Skip to main content

Corporate governance report

Directors’ report

The Directors’ report provides information on the senior leadership of the CPS, including membership of the key governance bodies. It additionally reports on information security, including personal data related incidents that have been reported to the Information Commissioner’s Office (ICO).

Membership of boards and committees

April 2022 – March 2023Meetings
Members

CPS Board

Audit and Risk Assurance Committee

Nominations, Leadership and Remuneration Committee

Non-Executive Board Members
Caroline Wayman
Non-Executive Board Member
(contract ended 31/05/2022)

1/1

-

1/1 CHAIR

Simon Jeffreys
Non-Executive Board Member

8/8

4/4 CHAIR

-

Mark Hammond
Non-Executive Board Member

8/8

3/4

-

Monica Burch
Non-Executive Board Member

8/8 CHAIR

-

4/4

Dr Subo Shanmuganathan
Non-Executive Board Member
(from 03/10/2022)

4/4

2/2

 

Kathryn Stone OBE
Non-Executive Board Member
(from 03/10/2022)

1/4

-

1/2

Independent ARAC Members

Michael Dunn
Non-Executive ARAC Member

-

4/4

-

Deborah Harris
Non-Executive ARAC Member

-

4/4

-

Executive Board Members

Max Hill KC
Director of Public Prosecutions

8/8

3/4

4/4

Rebecca Lawrence1
Chief Executive Officer

-

1/1

1/1

Sue Hemming1
Interim Chief Executive Officer (from
26/09/2022)

5/5

2/2

2/2

April 2022 – March 2023

Meetings

CPS Executive Group

 

Rebecca Lawrence1
Chief Executive Officer

2/2

Max Hill KC
Director of Public Prosecutions

10/11

Gregor McGill
Director of Legal Services

9/11

Sue Hemming1
Interim Chief Executive Officer (from 26/09/2022)
previously Director of Legal Services

9/11

Mark Gray
Chief Digital and Information Officer

10/11

Dawn Brodrick
Chief People Officer

8/11

Baljit Ubhey
Director of Strategy and Policy

11/11

Steve Buckingham
Chief Finance Officer

11/11

Sandra McKay
Director of Communications

11/11

Grace Ononiwu
Director of Legal Service

8/11

Tristan Bradshaw
Interim Director Operational Change & Delivery

5/5

Security and information assurance

We apply proportionate security controls as outlined in the Government Functional Standard (GOVS007). Our compliance with the standard is reported to the Cabinet Office in the annual Departmental Security Health Check (DSHC) and is assessed against ‘Minimum Security Standards’ for Cyber, Incident Management, Personnel and Physical. In 2022, the Cabinet Office concluded that as an overall rating we are 99.1% compliant with the GOVS007 Standards.

We ensure all projects and programmes put in place appropriate technical and organisational measures to implement the data protection principles effectively and safeguard individual rights. Cross CPS collaboration ensures that innovation is encouraged but managed securely; where necessary, we consult with the Regulator.

Cyber security

The Cyber Security Team (CST) continue to consolidate our resilience to cyber-attacks and data compromise. Their new cyber security incident response plan and playbooks have further increased our capability to successfully respond to such incidents. During the year, the Team responded to several attacks affecting criminal justice partners which threatened to compromise us. In August 2022, they worked with police colleagues in response to a ransomware attack on a firm of solicitors. Utilising our response plan, we took pre-emptive action to block their email domains and thereby ensured that the CPS suffered no detrimental impact.

CST are now joint chairs of a legal sector Security Working Group (SWG) with NCSC which includes the Bar Council, Law Society, Legal Aid Authority and Ministry of Justice. The Group aims to increase joint understanding of cross sector risks and our overall capacity to withstand attacks. The Group is currently focussing on Business Email Compromise (BEC) and cyber hygiene.

In July 2022, the Government Internal Audit Agency (GIAA) provided their report on the CPS’ cyber security; they judged our performance as ‘Moderate’, the second highest rating.

The team have developed a Cyber Security Education, Training & Awareness (CSETA) programme for all our staff. It is a rolling 12-month programme which includes 3 mandatory assessments and is designed to increase cyber knowledge and awareness. We have already seen the benefit of continuous cyber training; a sustained focus on cyber security awareness, which includes frequent phishing campaigns, has enhanced the security culture across our workforce.

We have reduced the threat of a cyber security supply chain attack by requiring all suppliers to complete a Security Management Plan (SMP) and Assurance Questionnaire. This best practice approach provides assurance to SIAD with regards to the supplier, in their service required deliverables to the CPS. The CPS approach has since been adopted by another Government Department.

Operational security

The Operational Security Team (OST) continues to work with the business to ensure the rigorous application of security standards, as outlined in the GovS007 Functional Standard. Area based Security & Information Managers have now been embedded across the department. Their compliance with government security standards is reported annually through the Security & Information Assurance Framework, aligned to the GovS007 minimum standards. This, in turn, forms the basis of our Departmental Security Health Check report to the Cabinet Office. The CPS continues to perform well in the DSHC; exceeding the baseline assessment scores in all areas.

We have undertaken an organisation-wide vetting review. All CPS roles have been assessed to ensure appropriate vetting levels, proportionate to risk. The review will provide the framework for our transition to new vetting levels.

Business continuity

The CPS’ Business Continuity (BC) capabilities and resilience remain consistently high and are regularly tested. In November 2022, we worked with digital colleagues to assess our operational response to various IT failures across the CPS. We have also participated in several cross-government exercises. We review our BC plans as part of the testing regime or following a ‘live’ incident.

The GIAA reviewed our BC arrangements in May 2022 and assessed our performance as ‘Moderate’, the second highest rating.

General Data Protection Regulation (GDPR) and Data Protection Act 2018

We have continued to strengthen our data protection processes to ensure we optimise the value of the data we hold and comply with current legislation. Our Information Governance Group (IGG) has been expanded to ensure all aspects of the business are represented and provides assurance to the Executive Group and the Audit Risk and Assurance Committee with regards our compliance with the Data Protection Act 2018. Our Information Assurance Forum (IAF) considers issues from a multi-disciplinary perspective by working with colleagues in areas/HQ Directorates and maintains links between IA specialists in the Security and Information Assurance Division (SIAD) to enable the swift exchange of information as well as feeding directly into the IGG.

Our Information Governance Group (IGG) has been expanded to ensure all aspects of the business are represented and provides assurance to the Executive Group and the Audit Risk and Assurance Committee with regards our compliance with the Data Protection Act 2018. Our Information Asset Owners (IAO) Network is well established and assists our senior leaders to effectively carry out this key role. Supported by local Data Assurance Forums, their Security and Information Managers and our ‘Security and Information Assurance Framework’, they now have a comprehensive appreciation of compliance across their business unit. The SIRO and Data Protection Officer meet each of the IAOs bi-annually to review progress and agree future goals.

All data protection policies and guidance are regularly reviewed by SIAD’s Policy Review Board on behalf of the IGG. By assisting project teams undertaking data protection impact assessments, we have ensured all new systems comply with data protection legislation which has helped further embed a culture of ‘data protection by design and default’. The Data Protection and Compliance Team (DCPT) have embedded a new improved Data Protection Impact Assessment process, developing a streamlined two-stage approach which enables identification issues that require remedial action in order for the programme/project to be GDPR/DPA compliant.

We have delivered an entirely bespoke training on data protection legislation for all staff which included law enforcement processing; a compliance rate of 99% was achieved. We have actively contributed to developments on redaction which included an urgent review of the joint police/ CPS guidance for ‘front line staff’, ensuring our guidance compliments and supports the Attorney General’s Legal Guidance on Disclosure.

Information assurance and compliance

The CPS compliance rate statistics for information requests are as follows:

Freedom of Information Requests (FOIs)

01 April 2022 to 31 March 2023

01 April 2021 to 31 March 2022

Number received

740

708

Number responded within deadline (either 20 working days or PIT extension)

648

605

Compliance rate

88%

85%

Rights of Access Requests (ROARs)01 April 2022 to 31 March 202301 April 2021 to 31 March 2022
Number received

495

504

Number responded to within deadline

450

395

Compliance rate

91%

78%

GDPR rights requests01 April 2022 to 31 March 202301 April 2021 to 31 March 2022
Number received

12

24

Number responded to within deadline

12

24

Compliance rate

100%

100%

CPS legacy case records for national interest

To meet the CPS’ obligations under the Public Records Act 1958 and 20-Year Rule transition timetable, the Records Management Team (RMT) selected 20 legacy prosecution case files (937 pieces) from 1996 and transferred them to The National Archives (TNA).

For years 1997 and 1998, 47 case files (1,220 pieces) have been selected and prepared for transfer to TNA during 2023/24.

For years 1999 to 2002, 56 cases have been selected and are in the process of preparation for transfer to TNA. It is expected cases from 1999 will be transferred in 2023/24.

