Subscribe to updates
You'll receive weekly summaries about Islington Council every week.
If you have any requests or comments please let us know at community@opencouncil.network. We can also provide custom updates on particular topics across councils.
Audit and Risk Committee - Monday, 15 June 2026 - 7.00 pm
June 15, 2026 at 7:00 pm Audit and Risk Committee View on council websiteSummary
Open Council Network is an independent organisation. We report on Islington and are not the council. About us
The Audit and Risk Committee of Islington Council met on Monday 15 June 2026 to review the council's risk management framework, audit plans, and governance statements. The meeting's agenda included discussions on the external and internal audit plans, the principal risk report, cyber defence assurance, and the review of the Regulation of Investigatory Powers Act (RIPA) policy.
Membership, Terms of Reference and Dates of Meetings
The committee was scheduled to review and note the membership, terms of reference, and dates of meetings for the Audit and Risk Committee for the municipal year 2026-27. This report ensures the committee is properly constituted and informed of its operational schedule.
Verbal Financial Update
A verbal update on the council's financial position was scheduled to be provided.
External Audit Plan and Strategy for the year ending 31 March 2026 - Islington Council and Pension Fund
The committee was set to consider the external auditor's plans for the 2025/26 audit of both the London Borough of Islington and the Islington Pension Fund. This included an overview of the planned scope, materiality levels, and the audit approach for the year. The external auditors, KPMG LLP, outlined their risk assessment, planned audit procedures, and mandatory communications. Key areas of focus for the council's audit included the valuation of land and buildings, post-retirement benefit obligations, and management override of controls. For the Pension Fund, the audit plan addressed risks related to investment valuations, contributions, and management override of controls.
Internal Audit Annual Report
The committee was to receive the Internal Audit Annual Report for 2025/26. This report details the work undertaken by Internal Audit in delivering the 2025/26 Internal Audit Plan, providing assurance on the council's governance, risk management, and internal control framework. The Chief Audit Executive's conclusion for 2025/26 was a Moderate Assurance,
indicating that while overall arrangements are adequate, some improvement is required. The report also highlighted high-priority recommendations and the outcomes of follow-up audits.
Principal Risk Report
The committee was scheduled to review the Principal Risk Report for June 2026, which outlines the key risks facing Islington Council. This report, aligned with the revised Risk Management Strategy approved in January 2026, identifies 11 principal risks, including those related to health and safety compliance, capital programme delivery, financial stability, safeguarding, cyber security, school viability, waste management infrastructure, climate change impacts, partnership governance, and borough resilience. The report includes a risk map, links to strategic objectives, and detailed action plans for each risk.
Annual Governance Statement
The agenda indicated that the Annual Governance Statement was to follow. This statement provides assurance on the adequacy of the council's governance framework.
Cyber Defence Assurance Annual Report
The committee was to receive an annual update on the council's cybersecurity defences. The report aimed to provide assurance that adequate protections are in place to safeguard the council's operations and data. It highlighted the ongoing threat landscape, including phishing attempts and sophisticated technical attacks, and detailed the council's defensive measures, training programmes, and compliance efforts. The report noted that no cyber events were reported to the Information Commissioner's Office (ICO) during the last financial year. The council's commitment to achieving accreditation with the Cyber Assessment Framework (CAF) was also mentioned.
Review and Update of RIPA Policy
The committee was asked to review and approve an updated Regulation of Investigatory Powers Act (RIPA) Policy Document and Procedural Notes. This policy provides guidance on the lawful use of directed surveillance and access to communications data by the council, ensuring compliance with human rights legislation. The report noted that the council's previous inspection by the Investigatory Powers Commissioner's Office (IPCO) in 2023 found satisfactory compliance, with the next inspection due in 2026. The policy update aims to ensure continued compliance and fitness for purpose, with recommendations for annual review by elected members and internal reporting.
Attendees
Topics
Meeting Documents
Additional Documents