Agenda item
Internal Audit Plan 2026-27 and Internal Audit Strategy 2024-27 Year 2 Review
This report presents the proposed Internal Audit Plan for 2026-27. The report also includes an assessment of the progress made at the end of Year 2 towards achieving the objectives outlined in the Internal Audit Strategy 2024-27, which was approved by Audit and Standards Advisory Committee in March 2024.
Minutes:
Darren Armstrong (Deputy Director, Organisational Assurance and Resilience and Head of Internal Audit, Brent Council) was invited to introduce the report, covering the developments made to the Council’s Internal Audit function since adopting its revised hybrid and flexible approach, which was now entering its third year of operation. The plan for 2026–27 was contained within Appendix 1 to the report, with priority ratings applied to all planned risk-based audits.
In presenting the report, members were advised:
· Section A covered core assurance work for 2026–27, providing coverage of key and core financial systems and controls.
· Section B set out the Audit Team’s agile risk-based plan, designed to be flexible and responsive to emerging risks outside the scope of the core assurance plan, with an overview of the Council’s intended audits for 2026–27. Priority ratings had been included to inform the Committee of the relative urgency of the risks identified.
· Section C covered consultancy and advisory work, comprising primarily reactive activity following requests from senior leadership, with four consultancy and advisory reviews planned for the coming year.
· Section D covered ongoing work, including active audits and the tracking of progress through to completion.
· Section E reflected the Council’s strategic risks within the plan, demonstrating the coverage of the Internal Audit function against each key strategic risk.
· Section F was included for the Committee’s information, setting out the assurance ratings intended to be applied to completed audits in 2026–27.
· Appendix 2 reported on the achievements made by the Council in meeting its strategic objectives. With work entering the final year of the current three-year plan, efforts were already underway to determine the goals and objectives for the subsequent three-year plan, with an overarching organisational resilience theme identified for 2026–27 work, recognising the heightened level of strategic uncertainty under which the Council was operating. Certain audit scopes would be extended, and an integrated assurance pilot involving experts from across the Council – including Health and Safety, Emergency Planning and Counter Fraud – would be introduced to provide additional assurance.
Having thanked Darren Armstrong for presenting the report, the Chair then invited questions and comments from the Committee, with the following issues discussed:
· Members enquired about AI governance, which was listed for follow-up audit in Q2 2026, and requested confirmation on the status of the Council-wide AI Strategy and Data Ethics Board, as well as how the Council was protecting itself from cyber risks associated with the rapid deployment of new automations. In response, Darren Armstrong confirmed that AI governance audit conclusions had been reflected in the September audit report and in recent action plans, setting out the Council’s commitments to addressing these matters. Board-level assurance on AI and follow-up work on AI governance were planned accordingly. On the question of cyber risk, this was subject to annual assurance as a standing commitment within the core assurance programme, with a number of controls and mitigating actions already in place.
· Members asked whether audit reports were built back into the work undertaken to close entries on the risk register. In response, Darren Armstrong confirmed that the risk register was one of several information streams feeding into audit activity. Reports from assurance providers played a key role in informing audit progress, with issues identified by providers scored and used to assess the maturity of risks in different areas. Duplication and repetition of audit risks and findings were not accepted, with findings from previous audits factored into subsequent risk assessments to avoid such overlap.
· Regarding the Internal Audit Strategy and the streamlining of the follow-up process, members noted that the percentage of days allocated to follow-up activity was currently 19% and sought clarification as to whether reducing the administrative burden in this area would result in more in-depth follow-up or additional capacity for other audit work. In response, Darren Armstrong confirmed that the function was modernising its follow-up processes, including through automated email reminders. Any time freed up as a result would be reinvested primarily into greater levels of follow-up activity, potentially enabling additional forms of audit engagement, whilst also improving the service for auditees and allowing more time to assess whether controls had been fully embedded.
· Members noted that both the lack of affordable accommodation and non-compliance with housing duties within Brent featured on the Strategic Risk Register and sought clarification on what a likelihood score of 5 meant in the context of the register. Darren Armstrong explained that these were treated as separate items within the register and confirmed that a likelihood score of 5 indicated that the relevant risk was considered very likely to materialise.
· Members sought to gauge whether the direct access provided to the Internal Audit Team by the Chief Executive had improved the effectiveness of the function and whether a positive cultural change was developing across the Council in response to audit findings. In response, Darren Armstrong confirmed that the Internal Audit Team had been provided with improved access to both the Chief Executive and the wider Council, and that the function was aligned with the organisation’s direction of travel, producing positive outcomes in terms of risk improvement and audit efficiency. The team was stated to now sit on a number of governance boards, ensuring that management intelligence informed audit strategy, and provided regular updates to the Corporate Management Team. Corporate Directors were also reported to be finding it easier to hold Heads of Service to account, with concerns now being raised more consistently at the right levels and at the right times.
· Members observed that organisational resilience was identified as a new overarching theme in the plan and asked whether training would be provided to members to assist them in asking the right questions to support this agenda. In response, Darren Armstrong outlined how the Audit Team worked with Brent as an organisation to add value, improve resilience arrangements and strengthen governance and control. Changes had been set out in a scoping document, seeking to define what would be undertaken for each risk, how it would be approached, and the precise nature of the assurance the team would provide. Service area controls, IT systems and business continuity arrangements would all be reviewed to ensure, for example, that payments to vulnerable residents could continue during any period of system downtime. Where arrangements were not found to be in place, Darren Armstrong confirmed that the Internal Audit Team would work to support their implementation.
· Members wished to know whether vehicle reliability had been incorporated within the scope of the audit listed as RB25, which explored SEND transport, as this had been reported to them as a significant operational issue. Officers confirmed that the scope of that review had not yet been defined but that the points raised by members would be noted. It was also noted that organisational resilience was intended to be a collaborative and collective exercise, with the team’s intended scope drawn on business continuity methods.
· Concerns were expressed regarding the likelihood of lower-priority audits receiving coverage. In response, Darren Armstrong confirmed that items designated as priority 3 might not remain at that level throughout the year, given the plan’s flexibility and the regular reviews undertaken to adjust priorities in response to new developments. Items could also be progressed earlier if capacity permitted, with any changes communicated to the Committee.
· In relation to the Renters’ Rights Act and its implications for homelessness and housing demand, Matteo Biondi (Deputy Head of Assurance, Brent Council) advised that, whilst the Act was expected to reduce homelessness in the longer term, a surge in evictions had been observed in advance of the legislative change taking effect. The current impact on private landlords could not yet be fully assessed, but this would be incorporated into the scope of the relevant audit. Darren Armstrong added that these were matters under active discussion with wider Council management.
· Members raised concerns regarding the Council’s telephone lines, noting that residents had reported waiting on hold for over an hour before being disconnected, and asked whether an audit into this issue could be accommodated within the current programme. In response, Darren Armstrong confirmed that this was possible. The Internal Audit Team would seek to determine the scope of improvement work currently planned, the improvements proposed and how assurance could be provided regarding their implementation.
In closing the discussion, the Chair noted that demand seriously exceeded resources in a number of the areas under consideration and emphasised the importance of the Committee’s oversight role in driving improvements. The Committee then RESOLVED to:
(a) Consider and note the Internal Audit Plan for 2026–27.
(b) Note the Internal Audit Strategy 2024–2027 Year 2 Review.
Supporting documents:
-
11. Internal Audit Plan and Strategy, item 13.
PDF 270 KB -
11a. Appendix 1 - Draft Internal Audit Plan 2026-27, item 13.
PDF 610 KB -
11b. Appendix 2 - Internal Audit Strategy 2024-27 - Year 2 Review, item 13.
PDF 881 KB