Skip to main content

Audit and Risk Committee Charter 2026-27

PURPOSE

The AOFM Chief Executive Officer (CEO) has established the Audit and Risk Committee in accordance with section 45 of the Public Governance, Performance and Accountability Act 2013 (PGPA Act) and section 17 of the Public Governance, Performance and Accountability Rule 2014 (PGPA Rule). 

The role of the Audit and Risk Committee is to provide independent advice to the CEO on the appropriateness of the AOFM’s financial reporting, performance reporting, system of risk oversight and management, system of internal control and governance arrangements (including code of conduct). 

The Committee is directly accountable to the CEO for the performance of its functions.

RESPONSIBILITIES AND FUNCTIONS

FINANCIAL REPORTING [PGPA RULE 17(2)(a)]

The Committee will review the financial statements and provide written independent advice to the CEO on its view of the appropriateness of the AOFM’s: 

  • Annual financial statements and additional information required by the Department of Finance to prepare the Australian Government’s consolidated financial statements, including the supplementary reporting package, specifically that they comply with the PGPA Framework, Accounting Standards and supporting guidance. 

  • Financial reporting framework and associated procedures for effective internal control (including appropriate management sign-offs), management responses to audit recommendations and adjustments, and compliance with relevant Accounting Standards, laws or regulations.

  • Processes to ensure that financial information included in the AOFM’s Annual Report is consistent with the signed financial statements. 

PERFORMANCE REPORTING [PGPA RULE 17(2)(b)] 

The Committee will review the performance information, systems and framework and provide written independent advice to the CEO on its view of the appropriateness of the AOFM’s:

  • Systems and processes for measuring, assessing, monitoring, and reporting the achievement of the AOFM’s performance, and determine that: 

    • the Portfolio Budget Statements and Corporate Plan contain appropriate details of how the AOFM will achieve its purposes and measure and assess its performance. 

    • the approach to measuring performance covers the whole performance reporting lifecycle and sufficiently addresses the AOFM’s performance measurement and assessment, and has considered guidance issued by the Department of Finance (including the Commonwealth Performance Framework and Resource Management Guides) and the ANAO;

    • appropriate records are maintained to enable the preparation of the Annual Performance Statement and systems and processes are in place for inclusion of the statements in the AOFM’s Annual Report.

  • Processes to ensure the AOFM’s proposed Performance Statement is consistent with the Corporate Plan and Portfolio Budget Statements.

  • Annual Performance Statement and performance reporting.

SYSTEM OF RISK OVERSIGHT AND MANAGEMENT [PGPA RULE 17(2)(C)]

The Committee will review the system of risk oversight and management and provide written independent advice to the CEO on its view of the appropriateness of the AOFM’s:

  • Enterprise Risk Management (ERM) Framework, ensuring it is consistent with the Committee’s understanding of the AOFM’s operating context and the Commonwealth Risk Management Policy. 

  • Use of the ERM in managing the AOFM’s major risks and identifying the prospect of emerging risks, including those associated with individual projects, program implementation, legal obligations and other business process activities.

  • Governance arrangements for the development, review and approval of the annual remit (Debt Management Strategy and Liquidity Management Strategy) and Financial Risk Management Policy. Governance arrangements include:

    • Advisory Board consideration of the:

      • annual Debt Management Strategy and Liquidity Management Strategy

      • Financial Risk Management Policy

      • Annual evaluation of the implementation and impacts of the Debt Management Strategy and Liquidity Management Strategy.

    • Treasury Secretary approval of the Annual Remit (annually) and the Financial Risk Management Policy (every two years).

    • Portfolio Strategy Meetings and Cash Meetings are held in line with policy requirements.

  • Approach to business continuity and disaster recovery management, including ongoing maintenance and testing of plans.

  • Risk management capability and whether key roles, responsibilities and authorities relating to risk management are clearly articulated and adhered to.

  • Fraud and corruption control arrangements, including preventing, detecting, capturing and responding to fraud and corruption risk, in accordance with the Commonwealth Fraud and Corruption Control Framework. 

  • Integrity framework, and whether the framework is sufficient to manage integrity risks, and monitor, report, and act on integrity matters. 

SYSTEM OF INTERNAL CONTROL [PGPA RULE 17(2)(d)]

The Committee will review the system of internal control and provide written independent advice to the CEO on its view of the appropriateness of the AOFM’s: 

INTERNAL CONTROL FRAMEWORK
  • Approach to maintaining an effective internal control framework, including for critical business processes, contract management, business continuity, delegations, and lawful conduct. 

  • Assurance map and strategy and whether planned assurance activities ensure key obligations, policies and procedures are complied with, and gaps or inefficiencies in assurance activities are identified. 

  • Approach to maintaining effective protective security arrangements, including cyber, in accordance with the Protective Security Policy Framework. 

LEGISLATIVE AND POLICY COMPLIANCE
  • Systems for monitoring compliance and other assurance activities regarding relevant laws, regulations and associated government policies. 

  • Reports on compliance regarding breaches of legislative or policy compliance, the status of any ongoing remedial activities and any changes to risks of the AOFM. 

ADDITIONAL RESPONSIBILITIES

The CEO requires the Committee to undertake the following additional functions beyond those prescribed by the PGPA Rule. 

INTERNAL AUDIT 
  • Review the proposed internal audit coverage regarding its alignment with the AOFM’s key risks and endorse approval of the Internal Audit Plan by the CEO. 

  • Provide written independent advice to the CEO on the allocation of internal audit resources (topics) either through review of the annual internal audit plan and/or requests for specific topics. 

  • Review all audit reports and provide advice to the CEO on significant issues identified in audit reports and action to be taken on issues raised. 

  • Monitor management’s implementation of internal audit recommendations. 

  • Review annual reports from the internal auditor on the overall state of the AOFM’s internal controls. 

  • Periodically review the internal audit charter to ensure appropriate authority, access and reporting arrangements are in place.

  • Periodically review the performance of the internal auditor.

  • Meet privately with the internal auditor at least once per year. 

EXTERNAL AUDIT
  • Consider all external audit plans and reports in respect of planned or completed audits. 

  • Monitor management’s implementation of external audit recommendations. 

  • Provide written independent advice to the CEO on action to be taken on significant issues raised in relevant external audit reports. 

  • Meet privately with the external auditor at least once per year. 

EXCLUSIONS FROM AUDIT AND RISK COMMITTEE REMIT

The Committee has no managerial responsibilities and does not make decisions in relation to the AOFM’s processes and functions. The Committee has no executive powers in relation to the operations of the entity. The Committee may only review the appropriateness of aspects of those operations, consistent with its functions, and advise the CEO accordingly. 

Responsibility for approving the AOFM’s annual remit and financial risk management policy rests with the Secretary to the Treasury. The Committee does not advise on the appropriateness of the content of these artefacts, that is the role of the AOFM Advisory Board. 

The Secretary’s responsibilities include setting policy and operational limits with respect to credit, interest rate and liquidity risk. 

Responsibilities of the Committee will not overlap with the policy role of the Secretary and AOFM Advisory Board. 

AUTHORITY

The CEO authorises the Committee, within the scope of its functions, to obtain information from, hold discussions with, or request presentations by any official, external party or external auditors, as it deems necessary to fulfill its objectives. All requests are subject to appropriate legal and confidentiality considerations. 

The AOFM will meet reasonable expenditure in relation to legal or professional advice where appropriate consultation with the AOFM is undertaken and financial approval from the Chief Operating Officer (COO) is received. 

The Chair may contact the Secretary to the Treasury directly regarding any audit matter judged to be of sufficient concern. 

MEMBERSHIP

In accordance with section 17 of the PGPA Rule, the Audit and Risk Committee will consist of three independent members, appointed by the CEO. The CEO will appoint one member as Chair of the Committee. 

Committee members will have broad range of skills and experience relevant to the operations of the AOFM. The Audit and Risk Committee will comprise of members who collectively possess:  

  • accounting or related financial management experience; 

  • risk and performance management experience; and 

  • financial markets experience. 

The Chair is authorised to appoint a member as Deputy Chair, who will act as Chair when required.

Members will be appointed for an initial term of up to five years. Members may be appointed for further periods, at the discretion of the CEO, with a maximum term of 10 years. 

RESPONSIBILITIES OF AUDIT AND RISK COMMITTEE MEMBERS

Members of the Committee are expected to understand and observe the legal requirements of the PGPA Act and Rules. Members are also expected to: 

  • Have a sound understanding of the AOFM’s functions, objectives and operational context. 

  • Act in the best interests of the AOFM and the Commonwealth. 

  • Apply objectivity, sound analytical skills, and sound judgment in meeting the Committee’s objective.  

  • Express opinions constructively and openly, raise issues that relate to the Committee’s responsibilities and pursue independent lines of enquiry. 

  • Contribute the time required to meet their responsibilities.

Engagement with AOFM Advisory Board and Treasury Audit and Risk Committee
  • The Chair will, from time to time as appropriate, seek to engage with a representative of the AOFM Advisory Board and the Treasury Audit and Risk Committee to ensure the alignment of understanding of key risks and controls. 

INDUCTION 

New members will receive relevant information and briefings on their appointment to assist them to meet their responsibilities. 

CONFLICTS OF INTEREST 

Upon engagement members of the Committee will provide written declarations to the CEO declaring any real or apparent conflicts of interest they may have in relation to their responsibilities. 

Following initial engagement, members are required to provide written declarations of any real or apparent conflicts of interest annually following engagement. Members should consider past employment, consultancy arrangements and related party issues in making these declarations. The CEO, in consultation with the Chair, must be satisfied there are sufficient processes in place to manage any real or apparent conflicts of interest.

At the beginning of each Committee meeting, members are required to declare any real or apparent conflicts of interest that may apply to specific matters on the meeting agenda or any circumstances relating to real or apparent conflicts of interest that have changed since the previous meeting of the Committee or engagement/annual declaration process, whichever is most recent.

Where required by the Chair, the member will be excused from meetings or from the Committee’s consideration of certain agenda item(s). The Chair must also determine, in consultation with the CEO, if they should excuse themselves from the meeting or from the Committee’s consideration of the relevant agenda item(s). 

Details of real or apparent conflicts of interest declared by the Chair and other members through the course of a meeting, and any subsequent action taken, will be recorded in meeting minutes.

REPORTING

The Chair will report to the CEO after each meeting. The Chair may also meet with the CEO from time to time to discuss any matters related to the role of the Committee. 

The Committee will report to the CEO annually on its operation and activities against the responsibilities outlined in this charter. An annual written report outlining the Committee’s view of the appropriateness of the AOFM’s financial reporting, performance reporting, system of internal control and system of risk oversight and management will be provided to the CEO. In providing its view, the Committee should also note any areas of concern, non-remediation of significant recommendations, and/or suggestions or process improvements. 

The Committee may report to the CEO any other matter it deems of sufficient importance at any time. Individual Committee members may also request a meeting with the CEO at any time. 

ANNUAL REPORTING REQUIREMENTS

In accordance with section 17AG of the PGPA Rule, the Annual Report will include the following: 

  • A direct electronic address of the charter determining the functions of the Committee for the entity.

  • The name of each member of the Committee during the period. 

  • The qualifications, knowledge and skills or experience of those members. 

  • Information about each of those members’ attendance at meetings of the Committee during the period. 

  • The remuneration of each of those members. 

ADMINISTRATIVE ARRANGEMENTS

MEETINGS

The Committee will meet at least four times per year. Meetings will be conducted on a face-to-face basis and/or by video conference as necessary. With the approval of the Chair, the Committee can also agree items out of session by email communication. 

Out of session meetings may be held to discuss any matter deemed sufficiently significant. Out of session meetings are held annually to consider the Corporate Plan and draft financial statements. Other topics for out of session meetings, as agreed with the Chair, could include AOFM’s performance measures and/or delivery of strategic programs of work. 

The Chair is required to call a meeting if asked to do so by the CEO, members of the Committee, the internal auditor, or the external auditor. 

MEETING ATTENDANCE BY NON-MEMBERS

The CEO will appoint two internal advisors with relevant experience to assist the business of the Committee to attend all meetings on behalf of the CEO. The COO and Chief Risk and Assurance Officer (CRAO) are appointed as internal advisors for the term of this charter.   

The Committee may, at its discretion, deal with issues or agenda items with none, some or all invitees present. The Committee may also, at its discretion, ask invitees to excuse   themselves from meetings or certain agenda items.

The CEO will provide an update to the Committee as part of all regular meetings. Where the CEO is unavailable, this update can be submitted to the Committee in writing. The CEO may attend meetings at their own discretion. 

The Chief Financial Officer (CFO), internal auditor, or external auditor may attend meetings at the invitation of the Chair. 

Other AOFM officials may be required to attend meetings at the invitation of the Committee to provide updates and advice to the Committee on topics within the remit of their role. 

Other AOFM officials may attend meetings of the Committee as an observer from time-to-time if determined to be appropriate by the CEO and the Chair. 

QUORUM

A quorum for any Committee meeting is a majority (two) of members, one of whom must be the Chair or the Deputy Chair of the Committee. The quorum must remain in place during the meeting. 

FORWARD WORK PLAN 

The Committee will develop an annual forward work plan, detailing proposed agenda items for each meeting for the forthcoming year. The forward work plan will include all responsibilities outlined in this charter. 

Additional or emerging items identified throughout the forward work plan period will be added to the forward work plan as approved by the Chair. 

SECRETARIAT

The Secretariat function is managed by the Governance and Strategic Planning Team, with oversight from the CRAO. The Secretariat is responsible for providing administrative and strategic support to the Committee including, but not limited to: 

  • Ensuring the meeting agenda is approved by the Chair.

  • Ensuring the agenda and supporting papers are circulated at least one week before meeting.  

  • Ensuring meeting minutes are prepared and distributed to the Chair and members for review at the conclusion of each Committee meeting.

  • Ensuring appropriate records regarding Committee activities and decisions are maintained.

  • Following up on actions agreed during the meeting. 

DISCLOSURE AND USE OF INFORMATION

Committee members must not use or disclose information obtained by the Committee except in meeting the Committee’s responsibilities, or unless expressly agreed by the CEO. 

REVIEW ARRANGEMENTS

PERFORMANCE REVIEW

The Chair, in consultation with the CEO, will initiate a review of the performance of the Committee biennially against its charter and work plan. The review will be conducted on a self-assessment basis (unless otherwise determined by the CEO) with appropriate input sought from the CEO, Committee members, the COO, and any other relevant stakeholders, as determined by the CEO. 

CHARTER REVIEW

The Committee will review the appropriateness of this charter annually and recommend any substantive changes for consideration by the CEO. 

APPROVAL 

The Audit and Risk Committee charter was approved by the CEO on 27 July 2026.