Skip to main content
Document

Audit Minutes 19 Feb 2020

  • Last updated:

Minutes Of The Meeting Of The Cardiff University Audit Committee Held On Wednesday 19 February 2020 In Room 0.51, Main Building At 10:00am

Present: Mr Michael Hampson (Chair), Mr Paul Benjamin, Mr Dónall Curtin, Dr Janet Wademan and Ms Agnes Xavier-Phillips.

In Attendance: Professor Colin Riordan [Minute 779-781], Mr John Britton, Ms Deborah Collins, Mr Ian Davies [Minute 774-763.6], Mr David Edwards [Minute 782-783.2], Ms Clare Eveleigh, Ms Laura Hallez [Minute 774 – 780-786], Ms Alison Jarvis, Ms Faye Lloyd, Mr Paul Merison [Minute 782-783.2], Ms Alex Payne (Minute-taker), Mr Richard Walters [Minute 774-789], Mr Robert Williams, and Ms Wendy Wright.

Apologies:  Mr Jason Clarke (PricewaterhouseCoopers).

774 Preliminaries

NOTED

774.1 that Mr Ian Davies, representative from PricewaterhouseCoopers, was welcomed to the meeting, and that the Vice-Chancellor would be in attendance in respect of the Risk Register and Transforming Cardiff Assurance Update;

775  Minutes From the Previous Meeting

NOTED

775.1 that the minutes from the meetings held on the 03 October 2019 and the 13 November 2019 were considered, and that the University Secretary gave detail in respect of the Publication Policy and its application to the preparation of the minutes;

RESOLVED

775.2 the minutes of the meeting held on the 03 October 2019 and the 13 November 2019 were approved as a true and accurate record.

776 Matters Arising from the Minutes

NOTED

776.1 that an action from the last meeting in relation to the Risk Register & Risk Appetite [19/183B] was yet to be completed as it was unclear whether the requested information – the ASSUR report - had been issued to members of the Committee;

776.2 that in relation to the action from the last meeting for there to be an internal audit of the joint venture, it was advised that this audit would be completed by the end of the current academic year;

776.3 the importance of continuing to monitor actions from previous meetings and avoiding use of ‘as soon as possible’ as a deadline;

776.4 that the Chief Operating Officer (COO) gave an overview of the remit of the Governance, Risk and Assurance Group (GRAG), and suggested that it could be useful for a GRAG Chair’s Report to be received at future Committee meetings.

RESOLVED

776.5 that the Chief Financial Officer (CFO) would complete the action from the last meeting by issuing the ASSUR report to members of the Committee;

776.6 that it was agreed that the GRAG Chair’s Report would be presented to future meetings of the Committee starting in June 2020.

777 Declarations of Interest

There were no declarations of interest.

778 Live Incidents

Received and considered for debate paper 19/385B, ‘Live Incidents’.

NOTED

778.1 that the Coronavirus major incident detailed in the report was discussed, and that the Executive have been reviewing risks and managing issues as they emerged;

778.2 that the impact of this incident on future recruitment of international students was under consideration (minute 780 refers);

778.3 that the University has been working closely with the Students’ Union in respect of student welfare issues following incidents of victimisation of students in relation to the spread of the pandemic.

779 Annual Counter-Fraud, Bribery & Financial Compliance Report

Received and considered for debate paper 19/398B, ‘Annual Report – Fraud, Bribery and other Financial Compliance’. Deborah Collins, Chief Operating Officer, was invited to speak to this item. Laura Hallez, Senior Risk Advisor, was in attendance for this item.

NOTED

779.1 the report having been issued to the Committee late, and that it was important for papers to be issued to members no later than seven days before a meeting;

779.2 that reference was made to the Criminal Finances Act 2017, which covered corruption, money laundering and tax evasion, and that relevant data had been presented to the Committee for information;

779.3 issues around staff completion rates for the Counter-Fraud and Anti-Bribery training, and the importance of staff in high risk areas such as Estates, completing this mandatory training;

779.4 that the Counter-Fraud and Anti-Bribery training content had been developed from a sector-wide package which had been adopted by many universities;

779.5 that it was necessary to improve the suite of policies which inform this training, and that it was important to improve the cultural issues associated with compliance against training requirements;

779.6 that it would be prudent to receive an update on completion rates in relation to mandatory training requirements.

RESOLVED

779.7 that at an appropriate stage in 2020/2021 the Committee receive an update on completion rates in relation to mandatory training requirements, particularly in relation to Counter-Fraud and Anti-Bribery training.

780 Risk Register

Received and considered for debate paper 19/386B, ‘Risk Register’. The Vice-Chancellor was invited to speak to this item. Laura Hallez, Senior Risk Advisor, was in attendance for this item.

NOTED

780.1 that the Vice-Chancellor confirmed that he had requested that a risk in respect of the Coronavirus major incident be included in the Risk Register going forward;

780.2 the anticipated significant impact of Coronavirus from September 2020 onwards on student recruitment and financial performance;

780.3 that the Executive will continue to monitor the incident and review the potential impact on the financial position;

780.4 that in discussing the emerging ‘cyber security’ risk it was noted that this risk has been managed locally across the University and that work is being done to allow for its inclusion in the Risk Register;

780.5 discussions relating to risks relating to the Research Excellence Framework (REF) and that future action to mitigate these risks would include the development of secure systems to support data submission;

780.6 the changes to risks detailed in the report, particularly the net score for risks relating to industrial action;

780.7 on-going discussions between the University and representatives from the University & College Union on industrial action;

780.8 that there had not been a “deep dive” review on the REF risk because there had been no changes in risk elements since this risk was last considered and presented;

780.9 that it was important to consider whether sufficient time was being spent by the Committee on risk management and whether it would be appropriate for staff who support specific operations to attend future meetings to inform discussions;

RESOLVED

780.10 that consideration would be given on how to approach a more detailed consideration of risks, particularly on whether it would be appropriate to invite specific staff to future meetings to inform discussions;

780.11 that, subject to the inclusion of Coronavirus as a major incident, the Risk Register was endorsed for progression to Council for approval.

781 Transforming Cardiff Assurance Update

Received and considered for debate paper 19/933B, 19/100B and 19/401B, ‘Transforming Cardiff Assurance Update (Management Response)’. The Vice-Chancellor was invited to speak to this item.

NOTED

781.1 [REDACTED]

781.2 [REDACTED]

781.3 [REDACTED]

781.4 [REDACTED]

781.5 [REDACTED]

781.6 [REDACTED]

781.7 [REDACTED]

RESOLVED

781.8 that the Executive review and assess the assurance framework to ensure that it is fit for purpose;

781.9 that the June 2020 meeting Committee receives information in respect of benefits realisation of the assurance framework;

781.10 that the report due to be prepared for the Policy & Resources Committee be received by the Audit Committee at the earliest practical date.

782 Progress Report Against Internal Audit Programme

Received and considered for debate paper 19/387B, ‘Progress Report: 2019/2020 Audit Programme’. Faye Lloyd, Head of Internal Audit, was available to speak to this item.

783 Discussion Points For Internal Audit Reports

Received and considered for debate paper 19/388B, ‘Discussion Points for Internal Audit Reports’. Faye Lloyd, Head of Internal Audit, was invited to speak to this item.

783.1 CoBIT Risk & Maturity Assessment: Advisory Report

NOTED
.1 that David Edwards, Director of IT at Cardiff University, and Paul Merison, representative from TIAA, were welcomed to the meeting in respect of the CoBIT Risk & Maturity Assessment audit report;
.2  that in 2017 a comprehensive IT risk-based audit needs assessment was completed which informed the development of the 2017-2019 IT Audit Strategy;
.3 that through this process the IT function completed CoBIT 5 self-assessment of the 37 CoBIT processes, to identify the perceived maturity, needs, culture and risks;
.4 that this assessment was informed by a full review of the University’s latest IT and Risk Register, in addition to comprehensive engagement with the Executive;
.5 that this activity included a review of previous IT audits, regulatory requirements and recommendations, external audit concerns, and relevant corporate document;
.6 that a component of the review process was a light touch assessment undertaken with management in November 2019 to confirm the maturity position;
.7 that there is an appetite for improvement at Cardiff University and that the general direction and progress of works are positive;
.8 that the need for adequate resourcing was considered, and that the target levels indicated were achievable with the right enabling actions;
.9 that in congratulating the University’s IT function on progress made, the meeting emphasised the importance of the effectiveness of this area of operation.

RESOLVED

.10 that copies of the maturity radar charts would be provided for information.

783.2 IT Innovation Strategy Progress: Follow Up

NOTED
.1 that David Edwards, Director of IT at Cardiff University was invited to provide an update in respect of the IT Innovation Strategy and progress since the last meeting;
.2 that progress was somewhat dependent on approval of the University’s digital strategy, and that it would be necessary to make a case for adequate investment in this area;
.3 that both David Edwards and Paul Merison were thanked by the Committee for their work in an area that was central to the aim of continual improvement.

783.3 Data Quality Management Milestones: Follow Up

NOTED
.1 a verbal update by John Briton, Director of Strategic Planning and Governance, on data quality management and the associated activity;
.2 the need for greater awareness of governance, risk, and assurance at all levels of the organisation, thus reducing reliance on individual members of the senior staff;
.3 that there has been a University-wide focus on continual professional development and a Departmental focus on risk identification and management;

RESOLVED
.4 that an update in respect of data quality management would be received   at the October 2020 meeting.

783.4 GDPR Compliance Arrangements Limited Assurance Report

NOTED
.1 that key issues identified were completion rates in respect of mandatory information security training and completion of the University Register of Processing Activity;
.2 that the significant issues identified had been risk-assessed and prioritised.

RESOLVED
.3 that a report would be received in due course on development of information security training.

783.5 Income Controls (Fee Income Focus) Limited Assurance Report

NOTED
.1 that weaknesses in the Financial Regulations and policy documentation hampered improvements in good financial management and control, that PCI-DSS issues were unresolved and that local business continuity plans were not in place for key systems;
.2 that the University had taken steps to improve its counter-fraud control environment but that further progress in this area was dependent upon adequate resourcing.

783.6 Teaching Excellence Framework (TEF): Follow Up Report

NOTED
.1 that the risk landscape in respect of the TEF had changed, and that progress through Nicholls Review could not be evidenced as initially proposed by management.

783.7 Residences Missing Money: Follow Up Report

NOTED
.1 that the outcome of this report was ‘satisfactory’ and that the risks had been fully addressed through a move to a cashless campus operating model.

783.8 Review of Financial Regulations (Phase 1): Advisory Report

NOTED
.1 that a presentation was delivered by a Senior Internal Auditor, in respect of the Review of Financial Regulations (Phase 1) Advisory Report;
.2 that a commitment was made to HEFCW to review and update the Financial Regulations following the 2018 HEFCW Institutional Assurance Review;
.3 that it is a requirement of the HEFCW Financial Management Code for the University to have appropriate arrangements for the organisation and management of its financial affairs;
.4 that the Committee had received a high-level plan regarding the schedule for reviewing and updating the Financial Regulations, after which a request was made for support from Internal Audit;
.5  that the Financial Regulations had been reviewed in 2012 and 2015 but there remained no alignment between the Regulations and associated policies and procedures;
.6 that the themes identified from the 2018/2019 audit programme focused on policy, procedure, and internal control as areas requiring improvement;
.7 that there are weaknesses in the first and second lines of defence, and that the institution cannot easily evidence the second line of defence;
.8 that critical success factors in the delivery of the new Financial Regulations include ownership, resource capacity, resource capability, collaboration, and effective communication;
.9 that a further presentation was delivered by the Director of Financial Operations, providing further information from a Finance Department perspective;
.10 that the challenges facing the Finance Department were acknowledged, and that these included a lack of investment over the last ten years, the complexity of the system landscape, the transactional nature of financial operations and the low number of professionally qualified staff;
.11 that despite these challenges the University has continually delivered a   clean audit opinion of the annual financial statements;
.12 that there were 34 recommendations on the Tracker which relate to finance, many of which were inherited – it was acknowledged that it is important to address the challenges holistically and employ a milestone approach;
.13 that it was important to approach the improvements required strategically and that investment was required to ensure continual improvement;
.14 that the Executive recognised the need for resources to support this activity and that impending appointments such as that of Deputy Secretary and General Counsel would assist in making progress;
.15 that such developments were supported by the GRAG which encouraged employment of a systemic and cohesive approach;

RESOLVED
.16 that a strategy for the maturation / development of Finance and its core functions be developed and presented to the Committee;
.17 that from June 2020 the Committee receive a standing report at each meeting on progress against the schedule for review and update of the Financial Regulations;
.18 that Finance would discuss and agree with Internal Audit priorities in respect of the tracker recommendations and the timing of receipt of a substantive progress report.

