Navigating the Audit Committee: Strengthening Internal Controls in the GCC

Business professionals engaged in discussion and reviewing documents - Navigating the Audit Committee_ Strengthening Internal Controls in the GCC

Introduction

When a GCC company’s internal controls fail, the audit committee is usually the first body asked why it did not see the problem coming. The honest answer, more often than not, is that the committee was never built to see it. The board audit committee sits at the intersection of financial integrity, regulatory accountability, and board-level risk oversight. Get the composition wrong, resource it poorly, or reduce its mandate to a procedural checklist, and you have not created governance protection; you have created the appearance of it. That distinction now carries real regulatory consequences.

Under Saudi Arabia’s Capital Market Authority Corporate Governance Regulations, as amended effective January 2024, listed companies face explicit new requirements: the audit committee must recommend the appointment and dismissal of internal auditors (Article 24(4)), oversee internal audit resources (Article 52(b)(3)), mandate training for board and executive members (Article 37), and hold periodic meetings with auditors as a standalone accountability layer (Article 54(b)). These are not aspirational guidelines. They are enforcement-grade provisions. The OECD Corporate Governance Factbook 2025 confirmed these changes are in force, and noted that the CMA’s 2024-2026 strategic plan includes a dedicated initiative to further develop the Corporate Governance Regulations – meaning the trajectory is toward more accountability, not less.

What the Regulatory Frameworks Require Across the GCC

Financial oversight GCC requirements differ by jurisdiction, but the direction is consistent across all three major markets. In the UAE, Federal Decree-Law No. 32 of 2021 requires public joint-stock companies and larger private companies to establish audit committees. Executive directors and company management are explicitly prohibited from serving on the committee. The UAE Ministry of Finance’s Ministerial Decision No. 84 of 2025 extended mandatory audited financial statements to companies exceeding AED 50 million in revenue for Corporate Tax purposes – pulling a wider set of businesses into formal audit discipline. The Central Bank of the UAE mandates external auditor rotation at the firm level every six years, and lead partner rotation every three years – obligations the audit committee is responsible for tracking.

In Bahrain, the Corporate Governance Code (Decree No. 91 of 2022) requires all joint-stock companies to establish an audit committee of at least three members, chaired by an independent board member. A majority of members must possess the financial literacy qualifications defined in the Code’s Appendix B. External auditor terms are capped at five consecutive years. The Code also requires the audit committee to oversee the company’s whistleblower program – a compliance monitoring obligation that extends the committee’s reach into conduct risk, not just financial reporting.

In all three jurisdictions, the audit committee is expected to function as a genuine oversight body with independent authority. In many GCC boardrooms, that expectation and current practice have not yet converged. MEIoD’s blog on the corporate secretary’s evolving role in MENA covers a closely related governance function: the procedural backbone that ensures committee decisions, including the audit committee’s, are properly documented and reported to the full board.

The Competency Problem

Board financial literacy is the enabling condition for everything the audit committee is supposed to do. Without it, the committee receives management information it cannot interrogate and hears auditor reports it cannot evaluate. The governance protection exists on paper. It does not exist in the room. The GCC BDI and Heidrick & Struggles Board Effectiveness Review 2025 – drawing on 193 directors and executives across the region – found that directors identified finance as a growing expertise gap, cited by 17 percent of respondents, up sharply from just 6 percent in 2023. That near-tripling of concern in a two-year cycle suggests the gap is not resolving naturally as boards evolve.

The Institute of Internal Auditors released its 2024 Global Internal Audit Standards (GIAS), with mandatory implementation from January 9, 2025. The new framework consolidated multiple previous documents into 15 guiding principles and introduced Topical Requirements covering cybersecurity, IT governance, ESG, and third-party management. This matters directly to audit committees: the standard against which an internal audit function is now assessed has moved. A committee that was adequate for oversight for a 2017-standard function may not be adequate for one operating under GIAS 2024.

The financial literacy the audit committee needs in the current environment covers more than reading financial statements. It includes understanding the three-lines-of-defence model and where each line is accountable, the ability to evaluate whether an internal audit plan is genuinely risk-based rather than a repeat of prior-year coverage, and sufficient knowledge of the external audit process to ask whether significant disagreements with management are being surfaced or quietly managed down.

MEIoD’s Corporate Directors Program – CDP Part III covers these competencies directly. The audit responsibilities, internal control, and risk management modules are built specifically for directors who sit on or chair audit committees – not general director education, but the technical depth the role now demands. The September 2026 cohort opens on 13 September.

Internal Audit Independence – Where Most GCC Committees Fall Short

Internal audit standards have a structural problem across the GCC: the requirement to have a function exists, but the requirement to have it function independently is harder to enforce. In practice, the internal audit function in many companies reports to the CFO or CEO, and this reporting line shapes everything about what the function finds. The IIA’s GIAS 2024 addressed this directly. Standard 7.1 requires the Chief Audit Executive to report to a board-level authority, not to management. This is not a preference. It is the standard against which the function’s independence is now assessed. Saudi Arabia’s January 2024 CMA amendments reinforced this at the regulatory level: the audit committee now carries explicit responsibility for recommending the appointment and dismissal of internal auditors – removing that authority from management and placing it where independence requires it to sit. The diagnostic questions any audit committee should be able to answer include:

  • Does the Chief Audit Executive have direct, private access to the audit committee chair without management present?
  • Is the internal audit plan built from a formal risk assessment, or from last year’s plan with minor modifications?
  • Has the function received an external quality assessment in the last five years, as required under IIA standards?