Personal data-related incidents

A summary of protected personal data-related incidents formally reported to the Information Commissioner’s Office (ICO) in 2022-23 is set out below.

Personal data incidents reported to the ICO in 2022-23:

Date of incident (month)Nature of incidentNature of data involvedNumber of people potentially affected
April to June 20226 Data Handling Losses
4 Unauthorised Disclosures
Case Information
Hardcopy Papers
USB containing Exhibits
Court Bundles
Trial Packs
Incorrect PNC Print
Contractor who did not have required licence

43

Operational Security Notified and Breaches reported to the ICO. Ten breaches closed by ICO-no regulatory action taken.
July to September 20222 Data Handling Losses
1 Unauthorised Disclosure
Archived Case Files
Court Bundles
Case Information

5

Operational Security Notified and Breaches reported to the ICO. Three Breaches closed by ICO-no regulatory action taken.
October to December 20221 Data Handling LossLibra List

36

Operational Security Notified and Breaches reported to the ICO. One Breach closed by ICO-no regulatory action taken.
January to March 2023NoneNone

0

None

A summary of personal data incidents in 2022-23 is set out below.

Total personal data incidents in 2022-23:

CategoryTotal reportedExplanatory note
Data Handling Losses

76

In 54 of these incidents the data loss was very minor and eventually recovered.
Unauthorised disclosure

2,445

In 2,367 of these incidents, the data loss was very minor or retained within the criminal justice profession, who are bound to professional standards of data protection.
Lost/Stolen ICT Equipment

34

In all 34 of these incidents the devices were successfully deactivated. All devices were encrypted to the government standard; therefore, no CPS data has been compromised.

Statement of Accounting Officer’s responsibilities

Under the Government Resources and Accounts Act 2000, HM Treasury has directed the CPS to prepare, for each financial year, accounts detailing the resources acquired, held or disposed of during the year and the use of resources by the Department during the year. The accounts are prepared on an accruals basis and must give a true and fair view of the state of affairs of the CPS and of its income and expenditure, Statement of Financial Position and cash flows for the financial year.

In preparing the accounts, the Accounting Officer is required to comply with the requirements of the Government Financial Reporting Manual and in particular to:

  • observe the Accounts Direction issued by HM Treasury, including the relevant accounting and disclosure requirements, and apply suitable accounting policies on a consistent basis;
  • make judgements and estimates on a reasonable basis;
  • state whether applicable accounting standards as set out in the Government Financial Reporting Manual have been followed, and disclose and explain any material departures in the accounts;
  • prepare the accounts on a going concern basis; and

HM Treasury has appointed the Director of Public Prosecutions as Accounting Officer of the Department, and the Director of Public Prosecutions has appointed the Chief Executive Officer as an additional Accounting Officer. This appointment does not detract from the Director of Public Prosecutions’ overall responsibility as Accounting Officer for the Department’s accounts.

The responsibilities of an Accounting Officer, including responsibility for the propriety and regularity of the public finances for which the Accounting Officer is answerable, for keeping proper records and for safeguarding the CPS’ assets, are set out in Managing Public Money published by HM Treasury.

The Accounting Officer confirms that he has taken all the steps that he ought to have taken to make himself aware of any relevant audit information and to establish that the CPS’ auditors are aware of that information. So far as he is aware, there is no relevant audit information of which the auditors are unaware.

The Accounting Officer confirms that the Annual Report and Accounts as a whole is fair, balanced and understandable and he takes personal responsibility for the Annual Report and the judgements required for determining that it is fair, balanced and understandable.

Governance statement

This Governance Statement sets out the CPS’ governance, risk and assurance management and internal control framework and how, during 2022-23, we managed the significant risks to the achievement of our strategic objectives. We ensure that robust governance arrangements are in place to promote high performance and safeguard probity and regularity. The CPS is a Non-Ministerial Department that is not subject to the protocol on enhanced departmental boards but has sought to comply as far as possible with the practices set out in Cabinet Office’s and HM Treasury’s Corporate Governance Code of Good Practice. Details of attendance at the CPS’ boards and committees are given in the Directors’ report above.

Governance framework

The CPS Board

The primary function of the CPS Board is to agree the strategic direction and priorities for the CPS, and to provide a forum for constructive challenge on proposals and the implementation of decisions by the Executive Group. The Board plays a key role in ensuring that the CPS is equipped to provide a professional, efficient and high-quality service.

The Cabinet Office’s and HM Treasury’s Corporate Governance Code of Good Practice provides guidance on Board composition and remit. In response to the findings of an external Board Effectiveness Evaluation review, completed in 2022, the role of the Board was altered to ensure it had more oversight of strategy and could assess its delivery. The Board also has a role in the oversight of the talent and culture of the CPS, it monitors performance and outputs and provides leadership to the organisation.

This year the Board has considered a number of key issues. The Board received regular updates on the progress of the Victims Transformation Programme, the issues around implementation of the Common Platform, the Casework Quality Strategy and on developments from the first phase of the Disproportionality research.

To ensure the Board is satisfied with the quality of data it receives, the Board has worked closely with performance management teams throughout the development of the quarterly highlight report and has dedicated itself to the CPS’s ongoing commitment to transparency on prosecution performance. The Board has also been closely involved in the development of business plan reporting, which continues to track progress against the CPS 2025 values and on its Spending Review commitments.

A key focus for the Board remains operational recovery and the mechanisms in place to monitor overall resourcing and the structures to manage inflated caseloads.

Audit and Risk Assurance Committee (ARAC)

The Audit, Risk & Assurance Committee (ARAC) is accountable to the CPS Board. It has delegated responsibility and authority for advising the Board on key elements of effectiveness linked to risk management, assurance management and the framework of internal control. The ARAC also reviews the comprehensiveness and reliability of assurances provided by internal audit, external audit, and the Executive Group, and challenges where necessary when gaps in processes are identified and where weaknesses are exposed.

Nominations, Leadership and Remuneration Committee (NLRC)

The Nominations, Leadership and Remuneration Committee (NLRC) is accountable to the CPS Board. It has delegated responsibility and authority for advising the Board on key elements of effectiveness linked to organisational culture and leadership strategies. This includes ensuring that leadership strategies and senior organisational design are fit for purpose and that there are robust systems in place to identify and develop senior leaders from diverse talent pools, draw up appropriate workforce and succession plans, and scrutinise incentive structures.

Executive Group (EG)

The Executive Group comprises the most senior members of CPS staff. It oversees the CPS’s overall performance and delivery and focuses on strategic leadership, management, direction, and ensuring the most effective prioritisation of resources. EG, as the executive management team of the CPS, informs and acts on decisions taken by the Director of Public Prosecutions and the Chief Executive Officer and takes collective decisions on key corporate issues affecting the CPS.

Risk management

The early identification and effective management of risk is fundamental to the achievement of our mission, goals, and strategic objectives. Our approach encompasses managing risk across all our activities at operational, tactical, and strategic levels.

Risk management and risk profile

For the CPS to meet the changing demands of the criminal justice system and fulfil our stakeholders’ expectations, we need to give the highest priority to risk across all levels of the organisation and ensure it is aligned with the achievement of our objectives.

In CPS, Risk Management is aligned to best practice from the Treasury’s ‘Orange Book’. This is underpinned by risk management processes designed to inform business decisions; enable more effective use of resources; enhance strategic and business plans; and strengthen contingency planning.

Effective governance of the process allows for escalation and reporting of risk to appropriate tiers of management including the Performance and Risk Group, Executive Group, Audit and Risk Assurance Committee, and the Board. Additionally, the Integrated Internal Audit programme and work of HM Crown Prosecution Service Inspectorate is informed by regular mapping to ensure adequate coverage of all key areas of risk.

Risk appetite statement

The CPS has a very low risk appetite towards any risk likely to result in the miscarriage of justice, that would expose the CPS to significant reputational damage, or that risks a material financial loss.

Key risk activities planned and in progress

During 2022-23, the CPS continued to strengthen its risk management framework and carried out the following key activities:

  • Integrated, improved, and simplified the Risk Management Framework with CPS purpose across all levels of the organisation to manage potential threats and existing issues, and deliver benefits for CPS stakeholders.
  • Risk management reviews have been carried out on all strategic risks with the respective Senior Risk Owners and ongoing work is in place to actively monitor risk progression in relation to the effectiveness of mitigations.
  • Risk training, risk workshops and risk reviews have been carried out and will continue to run over the next year with the aim of increasing risk maturity in the CPS. All senior civil servants have undertaken specific mandatory training aimed at improving their understanding of and management of risk at all levels.
  • In-depth reviews of risk returns are carried out quarterly, as well as regular deep dives into specific areas on a rolling basis. These activities measure the key risk themes coming from each CPS Area and Directorate and allow the Executive team to monitor the risk landscape at both a corporate and operational level.

Roles and responsibilities

The CPS Board has overall responsibility for our risk appetite, determining the amount and type of risk that we are willing to take to meet our strategic objectives.

The Director of Public Prosecutions and our Chief Executive Officer (as Accounting Officers) are accountable to Parliament for ensuring that all risks are managed effectively. On their behalf, the Chief Finance Officer and the Risk Management Team coordinate the deployment of risk management arrangements, ensure consistency of approach, and periodically report the top risks to the Executive Group, Audit and Risk Assurance Committee and the Board.

Ownership of risk registers is assigned to relevant senior managers, and individual risks are owned by the most appropriate team or individual.

Corporate performance, including current risk and financial metrics, is reviewed monthly by the Performance and Risk Group, with a formal review of the top risks presented to the Executive Group on a quarterly basis to agree the required controls and mitigating actions required to reduce risks to within tolerance levels and to consider emerging issues.

The Audit and Risk Assurance Committee, which meets quarterly, provides oversight of corporate risks, reviewing the status and the progress of mitigations identified by the risk owners.

The Board formally reviews key risks, and the risk landscape is used to inform the business strategy and the audit programmes to aid management in the delivery of business objectives.

Individual risks are assessed using our Enterprise Risk Management methodology under one of 10 underlying risk themes.

risk themes: Information Management, Casework & Legal Decision Making, Security &
Digital Technology, Fraud, Governance & Compliance, Health & Safety, Financial Management, Public
Confidence, Service to Victims, Capability, People & Resources

Our principal risks

Risk ThemeRisk DescriptionKey Activities to Manage Our RiskRisk Assessment and Direction of Assurance

Information Management

Public  Confidence

Security and Information Management, Training and Governance:

Sensitive case information relating to victims or witnesses could be disclosed in error, placing them at risk.

  • CPS’s formal steering group continues to have oversight of all information governance performance and activities across the whole organisation.
  • The vast majority of data transfers from within criminal justice system networks happens via Egress rather than physical removable media device.
  • The procedures for granting, monitoring and restricting access to removable media are formally documented.
  • Mandated information governance training is updated and rolled out across the organisation every year, with compliance monitored to ensure completion.

This is identified as a severe risk where CPS has a very low risk appetite.

Mitigating actions are ongoing to bring this risk within tolerance levels and prevent escalation.

Security & Digital Technology

Public Confidence

Cyber Security:

Our data or infrastructure is compromised by hostile cyber activity leading to potential major disruption to core business operations, risk to life if sensitive data is breached and significant reputational damage and loss of partner and public confidence.

  • CPS has an advanced threat intelligence service as part of our Security Operations Centre. We focus on continuing to increase our pro-active monitoring of potential threats.
  • All digital procurement requires that suppliers provide a rigorously security- assured service, and we conduct regular health checks and penetration checks as matter of course.
  • Cyber skills and education training continues to be provided to all Information Asset Owners.
  • We continue to engage with the National Cyber Security Centre for advice, guidance and best practice updates.
We continually review our cyber security reliance to address cyber risk and maintain all digital technology risks within tolerance levels.

Casework & Legal Decision Making

Public Confidence

Rape and Strategic Partnerships:

Ongoing political and public scrutiny of the historically low
numbers of rape cases prosecutions, with government targets for a return to 2016- 17 volumes by the end of this Parliament.
Scorecards are to be introduced which will include metrics for investigation, prosecution, and the courts. This could lead to increased levels of political scrutiny, negative media coverage and reputational damage.

  • An extensive programme of stakeholder and partner engagement continues to be a priority action as part of our RASSO 2025 strategy, to build understanding of our work and increase levels of trust with influential partners in order to improve co- operation.
  • We have published a digital walkthrough and public focused material for victims of rape and serious sexual offences.
  • Joint National Action Plan, (JNAP) developed to better address all aspects of this type of offending launched and publicised internally and externally.
We continue to work with partners across the criminal justice system and through implementation of the RASSO strategy we are determined to drive up the number of rape cases that are going to court.

Service to Victims

Public Confidence

Operational Recovery & Improvement:

Resources and ways of operating effectively under COVID-19 conditions have created backlogs resulting in increased organisational stress and resilience issues to the operational management of casework.

  • A menu of pressure easing measures has been invoked in Areas, Casework Divisions and CPS Direct. CPS has secured funding under SR21 to continue recruitment of additional front-line staff.
  • Working with Resident Judges, we triage cases in backlogs to assess cases being listed for trial. The priority is custody cases awaiting trial.
  • We continue to conduct cross-agency meetings from senior leadership down, including the Joint Operational Improvement Board and bilaterals with senior judiciary, courts and police.

Court backlogs that have materialised during the COVID-19 pandemic
have led to unacceptable delays in the delivery of justice.

Our continued engagement with partners across the Criminal Justice System in operational recovery is beginning to make progress.

Capability, People & Resources

Change Management:

CPS is unable to realise the benefits associated with the change as there is not the capacity to accept and embed the changes.

  • We are committed to developing an organisation-wide portfolio management capability to mitigate this risk. A change portfolio overview forum has been created and is meeting regularly to review the organisation’s capacity and capability to deliver and embed change.
  • An advisory audit undertaken by GIAA on the CPS’ Management of the Portfolio of Change has been undertaken to highlight immediate areas of focus. The Report endorsed the current approach being taken to change in the various existing change teams e.g. “hub and spoke” arrangements, noting the requirement to join this up more through the development of the portfolio office.
We continually review this risk through internal governance fora, and work with our strategic partners across government to ensure that we are aware of, and able to react to, changes in policy or direction external to CPS.
Capability, People & Resources

Our People:

CPS does not have the right people with the right skills who are engaged and empowered to deliver high quality casework outcomes.

  • We have improved workforce planning with engagement from local leaders and all those involved across the CPS in workforce planning.
  • Leadership and management development is aligned with our strategic people ambition and supports a thrive culture.
  • We continue to engage with Departmental Trade Union Side at national and area level plus change programme specific engagement at early opportunities.
  • Formalise Hybrid working environment to support development of CPS desired culture which will help employees thrive as well support attraction, retention and inclusion.

We continually review this risk at both strategic and operational levels to manage recruitment and workforce planning over the medium to long term.

We engage regularly with strategic partners cross-government to ensure our forecasts are impacted with the latest information in a timely fashion.

Service to Victims

Supporting Victims:

Victims lack trust in the CPS and wider criminal justice system to serve justice.

  • We have conducted a fundamental review of the way we deal with victims to ensure that the CPS response is better focused and properly aligned with our role as a modern prosecution service, and that quality is improved.
  • We are developing a CPS Victims Strategy setting out wide-ranging plans to improve the service to victims.
  • We are producing virtual guides for victims in different languages showing the prosecution process from start to finish to improve public understanding of the process.
  • Information provided to victims is in a timely manner and outlines the stage of the process.
Although quality and timeliness of communications with victims continues to improve it is below levels of aspiration.

All risks that fall outside CPS risk tolerance are periodically reviewed by the Audit and Risk Assurance Committee to ensure effective mitigation is ongoing with a view to bringing these appropriately back within tolerance. Our risks are largely inherent to our business or are long- term risks so the risk levels are unchanged in 2022-23. Our work has prevented deterioration of the risk level but at this time it is not appropriate to downgrade them whilst work is ongoing to prevent further escalation.

Identifying and managing conflicts of interest

The Civil Service Management Code sets out standards of propriety expected of civil servants in respect of external interests. The CPS has a policy in place for the declaration and management of interests for all staff, which includes declaration of any interests that may give rise to a conflict or perceived conflict of interest and adheres to the requirements of the Code. In addition to the established processes in place for managing interests, an annual audit exercise takes place which requires all staff to make a declaration of any private, personal or financial interests or, for those in SCS and equivalent grades and senior employees in a Commercial role, to make a nil declaration. Where a conflict or perceived conflict of interest arises, these will be recorded, considered assessed and managed by appropriate senior managers with the support of Risk and HR practitioners.

Business appointments

In compliance with business appointment rules, the CPS is transparent in the advice given to individual applications for senior staff, including special advisers. None of the SCS leavers in 2022-23 required a BAR application and/or conditions set.

His Majesty’s Crown Prosecution Service Inspectorate

His Majesty’s Crown Prosecution Service Inspectorate inspects the Crown Prosecution Service and the Serious Fraud Office. It provides independently assessed evidence to help drive improvement and build public confidence in the prosecution process.

HMCPSI priorities for inspection are set out in an annual Business Plan and it reports annually to the Attorney General on the performance of the CPS, in addition to other individual and thematic inspection reports.

As part of HMCPSI’s Area Inspection Programme, all 14 CPS Areas were subject to a baseline inspection and will have a follow-up inspection within two-years. No recommendations were made in the baseline reports.

During 2022-23, HMCPSI completed ten inspections which are summarised below. The full responses from CPS to the reports are available online at https://www.cps.gov.uk/publication-type/cps-responses-hmcpsi.

Yorkshire & Humberside Area Inspection Programme Baseline Report – published 5 April 2022

Inspectors found that there was good grip of Crown Court cases, which generally progressed efficiently and effectively. This grip was noted as “truly impressive in the circumstances” of a large increase in cases being received from the police and the additional challenges resulting from the pandemic. The report commended the Area’s Rape and Serious Sexual offences team for seeking appropriate orders on sentencing, and also for making correct charging decisions in 100% of its cases.

Wessex Area Inspection Programme Baseline Report – published 12 April 2022

The Inspectors have set out fairly the context, and caseload and resourcing pressures that the Area was dealing with at the time of the inspection. The Inspectors noted that as the unique pressures of the pandemic ease, and recruitment increases to the necessary levels, the Area should be in a good position to build on the aspects which currently meet the casework quality standards, and to improve the quality of casework right across the business.

London North Area Inspection Programme Baseline Report – published 6 May 2022

This report noted the context of Area challenges arising from the pandemic, including a significant increase in caseload and substantial backlogs in the Crown Court. The inspection identified that the Area adds value through its code compliant decision making in Magistrates and Crown Court casework, with good evidence of grip in the Magistrates Court with clear audit trails of key events, decisions and action taken, and in the Crown Court, inspectors agreed with all decision making regarding handling of pleas.

South West Area Inspection Programme Baseline Report – published 25 August 2022

The report recognises the hard work and dedication of all staff in the Area and the joint working with criminal justice agencies to sustain and improve performance despite the challenging operating environment created by the COVID-19 pandemic. The Inspectors noted that as pressures ease and the recruitment position stabilises, the Area should be in a good position to build on the aspects highlighted for improvement within the report.

Mersey-Cheshire Area Inspection Programme Baseline Report – published 29 September 2022

The report recognises the strengths of the Area particularly around sound legal decision making and the value-add to casework. The Area acknowledge there are improvements to be made and are committed to addressing these over the next twelve months. The Area have previously identified areas for improvement which accord with those of HMCPSI.

East Midlands Area Inspection Programme Baseline Report – published 13 October 2022

Inspectors recognised the Area’s grip in some of the most challenging cases, with examples of excellent casework across all units. The service provided to victims and witnesses was also described as a real strength. Inspectors found constructive engagement with all 5 police forces and commended the Area for continued direct engagement with the defence. Inspectors highlighted the focus on staff well-being during the time of unprecedented pressures which had a positive impact on staff engagement.

North West Area Inspection Programme Baseline Report – published 27 October 2022

The report recognises the hard work of all staff in the North West Area and the joint working with criminal justice agencies to sustain and improve performance and service to the communities of Greater Manchester, Lancashire and Cumbria. Inspectors recognised that the Area maintained a good grip of casework, especially in the face of unprecedented challenges caused by the pandemic. The Area had already identified most of the aspects that required improvement and have taken steps to address them.

Thames and Chiltern Area Inspection Programme Baseline Report – published 10 November 2022

The Inspectorate focused on the quality of casework, finding that the Area makes charging decisions that reflect the gravity of offending, consults with victims well, handles correspondence from the courts, defence and police in a timely way, and has effective stakeholder relationships. Against a backdrop of increased caseloads and challenges in recruiting new staff, the Inspectorate commended the Area for reacting quickly to the pandemic and for its ongoing operational recovery work with partners.

Additionally, HMCPSI conducted the following thematic and joint inspections:

The impact of the Covid-19 pandemic on the criminal justice system – a progress report – published 17 May 2022

This was a joint CJS Inspectorate progress report to the January 2021 ‘state of the nation’ report on the criminal justice system (CJS) and was based on combined inspection findings over the previous year, when the COVID-19 pandemic severely disrupted services.

The report highlights the demands placed on our people to manage increased workloads as part of the recovery phase and the sustainability of this environment without building up wellbeing or morale issues. Inspectors recognised the significant levels of recruitment being undertaken to mitigate these issues alongside strong management and corporate support to best balance the health, safety, and wellbeing of our people. It was also noted how CPS Areas consistently applied well-structured induction programmes to onboard people in an effective manner.

There were no recommendations or aspects for improvement in this report.

The service from the CPS to victims of domestic abuse – published 30 March 2023

This is a thematic inspection of the handling by the Crown Prosecution Service of domestic abuse cases in the magistrates’ courts. HMCPSI have recognised the passion and commitment of CPS staff locally and nationally to achieve the best possible outcome for victims. Overwhelmingly, our prosecutors are making decisions in accordance with our Code.

CPS, together with the NPCC leads, are working collaboratively with stakeholders to develop a domestic abuse Joint Justice Plan that will improve the investigation, prosecution, and collective handling of domestic abuse to better secure justice for victims.

There are 6 recommendations from the report and we will continue to work with CJS partners to deliver the recommendations.

Commercial arrangements

The CPS Commercial Policy sets out the governance for our commercial activity, ensuring legal compliance to Public Contract Regulations, Cabinet Office spend controls and delegated authority limits which are structured around value and risk of the procurement or contract change involved.

Out Policy and Governance team have supported implementation of the policy across CPS including the roll out of a full package of commercial training courses which commenced in 2021‐22 and will continue into the 2023-24 financial year.

The policy is supported by a robust approval framework with gateways encompassing the full commercial lifecycle from concept through to contract exit. The introduction of Strategic Sourcing specialisms has enabled earlier engagement with the business, resulting in an enhanced understanding of our commercial pipeline. This has created better assessment of ‘make’ or ‘buy’ decisions and greater engagement with the marketplace to better understand our requirements.

Commercial are integral to the business case process, both for internal approvals via the Investment Committee and for Cabinet Office and Treasury controls. This ensures the right commercial risks are raised at business planning stage to ensure that appropriate mitigation measures are identified, implemented, and monitored throughout the commercial lifecycle. The Commercial function are also represented on internal governance boards to provide commercial insight and oversight, thereby ensuring that compliance is maintained, and the most advantageous commercial model is delivered to the CPS.

The CPS and AGO have worked together again this year to produce our Anti Modern Slavery statement to be incorporated into a cross-government document. We achieved all the targets we laid out in the 2021‐22 statement and exceeded this year’s risk assessment target to review our most strategically important and highest value contracts, by risk assessing our entire contract portfolio. We have also provided our team invaluable insight by harnessing our prosecution colleagues’ experiences to bring some of the complex crimes to life. This had a real impact on our commercial team as it highlighted how important the work, they are doing with our supply chain is to ensure vulnerable workers are protected and exploitation is eradicated.

Review of effectiveness

The Accounting Officer has responsibility for reviewing the effectiveness of the system of internal control in the CPS.

His review is informed by the work of Internal Audit and members of the Executive Group, which has responsibility for the development and maintenance of the internal control framework, and comments and recommendations made by the external auditors in their annual management letter and other reports.

The Chief Executive Officer or Corporate Services Lead Director acts as an Additional Accounting Officer of the CPS.

Assurance audits

The CPS uses the Government Internal Audit Agency (GIAA) to provide objective insight aimed at helping achieve better outcomes and value for money for the public. In 2022-23 GIAA assessed the overall level of assurance in the CPS as a whole to be ‘moderate’. This reflects that some improvements were identified to further enhance the adequacy and effectiveness of the framework of governance, risk management and control.

Internal Audit use a four-point scale in assessing the level of assurance:

Substantial The framework of governance, risk management and control is adequate and effective.
Moderate Some improvements are required to enhance the adequacy and effectiveness of the framework of governance, risk management and control.
Limited There are significant weaknesses in the framework of governance, risk management and control such that it could be or could become inadequate and ineffective.
Unsatisfactory There are fundamental weaknesses in the framework of governance, risk management and control such that it is inadequate and ineffective or is likely to fail.

The following table represents the high-level outcomes achieved for each of the areas audited during 2022-23:

Area of inspection

Outcome from review of effectiveness

Date report finalised

Cyber Security

MODERATE

June 2022

Records Management

LIMITED

June 2022

Contract Management

LIMITED

September 2022

Right of Access Requests

SUBSTANTIAL

November 2022

Payroll

MODERATE

January 2023

Oracle

MODERATE

January 2023

Hybrid Working

SUBSTANTIAL

February 2023

Strategic Recruitment

SUBSTANTIAL

March 2023

Digital Supplier Disaggregation

LIMITED

April 2023

Based on the above, it is concluded that there were some weaknesses in the CPS’ governance and control framework that affected achievement of its strategic objectives in 2022-23, but that these can be rectified through actioning GIAA’s recommendations.

Advisory audits

As well as the above assurance audits, the GIAA also conducted one advisory audit during 2022-23. Advisory audits involve GIAA working together with subject matter experts from across the CPS in an advisory role and are not subject to an opinion. The advisory audit carried out in 2022-23 was in respect of Digital Upskilling, with the report being issued in February 2023.

  1. Rebecca Lawrence was absent from 26 September 2022 to the end of the financial year, and as a consequence the Interim CEO took up the Additional Accounting Officer role for that period
Loading...