Audit Committee Scrutiny in 2026: The Controls Artifacts CFOs Should Bring
PwC's 2025 director survey records the highest replacement sentiment in its history. KPMG's 2025 agenda puts AI oversight, cyber, and the DOJ's revised compliance framework on the audit committee's docket. CFOs are being asked for exhibits, not assurances.
In brief: PwC's 2025 Annual Corporate Directors Survey finds 55% of directors say at least one of their colleagues should be replaced, the highest level in the survey's history. KPMG's 2025 Audit Committee Agenda expands the docket to AI oversight, cyber risk, and the DOJ's September Evaluation of Corporate Compliance.
What changed on the audit committee
The audit committee that signed off two years ago is not the audit committee you will brief in 2026. The shift is not only about workload, although the workload has grown. It is about willingness to act. PwC's 2025 Annual Corporate Directors Survey records the sharpest reading on director performance to date.
"Over half (55%) of directors reported that at least one of their colleagues should be replaced — the highest level in the survey's history." PwC, 2025 Annual Corporate Directors Survey
A board willing to replace its own members is a board that will ask sharper questions of management. That pressure lands first on the audit committee, which sits at the intersection of financial reporting, risk oversight, and, increasingly, technology and compliance. The CFO reports directly into that committee and carries the burden of proof that controls are operating.
The committee's remit has also widened. KPMG's 2025 Audit Committee Agenda pushes committees well past the traditional financial reporting checklist. It names AI governance, cybersecurity disclosure, climate, and compliance program effectiveness as issues committees must engage with in 2025 and 2026. One line from that agenda cuts closest to the CFO:
"Probe whether management has reassessed the company's compliance and whistle-blower programs in light of the DOJ's September Evaluation of Corporate Compliance Programs guidance." KPMG, On the 2025 Audit Committee Agenda
That sentence changes the meeting. A prosecutor's evaluation framework is now a boardroom checklist. The committee will not accept "we are on track" as an answer. It will ask for exhibits.
The stakes on the CFO's side of the table
Audit committee scrutiny is not abstract. It translates into concrete consequences for the CFO: more frequent executive sessions without management present, sharper follow-ups on prior-period commitments, and tighter linkage between committee feedback and compensation committee decisions. The PwC 2025 signal is cultural: boards that will act on peer-director underperformance tend to ask sharper, more documentary questions of management across the table.
The second-order effects matter too. Audit committees that find themselves short of evidence on compliance effectiveness bring in external advisors, expand the scope of internal audit, and request more frequent interim briefings. Each of those consumes CFO time and finance-team capacity. Committees with a clear exhibits cadence from management typically have less need to commission external reviews on the same question.
Exhibits, not assurances
The practical translation of the KPMG agenda is a shift from verbal assurance to documentary evidence. An audit committee working through the DOJ's Evaluation of Corporate Compliance Programs will ask specific, exhibit-driven questions: who approved this policy and when, who reviewed and who actually signed off, where the version history lives, how terminology is governed across the systems management uses to communicate with auditors, regulators, and investors.
A clean audit committee record — a meeting where each question has a concrete exhibit attached — supports investor confidence on the other side. Proxy advisors, activist investors, and ratings agencies read committee disclosures and governance reports as proxies for controls maturity. The revenue effect here is indirect but real: fewer investor concerns on governance reduce the friction around capital raises, convertible issuances, and large private placements where governance due diligence is part of the diligence workstream.
How terminology governance addresses this
Compliance Glossary is not a substitute for a compliance program, an internal audit function, or an ICFR framework. It provides a narrow but visible artifact: controlled terminology, approved by named people, versioned, timestamped, and exportable. For audit committees that ask to see how management governs the definitional record behind its policies and disclosures, it is a concrete exhibit.
- Four-eyes approval. Every term requires a reviewer and a separate approver, recorded by Atlassian account ID — the kind of dual-control evidence the DOJ's Evaluation of Corporate Compliance Programs asks questions about under "Policies and Procedures" and "Autonomy and Resources."
- Version history. Every change to a regulatory or financial term is retained with the prior version, supporting the committee's ability to inspect drift over time.
- Audit trail with timestamps. Who, what, when, and why is recorded before the entity change, following ALCOA+ Contemporaneous and Attributable principles.
- Compliance scanner. Reports where deprecated or unapproved terms appear across Confluence spaces, giving the committee a coverage metric rather than a narrative.
- CSV export with full version history (PDF audit-package export on the 2026 roadmap). Committee materials can include a complete CSV snapshot of the approved glossary on the meeting date.
For current pricing, see the Atlassian Marketplace.
Frequently asked questions
What does the PwC 2025 director survey actually say?
PwC's 2025 Annual Corporate Directors Survey reports that 55% of directors said at least one of their colleagues should be replaced, the highest level in the survey's history. The finding signals an audit committee culture that is more willing to act on underperformance and asks sharper questions of management, including the CFO, on controls evidence.
Why does the DOJ's Evaluation of Corporate Compliance matter to an audit committee?
KPMG's 2025 Audit Committee Agenda asks committees to probe whether management has reassessed the company's compliance and whistle-blower programs in light of the DOJ's September Evaluation of Corporate Compliance Programs guidance. That turns a prosecutor's framework into a boardroom checklist. The CFO is expected to produce tangible evidence of controls maturity, not assurances.
Is an auditable glossary a substitute for ICFR or a compliance program?
No. An auditable glossary is a supporting artifact. It does not replace internal control over financial reporting, a compliance program, or the DOJ-style effectiveness review. It provides one concrete, time-stamped exhibit that the CFO can cite when the audit committee asks how terminology and definitional consistency are governed across Confluence.
How do we show an audit committee that controls are maturing?
Bring exhibits, not assurances. Four-eyes approval logs, version history on regulatory definitions, a timestamped audit trail, CSV exports (with full version history) of approved terms, and a coverage report across spaces. PDF audit-package export is on the 2026 roadmap. An auditable glossary produces all five in a format an external auditor can inspect and test, which is the format audit committees increasingly ask for.
Give the audit committee an exhibit, not a summary
For current pricing, see the Atlassian Marketplace.
Evaluate in Confluence Read the Security WhitepaperRelated reading
- Compliance for Confluence — approved terms, page scanning, and audit evidence for CFO-owned controls and disclosures in Confluence
- SOX 302 in the AI Era — what "reasonable care" looks like when the 10-K talks about AI
- Material Weakness and CFO Departure — Notre Dame data on failed remediation and C-suite turnover
- M&A VDR Readiness — how a controlled glossary survives buy-side diligence
- Board regulatory disclosure: CEO credibility test
- Compliance Guide — frameworks covered (SOX, DORA, NIS2, FDA, ISO)
- Security Whitepaper — vendor assessment detail for procurement