A quarterly internal audit Audit Committee pack should be a governance decision file, not a slide dump. It should show what internal audit completed, what changed, which high-risk issues need challenge, which actions are overdue, where scope was limited, and what the committee must decide before the next meeting.
Download the Excel/PDF pack for the meeting agenda, pre-read index, decision register, high observations, ATR ageing, limitations, private-session notes, minutes and product workflow fields.
An internal audit Audit Committee pack is the periodic reporting file that turns fieldwork, dashboards and action tracking into committee decisions. It should connect internal audit’s approved mandate, annual plan, current risk assessment, significant observations, management action status and scope limitations into a single meeting-ready record.
List every paper, dashboard, report, plan change, limitation note and decision item sent before the meeting.
Summarise plan status, high-risk work completed, major delays, fieldwork blockers, resourcing constraints and emerging risks.
Show only matters requiring committee attention: high findings, repeat root causes, management disagreement and overdue closure.
Age open management actions by owner, original due date, revised due date, closure evidence status and escalation level.
Separate approved deferrals, proposed additions, evidence restrictions, unavailable reports and management-imposed limitations.
State exactly what the committee must approve, note, challenge, escalate or send back to management.
Record independence, access, interference, sensitive investigations and resourcing concerns discussed without operating management where appropriate.
Convert committee discussion into owner, due date, evidence, next-meeting status and closure criteria.
Open actions from the prior committee meeting and evidence of closure.
Confirm whether members received papers early enough and whether late papers need deferral.
Completed reviews, in-progress work, slippage, added reviews, deferred reviews and capacity impact.
High issues, repeat findings, disputed ratings, fraud indicators, control override and material compliance exposure.
Overdue actions, revised dates, weak closure evidence, repeat owners and accepted-risk items.
Changes to annual plan, risk coverage, specialist support, co-source support or timing.
Independence, access, resourcing, sensitive matters and restrictions on internal audit work.
Decision owner, due date, report-out path and next committee follow-up.
Add, defer, accelerate or cancel a review because risk, capacity or business change has moved.
Require executive ownership, revised due date, stronger evidence or committee-level follow-up for overdue actions.
Accept alternate procedures, require evidence access, expand testing or disclose limitation in reporting.
Approve outside expertise for cyber, AI governance, process mining, data analytics, treasury or sector-specific work.
Challenge management when residual risk is accepted without authority, evidence or compensating controls.
Ask internal audit to perform an unplanned review because of incidents, complaints, regulatory movement or monitoring exceptions.
The private-session section should not become theatre. Use it for topics that cannot be handled safely in a management-heavy meeting: denied evidence, restricted access, pressure to change ratings, sensitive investigations, unresolved fraud indicators, resourcing constraints and concerns about the independence or authority of internal audit.
Committee members see audit completion percentages but not the decisions or escalations they must act on.
Significant issues lose urgency and overdue owners avoid visible challenge.
Plan status, issue ageing and monitoring exceptions cannot be reconciled to internal audit workpapers.
Evidence restrictions and unavailable system reports disappear before annual assurance reporting.
Independence, interference and sensitive matters may never reach the committee chair directly.
The same overdue actions return every quarter with no owner, due date or closure evidence standard.
The website download and the product build stay separate, but this format can become the specification for a future CORAA committee-pack workflow: paper index, decision routing, limitation escalation, private-session permissions and ATR follow-up.
| Artifact | Module | Likely fields |
|---|---|---|
| Committee pack builder | Board reporting | Meeting date, period, paper index, dashboard snapshot, pack owner, reviewer approval, version history. |
| Decision register | Governance workflow | Decision type, approver, owner, due date, source paper, status, next committee date. |
| ATR escalation model | Observation and ATR workflow | Issue rating, owner, original due date, revised due date, ageing, closure evidence, escalation level. |
| Limitation register | Evidence workflow | Blocked source, alternate procedure, assurance impact, management owner, committee direction. |
| Private session control | Permissions and minutes | Attendees, sensitive topic tag, access level, restricted notes, follow-up owner. |
An internal audit Audit Committee reporting pack is the periodic set of papers used to brief the committee on internal audit plan progress, significant observations, overdue management actions, scope limitations, risk changes and decisions required from the committee.
Include a pre-read index, plan status dashboard, high-risk observations, ATR ageing, plan-change requests, evidence blockers, scope limitations, emerging risks, decisions required, private-session topics and a minutes/action tracker.
A private session is a strong governance practice and is expected in many mature internal audit charters, but requirements depend on the entity, listing obligations and committee charter. Treat it as a recommended independence safeguard unless a specific rule applies.
The quarterly pack supports live governance decisions during the year. The annual report rolls up full-year coverage, assurance basis, unresolved risk, limitations and next-year planning.
The committee pack is strongest when it is fed by the same dashboard metrics, issue ratings, ATR evidence and plan-change log used by the internal audit team.