[codicts-css-switcher id=”346″]

Global Law Experts Logo
audit committees role changing five questions

Author

  • GOLD

The Audit Committee's Role Is Changing: Five Questions Boards in Ghana Should Be Asking Their Auditors in 2026

By Richard Dwumor
– posted 1 day ago

The audit committee’s role has become one of the most useful governance tools available to Ghanaian boards in 2026, precisely because the scope of external audit is expanding faster than most oversight practices can keep pace with. Regulatory updates, escalating cyber and fraud risk, growing demand for environmental, social and governance (ESG) disclosure, and technology-driven audit techniques have collectively redrawn what a competent audit committee must supervise. Boards that continue to treat the annual audit as a routine compliance exercise risk missing the very signals the audit is now capable of surfacing.

This guide sets out five direct, practical questions that audit committee chairs, company secretaries, chief financial officers and non-executive directors can put to their external auditors, along with the evidence to request and the red flags to watch for. It grounds each question in Ghana’s regulatory landscape and in the relevant International Standards on Auditing so that boards can verify what they are told.

Why audit committees must change in 2026

The traditional audit committee focused narrowly on the financial statements, the management letter and the auditor’s opinion. That model is no longer sufficient. Entities in Ghana now operate in an environment shaped by rapid digitalisation, fintech disruption, more assertive prudential supervision in the financial sector, and rising stakeholder expectations around non-financial reporting. Each of these developments changes what an audit should examine and how a committee should interrogate the results.

Understanding why the audit committee’s role is changing matters begins with the recognition that risk itself has migrated. Fraud increasingly travels through digital channels, going-concern judgements have grown more complex amid currency and financing pressures, and ESG claims are now made in public reporting that was previously unaudited. Auditors have responded with data analytics, continuous monitoring and specialist input, but the value of those methods only reaches the board if the committee knows what to ask for.

In Ghana, the oversight architecture involves several bodies working in parallel. The Securities and Exchange Commission oversees disclosure obligations for listed companies, the Bank of Ghana sets prudential expectations for banks and specialised deposit-taking institutions, the Institute of Chartered Accountants, Ghana governs the conduct and competence of auditors, and the Companies Act, 2019 (Act 992) establishes the underlying corporate duties that frame committee responsibilities. A modern audit committee must connect all of these to the questions it asks.

The five questions below are deliberately framed for non-technical directors, but each links to the standards and regulations that allow the committee to test the answers. Used together, they convert a passive review into an active challenge, which is exactly what the audit committee’s role changing five questions model is designed to achieve.

Regulatory and market context in Ghana: what boards must know

Before asking any question, an audit committee should understand the rules that shape both its own duties and those of the auditor. The Companies Act, 2019 (Act 992) sets out directors’ duties and the governance obligations that underpin the work of board committees, including the responsibility to ensure that financial reporting is reliable and that appropriate oversight of the external audit exists. Committee members carry these duties personally, which is why informed questioning is not optional.

For listed entities, the Securities and Exchange Commission issues disclosure requirements that affect the timing and content of auditor reporting, and the Ghana Stock Exchange listing rules incorporate corporate governance expectations that bear on how audit committees are constituted and how they interact with auditors. Committees at listed companies should read the auditor’s work against these disclosure obligations, not merely against the accounting standards.

Financial institutions face an additional layer. The Bank of Ghana’s prudential directives and guidelines set specific expectations for corporate governance and audit committee oversight in banks and specialised deposit-taking institutions, including the committee’s role in reviewing internal controls, risk management and the relationship with the external auditor. A bank’s audit committee therefore has a broader mandate than a committee at a typical private company, and its questions to the auditor should reflect that.

The Institute of Chartered Accountants, Ghana provides the professional backbone. ICAG, whose statutory basis is the Chartered Accountants Act, 2020 (Act 1058), regulates the profession and adopts standards on auditor independence, professional conduct and audit quality, and sets continuing professional development requirements for practising members. When a committee tests independence or competence, ICAG’s framework is the reference point. In the public sector, the Ghana Audit Service carries the constitutional mandate under Article 187 of the 1992 Constitution for auditing public accounts and institutions; while its remit is distinct from private-sector audit, its published work is a useful benchmark for what rigorous, independent audit looks like in the Ghanaian context.

Private-sector committees can draw on these regulators collectively to frame informed expectations.

Five questions boards in Ghana should be asking their auditors (2026)

The following five questions form a compact agenda for any pre-audit or post-audit meeting. Each is expanded below with the response a committee should expect, the evidence it should request, and the warning signs that suggest the answer is inadequate.

  • How have you adjusted the audit plan for emerging and entity-specific risks?
  • How are you using technology and data analytics to enhance audit quality?
  • What are you doing about fraud, cyber threats and going-concern uncertainties?
  • How are you auditing non-financial reporting, including ESG and sustainability claims?
  • How do you ensure auditor independence, expertise and effective communication with the committee?

Q1. How have you adjusted the audit plan for emerging and entity-specific risks?

The first questions goes to the heart of audit relevance. An audit plan that looks identical to last year’s is a signal that the auditor may not have reassessed the entity’s risk profile. Under International Standards on Auditing, notably ISA 315 on identifying and assessing the risks of material misstatement and ISA 330 on the auditor’s responses to assessed risks, auditors are required to update their understanding of the entity and its environment each year and to design procedures that respond to the specific risks identified.

What to expect in the auditor response

A competent response should describe how the risk assessment changed since the previous engagement, which new or heightened risks were identified, and how those risks altered the scope, timing and nature of testing. The auditor should be able to explain any revision to materiality and to connect that revision to the entity’s circumstances, for example, a new business line, a significant acquisition, foreign-currency exposure, or a change in financing.

Evidence to request

The committee should ask for the risk assessment summary, the scoping memorandum, and the rationale for the materiality figure applied. Where the entity operates across multiple locations or subsidiaries, the committee should ask how components were selected for full-scope, specific-scope or analytical procedures. These documents allow directors to see whether the plan genuinely reflects the business as it is today.

Red flags

  • Boilerplate answers. Generic descriptions of “standard audit procedures” with no reference to the entity’s actual risks.
  • No year-on-year change. An identical plan despite material changes in operations, financing or the external environment.
  • Unexplained materiality. A materiality figure the auditor cannot link to the entity’s size, complexity or risk.

Q2. How are you using technology and data analytics to enhance audit quality?

Modern audit increasingly relies on technology, and the committee should understand how. Computer-assisted audit techniques (CAATs), continuous monitoring and analytics-driven sampling allow auditors to test entire populations rather than small samples, to identify anomalies at scale, and to focus human effort on the exceptions that matter. This is one of the clearest ways the current audit committee’s role differs from the checklist of a decade ago.

Types of analytics and technology

Auditors may deploy full-population testing of journal entries, revenue and expense analytics, duplicate-payment detection, trend and ratio analysis, and increasingly AI-assisted tools that flag unusual patterns for further investigation. The committee does not need to understand the mechanics, but it should understand what was tested, how completely, and what the tools revealed.

Expected deliverables

The auditor should be able to identify the data sources used, describe the tools applied in plain language, and, crucially, state the limitations of those tools. Analytics are only as good as the data they consume, so the committee should ask about data access and data quality. The auditor should provide key exception reports and explain how flagged items were resolved.

Red flags

  • No data access. An auditor who could not obtain reliable data from the entity’s systems and fell back on manual sampling without saying so.
  • Black-box statements. Vague assurances that “advanced analytics” were used, with no description of scope, data or exceptions.
  • Unexplained exceptions. Analytics that generated anomalies which were never followed through to resolution.

Q3. What are you doing about fraud, cyber threats and going-concern uncertainties?

This question addresses the risks that most often damage an organisation between audits. ISA 240 sets out the auditor’s responsibilities relating to fraud in an audit of financial statements, requiring specific procedures to address the risk of management override of controls and the risk of fraudulent financial reporting. ISA 570 governs the auditor’s evaluation of going concern. Both standards demand more than a review of management’s assertions.

Fraud risk procedures

The committee should ask how the auditor identified fraud risks, what specific procedures addressed management override, such as testing of journal entries and review of significant estimates for bias, and whether any indicators of fraud emerged. A robust response describes professional scepticism in practice, not merely as a principle.

Cyber-security considerations

Cyber risk has become central to audit relevance in Ghana’s rapidly digitalising economy. The committee should ask how the auditor assessed IT general controls, whether specialists were engaged to evaluate the entity’s information systems, and how any control weaknesses affected the audit approach. An audit that penetrates IT controls only superficially may miss the very exposures most likely to cause loss.

Going-concern evaluation

On going concern, the auditor should explain how it evaluated management’s assessment, what indicators it considered, liquidity, financing renewals, covenant compliance, currency exposure, and what would trigger a modified conclusion. Given the financing and currency pressures affecting many Ghanaian entities, the going-concern discussion deserves particular attention.

