Annual governance statement
Scope of responsibility
As Accountable Officer, I have responsibility for maintaining a sound system of internal control that supports the achievement of the NHS Trust’s policies, aims and objectives, whilst safeguarding the public funds and departmental assets for which I am personally responsible, in accordance with the responsibilities assigned to me. I am also responsible for ensuring that the NHS Trust is administered prudently and economically and that resources are applied efficiently and effectively. I also acknowledge my responsibilities as set out in the NHS Trust Accountable Officer Memorandum.
The purpose of the system of internal control
The system of internal control is designed to manage risk to a reasonable level rather than to eliminate all risk of failure to achieve policies, aims and objectives; it can therefore only provide reasonable and not absolute assurance of effectiveness. The system of internal control is based on an ongoing process designed to identify and prioritise the risks to the achievement of our policies, aims and objectives , to evaluate the likelihood of those risks being realised and the impact should they be realised, and to manage them efficiently, effectively and economically. The system of internal control has been in place in the Trust for the year ended 31 March 2026 and up to the date of approval of the Annual Report and accounts.
Capacity to handle risk
The Trust has a range of ways in which risks are identified which include:
• Incident and accident reporting, including near misses
• Outcomes of complaints, investigations and deep dive reviews
• Performance systems and dashboards
• Routine internal and external audits, such as annual safety audits
• External reviews, such as those by the Care Quality Commission
• Benchmarking, including through the NHS Benchmarking Network
• Utilisation of intelligence from system working with our partners in the South West London Integrated Care System and the South London Community and Mental Health Partnership, as well as input from Health Overview and Scrutiny Committees and local Healthwatch organisations
• Through the work of committees and groups
• Quality, equality and privacy impact assessments of change programmes
• Staff, patient, carer and stakeholder feedback.
The Trust recognises the importance of making available appropriate resources and infrastructure to successfully manage risk, so that it can effectively deliver its plans and on-going risk management activities.
These resources include:
· People - Making sure our staff have the skills, capability, knowledge and support they need to deliver their risk management responsibilities and have the capacity to do so. Training and coaching will be provided to those who need it. Assessing and providing development needs of staff is integral to our risk management annual plan. The Trust promotes an open learning culture where staff have the space and opportunities to develop.
· Tools – Making sure that people have the tools they need to deliver their risk management responsibilities. This includes access to guidance, risk forms, risk register software, incident reporting software, analytical tools, decision support tools (e.g., a risk matrix), etc. Our plan will include on-going development/improvement of supporting tools and information.
· Co-operation – Commitment to support each other in managing our risks. To be successful we all need to work together. Something could potentially ‘go wrong’ in one part of our organisation or health system; however, the causal factors may originate in another part of our organisation or be external. Our risk management processes will include arrangements to promote work across disciplines and service lines and the means to handle mitigation and management of risk across the organisation and externally where required.
All identified risks are required to be assessed and recorded in the Trust’s risk register system and escalated to executive (high risk) risk registers or the Board Assurance Framework (BAF) as appropriate. Ward/Departmental managers (and above) are authorised to add risks to the risk register system (Ulysses) and must ensure that the risk is properly and fully completed, recognising that once the risk is submitted, the system will send automatic notifications to a number of staff members. These notifications will invite the receiver to view and/or review the risks and will typically be sent to the risk owners (depending on risks levels) and those who have been assigned actions in the system.
At each stage risks and the risk scoring are formally reviewed through the applicable groups and committees, in line with the Board’s agreed Risk Appetite. This provides levels of risk moderation and challenge to help ensure risks are appropriately articulated, assessed, managed and are escalated in line with defined risks levels and escalation processes.
We ensure that adequate training is provided to help equip our staff to understand and apply our systems and processes in the successful management of risk. The risk management strategy is being delivered by linking the Trust’s strategic objectives to local objectives and by delivering a focused training programme.
The current risks on the BAF at the end of 2025/26 were:
• Failure to deliver a great place to work to enable the delivery of great care for our patients and service users.
• A failure to achieve financial targets
• A failure to deliver transformed models of care, working practices and environments within available resources
• Failure to consistently deliver high-quality, safe, and equitable care, alongside a positive experience for patients, families, and carers
• A failure to meet the increasing demand on services relating to adult care pathways while maintaining safe, timely and high-quality care
Work has been done this year to refresh and streamline the BAF alongside updating the assurance map.
The risk and control framework
The Trust adopted an updated Risk Management Framework in 2021. The Framework combines the risk strategy, policy and procedures into one document. This avoids unnecessary duplication and provides a single document detailing the Trust’s aims, approach and arrangements for managing risk throughout the organisation. The Framework is reviewed annually via (RSM) Internal Audit and overseen by the Audit Committee.
The Risk Management Framework sets a clear organisational policy for the management of risk and a strategy to deliver effective risk management through the organisation’s architecture, systems and processes to ensure objectives are met, and includes full reference to the risk appetite agreed by the Board.
The Framework covers the strategic elements for risk and extends to describe the key processes and procedures staff at specific levels are required to follow. These cover risk identification through to assessment, mitigation, actions and assurances. The framework clearly establishes the responsibilities for various committees and individuals.
The scope of the framework is, by its nature, wide, covering areas such as operational management, performance and finance. The Trust also has a clinical risk policy which covers clinical risk assessment and management. The Board has adopted the following risk policy statement:
The Board is committed to ensuring that:
• Effective frameworks, structures and accountabilities are in place for the effective management of risk at all levels throughout the Trust, achieving a clear line of sight of risks from board to floor.
• Risk is considered, co-ordinated and managed in an integrated way and not in silos.
• Sufficient resources, people, training and other arrangements are in place to successfully implement the risk management policy, though service line management and corporate structures.
• A culture exists where staff feel empowered to report risk and have the systems and tools to formally assess and escalate risk where necessary.
• Risks are managed in a positive, sensible and proportionate way to maximise opportunities to achieve objectives and the delivery of services, although recognising the Trust has a low-risk appetite to risks in regard to the safety and wellbeing of patients, staff and visitors.
• When risks are realised, there are resilience plans and arrangements to respond and recover, particularly in regard to patient care.
• The Trust focuses upon experience and learning to eliminate or reduce all risks to an acceptable level.
• There is a clear risk management system is in place to enable staff to identify, assess and escalate risks to the appropriate level of management with the necessary authority to appropriately respond to the risk
The Trust has the following risk management objectives:
• Ensure effective structures are in place to enable and provide the leadership support needed for staff to undertake their risk management responsibilities, and to build their risk management capabilities.
• Minimise the potential for harm to patients, staff and visitors to as low as is reasonably practicable, thereby providing a safe environment in which patients can be cared for, staff can work, and the public can visit.
• Promote an open and just culture that makes risk visible, adapts to protect everything of value, providing organisational resilience.
• Raise abilities of all staff through ongoing training and awareness that is appropriate to specific roles and their responsibilities, ensuring that the benefits of risk management are championed, and systems and processes are understood.
• Systematic processes are used to learn lessons from our successes, best practice, errors and failures.
• Support innovation by enabling initiatives where the management of risk is part of success and not an obstacle.
• Risks are identified and managed protecting the reputation of the Trust and items of value.
• Risks are regularly reviewed and updated by accountable managers, supported by robust action plans.
• Assurance on the effectiveness of controls / mitigations is provided with gaps in controls identified and proactively managed.
• Maintain high levels of organisational compliance, particularly in relation to standards and requirements associated with safety, assurance and legislation.
• Our approach to risk and opportunity taking and how that affects our decisions is communicated with internal and external stakeholders.
• Maximise opportunities by adapting to changing risk factors and learning experience when things go wrong, to continually improve our processes and the way we undertake our activities.
• Measurement to monitor risk performance and provide necessary assurances.