Public companies operate in an increasingly complex environment shaped by rapid technological advancement, evolving business risks and heightened stakeholder expectations. Confidence in corporate reporting relies on a strong reporting ecosystem in which management, audit committees, internal and external auditors, and regulators share responsibility for effective governance and oversight.
As organizations assess how today’s business landscape affects strategy, operations and financial reporting, audit committees’ role within this ecosystem continues to evolve as their oversight responsibilities expand beyond their core mandate into areas such as cybersecurity and artificial intelligence.
To help audit committee members and governance professionals navigate these shifting responsibilities, the Audit Committee Practices Report (ACPR) examines current oversight priorities, emerging trends and committee readiness. The report also serves as a valuable benchmark, helping audit committees evaluate their practices against peers and identify opportunities to enhance effectiveness.
The fifth edition of the report, a collaboration between the Center for Audit Quality (CAQ) and Deloitte’s Center for Board Effectiveness, draws on insights from nearly 250 audit committee chairs and members. The findings show that audit committees are placing increased focus on emerging risks and oversight challenges.
Read on for three key findings and considerations for strengthening audit committee oversight.
Enterprise Risk Management Is the Top Oversight Priority
For the first time since the survey was launched, enterprise risk management (ERM) emerged as audit committees’ top priority. Thirty-nine percent of respondents ranked ERM as their number one focus area, and 77 percent included it among their top three priorities. Cybersecurity was cited as a top three priority by 87 percent of respondents, more than any other oversight area, while AI governance saw a 40 percent increase compared with last year’s results. These findings highlight the increasingly interconnected nature of risk oversight. ERM provides the framework for identifying and monitoring a broad range of risks, including cybersecurity, AI and other emerging challenges.

Advanced technologies and their related risks are top of mind for both boards and management teams. The CAQ’s Audit Partner Pulse Survey (APPS) found that audit partners view technology disruption and AI-competitive pressures as the most significant economic risks facing companies in the industries they audit. While technology can drive efficiency, innovation and growth, it also introduces new governance, operational and reporting considerations that require ongoing oversight.
Audit committees generally feel well prepared to oversee ERM, with only 27 percent indicating that additional expertise would improve effectiveness. By comparison, 70 percent said technology or AI expertise would enhance committee effectiveness, and 45 percent identified a need for greater cybersecurity expertise. While audit committees are generally confident in overseeing enterprise risk, many are seeking deeper expertise in rapidly evolving technologies, particularly AI.
Effective AI Governance and Oversight Requires Collaboration
The report identified a gap between audit committees’ AI responsibilities and their readiness to fulfill them. AI governance has quickly become one of audit committees’ top priorities, yet it is also the area where respondents report the largest skills gap and the lowest level of oversight confidence. Respondents in the APPS also reported that insufficient in-house AI expertise and lack of governance frameworks are top internal control challenges facing their largest clients.
This is reflected in the ACPR, with more than four in five respondents saying that AI governance oversight is still a work in progress at the companies they audit. As organizations increasingly integrate AI into business processes and financial reporting activities, audit committees are being asked to oversee a rapidly evolving technology while governance frameworks and leading practices continue to mature. Increased reporting from stakeholders into how AI is being deployed, monitored and governed across the organization support effective audit committee oversight. Roughly two thirds of respondents report having moderate or significant visibility into stakeholders’ AI use, but greater collaboration among audit committees, management, finance, internal audit and the external auditor foster stronger oversight.

High-Quality Engagement and Communication Drive Effectiveness
While emerging risks and new technologies continue to expand audit committees’ oversight responsibilities, survey respondents consistently pointed to higher-quality discussions as a leading opportunity to enhance effectiveness. Creating space for thoughtful discussion may involve refining committee materials, focusing agendas on the most significant matters and investing in relationships that foster trust and candid conversations.

The importance of communication is also evident in how audit committees evaluate their external auditors. Respondents indicated that technical competence is expected and serves as a baseline requirement, but what differentiates an external auditor is the ability to provide timely insights, maintain continuity and communicate clearly and candidly with the committee. These qualities help build trusted relationships that support more effective oversight and decision-making.
Looking Ahead
This year’s survey findings show that audit committees are being asked to oversee more than ever but continue to center audit quality and trust in financial reporting. By combining strong ERM practices with greater AI fluency and governance and consistent, high-quality engagement with stakeholders, audit committees will be better prepared to oversee an increasingly complex business environment.
For additional insights and sample questions to help assess your committee’s effectiveness and identify priorities for the year ahead, read the full Audit Committee Practices Report.


