Minutes:
Stuart Cutts explained that the position of each audit is
provided within the appendices and highlighted the recommendations within the
report.
A query was raised regarding the process for completing the
report on the Scarborough Water Park, noting that despite repeated requests to
see the draft version, this was not sent, and it was not reviewed by the Audit
Committee before the report was made public. The member queried what occurred
during the year and whether the final published report differed from earlier
draft versions. It was noted that this query had previously been raised during
an informal private briefing.
In response, it was confirmed that the report followed the
standard audit process: a draft was shared with officers to allow for comments,
clarification, and the identification of any errors or omissions. This was
followed by a series of discussions, and once agreement was reached, the report
was finalised. It was reported that due to the age of the subject matter,
records were sometimes difficult to obtain and
recollections varied. The audit team sought to present a comprehensive account
of the decision-making process and the rationale behind the actions taken. It
was confirmed that Internal Audit were not put under pressure to make changes
to the draft reports and that the process followed was consistent with how
Internal Audit should operate – objectively and independently. It was also
highlighted that North Yorkshire Council is now the owner of Scarborough Water
Park following local government reorganisation.
It was explained that once the report was finalised, the
Chief Executive decided to publish it, due to the nature of the issues
involved. A member briefing was held the day before publication to provide
members with an opportunity to hear the findings and ask questions. Following
publication, the report has been brought to the Audit Committee for
consideration. The Committee was advised that it may now decide how to proceed,
whether that be to refer the report to the Executive, consider its conclusions,
make recommendations, or request further discussion at a future meeting.
The Committee emphasised that even if no further action is
deemed necessary, it is appropriate for the Audit Committee to formally
consider the Scarborough Water Park report as a separate agenda item. In
response, it was advised that the terms of reference for such a discussion
should be agreed in advance, with input from legal officers, to ensure the
conversation is appropriately framed and avoids any risk of misunderstanding or
legal implications. It was noted that the item could be considered in confidential
session if necessary.
A member queried why no audit opinion was provided for the
Council Companies audit listed in the 2025/26 internal audit work programme
(page 55 of the Audit Committee papers), noting that while the absence of an
opinion for the Scarborough Water Park audit might be expected, the rationale
for excluding an opinion on Council Companies was unclear.
In response, members were directed to page 72 of the Audit
Committee papers, which outlines the four possible audit opinions. It was noted
that in certain cases – such as projects, investigations, targeted support,
consultancy, grant certification, and follow-up work – it is not appropriate to
give an assurance level, and a ‘No opinion’ is recorded. The Council Companies
audit fell into this category. It was explained that the audit team took a
different approach due to the lack of sufficiently developed internal
arrangements at the time and therefore auditors obtained information directly
from the council-owned companies. A key finding was that the Council’s internal
arrangements need further development to provide ongoing assurance on the
governance of its companies and this approach was agreed with officers.
It was highlighted that on page 73 of the Audit Committee
papers, ‘Council companies and other commercial operations’ was marked as ‘Do
later.’ It was queried whether the intention was to revisit council companies
in future. It was confirmed that this is the case and that the audit of council
companies is intended to be scheduled in due course. Items marked as “Do later”
will be re-evaluated during Quarter 4 of the 2025/26 financial year to
determine their timing within the 2026/27 audit planning cycle.
It was noted that page 74 of the Audit Committee papers does
not specify when audit work on ‘Harbours’ will commence. In response, it was
reported that this work is expected to be scheduled either as a “Do next” or
“Do later” item.
Daniel Clubb then highlighted the key points from the
Counter Fraud Progress Report. The following queries were raised in the
discussion.
· The figures presented in the table on page 82 of the Audit Committee papers were clarified, and it was confirmed that the first column reflects actual results up to 31 August 2025 (58%), while the second column shows the full-year target (30%), which has already been exceeded. A query was raised regarding the reason for the improved results. In response, it was explained that the percentage reflects the proportion of cases resulting in positive outcomes for the Council, such as fraud detection, sanctions, or savings. It was reported that the uplift is due to the effectiveness of the work undertaken, rather than an increase in the number of cases. A further query was raised about how the 30% target was set, and it was confirmed that targets are agreed with officers at the beginning of the year. It was noted that the target is generally based on historic performance, but given the significant uplift in outcomes this year, a review of the target may be appropriate. It was also acknowledged that the nature and mix of fraud cases can vary significantly from year to year, and that targets should not be established in isolation.
·
A query was raised regarding the Council’s
efforts to prevent cyber attacks. In response, it was
noted that the Counter Fraud team supports the Council in responding to
cyber-related incidents and works with the IT department to regularly test
cyber security arrangements. Awareness-raising is part of the team’s annual
activity, including planned communications for Cyber Crime Awareness Month in
October. Cyber security is recognised as a key corporate risk, with resources
invested to mitigate threats. While risks cannot be fully eliminated, efforts
focus on minimising exposure and ensuring recovery plans are in place. Audit
work is undertaken on these arrangements and reported accordingly. It was
acknowledged that cyber threats continue to evolve, and that user behaviour –
such as avoiding unsafe email links – remains a critical factor in maintaining
security.
Resolved
a) That report is noted.
b) That an item covering the Scarborough Waterpark Report is brought to the Audit Committee.
Supporting documents: