Corporate governance report
Directors’ report
The Directors’ report provides information on the senior leadership of the CPS, including membership of the key governance bodies. It additionally reports on information security, including personal data related incidents that have been reported to the Information Commissioner’s Office (ICO).
Membership of boards and committees
| April 2021 – March 2022 | Meetings | ||
|---|---|---|---|
| Members | CPS Board | Audit and Risk Assurance Committee5 |
Nominations and Governance Committee |
| Non-Executive Board Members | |||
| Caroline Wayman Non-Executive Board Member |
8/9 | - | 4/4 CHAIR |
| Simon Jeffreys Non-Executive Board Member |
9/9 | 4/4 CHAIR | - |
| Mark Hammond Non-Executive Board Member |
9/9 | 4/4 | - |
| Monica Burch Non-Executive Board Member |
9/9 CHAIR | - | 4/4 |
| Independent ARAC Members | |||
| Jennifer Rowe Non-Executive ARAC Member Left 2 August 2021 |
- | 2/2 | - |
| Marta Phillips Non-Executive ARAC Member From 1 November 2021 |
- | 2/2 | - |
| Deborah Harris Non-Executive ARAC Member From 10 January 2022 |
- | 2/2 | - |
| Executive Board Members | |||
| Max Hill Director Of Public Prosecutions |
9/9 | 4 | 4/4 |
| Rebecca Lawrence Chief Executive Officer |
9/9 | 4 | 4/4 |
| April 2021 – March 2022 | Meetings |
|---|---|
| CPS Executive Group | |
| Rebecca Lawrence Chief Executive Officer |
10/10 |
| Max Hill QC Director of Public Prosecutions |
9/10 |
| Gregor McGill Director of Legal Services |
8/10 |
| Sue Hemming Director of Legal Services |
10/10 |
| Mark Gray Chief Digital and Information Officer |
9/10 |
| Dawn Brodrick Chief People Officer |
10/10 |
| Baljit Ubhey Director of Strategy and Policy |
10/10 |
| Chris Sharp Director of Finance and Estates Left 30 April 2021 |
1/1 |
| Steve Buckingham Chief Finance Officer From 4 May 2021 |
9/9 |
| Sandra McKay Director of Communications |
10/10 |
| Grace Ononiwu Director of Legal Services |
10/10 |
Security and information assurance
The CPS applies proportionate security controls as outlined in the Government Functional Standard (GovS 007). Our compliance with the standard is reported to the Cabinet Office in the annual Departmental Security Health Check (DSHC) and is assessed against ‘Minimum Security Standards’ for Cyber, Incident Management, Personnel and Physical. The CPS’ performance exceeded the minimum standards in Cyber and Incident Management. In relation to the Personnel and Physical standards, our performance was judged as ‘Mostly meeting the standard’. We have an ongoing process of security review and improvement and have worked closely with the Government Security Centre over the reporting year to review our security position regarding the physical security of our buildings, with a view to further improvements where necessary.
Cyber security
The CPS Cyber Security Team (CST) continue to be proactive in their attack vector scanning and reacted swiftly to previously unknown vulnerabilities, such as the Log4j vulnerability revealed in December 2021. After intensive investigations it was confirmed, we had a small number of servers that were affected. Appropriate patches were promptly installed.
We work with relevant parties – both internally and across the criminal justice system – on cyber security attacks, to understand the extent of any CPS exposure, and to ensure appropriate steps are taken to increase wider resilience. Our Security Operations Centre takes data feeds from a number of CPS network services to detect anomalous activity. The CST works closely with the National Cyber Security Centre (NCSC) and our strategy is in line with the Government’s Cyber Security Strategy; undertaking the Cyber Assessment Framework as part of the Gov Assured future work will be a key priority for next year.
Our regular phishing exercises involving all staff have continued. A member of the national Information Governance Group is now working with the CST lead to further increase awareness of this key aspect of cyber risk. A service wide Cyber Security Training Programme will be introduced shortly once the outcome of the current pilot has been evaluated.
Working with suppliers, both internal and external, we continue to ensure new products are appropriately secure. As part of that programme, we deployed a new ‘secure build’ Android smartphone during 2021. Currently, we are working on a Cloud Managed End User Design build that will allow us to control security patching, updating and any firmware upgrades.
Operational security
The Operational Security Team (OST) has continued to work with the business to ensure security policies remain compliant with government technical standards outlined in GovS 007. The local security provision has been further improved by the recruitment of Security and Information Managers (SIM) across the estate. Their work has been underpinned by the implementation of a Security and Information Assurance Framework, which outlines key compliance activities across all aspects of security and information assurance. Each business unit has an agreed Security and Information Assurance Improvement Plan in place and progress is regularly assessed by local Senior Management Teams.
Business continuity
The CPS’ Business Continuity capabilities and resilience continued to be tested last year as a result of the pandemic. The continued closure of offices and courts led to most staff continuing home-based working throughout the year. The Gold/Silver command structure continued to lead the CPS’ response to the pandemic and contribution to the criminal justice system’s recovery.
A Gold and Silver Business Continuity exercise took place in the latter stages of the year, testing the CPS’ response to a system wide IT outage without prior notice. The outputs from this Exercise will inform our future Business Continuity Plans and Policy and will be tested early in 2022-23 as part of a Silver/Bronze exercise programme.
General Data Protection Regulation (GDPR) and Data Protection Act 2018
We have continued to strengthen our data protection processes to ensure we optimise the value of the data we hold whilst protecting the ‘rights and freedoms’ of all data subjects.
Our Information Governance Group (IGG) continues to provide assurance to both the Executive Group and the Audit Risk and Assurance Committee of the CPS’ compliance with information security requirements. An Information Asset Owners (IAO) Network has been established to assist our senior leaders to effectively carry out this key role. Supported by local Data Assurance Forums they have a ‘real time’ picture of compliance across their business unit. Both these groups report to the IGG which, with its enhanced understanding of information management and data protection issues, provides clear direction to the business to ensure ongoing compliance.
All data protection policies and guidance were reviewed by Security function’s Policy Review Board on behalf of the IGG.
We have delivered new and improved training on data protection legislation for all staff which included law enforcement processing; a compliance rate of 99% was achieved. We also helped develop guidance on redaction training in various formats to assist front line staff in decision making at pace.
By assisting project teams undertaking data protection impact assessments, we have ensured all new systems comply with the Data Protection Act 2018 and helped further embed a culture of ‘data protection by design and default’.
Information assurance and compliance
The CPS compliance rate statistics for information requests are as follows:
Freedom of Information Requests (FOIs)
April 2021 to March 2022
Received: 708
Responded within Deadline: 605
Compliance Rate: 85%
Rights of Access Requests (ROARs)
April 2021 to March 2022
Received: 504
Responded within Deadline: 395
Compliance Rate: 78%
GDPR rights requests
Total Received: 24
Responded to within deadline: 24
Compliance rate: 100%
CPS legacy case records for national interest
To meet our obligations under the Public Records Act 1958 and the 20 year transition programme, the Records Management Team selected and transferred to The National Archive (TNA) legacy criminal cases for years 1994 (22 cases, 502 pieces) and 1995 (35 cases, 872 pieces). It is expected for year 1996 that 20 cases (circa 1050 pieces) will be transferred to TNA in Spring 2022.
It is expected that all legacy records up until year 2002 will be transferred to TNA by the end of 2022.
Personal data-related incidents
A summary of protected personal data-related incidents formally reported to the Information Commissioner’s Office (ICO) in 2021-22 is set out below.
