Key Takeaways

  • Audit committees at the largest U.S. companies have expanded their oversight this decade beyond financial challenges to include cybersecurity, sustainability, and artificial intelligence-related risks, Ernst & Young said on Monday.
  • The share of S&P 500 companies that list sustainability as an audit committee responsibility surged to 22% this year from 6% in 2021, according to the EY survey.
  • "This trend is likely related to companies preparing to comply with various new global reporting standards, including the SEC's climate-related disclosure requirements," EY said in the report.

In-Depth Analysis

The U.S. Securities and Exchange Commission (SEC) this year weakened a requirement in a climate risk disclosure rule before facing legal challenges, then shelved the rule. Had the rule taken effect, companies would have been required to disclose the impact of climate change on their finances, operations, and business strategy.

Since President Joe Biden appointed Gary Gensler as SEC chair in 2021, the share of S&P 500 companies mentioning environment and climate in their audit committee descriptions has doubled to 14% this year from 7%, EY said.

EY noted that audit committees in many cases focus on the reliability of environmental, social, and governance (ESG) disclosures, including related controls and procedures, as well as sustainability-related risks.

Gensler, a leading advocate of the climate risk disclosure rule, has said that in recent years institutional and retail investors have sought detailed and consistent corporate disclosures about ESG risks.

Citing another survey, EY said nearly four in five investors (79%) believe boards should demonstrate expertise in climate, cybersecurity, and other risks by detailing the work they have done to mitigate such harms.

At most large companies, audit committees are increasingly responsible for overseeing cybersecurity risks, EY said. According to EY data, the share of S&P 500 companies listing cybersecurity as an audit committee responsibility rose to 77% this year from 25% in 2019.

Under Gensler, the SEC required public companies to disclose material cybersecurity incidents within four business days of determining their materiality, using Form 8-K. Companies could delay disclosure only if the Attorney General determined that such disclosure would pose a substantial risk to national security or public safety.

SEC rules also require companies to designate a board committee or subcommittee to oversee cybersecurity risks. EY said the share of S&P 500 boards that do not explicitly assign cybersecurity responsibilities to a specific committee in their proxy statements has fallen to 5% from 15% in 2021.

Companies are beginning to disclose some level of oversight over AI risks, and most often list such risks as an audit committee oversight priority, EY said.

"AI is beginning to emerge as an area of focus for committees," EY said, noting that 13% of technology committee descriptions mention this rapidly evolving technology.