Certificates of assurance
Scope
This section details the principles on the provision of certificates of assurance to support the signing of the governance statements provided by Accountable Officers as part of the annual accounts of all organisations to which the Scottish Public Finance Manual (SPFM) is directly applicable.
Applicability
The assurance framework applies to constituent parts of the Scottish Administration i.e. the core Scottish Government (SG), the Crown Office and Procurator Fiscal Service, SG Executive Agencies, and non-ministerial offices. Other organisations to which the SPFM is directly applicable – including separate accounting bodies sponsored by the SG – should arrange for appropriate assurance frameworks consistent with this guidance to be put in place.
Definitions
Shall/Must: Denotes a requirement; a mandatory element
Should: Denotes a recommendation; an advisory element
May: Denotes approval
Might: Denotes a possibility
Can: Denotes both capability and possibility
Is/Are: Denotes a description
Links to guidance
Principles
- Defined in the Public Finance and Accountability Act (PFA Act) under sections 1-20
SG guidance
- Is available via SG Intranet and the Governance Hub
Public Sector Bodies Guidance
- Public Sector Bodies are equally subject to these principles and guidance on certificates of assurance processes are available via the Governance Hub
Review/update
Lead area: Scottish Government Finance Directorate; Risk Control and Assurance Division – Governance and Accountability Branch.
For update/review of this principle please refer to the Guidance and Procedure available on the SG intranet or from the Governance and Accountability team, this includes information on ministerial approval.
Accessibility guidance is available on the SG intranet.
Background
Accountable Officers must prepare a Governance Statements as part of the annual accounts for which they are directly responsible. The Governance Statement provides information to the reader on the organisation’s internal control structure and its management of resources including specific assurances from the Accountable Officer on the regularity, propriety, and value for money of the public finances for which they are answerable. It explains the internal control structure which has been applied during the year.
To sign governance statements, Accountable Officers require assurances on the maintenance and review of internal control systems within or affecting their area of responsibility. Internal control systems comprise the whole network of systems established in an organisation to provide assurance that organisational objectives will be achieved, with particular reference to:
- risk management
- the effectiveness of operations
- the economical and efficient use of resources
- compliance with applicable policies, procedures, laws, and regulations
- safeguards against losses, including those arising from fraud, irregularity or corruption
- the integrity and reliability of information and data
Assurances are required in relation to each financial year. Unqualified assurances can only be provided where best practice and any relevant guidance (e.g. the SPFM) had been followed throughout the accounting period. it is recognised that such assurances can provide only reasonable and not absolute assurance.
Assurance framework
Within the Scottish Administration assurances from Deputy Directors (or equivalents) to Directors (or equivalents) should be provided in the form set out in Annex 1.
The certificate should be completed in consultation, as appropriate, with relevant finance officials and internal auditor outlining that they are complying with required internal controls and as to whether any significant matters had arisen that would need to be raised to the Director (or equivalent)which could affect the level of assurance being given. The Internal Control Checklist at Annex 2 has been designed to identify any control weaknesses.
The Internal Control Checklist must be completed in full, with due diligence. Guidance and explanatory notes are provided in column 2 for further assistance on what is expected to provide assurance. The third column should record the steps taken to confirm and review the existence and strength of internal controls, highlighting any significant absence or weakness in the controls. The information recorded must reflect, and not contradict, the evidence and the various sources of existing reporting and assurance data and, where possible, available data and reporting should be signposted. The areas covered by the checklist are not exhaustive and the accompanying certificate of assurance must include any matters of significance that are not covered by the checklist.
Within the core Scottish Government the process is undertaken via the certificates of assurance online system, all other bodies within the Scottish Administration should undertake their own separate exercise. Sponsored bodies should also have separate processes for collecting and recording their assurances aligned to this chapter. Checklists should be reviewed by relevant finance officials to ensure the checklists have been completed in full and that the information provided is consistent with their knowledge of the area concerned. Directors (or equivalent) use the completed checklists, the associated certificates, and their own knowledge/review of the control and risk processes in their areas of responsibility when preparing their own certificates of assurance.
Completion of Annex 1 by Deputy Directors (or equivalent) with sponsorship responsibilities should outline accountability arrangements and take account of any internal control issues that should be included in the governance statements of relevant sponsored bodies. Any additional issues included in the finalised governance statements of sponsored bodies or significant matters arising between these governance statements being finalised and the signing of the Scottish Government consolidated accounts, must be reported up the line as and when they come to light. Deputy Directors (or equivalent) with sponsorship responsibilities decide, in consultation with relevant finance officials and internal auditors, what if any form of assurance is appropriate in relation to any sponsored bodies that are not separate accounting entities and do not complete governance statements.
Assurances from Directors (or equivalents) to Accountable Officers should be provided in the form set out in Annex 3. These certificates should be submitted to relevant audit (and assurance) committees together with, either a draft certificate of assurance for the Accountable Officer to provide to the Principal Accountable Officer for the Scottish Administration or a draft governance statement for signature by the Accountable Officer - see the following paragraph.
Accountable Officers sign governance statements in respect of the accounts for which they are directly responsible, and the Principal Accountable Officer signs the governance statement in respect of the Scottish Government consolidated accounts.
Assurances to the Principal Accountable Officer from Portfolio Accountable Officers - based on assurances from relevant Directors (or equivalents), should be provided in the form set out in Annex 4.
Assurances to the Principal Accountable Officer from the Accountable Officers of the Crown Office and Procurator Fiscal Service (COPFS) and Executive Agencies within the Scottish Government accounting boundary should take the form of the governance statements provided alongside the COPFS and Agency accounts. Relevant issues in the governance statements of NHS bodies within the Scottish Government accounting boundary must be included in the assurance from the Portfolio Accountable Officer for Health.
Assurances on Scottish Government corporate services in relation to the consolidated accounts will be provided to the Principal Accountable Officer by the Scottish Government Chief Financial Officer and the Director of Corporate Operations and the Director of People. These assurances on corporate services will be copied as appropriate to the Accountable Officers of those separate accounting entities (e.g. Executive Agencies, non-ministerial departments, and Scottish Government sponsored bodies) which rely to varying degrees on corporate services provided by the core Scottish Government.
Timetable/review
Certificates of assurance will be commissioned towards the end of each financial year allowing sufficient time for the completion of the process to meet the timetable for signature of relevant accounts for both the Scottish Government consolidated accounts and for relevant separate accounting entities.
The certificates of assurance process, including the completion and review of the Internal Control Checklists, is subject to review by both internal and external auditors as part and copies of the checklists and certificates must be kept locally. External auditors will review these as part of their audit of the accounts and internal auditors will review these as part of their internal review of governance matters.
Updated: August 2026