Risk management in a council cannot be reduced to maintaining a corporate risk register. It must help elected members and officers understand uncertainty, make informed choices, protect essential services and obtain reliable assurance that agreed responses are working.
That matters particularly in 2026. Councils are balancing financial pressure, service demand, transformation, cyber risk and, in parts of England, local government reorganisation. At the same time, current guidance places increasing emphasis on connecting risk with performance, finance, governance and decision-making.
This guide identifies five practical priorities for council leaders, risk teams, internal audit, service directors and audit committees. It distinguishes statutory requirements from guidance and sets out the evidence that effective oversight should produce.
Why Local Government Risk Management Needs More Than a Register
Councils manage public money and deliver services on which residents and communities depend. The Local Government Association’s risk management guide therefore treats risk management and effective assurance as important responsibilities for both political and managerial leaders.
The LGA’s central message is practical: risk management should be continuous, embedded and connected to normal management activity. A register can support that process, but it is not evidence of effective risk management by itself. The value comes from the decisions, challenge, escalation and action that the information enables.
HM Treasury’s Orange Book, updated on 29 July 2026, reinforces similar principles. It applies directly to central government departments and arm’s-length public bodies, while stating that its principles may also be useful across the wider UK public sector when adjusted for context. For councils, it can therefore be a useful reference point rather than a software certification or a substitute for the authority’s adopted governance framework.
Five Priorities at a Glance
| Priority | Practical objective | Evidence leaders should expect |
|---|---|---|
| Integrate risk with strategy, finance and performance | Use risk information when priorities, budgets and service decisions are considered | Connected reports, decision records, trends, indicators and escalation history |
| Make ownership and escalation work | Preserve service-level ownership while maintaining consistent council-wide oversight | Named owners, review dates, thresholds, approvals and clear escalation routes |
| Maintain continuous assurance evidence | Support governance conclusions with current evidence throughout the year | Controls, tests, audits, findings, actions, evidence and review histories |
| Control reorganisation and transformation risks | Manage dependencies and transition risks without losing sight of existing services | Dedicated programme registers, dependencies, mitigations, decisions and service-continuity evidence |
| Connect cyber resilience and critical services | Treat cyber risk as an enterprise and service-continuity issue | Critical-service mapping, cyber controls, incidents, recovery actions and assurance results |
Priority 1: Integrate Risk With Strategy, Finance and Performance
Risk reporting is most useful when it changes a decision, prompts intervention or gives leaders confidence that an objective remains achievable. It is less useful when it is produced separately from the information used to manage money, services and performance.
The LGA’s January 2026 guidance on performance, finance and risk reporting explains why these areas need to be considered together. Strong performance cannot be sustained indefinitely if the authority is financially unsustainable, while poorly managed risks can create higher costs, weaker performance and reputational damage. The guidance calls for a “golden thread” connecting information across service, directorate, corporate management and member levels.
What this means in practice
Connect strategic risks to the corporate objectives, services, programmes and savings proposals they could affect.
Consider risk appetite when choices are made about performance targets, budgets and resource allocation.
Use key risk and performance indicators to identify movement before a risk materialises fully.
Align reporting cycles where practical so that finance, performance and risk information can be reviewed together.
Record the assumptions supporting major decisions and revisit them when circumstances change.
Give audit committees and scrutiny functions enough context to challenge causes, controls and consequences rather than only reviewing a score.
Questions for members and senior officers
Does the report explain how risk could affect the council’s priorities and intended outcomes?
Can decision-makers see the financial and performance implications alongside the risk position?
Are worsening trends, threshold breaches and overdue actions visible?
Is the level of detail appropriate for the audience, with the ability to investigate further where necessary?
Is there a record of the challenge, decision and follow-up action?
Priority 2: Make Ownership and Escalation Work Across the Authority
Local government risk is distributed. Corporate risks may be overseen centrally, but the knowledge needed to manage them often sits in directorates, services, programmes, projects and partnerships. An effective framework needs to preserve that local knowledge without creating incompatible processes or isolated information.
The LGA emphasises clear accountability, practical processes and whole-organisation engagement. The updated Orange Book similarly places importance on clear roles, appropriate escalation, useful reporting and risk management at every organisational level.
A workable register structure
A council may need separate but connected registers for:
corporate or strategic risks
directorate and service risks
programmes, projects and transformation activity
partnerships and shared services
specialist areas such as cyber, information governance, health and safety or fraud.
Separate registers should not mean separate standards. The council can still apply agreed categories, scoring matrices, appetite thresholds, review requirements and escalation rules. The aim is to make ownership practical for services while retaining a consistent organisation-wide view.
Escalation should be based on more than a score
Likelihood and impact remain useful, but escalation may also be triggered by:
exposure moving outside the council’s stated appetite or tolerance
a control failure or loss of assurance
an incident, complaint or near miss
an overdue high-priority action
a material dependency on another service, supplier or partner
a significant change in financial, legal, political or operational circumstances
a risk affecting several services or objectives simultaneously.
