Audit and Risk Committee Terms of Reference (507kB pdf)
1. Constitution
1.1 The Audit, Risk and Assurance Committee is established by the Integrated Care Board (the Board) as a Committee of the Board in accordance with its Constitution, Standing Financial Instructions, Standing Orders and Scheme of Reservation and Delegation (SoRD).
1.2 These Terms of Reference (ToR) set out the membership, remit, responsibilities, and reporting arrangements of the Committee and may only be changed with the approval of the Board. They will be published as part of the Governance Handbook on the ICB’s website.
1.3 The Committee is a non-executive Committee of the Board and its members, including those who are not members of the Board, are bound by the Standing Orders and other policies of the ICB.
2. Authority
2.1 The Audit, Risk and Assurance Committee is authorised by Board to:
- Undertake any activity within its ToR.
- Seek any information it requires within its remit, from any employee or member of the
ICB (who are directed to co-operate with any request made by the Audit, Risk and Assurance Committee) within its remit as outlined in these ToR.
- Commission any reports it deems necessary to help fulfil its obligations.
- Obtain legal or other independent professional advice and secure the attendance
of advisors with relevant expertise if it considers this is necessary to fulfil its functions. In doing so, the Committee must follow any procedures put in place by the ICB for obtaining legal or professional advice.
- Create task and finish sub-groups in order to take forward specific programmes of
work as considered necessary by the Audit, Risk and Assurance Committee members. The Audit, Risk and Assurance Committee shall determine the membership and ToR of any such task and finish sub-groups in accordance with the ICB’s Constitution, Standing Orders and SoRD but may not delegate any decisions to such groups.
2.2 For the avoidance of doubt, the Audit, Risk and Assurance Committee will comply with, the ICB Standing Orders, Standing Financial Instructions and the SoRD, except as outlined in these ToR.
2.3 The Audit, Risk and Assurance Committee has no executive powers, other than those delegated in the SoRD and specified in these ToR.
3. Purpose
3.1 To contribute to the overall delivery of the ICB’s strategic and statutory objectives by providing oversight and assurance to the Board on the adequacy of governance, risk management and internal control processes within the ICB, and providing independent scrutiny that enhances decision-making, strengthens accountability, and supports continuous improvement.
3.2 The duties of the Committee will be driven by the organisation’s objectives and the associated risks. An annual programme of business will be agreed before the start of the financial year; however, this will be flexible to new and emerging priorities and risks.
4. Responsibilities of the Audit, Risk and Assurance Committee
4.1. The Committee will undertake the following principal duties:
4.2. Governance and internal control
- To review the adequacy and effectiveness of governance, risk management,
assurance and internal control systems across the ICB that support the achievement of its objectives, and to highlight any areas of weakness to the Board.
- To ensure that financial systems and governance are established which facilitate
compliance with DHSC’s Group Accounting Manual.
- To ensure that the ICB acts consistently with the principles and guidance established
in HMT’s Managing Public Money.
- To seek reports and assurance from directors and managers as appropriate,
concentrating on the systems of governance and internal control, together with indicators of their effectiveness.
- To identify opportunities to improve governance and internal control processes
across the ICB.
- To have oversight of urgent decisions exercised by the Board.
4.3. Internal audit
- To ensure that there is an effective internal audit function that meets the Public Sector
Internal Audit Standards and provides appropriate independent assurance to the Board. This will be achieved by: − Considering the provision of the internal audit service and the costs involved. − Approving the appointment of the ICB’s internal auditor service. − Reviewing and approving the annual internal audit plan and more detailed programme of work, ensuring that this is consistent with the audit needs of the organisation as identified in the assurance framework. − Considering the findings of all internal audit reports, including the Head of Internal Audit Opinion (and management’s response) and ensure coordination between the internal and external auditors to optimise the use of audit resources. − Ensuring that the internal audit function is adequately resourced and has appropriate standing within the organisation. − Monitoring the effectiveness of internal audit and carrying out an annual review.
4.4. External audit
- To review and monitor the external auditor’s independence and objectivity and the
effectiveness of the audit process. In particular, the committee will review the work and findings of the external auditors and review and assess the implications and management’s responses to their work. This will be achieved by: − Considering the performance of the external auditors, as far as the rules governing the appointment permit. − Discussing and agreeing with the external auditors, before the audit commences, the nature and scope of the audit as set out in the annual plan. − Discussing with the external auditors their evaluation of audit risks and assessment of the organisation and the impact on the audit fees. − Reviewing all external audit reports, including to those charged with governance (before its submission to the Board) and any work undertaken outside the annual audit plan, together with the appropriateness of management responses. − The Audit, Risk & Assurance Committee shall not have responsibility for appointment or selection of the external auditors.
4.5. Risk Management
- Report to the Board with a clear assessment of whether principal risks to the delivery of the organisation’s corporate objectives are controlled within appetite (where appropriate) and supported by sufficient, reliable assurance.
- To review the adequacy and effectiveness of the organisations risk management framework and its implementation across the ICB.
- To receive regular updates on the ICB’s Board Assurance Framework.
- Undertake periodic structured deep-dives into principal risks to assess control effectiveness, test assurance robustness, and identify required management actions.
4.6. Assurance
- To review and triangulate assurance from internal audit, external audit, regulatory bodies, and other ICB sources of information and business intelligence to form an
independent, evidence-based view of the ICB’s control environment.
- To maintain and scrutinise the Assurance Map aligned to strategic objectives, assessing the adequacy, balance and interdependency of assurance across the three lines model and identifying gaps, duplication or over-reliance on single sources.
- Monitor and independently test the implementation and effectiveness of agreed actions arising from audit and other reviews, ensuring that issues are genuinely resolved in practice and that underlying risks have been demonstrably reduced.
- Review and assess intelligence on organisational culture including speaking up and escalation mechanisms, to assess whether risks and issues surface within the organisation are followed up and resolved.
- To receive regular reports on tender waivers approved within the ICB.
- To review the findings of assurance functions in the ICB, and to consider the implications for the governance of the ICB.
- Working with chairs of ICB committees, to review the work of other committees in the ICB with the aim of providing relevant assurance to the Audit and Risk Committee’s own areas of responsibility.
- To review the assurance processes in place in relation to financial performance across the ICB including the completeness and accuracy of information provided.
- To review the findings of external bodies including the ICB’s external regulators, and consider the implications for governance of the ICB. These will include, but will not be limited to:
- Reviews and reports issued by arm’s length bodies or regulators and inspectors: e.g. National Audit Office, Select Committees, NHS Resolution, CQC; and reviews and reports issued by professional bodies with responsibility for the performance of staff or functions (e.g. Royal Colleges and accreditation bodies).
- Pay due regard to risk and assurance activities of providers with a view to sharing understanding and learning across the health and care system in circumstances where that may offer mutual benefit to all partners.
4.7. Counter fraud
- To assure itself that the ICB has adequate arrangements in place for counter fraud, bribery and corruption (including cyber security) that meet the NHS Counter Fraud Authority’s (NHSCFA) Requirements for the Counter Fraud Functional Standard and review the outcome of work in these areas. This should include assurance that the ICB has the appropriate “reasonable procedures to prevent the occurrence of
fraud” to mitigate the exposure of the ICB to the Failure to Prevent Fraud offence governed by the Economic Crime and Corporate Transparency Act 2023.
- To review, approve and monitor counter fraud work plans, receiving regular updates on counter fraud activity, monitor the implementation of action plans, provide direct access and liaison with those responsible for counter fraud, review annual reports on counter fraud, and discuss the outcomes of the annual Counter Fraud functional Standard Return (CFFSR).
- To ensure that the counter fraud service submits an Annual Report and CFFSR, outlining work undertaken during each financial year to meet the Requirements of the NHSCFA Counter Fraud Functional Standard.
- To ensure that the counter fraud service submits an Annual Report and Self-Review Assessment, outlining work undertaken during each financial year to meet the NHS Standards for Commissioners, Fraud, Bribery and Corruption.
4.8. Freedom to Speak Up
- To review the adequacy and security of the ICB’s arrangements for its employees, contractors and external parties to raise concerns, in confidence, in relation to financial, clinical management, or other matters. The Committee shall ensure that these arrangements allow proportionate and independent investigation of such matters and appropriate follow up action.
| 4.9. Information Governance (IG) | |
|---|---|
| • To receive regular updates on IG compliance (including uptake & completion of data | |
| security training), data breaches and any related issues and risks. | |
| • To review the annual Senior Information Risk Owner (SIRO) report, the submission | |
| for the Data Security & Protection Toolkit and relevant reports and action plans. | |
| • To receive reports on audits to assess information and IT security arrangements, | |
| including the annual Data Security & Protection Toolkit audit. | |
| • | |
| To provide assurance to the Board that there is an effective framework in place for | |
| the management of risks associated with information governance |
4.10. Financial Reporting
- To monitor the integrity of the annual financial statements of the ICB and any formal announcements relating to its financial performance.
- To ensure that the systems for financial reporting to the Board, including those of budgetary control, are subject to review as to the completeness and accuracy of the information provided.
- To review and recommend to the Board the annual report and annual financial
statements (including accounting policies) for submission, and reporting to the Board, focusing particularly on:
- The wording in the Governance Statement and other disclosures relevant to the Terms of Reference of the committee
- Changes in accounting policies, practices and estimation techniques
- Unadjusted mis-statements in the Financial Statements
- Significant judgements and estimates made in the preparation of the Financial Statements
- Significant adjustments resulting from the audit
- Letter of representation
- Qualitative aspects of financial reporting.
4.11. Conflicts of Interest
- The chair of the committee will be the nominated Conflicts of Interest Guardian.
- The committee shall satisfy itself that the ICB’s policy, systems and processes for the management of conflicts, (including gifts and hospitality and bribery) are effective, including receiving reports relating to non-compliance with the ICB’s policy and procedures relating to conflicts of interest.
5. Membership and attendance
Membership
5.1. The Committee members shall be appointed by the Board in accordance with the ICB Constitution.
5.2. The Board will appoint no fewer than three members of the Committee comprising three Non-Executive Members of the Board. Other members of the Committee need not be members of the Board, but they may be.
5.1 The role of Chair will be undertaken by ICB Non-Executive Member.
5.2 Members are required to attend a minimum of 75% of meetings, other than absence due to sickness.
5.3 Members may nominate deputies to represent them in their absence and make decisions on their behalf, subject to the approval of the Chair.
5.4 Members will possess between them knowledge, skills and experience in the issues pertinent to the Audit, Risk and Assurance Committee’s business. When determining the membership of the Audit, Risk and Assurance Committee, active consideration will be made to diversity and equality. Chair and vice chair
5.5 The Audit, Risk and Assurance Committee will be chaired by a member appointed on account of their specific knowledge skills and experience making them suitable to chair the Audit, Risk and Assurance Committee.
5.6 Audit, Risk and Assurance Committee members may appoint a Vice Chair who will be nominated by the Chair of the Audit, Risk and Assurance Committee. If the Committee Chair is absent or is disqualified from participating by a conflict of interest, the Vice Chair, if present, shall preside. If the Chair or Vice Chair are absent from any meeting, a Chair shall be nominated by other members attending that meeting. Attendees
5.7 The Audit, Risk and Assurance Committee shall have the following non-voting attendees:
- Chief Finance and Compliance Officer or their nominated deputy
- Representatives of internal and external audit, and the local counter fraud service provider
- ICB Director of Corporate Services
- Other attendees as appropriate, agreed in advance with the committee chair
- Representatives from other organisations, as required.
5.8 Attendees may present at meetings and contribute to the relevant discussions but are not allowed to participate in any formal vote.
5.9 Attendees may nominate deputies to represent them in their absence, with agreement of the Chair.
5.10 The Audit, Risk and Assurance Committee may call additional experts to attend meetings on a case-by-case basis to inform discussion.
5.11 The Audit, Risk and Assurance Committee may invite or allow people to attend meetings as observers. Observers may not present at meetings, contribute to any discussion or participate in any formal vote.
5.12 The Audit, Risk and Assurance Committee Chair may ask any or all of those who normally attend, but who are not members, to withdraw to facilitate private discussion of particular matters.
6. Meeting Frequency, Quoracy and Decisions
6.1 The Audit, Risk and Assurance Committee will usually meet quarterly. Arrangements and notice for calling meetings are set out in the Standing Orders. Additional meetings may take place as required.
