Guidance

Audit and Risk Assurance Committee Handbook

The Audit and Risk Assurance Committee handbook reflects developing best practice in governance.

Documents

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email digital.communications@hmtreasury.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Request an accessible format.
If you use assistive technology (such as a screen reader) and need a version of this document in a more accessible format, please email digital.communications@hmtreasury.gov.uk. Please tell us what format you need. It will help us if you say what assistive technology you use.

Details

This Audit and Risk Assurance Committee (ARAC) handbook covers the roles and responsibilities of an聽ARAC聽and provides guidance on good governance processes for ARACs.

Whilst it is not intended to provide guidance on areas that an聽ARAC聽may need to review, Annex F 鈥橩ey questions for an聽ARAC聽to ask鈥 does provide prompts of what ARACs should consider on a range of topics, including whistleblowing and cyber security. This Annex is not meant to be an exhaustive (or restrictive) list of questions relating to a particular topic.

The Handbook has been updated to include changes resulting from the introduction of the Global Internal Audit Standards.聽This has resulted in the introduction of a new Annex H 鈥楪overning the Internal Audit Function鈥, which outlines the key requirements contained in the Global Internal Audit standards, for ARACs. Consequently, the checklist which an聽ARAC聽could use to review its effectiveness is now at Annex I.

To help with an effectiveness review and take account of each member鈥檚 views, the questions from Annex I have been transferred to a spreadsheet (Audit and Risk Assurance Committee self-assessment tool) allowing all聽ARAC聽members (and the views of others) to be collated and analysed. This tool is a modified version of the National Audit Office鈥檚 Outcome Analyser and includes changes resulting from the introduction of the Global Internal Audit Standards. As an alternative, ARACs can consider using the , which incorporates leading practice alongside the essentials set out in the ARAC Handbook. This may be particularly appropriate for ARACs of large or complex organisations.

Updates to this page

Published 29 May 2013
Last updated 9 April 2025 show all updates
  1. ARAC handbook and GIAA Audit and Risk Assurance Committee Self-Assessment Tool updated.

  2. Updates made to body copy about the Audit and Risk Assurance Committee self-assessment tool.

  3. The Handbook has been fully refreshed to improve clarity and reflect changes in best practice in governance. The annexes on whistleblowing and cyber security have been removed, and some questions on these topics are now incorporated into Annex F 鈥楰ey questions for an ARAC to ask鈥. A checklist for ARACs to use to review their effectiveness has been added at Annex H. To help with this review and take account of each member鈥檚 views, the questions from Annex H have been transferred to a spreadsheet allowing all ARAC members (and the views of others) to be collated and analysed.

  4. Added Audit and Risk Assurance Committee Handbook Annex J Cyber Security

  5. new, updated PDF

  6. First published.

Sign up for emails or print this page