
Following the most recent formal review
of auditor independence, which took into
consideration a further report from EY on the
auditor’s own independence controls and
the level of audit fees and non-audit fees
paid to the auditor, the Committee continues
to consider that EY, and Victoria Venning as
lead audit partner, remain independent.
Auditor challenge, assessment
and reappointment
The Audit Committee challenges the
external auditor and assesses their
performance on an ongoing basis.
Within 2021, the Committee has sought
to challenge the auditors to provide the
Committee with more detailed breakdown of
their methodology and testing approaches
on various key audit matters, such as
revenue recognition. A formal review
is conducted annually, using a survey
framework that takes into consideration
factors such as the quality and depth of
the auditor’s reporting, their planning and
strategy for undertaking the audit and the
quality of the personnel undertaking the
audit. The Committee also considers the
feedback obtained from surveys of senior
management on the performance of EY,
including any highlighted opportunities to
enhance the audit process. Following the
formal review of auditor performance
for the 2021 audit, the Audit Committee
considers that EY remain independent and
objective, and continue to deliver a high
quality of audit. As such, the Committee has
recommended to the Board that EY be re-
appointed auditor.
The Company has complied with the
provisions of The Statutory Audit Services
for Large Companies Market Investigation
(Mandatory Use of Competitive Processes
and Audit Committee Responsibilities) Order
2014. In line with the provisions of this Order,
the Group is not required to re-tender its
audit provision until the full year audit for
2026; however, the Audit Committee will
monitor the performance of EY continuously,
and will make recommendations on future
tendering plans on an annual basis.
The Committee considers this approach to
tendering to be in the best interests of all
stakeholders given the high quality of audit
being delivered by EY and their detailed
understanding of the Group’s operations.
4. Review of the work of the Group
Internal Audit department
The Group Internal Audit Manager attends
all meetings of the Committee in full, and
presents for approval the annual risk-based
internal audit plan, results of all completed
internal audits, the follow-up status of
agreed actions, and performance indicators
for the department. The Group Internal
Audit department continues to work in
line with the Professional Standards of the
Chartered Institute of Internal Auditors (IIA)
and the IIA’s Internal Audit Code of Practice,
verified through periodic External Quality
Assessments. To ensure the continuous
improvement of the internal audit provision,
the Committee has reviewed and approved
the Group Internal Audit Development Plan,
and receives regular progress reports on
its implementation.
The Audit Committee members meet with
the Group Internal Audit Manager at least
annually without management present, to
ensure that independence and objectivity
of the Group Internal Audit department
is being maintained, and to consider the
appropriateness of the department’s
available skills and resources. Following the
2021 meeting, the Committee confirmed
it was satisfied that the overall level of
resource in place remains appropriate but
that it would be kept under review to ensure
it remains sufficient to support any changes
in the expectations placed on Group Internal
Audit. The Committee recognised that
for some specialist assurance work, the
department’s skills should continue to be
supplemented with co-sourced resource
from external providers.
Within the year, the Group Internal Audit
department has delivered its annual audit
plan effectively, through a combination
of remote auditing and physical site visits
(where permissible under the Group’s
Covid-19 SOPs). Audit reports were provided
on a range of topics, including the Group’s
anti-bribery and corruption controls, waste
management processes, payroll controls,
sub-contractor appointment processes and
professional advisor engagement controls.
The Committee is satisfied that the Group
Internal Audit department remains effective
in its provision of independent assurance
to the Board, and continues to meet the
expectations placed on it through the Group
Internal Audit Charter.
Whistleblowing
The Group Internal Audit department
also reviews all whistleblowing reports,
conducting investigations where necessary,
and provides detailed reporting to the
Committee. Having reviewed the reports
provided on whistleblowing matters within
the year, the Committee is satisfied that
the Group’s approach to whistleblowing
is appropriate, and that investigations
have been conducted swiftly and with the
necessary competence and sensitivity.
There were no material issues or control
weaknesses raised in the whistleblowing
reports received within 2021 that were found
to require any major management actions.
In the spirit of continuous improvement,
the Committee has agreed for the Group
to enter a partnership with Protect,
the whistleblowing charity, for 2022.
This will allow the Group to draw on Protect’s
expertise in this area, and ensure the
Group’s whistleblowing provision remains in
line with accepted good practice.
5. Risk Management, Internal
Control and BEIS Consultation
The effective management of risk is central
to the achievement of the Group’s objectives
and the long-term sustainability of our
business. The Audit Committee monitors
the Group’s systems of risk management
and internal control and reports to the
Board on their effectiveness on an annual
basis. The key aspects of these systems
and related considerations within 2021 are
as follows:
Principal risk identification
and risk management
In line with the provisions of the UK
Corporate Governance Code, the Board
routinely assesses the principal and
emerging risks facing the Group (see pages
55 to 61). The assessment is supported by
a detailed survey of the Board and senior
management, facilitated by the Group
Internal Audit department. The conclusions
of this assessment, including the
identification of new risk areas and
movements in assessment of risk impacts
and probabilities, are reported to the Board
at its annual strategy day. The assessment
feeds into the Group’s overall strategy, which
is agreed by the Board and implemented
operationally by senior management within
the Group. Thereafter, the approach to
risk management and strategy undergo
a continuous and iterative process of
implementation, review and adaptation
at Board meetings, and in response to
the evolution of conditions in which the
Group operates.
The Strategic Risk Register, including the
principal risks faced by the Group, was
presented to the Main Board at its annual
2021 strategy meeting, and was formally
reviewed, and accepted by the Risk and
Audit Committees in December 2021.
The risk register in its entirety (including
operational and departmental risk registers)
is updated on an ongoing basis in response
to the work of the Group Internal Audit
department, and subject to a detailed annual
review in consultation with senior staff
from across the Group, facilitated by Group
Internal Audit. The registers are presented
to the Risk and Audit Committees for their
review and approval.
System of Internal Controls
The Group’s internal control environment
is based upon the widely recognised
‘three lines’ model. The first line is
the routine management oversight of
operations, performed within a framework
of standardised controls developed and
overseen by second line functions operating
at Group level. The Group Internal Audit
department operates as the third line
of defence, providing independent and
objective assurance on the effectiveness
of all aspects of risk and internal control
through the delivery of their risk-based
annual audit plan. The Risk Committee
Strategic report Governance Financial statements Other information
103