Subscribe to updates
You'll receive weekly summaries about Rushmoor Council every week.
If you have any requests or comments please let us know at community@opencouncil.network. We can also provide custom updates on particular topics across councils.
Audit and Governance Committee - Wednesday, 10 June 2026 - 7.00 pm
June 10, 2026 at 7:00 pm Audit and Governance Committee View on council website Watch video of meetingSummary
Open Council Network is an independent organisation. We report on Rushmoor and are not the council. About us
The Audit and Governance Committee of Rushmoor Borough Council met on Wednesday, 10 June 2026. The meeting's agenda included a review of the proposed audit planning report for the 2025/26 financial year from the Council's external auditors, Ernst & Young (EY), and the annual audit opinion for 2025/26 from the Southern Internal Audit Partnership (SIAP).
External Audit Proposed Audit Planning Report 2025/26
The committee was to receive Ernst & Young's (EY) proposed audit planning report for the 2025/26 financial year. This report outlines EY's provisional audit plan, detailing their proposed approach and scope for auditing the Council's accounts. The report is prepared in accordance with the Local Audit and Accountability Act 2014 and the National Audit Office's (NAO) 2024 Code of Audit Practice. It addresses key issues driving the audit and the broader impact of government proposals for a sustainable local audit system.
The report highlights significant risks and areas of focus for the upcoming audit. These include the presumptive risk of management override of controls and the risk of fraud in revenue and expenditure recognition through inappropriate capitalisation of revenue expenditure. A significant risk has been identified concerning the valuation of land and buildings, particularly those valued under the depreciated replacement cost (DRC) and existing use value (EUV) methods. This is due to the inherent estimation and judgement involved, which necessitates the use of experts. The report notes that in previous years, EY was unable to substantiate key inputs and assumptions used in these valuations.
Another significant risk identified is the valuation of investment property, which relies on significant unobservable inputs such as management assumptions regarding rent growth and discount rates. The report also flags the risk of material misstatement in the valuation of pension assets and liabilities, which involves significant estimation and judgement by actuaries.
The report also details the audit materiality for 2025/26, set at £1.65 million, representing 2% of the forecast gross expenditure. Performance materiality has been set at £0.83 million. The NAO Code requires auditors to consider whether the Council has proper arrangements in place to secure economy, efficiency, and effectiveness in its use of resources. For 2025/26, a risk of significant weakness has been identified relating to financial sustainability, stemming from the current debt level and associated borrowing costs, and the use of reserves to balance the budget.
The report also outlines the audit timeline and the composition of the audit team, led by Simon Mathers. EY's approach to the use of specialists, including their valuations team and actuaries, is also detailed.
Internal Audit - Annual Audit Opinion 2025/26
The committee was to receive Report No. SIAP27/01 from the Southern Internal Audit Partnership (SIAP), which presents the independent annual audit opinion for 2025/26. This report provides the Chief Internal Auditor's opinion on the effectiveness of the Council's framework of governance, risk management, and control.
SIAP's assessment indicates that the Southern Internal Audit Partnership was assessed as 'Generally Conforms' against the Global Internal Audit Standards in the UK Public Sector during 2025-26. The report states that the revised internal audit plan for 2025-26 has been delivered in full. The Council's framework of governance, risk management, and management control is considered to be at a 'Reasonable' level, with audit testing demonstrating that controls are working in practice.
The report details the assurance opinions for various reviews completed during 2025-26. While most areas received 'Substantial' or 'Reasonable' assurance, specific areas were identified as requiring improvement. The audit of Agency Staff resulted in a 'No Assurance' opinion due to a lack of formal policies and procedures, non-compliance with procurement strategies and contract standing orders, and issues with mandatory training registration and IR35 status checks.
Disabled Facility Grants received 'Limited Assurance' due to concerns regarding the procurement of contractors and surveyors, with contract standing orders not being followed. There was also no contractor framework in place, and DBS checks were not part of due diligence.
The Pay360 application audit also resulted in 'Limited Assurance'. While access is secured, deviations from National Cyber Security Centre (NCSC) best practices regarding password expiry and length were noted. Access reviews were ad-hoc, and new user access was provisioned by copying existing permissions without full visibility. There were also inconsistencies in administrative access and a reliance on a single administrator account.
The Union Yard regeneration scheme audit also received 'Limited Assurance'. While reports after 2021 were satisfactory, pre-2021 reports lacked sufficient information for fully informed decision-making. The risk register also had instances where materialised risks were not specified with their full impact, and some entries lacked defined mitigating actions or updates.
The audit on the Effectiveness of Financial Rules also yielded 'Limited Assurance'. Responsibilities and execution of controls were not clearly documented, and virements over £50,000 had not been reported to or approved by Cabinet. Testing also highlighted that not all authorities for payment authorisation had been properly authorised, and the dual signatory control for cheques over £25,000 was not being enforced.
The report also discusses themes identified across multiple engagements, including 'Resources', 'Competencies & Training', 'Systems', 'Standards & Policies', 'Governance', 'Process & Procedures', 'Accountability', and 'Assurance & Monitoring'. The report concludes that no significant control deficiencies posing a significant fraud risk were identified.
The quality assurance and improvement programme for SIAP was assessed as 'generally achieves' against the Global Internal Audit Standards in the UK Public Sector, with 46 out of 52 standards fully achieved.
Attendees