Internal audit reports to the board, but the quality of that oversight depends almost entirely on the questions the board chooses to ask. Reviewing a list of findings is the least demanding version of the job.
1. What did we choose not to audit this year, and why?
Coverage decisions carry more information than findings. An area excluded three years running deserves an explicit rationale on the record.
2. Has management ever asked for a finding to be softened?
The answer is occasionally yes, and a function willing to say so is functioning. A function that has never experienced tension may not be testing anything uncomfortable.
3. How many prior findings remain open, and for how long?
Ageing of open findings is the single clearest indicator of whether audit output changes anything. A growing backlog is a governance issue in its own right.
4. Where would fraud be easiest here?
Asked directly, this question produces better answers than a formal risk register — because it invites judgement rather than a scoring exercise.
5. What do you need that you do not have?
Resourcing, access and skills constraints should surface at the committee rather than quietly limiting scope.
The purpose of the audit committee is not to receive assurance. It is to test whether the assurance is worth receiving.
This article is general commentary and not advice on any specific set of facts. For guidance on your own circumstances, speak to our team.

