This document is the British Business Bank Plc Group Audit and Risk Assurance Committee (ARAC) Terms of Reference
1. Constitution and Purpose
1.1 The Board Audit and Risk Assurance Committee (the “Committee” or “ARAC”) is constituted as a committee of the Board of British Business Bank plc (the “Company”), from which it derives its authority and to which it shall regularly report.
1.2 Its purpose is to assist the Board in fulfilling its oversight responsibilities in relation to financial and narrative reporting, risk management, internal controls, assurance, internal audit, external audit, compliance, fraud and financial crime prevention and whistleblowing.
1.3 The Committee shall support the Board in establishing, maintaining and reviewing the effectiveness of the Group’s risk management and internal control framework, including the Board’s monitoring and review of material controls for the purposes of the UK Corporate Governance Code 2024 and related reporting requirements.
1.4 The Committee shall have oversight of the Company, its major subsidiary undertakings and the Group as a whole, as appropriate, and shall take account of the Group’s status as a UK Government-owned development bank, its Shareholder Relationship Framework, Managing Public Money and applicable public-sector accountability requirements.
1.5 The Committee is an oversight and assurance committee. Unless expressly delegated authority by the Board, it shall not assume executive responsibility for the management of risk, controls, audit, compliance or financial reporting.
2. Membership
2.1 The Committee shall comprise at least three independent members. Members shall be appointed by the Board on the recommendation of the Governance and Nomination Committee, in consultation with the Chair of the Committee.
2.2 The Shareholder Representative Director shall be entitled to be a member of the Committee. Where the Shareholder Representative Director is a member and is unable to attend, the Shareholder Representative Director may nominate a representative of UK Government Investments or the Department for Business, Science, Innovation and Technology, or any successor body, to attend as an observer.
2.3 All members of the Committee, other than the Shareholder Representative Director, shall be independent Non-Executive Directors. The Chair of the Board shall not be a member of the Committee.
2.4 At least one member shall have recent and relevant financial experience, ideally supported by a professional qualification from a recognised accountancy body. The Committee as a whole shall have competence relevant to the Group’s activities, operating environment, portfolio, accounting judgements and risk profile.
2.5 Appointments to the Committee shall normally be for a period of up to three years, which may be extended for a further period of up to three years, provided the member continues to meet the criteria for membership. Any appointment beyond six years should be subject to rigorous review by the Governance and Nomination Committee.
2.6 The Board shall appoint, remove or replace the Committee Chair, who shall be an independent Non-Executive Director. In the absence of the Committee Chair or nominated deputy, the remaining members present shall elect one of themselves to chair the meeting.
2.7 Only members of the Committee shall have the right to attend Committee meetings. The Chair of the Board may attend meetings. Other individuals, including the Chief Executive Officer, Chief Financial Officer, Chief Risk Officer, Managing Director Internal Audit, External Audit Lead Partner, General Counsel, and other employees or advisers, may be invited to attend all or part of any meeting, as appropriate, at the discretion of the Committee Chair.
2.8 Any person invited to attend a meeting who is not a member of the Committee shall not be entitled to vote on any matter before the Committee.
3. Secretary
3.1 The Company Secretary, or their nominee, shall act as Secretary of the Committee.
3.2 The Secretary shall support the Committee Chair in planning the Committee’s work, preparing agendas, commissioning and circulating papers, maintaining minutes and records, and ensuring that the Committee receives information in a timely manner to enable full and proper consideration to be given to matters under discussion.
3.3 The Committee shall have access to the services of the Company Secretariat on all Committee matters.
4. Quorum
4.1 The quorum necessary for the transaction of business shall be two members, one of whom must be the Committee Chair or nominated deputy.
4.2 A duly convened meeting of the Committee at which a quorum is present shall be competent to exercise all or any of the authorities, powers and discretions vested in or exercisable by the Committee.
4.3 Decisions should normally be reached by consensus. In the event consensus cannot be reached, decisions may be taken by a majority of members present and voting, with the Committee Chair having a casting vote in the event of a tie.
4.4 A Committee member who remains opposed to a proposal after a vote may request that their dissent be recorded in the minutes
5. Meeting Frequency
5.1 The Committee shall meet at least four times each year at appropriate intervals in the financial reporting, risk, assurance and audit cycle and otherwise as required.
5.2 Meetings shall be scheduled to allow sufficient time for matters arising from the Committee to be considered by the Board.
