12 Audit Committee Questions Every Growth-Stage SME Should Be Ready to Answer
If your board or investors asked these questions tomorrow, would your evidence stand up? A practical guide to the questions that matter most.
Audit committees exist to provide independent oversight of financial reporting, internal controls and the external audit process. In listed companies, this function is well established. In growth-stage and PE-backed SMEs, the equivalent — whether a formal committee, a board subgroup or engaged investor representatives — can feel less structured, but the underlying questions are the same.
What changes is whether management is ready to answer them.
These are the twelve questions that come up most frequently in audit committee and board review settings — and that separate businesses with mature finance governance from those operating on assumption and goodwill.
1. "How do you know the financial statements give a true and fair view?"
This is the foundational question, and it is not answered by saying the auditors have signed them off. The committee wants to understand what management has done to satisfy itself — the controls that operate during the period, the review and challenge process, the areas of judgement and how they were resolved.
Be ready to walk through the control framework in outline: what prevents material misstatement, who reviews what and at what level of authority, and where the significant judgements sit.
2. "What are the most significant accounting judgements this year, and how were they made?"
Every set of financial statements contains areas where reasonable people could reach different conclusions. Revenue recognition on long-term contracts, impairment of goodwill, provisions for uncertain liabilities — these are areas where the process matters as much as the conclusion.
The committee wants to know: who made these calls, on what basis, who challenged them and what the range of outcomes looks like. A paper trail showing that judgements were deliberate, reviewed and documented is what good governance looks like in practice.
3. "Are there any areas where you and the auditors see things differently?"
This question is about candour. Audit committees want to know about disagreements, even resolved ones — because disagreements reveal where the genuine uncertainty sits.
If the answer is always "no", that can itself be a signal. Be ready to name the areas of discussion, explain how they were resolved and confirm whether the outcome was a judgement call by management or an agreed position.
4. "How effective is the external audit process?"
The committee is the primary point of contact for the external auditor and is responsible for assessing audit quality and effectiveness. They will want management's view.
This includes: whether the audit was conducted to the agreed timetable, the quality of the audit team, how well the auditors understood the business, whether findings were constructive, and whether the management letter contained anything unexpected.
5. "What did the prior year audit findings tell us, and what have we done about them?"
Any audit findings or management letter points from the prior year are tracked by the committee. They will want a clear account of each finding, the agreed action, who owned it and whether it has been implemented.
Coming to this meeting without a complete update on prior year findings is one of the most common — and most avoidable — governance failures.
6. "How confident are you in the going concern assessment?"
For growth-stage businesses, this is rarely a formality. The committee will want to understand the assumptions behind the going concern assessment, the time horizon covered, what scenarios were stress-tested and what would need to change for the conclusion to be different.
If there are debt covenants, investor commitments or working capital constraints, they will want comfort that these have been factored in and that the assessment is current.
7. "Do we have adequate financial controls, and how do we know?"
This question tests whether controls are documented, tested and owned — not just assumed to exist.
The strongest answer includes a summary of the key control areas, the frequency and method of testing, who is responsible for each control, and any gaps that have been identified and are being addressed. A control framework that lives only in the Finance Director's head is not a control framework for these purposes.
8. "Who has access to what in our financial systems, and is that appropriate?"
User access and segregation of duties in financial systems are among the most common sources of ITGC findings in SME audits. The committee may not ask this in technical terms, but the underlying concern is whether appropriate controls exist over who can initiate, approve and record financial transactions.
Be ready with a high-level summary of the access review process, how often it is performed, what happens when someone leaves and whether any segregation of duty conflicts exist and how they are compensated for.
9. "Are there any areas of regulatory or legal exposure we should know about?"
The committee has oversight of compliance as well as financial reporting. Any pending legal claims, regulatory investigations, tax disputes or compliance gaps should be on the table, with an honest assessment of the financial and reputational exposure.
This is not the place for optimistic summaries. The committee's role is to be informed, and they would rather hear difficult news from management than from auditors or regulators.
10. "How are related party transactions identified and controlled?"
Related party transactions — with investors, directors, connected entities or key management — require particular care in financial reporting and governance. The committee will want to know what the identification process looks like, who reviews and approves related party transactions, and whether disclosures in the financial statements are complete.
This question catches organisations that handle related party matters informally, particularly where PE investors or founders are involved in multiple related entities.
11. "What is management's assessment of fraud risk, and what controls address it?"
Audit committees are required to consider fraud risk as part of their oversight responsibilities, and auditors are required to assess it. Management's own view matters — it signals whether the organisation takes fraud risk seriously or treats it as a theoretical exercise.
A credible answer covers the main fraud scenarios relevant to the business (not generic ones), the controls that mitigate each, any incidents or near-misses in the period, and how the whistleblowing mechanism is operating.
12. "Are there any matters you would like to raise that are not on the agenda?"
This is the question that catches unprepared finance teams most off guard — because it is open-ended by design. The committee is offering an opportunity to surface anything that has not been formally tabled.
Good answers are not always comfortable ones. If there is a control weakness being worked through, a system issue that has caused reconciliation problems or a staffing gap in the finance team, this is the moment to raise it. Committees trust management teams that are forthcoming. They lose confidence in those who wait to be found out.
Being Ready Is Not the Same as Being Perfect
None of these questions require a perfect answer. Audit committees and engaged investors understand that SMEs operate with resource constraints and that governance matures over time.
What they are assessing is whether management understands its own environment, takes governance seriously and is operating with transparency. A finance team that can answer these twelve questions honestly, with evidence, earns credibility — even where gaps exist.
If answering these questions would require significant preparation work, that preparation is worth doing before the meeting rather than during it.
