Agenda and minutes

Audit and Governance Committee - Monday, 4th August, 2025 6.30 pm

Venue: Council Chamber, County Hall, Dorchester, DT1 1XJ. View directions

Contact: John Miles  Email: [email protected]

Media

Items
No. Item

129.

Apologies

To receive any apologies for absence.

Minutes:

Apologies for absence were received from Cllr Parry.

130.

Minutes pdf icon PDF 134 KB

To confirm the minutes of the meeting held on 30th June and 7th July 2025.

Additional documents:

Minutes:

The minutes of the meeting held on 30th June and 7th July 2025 were confirmed and signed.

131.

Declarations of Interest

To disclose any pecuniary, other registrable or non-registrable interest as set out in the adopted Code of Conduct.  In making their decision councillors are asked to state the agenda item, the nature of the interest and any action they propose to take as part of their declaration.

 

If required, further advice should be sought from the Monitoring Officer in advance of the meeting.

 

Minutes:

No declarations of disclosable pecuniary interests were made at the meeting.

 

 

132.

Public Participation pdf icon PDF 102 KB

Representatives of town or parish councils and members of the public who live, work, or represent an organisation within the Dorset Council area are welcome to submit either 1 question or 1 statement for each meeting.  You are welcome to attend the meeting in person or via MS Teams to read out your question and to receive the response. If you submit a statement for the committee this will be circulated to all members of the committee in advance of the meeting as a supplement to the agenda and appended to the minutes for the formal record but will not be read out at the meeting. The first 8 questions and the first 8 statements received from members of the public or organisations for each meeting will be accepted on a first come first served basis in accordance with the deadline set out below.

 

All submissions must be emailed in full to [email protected] by 8.30 am on 31st July 2025.

 

When submitting your question or statement please note that:

· You can submit 1 question or 1 statement.

· A question may include a short pre-amble to set the context.

· It must be a single question and any sub-divided questions will not be permitted.

· Each question will consist of no more than 450 words, and you will be given up to 3 minutes to present your question.

· When submitting a question please indicate who the question is for (e.g., the name of the committee or Portfolio Holder)

· Include your name, address, and contact details.  Only your name will be published but we may need your other details to contact you about your question or statement in advance of the meeting.

· Questions and statements received in line with the council’s rules for public participation will be published as a supplement to the agenda.

· All questions, statements and responses will be published in full within the minutes of the meeting. 

Minutes:

Ms Chedgy representation was read out to the Committee.

 

The swap report (item 6 on the agenda) states at page 7 that its counter fraud team has recently completed an investigation arising from a whistleblowing referral. What was the referral about and what was the outcome?

 

 

Cllr Suttle read out the response to her question:

 

The Council was contacted by a whistleblower in August 2024 making allegations against a member of staff, citing alleged potential conflicts of interest and circumventing of procedures alongside accusations of bullying.

 

The resultant SWAP investigation identified systemic failures with how this work was carried out including:

our financial and procurement rules not being followed,

a lack of oversight of interim staff and budget approvals

poor record-keeping and a lack of transparency in contract awards, instances of potential conflicts of interest and breaches of the Council’s Code of Conduct for employees.

A summary of the SWAP investigation findings has been made available to the public.

 

This audit investigation, and a separate audit into our contract and expenditure processes that was prompted during the investigation, have identified weaknesses in our governance, financial controls, procurement practices and oversight. We take this seriously and we have already begun to implement an action plan that will: strengthen our financial oversight and budget monitoring, improve procurement and contract management processes, review recruitment and management for interim and agency employees, provide enhanced training and guidance for employees, especially for those who manage budgets and procurement, ensure regular monitoring and reporting from officers to the Audit and Governance Committee

 

Mr Mills presented his question to the Committee:

 

I will preface this by saying I have no real knowledge of the inner workings of the Council and have never felt compelled to speak up in the past, so apologies if I am missing the point here somewhat and am misguided in some of my statements below as I’m probably unaware of the full picture.

 

The health and safety compliance report published on the council website is damning on so many levels, highlighting a complete lack of financial discipline, procedural oversight and mismanagement of what we are told are limited resources at a local government level with acute funding pressures.

 

What I really fail to grasp is how payments can be made without correct approval, staff can be recruited and pay rises implemented without a paper trail and reserves can be accessed without having to justify every penny spent. It is particularly troublesome where over £1m has been spent annually on internal and external audits combined, yet it was a whistleblower who uncovered the irregularities, despite the figures that are being quoted being well over a material misstatement of sorts.

 

I’m sure that when the dust settles and investigations are concluded we will be made aware that a criminal investigation has been raised against the terminated employees where appropriate and the suppliers who are guilty of overcharging and providing gifts and hospitality are blacklisted. There has to be significant and decisive consequences for those involved  ...  view the full minutes text for item 132.

133.

Minutes of the Audit & Governance Sub-committee

To note the minutes of the Audit & Governance Hearing Sub-committee (if any meetings have been held).

Minutes:

No Meetings held.

134.

Report of Internal Audit Activity Progress Report 2025/26 - July 2025 pdf icon PDF 1 MB

To receive a report by SWAP.

Minutes:

The Assistant Director for SWAP Internal Services, Sally White introduced the report. The progress report for July provided a key update on audit activities progress towards adequate management of significant risks and implementation of audit actions.  No new limited assurance opinions have been issued since the update in June. SWAP had completed a review of the governance framework for Our Future Council Program and due to the significance of this work a copy of the advisory report had been provided on pg 8 and 9 of the report. All actions in response to the climate emergency have now been fully implemented, and future audits would revisit this or related areas. She went through pages 3-4 Table of Audit Coverage and provided a more detailed explanation of what the tables were showing.

 

Mr Roach asked how important a priority 2 action was and focused on the word significant. He referenced pg 19 and 20 – actions not yet due but with multiple revisions, of which there were quite a few and when looking at revision dates vs the original dates, there were very significant delays in implementing these actions. He did not think that progress was being made on addressing the fundamental issues of resolving audit actions because these priority 2 actions were delayed for days to months or over a year in some instances. He proposed that if we did have actions with revised dates of more than 6 months or 9 months and if they were priority 1 or 2, that they should come to this Committee and audit should remind us of what the risk was and the directorate leader and accountable owner of the action, should explain to the Committee how the risk was being managed whilst the action was still outstanding.

 

Cllr Suttle had already had conversations with SWAP that when there was a significant delay, the Committee must see the officer in question and must have a full update on what was going on and the reasons why.

 

Noted.

 

135.

Annual Information Governance Report – 2024/25 pdf icon PDF 398 KB

To receive a report by Marc Eyre, Service Manager for Assurance.

Minutes:

The Service Manager for Assurance, Marc Eyre introduced the report. He went through the highlights of the report of which there were 382 data breaches within the financial year of which 14 were reportable to the information commissioner. In response, the service had implemented new sensitivity labels for documents and emails as part of the rollout. In the longer term, the technology should help reduce exposure particularly as the high proportion of the data breaches were related to email. Mandatory training levels for data protection and cyber risk had remained below the 95% compliance rate. There would be stronger compliance measures implemented which continued levels of non-compliance could lead to system access removal for users and were looking at how this would be implemented.

 

Cllr Holoway asked if this report should come to the committee on a more regular basis in the form of a follow up report 6 months down the line as a year was a long time and a lot could change in a year.

 

Marc Eyre agreed that it was a good idea as there were measures in place looking at the training rates and addition resource coming in around the action plan and it would be a good opportunity to provide assurance to the Committee in 6 months’ time.

 

Cllr Haynes commented that there was a lot of detail in the report and the Committee needed to understand for future reporting which of the data breaches were a danger to the Council and asked if the details in the data could be explained.

 

Mr Roach Co-opted member referenced para 552, training for data protection compliance and for cyber training compliance. He explained that training compliance was 65% down from 73% was woefully inadequate. He suggested that there needed to be consequences for individuals that did not complete the mandatory training. Humans were the weakest link in cyber security and only 65% of people had completed their training to educate about the risk and what to do and what not to do. Then there was a significant proportion of people that did not understand the risks. He suggested pursuing the people that had not completed the training.

 

Noted.

 

136.

Annual Fraud and Protected Disclosures Report pdf icon PDF 240 KB

To receive a report by Marc Eyre, Service Manager for Assurance.

 

Additional documents:

Minutes:

The Service Manager for Assurance, Marc Eyre introduced the report. There were no significant changes to the Whistleblowing policy but there was an emphasis on training and awareness. The Counter Fraud and Financial Crime policy brought together policies that were previously separate. The fraud bribery and corruption policy and the anti-money laundering policy and the anti-tax evasion policy had all been combined. These were brought together to remove repetition and inconsistencies.

 

Roger Ong Co-opted Member referenced 5.3, pg 87 on money laundering reporting, he highlighted that if a member of staff was aware of something and needed to report it. The document needed to make clear that if they failed to do that, they were liable as well for none reporting.

 

Decision: the Committee approved the revised “Protected Disclosure (Whistleblowing) Policy and the new “Counter Fraud and Financial Crime Policy”; and iv) note the compliance matrix. The annual update on fraud and protected disclosure activity was noted.

 

Reason for Decision:

To support the Council’s zero tolerance to fraud and other financial crimes.

 

137.

Annual Emergency Planning Report. pdf icon PDF 219 KB

To receive a report by Marc Eyre, Service Manager for Assurance.

 

Minutes:

The Cabinet Member for Planning and Emergency Planning, Cllr Bartlett and The Service Manager for Assurance, Marc Eyre introduced the report. The report had been requested by the previous membership of the Committee pre-election. The business continuity framework had been refreshed following an internal audit, due to concerns of the frequency of plan updates across the services and was now in a better position. The report covers the wide array of call outs that the team covers some large and some small. On a national level there had been a UK resilience action plan and a strategic defence review, which emphasise a growing focus on resilience and community resilience.

 

Noted. 

 

 

138.

Risk Management Update. pdf icon PDF 628 KB

To receive a report by Chris Swain, Risk Reporting Officer.

Minutes:

The Risk Reporting Officer, Chris Swain and Head of Service Strategy, Liz Crocker introduced the report. There were ongoing efforts to ensure that Dorset Council’s Risk Management Framework remained proportionate, well aligned and dynamic to the Council’s evolving needs. The key areas were covered; the principal risks were now fully embedded within the framework and offered deeper insights to how risks interrelate from a comprehensible organisational wide analysis. For strategic risks, which had been identified with senior leaders and integrated into regular reporting cycles. A further review of strategic risk would be undertaken given the audit report and dynamic nature.

 

Cllr Todd asked how directorates would be held to account if they operated outside the stated appetite risk?

 

Chris Swain and Liz Crocker responded that the risk appetite statement was the high-level strategic steer as the amount of risk that the Council would want to take. There was work in the pipeline to develop specific metrics for directorates around what they would accept and what they would not accept and routes of escalation, so further work was needed to develop it to business units. In the update that highlighted the changes and enhancements to the risk reporting register, there was opportunity for officers to identify risk falling outside of the risk appetite which would automatically escalate it for SLT consideration. It would be reported to the committee when risk fell outside of the appetite and needed to be escalated to SLT.

 

Decision: the Committee agreed and noted the recommendations set out in the report.

 

Reasons for the recommendation

To ensure that the council’s risk management methodologies support informed, risk-based decision-making while remaining proportionate and aligned with organisational objectives and key deliverables.

 

139.

Treasury Management Annual Report 2024/25 pdf icon PDF 353 KB

To receive a report by David Wilkes, Service Manager Treasury and Investments.

Minutes:

The Service Manager Treasury and Investments, David Wilkes introduced the report and went through a brief summary on pg 155.

 

The Corporate Director Transformation, Customer and Culture Lisa Cotton informed that all voluntary redundancies that came through under our future council would be scrutinised through a level of criteria and where critical roles needed to be retained within the organisation that would be considered as part of those decisions that would be made against those roles that came forward.

 

Noted.

 

140.

Update on Our Future Council Work.

To receive an update by Sean Cremer, Corporate Director Finance and Commercial.

Minutes:

The Corporate Director Transformation, Customer and Culture, Lisa Cotton gave an update on Our Future Council Work. She last reported to the Committee on the 30th June 2025 and provided a detailed overview of the Governance Framework supporting Our Future Council Transformation Programme, including internal audit review being conducted by SWAP. Since that report, the Council was now in full active delivery of the program, and 2 weeks into formal consultation with the Council’s workforce on the proposed organisation redesigns for customer experience business support and transformation office. This marked a significant milestone and was now in a dedicated period of meaningful consultation, engaging directly with employees, listening to feedback, responding to questions, considering alternatives. This was supported by structural change management activity and transitional planning. Ready for Autumn go live and the Council remained on track against the publish program timeline and the Council’s governance arrangements continue to provide assurance and oversight and risks were being actively monitored and managed.

 

141.

Grant Thornton - IT Audit Findings Report. pdf icon PDF 690 KB

To receive a report by Julie Masci, Grant Thornton.

Minutes:

Julie Masci from Grant Thornton introduced the report. There were two recommendations that the action plan highlighted as a red assessment. The first one covered the debugger access to the SAP system, the primary financial access system to the Council. 26 users in the system had been identified with a privilege level of access through the debugger role. Which allowed users to change or delete entries and to change underlying program code and to bypass normal authority checks and execute transactions. The council had taken a number of steps since the prior year to mitigate the previous finding. The overall number of users had been reduced down from 26 to 11, 8 users from the payroll team and 3 from business solution engineer team. Grant Thornton recognised the progress that the Council had made but those 11 users remain with that level of privileged access and this still presented a risk to the Council. Management was looking for alternative controls to manage the residual risk. She referenced the second significant finding on pg 188 which related to third party privileged user access on UPM, supporting pension information that supports the pension fund financial statements.

 

Simon Roach Co-opted Member commented that payroll users should not have that level of power as it presented a significant risk and it needed to be addressed urgently. He asked Julie Masci to what extent did Grant Thornton validate the response in that it satisfied the fundamental issue that Grant Thornton raised. He referenced pg 189 – management should take a review of all user accounts on the AD to identify all generic privileged accounts. He did not believe that management had agreed to do that and urged that they should and it was a gap that needed to be addressed.

 

Sean Cremer, Corporate Director Finance and Commercial responded that it was a fundamental flaw in how the system was configured and payroll could not be operated if permissions were removed. As the Council provided payroll services to a number of organisations and to remove access and put it back in would be an unworkable solution. He was working with Grant Thornton and their colleagues across the country to look at systems and how they had been configured but so far a solution had not been found.

 

The Committee members highlighted that in their view the management responses to the action plan did not fully address the findings raised by the external auditor and officers agreed to take these away to revisit and update.

 

Noted. 

 

142.

Work Programme pdf icon PDF 101 KB

To consider the work programme for the Committee.

143.

Urgent items

To consider any items of business which the Chairman has had prior notification and considers to be urgent pursuant to section 100B (4) b) of the Local Government Act 1972. The reason for the urgency shall be recorded in the minutes.

Minutes:

There were no urgent items.

144.

Exempt Business

There is no exempt business.

 

Minutes:

There was no exempt business.