Issue - meetings
Update on Risk Management Activity
Meeting: 09/06/2026 - Audit and Governance Committee (Item 144)
144 Update on Risk Management Activity
PDF 393 KB
To provide assurance of the adequacy of the council’s risk management framework and internal controls in 2025/26.
Additional documents:
Minutes:
The Director of Finance introduced the quarter 3 update (Oct–Dec) on the corporate risk register and risk management arrangements. The following principal were noted;
1. The risk register had been reviewed by the Corporate Leadership Team and Cabinet, including risk scores, controls, and mitigating actions.
2. One risk score had changed relating to SEND (Special Educational Needs and Disabilities) due to planned reforms and financial impact.
3. Ongoing risk management activity continued at directorate and service levels, with internal audit aligned to corporate risks.
4. A fuller assessment of risk management effectiveness is included in the Annual Governance Statement (to be discussed later in the meeting).
5. Future reports would highlight changes more clearly (e.g., using colour) for committee members. (Action 2026/27-1)
In response to committee questions, it was noted that;
I. Although most risks are rated high, this reflects their inherent significance at a corporate level, not a failure to manage them. Mitigations are applied to reduce their impact and likelihood where possible.
II. The council follows a risk appetite approach, meaning some higher risks are accepted in order to achieve strategic objectives (e.g. transformation), while others (like safeguarding) remain very risk averse.
III. Not all risks will reduce over time, some remain inherently high, even with strong controls in place.
IV. The corporate risk register only includes the top-level strategic risks; additional risks exist at directorate and project levels, with serious ones escalated upward.
V. The committee was reminded that their role was to ensure robust processes and oversight, rather than manage individual risks in detail.
VI. There are ongoing review, training, and potential audit of the risk framework to strengthen assurance and consistency across the organisation.
The committee noted the report.