Agenda item
Internal Audit Annual Report 2025-26 (including Annual Head of Internal Audit Opinion)
- Meeting of Audit and Standards Advisory Committee, Tuesday 16 June 2026 6.00 pm (Item 7.)
- View the background to item 7.
This report summarises the activity of Internal Audit for the financial year 2025-26, including an update on work completed since the previous updated provided in December 2025 including a summary on delivery of the Internal Audit Plan, key findings arising from audit work, and the extent to which agreed management actions have been implemented.
The report also provides the annual audit opinion, provided by the Deputy Director Organisational Assurance and Resilience (Head of Internal Audit), on the adequacy and effectiveness of the Council’s framework for governance, risk management and control, which is used to support the Council’s Annual Governance Statement.
Minutes:
Darren Armstrong (Deputy Director Organisational Assurance and Resilience) introduced a report from the Corporate Director Finance & Resources which outlined the activity undertaken by Internal Audit during 2025-26 (and work undertaken since the previous update in December 2025) and included the Annual Audit opinion provided by the Deputy Director Organisational Assurance and Resilience (as Head of Internal Audit) on the adequacy and effectiveness of the Council’s framework for governance, risk management and internal control used to support the Annual Governance Statement.
Members were advised that the report provided a consolidated overview of Internal Audit activity during 2025-26 including delivery of the Internal Audit Plan, key findings arising from audit work, and the extent to which agreed management actions had been implemented. The Chair advised that questions on the Annual Report would be taken first, followed by separate consideration of the Head of Internal Audit Opinion.
In considering the Internal Audit Annual Report (as detailed within Appendix 1 of the report) the Committee noted the following key points:
· The ongoing scale and complexity of the Council’s operations with Internal Audit continuing to deliver its work through a risk-based and flexible approach enabling the function to balance the need to provide assurance over core systems and controls while responding to emerging risks, organisational priorities and management requests. As in previous years the 2025-26 Internal Audit Plan (approved by the Committee in March 2025) had been structured across four components: Core assurance- providing assurance over key financial systems and fundamental controls; Agile risk-based work – enabling responsive coverage of emerging and priority risk areas; Consultancy and advisory work – supporting management in strengthening control design and governance and Follow-up activity – confirming that agreed audit actions had been implemented and embedded. Members were reminded that the approach outlined had been designed to reflect Internal Audit’s move towards a more agile and risk-focused model, ensuring that assurance activity remained aligned to the Council’s evolving risk profile while maintaining appropriate coverage of core systems.
· In terms of the approach outlined, members were advised that the Internal Audit Plan had therefore been designed to address key risk areas identified with the potential to impact on delivery of the Council’s objectives, drawing on the Strategic Risk Register, prior audit findings, sector intelligence and consultation with senior management with delivery of the Plan providing assurance across a broad range of areas, including - key financial systems; high inherent risk areas; ICT and cyber controls; major programmes and operational services as well as cross-cutting corporate functions such as procurement and contract management. At the same time, the plan had also retained flexibility to respond to emerging risks and priorities which had enabled Internal Audit to undertake additional work, including advisory reviews and management-requested assurance, where this has been identified as beneficial, with the Internal Audit structure including the ability to utilise external specialist expertise through the ongoing co-sourced provider arrangements providing a structure able to cover the full breadth of council risk.
Taken together the programme of work had been used to inform the Head of Internal Audit’s opinion, alongside insights from follow-up activity and other sources of assurance across the Council with further details on the outcomes delivered, including individual audit findings and assurance opinions, set out within the Annual Report in Appendix 1 of the report.
· In terms of the programme of work delivered during 2025–26, members were advised that a total of 53 reviews had been completed during the year comprising 11 core assurance reviews; 12 reviews of key inherent and emerging risk areas; 4 school audits; 5 consultancy and advisory engagements and 21 follow-up reviews, which it was felt had provided a robust and comprehensive evidence base to support the Head of Internal Audit’s annual opinion. The reviews had resulted in a mix of assurance opinions being provided, with the majority concluding moderate or limited assurance reflecting the focus of audit work on higher-risk and more complex areas, where control environments were typically less mature or subject to ongoing change. This work had also resulted in a significant number of improvement actions being identified, including high and medium risk findings requiring management attention with members advised that 100% of audit recommendations raised had been accepted by management, which it was felt had also demonstrated a strong commitment to addressing identified issues.
