Subscribe to updates
You'll receive weekly summaries about West of England Combined Authority Council every week.
If you have any requests or comments please let us know at community@opencouncil.network. We can also provide custom updates on particular topics across councils.
West of England Combined Authority Audit Committee - Monday, 6th July, 2026 10.30 am
July 6, 2026 at 10:30 am West of England Combined Authority Audit Committee View on council website Watch video of meeting Read transcript (Professional subscription required)Summary
Open Council Network is an independent organisation. We report on West of England Combined Authority and are not the council. About us
The West of England Combined Authority Audit Committee met on Monday 6 July 2026 to review the internal audit annual report for 2025/26, receive updates on cyber resilience and information governance, and discuss the expansion of the Combined Authority. The committee also reviewed the corporate risk register and received reports on health and safety, the Local Government and Social Care Ombudsman's annual review, and the treasury management outturn report for 2025/26.
Cyber Resilience Update
The committee received an update on cyber resilience improvements, noting the transition to new ICT service arrangements with Delt in October 2025, which have enhanced cyber security capabilities. These include improved services for managing risk, protecting systems, detecting events, and responding to incidents. The MCA has also achieved 'CAF Ready' status and is progressing with self-assessments against the Cyber Assessment Framework. Future plans focus on embedding and optimising these services, completing the review and validation of CAF assessments, and exploring further funding opportunities. The Digital and Data Strategy (2026–2029) will further embed cyber resilience, with a focus on secure-by-design principles and strengthened governance.
Information Governance Update
The committee was updated on the implementation of the Combined Authority's Information Governance Framework. This framework aims to provide a robust approach to managing information assets, ensuring data is secure, accurate, available, and processed legally. It includes establishing an Information Governance Board and clarifying roles and responsibilities for data protection. The committee was also asked to endorse the new statutory Data Protection Complaints Policy, which is a legal requirement under the Data (Use and Access) Act 2025. Performance in relation to Freedom of Information Act 2000 and Environmental Information Regulations 2004 requests for 2026/27 year-to-date was presented, showing that 90% of requests were responded to within the statutory timescale.
Expansion of the Combined Authority
An overview was provided of the work underway to expand the West of England Combined Authority (WECA) to include North Somerset Council (NSC). Both the WECA Committee and North Somerset Council have voted to support the expansion. The formal proposal and consultation findings have been submitted to the Secretary of State. The process for expansion is governed by the English Devolution and Community Empowerment Act 2026, and while the exact timing is unclear, it is anticipated to conclude within 2026. Current governance arrangements will remain in place until formal expansion is legislated.
Internal Audit Annual Report 2025/26
The committee received the closing Internal Audit Report for the financial year 2025/26. The report indicated that 21 out of 24 planned audit items were finalised or reporting, with a small number deferred to the following year. Recommendations from previous audits were followed up, with 96% of recommendations implemented. The report also noted that Internal Audit had not been involved in any fraud investigations or whistleblowing submissions during the year. The Head of Audit & Assurance provided an opinion that the internal control framework and systems to manage risk continue to be reasonable, with no fundamental system failures or control breakdowns identified.
Treasury Management Outturn Report 2025/26
The report reviewed the treasury management performance for the year ending 31 March 2026. The average rate of investment return was 4.6%, exceeding the benchmark rate. Gross interest earned on all investments was £22.9 million, resulting in a favourable variance of £7.2 million against the budget. The report detailed the investment portfolio, which was diversified across UK Banks and Local Authorities, and highlighted the strategic decisions made regarding investments in pooled funds. The Authority maintained a £5 million reserve to mitigate the impact of potential changes to the statutory override on pooled investment funds.
Corporate Risk Register Update
The committee reviewed the Corporate Risk Register (CRR), which identifies nine material risks facing the Authority. The two highest-rated risks remained CRR14 (City Region Sustainable Transport Settlements delivery) and CRR20 (Bristol Temple Quarter development). All risks were assessed as high before mitigation, with only CRR14 remaining rated as high after mitigation. Substantive updates included reframing CRR8 (Climate and Nature Integration) to focus on areas within the Combined Authority's direct control, and updating CRR10 (Recruitment, Retention and Workforce Diversity) to reflect workforce stability during the transition to the Target Operating Model. The report also detailed enhancements to the Corporate Risk Management Framework, including clearer risk categories, refined risk appetite statements, and stronger escalation triggers.
Health and Safety Update
An update was provided on health and safety performance for 2025/26, highlighting a strong safety record with zero RIDDOR-reportable incidents and zero lost-time injuries. There were six non-lost time injuries and one incident causing damage, all of which were investigated with remedial measures implemented. Proactive hazard reports doubled the annual target, indicating a mature approach to safety management. Key achievements included achieving 'Reasonable Assurance' status from a One West audit, signing a new Health and Safety Policy Statement, and delivering a health and safety session to elected members. Plans for 2026/27 include improving mandatory training compliance, further developing health and safety resources, and focusing on psychosocial risks.
Local Government and Social Care Ombudsman Annual Review Letter
The committee received the Local Government and Social Care Ombudsman Annual Review Letter for 2025/2026. During the period, a total of two complaints were considered by the Ombudsman. One was not for the Ombudsman, and the other was assessed and closed. The Ombudsman carried out no investigations and did not uphold any complaints during this period.
Forward Work Plan
The committee reviewed the proposed Forward Work Plan for 2026/27, which outlines anticipated business for future meetings. Members commented that the plan appeared full and suggested considering additional meetings to distribute business more evenly. Officers undertook to review the feasibility of additional meetings.
Annual Cyber Resilience Update
The committee received an update on recent cyber resilience improvements, ongoing management, and future plans. Since October 2025, enhanced cyber resilience services have been operational through a partnership with Delt. The MCA has also achieved 'CAF Ready' status and is progressing with self-assessments against the Cyber Assessment Framework. Future plans include embedding and optimising cyber resilience services, completing CAF assessments, and aligning with the Digital and Data Strategy.
Project Management Plan for Delivery of the 2025-26 Audit
The committee was informed of the Project Management Plan for the 2025-26 audit, as set out in the Accounts and Audit (Amendment) Regulations 2024. Grant Thornton, the external auditors, are aiming to complete the audit by the end of November 2026 as a dry run
to meet future deadlines. The committee was asked to set an Audit Committee date in advance of this deadline to enable the sign-off of the opinion.
The Audit Plan for West of England Combined Authority - Year Ending 31 March 2026
Grant Thornton presented their Audit Plan for the year ending 31 March 2026. The plan outlined significant risks identified, including management override of controls and the valuation of the net pension liability. It also detailed the approach to materiality, progress against prior year recommendations, the IT audit strategy, and value for money arrangements. The proposed audit fee was £194,731.
West of England Combined Authority - Auditor's Annual Report - Year Ending 31 March 2025
The committee received Grant Thornton's Final Auditor's Annual Report for the year ending 31 March 2025. The report included the external auditors' assessment of value for money arrangements, commentary on financial sustainability, governance, and improving economy, efficiency, and effectiveness. It also detailed the follow-up on previous statutory and key recommendations. The report noted significant progress in improving governance, with two statutory and six key recommendations closed. However, residual weaknesses remain, particularly concerning programme governance and the need to embed new arrangements. Key recommendations KR7 and KR8 were highlighted, focusing on strengthening governance culture and demonstrating effective governance for the CRSTS Programme. The report also confirmed an unqualified opinion on the financial statements.
Attendees
Topics
Meeting Documents
Reports Pack
Additional Documents