Interactive webcast player

Audit Committee
Thursday, 30th July 2026 at 7:30pm

 
Share this agenda point
Share this agenda point
Share this agenda point
Share this agenda point
Share this agenda point
  1. Webcast Finished

and audit processes. While the Committee is politically balanced, its work is non -partisan
and apolitical, with members focusing on oversight, accountability and good governance rather
than matters of policy. Members of the Committee, please switch on your microphones to confirm
your attendance. Councillor Critchard. Thank you. Councillor Anna Marie Critchard,
Tooting Beck Ward Labour. Councillor Barron.
Councillor Barron, Wandle Ward Conservative. Councillor C Davis.
Hello, good evening. Councillor Davis, Bessie Park Ward Conservative.
Councillor Hampton. Good evening, Councillor Hampton, West Partney Ward, Conservative.
And Councillor Worrall. Good evening, Councillor Worrall, Shaftesbury
and Queenstown Labour. I have present one independent member, I think
the other member may be on the way, but Alexander Priest.
Yes, Alexander Priest, independent member.
We have a number of officers present who will introduce themselves once they address the
committee with papers.
Suggest declarations of interest.
Are there any declarations either of a pecuniary, other registrable or non -registrable interests?

1 Declarations of Interests

Okay, no.
Where are we?
And that's it. So I will start with the second agenda item, which is the minutes. So I'm

2 Minutes - 11 March 2026

just asking members, are the minutes of the meeting held on the 11th of March agreed as
a correct record? One second, Councillor Warrell. I appreciate that we have new members here.
So Councillor Barron, Councillor Davies and Councillor Hampton, this is your first Audit
Committee meeting.
Yes, just an action in the minutes before we sign them off.
There was a correction that was asked to be made in one of the documents in terms of changes
of legislation and a new Act to be named.
Can I just get confirmation that that was done?
Sorry, say that for the last bit.
On page three, one of the papers referenced GDPR 2018, which should have been updated
to Data Use and Access Act 2025.
The officers said that they would change this in the paperwork.
I just want confirmation that this has been done.
Councillor Warrell, yes, thank you.
I'm Andrew Hamilton.
I'm the head of the South West London Audit Partnership and I'm here representing Paul
Gelotti as the Audit Committee's Chief Audit Executive.
Yes, so the correction was made but the report hasn't been republished but when we next use
that report the template is updated so we'll make sure it's correct going forwards.
So can we confirm that the minutes are accurate then?
Okay, thank you.
Okay, agenda item number three.
Sorry, Chair, I know it's a very hot room, but it's also now very noisy.
I just wondered if it's possible for us to turn the air con down a notch.
Yeah, and I'm beginning to think if I'm...
It's probably affecting my eyesight because I didn't see your hand up either.
You just weren't looking at me.
Let's see how it goes for the next, I say, 20 minutes or so.
And if everybody could just speak a little bit louder down the microphone, it might help
as well.

3 Update on the Accounts and External Audit 2025-26 (Paper No. 26-178)

So agenda item number three, update on the accounts and external audit 2526, paper number
26 -178.
Are there any questions from the committee members?
And I think I will introduce EY, who is a representative here.
Good evening, Chair.
My name is Adrian Bama.
I am the Senior Manager with EY, who are the External Auditors for the Council.
Before you tonight, we have got our external audit plan for 25, 26.
I'll just take the committee through a couple of key items within the report.
I'll take the report as read so I won't go through the whole report.
I'll just pick out a couple of areas.
So page 13 of the public report starts with a couple of different areas.
So we talk about the preparedness for audits.
The scope of the...
Excuse me.
I think you...
We're going to have problems because our pages are numbered from...
Sorry, Jen, I'll let you do it.
I think there's been a slight, in terms of the papers, some of the pages are numbered
differently.
Okay.
So maybe if we go via maybe the heading.
Yeah, I was going by the public report, the ones on the website.
Yeah, but I think some of them have been printed.
Yeah, this is the same, the numbers are the same I think.
So I would suggest that you read out the titles.
Yeah, you go by the titles.
Yeah, okay.
Okay, so page 13 is the headline title is the 2526 Audit Strategy Overview Rebuilding
Assurance, page 13.
So we just highlight a number of different areas that are relevant to the audit.
So one is just around the preparedness for the audit.
The scope of the audit is just a reminder we do the council, the value for money conclusion,
but we also do the subsidiary, which is the Winstanley York Road.
In terms of the timeline, that's further detailed in section 7, but in principle we've
I started the audit in July, we're working through to November with a view to kind of
conclude it and get the opinion issued by December, which will be a significant improvement
on last year and in line with the backstop requirement, which is the end of January 2027.
We just confirm at the bottom of page 13 our independence. And then on pages 14 and 15
is the kind of stunt of risks that we've identified for the audit for 25, 26. The good news is
that for this year our risk assessment essentially hasn't identified any new risks relevant for
the Council.
I'll just talk the Committee through these at high levels.
So the top two are two fraud risks that we identify.
These are kind of consistent across all of our audit plans.
Effectively they're in line with auditing standards and talking through the presumptive
risk of management override control.
The other one is around risk of fraud and revenue and expenditure recognition.
And in the right -hand column where we have the details, it talks you through kind of
the approach we'll take to kind of address those two risks.
We then move on to the valuation of land and buildings,
and we have a number of risks around
the different classifications within land and buildings.
So at the bottom of page 14,
we have the valuation of land and buildings
valued under existing use value and fair value.
And again, on the right -hand column,
we give the details of how you will approach
and address that risk.
And then on page 15, we move on,
and we have a number of different valuation risks
against a number of different areas of property plant equipment.
So the top of the page is risk around the valuation of investment properties.
Below that we have a specific risk around the valuation of the HRA with a focus on council
dwellings and a kind of restatement that needs to happen within the 25, 26 accounts and is
presented within the draught financial statements as presented for audits.
And then at the bottom of the page, the valuation of land and buildings specifically around
depreciated replacement costs.
And again, we detail in the right -hand column our approach to those.
And then on page 16 at the top is the valuation of pension assets and liabilities.
Again, this is consistent with the prior year.
And again, in the right -hand column, we talk through the details that we'll do in terms
of addressing the risk and the approach we'll take.
At the bottom of page 16, it's just important for the Committee to realise the materiality
we work to.
So the materiality is 21 .5 million, and that's in line with kind of agreed thresholds we
use.
So the 21 .5 million is calculated at 1 .8 percent of the audited revenue expenditure in the
24, 25 accounts.
We'll recalculate that based on the draught accounts that we've just received.
It's gone up slightly to about 22 .5 million.
So we just detail there in the bottom of page 16 the relevant thresholds and what we'll
report back to you.
And then the other page I wanted to touch on was page 17, which is in, talks you through
our approach to value for money.
So in line with auditing the draught financial statements, we also need to give an opinion
on the value for money conclusion.
Three key criteria, essentially.
So one is around financial sustainability.
The next is around governance.
And the last is around improving economy efficiency and effectiveness.
In the middle column along the bottom of that page, we talk you through any risks we'd identified
for 25, 26.
So just specifically on the financial sustainability piece we just touched there around the fact
that the latest MTFS highlights a number of pressures, obviously, in terms of the latest
funding review and some of the kind of service pressures.
So again, we'll do a piece of work just around the financial sustainability.
Governance, we had identified a risk last year around the critical findings in terms
of the report from the social housing regulator.
Again, we'll do a follow -up on that in terms of the 2526.
And then currently we didn't have any risks identified in terms of the last criteria,
which is improving economy efficiency and effectiveness.
I'll stop there and I'll take any questions that any other committee may have.
Councillors, anybody would like to answer a question?
If you can just raise your hand and then I'll introduce you.
Okay, Councillor Davidson.
So, thank you very much.
So I've got a couple of questions, but I'll do one because I'm sure others have got
ones as well.
So, I was just interested in your audit process.
You don't mention using AI tools as part of that.
So I just want to understand the extent to which you'll be using AI tools or not
and just making that clear and transparent to the committee
because obviously that can in and of itself raise risks.
I'm sure it's got benefit for you in terms of efficiency.
You'd be welcome to talk about that too.
But perhaps you can just describe if you will or won't be using AI tools and if so, which?
Yes, so we've invested quite heavily as a firm internationally using AI, not necessarily
in the audit itself, but some tools in the background.
So we'll automate some processes that previously would have been done by lower level staff.
For example, one of the areas that we can now do using some AI is around your draught
financial statements.
So essentially it's 160 or 190 page document.
We can use some AI tools to help us do that analysis in a kind of really efficient and
detailed way and the output from that will then feed into officers to kind of help them
where there has been maybe inconsistency between certain financial statements.
So that's the kind of main extent that we're currently using AI.
Obviously we still have some other functionality with things like Microsoft Copilot is an area
that kind of we work a partnership with Microsoft.
So we do use Copilot quite regularly within the team to things like, for example, if we
an internal meeting we can kind of use copilot to do the transcribing for that and give us
an output which is kind of really efficient. So those are the kind of key tools. So it
will potentially change significantly over the next few years but I think at this stage
that's the kind of level we're currently at with AI.
So to be clear in terms of the final report that you provide you won't be using AI as
part of writing that?
No. No.
Councillor Crenshaw?
I still do that.
I have some other questions, but what Councillor Davies said is quite interesting.
How then, if you're using AI to analyse our financial statements, will you be assured
yourselves that AI hasn't done anything daft? Because it does have that propensity.
And sometimes if you're doing, you know, unless it's been fully tested or you're running,
you've asked the correct questions, you can get an interesting and rather different answer. And I
hate us to be in a position where AI said something and the accounts aren't actually
quite like that.
I think to be clear, all we're using AI for is really data analysis on the financial statements.
We're not using them in any way to do any kind of judgments or assumptions.
So essentially all we're doing is taking the financial numbers as they're presented and
using AI to help us with an output, which gives us then a starting point.
That will always be checked by someone like myself before it actually goes back to officers,
so there's no risk that there will be any kind of false misrepresentation from AI.
I can also share with the Councillor various different, sorry,
I was going to say Alex independent member,
I can share with you some kind of materials as well within the kind of wider
accounting industry from like our audit regulators where they've kind of issued
reports on kind of how AI is being used in the industry,
which is kind of accounting firm agnostic as well,
just to give you a bit of insight into
what other firms are actually doing as well.
