North East Mayoral Strategic Authority Chooses Symbiant GRC Software

September 9, 2026

North East Mayoral Strategic Authority chooses Symbiant to support connected governance, risk, assurance and accountability across its regional responsibilities.

The North East Mayoral Strategic Authority has chosen Symbiant GRC software to support governance, risk and assurance across an organisation responsible for major regional funding, investment and delivery programmes.

The decision places Symbiant’s award-winning GRC Software at the heart of risk and accountability in one of England’s largest devolved regions. The Authority covers the local authority areas of County Durham, Gateshead, Newcastle, North Tyneside, Northumberland, South Tyneside and Sunderland. Together, those areas are home to around two million people and include major cities, industrial centres, coastal communities and some of England’s largest rural geographies.

That scale matters. Devolution gives regional leaders greater control over funding and decisions that were previously held by central government. It also creates a demanding governance environment: strategic objectives must be linked to investment decisions, risks must be understood across programmes and partnerships, and leaders must be able to show how public money is being controlled and what outcomes it is producing.

Symbiant provides a configurable platform through which risks, controls, actions, assurance activity and supporting evidence can be connected. This helps the Authority maintain a clear view of accountability as its responsibilities, funding arrangements and delivery portfolio continue to develop.

Powerful enough for complex regional governance, priced for the realities of public-sector budgets.

Symbiant gives the Authority the flexibility and connected capabilities expected from an enterprise GRC platform without the excessive cost, lengthy implementation or restrictive contracts often associated with traditional systems. Its modular structure means organisations can invest in the capabilities they need while retaining the flexibility to expand as their requirements develop.

Discover flexible, integrated software solutions designed to help organisations identify risks, strengthen controls, streamline audits, monitor compliance, and improve decision-making. Whether you're focused on risk management, audit assurance, or regulatory compliance, Symbiant provides the tools needed to create a connected, resilient and well-governed organisation.

What is the North East Mayoral Strategic Authority

The organisation was formed as the North East Combined Authority on 7 May 2024 following the North East devolution deal. On 18 May 2026, it became the North East Mayoral Strategic Authority, reflecting the wider role that strategic authorities now play as more funding and policy decisions move from central government to England’s regions.

The Authority is jointly run by the North East Mayor and the leaders of the seven constituent councils. It does not replace those councils or direct their ordinary local services. Each council remains a separate local authority with its own elected members, statutory responsibilities, governance arrangements and risk profile. The Authority provides the regional structure through which the Mayor and council leaders make decisions on devolved priorities and work collectively on matters that cross council boundaries.

Its responsibilities include transport, skills, business support, housing, regeneration, economic growth and environmental priorities. The original devolution deal included a £1.4 billion investment fund over 30 years, control of the Adult Education Budget and more than £500 million for transport investment. These long-term programmes depend on consistent oversight of delivery, finance, partners, dependencies and emerging risk.

The seven constituent council areas

The seven councils represented within the Authority vary substantially in geography, population and service pressures. The figures below are rounded Census 2021 populations and are included to show the scale and diversity of the region rather than to suggest that the Authority manages each council’s internal operations.

Constituent area

Population

Regional context

County Durham

About 522,100

A large unitary area covering Durham City, former mining communities, market towns and extensive rural areas.

Gateshead

About 196,200

An urban authority on the south bank of the Tyne, connected closely to the wider Tyneside economy.

Newcastle upon Tyne

About 300,100

The region’s largest city authority and a centre for employment, higher education, health, culture and transport.

North Tyneside

About 209,000

A mixed coastal and urban borough including North Shields, Wallsend, Whitley Bay and surrounding communities.

Northumberland

About 320,600

England’s northernmost unitary authority and one of its largest by area, with dispersed rural and coastal communities.

South Tyneside

About 147,800

A metropolitan borough including South Shields, Jarrow and Hebburn, with major coastal and industrial assets.

Sunderland

About 274,200

A city authority with a substantial advanced manufacturing base, urban communities and coastal areas.


Across these areas, regional programmes can involve different delivery bodies, funding conditions, local priorities and risk owners. A transport investment, skills programme or regeneration project may depend on several partners and produce evidence in several systems. Without a connected approach, senior leaders can receive separate reports that use different definitions, assessment methods and reporting dates.

A changing governance and regulatory environment

The Authority operates within the statutory framework for English local government and combined authorities. Its Constitution, Financial Regulations and Assurance Framework set out how decisions are taken and controlled. Several recent reforms and established public-sector requirements make the quality of the underlying evidence increasingly important.

Deeper devolution and integrated accountability

The English Devolution White Paper set out the government’s intention to widen and deepen devolution, increase mayoral powers and connect devolved funding more closely to outcomes and public accountability. For a mayoral strategic authority, this increases the need to demonstrate a clear line between regional missions, approved investment, delivery performance, risk and assurance. Policy reform is still distinct from enacted legal duties, but it sets the direction in which the Authority’s governance obligations are developing.

The Procurement Act 2023

The Procurement Act 2023 and Procurement Regulations 2024 came into force on 24 February 2025. The regime places greater emphasis on transparency throughout the commercial lifecycle and requires contracting authorities to manage notices, decisions, supplier performance, conflicts and contract changes within the new framework. The Authority already publishes quarterly expenditure data and an annual response to the Act. Connected records make it easier to link procurement risks and obligations to contracts, controls, responsible officers, reviews and evidence.

Public finance audit and annual governance

The Local Audit and Accountability Act 2014 and the Accounts and Audit Regulations 2015 form part of the core framework for local public audit and financial reporting. Relevant authorities must maintain effective systems of internal control, review those arrangements and publish an Annual Governance Statement alongside their accounts. The Authority also works through its audit and standards arrangements and publishes audit information. A governance platform can support this process by retaining the evidence behind assessments, findings, management actions and closure decisions.

Best Value and public accountability

The Local Government Act 1999 places a Best Value duty on relevant authorities to secure continuous improvement, taking account of economy, efficiency and effectiveness. For large investment and delivery portfolios, demonstrating Best Value depends on more than recording that a project was approved. Decision-makers need current information on delivery risk, financial exposure, benefits, control effectiveness and unresolved actions.

The Orange Book and public sector risk practice

HM Treasury’s Orange Book provides principles and concepts for managing risk in government organisations. It is guidance rather than a statute that automatically applies to every local authority in the same way. It is nevertheless an influential reference point for mature public-sector risk management, including governance, integration with decision-making, structured risk processes and continual improvement. The Orange Book collection was updated again in July 2026, reinforcing the need to work from current guidance rather than relying on superseded supporting documents.

Information governance transparency and equality

The Authority must also operate within wider duties such as the UK General Data Protection Regulation and Data Protection Act 2018, the Freedom of Information Act 2000, the Equality Act 2010 and its Public Sector Equality Duty, and statutory transparency and access-to-information requirements. These duties affect how information is collected, retained, shared, assessed and disclosed. They also create operational and reputational risks that may cut across programmes rather than sit within one department.

Why connected GRC matters at regional scale

Traditional risk registers can record individual risks, but regional governance requires the relationships around each risk to remain visible. Leaders may need to understand which objective is threatened, which programme or funding stream is affected, which controls are relied upon, who owns the response, what assurance has been completed and whether remedial action has been verified.

Symbiant can bring these elements into one configurable environment. The Authority can shape registers, workflows, permissions and reporting around its governance model rather than force complex public-sector processes into a fixed structure. Information can be connected across strategic risk, operational delivery, controls, incidents, audit findings and actions, providing a traceable evidence chain for management, committees and assurance teams.

CapabilityPractical value
Consistent risk informationCommon assessment criteria and workflows reduce variation between teams and programmes.
Clear accountabilityNamed owners, review dates, actions and escalation routes show who is responsible and what must happen next.
Connected assuranceControls, tests, findings, evidence and remediation can be linked to the risks and objectives they support.
Configurable reportingDifferent committees and leaders can receive information suited to their remit without rebuilding the underlying evidence.
Defensible decisionsA retained history of assessments, approvals, changes and supporting material helps explain how conclusions were reached.
Scalable accessA modular platform can support wider participation while maintaining role-based access and appropriate oversight.

What the decision says about Symbiant

Selection by the North East Mayoral Strategic Authority is significant because the organisation’s remit combines public accountability with long-term investment and delivery across a region of around two million people. Its governance needs are shaped by devolution, partnership working, regulatory duties and close scrutiny of public funds.

Symbiant is designed for precisely this kind of complexity. Its modular and configurable structure allows public bodies to create a proportionate system around their own terminology, responsibilities and reporting lines. Risks can be connected to the controls, incidents, audits, actions and evidence that demonstrate whether they are genuinely being managed.

Importantly, this depth of capability is priced to reflect the realities of public-sector budgets. Organisations can access powerful, enterprise-level GRC functionality without the excessive costs and restrictive contracts often associated with traditional platforms.

For Symbiant, the decision strengthens a growing record of supporting UK public-sector organisations and local authorities. For the North East Mayoral Strategic Authority, it provides a powerful yet proportionate foundation for maintaining visibility and accountability as the scale of devolved decision-making grows.

 

Sources

North East Mayoral Strategic Authority About

North East Mayoral Strategic Authority How We Work

North East Mayoral Strategic Authority Governance

North East Mayoral Strategic Authority Finance

UK Government North East Devolution Deal

UK Government English Devolution White Paper

UK Government Transforming Public Procurement

HM Treasury Orange Book

Office for National Statistics Population Estimates

About Symbiant GRC Software

Symbiant is a UK-based provider of configurable governance, risk, compliance and audit management software. Its modular platform helps organisations connect risks, controls, policies, incidents, audit work, findings, actions and assurance evidence within a single source of truth. Organisations can begin with the capabilities they need and adapt the system as their requirements develop, supported by UK-based implementation, training and customer support.

 

See how Symbiant supports public-sector governance and risk management.

Discover Symbiant's AI-Assisted Governance, Risk Management, Compliance (GRC) and Audit Management Software. Affordable, agile, fully customisable.