Cllr Liz McShane - 0:00:07
Good evening, everyone, and welcome to the meeting of the Audit and Governance Committee. 1 Apologies for Absence
This meeting will be webcast live to the internet. For those who do not wish to be recorded or
filmed, you will need to leave the chamber. For members, officers, and others speaking
at the meeting, it is important that microphones are used so viewers on the webcast and others
in the room may hear you.
Would anyone with a mobile phone please switch it to silent mode
as they can be distracting?
I would like to remind members that although we all have strong
opinions on matters under consideration,
it is important to treat members, officers,
and public speakers with respect.
Thank you.
And hopefully everybody's got enough water to do them
during the meeting.
So agenda item one, apologies for absence.
Microphone A - 0:00:57
Thank you, Chair. Yes, we've received apologies from Councillor Godfrey.
2 Declarations of Interest
Cllr Liz McShane - 0:01:01
Okay, thank you. Item 2, declarations of interest. No? Okay, great. And then the minutes from 3 Minutes
the last meeting, pages 7 to 14. Are we happy with, agree those minutes? Agreed? That's
4 Internal Audit Quarterly Update Report from the Head of East Kent Audit Partnership
great. So we move on to item 4. So we're getting into the meaty part. So the internal audit
quarterly update report from the head of East Kent Audit Partnership, and that's pages 15
to 34 of the pack. So, would Alan like to introduce it? Oh, sorry. Is it Alan? Or Chris?
Microphone F - 0:01:35
Thank you, Chair. Yes, the report on page 15 is the internal audit update report that shows the internal audit work that's been completed since the last committee meeting.
If I can direct you to page 19, this shows the main reports that have been completed
within the period, there being five in total.
The assurance levels coming out for these
were three substantials, one reasonable
and one not applicable.
The reason one was shown as not applicable
was the supply chain cyber security review
was undertaken as a consultancy piece of work
and it was undertaken by KCC computer auditor
on behalf of ECAP.
So there's no concerns there for the committee
from the main reports completed.
Moving on to page 26, which shows the follow -ups that have been reported,
and there were seven follow -ups reported for the period.
These coming out with six assurances of substantial and one reasonable.
And on the reasonable assurance, which was GDPR,
there was one high recommendation, which is still ongoing,
That is shown or mentioned in section 3 .3, which shows that it has been taken on and it's being worked on across Kent.
They hope to have this fully implemented by September 2026.
Moving on to page 32. This shows the audit plan for the period up to the 31st of May.
The target for the period being just under 17 % and it comes out at 11 % for Folkestone.
So it is just slightly behind and we hope to catch that up over the coming months.
Those are the main points of the report and we would be pleased to take any questions
you may have.
Thank you.
Thank you Chris.
Cllr Liz McShane - 0:03:38
Any questions from members? Who would like to go?
Councillor Walker, sorry.
Thank you, Chair.
Cllr Belinda Walker - 0:03:54
There's just one really on page 25 where it says, and the bullet point's at the bottom there,
no single complete list of suppliers
having council data or accessing systems is in place.
I just wondered in light of that
if it should be a corporate risk on that.
I don't know what people feel about that.
Thank you.
Who would like to answer that?
Cllr Liz McShane - 0:04:14
Kristin. Thank you.
Microphone E - 0:04:18
Within the action plan for this particular review, the response to that is, as we sort of set out in the explanation
of why we undertook this piece of work as a consultancy,
because the authority is working towards the framework
and they're aware of what they must do,
there are processes in place to ensure
that's already happening.
And the concept around this action plan
was to make sure there was a roadmap
to make sure everything was signposted
to what should be happening.
So it's a good point to say,
should it be escalated to be in a corporate race?
But I don't think we're at that point in the sense,
well obviously the risk experts will consider that.
From the aspect of what we raised
within the internal audit report,
it wasn't seen to be critical
and therefore wasn't escalated.
But for the organisation to take a second look at that
and reassess it is obviously part of what you're raising.
But we weren't so concerned when we considered it.
It's just something that they do need to do
as they move forward to reach the CAF.
Thank you.
Councillor Thomas.
Cllr Liz McShane - 0:05:18
Thank you, Chair. Just following up on that,
Cllr Paul Thomas - 0:05:24
the second, sorry, the third bullet point sort of carries on that same thing,
which says due diligence for suppliers' cybersecurity
before contract award is not consistent or risk -based.
So when you look at that and you think,
we don't have complete list of all those people
who can access council data and access systems,
and there's no due diligence of the suppliers' cybersecurity,
so how good are their systems
that are interfacing with ours?
And are we sure that that is not going to create a problem
for us either now or sometime in the future?
Thank you.
Good point, Councillor Thomas.
Thank you, Chair.
Microphone E - 0:06:09
So the key words there were consistency. It was happening and the programme to completely assess all of the third -party suppliers is
in place.
We did have a presentation at this committee two meetings ago, I think, from the digital
lead explaining where they were at and where the complete action plan was sort of presented.
so it might be worth us perhaps re -bringing that
when we do the follow -up to this piece of work.
So it was more about the consistency and the application,
not that it was completely missing.
So yeah, perhaps this could have been worded slightly
broader to explain that to the committee.
But yeah, these things are known
that they need to be happening.
The third -party risks are being assessed.
It was the completeness and the consistency of that
that this review was picking up.
And as I said, the authority already knew
that they needed to be doing this and had plans in place,
so this was just capturing that in that form.
I hope that helps give assurance to the committee
that there was nothing, no real alarm bells here.
Thanks for clarifying that.
Cllr Liz McShane - 0:07:11
Any other questions? Jonathan?
Thanks, Chair.
Mr Jonathan Hicks - 0:07:17
Just to come back on that point, the modules, the action plan for the cyber assessment framework
is part of the actions that's included
in the corporate risk already for cyber threat.
So it's at the point that this report was written,
it was in relation to the complete in the audit,
but it's an ongoing process.
And as part of that, there are modules
that are still being completed.
And some of those actions will be in that.
Thank you.
Councillor Chalmers.
Cllr Liz McShane - 0:07:49
Sorry to say, just coming back on that. Cllr Paul Thomas - 0:07:55
That seems to be slightly inconsistent then. In the gender item nine, we'll get there.
Under C1, under cyber threat.
We've actually reduced cyber threat
because we've said the score's gone from 12 to nine.
So therefore it's now tolerable.
But we do seem to have this incomplete piece over here
which is who's accessing our systems
and how robust are their systems they are accessing us.
So I just wonder, how was that score reduced from 12 to nine
to make that risk tolerable?
Thank you.
You can leave it to agenda item,
next agenda item if you want to.
Yeah, okay, thanks.
5 Internal Audit Annual Report 2025/26
Cllr Liz McShane - 0:09:11
Cllr Liz McShane - 0:09:12
Are we all happy? Are we agreed? Agreed. That's agreed. Thank you. So moving on to item five. Thank you.
Which is the internal audit annual report 25 to 26.
Who would like to introduce this?
Christine, thank you.
Thank you, Chair.
Microphone E - 0:09:31
Members before you tonight is the annual report. It is a backward look at 25 -6 and all of the pieces of work that are assessed within this
report are pieces of work that have been presented to the previous four meetings of this committee.
so there's nothing new in this report,
but paragraph 1 .1 on page 36
sets out the purpose for the report.
It's a very important report in the calendar
for this committee to consider.
And it leads very, very nicely into meeting the objectives
of the committee when you consider
the annual governance statement.
Internal object is only one of many sources of assurance,
but it is a key source of assurance for you.
So those bullet points set out in paragraph 1 .1
are the aims of the report, and I hope to just take you
through the report and meet those aims
as we consider the conclusion.
So paragraph, page 40 is the next part that I'll take you to
because the report itself is in two halves, really.
And the first half of that starts on page 40
in paragraph three where we talk about the performance
of the East Kent -Aldrick partnership itself
rather than what we have discovered in our work.
Again, it's very good to be able to report to you that the team has met its objectives
for the year, and we have returned within the year of a saving to the partners of 20 ,000
and rolled over a small pot of 27 ,000 that we will agree with the Section 151 officers
whether we spend or refund that to the partners in 26 -7.
And some of that work has enabled us to engage the KCC computer auditors as well to balance
out our needs and bring in those specialisms
for some of the work that we've undertaken.
So that's an added bonus.
We weren't set up to make savings and deliver savings,
but it's always nice when we can do that.
You'll see though from the balanced scorecard,
which is one of the key appendices there,
that we haven't delivered 100 % of the days
to all of the partners, and we did owe some of the days
to folks to indeed in this year.
And clearly we talked to our shared services being,
well as at the 31st of March of the year,
we will of course have some work in progress
at each site and we'd be slightly ahead and slightly behind.
We did have a vacancy in the team,
which helped create the saving,
but also helped us fall behind.
So we have got plans in place to catch up.
So, but none of that delay, if you like,
it just pushes audits back in the overall strategic plan.
So that, I have been able to consider
whether we have completed enough assurance work
to provide a conclusion in this report,
which I shall now take you through
as the second part of the report,
which starts on paragraph four.
So we take three key high -level views
of the work that we've completed in the year,
and paragraph 4 .1 on page 42 talks about
the 127 recommendations that fell out
of the reports that we concluded.
The criticality is spit out there.
There were no critical recommendations,
37 high priority, medium, 58, and low, 32.
We'll come back to those in a later part of the report.
The assurances that we concluded in each of the 22 pieces
of work that were finalised, 100 % of the assurances
resulting from the internal audit work were reasonable
or substantial assurance.
This is an absolutely excellent record.
We always talk about follow up being a really important
part of internal audit work.
We turn up, we take a snapshot in time,
and we make our recommendations,
but we need to go back and say,
what's changed, have controls improved,
have weaknesses or risks been mitigated
through these recommendations?
We need to test them to see that they're effective embedded
and you can take assurance from those.
So paragraph 4 .3 starts talking about that follow -up work.
20 follow -ups were completed in the year.
There were three that had a limited assurance
from the year before that were followed up in 25 .6,
and you can see in the table on page 44,
just over the page there, that each of those were resolved
with a reasonable assurance improvements
and no recommendations outstanding at the time of follow -up.
And all of the other follow -ups resulted
in either substantial or reasonable assurance.
So again, a very, very clean track of how that's progressed.
A new table for you this year in paragraph 4 .4,
in terms of our recommendation tracking,
external audit at one of our other sites,
we're very keen to see in the one place
the recommendations we've raised,
the recommendations we've followed up,
the recommendations that haven't been implemented,
and for whatever reason in terms of the amount of risk
that might be carried, and anything that's been escalated
to the committee.
So the colourful table there is very, very green
in this report, and you will see the first line there,
the 34 of those recommendations are yet to be followed up.
Now that's not because we're behind,
that's because they're not due yet.
We've talked to the committee before,
There's never an ideal time to do the follow up,
but it's clearly going to be after the date
that management have said that they will complete it
by it's point that's going in beforehand.
And we also need enough transactions
to have gone through that process
to be able to test something
to confirm it's effective and operational.
So those are featured in the table below the colourful table.
You can see the spread over those pieces of work
that are yet to be done.
They will be scheduled in and of course reported
through the quarterly update reports
in the future committee meetings,
impact some of those have already probably done
or are a work in progress.
What's another point to draw members' attention to here?
There were two high risks that were tolerated in the end,
and one of those was to do with an interface
that couldn't be written within one of the systems,
so there's almost nothing that could be do about that.
But again, in terms of what I need to escalate to you,
members, at this point in the year, and say,
these are areas of concern.
There is nothing to flag in this report.
So I'm very, very happy to present that table
for the first time, and we'll see that hopefully develop
as we move through future years.
So that leads me very nicely to the conclusion,
and that's a very big change.
The Internal Audit Annual Report has always asked
for an opinion, we've always been paid to give you
an opinion, which has been a pleasure.
But the new standards this year introduced it
as a conclusion.
I have, although, continued to split it
into the three elements of corporate governance,
risk management, and internal control.
Paragraphs 5 .1, two, and three
give those summary results from the work.
This led me to form my overall conclusion,
and with much deliberation,
it was very, very difficult to conclude anything
other than when you read our definition
of providing a substantial assurance,
which provides a sound system of governance,
risk management and control,
with those internal controls operating effectively
and being consistently applied
to support the achievement of objectives
in those areas that we have audited.
And that's the only caveat that I can give you, members.
This opinion applies to the areas we have audited.
There is no way of giving absolute assurance,
but this is the first time, and with great pleasure,
that I give this opinion to you.
I'm happy to take any questions.
Thank you. That really feels like a strong report,
Cllr Liz McShane - 0:16:52
and thanks for all the work that the East Kent Audit Partnership has done, for the other game. Any questions on this agenda item?
Who would like to start?
Not looking at you, but...
Yeah, thank you.
Yeah, thank you very much for the report.
Cllr Paul Thomas - 0:17:11
It's laid out in a way that makes it very easy for us to go through and have a look at it. Just coming back in terms of page 45 on the table there,
The reviews that are,
they said there are a number of progress reports
yet to be undertaken.
Eight of those are in the area of network security.
We've just, I've raised the issue about cyber security
and the fact that the corporate risk has been reduced.
So again, I wondered, is there anything that's likely
to come out from the network security relationship
related recommendations yet to be followed up that could affect that corporate risk to
do with cyber security? That's my question. Thank you.
Microphone E - 0:18:06
Thank you. Thank you, Chair. The follow -up report will track the recommendations made previously. It won't be a complete renewed audit of network security. That said, we've
to IT related audits in the plan for this year
that are about to kick off hopefully soon.
The action plan, I'd have to look it up
to give you the detail of what's in there,
but in terms of the year end hasn't escalated those risks.
How many are there?
Sorry, that's in that table, isn't it?
One page though, network security.
There's AHS, you're right, sorry.
I can get the profile before the end of the meeting
if you want to see the criticality of those.
Rest assured, when we have agreed the final report
and that interval between internal audit leaving
and going back to do the follow up,
that is the point where management are,
we ask management to give themselves a challenging
but realistic timetable to deliver those things,
because if it's right to policy and it's got to go through
several committees to be, before it can be adopted,
we need a slightly longer time scale.
If it's deliver certain management actions,
because they can be usually shorter timescale.
And naturally, if we're saying,
well, we haven't had any critical risks here this year,
but if it's a high -priority risk,
we'd like to see it close down sooner
rather than next April.
So all of that is a balancing act
when we agree that final action plan,
when we sign off that report,
and the timing of the follow -up, as we say,
is the best fit for that,
because it needs to have been embedded
before we come back and tell you
management haven't had enough time to deliver that yet,
which is pointless.
So I appreciate I'm a bit rambling here,
but we are not escalating anything at this point in time
to you, and of course you're absolutely right,
it picks up to when internal audits work
does touch upon anything that needs to come up
in the corporate register, which is a conversation
we'll have at the next item.
But yeah, I hope you can trust this report
to highlight anything that you need to have concerns
about now, and that's the point of this report,
is there isn't anything else.
Yeah, and thank you for that.
I mean, it's always difficult at the time.
I appreciate how difficult it is,
the fact that you do have that lag
between one and the other.
So my follow up question on that really is,
of those, is there anything in there
Cllr Paul Thomas - 0:20:25
that is a repeat from the previous year or something that hasn't been satisfactorily mitigated
through a previous action?
Is that something that is looked at to say,
we thought we'd fixed it, but we haven't.
It's just, and particularly around the area of network security and cyber security.
That's my question, thank you.
Thank you, that's a great question.
Microphone E - 0:20:54
And I can point to one of the other partner sites where I can say categorically there are some themed reoccurring issues.
I can't think of any here that are on this committee paper here, that we are saying,
yeah, we've told you about this before and it's still limited.
We've told you about this before, it's still limited.
That is just not the case.
Cllr Liz McShane - 0:21:14
So again, I think part of what I was looking for that is, Cllr Paul Thomas - 0:21:17
you know, are there, you know, organisational weaknesses that this thing is identifying
that are not necessarily being fixed in a timely manner?
Does that make sense?
Yeah, thank you.
That's the only thing I was trying to get to.
Yeah, thank you.
If we go to that colourful table,
Microphone E - 0:21:35
I asked AI to give me a summary of it. And it talks about the conversion rate.
And in fact, it identified the 34 as a backlog and a lag.
And I thought, no, no, you don't understand AI.
That's because they're not due yet.
But it talked about that conversion rate,
and it said, best in class, excellent.
So I think if we're tracking the amount of green
in terms of internal identifying a potential issue,
managing considering that,
and deciding what they're going to do about it,
us coming back and testing that it's been done,
and telling the committee it signed off,
that theme is working really well at this authority.
Thank you, Councillor Thomas.
Cllr Liz McShane - 0:22:15
I see Councillor Prita would like to ask a question, maybe? Just going to ask a question for clarification on this.
Cllr Tim Prater - 0:22:23
Thank you for the report and the conclusion of substantial assurance.
Being something of a relic of governance audit,
I don't think that I've seen substantial assurance
very often, and you've been doing this,
Can you remind me how long you have been providing us with an opinion for this council and also
how many councils you provide opinions for and how often you've given substantial assurance
across that time?
I can answer that very clearly, thank you.
Microphone E - 0:22:52
E -CAP celebrated its 20th birthday in April, so the answer to the first question is 20 years.
It's starting to show on me, I mean.
I have never given substantial assurance and we are giving an opinion, or conclusion sorry,
now for authorities.
Never before.
I have given limited assurance before, but never substantial.
That's great to hear.
Anybody else?
Cllr Liz McShane - 0:23:26
Are we all good on this item? In that case, we'll go to the recommendations,
which are to receive and note the conclusion
of the head of Audit Partnership and Report,
Audit and Governance 2604.
Second, to receive and note the annual report
detailing the work of the ECAP and its performance
to underpin the 25 -26 conclusion.
Who would like to propose this?
Councillor Wing, thank you.
And a seconder?
Councillor, I'll look back at you.
And can we agree this, please?
Agreed.
6 Annual Governance Statement
Cllr Liz McShane - 0:24:01
Moving on to item 6, we have the Annual Governance Statement 2526. Over to you, Ian.
Thank you, Chair.
Mr Ewan Green - 0:24:09
Members, this is the annual report that you receive, and each year the Council is required to produce the Annual Governance Statement.
It really describes the corporate governance arrangements that underpin the business of
the Council.
What are the controls, the processes, the safeguards that we have in place, the way
of measuring the governance of what we do and the strength of that?
Part of the responsibility here is the responsibility for ensuring that our business is conducted
in accordance with the law and proper standards and that public money is safeguarded and properly
accounted for.
So what you have before you tonight is the annual report
and the format of this sets out, I think,
how the council has met these governance commitments
as set out in our code of corporate governance.
And it's a fairly meaty report, I appreciate,
so there's a lot of content in there.
And it's also a public -facing report,
so it's a really important document for us as a council,
which relates for you as members and for the public
in demonstrating the strength and robustness of our corporate governance in the framework.
So what you have before you tonight in Appendix 1 is the governance statement and as part
of that we have the action plan for 26 -27 which is areas we want to focus on as an officer
team for you. And the second appendix that you have tonight is the action plan that you
agreed last year in 25 -26, just giving you an update on the progress against these actions.
The recommendation is this evening to approve the Governor's statement itself and the action
plan for 26 -27 and to note the progress, as we said, in Appendix 2 for the 25 -26 action
plan.
I think the report is fairly self -explanatory after that year, so I will stop there.
I am very happy to take questions.
Cllr Liz McShane - 0:26:09
Who would like to ask the first question of this item? Councillor Thomas.
Cllr Liz McShane - 0:26:22
Cllr Paul Thomas - 0:26:26
I think, had it not been for the fact that we spent an hour and a half on local government due organisation, I know you were in scrutiny last night.
I've probably been asking a few more questions around there.
but I'd say if you want to know,
go and have a look at the webcast from last night.
So again, the things that I picked out
were all really around our management
of local government reorganisation,
which we went through last night.
So I have to say I'm satisfied with where we are
at this moment in time, thank you.
Ian?
Cllr Liz McShane - 0:26:59
Thank you, that's a really good point to raise, Mr Ewan Green - 0:27:02
I think what I would point out is this is the backward loop, so 2526, and I think you can feel certain that next year's statement when you have it, there's going to be a significant
amount more about local government organisation for you to pick up. Very good point, thank
you.
Cllr Liz McShane - 0:27:19
I've just got one. Since year end, have any significant governance issues emerged which members should know about before approving the statement?
No. Thank you.
Mr Ewan Green - 0:27:33
Cllr Liz McShane - 0:27:35
Anyone else? No? Okay. We've got three recommendations. One, to receive and note the report. Two, to approve the draught annual governance statement for 25 -26 and the action plan for improvement
following review of effectiveness of governance arrangements for 26 -27 as set out in Appendix
one. And three, to note the end of year progress updates against the action plan for 25 -26
as set out in Appendix 2. Could I have a proposer, please? Councillor Thomas, thank you. And
a seconder, Councillor Walker, great. We're all happy to agree these recommendations?
Agreed? Thank you. So moving on to Item 7, which is the update on the Statement of Accounts
2526 and external audits.
Who would like to take this?
Jonathan, thank you.
Thank you, Chair.
Jonathan Smith - 0:28:32
So this report presents an update on the statement of accounts and the audit for 2526 and updates members on the 2425 audit.
The audit partner for Grant Thornton is here to talk through their report,
which is attached at Appendix 1 of the report.
That's Paul Dossett to my right.
The Council publishes statement of accounts on time on the 30th of June,
As members will be aware from the March A &G meeting
and discussions there, we were obviously going through
a finance system upgrade and this is an achievement
in terms of in the intervening period
of obviously change systems and close our accounts
in the new system.
Section two of the report covers the update
to the 25, 26 statement of accounts.
Section three of the report goes through the report
updates members on the 24, 25 accounts.
So whilst the auditors issued their audit opinion on the 4th of February 2026 for the 24 -25 accounts,
they were not able to close the audit whilst there was sort of outstanding matters
such as the whole of government accounts, WGA and other matters.
Those matters have now been concluded and the audit certificate was issued on the 14th of July 2026 for the 24 -25 audit.
That was published on our website last week and that's formally closed the 24 -25 audit.
The other matter to highlight is the change in materiality threshold.
The auditors are part of their audit planning.
We use an estimate to determine materiality.
They made an estimate based on balances from 24, 25 as part of their audit planning.
However, since their week past year ends, they've obviously updated that and reviewed
that materiality position.
That's dealt with section four of the report and the thresholds listed there.
I'll now pass over to Paul Dossett who will talk through their part of the report.
Microphone D - 0:30:18
Thank you Jonathan, good evening members. Obviously we're into the business end of the audit. Just a reminder to members in terms of what we're trying to achieve this year.
So we've done some interim testing and planning early part of the year. Obviously we're taking
into account the new ledger and obviously Jonathan said that has delayed us a bit but
It didn't delay the accounts being produced on time,
that's a good achievement.
So then we've done some sample selection
in the last few weeks.
That hasn't been as complete as we would like,
but I think that's probably to be expected
given the sort of changing system.
And then we're coming back in mid -September
to complete the work,
and we're coming to report to this committee on the work.
I think it's December 2nd or whenever your next meeting is or your next meeting that's
near the end of November target that we have put in place.
So it's incredibly, although we are a bit behind, I think we can catch that up.
It's obviously going to be reasonably tight and obviously we expect to continue the good
working relationship that we have with the Council to achieve that.
Obviously the local government audit is under more scrutiny now than it probably has been for a long time.
MHCLGR regularly contacted us to cheque whether people have produced accounts and things like that.
They'll be contacted us again, no doubt, to monitor progress.
So we are absolutely committed to making that work.
The Council is in the half of all Councils, roughly,
where we have an unqualified opinion to carry forward.
So that's clearly an objective for us all to maintain.
And obviously that's what we're aiming to do.
So the most crucial part of the work is the selection,
samples, assessment by Council,
and then back to us for completion.
That's the most time -consuming bit of the work.
So clearly we need to hit the ground running in September,
although colleagues on our side, my manager, Kiran,
will be keeping regular contact with Jonathan
to make sure that we're happy with the progress of that.
So I think at the moment, I think we're sort of broadly
satisfied with where we are in the circumstances of the new ledger.
I think we'd be further ahead if it wasn't a new ledger, but there is.
so we've got to work with that.
So that's the main thing I'd like to say about 25 -6, really.
I think we're on target.
Alongside that, we need to do the value for money work.
As we reported in our plan,
we hadn't identified any significant weaknesses,
but we probably will do it now that the LGR plans have been set up,
we'll probably do some commentary and some thought processes
for grant forms about what we expect going forward.
And one of the more obvious ones that's relevant to the Council,
I'll mention it now, is what arrangements is the Council putting in place?
I know it's early days to ensure that your 27 -8 accounts,
your final year of folks in the High District Council,
are prepared by June the 30th and audited by the 30th of November,
which will be the statutory deadline in place.
And what arrangements are in place for that?
a question that's not particular to you, we'd be asking all councils undergoing LGR,
what are your arrangements for that? Because there's a significant risk of
course of things going backwards, which none of us want, certainly government
doesn't want, and therefore effectively spoke to MACOG about this only on
Tuesday, that we need to have arrangements in place and they need to
support them in whatever way they can, of course all councils undergoing LGR. So
So that'll be a crucial part of it.
So that'll be something we'll be monitoring progress on
over the next couple of years.
Just to reflect on the 24 -5 certificate closing,
all audits have to, basically you have an audit opinion,
which we gave earlier in this calendar year on 24 -5,
and then we have to certify the audit closed.
There's essentially two things that stop you doing that.
One is the work the National Audit Office do
on the whole of government accounts.
And that's quite a cumbersome process.
It does take some time.
And the second one is where you have objections
raised by local electors.
And you will have to consider those objections.
That also takes some time.
And we were able to conclude on,
well, both those things were concluded just before
we were able to issue the certificate in July.
So all prior years are now closed completely.
so nobody can ever come back to them and ask questions from an audit point of view.
And we're now on to 25 .6, and we'll see how that goes in that regard.
We haven't had any, what I would call, formal formal objections yet,
but we have had some correspondence, I think it will be fair to say.
So that's where we are, members.
The rest of the progress report sets out wider Grant Thornton commentary
and reports from other bodies.
So I'm just happy to take any questions that members may have.
Cllr Liz McShane - 0:35:53
Thank you, Paul, and thank you for your comments and insights. It sounds like we're on track and all the good work's paying off.
Just one comment. You mentioned in your report, page 109,
I think it was page 109, that some papers weren't ready
for when you were doing the July 1st sampling.
Will that have any impact or risk to the completion of the audit timetable?
Thank you.
Microphone D - 0:36:16
I mean clearly, ideally everything is done by this first stage that we were doing so that everything is ready in mid -September.
So we are a little bit behind, but I mean behind doesn't mean we can't catch it up,
Chair.
We will be working to catch it up.
The audit team are very clear about the deadlines and what they need to achieve to do this.
I'm sure the finance team are equally clear.
So I'm sure we can work together to catch up.
Thank you, that's good to hear.
Cllr Liz McShane - 0:36:43
Questions for members? Councillor Morget.
Good evening.
Thank you so much for all the work you put into.
Cllr Rich Holgate - 0:36:51
I had two questions. My first one is perhaps one of pedantry, so forgive me, but on Appendix 1, Grant Thornton
mentions that the report will be back in November 26th, but then the overlying report to Section
2 .2 says it will be back in December 26th.
Was that intentional because of the meeting calendar mechanism?
or is that...
It's not to do with this.
So what we have...
Microphone D - 0:37:19
The reason that I mentioned both dates are covered, December is when the meeting is,
so that's the meeting it will come to.
The reason we talk a lot about November
in our communications more broadly
is we are aiming across Grant Thornton
to bring every single audit home
and finish by November the 30th.
The reason we are targeting November the 30th
is that that is the statutory deadline from 26 .7 onwards.
So for example, in 26 .7 you can't have an order committee in December to deal with this.
You have to have one in November.
Technically the deadline for 25 .6, the statutory deadline is 31st of January.
So in theory, although we're working to this December order committee,
we could carry on in theory according to the government rules, but we're not planning to do that
Because if we take it all the way to 31st of January, it doesn't say a great deal about our capacity to meet the deadline next year.
So that's why the two... Obviously, from a technical point of view, it doesn't matter this year that we have the audit committee on December the 2nd or whenever,
and then sign immediately after that. That's fine, because that's over two months before the deadline.
But if we can hit December 2nd audit committee and sign the next day, it means we can do
it the year after for November 30th.
So that's why I talk about the two debates.
Thanks so much.
Cllr Rich Holgate - 0:38:44
And my second question was on Appendix 2. You mentioned about completed consideration of an objection brought to our attention.
I'm just wondering, you just said that these matters have now been dealt with.
It's suspiciously vague.
I don't know whether you could share some more information on that.
So, where...
Microphone D - 0:39:12
Yeah, local elector raised some issues about contracts and waivers, documentation on the Council's website and compliance with regulations. So, because it was a formal objection whereby the local elector made allegations,
is not the right word, but asked questions and challenges about whether that was appropriate
or whether the way the council was carrying that out was appropriate.
So, we had to investigate that.
We worked with council officers to understand what they were doing,
to understand some of the things they were changing in terms of practise
around procurement and things like that.
And we were satisfied that the Council's response
was adequate and there was no need for us to do any more work
or do anything else because there's a very high,
local government electors raise questions.
That is a cost to the taxpayer.
So what we do is we consider it and we investigate it
if we think it's properly formed.
But in terms of the actions we might then take, they can be quite time consuming.
So for example, we could conclude that a local elector had a good point or such a good point
that we were going to do a public interest report, which would be hugely expensive and
time consuming and we do do them in some cases, but mostly we take the view that it wouldn't
be in public interest to take these things forward.
In this particular case, we took the view that no further action was needed.
What the council were doing to regularise its arrangements was satisfactory.
Cllr Liz McShane - 0:40:58
Thank you. Any further questions on this agenda item? No? In that case, we've got four recommendations.
One, to receive and note the report.
Two, to note the Grant Thornton progress update, section two of the report.
3, to note the audit certificate for the 24 -25 statement of accounts, section 3.
And finally, to note the update to the materiality levels
for the 25 -26 statement of accounts since March 26, section 4 of the report.
And could I have a proposer, please?
Councillor Holgate, thank you. A seconder?
Councillor Wing, are we all happy to agree this item, the recommendations?
Agreed.
8 Council Contract Variations and CSO Waivers
Moving on to agenda item 8, procurement,
Council contract variations and contract standing orders.
We have those.
Who would like to introduce this?
Mary, thank you.
Thank you, Chair.
So this report is an update on procurement governance
Folkestone & Hythe Officer - 0:41:51
activity further to report presented to this committee back in July, 2025.
It contains a summary on the use of contract variations
and waivers under the Council's contract standing orders
for the financial year 2025 -26.
It also contains an update on the work
the procurement function has been doing
to improve compliance with the CSOs
in the 12 months since the previous report.
So section one of the report provides
the background and context.
You'll have noticed in the graph presented
at paragraph 1 .1 that overall there has been
a reduction in the volume of both contract variations
and waivers since the last report.
Section 2 contains a review of contract variations
in the period with a breakdown of the reasons
that officers gave for seeking those contract variations.
And section 3 similarly contains a review
of the use of waivers and the justifications
that were given on the waiver requests.
And then section 4 sets out what the procurement function
has done to improve CSO compliance
across the council service areas.
The main points to highlight are that
the implementation of the council's
new financial management system
has enabled us to embed new controls
in the purchasing process to support CSO compliance.
And the recommendations for updating
the council's constitution included some updates
to the CSOs to improve the council's agility in procurement.
Those changes were accepted at full council last week.
As a result, we expect to see some further reduction
in waiver and variation requests coming out
of some of those changes to the CSOs.
And there's ongoing work from the procurement function
to improve procurement planning across service areas,
which will also contribute to reducing the numbers
of waivers and variations going forward.
You've answered two of my questions that I have, so thank you for that.
Cllr Liz McShane - 0:44:00
Are any particular service areas requesting repeated waivers? Is there a particular areas using them more than others?
Is it quite broad brush?
It's quite broad.
Folkestone & Hythe Officer - 0:44:18
Some of the waivers that we've seen this year, in the first part of this year, have been related to the renewal of low value ICT systems
and subscriptions to online journals,
but otherwise it's spread across various services.
We had quite a lot of questions
Cllr Liz McShane - 0:44:44
when we discussed this earlier as the committee beforehand, so I'm sure there's some questions that they want to ask.
Who would like to start?
Cllr Paul Thomas - 0:44:57
Thank you very much for the report. It is good to see that, and it shows that increase in control that you talked about in terms of we're now not applying as many waivers
to standing orders as we had been previously. There's still a couple of things that I think
can be worthwhile exploring if that's okay.
So although 26 waivers were approved,
how many waivers were not approved is one question.
In terms of those waivers that were approved,
what is the total value of the contracts
that were waived through waiving standing orders?
And thirdly, what was the highest contract value
that was where the waiver was applied?
Thank you.
Thank you, Councillor Thomas.
Cllr Liz McShane - 0:45:48
Oh, Alan, you happy to answer this? Thank you for the question, Councillor Thomas.
So I think the point is,
Mr Alan Mitchell - 0:45:56
is that quite a few of the waivers that came previously were due to poor planning,
and that we were getting to the point
where we required a waiver
because we hadn't done the necessary procurement.
and there's been a strong emphasis on procurement planning.
So what we were finding is that we weren't actually getting the waivers coming forward
that we therefore needed to decline or to reject because the planning was in place so
that the procurement was undertaken and therefore waiver wasn't required in the first place.
However, we have included a waiver strategy which has strengthened the whole procurement
process, particularly around waivers and contract variations, that we've seen a dramatic reduction
because of the work that Maori and her team have done on that. In terms of values, that's
information that we can go away and get for you and for the committee if that's okay.
Thank you. So again, I think one of my questions was how many waivers were refused?
Cllr Paul Thomas - 0:46:55
Folkestone & Hythe Officer - 0:47:04
I'm not certain off the top of my head because we don't record it. There were maybe three or four. I don't record it specifically. It's more that I send people away and that we have another route to go through.
Cllr Liz McShane - 0:47:18
Is there a plan to record a number of waivers that were refused just to keep a complete audit or is that not necessary?
Mr Alan Mitchell - 0:47:30
It's not required, so you know in fact this whole report isn't required, but because we brought it last year, we wanted to bring it to members again just to show progress
around the the waiver and the contract variation strategy that we put in place.
But it's something that we can record, but it's not required.
Cllr Rich Holgate - 0:47:58
Just maybe to piggyback on this point, the recommendation too talks about the content of robust governance, I suppose with that lens, I think it would be very valuable to
have the rejection rates too for that complete picture.
I suppose for me the values, the lack of values in there, it's again I think a
missing component of the report because when as a committee how can we accept
them and accept that they've all been legally permissible in absence of the
values I suppose that's kind of my curiosity and if we don't have the
values again can we either get an information on that or future proof that
for future reports. Thank you. So we can certainly get the values that's not a
Mr Alan Mitchell - 0:48:44
problem I think one of the reasons why we don't include in to report is because you could skew it so you could have one single contract that's quite large but
then you can have it against seven variations for example say that
information would necessarily be transparent enough in this report but I
think we can certainly find the information there's no problem in
finding information on the number of waivers and also the values of that
That's absolutely fine.
Thank you, Alan.
Members, any more questions or comments?
Councillor Thomas.
Cllr Liz McShane - 0:49:14
Thank you, Chair. Just one sort of, just picking up on something
Cllr Paul Thomas - 0:49:19
that Councillor Holgic said as well about understanding the totality.
So, seven of the justifications are insufficient
number of responses to request for quotations
with insufficient time to retender.
We said procurement planning was the thing that we're sort of hanging our hat on for
the future to understand what needed to be done to make sure we did comply and therefore
didn't need to do the waiver.
So what do you believe is driving that particular number, the insufficient number of responses?
Is that the fact that we might not have on our approved suppliers list sufficient people
in that area, is it indicating that within our environment
that we operate in, there are insufficient people
to provide that service?
So it's trying to understand where do we sit with that.
Thank you.
So for a bit of extra context, a request of four quotation
is where one of the responsible officers
Folkestone & Hythe Officer - 0:50:24
from the service area goes out and obtains quotes without assistance from procurement.
In most of these cases, the procurement has been carried out
with not a lot of lead -in time
before they need the work to start.
And in some cases, they hadn't really invited
enough suppliers to provide quotes
to ensure a successful RFQ.
So if they need three quotes in hand,
in a couple of these instances,
they'd only requested three quotes from three suppliers.
So they hadn't allowed for some of them to not respond.
That wasn't the case for all of them,
but for some of the ones on there.
and I did go back to that officer in question
to raise that with them to make sure
that they invite enough suppliers for the failure rate.
Thank you for that clarification.
Councillor O 'Dia.
Cllr Liz McShane - 0:51:15
So I just want one more for me. Cllr Rich Holgate - 0:51:18
4 .2 talks about the training that was delivered in April in regards to the procurement,
or the lake procurement and issues attached to that,
because it was the largest waiver category,
seven of the 26 were due to late procurement.
Just suppose anecdotally, what's been the impact
of that training on late procurement since April?
Have you seen a noticeable uplift,
or does that remain a challenge?
There has been some improvement with some areas
coming forward earlier.
Folkestone & Hythe Officer - 0:51:53
and particularly with the LGR work coming up as well, there's more forward thought and fore planning
of starting that tendering process early
for the larger contracts to make sure
that we're able to close those out
with room around the other work
that officers will need to do with LGR.
Thank you.
So we're ready to go to the recommendations
Cllr Liz McShane - 0:52:21
to receive a note of the report. Number two, note the continued robust governance of procurement activities and adherence to
contract variation protocols. And three, note ongoing efforts to embed and refine procurement
processes in line with evolving statutory obligations and market dynamics. Who would
like to propose this? Councillor Thomas, thank you. Seconder? Councillor Walker, thank you.
And are we happy to agree this item? Great, thank you. Moving on to Agenda Item 9, which
9 Corporate Risk Register
which is a corporate risk register.
So over to you Jonathan for the dashboard part.
Mr Jonathan Hicks - 0:52:56
Good evening, thank you Chair and good evening members. This report provides the committee with its regular update
on the Council's corporate risk register,
which is reviewed quarterly to ensure risks
remain appropriately identified, managed and monitored.
The register currently reflects the key risks
that could affect the delivery of the Council's strategic projects and services.
Since the last report to this committee in March,
the overall risk profile remains relatively stable,
with no new risks added and no significant changes to the risk scores.
Cyber threat continues to be our highest rated corporate risk,
reflecting the ongoing threat faced by all our public sector organisations.
but it has already been noted that we've reduced the risk score from extreme risk to high risk.
Now, Councillor Thomas asked a question on this previous item and I'd be happy to pick up on this if you wanted to pose that question again.
But I'll pick up a couple of other points to note in the report.
One, that local government reorganisation remains a key strategic risk,
given the uncertainty in the scale of change involved,
although that's a shifting landscape.
Other pressures relating to temporary accommodation,
sports and leisure provision,
and the implementation of the EU entry -exit system
continue to be closely monitored.
On the latter, the EU entry -exit system will note
that we've increased the level of risk
due to the peak holiday season
and potential disruption to traffic,
and the continued rollout of biometric testing,
which may delay access to the Port of Dover.
Members may also wish to note the continued focus
on our carbon neutral commitment
and wider climate change resilience,
alongside the management of major regeneration
and transformation programmes like FOCA
and the Focus to the Brighter Future project,
which remain on the register.
So the purpose of tonight's report is to provide assurance
that these risks are being actively managed
to highlight any emerging issues
and to give the committee an opportunity
to challenge and comment on the risk profile
before the register proceeds through its next review cycle.
In the report on page 135,
you'll see a sort of summary table
which gives you a bit more detail
on some of the actions that we're doing
against the highest risks and as usual,
appended to the report from page 139
is the overview matrix and dashboard.
Some of the risks on there you'll see
are marked as red on that dashboard.
This simply means that the risk is higher
than you would like it to be
and serves as an indicator to us
that we should be actively trying to reduce it.
Many of those risks, however, have pending actions
that, once implemented, may do this.
So the recommendations are to review the overview,
register and make any necessary recommendations
regarding the Council's management of risk.
And I now have to take any questions.
Who would like to start?
Councillor, Councillor Ring.
Thank you, Chair.
Probably more comment.
Starting with C6, which is the EU entry and exit.
I mean, obviously it's in public domain now,
about the new Westinghouse race course.
And also I know recently they're gonna extend
over Western docks with a small area.
I mean, I presume that will reduce the risk.
Do you see that reducing the risk on that?
Yes, I'm happy to come back on that one.
I think the reason why it's increased rather than decreased
is the fact that there's a lot of unknown.
We haven't seen the full impact of the biometric testing.
So when you have first, what I understand is you have
first time registrations can take a little bit longer.
So that might affect normal traffic.
I think that is the reason why that's gone up.
We've got contingency plans in place
and regular liaison with the Port of Dover
and Kent Highways to manage that risk.
I think it's just to reflect that there's that potential disruption, that it's just
to flag that a little bit higher.
And also C2, which is the LGR, I agree with Councillor Thomas. I was sitting through that
Cllr John Wing - 0:57:42
presentation for overview last night. I, someone, it's been sitting a bit outside the process, I feel a lot more happier now that, I mean obviously we don't want to come down the road
in New Cripe like the risk of that, but I feel in myself more comfortable. And I was
actually surprised about the amount of work that actually has been carrying on behind,
almost behind closed door. And I think the officers who have been doing that work deserve
a big round of applause. That's all. Thank you.
Thank you, Councillor Wing. Any other questions? Councillor Thomas.
Cllr Liz McShane - 0:58:14
Cllr Paul Thomas - 0:58:18
Just coming back to my early question then on cyber, security cyber threats. I said because Because there's no complete list of suppliers
who can access the system or corporate data access.
And the fact that we've reduced the risk from 12 to nine,
but also in here is what we talk about the fact that
that reduction is partly reliant on systems
and certification, for example, CAF,
that are not yet complete.
So again, it seems, are we jumping the gun a little bit here
in terms of reducing that, or are we recognising the work that has been carried out,
and that based on what we are proposing to do,
that we will see that risk reduced when those other actions are completed?
Thank you, Chair.
Mr Jonathan Hicks - 0:59:13
Sorry, yes. Thank you, Councillor Thomas. Just two parts of that.
One is about the relationship to the audit risk
and the reduction here.
But I think if I may take you to section 2 .3 as a report,
it's on page 134.
I'm gonna read what I've written there
and maybe expand a bit on it.
So I think it'd be helpful to understand
what we consider as the risk
and how we have
scored it and the reasons why we've reduced it.
So at 2 .3 I've said that the risk has been reduced to the robust measures put in place
over the past year, including actions undertaken towards a cyber assessment framework.
Also there's been no critical disruption to services and I've said that officers are therefore
confident in reducing the likelihood from very likely, which is more than 85 % chance
of occurrence or regular occurrence to likely more than 50 % chance of occurrence
or likely to occur within the next 12 months. So this is reduce the overall
score from 12 to 9 and brings the risk within tolerance. So there's two
factors in the measurement of risk. One is the impact of that happening and just
to look at the definition of what this risk really is. It is the cyber attack
critically disrupts services, compromises data,
and results in financial penalties.
So that could mean loss of access to networks
and systems going down, not being able to have
the financial system, not being able to pay benefit,
resulting in potential data breaches that might happen,
as well as service interruptions.
So the risk is not about the threat
of us having an attack,
but that it critically disrupts our services.
So we look at the impact score on that, as well as the likelihood of that happening.
So due to the fact that over the last year we've had cyber threat as at the
extreme level, for an entire year, and what that's telling us is
it's imminent, it's going to happen, and we can expect it. We haven't had that
critical disruption to services.
We have a range of actions in place
through governmental compliance,
multi -lay protection, antivirus systems,
as well as the policy framework and training,
data resilience testing, testing backup systems,
as well as working towards the cyber assessment framework,
successful audit.
So all of those things,
to pick up the second point that you made there,
it's about that's provided assurance to us
that we've managed, or we are managing everything
that we can do, and we've reduced this risk
to as low as it could possibly be.
It's still high, we're still saying it's going to happen,
or likely to happen in the next year.
But it's not an imminent threat.
Caveat to all of that, part of your role in the committee
is to provide us with recommendations.
So if the committee's view is that we are premature
in reducing that risk, we can take that back to officers
or provide more assurance to you.
Thomas.
Cllr Liz McShane - 1:02:43
Yeah, so again, the thing which is, so I accept what you're saying,
Cllr Paul Thomas - 1:02:47
and I did agree that which is where I made my comments on for a year long, but we've still got a new financial system
that we're only three months into.
So, you know, you couldn't say that that system's embedded in the organisation yet,
arguably, you know, because I imagine we're still, you know, finding things out about it,
you know, and maybe even tweaking it a little bit.
So, again, I just wonder whether it's worth recognising that within the text somewhere,
to say, almost caveat it, to say, you know, and let's be fair, you know,
we've had a lot of discussion about the new financial system and its potential impact
on the organisation.
So again, I think somewhere we just need to qualify and say,
and this is what we're doing to make sure
that this new system doesn't give us additional issues.
And if that's underpinned by, you know, the level of training
the staff have received, you know, the way that access
to the system is being managed, then I think, you know,
that perhaps tells a little bit more of the storey
about where we were and how we can satisfy ourselves
that although it's, you say, significant, is reduced.
Thank you.
Cllr Liz McShane - 1:04:00
Thank you, Councillor. Mr Jonathan Hicks - 1:04:06
We did have the new system as a risk on here for implementation of the new financial system.
We've taken it off, you'll see that in the report.
That doesn't mean that any risk associated
with the rollout of that and other modules
aren't being monitored.
it just means that it's not a critical,
or not a strategic threat to us,
since the risk was about implementing that system.
I think, just for clarity, the cyber attack risk,
the cyber threat is about us being critically disrupted
from the cyber attack,
rather than our own systems failing.
So I think they're slightly different issues.
If I may, Chair, sorry,
so that's the lack of understanding on my part,
Cllr Paul Thomas - 1:04:57
in terms of the ability of external organisations to access the new financial system, because I think that's where that would likely come from.
So if that is highly unlikely, then I can accept what you've said as justification for bringing that risk down.
Thank you very much, Chair. Thank you.
Thanks for your details and response to Norton.
I'm lost of reassurance.
Cllr Liz McShane - 1:05:21
I'm sorry. Cllr Rich Holgate - 1:05:24
Paul. Thank you, Jude.
Cllr Liz McShane - 1:05:26
Microphone D - 1:05:27
I mean, not really related per se to the risk assessment in terms of the new ledger, but one of the things we have done as part of our audit planning work is to, our IT team
has been looking at the implementation of the ledger in terms of wider control framework
and has not identified through that process any significant weaknesses.
Now that doesn't mean we won't identify things during the course of the actual financial
statements order, but in terms of a start point for where we are, that's quite a positive
outcome because clearly they do look at those type of controls and cyber security and things
like that as part of that process and would have identified certainly any glaring holes
in that.
So I think we're in quite a good place in that respect.
I think it is right though to reflect on the end of this audit.
If we end in a place where we come back to meeting in December,
we have a few, the normal audit points, it feels like a normal audit year.
Certainly from an audit and accounting and evidence base,
the system would have demonstrated its value, I think, at that point.
Cllr Liz McShane - 1:06:42
Mr Halgett. Cllr Rich Holgate - 1:06:46
Actually, yes, I'm similar to Councillor Thomas, I wanted to pick up on this finance system because I didn't understand why it had come off.
I know we just talked about it a little bit, so I appreciate we've gone over the covered
ground, but what it didn't make sense to me was that whilst it has been implemented, the
fact that it has come off the risk register contradicts points we've already talked about
in earlier agenda items.
So, for example, in the audit account, we talked about the fact the new system has contributed
to two and a half weeks of shortened timetable.
And then in the procurement paper, we talked about a whole new set
of preventive CSO controls in the same system.
And so given that we've got statutory accounts timetable disrupted over here
and we've got new procurement processes dependent on it over here, I was then surprised
on the next agenda item going through that, we don't think it's a risk anymore. Now again,
I appreciate maybe there wasn't the detail of the word implementation, but I think therefore,
if you're looking for recommendations, for me personally, I think it'd be prudent for the
next year to have the ongoing implementation. As you mentioned in 2 .5, we are going to potentially
look at additional modules. There will be more of a continued impact on other areas of the Council.
So I politely don't agree that it should come off.
And that's my reason why I suppose.
Come back.
Yes, of course.
Thank you, Councillor.
Cllr Liz McShane - 1:08:16
Mr Jonathan Hicks - 1:08:17
I think that's one I'll take back with my finance colleagues and we can discuss that and maybe look at maybe reframing that.
This one was very specifically about the financial impact
of not having a system and what that would mean
if we carry on using the old system.
So, yeah, we'll take the recommendation we can have a look at.
Okay.
Cllr Liz McShane - 1:08:39
In terms of recommendations, we've got two to agree. One to receive and note the report.
Two, the Audit and Governance Committee reviews the corporate risk register overview, Appendix 1,
and makes any necessary recommendations regarding Council's management of risk.
Could I have a...
I'm not proposing sharing my thoughts.
Oh, sorry, sorry, sorry, I'm ahead of myself.
Okay, thank you.
I would be happy to propose, we'll see.
It's really just going back to our old friend,
EU entry -exit system.
Cllr Belinda Walker - 1:09:05
I think the question I have is answered quite comprehensively, but I just wonder,
I know we've increased the risk with the holiday season.
What if things are worse than we think?
Do we actually have a contingency plan
to step up with our partners if necessary?
I'm not talking about terrorist attack or fire,
and that just generally more traffic delays
in the system, et cetera.
I shall have a go at answering this,
but very happy for colleagues to step in.
Mr Jonathan Hicks - 1:09:33
So having spoken to the lead officer for this yesterday, my understanding is that our role generally is reaction
to that, it's business as usual.
And the decisions that get made on the traffic
is down to Kent Highways, the AZ with Port of Dover.
and we kept in the loop with regular meetings,
which are in the calendar already,
strategic meetings that assess the status of the roads
and they're cancelled if they're not needed.
In addition, we get four hourly updates
on the current status of things.
So the Port of Dover and Kent Highways
contingency arrangements do include at the moment
and it's then the instigate, it's not us,
Operation TAP of the A20 freight management,
and if required, Operation Brock on the M20.
And so therefore we get informed of those,
they take action, but we maintain that business
as usual position, ready to respond if conditions
deteriorate, and we've already mentioned
what the council itself has offered in terms of use
of the Otipool race course as a potential temporary holding area.
So there's a lot of us.
It's more about understanding the impact it has on residents going
about the district, the operation of our services within the district.
And we have within our emergency planning team contingencies
for how we would deal with that if we can't get around.
So I hope that is answered.
Seems to us prepared.
We can. Thank you so much for the answer. Thank you.
Cllr Belinda Walker - 1:11:21
Cllr Liz McShane - 1:11:21
Thank you. So back to the recommendations. One, to receive and note the report, and two, that Audit and Governance Committee reviews the Corporate Risk Register Overview Appendix
1 and makes any necessary recommendations regarding the Council's management of risk.
So could I have a proposer, please, Councillor Walker, thank you. And a seconder, Councillor
Holgate, thank you. We're all happy to agree with the recommendations? Agreed? Thank you.
10 Health and Safety Annual Report
So, agenda item 10 is the Health and Safety Annual Report.
Go over to you Jonathan, again.
That's me again, thank you Chair and members.
Mr Jonathan Hicks - 1:11:54
So this report, it provides the committee with the annual review of health and safety.
You'll note that we had one this time last year
and we committed to doing a half yearly report in December
and we will intend to do the same.
So this will give you an overview of health and safety performance for the 2025 -26 year.
And the purpose of this is to provide assurance that appropriate health and safety arrangements
remain in place and are operating effectively across our services, workplaces and activities.
So inside the report, it summarises the activity during the year, including staff training,
fire safety, first aid, inspections and site visits,
procedure reviews, accident and incident reporting,
and compliance with our statutory duties as an employer.
Members may wish to note that the report highlights
the range of preventative work undertaken during the year,
with a continued focus on maintaining positive
health and safety culture,
ensuring staff receive appropriate training,
and monitoring incidents and near misses
so that lessons can be identified and acted upon.
At the end of the report, it looks ahead
to future priorities and areas for continued improvement,
helping to ensure that health and safety
remains embedded within the council's day -to -day operations
and decision -making.
Overall, the report provides assurance
on the council's health and safety arrangements,
and I therefore commend it to the committee
for noting and happy to take any questions.
Thank you, Jonathan. Can I just have a look at it?
Cllr Liz McShane - 1:13:37
Cllr Rich Holgate - 1:13:41
It's a great report. Thank you so much. I had two minor questions. One is paragraph 3 .8 .1 talks about noise surveying presented no anomalies, but then the very next paragraph
suggests that staff are experiencing hearing difficulties. And maybe I'm making two and
make five, but I did understand how those two paragraphs can both be true. And then in
3 .7 .2, it talks about the BEATS risk assessments and talks about the closure, the
feedback loops back with EA and so forth. I thought that was great, but
maybe this is my nosiness, but I'd love to have seen what were those assessments,
what were the recommendations, what were the feedback, and just maybe more if
if capacity allows in the report,
more broad information about what the assessments are
and what is gonna be done and so forth.
Thank you very much, Councillor.
Mr Jonathan Hicks - 1:14:37
The first point about the noise testing. So this is about us testing all the equipment
that our operators, engineers and grounds maintenance staff
use so it could be leaf blower or lawnmower,
that sort of thing.
and they have to be within a certain level to be safe.
But what we've also considered is the long term use of this
and how that might affect.
So whilst we can tick the box as if all the equipment
is working within acceptable levels,
this is about recognising that long term exposure to this
may have a detrimental effect
and that's what we're starting to.
Yes, longer term.
Yeah, and in which case, if we're recognising this
within the staff then that is a reportable thing.
And the second question, sorry,
was around more information at this reach, BISC, sorry.
Start again.
Beach risk assessment.
Yeah, so this was a new thing we did,
or at least certainly since we've had
our new corporate health and safety officer,
and she can't be with us tonight,
so I might have to take that one back to her
and get some more information on that.
It is more of information in the report. The fact that this is done, I think it is a really
great report. I would love to see what was her observation, what were the recommendations
and just a bit more broad information. We can expand on that.
Thank you. Councillor Wing.
Cllr Liz McShane - 1:16:08
Cllr John Wing - 1:16:12
Thank you, Chair. My first point in Councillor Holger has actually beat me to it. Me and Councillor Tony Hills has been, as you know,
been recently involved in mud flats
and we managed to get some signs changed.
We'd like to thank the council since they've
quickly getting the change.
We'd like to see more, but we hear on news
from the else side today up in Essex.
We have a fantastic coastline and I'm concerned.
I want to see the council doing everything they can.
So to emphasise, Councillor Holgate's point,
I'd love to see his assessment and see what's actually
been done and how these assessments actually take place.
And my second point is on 4 .4, going down on page 151 in the PDF, and I can find it
myself.
Yes, it talks about an increased number of verbal abuse incidents from customers of concern
and it says down against staff and councillors.
I personally don't know about this customer of concern,
which I don't think any other councillor
on this committee knows about it.
I'd like to know more information about it
because I think the councillors can be on the front line
of urban abuse.
I've personally been shouted at in High Street
from the plan decision made.
So I just wanted more information
about this customer of concern register.
What is it basically?
Thank you, Councillor.
On the first point, just to on the beach risk assessments,
Mr Jonathan Hicks - 1:17:44
I think on both those points, if we look to maybe including a bit more information
and any risks that come out of that.
But just to note, I mean, this report is a summary.
It's an overview of the work that's happening last year.
And we'll only see it in hindsight, retrospectively.
the monitoring of health and safety does happen through,
as a staff forum,
which acts as our health and safety committee's offices,
and through the cabinet portfolio holder,
Councillor Speedman.
And on the second point,
I have spoken to him at length on the verbal abuse
and the customers are concerned register.
So it might be something that we look at,
maybe discuss with committee services
around how we share that information with you.
But on that point, it is perhaps one of the things that sticks out.
This report captures all the work that we've done, but also within the stats it highlights any trends.
And as you may recall, for those that were members of the committee maybe two years ago,
we did a lot of work to try to get all the reporting to where we felt it ought to be,
and to provide you with more assurance of what we're doing.
Part of that is recording data, because if you can't record accurate data in the same way, you can't see what the trends are.
The most striking thing there, and you'll see it from the page on the stats, the performance information, I think it's on page 150, 4 .2.
You can see it there, the incidents of verbal abuse, 27 recorded over the last year.
There's two factors at play here.
One is that there may well be a very real increase
in the number of fees.
Certainly anecdotally we feel that.
But secondly, we introduced reporting on this in year.
So there's a lot that may have been unreported
in previous years.
The catch on this data,
we haven't had a full year's worth of it yet.
We don't know what normal is.
We don't know what normal is.
we don't know whether or not we need to, how we need to react.
So one of the measures we've put in place is being able to,
within GDPR, data protection, is to be able to,
for officers to be able to know when there's a potential threat
or a customer of concern and what measures might need to be put in place.
if they are visiting that person or they come into the CAP.
But I think we can note that we want to give you some further feedback on that.
Other measures we put in place are around key messages.
So this is about zero tolerance, signage which we're working on.
And one of the things we're looking at at the moment, taking advice from the police.
and it's a piece of work that we're doing
in the customer access point,
we're taking a redesign so that it makes it safer
for officers to, for people visiting,
and conducting interviews.
But it's something we're monitoring continually.
But I think we will make a note to provide
some additional information for councillors on that,
perhaps through Councillor Speakman.
Thank you.
Another question?
Paul Ewing.
When it says verbal abuse, does this include email and Facebook posts and things as well?
Cllr John Wing - 1:21:22
Mr Jonathan Hicks - 1:21:31
I think, yes, we would record some of those, but primarily it is face -to -face or through on the phone. Cllr Liz McShane - 1:21:40
Any more questions for this item? Councillor Thomas. Cllr Paul Thomas - 1:21:46
Thank you very much for the report. A couple of things just to help with my ignorance actually. On page 150 you got peeps reviewed. What's a peep? What's the acronym?
Thank you. Helpfully, and I'm hoping that I can be proved right on this, we've put that
Mr Jonathan Hicks - 1:22:03
in section two definitions. That's fine. You won't want to know unless you know all these reports and keep them all in your head. So personal evacuation, personal emergency
evacuation plan. So there's certain people that we need in an event of an emergency, we need to have one of these in place if they have additional access needs.
Cllr Paul Thomas - 1:22:32
Okay, so if I may, you also talk on that table as well about the number of spot cheques that have been carried out. So my question is who carries out those spot cheques? The spot cheques are carried out by our Health and Safety Officer, so we have a court for
Mr Jonathan Hicks - 1:22:45
Health and Safety Officer that will do random spot cheques around the district. So we have scheduled site visits to do fire risk assessments and do other formal risk
assessments, but the idea of the spot cheques up around the district is to cheque people
using PPE and checking they're doing what they're following with inspections. So they are random,
so they don't know we're turning up and we've put a target to do about six per month, which is what we do.
Cllr Paul Thomas - 1:23:22
If I may just follow it up on the same couple of pages if I may. So the Health and Safety Committee membership, it doesn't include an elected member, there's no elected member on there, or doesn't
appear to be, or a contractor representative,
and yet when you look at some of the big contracts
you have like the waste contract,
I mean they have a significant number of staff, don't they?
So again, and they interface with the public
more than anybody probably,
and they're probably subject to verbal abuse
more than anybody else.
So again, I just wonder whether,
in terms of that staff consultation forum,
the Health and Safety Committee side of that
could actually consider whether an elected member
would make a valuable contribution.
I personally think they would do,
not that I'd put my name up for it.
But I would also, I also think that having a contractor,
you know, maybe somebody from VEOBA,
you know, they might bring a slightly different perspective
to the kind of things that are there.
And then that takes me on to my final bit,
which is on page 146, under 3 .2, driving at work.
There's a significant number of people
have been trained in driving at work.
and I can understand why, as I said prior to this
in a previous life, you know,
this is one of the highest risks, you know,
when you are travelling on company business,
particularly if you're travelling any distance.
And again, I know we would focus particularly on, say,
the grounds maintenance staff who are out all the time,
but again, I think having input from our main contractors
in that would be very useful as well.
Thank you very much, Chair.
Cllr Liz McShane - 1:24:58
Any other questions or comments? No. In that case... Cllr Liz McShane - 1:25:02
Mr Jonathan Hicks - 1:25:05
I mean, if you're satisfied without a response, then... Okay, yes. So I think I might be able to answer both of those parts in one.
So the remit of the corporate health and safety officer is around staff,
staff safety and in our buildings that we manage.
So the health and safety contract management,
for example, within our housing team,
we have a whole compliance team
that deals with health and safety there.
So this is about operations of staff.
So therefore, the internal monitoring of this
with officers is an officer led group
and the governance committee is the member oversight of health and safety activity.
Can I come back on that show if I may?
So again, I think, my question really is about looking a little bit more holistically at this
Cllr Paul Thomas - 1:26:08
in terms of Veolia and other major contractors, our waste contractor, I mean, they're as much a part of the staff as anybody else is in my opinion.
And they're subjected to the same risks that are rejected, like I said earlier on,
to the same interfaces with the public,
they are likely to be involved in high risk activities.
I mean, they're doing a lot of mangled handling,
their potential for trips and falls,
the driving side of things is part and parcel of that.
So for me to understand how corporately
we understand our health and safety position,
to have the input from, even if we said
it would be our major contractor, then I think that would expand all of this.
And again, an opportunity for us as an organisation to learn and maybe put things in place,
which helps everybody, not just those who are directly employed by this organisation.
Thank you.
Ewan, go ahead.
Thank you, Councillor Thomas.
I understand the point you're raising. I think it's a good one.
Mr Ewan Green - 1:27:09
I think, though, we're crossing over between the Council's corporate responsibility for its staff and contractual arrangements.
I think though, picking up on the point,
and it's a good one, in future reports,
we can build in commentary on health and safety
of our main contracts, because I think it's a valid point
for a committee to raise that.
Any other questions?
Cllr Liz McShane - 1:27:34
Okay, I think we're good to go to the recommendations. We just got one.
Could I have a proposer, please?
Councillor Holgate, thank you, and a proposer.
So the recommendation is to receive and note the report. Are we all agreed? Agreed. Thank
11 Quarterly update on Code of Conduct Complaints
you. And moving on to the last item, item 11, which is quarterly code of conduct complaints
Mr Ewan Green - 1:28:00
update report. Over to you, Ewan. Thank you. Save the best for last year, Chair. Sorry. And we're actually covering two quarters in this one. This reflects just the way the nature
of the meetings and the timetabling. So this is covering quarter four of 25 -26 of the previous
year and the first quarter of this year and so the report through 2 .1 gives you the stats
in terms of the number of complaints received. We give a bit of commentary as we always do
just very high level commentary obviously on the types of complaints and then in 2 .3
just a commentary there on any complaints that have gone to the investigation stage.
So it's the normal report you have before you Chair. I'm happy to take any questions.
I've just got a couple of myself.
Cllr Liz McShane - 1:28:42
Are there any themes emerging from the complaints? And, yeah, that's the first question.
Mr Ewan Green - 1:28:49
Not really trends, if you like, but I would say that I think possibly a comment I've made previously is that there is a general increase in complaints around behaviour or social media use on that side of it.
and naturally as social media use has increased.
Is any further member training required, do you think?
Cllr Liz McShane - 1:29:15
Actually, it's a very good point Mr Ewan Green - 1:29:18
and we are actually planning further member training. Now the constitution has been updated
through Council last week,
so we will be, before the start of the next session,
September, planning on some more member training
on code of conduct.
Cllr Liz McShane - 1:29:35
I'll get that in my diaries. Any questions from the members? Cllr Rich Holgate - 1:29:41
I had two. In the first one, I just need to read off my screen a bit because apologies, you and I have been a bit nerdy. Like the old HR, we were curious on the process of
investigations. Section 2 .3 talks about, will be carried out by an independent person who
then reports to the monitoring officer. When I was looking, there's a nerdy bit, at the
It talks about the independent person having a specific statutory role.
That suggests that ultimately they need to keep an investigation and a recommendation
separate.
So my question was, here, do we have an independent person conducting investigations or do we
separate the investigator and the recommend?
Do you see where I'm headed?
I'm curious.
You're straight.
Okay, thank you.
because I'll come back to my second question after that.
Thank you.
Thank you, and I think it's our wording in the report.
Mr Ewan Green - 1:30:36
We do have an independent person, a number of independent persons that have been appointed
through a council that we use.
This purely means, and it's badly wording,
that we have somebody who's independent of the council
to carry out the investigation.
Cllr Rich Holgate - 1:30:53
Thank you, yes, again, a touch of pengency on me. We talked earlier about totality of information
and robust governance. Five of the eight complaints were dismissed by the monetary officer, but
we don't see any details of those ones that were dismissed. And again, I wonder whether
there's value in the spirit of transparency to see more information on at least the themes
and reasons as to why they were dismissed. I appreciate there's probably some sensitivities
involved, but again, unless I've missed it, it's not in the report.
Thank you.
Mr Ewan Green - 1:31:31
The reasons for not taking them forward is around the jurisdiction tests. There are some tests after we met and thresholds met before we can take them forward.
I am very happy to include some more detail in the future.
What I will do is provide members of the committee with maybe a summary of the jurisdiction tests
and how we apply them as well.
There are criterias behind this.
Cllr Rich Holgate - 1:31:55
I suppose maybe it's the same thing, the waiver principle, where it's just like, here's the total set of information and the breakdown of all of it, as opposed to just this slice.
And for valid reason, I appreciate it, but personally, as the Northern Governance Committee
and the raise in debt we have, I think it'd be good to see everything.
Not a hard thing to do at all. Happy to do that.
Mr Ewan Green - 1:32:15
Thank you, Ian. Any questions? Councillor Thomas? Charles?
Yeah, I just have one actually,
Cllr Liz McShane - 1:32:20
Cllr Paul Thomas - 1:32:23
and it comes down to the granularity of the information that we're provided with.
So could we actually, in future,
have somebody who's made multiple complaints
separated from, so if we've got one person
who's made five complaints, and then got three others,
so I think it just helps us in terms of
in how many people have made complaints.
So if we've got 26 complaints made by three people,
then I think it's useful information for us to have.
Thank you.
Any other questions?
Councillor Wing.
Cllr Liz McShane - 1:32:55
It's more of a committee, if I remember rightly, from the new constitution,
Cllr John Wing - 1:32:59
there'll be a small committee set up for this, if it goes that far, there'll be a small committee set up.
Is that correct?
Yes, I think you're referring to the establishment
Mr Ewan Green - 1:33:13
of the subcommittee on discipline. if an investigation went to a hearing.
Cllr Liz McShane - 1:33:22
Any others? No?
In that case, we've just got one recommendation.
And that's to receive and note the reports.
Could I have a proposal, please?
Councillor Wing, thank you, and a seconder.
Councillor Walker, thank you.
Are we happy to agree on that?
Agreed.
So that's Item 11 agreed.
Thank you everyone for putting up with the heat and thanks for all your contributions
from members and thank you also to officers and partners for all your constant hard work
and keeping us on track.