5.3 Outside the formal meeting programme, the Committee Chair shall maintain appropriate dialogue with key individuals involved in the Company’s governance and assurance arrangements, including the Board Chair, Chief Executive Officer, Chief Financial Officer, Chief Risk Officer, Managing Director Internal Audit and External Audit Lead Partner. In addition, the Committee Chair should seek engagement with the Shareholder’s Representative on significant matters related to the Committee’s areas of responsibility.
5.4 The Committee shall meet the Managing Director Internal Audit and the External Auditor at least once each year without executive management present. The Committee Chair may also hold private sessions with the Chief Risk Officer, General Counsel or other assurance providers where appropriate
6. Notice of Meetings
6.1 Meetings of the Committee shall be convened by the Secretary at the request of the Committee Chair, any Committee member, the Chief Risk Officer, the Managing Director Internal Audit, the External Audit Lead Partner, the Chief Financial Officer or the Chair of the Board, if they consider a meeting necessary.
6.2 Unless otherwise agreed, notice of each meeting confirming the venue, time and date, together with an agenda of items to be discussed, shall be forwarded to each Committee member and any other person required to attend no later than five working days before the meeting.
6.3 Supporting papers shall be circulated to Committee members and, where appropriate, attendees at the same time as the agenda. Committee papers shall be available for review by Board members unless the Committee Chair determines that it would be inappropriate to do so.
6.4 Meetings may be held in person, by telephone, by video conference or by other electronic means, provided all participants are able to contribute to the meeting simultaneously.
7. Minutes of Meetings
7.1 The Secretary shall minute the proceedings and decisions of all Committee meetings, including recording the names of those present and in attendance.
7.2 Draft minutes shall be circulated to the Committee Chair within three weeks of the meeting for review. Minutes should be submitted for approval at the next Committee meeting.
7.3 Once approved, minutes shall be made available to all members of the Board unless it would be inappropriate to do so in the opinion of the Committee Chair.
7.4 Final approved minutes shall be maintained for the Company’s records.
8. Duties and Delegated Responsibilities
8.1 The Committee shall have oversight and carry out the duties detailed below for the Company, major subsidiary undertakings and the Group as a whole, as appropriate.
8.2 The Committee shall discharge these responsibilities on a risk-based and proportionate basis through its annual workplan, focusing on matters that are material to the Group’s financial reporting, risk profile, internal control environment, assurance framework, public accountability obligations or Board decision-making.
8.3 Examples included in this section are illustrative and shall not limit the Committee’s authority to consider any matter within its remit. Detailed cyclical requirements may be captured in the annual ARAC workplan, policy approvals schedule or delegated authority frameworks.
A. Financial Information and Reporting
8.A1 Monitor the integrity, clarity and completeness of the Company’s and Group’s financial statements, Annual Report and Accounts and related formal reporting, and report to the Board on significant financial reporting matters and judgements.
8.A2 Review and challenge significant accounting policies, estimates, judgements, methodologies and treatments, including, where material, expected credit losses, fair value valuations, overlays, staging and significant or unusual transactions.
8.A3 Review material disclosures and information presented with the financial statements, including strategic, governance, audit, risk management and internal control reporting.
8.A4 Review, challenge and, where within delegated authority, approve material financial information to be provided to the Shareholder, Government or Parliament, including reporting required under the Shareholder Relationship Framework, Managing Public Money, Government Accounting requirements or other applicable public-sector requirements.
8.A5 Where the Company is responsible for providing to the Department for Business, Innovation, Science and Trade (or successor Department) financial reporting information for assets and liabilities that are held directly on their Statement of Financial Position the Committee shall review, challenge, and approve before this information is provided at key reporting dates including year-end. This includes, but is not limited to, the Covid Guarantee Loan Schemes Expected Credit Losses and fraud estimates and Future Fund fair valuations.
8.A6 Review going concern and viability assessments, associated disclosures and relevant Shareholder support or assurance arrangements, and advise the Board accordingly.
8.A7 Recommend the Annual Report and Accounts, or relevant financial statements, to the Board for approval.
B. Narrative Reporting, Sustainability and Statutory Disclosures
8.B1 Review the Annual Report and Accounts and advise the Board on whether, taken as a whole, it is fair, balanced and understandable and provides the information necessary for stakeholders to assess the Group’s performance, business model, risk profile, climate-related disclosures, and strategy
8.B2 Review material narrative reporting and disclosures within the Committee’s remit, including statements on risk management, internal controls, principal and emerging risks, going concern, viability including sustainability-related matters.
8.B3 Review, where material or legally required, non-financial reporting and related assurance arrangements, including the integrity of climate-related financial disclosures, sustainability disclosures, wider climate and sustainability related matters, and the Modern Slavery Statement.
