top of page

Tax Audit Tips: Board approved tax risk appetite is not a tax control framework

A board-approved tax risk appetite does not, by itself, show that tax risk is being controlled. It records a threshold or position, but it does not prove that risks have been identified, allocated, documented, monitored or tested.


For technology and SaaS groups, that gap can matter quickly. Revenue models, overseas contracting, R&D activity, intercompany charging and rapid market entry can create tax governance questions before the board has clear evidence that management controls are operating.


Wide-angle view of an Australian audit committee reviewing a tax-control dashboard on a boardroom screen.
Risk appetite needs an operating model behind it.

Why a risk appetite is only the starting point


A risk appetite statement is a governance position. It may say that the group has low tolerance for uncertain tax positions, late lodgements, weak substantiation or arrangements that lack a commercial basis.


That is useful, but it is not the same as a control framework.


The statement does not identify each material tax risk. It does not assign an owner. It does not tell management when to seek advice, when to escalate to the audit committee, what evidence to keep, how exceptions are reported, or how the control is tested.


A tax risk appetite can also become too broad to be useful. Phrases such as “low risk” or “compliant approach” may be acceptable as board language, but they need conversion into working rules. Without that conversion, management may interpret the appetite differently across product, finance, legal, people and tax functions.


For a SaaS group, this risk is practical. Commercial teams may sign overseas customer contracts. Product teams may manage development activity that supports R&D claims. Finance teams may book intercompany charges. Legal teams may approve terms that affect taxing rights or withholding issues. A board appetite statement will not control those decisions unless it is embedded into the way those functions act.


The governance problem is evidence. When a board or audit committee asks whether the tax position is controlled, management should be able to point to more than policy language. It should be able to show how the appetite has been translated into decisions, records, review steps and reporting.


The control chain a board should expect


A board does not need to operate every tax control. It should, though, expect a clear control chain. A concise six-part framework can help test whether the board-approved position has been turned into something management can run.


1. Risk identification


Management should maintain a current view of the group’s material tax risks. For a technology or SaaS group, that may include Australian income tax, GST, PAYG withholding, employee and contractor classification, R&D claims, transfer pricing, withholding tax, permanent establishment risk and indirect tax exposures on cross-border sales.


The list should be specific enough to guide behaviour. “International tax” is usually too broad. “Overseas customer contracting that may create foreign tax registration, withholding or permanent establishment issues” is more useful.


2. Ownership


Each material tax risk should have an accountable owner. Ownership should sit with a person or role that can influence the relevant decision, not only with the tax function after the event.


Some controls will sit with finance or tax. Others may sit with legal, people and culture, product, commercial operations or procurement. The framework should show who prepares, who reviews, who approves and who escalates.


Unclear ownership is a common weakness. If everyone assumes tax will review an issue, but tax is not involved before the contract is signed, the appetite has not been operationalised.


3. Decision and escalation rules


A control framework should convert appetite into decision rules. These rules should state when management can proceed, when tax review is required, and when the matter must be escalated.


Examples include:


  • new overseas customer contract types requiring tax review before signature

  • R&D claim categories requiring technical and evidentiary review before inclusion

  • intercompany charges above a set materiality threshold requiring documented pricing support

  • uncertain positions requiring audit committee reporting before lodgement or disclosure

  • exceptions requiring documented approval and remediation steps


The thresholds should be tailored to the group. They should reflect size, complexity, systems, resourcing and the board’s approved appetite.


4. Evidence


A tax control framework should identify the records that prove the control operated. Evidence may include review sign-offs, position papers, contract checklists, R&D activity records, intercompany agreements, working papers, reconciliations, meeting minutes and exception logs.


Evidence needs to be retained in a way that can be found later. A control that depends on informal email trails or personal knowledge is weak. Key person knowledge does not give the board a reliable audit trail.


5. Monitoring


Monitoring shows whether the controls are being followed during the year. It is different from annual review.


Monitoring may include periodic status reporting, exception dashboards, overdue action tracking, review of tax-sensitive contract approvals, or sample checks of control performance. The board or audit committee should receive reporting that distinguishes between the existence of a policy and the operation of a control.


Effective monitoring should also show what changed. For technology and SaaS groups, relevant changes may include new markets, new pricing models, new group entities, new development centres, new funding arrangements, acquisitions or changes in contracting flows.


6. Periodic testing


Testing assesses whether controls are designed and operating as intended. It may be performed internally or with external support, depending on the group’s scale, risk profile and assurance needs.


Testing should be planned, documented and reported. It should identify findings, management responses, timeframes and closure evidence.


The board does not need excessive detail. It should expect enough information to understand whether the control design remains fit for purpose and whether the controls are operating in practice.


Close-up view of a control-owner evidence map linking tax risks to named roles and records.
A control map helps turn governance intent into evidence.

Board oversight versus management operation


Board tax governance should not collapse into management operation. The board approves appetite, expects a framework, receives assurance and challenges gaps. Management designs, operates and documents the controls.


The separation matters.


If the board only approves the appetite, it may not know whether controls exist. If the board tries to operate controls, accountability becomes blurred. The better position is disciplined oversight supported by clear management ownership.


A board or audit committee should generally focus on questions such as:


  • whether material tax risks have been identified and ranked

  • whether each risk has an accountable owner

  • whether decision and escalation rules are documented

  • whether evidence requirements are clear

  • whether monitoring reports show control performance

  • whether periodic testing has identified issues and whether those issues are closed


Management should be able to answer with documents, not only explanations. Oral assurance may help, but it should not replace records.


The board pack should also distinguish between three different things:


Governance item

What it shows

What it does not prove

Risk appetite statement

The board’s tolerance and expectations

That controls exist or operate

Tax policy

Management’s intended approach

That decisions follow the policy

Control evidence

How a control operated in a particular case

That all other controls are effective


This distinction is central to audit committee tax risk oversight. A policy can be well drafted and still fail if the business does not use it at decision points.


Worked scenario — a SaaS group with an approved appetite but no documented control for overseas contracting, R&D claims and intercompany charges


Consider an Australian-headquartered SaaS group. The board has approved a low tolerance for material tax uncertainty and has stated that tax positions should be supportable and documented.


The group is growing into overseas markets. Its sales team negotiates customer contracts with enterprise customers outside Australia. Its product team undertakes development work that may support R&D claims. Its finance team charges costs between Australian and overseas group entities.


The appetite is clear at board level. The control framework is not.


For overseas contracting, there is no documented rule that requires tax review before a new contracting structure is used. Legal reviews terms for commercial and liability issues, but the checklist does not include tax-sensitive matters. Sales can approve variations without a tax sign-off. Management later reports that contracts are “generally consistent” with the appetite, but cannot show a control that operated before signature.


For R&D claims, the group keeps project records in product systems and finance records in accounting systems. There is no mapped evidence requirement that links claim categories to technical records, cost records and review sign-offs. The tax team relies on year-end interviews. The board has no clear report showing whether R&D evidence is complete before a claim position is finalised.


For intercompany charges, finance raises periodic charges between entities. There are intercompany agreements, but no current evidence map showing which charges are covered, who reviews them, what support is retained, and when transfer pricing documentation is refreshed. Management can explain the approach, but the explanation is not the same as tested control evidence.


In this scenario, the board’s appetite has not failed. The failure is the missing conversion layer.


The practical concern is not whether the group intended to manage tax risk. The concern is whether it can prove that management decisions were made under documented, assigned and monitored controls.


A remediation plan would usually start with a risk-to-control map. It would then assign owners, set decision and escalation rules, define evidence, create monitoring reports and schedule testing. The detail should be tailored to the group’s operations and risk profile. It should not be treated as a template exercise.


Evidence a board or audit committee should request


A board or audit committee reviewing a tax control framework should request evidence that shows design and operation. The following checklist can be adapted to the group’s size and complexity.


  • Board-approved appetite and tax policy


The current approved documents, with dates, review history and the scope of tax matters covered.


  • Material tax risk register


A current register that identifies material tax risks, relevant business processes, risk ratings and related controls.


  • Control owner matrix


A map showing accountable owners, reviewers and approvers for each material tax control.


  • Decision rules


Documented triggers for tax review, management approval and board or audit committee escalation.


  • Evidence requirements


A clear list of records required to support each control, where those records are stored and who is responsible for maintaining them.


  • Exception reporting


A log showing control breaches, late reviews, undocumented decisions, unresolved issues and remediation actions.


  • Monitoring reports


Periodic reporting that shows whether controls operated, not only whether policies exist.


  • Testing plan


A plan setting out which controls will be tested, when testing will occur, who will perform it and how findings will be reported.


  • Testing results


Reports showing test scope, samples, findings, management responses, action owners and closure evidence.


  • Change assessment


Evidence that tax risks and controls were reconsidered after material business changes, such as new markets, new entities, new products or acquisitions.


This checklist should not be read as a fixed compliance list. It is a practical governance tool. The right level of evidence will depend on the group, its risk profile and the board’s assurance requirements.


Questions that indicate a control gap


Certain questions tend to expose whether the framework is operating or only documented. They are useful because they ask for proof.


  • Which tax risks changed during the year, and who approved the control response?

  • Which business decisions require tax review before they are made?

  • What matters must be escalated to the audit committee?

  • Who owns the tax control for overseas contracting?

  • Where is the evidence that the R&D claim review control operated?

  • How does finance confirm that intercompany charges follow the approved approach?

  • What exceptions were identified, and how were they closed?

  • When were key controls last tested?

  • What failed testing, and what has management done about it?

  • What tax-sensitive decisions rely on informal judgement rather than documented rules?

  • Which controls depend on a single person’s knowledge?

  • What would change in the framework if the group entered another overseas market?


If these questions can only be answered verbally, there may be a documentation gap. If management cannot identify an owner, there may be an accountability gap. If reports show activity but not exceptions or testing, there may be a monitoring gap.


A mature response does not need to be lengthy. It needs to be traceable.


Primary sources


The Australian Taxation Office materials on tax risk management and governance describe better practices that large businesses and reviewers may use when considering tax governance. They should be tailored to the organisation. They should not be described as mandatory law.


Relevant ATO source materials include:


These sources provide a useful reference point for board tax governance discussions. They do not replace advice on the group’s specific facts, governance structure, systems or tax profile.


Review a tax control framework


A board-approved appetite is a necessary start. It is not sufficient evidence that tax risk is controlled.


The practical test is whether management can show a working chain from risk identification to ownership, decision rules, evidence, monitoring and periodic testing. That chain should be clear enough for the board or audit committee to oversee, and practical enough for management to operate.


Extax Advisory can review whether an existing tax control framework has been translated into documented controls, assigned owners, reporting routines and testing evidence. Confidential enquiries may be directed to info@extax.net.




Current at 29 July 2026. Technical review required before publication. General information only.


Comments


bottom of page