Minutes of the East Durham College Audit and Risk Committee Meeting held on 27th November 2025
Present:
R Harrison (Chair),S Laverick, V Bailey and G Edmunds
In Attendance:
S. Bullock, Principal and CEO
J. Mitchelson, Vice Principal Finance and Business Planning
C. Briggs, Vice Principal Curriculum and Performance
C. Leece (RSM, External Auditor)
C. McGinley (WBG, Internal Auditor)
S Pritchard (Clerk to Corporation)
V Charlton (Committee Secretary)
Apologies for Absence
No Apologies
611 1 Private Session of Committee and Auditors
Discussion between Committee members and Auditors took place prior to arrival of college officers.
612 2 Conflicts of Interest
The Chair invited the committee to disclose any interests which related to the items proposed to be discussed on the agenda. There were no interests declared.
613 3 Minutes of meeting – June 2025
The minutes were approved as a correct record.
614 4 Matters Arising
None
615 5 Internal Audit Reports:
Annual Internal Audit Report
WBG presented a summary of all audit work completed during the year, covering sickness and absence, financial controls, curriculum planning, IT web filtering, and the Adult Skills Fund (ASF) funding audit. The report reached an overall strong, substantial assurance conclusion, highlighting specific findings.
There was one low and one medium recommendation relating to sickness and absence, and two low-level recommendations for financial controls. The College is in a strong position compared with the client average for the Adult Skills Fund. WBG confirmed that all audit key performance indicators were met, including timescales for issuing draft and final reports.
A Governor raised questions regarding benchmarking, noting that its value depends on the size of the comparison pool. Auditors advised that benchmarking is against all comparable college audits within their system, with numbers varying by audit. The Chair requested that future reports include the size of the benchmarking pool to assess materiality. Auditors confirmed they would explore providing this information after the meeting and include in future reports.
The Principal asked whether benchmarking scope could be considered at the audit scoping stage, for example selecting audits with a larger comparison pool where possible. Auditors confirmed this could be feasible and would feed this back to WBG, noting that benchmarking may be an objective depending on the audit type. A Governor added that where an area is high risk or on the risk register, the audit should proceed regardless, but the benchmarking context should always be clearly stated.
WBG and the Vice Principal Finance and Business Planning confirmed that the exam arrangements audit will commence on 1 December.
The Committee noted the report.
IT Web Filtering
WBG presented the report, which was strong and contained no recommendations. There were two observations and a significant amount of good practice identified. Auditors were satisfied with the smoothwall arrangements and its functionality.
A Governor asked who determines the scope of audits and what drives that decision. WBG explained that the outline scope is agreed during the annual planning stage through discussion with the key contact. The Governor commented that asking managers to identify areas for testing where they hold responsibility could be problematic.
The Vice Principal Finance and Business Planning responded that the scope is set by the auditors and that the college provides what it can to support this. While there is some opportunity to influence areas, this does not mean the college avoids particular topics.
The Chair of Audit and Risk Committee commented that the scope and objectives should ensure both the college and auditors are focusing on the right areas. This is not about selecting preferred topics, but about ensuring relevance and clearly identifying any limitations, for example where an area is technically in scope but not applicable to the college. The Governor reiterated that, from an external audit and Ofsted perspective, this was a significant concern. Their view was that the Audit and Risk Committee should set the areas where governors require assurance, with the audit providing that assurance (or not) and should be made aware if the scope was limited.
WBG clarified that if there was a significant issue on which the Board required assurance, this could be included in the audit. The Vice Principal Curriculum and Performance added that the Board does influence audit areas, often in response to statutory or regulatory changes, and that it is not a case of managers choosing areas for audit. WBG responded that any limitation of scope would be fed back in advance. The Chair of Audit and Risk Committee noted that the committee does not meet frequently and that, should this situation arise, members would need to be informed outside the meeting cycle to ensure appropriate oversight. The Governor agreed with this approach.
The Principal expressed satisfaction with the audit outcome, acknowledged the two areas for continued observation, and noted that despite the strong report, the matter would remain a significant risk on the risk register.
The Vice Chair added that the report demonstrated the college’s strong working relationship with JISC, highlighting effective collaboration in a challenging environment that requires significant resourcing. He congratulated the team on their work. All governors recognised the value of JISC’s contribution.
The Committee noted the report.
616 6 External Audit Update
Draft Audit Findings Report
RSM presented the draft audit findings outlining the main areas of risk. A DfE funding audit is also taking place and the final report is awaited. Auditors expect to issue a clean audit opinion, confirming that the financial statements give a true and fair view. Some adjustments were required, mainly relating to income recognition, and updated accounts were received this week and are currently being reviewed. Last year’s modified opinion related to a severance payment that had already been identified by management, discussed by the Board and carried into this year.
The auditors highlighted two standard significant risks: management override of controls and income recognition, including clawback and correct timing of income. Additional areas reviewed included going concern, pensions, capital works and regularity.
The auditors reviewed forecasts and bank covenant compliance to assess going concern and concluded that there was sufficient evidence that the college can continue to operate for the next 12 months. No covenant breaches were identified, and management confirmed that covenants are calculated monthly and actively managed throughout the year.
Regularity matters included further discussion of the severance payment and a review of procurement. This was the first year the new procurement process had been in place for the full year. Several control recommendations were made and included improving in-year reconciliation of funding to avoid year-end adjustments, which management has already begun to implement.
The Chair invited comments from governors, and it was confirmed that the issues had already been discussed with management and that responses and additional controls had been agreed. A formal action plan will be developed, with a preference for it to be reported to the board. The updated financial statements reflect the audit adjustment.
FE – Emerging Issues
RSM presented the report, noting discussion of the Risk Register and Audit Plan. As part of the audit process, risk registers for approximately 70 clients were reviewed to identify trends. Key themes included affordability and cost pressures, organisational instability, political change, rapid technological developments (including AI), and economic slowdown. The report was considered a useful overview of emerging risks across the sector and was seen as valuable for sharing with the wider Board.
The Chair of the Audit and Risk Committee expressed uncertainty regarding the College’s current position on AI and its future direction, and questioned whether further discussion would be beneficial. The Vice Principal Curriculum and Performance confirmed that AI is already being considered internally as part of the development of a digital strategy, including its use by staff and students and links to GDPR, while acknowledging the challenges of managing its rapid development. She shared the Chair’s concerns.
It was agreed that the Vice Principal Curriculum and Performance would present a paper on AI to a future Curriculum Quality and Standards Committee, followed by the Full Board, and would also explore arranging a governor training/development session, potentially with external support.
Members Report and Financial Statements
RSM advised that there had been a recent change to terminology in relation to DfE. The audit report was unqualified, and there were no significant changes to the disclosures within the notes.
Governors noted that they had received the latest version of the document on the day of the meeting and considered this insufficient time for review.
The Vice Principal Finance and Business Planning explained that the delay was due to last-minute amendments to ensure the information provided was accurate and up to date, and confirmed that carbon reporting would be added the following day. The Vice Principal Finance and Business Planning and RSM offered to respond to any questions outside of the meeting if further discussion was required.
The Chair agreed that, given the size and importance of the document, members should be given until close of business on Tuesday to review and submit comments to the Vice Principal Finance and Business Planning. CL (RSM) suggested that questions be shared collectively to avoid duplication and resolve queries more efficiently.
A written resolution would be prepared on Wednesday and circulated by the Clerk. The final papers are due to be circulated on 4 December 2025.
Action: The Clerk to circulate a written resolution to recommend the report and financial statements to the Board.
Regularity Self-Assessment Questionnaire
The Regularity Self-Assessment was updated following the identification of issues discussed. This document is provided on an annual basis and reflects changes in regularity, particularly in relation to reporting requirements.
The Clerk advised that the Audit and Risk Committee would ordinarily recommend this document to the Board for approval and noted that it could be included within the written resolution, should this be helpful.
A Governor indicated a preference for additional time to review the document prior to approval.
The Chair of the Committee requested that, going forward, all papers clearly state what action is required of the Committee, specifically whether items are presented for noting, recommendation, or approval.
617 7 College Leadership Group Reports
Breaches and Waivers and High Value Orders
The Vice Principal for Finance and Planning presented the report which was confidential due to commercial sensitivity.
The Committee noted the report.
Risk Management
The Principal presented the report, explaining that its purpose was to alert governors to key risks. The report focused on areas where residual risk scores were highest, had changed since the previous review, or where risks had been removed.
The report was confidential due to the commercial sensitivity.
The Committee noted the report.
Sub -Contract Arrangements
The Vice Principal for Curriculum and Performance presented the confidential report.
Activity planned for 2025/26 is broadly in line with the previous academic year. The main change is a stronger focus on two sector areas—engineering and construction—to support growth.
A Governor noted some reassurance that the college is now more confident in its approach to a previous subcontractor. The Vice Principal advised that delivery has only just commenced.
The Committee agreed the Subcontracting Agreement.
Cyber Security Progress against NCSC Checklist
The Vice Principal for Finance and Business Planning presented the Cyber Security Progress Report. At the previous meeting, members had requested an update on progress against the National Cyber Security Centre (NCSC) Checklist, and it was confirmed that this will be reported annually going forward.
A Governor noted that Board members had previously received cyber security training and, given the number of new members, suggested that consideration be given to arranging a further training session.
The Committee noted the progress.
Gifts and Hospitality Declaration
The Vice Principal for Finance and Business Planning advised that the Gifts and Hospitality Declaration provides assurance to Board members that such matters are being appropriately monitored. There were no significant issues to report; however, providing an update to the Board is a required governance process.
Annual Report of the Audit Committee
The Chair of Audit and Risk Committee presented the Annual Report of the Audit Committed. Draft had been previously circulated and an updated version was uploaded today to cover some of the things discussed at the start of this meeting.
The Committee noted the report.
8.5 8 Audit Tracker
The Vice Principal for Finance and Business Planning presented the audit tracker and confirmed that, since its circulation, the majority of actions have been closed.
The Committee noted the progress against recommendations.
618 9 Any Other Business
No further Items to discuss