Red flags

  • Reliance on management representations alone. Fraud or going-concern conclusions supported only by management’s word, without corroborating evidence.
  • Superficial IT coverage. Cyber and IT controls addressed only at a high level with no specialist involvement.
  • No trigger analysis. An inability to say what circumstances would change the going-concern conclusion.

Q4. How are you auditing non-financial reporting, including ESG and sustainability claims?

ESG reporting in Ghana is maturing, and boards are increasingly making public claims about environmental performance, social impact and governance practices. Where those claims appear in reporting, stakeholders expect a level of assurance. This is a comparatively new frontier, and it is a defining element of the audit committee’s role changing roles.

Scope and level of assurance

The committee should establish precisely which non-financial disclosures are within the auditor’s scope and at what level of assurance. Assurance engagements over non-financial information are typically performed under the IAASB’s assurance framework (such as ISAE 3000), and the committee should understand whether the engagement provides limited or reasonable assurance, the two differ substantially in the depth of work and the confidence conveyed.

Materiality and specialist competence

Non-financial reporting raises distinct materiality questions, because what matters to a stakeholder may not be captured by financial thresholds. The committee should ask how materiality was determined for ESG metrics and whether the audit team possesses, or has brought in, the competencies needed to evaluate environmental or social data. Not every audit firm has deep ESG capability, and honest disclosure of that fact is a mark of integrity.

Evidence to request

The committee should request the assurance engagement scope, the standard applied, and a description of the specialists involved. It should ask how data underlying ESG claims was verified, since much of that data originates outside the finance function.

Red flags

  • Vague scope. Uncertainty about which ESG claims were actually examined.
  • Missing expertise. An audit firm assuring ESG metrics without demonstrable competence or specialist support.
  • Assurance level confusion. Public statements implying more assurance than the engagement actually provided.

Q5. Auditor independence and the audit committee’s role on communication

The fifth question protects the credibility of everything that precedes it. An audit is only as valuable as the independence and competence behind it, and effective communication is what allows the committee to act on what the auditor finds. ICAG issues guidance on auditor independence and professional conduct, and the committee should treat independence as a matter to be tested, not assumed.

Independence, rotation and tendering

The committee should confirm that the auditor has assessed threats to independence, including non-audit services provided to the entity, and how those threats were safeguarded. It should also consider partner rotation and periodic tendering, both of which support fresh perspective and reduce familiarity risk. For financial institutions and listed entities, these considerations carry additional regulatory weight; committees should confirm the applicable rotation requirements with reference to the current rules of the relevant regulator.

Expertise and talent continuity

The committee should understand who is on the engagement team, whether the key personnel have relevant sector experience, and how continuity is maintained across years. Frequent unexplained turnover of engagement staff can undermine audit quality.

Communication protocols

Finally, the committee should agree how and when the auditor will communicate. Timely management letters, clear reporting of control deficiencies, and structured follow-up on prior-year findings are essential. The committee should own the remediation tracker and hold both management and auditor accountable for closing issues.

Red flags

  • Late reporting. Management letters delivered long after fieldwork, leaving no time to act.
  • Unresolved control issues. Deficiencies that recur year after year without remediation.
  • Independence ambiguity. Significant non-audit fees with no clear safeguard analysis.

Comparison table: traditional audit scope versus the evolving 2026 focus

The table below contrasts the traditional audit model with the evolving expectations of 2026 and sets out what the committee should ask on each dimension. Committees should weight these priorities according to entity size and sector, a bank or listed company will need to press harder on cyber, prudential controls and independence than a small private company.

Dimension Traditional audit (pre-2020s) Evolving audit (2026 focus) What the committee should ask
Scope Financial statements and opinion Financial statements plus emerging entity-specific risks and selected non-financial disclosures How has scope changed to reflect our current risk profile?
Technologies used Sample-based manual testing CAATs, full-population testing, continuous monitoring, AI-assisted analytics What data did you test, how completely, and what limitations applied?
Fraud and cyber focus Standard fraud enquiry; limited IT review Targeted fraud procedures under ISA 240 and specialist IT-controls assessment How did you address management override and evaluate our IT controls?
Non-financial reporting Generally out of scope Limited or reasonable assurance over ESG and sustainability claims Which claims were assured, at what level, and by whom?
Communication cadence Annual meeting around sign-off Pre-audit planning, interim updates and post-audit review How and when will you report findings and track remediation?
Auditor specialists Rarely used IT, valuation, ESG and data specialists as needed Which specialists were engaged and why?

Practical checklist: sample requests, meeting agenda and templates

The following action kit turns the audit committee’s roles into concrete steps. Each item should have a named owner, typically the committee chair, the company secretary or the chief financial officer.

