Corporate governance report
This report explains the composition and organisation of CPS’ governance structures and how they support the achievement of our strategic objectives.
Directors' report
The Directors’ report provides information on the senior leadership of the CPS, including membership of the key governance bodies. It additionally reports on information security, including personal data related incidents that have been reported to the Information Commissioner’s Office (ICO).
Membership of boards and committees
| April 2024 – March 2025 | Meetings | ||
|---|---|---|---|
| Members | CPS Board | Audit and Risk Assurance Committee | Nominations, Leadership and Remuneration Committee |
| Non-Executive Board Members | |||
| Simon Jeffreys | 6/8 | 3/3 CHAIR | - |
| Dr Peter Kane (from December 2024) | 3/3 | 1/1 CHAIR | - |
| Monica Burch | 8/8 CHAIR | - | 4/4 |
| Dr Subo Shanmuganathan | 7/8 | 4/4 | |
| Kathryn Stone OBE | 7/8 | - | 4/4 CHAIR |
| Independent ARAC Members | |||
| Michael Dunn | - | 4/4 | - |
| Deborah Harris (to January 2025) | - | 3/3 | - |
| Executive Board Members | |||
| Stephen Parkinson Director of Public Prosecutions | 8/8 | 4/4 | 4/4 |
| Julie Lennard Chief Operating Officer (from November 2024) | 3/3 | 1/1 | 1/1 |
| Steve Buckingham Chief Finance Officer | 3/4 | - | - |
| April 2024 – March 2025 | Meetings |
|---|---|
| CPS Executive Group | |
| Stephen Parkinson Director of Public Prosecutions (Chair) | 19/19 |
| Julie Lennard Chief Operating Officer (from November 2024) | 7/7 |
| Grace Ononiwu Director of Legal Services | 13/19 |
| Gregor McGill Director of Legal Services (to April 2024) | 1/1 |
| Nick Price Director of Legal Services (from May 2024) | 15/18 |
| Baljit Ubhey Director of Policy | 17/19 |
| Tristan Bradshaw Interim Director Operational Change & Delivery (to February 25) Director of Transformance & Change (from February 2025) | 16/19 |
| Steve Buckingham Chief Finance Officer | 17/19 |
| Dawn Brodrick Chief People Officer (to June 2024) | 4/5 |
| Helen Starkey Interim Chief People Officer (from July 2024) | 15/15 |
| Mike Browne Interim Director of Communications (to April 2024) | 1/1 |
| Lisa Benbow Director of Communications (from April 2024) | 18/19 |
| Matthew Cain Interim Chief Digital and Information Officer (to January 2025) | 14/15 |
| Lee Noon Interim Chief Digital & Information Officer (from February 2025) | 3/3 |
Security and information assurance
Our corporate knowledge and information management teams ensure that data is effectively managed in line with the principles of UKGDPR, the Data Protection Act 2018, the Public Records Act 1958, and the Freedom of Information (FOI) Act 2000.
The teams work closely with the business to ensure robust controls are in place to protect individual rights, ensuring that the development of products and services are ‘secure by design’.
Cyber security
Our cyber security team continues to identify, assess, and mitigate cyber threats across a dynamic and complex threat landscape. Their key achievements during the year include:
- GovAssure programme – By the end of March 2025, we had successfully implemented various outcomes from the initial GovAssure programme – the Cabinet Office’s new assessment tool for cyber security. These included enhancements to our incident response processes and threat intelligence capabilities further strengthening our cyber security resilience.
- An updated security management plan which reflects the Central Digital and Data Office standards, has enabled adoption of Artificial Intelligence (AI) and ‘Secure by Design’ practices; it has been embedded through supplier engagements.
- AI continues to be a high-priority and high-risk area. The team has developed and implemented an AI security & ethics framework and a ‘responsible AI policy’ have been developed. Risk management strategies have been built into project-level and organisational governance, with threat modelling and ethics assessment tools soon to be deployed across initiatives.
- A data-driven approach to our cyber security education, training and awareness programme. Our 2024 baseline assessment achieved a 97.6% completion rate and a 91% average score. The programme now includes regular phishing simulations and role based bespoke training.
Operational security
The Operational Security Team (OST) continues to work with the business to ensure the rigorous application of all security standards.
Area based Security & Information Managers facilitate compliance at a local level. Area compliance is reported annually to OST through our Security & Information Assurance Framework, which is aligned to the GovS 007 minimum standards. This, in turn, informs our Departmental Security Health Check report to the Cabinet Office.
The CPS is committed to maturing its security resilience through a process of continuous review and robust risk and threat monitoring, evaluation and response.
Business continuity
The CPS’ business continuity capabilities and response are reviewed annually and following a ‘live’ incident. Our primary focus this year has been to extend our current policies and processes to incorporate those linked to the cyber security ecosystem.
General Data Protection Regulation (GDPR) and Data Protection Act 2018
We actively promote a security and information assurance culture across all aspects of our business and all staff and contractors are personally responsible for the safety of the data we hold. To maintain this awareness our bespoke annual mandatory training programme reflects organisational changes and user needs. In 2024, it included specific guidance on records management and retention. 99% of our staff completed the annual training.
To maintain the integrity of the information we hold and remain compliant with relevant legislation. our data protection policies and guidance are regularly reviewed. This year we also reviewed our overarching data protection policy and streamlined the data sharing agreement process, to make it more efficient for users. New and existing systems reflect data protection ‘by design and default’.
The Information Governance Group retains overall responsibility for information assurance across the CPS; it reviews all proposed policy changes which involve significant differences in approach or where performance sits outside our risk tolerance. Bespoke training is regularly provided to all information asset owners to ensure consistent local management of critical assets.
Information assurance and compliance
The CPS compliance rate statistics for information requests are as follows:
| 1 April 2024 to 31 March 2025 | 1 April 2023 to 31 March 2024 | |
|---|---|---|
| FOI requests | ||
| Number received | 917 | 892 |
| Number responded to within deadline (either 20 working days or public interest test extension) | 841 | 812 |
| Compliance rate | 92% | 91% |
| GDPR rights requests | ||
| Number received | 18 | 36 |
| Number responded to within deadline | 17 | 35 |
| Compliance rate | 94% | 97% |
| Rights of access requests | ||
| Number received | 650 | 562 |
| Number responded to within deadline | 570 | 480 |
| Compliance rate | 87% | 85% |
CPS legacy case records for national interest
Under the Public Records Act 1958, public bodies must select and transfer records for permanent preservation within statutory timeframes to the National Archives (TNA). These records should be transferred when they are 20 years old. The CPS currently transfers selected criminal case records to TNA and for the time referred to were paper records. In the main, section 38 (Health & Safety) and section 40 (Personal Information) of the FOI Act 2000 apply to all finalised criminal case files, which are exported and closed to public access.
This is due to personal sensitivities of the cases and the impact that release into the public domain could have on an individual’s physical or mental health.
The following table shows the CPS transfer position for the reporting year.
| CPS Year | Transferred to TNA | Starting piece number | Ending piece number | Total number of pieces | Total number of criminal case files |
|---|---|---|---|---|---|
| CPS 2000 | Transferred May 2024 | 19,179 | 19,538 | 359 | 15 |
| CPS 2001 | Transfer due May 2025 | 19,539 | 20,405 | 866 | 14 |
| CPS 2002 | Transfer expected Oct/Nov 2025 | 20,406 | 20,901 | 495 | 12 |
| CPS 2003 | Transfer expected Oct/Nov 2025 | 20,902 | 21,177 | 275 | 8 |
| CPS 2004 | Selections made; preparation work in progress | N/A | N/A | N/A | 12 |
| CPS 2005 | Selections made; preparation work in progress | N/A | N/A | N/A | 13 |
Personal data-related incidents
A summary of personal data-related incidents formally reported to the ICO in 2024-25 is set out below.
Personal data incidents reported to the ICO in 2024-25:
| Period | Nature of incident | Nature of data involved | Number of people potentially affected | |
|---|---|---|---|---|
| April to June 2024 | None | None | 0 | None |
| July to September 2024 | 2 unauthorised disclosure breaches | Personal data related to casework material | TBC | Breach Ref 12333- Operation Lytton – Ongoing Breach Ref 12511 – Y&H – closed – ICO NFA |
| October to December 2024 | None | None | 0 | None |
| January to March 2025 | None | None | 0 | None |
Total personal data incidents in 2024-25:
| Category | Total reported in 2024-25 (2023-24) | Explanatory note |
|---|---|---|
| Data Handling Losses | 50 (49) | In all 50 of these incidents the data loss was very minor and recovered. |
| Unauthorised disclosure | 2,188 (2,154) | In 2,188 of these incidents, the data loss was very minor or retained within the criminal justice profession, who are bound to professional standards of data protection. |
| Lost/Stolen ICT Equipment | 42 (34) | In all these incidents the devices were successfully deactivated. All devices were encrypted to the government standard; therefore, no CPS data was compromised. |
Statement of the Accounting Officer’s responsibilities
Under the Government Resources and Accounts Act 2000, HM Treasury has directed the CPS to prepare, for each financial year, accounts detailing the resources acquired, held or disposed of during the year and the use of resources by the Department during the year. The accounts are prepared on an accruals basis and must give a true and fair view of the state of affairs of the CPS and of its income and expenditure, Statement of Financial Position and cash flows for the financial year.
In preparing the accounts, the Accounting Officer is required to comply with the requirements of the Government Financial Reporting Manual and in particular to:
- observe the Accounts Direction issued by HM Treasury, including the relevant accounting and disclosure requirements, and apply suitable accounting policies on a consistent basis;
- make judgements and estimates on a reasonable basis;
- state whether applicable accounting standards as set out in the Government Financial Reporting Manual have been followed, and disclose and explain any material departures in the accounts;
- prepare the accounts on a going concern basis.
HM Treasury has appointed the Director of Public Prosecutions as Accounting Officer of the Department, and the Director of Public Prosecutions has appointed the Chief Operating Officer as an Additional Accounting Officer. This appointment does not detract from the Director of Public Prosecutions’ overall responsibility as Accounting Officer for the Department’s accounts.
The responsibilities of an Accounting Officer, including responsibility for the propriety and regularity of the public finances for which the Accounting Officer is answerable, for keeping proper records and for safeguarding the CPS’ assets, are set out in Managing Public Money published by HM Treasury.
The Accounting Officer confirms that he has taken all the steps that he ought to have taken to make himself aware of any relevant audit information and to establish that the CPS’ auditors are aware of that information. So far as he is aware, there is no relevant audit information of which the auditors are unaware.
The Accounting Officer confirms that the Annual Report and Accounts as a whole is fair, balanced and understandable and he takes personal responsibility for the Annual Report and the judgements required for determining that it is fair, balanced and understandable.
Governance statement
This Governance Statement sets out the CPS’ governance, risk and assurance management and internal control framework and how, during 2024-25, we managed the significant risks to the achievement of our strategic objectives. We ensure that robust governance arrangements are in place to promote high performance and safeguard probity and regularity. The CPS is a Non-Ministerial Governance framework Department that is not subject to the protocol on enhanced departmental boards but has sought to comply as far as possible with the practices set out in Cabinet Office’s and HM Treasury’s Corporate Governance Code of Good Practice. Details of attendance at the CPS’ boards and committees are given in the Directors’ report.

The CPS Board
The primary function of the CPS Board is to agree the strategic direction and priorities for the CPS, and to provide a forum for constructive challenge on proposals and the implementation of decisions by the Executive Group. The Board plays a key role in ensuring that the CPS is equipped to provide a professional, efficient and high-quality service.
The Cabinet Office’s and HM Treasury’s Corporate Governance Code of Good Practice provides guidance on Board composition and remit. The role of the Board continues to be one that provides oversight of strategy and an assessment of delivery. The Board also has a role in the oversight of the talent and culture of the CPS, it monitors performance and outputs and provides leadership to the organisation.
Audit and Risk Assurance Committee (ARAC)
ARAC reports to the CPS Board. It has delegated responsibility and authority for advising the Board on key elements of effectiveness linked to risk management, assurance management and the framework of internal control. The ARAC also reviews the comprehensiveness and reliability of assurances provided by internal audit, external audit, and the Executive Group, and challenges where necessary when gaps in processes are identified and where weaknesses are exposed.
Remuneration Committee (RemCom)
RemCom reports to the CPS Board. It has delegated responsibility and authority for advising the Board on key elements of effectiveness linked to organisational and leadership strategies. This includes ensuring that leadership strategies and senior organisational design are fit for purpose and that there are robust systems in place to identify and develop senior leaders from diverse talent pools, draw up appropriate senior workforce and succession plans, and scrutinise incentive structures.
Executive Group (EG)
EG comprises the most senior members of CPS staff. It oversees the CPS’ overall performance and delivery and focuses on strategic leadership, management, direction, and ensuring the most effective prioritisation of resources. EG, as the executive management team of the CPS, informs and acts on decisions taken by the DPP and takes collective decisions on key corporate issues affecting the CPS.
Risk management
CPS’ approach to risk management
We follow the Orange Book’s five risk management principles, using clear processes to help us spot and manage risks at all levels. This approach supports better decision- making, efficient use of resources, and stronger contingency planning.
Roles and responsibilities
Good oversight ensures that risks are reported to the right groups, including the Finance, Performance and Risk Group, the Executive Group, the Audit, Risk & Assurance Committee, and the Board. Our strategic risk register is regularly reviewed, helping guide both our Internal Audit programme and the work of HM Crown Prosecution Service Inspectorate to make sure all major risks are properly covered.
CPS EG reviews and refreshes the Strategic Risk Register every year to ensure it remains current and adequately reflects the biggest areas of risk to the CPS’ strategic objectives. EG also has clearly defined risk appetite statements which set firm thresholds that help the CPS both focus attention on those risks close to or exceeding our organisational risk appetite while keeping control of our risk environment.
We review risk reports every quarter and regularly take a closer look at specific areas. This helps us understand the main risk issues from each CPS Area and Directorate, and allows the Executive team to keep track of risks at both the corporate and operational level.
Roles and responsibilities
| Entity | Role and responsibilities |
|---|---|
| CPS Board | Sets the overall risk appetite; reviews key risks and uses the risk landscape to guide strategy and audit plans. |
| Accounting Officers (Director of Public Prosecutions and Chief Operating Officer) | Accountable to Parliament for effective risk management across the organisation. |
| Chief Finance Officer & Risk & Assurance Team | Coordinate risk management efforts, ensure a consistent approach, and report top risks to senior groups. |
| Senior Managers | Own and manage risk registers for their areas. |
| Teams or Individuals (Risk Owners) | Responsible for managing specific individual risks. |
| Finance, Performance and Risk Group | Reviews corporate performance, financial and risk data monthly; escalates top risks quarterly. |
| Executive Group | Reviews top risks quarterly, agrees on necessary controls and mitigation, and monitors emerging risks. |
| Audit and Risk Assurance Committee | Provides quarterly oversight of strategic risks and tracks progress on mitigation actions. |
Our principal risks
CPS’ principal risks during the year 2024-25 included:
| Risk | Trend | Comment on trend | External Factors |
|---|---|---|---|
| CPS is unable to meet demand for its services due to a large backlog of cases and increased pressure externally in terms of case volumes | → | The backlog of cases remains high but has not become significantly worse since last year. Our resources have remained strained since the pandemic and the timeliness of case progression has been affected, leading to delays in delivering justice. The Central Prosecutor Team (CPT) was developed in September 2022 and is based within CPS Direct. This team is deployed to areas of high demand to work on high-volume pre-charge decisions, enabling spikes of work to be managed effectively. We have also introduced new digital services and automated processes for frontline colleagues, resulting in improved casework management. Despite these efforts, the increase in case complexity and case mix has prolonged the time it takes to verify that police file submissions are of appropriate quality to ensure a timely charging decision can be made within the Service Level Agreements. We have continued to prioritise improvements in how we progress rape and serious sexual offences cases, with the launch of the CPS National Operating Model for prosecuting adult rape. These measures have helped to address some of the challenges, but the dynamic nature of risks means that we must remain vigilant and adaptable, continuously refining our risk management practices to address emerging threats and opportunities. | The ongoing impact of the pandemic and Criminal Bar Association action have led to unprecedented Crown Court backlogs. The disorder that occurred in Summer 2024 prevented this risk from trending downwards due to the volume of cases that required swift progression and prioritisation. |
| An inability to attract, recruit and retain staff with the necessary skills and experience to deliver its objectives | ↑ | An ageing workforce at CPS has increased the rating of this risk, as there is a very real threat of losing knowledge and experience as staff exit the workforce through retirement or reduce their hours. There are a number of mitigations, both current and planned, that we hope will prevent the continued upward trend of this risk in future. | Senior legal staff are difficult to attract from outside the CPS due to a number of factors, including pay and the highly specialist skills required. |
| Cyber security is compromised by cyber- attack by criminals or foreign powers, leading to interference in our criminal justice system, loss of data and/or reputational damage | → | CPS maintains a security baseline grounded in the defence-in-depth principle, mitigating risks through comprehensive operational and cybersecurity controls. This includes authentication measures, secure architecture, vulnerability management, and continuous monitoring and auditing of CPS systems. Whilst this remains a critical risk, it remains stable. The risk of data loss has remained out of tolerance for the duration of the financial year – our risk appetite in this area is minimal due to the potentially enormous consequences loss of data can have for victims and witnesses. Executive Group have commissioned regular reports on this risk. | CPS, in common with other government bodies, continues to be of interest for external hostile agents. |
| Victims, particularly victims of rape and sexual offences, lack trust in the CPS and wider criminal justice system to serve justice because the pace of change does not permit sufficient time to rigorously test and review proposed key changes | → | An extensive programme of engagement with stakeholders has been established to improve their confidence in work undertaken by CPS, including improving the service we provide to victims of crime. Direct engagement with senior partners is a feature of this programme, developing greater trust and confidence amongst influential partners. The National Operation Model was launched this year and has been well-received by stakeholders. | Continuing engagement with Police, supporting an effective and appropriate joint approach to this type of offending. |
| Insufficient funding to enable us to meet demand and make necessary changes | ↓ | CPS secured increased funding for the financial year 2024-25 to cover known financial pressures (notably prosecution costs). This additional funding was confirmed at the Budget in November. | The Spending Review settlement for CPS from HMT has provided further mitigation that this risk will continue its downward trend in future years. |
| The pace of change within CPS and the wider criminal justice system is unsustainable and leads to worsening performance. Multiple change projects taking place simultaneously may lead to change fatigue within the organisation, as well as competing priorities. | → | Whilst the pace of change remains ambitious, all change programmes continue to have oversight, with representation from across the various CPS functions to proactively manage dependencies and ensure the sharing of knowledge across the organisation. | Political pressure for reform of the justice system continues to impact CPS. It is prudent to expect this pressure to continue throughout the lift of this Parliament and beyond. |
Functional Standards
The CPS is currently assessing its compliance with the mandatory elements of the Government Functional Standards via rigorous, evidence-based assessments and utilising inter-government peer reviews to ensure appropriate challenge and scrutiny. Where areas for improvement are identified, including for non-mandatory elements, the CPS is developing action plans to address these during 2025-26.
Identifying and managing conflicts of interest
The Civil Service Management Code sets out standards of propriety expected of civil servants in respect of external interests. The CPS has a policy in place for the declaration and management of interests for all staff, which includes declaration of any interests that may give rise to a conflict or perceived conflict of interest and adheres to the requirements of the Code.
In addition to the established processes in place for managing interests, an annual audit exercise takes place which requires all staff to make a declaration of any private, personal, or financial interests or, for those in SCS and equivalent grades and senior employees in a Commercial role, to make a nil declaration. Where a conflict or perceived conflict of interest arises, these will be recorded, considered assessed and managed by appropriate senior managers with the support of Risk and HR practitioners.
Business appointments
In compliance with business appointment rules, the CPS is transparent in the expectations of, and advice given to senior staff. There was one SCS leaver in 2024-25 who required a BAR application, with conditions set.
His Majesty’s Crown Prosecution Service Inspectorate (HMCPSI)
HMCPSI inspects the CPS and the Serious Fraud Office (SFO). It provides independently assessed evidence to help drive improvement and build public confidence in the prosecution process.
HMCPSI priorities for inspection are set out in an annual Business Plan and it reports annually to the Attorney General on the performance of the CPS, in addition to other individual and thematic inspection reports.
During 2024-25, HMCPSI completed seven inspections. The full responses from the CPS to the reports are available online at Our report – HM Crown Prosecution Service Inspectorate.
Commercial arrangements
The CPS Commercial Policy ensures compliance with Procurement Regulations, Cabinet Office rules, and spend controls, while adhering to delegated authority limits. It aims to create an effective system.
Since FY 2021-22, we have rolled out evolving training programs, ensuring everyone is equipped to handle current challenges. Weekly Commercial Board Gateway meetings guide our processes, from defining needs to managing contracts. Early involvement of strategic sourcing experts has shaped our Commercial Pipeline, updated quarterly and shared publicly.
The Commercial Function plays a key role in corporate governance and risk management, identifying risks early and implementing plans throughout the commercial lifecycle. Our commercial expertise ensures competitiveness and optimal deals, with smarter pre-market engagement, make-versus-buy evaluations, and cost modelling, supported by regular contract management.
Enhanced collaboration with colleagues has provided insights into our supply chains impact on modern slavery; protecting people and preventing exploitation.
We aim to leverage new procurement regulations to maximise value for money, foster innovation, and strengthen supplier relationships. We are committed to embedding updated procedures across the organisation, promoting compliance, and driving impactful outcomes for the CPS and its stakeholders. By staying proactive and adaptable, we are ready to navigate future challenges and opportunities in the evolving procurement landscape.
Review of effectiveness
The Accounting Officer has responsibility for reviewing the effectiveness of the system of internal control in the CPS.
His review is informed by the work of Internal Audit and members of EG, which has responsibility for the development and
maintenance of the internal control framework, and comments and recommendations made by the external auditors in their annual management letter and other reports.
The Chief Operating Officer has acted as the Additional Accounting Officer of the CPS since November 2024.
Assurance audits
The CPS uses the Government Internal Audit Agency (GIAA) to provide objective insight aimed at helping achieve better outcomes and value for money for the public. In 2024-25 GIAA assessed the overall level of assurance in the CPS as a whole to be ‘moderate’.
This reflects that some improvements were identified to further enhance the adequacy and effectiveness of the framework of governance, risk management and control.
Internal Audit use a four-point scale in assessing the level of assurance:
| Substantial | The framework of governance, risk management and control is adequate and effective. | |
|---|---|---|
| Moderate | Some improvements are required to enhance the adequacy and effectiveness of the framework of governance, risk management and control. | |
| Limited | There are significant weaknesses in the framework of governance, risk management and control such that it could be or could become inadequate and ineffective. | |
| Unsatisfactory | There are fundamental weaknesses in the framework of governance, risk management and control such that it is inadequate and ineffective or is likely to fail. |
GIAA, it is concluded that there were some limited weaknesses in the CPS’ governance and control framework that affected achievement of its strategic objectives in 2024-25, but that these can be rectified through actioning GIAA’s recommendations.
Advisory audits
As well as the above assurance audits, the GIAA also conducted one advisory audit during 2024-25. Advisory audits involve GIAA working together with subject matter experts from across the CPS in an advisory role and are not subject to an opinion. The advisory audit carried out in 2024-25 was relating to a high- level review of CPS assurance framework, with the report being issued in June 2025.