Good governance leaves a record.
Boards and management make decisions, exercise delegations, appoint officeholders, manage conflicts, approve policies, oversee risk and compliance, engage with regulators and monitor whether agreed actions are completed. The quality of the records supporting those activities matters because those records help demonstrate not only what an organisation decided, but how its governance arrangements actually operated.
Yet governance records can be easy to take for granted. A register may be maintained but not reconciled. A charter may still name a committee structure that changed two years ago. A policy may have missed its review date. A director handbook may contain superseded material. Board templates may have evolved inconsistently across committees. Regulatory lodgements may sit in one system while the underlying approvals sit somewhere else.
Records may technically exist, but be difficult to find, poorly version-controlled or accessible to the wrong people.
That is why a periodic governance health check can be worthwhile.
What is a “governance record”?
There is no single statutory category called a “governance record”. The expression is useful shorthand for the much wider body of records that evidence an organisation's governance arrangements, decisions and compliance.
For a company, that can include statutory registers; the constitution; directors' consents and appointment records; minutes and resolutions; board and committee charters; delegations; policies and procedures; director induction and reference materials; board and committee calendars and workplans; agendas, board papers and action registers; records of conflicts and interests; regulatory lodgements; and records showing how governance controls and approval processes operated.
The legal requirements are spread across different sources. ASIC reminds company officeholders that they are responsible for ensuring required company records are kept, including financial records, registers, meeting records and the constitution where applicable. The Corporations Act 2001 also contains specific requirements concerning financial records, statutory registers and minutes. For entities required to prepare sustainability reports, the Act now also contains sustainability-record obligations.
For registered charities, the ACNC similarly requires appropriate financial and operational records, with the detail depending on matters such as the charity's size, complexity and activities. That reinforces a broader point: good record keeping is not one-size-fits-all. It should be proportionate to the organisation.
What does “healthy” look like?
A healthy governance record set should be more than technically compliant. It should be complete enough to evidence the organisation's governance arrangements and key decisions; accurate, current and internally consistent; readily retrievable by authorised users; subject to clear ownership, approval and version control; appropriately protected; retained for the correct period; and aligned with applicable laws, regulatory requirements, governing documents and internal policies.
Most importantly, it should be fit for purpose.
A large listed or prudentially regulated group needs a different level of governance infrastructure from a small proprietary company. A large charity may have another set of statutory and stakeholder expectations again. A health check should not reward bureaucracy for its own sake. It should ask whether the organisation has enough governance structure and evidence to support sound decisions, compliance and accountability – without unnecessary process.
Where can problems arise?
There is no reliable Australian evidence allowing us to say that organisations generally keep either good or poor governance records. Nor is there convincing public data showing that particular governance-record failures are universally the “most common”.
A health check can nevertheless sensibly test a number of diagnostic hotspots.
These include gaps and inconsistencies between regulator records and internal registers (which do happen from time to time and can be identified through comparison reports); significant differences in key terms / definitions; inconsistencies in the interpretation and application of policies and/or procedures; unsigned or incomplete minutes and resolutions; policies or charters overdue for review; unclear document ownership; inconsistent templates; missing evidence behind annual attestations; weak handovers following staff turnover; fragmented records across email, board portals, shared drives and entity-management systems; excessive access permissions; inadequate retention and destruction controls; and discrepancies between a group governance framework and what subsidiaries actually do.
These are not simply housekeeping considerations. ASIC continues to take enforcement and administrative action in cases where inadequate financial records form part of the identified misconduct. Several 2026 director-disqualification decisions have included failures to maintain proper financial records among ASIC's findings.
The broader lesson is straightforward: records are part of the control environment, not an administrative afterthought.
Isn't this what the auditors do?
Not necessarily – and this is where roles need to be distinguished carefully.
An external financial report audit is designed to enable the auditor to express an opinion on the financial report. Under Australian Auditing Standards, the auditor seeks reasonable assurance that the financial report as a whole is free from material misstatement. In doing that work, the auditor may identify and communicate significant deficiencies in internal control. But the financial report audit is not, by itself, a comprehensive opinion on the organisation's entire governance record set or the effectiveness of every governance process.
Internal audit can have a much broader remit. The Institute of Internal Auditors describes internal audit as providing independent advice and assurance concerning governance, risk management and controls. Whether governance records are examined – and how deeply – will depend on the internal audit plan and particular engagement scope.
A specialist governance health check therefore should not be positioned as replacing or second-guessing either function. Its value lies in a deliberately focused review of governance records, processes and practical governance architecture by someone with relevant specialist experience.
Done well, it should complement the company secretary, management, internal audit and external audit.
What about annual attestations and audit representation letters?
Attestations can be useful controls, but they are only as strong as their scope, evidence and challenge.
A statement that “all records are in order” provides limited comfort if there is no common definition of what records are covered, no underlying evidence, no process for identifying exceptions and no clear accountability for remediation.
Better attestation processes identify what is actually being attested to, nominate the responsible owner, require appropriate enquiries and supporting evidence, surface exceptions and track outstanding actions.
There is a useful analogy in external audit. ASA 580 treats written representations from management – and, where appropriate, those charged with governance – as necessary audit evidence in relevant circumstances, but expressly states that written representations do not provide sufficient appropriate audit evidence on their own.
That also corrects a possible misconception. An audit representation letter is not necessarily a letter signed by every director. Directors should obtain comfort through the organisation's underlying systems, controls, information and evidence rather than treating a representation letter as a substitute for them.
How often should a health check be done?
There is no prescribed Australian rule requiring an independent governance health check every two or three years.
Nevertheless, a practical model for many organisations could involve routine annual governance housekeeping by the internal owner, a deeper independent review every two or three years adjusted for growth, risk and complexity, and additional event-driven reviews when circumstances materially change (e.g., following a significant M&A transaction).
Potential triggers include an acquisition or restructure; rapid organisational growth; significant changes to the board, company secretary or senior governance personnel; major regulatory reform; implementation of a new board portal or entity-management system; a cyber or records incident; significant remediation; or preparation for an IPO, transaction or other major assurance exercise.
Conducting a review sufficiently ahead of financial year-end may also be useful where governance records intersect with the external audit process.
But the case for a governance health check is much broader than audit readiness. For organisations that are not externally audited, an independent review may provide another source of assurance precisely because that annual external touchpoint is absent.
Privacy, cyber security and the danger of “keep everything”
Good record keeping does not mean keeping everything forever.
For entities covered by the Privacy Act, APP 11 requires reasonable steps to protect personal information and, subject to relevant exceptions, to destroy or de-identify personal information when it is no longer needed for a permitted purpose. Other laws may require particular records to be retained for specified periods. Retention therefore needs to be managed by record category and applicable obligation rather than through a blanket “keep everything” rule.
For APRA-regulated entities, CPS 234 provides another dimension. It requires information-security controls commensurate with the criticality and sensitivity of information assets, including controls across the information-asset lifecycle and where information is managed by related or third parties.
A governance health check should therefore look not only at whether records exist, but where they are held; who can access them; whether authoritative versions are identifiable; whether records can be recovered or exported if a vendor relationship ends; how backups and audit trails operate; and whether retention and destruction requirements are actually implemented.
Where does AI fit?
AI can potentially help governance teams search and classify large record sets, identify apparent inconsistencies, extract information, compare versions, map obligations and highlight possible gaps.
Used carefully, that could make aspects of a governance health check faster and more economical.
But AI should not become a new source of unreliable corporate records.
Australian Government guidance on AI adoption emphasises accountability, understanding impacts, risk management, transparency, testing and monitoring, and meaningful human control. APRA has also warned regulated entities in 2026 that aspects of governance, risk management, assurance and operational resilience have not kept pace with AI adoption.
For governance records, that translates into practical disciplines: protect confidential and personal information; understand where information is processed and retained; maintain provenance; control access; validate AI-generated classifications or summaries; preserve the authoritative source record; and keep humans responsible for judgement and final sign-off.
The recently updated AICD/Governance Institute guidance on board minutes similarly stresses that AI should not replace human oversight and that appropriate controls are needed to preserve the integrity and reliability of board minutes.
What would an independent governance health check involve?
The scope should be agreed before work begins. A light-touch review might test a defined set of high-value records and processes. A deeper review might examine the organisation's governance framework end-to-end.
A sensible methodology would ordinarily involve mapping the relevant obligations and governance artefacts; reviewing and sampling records; reconciling key registers and regulatory information; testing ownership, approval, version-control, access, retention and security arrangements; assessing meeting and decision-recording processes; interviewing key custodians; benchmarking practice; and producing a prioritised remediation plan with clear owners and timeframes.
The output should be practical.
The objective is not to produce a long report proving that a review occurred. It is to tell the board and management what is sound, what needs attention, what matters most and what should happen next.
There is no authoritative public Australian fee benchmark for this particular type of specialist engagement. Cost will depend heavily on scope, entity size, number of entities, record quality, systems, regulatory complexity and depth of testing. A scoped fixed fee will therefore often provide a client with greater certainty than an open-ended hourly arrangement.
A fresh pair of eyes – not a vote of no confidence
The best positioning for a governance health check is constructive.
It is not an assertion that the company secretary, governance team or auditors have failed. In many organisations, records have developed over years under different people, systems and regulatory settings. Experienced internal teams can also become accustomed to workarounds that a fresh reviewer notices immediately.
The benefit of a specialist external review is therefore independence of perspective, concentrated governance expertise and benchmarking. It can validate what is working well just as importantly as identifying gaps.
Ultimately, good governance hygiene is about being able to answer a simple question with confidence:
If the board, an auditor, a regulator, a transaction team or a newly appointed company secretary needed the organisation's governance evidence tomorrow, could the right records be found quickly – and relied upon?
Governance in Action Pty Ltd can assist clients with conducting independent health checks of corporate records and processes.
David Cantrick-Brooks FGIA FCG, Principal & Director of Governance in Action Pty Ltd, would be pleased to assist with enquiries. Please feel free to reach out via LinkedIn or via gia.net.au.
AI-assisted tools and techniques were used here to support the research, drafting and editing of this publication. Responsibility for the final content rests with David Cantrick-Brooks.
Whilst accounting and legal terms and references may be contained in this publication, it does not constitute or purport to be or represent accounting or legal advice of any kind – whatsoever. Readers should seek their own independent professional advice.