C. Risk Appetite, Risk Management and Risk Strategy
8.C1 Review and recommend to the Board the Group’s overall risk appetite, tolerance and risk strategy, and oversee performance against approved appetite.
8.C2 Review the Group’s current and prospective risk profile, including principal and emerging risks, material concentrations, risk-return considerations, public policy objectives and strategic plan delivery.
8.C3 Review the effectiveness of the Group’s Risk Management Framework, Risk Taxonomy, principal risk methodologies, key risk policies and risk assessment processes, including whether these remain appropriate to the Group’s activities, scale, complexity and risk profile.
8.C4 Review reports on material breaches of risk appetite, limits or policy requirements and the adequacy of management’s proposed actions.
8.C5 Review material risks associated with major programmes, interventions, guarantees, investment activities and other Board-referred matters.
8.C6 Review, where material, sustainability, climate, cyber, operational resilience, reputational, financial crime, subsidy control and other compliance-related risks within the Committee’s remit.
8.C7 Advise the Board on the adequacy of risk governance, controls and assurance arrangements for material risks.
D. Internal Controls and Assurance
8.D1 Support the Board in establishing, maintaining and reviewing the effectiveness of the Group’s risk management and internal control framework, including material financial, operational, reporting and compliance controls.
8.D2 Review management’s assessment of material internal controls, including the methodology, evidence, assurance and conclusions supporting any Board declarations or Annual Report disclosures.
8.D3 Review assurance from Internal Audit, External Audit, Risk, Compliance and other assurance providers on the effectiveness of governance, risk management and internal controls.
8.D4 Review significant deficiencies, control failures, material weaknesses and remediation plans, including management’s assessment of root causes, progress and effectiveness of actions taken.
8.D5 Review the effectiveness and coordination of the Group assurance framework, including first, second and third line assurance arrangements, and report its overall conclusions to the Board.
E. Compliance, Fraud, Financial Crime, and Whistleblowing
8.E1 Review the adequacy and effectiveness of whistleblowing and Speak Up arrangements, including arrangements for confidential reporting, independent investigation, follow-up action, themes and lessons learned.
8.E2 Review the adequacy and effectiveness of arrangements for preventing, detecting, responding to and reporting fraud, bribery, corruption, money laundering, sanctions and other financial crime risks including the annual Money Laundering Reporting Officer report.
8.E3 Review significant legal, regulatory, compliance, shareholder, Government and Parliamentary accountability matters within the Committee’s remit, including material findings from second-line compliance activity.
8.E4 Approve or recommend to the Board, where required under the Policy Governance Framework or applicable delegations, policies, statutory strategies (e.g. tax strategy) or statements within the Committee’s remit.
F. Risk and Compliance Function and Chief Risk Officer
8.F1 Keep under review the remit of the Risk and Compliance function and ensure it has the appropriate resources and capabilities alongside access to information to enable it to perform its function effectively and in accordance with the relevant professional standards
8.F2 Recommend to the Board the appointment or removal of the Chief Risk Officer and provide input into the Chief Risk Officer's performance assessment and remuneration arrangements where appropriate.
8.F3 Ensure the Chief Risk Officer has unrestricted access to the Committee and Committee Chair, including private meetings without executive management present.
8. F4 Review material reports from the Chief Risk Officer, significant risk and compliance findings, management responses and progress implementing agreed actions.
8.F5 Oversee the remit, standing, independence, effectiveness, resourcing and access of the Risk and Compliance Function, including reviewing material reports from the Chief Risk Officer, monitoring management responsiveness to findings and recommendations, ensuring appropriate direct access to the Committee Chair and Board Chair.
8.F6 Assess annually the effectiveness, independence, objectivity and quality of the Risk and Compliance Function including relevant expectations under applicable professional standards.
G. Internal Audit
8.G1 Approve and annually review the Internal Audit Charter, including Internal Audit’s mandate, authority, role, responsibilities, scope and services.
8.G2 Approve the risk-based annual Internal Audit Plan and review whether Internal Audit has sufficient budget, resources, skills, access and information to deliver it effectively.
8.G3 Authorise the appointment and removal of the Managing Director Internal Audit and approve or provide input to remuneration and performance evaluation in accordance with applicable Company processes.
8.G4 Ensure the Managing Director Internal Audit has unrestricted access to the Committee and Committee Chair, including private meetings without executive management present.
8.G5 Review Internal Audit reports, the annual Internal Audit opinion, significant findings, management responses and progress implementing agreed actions.
