Minutes of the VSS Audit and Risk Committee

Wednesday 15 January 2026 at 10.00am (Members only) and 10.30am (All attendees)

Online via MS Teams

ARC Members Present:

John Cahill – ARC Chair

Briege Lafferty – ARC Member

Brian Gilfedder – ARC Member

 

VSS Officers in Attendance:

Andrew Walker – Chief Executive Officer

Victoria Murray – Acting Head of Corporate Services

Adam Strong – Risk and Governance Manager

Brσnach Twomey – Administrative Officer (Minutes)

 

Others in Attendance:

Caroline Laird – NIAO (External Audit)

Marcin Klimasz – The Executive Office (TEO)

Elicia Erasmus – Cavanagh Kelly (Internal Audit)

 

Apologies:

Courtney Powell – Acting Finance Manager

 

1. Opening, Minutes, and Actions

·         The minutes of the previous meeting (15 October 2025) were approved.

·         Cyber Security Risk: Review ongoing; to be brought back to ARC once completed.

·         13.08.25 AP2 and 15.10.25 AP1 closed

·         No conflicts of interest were declared.

 

2. Accounting Officer / CEO Update – Key Issues

Victims Support Programme (VSP) Call:

·         Funding call significantly oversubscribed (£12.3m bids vs £7.9m budget).

Budget 2025/26:

MBIMLW Redress Preparation:

Historical Institutional Abuse (HIA):

Budget 2026/27 Outlook:

TPDPS:

 

3. Finance and Budget Position

·         December Monitoring Allocation received on 15 December 2025: £21,059k

·         Troubles/conflict: Spend broadly on track, underspend reallocated to INP.

·         MBMLW further easement of £128k projected.

·         HIA underspend improving; £60k projected.

·         TPDPS underspend risk remains, engagement with partners to maximise utilisation

·         PEACEPLUS underspend due to delayed recruitment, extension request to SEUPB planned.

4. Organisational Risk Register

·         Six strategic risks remain open, 3 amber and 3 red.

·         Key Highlights:

·         STG80 – Budget pressure remains at maximum score.

·         STG82 – MBMLW redress scaling requires additional staffing modelling.

·         STG84 – HIA 10‑year delivery risk linked to large budget gap under review by TEO.

·         Risks related to PEACEPLUS sustainability and governance oversight also tracked.

5. Assurance and Quarterly Reporting

·         Quarterly ALB Report and Assurance Statement noted.

6. Internal Audit

·         Internal Audit Report on Corporate Governance presented, containing no audit recommendations for action.

7. External Audit

·         2024-25 accounts certified on 28 November 2025

·         Final Report to those Charged with Governance presented by NIAO; two priority 2 audit recommendations accepted by management, one priority 3 recommendation (Board complement) partially accepted.

·         2025-26 Letter of Understanding noted by members.

 

8. Standing Agenda Items

·         ARC Self-Assessment and Action Plan: Skills Matrix to be issued to members, cyber training action moved to Board. ESG and sustainability policy action remains open.

·         No new audit recommendations in quarter, 2 of 4 P1/2 recommendations will close during next quarter.

·         Gifts and hospitality paper noted

·         Compliance paper noted, action to include indicative values against open fraud cases going forward.

·         Procurement update: 3 business cases approved in quarter, 2 contracts >£10k awarded for legal services and independent appeals panel members.

·         FD/DAO updates noted.

 

9. Any Other Business

·         Health and Wellbeing Risk Register included for rotational review; amber risk related to RTN strategic outcomes with three year review upcoming.

 

10. Date of Next Meeting – 20 April 2026