 

Most GCC audit committees do not have clean answers to all three. That gap is where control failures originate, not in the financial statements, but in the oversight architecture that should have caught the problem before it got there. For a structured assessment of where these gaps exist in your board’s governance architecture, MEIoD’s CG Assessment reviews internal audit independence, committee effectiveness, and financial oversight mechanisms against current GCC regulatory standards.

Risk Frameworks and What the Committee Is Actually Responsible For

Risk frameworks are where audit committee responsibility and enterprise risk management intersect and where the boundary between the committee’s role and management’s is most frequently blurred. The audit committee does not manage risk. It oversees whether management is managing it adequately, and whether the internal audit is providing genuine independent assurance on that claim.

The GCC BDI Board Effectiveness Review 2025 found that only 15 percent of GCC boards have a formal framework for geopolitical risk oversight, and that 63 percent lack a defined AI strategy. Both carry direct audit committee implications: geopolitical exposure affects going-concern assumptions and contingent liability disclosures; AI adoption creates data governance and model risks that the internal audit function should be assessing. If it is not, the committee should be asking why. MEIoD’s article on board governance planning for the second half of 2026 addresses both of these gaps as part of a broader six-priority planning framework relevant to every board committee. 

The CMA regulations require the audit committee to review policies on related-party transactions, anti-bribery and corruption, and whistleblowing, with the audit committee chair required to update the full board on material cases. These are not administrative tasks. They are the mechanisms through which boards exercise real conduct oversight. A committee that processes these as paperwork rather than accountability moments has misread its own mandate. MEIoD’s webinar on the Nomination & Remuneration Committee and the broader question of how committees and boards interact provides useful context for where the audit committee’s mandate sits relative to the board’s other standing committees. 

Strengthen Your Board with MEIoD

An effective audit committee is one of the most consequential governance assets a GCC board can build. MEIoD works with boards and directors across the region to develop the structures and competencies that genuine financial oversight requires.

  • Corporate Directors Program – CDP Part III – audit responsibilities, internal control, and risk management modules built for directors serving on audit committees, offered in association with the IFC and leading to Qualified Director Status. July 2026 cohort: 12 July. September 2026 cohort: 13 September
  • CG Assessment – structured review of governance practices, including audit committee effectiveness and internal audit independence, benchmarked against current GCC regulatory requirements
  • Board Evaluations – independent assessment of whether the audit committee is receiving the quality of information and exercising the level of scrutiny its mandate requires
  • ESG in the Boardroom – as non-financial reporting obligations expand, audit committee members need to understand how ESG disclosures should be governed and assured

 

Not sure if your audit committee is positioned to meet these obligations? Start with MEIoD’s CG Quiz for a quick self-assessment. The audit committee is not a compliance checkbox. It is the board’s mechanism for knowing what is actually happening inside the organisation. Contact MEIoD to assess whether yours is built for that purpose.

FAQ

What are the audit committee composition requirements for listed companies in Saudi Arabia?

Under the CMA Corporate Governance Regulations (effective January 2024), listed companies must establish an audit committee of at least three members, a majority independent, with at least one member holding financial or accounting expertise. The 2024 amendments gave the committee explicit authority to recommend appointment and dismissal of internal auditors and mandated periodic private meetings between the committee and the auditors.

The IIA’s 2024 GIAS, mandatory from January 9, 2025, consolidated previous frameworks into 15 guiding principles and added Topical Requirements covering cybersecurity, ESG, and third-party management. For audit committees, it raised the standard against which internal audit functions are assessed – and placed the Chief Audit Executive’s reporting line to the board, not management, as a non-negotiable independence requirement.

MEIoD’s Corporate Directors Program covers audit responsibilities, internal control, and risk management as dedicated modules in Part III. It is designed for directors serving on or chairing audit committees – building the financial literacy to evaluate internal audit plans, challenge external auditors, and assess whether the committee’s oversight mandate is being fulfilled. Offered in association with the IFC, it leads to Qualified Director Status.

Under Bahrain’s Corporate Governance Code (amended by Decree No. 91 of 2022), the audit committee must oversee the company’s whistleblower program and receive reports on financial or legal improprieties raised through it. The chair must be an independent board member, and a majority of members must meet the financial literacy qualifications in the Code’s Appendix B. External auditor terms are capped at five consecutive years, with the committee responsible for managing rotation.

Share:

Recent posts

SignUp for Newsletter

About MEIoD

Raising the standard of corporate governance in the middle east. We believe that entrepreneurs, business owners, executives, and investors alike benefit significantly from the implementation of effective corporate governance within companies of all sizes across the region.

© 2026 MEIoD. All rights reserved | Powered By Epirco.

Assess Your Governance Readiness

Main valuable insights into your governance strengths and gaps. Start with our quick tools designed to help leaders, businesses, and investors assess their governance maturity.