Agenda item

Internal Audit Annual Report 2025/26

To present the report of the Head of Audit and Risk.

Minutes:

The report of the Head of Audit and Risk incorporating the Internal Audit Annual Report for 2025/26 was presented for the committee’s consideration. The annual report provides the Head of Audit and Risk’s overall opinion on the adequacy and effectiveness of the Council’s framework of governance, risk management and control during the year.

 

The Head of Audit and Risk presented the report and confirmed that based on the work carried out during the year and the assurances provided, the Isle of Anglesey County  Council has an adequate and effective framework of risk management, governance and control for the year ending 31 March 2026. While there are no areas of significant corporate concern, some areas require the introduction or improvement of internal controls to ensure the achievement of objectives and these are the subject of monitoring. There are no qualifications to this opinion.

 

In outlining the basis for this opinion, the Head of Audit and Risk reported that Internal Audit met its key performance target by reviewing 80% of the Council’s 11 strategic risks with red or amber residual risk ratings within the planned 24 month period. All but one of these risks  received “Reasonable” assurance; the Secondary School ICT Security review received “Limited” assurance, and a follow up is underway. Assurance for one strategic risk relating to the Council’s Net Zero goals was provided by an external body.

 

Of the nine audits of other key areas, one received  “Substantial” assurance, five “Reasonable” assurance and three “Limited” assurance. Overall, Internal Audit provided “Reasonable” assurance or above for 73% (72% in 2024/25) of all the audits undertaken, with four audits (27%) receiving “Limited” assurance and none receiving “No” assurance.

 

The service continued to meet professional standards. The most recent External Quality Assessment in 2023 conducted by Flintshire County Council concluded that the service “Generally Conforms” which is the highest level of conformance. A self-assessment against the new Global Internal Audit Standards in June 2025 confirmed that the service generally meets the new requirements with some strengthening needed around evidence gathering.

 

Internal Audit performed well against most of its 2025/26 performance indicators with four out of six targets met, including the core target of reviewing 80% of the red and amber residual risks in the Strategic Risk Register.

 

In response to questions by the committee, the Head of Audit and Risk explained the distinction between an advisory review and a formal audit review. She also clarified that whereas Internal Audit previously carried out compliance checks across services, capacity constraints and a leaner audit team mean this is no longer feasible. Consequently, responsibility for compliance checking now rests with service managers, with most services supported by their own Business Service Manager to undertake this work.

 

It was resolved –

 

·      To note the Internal Audit Annual Report for 2025/26 including the Head of Audit and Risk’s opinion that the Council’s governance, risk management and internal control arrangements are adequate and effective.

·      To note the summary of the work carried out during the year and the assurances  provided as a basis for the opinion.

·      To note the performance of the internal audit function, in particular the level of conformance with the Global Internal Audit Standards in the UK Public Sector.

 

Supporting documents: