To present the report of the Head of Audit and Risk.
Minutes:
The report of the Head of Audit and Risk incorporating the Internal Audit Strategy and Plan for 2026/2027 was presented for the committee’s consideration. The strategy sets out how the internal audit function will provide independent, risk-based assurance to support the Council in achieving its strategic objectives.
The Head of Audit and Risk presented the report noting that the strategy has been developed in line with the new Global Internal Audit Standards (GIAS) and CIPFA requirements and reflects the challenging environment in which the Council continues to operate, particularly ongoing financial pressures. Internal Audit will continue to apply an agile, risk based approach, updating the plan throughout the year as risks and priorities change.
The strategy outlines a vision for a mature, innovative and collaborative internal audit function, supported by three strategic objectives – achieving a fully skilled and qualified team, embedding audit technology and data analytics into audit work and seeking opportunities for collaborating regionally and nationally. She reported that the plan prioritises audits of the Council’s strategic risks over a rolling two year period as detailed in Appendix B with a focus on inherent “red” risks and residual “red” or “amber” risks.
She outlined the proposed IT audit work programme to be delivered by Salford Council’s IT auditors together with other areas of audit activity that will be continually updated and refreshed, as well as outstanding reviews from 2025/26. The strategy also includes performance measures for 2026/27 with two new indicators covering assurance of Corporate Plan strategic objectives and staff self-assessment against the IIA Competency Framework.
The committee discussed the following matters –
· Members sought clarification of the extent to which the plan can be amended, mindful that the committee cannot direct Internal Audit.
The Head of Audit and Risk explained that CIPFA guidance is clear that audit committees must not direct Internal Audit work, in order to prevent conflicts of interest, for example, an audit committee steering Internal Audit away from politically sensitive areas. She emphasised that the Council’s Internal Audit service has a strong working relationship with officers and with the committee, and that through an agile approach, Internal Audit can adjust the plan to accommodate requests for review where specific issues arise.
· Whether allergens is an issue in Anglesey’s schools, noting that the matter is the subject of an audit deferred from 2025/26. The Head of Audit and Risk explained that an incident in a neighbouring authority had highlighted weaknesses in how school meal provision considered allergens, and that the North and Mid-Wales Audit Partnership had also examined the issue. She confirmed that the situation in Anglesey is different as school meal provision is outsourced.
The committee further enquired about the impact on internal audit resources of this and potential other requirements under the new standards.
The Head of Internal Audit explained that because the service was already operating in a modern way, the introduction of the GIAS did not have major impact on its work, other that requiring a stronger evidence base to support its activity. She noted that the service is seeking to meet this requirement in a smart way to avoid unnecessary administrative burden. While no further major overhaul of the standards is expected for some time, topical requirements are being introduced for specific areas e.g. in relation to cyber security and the internal audit service is able to draw on Salford Council’s specialist IT audit expertise in this area.
In response to a question about whether constraints on Salford Council’s IT audit capacity could affect the Council’s Internal Audit plans or present a risk, the Head of Audit and Risk advised that the Salford Council IT audit team is large, serves multiple clients and operates almost as a semi-professional unit. It is able to absorb staff absences and she therefore did not consider this a risk. She added that the market for IT audit providers is limited and external providers are often expensive whereas as a local authority, Salford Council’s IT audit service is cost-effective.
· Under Strategic Objective 2, members asked about the use of data analytics in audits and how this is measured.
The Head of Audit and Risk explained that the service now has software enabling it to examine large volumes of data quickly, and that internal audit practice is moving away from sampling to reach broad conclusions about subject areas. While data analytics cannot be applied to every audit, the service intends to expand its use with progress measured by the number of audits undertaken in the year and how many of those utilised data analytics.
It was resolved –
· To approve the risk based Internal Audit Strategy and Plan for 2026/27 as providing the Council with the assurance it needs.
· To confirm that the committee is content with Internal Audit’s resources requirements and the use of other sources of assurance and that there are no inappropriate scope or resource limitations.
· To approve the Internal Audit performance measures as set out in the strategy and plan.
Supporting documents: