An Audit Committee Chairs Forum was held on Friday 17 July 2026. This communique summarises key messages, discussion themes and practical considerations for audit and risk committees arising from the forum.

Auditor-General’s update

Dr Caralee McLiesh PSM, Auditor-General for Australia, addressed the Audit Committee Chairs Forum. A summary of the key points from her presentation is below.

Annual Audit Work Program

The Annual Audit Work Program (AAWP) is designed to reflect the Australian National Audit Office’s (ANAO) audit strategy and inform the Parliament, government entities and the public of the planned audit coverage for the Australian Government sector. The program will signal a multi-year approach, with topics identified for 2026–27 and future years. It will also be a multi-product program, recognising that topics can be addressed through financial statements audits, performance statements audits, performance audits and other ANAO products.

The 2026–27 program will aim to provide broad coverage across the sector and different types of activity, with emphasis on large areas of government expenditure and revenue, value for money and delivery of outcomes, preparedness for and effective use of digital technologies, and efficiency in public sector administration.

Product mix and rapid reviews

The ANAO continues to develop its product mix to provide timely assurance and insights. Rapid reviews are intended to provide more timely observations on areas of public service delivery where a shorter, focused audit can support accountability, reform or implementation activity.

Key messages on rapid reviews included:

  • rapid reviews maintain high-quality standards, while using more flexible formats and production processes;
  • the approach is best suited to well-defined, risk-focused topics; and\
  • successful rapid reviews require strong senior-level engagement from entities, including early clarity on priorities, timeframes and audit approaches.

Lessons from performance audits

The ANAO’s performance audit reports point to three recurring lessons that are relevant to audit and risk committees.

First, entities should break down organisational silos and take an enterprise-wide view of risks, issues and lessons learned. Significant risks, audit findings and improvement opportunities should be shared across the organisation to support continuous improvement and avoid repeating known issues.

Second, risk management needs to be active in practice. Effective risk management supports decision-making, enables the early identification and escalation of emerging issues, and helps ensure risks are addressed at the appropriate level.

Third, entities need evidence to explain decisions. Capturing the rationale for decisions is not simply an administrative record-keeping issue; it is fundamental to demonstrating that frameworks have been applied properly, requirements have been met and decisions are robust.

Questions Audit and Risk Committees may wish to ask

  • How are significant risks, issues and lessons communicated across the entity?
    • How can the Audit and Risk Committee be assured that the right information is reaching the right people in time to support effective oversight and risk management?
  • Are ANAO findings and recommendations being applied more broadly than the area audited?
  • What mechanisms are in place to identify emerging risks, escalate them and ensure they are acted upon at the right levels?
  • What assurance do we have that risk management is driving decisions rather than being treated as a compliance exercise?
  • Can management clearly demonstrate the rationale and evidence supporting significant decisions? 

Performance statements audits

The ANAO is continuing to develop its approach to performance statements audits. A joint ANAO and Department of Finance working group has been established to consider practical improvements to the Commonwealth Performance Framework and Program, including how to reduce red and beige tape (unnecessary administrative burden) and support a risk-based and proportionate approach.

Performance reporting should be more than a compliance exercise. Audit and risk committees may wish to consider whether their entity’s performance statements provide relevant, credible and useful performance information that helps management understand what is working and what is not.

Questions Audit and Risk Committees may wish to ask

  • Do the performance statements tell a clear, balanced, credible and complete story about what the entity achieved?
  • What would a critical reader say is missing, weak or insufficiently explained in the statements?
  • Are the main messages consistent with internal reporting, risk reporting and executive updates during the year?
  • Which results or disclosures are most likely to attract audit, parliamentary or public challenge, and are they properly evidenced and explained?
  • Does the accountable authority have sufficient assurance to sign the statements confidently?

Financial statements audits

The ANAO’s Interim Report on Key Financial Controls of Major Entities identified several key messages. Internal controls are generally effective to support financial reporting across major entities, but IT-related findings continue to be a significant area of risk.

