Governance Audits in Australia: What Boards Can Learn from the Public Sector
Governance Audits in Australia: What Boards Can Learn from the Public Sector
David Cantrick-Brooks | 18/08/2026

Most organisations can produce a governance framework, a suite of policies, committee charters and a delegations matrix. The harder question is whether those arrangements actually work.

That is where a governance audit – or, depending on the nature of the engagement, a governance review or governance health check – can add value. For present purposes, a governance audit is a structured, evidence-based examination of whether an organisation’s governance arrangements are appropriately designed, implemented and operating as intended, and whether they support effective oversight, accountability, decision-making, risk management, integrity and organisational purpose.

The label matters less than the substance. A review that merely confirms that documents exist is unlikely to reveal much about governance effectiveness. A useful governance audit tests the gap between policy and practice.

Is “governance audit” a recognised discipline?

There is no single Australian statutory template for a generic “governance audit”, and the term can describe different kinds of work. An engagement might be advisory, an internal-audit engagement, an independent governance effectiveness review or – where an assurance conclusion is to be expressed against suitable criteria – a formal assurance engagement. Australian assurance standards separately regulate assurance engagements outside audits or reviews of historical financial information.

The scope, criteria, evidence standard and wording of the report should therefore be clear from the outset. This distinction matters: calling an exercise an “audit” can imply a level of independence, testing and assurance that a lighter-touch review may not provide.

Governance itself is necessarily broad. The current ASX Corporate Governance Principles and Recommendations describe corporate governance as the framework of rules, relationships, systems and processes by which authority is exercised and controlled, including the mechanisms by which companies and those in control are held to account. A governance audit can therefore cut across areas that organisations often examine separately.

Why does governance auditing seem more visible in government?

The proposition needs some qualification. It is difficult to demonstrate that standalone “governance audits” are universally or routinely performed across the Australian public sector. What can be demonstrated is that governance assurance is often more formalised, transparent and publicly visible.

The Australian National Audit Office (ANAO), for example, has expressly conducted a series of board governance audits using a standard methodology across corporate Commonwealth entities. Those audits considered compliance with legislative and policy requirements as well as practices supporting effective governance.

That public accountability architecture matters. Commonwealth entities operate within the Public Governance, Performance and Accountability framework. Audit committees are an integral part of that framework and provide independent advice to accountable authorities; the PGPA Rule requires them to review areas including financial and performance reporting and systems of risk and internal control. Public audit reports are also ordinarily visible in a way that private internal-audit reports, board evaluations and governance reviews are not.

Government Business Enterprises sit somewhere between the two worlds. Commonwealth guidance expects GBEs to disclose key governance practices, including board committees, director education and performance-review processes, and ethics and risk-management processes. Their financial statements are subject to Auditor-General arrangements and they can be subject to performance audit. However, the Commonwealth GBE guidance does not impose a blanket requirement to commission a recurring standalone exercise called a “governance audit”.

The private sector may be doing the work under different names

The relative absence of the label “governance audit” in commercial organisations should not be mistaken for an absence of governance assurance.

For ASX-listed entities, the current fourth edition of the ASX Principles contains several separate assurance mechanisms. Recommendation 1.6 calls for a process to periodically evaluate the board, its committees and individual directors; its commentary supports regular review, preferably annually, and periodic use of external facilitators. Recommendation 7.2 requires the risk-management framework to be reviewed at least annually. Recommendation 7.3 addresses internal audit or, where there is no internal-audit function, the processes used to evaluate and continually improve governance, risk management and internal control.

As at 18 August 2026, the fourth edition remains in effect while ASX consults on a draft fifth edition.

Internal audit itself is now governed internationally by the IIA’s 2024 Global Internal Audit Standards, which became effective on 9 January 2025. Among other matters, those standards emphasise board authorisation and oversight, independence, objective engagement work, communication of results and monitoring of action plans.

In other words, private-sector governance assurance is frequently fragmented across board and committee evaluations, internal audit, risk and compliance reviews, culture assessments, policy reviews, external assurance and regulatory examinations. Each may be valuable. The potential blind spot is that nobody periodically steps back and asks whether the governance system works effectively as a whole.

What should a good governance audit test?

A strong governance audit should examine three dimensions: design, operation and outcomes.

Design: Are the governance arrangements fit for purpose? This includes the constitution or other constituent documents; board and committee mandates; decision rights; reserved matters and delegations; reporting lines; conflicts arrangements; codes and policies; risk and compliance frameworks; whistleblowing and speak-up arrangements; assurance structures; and information and escalation protocols.

Benchmarking may help, but “best practice” should not become a substitute for judgement. Appropriate arrangements vary with an organisation’s size, complexity, sector, legal obligations, ownership structure and risk profile – a principle also reflected in the ASX framework.

Operation: Are those arrangements actually used? Evidence might include board and committee papers and minutes; approval trails; conflicts disclosures; delegation testing; breach and incident logs; regulatory correspondence; whistleblowing data; internal-audit reports; risk-acceptance decisions; policy attestations; training records; remediation trackers; and interviews with directors, executives and staff.

This is where a governance audit can distinguish between having a checklist and actually using it; having an escalation procedure and seeing bad news reach the board promptly; or having a conflicts policy and observing how conflicts are handled in practice.

Outcomes: Are the arrangements producing the behaviours and results they were intended to produce? Are directors receiving information of suitable quality and timeliness? Is challenge effective? Are material matters escalated? Are incidents investigated and lessons embedded? Are regulatory, audit and review findings genuinely remediated rather than administratively “closed” while the underlying problem persists?

This three-lens approach helps avoid the classic governance trap: a technically complete framework that is ineffective in practice.

Culture is relevant – but difficult to “audit”

Culture belongs within a governance assessment, but it cannot sensibly be reduced to an employee Net Promoter Score or a speak-up statistic.

Useful evidence can include employee surveys, whistleblowing and speak-up data, conduct and complaints information, staff turnover, risk events, remuneration consequences, customer outcomes, interviews, observations of board and committee dynamics and the consistency between stated values and actual decisions.

The evidence should be triangulated. A low number of whistleblowing reports, for example, could indicate good conduct – or reluctance to speak up. A high number might signify problems – or greater confidence in the reporting system.

A governance auditor should therefore be cautious about claiming to have “measured culture” conclusively. The more defensible question is whether the governance system promotes, detects and responds to behaviours that are consistent – or inconsistent – with the organisation’s stated values, risk appetite and obligations.

Governance assurance functions also need scrutiny

A holistic review should consider whether the board is receiving candid, timely and appropriately objective advice from the functions on which it relies.

For internal audit, independence and objectivity are formal professional requirements under the Global Internal Audit Standards. For the company secretariat, legal, risk and compliance functions, the analysis should instead focus on matters such as mandate, authority, reporting lines, access to the board, resourcing, capability, conflicts and freedom to escalate without inappropriate management interference.

These functions are not interchangeable, and “independence” does not have an identical meaning for each. For example, the current ASX Principles provide that the company secretary should be accountable directly to the board, through the chair, on matters relating to the proper functioning of the board.

A governance audit should also recognise its own conflicts. An internal function reviewing arrangements it designed may be capable of useful self-assessment, but an external reviewer may offer greater objectivity for sensitive issues involving the board, senior management, organisational culture or the effectiveness of second- and third-line functions.

What is outside scope?

A governance audit can assess whether business continuity, disaster recovery, cyber-security and incident-management arrangements are appropriately governed, tested, reported and remediated.

It should not automatically be assumed to include technical penetration testing, simulated cyber attacks or specialist IT-control testing. Those activities require appropriate expertise and should be separately scoped where required.

Likewise, a governance audit is not a substitute for a legal compliance review, financial statement audit, board performance evaluation, culture review or specialist regulatory assurance engagement. It may instead draw together evidence from all of them and identify gaps or inconsistencies between them.

How often should one be undertaken?

There is no universal cycle.

Some governance components have their own legal, regulatory or better-practice review expectations. For example, the ASX Principles address periodic board evaluation and at-least-annual review of the risk-management framework for listed entities. Other organisations will have sector-specific requirements.

For a holistic governance audit, frequency should be driven by risk, complexity and change. A board might use continuous or annual component assurance and commission a broader independent review periodically.

Trigger events can be just as important as elapsed time: a major acquisition or restructuring; rapid growth; a new regulatory regime; significant leadership change; a serious incident; repeated control failures; whistleblowing themes; adverse regulatory findings; sustained underperformance; or evidence that remediation is not working.

The question is not simply “Has three years passed?” but “What assurance does the board need now?”

Can AI make governance audits better and cheaper?

Potentially – but without the false precision sometimes attached to the subject.

AI can assist with document comparison, obligation and policy mapping, analysis of large document populations, synthesis of questionnaire responses, preparation of interview questions, preliminary work programs and first drafts of workpapers and reports. The IIA has documented comparable internal-audit applications ranging from scoping and interview guides to document analysis, testing and report drafting.

Those efficiencies can allow human reviewers to spend more time on the difficult work: understanding context, interviewing people, challenging explanations, assessing materiality, interpreting contradictory evidence and forming conclusions. The IIA itself stresses that the internal auditor must remain central to the process and that professional judgement remains necessary.

AI also creates governance risks of its own. Confidential or personal information should not be placed into tools without appropriate controls. The OAIC recommends due diligence before adopting commercially available AI products, human oversight, consideration of privacy and security, ongoing monitoring and appropriate steps to address accuracy. It specifically cautions against entering personal – particularly sensitive – information into publicly available generative-AI tools.

AI outputs can be wrong while sounding convincing. An auditable human-review process therefore remains essential.

There is no reliable basis for saying that a fixed percentage of every governance audit can be automated. The answer will vary materially with scope, data quality, systems access, the type of evidence being examined, risk and the organisation’s technology maturity.

What does a governance audit cost and how long does it take?

There is no credible one-size-fits-all figure.

Cost and duration depend on matters including organisational size and geographic footprint; regulatory complexity; number of entities and business units; scope; quality and accessibility of records; number of interviews; depth of testing; use of data analytics; and whether board-effectiveness or culture work is included.

A tightly scoped governance health check may be relatively modest. A group-wide independent review of a complex regulated organisation could be a substantial engagement. Quoting a generic market price or standard timetable without these inputs risks creating false expectations.

Boards should instead require a transparent scope, methodology, evidence plan, deliverables, project timetable, fee basis and assumptions before the work begins.

The real lesson for the private sector

The strongest lesson from public-sector practice is not that private organisations should copy government audit machinery. Their purposes, stakeholders, accountability mechanisms and risk tolerances differ.

The more useful lesson is discipline: define criteria, gather evidence, test whether arrangements operate in practice, report findings clearly, assign accountability for remediation and follow through until the underlying issue is demonstrably fixed.

For many private organisations, the opportunity is to connect assurance that already exists.

A board evaluation may tell you how directors perceive board effectiveness. Internal audit may tell you how selected controls operate. Compliance may identify breaches. Risk may highlight exposures. Culture data may reveal behavioural warning signs.

A governance audit can ask what those pieces say collectively about the health of the governance system.

That is a more demanding question than whether the organisation has the right documents.

It is also the question that matters most:

Does our governance framework merely exist, or does it work?

Governance in Action Pty Ltd can assist clients (depending on type and size) with facilitating and conducting governance audits.

David Cantrick-Brooks FGIA FCG, Principal & Director of Governance in Action Pty Ltd, would be pleased to assist with enquiries. Please feel free to reach out via LinkedIn or via gia.net.au.

AI-assisted tools and techniques were used here to support the research, drafting and editing of this publication. Responsibility for the final content rests with David Cantrick-Brooks.

Whilst accounting and legal terms and references may be contained in this publication, it does not constitute or purport to be or represent accounting or legal advice of any kind – whatsoever. Readers should seek their own independent professional advice.

PreviousNext

Related Articles

Lead and Lag Indicators in Corporate Governance: From Rear-View Reporting to Early Warning

Boards need more than a rear-view mirror. Lagging indicators such as breaches, losses, incidents and missed targets remain essential for accountability, but well-designed leading indicators can provide earlier warning of changing risk, culture, capability and control conditions. This article examines what lead and lag indicators actually mean in corporate governance, why the same measure can sometimes be both, and why “leading” should not automatically be equated with “predictive”. It proposes a practical indicator framework across strategy, risk and compliance, culture, WHS, board effectiveness, internal audit, technology, data, customers and third parties. It also considers how big data, analytics and AI can strengthen governance – provided boards first address data quality, privacy, context and assurance. The objective is not perfect prediction, but earlier recognition, better questions and better-informed board decisions.

08/13/2026

Tranche 2 AML/CTF: An Early Temperature Check for Professional Service Providers

Australia’s Tranche 2 AML/CTF reforms moved into live operation on 1 July 2026. One month later, the evidence is not strong enough for a verdict - but it is sufficient to identify the questions that matter. This article explains why scope mapping remains the first control, clarifies the significance of the 29 July enrolment deadline, and examines the shift from having policies and templates to operating an effective AML/CTF framework. It also considers the position of governance and company secretarial providers, the need to integrate customer due diligence into ordinary workflows, the interaction between recordkeeping and privacy, and the responsibilities of governing bodies, senior managers and compliance officers. The central lesson is that commencement readiness is not completion: the next phase is to test, evidence and improve how the program works in live engagements.

08/02/2026

APRA’s proposed recast CPS 510: What changes, what matters and how boards should prepare

APRA’s proposed recast CPS 510 Governance is more than a technical consolidation. It would combine five prudential standards into one cross-industry framework and impose clearer, more evidence-based expectations for board accountability, delegation, management information, skills, performance, renewal, conflicts and fitness and propriety. The most consequential proposals include a mandatory measurable board skills matrix, an independent external board review every three years for significant financial institutions, and a 12-year maximum tenure for non-executive directors. The draft also creates sharper requirements for group-board independence and board information, while reducing routine fit-and-proper reporting through alignment with the Financial Accountability Regime. This article explains the key changes, contrasts them with the draft 5th edition of the ASX Corporate Governance Principles and Recommendations, and sets out a practical implementation agenda for boards, company secretaries and governance advisers. Although commencement is expected in early 2028, long-lead matters such as director succession, committee composition, constitutions, charters and systems should be identified well before the final standard takes effect.

08/01/2026