Agenda item

Internal Audit and Counter Fraud Progress Report

Minutes:

Stuart Cutts explained that the position of each audit is provided within the appendices and highlighted the recommendations within the report.

 

A query was raised regarding the process for completing the report on the Scarborough Water Park, noting that despite repeated requests to see the draft version, this was not sent, and it was not reviewed by the Audit Committee before the report was made public. The member queried what occurred during the year and whether the final published report differed from earlier draft versions. It was noted that this query had previously been raised during an informal private briefing.

 

In response, it was confirmed that the report followed the standard audit process: a draft was shared with officers to allow for comments, clarification, and the identification of any errors or omissions. This was followed by a series of discussions, and once agreement was reached, the report was finalised. It was reported that due to the age of the subject matter, records were sometimes difficult to obtain and recollections varied. The audit team sought to present a comprehensive account of the decision-making process and the rationale behind the actions taken. It was confirmed that Internal Audit were not put under pressure to make changes to the draft reports and that the process followed was consistent with how Internal Audit should operate – objectively and independently. It was also highlighted that North Yorkshire Council is now the owner of Scarborough Water Park following local government reorganisation.

 

It was explained that once the report was finalised, the Chief Executive decided to publish it, due to the nature of the issues involved. A member briefing was held the day before publication to provide members with an opportunity to hear the findings and ask questions. Following publication, the report has been brought to the Audit Committee for consideration. The Committee was advised that it may now decide how to proceed, whether that be to refer the report to the Executive, consider its conclusions, make recommendations, or request further discussion at a future meeting.

 

The Committee emphasised that even if no further action is deemed necessary, it is appropriate for the Audit Committee to formally consider the Scarborough Water Park report as a separate agenda item. In response, it was advised that the terms of reference for such a discussion should be agreed in advance, with input from legal officers, to ensure the conversation is appropriately framed and avoids any risk of misunderstanding or legal implications. It was noted that the item could be considered in confidential session if necessary.

 

A member queried why no audit opinion was provided for the Council Companies audit listed in the 2025/26 internal audit work programme (page 55 of the Audit Committee papers), noting that while the absence of an opinion for the Scarborough Water Park audit might be expected, the rationale for excluding an opinion on Council Companies was unclear.

 

In response, members were directed to page 72 of the Audit Committee papers, which outlines the four possible audit opinions. It was noted that in certain cases – such as projects, investigations, targeted support, consultancy, grant certification, and follow-up work – it is not appropriate to give an assurance level, and a ‘No opinion’ is recorded. The Council Companies audit fell into this category. It was explained that the audit team took a different approach due to the lack of sufficiently developed internal arrangements at the time and therefore auditors obtained information directly from the council-owned companies. A key finding was that the Council’s internal arrangements need further development to provide ongoing assurance on the governance of its companies and this approach was agreed with officers.

 

It was highlighted that on page 73 of the Audit Committee papers, ‘Council companies and other commercial operations’ was marked as ‘Do later.’ It was queried whether the intention was to revisit council companies in future. It was confirmed that this is the case and that the audit of council companies is intended to be scheduled in due course. Items marked as “Do later” will be re-evaluated during Quarter 4 of the 2025/26 financial year to determine their timing within the 2026/27 audit planning cycle.

 

It was noted that page 74 of the Audit Committee papers does not specify when audit work on ‘Harbours’ will commence. In response, it was reported that this work is expected to be scheduled either as a “Do next” or “Do later” item.

 

Daniel Clubb then highlighted the key points from the Counter Fraud Progress Report. The following queries were raised in the discussion.

 

·        The figures presented in the table on page 82 of the Audit Committee papers were clarified, and it was confirmed that the first column reflects actual results up to 31 August 2025 (58%), while the second column shows the full-year target (30%), which has already been exceeded. A query was raised regarding the reason for the improved results. In response, it was explained that the percentage reflects the proportion of cases resulting in positive outcomes for the Council, such as fraud detection, sanctions, or savings. It was reported that the uplift is due to the effectiveness of the work undertaken, rather than an increase in the number of cases. A further query was raised about how the 30% target was set, and it was confirmed that targets are agreed with officers at the beginning of the year. It was noted that the target is generally based on historic performance, but given the significant uplift in outcomes this year, a review of the target may be appropriate. It was also acknowledged that the nature and mix of fraud cases can vary significantly from year to year, and that targets should not be established in isolation.

 

·        A query was raised regarding the Council’s efforts to prevent cyber attacks. In response, it was noted that the Counter Fraud team supports the Council in responding to cyber-related incidents and works with the IT department to regularly test cyber security arrangements. Awareness-raising is part of the team’s annual activity, including planned communications for Cyber Crime Awareness Month in October. Cyber security is recognised as a key corporate risk, with resources invested to mitigate threats. While risks cannot be fully eliminated, efforts focus on minimising exposure and ensuring recovery plans are in place. Audit work is undertaken on these arrangements and reported accordingly. It was acknowledged that cyber threats continue to evolve, and that user behaviour – such as avoiding unsafe email links – remains a critical factor in maintaining security.

 

Resolved

 

a)     That report is noted.

b)     That an item covering the Scarborough Waterpark Report is brought to the Audit Committee.

Supporting documents: