Monitoring and Audit Committee: 27 August 2026
Internal Audit Annual Report and Opinion
Report by Chief Internal Auditor.
1. Overview
1.1. This report presents the Internal Audit Annual Report and Opinion 2025/2026, for members’ scrutiny.
1.2. The Local Authority Accounts (Scotland) Regulations 2014 established the statutory duty for the Council to have in place a professional and objective Internal Auditing Service in accordance with recognised standards and practices.
1.3. The Global Internal Audit Standards in the UK Public Sector require the Chief Internal Auditor to deliver an Internal Audit Annual Report and Opinion that can be used by the organisation to inform its governance statement. The annual opinion must conclude on the overall adequacy and effectiveness of the organisation’s framework of governance, risk management and control.
1.4. The Annual Audit Report and Opinion, attached as Appendix 1 to this report, details the level of completion of work achieved in respect of the 2025/26 audit plan.
1.5. The report provides assurance on the systems examined by Internal Audit during the financial year. In respect of the areas subject to audit review during 2025/26, as well as a review of outstanding audit recommendations, it was found that the framework of controls in place provides adequate assurance regarding governance, internal control, and risk management.
2. Recommendations
2.1. It is recommended that members of the Committee:
- Scrutinise the Internal Audit Annual Report and Opinion for 2025/26, attached as Appendix 1 to this report, in order to obtain assurance in respect of the overall opinion stated at paragraph 1.5. above.
For Further Information please contact
Andrew Paterson, Chief Internal Auditor, Extension 2107, email andrew.paterson@orkney.gov.uk.
Implications of Report
Financial: None directly related to the recommendations in this report.
Legal: None directly related to the recommendations in this report.
Corporate Governance: The Internal Audit Annual Report and Opinion plays a crucial role in enhancing the corporate governance of the Council by providing an independent and objective assessment of the organisation's internal controls, risk management, and governance processes.
Human Resources: None directly related to the recommendations in this report.
Equalities: An Equality Impact Assessment is not required in respect of Internal Audit reporting.
Island Communities Impact: An Island Communities Impact Assessment is not required in respect of Internal Audit reporting.
Links to Council Plan: The proposals in this report support and contribute to improved outcomes for communities as outlined in the following Council Plan strategic priorities:
- ☒ Growing our Economy.
- ☒ Strengthening our Communities.
- ☒ Developing our Infrastructure.
- ☒ Transforming our Council.
Links to Local Outcomes Improvement Plan: The proposals in this report support and contribute to improved outcomes for communities as outlined in the following Local Outcomes Improvement Plan priorities:
- ☒ Cost of Living.
- ☒ Sustainable Development.
- ☒ Local Equality.
- ☒ Improving Population Health.
Environmental and Climate Risk: None directly related to the recommendations in this report.
Risk: Internal Audit evaluates the effectiveness, and contributes to the improvement, of the risk management processes.
Procurement: None directly related to the recommendations in this report.
Health and Safety: None directly related to the recommendations in this report.
Property and Assets: None directly related to the recommendations in this report.
Information Technology: None directly related to the recommendations in this report.
Cost of Living: None directly related to the recommendations in this report.
List of Background Papers
Global Internal Audit Standards in the UK Public Sector.
Appendix
Appendix 1: Internal Audit Annual Report and Opinion 2025/26.
Appendix 1
Internal Audit
Internal Audit Annual Report and Opinion 2025-2026
Issue date: 15 July 2026
Contents
Introduction — 1
Overall Opinion — 1
Governance — 2
Risk Management — 3
Control Framework — 3
Internal Audit — 3
Achievement of Annual Audit Plan — 4
Quality Assurance and Improvement Programme — 6
Staffing and Training — 7
Annex 1 – 2024-25 Internal Audit Plan — 9
Annex 2 – Key to Audit Opinions. — 11
1. Introduction
1.1. The Global Internal Audit Standards in the UK Public Sector require that the Chief Internal Auditor must prepare an overall conclusion about the effectiveness of governance, risk management and control at least annually in support of wider governance reporting. The overall conclusion must encompass governance, risk management and control.
1.2. The purpose of this document is to report on the internal audit work completed during 2025/26 including planned, unplanned and annual audits. The report provides the Chief Internal Auditor’s annual internal audit opinion on the Council’s framework of governance, risk management and control.
2. Overall Opinion
Adequate: Some improvements are required to enhance the effectiveness of the framework of governance, risk management and control.
2.1. On the basis of the audit work performed in 2025/26, my opinion is that the Council has a framework of controls in place that provides adequate assurance regarding the organisation’s governance framework, related internal controls, and the management of key risks.
2.2. The recommendations made as a result of the audit work carried out did not impact on the overall governance arrangements of the Council but have identified areas for improvement in some key areas.
2.3. There was one potential fraud issue reported through whistleblowing during 2024/25 and the Police investigation into this is still ongoing. A further three whistleblowing concerns were received in 2025/26; two of these are complete and a Police investigation is still ongoing into the third.
2.4. My opinion has not been limited by any shortfall in resources, absence of skills, or any limitation of scope of internal audit activity that would adversely affect my ability to form an opinion.
2.5. In coming to my opinion, I have not relied on assurance from any other assurance providers.
Themes
2.6. The overall control environment is generally stable but requiring improvement in consistency and maturity. Audit findings are predominantly medium and low priority, with limited high-risk issues identified. Weaknesses tend to reflect inconsistent application of controls, rather than control failure.
2.7. From the 24 audits completed during the year, the key recurring theme was incomplete, outdated, or inconsistently applied policies, procedures and guidance. This featured in recommendations in 14 of the audits completed and has the effect of increasing reliance on staff knowledge rather than formal controls and can create a risk of inconsistency and non-compliance.
Status of Audit Recommendations
2.8. The Council’s performance and risk management system, Ideagen Risk Management, is used to monitor the implementation of agreed internal audit recommendations.
2.9. When internal audit reports have been finalised, the actions are uploaded to Ideagen and the officers responsible for implementing the audit recommendations are then required to provide updates on progress. The status of all recommendations is reported quarterly to the Corporate Leadership Team and on a six-monthly basis to the Monitoring and Audit Committee.
2.10. At the financial year end there were 28 recommendations which were past the agreed target date for completion, this compares to 25 at the end of the previous year. Of these 4 were high priority, 9 were medium and 15 were low priority.
3. Governance
3.1. Governance comprises the arrangements put in place to ensure that the intended outcomes for stakeholders are defined and achieved. The fundamental function of good governance in the public sector is to ensure that entities achieve their intended outcomes while acting in the public interest at all times. The core principles of good governance are:
- Behaving with integrity, demonstrating strong commitment to ethical values and respecting the rule of law.
- Ensuring openness and comprehensive stakeholder engagement.
- Defining outcomes in terms of sustainable economic, social, and environmental benefits.
- Determining the interventions necessary to optimise the achievement of the intended outcomes.
- Developing the entity’s capacity, including the capability of its leadership and the individuals within it.
- Managing risks and performance through robust internal control and strong public financial management.
- Implementing good practices in transparency, reporting and audit, to deliver effective accountability.
3.2. The Council approved a Local Code of Corporate Governance in October 2017, which was revised in September 2022, this was updated in April 2026 to align with the latest revision of the 2016 edition of Delivering Good Governance in Local Government Framework produced by the Chartered Institute of Public Finance and Accountancy (CIPFA).
3.3. The Local Code includes an annual self-assessment process. The self-assessment approach under the revised Code focuses on Council-wide evaluation of key governance arrangements, considering how effective the arrangements are.
3.4. The 2025/26 self-assessment was undertaken by the Extended Corporate Leadership Team through facilitated discussion.
3.5. The results of the self-assessment process were considered as part of the preparation of the Annual Governance Statement for 2025/26. The Statement is structured in accordance with the relevant guidance.
4. Risk Management
4.1. Risk management is the planned and systematic approach to the identification, evaluation and control of risk. The objective of risk management is to secure the assets and reputation of the Council and to ensure the continued financial and organisational well-being of the Council. The Council approved an updated Risk Management Policy and Strategy for 2024-2026 in October 2024. The measures which the Council has adopted are principles of good management practice which seek to control and balance risk and opportunity.
4.2. The Council’s risk management objectives are to:
- Ensure that risk management is thoroughly and consistently embedded in the Council’s culture.
- Manage risk according to best practice standards.
- Anticipate and adapt to evolving social, environmental and legislative changes.
- Treat compliance with health and safety, insurance and legal requirements as a baseline standard.
- Prevent death, injury, damage and losses, while minimising the cost of incidents and accidents.
- Inform policy and operational decisions by identifying risks and assessing their potential impact.
- Raise awareness of the importance of risk management among all those involved in the Council’s service delivery.
- Recognise that effective risk management includes positive risk taking and the identification of opportunities.
5. Control Framework
5.1. The policies, procedures and activities that are part of a control framework are designed and operated to ensure that risks are contained within the level that the organisation is willing to accept.
5.2. The control environment includes the following elements:
- Integrity and ethical values.
- Management’s philosophy and operating style.
- Organisational structure.
- Assignment of authority and responsibility.
- Human resource policies and practices.
- Competence of personnel.
6. Internal Audit
6.1. The Local Authority Accounts (Scotland) Regulations 2014 came into force on 10 October 2014.
6.2. These regulations established the statutory duty for the Council to have in place a professional and objective Internal Auditing Service in accordance with recognised standards and practices.
6.3. The Internal Audit Charter 2025-26, presented to the Monitoring and Audit Committee in April 2025, and approved by the Council in May 2025, defined the purpose, mandate, authority and responsibility for the Internal Audit Service and complied with the Global Internal Audit Standards in the UK Public Sector.
6.4. Internal Audit has organisational independence, and this independence was maintained throughout 2025/26. The Chief Internal Auditor (CIA) does not have operational responsibility for any of the activities audited.
6.5. The responsibilities, role and authority of Internal Audit are summarised in the Council’s Financial Regulations which state:
“The primary role of Internal Audit is that of an assurance function which provides an independent and objective opinion on the adequacy of the Council’s control environment. Internal audit work is designed to add value and improve an organisation’s operations, in particular in evaluating and improving the effectiveness of risk management, control and governance processes. In addition to the provision of assurances, Internal Audit undertakes non-assurance work including consulting services and fraud related work.”
6.6. The Internal Audit Strategy is reviewed and approved annually. The Strategy for 2025/26 was presented to the Monitoring and Audit Committee in April 2025 and subsequently approved by the Council in May 2025. A risk-based planning exercise is carried out each year to determine priorities and to establish and achieve objectives. This helps to control and direct audit work and to ensure the efficient and effective use of resources.
6.7. In carrying out audit planning, consultation is carried out with senior management throughout the Council to review the audit risk universe which includes a detailed list of Council services which are assessed on a number of risk factors. Emphasis is also placed on the Council’s risk registers when preparing the audit universe and considering which areas should be subject to audit.
7. Achievement of Annual Audit Plan
Planned Audit Work
7.1. The internal audit plan included audits of core financial systems, other systems, project reviews, annual audits, corporate reviews and follow up work. A detailed summary of the 2025/26 plan is included as Annex 1 to this report.
7.2. The internal audit team has completed the following level of planned work:
| Category of Audit | Status |
|---|---|
| Financial Systems | Four audits completed. |
| Other Systems | Eleven audits completed. |
| Project Audits | One audit completed. |
| Annual Audits | Six audits completed. |
| Corporate Reviews | One audit completed. |
| Follow Up | One Follow up audit completed, and all other actions monitored via the Ideagen Risk Management system. |
Allocation of Audit Days
7.3. In preparing the audit plan the time required to complete each audit was estimated and days then allocated within the plan. The planning process cannot be an exact science as unplanned issues often arise which have to be addressed immediately. In addition, there will be situations where the planned input must be exceeded; this may be due to the number or materiality of findings encountered, or changes in the personnel involved. A contingency element is contained within the annual plan in anticipation of these types of issues arising.
7.4. At the end of the year the actual days to complete each audit has been compared to the estimated days. The comparison shows that there were audits which were completed more quickly than expected as well as audits which took longer. Where audits required a higher number of days, this was generally to extend audit testing to verify results.
Unplanned Audit Work
7.5. Each year the Internal Audit Team undertake audit work that is not included in the annual plan, and a contingency element is built into the plan to allow for this. During 2025/26 the contingency element was used for the work shown in the table below.
| Category of Work | Status |
|---|---|
| School Meals Consultancy | Complete. |
| Whistleblowing Concern carried over from 2024/25 | Ongoing investigation. |
| Whistleblowing Concern 1. | Ongoing investigation. |
| Whistleblowing Concern 2. | Complete. |
| Whistleblowing Concern 3. | Complete. |
| UHI Shetland College Credits. | Complete. |
7.6. The contingency allowance is also used to complete work connected with the Integration Joint Board (IJB). Time from the contingency allowance was used for the audit of Financial Planning, Monitoring and Reporting as well as the Chief Internal Auditor’s preparation for and attendance at meetings of the IJB Performance and Audit Committee.
7.7. The provision of an Internal Audit Service to the Orkney and Shetland Valuation Joint Board is also done utilising time from the contingency allowance.
7.8. Various other tasks have been carried out throughout the year; whilst these on an individual level did not impact greatly on the audit plan, cumulatively they have taken up several days. These tasks included responding to service queries, carrying out smaller fact-finding exercises, provision of information to external bodies or persons and attending internal meetings.
8. Quality Assurance and Improvement Programme
8.1. Internal Audit monitors its performance to gauge the effectiveness of the service and to inform future service improvements.
8.2. The Global Internal Audit Standards in the UK Public Sector has a specific requirement for the Internal Audit Service to have in place a Quality Assurance and Improvement Programme (QAIP). The purpose of the programme is to “enable an evaluation of the internal audit activity’s conformance with the Definition of Internal Auditing and the Standards and an evaluation of whether internal auditors apply the Code of Ethics. The programme also assesses the efficiency and effectiveness of the internal audit activity and identifies opportunity for improvement.”
8.3. There are two aspects to the programme, internal and external assessment.
Internal Assessment
8.4. Internal assessment includes the ongoing monitoring of the performance of internal audit activity. A suite of Key Performance Indicators (KPIs) is in place to measure aspects of the service provided; the results are shown in the table below. Part of the day-to-day work of the Chief Internal Auditor includes supervision and file review of all audit assignments completed. In addition, Internal Audit produce a mid-year report for the Monitoring and Audit Committee on progress made against the approved plan.
| Indicator | Measure | Target | Achieved |
|---|---|---|---|
| Quality | |||
| Customer surveys | Return rate for customer surveys. | 90%. | 53%. |
| Customer surveys | Percentage of surveys with a score of 8 or more. | 90%. | 100%. |
| Recommendations accepted | Percentage of recommendations accepted by the client. | 90%. | 100%. |
| Efficiency | |||
| Issue of draft report | Percentage of draft reports issued within 10 days of fieldwork completion. | 90%. | 95%. |
| Issue of final report | Percentage of final reports issued within 5 days of final comments received. | 90%. | 100%. |
| Delivery | |||
| Delivery of plan | Percentage of audits completed in year compared to plan. | 90%. | 83%. |
| Resource | |||
| Cost of Internal Audit | Manage the costs of the team within agreed budget. | N/A. | Achieved. |
8.5. Internal assessment also includes a periodic self-assessment which is completed by the Chief Internal Auditor. The “Checklist for Assessing Conformance with the Public Sector Internal Audit Standards (PSIAS) and the Local Government Application Note” produced by CIPFA was used for the last self-assessment. This provides a very detailed examination of the service and assesses conformance with the PSIAS. The latest self-assessment was carried out in 2023 and issues identified have been addressed.
8.6. An Internal Assessment against the new Global Internal Audit Standards is planned for 2026 to ensure continued compliance with the Standards.
8.7. The quality of the service provided by Internal Audit is measured via the issue of customer satisfaction surveys following completion of each audit. The results of these surveys feed into reviews of working practices and the annual Good Conversation process. In an effort to increase the return rate for surveys an online survey has recently been adopted.
8.8. A further indicator of the quality of internal audit reporting is the number of recommendations made within audit reports that are accepted by the client. During 2025/26 a total of 87 recommendations were made by Internal Audit and all were accepted by the clients.
External Assessment
8.9. The Monitoring and Audit Committee recommended approval of the Internal Audit QAIP in September 2020. Within this plan there is an agreement through the Scottish Local Authority Chief Internal Auditors’ Group (SLACIAG) that peer review assessments are carried out on a five-year cycle using the SLACIAG External Quality Assessment Framework. The allocation of assessors is rotated to ensure independence is maintained. In May 2022, the assessment on this Council’s service was completed by Glasgow City Council’s Internal Audit Service.
8.10. The results of the assessment were reported to the Monitoring and Audit Committee on 9 June 2022. The overall conclusion of the assessment was that the Internal Audit Service conformed with the PSIAS requirements. There were four minor issues which resulted in recommendations, all of these were addressed within the agreed timeframe.
8.11. In my opinion during 2025/26 the Council’s Internal Audit Service substantially complied with the Global Internal Audit Standards in the UK Public Sector.
9. Staffing and Training
9.1. The Internal Audit Section staff allocation for 2025/26 was four full time equivalent (FTE) members of staff. This included 1 FTE Chief Internal Auditor and 1 FTE Internal Auditor and 2 FTE Trainee Internal Auditors.
9.2. Audit staff have completed all of the Council mandatory ILEARN training courses. Audit staff have also attended various courses and webinars during 2025/26 to meet Continuing Professional Development (CPD) requirements, including:
- The Chartered Institute of Internal Auditors – Regular Forums on Data Analytics and AI.
- The Chartered Institute of Internal Auditors – Auditing Fraud and Financial Crime.
- The Chartered Institute of Internal Auditors – Artificial Intelligence for Internal Audit.
- The Chartered Institute of Internal Auditors – Data Analytics and Data Visualisation.
- The Chartered Institute of Internal Auditors – Assurance Mapping and Co-ordination.
- Chartered Institute of Public Finance and Accountancy - Internal Audit Update.
- Mindgrove – Root Cause Analysis.
- Business Risk Management– The Developing Internal Auditor.
- Business Risk Management – Fraud Prevention, Detection and Investigation.
- Business Risk Management – Writing Effective Audit Reports.
- Credit Industry Fraud Avoidance Systems (CIFAS) - Fraud Webinar.
9.3. Our two Trainee Internal Auditors are studying with the Institute of Internal Auditors. Both have achieved the Certified Internal Auditor Qualification and are continuing with the Chartered Internal Auditor course.
9.4. The Chief Internal Auditor is the Council’s representative on the Scottish Local Authorities Chief Internal Auditors Group (SLACIAG). The Group held four virtual meetings to discuss current audit issues and to share best practice during 2025/26. All of these meetings were attended by the Chief Internal Auditor. There are various SLACIAG sub-groups and either the Chief Internal Auditor or another member of the team has attended sub-groups for IT Audit and Fraud Investigation throughout the year. The Chief Internal Auditor is also part of the SLACIAG Subgroup formed to deliver the updated External Quality Assessment Framework.
9.5. In accordance with the Council’s Good Conversation Process, meetings took place for all Internal Audit staff during 2025/26.
Andrew Paterson MSc CMIIA
Chief Internal Auditor
Annex 1 – 2024-25 Internal Audit Plan
| Ref. | Name of Audit | Status | Opinion |
|---|---|---|---|
| A. | Financial Systems. | ||
| 1. | Non-Domestic Rates. | Complete. | Limited. |
| 2. | Treasury Management. | Complete. | Substantial. |
| 3. | Fixed Assets. | Complete. | Substantial. |
| 4. | Financial Sustainability. | Complete. | Adequate. |
| B. | Other Systems. | ||
| 1. | School Establishment Audit – St Andrew’s Primary. | Complete. | Adequate. |
| 2. | School Establishment Audit – Stromness Primary. | Complete. | Adequate. |
| 3. | School Establishment Audit – Westray Junior High. | Complete. | Adequate. |
| 4. | School Establishment Audit – Papa Westray Primary. | Complete. | Substantial. |
| 5. | School Establishment Audit – Papdale Primary. | Complete. | Substantial. |
| 6. | Recruitment and Staff Changes. | Complete. | Substantial. |
| 7. | Refuse Collection and Street Cleansing. | Deferred to 2026/27. | N/A. |
| 8. | HEES: ABS. | Complete. | Substantial. |
| 9. | Climate Change – Net Zero Ambitions. | Deferred to 2026/27. | N/A. |
| 10. | Pickaquoy Centre Trust Service Agreement. | Complete. | Adequate. |
| 11. | Operational Property. | Complete. | Adequate. |
| 12. | Marine Services – Maintenance and Inspection. | Complete. | Adequate. |
| 13. | Criminal Justice Social Work. | Complete. | Adequate. |
| 14. | Elderly Residential Care. | Deferred to 2026/27. | N/A. |
| C. | Project Reviews. | ||
| 1. | Strategic Projects – Quanterness Wind Farm. | Complete. | Adequate. |
| D. | Annual Audits. | ||
| 1. | UHI Orkney – Credits Audit. | Complete. | Substantial. |
| 2. | UHI Orkney – Discretionary and Childcare Funds. | Complete. | Substantial. |
| 3. | Climate Change Reporting. | Completed by consultancy review. | N/A. |
| 4. | Statutory Performance Indicators. | Complete. | Substantial. |
| 5. | Stock Checks. | Complete. | Substantial. |
| 6. | Miscellaneous Grant Claims. | Complete. | N/A. |
| E. | Corporate Reviews. | ||
| 1. | Procurement Processes. | Complete. | Adequate. |
| F. | Follow Up. | ||
| 1. | OHAC Payment Processes. | Complete. | Partially Implemented. |
| 2. | Kirkwall Grammar School. | Deferred to 2026/27. | N/A. |
| G. | Contingency Allocation. | ||
| 1. | School Meals and Music Tuition Consultancy. | Complete. | N/A. |
| 2. | Whistleblowing Concerns carried over from 2024/25. | Ongoing. | N/A. |
| 3. | Whistleblowing Concern 1. | Ongoing. | N/A. |
| 4. | Whistleblowing Concern 2. | Complete. | N/A. |
| 5. | Whistleblowing Concern 3. | Complete. | N/A. |
| 6. | UHI Shetland Credits Audit. | Complete. | N/A. |
| 7. | IJB Internal Audit Provision. | Complete. | N/A. |
| 8. | OSVJB Internal Audit Provision. | Complete. | N/A. |
Annex 2 – Key to Audit Opinions
| Opinion | Definition |
|---|---|
| Substantial | The framework of governance, risk management and control were found to be comprehensive and effective. |
| Adequate | Some improvements are required to enhance the effectiveness of the framework of governance, risk management and control. |
| Limited | There are significant weaknesses in the framework of governance, risk management and control such that it could be or become inadequate and ineffective. |
| Unsatisfactory | There are fundamental weaknesses in the framework of governance, risk management and control such that it is inadequate and ineffective or is likely to fail. |