, the challenge is different: ensuring that a wide agenda does not allow major strategic risk issues to crowd out detailed control and assurance matters, or vice versa.
Emerging areas of board oversight
The Audit and Risk agenda continues to expand.
Digital resilience and cyber risk
Technology risk is no longer primarily an operational IT matter. Boards need visibility on resilience, critical dependencies, third-party exposure, incident management and recovery capability.
Regulatory frameworks such as DORA have reinforced the expectation that operational resilience is a board-level responsibility.
Data and artificial intelligence
The increasing use of data-driven models and artificial intelligence raises questions around governance, accountability, explainability, model risk, data quality and decision rights.
Boards do not need to become technical management teams, but they do need sufficient understanding to challenge how technology is governed and where material risks arise.
My engineering background in Computer Science provides an additional perspective when considering technology, cyber resilience and AI governance at board level.
Regulatory change
Regulated institutions operate in an environment of continuous supervisory change. The board should therefore distinguish between compliance with new rules and the broader question of whether governance, controls and organisational behaviour meet the regulator's underlying expectations.
Governance during transformation
Transformation frequently creates temporary increases in risk.
Mergers, carve-outs, new operating models, technology migrations, regulatory remediation and leadership transitions can all weaken established controls while new ones are still developing.
The board should therefore consider transformation not only from a strategic and financial perspective, but also through the lens of governance and risk.
Key questions include:
-
Which controls are changing?
-
Where are temporary governance gaps emerging?
-
Who owns residual risks during transition?
-
Are assurance functions involved early enough?
-
Is management reporting giving the board a sufficiently realistic picture of implementation risk?
My executive and interim work has included regulated transformation, compliance remediation, strategic carve-outs and operating-model redesign. This experience reinforces my view that board oversight is most effective when governance considerations are incorporated into transformation from the beginning rather than added after problems emerge.
My board perspective
My approach to Audit and Risk governance combines independent board challenge with the practical perspective of a former international CEO.
I have worked across banking, non-life insurance and other regulated sectors in Europe, Asia and the Americas, including senior leadership roles with KBC and Coface and current independent board responsibilities at Argenta and Etihad Credit Insurance.
At board level, I focus particularly on:
-
financial integrity and quality of management information;
-
risk appetite and escalation;
-
effectiveness of internal controls;
-
independence and impact of assurance functions;
-
regulatory dialogue;
-
governance of transformation;
-
and the quality of interaction between the board and executive management.
Good governance should help a board see problems earlier, understand who owns them and judge whether management is dealing with them fast enough.
Bart A. Pattyn is an Independent Non-Executive Director and Audit & Risk Committee Chair with international experience in banking, non-life insurance and regulated financial institutions. He currently serves on the boards of Argenta Bank & Insurance Group and Etihad Credit Insurance and previously held senior executive roles with KBC and Coface.