Corporate governance report
Directors’ report
The Directors’ report provides information on the senior leadership of the CPS, including membership of the key governance bodies. It additionally reports on information security, including personal data related incidents that have been reported to the Information Commissioner’s Office (ICO).
Membership of boards and committees
| April 2022 – March 2023 | Meetings | ||
|---|---|---|---|
| Members | CPS Board | Audit and Risk Assurance Committee | Nominations, Leadership and Remuneration Committee |
| Non-Executive Board Members | |||
| Caroline Wayman Non-Executive Board Member (contract ended 31/05/2022) | 1/1 | - | 1/1 CHAIR |
| Simon Jeffreys Non-Executive Board Member | 8/8 | 4/4 CHAIR | - |
| Mark Hammond Non-Executive Board Member | 8/8 | 3/4 | - |
| Monica Burch Non-Executive Board Member | 8/8 CHAIR | - | 4/4 |
| Dr Subo Shanmuganathan Non-Executive Board Member (from 03/10/2022) | 4/4 | 2/2 |
|
| Kathryn Stone OBE Non-Executive Board Member (from 03/10/2022) | 1/4 | - | 1/2 |
Independent ARAC Members | |||
Michael Dunn | - | 4/4 | - |
Deborah Harris | - | 4/4 | - |
Executive Board Members | |||
Max Hill KC | 8/8 | 3/4 | 4/4 |
Rebecca Lawrence1 | - | 1/1 | 1/1 |
Sue Hemming1 | 5/5 | 2/2 | 2/2 |
| April 2022 – March 2023 | Meetings |
|---|---|
| CPS Executive Group |
|
| Rebecca Lawrence1 Chief Executive Officer | 2/2 |
| Max Hill KC Director of Public Prosecutions | 10/11 |
| Gregor McGill Director of Legal Services | 9/11 |
| Sue Hemming1 Interim Chief Executive Officer (from 26/09/2022) previously Director of Legal Services | 9/11 |
| Mark Gray Chief Digital and Information Officer | 10/11 |
| Dawn Brodrick Chief People Officer | 8/11 |
| Baljit Ubhey Director of Strategy and Policy | 11/11 |
| Steve Buckingham Chief Finance Officer | 11/11 |
| Sandra McKay Director of Communications | 11/11 |
| Grace Ononiwu Director of Legal Service | 8/11 |
| Tristan Bradshaw Interim Director Operational Change & Delivery | 5/5 |
Security and information assurance
We apply proportionate security controls as outlined in the Government Functional Standard (GOVS007). Our compliance with the standard is reported to the Cabinet Office in the annual Departmental Security Health Check (DSHC) and is assessed against ‘Minimum Security Standards’ for Cyber, Incident Management, Personnel and Physical. In 2022, the Cabinet Office concluded that as an overall rating we are 99.1% compliant with the GOVS007 Standards.
We ensure all projects and programmes put in place appropriate technical and organisational measures to implement the data protection principles effectively and safeguard individual rights. Cross CPS collaboration ensures that innovation is encouraged but managed securely; where necessary, we consult with the Regulator.
Cyber security
The Cyber Security Team (CST) continue to consolidate our resilience to cyber-attacks and data compromise. Their new cyber security incident response plan and playbooks have further increased our capability to successfully respond to such incidents. During the year, the Team responded to several attacks affecting criminal justice partners which threatened to compromise us. In August 2022, they worked with police colleagues in response to a ransomware attack on a firm of solicitors. Utilising our response plan, we took pre-emptive action to block their email domains and thereby ensured that the CPS suffered no detrimental impact.
CST are now joint chairs of a legal sector Security Working Group (SWG) with NCSC which includes the Bar Council, Law Society, Legal Aid Authority and Ministry of Justice. The Group aims to increase joint understanding of cross sector risks and our overall capacity to withstand attacks. The Group is currently focussing on Business Email Compromise (BEC) and cyber hygiene.
In July 2022, the Government Internal Audit Agency (GIAA) provided their report on the CPS’ cyber security; they judged our performance as ‘Moderate’, the second highest rating.
The team have developed a Cyber Security Education, Training & Awareness (CSETA) programme for all our staff. It is a rolling 12-month programme which includes 3 mandatory assessments and is designed to increase cyber knowledge and awareness. We have already seen the benefit of continuous cyber training; a sustained focus on cyber security awareness, which includes frequent phishing campaigns, has enhanced the security culture across our workforce.
We have reduced the threat of a cyber security supply chain attack by requiring all suppliers to complete a Security Management Plan (SMP) and Assurance Questionnaire. This best practice approach provides assurance to SIAD with regards to the supplier, in their service required deliverables to the CPS. The CPS approach has since been adopted by another Government Department.
Operational security
The Operational Security Team (OST) continues to work with the business to ensure the rigorous application of security standards, as outlined in the GovS007 Functional Standard. Area based Security & Information Managers have now been embedded across the department. Their compliance with government security standards is reported annually through the Security & Information Assurance Framework, aligned to the GovS007 minimum standards. This, in turn, forms the basis of our Departmental Security Health Check report to the Cabinet Office. The CPS continues to perform well in the DSHC; exceeding the baseline assessment scores in all areas.
We have undertaken an organisation-wide vetting review. All CPS roles have been assessed to ensure appropriate vetting levels, proportionate to risk. The review will provide the framework for our transition to new vetting levels.
Business continuity
The CPS’ Business Continuity (BC) capabilities and resilience remain consistently high and are regularly tested. In November 2022, we worked with digital colleagues to assess our operational response to various IT failures across the CPS. We have also participated in several cross-government exercises. We review our BC plans as part of the testing regime or following a ‘live’ incident.
The GIAA reviewed our BC arrangements in May 2022 and assessed our performance as ‘Moderate’, the second highest rating.
General Data Protection Regulation (GDPR) and Data Protection Act 2018
We have continued to strengthen our data protection processes to ensure we optimise the value of the data we hold and comply with current legislation. Our Information Governance Group (IGG) has been expanded to ensure all aspects of the business are represented and provides assurance to the Executive Group and the Audit Risk and Assurance Committee with regards our compliance with the Data Protection Act 2018. Our Information Assurance Forum (IAF) considers issues from a multi-disciplinary perspective by working with colleagues in areas/HQ Directorates and maintains links between IA specialists in the Security and Information Assurance Division (SIAD) to enable the swift exchange of information as well as feeding directly into the IGG.
Our Information Governance Group (IGG) has been expanded to ensure all aspects of the business are represented and provides assurance to the Executive Group and the Audit Risk and Assurance Committee with regards our compliance with the Data Protection Act 2018. Our Information Asset Owners (IAO) Network is well established and assists our senior leaders to effectively carry out this key role. Supported by local Data Assurance Forums, their Security and Information Managers and our ‘Security and Information Assurance Framework’, they now have a comprehensive appreciation of compliance across their business unit. The SIRO and Data Protection Officer meet each of the IAOs bi-annually to review progress and agree future goals.
All data protection policies and guidance are regularly reviewed by SIAD’s Policy Review Board on behalf of the IGG. By assisting project teams undertaking data protection impact assessments, we have ensured all new systems comply with data protection legislation which has helped further embed a culture of ‘data protection by design and default’. The Data Protection and Compliance Team (DCPT) have embedded a new improved Data Protection Impact Assessment process, developing a streamlined two-stage approach which enables identification issues that require remedial action in order for the programme/project to be GDPR/DPA compliant.
We have delivered an entirely bespoke training on data protection legislation for all staff which included law enforcement processing; a compliance rate of 99% was achieved. We have actively contributed to developments on redaction which included an urgent review of the joint police/ CPS guidance for ‘front line staff’, ensuring our guidance compliments and supports the Attorney General’s Legal Guidance on Disclosure.
Information assurance and compliance
The CPS compliance rate statistics for information requests are as follows:
| Freedom of Information Requests (FOIs) | 01 April 2022 to 31 March 2023 | 01 April 2021 to 31 March 2022 |
|---|---|---|
| Number received | 740 | 708 |
| Number responded within deadline (either 20 working days or PIT extension) | 648 | 605 |
| Compliance rate | 88% | 85% |
| Rights of Access Requests (ROARs) | 01 April 2022 to 31 March 2023 | 01 April 2021 to 31 March 2022 |
| Number received | 495 | 504 |
| Number responded to within deadline | 450 | 395 |
| Compliance rate | 91% | 78% |
| GDPR rights requests | 01 April 2022 to 31 March 2023 | 01 April 2021 to 31 March 2022 |
| Number received | 12 | 24 |
| Number responded to within deadline | 12 | 24 |
| Compliance rate | 100% | 100% |
CPS legacy case records for national interest
To meet the CPS’ obligations under the Public Records Act 1958 and 20-Year Rule transition timetable, the Records Management Team (RMT) selected 20 legacy prosecution case files (937 pieces) from 1996 and transferred them to The National Archives (TNA).
For years 1997 and 1998, 47 case files (1,220 pieces) have been selected and prepared for transfer to TNA during 2023/24.
For years 1999 to 2002, 56 cases have been selected and are in the process of preparation for transfer to TNA. It is expected cases from 1999 will be transferred in 2023/24.
Personal data-related incidents
A summary of protected personal data-related incidents formally reported to the Information Commissioner’s Office (ICO) in 2022-23 is set out below.
Personal data incidents reported to the ICO in 2022-23:
| Date of incident (month) | Nature of incident | Nature of data involved | Number of people potentially affected | |
|---|---|---|---|---|
| April to June 2022 | 6 Data Handling Losses 4 Unauthorised Disclosures | Case Information Hardcopy Papers USB containing Exhibits Court Bundles Trial Packs Incorrect PNC Print Contractor who did not have required licence | 43 | Operational Security Notified and Breaches reported to the ICO. Ten breaches closed by ICO-no regulatory action taken. |
| July to September 2022 | 2 Data Handling Losses 1 Unauthorised Disclosure | Archived Case Files Court Bundles Case Information | 5 | Operational Security Notified and Breaches reported to the ICO. Three Breaches closed by ICO-no regulatory action taken. |
| October to December 2022 | 1 Data Handling Loss | Libra List | 36 | Operational Security Notified and Breaches reported to the ICO. One Breach closed by ICO-no regulatory action taken. |
| January to March 2023 | None | None | 0 | None |
A summary of personal data incidents in 2022-23 is set out below.
Total personal data incidents in 2022-23:
| Category | Total reported | Explanatory note |
|---|---|---|
| Data Handling Losses | 76 | In 54 of these incidents the data loss was very minor and eventually recovered. |
| Unauthorised disclosure | 2,445 | In 2,367 of these incidents, the data loss was very minor or retained within the criminal justice profession, who are bound to professional standards of data protection. |
| Lost/Stolen ICT Equipment | 34 | In all 34 of these incidents the devices were successfully deactivated. All devices were encrypted to the government standard; therefore, no CPS data has been compromised. |
Statement of Accounting Officer’s responsibilities
Under the Government Resources and Accounts Act 2000, HM Treasury has directed the CPS to prepare, for each financial year, accounts detailing the resources acquired, held or disposed of during the year and the use of resources by the Department during the year. The accounts are prepared on an accruals basis and must give a true and fair view of the state of affairs of the CPS and of its income and expenditure, Statement of Financial Position and cash flows for the financial year.
In preparing the accounts, the Accounting Officer is required to comply with the requirements of the Government Financial Reporting Manual and in particular to:
- observe the Accounts Direction issued by HM Treasury, including the relevant accounting and disclosure requirements, and apply suitable accounting policies on a consistent basis;
- make judgements and estimates on a reasonable basis;
- state whether applicable accounting standards as set out in the Government Financial Reporting Manual have been followed, and disclose and explain any material departures in the accounts;
- prepare the accounts on a going concern basis; and
HM Treasury has appointed the Director of Public Prosecutions as Accounting Officer of the Department, and the Director of Public Prosecutions has appointed the Chief Executive Officer as an additional Accounting Officer. This appointment does not detract from the Director of Public Prosecutions’ overall responsibility as Accounting Officer for the Department’s accounts.
The responsibilities of an Accounting Officer, including responsibility for the propriety and regularity of the public finances for which the Accounting Officer is answerable, for keeping proper records and for safeguarding the CPS’ assets, are set out in Managing Public Money published by HM Treasury.
The Accounting Officer confirms that he has taken all the steps that he ought to have taken to make himself aware of any relevant audit information and to establish that the CPS’ auditors are aware of that information. So far as he is aware, there is no relevant audit information of which the auditors are unaware.
The Accounting Officer confirms that the Annual Report and Accounts as a whole is fair, balanced and understandable and he takes personal responsibility for the Annual Report and the judgements required for determining that it is fair, balanced and understandable.
Governance statement
This Governance Statement sets out the CPS’ governance, risk and assurance management and internal control framework and how, during 2022-23, we managed the significant risks to the achievement of our strategic objectives. We ensure that robust governance arrangements are in place to promote high performance and safeguard probity and regularity. The CPS is a Non-Ministerial Department that is not subject to the protocol on enhanced departmental boards but has sought to comply as far as possible with the practices set out in Cabinet Office’s and HM Treasury’s Corporate Governance Code of Good Practice. Details of attendance at the CPS’ boards and committees are given in the Directors’ report above.
Governance framework

The CPS Board
The primary function of the CPS Board is to agree the strategic direction and priorities for the CPS, and to provide a forum for constructive challenge on proposals and the implementation of decisions by the Executive Group. The Board plays a key role in ensuring that the CPS is equipped to provide a professional, efficient and high-quality service.
The Cabinet Office’s and HM Treasury’s Corporate Governance Code of Good Practice provides guidance on Board composition and remit. In response to the findings of an external Board Effectiveness Evaluation review, completed in 2022, the role of the Board was altered to ensure it had more oversight of strategy and could assess its delivery. The Board also has a role in the oversight of the talent and culture of the CPS, it monitors performance and outputs and provides leadership to the organisation.
This year the Board has considered a number of key issues. The Board received regular updates on the progress of the Victims Transformation Programme, the issues around implementation of the Common Platform, the Casework Quality Strategy and on developments from the first phase of the Disproportionality research.
To ensure the Board is satisfied with the quality of data it receives, the Board has worked closely with performance management teams throughout the development of the quarterly highlight report and has dedicated itself to the CPS’s ongoing commitment to transparency on prosecution performance. The Board has also been closely involved in the development of business plan reporting, which continues to track progress against the CPS 2025 values and on its Spending Review commitments.
A key focus for the Board remains operational recovery and the mechanisms in place to monitor overall resourcing and the structures to manage inflated caseloads.
Audit and Risk Assurance Committee (ARAC)
The Audit, Risk & Assurance Committee (ARAC) is accountable to the CPS Board. It has delegated responsibility and authority for advising the Board on key elements of effectiveness linked to risk management, assurance management and the framework of internal control. The ARAC also reviews the comprehensiveness and reliability of assurances provided by internal audit, external audit, and the Executive Group, and challenges where necessary when gaps in processes are identified and where weaknesses are exposed.
Nominations, Leadership and Remuneration Committee (NLRC)
The Nominations, Leadership and Remuneration Committee (NLRC) is accountable to the CPS Board. It has delegated responsibility and authority for advising the Board on key elements of effectiveness linked to organisational culture and leadership strategies. This includes ensuring that leadership strategies and senior organisational design are fit for purpose and that there are robust systems in place to identify and develop senior leaders from diverse talent pools, draw up appropriate workforce and succession plans, and scrutinise incentive structures.
Executive Group (EG)
The Executive Group comprises the most senior members of CPS staff. It oversees the CPS’s overall performance and delivery and focuses on strategic leadership, management, direction, and ensuring the most effective prioritisation of resources. EG, as the executive management team of the CPS, informs and acts on decisions taken by the Director of Public Prosecutions and the Chief Executive Officer and takes collective decisions on key corporate issues affecting the CPS.
Risk management
The early identification and effective management of risk is fundamental to the achievement of our mission, goals, and strategic objectives. Our approach encompasses managing risk across all our activities at operational, tactical, and strategic levels.
Risk management and risk profile
For the CPS to meet the changing demands of the criminal justice system and fulfil our stakeholders’ expectations, we need to give the highest priority to risk across all levels of the organisation and ensure it is aligned with the achievement of our objectives.
In CPS, Risk Management is aligned to best practice from the Treasury’s ‘Orange Book’. This is underpinned by risk management processes designed to inform business decisions; enable more effective use of resources; enhance strategic and business plans; and strengthen contingency planning.
Effective governance of the process allows for escalation and reporting of risk to appropriate tiers of management including the Performance and Risk Group, Executive Group, Audit and Risk Assurance Committee, and the Board. Additionally, the Integrated Internal Audit programme and work of HM Crown Prosecution Service Inspectorate is informed by regular mapping to ensure adequate coverage of all key areas of risk.
Risk appetite statement
The CPS has a very low risk appetite towards any risk likely to result in the miscarriage of justice, that would expose the CPS to significant reputational damage, or that risks a material financial loss.
Key risk activities planned and in progress
During 2022-23, the CPS continued to strengthen its risk management framework and carried out the following key activities:
- Integrated, improved, and simplified the Risk Management Framework with CPS purpose across all levels of the organisation to manage potential threats and existing issues, and deliver benefits for CPS stakeholders.
- Risk management reviews have been carried out on all strategic risks with the respective Senior Risk Owners and ongoing work is in place to actively monitor risk progression in relation to the effectiveness of mitigations.
- Risk training, risk workshops and risk reviews have been carried out and will continue to run over the next year with the aim of increasing risk maturity in the CPS. All senior civil servants have undertaken specific mandatory training aimed at improving their understanding of and management of risk at all levels.
- In-depth reviews of risk returns are carried out quarterly, as well as regular deep dives into specific areas on a rolling basis. These activities measure the key risk themes coming from each CPS Area and Directorate and allow the Executive team to monitor the risk landscape at both a corporate and operational level.
Roles and responsibilities
The CPS Board has overall responsibility for our risk appetite, determining the amount and type of risk that we are willing to take to meet our strategic objectives.
The Director of Public Prosecutions and our Chief Executive Officer (as Accounting Officers) are accountable to Parliament for ensuring that all risks are managed effectively. On their behalf, the Chief Finance Officer and the Risk Management Team coordinate the deployment of risk management arrangements, ensure consistency of approach, and periodically report the top risks to the Executive Group, Audit and Risk Assurance Committee and the Board.
Ownership of risk registers is assigned to relevant senior managers, and individual risks are owned by the most appropriate team or individual.
Corporate performance, including current risk and financial metrics, is reviewed monthly by the Performance and Risk Group, with a formal review of the top risks presented to the Executive Group on a quarterly basis to agree the required controls and mitigating actions required to reduce risks to within tolerance levels and to consider emerging issues.
The Audit and Risk Assurance Committee, which meets quarterly, provides oversight of corporate risks, reviewing the status and the progress of mitigations identified by the risk owners.
The Board formally reviews key risks, and the risk landscape is used to inform the business strategy and the audit programmes to aid management in the delivery of business objectives.
Individual risks are assessed using our Enterprise Risk Management methodology under one of 10 underlying risk themes.

Our principal risks
| Risk Theme | Risk Description | Key Activities to Manage Our Risk | Risk Assessment and Direction of Assurance |
|---|---|---|---|
Information Management Public Confidence | Security and Information Management, Training and Governance: Sensitive case information relating to victims or witnesses could be disclosed in error, placing them at risk. |
| This is identified as a severe risk where CPS has a very low risk appetite. Mitigating actions are ongoing to bring this risk within tolerance levels and prevent escalation. |
Security & Digital Technology Public Confidence | Cyber Security: Our data or infrastructure is compromised by hostile cyber activity leading to potential major disruption to core business operations, risk to life if sensitive data is breached and significant reputational damage and loss of partner and public confidence. |
| We continually review our cyber security reliance to address cyber risk and maintain all digital technology risks within tolerance levels. |
Casework & Legal Decision Making Public Confidence | Rape and Strategic Partnerships: Ongoing political and public scrutiny of the historically low |
| We continue to work with partners across the criminal justice system and through implementation of the RASSO strategy we are determined to drive up the number of rape cases that are going to court. |
Service to Victims Public Confidence | Operational Recovery & Improvement: Resources and ways of operating effectively under COVID-19 conditions have created backlogs resulting in increased organisational stress and resilience issues to the operational management of casework. |
| Court backlogs that have materialised during the COVID-19 pandemic Our continued engagement with partners across the Criminal Justice System in operational recovery is beginning to make progress. |
| Capability, People & Resources | Change Management: CPS is unable to realise the benefits associated with the change as there is not the capacity to accept and embed the changes. |
| We continually review this risk through internal governance fora, and work with our strategic partners across government to ensure that we are aware of, and able to react to, changes in policy or direction external to CPS. |
| Capability, People & Resources | Our People: CPS does not have the right people with the right skills who are engaged and empowered to deliver high quality casework outcomes. |
| We continually review this risk at both strategic and operational levels to manage recruitment and workforce planning over the medium to long term. We engage regularly with strategic partners cross-government to ensure our forecasts are impacted with the latest information in a timely fashion. |
| Service to Victims | Supporting Victims: Victims lack trust in the CPS and wider criminal justice system to serve justice. |
| Although quality and timeliness of communications with victims continues to improve it is below levels of aspiration. |
All risks that fall outside CPS risk tolerance are periodically reviewed by the Audit and Risk Assurance Committee to ensure effective mitigation is ongoing with a view to bringing these appropriately back within tolerance. Our risks are largely inherent to our business or are long- term risks so the risk levels are unchanged in 2022-23. Our work has prevented deterioration of the risk level but at this time it is not appropriate to downgrade them whilst work is ongoing to prevent further escalation.
Identifying and managing conflicts of interest
The Civil Service Management Code sets out standards of propriety expected of civil servants in respect of external interests. The CPS has a policy in place for the declaration and management of interests for all staff, which includes declaration of any interests that may give rise to a conflict or perceived conflict of interest and adheres to the requirements of the Code. In addition to the established processes in place for managing interests, an annual audit exercise takes place which requires all staff to make a declaration of any private, personal or financial interests or, for those in SCS and equivalent grades and senior employees in a Commercial role, to make a nil declaration. Where a conflict or perceived conflict of interest arises, these will be recorded, considered assessed and managed by appropriate senior managers with the support of Risk and HR practitioners.
Business appointments
In compliance with business appointment rules, the CPS is transparent in the advice given to individual applications for senior staff, including special advisers. None of the SCS leavers in 2022-23 required a BAR application and/or conditions set.
His Majesty’s Crown Prosecution Service Inspectorate
His Majesty’s Crown Prosecution Service Inspectorate inspects the Crown Prosecution Service and the Serious Fraud Office. It provides independently assessed evidence to help drive improvement and build public confidence in the prosecution process.
HMCPSI priorities for inspection are set out in an annual Business Plan and it reports annually to the Attorney General on the performance of the CPS, in addition to other individual and thematic inspection reports.
As part of HMCPSI’s Area Inspection Programme, all 14 CPS Areas were subject to a baseline inspection and will have a follow-up inspection within two-years. No recommendations were made in the baseline reports.
During 2022-23, HMCPSI completed ten inspections which are summarised below. The full responses from CPS to the reports are available online at https://www.cps.gov.uk/publication-type/cps-responses-hmcpsi.
Yorkshire & Humberside Area Inspection Programme Baseline Report – published 5 April 2022
Inspectors found that there was good grip of Crown Court cases, which generally progressed efficiently and effectively. This grip was noted as “truly impressive in the circumstances” of a large increase in cases being received from the police and the additional challenges resulting from the pandemic. The report commended the Area’s Rape and Serious Sexual offences team for seeking appropriate orders on sentencing, and also for making correct charging decisions in 100% of its cases.
Wessex Area Inspection Programme Baseline Report – published 12 April 2022
The Inspectors have set out fairly the context, and caseload and resourcing pressures that the Area was dealing with at the time of the inspection. The Inspectors noted that as the unique pressures of the pandemic ease, and recruitment increases to the necessary levels, the Area should be in a good position to build on the aspects which currently meet the casework quality standards, and to improve the quality of casework right across the business.
London North Area Inspection Programme Baseline Report – published 6 May 2022
This report noted the context of Area challenges arising from the pandemic, including a significant increase in caseload and substantial backlogs in the Crown Court. The inspection identified that the Area adds value through its code compliant decision making in Magistrates and Crown Court casework, with good evidence of grip in the Magistrates Court with clear audit trails of key events, decisions and action taken, and in the Crown Court, inspectors agreed with all decision making regarding handling of pleas.
South West Area Inspection Programme Baseline Report – published 25 August 2022
The report recognises the hard work and dedication of all staff in the Area and the joint working with criminal justice agencies to sustain and improve performance despite the challenging operating environment created by the COVID-19 pandemic. The Inspectors noted that as pressures ease and the recruitment position stabilises, the Area should be in a good position to build on the aspects highlighted for improvement within the report.
Mersey-Cheshire Area Inspection Programme Baseline Report – published 29 September 2022
The report recognises the strengths of the Area particularly around sound legal decision making and the value-add to casework. The Area acknowledge there are improvements to be made and are committed to addressing these over the next twelve months. The Area have previously identified areas for improvement which accord with those of HMCPSI.
East Midlands Area Inspection Programme Baseline Report – published 13 October 2022
Inspectors recognised the Area’s grip in some of the most challenging cases, with examples of excellent casework across all units. The service provided to victims and witnesses was also described as a real strength. Inspectors found constructive engagement with all 5 police forces and commended the Area for continued direct engagement with the defence. Inspectors highlighted the focus on staff well-being during the time of unprecedented pressures which had a positive impact on staff engagement.
North West Area Inspection Programme Baseline Report – published 27 October 2022
The report recognises the hard work of all staff in the North West Area and the joint working with criminal justice agencies to sustain and improve performance and service to the communities of Greater Manchester, Lancashire and Cumbria. Inspectors recognised that the Area maintained a good grip of casework, especially in the face of unprecedented challenges caused by the pandemic. The Area had already identified most of the aspects that required improvement and have taken steps to address them.
Thames and Chiltern Area Inspection Programme Baseline Report – published 10 November 2022
The Inspectorate focused on the quality of casework, finding that the Area makes charging decisions that reflect the gravity of offending, consults with victims well, handles correspondence from the courts, defence and police in a timely way, and has effective stakeholder relationships. Against a backdrop of increased caseloads and challenges in recruiting new staff, the Inspectorate commended the Area for reacting quickly to the pandemic and for its ongoing operational recovery work with partners.
Additionally, HMCPSI conducted the following thematic and joint inspections:
The impact of the Covid-19 pandemic on the criminal justice system – a progress report – published 17 May 2022
This was a joint CJS Inspectorate progress report to the January 2021 ‘state of the nation’ report on the criminal justice system (CJS) and was based on combined inspection findings over the previous year, when the COVID-19 pandemic severely disrupted services.
The report highlights the demands placed on our people to manage increased workloads as part of the recovery phase and the sustainability of this environment without building up wellbeing or morale issues. Inspectors recognised the significant levels of recruitment being undertaken to mitigate these issues alongside strong management and corporate support to best balance the health, safety, and wellbeing of our people. It was also noted how CPS Areas consistently applied well-structured induction programmes to onboard people in an effective manner.
There were no recommendations or aspects for improvement in this report.
The service from the CPS to victims of domestic abuse – published 30 March 2023
This is a thematic inspection of the handling by the Crown Prosecution Service of domestic abuse cases in the magistrates’ courts. HMCPSI have recognised the passion and commitment of CPS staff locally and nationally to achieve the best possible outcome for victims. Overwhelmingly, our prosecutors are making decisions in accordance with our Code.
CPS, together with the NPCC leads, are working collaboratively with stakeholders to develop a domestic abuse Joint Justice Plan that will improve the investigation, prosecution, and collective handling of domestic abuse to better secure justice for victims.
There are 6 recommendations from the report and we will continue to work with CJS partners to deliver the recommendations.
Commercial arrangements
The CPS Commercial Policy sets out the governance for our commercial activity, ensuring legal compliance to Public Contract Regulations, Cabinet Office spend controls and delegated authority limits which are structured around value and risk of the procurement or contract change involved.
