Skip to content
Please be aware the content below has been generated by an AI model from a source PDF.

240621ARCPaper3CNPA202324AnnualReportFINAL

Cairngorms Nation­al Park Authority

Intern­al Audit Annu­al Report 202324

June 2024


Con­tents

  • Intro­duc­tion 2
  • Over­all intern­al audit opin­ion 3
  • Intern­al audit work per­formed 4
  • Appendix 1 – Planned v actu­al days 202324 9
  • Appendix 2 – Sum­mary of Qual­ity Assur­ance Assess­ment 10

Intro­duc­tion

The Pub­lic Sec­tor Intern­al Audit Stand­ards (PSI­AS) state that:

The Chief Audit Exec­ut­ive must deliv­er an annu­al intern­al audit opin­ion and report that can be used by the organ­isa­tion to inform its gov­ernance statement.”

The annu­al intern­al audit opin­ion must con­clude on the over­all adequacy and effect­ive­ness of the organisation’s frame­work of gov­ernance, risk man­age­ment and control.”

To meet the above require­ments, this Annu­al Report sum­mar­ises our con­clu­sions and key find­ings from the intern­al audit work under­taken at Cairngorms Nation­al Park Author­ity dur­ing the year ended 31 March 2024, includ­ing our over­all opin­ion on Cairngorms Nation­al Park Authority’s intern­al con­trol system.

Acknow­ledge­ment

We would like to take this oppor­tun­ity to thank all mem­bers of man­age­ment and staff for the help, cour­tesy and co-oper­a­tion exten­ded to us dur­ing the year.


Over­all intern­al audit opinion

Basis of opinion

As the Intern­al Aud­it­or of the Cairngorms Nation­al Park Author­ity, we are required to provide the Audit and Risk Com­mit­tee with assur­ance on the whole sys­tem of intern­al con­trol. In giv­ing our opin­ion it should be noted that assur­ance can nev­er be abso­lute. The most that the intern­al audit ser­vice can provide is reas­on­able assur­ance that there are no major weak­nesses in the whole sys­tem of intern­al control.

In assess­ing the level of assur­ance to be giv­en, we have taken into account:

  • All reviews under­taken as part of the 202324 intern­al audit plan.
  • Any scope lim­it­a­tions imposed by management.
  • Mat­ters arising from pre­vi­ous reviews and the extent of fol­low-up action taken includ­ing in year audits.
  • Expect­a­tions of seni­or man­age­ment, the Audit and Risk Com­mit­tee and oth­er stakeholders.
  • The extent to which intern­al con­trols address the client’s risk man­age­ment /​control framework.
  • The effect of any sig­ni­fic­ant changes in Cairngorms Nation­al Park Authority’s object­ives or systems.
  • The intern­al audit cov­er­age achieved to date.

In my pro­fes­sion­al judge­ment as Head of Intern­al Audit, suf­fi­cient and appro­pri­ate audit pro­ced­ures have been con­duc­ted and evid­ence gathered to sup­port the basis and the accur­acy of the con­clu­sions reached and con­tained in this report. The con­clu­sions are based on the con­di­tions as they exis­ted at the time of the audit. The con­clu­sions are only applic­able for the entity examined. The evid­ence gathered meets pro­fes­sion­al audit stand­ards and is suf­fi­cient to provide seni­or man­age­ment with appro­pri­ate assur­ance from the work of intern­al audit.

Intern­al Audit Opinion

In our opin­ion, Cairngorms Nation­al Park Author­ity has a frame­work of gov­ernance, risk man­age­ment and con­trols that provides reas­on­able assur­ance regard­ing the effect­ive and effi­cient achieve­ment of object­ives, except in rela­tion to pro­cure­ment. Our work in this area found a num­ber of sig­ni­fic­ant weak­nesses in the con­trol frame­work in place and poten­tial non-com­pli­ance with pro­cure­ment legislation.

Azets

June 2024


Intern­al audit work performed

Scope and responsibilities

Man­age­ment

It is management’s respons­ib­il­ity to estab­lish a sound intern­al con­trol sys­tem. The intern­al con­trol sys­tem com­prises the whole net­work of sys­tems and pro­cesses estab­lished to provide reas­on­able assur­ance that organ­isa­tion­al object­ives will be achieved, with par­tic­u­lar ref­er­ence to:

  • risk man­age­ment.
  • the effect­ive­ness of operations.
  • the eco­nom­ic and effi­cient use of resources.
  • com­pli­ance with applic­able policies, pro­ced­ures, laws and regulations.
  • safe­guards against losses, includ­ing those arising from fraud, irreg­u­lar­ity or cor­rup­tion; and
  • the integ­rity and reli­ab­il­ity of inform­a­tion and data.

Intern­al auditor

The Intern­al Aud­it­or assists man­age­ment by examin­ing, eval­u­at­ing and report­ing on the con­trols in order to provide an inde­pend­ent assess­ment of the adequacy of the intern­al con­trol sys­tem. To achieve this, the Intern­al Aud­it­or should:

  • ana­lyse the intern­al con­trol sys­tem and estab­lish a review programme.
  • identi­fy and eval­u­ate the con­trols which are estab­lished to achieve object­ives in the most eco­nom­ic and effi­cient manner.
  • report find­ings and con­clu­sions and, where appro­pri­ate, make recom­mend­a­tions for improvement.
  • provide an opin­ion on the reli­ab­il­ity of the con­trols in the sys­tem under review; and
  • provide an assur­ance based on the eval­u­ation of the intern­al con­trol sys­tem with­in the organ­isa­tion as a whole.

Plan­ning process

Our stra­tegic and annu­al intern­al audit plans are designed to provide the Audit and Risk Com­mit­tee with assur­ance that Cairngorms Nation­al Park Authority’s intern­al con­trol sys­tem is effect­ive in man­aging the key risks and best value is being achieved. The plans are there­fore informed by Cairngorms Nation­al Park Authority’s risk man­age­ment sys­tem and linked to the Cor­por­ate Risk Register.

The Stra­tegic Intern­al Audit Plan was agreed in con­sulta­tion with seni­or man­age­ment and form­ally approved by the Audit and Risk Com­mit­tee in March 2023.

The Annu­al Intern­al Audit Plan is sub­ject to revi­sion through­out the year to reflect changes in Cairngorms Nation­al Park Author­ity’ risk pro­file. No changes were made to the 202324 plan.

We planned our work so that we have a reas­on­able expect­a­tion of detect­ing sig­ni­fic­ant con­trol weak­nesses. How­ever, intern­al audit can nev­er guar­an­tee to detect all fraud or oth­er irreg­u­lar­it­ies and can­not be held respons­ible for intern­al con­trol failures.

Cov­er achieved

The 202324 Intern­al Audit Plan com­prised 62 days of audit work and we com­pleted the full pro­gramme. A com­par­is­on of actu­al cov­er­age against the 202324 plan is attached at Appendix 1.

We con­firm that there were no resource lim­it­a­tions that impinged on our abil­ity to meet the full audit needs of the Cairngorms Nation­al Park Author­ity and no restric­tions were placed on our work by management.

We did not rely on the work per­formed by a third party dur­ing the period.

Reports

We pre­pared a report from each review and presen­ted these reports to the Audit and Risk Com­mit­tee. The reports are sum­mar­ised in the table below.

Where rel­ev­ant, all reports con­tained action plans detail­ing respons­ible officers and imple­ment­a­tion dates. The reports were fully dis­cussed and agreed with man­age­ment pri­or to sub­mis­sion to the Audit and Risk Com­mit­tee. We made no sig­ni­fic­ant recom­mend­a­tions that were not accep­ted by management.

ReviewCon­trol object­ive assess­ment4321
Expendit­ure and Creditors12
Risk Man­age­ment44
Health and Safety33
Pro­cure­ment43
Her­it­age Horizons11
Fin­ance SystemN/A Due to the style of report
Fol­low up Part 1N/A Due to the style of report
Fol­low up Part 2N/A Due to the style of report

Con­trol object­ive assess­ment definitions

  • R: Fun­da­ment­al absence or fail­ure of key controls.
  • A: Con­trol object­ive not achieved — con­trols are inad­equate or ineffective.
  • Y: Con­trol object­ive achieved — no major weak­nesses but scope for improvement.
  • G: Con­trol object­ive achieved — con­trols are adequate, effect­ive and efficient.

Man­age­ment action pri­or­it­isa­tion definitions

  • 4: Very high risk expos­ure — major con­cerns requir­ing imme­di­ate seni­or atten­tion that cre­ate fun­da­ment­al risks with­in the organisation.
  • 3: High risk expos­ure — absence / fail­ure of key con­trols that cre­ate sig­ni­fic­ant risks with­in the organisation.
  • 2: Mod­er­ate risk expos­ure — con­trols are not work­ing effect­ively and effi­ciently and may cre­ate mod­er­ate risks with­in the organisation.
  • 1: Lim­ited risk expos­ure — con­trols are work­ing effect­ively, but could be strengthened to pre­vent the cre­ation of minor risks or address gen­er­al house-keep­ing issues.

Pro­gress in imple­ment­ing pre­vi­ous intern­al audit actions

We reviewed the pro­gress of 63 actions dur­ing the course of the year and obtained suf­fi­cient evid­ence to close 28 (45%) of these. In addi­tion, two (3%) were con­sidered com­plete pending evid­ence and a fur­ther five (8%) were superseded.

Of the 28 remain­ing actions, 22 (79%) are par­tially com­plete, 14 (14%) are incom­plete and two (7%) were not yet due for completion.

Key themes from audit work in 202324

Pro­cure­ment

We iden­ti­fied a num­ber of sig­ni­fic­ant and high-risk issues regard­ing pro­cure­ment pro­cesses and con­trols. These included the lack of up-to-date Pro­cure­ment Strategy and asso­ci­ated policies and pro­ced­ures. We noted a lack of adher­ence to pro­cure­ment legis­la­tion, with our test­ing being unable to con­firm appro­pri­ate pro­ced­ures had been fol­lowed. This included an inab­il­ity to demon­strate that appro­pri­ate eval­u­ation arrange­ments were in place, with a lack of evid­ence retained in a num­ber of cases. We also con­firmed that CNPA do not pro­duce an annu­al pro­cure­ment report or main­tain a con­tracts register, which was a com­mit­ment of the pre­vi­ous CNPA pro­cure­ment strategy.

Risk Man­age­ment

We iden­ti­fied a num­ber of issues with regards to risk man­age­ment. These included the lack of an up-to-date Risk Man­age­ment Strategy, includ­ing the pro­cess for main­ten­ance of oper­a­tion­al risk registers and the escal­a­tion and de-escal­a­tion of risks. We also iden­ti­fied issues with the Stra­tegic Risk Register tem­plate such as the lack of a risk scor­ing mat­rix and links to risk appetite.

We have how­ever con­firmed that man­age­ment has made sig­ni­fic­ant pro­gress in imple­ment­ing our risk man­age­ment recom­mend­a­tions over the course of 202324. This includes the Risk Man­age­ment Policy being updated in a num­ber of areas, with the Policy also being approved by the Audit and Risk Com­mit­tee. A form­al risk scor­ing mat­rix has been developed and used to score risks on the Stra­tegic Risk Register. The Stra­tegic Risk Register tem­plate has also been updated to include, risk cat­egory, risk appet­ite, cur­rent score, tar­get score and due dates for mit­ig­at­ing actions.

Health and Safety

We found a num­ber of con­trol weak­nesses with­in health and safety, includ­ing policies and pro­ced­ures not being sub­ject to reg­u­lar review and a lack of com­ple­tion of health and safety train­ing, both induc­tion and refresh­er train­ing. In addi­tion, we found there to be a lack of form­al pro­cess for under­tak­ing invest­ig­a­tions and ensur­ing Incid­ent and Acci­dent Record­ing Forms are com­pleted fully. We have con­firmed some pro­gress has been made with the imple­ment­a­tion of our recom­mend­a­tions, includ­ing sourcing on-line train­ing for invest­ig­a­tions for rel­ev­ant staff, and the Health and Safety Com­mit­tee minutes being cir­cu­lated to SMT.

Inde­pend­ence

PSI­AS require us to com­mu­nic­ate on a timely basis all facts and mat­ters that may have a bear­ing on our independence.

We can con­firm that the staff mem­bers involved in each 202324 intern­al audit review were inde­pend­ent of Cairngorms Nation­al Park Author­ity and their objectiv­ity was not com­prom­ised in any way.

Con­form­ance with Pub­lic Sec­tor Intern­al Audit Standards

We con­firm that our intern­al audit ser­vice con­forms to the Pub­lic Sec­tor Intern­al Audit Stand­ards, which are based on the Inter­na­tion­al Stand­ards for the Pro­fes­sion­al Prac­tice of Intern­al Audit­ing. This is con­firmed through our qual­ity assur­ance and improve­ment pro­gramme, which includes cyc­lic­al intern­al and extern­al assess­ments of our meth­od­o­logy and prac­tice against the standards.

A sum­mary of the res­ults of our most recent extern­al assess­ment is provided at Appendix 2.


Appendix 1 – Planned v actu­al days 202324

Ref and Name of reportPlanned DaysActu­al Days
Expendit­ure and Creditors77
Fin­ance System88
Risk Man­age­ment77
Health and Safety77
Pro­cure­ment1111
Her­it­age Horizons88
Fol­low Up33
Intern­al Audit Man­age­ment and Administration22
Audit and Risk Com­mit­tee Plan­ning, Report­ing and Attendance33
Audit Needs Ana­lys­is – Stra­tegic and Oper­a­tion­al Planning33
Con­tact Management22
Annu­al Intern­al Audit Report11
Total6262

Appendix 2 – Sum­mary of Qual­ity Assur­ance Assessment

As part of our reg­u­lar qual­ity assess­ment pro­ced­ures, we com­mis­sioned an extern­al qual­ity assess­ment (EQA) against the Insti­tute of Intern­al Aud­it­ors (IIAs) Inter­na­tion­al Pro­fes­sion­al Prac­tices frame­work (IPPF) and, where appro­pri­ate, the Pub­lic Sec­tor Intern­al Audit Stand­ards (PSI­AS).

We are pleased to dis­close the out­come of this assess­ment as we believe it is import­ant to provide you with assur­ance that the ser­vice you receive is of a high qual­ity and fully com­pli­ant with intern­al audit standards.

Out­lined below are extracts from our most recent extern­al qual­ity assess­ment under­taken in Feb­ru­ary 2023.

Extern­al Qual­ity Assess­ment summary

Exec­ut­ive Summary

I am pleased to report that there are no mater­i­al gov­ernance, meth­od­o­logy or prac­tic­al issues that are impact­ing Azets Risk Assurance’s over­all con­form­ance with the Insti­tute of Intern­al Aud­it­ors (IIAs) Inter­na­tion­al Pro­fes­sion­al Prac­tices frame­work (IPPF).

Intern­al Audit have achieved the highest level of con­form­ance with the Stand­ards, as well as the Defin­i­tion, Core Prin­ciples, and the Code of Eth­ics, which form the man­dat­ory ele­ments of the IPPF, the glob­al stand­ard for qual­ity in Intern­al Audit­ing. The Insti­tute describe this as Gen­er­ally Conforms.”

This is an excel­lent res­ult and is based on an extens­ive EQA cov­er­ing the team’s approach, meth­od­o­logy, pro­cesses, and an extens­ive sample of engage­ment files. The EQA assessor is an exper­i­enced, former Chief Assur­ance Officer and cur­rent Audit Com­mit­tee Chair.

Con­form­ance Opinion

The IPPF/PSIAS includes the Mis­sion and Defin­i­tion of Intern­al Audit­ing, the Core Prin­ciples, Code of Eth­ics, and Inter­na­tion­al Stand­ards. There are 64 fun­da­ment­al prin­ciples to achieve, with 118 points of recom­men­ded practice.

I am delighted to con­firm that Azets Risk Assur­ance gen­er­ally con­form with 62 of these 64 fun­da­ment­al prin­ciples. This is an excel­lent res­ult. Fur­ther­more, there are no areas of par­tial’ or non-con­form­ance’ with any of the remain­ing fun­da­ment­al principles.

The over­all assess­ment res­ult­ing from the EQA is that Azets Risk Assur­ance gen­er­ally con­forms to the Inter­na­tion­al Pro­fes­sion­al Prac­tices Frame­work.” The term gen­er­ally con­forms” is used by the IIA to rep­res­ent the highest level of achieve­ment and performance.

I include a sum­mary of Azets Risk Assurance’s con­form­ance to these fun­da­ment­al prin­ciples below. Over­all, I believe that Azets Risk Assur­ance has achieved an excel­lent per­form­ance giv­en the breadth of the IPPF, and the diverse work and activ­ity the team undertakes.

Sum­mary of IIA Con­form­anceStand­ardsN/ADoes not Con­formPar­tially Con­formsGen­er­ally Con­formsTotal
Defin­i­tion of IA and Code of EthicsRules of conduct1212
Pur­pose1000 — 113088
Pro­fi­ciency and Due Pro­fes­sion­al Care1200 — 123044
Qual­ity Assur­ance and Improve­ment Programme1300 — 1322167
Man­aging the Intern­al Audit Activity2000 — 21301212
Engage­ment Plan­ning and Delivery2200 — 260012021
Total2006264

Our response

The review iden­ti­fied a num­ber of areas for future con­sid­er­a­tion to fur­ther enhance our intern­al audit prac­tices. We wel­come these find­ings and as such, a detailed action plan will be put into place to address the areas for fur­ther development.


© Azets 2024. All rights reserved. Azets refers to Azets Audit Ser­vices Lim­ited. Registered in Eng­land & Wales Registered No. 09652677. VAT Regis­tra­tion No. 219 0608 22.

Registered to carry on audit work in the UK and reg­u­lated for a range of invest­ment busi­ness activ­it­ies by the Insti­tute of Chartered Account­ants in Eng­land and Wales.

×

We want your feedback

Thank you for visiting our new website. We'd appreciate any feedback using our quick feedback form. Your thoughts make a big difference.

Thank you!