Personal data incidents reported to the ICO in 2021-22:
| Date of incident (month) | Nature of incident | Nature of data involved | Number of people potentially affected | |
|---|---|---|---|---|
| April to June 2021 | 3 data handling loss 5 unauthorised disclosures |
Disc and archived case files Case information |
16 | Operational Security notified and breaches reported to ICO. Four breaches closed by ICO – no regulatory action taken. Four breaches being considered by ICO as at 1 April 2022. |
| July to September 2021 | 4 unauthorised disclosures | VRR letter Case information |
5 | Operational Security notified and breaches reported to ICO. Three breaches closed by ICO – no regulatory action taken. One breach being considered by ICO as at 1 April 2022. |
| October to December 2021 | 2 data handling Losses 1 unauthorised disclosure |
Archive case files and court bundles Case information Discs and hard copy papers |
3 | Operational Security notified and breaches reported to ICO. Three breaches being considered by ICO as of 1 April 2022. |
| January to March 2022 | 5 unauthorised disclosures 1 data handling loss |
Case information Hard copy papers Disc |
7 | Operational Security notified and breaches reported to ICO. Four breaches closed by ICO – no regulatory action taken. Two breaches being considered by ICO as of 8 June 2022. |
A summary of personal data incidents in 2021-22 is set out below.
Total personal data incidents in 2021-22:
| Category | Total reported | Explanatory note |
|---|---|---|
| Loss of electronic media and paper documents | 86 | In 71 of these incidents the data loss was very minor and was eventually recovered; or reported but caused by non-CPS staff. |
| Unauthorised disclosure | 2,628 | In 2,447 of these incidents the data loss was very minor or retained within the criminal justice profession, who are bound to professional standards of data protection. |
| Lost laptops/tablets/smartphones | 27 | In 26 of these incidents the devices were eventually recovered. All devices were encrypted to the government standard; therefore no CPS data has been compromised. |
Statement of Accounting Officer’s responsibilities
Under the Government Resources and Accounts Act 2000, HM Treasury has directed the CPS to prepare, for each financial year, accounts detailing the resources acquired, held or disposed of during the year and the use of resources by the Department during the year. The accounts are prepared on an accruals basis and must give a true and fair view of the state of affairs of the CPS and of its income and expenditure, Statement of Financial Position and cash flows for the financial year.
In preparing the accounts, the Accounting Officer is required to comply with the requirements of the Government Financial Reporting Manual and in particular to:
- observe the Accounts Direction issued by HM Treasury, including the relevant accounting and disclosure requirements, and apply suitable accounting policies on a consistent basis;
- make judgements and estimates on a reasonable basis;
- state whether applicable accounting standards as set out in the Government Financial Reporting Manual have been followed, and disclose and explain any material departures in the accounts;
- prepare the accounts on a going concern basis.
HM Treasury has appointed the Director of Public Prosecutions as Accounting Officer of the Department, and the Director of Public Prosecutions has appointed the Chief Executive Officer as an additional Accounting Officer. This appointment does not detract from the Director of Public Prosecutions’ overall responsibility as Accounting Officer for the Department’s accounts.
The responsibilities of an Accounting Officer, including responsibility for the propriety and regularity of the public finances for which the Accounting Officer is answerable, for keeping proper records and for safeguarding the CPS’ assets, are set out in Managing Public Money published by HM Treasury.
The Accounting Officer confirms that he has taken all the steps that he ought to have taken to make himself aware of any relevant audit information and to establish that the CPS’ auditors are aware of that information. So far as he is aware, there is no relevant audit information of which the auditors are unaware.
The Accounting Officer confirms that the Annual Report and Accounts as a whole is fair, balanced and understandable and he takes personal responsibility for the Annual Report and the judgements required for determining that it is fair, balanced and understandable.
Governance statement
This Governance Statement sets out the CPS’ governance, risk and assurance management and internal control framework and how, during 2021-22, we managed the significant risks to the achievement of our strategic objectives. We ensure that robust governance arrangements are in place to promote high performance and safeguard probity and regularity. The CPS is a Non‑Ministerial Department that is not subject to the protocol on enhanced departmental boards but has sought to comply as far as possible with the practices set out in Cabinet Office’s and HM Treasury’s Corporate Governance Code of Good Practice. Details of attendance at the CPS’ boards and committees are given in the Directors’ report above.
Governance framework

The CPS Board
The Board provides oversight and governance for the CPS and is responsible for the delivery of the organisation’s aims and objectives and the wider contribution it makes to the criminal justice system. It plays a key role in ensuring that the CPS is equipped to provide a professional, efficient and high-quality service.
The Cabinet Office’s and HM Treasury’s Corporate Governance Code of Good Practice provides guidance on Board composition and remit. In response to the findings of a 2019 review of CPS governance, changes to the Board composition were made, motivated by an intention to make the Board more strategic, streamlined and independent.
The primary function of the CPS Board is to set the strategic direction and priorities for the CPS, and to provide a forum for constructive challenge on proposals and the implementation of decisions by the Executive Group as appropriate.
This year the Board has considered a number of key issues. The Board received regular updates on the progress of the Future Working Programme and on activities to support staff wellbeing during the pandemic.
To ensure the Board is satisfied with the quality of data it receives, the Board has worked closely with performance teams throughout the development of a new quarterly highlight report to track progress against the CPS 2025 values and the Business Plan. The Board has also been closely involved in the development of performance data reporting, which reported for the first time during the year.
A key focus for the Board remains the Operational Recovery and Improvement Programme, which continues to monitor overall resource and structures to manage inflated caseloads and engagement with the Crown Court National Improvement Team.
Audit and Risk Assurance Committee (ARAC)
The Audit and Risk Assurance Committee (ARAC) advises the Accounting Officers on financial and risk management and assurance arrangements in the CPS. It reviews the comprehensiveness and reliability of assurances provided by the Government Internal Audit Agency (GIAA), the National Audit Office (NAO) and the executive management team. The committee also gives scrutiny to the CPS’ risk management process and the effectiveness of the assurance framework.
The CPS Bespoke Assurance Framework continued to ensure that members of the Executive Group were accountable for their respective portfolios. The reports the Committee have received have provided assurance to the CPS Board on the effectiveness of internal controls within the CPS.
The Committee continued to receive updates on risk management process at each meeting. In addition, the Committee conducted regular deep dives on specific risks including regular updates from the Rape and Serious Sexual Offences programme.
Executive Group (EG)
The Executive Group comprises the most senior members of headquarters staff. It takes the strategic direction of the Board and delivers supporting plans and guidance to the business. It is responsible for refining and delivering CPS strategy and for collective delivery of the strategic objectives and efficiencies supporting the operational delivery of the business. It gives regular scrutiny to the financial management of the business.
Nominations and Governance Committee (NLRC)
The Nominations, leadership and Remuneration Committee (NLRC) advises the Board on key elements of effectiveness, including:
- ensuring that there are satisfactory systems for identifying and developing leadership and high potential talent;
- succession planning for appointments to the Board and to other senior roles in order to maintain an appropriate balance of skills, experience and diversity;
- overseeing the departmental commitment to Equality, Diversity and Inclusion in relation to leadership behaviours and senior appointments and development; and
- scrutinising the incentive structure, and succession planning, for the Board and senior leadership of the CPS.
It has specific decision-making responsibility in respect of the performance and remuneration of CPS senior management. The Committee has maintained oversight of senior talent management and succession planning, and the Senior Operating Model.
Risk management
The early identification and effective management of risk is fundamental to the achievement of our mission, goals, and strategic objectives. Our approach encompasses managing risk across all our activities at operational, tactical, and strategic levels.
Risk management and risk profile
For the CPS to meet the changing demands of the criminal justice system and fulfil our stakeholders’ expectations, we need to give the highest priority to risk across all levels of the organisation and ensure it is aligned with the achievement of our objectives.
The CPS Enterprise Risk Management framework was written to provide the methodology and philosophy to ensure that risks are effectively mitigated in line with the Treasury’s ‘Orange Book’. This is underpinned by risk management processes designed to inform business decisions; enable more effective use of resources; enhance strategic and business plans and strengthen contingency planning.
Effective governance of the process allows for escalation and reporting of risk to appropriate tiers of management including the Performance and Risk Group, Executive Group, Audit and Risk Assurance Committee, and the Board. Additionally, the Integrated Internal Audit programme and work of HM Crown Prosecution Service Inspectorate is informed by regular mapping to ensure adequate coverage of all key areas of risk.
Risk appetite statement
The CPS has a very low risk appetite towards any risk likely to result in the miscarriage of justice, that would expose the CPS to significant reputational damage, or that risks a material financial loss.
Key risk activities planned and in progress
During 2021-22, the CPS continued to strengthen its risk management framework and carried out the following key activities:
- Integrated, improved, and simplified the Enterprise Risk Management Framework across all levels of the organisation to manage potential threats and existing issues, and deliver benefits for CPS stakeholders.
- Risk management reviews have been carried out on all strategic risks with the respective Senior Risk Owners and ongoing work is in place to actively monitor risk progression in relation to the effectiveness of mitigations.
- A comprehensive deep dive was carried out into the rape and serious sexual offences programme to understand and articulate associated risks and sub-risks.
- Risk training, risk workshops and risk reviews have been carried out and will continue to run over the next year with the aim of increasing risk maturity in the CPS.
- In-depth quarterly reviews of risk returns have been carried out and will continue to be reviewed on a regular basis. This activity measures the key risk themes coming from each CPS Area.
- Ongoing activities are underway to improve risk and assurance management across the CPS. One aspect of this is the integration of assurance into the risk framework. This will establish a solid ‘three lines of defence’ capability for risk management across the CPS.
Roles and responsibilities
The CPS Board has overall responsibility for our risk appetite, determining the amount and type of risk that we are willing to take to meet our strategic objectives.
The Director of Public Prosecutions and our Chief Executive Officer (as Accounting Officers) are accountable to Parliament for ensuring that all risks are managed effectively. On their behalf, the Chief Finance Officer and the Risk Management Team coordinate the deployment of risk management arrangements, ensure consistency of approach, and periodically report the top risks to the Executive Group, Audit and Risk Assurance Committee and the Board.
Ownership of risk registers is assigned to relevant senior managers, and individual risks are owned by the most appropriate team or individual.
Corporate performance, including current risk and financial metrics, is reviewed monthly by the Performance and Risk Group, with a formal review of the top risks presented to the Executive Group on a quarterly basis to agree the controls and mitigating actions required to reduce risks to within tolerance levels and to consider emerging issues.
The Audit and Risk Assurance Committee, which meets quarterly, provides oversight of corporate risks, reviewing the status and the progress of mitigations identified by the risk owners.
The Board formally reviews key risks, and the risk landscape is used to inform the business strategy and the audit programmes to aid management in the delivery of business objectives.
Individual risks are assessed using our Enterprise Risk Management methodology under one of 10 underlying risk themes.

Our principal risks
| Risk Category | Risk Description | Key Activities to Manage Our Risk | Risk Assessment and Direction of Assurance |
|---|---|---|---|
|
Information Management Public Confidence |
Security and Information Management, Training and Governance: Sensitive case information relating to victims or witnesses could be disclosed in error, placing them at risk. |
|
This is identified as a severe risk where CPS has a very low risk appetite. Further mitigating actions have been identified to bring this risk within tolerance levels. |
|
Security Public |
Cyber Security: Our data or infrastructure is compromised by hostile cyber activity leading to potential major disruption to core business operations, risk to life if sensitive data is breached and significant reputational damage and loss of partner and public confidence. |
|
We continually review our cyber security risk and maintain all digital technology risks within tolerance levels. |
|
Casework Public |
Rape and Strategic Partnerships: Ongoing political and public scrutiny of the historically low numbers of rape cases prosecutions, with government targets for a return to 2016-17 volumes by the end of this Parliament. Scorecards are to be introduced which will include metrics for investigation, prosecution, and the courts. This could lead to increased levels of political scrutiny, negative media coverage and reputational damage. |
|
We continue to work with partners across the criminal justice system and, through implementation of the RASSO 2025 strategy, we are determined to drive up the number of rape cases that are going to court. |
|
Service to Public |
Operational Recovery & Improvement: Resources and ways of operating effectively under coronavirus conditions have created backlogs resulting in increased organisational stress and resilience issues to the operational management of casework. |
|
Court backlogs that have materialised during the COVID-19 pandemic have led to unacceptable delays in the delivery of justice. Our continued engagement with partners across the criminal justice system in operational recovery |
| Capability, People & Resources |
Change Management: CPS is unable to realise the benefits associated with change as there |
|
|
| Capability, People & Resources |
Our People: The CPS does not have the right people with the right skills who are engaged and empowered to deliver high quality casework outcomes. |
|
|
| Service to Victims |
Supporting Victims: Victims lack trust in the CPS and the wider criminal justice system to serve justice. |
|
Although quality and timeliness of communications with victims continues to improve it is below levels of aspiration. |
All risks that fall outside CPS risk tolerance are periodically reviewed by the Audit and Risk Assurance Committee to ensure effective mitigation is ongoing with a view to bringing these appropriately back within tolerance.