I can share that material afterwards.
So, Davis.
That's great, actually.
It'd be great to share that perhaps with the entire committee.
So, my next question is just in terms of costs.
So, the costs have gone up quite dramatically.
Part of the reason I'm asking for the AI question
is obviously to understand the sort of hallucinations
that we may or may not get, which is just exactly as Councillor
Critch has said.
But the other reason for asking, of course,
is how you see that reflected in the efficiency and the cost.
So the costs have gone up a lot.
So I'm sure you're able to explain.
So perhaps you could just, for the committee,
explain what's underlying in that significant increase.
Yeah, so the costs of the audit aren't actually
decided by ourselves.
They're obviously set by PSA here, an independent body.
At the stage, the PSA reset the five -year fee, so effectively the contract was then
retendered on a five -year cycle.
They then looked at the requirements of audit, which had changed significantly since the
last five -year period.
And obviously, when they reset the next fee after five years, they'll obviously be looking
at use of AI, maybe as an example to say, has AI significantly increased the efficiency
of an audit, and then is there an impact on cost?
But again, the reset at that point in time, where you'll see a significant uplift, for
for example, from 21, 22 to 23, 24, was really a reflection of the market at that time, and
that was kind of the kind of general trend across all elements of the public sector.
We saw, you know, upward fees as a result of a lot of additional work that auditors
needed to do, and actually the work we now do and the kind of demands of auditors and
staff as well has kind of significantly increased as a result of a number of changes to accounting
standards, for example.
So could I opportunistically say that maybe we see the fees come down in future?
Before I take the next question of Councillor Hamilton, I just wanted to mention that the
independent Ilver and Fontaine Kanna is online virtually, so just in case you wanted to come
in with a question as well.
So Councillor Hampton.
Lovely, thank you very much.
Yeah, I also noticed that the fee had jumped enormously.
My question is actually about how many people
can actually do this, how many firms are we talking about?
So we're effectively talking about procurement here.
So I would like to understand how many you can
actually choose from and I would like to understand
about the benchmarking when you're doing that exercise.
Thank you. Catherine Burston, Director of Financial Management, leading the Council's
audit, sorry, accounting team and the relationship with EY as our auditors. So back in 2021 or
22, we had the opportunity to opt in or out of the PSAA procurement for external auditors.
At that point, the council opted in to that procurement where PSAA had a number of firms
who were able to provide the required audit standards for local government
and PSAA actually awarded the auditor for each council.
And EY was appointed as our auditors from 23 -24 for a five -year period
and that's since been extended for another two years.
So we have EY until 2930.
It's a, I understand that at that point in time,
a full options analysis was undertaken
and PSAA were our most efficient route for providing the service.
And most councils did opt into that.
PSAA completed a full procurement exercise
is to make sure it was providing value for money.
So basically that's no choice.
I just like it minuteted that I raised that.
Alexander.
So like, I'm actually in order to myself for another firm.
And what I would say, the levers on an audit fee
typically are maybe two.
Rather than AI, and I can explain this after the meeting
and give a bit more kind of insight to that.
Like, I am seeing huge efficiencies in certain pockets,
but it just depends on clients.
So we can discuss maybe whether you're offline,
where they're focusing it.
But risk assessment, if you really refine
your risk assessment and what's key to the council.
So the materiality figure here,
I see that you're using 50 % haircut
to your overall materiality,
therefore that's likely to increase sample sizes
and it will increase sample sizes
to your actual departments as well.
So potentially, I don't know whether that's because
of errors that you're actually seeing.
So whether than taking 25 % haircut, sorry,
a 50 % haircut, you can move to a 25 % haircut
and save money there.
And one other thing is I'm not seeing any kind of,
we've got a term in the industry and you may have it as well
of not significant but material.
And that's where you've got line items
which are probably not risky,
which some firms may go into a lot of depth and test it
just because it's above those materiality thresholds,
but in reality there isn't actually much risk there.
Now inherently cash and so on will have that,
but my challenge would be have they considered
some of that from a risk assessment standpoint
to maybe increase efficiencies and reduce the fee
because there are other demands on the industry.
Yeah, so the 50 % threshold we've used
is a reflection of the prior year errors
and also the fact that there was
exclaimed opinion issued in the prior year.
So our assumption is that those errors
would continue into the next year until we kind of get to a point where we're kind of
comfortable that the error on the expectation of errors would have reduced significantly.
Thank you, Chair.
Just a request, and this came up last year as well when I was on the committee, just
as a reminder that we have people watching who might not be auditors themselves, not
necessarily understand the jargon that's actually involved, and it would be useful sometimes
rather than making an assumption that people do understand what you're saying, is to not fall back on in -house jargon
and that she explains some of the principles actually involved. It just helps the transparency in relation to the process.
Thank you, Councillor Worrall. That was a good comment.
Councillor Critchup.
Thank you, Chair. I've got a couple of questions. As we're on the
fees, I'll ask the fees question, and then I'd quite like to go back through to start at the start of the
at the start of the paper. But on the fees, so the scale fee has gone up 320 %
over what it had been, what it has been, and we expect, EOI are obviously
expecting to ask for additional fees this, for last year and probably more for
the next year, sorry, for this year coming. What do we think the additional fees are going
to be? And actually this leads on from what Mr Priest has been saying is, is there any,
what steps are we taking to manage audit costs? And I think we've just been offered one and
I'd be interested to hear both from our auditors and also from Catherine Burston about her
thoughts on that.
So, our starting point is that the assumption is there would be no additional fees.
There would be no additional fees.
So if you look at the fees section of our report, it kind of makes the assumption and
says that if we receive working papers which satisfy all of our requirements, so we're
able to address queries first time around or kind of with very little additional input,
then the core fee should settle what we need to do.
The additional fees we've done in the previous years have always resulted from the fact that
we've had to do either there's been lots of errors in particular areas or we've had to
lots of additional work and some areas we needed to go back multiple times.
So actually that's kind of what drives the additional fees.
So our assumption and starting point would always be that unless something new significantly
develops on the audit which we haven't reported to you, then that would drive additional fees.
But the starting assumption always would be that if we get all of the working papers to
the level that we require, we get the input from staff that we require and actually we're
able to kind of deliver the audit as efficiently as possible, then the assumption would be
that the core audit fee as it was kind of originally presented to you should be sufficient.
So that's kind of always our starting point.
So we're not building additional fees and anything we do,
bill as additional has to go through PSA, it's moderated,
it's benchmarked against other firms, and that's kind of the process
that we go through in terms of fees.
I just wanted to, just before Catherine comes in,
I just wanted to add, I think Councillor Critchard is mentioning,
there is mention within the report around additional work,
which is going to give rise to the additional fee,
and I think it's the additional, what that additional work was going to be,
because it's already been mentioned.
So the additional work hasn't been agreed.
So this is part of the build back process
to kind of get us away from a disclaimed opinion.
We've been in contact with Catherine today
to kind of say that we'll sit down with both teams
over the next few weeks to look at that
and actually if we believe that that isn't cost efficient,
then we won't do the work.
That's kind of the principle we're working to
and that's what we communicate with Catherine today.
Thank you.
Oh, sorry.
Thank you.
I think it's comforting that the initial point is that the scale fee should be sufficient,
particularly as we are now in a new procurement period where the original fees have been added
on now to the scale fee to reflect the changes in legislation and the additional work that
is required from the audit.
We obviously want to get back to a clean opinion for our audits and the additional work to
move from a disclaimed opinion up to that.
We have provided, we have put the additional resources
in from the officer's side to provide
the additional requirements and data and information.
And we are working together with EY to work through that.
And we hope to do that.
As I said, as we've said before, any additional fees
do go through PSAA.
And we always challenge them.
And we do say, are these really additional requirements?
It is quite difficult to understand what the audit firm has assumed to be appropriate working
papers when we feel that we have done a lot of work in improving our working papers to
make sure they are up to standard to provide all the information required so that there
isn't extra work by the auditors that they would then come back and charge us for.
So we are working really well together to try and reduce those additional fees, but
inevitably it's an audit firm that will need to cover if there is additional resource that
is required, but we're working together to make sure that's minimised.
Just to kind of reassure the committee, so we spent a lot of time, as Catherine said,
so we did a training session with the whole finance team where we went through all of
the kind of issues we identified in the prior year. We came up with project plans that are
really kind of detailed and kind of will kind of get us to a point which is more efficient.
So we're really working well together, I would say, in terms of both teams, and there is
a real desire from both teams to get to a point where actually we don't have lost
additional fees and overruns and we're actually able to kind of deliver the audit as per the
timeline and we can all move away. Officers can move on with their day job and we can
move on to other audits that we need to do in different sectors.
Just wanted to bring in Elva Fontana because she's got a question.
Hello. So my question would be on the financial liability risk. I see that in the value for
report but I don't see that in the rate as a significant risk and you know with
all the pressure now do you still consider is not a significant risk for
once worth thank you
so I can address the question on that one so essentially financial
sustainability is separate from the financial statements so it sits as part
of our value for money work.
So we have identified that there is a risk,
but it's not a financial statements risk.
It's a value for money risk.
So the risk distinction is different between the two.
Yeah, so what do you mean by that in simple words?
Is it not a going concern risk?
Is it not a risk that we will run out
of money in the immediate future?
How many years do you consider, three, five,
and can you make it more explicit?
Yeah, so as part of our value for money work,
essentially we need to look at certain elements of the Council. One of them is their financial
environment they are currently operating in and obviously the medium term financial strategy
is a key element of that. We did look at the refresh that was done in September 25 last
year. That obviously kind of pictured a really kind of difficult forecast in terms of fair
funding review 2 .0, pressure on budgets, pressure on reserves. So in line with our requirements
under the NAO Code. We then need to make a risk assessment. Do we see that there's actually
a potential risk of significant weakness there? If we identify a risk, then we need to do
additional work. We would then look at that additional work, and we would then make a
number of inquiries to really do a detailed review of the MTFS and the key assumptions.
And then we would make a judgement at the end of that. Is there evidence of weakness in
arrangements, which is our ultimate conclusion? And if there was, we would then report that
back through the committee. So it's very, very different from a financial statement
risk where we have defined audit procedures where we would test a number of assets or
a number of liabilities. This is a very different piece of work and it's kind of in line with
what we need to do under the National Office Code.
Okay, because I have seen in other councils that where they are really struggling and
they will have a deficiency in like two, three years' time in the budget, that becoming
a significant risk in the audit report, but you think that risk is remote for us for now?
No, I'm saying we've identified a risk, but we need to do the work to identify if there's evidence of weakness and arrangements
Okay, and then you will
reconsider that
We will we will report back to this committee in November and give you our conclusions
And that will then take into account the leaders to MTFS, which will be published in September 26
I think Catherine was just going to come back on that as well. Thank you chair. Yeah, I just wanted to reassure that
Although that's not picked up in the financial statements as a risk, it's in the Council's
risk and is in a paper later on the agenda as part of the risk register.
So just to cheque timelines, you'll come back in November, and in November, by the point
that we've just heard, you'll give us a view about the value for, as part of the value
for money part of the audit, you'll give us a view around financial sustainability, et
et cetera, but the medium -term financial strategy is coming two months prior to that, correct?
Yes, so the medium -term financial strategy will be refreshed in September.
So we'll review September refresh in September 26, and we will do a number of pieces of work
across that, looking at key assumptions, and we'll do a really detailed review.
We will then make an assessment of our review and make a conclusion.
The conclusion will either be that we believe the assumptions within the MTFS based on the
information available to the council are reasonable, or we will let them, if the converse of that
is true, we would then have evidence of weakness and arrangements and we would report that
back to this committee back in November.
So just for clarity, sorry to hold the mic, but just for clarity, when we hear your report
in November, that will be referring to the midterm financial strategy that's published
in September this year?
Yeah, great.
Right. Thank you.
I'm just going to say I find it slightly tricky as we've been moving around the papers.
So can I start with the questions that I had from the beginning?
On page 4, paragraph 5, the independent local audit office,
it does actually say we've had no update.
I just wondered if there is any even vague whisperings in the wind about what might happen
about that and where we could see it and what the effect will be for us.
That was the first question.
I've got some more.
Thank you, Councillor.
I have heard since this was published that the Government have appointed a chair.
That's as much as I know.
We don't know any more about it or what they will be doing, but a chair has been appointed
to that body.
And once the chair's been appointed, we've just got no idea after that.
We briefly talked about the timeline, which appears in paragraph 10, but also in the audit
itself.
I just wanted to confirm particularly our side's view on how we're managing for that
timeline, whether we've got everything ready and we should be able to meet the deadline
simply because obviously this has been shoved.
We're reporting a month earlier than we did last time, so it's obviously very tight and
I've heard that you've said that you're very confident you've been giving everyone the
right pieces of paper.
So a bit more on that, please.
Rishi Sharma, Corporate County Manager.
I think we have confidence that we've got resources in place to be able to deliver this plan.
So we've got a fully staffed team. The audit's obviously started, so testing's commenced.
And we've been working very communitatively and cooperatively with our EY team.
So it's obviously early days in the audit, but I think we would say we're in a good position, things are on track.
and yeah I think there's confidence that we can deliver to the plan.
Are there a number of questions Councillor Critchard?
Okay but I mean I don't know if anyone else has them. Right picking up on
something you said Mr Bamber and Mr Bamber could ask you really please would
you be able to speak slightly more slowly for me? We talked about the
materiality and one of the things that I think it I can't remember which page it is
but we are actually asked as an audit committee to confirm that we've understood the materiality and that was around the
20 .5 million and various other bits if someone could give me the page that we really helped Claire's good
Yeah
Yeah, so could you?
And tell us a little bit more about that so that if we're going to confirm our agreement
we fully understand what we're confirming.
Yes so materiality is kind of an audit, a key audit principle.
So effectively the 21 .5 million that we've identified there.
Talking audit terms.
Yeah.
So essentially, anything under 21 .5 million, for us, to put it in a layman's terms, is
under a threshold that we would consider not to be significant for the users of the financial
statements.
So based on the size of the Council, we would say that anything under 21 .5 million, based
on audit thresholds, which are kind of recognised internationally and we kind of apply a range,
we would say that actually we would report back to you anything over 21 .5 million would
be kind of considered to be significant.
In terms of errors, which is kind of another key area of the audit, we would report back
to you again anything over 10 .7 million, which is our 50 percent threshold.
Again, we'd consider that to be significant for the users of financial statements, but
also equally for you as a committee.
On the right -hand side, we also then identify a number of different areas, which kind of
are more sensitive.
These tend to kind of revolve around a number of different areas, so things like related
party transactions.
Exit packages is an area which could be particularly sensitive.
And again, with those, we tend to work to a much smaller threshold.
That's kind of done on a judgement basis within the audit team.
It could be as low as 50 ,000 pounds, for example, on an area of an exit package, which obviously
we wouldn't operate to the 21 .5 million because most of the – obviously all of the exit
packages wouldn't be at that level.
So we want to make sure that anything that's particularly sensitive to taxpayers or you
as a committee, that we've actually done a rigorous piece of work at a much lower threshold
to really give you the assurance that anything that's considered to be significant or sensitive,
we've actually reviewed it in a kind of different light from the $21 .5 million.
But looking at your core financial statements on the balance sheet or the income and expenditure
statement, the $21 .5 million is what we would consider to be significant for both the users
of the financial statements and us as auditors.
Hold on one second.
Is that cumulative or individual transit?
So we would look at a line by line basis.
So we would take your balance sheet for example, we would break down properly planned equipment
into the different classifications that we've got for those and identified in the risk assessment.
Another area might be your debtors for example.
So anything that would trigger anything over 10 .5 million or 10 .7 million, we would consider
that a significant account.
We would then do audit procedures which would then address the risk or address that particular
significant account.
And then we would kind of work that down to make sure we've covered all of the balance
sheet and the kind of relevant primary statements.
Just before you come in Councillor, I don't know if Mr Priest wanted to come back in.
Was it a similar question on this train or?
It wasn't necessarily a question.
Can you hear me?
Sorry.
It wasn't really a question, it was just a point of anything, just to be very clear,
reported to this committee, anything below one million will not be reported to this committee.
Anything above that threshold will be reported to this committee and then they'll look at
all the errors in aggregation.
Now if this committee determines that in fact one million is too low of a threshold, that
rarely five million is more of an area
which you care about, then they do need to take
into consideration what the public
and what this committee actually will need.
So sometimes it's done independently as a firm
and they assume, but what is really critically material
to you and the committee as an individual?
Because the 10 million is pretty much
a internal threshold for EY to determine sample sizes
an approach, whereas they offer a reasonable assurance opinion.
So if you look at the financial statements, their opinion says in real terms that they've
set this threshold which is material to both the public, uses the financial statements
of 21 million and can give reasonable assurance that it's not misstated to that level.
And that there are no material frauds that there are in that sense.
Just to be clear we'll report correct differences over the 10 .7 million
Uncorrect, there will be everything over a million
Council, sorry
Thank you, just picking up on the 21 million figure for somebody watching on the outside
That's a scary that's a scary number and I notice in the in the original paragraph you say it represents 1 .8
But I suppose it's in comparison to other councils around us, are we operating on a
similar level or is it higher or lower than how other councils would do in terms of their
aptitude for this sort of level?
It just helps the general public understand what that actually means.
Because as I said, it's a huge number and if somebody watching who might think, oh my
God, you know, that's a lot of money.
Yeah, of course, and when I first started auditing as well, materiality was something
which was completely, you know, blew me away.
But essentially, if you think that the Council has expenditure of well over a billion, you
know, we would then kind of do that calculation, and I appreciate the number can be large.
For example, some of the NHS trusts we do have got, you know, materiality would be three
times of that because they might have expenditure of three billion.
I appreciate it as a large number, but it kind of puts into context for us to kind of
say on a 1 .5 billion of expenditure,
what is significant and relevant?
And we think that's probably the relevant amount
that we would kind of say is material.
The second part of the second part?
Counts.
Can you just repeat the question, the second part?
The second part was in comparison
to other local authorities and in terms of the aptitude
for the risk associated with that.
Are we higher or lower or comparable?
I think within London, the range across London
will be fairly consistent, I would say.
I do this one on Richmond, which I
know is kind of less than that.
But that's just basically a reflection
on the size of the council.
So I would say you're probably in the middle.
There are obviously some councils which are larger.
The materiality would obviously be larger as well.
So I think it's just a circumstance.
And obviously, once you move outside London
and go into some of the smaller districts,
you could be talking 3 to 5 million.
So really it's relevant just to the size of the organisation.
Just as a reminder, could you direct your questions towards me so I can kind of, everybody
can get a chance because I'm getting hands and everything and eyes and things.
Anybody else with any questions?
Councillor Critchard then.
Thank you.
Okay.
Thank you, Steve, because that was my follow up and you've got it.
Page 41, this also leads into how we're going to manage the audit.
The EY have given our teams various RAG ratings for how things have been going, and we've
got quite a lot that have improved from previous year but still requires improvement.
And I would like to know what do our teams need to do to get to green, because I'm pretty
sure if it's all green that means everything's going to work very smoothly and perhaps maybe
it's Ms Burston who could one of the team could answer both sides could answer that one for me.
Yeah I can take that one first actually so I think this last year was the first year we did
this rag written and I think it's you know on a one page it's quite powerful I think so it kind
gives us a real sense and stand back. As reflected on there, there are a number of areas where
the Council had made significant progress from the previous year, but there just wasn't
enough progress to kind of put it into the green category. And I think we've taken a
number of actions this year which are kind of clearly designed to try and push that into
green on all those areas. So as I say, we spent half a day with the finance team going
through a really detailed training session. Internally, there's been a number of pieces
is the work that has been done to try and improve output and just kind of efficiency
on the audits.
And even yesterday we were on a call with Rishti and his team where we spent an hour
or so looking at kind of the project management of the audit, how we really control the key
aspects of the audit to really make it efficient.
And I think generally our assumption would be if all those things work and we're able
to deliver what we both agreed to, then when you see this coming back to you in November,
hopefully there should be a lot more green on there.
And that would be credit to the finance team for actually kind of working really diligently
through some of those areas to kind of make the improvement leader where we've kind of
identified that in the past.
Yeah, so I would obviously echo a lot of that.
I think the other thing I would say is obviously the identification of these areas requiring
improvement.
We do have amongst the team a review of what went well the previous year, what perhaps
could have been done better the previous year.
And that's really focusing on the things
that may have caused or contributed
towards these RAG ratings.
So we take those kind of points forward,
and then we look to really focus on how we can actually
make those improvements in the current year.
So a lot of those points are centred
around the delivery of working papers and particular things
around timeliness, and also pinpointing particular areas
where the quality of the working papers
could have been a little bit better to kind of facilitate
a quicker process.
So we've definitely taken some particular kind of time
to address those things as a team.
And I think so far, hopefully Adrian will echo this,
that things have been provided on time.
We've been working very proactively
to try and make sure things, we work on a portal,
so everything's got a date by which things
have to be submitted by.
And we basically have quite a, as I said earlier,
collaborative process where we're regularly checking in
with Adrian and his team to make sure things are on track.
So I'd say, obviously, it's, again, early in the process,
but I think there's confidence that a lot of those RAG ratings
will move along this year.
Councillor Davies.
Yes, so just to join the dots then to cheque I understand.
This is like a leading indicator of these additional fees
that we talked about earlier.
Is that right?
So obviously, this is last year's data, isn't it?
but you've started your month in -ish to the existing.
So do you have the rag for the currently,
and what's that looking like?
Just out of interest?
It's too soon to do that yet.
So essentially the first month of the audit,
we've really been sampling.
So we effectively spend the first month or so
doing a really detailed sampling.
And then from August, we kind of plan to move into testing.
So it's too soon to kind of say, yeah,
because essentially we've just been working through queries
in terms of samples and data analysis.
Councillor Mitchell.
Sorry, I was just about to say, just to thank Ms Bursfield and the team for obviously the
thought and hard work that's been going into trying to improve things to make the audit
run more smoothly this year.
I'm sure from the whole committee, please pass that on.
Thank you.
Aye.
Is that the end of the questions?
So I can pose the recommendations.
The recommendations asked for the Audit Committee are being asked to note the completion and
publication of the final audited 24 -25 accounts, that's A. B is note the publication of the
draught 25 -26 accounts and Ernst & Young's audit planning report at Appendix A. And also at
see the fees update in paragraph 13 to 16. Are you agreed or agreed? Thank you. Thank
Thank you.

4 Annual Governance Report 2025/26 (Paper No. 26-179)

Okay, we're moving on to agenda item number four, which is the Annual Governance Report,
2526.
I think that is Andrew.
Thank you, Chair.
So this report brings together two related but quite distinct pieces of statutory assurance
work and for the benefit of the committee, these reports are both backward looking.
So these cover the period 2025 -26.
First of all, it presents the annual internal audit report and the chief audit executive's
annual opinion on the council's governance, risk management, and internal control arrangements.
And second, it supports the committee's consideration of the draught annual governance statement, which is attached at Appendix B.
And subject to approval will be signed and published alongside the council's accounts.
These are both important annual assurance documents that help this committee fulfil its responsibilities for
overseeing the effectiveness of the council's governance arrangements.
And for members who are new to the committee, the important point is that these reports are about assurance.
They aren't saying that there are no weaknesses.
They are assessing whether the council's arrangements are operating effectively and
identifying areas where further improvement is required.
The overall opinion, the overall audit opinion is that the council has reasonable arrangements in place for governance, risk management, and internal control.
And that opinion is based upon the work completed by the internal team during the previous year.
The follow up of previous recommendations made significant issues reported to committee and
relevant assurances obtained from other sources.
The annual governance statement opinion is that the council generally has effective governance arrangements in place.
So, whilst this is positive, it's not a completely clean bill of health in every area.
The reports do identify a number of significance, governance issues, and
specific audit findings that require continued management attention.
And the key question for the committee this evening is whether the annual internal audit report and opinion and
the annual governance statement provide a fair, balanced, and
evidence -based assessment of those issues and the actions being taken to address them.
So I think in summary, the overall assurance opinion remains positive, but
So there are a number of significant governance issues and
specific control weaknesses that management continue to address and monitor.
And I should note that assurance is never absolute.
It's only based upon the work that we complete during the year.
Action plans are in place to cover all of the weaknesses that have been identified and
this order committee will be provided with continued assurances during the 2026,
27 year to close that gap in terms of control weaknesses.
I'm not going to talk anymore about the reports because they're quite long.
I guess I would just summarise in terms of the annual internal audit report.
It also covers the work of the internal audit team during the year.
It sets out whether we've met our KPIs in terms of delivery of the audit plan.
And it gives you some detail around the significant recommendations that have been made during the year.
But I'm happy to take any questions.
questions from the committee. Councillor Hamilton.
Yes, thank you very much. I'd just like to refer you to, so we talk about page 71 on
number 35. So, this is about deferment due to service restructures. I'd just like you
to expand a bit more on that because that's quite a number of things, including all the
So it's quite a lot.
Can you just sort of expand on what exactly that is, why it happened, and will it happen again?
Sure, yeah, thank you for that question.
So the audit plan has to remain flexible.
So it is based on risk.
We produced the plan, we bring it to this committee in April and that sets out at that point in time the intention of the work we're going to complete.
The reality is we work in an organisation that's changing.
And when we come to complete a piece of work, if that department is going through a significant reorganisation,
or they are implementing a new system, actually that's not helpful for us to do that work at that time.
So as well as officers not having the time to devote to us and answer our questions,
if there's going to be a significant change, what we ought to audit at that point will change shortly afterwards.
So we will be giving an opinion on something that we know is going to change.
So it makes more sense for us to come in after those changes have been completed and audit
at that point to give an opinion or an assurance on the actual arrangements in place once they've
been finalised.
Yeah, but we're talking about the commercial management waste, community infrastructure
levy, section 106.
So section 106 and the SIL are sort of fitting together.
But these are quite big areas.
As I said, I just want to understand what the problem was, why there was a delay.
Well, the problem was the changes in the service areas.
It would have been unhelpful for us to go in at that point due to changes being made.
But what I would say is that the audits weren't cancelled, they were deferred.
So they are in this year's plan.
So we will still complete the work and we will come back to the committee with updates
as those pieces of work are completed.
I suppose whilst we look at an annual period for the assurance opinion,
the reality is we also look back further, so we might look over the previous three years.
If systems haven't significantly changed, then there's less value in us auditing something, or we get less out of it.
So we are interested in whether there's been a significant system change, and if there has been, then for us it's appropriate to delay that piece of work.
But I understand there's a requirement for us to report to this committee where there have been changes to the audit plan,
because it's a plan approved by the committee, and that's why we set it out in detail.
But you'll also notice, for instance, there's been a significant number of additions to the plan as well.
And that will be either where we've had time made available because of deferments,
or it's because something else where the risk profile has increased, and so we want to defer work to enable us to do high risk pieces of work.
But it is flexible and you will continue to see that as we report through the through the forthcoming year
And we'll hold your feet to the fire
Just following on from councillor Hamilton Hampton's question
Is there scope to do like an advisory review when you're in that sort of situation whereby it's not a full -on order
But you're still in there
Advising and looking at the plans that are being proposed to be put in place
Yes, definitely.
So, for instance, when it's a new system, we like to be involved at that stage.
And there are a couple of pieces in this year's plan that were, in last year's plan, sorry,
that were added.
Even myself or Tanya, who's the audit manager, where we've sat on boards where there's been
new computer systems implemented.
So where we can give advice around control, design of control in a system itself, then
yes, we want to be involved.
There isn't always capacity to do that with our team, but where we can, we will.
I had Councillor Worrall, then Councillor Davies, and then Councillor Bowern.
Thank you, Chair.
I just want to comment and want to request.
Just as a comment, I am the sort of person that actually likes to see timelines clearly
mapped out in a table for different activities.
It's really to do with layout with papers like these, is that lots of timelines are
buried in here, and you have to really rummage around
to find them.
Just as a suggestion for the future,
if there are actions that need to take place or activities,
as there are several named here, if we could have a timeline
through the year so we could actually just
get an overall picture of what that actually looks like.
Because also it helps us understand
where the pressure points might be.
Because things will slip.
There's no doubt about it.
Nothing keeps the time.
But if we had an understanding, even
if it's just a very basic Gantt chart or something like that, that would be really helpful just understanding the context of this data takes place.
So that's my suggestion.
I've also got a proposal for a change in the governance statement.
But I'll wait to the end of all the questions before I come back on that one.
Thank you, Councillor Davies.
Sorry.
Sorry, Councillor Wall, thank you for your comment first of all.
Can I just get a bit more detail in terms of the timelines that you're specifically
looking for us to record?
Yeah, when I look through here, there's several reference areas where, for example, work activities
taking place.
So, there's a recommendation of due dates on page 79.
Yet, when I go to look at other things that's actually happening around some of the other,
like building control, et cetera, and work that needs to be done, it's very unclear to
know when that's actually due or when it will actually come back.
So just simple things like that.
Thank you.
So I would be supportive of that.
I think at a minimum, again, a chart of when the audit is planning to take place, but also
as what Councillor Wall was saying.
So then also maybe just another change to pick up on my colleagues' point is you give
a general statement here on 35, page 71, about the reasons for things being deferred that
were picked up. But there's not a by item reason. It will exist, but it isn't written
here. So I actually think that would be useful to help understand, I don't need to answer
it now, but why these specific items and likewise why specific things were added in. It doesn't
It would be useful.
Yeah, I can see why there would be a benefit for the committee for that.
I'll take that away.
My concern off the top of my head would be that we get into the nitty gritty of discussing whether a specific audit should have been cancelled or not.
And whether the committee thinks that's a reasonable conclusion.
But I think I'll take it away and see what it looks like in the next report.
Thank you.
Councillor Barron.
So just on page 70, per 30, so in the similar theme too, I mean obviously 60 of the audit
reviews out of 61 have been completed, which is 98%, above the target of 90%, which is
Very good.
And this, obviously, that is good, but can we get a bit more detail on, and I apologise
if I missed this at some point in the papers, but what is the one that has not been completed?
Oh, gosh, so there's not a straightforward answer to that question.
This is one of those audit KPI things, isn't it?
So we have a certain number of audits in the plan.
The reality is that with the additions and cancelations and changes, that number shifts
through the year.
So it could even be that it was one of the additions that got cancelled in the end.
I think the point I would stress is that the performance has been really good.
Although that said, it might be more important for the committee to understand whether the audits that were completed were the right ones.
Or whether they completed the right quality rather than just the numbers.
But it is a KPR we have, so we do like to report when we've exceeded it.
So I've got Miss Kanna.
Yeah, I've also noted that the agreed implementation date is not stated for all the key findings.
And for me, the buildings control and the inspections are quite key.
So yeah, my proposal as well would be to just have an agreed implementation date for all
the key findings of the list.
Yep, thank you.
Noted.
I guess the only other thing I would just say, well, actually, first of all, my colleague has reminded me that in Appendix A,
I think we do give a more detailed breakdown for each individual audit as to why it was cancelled.
So there is more detail in the report.
I think the other thing just for me to note, I suppose, is that this is a summary of work completed last year.
And when we bring up date reports, we will give you more detailed information about recommendations,
when they were made, and what the implementation dates are.
But it doesn't, but I think that, and I've made this from my own back, haven't I, by
including it in some places and not in others.
So I'll take that point away.
Thank you.
I think, I think we've got to remember that because this is a government statement, it
wouldn't necessarily have that level of detail.
But I think that the information that we're requesting here, I think definitely we should
be calling to actually look at that further.
but in terms of the actual statement itself, because it could get quite big,
but definitely for us to be asking that question to get the additional information
and probe a bit more in the meeting.
So I've got Councillor Crichard next.
Thank you.
Yeah, like everyone else, I noticed the lack of the dates.
But perhaps one thing for our new colleagues is to say is that those of us who've been,
there is a point in the cycle where we see what audits are planned for the next year.
And so we've seen that and obviously because your Councillor Hedges is doing other things
and Councillor Caddy is no longer with us, that information isn't there and perhaps
we can point you in the right direction to where this was set up, which would help when
you were looking at this.
Moving on from the audits, there's a couple of things I wanted to pick up on the ones that you've said.
On the SILL, particularly Section 106, I was quite interested to know what will be audited,
because one of the things that we as a council have to do is look at income generation.
And therefore, if we're not getting SILL money, we should have.
So are we going to be looking at that with the opportunity to improve our income collection?
And I'd say the same thing applies for the building control inspection.
So I was looking at that thinking, there's a fair bit of money possibly around here.
And for me, if we need to improve our income generation, I would hope that would be happening very quickly.
So I'd be very interested separately if you could let us know when that's going
to be sorted out. And I think that sort of must be a theme is income generation.
And then the last thing, where was it, there's something else around that. Oh
yeah, and the only other thing I would comment is that one of the things that I
I appreciate from an officer's point of view you're looking at it as an auditor.
But when we're talking about the telecare and billing there,
I think we should be very mindful that not getting this right can affect some of our very
vulnerable users who may then be faced with a big bill at some point that they can't pay.
And we need, I think, part of that is I'd just like to note that for
for the committee and for other people watching is that is also important.
And hopefully the service will be picking that up.
And I think I'll probably add, I think a load of the adult social services
audits were postponed last year, weren't they?
Because we had CQC inspection.
And obviously the office is working to that at the time, which is why those ones have been postponed.
Just before you speak, Mr Habat -Zun, I think Tanya wants to come in as well, so I don't
know if you're...
Hi, good evening. My name is Tanya Kalaji. I'm a manager, a chancellor. So back to looking
at revenue, one of the priorities on all our audits is to make sure that we also look that
the revenue is collected, where it should be collected. We have three priorities. One
One of those is collection and being visual that we really do.
And if you look at it a little bit through the thematic of our findings this year, you
can see that we are quite often talking about the fees.
We are talking about the income that should be collected and brought to the council.
Secondly around the comments about the telecare, I absolutely agree.
And one of my comments back to the oddities at the exit meeting was about also sensitivity
about the residents.
and we shouldn't be really ever waiting for very long to be built.
To October, we will be bringing our audit recommendation and finding tracker,
which you probably remember is a table where we say what are the findings and where we are.
And at that point, we will be also reporting on the billing that being closed in terms of the telecare.
Thank you.
Mr. Preet?
Which question was?
My question was going to be related to kind of like when are we going to be presented
with the resolution, the timescales of these audits and key kind of focus matters.
But I think that will come to the committee in due course.
Hey were there any other questions?
So the committee are...
Sorry.
One other thing that I did have was, do we hold the right skills from an internal perspective
around cyber and other kind of technology to support the actual audits?
Because looking at this, there aren't that many deficiencies necessarily in that area.
is does the department actually need more support
in that sense?
And like do they need extra funding
with everything coming through?
Because Mythos and various different other kind of
like platforms out there,
which are becoming more widely available,
I mean I think complaints could increase for instance
because people have more access to AI
and they're able to send a complaint far more easily
than they would be previously.
and also spoofing and there's a lot of different risks
out there which wouldn't necessarily have previously
been on my mind a year or two ago,
but are we going to be ahead of the curve there
in planning what skills do we need to bring
into the department and do you need to get extra funding
and hopefully this committee would support that.
Thank you for the question.
We don't, I mean, yeah, the short answer is
we don't have the required skills in the in -house team
to audit cyber security, which is why we outsource that to
for -vis -mazals through a framework agreement we have.
So we hire in specific IT auditors to do that level of work
where we aren't able to, you know, have standards.
Quite clearly say that we shouldn't be completed
in audit work where we don't have the expertise
to do it ourselves, so we buy that in.
And we also have the option to buy in agency workers with,
again, with a specific skill set.
It's an area where we probably need to do a bit more work.
We do look at cyber security regularly, but obviously it's not just one audit, it's a number of different areas that we would be looking at.
I don't think we need any more resource at the moment. We are reasonably lucky with the size of the audit plan, because it's a combined one between the two councils.
We have enough resource at the moment to do that.
Yeah, I'll stop there before I say something I don't want to.
Thank you.
Well, I'm going to ask this question in the next agenda topic around organisational learning.
This for me would be a great example of something where when we think about the risk management
framework and how the insights from the audits that you're doing are fed back into the organisation
and the members, because I think the spoofing idea and the things that you've already mentioned,
And I would recognise some of that coming my way.
Any other questions?
Okay.
The Audit Committee are asked to...
How's the world?
Yes, sorry, Chair.
It's the second part of the proposal.
Can I take the Committee to page 95, please?
And the third paragraph down.
The paper that we have in front of us is an analysis of the previous year.
I feel that this paragraph in here is actually inappropriate to be placing in this particular report.
As it's a commentary on now and moving forward, which is not part of the statute paper.
Also, it is also inappropriate to be naming a particular counsellor in this particular paragraph
in relation to activities.
And also the last line is at this moment in time, as we have no overall control and we're
still in negotiations around different things, the decision -making and constitutional mechanisms
are not fully operational.
So that cannot be a truthful statement in terms of this.
So what I would like to propose is in relation to this appendix is that paragraph gets removed.
If that paragraph is removed, I am very happy to support this.
If not, then I am not happy to actually sign this off.
The third paragraph down saying, following the May 2026 local elections.
Mr. Hamilton?
Yeah, I suppose a point of clarity, I suppose.
So the SITF Redendem that came out last year required us to consider forward -looking issues
in the annual governance statement as well as looking back, which is why that's in there.
We considered it to be a significant governance change.
I do agree, actually, that we should take out names.
We shouldn't name people in there.
But I think it is, and actually, I guess the other point is,
that in terms of timing issues, this continued to be updated
all the way up to the wire of issuing.
But actually, things are quite fluid at the moment.
So I'll take out the names.
Yeah, I think, I'm trying to think what the best way is to move this forward.
So I think we've got some time before the accounts are signed off, which is when it
needs to be signed.
So I will go back.
I'm also conscious that this is a report that, it's not just my report, right?
So this goes to, this is an executive director sign off.
So I'll need to take it back at that level to get the, any changes agreed or discussed.
Just one question though.
I think if we are waiting and given that it is mentioned by election, so that date may
pass as well, so then you've got even a further update.
I think more than anything, I think it's about agreeing that that paragraph is amended and
the Councillor's name removed.
I don't know if you're happy with that.
Sorry, just to respond.
I am not happy with that.
What is contained in this, the rest, the whole paper is a process discussion that's actually
taking place and a good one for people to follow through.
This is actually partially political in relation to this.
Also the last line is factually not accurate.
And it won't be accurate for a considerable period of time because the OSCs, et cetera,
are not operational.
So therefore, I cannot support that.
And so, which is a shame, because the rest of the
statements is really good.
And what's contained here is a neutral approach to this.
But this one actually, I think, is loaded with so much.
And I think it sits inappropriately with this.
Councillor Hampton and then Councillor Doudna.
I would say that this is factual.
I absolutely agree with you that no Councillor should be named personally.
I think that that is right.
But as far as I'm concerned, this is factual.
And as you said, this is a slightly rolling move, so I would support this.
And this is coming from the Executive, so it is not really for us to choose or not to
choose.
Councillor Davies.
Yes, so again, support the point about removing the names.
I think I'm sure the author will reflect that probably in retrospect that probably wasn't
so wise.
On the point that you're raising about the governance, I guess what it, you know, the
governance is listed in a page and a half of text, page 2 of 18 and a quarter of page
3 of 18.
This outlines the governance of the Council, covering the point about what is the general
role of OSCs, what is the general role of Cabinet.
So I understand where you're coming from with sort of the interim, let's say, arrangements,
but when you read that line together with this, I'm a bit struggling.
So, yeah.
So, quick chat.
Thank you, Chair.
I think it's probably also worth remembering that actually in, from May 2025, we changed
our governance arrangements.
One of the, because from May 25 to 26, the roles and the review of, the roles and remit
of the overview and scrutiny committees changed from what they had been previously.
Now, I think that this report doesn't actually reflect that.
And our problem at the moment, it doesn't say, I mean, I would have liked to have seen something saying,
these functions changed quite significantly in this year and some reflection on what happened in the previous year.
And I appreciate that obviously you three are new this year, so you won't have, you may not have, yeah.
But there has been a change, there was quite a significant change in the way we operated our overview and scrutiny committees.
So I think that's the -
clear collegiate on this. I said it had changed. I didn't say anything about the
arrangements that it has changed, right, and there was not a reflection of this
here and one of the complications looking forward I would say is because
we haven't had any OSEs and we won't have any until September, I would say
that is probably a governance risk, right?
Because there are things that won't have come through.
So I suggest I would be very supportive of what Councillor Worrell says about,
well certainly we obviously all agreed that names should never have been in there.
And I think that it would be quite helpful if that stayed out,
because actually it says pending outcome continues to operate within its established
constitutional governance framework. Actually we didn't operate in quite the same way as we
would have done normally so maybe if that goes that just is quite helpful.
Okay so I've got Councillor Warren, Councillor Quisti, obviously wanting the paragraph and I
I do understand why there is a need to,
one second, there is a need to, or,
sorry, yeah.
Did you want to?
Sorry, can I understand your opposition to not changing,
because, sorry, I've heard this side's kind of approach
to actually wanting to actually remove that.
I'm impartial either way, to be honest with you,
because I'm not inside within the council.
I don't necessarily see what the kind of changes
from a governance structure
and how it's operating internally.
I think on the face of it,
if there is serious opposition to this statement,
it leads me as an independent member
who doesn't see the day -to -day running of the council
question whether that is actually factually accurate or not.
So, either way, I'm not approving the statement.
I would just, as an independent member,
like to understand your position to not changing that
and why you see that it's currently operating effectively.
So, I was a councillor for eight years
and stood down in 2022.
And the OSCs was very much how we adopted
the way that we dealt with democracy.
That was changed to become much more executive.
Now, I wasn't a councillor for the last four years.
So I'm saying that it is factually incorrect really because that was something that the conservative side
Objected to from a democracy point of view from our point of view so which is a valid
Argument and that's just factual that's that's noted
I wasn't actually here
But I know that that was the case so I think to twist this around when it's been presented for us is unfortunate as I said
I absolutely agree that the name of the council should be removed.
I don't think that is relevant or healthy, but the rest should stand.
I think at the moment we have, I mean, we do have a governance structure,
but it's just leader in cabinet in terms of the RSCs that hasn't been decided on.
And I think if that, I mean, taking what I'm hearing from, obviously,
Councillor Royal and Councillor Critchard and obviously onside,
there is just the first level of that governance structure.
Do you agree with that?
Because we've got cabinet and we've got leader,
but it's the OSC element that isn't part of the governance structure
which you would expect to be because that was what was in place previously.
Councillor Davies?
Well, if I'm honest, I think that this section needs to be taken away together with pages
two and top of three, and it needs to reflect the arrangements in place. I think the challenge
that's being raised is that there's been an interim arrangement, I'll use that word, I
but this perhaps doesn't reflect an interim arrangement.
And obviously things are fluid, as you rightly point out,
but this I guess the bit that we're missing in this,
this is an annual governance statement.
Is this, this is written on the basis of the year ending March 26th,
but you have, you're required to give some kind of forwards.
I just, it's just muddled given that we're in an interim state,
And I feel that given that, the author should just reflect that appropriately.
Councillor Woll.
Ousey -dosey, I am prepared to suggest a compromise in this,
that the first part of the statement stands,
and the second part of the statement from in July 2026 onwards gets removed.
because the first part of the statement is factually correct.
And I think that's...
And that there is, you know,
that is a good reflection of the situation that we're in.
So take out...
Take out everything from in July 2026 onwards
for the rest of that paragraph,
but the first half of the paragraph stays.
I would be prepared to accept that as a compromise.
Any comments?
Kate, would you like to take this to a vote?
I think that because this is something that hasn't happened, I accept that as long as
we keep the first bidding.
Are you content with that?
Yeah.
Yeah, I think because it hasn't happened.
So you're happy to take that?
Okay, so we're agreeing to retain the first part of the paragraph and the paragraph which
begins with in July 2026 onwards to the end is removed.
Just take it out.
Thank you Chair, I think that's the first time we've had a good discussion about the
in your government statement, so that's helpful.
So what I will do is I will suggest that amendment
to the monitoring officer and the chief executive.
I assume that they will accept that.
And then we will get it solved on that basis.
If there's any disagreement between officers,
I'll come back to the chair to see what the way forward is,
I think.
I guess my only question, and this is really,
you will, I'm sure, include this in your comment,
is when you, Councillor O 'Rourke, raised this point about the fact that it was forward -looking,
you answered by saying, despite the fact this is a government statement until the end of
the fiscal year, the financial year to 26, that there's some requirement to place some
forward thinking. So I guess my only kind of comment is one of policy, I guess, is if
this is removed, does it make it deficient in some way? I don't know the answer. So please.
Yeah, if it doesn't, then fine. But I would like to understand from that point of view.
I think to add to that as well, I think is there like the appetite in terms of what is
entered in in terms of what the forward looking it's a decision that you just make or is it
it's not complicit to say, oh, I have to put this specific power. It could be anything
across the whole governance thing?
That's right, the guidance is really broad and not specific.
So it is up, you know, this is the Council's annual governance statement, right?
And it's written by me initially, but it then goes through challenge by executive directors.
And then it comes to committee for sign -off.
And so it's right that it's discussed, and it's right that actually senior officers
and this committee get to have an input into that, because it is the Council's,
it's not my statement, right?
So I've written it based on how I interpreted the guidance,
but removing that paragraph from my,
it won't affect the validity of the statement,
it won't mean that we haven't complied with anything.
Councillor Worrall, then Councillor.
Thank you, my question is more a practical one.
Hey, so you'll come back to us,
can we get a timeframe for when that might be?
Because obviously, if it is a while,
then the subject changes.
So the other point, I suppose, that's relevant is that up until the point that the statements
are signed, the financial statements are signed, there is a requirement to continually review
this document, which is unhelpful in some ways, but that is the reality.
I'll go back to Chief Hostess tomorrow and ask for comment, and we'll get back to you
as soon as we can.
I don't envisage that it will be a long, drawn -out process.
Hopefully it will just be a quick discussion and as I said, I'll report back through the
chair if that's okay.
Councillor Wyl.
Thank you, Chair.
I'd just like to also put on record, this is the first time that we've come together.
This is the first disagreement that we've had.
But also say a big thank you to Councillors Baran and Davis for agreeing to the compromise
and working through this.
appreciated. Okay, let me go back to the recommendations.
So the Audit Committee are being asked to note the Council's statutory annual review
of its governance arrangements. That's A. Is that agreed?
Yeah. B, note the annual internal audit report incorporating
the Chief Audit Executive's annual opinion on the Council's governance risk
management and internal control arrangements and approve the proposed annual governance
statements for 25 -26 in Appendix B for signature and publication with the Council's accounts.
We have agreed amongst us that the last paragraph on page 95 from July will be removed. Is that
agreed all recommendations agreed. Thank you. So it was quite a detailed conversation discussion

5 Strategic Review of Risk Management (Paper No. 26-180)

around the governance statement. So the final paper for this evening is gender number five
strategic review of risk management paper number 26 to 180. And the officer Mr. Holland.
Thank you, Chair. I'm Kevin Holland. I'm the Assistant Director for Fraud, Risk and
Insurance. This report provides an update on the changes that have been made to the
risk management oversight arrangements that seek to increase transparency and assurance
of the Council's risk management arrangements. Please note that whilst these changes have
made to the oversight arrangements, this does not mean that risk management itself is halted,
risk management is something that's continuous, it's an activity excised by managers at all
levels on a near daily basis.
Just to go back over some for new members of the committee, some of the key changes
to our arrangements for the oversight of risk management have been the development or inclusion
of a digital platform to actually record risks. This in turn will give greater opportunity for
more involved analysis and perhaps some support and challenge on individual risk and risk risk
assessments. Other key changes that we have in terms of how risk management is captured
is that we now seek to capture
inherit risk scores and risk appetite scores.
We've started this by
building it at a service head level
and that process is in place and live.
What I would like to say is that when we talk about
risk appetite being something new. It's not new to the Council, it's something new that
we're actually capturing for being able to report back upon. The platform is live at
a service head level and for next week, so through August, I will be taking it to look
to build from the service level returns, service head returns, to build the first indicative
departmental risk registers. So there are four methods that service risks are elevated
up for suggestion to be included in the departmental risk register. These are reviewed by the directors
and executive directors for the department. That process also helps with self -moderation.
Risk management isn't something, this has not been done to the services, risk management
it's something that's done and owned by the service.
This is just giving them a framework by which they can measure and understand where they
are in their risk management situation.
From the departmental risk registers, there is a process where they will then be elevated
up for consideration within the corporate risk register or even amendments to the corporate
risk register. But again, as I said, we've talked about this new digital platform that's
a bottom -up approach. We're not allowed to stand still, so that's why back in November
and January we had some sessions with the exec board and the directors for them to come
up with what they consider to be their key corporate risks, which is attached at Appendix
B to this report.
That is, I would say, an introductory to the new approach of how things are captured.
They haven't had the full opportunity of information that's coming up through the ranks in terms
of what's captured on the platform, but of course they still have those daily monthly
meetings with their service heads and service leads.
So again, their views will have been informed by what's
happening in the services.
It's just that we haven't got the process that shows or
demonstrates that.
I'm happy to take questions.
Councillor Hampton.
I think I want to bring in a number of strands that we've
been talking about tonight.
So digital transformation, completely get it, absolutely
marvellous if it's done properly. My absolute concern, I work in the insurance
industry and I've been doing it for a long time. I've seen some absolute
shockers, rubbish in rubbish out. So my question and I think it's very pertinent
to this committee is how do we know that the digital transformation is actually
going to enhance the offering and that it's not actually going to deteriorate
from what we're doing, because I'm
quite nervous on the back of what we've been talking about.
A difficult question to answer in that we don't know until you
actually give it a try.
The oversight resource that the council
provides for risk management is quite limited.
It's part of my role and it is part of some of the duties that Mr. Giuliani, who also
comes to this committee, part of his role.
And that's about it.
Previously the capture on the other side of that and training given out to service heads,
which is something that's just arranged by the two of us, the returns were collated manually.
So a lot of time and resources taken in to actually get those returns in,
leaving very little time to then go back and...
The word to the service heads is to support them in their assessments
and understanding of the assessment methodology.
In reality, it is to challenge where the challenge is needed.
This process brings in something that helps us in that,
in that it requires the East Department and the directors to actually go and review
and their own self -moderation, both in terms of scores that are coming through
and very much so the understanding of the risk appetite in the different service areas.
The way we started, risk appetite appears as if it's been sort of coming from the bottom up.
I mean, it's never going to be that, but we had to start somewhere.
This will help inform the directors themselves in their perceptions of where they think the
risk appetite should be and their understanding in terms of their key service heads where
there may be differences so they can address and resolve those.
So again, that opportunity to have those discussions I see is of great value in terms of moving
progressively the organization's approach to risk management.
Sorry, I was just saying I think it would be very useful if that was brought back to
the next committee so that we can track what is happening and whether it's working and
whether there are glitches in it.
Thanks.
Thank you.
thinking about any possible viewers who may be around, perhaps we could just have a bit
of clarity about the difference between corporate risk for the council and the risk register
that we hold of risks for the borough and its residents that's on the website. So I
think I could probably give a summary of it, but I just wondered if we could just make
it clear that they're two very different things is my understanding.
So the corporate risk register has been part of this report so it is a published document.
So is that out there? Are you saying as opposed to risks or objectives?
Perhaps I could, shall I just say, is we have a risk register on the council which is things
like how likely is it there's a major flood, given that's probably the biggest one that
is affected and what we would do about it.
And that is our risk register is held on the council website, but that is dealing pretty
much with external risks, our rating of them and how it works.
whereas the corporate risk strategy is focused on the council itself as an
organisation isn't it and that's the difference between the two just in case
there's any realisation that we're not talking we haven't discussed is there
going to be a flood it is the Thames kind of flood here is that yes the
victory saying that some of those in the emergency planning side they will come
back because they to the corporate issue in terms of resourcing and resource
demands so that's why the way I say the risk register with a build across all
the service level those ones for emergency planning are part of the
pyramid process that feed into informal ideas or suggestions of what should be
included in the corporate risk register and if something like a flooding danger
was at such a level then that could in its own right be a separate key corporate
risk?
I think some of that, what you mentioned, Councillor Critchard, is almost like scenario
planning, so you're kind of looking at the what if in terms of what could happen, and
then sometimes the risks will flow out of that.
I don't mean it, I know it says that on there, but it's probably part of a scenario planning
activity to pull those ones out.
Yeah, yeah.
And if I could, and that would say that, again,
that was part of one of the requested changes.
So the old methodology for the oversight risk management
only looked at the residual risk score,
and we were only interested in things
that were currently deemed to be high risk.
This approach now where we're looking
at the inherent risk score means that
that's, those dangers are recognised,
and therefore the, perhaps, hopefully the process
the time given and resources given to actually thrash out some of those scenarios or even
some of the testing that goes on will be elevated because their voice is heard.
Okay, Mr Priest.
So, I was going to say, just like Councillor Warrell mentioned last time around materiality,
have you done benchmarking against other councils to understand their risks and kind of their
elevation and how that maybe just compares within London as well.
So yes, some of that has been done.
Some of that's been undertaken by our, by my audio colleague, Mr Hamilton, and that's
when we first, probably a year and a half ago, we first looked to improve what we had.
Our starting point was to look at what our neighbouring councils actually do and undertake.
So that that part that has been done and will continue to be used
Yeah, could you maybe share that?
Benchmarking I don't know whether it be with me or this committee afterwards that that'd be helpful for me to understand this whole concept
Counsellor quick, okay, I think it's reference to a previous report to this committee
Was that provided?
Just waiting in case anyone else had it.
I've actually got a few questions, but other people may come in with them.
My question on this is that how will this approach help us avoid silo working within the directorates of the council?
because I think that's something that I know officers have been working very hard to try
and work more across areas, but I don't think we've got it quite right.
And what concerns me is that there's an issue here where if an officer thinks or a director
thinks that this risk might affect someone else, another area, they can raise it.
but how do we manage to make sure that we look at that more broadly,
so it's not down to an individual, but so we can use this and share across directorates?
Again, this is part of what's still being worked through in the development of the online platform.
So previously paper -based returns, they were very much held, returned to me, but held within the
the platform is going to be more widely available so directorates can see what other directorates
are coming up with.
And part of that, and part of going forward once this is embedded, I think part of my
task or whoever is in my role will be to look at those synergies or benefits that can be
held from similar risks across different service levels to see if different approaches have
be applied, whether there's one that is a better way or whether they should be combined
and things. So that is another outcome from being able to move from what was a very dated,
paper -based approach to a platform that could be shared and used by all.
Councillor Bowern.
Just on the online platform, are the mechanisms in place to receive user feedback? I mean,
it said such as it since June,
obviously it's quite a short period,
but are the mechanisms in place for feedback
and have you got any initial feedback
from users straight away?
So we've held six sort of drop -in training sessions
for users and yes, feedback on those
and yes, the email that's gone out to them
is very much that the platform is still being built.
So any feedback from them is very much welcome.
And we have had some good, an example for me, good practicality,
but it's not risk -related, but purely to even some of the accessibility of it,
given the choices of font or colours of bits and pieces we have in some of the drop -downs.
So again, that's all been taken on board and adjusted in phases as we move through.
Just before you answer a question, Councillor, I was just wondering, just when you're talking
about training, how big is the actual team that is working with the Council, but also
are they like champions or local risk advisors in place that support this?
The Council's approach, historic approach, and part of the ongoing approach is risk management
is owned by every single officer.
It's a frontline activity.
That means that the support function,
the review function, as I mentioned,
it's part of what I do.
It's even a smaller part of what Mr. Giuliati does.
And in these changes, yes, I've got support from IT
who are developing the platform,
and I've got a bit of time from one of the graduates
services going through, just to help me through some of the review mechanisms.
That's the extent of it because the bulk of it is done by the managers, the services,
the SMT meetings are going on.
But the oversight capturing of what they're doing is what they are trying to do in a way
that will support them, add a bit of structure, but support and organise what they're doing
and also to, as you might say, highlight areas where perhaps people aren't doing what they should,
perhaps they're not, they think they know it all, know their areas so instinctively,
where perhaps if they just gave a moment to step aside, they might view things slightly differently.
So...
I just wanted to sort of understand a bit more, because you're embedding a risk culture,
so whilst you're embedding, I would probably expect to see that there is kind of a bit more formal training
as opposed to an expectation that if you're a manager or somebody senior that you should
understand and know how to take forward that.
But yes, everybody may know that, but it's just that embedding, if you're going to embed
a culture, I think it probably, it may need more than that.
I'm just wondering about what that is.
If I can, for those bits going forward, so the training and dropping sessions at the
They'd be mixed between people who actually need to understand how they have sufficient
understanding of the risk in their area, it's how they actually enter it onto this new platform,
and those who are new to the Council haven't done any risk returns before, and then having
to, how do they go about identifying what their service key risks are.
What we have going forward is, so look after the insurance as well, we have some extra
days, free training days available from our insurers.
And we're looking for them to actually provide an online training session for the service
manager level in terms of what they need to do and what thought processes they need to
go through in terms of trying to identify what their key service risk areas are, both
at that inherent level, because unfortunately we've operated a while about, say, just focusing
on issues and some of the things I've seen at the moment are managers saying, well, oh,
I haven't got any risks, they're all managed effectively.
Well, yes, you have risks.
You need to identify those.
You need to document the controls you have in place because those controls are working
well, may be available for use in other service areas.
So again, it's part of that ongoing learning process.
Mr. Worrall.
My comments are in relation to the table at the end of the paper, so I'm happy to wait
if anybody's got any substantive questions around the main part of the paper.
Sir Davies, then Councillor Quichotte after.
So it's just a question.
So you outlined in the framework...
Oh, I haven't got to it yet.
So in the procedure, appendix A starting in 117, you talk about different roles and you
obviously, you know, it's your issue as you describe, this is about the, you know, leaders
and managers within the firm, within the council, that's their responsibility.
But obviously the number of services are outsourced.
So I just wondered, there's no, I can't see any mention in here of any obligation of the
person who's, I forget which role you termed it as, I think it's the, is it the, it's the,
the role of the person who has to gather this process together.
Recording officer I think it is in the roles and responsibilities on page 129.
I don't see anything here that says, you know, make sure you consider all the various actors
that are important in delivering that service.
I just wondered, do you think about that?
Is that something, has that come up in the past?
Just an interesting, just out of interest.
It is something that's come up in the past
in that the previous renditions of the council's key risks
have included a risk around contract management.
And our approach at the moment for that
is that for each of these outsourced contracts,
there is an officer who's responsible for it, and it's for them to identify these risks.
Well, what you're saying, and he's shortfall from here, is perhaps an extra reminder to
them in the procedural notes saying, don't forget about, you know.
If I may, that is a good point.
I think, just to cheque, what I'm actually referring to is that the executive officer
who is accountable and gathering, you know, input for the risks to ensure that they talk
to the suppliers.
So not just from a contract management point of view, but often suppliers see risks because
they are delivering the services.
So almost treating them in that instance as if they were an employee of the council and
asking them to participate in some sort of way or at least consider it.
perhaps something to take away and think about?
It is something to take away.
It is, dare I say, that's getting more into running the individual services
and what you are talking about is what I would like to see happening anyway
because as soon as we get back to a manager taking decisions,
well, in order to take decisions you've got to be gathering the best possible information
and if your decision is as a contract manager where the frontline is delivered by
Outsource staff then you got to have some sort of mechanisms to gather what's going on outside there, so
Yes, is it as far along as I'd like it to be?
Probably not so it is something that needs to be developed further
Okay, Councillor...
Thank you. Actually, I was going to say, Catherine, a very interesting point. And maybe if we
have further information around the new contract management system at some point that was introduced,
perhaps that could also be discussed then. But my particular point was this, obviously
because it's corporate risk, is very much focused on the directors, the corporate structure.
What input do members have to this? Because obviously it's the corporate stuff, but it
affects members and also there's a point where there's been discussion about political risk,
for example, which would usually be judged by the members.
And particularly, I sort of felt to myself, I feel anyway,
that I'm going to recommend that this paper goes to Cabinet,
but actually also that Cabinet probably have a regular,
even if it's only annual, update on what the corporate risks are.
Yeah? So I suppose what I'm saying is how do you see the role of members and actually
are we using, does this use members and the cabinet and the political side of the council
as well as it could?
I think probably that, pragmatically or maybe naively, assume that the member lead officer
discussions take place so therefore we should be capturing the members' wishes
through those officers. Again I'm not commenting on whether that does or does not
happen. This report itself as I say is the progress on what we're doing in
changing the oversight of risk management. The reports that this
committee would normally receive would be the full -blown risk management
strategy which again is still, we're not there yet because we're still going through the
change so that's where I would hope it will be there for the October -November cycle but
I have to wait to see where we're at.
And what you get is the actual risk management strategy to approve and then the outcomes
being the key corporate risk and a little bit of analysis of what's been perhaps identified
at a service and a departmental level to give you a flavour of what's risk management taking
place.
So, that's why I said even this report, and so you're allowing it, it's not the usual
report that comes to committee, it's part of this interim process.
But comments for the, whether we should be sending a return or asking a return from members
to complete the online, make the portal open to them for their suggestions, is something
I can take forward.
Yeah, and I think what you said about the part where the responsible cabinet member
should be talking to the director about risks.
I think it probably does happen, but maybe it's something that maybe thinking about how
the process works needs to be explicit plus how the full risks are sent to the
cabinet and the leader.
So it's like a proper... but just having a formal mechanism if that... Sorry yeah and I
think I'll probably comment through the chair is one of the things about audit
committee is that it is it doesn't necessarily get reported to cabinet
because it's a committee that's reports the council directly I think I'm looking
a bit at our committee clerk because she's more okay with that and I think in
the past what we've had to do from this committee if we want the cabinet to see
the papers we have actually had to suggest that it goes to cabinet on to
part there as something for them to review it's mr. priest did you have
You did, yeah.
I mean, I don't know.
I think that's quite a bit of detail.
But one thing that I would say is,
are we documenting these processes
and retaining the processes,
and therefore identifying the risks and controls
in those processes?
Because if they're just identifying risks
and logging controls, then the crux of all of that
to enable someone to make a decision there,
as to whether that control is relevant
and we need to test it and so on and so forth.
It is kind of undermined if firms and your organisation
doesn't retain detailed documentation there.
So I've seen that in many organisations
where they kind of have control matrices or risk matrices,
but it doesn't directly align to process.
So, again, part of the platform is that BUILD will capture that if the residual risk score
is still above the risk appetite, it means further work is still required.
And that's either in terms of changes to process, changes to activity, or getting a formal risk
acceptance that whilst the activity is above what the risk concerns are above what we feel
comfortable with, there's still a need to do it and there is a full going to be a
formal sign -off process for that. In terms of the changes, no, I hope those will be
captured identifying the delivery officers and timescales so those can be
monitored through. Sorry just one follow -up just around completeness of
identification of risks you need to understand the process and then outline
for purposes of review, so I guess if it's left up
to an individual to immediately go,
here is the risk that I foresee,
I mean it's just hard to assess that
if you don't have the process,
but I mean it's something that a lot of firms struggle with,
so I just don't want you to over -identify risks
which are unnecessarily in places yet also miss out some.
So it's part of what an auditor does,
they walk through a process, then they identify their risks.
They don't necessarily start with the risks.
So either way, it's purely judgement, and I don't want to overburden the firm doing that.
As I say, Mr. Hamilton is part of the group who's helping to design this new approach,
and part of that is so that for future audits, they can take a look at what we have coming
through its controls or risks, not just accepting them, but it's a starting point in understanding
where that service is at.
So some of what you're saying is the organisational growth and learning and maturity in terms
of risk management, risk identification and even control identification.
This approach, as I say, is still new, doing it to that level of detail.
For me, I'm hoping that it will grow and that maturity will then benefit the organisation
towards the sorts of things that you're suggesting.
Are there any other questions?
Can I do one more before we look at the grid?
Of course, Steve.
It's pretty much a comment.
On page 120, I've noticed that the organisation has a moderate risk appetite for operational
innovation.
Given that we're in a position where we're going to have to make a lot of change at pace,
it seems to me that actually we ought to have a higher risk appetite for that.
Now, how we change that, as a comment from me as a member of the Audit Committee, going
forward I would think we should be looking to be more flexible and use in
trying new things. How do we, okay that's my view, I don't know if the rest of the
Audit Committee agree, but how would we feed that back and say that probably
isn't the correct level at this time given the organisational change we're
going to have to go through?
I can answer part of that.
So part of that is what's now being gathered and go through the departments for them to
challenge that.
So what I'm gathering, we're not setting the levels.
We're working with what they provide and to help challenge them over those.
I know it was having to tell you the transformation programme, the IT innovations that we're looking
go through, there are different approaches and it's a bit when we talk about the maturity
of risk appetite.
An organisation such as Council, so vast and so many different functional areas, it's
very hard to try and – if you end up with something like that, we saw an averaged risk
appetite.
I think what we're having now with the new digital and data department where they've
coming up with a new change of process in review and applications, the appetite may
change from request to request in terms of its priority needs, what's its impact going
to be on the council's activities.
So that's where I say I don't know yet what the final outcome will be of risk appetite,
whether we can say something that says, well, generically on average, we are higher or we're
in terms of this or whether it's left to individual projects to go through and how those are assessed.
Obviously, I don't know what the outcome of that will be yet, but hopefully this will
help capture what that's going to be.
Just – I just wanted to just ask a question before your question.
Just around the risk appetite, so I'm just – I probably would expect, like, a board
level that would set the appetite for an organisation, and I appreciate this is a council, so we've
got a directing board, and the appetite would be set maybe within a range, so it's not necessary
to say it's averse or it's minimalist or it's cautious.
It will be between two, you know, so that depending on what the organisation is doing,
it could sit anywhere between that depending on what the activity is or what the function
is as well.
So is the risk appetite, has the risk appetite been set by the directing board?
or are you saying that this is something that is being discussed at a lower level and then
it might philtre up, if I understand rightly?
So the approach of the documented risk appetite is there, does exist in the current risk management
strategy document that's two years old.
We've moved a long way in these two years and that's where I'm saying that's one of
things that we wish to renew and that's where we will hopefully get that better top -down approach.
The drivers for improving the identification and quantification of risk appetite,
I've been using the platform to capture that sort of information and that's why I say whilst it's
starting bottom -up, it's never going to be bottom -up. I complete a return, I'm not in
say what my risk appetite is, my service, others will tell me that. I could suggest
things up and it's the suggestion that we're hoping that we will then get
greater clarity passing back down once the process allows these to be fed
up through directors and to the executive board. So I do expect that we
will have great clarity on perhaps key themed areas for what the organisational
risk is and those will be pushed down or led by the Council and the
executives. But there also needs to be sufficient, I suppose, mobility
because events can change risks and also risk appetites overnight. So it's got to
be something that yes there's something set and then the mechanism for recording
where people wish to do something different to that. I think that's what I
mentioned earlier where it's above an accepted risk appetite level we will
have a formal sign off process at an appropriate level by either the service head or director
or even if it has to go all the way up to the chief executive for them to say right
we've got a documented risk appetite of X this is above that but we're still wanting
to go ahead with that activity because at this time this set of circumstances dictate
that the benefits outweigh those risk considerations.
I know we've been sitting for quite a while.
I don't know if anybody wanted to take a quick comfort break or do you want to continue?
Okay, all right.
I will be brief.
Just one point, I think the idea of a paper like this going to cabinets is a good idea,
but also to the shadow cabinet and also the chairs of OACs when they take over, or our
needs because not every appointee is skilled in a certain area because we know the nature
of political appointments as you put people in to say thank you sometimes and everything
else.
So we have to face reality and something like this would be useful to give them insight
as to our thinking about approaches to things.
So it's just an aside.
In terms of the paper, just a couple of clarifications.
So, on page 132, the one risk area is the cost of living, and you've put a control in
a cost of living strategy and work to develop an anti -poverty approach.
It would be really useful for something like this to have a timeline put in as to when
you could actually expect that, because that could be in four years' time, and this is
supposed to be a living document, actually is guiding people towards dealing with risks.
So that's just one point.
The other query I have is on page 133, where it's around climate.
It says cold and warm weather response planes.
I presume that's a typo.
But it would be useful to know what those actually include.
Is that about changing working conditions as well for our staff as well as service delivery?
Just as if that could be expanded a bit on.
And also the other one, outcomes framework.
It would be useful, I suppose, in part of the mitigating, which is service KPIs and
annual budget review process, is if the KPIs could also look at some sort of impact measurement
rather than just pure, because outcomes is such a broad topic and we are trying to get
the maximum impact for our investment in terms of our service delivery.
So it would be useful if that could be explicit within that line.
And that's it.
Thank you.
I'll take those suggestions back to the people that say this is not something done for them,
this is something done by them.
And yeah.
Were there any other questions?
Oh, Mr. Priest?
I think I will make my opinions about Thames Water very clear because I like to do this
every single time.
But I think that there is significant risk around the failure of Thames Water in London
if you look at their infrastructure in northern London and their ability to actually sustain
that.
And I think that with the ongoing threats around kind of nationalisation and
changes within the organisation, if there was disruption at a pumping station in
northern London, it would severely affect our social care.
It will affect schools, it will affect businesses.
And I think that I just want people to fully understand the risks of,
it's not a simple case of southern water where they will get the army in to
provide a few bottles of water, there is significant risk to the council.
And I think that it is a very large risk which should be taken seriously.
Councillor Ketchum.
Actually, we live down the A24 and
I mean that has been dug up for months, years.
Maybe that risk, though the Thames Water one, is on the Borough Risk Register.
Should go on the Borough...
Okay, any other...
I'll talk to you afterwards.
Oh, okay.
Any other questions?
Okay, so the Committee are recommended to note and comment on the Corporate Risk Register
as set out in Appendix A, which we have done, and note the progress with updating the Council's
risk management approach and digital platform.
So noted.
Councillor Creight -Chard.
I propose that this paper is forwarded to Cabinet for their review as well.
Sorry, have I got a seconder for that? I need a seconder.
So we'll take a vote on this then. So who agrees with sharing this paper with the cabinet,
Cabinet, Shadow Cabinet and Chairs of Committees.
My objection is because I think that it's outside our remit.
Who is against sharing this paper with the Cabinet Shadow Committee and the OSC's chairs?
Okay.
Okay, can we keep the conversation as part of the committee?
Okay.
So I'm able to use my casting vote for it to be shared with all the committees, the
and the committee chairs as well.
So I think it's been carried that the risk register will be presented and shared with
those individuals.
I'd like it noted, minuted that I didn't agree because I believe that it's outside our remit
to demand that.
I think I've been...
Councillor?
Okay, well, that is the end of the Audit Committee.
I'd just like to say thank you to everyone who attended today.
It was a very kind of, really good meeting actually, each of the papers we discussed
well.
And thank you to the officers who contributed and also to Mr Priest and Ms Khanna as well.
Thank you very much and I'll see you at the next one.
Thank you.
Bye.
Thank you.
Thank you.