· In terms of Follow-up work, this continued to remain a key component of Internal Audit activity. During 2025–26 this had involved 90 actions being followed up. Whilst this had resulted in an overall improvement in implementation rates to 79% within original timescales, members were assured that performance (with a focus on high-risk actions) continued to be closely monitored with a small number of actions still identified as overdue. Whilst these were not considered significant in aggregate to the overall control environment, it was felt they demonstrated the importance of sustained management focus to ensure timely implementation of agreed improvements and need for ongoing monitoring by the Committee to ensure any control weaknesses identified, particularly in relation to higher-risk, complex or cross-cutting areas, were addressed.
Whilst noting that the Annual Report had identified the Council as having a sound framework of governance, risk management and internal control, it was recognised that areas for improvement remained. Whilst seeking to address these through management action and improvement programmes it was noted that Internal Audit would also continue to monitor progress in addressing identified issues in order to provide ongoing assurance, advice and insight to support and further strengthen the Council’s governance and control environment.
The Chair thanked Darren Armstrong for the report along with the internal audit team for their work over the year recognising the level of activity undertaken and outcomes achieved within the resource available before inviting comments on the outline provided of the Internal Audit Annual Report, with the following issues raised by the Committee:
· Members raised queries on the overdue health and safety compliance actions identified within Section 9c of the Annual Report; with officers explaining the delay had related to a cross-cutting review of the Council's corporate health and safety arrangements and management capacity, with progress now being made and updates to follow.
· Moving to the subject of the four findings relating to children's safeguarding as part of the core assurance activity undertaken during 2025-29 (as detailed in section 5c of the Annual Report, officers were asked to explain why each had been rated medium rather than high risk. In response, officers explained that risk ratings were determined according to a defined methodology considering factors such as the presence of mitigating or compensating controls, management's response, and other sources of assurance (including Ofsted's more detailed, targeted review of this area) as a result of the issue raised officers agreed to provide further clarification as part of next Internal Audit Plan update around the basis on which the summary of findings from the Core Assurance (inherent risk) audit work undertaken in relation to Children’s Safeguarding had been classified as Medium Risk and on the associated assurance process.
· Further clarification was provided on the meaning of the assurance ratings used (substantial, moderate, limited and no assurance) and on the follow-up process associated with each. Officers explained that limited assurance ratings, typically driven by a higher number of high-risk findings, resulted in prioritised follow-up of those high-risk actions together with a fuller end-to-end review of the area to address underlying root causes, whereas moderate assurance findings were followed up on a more piecemeal basis specific to the issue identified. Officers also clarified that the summary of follow up actions detailed within section 9b of the Annual Report for each audit completed in 2024–25, set out the number of actions agreed with management and the number subsequently implemented at follow-up.
· Follow up questions were asked about the significant weaknesses concerning financial sustainability and the self-referral to the Regulator of Social Housing referenced within the basis of the Head of Internal Audit Opinion. Officers confirmed these had previously been reported to the Committee by External Audit (Grant Thornton) and had subsequently been referenced within the Annual Report as part of the evidence base for the Head of Internal Audit opinion rather than as new matters. In noting that the areas identified had been subject to regular monitoring by the Committee, members were assured that progress in addressing the weaknesses identified would continue to be monitored as part of the Committee's work programme and through the Annual Governance Statement.
· In highlighting the increase in high-risk findings raised within individual audit reviews, details were sought on any longer-term trends identified with officers responding that year-on-year comparison was difficult given that different areas were audited each year, and that the increase was not considered a cause for concern in itself, since this reflected the risk-based focus of the audit plan. Having acknowledged the concerns identified, however, officers advised they would review the future presentation of trends in relation to the issuing of Limited Assurance opinions and High Risk findings as part of the Interim update on the Audit Plan in order to provide further clarification against the context relating to the risk based nature of the internal audit approach and their relationship to the Council’s overall governance arrangements and system of internal control.
· In response to clarification being sought on the Limited Assurance and progress in addressing High and Medium Risk findings as an outcome of the risk-based audit activity relating to Deputyship/Appointees, officers confirmed that a comprehensive improvement plan was in place on which a further update would be included as part of next Internal Audit Plan update.
· Members noted the summary of consultancy and advisory and School Audit activity delivered by the audit function during 2025-26 as detailed within sections 7 and 8 of the Annual Report with members advised that the selection of schools for audit remained a collaborative process with in Children’s Services based primarily on Internal Audit's own risk assessment (operating on a semi-cyclical basis), informed by factors such as time since the last audit, changes in headteacher or business manager, and recent Ofsted outcomes.
· The structure of the Internal Audit function was also outlined as comprising a small in-house team (the Head of Internal Audit, a Deputy Head of Assurance and three principal auditors acting as in-house subject matter experts for the Council) supplemented by a co-sourced provider for specialist areas such as cyber security and financial management which it was considered represented the most effective structure for covering the full breadth of council risk.
The Chair then moved on to the Head of Internal Audit Opinion, noting the importance of assurance to the Council. In presenting the opinion, the Committee noted:
· As detailed within section 10 of the Annual Report, the Head of Internal Audit had been satisfied that the work undertaken by Internal Audit during 2025-26, as well as wider governance arrangements, had enabled a “reasonable assurance” audit opinion to be provided on the Council’s control framework, risk management and governance arrangements, which had been consistent with the opinion issued in prior years.
In noting the basis of the opinion provided, which had been primarily supported by internal audit activity undertaken during 2025-26 the Committee were also advised of the limitations identified given it was not possible for the Plan to address all risks facing the Council and represented the deployment of a limited audit resource. In addition, it was recognised that the assurance provided could never be absolute given the difficulty in internal audit being able to identify and address all issues and weaknesses that may exist and the responsibility for maintaining adequate and appropriate systems of control residing with management as opposed to internal audit. In outlining the basis of the opinion, the Committee were also advised of the other sources of assurance which had been considered which included the Corporate Peer Challenge, External Audit Annual Report, Procurement Peer Review, counter fraud activity and assessment of the Council’s framework of governance against the Delivering Good Governance in Local Government guidance.
· In determining the annual opinion, the Head of Internal Audit had considered which key themes from audit work undertaken in 2025-26 could be enhanced in the future to better support the Council’s governance, risk management and internal control frameworks. The areas of improvement identified as a result had been detailed within section 10 of the Annual Report and included:
o The need to ensure a complete and accurate asset register was maintained to ensure robust financial reporting, effective asset management and compliance with CIPFA requirements given the substantial and diverse property portfolio held by the Council which underpinned service delivery, regeneration activity and income generation and significant weaknesses previously identified in the governance and control environment supporting the Council’s two key registers: the Finance?led Fixed Asset Register (FAR) and the Property?led Property Asset Register (PAR).
o The ongoing work being undertaken to strengthen the governance and assurance of the Council’s housing compliance responsibilities following the self-referral to the Regulator of Social Housing.
o The need to ensure (given the scale and cross?cutting nature of the improvements identified as required) consistent implementation of the Procurement Improvement Programme across Directorates to achieve the intended benefits.
o The need to maintain a focus on cross-council ownership, collaboration and control integration in order to strengthen cross?council collaboration, clarify single?point accountability for shared risks, and embed second?line oversight more fully into service?level processes as operational complexity and delivery pressures continued to increase.
· The Head of Internal Audit’s opinion had concluded that the Council’s governance, risk management and control arrangements were generally adequate and effective, with some improvement required with the opinion forming a key source of assurance supporting the Council’s Annual Governance Statement.
Having once again thanked Darren Armstrong for presenting the Head of Internal Audit Annual Opinion, the chair then invited comments, with the following issue raised:
· Details were sought on the level of strategic oversight in terms of breaking down departmental silos and improving cross-council collaboration. Darren Armstrong confirmed this remained an area of ongoing focus, with work already underway across the Council (including through the Local Government Association Peer Review) to improve collective ownership and address gaps, and that Internal Audit would continue to report where target dates were missed for this reason. It was asked whether these cross-cutting findings influenced the following year's audit plan with officers confirming that the degree of collective ownership of an area was now one of the risk factors considered as part of Internal Audit's ongoing risk assessment when allocating resources.
With no further issues raised, the Chair once again thanked Darren Armstrong and the Internal Audit team for the work undertaken to deliver the Plan whilst also recognising the ongoing challenges and risks identified involving not only core assurance activity but also identified through the more agile risk based approach, including the ongoing focus on issues relating to the second line of defence and implementation of audit findings.
Having commended and welcomed the update provided the Committee RESOLVED to note:
(1) the outcomes of the internal audit work completed in 2025-26.
(2) the Annual Internal Audit opinion on the adequacy and effectiveness of the Council’s framework for governance, risk management and control.
Supporting documents:
-
07. Internal Audit Annual Report 2025-26, item 7.
PDF 225 KB -
07a. Appendix 1 - Internal Audit Annual Report 2025-26, item 7.
PDF 1 MB