784 IIA Audit Code Of Practice – Guidance For Effective Internal Audit

Received and considered for debate paper 19/389, ‘IIA Audit Code of Practice – Guidance Note’. Faye Lloyd, Head of Internal Audit, was available to speak to this item.

785 Follow Up Of Highly Rated Recommendations Report

Received and considered for debate paper 19/392B, ‘Follow-Up of Highly Rated Recommendations Report’. Faye Lloyd, Head of Internal Audit, was invited to speak to this item.

NOTED

785.1 that it would be helpful to include milestone information on the tracker document.

786 Financial Irregularities Report

Received for information paper 19/396B, ‘Financial Irregularities Report’. Alison Jarvis, Director of Financial Operations, was available to speak to this item.

787 Contract Tender Update – External And Internal Audit

Received and considered for debate paper 19/410B, ‘Contract Tender – External and Internal Audit’. Rob Williams, Chief Financial Officer, was invited to speak to this item. Ian Davies, PricewaterhouseCoopers, was absent for this item.

NOTED

787.1 that the Committee’s attention was drawn to the second-tier firms that the University had informally engaged with, and the anticipated cost of a new external audit contract,

787.2 that there was a greater appetite to bid for provision of internal rather than external audit services and that it is possible that one supplier could meet all the University’s externally-provided internal audit requirements;

787.3 that the tender process should be endorsed by the Audit Committee through its Chair and that and that a recommendation for appointment would be brought to the Committee for consideration in June;

787.4 that it was suggested that the procurement panel could comprise the Chair of the Audit Committee, the Head of Internal Audit, and the CFO.

RESOLVED

787.5 that the tender process and schedule detailed in the paper was agreed, and that consideration would be given to the composition of the procurement panel and the level of visibility of the process required by the Committee.

788 Serious Incident Reporting – Update

NOTED

788.1 that a verbal update was given by the Interim Head of Governance Services, and that further work was to be undertaken to identify each of the reporting thresholds and reporting mechanisms;

788.2 that it was intended that a report would be presented to GRAG before submission to the Audit Committee for information.

789  Specific Serious Incident Report – Update

NOTED

789.1 that a verbal update was given on this matter by the COO, and that the investigation into incident to which this report refers had concluded;

789.2 that a related internal audit review would be carried out and a report presented to the Committee in due course.

790 Any Other Business

NOTED

790.1 that the Powell Review recommended that the Audit Committee become the Audit and Risk Assurance Committee, and that this change would take effect following Council’s formal approval of the Powell Review’s recommendations.
Cardiff Innovation Campus

790.2 [REDACTED]

790.3 [REDACTED]

790.4 [REDACTED]

790.5 [REDACTED]

790.6 [REDACTED]

790.7 [REDACTED]

790.8 [REDACTED]

791 Agenda for the Next Meeting

Received and considered for decision paper 19/390B, ‘Agenda for the Next Meeting – June 2020’. This item was led by the Chair of the Audit Committee.

RESOLVED

791.1 that the agenda for the next meeting of the Committee on the 10 June 2020 was agreed.

792 Receipt of Minutes

NOTED

792.1 that the minutes of the meeting of the Governance Committee on the 25 September 2019 had been received by the Committee;

792.2 that the minutes of the meeting of the Policy & Resources Committee on the 07 November 2019 had been received by the Committee.

793 December 2019 Financial Update

Received for information paper 19/397B, ‘December 2019 Financial Update’. Rob Williams, Chief Financial Officer, was available to speak to this item.

794 HEFCW Institutional Assurance Review 2018 – Management Response

Received for information paper 19/391B, ‘HEFCW Institutional Assurance Review 2018 – Management Response’. John Britton, Director of Strategic Planning & Governance, was available to speak to this item.

In-Camera

Following the meeting an in-camera meeting was held of Members and the Head of Internal Audit.