Identifying and managing conflicts of interest
The Civil Service Management Code sets out standards of propriety expected of civil servants in respect of external interests. The CPS has a policy in place for the declaration and management of interests for all staff, which includes declaration of any interests that may give rise to a conflict or perceived conflict of interest, and adheres to the requirements of the Code. In addition to the established processes in place for managing interests, an annual audit exercise takes place which requires all staff to make a declaration of any private, personal or financial interests or, for those in SCS and equivalent grades and senior employees in a Commercial role, to make a nil declaration. Where a conflict or perceived conflict of interest arises, these will be recorded, considered, assessed and managed by appropriate senior managers with the support of Risk and HR practitioners.
Business appointments
In compliance with business appointment rules, the CPS is transparent in the advice given to individual applications for senior staff. We had five business appointment declarations from employees who left during 2021-22.
Her Majesty’s Crown Prosecution Service Inspectorate
Her Majesty’s Crown Prosecution Service Inspectorate (HMCPSI) inspects the Crown Prosecution Service and the Serious Fraud Office. It provides independently assessed evidence to help drive improvement and build public confidence in the prosecution process.
HMCPSI priorities for inspection are set out in an annual Business Plan and it reports annually to the Attorney General on the performance of the CPS, in addition to other individual and thematic inspection reports.
During 2021-22, HMCPSI completed eleven inspections:
As part of HMCPSI’s Area Inspection Programme, they assess all 14 CPS Areas against a consistent inspection framework. Each Area is subject to a baseline inspection and follow-up inspection within a three-year period. No recommendations are being made in these reports. In this period, the following reports were published:
Cymru/Wales Area Inspection Programme Baseline Report – published 12 October 2021
The report recognises the pressures that the coronavirus pandemic has brought, which coincided with a period of change in the Area workforce, resulting in a loss of experience. The report also recognised that the Area had been under significant pressure with increasing caseloads. Overall, Inspectors found that the Area had effective systems and processes in place to ensure that cases are managed and progressed effectively.
North East Area Inspection Programme Baseline Report – published 12 October 2021
The report recognises the progress in, and commitment to, improving casework quality within the Area, and the hard work of the casework teams. Inspectors found particular strengths in service to victims, and in casework quality in rape and serious sexual offence cases. It also identified a number of issues which are being addressed both internally and with criminal justice system partners.
South East Area Inspection Programme Baseline Report – published 12 October 2021
The report shows that a sustained focus on casework quality and decision making in the area is having an impact on how effectively cases are progressed. The area had already identified the same areas for improvement as Inspectors and had begun work to ensure that these were addressed.
West Midlands Area Inspection Programme Baseline Report – published 12 October 2021
The report recognises the strengths of the Area, including noting that the Area added significant value and excelled in making good prosecutorial decisions, as well as adding value when making decisions and considering issues relating to victims and witnesses. The report also acknowledges the challenging environment within which the Area has been operating within during the COVID-19 pandemic, given the significant increase in casework at a time when the Area was carrying out a significant recruitment drive.
CPS London South Baseline Report – published 17 February 2021
The report reflects the context of a significant increase in London South’s caseload following court closures in the initial lockdown in March 2020 and an increase in receipts from the police, which have created backlogs in the Area. Whilst there were notable aspects of the Area’s casework that were done well, the inspectorate found that there were aspects of casework quality where improvement is needed. Also, the consideration of victim and witness issues post-charge was a strength, but the inspectorate identified that pre charge victim issues required improvement across all units.
CPS East of England, Baseline Report – published 24 March 2022
Inspectors noted caseload and resourcing pressures with which the Area is dealing, acknowledging the hard work of all staff, and the joint working with criminal justice partners. In addition, it was recognised that the area adds value through good quality decision-making around disclosure of unused material, particularly in the Crown Court, and in rape and serious sexual offences casework.
Additionally, HMCPSI conducted the following thematic and joint inspections:
A joint thematic inspection of the police and Crown Prosecution Service’s response to rape – Phase one: From report to police or CPS decision to take no further action - published 16 July 2021.
The Criminal Justice Joint Inspectorate (CJJI) published two reports about the police and CPS response to rape at every stage of a case – from first report through to finalisation. The first phase focused on those cases where either the police or the CPS made the decision to take no further action (i.e. not to proceed with the case). Inspectors found that a lack of collaboration between the police and prosecutors had led to delays and poor communication with victims. They recognised, however, that work was already underway at a national level and that the police and the CPS were jointly making improvements.
An inspection of the operation of CPS and SFO Proceeds of Crime Divisions – published 22 July 2021
This inspection examined the effectiveness of domestic restraint and confiscation casework in the CPS Proceeds of Crime Division and the SFO Proceeds of Crime and International Assistance Division. Inspectors identified strengths and aspects of good practice in the CPS, in addition to finding that staff were professional, very capable, and highly motivated, with considerable skill, knowledge and commitment.
Joint thematic inspection of the progress of individuals who have mental health problems through the criminal justice system – published 17 November 2021
This is a clear and thorough report which highlights the need for progress and change in handling cases where the suspect or defendant has a mental health condition or disorder. The CPS recognises that there is more work to be done to improve the handling of mental health cases within the criminal justice system and looks forward to progressing work on the three of the Inspectorate’s recommendations which also apply to the CPS (out of a total of 22).
CPS Handling of Custody Time Limits – published 16 December 2021
Inspectors found that the temporary legislative changes due to the pandemic had been clearly communicated to staff, that tools and guidance provided were effective in minimising errors, and that monitoring systems were appropriate. The findings demonstrate that staff responded well to the increasing demands placed upon them by the changes to Custody Time Limits (CTLs) arising from the pandemic. The report makes three recommendations which will assist us to further improve the accurate calculation of CTLs, the standard of our reviews, and the quality of our CTL extension applications.
A joint thematic inspection of the police and Crown Prosecution Service’s response to rape – Phase two – How well the criminal justice system serves survivors of rape - published 25 February 2022
The second phase considered what the barriers are to the progression of rape reports in the criminal justice system following charge. We recognise that the approach to the investigation and prosecution of rape and our response, as well as that of the wider criminal justice system, must improve. Actions taken to transform how we handle rape cases have therefore prioritised three main areas, in respect of which work is ongoing:
- better collaboration with the police from the very start of an investigation, taking an offender-centric approach to case-building;
- supporting our prosecutors and expanding the size of our specialist units so that they are properly resourced to respond to these challenging and complex cases; and
- improving the support given to victims, and recognising the trauma they experience.
Commercial arrangements
The CPS Commercial Policy sets out the governance for our commercial activity, ensuring legal compliance with Public Contract Regulations, Cabinet Office spending controls and delegated authority limits, which are structured around value and risk of the procurement or contract change involved. The new role of Head of Commercial Policy has supported implementation of the policy across the CPS, including the roll out of a full package of commercial training courses which commenced in 2021‑22 and will continue into the 2022-23 financial year.
The policy is supported by a robust approval framework with gateways encompassing the full commercial lifecycle from concept through to contract exit. The introduction of Strategic Sourcing specialisms has enabled earlier engagement with the business, resulting in an enhanced understanding of our commercial pipeline. This has created better assessment of ‘make or ‘buy’ decisions and greater engagement with the marketplace to better understand our requirements.
The Commercial function is integral to the business case process, both for internal approvals via the Investment Committee and for Cabinet Office and Treasury controls. This ensures the right commercial risks are raised at business planning stage to ensure that appropriate mitigation measures are identified, implemented and monitored throughout the commercial lifecycle. The Commercial function is also represented on internal governance boards to provide commercial insight and oversight, thereby ensuring that compliance is maintained and the most advantageous commercial model is delivered to the CPS.
In 2021-22 the CPS have jointly issued their first Anti-Modern Slavery Statement with the Attorney General’s Office (AGO), reasserting our organisations’ combined commitment to preventing modern slavery within our supply chains. The 2015 Modern Slavery Act gives law enforcement agencies enhanced tools to tackle modern slavery. In 2020, the UK published the world’s first government modern slavery statement setting out the steps taken to prevent modern slavery in central government supply chains. This includes a commitment for government departments to publish their own annual statement in 2021.
Due in part to our role within the criminal justice system, the CPS knows the importance of tackling these complex crimes at the highest levels and is fully committed to helping deliver the Government’s objectives, ensuring taxpayers’ money does not inadvertently fund criminal activities, and to protect vulnerable workers in global supply chains from exploitation.
The statement outlines the steps the AGO and CPS have taken to prevent modern slavery in their supply chains and ensure transparency in areas where AGO and CPS suppliers may need to improve. The statement also sets out formal goals across a range of measures, from training and raising awareness to addressing risks with our key suppliers and their supply chains. A report on the progress towards these objectives will be released in 2022 as part of the next statement.
Review of effectiveness
The Accounting Officer has responsibility for reviewing the effectiveness of the system of internal control in the CPS.
His review is informed by the work of Internal Audit and members of the Executive Group, which has responsibility for the development and maintenance of the internal control framework, and comments and recommendations made by the external auditors in their annual management letter and other reports.
Rebecca Lawrence acts as an Additional Accounting Officer of the CPS.
Assurance audits
The CPS uses the Government Internal Audit Agency (GIAA) to provide objective insight aimed at helping achieve better outcomes and value for money for the public. In 2021-22 GIAA assessed the overall level of assurance in the CPS as a whole to be ‘moderate’. This reflects that some improvements were identified to further enhance the adequacy and effectiveness of the framework of governance, risk management and control.
Internal Audit use a four-point scale in assessing the level of assurance:
| Substantial | The framework of governance, risk management and control is adequate and effective. | |
|---|---|---|
| Moderate | Some improvements are required to enhance the adequacy and effectiveness of the framework of governance, risk management and control. | |
| Limited | There are significant weaknesses in the framework of governance, risk management and control such that it could be or could become inadequate and ineffective. | |
| Unsatisfactory | There are fundamental weaknesses in the framework of governance, risk management and control such that it is inadequate and ineffective or is likely to fail. |
The following table represents the high-level outcomes achieved for each of the areas audited during 2021-22:
| Area of inspection | Outcome from review of effectiveness | Date report finalised |
|---|---|---|
| Personal Injury Claims | MODERATE | October 2021 |
| Strategic Procurements | MODERATE | October 2021 |
| CPS 2025 | MODERATE | October 2021 |
| Disclosure | MODERATE | February 2022 |
| Deployment of Paralegal Resources | MODERATE | March 2022 |
| National Resource Model (NRM) | MODERATE | March 2022 |
| Casework Quality | SUBSTANTIAL | May 2022 |
| Business Continuity | MODERATE | May 2022 |
Based on the above, it is concluded that there were no significant weaknesses in the CPS’ governance and control framework that affected achievement of its strategic objectives in 2021‑22.
Advisory audits
As well as the above assurance audits, the GIAA also conducted two advisory audits during 2021‑22. Advisory audits involve GIAA working together with subject matter experts from across the CPS in an advisory role and are not subject to an opinion. The two advisory audits carried out in 2021-22 were in respect of Whistleblowing and Management of the Portfolio of Change, with reports being issued in August 2021 and March 2022 respectively.
- The Director of Public Prosecutions and Chief Executive Officer are not formal members of the Audit and Risk Assurance Committee but attend by invitation. Details are shown for those meetings they attended.