Audit, risk, organisational security and resilience

 The Council will adhere to Education Scotland’s risk management procedures and ensure that any major risk to the Council, Education Scotland and/or Scottish Government is identified and reported through Education Scotland’s Risk Management processes and procedures.  The Council will ensure that both a risk register and a business continuity plan, covering all aspects of the Council’s operations are maintained.  These  may be tabled at Audit and Risk Committee as required.  

As part of the risk management arrangements the Director of the Council will ensure that the Council has a comprehensive understanding of the key risks, threats and hazards the Council may face, including those in the personnel, physical and cyber domains, and take action to ensure appropriate organisational resilience to those risks/threats/hazards. The Council will have particular regard to the following key sources of information to help guide its approach:

Education Scotland  has an independent Audit and Risk Committee with membership and operating procedures determined by the appropriate guidance in the Scottish Public Finance Manual and the Audit Committee Handbook.  The remit of the Audit and Risk Committee includes gathering assurance about Education Scotland and the Council’s efficient and effective use of expenditure and the associated responsibilities for risk, control, governance and assurance. The Chief Executive, as Accountable Officer, also reserves the right to have appropriate representatives (e.g. Internal Audit) undertake any work required to provide independent assurance about the Council’s management and control, if she considers it necessary.  While the Chair cannot directly instruct Internal Audit, the Chair will raise with the Chief Executive any issues that require consideration for inclusion in the Internal Audit annual Audit Plan.