Cybersecurity remains the top priority for audit committees at public companies, outside of financial reporting and internal controls, according to survey findings released in the ‘Audit Committee Practices Report: Common Threads Across Audit Committees’. This is a joint publication developed by Deloitte’s Center for Board Effectiveness and the Center for Audit Quality (CAQ).
On a broader scale, enterprise risk management is ranked as the second highest priority for audit committees. Finance and internal talent remain the third-highest priority.
The report also shows how artificial intelligence governance is growing in importance as an audit committee consideration, reflective of the rapid adoption of transformative digital technologies that have ushered in a new era of business risk.
A total of 237 respondents participated in the survey, primarily on boards of US (89%) public (86%) companies with $2 billion or more in market cap (72%). Directors on boards of financial services companies made up 27% of the respondents.
The survey found that 93% of respondents ranked cybersecurity as one of their top three priorities, with 50% ranking it as the leading priority for the audit committee. Further, 71% report cybersecurity is on their agenda on a quarterly basis. Cybersecurity has consistently been ranked as the top priority of audit committees in each of the four years the survey has been conducted, a clear indication that complex and evolving risk will continue to be a focus for audit committees in years to come.
Enhanced focus on AI governance
The survey found an increased emphasis on understanding the impact and usage of AI technologies throughout the organization by the C-suite and board. The number of respondents who identified AI governance as a priority grew year over year, jumping to 35% from 20% last year. A growing portion of audit committees are taking on primary oversight of AI governance (up to 20% from 14% last year). Still, oversight mostly falls with the full board (58%).
Additionally, survey results suggest that work has been done to develop governance structures for AI oversight, with fewer respondents (6%) acknowledging they ‘don’t know’ where AI oversight falls within their organization this year versus last year (17%). Amid ongoing conversations around how organizations govern AI, the question of who should be responsible for primary oversight continues to evolve.