Each trigger should lead to a defined response: who is notified, who reviews the position, what evidence is required and which body has authority to accept or change the response.
Priority 3: Maintain Continuous Assurance Evidence
Risk reporting describes exposure. Assurance addresses a different question: what evidence supports confidence that governance, controls and risk responses are working as intended?
For relevant authorities covered by the Accounts and Audit Regulations 2015, regulation 6 requires an annual review of the effectiveness of the system of internal control and approval of an Annual Governance Statement. The requirement is annual, but the evidence should not be assembled only at year end.
CIPFA’s governance, risk and assurance guidance describes the governance statement as drawing together evidence about governance, risk management and internal control. It also stresses that the statement should reflect live governance arrangements rather than being created solely for the annual reporting exercise.
Build evidence during normal activity
For each material risk or governance conclusion, councils should be able to locate relevant evidence such as:
the accountable owner and latest completed review
the controls intended to reduce the exposure
evidence that key controls have operated
control testing or management assurance results
internal audit work and conclusions
external inspection or assurance findings where relevant
incidents, complaints, breaches and performance exceptions
agreed actions, due dates, updates and closure evidence
decisions to accept exposure and the authority for those decisions
changes made in response to weaknesses or emerging information.
This does not mean attaching every document to every risk. It means maintaining a clear relationship between a governance conclusion and the evidence relied upon.
Distinguish action completion from assurance
An action being marked complete does not automatically demonstrate that the underlying risk has reduced. Closure should be supported by appropriate evidence, and the responsible reviewer should consider whether:
the action was completed as designed
the related control now operates effectively
the residual exposure has changed
further monitoring is required
independent validation is proportionate to the significance of the issue.
Priority 4: Control Reorganisation and Major Transformation Risks
Local government reorganisation creates an unusually concentrated set of strategic, operational and programme risks. Councils must plan for future structures while continuing to deliver existing statutory and essential services.
The LGA and MHCLG risk-mitigation aide-memoire identifies transition risks across assets, communications, data quality, finance, governance, workforce, technology, legal matters, policy implementation and service continuity. The LGA’s February 2026 checklist organises actions around the main stages leading to elections and vesting day, while its July 2026 support guide brings together developing resources across services, governance, finance, digital, cyber, procurement and transformation.
Practical controls for reorganisation risk
Create dedicated programme and transition registers rather than obscuring LGR exposure within ordinary service registers.
Link each risk to the relevant workstream, milestone, decision, dependency and accountable lead.
Record whether an action belongs to an existing council, a joint programme, a shadow authority or the future authority.
Track dependencies across people, assets, contracts, data, systems, finances and service providers.
Maintain a clear decision and evidence history so that knowledge survives organisational change.
Monitor the effect of transformation activity on business-as-usual services and control environments.
Use common categories and reporting definitions across participating authorities where possible.
Escalate cross-cutting risks that no individual workstream can manage alone.
Do not treat LGR as a temporary project bubble
Transition risks can crystallise through normal operations: delayed recruitment, unclear ownership, expiring contracts, inconsistent data, weakened controls or competing change programmes. The reorganisation register therefore needs connections to service, financial, workforce, cyber and continuity information rather than operating as a standalone project document.
Priority 5: Connect Cyber Resilience With Critical-Service Continuity
Cyber risk is not solely an IT issue. A cyber event can disrupt critical services, expose information, affect suppliers, create financial loss and undermine public confidence. Council oversight should therefore connect cyber controls with the services, systems, data and recovery requirements they protect.
The Cyber Assessment Framework for local government adapts the National Cyber Security Centre’s approach for the sector. The underlying NCSC Cyber Assessment Framework is designed to help organisations assess and improve cyber security and resilience for important functions.
Evidence leaders should expect
an agreed inventory of critical services and the systems, suppliers, data and people on which they depend
clear cyber-risk ownership at service and corporate levels
controls mapped to the risks and critical functions they protect
assessment findings and improvement actions with accountable owners
incidents and near misses linked back to relevant risks and controls
recovery objectives, continuity plans and completed exercise evidence
a process for escalating material weaknesses, overdue actions and emerging threats
assurance that lessons from incidents and exercises have changed controls or plans where necessary.
Cyber assurance should be proportionate and technically informed, but the final governance question is accessible: can the council demonstrate that it understands the threat to essential services, has taken appropriate action and can recover when disruption occurs?
What Effective Council Risk Management Should Produce
By the end of 2026, an effective council risk framework should enable leaders to answer the following questions without commissioning a manual data-gathering exercise:
What are the most significant threats and opportunities affecting council priorities and essential services?
Which exposures sit outside agreed appetite or tolerance?
Who owns each risk, control and improvement action?
Which risks are worsening, overdue for review or affected by significant change?
What evidence shows that key controls and mitigations are operating?
Which incidents, complaints, audit findings or performance exceptions have changed the risk position?
Where do several services, projects or partners depend on the same control, supplier, system or resource?
What requires member, senior management, audit committee or scrutiny attention?
What has been accepted, by whom and on what evidence?
Can the council trace the information supporting its governance and assurance conclusions?
If these questions require several teams to reconcile different spreadsheets, email chains and documents, the issue is not simply administrative. It limits the timeliness and reliability of governance information.
A Practical Evidence Map
| Governance question | Evidence to connect | Typical oversight route |
| Are priority risks understood? | Objectives, risks, scores, appetite and trends | Cabinet, senior leadership and service management |
| Are responses working? | Controls, tests, indicators, incidents and management assurance | Risk owners, directorates and audit committee |
| Are weaknesses being corrected? | Findings, actions, due dates, updates and closure evidence | Management, internal audit and audit committee |
| Can services continue through disruption? | Critical-service mapping, dependencies, continuity plans and exercises | Service leadership and resilience governance |
| Is transformation controlled? | Programme risks, milestones, decisions, dependencies and benefits | Programme board, senior leadership and members |
| Is the governance conclusion supportable? | Assurance map, internal audit opinion, reviews, exceptions and action history | Those preparing and approving the AGS |
Where Technology Helps and Where It Does Not
Technology can make risk and assurance information easier to maintain, connect and report. It can provide separate service registers, consistent scoring, automated reminders, permissions, dashboards and a reliable history of changes. It can also connect risks to controls, audits, actions, incidents, objectives and continuity information.
Technology cannot decide the council’s risk appetite, replace accountable ownership or determine whether an assurance conclusion is justified. Those remain governance and professional judgements. Software should support the council’s adopted framework rather than force the authority into a vendor’s terminology or method.
When evaluating a system, councils should therefore ask whether it can:
reflect existing terminology, categories, scoring and governance structures
support separate but connected registers
define permissions appropriate to different services and roles
automate reviews, reminders, approvals and escalation
connect risks with controls, tests, evidence, audits, actions and incidents
produce different levels of reporting without rebuilding the underlying information
retain an audit trail of reviews, decisions and changes
expand in stages without requiring a new platform.
How Symbiant GRC Supports Local Government Risk and Assurance
Symbiant provides an affordable, configurable GRC and audit management platform for councils. Authorities can start with the modules they need and add further connected capabilities as requirements develop, without introducing separate systems for each process, helping them maintain a Single SOurce of Truth (SSOT).
The platform can be configured around a council’s existing terminology, risk methodology, scoring matrices, ownership model and reporting structure. This includes approaches informed by the Orange Book where the authority has chosen to use those principles; Symbiant does not impose a single governance framework.
Councils can use Symbiant to:
maintain corporate, directorate, service, programme and project risk registers
connect risks to controls, policies, tests and evidence
link internal audit findings and actions to the risks and controls they affect
automate reviews, reminders, approvals and escalation
maintain decision, change and closure histories
produce dashboards and reports for officers, leadership teams and members
connect incidents, complaints, objectives, indicators and continuity information
use optional AI-assisted capabilities subject to human review and approval.
Additional sources and further reading
Local Government Association: Must know guide — Risk management, 24 January 2025.
Local Government Association: Performance, finance and risk reporting — Guidance and top tips, 26 January 2026.
HM Treasury: The Orange Book — Management of Risk, Principles and Concepts, updated 29 July 2026.
LGA and MHCLG: LGR — Examples and options for risk mitigation by councils, 17 November 2025.
Local Government Association: LGR Checklist, 12 February 2026.
Local Government Association: Local government reorganisation support, 16 July 2026.
Government Security: Cyber Assessment Framework for local government.
Bring Council Risk and Assurance into One Connected System
Symbiant GRC helps local authorities replace fragmented spreadsheets and disconnected processes with a configurable platform for risk registers, controls, internal audit, actions, incidents, compliance and business continuity.
Configure the platform around your council’s terminology, scoring methods and governance structure—including approaches informed by the Orange Book—while maintaining clear ownership, consistent evidence and council-wide oversight.
Symbiant is modular and affordable, so you can begin with the capabilities you need and expand when required. Configuration, training and ongoing support are included.
See how Symbiant could support your council’s risk and assurance framework.

Frequently Asked Questions
What is local government risk management?
Does every council need a corporate risk register?
Does the Orange Book apply to local authorities?
How does risk management support the Annual Governance Statement?
Risk management provides part of the evidence used to evaluate governance and internal control. A council should be able to connect material risks with controls, assurance work, audit conclusions, weaknesses, actions and review histories so that statements about effectiveness are supported by current evidence.
How often should a council review its risks?
There is no single frequency suitable for every risk. The council should define minimum review cycles and increase the frequency when exposure is high, conditions are changing, controls have failed or decisions are required. Material events should trigger review rather than waiting for the next scheduled date.
Can separate council services use different risk registers?
Yes. Separate registers can reflect service, project or specialist needs while using consistent council-wide rules for categories, scoring, appetite, escalation and reporting. The important requirement is that information can be aggregated and escalated without manual reconciliation.

