Subscribe to updates

You'll receive weekly summaries about Lambeth Council every week.

If you have any requests or comments please let us know at community@opencouncil.network. We can also provide custom updates on particular topics across councils.

Audit and Risk Committee - Thursday, 23 July 2026 - 5.30 pm

July 23, 2026 at 5:30 pm Audit and Risk Committee View on council website Watch video of meeting Read transcript (Professional subscription required)

Chat with this meeting

Subscribe to our professional plan to ask questions about this meeting.

“What risks will the committee assess?”

Subscribe to chat
AI Generated

Summary

Open Council Network is an independent organisation. We report on Lambeth and are not the council. About us

The Audit and Risk Committee of Lambeth Council met on Thursday 23 July 2026 to review a range of reports concerning the council's governance, risk management, and financial oversight. Key discussions included the council's internal audit performance, counter fraud activities, information governance, and the handling of complaints and member enquiries. The committee received updates on the council's response to statutory recommendations, the draft statement of accounts, and the application of the Regulation of Investigatory Powers Act 2000.

Annual Information Governance Report

The committee received the Annual Information Governance Report for 2025/26, which detailed the council's arrangements for handling information securely and lawfully. Matthew Ginn, the Data Protection Officer, presented the report, highlighting that 103 potential data breaches were reported between April 2025 and March 2026, with 92 assessed as valid breaches. All were deemed low-level and did not require reporting to the Information Commissioner's Office. The report identified areas for improvement, including strengthening data ownership, ensuring compliance with mandatory data protection training, enhancing breach learning, and improving information asset management. The committee endorsed the forward improvement actions set out in the report, which include annual mandatory data protection training, data owner training for Heads of Service, and the introduction of virtual information governance clinics to increase accessibility.

Internal Audit Annual Report and Opinion 2025-2026

The committee reviewed the Internal Audit Annual Report and Opinion for 2025-2026, presented by Paul Rock, Assistant Director of Internal Audit and Counter Fraud. The report concluded that the council's governance, risk management, and internal control arrangements provided Reasonable Assurance, an improvement from the previous year. While core governance and financial frameworks were found to be established and operating effectively, control effectiveness was noted as inconsistent across all areas, particularly in demand-led and operationally complex services. The report highlighted the council's challenging financial environment and reliance on exceptional financial support, but noted that management's response and implementation of audit actions had improved significantly. The committee was assured that no resource limitations had impacted the scope of the annual conclusion.

Management Update for Actions Arising from Limited Assurance Internal Audits

Paul Rock also presented an update on actions arising from internal audits that had previously received a Limited Assurance opinion. Directors from relevant services attended to provide updates on progress. The Director of Housing Need and Prevention discussed improvements in homelessness prevention and temporary accommodation, noting that while staffing levels were a challenge, a cohort-based approach was being used to prioritise households. Updates were also provided on HR Case Management, with revised target dates for implementing a new case management system and strengthening processes for case resolution timelines and documentation. The Director of Children's Social Care reported on progress in age assessment processes, placement agreements, performance monitoring, and expenditure linked to Unaccompanied Asylum Seeking Children (UASC).

Counter Fraud Annual Report 2025/26

Michael O'Reilly, Head of Counter Fraud, presented the annual report for 2025/26. The service reported significant achievements, including 79 tenancy recoveries, £1.2 million in savings from preventing fraudulent Right to Buy applications, and the prevention of nine unsuitable candidates from employment through CIFAS vetting. The report highlighted tenancy fraud as a prominent issue, accounting for approximately 70% of investigations. Emerging risks such as dual employment were noted, with upcoming National Fraud Initiative (NFI) data-matching exercises expected to enhance detection capabilities. The committee was informed that Blue Badge fraud investigations were handled by a separate team within Parking Services, which had been addressing a backlog of cases.

Annual Governance Statement 2025/26

Andrew Pavlou, Principal Lawyer, presented the council's Annual Governance Statement (AGS) for 2025/26 for approval. The AGS is a statutory document outlining the council's review of its governance, risk management, and internal control arrangements. It draws on various assurance sources, including Directorate Assurance Returns, statutory officer assurances, and audit findings. The committee was informed that the AGS had been drafted by Legal Services for the first time, following CIPFA guidance. The statement assessed the council's arrangements against the CIPFA/SOLACE Principles of Good Governance and included an action plan for 2026/27.

Disaster and Emergency Planning

Dipti Patel, Corporate Director of Growth and Environment, presented the Disaster and Emergency Planning report. The council had managed 41 incidents during the reporting period, with its emergency planning capability remaining strong and showing improvements against London Resilience Standards. The report highlighted the importance of maintaining preparedness and response arrangements, acknowledging that significant incidents could impact service delivery capacity. The council maintained a comprehensive training programme for officers and Members involved in emergency response.

Annual Information Governance Report

Matthew Ginn, Data Protection Officer, presented the Annual Information Governance Report for 2025/26. He detailed the council's information governance arrangements, including the Data Protection Officer function, information asset roles, staff training, and breach management. The report noted that 92 out of 103 potential data breaches reported were assessed as valid, low-level breaches, none of which required reporting to the Information Commissioner's Office. The committee endorsed proposed improvements, including annual mandatory data protection training, data owner training, and enhanced breach learning.

Report on Regulation of Investigatory Powers Act 2000

Paul Rock, Assistant Director of Internal Audit and Counter Fraud, presented the annual review of the council's policy on the Regulation of Investigatory Powers Act 2000 (RIPA). It was confirmed that the council had not authorised any RIPA-regulated surveillance activities since 2017, a trend mirrored by other London boroughs. The council maintained an up-to-date RIPA Policy to comply with statutory obligations, and the attached policy, covering Directed Surveillance and Covert Human Intelligence Sources, was approved by the committee. The report noted that the Investigatory Powers Commissioner's Office (IPCO) had previously found the council to be compliant with RIPA and IPA requirements.

Annual Update – Complaints, Member's Enquiries, Subject Access Requests, Freedom of Information Act Requests and Ombudsman Cases – Year 2025/2026

Nataša Patterson, Chief Digital and Data Officer, presented the annual update on casework performance. Overall casework volumes increased significantly from 18,260 in 2024/25 to 27,563 in 2025/26, with notable rises in Members' Enquiries and Stage 1 complaints. While SAR and FOI performance improved, complaint and Member's Enquiry timeliness declined, indicating pressure on capacity. Housing Management remained the highest-volume and highest-risk area. The report highlighted persistent root causes such as delays, missed actions, and communication gaps. Ombudsman-directed compensation increased, primarily driven by Housing. The committee noted the ongoing work on the Customer Services Transformation Programme and a review of the Housing Complaints Service. The committee noted the contents of this report.

The meeting concluded with the committee noting the reports presented.

Attendees

Profile image for Councillor Matt Wilcock
Councillor Matt Wilcock Chief Whip (job-share) Green Knight's Hill
Paula Mills
Profile image for Councillor Matthew Bryant
Councillor Matthew Bryant Group Leader Liberal Democrats Streatham Hill West and Thornton
Profile image for Councillor David Amos
Councillor David Amos Labour Kennington
Profile image for Councillor Judith Cavanagh
Councillor Judith Cavanagh Group Whip Labour West Dulwich
Profile image for Councillor Jacqueline Bond
Councillor Jacqueline Bond Green Vauxhall

Topics

Information Commissioner's Office (ICO) Regulation of Investigatory Powers Act 2000 Affordable Housing Air Quality Digital Transformation Hate Crime Underreporting School Place Shortage Traffic Homelessness Tenancy Fraud Right to Buy (RtB) Vetting dual working Financial Sustainability Emergency Planning health and safety compliance Subject Access Requests (SARs) Freedom of Information (FOI) requests governance model risk management Financial oversight Internal audit Surveillance powers Information Governance data breaches corporate safeguarding HR Case Management Homelessness Prevention Temporary Accommodation Unaccompanied Asylum-Seeking Children (UASC) Counter Fraud Covert surveillance information gathering techniques corporate and directorate risk registers Mitigation Measures Lambeth Council Audit and Risk Committee (Islington Council) Directed Surveillance and Covert Human Intelligence Sources Customer Access Service Transformation (CAST) programme Violence Against Residents Ombudsman timeliness Casework Capacity Data Protection Training Compliance Data Owner Responsibilities Breach Learning Complaints and Enquiries Review and Move On Overt Investigative Methods Assurance Provided by Management

Meeting Documents

Agenda

Agenda frontsheet Thursday 23-Jul-2026 17.30 Audit and Risk Committee.pdf

Reports Pack

Public reports pack Thursday 23-Jul-2026 17.30 Audit and Risk Committee.pdf

Additional Documents

Published ARC Minutes 220626.pdf
Cover Report Management Update on Limited Assurance Reports July 2026.pdf
2607 Counter Fraud Annual Report 2025-26.pdf
Annual Information Governance Report July 2026.pdf
2607 RIPA Report to Audit and Risk Committee.pdf
Audit and Risk Cttee GE risk report July 26 v3.pdf
Appendix A GE Directorate risks for Audit Risk Committee July 2026.pdf
Councils Response to Statutory Recommendations - July 2026.pdf
Audit and Risk Committee Supplement- Councils Response to Statutory Recommendations Thursday 23-Jul.pdf
Appendix A - Statutory Recommendations Action Plan Response - July 2026.pdf
RA report - Emergency Planning FY25-26 V3.pdf
Draft SoA 2025-26 - published July 2026.pdf
Report - Work Programme and Action Log 2026-2027.pdf
Appx A - Audit Risk Work Programme 2026-27.pdf
Appx B - Action Monitoring Log 2026-27.pdf
Cover Report - Annual Report and Opinion.pdf
Internal Audit Annual Report and Conclusion 2025-26.pdf
Appendix One - Annual Report 2025-26.pdf
Appendix One - RIPA Policy 2026.pdf
Audit and Risk Committee 23 July 26 Annual Casework Report.pdf
Appendix 1 - AUDIT AND RISK COMMITTEE 23 July 26 figures.pdf
Appendix A - Management Update on Limited Assurance Reports.pdf
Appendix 2 - tactical improvements.pdf
Audit and Risk Committee Supplement - Annual Governance Statement Thursday 23-Jul-2026 17.30 Audit.pdf
Cover Report for AGS 2025 to 2026 - Final.pdf
New Appendix 2 - Strengths Issues and Challenges Identified for 202526 Final.pdf
New Appendix 3 - Action Plan going into 202627 and how to address Final.pdf
New Appendix 1 - Progress with Addressing Issues and Challenges from 2024-25 Final.pdf
Annual Governance Statement 2025-2026 Appendix A Final.pdf
Audit and Risk Committee Supplement - Assurance on key Council risks held by the Growth and Environm.pdf
Audit and Risk Committee Supplement - Disaster and Emergency Planning Thursday 23-Jul-2026 17.30 A.pdf
Audit and Risk Committee Supplement - Update on Draft Statement of Accounts Thursday 23-Jul-2026 17.pdf
Accounts Update Report - Audit and Risk Ctte 230726.pdf
Printed minutes Thursday 23-Jul-2026 17.30 Audit and Risk Committee.pdf