Audit Committees represent the executive arm of the Board of Directors, overseeing the effectiveness of internal controls, the integrity of financial statements, and the performance of internal and external audit functions. Traditionally, this work has focused on reviewing past accounting events and verifying strict regulatory compliance. However, in an environment characterized by the accelerated adoption of disruptive technologies, the oversight of corporate governance needs to evolve substantially. Artificial intelligence, robotic process automation, and cloud computing have redefined business operations, transforming digitalization into an engine of competitiveness and, simultaneously, a constant source of complex risks.
There is an inherent paradox in digital transformation: while technology promises unprecedented levels of operational efficiency, agility, and cost optimization, it simultaneously opens a window to new and rapidly evolving risks. What was once considered a secure system may now be vulnerable to sophisticated cybersecurity threats, data integrity breaches, or disruptions in the digital supply chain. It is crucial to clarify that the Audit Committee does not approve technology investments—that responsibility lies with management and the Board of Directors—its true role and challenge is to ensure that the controls implemented by management over new technologies provide reasonable assurances to mitigate the company’s risks.
Therefore, the Audit Committee’s role in the face of digital acceleration materializes in three main supervisory actions:
- Governance, Culture, and Digital Ethics: Ensure that management promotes clear policies on governance and the responsible use of technology and artificial intelligence. It is essential to monitor whether the responsible departments establish a “leadership tone” where the use of digital tools remains strictly aligned with the organization’s values and code of ethics.
- Dynamic Inventory of Technological Risks: Identify and verify that the Chief Information Security Officer (CISO) maintains an up-to-date and dynamic inventory of risks associated with the implementation of new technologies, ensuring that emerging threats are assessed in relation to the company’s risk appetite.
- Robust Controls and Operational Resilience: verify the existence of robust internal controls, designed to mitigate potential breaches of technological infrastructure and data integrity, preventing cyber events or system failures from negatively impacting the company’s operations and financial stability.
In overseeing financial information, this sensitivity implies understanding the governance of algorithms and artificial intelligence involved in generating accounting estimates and reports. Management retains the responsibility to prepare reasonable financial statements, but the committee must ensure that automated models are impartial, traceable, and properly validated. Simultaneously, internal audit must modernize, adopting continuous monitoring systems that allow for the timely detection of deviations, while maintaining its independence and objectivity at all times.
In this supervisory context, external auditing positions itself as an indispensable ally and a pillar of independent assurance for corporate governance. Thanks to the use of advanced analytics and artificial intelligence, external auditors can examine complete datasets instead of small samples, identifying anomalies or atypical transactions with high precision. Their objective assessment of information technology controls provides the Audit Committee with a rigorous diagnosis of the company’s digital maturity, validating whether the reported technological efficiency corresponds to a controlled operational reality.
To lead this expanded agenda, Audit Committees must review their own composition and incorporate specialized capabilities or consulting services in the area of technology risks. Digital transformation does not alter the fundamental purpose of corporate governance; on the contrary, it requires elevating oversight to a strategic level, where prudence, continuous risk assessment, and alignment with organizational ambitions ensure the long-term sustainability and resilience of the business.
By Héctor Gabriel Gavilanes Ibarra, Audit and Assurance Partner at Deloitte.