Annex A, Cabinet
In plain English
Noted · Received for information; no decision followed.
The Council's Internal Audit Strategy and Annual Audit Plan is updated annually, based on management's assessment of risk and Internal Audit's own risk assessment of the Council's major systems and other auditable areas. p9
The 2026/27 audit planning process included consultation with a range of stakeholders on risks and current issues within individual departments and corporately. p9
Key areas identified for audit activity include strategic risks and issues, key priority projects and programmes, priority service reviews, key financial systems, and grant claims. p10
Show the 2 passages this is based on
- p92.1 East Sussex County Council’s Internal Audit Strategy and Annual Audit Plan is updated annually and is based on a number of factors, especially management’s assessment of risk (including that set out within the strategic and departmental risk registers) and our own risk assessment of the Council’s major systems and other auditable areas. This allows us to prioritise those areas to be included within the audit plan on the basis of risk. 2.2 The annual planning process has once again involved consultation with a range of stakeholders to ensure that their views on risks and current issues, within individual departments and corporately, are identified and considered. In order to ensure that the most effective use is made of available resources, to avoid duplication and to minimise service disruption, efforts will continue to be made to identify, and where possible, rely upon, other sources of assurance available. The following diagram sets out the various sources of information used to inform our 2026/27 audit planning process:
- p102.3 Through this process, we are able to identify key areas for audit activity, including strategic risks and issues, key priority projects and programmes, priority service reviews, key financial systems, and grant claims. We also earmark time for emerging risk which enables us to respond to the rapidly changing risk landscape across the Authority.