Agenda - Senedd Commission Audit and Risk Assurance Committee


Meeting Venue: Hybrid - Conference room 4B/MS Teams

Meeting date: 18 November 2024

Meeting time: 10.00-12:30
For further information contact:

Clerk: Kathryn Hughes

Committee Clerk

0300 200 6543

Kathryn.Hughes@senedd.wales


------

<AI1>

1       Introductions, apologies and declaration of interests

                                                                                                                          

 

Oral item

</AI1>

<AI2>

2       Actions and matters arising

                                                                                                     (Pages 1 - 2)

Attached Documents:
ARAC (24-05) Paper 1 - Summary of actions

</AI2>

<AI3>

3       Internal Audit Plan 2024-25 and review of progress of Internal Audit activity

                                                                                                   (Pages 3 - 10)

Attached Documents:
ARAC (24-05) Paper 2 - Internal Audit Plan 2024-25 and Progress Report

</AI3>

<AI4>

4       Internal Audit Report

                                                                                                 (Pages 11 - 21)

Attached Documents:
ARAC (24-05) Paper 3 - Internal Audit Report - Members' Expenses - 2024

</AI4>

<AI5>

5       Audit Wales Update (to include knowledge of wider public sector studies and reports and how they impact the Senedd Commission)

                                                                                                 (Pages 22 - 29)

Attached Documents:
ARAC (24-05) Paper 4 – Audit Wales Update Report - Nov 2024

</AI5>

<AI6>

6       Update on cyber security

                                                                                                 (Pages 30 - 68)

Attached Documents:
ARAC (24-05) Paper 5 -  Internal Audit Report - Cyber Security - 2024
ARAC (24-05) Paper 6 – Cyber Security Assurance Report
ARAC (24-05) Paper 7 – Supply Chain Security

</AI6>

<AI7>

7       Budget Update

                                                                                                                          

Oral item

</AI7>

<AI8>

8       Governance Update Report

                                                                                                 (Pages 69 - 73)

Attached Documents:
ARAC (24-05) Paper 8 – Governance Update Report - Nov 2024

</AI8>

<AI9>

9       Reflection on Key Performance Indicators (KPIs)

                                                                                                 (Pages 74 - 84)

Attached Documents:
ARAC (24-05) Paper 9 - KPIs

</AI9>

<AI10>

10    Reporting on data breaches

                                                                                                 (Pages 85 - 86)

Attached Documents:
ARAC (24-05) Paper 10 - Data Breaches

</AI10>

<AI11>

11    Corporate Risks

                                                                                               (Pages 87 - 119)

Attached Documents:
ARAC (24-05) Paper 11 - Corporate Risk
ARAC (24-05) Paper 11 - Corporate Risk - Annex A - Summary Corporate Risk Report
ARAC (24-05) Paper 11 - Corporate Risk - Annex B - Corporate Risks Plotted

</AI11>

<AI12>

12    Critical examination of one identified corporate risk or topical issue - EFM-R-192 - Failure of the Bay 2032 Project

                                                                                                                          

 

Oral item

</AI12>

<AI13>

13    Departure Summary and trend analysis on all departures from normal procurement procedures over the past two years

                                                                                             (Pages 120 - 126)

Attached Documents:
ARAC (24-05) Paper 12 - Departure summary and trend analysis
ARAC (24-05) Paper 12 – Annex 1 Departure approvals

</AI13>

<AI14>

14    Results of Committee's effectiveness survey

                                                                                             (Pages 127 - 141)

Attached Documents:
ARAC (24-05) Paper 13 - ARAC Effectiveness Survey 2024 - Report

</AI14>

<AI15>

15    HMT/other guidance for Audit and Risk Assurance Committees

                                                                                                         (Page 142)

Attached Documents:
ARAC (24-05) Paper 14 – HMT-handbook 2024

</AI15>

<AI16>

16    Review of Terms of Reference

                                                                                             (Pages 143 - 146)

Attached Documents:
ARAC (24-05) Paper 15 – Terms of Reference

</AI16>

<AI17>

17    Forward work programme

                                                                                             (Pages 147 - 152)

Attached Documents:
ARAC (24-05) Paper 16 – Forward Work Programme

</AI17>

<AI18>

18    People and Remuneration Project (HR/Payroll system)

                                                                                                                          

 

Oral item

</AI18>

<AI19>

19    Ways of Working

                                                                                                                          

 

Oral item

</AI19>

<AI20>

20    Seventh Senedd

                                                                                                                          

 

Oral item

</AI20>

<AI21>

21    Any Other Business

                                                                                                                          

 

</AI21>

<TRAILER_SECTION>

</TRAILER_SECTION>

<LAYOUT_SECTION>

1.          FIELD_TITLE

FIELD_FOOTNOTE                                                                                                                                      F_PR

FIELD_SUMMARY

FIELD_LABELLED_ATTACHMENTS

</LAYOUT_SECTION>

<TITLE_ONLY_LAYOUT_SECTION>

2.          FIELD_TITLE

FIELD_FOOTNOTE                                                                                                                                      F_PR

FIELD_LABELLED_ATTACHMENTS

</TITLE_ONLY_LAYOUT_SECTION>

<HEADING_LAYOUT_SECTION>

FIELD_TITLE

FIELD_FOOTNOTE

</HEADING_LAYOUT_SECTION>

<TITLED_COMMENT_LAYOUT_SECTION>

FIELD_TITLE

FIELD_FOOTNOTE

FIELD_SUMMARY

</TITLED_COMMENT_LAYOUT_SECTION>

 

<COMMENT_LAYOUT_SECTION>

FIELD_SUMMARY

</COMMENT_LAYOUT_SECTION>

<SUBNUMBER_LAYOUT_SECTION>

2.1.          FIELD_TITLE

FIELD_FOOTNOTE                                                                                                                                      F_PR

FIELD_SUMMARY

FIELD_LABELLED_ATTACHMENTS

</SUBNUMBER_LAYOUT_SECTION>

 

<TITLE_ONLY_SUBNUMBER_LAYOUT_SECTION>

2.2.          FIELD_TITLE

FIELD_FOOTNOTE                                                                                                                                      F_PR

FIELD_LABELLED_ATTACHMENTS

</TITLE_ONLY_SUBNUMBER_LAYOUT_SECTION>