To receive a report by Sally White, SWAP and Liz Crocker, Head of Service -Strategy.
Minutes:
Sally White, Assistant Director for SWAP introduced the report. 4 Audits had been identified, and 3 officers were in attendance, to provide members with an update on each of the 4 audits.
Steven Ford, Corporate Director for Strategy, Performance and Sustainability added that work had been done to re-calibrate the way that they were monitoring compliance in a general sense and how outstanding external audits were monitored and strengthening the relationship between risk management and outstanding audits.
James Ailward, Head of ICT Operations addressed the Application Portfolio Management Issue and the specific action that was outstanding was communicating the general ledger codes to commissioning managers such that they were coding software purchases accurately within our SAP system such that we have an understanding of the spend that we have across the Council on application software and an outstanding action that could be addressed immediately and completed by the end of the month. It was a part of a bigger piece of work and had been lost in that bigger piece of work. Looking at the broader application portfolio and understanding more strategically how the software portfolio that we use supports the objectives of the organisation. The risk of the action remaining open was that there would not be a proper understanding of costs and they aimed to mitigate the risk through the new design authority approach to governing change by doing just in time analysis of the portfolio in a broader sense to allow change decisions around commissioning of new software to be completed in a way that understands the costs as well as some of the other aspects like alignment and technology health and capability. Such that the organisation was making considered decisions around the software and its commissioning. The just in time approach had already been started and introduced to the design authority. He covered the two actions that were outstanding on IT management, one of the actions was complete and the other was near completion. The first action which was near completion and related to ensuring that the risk and impact assessment were completed for all proposed changes. To develop robust testing and validation protocols prior to deployment and to provide targeted training relevant to teams and then to do an audit to ensure compliance with that process. So, the element of that which was not complete was the audit which would be done by the end of March 2026. The other action related to updating the policy to account for shifts in recent years around IT best practice for change management. At this point the residual risk was significantly reduced.
Marc Eyre, Service Manager for Assurance, went through two actions that had been identified as part of an internal audit on the Council’s whistleblowing arrangements. The Audit provided a reasonable assurance level but identified a couple of priority three recommendations around training. As part of the audit, five managers, one from each directorate area were approach by SWAP to ask to what extent were they aware of the whistleblowing policy. All five confirmed that they were aware of the policy but two had to refer to the document to understand what was meant by a protected disclosure and to understand the reporting lines and that prompted these particular actions in order to try and increase manager awareness. There had been some delays in responding to the actions, firstly the revision of the policy documentation that underpinned the training was delayed until August to alleviate pressure on the Committee agenda, which then had a knock-on impact on the wider actions. The revised protected disclosure whistleblowing policy was approved by the Committee in August 2025 and since then he had been working with colleagues in the learning and development team to create a revised training module. The risk had been mitigated to quite a high degree.
Sean Cremer, Corporate Director Finance and Commercial
gave an update on behalf of Katie Hale, Head of Revenues and Benefits
Transformation, Customer and Cultural Services.
Council tax accounts that were routinely monitored and checked through a
process which ensured accuracy and timely refunds. For risk management there
was regular reporting in place to identify accounts that were in credit and
quarterly reviews for tracing complex cases to try and minimise the risk. The
process meant that it was actively managed and refunds were proactive where
possible. He added that he would circulate a more detailed written answer which
would go into more detail on the process and this would be shared with SWAP.
Noted.
Supporting documents: