Submit your papersSubmit Now
For Enquiries: [email protected]
IIARD LogoIIARD

The Role of Audit Committee in Cyber Risk Governance and Accountability: A Literature Review Perspective

Okor Eno Eyo

Abstract

The study examined the role of audit committee in cyber risk governance and accountability. The audit committee can contribute by reviewing cyber risk assessments, monitoring the effectiveness of internal controls, questioning management on cybersecurity preparedness and ensuring that significant cyber risks are appropriately communicated to the board and relevant stakeholders. Cyber risk governance is particularly important because weak oversight can create gaps between an organisation's cybersecurity policies and their actual implementation. The study recommended that organisations should strengthen the independence of audit committee members by ensuring that the committee is composed predominantly of members who can exercise objective judgement without undue influence from management. Also, organisations should ensure that audit committees possess adequate cybersecurity, information technology, accounting, auditing and risk-management expertise.

Keywords

Audit committeecyber risk governanceaccountabilitycyber risk assessmentsinternal controls

References

Bhattacharjee, S., et al. (2024). Inexpert supervision: Field evidence on boards’ oversight of cybersecurity. Management Science. Dziwa, A. A. (2023). Governance and board oversight do matter. ISACA Now. Gao, L., & Calderon, T. G. (2025). Cybersecurity risk governance and companies’ cybersecurity risk disclosures in their 10-K filings. Journal of Accounting and Public Policy, 54, 107376. Guohong, Z., Zhongwei, X., Feng, H., & Zhongyi, X. (2025). The audit committee’s IT expertise and its impact on the disclosure of cybersecurity risk. Research in International Business and Finance, 73, 102542. https://doi.org/10.1016/j.ribaf.2024.102542 Institute of Internal Auditors. (2020). Assessing cybersecurity risk: The three lines model. The Institute of Internal Auditors. Institute of Internal Auditors. (2024). Auditing cyber incident response and recovery. The Institute of Internal Auditors. Institute of Internal Auditors. (2025). Auditing cybersecurity operations: Prevention and detection (2nd ed.). The Institute of Internal Auditors. Jensen, M. C., & Meckling, W. H. (1976). Theory of the firm: Managerial behaviour, agency costs and ownership structure. Journal of Financial Economics, 3(4), 305–360. Lanz, J. (2023). The audit committee's oversight for cybersecurity. The CPA Journal. Ojeka, S. A., Ben-Caleb, E., & Ekpe, E.-O. I. (2017). Cyber security in the Nigerian banking sector: An appraisal of audit committee effectiveness. International Review of Management and Marketing, 7(2), 340–346. Pascoe, C., Quinn, S., & Scarfone, K. (2024). The NIST cybersecurity framework 2.0 (NIST Cybersecurity White Paper 29). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.CSWP.29 Pascoe, C., Quinn, S., & Scarfone, K. (2024). The NIST Cybersecurity Framework 2.0 (NIST Cybersecurity White Paper 29). National Institute of Standards and Technology. Pfeffer, J., & Salancik, G. R. (1978). The external control of organizations: A resource dependence perspective. Harper & Row. Quinn, S., Pascoe, C., Barrett, M., Scarfone, K., & Witte, G. (2024). NIST Cybersecurity Framework 2.0: Quick-start guide for using the CSF tiers (NIST Special Publication 1302). National Institute of Standards and Technology. Smith, J. L., et al. (2021). Cybersecurity breaches and the role of information technology governance in audit committee charters. Journal of Information Systems, 35(1), 101–119. World Economic Forum. (2024). Global cybersecurity outlook 2024. World Economic Forum.

More Articles from JOURNAL OF ACCOUNTING AND FINANCIAL MANAGEMENT