Present
|
Present: |
|
|
Doris Jamieson (DJ) |
SHR Committee Chair |
|
Lindsay Patterson (LP) |
SHR Committee member |
|
Abhishek Agarwal (AA) |
SHR Committee member |
|
Ewan Fraser (EF) |
SHR Committee member |
|
In attendance: |
|
|
Paul Lindsay (PL) |
Senior Audit Manager - Audit Scotland. |
|
Iain Burns (IB) |
Senior Internal Audit Manager, Scottish Government |
|
Paul Cooper (PC) |
Internal Audit Manager, Scottish Government |
|
Michael Cameron (MC) |
SHR Chief Executive (items 1- 9) |
|
Iain Muirhead (IM) |
SHR Director of Digital and Business Support (items 1-9) |
|
Roisin Harris (RH) |
SHR Corporate Governance Manager (items 1-9) |
|
Clare Nicolson (CN) |
SHR Business Manager (items 1-9) |
|
Nicola Kane (NK) |
SHR Business Support Officer (items 1-9) |
|
Alex Hall (AH) |
Staff observer - SHR Record, Information and People Officer |
Chair’s welcome, apologies, and declarations
The Chair welcomed everyone present, especially staff observer AH and PL who is the new Senior Audit Manager for Audit Scotland working with SHR.
ARAC noted apologies from Louise Carmichael, Scottish Government. It also noted that SHR Chair Garry Coutts plans to attend to observe a future ARAC meeting.
There were no declarations of interest.
Minutes of the previous meeting, matters arising & audit log
ARAC considered and approved the minutes from the last meeting on 10 March 2026.
ARAC considered and noted the matters arising report and the audit recommendation status log. DJ reported that the ARAC self assessment was due to be discussed at the meeting, but given the volume of other papers it has been deferred until September 2026. She explained that she, EF and CN have a meeting planned to discuss this.
Internal Audit Progress Report
PC presented an update on internal audit work.
PC reported on the follow up review of serious concerns, confirming that the two recommendations are now fully completed and implemented.
PC also reported on the Business Continuity and Cyber Resilience review. He reported a substantial assurance opinion with three low level recommendations. PC explained that the approach to expand the cyber response plan to include business continuity works for SHR. He confirmed that there is good engagement and awareness with suppliers including Scottish Government. PC reported on the three low level recommendations, confirming that a transparent remit for its Business Intelligence System Governance Board has been approved. He explained a recommendation for a forward-looking review process and schedule for all documents associated with the Incidence Response Plan (IRP) to ensure they remain up-to date. ARAC noted this is expected to be completed by quarter three. Finally PC explained that SHR should strengthen the approach to evidencing consideration of wider risks posed to the organisation which may lead to the need to instigate its IRP. PC highlighted that as the plan is not due for review until 2028/29, Internal Audit will take a view on any work towards this at the end of quarter four 2026/27, while recognising 2028/29 is the end date.
ARAC discussed recommendations from the serious concerns review, noting guidance is in place now so these are fully completed and implemented.
ARAC also discussed the review date for the IRP. It noted that the risk management review is planned for this year and that will feed into the review preparation. Internal Audit confirmed that it is content the timescales are reasonable and it will follow up on the other recommendations prior to this. IM reported that the management plan is reviewed quarterly
and the 2028/29 IRP review is focussed on the non-cyber scenarios, such as pandemics that could potentially cause disruptions. The management team last reviewed non-cyber scenarios in late 2025.
ARAC also discussed out of hours monitoring of IT systems. It discussed the arrangements for the Scottish Government services SHR uses and whether other bodies have supplementary support arrangements. It noted SHR’s arrangements with its Business Intelligence and web hosting and support suppliers. ARAC noted the arrangements and agreed it would be useful to understand the approach others are taking and asked IM to explore further and update the Board, noting that IM is also looking at cyber metrics for inclusion in future Board performance reporting.
ARAC also discussed oversight of cyber related metrics and asked IB to advise it on any practice examples. ARAC noted a recent related Board discussion and that IM is considering relevant metrics for inclusion in the Corporate Performance report to SHR Board in August.
IB presented the progress report for Internal Audit. He highlighted:
- that planning work with SHR has started for 2026/27;
- positive results from the Internal Audit external quality assessment and related follow up
work; and - Internal Audit’s IT system changes.
IB confirmed that as Internal Audit is providing a substantial assurance annual assurance opinion for 2025/26 to SHR’s Accountable Officer, and this will be reflected in the governance statement and accounts
ARAC thanked IB and PC for their assurance work and welcomed the opinion provided.
Action:
- PC/IB to advise on other organisations’ out of hours monitoring for Scots and share any information available on cyber performance board oversight good practice.
- IM to update the Board on out of hours cyber cover, alongside the work on cyber metrics for future Board performance reporting.
External Audit
PL presented External Audit’s Annual Audit Report for 2025/26. He explained that the annual report and accounts are considered free from misstatement and there were no significant matters to report. PL also highlighted the wider scope aspects of the audit. He reported that there are no uncorrected misstatements and no new recommendations. There has been good progress against prior recommendations, and no open recommendations. PL thanked the SHR team who assisted in the audit.
ARAC thanked PL and welcomed the audit outcome, noting this provided a good basis for SHR going forward.
ARAC discussed certificates of assurance from Scottish Government around shared services provided to SHR. It noted some follow up work around those concerning corporate services. MC confirmed he raised this issue at the Scottish Public Bodies Delivery Group and that SHR will also discuss it with colleagues in the Housing Directorate to clarify what action Scottish Government is taking to address concerns. MC confirmed that the concerns related to ability to deliver services that SHR and other public bodies draw on and pay for.
IB confirmed that Internal Audit are aware of the concerns and discussions within Scottish Government are ongoing. He updated ARAC on the Scottish Government’s assurance opinion that he will keep SHR updated. IM confirmed that this development is reflected in SHR’s risk register.
ARAC thanked PL and noted the Annual Audit report.
Actions: MC and IB to keep ARAC updated on concerns around certificates of assurance from Scottish Government.
SHR Annual Report and Accounts
CN presented SHR’s Annual Report and Accounts for 2025/26 and thanked members for their input. She explained the final pieces of work ongoing to conclude the report and accounts prior to SHR Board considering it in August are:
- receipt of final pensions data;
- engagement with Scottish Government on the Certificate of assurance; and
- a final checks for typos and in-house publication design.
ARAC thanked all involved in production and the Audit Teams. It agreed subject to completion of the final pieces of work to recommend the Annual Report and Accounts to the Board for approval and signing by MC as Accountable Officer in August 2026.
Annual report on Fraud, Security and Whistleblowing
CN presented the annual report on fraud and security breaches. She highlighted work to update policies. CN reported that there had been no fraud or whistleblowing cases and there had been two minor data breaches concerning emails to incorrect addresses. She also highlighted the appended compliance report from SHR’s Data Protection Officer. ARAC
considered the report and discussed:
- mitigation for the data breaches, noting regulator communications to staff and confirmation via line managers that auto complete for emails is disabled;
- security when using Board member email addresses, noting that Egress is not available to SHR and like Scottish Government, it uses Objective Connect to share sensitive material externally.
ARAC noted and thanked CN for the report, welcoming the mitigation actions.
ARAC’s report to SHR Board
CN presented a summary of the work of ARAC for 2025/26 explaining that DJ would present this to SHR Board in August to provide it and the Accountable Officer assurance.
ARAC approved the statement of assurance and asked DJ to present it to SHR Board and Accountable Officer in August.
Action: DJ to present the ARAC statement of Assurance to SHR Board and Accountable Officer.
Risk Report
IM presented SHR’s risk register to ARAC. He explained some minor adjustments to the report format following discussions with DJ and that a more comprehensive review is planned for the second half of the financial year. IM highlighted score changes in relation to shared shares, explaining that Management Team had previously decreased the score, but then increased it following receipt of the certificates of assurance for Scottish Government shared services.
ARAC considered the risk register. It discussed Public Service Reform including:
- scope for internal audit focus;
- how the risk register scores reflect SHR funding settlement and the anticipated spending
review; - SHR contribution, noting it had reduced in size, shared services, shared an office with Social Security Scotland, taken a smaller footprint and used a cloud-based business intelligence model to achieve savings. Scope to achieve more is limited, which is reflected in the likelihood risk score;
- the Scottish Government’s agenda to reduce the number of public bodies;
- work to review SHR’s operating model to explore the scope to be as effective as possible with less resource;
- the high level of risk, noting that the management of risk sits with SHR, but that it relies on Scottish Government for funding and that it and the Scottish Parliament are aware of SHR’s budget situation; and
- the importance of SHR’s stakeholders understanding the consequences of the outcome of the operating model review.
ARAC noted that the organisation-wide operating model review work with SHR Board is SHR’s strategic response to the risk around resourcing. ARAC discussed how SHR can demonstrate externally the actions it is taking, including consideration of the impact on tenants and other stakeholders. MC confirmed that much of that is set out in SHR’s last funding business case to the Scottish Government and in Board reports. ARAC welcomed some aspects of this would be included in subsequent risk reports.
ARAC noted the risk report.
Action: MC to include additional information summarising the work that SHR has done around resources to append to subsequent risk reports.
Agenda Planner & AOB
ARAC considered and noted the agenda planner.
AH welcomed the opportunity to observe ARAC and provided feedback on her experience.
IM reported that Audit Scotland is consulting on Audit Practice and SHR has been invited to participate in a survey on fees and funding. IM reported he will email ARAC in follow up.
Action: IM to email ARAC with more information on Audit Scotland’s survey on fees
and funding.
There were no other matters raised under AOB.
Private session
ARAC held a private meeting with the auditors.