Sample email to the auditor requesting an updated audit plan

“Ahead of our planning meeting, please provide the current-year audit plan, a summary of your risk assessment and any changes from the prior year, the materiality basis applied, the scope of data analytics to be performed, and a description of any specialists (IT, ESG, valuation) you intend to involve. Kindly indicate the level of assurance proposed for any non-financial disclosures within scope.”

Suggested audit committee meeting agenda

  1. Review of the updated audit plan and risk assessment (Q1).
  2. Technology and data analytics approach, including exception reporting (Q2).
  3. Fraud, cyber and going-concern procedures and findings (Q3).
  4. Non-financial and ESG assurance scope and results (Q4).
  5. Independence confirmation, engagement team and communication plan (Q5).
  6. Prior-year findings and remediation tracker.
  7. Management letter responses and action owners.

Twelve-point committee checklist

  • Plan reviewed. Current-year audit plan received and challenged.
  • Risks mapped. Entity-specific risks reflected in scope.
  • Materiality understood. Basis explained and reasonable.
  • Analytics confirmed. Data sources, tools and limitations disclosed.
  • Fraud procedures. ISA 240 responses discussed.
  • Cyber controls. IT-controls assessment and specialist use confirmed.
  • Going concern. Evaluation process and triggers understood.
  • ESG scope. Non-financial assurance scope and level agreed.
  • Independence. Threats, safeguards and non-audit fees reviewed.
  • Rotation. Partner rotation and tendering considered.
  • Communication. Reporting cadence and management letter timing agreed.
  • Remediation. Prior findings tracked to closure with owners.

On the recurring question of cost, boards frequently ask how much auditors are paid and how fees should be budgeted. Fees vary considerably by the size, sector and complexity of the entity; for a fuller treatment see Statutory audit fees in Ghana (2026). The committee’s focus should be on value and capability rather than price alone.

Conclusion: next steps for boards in Ghana

The audit committee’s changing role gives boards in Ghana a disciplined way to modernise their oversight without becoming technical experts. By asking how the audit plan reflects current risk, how technology and analytics were used, how fraud, cyber and going-concern uncertainties were addressed, how non-financial reporting was assured, and how independence and communication are maintained, a committee can hold its auditor to the standard that the future demands. The practical next step is to embed these questions into the pre-audit and post-audit agendas, assign owners to each follow-up, and set a remediation timeline that reports back to the full board.

Where an issue is material, a significant control failure, an unresolved going-concern concern, or an independence conflict, it should be escalated to the board without delay. Committees seeking to update their processes can request advisory input to tailor the audit committee’s role checklist to their sector and size.

Need Expert Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Richard Dwumor at RDK Consulting Services, a member of the Global Law Experts network.

Sources

  1. Ghana Audit Service
  2. Securities and Exchange Commission, Ghana
  3. Bank of Ghana
  4. Institute of Chartered Accountants, Ghana
  5. Parliament of Ghana, Companies Act, 2019 (Act 992)
  6. International Auditing and Assurance Standards Board (IAASB)
  7. The Institute of Internal Auditors (IIA)
  8. Ghana Stock Exchange

FAQs

How much are statutory audit fees in Ghana in 2026?
Fees vary by the size, sector and complexity of the entity, and there is no single figure. A larger, regulated or listed entity will pay considerably more than a small private company. For detailed budgeting guidance see the Global Law Experts guide on statutory audit fees in Ghana (2026).
The largest firms operating in Ghana include the major international networks and established local practices. Rather than selecting on brand alone, committees should evaluate sector expertise, data-analytics capability, ESG competence and independence when appointing or reappointing an auditor.
Oversight is shared among several bodies: the Securities and Exchange Commission for listed-company disclosure, the Bank of Ghana for banks and specialised deposit-taking institutions, the Institute of Chartered Accountants, Ghana for professional conduct and audit quality, and the Ghana Audit Service for public-sector audit.
The committee should define which non-financial claims are assured, confirm whether the engagement provides limited or reasonable assurance, test whether the audit team has the necessary ESG competence, and ensure the underlying data is verified. This is central to how the audit committee’s role changing five questions applies to sustainability reporting.
Best practice is to meet at least twice a year, with pre-audit planning and post-audit review sessions, and more frequently for complex, regulated or listed entities. Committees should also hold at least one session with the auditor without management present.
big 7 law firms indonesia
By Global Law Experts

posted 37 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

The Audit Committee's Role Is Changing: Five Questions Boards in Ghana Should Be Asking Their Auditors in 2026

Send welcome message

Custom Message