Agenda item

To provide a periodic report on the Internal Audit function for the period September 2025 – January 2026 and to provide an annual review of the Anti-Fraud and Corruption Strategy for approval by the Audit Committee.

Minutes:

The Internal Audit Manager provided a periodic report on the Internal Audit function for the period September 2025 – January 2026 along with an annual review of the Anti-Fraud and Corruption Strategy.

 

The Committee was informed that the Global Audit Standards required the Internal Audit Manager to plan for reporting to senior management (Management Board) and to the board (Audit Committee) during the year, and to produce an annual Internal Audit opinion and report that could be used to inform the Annual Governance Statement.

 

It was reported that seven audits had been completed since the last meeting of the Audit Committee held in September 2025 and that all seven audits had received a satisfactory level of overall assurance of ‘Adequate Assurance’ or ‘Substantial Assurance’.

 

A further eight audits from the 2025/26 Internal Audit Plan had been allocated (three of which were consultative reviews) and nine were currently at the fieldwork phase.

 

The audits that had been completed in this period were:

 

·         Corporate Governance

·         Housing Strategy and Homelessness

·         Environmental Services

·         Emergency Planning

·         Corporate Complaints

·         Members Conduct and Expenses

·         Treasury Management

 

No significant issues had been identified for the Audit Committee to be concerned about, with only some moderate actions agreed to be managed through the regular follow-up process with the service.

 

Quality Assurance – The Internal Audit function issued satisfaction surveys for each audit had been completed. No unsatisfactory responses had been received in this period.

 

Resourcing

 

Members were informed that Internal Audit currently had an establishment of 4 FTE posts with access to a third-party provider of Internal Audit Services for specialist audit days as and when required. The Internal Audit Team currently had an Audit Technician post vacant. They had had an apprentice working within the team for over a year who was continuing to develop well and who had currently been undertaking the administrative responsibilities for the Audit, Fraud and Compliance functions.

 

Outcomes of Internal Audit Work

 

The Public Sector Internal Audit Standards required the Internal Audit Manager to report to the Audit Committee on significant risk exposures and control issues. Since the last report four audits had been completed and the final report issued.

 

 

Assurance

Colour

Number this Period

Total for 2025/26 Plan

 

Substantial

 

4

5

 

Adequate

 

3

5

 

Improvement Required

 

0

1

 

Significant Improvement Required

 

0

0

 

No Opinion Required

 

0

0

Three consultative engagements in 2025/26 to date

 

For the purpose of the colour coding approach, both the substantial and adequate opinions had been shown in green as both were within acceptable tolerances.

 

Members heard that no issues had been reported arising from audits completed in the period under review with none receiving an ‘Improvement Required’ opinion that required reporting to the Audit Committee.

 

Management Response to Internal Audit Findings

 

It was reported that there were processes in place to track the action taken regarding findings that had been raised in Internal Audit reports and to seek assurance that appropriate corrective action had been taken. Where appropriate, follow up audits had been arranged to revisit significant issues identified after an appropriate time.

 

The number of high severity issues outstanding was as follows:-

 

Status

Number

Comments

Overdue more than 3 months

0

 

Overdue less than 3 months

 

0

 

Not yet due

2

 

 

The Audit Committee had previously requested more detail on the outstanding actions within the above table and on previous significant findings as a matter of context. Appendix B, to the A.2 report, showed a summary of those findings and agreed actions as well as including the service response and internal audit status. It was noted that this would become a regular appendix of the periodic progress reports going forward.

 

It was reported that the Council was required to have an Anti-Fraud and Corruption Strategy, which had been last updated in March 2025. The Strategy was subject to an annual review process.

 

The amended strategy was set out in Appendix C to the A.2 report. Amendments made since the last review had been highlighted in red font.

 

Members were informed that the main updates related to the inclusion of the Fighting Fraud Locally pillars ‘Govern, Prevent and Protect’ and to also include a reference to the Economic Crime and Corporate Transparency Act 2023, relating to the requirement for all organisations over a certain size to evidence that they had reasonably tried to prevent fraud. If the Authority could not evidence that, fines and sanctions could be imposed.

 

The Strategy had continued to be based on CIPFA’s code of practice on managing the risk of fraud and corruption. As its foundation, the Strategy had set out the Council’s commitments along with the following key areas:

 

·         Strategic Framework

·         Legislation and General Governance

·         Definitions

·         Standards, Expectations and Commitment

·         Roles and Responsibilities

·         Prevention

·         Detection and Investigation

·         Resources and Invested in Counter Fraud and Corruption

 

The Committee heard that the Strategy would continue to be subject to an annual review process against identified actions and had therefore been included on the ongoing work programme of the Committee. It was acknowledged that through its application, the Strategy would evolve to reflect the various strands of work that were being developed within the Council, which would be included in future updates presented to the Audit Committee.

 

The Committee had also been provided with a Fraud Risk Register within Appendix D to review and adopt. The Fraud Risk Register had now been updated with the mitigating controls evidencing how the Council defenced itself against different types of fraud.

 

To demonstrate the effectiveness of the Anti-Fraud and Corruption Strategy and address how fraud risks impacted on achieving the Council's objectives and its service users, the Internal Audit Manager would continue to provide an update on the work undertaken by the Fraud and Risk Team and the outcomes of that work on a bi-annual basis.

 

The Internal Audit Manager reported that he was required to undertake an annual Quality Assurance Improvement Programme (QAIP) via a self-assessment of the Internal Audit Function against the Global Internal Audit Standards. That was a full review of the Council’s working practices against the standards set by the Institute of Internal Audit and adopted by CIPFA.

 

It was further reported that the assessment against those standards had been now completed and any actions and recommendations deemed necessary had been reported in Appendix E to the A.2 report. There was a programme of work to be carried out over the forthcoming twelve to eighteen months as there had been some changes in the Global Internal Audit Standards that had not been previously in the Public Sector Internal Audit Standards. The team would work to action those requirements where possible and update the Audit Committee on their progress.

 

Currently, the current Internal Audit Team would be classified as non-compliant as they had yet to undergo another External Quality Assessment, which was required every five years. In the light of Local Government Reorganisation (LGR), the Internal Audit Manager had felt it prudent to discuss with the Audit Committee as to whether the external assessment was worth completing due to the fact that the team, in its current form, would not exist and therefore any new audit function under a Unitary Council would need another external assessment. Those external assessments could cost anywhere £6,000 to £12,000 dependent on the size of the authority. Those assessments could also be very resource intensive, which would mean less availability of Officers during the LGR transition period.

 

It was moved by Councillor Fairley, seconded by Councillor Sudra and RESOLVED that the Committee:-

 

(a)  notes the External Auditor’s Periodic Report September 2025 – January 2026, and agrees that a satisfactory level of assurance has been provided within the following reports submitted by the Internal Audit Manager:

 

·         Periodic Internal Audit Report

·         Appendix A – Internal Audit Progress Report

·         Appendix B – Agreed Action Tracking

·         Appendix C – Anti-Fraud and Corruption Strategy

·         Appendix D – Fraud Risk Register

·         Appendix E – Quality Assurance Improvement Programme (QAIP)

Supporting documents: