Skip to main content

Annual Governance Statement 2025/26

4. Annual review

Sources of assurance

4.1 As noted in paragraph 2.3, the annual review process is an important aspect of the work undertaken each year to assess the effectiveness of the council’s governance arrangements and systems of internal control and establish the evidence base to inform the Annual Governance Statement.  As such, various elements and mechanisms, and roles and responsibilities, are key to this process.  These sources of assurance are listed below:

  1. Compliance with the CIPFA Position Statement: Audit Committees in Local Authorities (2022). 
  2. Compliance with the CIPFA Statement on the role of the Head of Internal Audit in public service organisations (2019). 
  3. Compliance with the CIPFA Statement on the role of the Chief Financial Officer in Local Government (2016). 
  4. Compliance with the CIPFA Code of Practice on Managing the Risk of Fraud and Corruption (2014). 
  5. Compliance with the Global Internal Audit Standards (GIAS) - this replaced the Public Sector Internal Audit Standards (PSIAS) from April 2025.
  6. Chief Officers year end good governance assurance certificates and checklists.
  7. Arm’s length external organisations (ALEOs) year-end good governance assurance certificates and checklists. 
  8. Annual review and update of the council’s Local Code of Governance and its accompanying review programme (i.e. the Strategic Governance Framework). 
  9. The Annual Audit Report (AAR) process undertaken by the external auditors, together with the national approach to auditing Best Value through thematic audit work.
  10. Findings from other audit, scrutiny, or inspection bodies in relation to service specific assessments.
  11. The role of the senior management team structure of meetings in respect of providing assurance in relation to the council’s governance arrangements, systems of internal control, and continuous improvement activity.

Assessment of assurance

4.2 Each of the assurance sources listed in paragraph 4.1 has undergone a review and assessment process to ensure the information reported in the Annual Governance Statement reflects the most up-to-date position and provides the relevant assurances in respect of the council’s governance arrangements and systems of internal control.  A summary of these assurance assessments is noted in paragraph 4.3 below at points (1) to (11).

4.3 While individually each of these 11 sources of assurance are supported by separate processes and arrangements, collectively they provide an evidence base that is aligned in support of the one council approach that underpins implementation of The Plan for North Lanarkshire.  As such, where improvements have been made during the year, or found to be required moving forward, these are highlighted within each item.

1. Compliance with the CIPFA Position Statement: Audit Committees in Local Authorities (2022).  In this respect the activities and functions of the council’s Audit and Scrutiny Panel are required to reflect the standards set out in the CIPFA Statement. 

The Strategic Governance Framework sets out the evidence in this respect and confirms that during 2025/26 the purpose of the Audit and Scrutiny Panel, as set out in the Scheme of Administration reflects the standards set out in the CIPFA Statement in that its role is to “provide independent assurance to the council and those charged with governance on the adequacy of the council's risk management framework and internal control environment”. 

The Scheme of Administration confirms that the Audit and Scrutiny Panel is responsible for “providing an independent review of the council's governance, risk management, performance, and control frameworks, and overseeing the financial reporting and annual governance processes. It oversees the council's internal and external audit arrangements, helping to ensure efficient and effective assurance arrangements are in place.  It also undertakes the scrutiny function within the council’s governance framework and undertakes in-depth examination of particular areas of policy and/or service delivery with a view to making recommendations for improvement.” 

The Scheme of Administration also sets out the Audit and Scrutiny Panel’s specific duties in relation to the Annual Governance Statement which is to “review the Annual Governance Statement prior to approval and consider whether it properly reflects the risk environment and supporting assurances, taking into account Internal Audit’s opinion on the overall adequacy and effectiveness of the council’s framework of governance, risk management and control.”

During 2025/26, the Audit and Scrutiny Panel held its meetings as scheduled once every cycle, with special meetings held at the end of June and September 2025 to support the council in discharging its duties in respect of the 2024/25 year-end Annual Accounts.  A summary of agenda items considered by the Audit and Scrutiny Panel during the year is contained in the extract below.

Summary of Audit and Scrutiny Panel agenda items during 2025/26

  • Internal Audit - four progress reports covering 21 audit assignments undertaken from the audit plan which resulted in 59 recommendations, four follow up reports of actions previously agreed by management in response to audit recommendations, as well as reports in respect of the National Fraud Initiative, Internal Audit Charter, Internal Audit annual plan, and Internal Audit annual report and opinion, and a remit in respect of the adult care and social work annual quality assurance report.
  • Risk management - four risk management updates in respect of the Corporate Risk Register, with one report providing the updated Corporate Risk Register for 2025/26. Two of these reports provided an updated summary of key risks from service risk registers to enable Elected Members to have sight of those risks with the highest residual risk scores.
  • Financial management - one report in relation to the unaudited Annual Accounts for 2024/25 and one in relation to the audited Annual Accounts for 2024/25.
  • External audit - with reports in relation to the Audit Scotland annual audit plan, the council’s Annual Audit Report (AAR) and accompanying year-end statements, and an outcome report from the Best Value thematic audit on Transformation.
  • Scrutiny - two reports arising from Panel member led scrutiny (in relation to a referral from the Housing Committee and a housing performance update), three quarterly performance assurance review reports providing a composite summary of all performance reports considered by the council committees in the previous cycle, an annual update in relation to the scrutiny work programme, an update on the new national Statutory Performance Information Direction for performance reporting, an update on the new national approach to auditing Best Value, reports providing an update in relation to aspects of the frameworks supporting The Plan for North Lanarkshire and Programme of Work (i.e. the Strategic Governance Framework, Project Management Framework quality assurance annual report, and the Annual Position Statement for the frameworks), and the Annual Governance Statement.

As noted in paragraph 3.12.2, a follow up self-evaluation of the Audit and Scrutiny Panel in 2025/26 confirmed it remains effective in discharging its role, building on the initial 2023 review. Findings were reported to the Audit and Scrutiny Panel in August 2025 with the Panel being given the opportunity to identify further developments and next steps actions required to inform the improvement plan. No developments or actions were identified.

2. Compliance with the CIPFA Statement on the role of the Head of Internal Audit in public service organisations (2019). 

To enable the Chief Officer (Audit and Risk) to fulfil the role in this respect, the council’s senior management team is required to ensure they “set out how the framework of assurance supports the Annual Governance Statement and identify internal audit’s role within it”. This assurance is provided through the Strategic Governance Framework which sets out the role of Internal Audit and depicts in a diagram the steps in the annual review process which informs the content of the Annual Governance Statement.  The Strategic Governance Framework undergoes a review and refresh exercise each year to ensure it remains up to date in reflecting the council’s governance arrangements and it is reviewed and endorsed annually by the council’s senior management team. 

In line with the CIPFA statement, the Chief Officer (Audit and Risk) has also provided an annual opinion for 2025/26 on the “overall adequacy and effectiveness of the organisation’s framework of governance, risk management, and control” through the Internal Audit annual report. In line with the Global Internal Audit Standards (GIAS), and the council’s Internal Audit Charter, the council’s senior management team (through both the Business Management Team and Corporate Management Team) considered and noted the Internal Audit annual report and opinion for 2025/26 from the Chief Officer (Audit and Risk) on 11th June 2026 and 23rd June 2026 respectively.  This presented an independent and objective assurance as to the adequacy and effectiveness of governance, internal control, and risk management arrangements within the council and stated: 

  • “The annual opinion is unqualified and states that reasonable assurance can be placed on the council’s governance, risk management, and internal control arrangements” for 2025/26.
  • “There is generally an overall sound system of governance, risk management and internal control in place. While some issues, non-compliance or scope for improvement were identified, individually these do not significantly impair the council’s system of internal control.”

The CIPFA Statement considers the annual opinion from Internal Audit to be the most important output and one of the main sources of objective assurance that the Chief Executive and the council’s senior management team has to support the Annual Governance Statement.  The annual Internal Audit opinion is set out in more detail in paragraph 4.3 (5) below.

3. Compliance with the CIPFA Statement on the role of the Chief Financial Officer in Local Government (2016).  It is specified in this CIPFA Statement that the Annual Governance Statement is required to “address the authority’s arrangements for financial and internal control and for managing risk”. 

This is addressed through the external auditors’ annual audit of the financial statements which is undertaken as part of the audit of the Annual Accounts.

The external auditors Annual Audit Report (AAR) in October 2024 continued to report positively on the council’s approach to financial management and financial sustainability.  This was also the case in the Annual Audit Report (AAR) in September 2025 which recognised the council’s strong track record of delivering savings and operating within budget.  However, it recommended that, given the scale of emerging challenges and the widening budget gap, a strategic shift was needed to ensure continued financial sustainability and service delivery. 

To support this strategic shift - ensuring continued financial sustainability and effective service delivery - the existing Programme of Work and its priorities have been refocused and further enhanced.  This has been achieved through the integration of six new strategic deliverables and more integrated and co-ordinated, council-wide approach to service redesign and transformation, as set out in the report to committee in June 2026.

The extent of the council’s compliance with this statement (and the role of the Chief Financial Officer therein) is further demonstrated through the self-evaluation exercise undertaken in 2025 (noted in paragraph 3.12.2) which concluded that the council’s financial management practices comply with all aspects of the CIPFA Financial Management Code.  The self-evaluation also confirmed that the council’s Chief Financial Officer operates in a way that is consistent with the CIPFA Statement. 

4. Compliance with the CIPFA Code of Practice on Managing the Risk of Fraud and Corruption (2014).  This statement looks for compliance in terms of developing a strategy and identifying the risks. 

The Strategic Governance Framework sets out the evidence in this respect and shows that the council has a number of policies and procedures in place which are kept under review and regularly updated as required.  The key policies and procedures are listed below:

  • Corporate Fraud Policy - following a review of the council’s anti-fraud arrangements, an updated Corporate Fraud Policy was approved by the Policy and Strategy Committee in March 2026.  This sets out the council’s expectations (that extend to all individuals and organisations with whom it deals) in terms of acting honestly and with integrity, and in safeguarding public resources.  
  • Whistleblowing Procedure - an annual review process is in place in respect of the use of the procedure and to identify any amendments required to the procedure.  An updated Whistleblowing Procedure was approved by the Policy and Strategy Committee in March 2024.  The annual review for 2025 has continued into 2026 and the outcome is scheduled to be reported to committee in cycle 4 of 2026.
  • Gifts and Hospitality and Conflicts of Interest procedures for employees - guidance in this respect was first incorporated into the Employee Code of Conduct in 2018 and updates to this document have continued to reiterate employee responsibilities in this respect; this includes the most recent update to the Employee Code of Conduct in February 2025. The year-end review process is well established whereby Chief Officers are required to submit their up-to- date Service Registers annually (as part of the Chief Officer’s Assurance Certificate and Checklist process) for independent review and reporting to the council’s senior management team.  The 2025/26 review of Registers found no significant trends or issues of concern that required to be reported to the senior management team.  Notwithstanding this, procedural issues were identified in relation to the maintenance and storage of service registers that support the annual governance review process. These will be addressed through targeted awareness-raising and training activities during 2026/27.
  • Code of Conduct for Chief Officers - the latest update in this respect was approved by the Policy and Strategy Committee in June 2024.  The Code of Conduct for Chief Officers provides a framework within which Chief Officers of the council are expected to undertake their duties in a manner which meets the required standards for good governance.
  • Councillors Code of Conduct - this is approved by the Scottish Parliament and issued by Scottish Ministers.  The Standards Commission for Scotland is responsible for the enforcement of the code of conduct. It also has responsibility for issuing guidance to assist local authorities and councillors about the code of conduct and also for hearing complaints about a councillor. The latest code and relevant guidance were published in December 2021 and was shared with new and returning Elected Members following the local government elections in May 2022 with training provided on the content; this Code of Conduct is available from the council’s website.
  • Information and Cyber Security Policy - the latest update in this respect was approved by the Policy and Strategy Committee in March 2026.  This followed a review that resulted in the policy now incorporating both information security and cyber security to reflect the importance of cyber security in the council’s daily operations and strategic approach to service delivery (as defined in both the Digital and IT Strategy and The Plan for North Lanarkshire). As the council takes a digital by default approach to service delivery and much information is now in a digital format, this incorporates cyber threats that must be mitigated and managed to protect the council’s information and IT assets. 
  • Risk Management - the identification of risks is carried out in line with the council’s Risk Management Strategy (which was most recently updated and approved at Committee in March 2026) and through the risk for serious organised crime, fraud, and corruption which sits within the Corporate Risk Register. The Chief Officer (Legal and Democratic) - the council’s Monitoring Officer - is the identified lead for this specific risk.

In addition, the council actively seeks to detect fraudulent activity through participating in the National Fraud Initiative (NFI). This is a comprehensive data matching exercise between public bodies to highlight potential frauds and errors that is regularly reviewed by Internal Audit. The latest report in respect of the progress made in the follow up of matches were reported to the Audit and Scrutiny Panel in August 2025.

The CIPFA statement also requires responsibility to be acknowledged. In this respect the Internal Audit annual report 2025/26 from the Chief Officer (Audit and Risk) confirms that Internal Audit “has responsibility for investigating alleged frauds and irregularities brought to our attention in accordance with the council’s Corporate Fraud Policy. Where detailed work is carried out, the findings are reported to the Chief Executive and the relevant Chief Officer, with details of the work presented to the [Audit and Scrutiny] Panel in line with the Internal Audit Charter.”

The Internal Audit annual report 2025/26 from the Chief Officer (Audit and Risk) also notes that one fraud investigation was undertaken during the year, following concerns identified by officers in relation to applications for business grants. The investigation concluded that six grant applications were potentially fraudulent and linked to an external third party. Three of these applications were refused at assessment stage, but three were awarded totalling £134,000 - these payments could have been prevented and were a result of the weaknesses in internal processes and a failure to adhere to guidance and carry out appropriate checks. The investigation report was presented to the Audit and Scrutiny Panel in August 2026, and the findings of the investigation have been reported to Police Scotland.

An Internal Audit on Information Governance (reported to the Audit and Scrutiny Panel in November 2025) was concluded with a reasonable assurance opinion.  This found that the council has generally effective arrangements in place, including strong governance structures, clear oversight, and appropriate consideration of risks. Established bodies such as the Data Governance Board and the Data Management and Compliance Group provide strategic direction and assurance, supported by defined roles such as the Senior Information Risk Owner and Data Protection Officer. In addition, the council has a range of policies, procedures, and training in place, and information governance is appropriately recognised as a high corporate risk, with monitoring and reporting arrangements operating effectively.

  • The audit identified a small number of areas for improvement to further strengthen and mature the approach to information governance. These include the need to complete ongoing updates to policies within required timescales, ensure roles and responsibilities are clearly defined and aligned, and refresh training materials to reflect updated policies. Progress is also required on key governance workstreams such as data sharing agreements, retention schedules, and the development of the Information Asset Register. Overall, while the foundations are sound, it was considered that the council should continue to deliver the Data Governance Board’s workplan to address identified gaps and ensure arrangements remain fully compliant and effective.
  • In this context, a summary of items considered, developed, or approved at Data Governance Board meetings during 2025/26 is set out in the table below, demonstrating the progress being made against the Board’s workplan and ongoing enhancement of information governance arrangements.

Summary of Data Governance Board agenda items during 2025/26

Governance and structure

  • Agreed updates to Data Governance Board (DGB) and Data Management Compliance Group (DMCG) membership, roles, and Terms of Reference. 
  • Re-established DMCG as an operational group with responsibility for development, implementation, and reporting back to the DGB. 
  • Agreed revised governance arrangements, including reporting of DGB minutes and papers to the Business Management Team. 
  • Ongoing review and approval of DGB Terms of Reference and governance processes, including future AI oversight responsibilities. 

Policies, standards, and compliance

  • Approved / updated key policies and frameworks, including: 
    • Information classification and handling standards. 
    • Data Protection Policy and Subject Access Request guidance and templates. 
    • Records and Information Management Policy and guidelines. 
    • Acceptable Use of ICT Policy.
    • AI Policy (draft).
  • Approved updates to records retention schedules across services.
  • Oversight of compliance with Data Protection legislation and preparation of annual compliance reports.

Risk, security, and resilience

  • Reviewed and approved disaggregated corporate risks for cyber security, information security, and information governance. 
  • Approved Major Cyber Incident Response Plan and development of supporting playbooks. 
  • Monitoring of cyber security performance, audits, and resilience frameworks. 
  • Oversight of business continuity and disaster recovery improvements, including audit actions. 

Data protection and surveillance compliance 

  • Ongoing monitoring and improvement of Subject Access Request performance, backlog reduction, and compliance. 
  • Introduced centralised processes for Schedule 2 Data Protection Act requests. 
  • Oversight of Data Use and Access Act 2025 implementation, including action planning and compliance tracking. 
  • RIPSA (Regulation of Investigatory Powers (Scotland) Act) - updated policy and procedures, approval of monitoring arrangements for social media / online investigations, and DGB approval prior to committee submission.
  • IPCO (Investigatory Powers Commissioner’s Office) - reviewed annual return, statistics, and reporting requirements along with agreement of the need for ongoing compliance with legislation and codes of practice.   Review commissioned to update internal policies and procedure.

Records and data management

  • Progressed corporate approach to records management, including for electronic records.
  • Developed naming standards and transfer guidance.
  • Reviewed and updated the Information Asset Register and agreed responsibilities for ongoing maintenance.
  • Addressed records management compliance actions and publication of findings. 

Performance, monitoring, and reporting

  • Developed and implemented DGB performance indicators and dashboards. 
  • Regular monitoring of data protection performance, cyber/security metrics, and training compliance (through the mandatory e-learning modules).
  • Reviewed and signed off various reports prior to oversight by the Business Management Team, Corporate Management Team, and respective Committee. 

Operational oversight and continuous improvement

  • Regular review of audit findings, action plans, and compliance gaps. 
  • Agreement on key messages and actions to cascade across governance groups, services, and staff. 
  • Continuous refinement of work programme, agendas, and forward plans.

5. Compliance with the Global Internal Audit Standards (GIAS) 

As reported in the Internal Audit annual report for 2025/26, since their introduction in 2013, the Public Sector Internal Audit Standards (PSIAS) were mandatory for Internal Audit functions. The PSIAS required the Chief Officer (Audit and Risk) to develop and maintain a Quality Assurance and Improvement Programme (QAIP) which included periodic internal assessments, and an independent External Quality Assessment (EQA) to be undertaken at least every five years. 

During 2024/25, internal monitoring and assessment confirmed that Internal Audit continued to operate in accordance with the PSIAS. The most recent independent EQA was undertaken by Stirling Council in 2024 and confirmed that Internal Audit fully conformed with the PSIAS. This was reported to the Audit and Scrutiny Panel in May 2024. Both the self-assessment and EQA highlighted some areas for improvement and consideration.

From April 2025, the PSIAS was replaced by the Global Internal Audit Standards (GIAS), which required a revision to the current internal audit methodology and working practices. A gap analysis exercise was undertaken to determine actions to ensure compliance with the new standards, and the council is working towards this in preparation for the next EQA in 2028/29. As part of the QAIP, the GIAS also require ongoing internal review and periodic self-assessment. 

As reported in the Internal Audit annual report for 2025/26, Internal Audit is an independent, objective assurance and advisory function designed to add value and improve the council’s operations.  It helps the council accomplish its objectives by bringing a systematic, disciplined approach to evaluating and improving the effectiveness of the council’s risk management, internal control, and governance processes. 

  • The purpose, mandate, authority and responsibilities of the council’s Internal Audit function are outlined in the Internal Audit Charter, the most recent version of which was approved by the Audit and Scrutiny Panel in May 2026.  Internal Audit reports its outputs regularly throughout the year to the Panel in accordance with the Charter.  The Panel also approves the Internal Audit annual audit plan and monitors the performance of the function.
  • Internal Audit aims to provide a high quality and customer focused service which is responsive and flexible, consistent with best professional practice, focuses on areas that matter, uses resources efficiently and effectively, and is seen by stakeholders as adding value and making a vibrant and relevant contribution to the council.
  • Internal Audit’s primary objectives are:
    • To examine and evaluate internal control systems and governance arrangements within the council.
    • To provide assurance to Elected Members and senior officers on the adequacy and robustness of these systems.
    • To assist the Audit and Scrutiny Panel, Elected Members, and officers of the council in the effective discharge of their responsibilities.
  • It should be noted that the presence of an effective Internal Audit function contributes towards, but is not a substitute for, effective control.  It is primarily the responsibility of management to establish internal controls so that the council’s activities are conducted in an efficient and well-ordered manner, to ensure that management policies and directives are adhered to, and that assets and records are safeguarded.
  • The council’s internal audit arrangements are consistent with the CIPFA Statement on the role of the Head of Internal Audit in public service organisations (2019). 

Internal Audit activity is planned to enable the Chief Officer (Audit and Risk) to provide an independent annual opinion on the adequacy and effectiveness of internal controls within the authority, including the systems designed to achieve the corporate objectives of the council and those that manage the material risks faced by the authority.

In the Internal Audit annual report, the Chief Officer (Audit and Risk) provides an overview of the activities of the Internal Audit section for 2025/26.  This includes highlights of issues arising from Internal Audit activity during the year and an extract in this respect is set out in the table below.

Extract from the Internal Audit annual report for 2025/26, June 2026

In the Internal Audit annual report for 2025/26, presented to the Chief Executive and both the Business Management Team and Corporate Management Team in June 2026, the Chief Officer (Audit and Risk) provides an overview of Internal Audit activity against the 2025/26 Annual Plan and includes details of when each assignment was reported to the Audit and Scrutiny Panel (where not yet formally reported, status and expected dates are given). 

Key issues arising from Internal Audit outputs are highlighted in the Internal Audit progress report presented to each meeting of the Panel.

Audit issues 2025/26

The nature of audit assignments is such that most Internal Audit reports identify some weaknesses or areas where scope for improvement exists, and during 2025/26, a number of recommendations were made to address such areas identified from the audit work undertaken. 

The majority of audits undertaken during the year received opinions of either Reasonable or Substantial Assurance, and there are no issues arising from these audits which require to be highlighted.   There are issues (listed below) that while they could be significant to the control environment in the individual system or areas audited, they are considered not material enough to have a significant impact on the Chief Officer (Audit and Risk) overall opinion on the adequacy of the council’s control environment.

  • The 2023/24 annual report discussed reports on the Housing and Corporate Property Maintenance Contract and the whistleblowing allegations received by Audit Scotland, and audit work during 2024/25 concluded that significant progress had been made in implementing the recommendations in both reports, with some aspects being fully implemented. Substantive audit work on the operation of the new contract was included in the Internal Audit Plan for 2025/26, and no significant issues have been identified. 
  • Two audits during 2025/26 provided limited assurance. The first was in relation to unannounced spot check visits at a sample of education establishments - while the audit testing also considered physical security, health and safety, and information security arrangements, the limited assurance opinion was due to control weaknesses in the management of school funds (specifically non-compliance with procedures, and insufficient oversight of the processes by Head Teachers and senior school management). 
  • The control environment around school funds has been the subject of repeated audit activity over recent years and was mentioned specifically in the Internal Audit annual report for 2024/25. While work is ongoing to address the control weaknesses, the agreed actions from previous audits have not yet been fully implemented, meaning the areas of concern identified have not been addressed. Further work in this area has been included as part of the 2026/27 Internal Audit Plan. 
  • The second report with limited assurance relates to the arrangements for the use of Self-Directed Support (SDS). The audit found significant weaknesses in relation to the application of procedures and retention of key documentation for each of the four care delivery options available to service users, as well as in the consistency of monitoring direct payment expenditure. These weaknesses could lead to funds being misused, assessed needs not being met and potential financial loss and reputational damage for the council (although there was no evidence of misuse of funds from the sample of cases tested). 
  • One fraud investigation was undertaken during the year following concerns identified by officers in relation to applications for business grants. The investigation concluded that six grant applications were potentially fraudulent and linked to an external third party. Three of these applications were refused at assessment stage, but three were awarded totalling £134,000 - these payments could have been prevented and were a result of the weaknesses in internal processes and a failure to adhere to guidance and carry out appropriate checks. The investigation report was presented to the Audit and Scrutiny Panel in August 2026, and the findings of the investigation have been reported to Police Scotland. 

6. Chief Officer’s year-end good governance assurance certificates and checklists.  This requires Chief Officers to review various aspects within their service areas and advise of any specific issues which require to be identified in the Annual Governance Statement.

Through this process Chief Officers have reviewed the effectiveness of governance arrangements during the year within their area of responsibility by completing a Certificate of Assurance and updating a Checklist to support the preparation of the council’s statements on corporate governance and internal financial control for the year ending 31 March 2026.

Following a review of the 14 certificates and checklists completed for 2025/26, Chief Officers have confirmed corporate governance arrangements and financial controls in their area of responsibility have been, and are, working well and there are (in their opinion) no significant matters arising which would require to be raised specifically in the Annual Governance Statement.

The annual review concluded that the Chief Officer’s year-end governance assurance checklist process continues to provide an effective and robust source of assurance across all council services, with returns completed by all Chief Officers, including those undertaking statutory officer roles. The review also identified an opportunity to further strengthen the process by introducing a formal Monitoring Officer assurance assessment. This assessment would consider compliance with statutory enactments and the rule of law, and identify any instances of maladministration or injustice relevant to Part II of the Local Government (Scotland) Act 1975. The outcomes of the assessment would inform and be reported through the Annual Governance Statement, providing an additional source of governance assurance.

7. Arm’s length external organisations (ALEOs) year-end good governance assurance certificates and checklists.  This requires the Chief Executive or Senior Representative of each ALEO (Fusion Assets Limited, Routes to Work Limited, and North Lanarkshire Properties LLP) to review various aspects within their service areas and advise of any specific issues which require to be identified in the Annual Governance Statement.

Through this process the council’s three arm’s length external organisations (ALEOs) - Fusion Assets Limited, Routes to Work Limited and North Lanarkshire Properties LLP - have reviewed the effectiveness of governance arrangements during the year within their organisation by completing a Certificate of Assurance and updating a Checklist to support the preparation of the council’s statements on corporate governance and internal financial control for the year ending 31 March 2026.

In this respect, the Chief Executive or Senior Representative for each ALEO has confirmed corporate governance arrangements and financial controls in their organisation have been, and are, working well and there are (in their opinion) no significant matters arising which would require to be raised specifically in the council’s Annual Governance Statement. 

Assurance arrangements were enhanced during 2025/26 following committee agreement that future revenue monitoring council summary reports - which are reported to the Finance and Resources Committee each cycle - will incorporate financial performance information in relation to the three ALEOs. 

8. Annual review and update of the Local Code of Governance and its accompanying review programme (i.e. the Strategic Governance Framework).

The council’s Local Code of Governance brings the principles of good governance together with legislative requirements and management processes by which the council is directed and controlled and through which it is accountable to, engages with, and leads the local community.  Taking into account the local environment within which the council operates, this aims to ensure the council is able to effectively pursue the long-term ambition set out in The Plan for North Lanarkshire, while ensuring this is underpinned with control and the management of risk, and:

  • Resources are directed in accordance with agreed policies and according to priorities and in line with corporate project management procedures.
  • There is sound and inclusive decision making.
  • There is clear accountability for the use of those resources in achieving defined outcomes for service users and local communities.

The council’s Local Code of Governance is set out in the Strategic Governance Framework which is one of inter-related strategic frameworks that aim to maintain a corporate one place, one plan, one council approach.  These frameworks are key to evaluating the success of The Plan for North Lanarkshire and assessing delivery of the Programme of Work, while ensuring each stage of delivery towards achieving the overall vision is appropriately aligned, planned, guided, implemented, monitored, and governed.

As such, the Strategic Governance Framework:

  • Gathers together all existing governance arrangements into a list of elements and mechanisms that demonstrates the council’s compliance with the 7 principles, 21 sub-principles, and 91 behaviours and actions contained within the CIPFA Framework. By  collating all existing elements and mechanisms (produced by the respective Chief Officer) into the one local code for annual review, assessment, assurance, and reporting purposes, the Strategic Governance Framework and its Review Programme provide an efficient mechanism through which the annual review can be undertaken. 
  • This also ensures appropriate oversight and governance of The Plan for North Lanarkshire and supporting Programme of Work and enables the council to monitor the delivery of its ambitions while ensuring arrangements for corporate governance, risk management, and internal financial controls are sound. 
  • Sets out the role of the Chief Officers (and the council’s senior management team and its structure of meetings), Elected Members, and the Audit and Scrutiny Panel who are responsible for determining and implementing the council’s governance arrangements, ensuring the local code is assessed on an annual basis to ensure ongoing effectiveness and compliance, and identifying any improvement actions and/or future planned developments required in relation to the council’s key governance arrangements and continuous improvement activity.
  • Comprises a diagram that depicts the steps in the annual review process which ensures that the council’s governance arrangements are regularly assessed for ongoing effectiveness within the context of The Plan for North Lanarkshire and to provide evidence to inform the content of the Annual Governance Statement.
  • Remains under review through the annual review process whereby each of the elements and mechanisms in the review programme are examined and updated as required to reflect the relevant documentation and hyperlinks, as well as the review timeframe and date of next update. 
  • Is supported by an annual assessment of the current position of the elements and mechanisms in the review programme to ensure they remain timely and effective in supporting delivery of The Plan for North Lanarkshire.  This involves assigning a corresponding RAG status to provide a method by which to identify and prioritise items requiring to be reviewed and updated further.  The latest position following the 2025/26 year-end review identified no Red elements or mechanisms, one Amber, and the rest were Green.  For the one assessed as Amber (i.e. the annual review and update to the Whistleblowing Policy), there is a commitment by the respective Chief Officer to ensure an update is undertaken during 2026/27. 

The annual review and update of the Strategic Governance Framework is reviewed and endorsed each year by the council’s senior management team (through both the Business Management Team and Corporate Management Team) in line with their respective governance, strategic oversight, assurance, and continuous improvement roles in respect of the council’s governance arrangements and delivery of The Plan for North Lanarkshire.

The Strategic Governance Framework, and its accompanying review programme, have been recognised as an area of good practice in several year’s annual Internal Audits on Corporate Governance.  As reported to the Audit and Scrutiny Panel in August 2025, the most recent Internal Audit confirmed that arrangements are adequate and operating effectively, and no areas for improvement were identified.  It was, however, noted that the council should continue to monitor changes in the legal, risk, and control environment and adapt its governance arrangements accordingly to maintain this level of compliance.  The Strategic Governance Framework review programme, which continues to be updated and reported to the Audit and Scrutiny Panel annually, provides ongoing review and assurance mechanism in this regard.

9. The Annual Audit Report (AAR) process undertaken by the external auditors, together with the national approach to auditing Best Value through thematic audit work.

Published in May 2019, the North Lanarkshire Best Value Assurance Report (BVAR) comprised eight recommendations for action by the council.  Various updates have been provided to committee since, and the external auditors Annual Audit Report (AAR) has provided updates every year in terms of completed recommendations.  The Annual Audit Report (AAR) in October 2023 reported that all eight recommendations had been fully implemented and were now complete.

As reported to the Audit and Scrutiny Panel, auditing Best Value has evolved over time, and the most recent framework came into effect with the new five‑year external audit appointments in 2022/23. Under this approach:

  • Auditing Best Value is fully integrated within the wider annual audit, with findings reported through the external auditor’s Annual Audit Report (AAR).
  • Thematic Best Value audit work is undertaken each year by the external auditor, in line with Accounts Commission requirements, to provide assurance on areas of risk or interest across Scotland at a defined point in time.
  • Each council’s Annual Audit Reports (AARs) and Best Value reports are considered by the Accounts Commission once during the five‑year appointment, informing a statutory report produced by the Controller of Audit under Section 102(1) of the amended Local Government (Scotland) Act 1973.

Since the new approach was implemented, the various outcome reports (listed below) have been able to be viewed through the Policy and Strategy Committee and/or the Audit and Scrutiny Panel.  In addition, the latest of these reports - the Controller of Audit report prepared under Section 102(1) of the amended Local Government (Scotland) Act 1973 - was submitted to full Council in April 2026 to enable formal consideration through the council’s committee process and to set out the council’s response to the Accounts Commission’s findings.

A wide range of information over many years was used by the external auditors to inform the Controller of Audit report.  The evidence considered included the following:

  1. The North Lanarkshire Best Value Assurance Report (BVAR) produced in 2019 as part of the national audit programme at that time - reported to full Council in June 2019. Implementation of the eight recommendations arising from the BVAR was confirmed as complete in the Annual Audit Report (AAR) 2022/23.
  2. Outcome reports produced for the council as part of the national thematic Best Value audit programme, covering:
    1. Leadership of the development of new strategic priorities - reported to the Audit and Scrutiny Panel in October 2023 and the Policy and Strategy Committee in December 2023. Implementation of the three recommendations arising from this audit was confirmed as complete in the Annual Audit Report (AAR) 2023/24. 
    2. Workforce innovation (how the council is responding to current workforce challenges through building capacity, increasing productivity, and innovation) - reported to the Audit and Scrutiny Panel in August 2024 and the Policy and Strategy Committee in September 2024. 
    3. Transformation (how councils are redesigning and delivering more efficient services to achieve planned outcomes) - reported to the Audit and Scrutiny Panel and the Policy and Strategy Committee in September 2025. 
  3. Annual Audit Reports (AARs) for:
    1. 2022/23 - reported to the Audit and Scrutiny Panel in October 2023.
    2. 2023/24 - reported to the Audit and Scrutiny Panel in October 2024.
    3. 2024/25 - reported to the Audit and Scrutiny Panel in September 2025.

 As such, the Controller of Audit report comprised previous years’ findings that the council has already addressed through the reports listed above, along with recommendations that have since been completed or are in the process of being implemented.

Following their meeting on 11th December 2025, the Accounts Commission reported that it welcomed and endorsed the Controller of Audit report on Best Value in North Lanarkshire Council, as well as the recommendations made by auditors in their Annual Audit Report 2024/25. After considering these reports, the Commission agreed a number of findings, which are summarised below:

Best Value in North Lanarkshire Council - extract from Accounts Commission’s findings (Controller of Audit report, January 2026)

  1. As one of Scotland’s largest councils, and with significant and persistent socio-economic challenges, we are impressed with North Lanarkshire’s commitment to improving outcomes for its communities and its outward-facing approach to working with partners across and outwith the region.
  2. The council has an ambitious vision for the area that is shared with partners, underpinned by a well-established programme of work. Combined with effective financial and performance management, a track record of delivering savings, integrated workforce planning, and prioritisation of community engagement, the council has strong foundations for addressing its widening budget gap.
  3. Transformation is embedded at a service level, and the council is taking an innovative place-based approach to addressing future financial sustainability and improving outcomes, including creating community hubs with partners such as the NHS. 
  4. The council’s approach to housing and homelessness should be recognised and its Local Government Benchmarking Framework performance indicators in this service area are among the best in Scotland, demonstrating the impact of its sustained investment and preventative approaches.
  5. We are pleased to see that the council has responded positively to the auditor’s recommendations around improving processes for elected member engagement, including in strategic planning. 
  6. The council has made its expectations of staff very clear in relation to hybrid working.

In setting out their findings to the Controller of Audit report, the Accounts Commission also reiterated a number of recommendations which had been previously made through the reports listed above. These findings are set out in the report to full Council in April 2026 along with the council’s response.

The external auditors outcome report from the Best Value thematic audit on transformation (reported to the Audit and Scrutiny Panel in September 2025) reflected on the effective governance arrangements the council has in place to oversee its transformation work.  In addition, an Internal Audit review of the council’s strategic governance arrangements in place to oversee the delivery of the Programme of Work (reported to the Audit and Scrutiny Panel in August 2025) found the governance arrangements to be robust and consistent, with effective oversight provided through regular Strategic Board meetings and progress reporting to senior officers and elected members. This audit received a substantial assurance rating, with one area for improvement recommended in relation to the development and introduction of arrangements to ensure intended benefits of the Programme are realised.

The external auditor’s latest Annual Audit Report (AAR), presented to the Audit and Scrutiny Panel in September 2025, outlined key findings from the audit of the 2024/25 financial statements and wider areas including financial management and sustainability, governance, best value, and use of resources. It included the audit opinion and identified areas requiring action or further improvement.  A small number of recommendations were agreed, with management actions in place. Progress is monitored by Internal Audit and regularly reported to the Audit and Scrutiny Panel, with the most recent in May 2026. An update on the position previously reported in the 2024/25 Annual Governance Statement is set out in the table below; note this provides the position as at the May 2026 Internal Audit report.

Recommendation and actionUpdate
2023/24 Annual Audit Report (AAR) recommendations
Replacement of assets - management should establish a process to ensure assets replaced are appropriately removed from the asset register and accounted for as a disposal appropriately.

Complete

Reported to the Audit and Scrutiny Panel in November 2025.

Statutory override - the council should proactively work with CIPFA and the wider local government sector to arrive at appropriate solution for the implementation of accounting for infrastructure assets.Ongoing, due for completion 2026/27.
Reinforced autoclave aerated concrete (RAAC) - for those properties where RAAC has been identified, the council should determine a more accurate measure of the level of impairment in line with the requirement of accounting standards.

Complete

Reported to the Audit and Scrutiny Panel in November 2025.

Continuity and security of IT operations - the council should ensure there is appropriate oversight of its continuity and security of IT operations and ensure the necessary assurances are obtained for externally hosted systems.

Complete in respect of Business Continuity.

Reported to the Audit and Scrutiny Panel in May 2025.

Oversight of IT security and Disaster Recovery ongoing, due for completion November 2026.

Public performance reporting - the council should improve its public performance reporting to provide its citizens and communities with a clear summary of performance.

Ongoing, due for completion June 2026.

 

2023/24 recommendations from the Best Value thematic report
Acting on staff engagement feedback - as the council develops its staff engagement approach, it should ensure that as well as providing information to staff on council decisions, it also incorporates the views of staff and trade unions to support transparent decision making, and evidence how it is acting on findings from the Summer 2024 roadshow sessions.

Refresh of staff survey - complete.  Full update will be presented to committee in December 2026.

Review of trade union consultation arrangements - complete. Reported to Finance and Resources Committee in May 2026.

Hybrid working policy - the council should continue to monitor the impact of its hybrid working approach. It should continually assess the impact of increasing the number of office days, in terms of performance, staff wellbeing, and recruitment and retention.Complete.
Temporary workforce - the council should include data reporting on its temporary workforce as part of published workforce data, and once available it should include data on agency workers.Complete.
2024/25 Annual Audit Report (AAR) recommendations
Fixed asset register - the council should undertake a review of the fixed asset register to assess its capability to support accurate reporting.Complete.
Common good assets - the council should continue to review requirements to disclose Common Good assets separately from council assets.

Ongoing, due for completion June 2026.

 

Strategic use of reserves - the council should undertake a review of its reserves to determine what the planned or targeted level of reserves is appropriate. It should also look to define when certain earmarked reserves such as those earmarked for future budget pressures would be utilised as it is unclear whether these would be used to address short term pressures or to support investment to support long-term sustainability and improved outcomes.

Ongoing, due for completion June 2026.

 

Exit packages - there are opportunities for the council to enhance the standard of documentation of early retirement decisions. The council should also review its policies and procedures to ensure that exit packages of senior officers are subject to additional scrutiny.

Ongoing, an update on the review of the council’s democratic, committee, and decision-making governance procedures was presented to Policy and Strategy Committee in March 2026. 

Phase 4 of the review includes a review and update of the Scheme of Administration and Delegation and is scheduled to be completed by December 2026.

2023/24 recommendations from the Best Value thematic report
Benefits realisation - the council should prioritise completion of its benefits realisation framework and incorporate reporting on both financial and non-financial benefits into regular monitoring reports. Given the financial challenges the council is facing there is a need to increasingly monitor and track cost and benefits of transformation projects. This will help inform officers and members of the extent to which transformation projects are delivering their intended benefits.

Ongoing, due for completion June 2026.

 

Improving public reporting of progress against the 28 health check indicators - the council should ensure that the reporting of progress against its 28 health check indicators is more accessible to the public.Ongoing, due for completion June 2026.

10. Findings from other audit, scrutiny, or inspection bodies in relation to service specific assessments.

A dedicated page on the council’s website provides a central location for reporting on findings and recommendations from all national audits and inspections. This continues to be kept up to date as and when new reports become available nationally.  Inspection reports published during 2025/26 include the following: 

11. The role of the council’s senior management team structure of meetings in respect of providing assurance in relation to the council’s governance arrangements, systems of internal control, and continuous improvement activity.

The council recognises that a key aspect of delivering effective governance lies in how it is applied in practice. The ethos of good governance cannot be achieved through structures, rules, and procedures alone. Instead, it must be embedded within the council’s culture, with the importance and value of good governance clearly understood and articulated.

Accordingly, all references to the frameworks that support The Plan for North Lanarkshire and its supporting governance arrangements are made consistently. This ensures completeness, strengthens alignment, and reinforces awareness of the critical role that good governance plays in delivering the council’s strategic ambitions.

The role of, and need for, good governance is also reiterated in the Guidance accompanying the Report Template which requires to be used for all internal reporting purposes. 

In assessing the effectiveness of the council’s governance arrangements, the Business Management Team and Corporate Management Team each play a distinct role in monitoring, evaluating, and identifying areas for improvement across governance, systems of internal control, and continuous improvement activity.

Business Management Team (BMT):

RoleAssurance, governance oversight, and monitoring of compliance and effectiveness.
PurposeTo monitor the efficient and effective operation of the council and secure the assurances required to support achievement of the long-term ambition set out in The Plan for North Lanarkshire.
GovernanceTo ensure governance is underpinned by robust controls across corporate governance (including performance, legal and HR), risk management, and financial management.
AssuranceTo seek and evaluate assurances, compliance, and effectiveness, intervening where risks or issues in the council’s system of internal control are identified. 
ImprovementTo identify issues through assurance processes, prompting corrective action where required.

Reflecting the changes to the council’s senior management team structure as outlined in the Realising North Lanarkshire as the place to live, learn, work, invest, and visit report in December 2025 report (link to file) to committee in December 2025, the Chief Executive, Depute Chief Executive, Section 95 Officer, and Monitoring Officer are members of the Business Management Team as well as the Chief Officers of Audit and Risk and People Resources, and the Senior Strategic Communications Manager.

Corporate Management Team (CMT):

RoleStrategic leadership, direction-setting, and driving organisational improvement.
PurposeTo consider the strategic context and operating environment, understand organisational position, and shape future direction.
GovernanceTo oversee implementation of strategic and policy decisions, ensuring alignment with The Plan for North Lanarkshire and Programme of Work and a one place, one plan, one council approach.
AssuranceTo oversee delivery and progress against strategic priorities, setting the one council approach required to achieve outcomes (including partnership working where appropriate).
ImprovementTo drive continuous improvement and ensure strategic priorities are progressed through the Programme of Work.

The Chief Executive, Depute Chief Executive, and all Chief Officers are members of the CMT.

4 x Service Management Teams (SMTs)

The Realising North Lanarkshire as the place to live, learn, work, invest, and visit report in December 2025 reiterated the four service groupings which were originally established in September 2018 and which have continued to operate effectively since - Chief Executive’s services, Enterprise and Communities, Education and Families, Adult Health and Social Care.

The focus of the SMTs is to manage the operational requirements of their service remits. They are also responsible for considering the implementation of strategic and corporate decisions at a service or service grouping level, taking account of the operating context within which services are delivered. In doing so, SMTs ensure that operational decisions align with, and support, the successful progression of the Programme of Work and The Plan for North Lanarkshire.

Operational Management Team:

Formally established in April 2021, the OMT comprises all senior managers and head teachers across the council. It operates under the principles of engage, develop, support, and inform, providing a structured forum to connect managers and strengthen their capacity to support teams in progressing the Programme of Work in line with The Plan for North Lanarkshire.

The OMT provides a collaborative environment to discuss the practical implications and implementation of strategic and corporate priorities, including the Programme of Work and relevant governance obligations. It is not a decision-making body; rather, it functions as an information-sharing and engagement forum, focused on communicating, exploring, and supporting the implementation of significant developments across the council’s operational management team.

Page last updated:
25 Sep 2026

Help us improve this pageClose

We're sorry this page didn't meet your expectations this time. Please let us know if you have any feedback to help us improve the content.

If you have a question or comment about a council service or would like a reply, please contact us.

Thank you for your feedback