Kingston Council's risk management arrangements have been described as reasonable
by its Chief Audit Executive, a term that has prompted questions from councillors regarding the distinction between this and a substantial
assurance level.
During the Audit, Governance and Standards Committee meeting on Wednesday, June 24, 2026, Andy Hamilton, Chief Audit Executive, presented the Annual Internal Audit Report for 2025/26. He stated that the council has reasonable
risk management, internal control, and governance arrangements in place. This means a generally sound system is in place, with some minor weaknesses identified, as opposed to a substantial
assurance level, which indicates a sound system with no significant weaknesses.

Councillor Peter Higgins, Chair of the committee, sought clarification on why reasonable
was the highest level of assurance that could be provided. Mr. Hamilton explained that this was due to resource limitations and the scope of work, which only allows for the assessment of a certain number of key controls and systems each year. We have a limited amount of resource within the internal section,
he stated.
The Annual Internal Audit Report indicates that beyond the overall reasonable
assurance, specific areas assessed also received this level. Four key financial systems reviews were completed, with one receiving a Reasonable Assurance opinion. The 'Climate Change' audit also received a Reasonable Assurance opinion, though it identified one Priority 1 finding related to the absence of a fully costed implementation plan. Similarly, the 'Development Management' audit received a Reasonable Assurance opinion, with a Priority 1 finding concerning a backlog and weak oversight of planning enforcement cases. Additionally, 'Contracts Thematic', 'Unsigned Contracts', and 'Debtors - Accounts Receivable' audits all achieved Reasonable Assurance opinions.
While the audit team successfully completed 92% of its planned work, exceeding its target, one report on Cash and Bank
received a limited assurance opinion. This was attributed to identified weaknesses in segregation of duties and system access controls. However, Mr. Hamilton clarified that these recommendations have since been implemented, and the issue has been closed with no residual risk. He noted that a follow-up on such matters would typically occur in about three years due to a three-year cycle.
Councillor George raised concerns about other areas also receiving limited assurance, but Mr. Hamilton clarified these were individual issues rather than systemic problems across the council.
Despite the reasonable
assurance on risk management, the discussions highlighted ongoing scrutiny of the council's governance and control processes.
Public reports pack Wednesday 24-Jun-2026 19.30 Audit Governance and Standards Committee.pdf