Agenda item
Third line assurance: Internal Audit Annual Report 2025/26
The report of the Head of Policy and Governance is attached.
Contact: Barry Hanson 07990 086409
Minutes:
The Head of Policy & Governance presented the Internal Audit Annual Report for the financial year 2025/26. The report provided a comprehensive summary of all internal audit work completed during the year, performance against the approved internal audit plan, and the annual opinion on the Council’s framework for governance, risk management, and internal control.
The Head of Policy & Governance reported that internal audit had delivered strongly against the plan, remained compliant with global internal audit standards, and maintained independence throughout the year. Customer feedback was positive, with 93% satisfaction overall and 98% of feedback forms rated excellent or good.
A total of 60 final audit reports were issued, resulting in 421 recommendations. Of the assurance opinions issued, 52% were rated as good or reasonable, representing a reduction compared to the previous year. Conversely, there were 23 limited assurance and six unsatisfactory opinions, meaning that 48% of completed audits resulted in a lower level of assurance. The proportion of significant and fundamental recommendations had increased compared to last year.
The Head of Policy & Governance referred to Paragraph 8.19 of the report, which set out all the matters that he had taken into account in arriving at his annual opinion. As Chief Audit Executive, the Head of Policy & Governance’s opinion for 2025/26 was “limited assurance,” marking the seventh consecutive year with this rating. The opinion reflected the continuing presence of significant weaknesses, particularly in budget monitoring, risk management, workforce resilience, debt recovery, and contract management arrangements. However, the report also recognized that action had been taken during the year, including strengthened oversight of spending, increased financial reporting to Cabinet, establishment of a statutory officers group, reinforced expectations around compliance, and increased leadership focus on governance, accountability, and escalation of significant issues. Internal audit had adapted its plan to reflect changing risks, and the 2026/27 internal audit plan had been reviewed accordingly. Early signs of improvement were noted in the final quarter, with no unsatisfactory assurance opinions or fundamental recommendations, but the full impact of improvement activities had not yet embedded.
Members thanked the Head of Policy & Governance for the report and noted the trends in assurance opinions and recommendations. They observed that the number of unsatisfactory opinions was the lowest in seven years and suggested that the audit plan was risk-based, meaning areas audited were more likely to have issues. They asked whether the seven years of limited assurance indicated persistent issues or whether new issues were emerging each year.
In response, the Head of Policy & Governance explained that the internal audit plan was based on risk and change within the organisation, and the areas audited could differ throughout the year and compared to previous years. The decision around the assurance level at year end was based purely on what had happened during the financial year. They clarified that “no assurance” would require catastrophic failure, such as a complete lack of a council constitution, governance mechanisms, financial rules, and a breakdown of controls, which was not the case. Therefore, the opinion was “limited assurance” and not “no assurance.”
It was explained that the risk profile of the organisation changes year to year, and the issues identified may differ. Comparing to seven years ago would be incomparable, as the assurance level is based on the current year’s findings.
The Internal Audit Manager provided further clarification on the definitions of assurance levels, referencing the breakdown of classifications in the report. She explained that “no assurance” would be issued if high-risk rated weaknesses were identified in assignments and observations, or if not enough audit work had been completed. She noted that the corporate governance audit was reasonable, indicating that the Council’s assurance frameworks and policies were generally sound, but individual non-compliance with those policies was the issue. Reasons for non-compliance included culture, lack of consequences, changing priorities, and lack of resources.
The Chair commented that, as a newer member, it was important to track whether recommendations were being implemented and whether audit findings led to improvement, especially in areas like adult social care. They asked how to ensure that the audit work resulted in positive impact and improvement.
The Internal Audit Manager explained that the Committee could add value by inviting managers to provide updates on progress in implementing recommendations. Internal audit engages with management to agree actions and deadlines, and the Committee can follow up to understand reasons for delays or non-implementation.
RESOLVED:
A. to note the performance of Internal Audit against the 2025/26 Audit Plan.
B. to note that Internal Audit have evaluated the effectiveness of the Council’s risk management, control and governance processes, considering Global Internal Audit Standards (GIAS) or guidance, the results of which can be used when considering the internal control environment and the Annual Governance Statement for 2025/26.
C. to note the Chief Audit Executive’s Limited assurance year-end opinion on the Council’s framework for governance, risk management and internal control.
D. to request the executive and senior officers to take the necessary action to address the weaknesses identified.
E. to note, despite the limited assurance opinion, the significant progress that the Council has made and continues to make since the announcement of the financial emergency, as evidenced especially in the Q4 performance report.
Supporting documents: