Agenda item

Internal Audit Annual Report 2021-22

Report of the Chief Operating Officer (Section 151 Officer)


The Audit and Procurement Committee considered a report of the Chief Operating Officer (Section 151 Officer) that summarised the Council’s Internal Audit activity for the period April 2021 to March 2022 against the agreed Audit Plan for 2021-2022 and the Public Sector Internal Audit Standards. The report also provided the Audit and Procurement Committee with the Chief Internal Auditor’s opinion on the overall adequacy and effectiveness of Coventry City Council's risk management, internal control and governance arrangements for the financial year 2021-2022.  Appendices to the report provided: details of the Audits completed in 2021-2022 and the Summary findings from key audit reports.


The Audit and Procurement Committee approved the Council's Internal Audit Plan for 2021-2022 at its meeting on the 28th June 2021.  During the last financial year, the Committee received a progress report summarising completed audit activity in November 2021 and March 2022. This report detailed the performance of the Internal Audit Service against the Plan for 2021-2022, which was presented in order for the Audit and Procurement Committee to discharge its responsibility, as reflected in its term of reference - “To consider the Head of Internal Audit's Annual Report and Opinion, and a summary of internal audit activities (actual and proposed) and the level of assurance given within the Annual Governance Statement incorporated in the Annual Accounts”.


The report was set out in the following sections:


  Assessment of the performance of the Internal Audit Service against its key targets.

  The results of the Quality Assurance and Improvement Programme and the Chief Internal Auditor’s statement on conformance with the Public Sector internal Audit Standards.

  A summary of the audit activity in 2021-22 and highlighting issues that have not been reported to the Audit and Procurement Committee previously and are relevant to the overall opinion.

  The Chief Internal Auditor’s opinion on the overall adequacy and effectiveness of Coventry City Council's risk management, internal control and governance arrangements.


The key target for the Internal Audit Service was to complete 90% of its agreed work plan by the 31st March 2022. Whilst the plan was originally developed on the basis of an estimate of 650 available audit days, this was subsequently slightly amended to 470 days following a reassessment of available resources in quarter four, and reflected the fact that establishing an accurate resource position was more difficult when changes in staffing occurred during the year. As a result, the performance of the Service had been assessed against the revised audit plan of 470 days. The service delivered 87% of the plan.


As a result of the pandemic and the need to prioritise work which had been required to support the Council’s ongoing response to Covid-19 throughout 2021-22, the Service had been unable to progress the improvement actions from the 2021-22 improvement plan. These actions had therefore been carried forward to the 2022/23 plan. Forthcoming progress against these actions would be included in future reports to the Committee. 


Details of audit reviews carried out in the financial year 2021-2022, along with the level of assurance provided, were set out in an Appendix to the report.


A summary of the findings of key audits that had not already been reported to the Committee during the Municipal Year 2021-2022 were included in further Appendices to the report. In all cases, the relevant managers had agreed to address the issues raised in line with the timescale stated. The reviews would be followed up in due course and the outcome reported to the Committee. 


In respect of follow up of disclosures made in the Internal Audit Annual Report 2020-21, in the previous annual report, the Chief Internal Auditor identified two areas where she believed significant control improvements were required.  The report provided an update on each of these areas: Information Risk Management and IT / Cyber Security.


The Public Sector Internal Audit Standards (PSIAS) highlights that a key responsibility of Internal Audit is to provide an objective evaluation of, and assurance on, the effectiveness of the organisation’s risk management, internal control and governance arrangements.  It requires that the annual internal audit opinion provided by the Chief Internal Auditor is a key element of the framework of assurance that informs the Annual Governance Statement. 


In the Chief Internal Auditor’s view, sufficient assurance has been obtained to form a reasonable conclusion on the adequacy and effectiveness of Coventry City Council’s risk management, internal control and governance arrangements.  This takes into account the internal audit work performed during 2021-22 and other sources of assurance, specifically the work of the Corporate Governance Steering Board (of which the Chief Internal Auditor is a member), Corporate Risk Register and the Covid-19 Risk Register.  It is the Chief Internal Auditor’s opinion that moderate assurance can be provided that there is generally an effective and adequate framework of governance, risk management and internal control in place to meet the Council’s objectives.


RESOLVED that the Audit and Procurement Committee considered and notes:


1)  The performance of Internal Audit against the Audit Plan for 2021-22.


2)  The results of the Quality Assurance and Improvement Programme and the Chief Internal Auditor’s statement on conformance with the Public Sector Internal Audit Standards.


3)  The summary findings of key audit reviews (attached at Appendix two to the report) that have not already been reported to Audit and Procurement Committee during municipal year 2021-22 and which are relevant to the opinion on the overall adequacy and effectiveness of Coventry City Council's internal control environment.


4)  The opinion of the Chief Internal Auditor on the overall adequacy and effectiveness of Coventry City Council's risk management, internal control and governance arrangements.

Supporting documents: