International Development Sub‑Committee on the Work of the Independent Commission for Aid Impact
Oral evidence: ICAI’s review on DFID’s approach to managing fiduciary risk in conflict-affected environments, HC 684
Wednesday 19 October 2016
Ordered by the House of Commons to be published on 21 October 2016.
Members present: Fiona Bruce (Chair); Dr Lisa Cameron; Stephen Doughty; Mr Nigel Evans; Jeremy Lefroy; Stephen Twigg
Questions 1-54
Witnesses
I: Dr Alison Evans, Chief Commissioner; and Stephen Blakeley, Senior Fellow, Agulhas Applied Knowledge, and Review Team Leader, Independent Commission for Aid Impact
II: Joy Hutcheon, Director General, Finance and Corporate Performance; David Hallam, Director, Middle East and North Africa; and Peter Taylor, Head of Better Delivery, DFID
Examination of witnesses
Dr Alison Evans, Chief Commissioner; and Stephen Blakeley, Senior Fellow, Agulhas Applied Knowledge, and Review Team Leader, Independent Commission for Aid Impact
Q1 Chair: You are most welcome, Dr Evans and Mr Blakeley. Would you like to introduce yourselves and make a brief opening statement about this report we are examining today: DFID’s Approach to Managing Fiduciary Risk in Conflict-Affected Environments? Tell us about your biggest areas of concern and where DFID needs to focus most on this work.
Dr Evans: Certainly. Thank you very much, Chair. I am Alison Evans, and I am the chief commissioner of ICAI.
Stephen Blakeley: I am Stephen Blakeley. I was the team leader for this review.
Dr Evans: Thank you very much for the opportunity to say a few words to start us off. This review picks up on a number of underlying pieces of work. The first would be that there was an ICAI review in phase 1 that looked at the scale-up impact of spending in fragile states, which drew attention to, or at least touched on, issues relating to the systems and controls around fiduciary risk management in fragile and conflict‑affected states, which we thought would be good to go back and look at in some depth.
It is also the case that there was an internal audit report in DFID in 2014 that looked at the whole risk management system in DFID, which raised a number of concerns and challenges around the comprehensiveness of that risk management system. We have gone back and looked at that as our baseline for assessing progress on fiduciary risk in particular. It is also, of course, open knowledge that DFID is committed to spending 50% of its budget in fragile and conflict‑affected states, so there is a commitment to major scale-up. In 2015‑16, the budget in these environments was in the order of £5.5 billion. This is a huge area of spending.
In the period between the first review that was undertaken by ICAI and this one, DFID has implemented its smart rules, which move from a more compliance‑based approach to a whole number of aspects of business process to a principles‑based one. We wanted to take in how much that was affecting and aiding fiduciary risk management.
Very quickly, on what we found, in this review we wanted to spend a lot of our time looking at what was going on at country level. That is the bulk of the evidence in this review. We found that, set against the Treasury guidelines around effective risk management, in almost all cases—country and programme—where we focused our attention, we found that fundamental aspects of fiduciary risk management and accountability are in place, with a strong emphasis on safeguarding UK taxpayer funds from misuse. We found that across the board. There is only one programme in our 27 where we express major concerns around the way fiduciary risk has been managed. We can perhaps talk in more detail about that, if you like, as we go through.
We also found that, at the front line, DFID’s fiduciary risk management was effective and proportionate in most areas. But we did find a number of areas of concern, and I would like to draw your attention to those. The first is that fragile and conflict‑affected environments are ones in which risks are often changing rapidly; they are often multiple and quite complex. To work in those environments is to take on risk. Let us be clear; effective fiduciary risk management is not about neutralising or eliminating all risk; it is about getting the balance between reducing the possibility of funds not being used for their intended purpose and justifying it against the potential benefits of working in that environment and achieving development benefit.
In that context, it is really important that the Department is able to set out what its risk appetite is. In the course of this review, we found that understanding about what risk appetite means and should look like varied quite widely. In some cases, staff at the front line expressed real uncertainty about how to assess risk appetite in such a way that they felt they had cover from the DFID corporate or DFID centre around their decisions. That is the first point, and we have a recommendation about that.
The second point is around risk transfer. DFID has a lot of systems, controls and procedures in place to manage its relationship with implementing partners, particularly lead implementing partners. However, there are often, particularly in fragile states, quite complex delivery chains that go on underneath the lead implementing partner. Now, DFID requires the lead implementing partner to do the all due diligence relating to those other partners. At times, we felt that it was not always clear how risk was being transferred down that delivery chain. DFID did a very good job in relation to its own lead implementing partner, but not necessarily such a clear job in relation to subcontractors down the delivery chain. We have a recommendation about that.
The final area I would like to draw your attention to is that the reform process around risk management has been quite slow in the Department. There is progress, and we are able to point to real areas of progress, particularly since the 2014 internal audit report. That is very promising, but our sense is that it is now a case of urgency that this reform process is completed, putting all the elements of risk management in place, particularly at a time when there is such a significant scale-up of funds in environments that are, by definition, risky.
Chair: Thank you very much, Dr Evans. You conclude that the review says performance is satisfactory in most areas, and yet you have a number of grave concerns. We will be returning to your concluding rating of green/amber at the end of our questions.
Q2 Stephen Twigg: Thanks, Chair. You mentioned the previous ICAI report on assessing the impact of the scale-up of DFID’s support to fragile states. I understand that, as part of both that review and this review, there were visits to DRC and Somalia. Can you tell us a bit more about what you found in those countries and, in particular, whether the findings from the earlier report had been properly addressed by DFID in those two countries?
Dr Evans: Yes. This was not an exercise in direct follow-up. The review was very much inspired by a number of background documents, of which the ICAI review on scale-up in fragile states was one. We did look into DRC and Somalia, and we did look at a set of programmes. Stephen might be able to provide an indication of the extent to which those programmes directly overlapped with ones that were looked at previously. To be fair, we did not go about checking against very specific points, because in that original ICAI report around fiduciary risk this was treated as one of many issues that were looked at, and it was not the core purpose of that review. In terms of recommendations, there was not a straightforward read‑across to this report.
Q3 Stephen Twigg: Were there particular aspects that related specifically to fiduciary risk in the previous report that you were able to assess any progress on in this piece of work?
Stephen Blakeley: Yes. One of the important things to mention is that one of our core team members was also on that scale-up review, and she was involved throughout the whole of this review. That helped. The scale-up review was most useful in informing our scope and how we went about doing our work, rather than directly dictating our follow-up, particularly in areas of risk appetite and on the expectations on staff. We looked at those areas in great detail and we have commented on both of those in the report and in the recommendations.
At the time of our follow-up of the scale-up review, one of the issues was that there was an ongoing piece of work by DFID to look at its risk framework, so we were unable to get an understanding of how that was going to play out and how it was going to impact on the ground. What we did in this review was to look and understand what had been put in place, and how that had changed what was going on on the ground. We found that staff in both of the two countries that we went back to had a much better understanding—or at least an awareness—of the importance of concepts such as risk appetite, zero tolerance to fraud and corruption, and what they meant in practice.
As Alison said, the interpretations of those were not always consistent, and at the moment, or at least when we were doing our work, there was still work to be done to embed those, but we did find a progression and improvement since then. What we did not see and what was not in place was a comprehensive risk management framework; that was still being worked on at the time of our work.
Q4 Stephen Twigg: We have spoken previously—this came up yesterday—about the different forms of review that ICAI now conducts. This was a performance review. Can you tell us what the implications of that are and, in particular, does it mean that there was more of a focus on value for money than perhaps there would be in the other forms of review?
Dr Evans: We have value for money front and centre in every review; we just look at it through slightly different lenses. It would be fair to say that value for money is as much an art as a science in the way it is operationalised within the Department and within any Government Department. We are trying to understand its operational features in any one context. As a performance review, but as a performance review looking at a particular area of risk management, we see this as a pillar of value for money. Without this in place, it is extremely hard if not impossible for the Department to achieve value for money in its programming, because without risks being managed appropriately, there is the likelihood that not only is our money not used for its intended purposes, but value is not created. This is a pillar of the Department’s agenda around value for money.
Q5 Dr Cameron: You mentioned staff at the front line having some concept and awareness of risk. Do you feel at all that there requires to be a training programme? If risk is fluid and risk indicators can occur quite quickly, surely staff having high awareness would help in alerting the organisation.
Dr Evans: I will take that, and maybe Stephen can follow on. Let me clarify: on the measure of what fiduciary risk is, staff had a very high level of awareness. There is a lot of support from a systems perspective to help them identify, assess and put in place mitigation measures at the front line. What Stephen was referring to was this concept of risk appetite, which is really how you judge risk versus reward and how much risk one should take in order to meet certain potential rewards that are part of the objectives.
For example, in DRC, an environment in which DFID does not work through Government at all because of the associated risks, the question is: can it deliver against development objectives in an environment where the institutions, the lack of rule of law and so forth mean that there are very high risks to the management of funds? It does so by working with particular kinds of partners through particular delivery channels, and it manages very closely.
That is happening. We are then observing that, at the highest level of the organisation, there is a statement that we have a high risk appetite in the work we do in fragile and conflict‑affected states. How is that being interpreted at the programme level? That is what we are not so convinced we are seeing consistently. The term is understood, but not how it works through practically: should they take more risk to achieve more benefit or less risk with the possibility of having less benefit? It is not entirely clear.
Q6 Dr Cameron: Does there need to be increased clarity for staff?
Dr Evans: Yes, and, in fact, one of the reasons why the reform programme has been perhaps slightly slower is that they have put a lot of emphasis on trying to train staff and see behaviour change. That is a slow process.
Stephen Blakeley: That is absolutely right. Staff at the front line were the most important tool in managing fiduciary risk and they were very effective in identifying and mitigating those risks. We found that across the board, with the exception of the one case study that we highlight in the report, in DRC. We were more concerned that there were differing interpretations of how to balance the taking of risk with DFID’s zero tolerance to fraud and corruption. In some cases, probably most cases, DFID was incredibly cautious and would sometimes not do things because of the perceived risk of fraud and corruption. In other cases, it was more comfortable to take those risks if the returns were justified.
A good example is the large-scale response in Syria, a very corrupt environment with a lack of rule of law, where DFID made a decision that it had to go in there and make a difference. It went into a very high-risk situation where it did not have an existing office. There are instances where DFID is consciously taking risk in order to achieve an objective, but we did not see an ability to compare the level of risk and level of risk appetite being taken across those countries. That is where we have some concerns.
Q7 Mr Evans: The Department has a decentralised approach to fiduciary risk management, which clearly gives it flexibility. Do you not see there is a downside to that as well?
Dr Evans: The short answer is that this is absolutely the crux of it: the balancing act between how much flexibility should be applied in something as central as fiduciary risk management and the need for consistency. Stephen, do you want to give some examples of that tension?
Stephen Blakeley: Yes, absolutely. For example, contracting with commercial contractors will be managed centrally, whereas engaging with and making grants to NGOs tends to happen right down at the country level. What we have is a not always consistent approach to what is centralised and what is not. Most other major development agencies are much more centralised. ECHO, the European humanitarian agency, for example, has a centralised grant audit process, whereas in DFID each individual programme may have a different auditor.
There are already some very big differences in how DFID does things. Sometimes this enables it to have flexibility in terms of making sure, for example, that the auditors understand the local context and are appropriate for that programme. There are some downsides, in the sense that it is much more difficult to collate the learning and knowledge that you can pick up through doing that type of work. Whereas ECHO is able to do that very easily and comprehensively, DFID finds it more difficult to collate the understanding of different agencies and organisations through the use of due diligence process. That is not to say that it cannot be done, but it means there are more challenges in doing that. There is always a tension between being flexible on the ground and being consistent.
The ability of DFID to make decisions was appreciated by many partners. The ability for it to be flexible was appreciated on the ground, and it was understood that that was an advantage, but there were also cases where partners felt that the inconsistency was challenging and that they would be treated differently depending on who was looking after them. There are some conflicts and tensions. Sometimes they are very healthy and important; other times there may be ways to improve consistency.
Q8 Mr Evans: Do you not think that the advantages of consistency would outweigh the flexibility?
Dr Evans: As an auditor, you can respond to that. My own view from the evidence that we had, and also from going to DRC on this review, was that there are certain things where consistency is paramount, including the rules and control systems around fraud and corruption, and escalating of cases. It seems to me there is no question that consistency is paramount. Then there is an area around which a certain amount of flexibility is necessary because of context differences, and differences in local markets around business and partners and so forth. We felt we needed to see a clearer line of demarcation around what is absolutely something that is required everywhere and that we need to be able to look at top‑down, and then the areas around flexibility, and actually risk appetite falls into that. It was not clear where that fell. Happy, Stephen?
Stephen Blakeley: Yes, absolutely.
Q9 Mr Evans: Is this under constant review and scrutiny?
Stephen Blakeley: It is. Most of the scrutiny and review happens at the local level. That is where we were concerned that there could be inconsistencies in the approach to risk appetite. Certainly at the local level, there is a continuous look at how to take risks. One example of that is around providing humanitarian support. You could have a one‑size‑fits‑all approach: we always give cash, always give vouchers or always give commodities. Clearly, that would not meet development objectives. You need to be flexible on the ground.
The choice of which of those routes you go down can also help to manage your fiduciary risk. You have the ability to take a flexible local approach, not even at a country level but possibly at a village level. We saw with some programmes that different approaches were being taken in different villages, informed partly by the risks that were observed there. That flexibility is incredibly important and is continually looked at at that local level. We did not see this overarching ability to understand how to compare those risks and build a full understanding of the exposure to risk in each individual country in relation to the next.
Q10 Mr Evans: Let us take Haiti as an example. Clearly there has been a massive disaster. I read somewhere that we were giving £5 million immediately. I am clearly not privy to exactly how that is being delivered, and whether it is just being given to the Government immediately to help alleviate the misery, suffering, pain, death and all that. Would something like that be an example of when you could give far more flexibility at a local level, just to make sure that money gets through as quickly as possible, even though clearly there is a huge risk in doing that?
Stephen Blakeley: We did not look at Haiti, but Syria is another example of that. DFID did not have an office in Syria and it was a middle‑income country until the violence escalated there. It did take more risks in putting money into Syria, and it consciously did that. That should and does happen. The question is whether you are making those decisions on the basis of risk versus benefit, and you have all the information to do that. That is the important part.
Dr Evans: The seniority of staff who are making that judgment is something we refer to in the report. We are not entirely convinced that that is always matched up with the high-risk environment in which DFID is working.
Q11 Chair: Thank you for mentioning that, Dr Evans, because my next question, if you can answer it very briefly, is: who is head of risk at DFID, and where do they sit on the organogram that you produced on page 17 of your report? Who is the named person?
Stephen Blakeley: DFID will be able to tell you a bit more about how it has organised those individuals. There are different responsibilities for risk. Primarily, that sits within the internal audit department, and the audit and risk committee is responsible for overseeing risk overall. That then reports directly up to the executive management committee.
Q12 Chair: Who on the executive management committee is ultimately responsible—because the lines of accountability obviously go up there—for ensuring this area of DFID’s work is carried out effectively?
Stephen Blakeley: Ultimate responsibility is with the Permanent Secretary.
Q13 Chair: Is he effectively head of risk?
Stephen Blakeley: He is responsible for risk overall, and then there are responsibilities right down the chain throughout DFID.
Q14 Chair: We do need to know where the buck stops.
Dr Evans: Permanent Secretary.
Chair: Thank you very much.
Q15 Dr Cameron: In the previous ICAI review of multilaterals, it found that DFID focuses heavily on its fiduciary controls and rarely finds them wanting. In this report, you raised concerns regarding the monitoring of fiduciary risk in programmes implemented by multilateral partners as a key concern. What has changed in that regard?
Dr Evans: Maybe Stephen can give a couple of examples. We saw some good examples—let me be clear about that—certainly in DRC. We saw examples of where local DFID staff there had managed to build up a very good and close working relationship with UNICEF, which was a key implementing partner. They were being given access to all kinds of information relating to their risk management and the risk management of downstream partners, which gave us considerable comfort that this was working extremely well. In a few other cases in the report, we point to areas where the relationship has allowed DFID to have access.
But it cannot be only relationship‑based, it seems to us. There are a number of instances where multilaterals have received bilateral funding through country programmes, and they use their own systems, of course, which is understood, but then do not have the same alacrity, perhaps, in telling DFID when there are problems or reporting at the end of the year. There is not an ongoing conversation.
It is those instances we were worried about. In fact, senior responsible owners who run programmes with DFID are also worried about this. We very much reflected a concern they have that bilateral funds are going through some multilateral organisations where they do not feel they are being given openness.
It is a mixed picture of progress. There is some progress. We saw some good examples, but we also saw some continuing areas of concern in this respect. In our view, it is not good enough for multilaterals to simply say, “We have an HQ‑based relationship with you, and we have assurances at HQ level” and for that not to somehow have an analogue at country level where programmes can have access to appropriate information around fiduciary risk.
Stephen Blakeley: That is right. Monitoring was one of the areas we rated amber/red because of the concerns we had there. DFID has done a huge amount of work to monitor the programmatic performance of its programmes. We felt that the ability to monitor the fiduciary risk performance was not as sophisticated. We raised specific concerns about multilaterals, which Alison has mentioned. We found that fiduciary risk was not systematically being looked at as part of the monitoring processes and that there was quite a lot of reliance on partners to self‑report. That is not a bad thing in itself, but it needs to be supplemented by other ways of getting information, and particularly more timely information, because often, if you are waiting for an annual report or an audit, you will be waiting six months after the event. We felt there were some weaknesses that needed to be looked at there.
Q16 Dr Cameron: Do you feel there should be clarity around risk indicators for each activity? How could DFID achieve better progress in this regard?
Stephen Blakeley: DFID has a huge amount of information, and sometimes it is too much to manage: there is information from annual reviews, from audit reports, from programmes elsewhere. It is not always using those when it could be. While this is more about assessing risk, a good example might be that, when it comes to looking at due diligence, the annual reviews that are used to monitor the progress of other programmes are not feeding on a systematic basis into the due diligence that is being done elsewhere. There are some ways that DFID could use the information it already has to be more effective. It is not necessarily about adding more processes.
In terms of risk indicators, the delivery plans and documentation that DFID has around programmes often have risk indicators in. They are not always followed up on. They are usually followed up on an annual basis, but they are not always followed up on when there are third‑party monitors involved. Third‑party monitors are not tasked with assessing fiduciary risk or activities in relation to fiduciary risk in the same way as they are tasked with looking at programmatic performance.
Q17 Dr Cameron: Could that not cause a problem, then, given that risk is so fluid and you need to know quickly?
Dr Evans: As Stephen says, there is a lot of information, but much of that sits with programme managers and SROs. It is not necessarily being widely shared in ways that could be useful to other programmes. You are right: there is a point about monitoring risk further down the delivery chain. DFID relies very heavily on its lead partners to do that. One thing we think it could do is to do spot checks down the delivery chain on a more consistent basis, to pick up on precisely your point about the fluidity of risk.
Q18 Stephen Doughty: You might be reluctant to answer, but which are the best practice examples in terms of multilaterals in this area and which are the worst?
Stephen Blakeley: We did not do a comprehensive review of multilaterals, so we would not be able to conclude on that, but there are some good examples and some negative examples as well. We give some of those in our report. The example that we have given of a negative situation for a programme in DRC involved UNOPS. UNOPS was very resistant to DFID having access to all the information that DFID wanted in relation to that programme. Interestingly, across the continent in Somalia, UNOPS was one of the good examples where it had openly allowed DFID to conduct audits, which is very unusual for a multilateral. That had been part of the agreement that DFID had made with that organisation. There were some positive examples, even within the same organisation.
In a number of countries we looked at, UNICEF was a very good example; it was very open and engaged. We saw that first-hand in our field visits in DRC. We also heard about similar programmes in some of the other case study countries we looked at. There were some really good examples where multilaterals were being open and engaged.
It tended to come down to a combination of personal relationships and DFID’s leverage in that particular country. If DFID was one of the biggest donors in that country—
Stephen Doughty: They were more open.
Stephen Blakeley: —they tended to be more open. I would not say that was always the case. That ended up meaning that multilaterals were treated very differently depending on what DFID could negotiate, rather than necessarily depending on the level of risk they were exposed to.
Q19 Chair: I said at the outset that we would come back to our view of your green/amber overall rating. I have to say, I am not the only member of the Committee who takes the view that it is too lenient. As you know, this is not the first time we have said that regarding your reports. I would like to probe that, if I may. You have five individual question scores, of which three are green/amber and two are amber/red. It is already quite borderline from your perspective.
I want to ask you about two of the green/amber ones, first on risk identification and delivery. The reason why I think you have been too lenient is the summary of green/amber does not reflect quite a large number of negative comments that you make in the body of the report. You say, for example, that often too junior staff are being asked to make decisions; finance staff are not always there; there are mixed rating measures; there is too much reliance on the judgment of individuals; there is inconsistent categorisation; and information on past performance is not used enough. How did you give a green/amber rating for risk identification and delivery, bearing in mind all these negative comments?
Dr Evans: We need to be very clear that each of those areas, in and of itself, is not a statement or a finding that undermines the more important finding that fiduciary risk is being managed effectively in all of the programmes we looked at, barring one particular case where we showed and shared real concern. DFID had already identified that case. We are balancing that finding against the fact that there are definitely things that can be improved. That is what green/amber means.
Q20 Chair: Let us have a look at learning, then, on which you also have quite a number of comments. You criticise DFID for the amount of time it has taken to reform the risk management systems, but the Treasury guidelines were produced in 2009. That is five years it took, almost, to look at those. The internal audit report was 2014, I believe. We are talking about years.
Do you think you have given DFID too much credit for its ongoing reforms, bearing in mind how many years it has taken it to get where it is now? In terms of learning, you talk about more urgency being required. You say that learning is uneven and several elements still need to be developed. What led you to give such a positive, rather than a negative, conclusion of the green/amber score for learning?
Dr Evans: I will ask Stephen to comment on that, but we need to be clear that the comprehensive reform process really got underway linked to the internal audit report. Yes, the guidance came out earlier and elements of the risk management approach set out by the Treasury were in place, but it was not a comprehensive system, which means all elements talk to one another and work as a joined‑up whole. That is the first thing. We are looking at progress, primarily in this review, since 2014.
That progress is there, and we have drawn attention to it. It is also the case that a lot of this lies not in terms of guidance and procedure, but in terms of behaviour change. That is the slightly slower element of this. There is a lot of training, piloting and trying to tackle what is a moving target around risk. That is important. It has invested a lot in learning about that, which is the green part of green/amber here. The better delivery team inside DFID has invested extensively in learning about that, more than we have probably seen in other development agencies. However, the amber will tell you that we are still concerned about a number of areas.
Yes, we have argued strongly that there needs to be an acceleration, and we would like to see that acknowledged more strongly in the management response. They acknowledge that the pace of reform perhaps needs addressing, but we are still looking for a timeframe in relation to their response there.
Stephen Blakeley: We are clear in our conclusion that, if it was not for the reforms that are happening now, we would have rated it lower. That is really important. We could go back and look at what it should have been doing in 2009, and DFID has been working on various different aspects of fiduciary risk management since then. It is not that fiduciary risk and learning have not been happening since that point. We did raise concerns, and we are concerned about the fact that it took so long to do those assessments.
By the time we were doing our review, DFID had done the work and it was looking at the right areas. In combination with the fact that risk management was happening on the ground and that DFID had identified the most important areas and was not just looking at them but had started to implement changes that we saw to be positive, that gave us confidence that that learning process, though perhaps it was not happening as quickly as it should have in 2009, by the time we were looking at it, certainly was.
Chair: I would accept that, were this a learning review; but it is a performance review. That is why I, personally, as Chair of this Sub‑Committee, have grave concerns about your overall assessment. Thank you very much.
Examination of witnesses
Joy Hutcheon, Director General, Finance and Corporate Performance; David Hallam, Director, Middle East and North Africa; and Peter Taylor, Head of Better Delivery, DFID
Q21 Chair: Welcome to Ms Hutcheon—again, for day two—and to Mr Taylor and Mr Hallam. I wonder if you could briefly introduce yourselves. It would be very helpful if you could also say where you are in terms of the organogram on page 17 as you very briefly introduce yourselves, so the Committee has an understanding of where your responsibility for risk lies.
Joy Hutcheon: I am a director general for finance and corporate performance. I am on the executive management committee and I am responsible for the director for value for money, who is also responsible for the better delivery department. Responsibility for risk is up through that chain. The buck passes through me on the way to the Permanent Secretary.
David Hallam: I am David Hallam. I am the director for the Middle East and North Africa. On the organogram, I am in the yellow row on the left‑hand side, and I report to the director general for country programmes, who is a colleague of Joy’s on the executive management committee.
Peter Taylor: I am head of the better delivery department, which, as Joy mentions, reports up through the director for value for money to Joy, to the EMC, and the risk team sits within the better delivery department.
Q22 Chair: Thank you very much indeed, and thank you for coming today. You heard earlier the evidence and questions regarding the fact that there is a decentralised risk management system in conflict‑affected environments, which, yes, can provide flexibility but also, at times, inconsistency. One of our previous witnesses said in evidence that there is not always a consistent approach. Could you comment on that and say whether you think there needs to be better guidance so there can be a way of mitigating inconsistencies?
Joy Hutcheon: Thank you, Chair. This is something we have been thinking very hard about at every stage of moving this forward, asking ourselves the question: is this an area where we need to prescribe a process, with the possible risk that people will tick a box and follow the process, but not change their behaviour or think about it; or is this somewhere that we want to prescribe an outcome? For example, in smart rule 7 we say that the SRO must assure that risk is assessed in every programme and then provide tools to support them in the way they do that, but not prescribe every single step of the process.
