Minutes:
Consideration was given to a report looking at the annual report of Internal Audit activity for 2025/26.
The Senior Audit Manager advised that the work carried out through the year had been broken up into three sections.
The table at paragraph 2.5 showed the results of the key financial systems audit, all but Payroll received a positive assurance opinion and the areas for improvement for Payroll were shown at paragraph 2.6.
Paragraph 2.8 showed all other Audit engagements and paragraph 2.11 outline high-level recommendations which had been made.
Due to resource pressures, two audits had yet to be completed and would be processed as soon as possible.
Paragraphs 2.12 to 2.17 summarised the Counter Fraud and Corruption work with further details attached at Appendix 2.
A number of data analytics exercises had been undertaken.
The Senior Audit Manager was pleased to report that, based on the work completed during the year, a substantial assurance opinion could be given on the overall adequacy and effectiveness of the Council’s governance, risk management and control framework.
Finally, compliance against the Global and Internal Audit Standards was outlined from paragraph 2.32 and no standards were shown as not being in place. An action plan had been developed to address the few areas that had been assessed as being partially in place but none were significant enough to affect the effectiveness of the Internal Audit standards of service or the annual opinion.
Councillor Lefroy raised concerns about there only being limited assurance on third party excess under ‘cyber’ and asked what measures had been taken to mitigate against the risks. It was confirmed that those control weaknesses had been addressed.
Councillor Lefroy asked if Internal Auditors were satisfied and had carried out tests to ensure that that was the case. Councillor Lefroy was advised that no immediate follow-ups were done from management responses, but would be taken into account during the year for the annual planning process. Councillor Lefroy asked that that be noted for throughout the year.
Councillor Holland stated that a previous iteration of the Committee had received a detailed report on cyber risk and asked if officers remembered the content of that report. If it was still relevant, would it be worthwhile to share the document confidentially. The Service Director stated that he would be happy to share that, confidentially.
Councillor Whieldon felt that testing should be done sooner rather than later as it could be too late by then. The Senior Audit Manager stated that if that were done, it would require further audit work, creating extra pressure on the Plan. If it was felt that it needed to be put in place it would have to be approved by this Committee.
Councillor Lefroy referred to the paragraph on debt recovery in the table at the bottom of page 141 of the report and asked for assurance that debt recovery was being strengthened. Councillor Lefroy was advised that it was still in a draft reporting stage with findings still ongoing. The Service Director confirmed that the Council had a Debt Recovery Policy which was approved in 2023. Work undertaken on sundry debtors had increased greatly. The Policy had set procedures but they were not always adhered to so work was being carried out to strengthen that.
Resolved: (i) That the outturn report containing the annual internal audit
opinion for 2025/26, be received.
(ii) That the ‘Substantial’ assurance opinion on the overall adequacy and effectiveness of the organisation’s governance, risk and control framework (i.e. the control environment) for the 2025/26 financial year, be noted.
Supporting documents: