I. Purpose
The Audit and Risk Committee assists the Board with oversight of financial reporting, external audit, internal controls, enterprise risk management, legal and regulatory compliance, ethics reporting, cybersecurity, insurance, and other matters assigned by the Board. Oversight does not transfer management's responsibility for records, controls, reporting, compliance, or risk ownership.
II. Composition
The Committee will consist of at least three directors when Board size permits. A majority should be independent under criteria adopted by the Board, and at least one member should possess financial expertise sufficient to understand financial statements, audit, and internal controls. If the Board has fewer than three suitable directors, the full Board may perform the Committee's functions and document that arrangement.
Members and the Chair are appointed and may be removed by the Board. No member may participate in a matter where an unaddressed conflict prevents objective judgment.
III. Meetings and authority
The Committee will meet at least quarterly and additionally as circumstances require. A majority of members constitutes a quorum. The Committee may meet separately with management, finance leadership, internal audit personnel, external auditors, compliance personnel, reserves engineers, cybersecurity advisers, and legal counsel.
The Committee may access Company records and personnel, investigate matters within its authority, and retain independent counsel, accountants, technical advisers, or other experts at Company expense. It may delegate tasks to a subcommittee but remains responsible for oversight and reporting.
IV. Financial reporting and audit responsibilities
- Review annual and interim financial statements, significant accounting policies, estimates, judgments, related-party transactions, unusual transactions, going-concern matters, and material corrections.
- Recommend appointment, compensation, retention, or removal of the external auditor; assess independence, competence, scope, findings, and management's response.
- Preapprove material non-audit services where auditor independence could be affected.
- Review management representation letters, audit adjustments, control deficiencies, fraud risks, and disagreements with auditors.
- Obtain written CEO and CFO certifications to the Board concerning records, controls, and the fairness of financial reporting.
- Oversee procedures for confidential and anonymous complaints concerning accounting, internal controls, auditing, fraud, or financial misconduct.
V. Internal controls and internal audit
The Committee will oversee the design and effectiveness of financial and operational controls, delegated authorities, treasury controls, commodity trading controls, sanctions screening, tax controls, cybersecurity controls, and records retention. It will assess at least annually whether an internal audit function should be established or outsourced and approve its mandate, plan, budget, independence, and material findings when present.
VI. Enterprise risk management
The Committee will review the enterprise risk framework, risk appetite, risk register, key risk indicators, insurance program, and material mitigation plans. Review must address exploration and reserves, well control, HSE, environmental remediation, commodity prices, credit and trading, liquidity and financing, license and concession continuity, country and political risk, joint ventures, sanctions and corruption, cybersecurity, climate, community relations, and business continuity.
VII. Reserves and technical information
Where reserves, resources, production forecasts, or technical estimates are used in financing, valuation, investor materials, or financial reporting, the Committee will oversee management's verification process, qualifications and independence of technical experts, key assumptions, reconciliation, and consistency across disclosures.
VIII. Compliance and investigations
The Committee will receive reports concerning material legal violations, significant government inquiries, whistleblower matters, fraud, bribery, sanctions, conflicts, and retaliation. Allegations involving the CEO, CFO, Chief Legal Officer, external auditor, or a director must be escalated directly to the Chair or an independent Board member.
IX. Reporting and evaluation
The Chair will report material deliberations and recommendations to the Board. Minutes will be maintained with appropriate protection for privileged material. The Committee will conduct an annual self-evaluation and recommend charter changes.
Administration
Implementation accountability rests with The Audit and Risk Committee. The responsible function will maintain this document and update it following a material legal, regulatory, operational, ownership, or business change.