The first question we ask ourselves when we are doing that is whether this is a key control point. The smart rules say that every business case has to have a risk appetite statement in it—an assessment of risk—and then that is approved by the programme approver. That is a really important control point. The second question is whether we need consistent processes so that we can collect and aggregate information in managing the whole of the Department, or whether we want to change the way people are thinking and behaving. Is a mandated process the best way of doing that, or are there other ways of doing it?
That is how we think about where we want to be prescriptive, where we want to support people and prescribe outcomes. The report is right that there are areas where our guidance needs to be clearer—which is in which category; and, where we are being prescriptive, precisely what it is that we want people to do.
Q23 Chair: You have agreed that there is confusion about risk appetite at the front line and that needs to be improved.
Joy Hutcheon: Yes. Would you like me to talk about risk appetite?
Q24 Chair: Briefly.
Joy Hutcheon: We absolutely agree that we need a clearer statement of risk appetite. Risk appetite is quite a complex concept to apply to something you are doing every day. We have in the past tried out some risk appetite statements with the Department and people have said, “I still do not really understand what that means.” That is the problem we have with this outcome.
We now feel that, because of the growth in awareness and understanding of risk around the Department, and because people are getting more comfortable handling it, we are able to give a more detailed statement of risk appetite that people will understand better and find more usable. That is what we are planning to do very shortly.
Q25 Stephen Twigg: Can I ask about experience? One of the things ICAI says is that the level of experience varies significantly across staff. It is critical of the Department’s response to the Syria crisis in particular, which it says was under‑resourced and lacked experienced programme managers, with an excessive reliance on junior staff. What is happening here? Why is it that experienced staff are not being matched to the most challenging situations?
Joy Hutcheon: I will let David talk a bit more about Syria. The first thing we need to do is make sure the leaders and managers understand what skills and experience they need, because the first mechanism we have for doing this is to advertise a job. We can do that very quickly, within a week—we can specify what we are looking for and see who is ready to go and do that. The advantage that has is that sometimes we want people to go to particular parts of the world and they need to be able to do that. We get an answer as to who has the experience and who is ready. We need to get quicker at specifying what we are looking for.
We are also getting much better data on our SROs, what they have done and what training they have. Should that process fail of looking at the skills you need and not getting a response, we are now able to go to the list of SROs or go to the programme management cadre, see who it is who has those skills and manage them into the job we need them in. That is a database we have been building over the past year.
Let me ask David to talk about Syria.
David Hallam: On Syria, it is true that we did scale up extremely quickly. There were some capacity gaps in that scale‑up. My sense is that we are now in a much better place: we have increased the number of staff on Syria; we have increased the amount of experience working on the Syria programme in our team. One of the most important parts of my job is to get the right people, particularly in those key roles that Joy is talking about. When the head of the Syria programme moved on to a new post, it was really important to ensure we replaced her with a very talented programme manager who had oodles of experience, both on the ground and from headquarters, which we were able to do. We are in a better place now. I should say, though, that we also have lots of young people who are really, really brilliant on our programmes.
Q26 Stephen Twigg: The other issue ICAI raised, which is related, is around the quality of the due diligence assessments that are undertaken. In fact, its report highlights two of your country offices that have created best practice, in DRC and Somalia, where one of the examples of best practice is that the head of office is required to sign off these assessments. Do you have plans to extend that kind of best practice to other country offices?
Joy Hutcheon: We have issued a new due diligence framework since the report came out, which is very specific about what we expect to see in a due diligence report. At the moment, the smart rules say that the head of office must take responsibility for ensuring due diligence is done. We have considered whether we should mandate the head of office to sign off every due diligence. At the moment, we would like to emphasise, in our training for heads of office and SROs, that responsibility for the head of office to be satisfied, so that there is still room for judgment at the country level about whether this is a rather straightforward due diligence and can be signed off by the SRO or whether it is one that needs to be escalated, so that the head of office is looking at the really serious cases.
We will certainty incorporate that best practice into our training of SROs and the mandatory finance training that we are going to run for the whole of the senior civil service next year. We are not, at this point, planning to turn it into a mandated requirement.
Q27 Mr Evans: How detailed do you think scrutiny should be, as far as looking at fiduciary risks?
Joy Hutcheon: It is a very broad question. We should be doing as much as we can to identify the fiduciary risk, making an assessment against return of whether it is a risk that is sensible to take, and escalating that up to the right level for that decision to be taken. Then we should look very carefully at the ways available to us to mitigate that risk and, with the residual risk—because we will not always be able to mitigate it—be clear in how we will monitor it and how we will know when it is crystallising. Our zero tolerance approach is about understanding when fiduciary risk that we have accepted is crystallising and then taking immediate action. If I had to say where we were across that spectrum at the moment, I would agree with the report that it is the monitoring that I want to see a bit more emphasis on.
Q28 Mr Evans: I was going to ask where you really think the weaknesses are in that. For instance, if I give an example of subcontractors, do you think it is a real problem that there is clearly less scrutiny as you go further down the chain?
Joy Hutcheon: We have accepted that we need to look further down the chain. We have included delivery chain mapping in our new due diligence guidance, so that we are looking at the risks all the way down the delivery chain. We do expect our partners to manage risk down that chain; we are not going to do this for them. We are sending a very clear message to partners that we cannot sit over their shoulders on every decision they are taking, but we can look at the delivery chain, see where we think the highest levels of risk are and maybe ask for a spot check on the due diligence where we think there is a particular area of risk in the delivery chain. We are clear that we can do more of that, but we do not want to take the pressure off our suppliers to do their job.
Q29 Mr Evans: I was just thinking about whether there is an acceptable level of shrinkage, as they call it in retail, which is shoplifting either by staff of by customers. Within DFID, do you think there is an acceptable level to which, further down the chain, there may be money being wasted or corruption that is not even being reported or seen? If a subcontractor is involved in this and maybe the prime contractor discovers it, they might rather carry the weight of it than report it, because if they report it the great fear is that the money may dry up completely. How much of that do you think is going on?
Q30 Dr Cameron: To answer your first question, no. The Secretary of State has been very clear about this, and Mark Lowcock was very clear about it yesterday at the hearing: as far as we are concerned, there is no acceptable level of shrinkage. Where we are aware that there are things going wrong, we expect to see immediate action. We expect the British taxpayer’s money to go to the purpose it is intended for. Our answer to suppliers that think, “We would rather keep this in house” is that you are not servicing the problem you have that enabled this to happen or looking at how to strengthen your systems and stop a bigger problem happening next week.
Q31 Jeremy Lefroy: Following on from Nigel’s questioning, the report says that some implementing partners are reluctant to report indirect losses, i.e. bribes or other forms or corruption, to DFID for fear of suspension of funding, and sometimes absorb the losses into operating costs. From my own experience, I would say that is absolutely correct. Basically, we are dealing with human nature here. What can you do to create positive incentives for people to share that information?
Everybody knows that getting aid through in certain circumstances requires the payment of bribes. That happens. We have heard it from the highest levels. Clearly it is not acceptable, but sometimes you are caught between a rock and a hard place on it. How can you use that and say, “Look, we understand that that happens. It is not acceptable; we want to use our influence with the authorities to challenge it”, but not use that as a stick to beat the particular deliverer of aid with, which makes them reluctant to talk about it?
Joy Hutcheon: David may want to come in on Syria on this, but the first thing I would say is that accepting bribes or offering bribes is illegal under the Bribery Act. There are no circumstances under which we are going to condone that.
Q32 Jeremy Lefroy: Yes, but let us be realistic. If somebody who is delivering aid through some checkpoints on the way to Aleppo is asked by a militia for money to get it through and that is the only way it is going to happen, it is going to happen whether we like it or not.
David Hallam: First of all, we are really clear with our partners on what our expectations are in terms of the law, but also in all our grant agreements we set out very clearly what they are required to do. Behind that, we try to build relationships with them so we are having an honest dialogue. For me, a good indication is when we get reporting. We get reporting sometimes of fraud, loss, diversion and sometimes of attempts by de facto authorities, as you are describing, to extract money or favour in some way. That is a good sign when it happens. We try to have that honest dialogue and create a culture of the relationship where partners will come to us and tell us when that is happening.
Q33 Jeremy Lefroy: Are you finding that does happen?
David Hallam: It does.
Q34 Jeremy Lefroy: Do they say, “Look, we have a real problem here; we need you to use your influence at a higher level to sort it out because people are demanding money off us to do things”?
David Hallam: We have a very good dialogue with them. That ranges from, for example, writing to organisations and reminding them of their responsibilities, which we have just done recently on Yemen; through inviting them into a workshop to discuss the issues that they are experiencing, to make sure everyone is clear, first, on roles and responsibilities but also about what those issues are; to informal conversations. I invite all my NGO counterparts around a table every quarter to have a chat about what is going on and, in a very informal way, understand the difficulties they are facing and discuss those with them.
Joy Hutcheon: We have done a lot of this in DRC as well. The office regularly has all the partners in to discuss how to handle these sorts of issues. I was pleased to see in the report that, when the team visited both DRC and Somalia, partners said that the offices had been encouraging them to report these kinds of issues early and regularly, and to have the conversation. The report also focused on the risk of multilaterals keeping issues to themselves. That is a matter of real concern to us and something we want to make progress on.
Q35 Jeremy Lefroy: That was what I was referring to. Do you have examples of where multilaterals are beginning to open up about that?
Joy Hutcheon: It is variable. We heard about the variable performance of multilaterals. To some extent, it depends on relationships in country; to some extent, it depends on messages down from the centre. We are clear that we will keep having the tough negotiations in country and sending messages about what we expect, and we are going to step up the dialogue at headquarters about the levels of accountability and transparency we are expecting from our multilateral partners.
Q36 Jeremy Lefroy: I will move on to refer to an ODI report on localising aid, which says that, along with smaller projects, we could have improved value for money through localising aid and supervising the smaller suppliers directly, rather than transferring the risk and responsibility to a lead supplier. This would also give DFID the opportunity to work with those local suppliers to improve their ability to resist corruption, as opposed to allowing them, through the lead supplier, to absorb it.
Joy Hutcheon: When we are looking at the market for delivering a programme, we are looking to deliver value for money in delivering that programme. We also want that to include developing the market. We are focused on both the broader SME market and the local markets in the countries where we are working. We have a market‑creation strategy, which includes activities to support local capacity‑building.
Realistically, the biggest opportunity there is going to be through the delivery chain: local suppliers coming into consortia with bigger or international suppliers, because our operating model means we cannot run lots and lots of little contracts. That is also helpful for capacity‑building purposes. We have run some market engagement activities in countries where we have been letting big contracts. We have just done that in Nepal for a large contract, and we got a good percentage of local supplier engagement in that.
Q37 Jeremy Lefroy: Which contract was that?
Joy Hutcheon: That was for the Accelerating Investment and Infrastructure programme. I can send you more details about that, if you would be interested. Then, in our statement of priorities and expectations for suppliers, which every supplier signs before we contract them, they have to commit to building local capacity by seeking to develop local markets. We have put that out there for our suppliers. Again, this is something we would like to make progress on, consistent with continuing to deliver value for money.
Q38 Jeremy Lefroy: Do you think that is effective? Sometimes the perception is that the big contractors are merely people or organisations that happen to have a lot of cash, which enables them to sit in that position, take a bit of risk and then slice off 20% or 30% of the value of the contract to cover their own costs, overhead and profit?
Joy Hutcheon: We have a key‑supplier relationship process with our big suppliers. We sit down with them quarterly and hold them to account against the statement of principles and expectations. Until I came into this job, I was the key relationship manager for Adam Smith International. We would sit down and talk about what they were doing to encourage the local supply market.
Q39 Chair: You have acknowledged, Ms Hutcheon, that, as the report says, fiduciary risk is not systematically monitored. That is what the report says. Am I wrong in interpreting your earlier responses in that way?
Joy Hutcheon: The report is drawing particular attention to issues around monitoring fiduciary risk through some supply chains, especially multilateral supply chains. We absolutely accept that we need to make progress on that.
Q40 Chair: I want to turn to the issue of learning, which, within the report, as an individual score, was given green/amber. Yet, on page 41, there is a summary of the comments by ICAI in its report about how effectively DFID is capturing and applying learning. Throughout that summary, there are some very negative comments. It says that it identified significant weaknesses. It comments that, since the internal audit of 2014, there has been a team established at DFID to develop a risk management framework, but the process has taken longer than envisaged. We have commented earlier about the Treasury guidelines being in 2009.
It says there are remaining areas of weakness, including risk appetite, risk-reward, risk transfer and escalation process, and that evidence of learning, while it saw it in some countries, was uneven and not yet routinely applied. How can you instil confidence in us and, indeed, how did you instil confidence in ICAI, bearing in mind the time it has taken you to look at all of this, that you will be implementing this with a sense of urgency, which is what ICAI says is required?
Joy Hutcheon: Let me talk about the timeline a bit, and then I will ask Peter to talk about the learning activities we have underway at the moment. I am not saying we could not have done any of this more quickly, but I want to reassure the Committee that risk was well on the agenda before 2014. Sometimes there are preparatory things you need to do, to build the capacity to get to where you want to get to. We had had a number of attempts at stepping up on risk. We had established a risk and control team in 2012. We established due diligence in 2013 and central assurance assessments for multilaterals.
Also at that stage, we put in place a programme of improving our finance capability and professionalising our finance capability. We recruited a new head of internal audit, who was a specialist in risk management, from outside the civil service. We increased the internal audit department by 65%. It was that new head of internal audit who, when he came in, chose to use the Treasury tool in 2014 to do the maturity assessment. He used a number of other tools as well. It is not the case that it is used by every government Department. That is a tool that he selected to move the Department on. It was very effective and gave us a very clear picture of where we were and where we needed to go.
Following that, in the two years since that audit report, we have introduced a new strategic risk register; we have launched a new risk management framework; we have published guidance on counter‑fraud and counter‑terrorist financing; we have strengthened our due diligence; we have introduced supply chain mapping; and we have trained about 1,000 staff in risk. My main point is a point that the chief commissioner made, which is that we could probably have got the documents out there earlier, but I would not have wanted to receive a report from ICAI that said, “You have written all the documents, but no one is doing anything.”
We have worked very hard with the business and the operation. We tried to make sure that the risk management framework was going to be intuitive and understood. We have worked in it; we have piloted it; we have talked to teams about it; we have taken feedback on it.
Let me pass over to Peter now, to talk about what we are doing next. The evidence is that, between the 2014 internal audit assessment and the 2016 internal audit assessment, when they came back to have another look, we had significantly moved across the risk maturity model, including on the two ticks where we were furthest to the left, one of which was about our people. We have been trying to do this process of culture change at the same time as trying to get the documents out there. It feels to us as though there has been a lot of activity, but I can see that, against the checklist of documents, it looks as if we might have done that faster.
Q41 Chair: You can appreciate why some of the Committee considered that this was quite a lenient rating, bearing in mind this is a performance review rather than a learning review.
Joy Hutcheon: I would go back to the evidence of the 2016 follow-up audit report, which said that we had made significant progress. It is a question of output or outcomes, isn’t it? What were the outputs and did we actually move the Department on to where we wanted it to be?
Q42 Chair: Yes. Yet we have had evidence that many of your front‑line staff are still confused.
Joy Hutcheon: In a way, I think the confusion is because they are thinking about it more, interrogating the risk statement more intelligently and saying, “Hang on a minute; you are saying there is a high risk. What exactly does that mean?” We have had a very good conversation with them about that, and I think we are now in a position to say something a bit more sophisticated. I fully expect that, in a year’s time, we will be able to articulate it further, as we work further with the business and people around the business, understand risk better and become more confident in handling it.
Q43 Chair: Do you think there will be less inconsistency in a few years’ time as well?
Joy Hutcheon: Yes, I do.
Peter Taylor: Part of it is to do with timing. When ICAI was doing its fieldwork, it was doing it at the time that we were rolling out the new framework. We rolled it out in April this year, basically when it was doing its fieldwork. There was that period of: “This is something new; what does it mean?” We were trying to get our head round it.
In terms of the training and the learning, we are targeting staff at very different levels. As Joy mentioned earlier, there will be financial management training for all senior civil servants next year. We have trained over 600 people in terms of the SRO role. They have had three days of dedicated training on that, including a focus on risk. We are also targeting programme managers, and we have a two-day risk and control masterclass, as we call it. 200 people will have gone through that over a 12-month period by February next year.
We keep in touch with all our staff: we do poll surveys and an annual progress review of how the better delivery reforms are bedding in. Both 12 months ago and in the most recent one, staff overwhelmingly said that they feel more confident in managing risk as a result of the changes we have made and the training and support we are providing.
Chair: Thank you for that information. With regard to your two-page management response, the Committee would find it more helpful if you gave more information like that in your responses to ICAI’s reports.
Q44 Stephen Twigg: Can I explore further the interaction between the principle of a high risk appetite with the absolutely correct zero tolerance stance on fraud and corruption? I have two different questions, in a sense. One is about how you manage what are potentially conflicting principles and, in particular, how that is communicated to staff so we have the kind of consistency in this area that Fiona was just talking about.
Joy Hutcheon: Overall, when we put the first risk appetite out, we were starting to get the organisation to focus on and think about risk. We really needed to get a statement out there that we had a high risk appetite, because we were in danger of the organisation tipping into risk aversion. If we become risk averse, we will simply not be able to deliver in the difficult environments that we are operating in. That was something we were trying to avoid.
We are about to issue new guidance on risk appetite. We are clear that we need to move beyond that and be clearer on it. We now have the organisation getting used to assessing risk in six categories, rather than generally talking about risk: looking at fiduciary, operational delivery, safeguarding and security risk. In terms of this apparent contradiction, we want to be clear with staff that we have an appetite for fiduciary risk where it is justified by the expected returns. That includes in places where, if we want to do anything, we do not have any other option. That does not feel like a high return, but the alternative of doing nothing is not acceptable.
The zero tolerance bit means that we need to be crystal clear about what the residual fiduciary risk is. We need to know how we are monitoring it; we need to know how we will know if it crystallises; and, if it crystallises, we will always take action. That is the zero tolerance point. I accept that we have not yet articulated that as clearly as I would like us to, to every member of the organisation.
Q45 Jeremy Lefroy: ICAI found that there are areas of good practice in various different countries and there was some informal sharing of the good practice. Are you looking at a more formal system, without wishing to do down informal systems, which can sometimes be extremely effective?
Joy Hutcheon: I will let Peter comment on this, but of course the informal systems are very effective. We know, for example, that our offices that need to do remote management all talk to each other all the time.
Q46 Jeremy Lefroy: When you say “remote management”, do you mean Syria?
Joy Hutcheon: Sorry, I mean Somalia, Syria, South Sudan—where they have access constraints. There is a lot of intensive sharing of information. The report noted that they had all been visiting each other. Some of this we will capture in the guidance, because it is best practice that we want to either mandate or strongly encourage people to follow. We have trained 1,000 people and a lot of what we have fed in is content from the business about what people have found works in particular places.
Peter Taylor: In terms of more formal sharing, we use the formal networks within DFID—for example, the professional cadres, be it governance, health, etc. For example, quite a few of them are having three‑day learning events at the moment. They are sharing experiences with each other on various things, including on programme management, programme design and issues that will inevitably be linked to risk. We are doing that. We also share examples through the programme management network that we have. We have developed case studies and examples of best practice, particularly in some of the fragile states we are talking about today. We put those on our intranet and share those with teams.
Our quality assurance unit, which looks at business cases over £40 million, plus anything innovative, novel or contentious from a technical perspective, will write reports as well. It flags up examples of good practice. We are trying to do more on what we call adaptive programme management: adaptive programmes, particularly where you are working in a very uncertain environment. Maybe at the start of your programme, you are not exactly sure how you are going to achieve what you want to achieve. We have had quite a big push on that in the last 12 months, sharing examples and helping people understand what that means in practice. We are doing that in quite a formal way, but, as Joy said, through informal networks as well.
Q47 Jeremy Lefroy: Thank you. In terms of sharing risk information between donors, it seems there is not much of that. Is there a move to try to strengthen that, in cases where it makes sense?
Joy Hutcheon: There is an awful lot of informal lot of informal sharing. Certainly from my own experience of running a country office, we were always talking to each other about where we were using the same partners. There is more formal sharing on pooled programmes. We would certainly encourage that, although there are data issues; you have to have the permission of the person you have done the due diligence of before you start sharing it with other people.
We tried to make delivery chain mapping more comprehensive and consistent earlier this year. We are about to launch more detailed guidance on delivery chain mapping. As the organisation gets better and develops more expertise in that, that will generate the opportunity for more exchange among donors, because I suspect we will be ahead of a lot of other donors in delivery chain mapping and we will see others starting to look at their delivery chains. Then we will be in a better position to see if there is a way of formalising some kind of exchange among donors that is useful enough. It is very easy to create cumbersome donor structures in country. In my view, we should look at how our offices progress with delivery chain mapping and ask ourselves that question, probably early next year.
Q48 Stephen Twigg: The Treasury guidance on risk management was published in 2009 and then, five years later, your internal audit identified a range of fundamental weaknesses in the risk management system. We have heard a bit today about some of the reforms. Why is it taking so long?
Joy Hutcheon: It goes back to the answer I gave the Chair a moment ago. We have been working on risk since I joined DFID in 2003. I can remember initiatives on risk and trying to improve risk management across the Department. It is quite a difficult thing to get traction on. In 2012, we created a risk and control team and really started thinking about how we were going to make progress. That was the point at which we started to strengthen our finance function, and concluded that we needed to strengthen our internal audit function and expand our internal audit function. It was at that point that our new head of internal audit came in and did the risk assessment in 2014.
I do not have data on this, but I would be surprised if we were the last government Department to have assessed ourselves against that.
Q49 Stephen Twigg: We want you to be the best. Your management response now agrees to an accelerated timetable for further reforms. Can you give us a timescale for that?
Joy Hutcheon: All of the reforms we have talked about this morning we want to have done largely by Christmas, certainly in the next few months. The confusion about the two years is that we are being a bit cautious about embedding as a description of culture change. We are absolutely clear: we want to change the culture in the department. When we are talking about embedding the new framework, we mean everybody understanding, getting it, changing their behaviour and growing in confidence. The framework will absolutely be out there as fast as we can. The framework is out there, and we have a suite of new guidance that will come out over the next few months.
Q50 Stephen Twigg: Will it all be in place by Christmas?
Joy Hutcheon: I am going to look at Peter now, to tell me what is not going to be ready.
Stephen Twigg: You said Christmas. That is much more specific than the normal answers I get.
Joy Hutcheon: The key thing is that we have asked internal audit to reassess us against that model in January, so they will be checking in on how we are doing. Then they are going to do that every year.
Peter Taylor: It is probably realistic to have everything in place by the end of this financial year. Some of it might slip to the other side of Christmas, but we are well on track to have all the key things that Joy has mentioned in place for staff to use on a daily basis certainly by the end of this financial year, and most of it by Christmas.
Stephen Twigg: It has slipped by three months between the two answers.
Joy Hutcheon: The new package of guidance, which I have seen and looks terrific, the new risk appetite statement and the guidance on delivery chain mapping, which are the crucial elements of this, will be out in the next few weeks and certainly before Christmas. We will continue doing things on this. As the internal audit report said, there is not a fixed end here. We will have to keep challenging ourselves and raising the bar.
Stephen Twigg: Thank you. That is helpful.
Q51 Chair: Can I go back again to this question of consistency, which the report is quite concerned about: consistency of rating measures, of rating risks and of categorisation? The report says, “At the time of our fieldwork, there was no detailed central guidance or standardised methodology” about this. You introduced some smart rules in April 2016—or updated them—with clearer guidance on assessing risks, but they are not mandatory. I am wondering how you can give us confidence that you are going to strengthen consistency across the board.
To throw another point in, for example in working with multilateral partners, some country officers have managed to negotiate risk mitigation and monitoring arrangements with specific multilateral partners, but it is inconsistent. Are you going to take this up, for example, at a central level with them to ensure consistency? This whole area of consistency is one I would really like to probe a little more.
Joy Hutcheon: It is a good question. We really expect to make a lot of progress on this with the guidance we are about to issue. The smart rules mandate that there must be an assessment of risk in programmes and that it is the SRO’s responsibility.
Chair: It says on page 23 of the report that they are not mandatory.
Peter Taylor: Which paragraph is that in page 23?
Q52 Chair: I am on 4.20, underneath table 3, which shows different methods of categorising risk across different countries.
Joy Hutcheon: The smart rules mandate an assessment of risk in the business case. We are about to issue guidance, which is absolutely clear that that assessment of risk must be against six categories of risk; it must be against categories of severity. They will be assessing it against six categories of risk; they will be assessing it against a set of categories of severity. The smart rules also then say they must manage, assess and monitor risk over the life of the programme.
Q53 Chair: Will they be mandatory rather than optional, if you say “they will mandate”?
Joy Hutcheon: The guidance is clear that that is what the risk assessment should look like.
Q54 Chair: And working with multilaterals?
Joy Hutcheon: On working with the multilaterals, I know you have discussed in this Committee many times the constraints we have in trying to shift multilaterals at the headquarters level. We will absolutely carry on trying to negotiate hard at country level to get the kind of agreements that some offices have. We will be stepping up the conversation at the headquarter level about a range of transparency and accountability issues.
Chair: If there are no further questions from my colleagues, thank you for your evidence today. It has been extremely helpful. I will, however, conclude that no doubt you noted in our earlier witness session that members of the Committee are concerned that the overall assessment ICAI has given to you was rather too lenient, bearing in mind the number of improvements that still need to be made. Thank you.