For many directors, particularly those without an accounting or audit background, the annual external audit can feel highly technical. Yet the governance proposition is straightforward: the auditor provides independent assurance, but the board remains responsible for the financial report.
That distinction matters. Under Australian Auditing Standard ASA 200, an audit is designed to obtain reasonable assurance – a high, but not absolute, level of assurance – that the financial report as a whole is free from material misstatement, whether caused by fraud or error. An audit is not a guarantee that every error, control weakness or fraud will be found.
ASIC is equally clear that directors cannot rely on the external auditor when forming their own opinion on the financial report. The audit follows, rather than replaces, the board’s own judgement.
When is an external audit required?
The answer depends on the entity and the applicable legal and regulatory framework.
Under section 301 of the Corporations Act 2001 (Cth), companies, registered schemes, registrable superannuation entities and disclosing entities that are required to prepare an annual financial report generally must have it audited, subject to specific exceptions and relief.
Large proprietary companies will ordinarily require an audit, although statutory relief can apply in particular circumstances. Different regimes apply to some companies limited by guarantee, charities and other entities. Constitutions, financing arrangements, grant conditions or other contracts may also require an audit even where legislation does not.
For ACNC-registered charities, for example, a large charity must have its annual financial report audited, while a medium charity may generally choose between a review and an audit. A review provides limited assurance; an audit provides reasonable assurance.
Directors should therefore confirm the precise audit obligation for their entity rather than assume that one rule applies to every organisation.
The board owns the financial report
The most important governance lesson is also the simplest: the external auditor is not a substitute for director judgement.
In ASIC v Healey [2011] FCA 717 – the Centro case – the Federal Court emphasised the personal responsibility of directors to read, understand and focus on the financial statements, using the knowledge they have of the company and making further enquiries where appropriate.
Section 189 of the Corporations Act permits reasonable reliance on specified information and expert advice in defined circumstances, but only where the statutory conditions are met, including good faith and an independent assessment.
The practical implication is not that every director must become an auditor or technical accountant. It is that every director must engage sufficiently with the financial report to form their own view. The Audit Committee can do much of the detailed work, but it does not displace the responsibility of the full board.
For listed entities, the current fourth edition of the ASX Corporate Governance Principles and Recommendations reinforces this architecture through Principle 4, including audit committee arrangements and CEO/CFO declarations. The draft fifth edition was released for consultation in July 2026, with submissions closing on 14 September 2026; it is not yet the operative edition.
What does the audit process usually look like?
There is no single timetable. A well-run audit is usually an annual cycle rather than a burst of work immediately after year-end.
The sequence commonly includes:
1. Appointment, continuance and independence
The entity and auditor confirm appointment arrangements, scope, terms of engagement, independence and resourcing. For a new auditor, transition planning and communication with the predecessor are important.
2. Planning and risk assessment
The audit team develops its strategy and plan, obtains an understanding of the entity and its environment, identifies risks of material misstatement and determines materiality.
Materiality is a matter of professional judgement and includes both quantitative and qualitative considerations; it should not be reduced to a universal percentage formula.
3. Interim work and controls
Depending on the audit approach, the auditor may perform walkthroughs and test relevant controls before year-end.
External auditors may use eligible work of an internal audit function where the requirements of ASA 610 are met, but the external auditor retains sole responsibility for the audit opinion. In Australia, internal auditors cannot be used to provide “direct assistance” on the external audit.
4. Year-end and substantive procedures
The auditor tests balances, transactions, disclosures, estimates and judgements; obtains confirmations or other evidence where appropriate; considers subsequent events, going concern and fraud risks; and evaluates whether sufficient appropriate audit evidence has been obtained.
5. Completion and reporting
Proposed and uncorrected misstatements are assessed; significant matters are communicated to management and those charged with governance; written representations are obtained; outstanding issues are resolved; and the auditor forms and issues the independent auditor’s report.
In practice, the process can span several months, particularly for a large or complex group.
Where should directors and the Audit Committee engage?
Directors should not attempt to manage the audit. They should govern the relationship and focus on audit quality.
Key touchpoints include:
• auditor selection and reappointment;
• the audit plan, scope and significant risks;
• material accounting estimates and judgements;
• the auditor’s independence and any non-audit services;
• changes in scope or fees;
• major control deficiencies;
• fraud or suspected fraud;
• uncorrected misstatements;
• going concern;
• significant disagreements with management; and
• the final audit report.
ASIC advises that audit tenders should focus primarily on audit quality rather than price. Relevant questions include whether the engagement partner and team have the required expertise, industry knowledge and capacity; whether the proposed fee permits a properly resourced audit; how specialists and component auditors will be used; and how the firm demonstrates professional scepticism and effective quality management.
There is no general Australian “best practice” rule that non-audit fees must stay below an arbitrary percentage of audit fees. The correct analysis is principles- and rules-based: identify the services, consider the Corporations Act and APES 110 independence requirements, assess threats to independence and applicable prohibitions, and ensure required approvals and disclosures are made.
Listed-company directors also have specific statutory reporting obligations concerning non-audit services and auditor independence.
A private session with the auditor, without management present, is also valuable governance practice. It can create space to ask:
• Did the auditor experience any restriction on scope, delay or difficulty obtaining information?
• Were there significant disagreements with management?
• Does the finance function have sufficient capability and resources?
• Does the auditor have concerns about management bias, fraud risk or tone?
• Is there anything the auditor believes the Committee should know that has not otherwise been discussed?
Written representations: management, board or both?
This is an area where practice can be confused with legal requirement.
ASA 580 requires the auditor to obtain written representations from management with appropriate responsibility for the financial report and knowledge of the relevant matters and, where appropriate, from those charged with governance.
The individuals involved depend on the entity’s governance structure. The standard notes that representations are often requested from the CEO and CFO, although in some circumstances those charged with governance are also responsible for preparing the financial report.
Accordingly, there is no universal rule requiring an identical “back-to-back” representation letter from management and the board before every audit opinion can be issued.
Other auditing standards may require specific representations. For example, ASA 450 requires a representation concerning the effect of uncorrected misstatements from management and, where appropriate, those charged with governance.
Written representations are audit evidence, but ASA 580 expressly says they are not sufficient appropriate audit evidence on their own. They should not become a ritual substitute for evidence, enquiry or board judgement.
They should also be distinguished from the statutory directors’ declaration under section 295 and, for listed entities, the CEO/CFO declarations under section 295A.
Uncorrected audit differences: “immaterial” does not mean “irrelevant”
ASA 450 requires the auditor to communicate uncorrected misstatements to those charged with governance and explain the effect they may have, individually or in aggregate, on the audit opinion.
Audit Committees should understand:
• why management proposes not to correct an item;
• whether there is any qualitative significance;
• whether multiple items point in the same direction;
• whether prior-period differences are accumulating; and
• whether the errors reveal a systems or process issue.
The key is proportionality. A small uncorrected difference is not automatically evidence of a control failure or misconduct. Equally, the fact that an item is below the auditor’s quantitative materiality threshold should not end the discussion.
Legal professional privilege needs active management
Audit evidence concerning litigation and claims can create a difficult interface with legal professional privilege.
ASA 502 expressly recognises that information about litigation may be privileged and warns that disclosure of information in a legal enquiry letter directly to the auditor for audit purposes is not itself privileged and may compromise privilege.
At the same time, AUASB Guidance Statement GS 011 acknowledges that pre-existing privileged documents or information may be present in an audit file and require careful handling.
There is no safe generic formula.
Where material legal matters are involved, the entity should involve its legal advisers early, agree a disciplined protocol for communications with the auditor, disclose what is necessary for the audit while minimising unnecessary dissemination of privileged advice, and consider privilege and waiver risks before documents are provided.
The auditor still needs sufficient appropriate audit evidence, so the practical objective is to reconcile the audit requirement with the protection of privilege – not simply to treat one as overriding the other.
Can the auditor report to ASIC without telling the company?
Yes, in some circumstances.
An auditor has statutory reporting obligations to ASIC, including under section 311 of the Corporations Act. ASIC states that relevant notifications must be made as soon as practicable and, in any event, within 28 days after the auditor becomes aware of the circumstances.
Other regimes can impose different and shorter timeframes – for example, particular obligations applying to auditors of Australian Financial Services licensees.
There is no general statutory condition that the auditor must first obtain the company’s consent or notify the board before making a required report to ASIC.
The exact reporting obligation depends on the facts and the applicable statutory regime. Boards should therefore treat an auditor’s regulatory reporting obligations as part of the independence architecture, not as a breach of the relationship.