IT-related findings continue to be an area of significant risk, with 71 per cent of findings in the most recent controls report relating to IT and around two-thirds of those relating to IT security. Privileged access and user termination controls remain areas of focus.

Lawfulness remains an important area for audit and risk committee scrutiny. An increase in legislative breaches was identified through interim controls work.

Long-standing risks associated with business-critical legacy IT systems and historical implementation arrangements remain an area of focus.

Questions Audit and Risk Committees may wish to ask

  • What assurance can management provide that IT controls are effectively managing risk?
  • How are privileged access arrangements and user access controls monitored?
  • What evidence can management provide that legislative compliance issues have appropriate governance, controls and assurance arrangements?
  •  What risks are being carried from legacy systems and historical decisions?
  • What plans are in place to address long-standing audit findings?

Artificial intelligence

The ANAO is developing its experience in auditing the use of artificial intelligence. The ANAO has audited Governance of Artificial Intelligence at the Australian Taxation Office, recently tabled a report on Artificial Intelligence Use in IP Australia, and is auditing the use of AI for managing health provider compliance at the Department of Health, Disability and Ageing.

Key messages from the recent audit into AI use in IP Australia included:

  • entities should be clear on objectives, risks and expected outcomes before adopting or scaling AI;
  • governance should be proportionate to the level of risk and maturity of each use case; and
  • controls should be in place across the AI lifecycle and regularly reviewed to manage risks, monitor outcomes and ensure AI continues to deliver value.

The Auditor-General’s update acknowledged that 2026 marks the ANAO’s 125th anniversary, reflecting the long-standing importance of independent scrutiny to parliamentary accountability and public trust.


 

Department of Finance update — 2025–26 Financial Reporting

Lasantha Samaranayake, Assistant Secretary, Accounting and Frameworks Branch, Financial Analysis, Reporting and Management Division, Department of Finance, provided an update:

  • Updated 2025–26 financial reporting guidance has been published on the Finance website.
  • Audit-cleared financial statements are due to be submitted to the Department of Finance (Finance) by 14 August 2026 for material entities and 28 August 2026 for small entities. These submissions support the preparation of the Australian Government’s Final Budget Outcome and Consolidated Financial Statements (CFS).
  • The supplementary reporting pack (SRP) is due to Finance by 18 August 2026 for material entities and 28 August 2026 for small entities.
  • For 2025–26 financial reporting, there are no significant accounting standard changes.
     

Procurement and contract management discussion

Carla Jago, Deputy Auditor-General, facilitated a discussion on audit committee approaches to gaining assurance over procurement and contract management.

The discussion was framed by changes to the Commonwealth Procurement Rules and recent procurement policy notes issued by Finance.

Attendees shared examples of good practice from audit committees, including:

  • requesting visibility of upcoming procurements, key supplier relationships, dependencies and associated risks;
  • using internal audit to review procurement planning, existing contracts and procurement maturity before new negotiations commence;
  •  obtaining regular updates from management on significant procurements, contract variations and contracts approaching expiry or option points;
  • asking whether value for money assessments are documented, particularly for contract variations;
  • considering supplier dependency, technology lock-in, modern slavery, fraud, ethical risks and other third-party risks;
  • establishing advisory groups or standing governance arrangements to support oversight of major procurements and contract negotiations; and
  • asking what reporting management uses internally to monitor procurement activity, consultancies, contract variations and sole-source procurements.

The discussion reinforced the importance of early planning, strong governance, risk-based scrutiny and clear evidence for procurement decisions.

Questions Audit and Risk Committees may wish to ask

  • What are our highest-value and highest-risk procurements, contract variations and supplier relationships?
  • Which significant contracts are approaching expiry, renewal or option points, and what planning is underway?
  • How are procurement and supplier risks reflected in enterprise risk reporting?
  • What assurance do we have that value for money assessments are appropriately documented?
  • Are we exposed to supplier dependency or technology lock-in risks?
  • What assurance do we receive from internal audit regarding procurement planning, contract management and procurement maturity?
  • What governance arrangements support oversight of our most significant procurements and contract negotiations?
  • How are third-party, fraud, ethical and modern slavery risks being managed?
     

Presentation: AI – public trust, assurance and accountability

Lucy Poole, Deputy Chief Executive Officer, Strategy, Planning and Performance at the Digital Transformation Agency, presented on artificial intelligence through the lens of public trust, assurance and accountability.

The presentation is available at: https://www.dta.gov.au/articles/speech-keeping-trust-loop.

Panel discussion: practical considerations for audit and risk committees

The forum included a panel discussion on artificial intelligence, chaired by Lesa Craswell, Group Executive Director, Systems Assurance and Data Analytics. Panel members were Lucy Poole, Margaret Tregurtha, Acting Director General of IP Australia, and Mark Sawade, Chief Information Officer at the Australian Taxation Office.

The panel discussed AI risks, lessons learned from agency experience and practical considerations for audit and risk committees.

Key themes included:

  • the importance of understanding organisational risk appetite and applying governance arrangements that are proportionate to different AI use cases;
  • balancing the risks of AI adoption with the risks of not adopting AI, particularly where opportunities to improve public services and organisational performance may be missed;
  • the need for transparency, observability and governance as AI initiatives move from experimentation to enterprise deployment;
  • ensuring agencies have clear visibility of AI activities and defined decision points for when pilots and trials become business-as-usual operations;
  • assessing value over time, including whether AI is delivering efficiency gains, improved quality, increased productivity or better public outcomes;
  • workforce implications, including changing roles, capability requirements and the need to engage staff openly on AI adoption;
  • the role of senior leaders in sponsoring AI innovation while ensuring risks are appropriately managed;
  • procurement and contract management challenges in a rapidly evolving technology market, including supplier dependency and technology lock-in risks;
  • the importance of understanding business processes and desired outcomes before selecting AI solutions; and
  • the need to maintain accountability, explainability and evidence where AI supports decision-making.

Panel members also discussed the limitations of relying on a ‘human in the loop’ control without considering whether reviewers can exercise independent judgement. The discussion highlighted the risk of automation bias and the importance of ensuring human oversight remains effective in practice.

The discussion also considered stakeholder engagement and capability development. Margaret Tregurtha noted the importance of building AI capability across leadership and the workforce, while creating opportunities for innovation within established risk management frameworks.

Questions Audit and Risk Committees may wish to ask

  • Do we have visibility of AI activities occurring across the organisation?
  • Is our approach to AI aligned with our risk appetite and organisational objectives?
  • When do AI pilots or experiments become operational capabilities, and what governance arrangements apply?
  • How are we assessing whether AI investments are delivering the intended value and outcomes?
  • Do we have the workforce capability and procurement expertise needed to implement and oversee AI effectively?
  • Are we exposed to supplier dependency or technology lock-in risks?
  • Are humans providing meaningful oversight of AI-supported decisions, or is there a risk of automation bias?
  • Can we explain and evidence how AI-informed decisions are made?
  • How are we balancing innovation with accountability, transparency and public trust?
     

Vote of thanks

Cath Ingram noted that the discussions throughout the forum reinforced the importance of translating emerging issues into practical oversight questions for audit and risk committees. She encouraged participants to continue sharing experiences and lessons learned, particularly as entities respond to evolving risks, changing technologies and increasing expectations around governance, accountability and public sector performance.

Future forums and feedback

Please note the December forum will move to February 2027 and will be held in person.

The ANAO remains committed to using the Audit Committee Chairs Forum as a platform for audit committee members to exchange good practice, engage with audit insights and contribute to public sector improvement. If you have any feedback, please contact external.relations@anao.gov.au.