Review Of The Audit And Risk Committee Charter & Review Of The Internal Audit Policy
See the votes on this matter →
What was decided?
The minuted decision sequence
No separately labelled carried Council Resolution has been identified here. Read each formal event and the complete item minutes; a lost motion is not necessarily the final outcome.
1Committee RecommendationCarried
Moved: Frank Wilkie · Seconded: Nicola Wilson
That Council
A. Note the report by the Executive Officer to the Services & Organisation Committee meeting dated 9 September 2025 regarding the Audit and Risk Committee Charter and Internal Audit Policy;
B. Adopt the
1. Audit and Risk Committee Charter provided as Attachment 1; and
2. Internal Audit Policy provided as Attachment 2.
Carried.
For 4 named
Jessica Phillips
Karen Finzel
Nicola Wilson
Frank WilkieAgainst 0 named
Official minutes · section 1
Read complete item-specific minutes
| Committee Recommendation |
| Moved: | Cr Frank Wilkie |
| Seconded: | Cr Nicola Wilson |
That Council
|
Carried. |
| For: | Cr Karen Finzel, Cr Jessica Phillips, Cr Nicola Wilson, Cr Frank Wilkie |
| Against: | None |
This summary follows this item’s minutes. The established voting totals use their existing method while differences are checked against the full records.
What was said?
Named discussion on NoosaWatch TV
These actual transcript passages match the item’s wording. The start and end of the item’s discussion are not yet confirmed; these excerpts are not measured item airtime or exact decision moments.
Karen Finzel61:52Thank you. Any further comments? Then we'll take it to the vote. All in favour? That's unanimous. Thank you. Very much. Keep up the good work. Looking forward to seeing it in action. Thank you. Just to note that Councillor Phillips has to, she's got responsibilities with family, which family comes first, and she's leaving the meeting table, but we'll jump online and continue with the meeting process. Having said that, we're moving into item 7.4 and we welcome to the table staff member Jonci Wolff to review the Audit and Risk Committee Charter and review of the Internal Audit Policy. Thank you Jonci. And welcome, good afternoon.
Thank you, good afternoon. Okay, I'll provide you're done with a high-level overview of this item. So this report seeks Council's adoption of two revised documents. One is the Audit and Risk Committee Charter and the other one is the Internal Audit Policy. These documents set out the framework how the Audit and Risk Committee operates and how Council undertakes internal auditing. Both documents are subject to routine annual review and so there are minor improvements to wording and structure in both documents. However, further improvements have been made and they stem from an internal audit and the advice from the Queensland Audit Office. Regarding the Audit and Risk Committee Charter, these changes include increasing the term of independent committee members from two to three years which is considered better practice so previously it was three by two years and now it's two by three years the final tenure is still six years in both scenarios. Then amending the meeting forum from three to two which was inaccurate in the charter before this is half the committee members in our case the Audit and Risk Committee has four members so it's two and in response to advice from the Queensland Audit Office the responsibilities of the committee have also been expanded for the review and oversight of corporate culture performance management and reporting the security systems and information significant projects and outsourcing and business continuity planning further to that the wording was strengthened for sections dealing with confidentiality conflict of interest further and internal controls and finally the definitions were also expanded they are at the latter part of the charter to assist the reader and the better understanding of the charter those are the more significant changes to the charter and then the internal audit policy has seen a few changes as well however the main body of the policy has not changed what has changed are the terms of reference to provide some further clarification. These relate to the internal audit methodology it's highlighting the methodologies to be applied in the audit process the internal auditing process to improve how audit are structured and actioned just to standardise the process that any report from internal auditors follows the same standard and makes it very clear to staff to understand also the responsibilities were clarified to clarify the responsibilities of CEO, Audit and Risk Committee and Council at large, the operational teams very importantly the management actions to clarify the responsibilities for the implementation of internal audit recommendations. Because if those are not implemented, then that defies the purpose of an internal audit in the first place. The final section that was amended is the evaluation of the internal audit performance to monitor internal audit performance and client satisfaction so that we also seek feedback from the audited areas of the performance of the internal auditors to ensure that we actually have received a good service. That concludes some pretty much the major changes of these two documents and available for questions if there are any.
It is first of all with the Audit and Risk Committee Charter that it clarifies the roles and responsibilities and also provides further oversight for which areas the Audit and Risk Committee has oversight. There is an expansion of that, as I said. Corporate culture, performance management and significant project business continuity planning, so they'll be added. And then obviously then in terms of the Internal Audit Policy, these are exactly the changes that were made. How first of all, changes to how we conduct the internal auditing, it provides advice on the methodology, so we make sure that we that auditing is conducted the way to standard. Then, how it's reported on, that's the changes as well. And, also how the actions are implemented. So this provides them more clarity. Yeah, provides more clarity. And the internal audit plan is, or the oversight for that lies with the Audit and Risk Committee. And they will then take the Internal Audit Policy, apply that and enact it. So that's how the risk is managed in terms of identifying high risk areas, developing an internal audit plan, ensuring that audits are conducted, and then that any recommendations stemming from those audits are implemented. And that goes further with Audit and Risk Committee also then reviews the. Strategic risk register, for example, and the strategic risk register informs the internal audit plan as well.
Frank Wilkie69:16Strategic risk register, for example, and the informs the internal audit plan as well. And the CEO sits on the Audit and Risk Committee, so. That's correct. Sets the link to the organisation. Absolutely, yep.
Frank Wilkie66:56Yes? Thank you Madam Chair. It's great to have the policy and the charter and the improvements. I guess the purpose of having an Audit and Risk Committee is to ensure that risk is managed within the organisation. How are these changes, what are the principal changes will improve the way we manage risk? How will it improve the way we manage our risk? To help ensure that the recommendations that come from the Audit and Risk Committee are acted upon.
1 suggested discussion start time
- 3746.0 seconds on the council source timeline · Recording time not yet verified. The end of the discussion is not yet confirmed.