Deloitte Audit Committee Practices Report Finds ERM Leading as AI Oversight Grows
Key Takeaways
- ERM Rises to the Top: Among audit committees responsible for ERM oversight, 39% ranked it their No. 1 priority and 77% placed it among their top three.
- Cybersecurity Remains Pervasive: Cybersecurity appeared among the top three priorities for 87% of respondents, the highest share of any issue measured.
- AI Responsibility Is Outpacing Readiness: 75% identified AI governance as a top-three priority, but 82% described their AI governance oversight as emerging or limited.
- Technology Skills Are in Demand: 70% said technology, including AI, was the skill most needed to improve audit committee effectiveness.
- Better Discussion Matters: 41% identified higher-quality discussion and challenge in meetings among their top three opportunities to improve committee effectiveness.
Deep Dive
Enterprise risk management has reached the top of the audit committee’s priority list. AI governance is not far behind, though the people charged with overseeing it are considerably less certain they have the machinery in place to do the job.
The fifth edition of the Audit Committee Practices Report, produced by Deloitte’s Center for Board Effectiveness and the Center for Audit Quality, draws on close to 250 responses from audit committee chairs and members. What emerges is an audit committee agenda growing faster than the capabilities needed to oversee everything now landing on it.
Among respondents whose audit committees oversee enterprise risk management, 39% ranked ERM as their No. 1 priority and 77% placed it among their top three. More than half of respondents, 54%, said their committees had increased their focus on emerging risks during the past year.
Cybersecurity casts an even wider shadow across the agenda. It was named among the top three priorities by 87% of respondents, the highest share for any issue measured. But there is an important difference between prevalence and rank: ERM was most likely to occupy the No. 1 position among committees responsible for it, while cybersecurity appeared on more top-three lists overall.
Three-quarters of respondents identified AI governance as a top-three priority, compared with 35% in the previous year’s survey. The responsibility has arrived faster than confidence in carrying it. Just 56% of respondents said they were confident in their committee’s ability to oversee AI governance effectively, and 82% described their oversight in this area as emerging or limited.
Those figures are difficult to separate from another finding in the report. When respondents were asked which skills would most improve audit committee effectiveness, 70% pointed to technology, including AI.
This is where the expansion of the audit committee’s remit becomes more than a matter of adding another item to the agenda. A committee can assign itself responsibility for AI governance on paper. Effective oversight asks considerably more: enough visibility into how the technology is being used, enough knowledge to understand the risks it creates, and reporting good enough to tell directors where management has control and where it does not.
There is more confidence around cybersecurity. Among committees responsible for its oversight, 82% of respondents said they were confident in their ability to oversee it effectively. The contrast with AI is useful. Both technologies now command considerable attention, but committees have had longer to develop the structures, reporting lines and experience needed to challenge management on cyber risk. AI governance is being built while the technology itself is still changing underneath it.
The findings also expose a less technical problem, and perhaps a more stubborn one. Asked where audit committee effectiveness could be improved, 41% of respondents selected higher-quality discussion and challenge during meetings among their top three opportunities, making it the leading response.
An audit committee can have the right expertise around the table and still fall short if information arrives without context, difficult questions are left unasked or meetings become exercises in moving through an agenda. The report puts weight on the quality of the exchange itself: candid communication, informed challenge and enough engagement for oversight to amount to more than receipt of management’s account.
The same point surfaces in the committee’s relationship with the independent auditor. When respondents were asked about considerations used to assess auditor quality and performance, 52% placed engagement team leadership, experience and continuity among their top three.
There is something revealing in where the report ultimately lands. The risks attracting audit committee attention are becoming more technical and, in the case of AI, developing at remarkable speed. Yet the weaknesses committees identify in themselves are not exclusively technical. They concern expertise, certainly, but also visibility, communication and the quality of discussion inside the room.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