Out Policy and Governance team have supported implementation of the policy across CPS including the roll out of a full package of commercial training courses which commenced in 2021‐22 and will continue into the 2023-24 financial year.
The policy is supported by a robust approval framework with gateways encompassing the full commercial lifecycle from concept through to contract exit. The introduction of Strategic Sourcing specialisms has enabled earlier engagement with the business, resulting in an enhanced understanding of our commercial pipeline. This has created better assessment of ‘make’ or ‘buy’ decisions and greater engagement with the marketplace to better understand our requirements.
Commercial are integral to the business case process, both for internal approvals via the Investment Committee and for Cabinet Office and Treasury controls. This ensures the right commercial risks are raised at business planning stage to ensure that appropriate mitigation measures are identified, implemented, and monitored throughout the commercial lifecycle. The Commercial function are also represented on internal governance boards to provide commercial insight and oversight, thereby ensuring that compliance is maintained, and the most advantageous commercial model is delivered to the CPS.
The CPS and AGO have worked together again this year to produce our Anti Modern Slavery statement to be incorporated into a cross-government document. We achieved all the targets we laid out in the 2021‐22 statement and exceeded this year’s risk assessment target to review our most strategically important and highest value contracts, by risk assessing our entire contract portfolio. We have also provided our team invaluable insight by harnessing our prosecution colleagues’ experiences to bring some of the complex crimes to life. This had a real impact on our commercial team as it highlighted how important the work, they are doing with our supply chain is to ensure vulnerable workers are protected and exploitation is eradicated.
Review of effectiveness
The Accounting Officer has responsibility for reviewing the effectiveness of the system of internal control in the CPS.
His review is informed by the work of Internal Audit and members of the Executive Group, which has responsibility for the development and maintenance of the internal control framework, and comments and recommendations made by the external auditors in their annual management letter and other reports.
The Chief Executive Officer or Corporate Services Lead Director acts as an Additional Accounting Officer of the CPS.
Assurance audits
The CPS uses the Government Internal Audit Agency (GIAA) to provide objective insight aimed at helping achieve better outcomes and value for money for the public. In 2022-23 GIAA assessed the overall level of assurance in the CPS as a whole to be ‘moderate’. This reflects that some improvements were identified to further enhance the adequacy and effectiveness of the framework of governance, risk management and control.
Internal Audit use a four-point scale in assessing the level of assurance:
| Substantial | The framework of governance, risk management and control is adequate and effective. | |
|---|---|---|
| Moderate | Some improvements are required to enhance the adequacy and effectiveness of the framework of governance, risk management and control. | |
| Limited | There are significant weaknesses in the framework of governance, risk management and control such that it could be or could become inadequate and ineffective. | |
| Unsatisfactory | There are fundamental weaknesses in the framework of governance, risk management and control such that it is inadequate and ineffective or is likely to fail. |
The following table represents the high-level outcomes achieved for each of the areas audited during 2022-23:
Area of inspection | Outcome from review of effectiveness | Date report finalised |
|---|---|---|
Cyber Security | MODERATE | June 2022 |
Records Management | LIMITED | June 2022 |
Contract Management | LIMITED | September 2022 |
Right of Access Requests | SUBSTANTIAL | November 2022 |
Payroll | MODERATE | January 2023 |
Oracle | MODERATE | January 2023 |
Hybrid Working | SUBSTANTIAL | February 2023 |
Strategic Recruitment | SUBSTANTIAL | March 2023 |
Digital Supplier Disaggregation | LIMITED | April 2023 |
Based on the above, it is concluded that there were some weaknesses in the CPS’ governance and control framework that affected achievement of its strategic objectives in 2022-23, but that these can be rectified through actioning GIAA’s recommendations.
Advisory audits
As well as the above assurance audits, the GIAA also conducted one advisory audit during 2022-23. Advisory audits involve GIAA working together with subject matter experts from across the CPS in an advisory role and are not subject to an opinion. The advisory audit carried out in 2022-23 was in respect of Digital Upskilling, with the report being issued in February 2023.
- Rebecca Lawrence was absent from 26 September 2022 to the end of the financial year, and as a consequence the Interim CEO took up the Additional Accounting Officer role for that period