Parish Council Risk Assessment: What AGAR Auditors Expect to See
16 July 2026
Risk assessment sits inside AGAR Assertion 5 — the council's governance statement confirms that it "carried out an assessment of the risks facing this smaller authority and took appropriate steps to manage those risks, including the introduction of internal controls and/or external insurance cover where required." Answering "yes" requires more than a one-page document that hasn't been touched in three years. This guide explains what the risk assessment needs to cover, how to structure it, and what auditors actually look at.
What the risk assessment is for
The purpose of a parish council risk assessment is to identify things that could go wrong during the year — financially, operationally, legally, physically — and to show that the council has considered what to do about them. It is not a compliance form for a regulator. It is the council's own evidence that it understands its risks.
The internal auditor's Annual Internal Audit Report (AIAR) assesses whether the council has an adequate risk management process. A risk assessment that exists but has never been reviewed is usually flagged as inadequate — the review is part of the evidence.
Format: the risk register
Most councils use a simple risk register — a table with columns for:
- Risk — what could go wrong
- Likelihood — low, medium, or high probability
- Impact — low, medium, or high severity if it happens
- Score — combined likelihood × impact (5-point scales work well)
- Controls in place — what is currently being done to mitigate the risk
- Action required — anything further needed
- Owner — who is responsible for monitoring this risk
- Review date — when this row was last assessed
There is no prescribed format. A simple spreadsheet or table in your minutes is sufficient. What matters is that it covers the council's actual risks, not a generic template that hasn't been adapted to your council.
What risks to include
Every council's risk register will look different — the relevant risks depend on what the council actually does. The categories most councils need to address:
Financial risks:
- Inadequate internal financial controls — unauthorised payments, misappropriation
- Precept setting error — under- or over-precept, billing authority relationship
- Investment of reserves — where funds are held and whether deposits are appropriately protected
- Fidelity guarantee gap — insurance covering employee or councillor fraud
Legal and governance risks:
- Failure to meet statutory deadlines — AGAR, Transparency Code, freedom of information
- Decisions taken outside the council's powers (ultra vires acts)
- Code of conduct breaches by councillors
- Non-compliance with employment law (if the council has staff)
Property and asset risks:
- Council-owned land, buildings, or equipment — damage, theft, public liability
- Assets not covered by current insurance (additions since last renewal)
- Lease agreements, licences to occupy, boundary disputes
Information and data risks:
- GDPR non-compliance — personal data security, breach risk
- Cybersecurity — ransomware, unauthorised access to council systems
- Loss of records — accounting records, minutes, legal documents
Operational risks:
- Key-person dependency — processes dependent on a single councillor or the clerk
- Health and safety — council events, council premises, contractor management
- Planning and environmental risks — developments affecting council land or responsibilities
Reputational risks:
- Press and social media — handling controversial decisions in public
- Complaints — unresolved complaints generating escalation to the monitoring officer
This is not an exhaustive list. Smaller councils with no land or employees will have shorter registers. Larger councils with parks, village halls, and cemeteries will need significantly more.
The annual review requirement
Assertion 5 requires that the council has "carried out an assessment of the risks" and "took appropriate steps to manage those risks" — past tense, referring to the current financial year. The risk assessment must be reviewed during the year being reported on, not just carried over from the year before.
In practice, the annual meeting of the council (which must take place between 1 and 30 May) is the natural point to review and re-approve the risk assessment alongside standing orders, financial regulations, and the code of conduct. The minutes should record that the risk assessment was reviewed and either approved as-is or amended.
If the review is deferred and never happens before the AGAR is approved, the auditor will flag it. The question is not whether the risk assessment exists, but whether it was reviewed in the year under audit.
Insurance linkage
The risk assessment links directly to the council's insurance programme. For each risk that is mitigated by insurance cover, the risk register should identify the relevant policy — public liability, employer's liability (if applicable), fidelity guarantee, property. The auditor checks that insurance is in place and that it matches the actual risk profile (new assets covered, disposed assets removed).
For the full picture on what insurance covers what risk, see our parish council insurance guide.
What the internal auditor checks
The internal auditor working through the Annual Internal Audit Report (AIAR) is looking for:
- A documented risk assessment that has been reviewed and approved by the council during the year
- Evidence in the minutes that the review took place (a resolution noting approval, or a minute recording that the risk assessment was reviewed and updated)
- Insurance cover that covers the risks the council has identified
- No obvious risks that have been overlooked
Common failures:
- Risk assessment not reviewed in the current year (most common)
- Insurance schedule doesn't cover a new asset (new equipment, new event)
- A material risk (GDPR, employment, boundary dispute) not included at all
- "Controls in place" column left blank for high-scored risks
Connecting risk assessment to the governance statement
When the council approves the Annual Governance Statement (Section 1 of the AGAR), it is affirming Assertion 5 — that risks have been assessed and appropriate steps taken to manage them. If the risk assessment hasn't been updated, this assertion gets a "no" answer, which must be explained.
A "no" is not fatal — it just requires an honest explanation in the AGAR and a note of what the council is doing to address the gap. But a pattern of "no" answers on the same assertion year after year will attract more scrutiny.
Use the free compliance checklist tool to self-assess across all AGAR assertions before the annual meeting, and our AGAR preparation guide for the full picture of Section 1 completion.
Sources
- Local Audit and Accountability Act 2014 — statutory basis for the AGAR process
- Smaller Authorities' Audit Appointments (SAAA) — AGAR forms and guidance
- National Association of Local Councils (NALC) — SAPPP Practitioners' Guide (annual publication; contact your county association for the current edition)
This article is for general guidance only and does not constitute legal advice. Risk assessment requirements for your council should be read alongside the current SAPPP Practitioners' Guide, published by JPAG through NALC and SLCC.