8.G6 Oversee the remit, standing, independence, effectiveness, resourcing and access of the Internal Audit Function, including reviewing material reports from the Managing Director Internal Audit, monitoring management responsiveness to findings and recommendations, ensuring appropriate direct access to the Committee Chair and Board Chair.
8.G7 Assess annually the effectiveness, independence, objectivity and quality of Internal Audit, including the quality assurance and improvement programme and relevant expectations under applicable internal audit standards including the Global Internal Audit Standards.
H. External Audit
8.H1 Oversee the relationship with the External Auditor and discharge, to the extent applicable to the Company, responsibilities under the Financial Reporting Council Audit Committees and the External Audit: Minimum Standard, including the matters set out below.
8.H2 recommending the appointment, re-appointment or removal of the External Auditor, subject to the Shareholder Relationship Framework and applicable approvals;
8.H3 approving the External Auditor’s terms of engagement, remuneration, audit scope and annual audit plan;
8.H4 reviewing and monitoring the External Auditor’s independence, objectivity, qualifications, expertise, resources and compliance with relevant ethical and professional requirements;
8.H5 developing and monitoring policies on non-audit services and the employment of former External Auditor staff;
8.H6) reviewing audit findings, significant accounting and audit judgements, errors, representation letters, management letters and management responses; and
8.H7 assessing the effectiveness and quality of the external audit process
8.H8 ensure the External Auditor has unrestricted access to the Committee and Committee Chair, including private meetings without executive management present at least annually.
I. Strategic Transactions, Programmes and Public Accountability
8.I1 Where requested by the Board, review the material risk, control and assurance implications of proposed strategic initiatives, major programmes, Government interventions, guarantees, investment activities and funding schemes before final Board approval.
8.I2 Review significant issues arising from Public Accounts Committee, National Audit Office, Shareholder or Government reviews where they fall within the Committee’s remit, and monitor management’s responses and agreed actions.
9. Reporting Responsibilities
9.1 The Committee Chair shall report formally to the Board after each Committee meeting on matters considered, decisions taken, recommendations made and any matters requiring Board attention or approval.
9.2 The Committee shall make recommendations to the Board on any area within its remit where action or improvement is required, including where the Committee has been unable to reach agreement.
9.3 The Committee shall prepare an annual ARAC report or input for the Annual Report and Accounts describing how it has discharged its responsibilities, including significant matters relating to financial reporting, audit, risk management, internal controls, assurance, whistleblowing, fraud prevention, going concern, viability and any other matters required by applicable governance standards. The Committee may cross-refer to information disclosed elsewhere in the Annual Report and Accounts where appropriate.
10. Other Matters
10.1 The Committee shall have access to sufficient resources to carry out its duties, including access to the Company Secretariat for assistance as required.
10.2 The Committee shall be provided with appropriate and timely training, both in the form of induction for new members and ongoing training for existing members.
10.3 The Committee shall give due consideration to applicable laws, regulations and guidance, including the Companies Act 2006, UK Corporate Governance Code, Managing Public Money, the Shareholder Relationship Framework, Government-wide corporate guidance and instructions, FRC guidance, Audit Committees and the External Audit: Minimum Standard, and any other applicable rules or requirements.
10.4 The Committee shall oversee any investigation of activities within its terms of reference.
10.5 The Committee shall work and liaise as necessary with other Board committees to ensure appropriate interaction and to avoid gaps or duplication in oversight.
10.6 The Committee shall arrange for periodic review of its own performance and, at least annually, review its constitution and terms of reference to ensure it is operating effectively and recommend any changes to the Board for approval.
11. Authority
11.1 The Committee is authorised by the Board to seek any information it requires from any director, employee, subsidiary undertaking, adviser or assurance provider of the Group in order to perform its duties.
11.2 The Committee is authorised to obtain, at the Company’s expense, independent legal, accounting or other professional advice on any matter within its terms of reference where it considers it necessary to do so.
11.3 The Committee is authorised to call any employee, adviser or assurance provider to be questioned at a meeting of the Committee as and when required.
11.4 The Committee may make written resolutions outside formal Committee meetings in accordance with the Company’s Articles of Association, including paragraphs 97(c) and 99, where applicable.
11.5 Where disagreement between the Committee and the Board cannot be resolved, the Committee may report the matter to the Board and, where required by applicable governance standards or regulation, disclose the matter in the Annual Report and Accounts.
12. Version Control
| Version | v0.1 |
|---|---|
| Author | Corporate Governance Team |
| Description | Audit and Risk Assurance Terms of Reference |
| Approved by | Board |
| Date Approved | 24 September 2026 |
| Date Published | 30 September 2026 |