6.2 The Board, Chair or Chief Executive may ask the Audit, Risk and Assurance Committee to convene further meetings to discuss particular issues on which they want the Audit, Risk and Assurance Committee advice.
6.3 Meetings will be held in-person, unless previously agreed by the Chair. The Audit, Risk and Assurance Committee may choose to meet online, via MS Teams or suitable alternative platform. Quorum
6.4 For a meeting to be quorate the following members will be required:
- 2 x ICB Non-Executive Directors
6.5 If any member of the Audit, Risk and Assurance Committee has been disqualified from participating in an item on the agenda, by reason of a declaration of conflicts of interest, then that individual shall no longer count towards the quorum.
6.6 If the quorum has not been reached, then the meeting may proceed if those attending agree, but no decisions may be taken.
Decision making and voting
6.7 Decisions will be taken in accordance with the Standing Orders. The Audit, Risk and Assurance Committee will ordinarily reach conclusions by consensus. When this is not possible the Chair may call a vote.
6.8 Only members of the Audit, Risk and Assurance Committee may vote. Each member is allowed one vote and a majority will be conclusive on any matter.
6.9 Where there is a split vote, with no clear majority, the Chair of the Audit, Risk and Assurance Committee will hold the casting vote.
6.10 If a decision is needed which cannot wait for the next scheduled meeting, the Chair may conduct business on a ‘virtual’ basis through email or other electronic communication.
6.11 Any decisions taken virtually must be recorded at the next scheduled meeting.
7. Accountability and reporting
7.1 The Audit, Risk and Assurance Committee is accountable to the ICB Board and shall provide reports to the ICB Board on how it discharges its responsibilities and shall draw to the attention to any issues that require disclosure or require action.
7.2 The Audit, Risk and Assurance Committee shall make any such recommendations to the ICB Board it deems appropriate on any area within its remit where action or improvement is needed.
7.3 The minutes of the meetings shall be formally recorded by the secretary and approved at the next scheduled meeting.
7.4 The Audit, Risk and Assurance Committee will report to ICB Board at least annually to describe how it has fulfilled its ToR, give details of any significant issues that it has considered, and how they were addressed.
8. Conflicts of Interest
8.1 Conflicts of Interest shall be dealt with in accordance with the ICB Conflicts of Interest Policy.
8.2 The Audit, Risk and Assurance Committee will have a Conflicts of Interest Register that will be presented as a standing item on the agenda.
8.3 All members and attendees of the Audit, Risk and Assurance Committee must declare any relevant personal, non-personal, pecuniary or potential interests at the commencement of any meeting. The Chair will determine if there is a conflict of interest such that the member and/or attendee will be required not to participate in a discussion.
9. Behaviours and Conduct
ICB values
9.1 Members will be expected to conduct business in line with the ICB values and objectives.
9.2 Members of, and those attending, the Committee shall behave in accordance with the ICB’s Constitution, Standing Orders, and Standards of Business Conduct Policy.
Equality and diversity
9.3 Members must demonstrably consider the equality and diversity implications of decisions they make.
10. Secretariat and Administration
10.1 The Audit, Risk and Assurance Committee shall be supported with a secretariat function which will include ensuring that:
- The agenda and papers are prepared and distributed in accordance with the Standing Orders having been agreed by the Chair with the support of the relevant executive lead;
- Attendance of those invited to each meeting is monitored and highlighting to the Chair those that do not meet the minimum requirements;
- Records of members’ appointments and renewal dates and the Board is prompted to renew membership and identify new members where necessary;
- Good quality minutes are taken, agreed with the Chair, and a record of matters arising. Action points and issues, with progress updates, will be carried forward between meetings;
- The Chair is supported to prepare and deliver reports to the ICB Board and
- The Audit, Risk and Assurance Committee is updated on pertinent issues / areas of interest / policy developments.
11. Review
11.1 The Audit, Risk and Assurance Committee will review its effectiveness at least annually and recommend any changes it considers necessary to ICB Board.
11.2 These ToR will be reviewed at least annually and more frequently if required. Any proposed amendments to the ToR will be submitted to ICB Board for approval.