August 15, 2026
Internal Controls Presentation for Audit Committee
The audit committee's oversight of internal controls is one of its most critical governance responsibilities. For management and internal audit alike, presenting the state of internal controls to the audit committee requires communicating technical complexity clearly, distinguishing between design deficiencies and operating deficiencies, and giving the committee what it needs to fulfill its oversight role.
What the Audit Committee Needs to Know
Audit committees ask three fundamental questions about internal controls:
- Are our controls designed to catch the risks that matter?
- Are those controls actually operating as designed?
- If they are not, what is management doing about it?
Every internal controls presentation should be organized to answer these three questions in that order.
Framework: COSO and SOX Context
Most internal controls frameworks reference COSO (Committee of Sponsoring Organizations) — its five components provide the organizing structure for any controls assessment:
- Control Environment: The tone set by leadership; integrity, ethical values, competency, and accountability
- Risk Assessment: Management's process for identifying and evaluating risks
- Control Activities: The specific policies and procedures that mitigate identified risks
- Information and Communication: Systems and processes that support control execution
- Monitoring Activities: Ongoing assessment of whether controls are functioning
For public companies, management is required to assess and report on the effectiveness of internal controls over financial reporting (ICFR) under SOX Section 404. For private companies, the framework is the same but the reporting obligation differs.
Use COSO component headers to organize your presentation — audit committee members familiar with governance frameworks will immediately orient themselves.
Slide Structure
Slide 1: Engagement Overview
- Reporting period
- Scope of the internal controls assessment
- Framework used (COSO 2013)
- Assessment approach: management self-assessment, internal audit testing, or third-party review
- Summary conclusion: management's overall assessment of ICFR effectiveness
Slide 2: Executive Summary
For audit committee efficiency, lead with the conclusion:
- Overall ICFR conclusion: Effective / Effective with noted exceptions / Material weakness identified
- Number of significant deficiencies and material weaknesses, if any
- Key changes to the control environment during the period (new systems, new personnel, acquisitions)
- Status of prior period remediation actions
If there is a material weakness, state it clearly on the executive summary slide. Audit committee members need to know immediately if there is a problem that could affect the financial statements or external audit opinion.
Slide 3: Control Environment Assessment
Evaluate the five components of COSO for the control environment component:
- Management's tone and commitment to controls
- Organizational structure and accountability lines
- HR practices around background checks, training, and performance management
- Code of conduct and ethics program
- Whistleblower program and results
Rate each element (Effective / Needs Improvement / Deficient) and explain the basis for the rating. This component sets the foundation — an ineffective control environment undermines every specific control activity.
Slide 4: Risk Assessment Process
How does management identify and respond to risks?
- Is there a formal enterprise risk management process?
- How frequently is the risk register reviewed?
- Are emerging risks being captured (cybersecurity, regulatory, third-party)?
- How does the risk assessment drive the control design process?
Weakness in risk assessment is often a leading indicator of control gaps — risks that are not identified do not get controlled.
Slide 5: In-Scope Business Processes
List the processes in scope for the controls assessment, typically aligned to financial statement assertions and significant account balances:
| Process | Risk Area | Controls in Scope | Assessment Result | |---------|-----------|------------------|-------------------| | Revenue recognition | Completeness, accuracy | 12 controls | Effective | | Procure-to-pay | Completeness, accuracy, authorization | 18 controls | 1 deficiency | | Financial close and reporting | Accuracy, presentation | 9 controls | Effective | | IT general controls | All processes | 24 controls | 2 deficiencies |
This table provides the at-a-glance view of the assessment results by process.
Slide 6: IT General Controls
IT general controls (ITGCs) deserve a dedicated slide because they are foundational — weaknesses in ITGCs affect every automated control built on top of the underlying systems.
Cover:
- Access management (logical access controls, privileged user access, segregation of duties)
- Change management (change request procedures, testing requirements, approval controls)
- Computer operations (backup and recovery, job scheduling, batch processing controls)
- Third-party/vendor controls
ITGC deficiencies often produce cascading findings. If user access controls are inadequate, the risk is not just unauthorized access — it is that multiple downstream financial controls relying on automated system outputs may also be called into question.
Slide 7: Segregation of Duties Analysis
SOD conflicts are one of the most common internal control weaknesses. Show:
- Processes where SOD conflicts were identified
- Nature of each conflict (e.g., same individual can both create and approve vendor payments)
- Compensating controls in place
- Remediation status
For smaller organizations, some SOD conflicts are unavoidable due to headcount constraints. The key is ensuring compensating controls (management review, enhanced monitoring, periodic reconciliation) are in place and effective.
Slide 8: Significant Deficiencies and Material Weaknesses
This is the most important section of the presentation. For each significant deficiency or material weakness:
Finding: Precise description of the control gap.
Severity Classification: Material weakness = reasonable possibility that a material misstatement could occur and not be detected. Significant deficiency = less severe than material weakness but still merits attention. Deficiency = design or operating gap that is less than significant.
Financial Statement Impact: Which accounts or disclosures are affected? What is the magnitude of potential misstatement?
Root Cause: Not just the symptom but the underlying reason. Personnel gap? Process design failure? System limitation? Inadequate training?
Remediation Plan: Specific actions, owners, and dates. The audit committee will expect management to report back on remediation status each quarter until the finding is resolved.
Slide 9: Control Changes During the Period
Flag any significant changes that affected the control environment:
- New ERP system implementation or major upgrades
- Acquisitions and integration of acquired entities
- Significant management changes in finance or accounting
- New accounting standards implemented
- Business restructuring or restatement of prior periods
Changes increase risk. The audit committee needs to understand what changed and how controls were adapted to manage the change-related risks.
Slide 10: Internal Audit Coverage
Show the relationship between the internal audit plan and the control assessment:
- Which processes were internally audited during the period?
- What testing was performed to support the ICFR assessment?
- Where was management self-assessment used without internal audit validation?
External auditors rely on the work of internal audit — understanding the coverage and quality of IA testing helps the audit committee assess what they can rely on.
Slide 11: Prior Period Remediation Status
For every finding from the prior assessment, show current status:
| Finding | Prior Rating | Remediation Target | Current Status | Audited? | |---------|-------------|-------------------|----------------|----------| | | | | Closed / Open / In Progress | |
Findings that remain open beyond their target dates require explanation. Persistent open items suggest management commitment to remediation may be lacking.
Slide 12: External Auditor Coordination
Briefly note:
- Status of the external audit and PCAOB requirements (for public companies)
- Any matters raised by external auditors
- Reliance by external auditors on internal audit work
- Any disagreements between management and external auditors on accounting matters
The audit committee is the interface between the external auditors and management — this slide helps them fulfill that role.
Presenting to the Audit Committee
Come prepared to discuss rather than just present. Audit committee members at sophisticated organizations will have reviewed the materials before the meeting. Use meeting time for:
- Discussion of the two or three most significant findings in depth
- Management's commitment and capacity to remediate
- Questions about the completeness of the scope
- Discussion of any areas where management and auditors disagree
Bring the responsible management owner (CFO, Controller, or process owner) to the meeting for significant findings so the committee can hear directly from the person accountable for remediation.
An internal controls presentation that is honest about gaps, clear about severity, and specific about remediation gives the audit committee the information it needs to fulfill its oversight obligations — and builds the credibility of the management team's financial stewardship.
Build your next presentation with AI
Generate editable .pptx decks in minutes. Free to start — no card required.
Try it free →