Understanding the audit opinion
The audit report should not be described as a ladder of progressively lower “assurance levels”. An audit is a reasonable-assurance engagement; the opinion communicates the auditor’s conclusion.
An unmodified opinion means the auditor concludes that the financial report is prepared, in all material respects, in accordance with the applicable reporting framework – in a fair-presentation framework, commonly that it gives a true and fair view.
ASA 705 then provides three forms of modified opinion:
• Qualified opinion – generally where the matter is material but not pervasive.
• Adverse opinion – where identified misstatements are material and pervasive.
• Disclaimer of opinion – where the auditor cannot obtain sufficient appropriate audit evidence and the possible effects could be material and pervasive.
An Emphasis of Matter paragraph or Other Matter paragraph under ASA 706 does not, of itself, modify the audit opinion.
Key Audit Matters under ASA 701 are also not separate audit opinions.
Technology, AI and the changing audit
AI and advanced analytics are increasingly relevant to audit, but governance should be proportionate.
AUASB guidance issued in July 2025 notes opportunities for AI in extracting and analysing information and identifying patterns or anomalies, while also identifying risks including automation bias, opaque models, unreliable outputs, changing logic, confidentiality and data-security concerns.
A sensible Audit Committee does not need to “approve” the auditor’s technology. It should, however, be comfortable that the audit firm’s use of technology does not weaken audit quality, professional judgement, confidentiality or evidence.
Useful questions include:
• What material parts of our audit use AI-enabled tools?
• How are outputs validated?
• What information leaves the firm’s controlled environment?
• What safeguards apply to confidential data?
• Who remains accountable for the audit conclusion?
The reporting perimeter is also expanding.
Sustainability reports required under the Corporations Act have their own phased review and audit requirements under section 301A, ASSA 5000 and ASSA 5010. These requirements are related to corporate reporting but should not be conflated with the financial statement audit.
Two forthcoming auditing standards also deserve attention: revised ASA 240 on fraud and ASA 570 on going concern apply to financial reporting periods beginning on or after 15 December 2026, with the revised going-concern standard permitting early adoption.
If the audit relationship is not working
Poor service, weak communication, unexpected overruns or concerns about quality should first be addressed candidly with the engagement partner and, if necessary, senior audit-firm leadership.
The Audit Committee should distinguish between legitimate concern about service quality and discomfort because the auditor is appropriately challenging management.
If a change is warranted, plan early. Auditor resignation, removal and replacement are regulated and the process differs by entity type.
In particular, resignation by the auditor of a public company generally requires ASIC consent. Removal of a company auditor follows a statutory member process. Australian law also imposes audit-partner rotation requirements for specified entities; it does not impose a general mandatory audit-firm rotation rule equivalent to some overseas regimes.
The Audit Committee should oversee the change and guard against any appearance of “opinion shopping”.
Questions every director should be able to answer
Before approving the financial report, a director should be able to answer, in substance:
• What were the most significant financial reporting judgements and audit risks this year?
• What changed from last year – in the business, accounting, systems, controls or audit scope?
• What did management and the auditor disagree about, and how was it resolved?
• What uncorrected differences remain, and why?
• Were there significant control deficiencies, fraud concerns, scope limitations or delays?
• Is the auditor independent in fact and appearance?
• Has the auditor had enough time, information, expertise and resources to conduct a quality audit?
• Is there anything in the financial report that I do not understand well enough to approve?
The final question is the most important.
An external audit is an important source of independent assurance. It is not board insurance.
The strongest governance occurs when management prepares high-quality reporting, the auditor challenges it independently, the Audit Committee interrogates both sides, and every director remains sufficiently informed and engaged to exercise their own judgement.
Governance in Action Pty Ltd can assist clients with understanding the typical audit process – from a corporate governance point of view.
David Cantrick-Brooks FGIA FCG, Principal & Director of Governance in Action Pty Ltd, would be pleased to assist with enquiries. Please feel free to reach out via LinkedIn or via gia.net.au.
AI-assisted tools and techniques were used here to support the research, drafting and editing of this publication. Responsibility for the final content rests with David Cantrick-Brooks.
Whilst accounting and legal terms and references may be contained in this publication, it does not constitute or purport to be or represent accounting or legal advice of any kind – whatsoever. Readers should seek their own independent professional advice.