Feedback

2026-2027 Triennial Audit Briefing

04 August 2026      Fiona Wilson, National Code Advisor

Preparing for your 2026-27 Triennial Audit 

A practical three-step approach for ACoP members 

Purpose. This briefing is for ACoP members undertaking a triennial audit in the 2026-27 cycle. It is intended to help members plan early, organise stakeholders, make best use of the annual self-audit, and submit a complete and well-evidenced audit by the ACoP deadline of 30 April. 

Context. The triennial audit is undertaken every three years through the formal audit process, with the annual self-audit acting as a signpost for the live triennial. The 2025-26 year was the first year of the new Code, which came into force on 1 May 2025. Members in this cycle therefore have the advantage of having completed at least one self-audit under the new Code and can draw on the membership team’s feedback from previous triennials to support a smoother, less painful process. 

Recommended approach 

Treat your triennial audit as a three-step activity: stakeholder onboarding, planning and implementing, and submitting the audit. 

At a glance 

Step 

Focus 

Main outcome 

1 

Stakeholder onboarding 

The right people are engaged early, with roles, responsibilities and approval routes understood. 

2 

Planning and implementing 

Evidence, actions, inspections, communications and tools are organised and actively managed. 

3 

Submitting the audit 

The audit is approved, all clause evidence is included, required declarations are made, and recommendations are entered on the CMS. 

Step 1: Stakeholder onboarding 

Aim 

Put the right people, meetings and accountabilities in place early so the audit does not rely on one individual or become compressed close to the deadline. 

  1. Book a place on your Audit & Risk Committee (ARC) (or equivalent body) meeting agenda for early in the new year. This helps ensure your final audit is reviewed and formally approved by your institution before the ACoP submission deadline of 30th April. 
  2. Book an initial meeting with your auditors early in the academic year and agree an action plan and timeline. 
  3. We recommend forming an ACoP working group as the evidence suggests this works successfully for those who adopt it. If possible, include representatives from each department involved in evidencing Code compliance ensuring a coordinated and consistent approach to the audit process. Senior leaders and departmental heads should have a clear understanding of roles, responsibilities, and accountabilities, and be prepared to provide support where required. 
  4. Schedule a briefing for stakeholders and cross-operational teams. Be clear about roles and responsibilities, action deadlines, and the need for agreement and support from managers for work being undertaken. 

Step 2: Planning and implementing 

Aim 

Use previous audit findings, self-audit evidence, auditor engagement and practical tools to identify and resolve issues before submission. 

  1. Check the actions from your previous triennial audit. Are they completed? The ACoP team sends timely reminders on overdue actions, but members should also check progress internally. 
  2. Use your previous self-audit to remind yourself where evidence is kept. If responsibility sits with another team or department, make sure they understand what is needed and by when. 
  3. Be proactive. Identify what needs fixing now. Use the self-audit to highlight potential non-compliance, agree what needs to be actioned with relevant teams and departments, and set reasonable deadlines.  
  4. For onsite inspections, ensure colleagues who may be impacted or involved are fully briefed on when inspections will take place and what to expect. 
  5. If you do not agree with your auditor, check The Code and challenge respectfully where you believe you meet compliance. Ask the ACoP team for help if needed. This is a reasonable part of the process. 
  6. Consider which tools will help manage the process. Ensure you are up to date with the CMS and that other team members have had recent training or familiarisation. Consider whether you need a folder structure for evidence, or a shared action plan document that teams and departments can access. 
  7. Agree how you will communicate with your auditor. For example, specify whether you prefer phone calls, weekly check-ins, face-to-face meetings or another approach. 
  8. Decide how you will keep stakeholders up to date and how you will escalate or request help if internal teams or departments are not responding to requests. 

Step 3: Submitting the audit 

Aim 

Submit a complete, approved triennial audit and provide assurance that required data and follow-up actions are accurate and actively managed. 

1. Complete the submission: 

  • Ensure the audit has been reviewed and approved by your ARC (or equivalent) and includes evidence for all 252 clauses. 
  • Formally submit (close) the triennial audit by uploading the report and evidence to the CMS once your recommendations have been entered onto the system. 

2. Make a declaration confirming that your building list, complaints, audit recommendations, self-audit and member record data is accurate. 

Note - Audit recommendations must be added to the CMS with target dates and a responsible person. Recommendations do not have to be completed before 30 April, but future deadlines must be reasonable and proportionate. For example, if an action is to update posters on noticeboards in kitchens, the deadline should not fall after the next residents have arrived. 

3. Respond to your audit outcome letter from the CASB, if required. The outcome will state whether the audit is accepted, accepted with actions or not accepted by ACoP. Depending on the outcome, the letter may set out actions requiring your organisation to provide additional assurance that you are engaged with ACoP and are committed to maintaining Code compliance. 

Practical questions for members to ask internally 

  • Who owns each area of evidence, and who can resolve issues if actions are delayed? 
  • Where is the evidence stored, and is it easy for relevant colleagues to access? 
  • Which actions can be resolved quickly, and which need senior oversight or additional resourcing? 
  • How will progress be tracked, reported and escalated? 
  • Has the ARC route and approval timing been confirmed? 
  • Is the CMS up to date, and are colleagues confident using it? 

Key message 

Start early, involve the right people, use the self-audit as your roadmap, and keep evidence and actions visible. The 2026-27 cycle gives members the benefit of prior self-audit activity under the new Code, alongside the learning and improvements ACoP have implemented after previous triennials. The aim is to make the process structured, timely and proportionate, while maintaining clear assurance around Code compliance. 



Read more



This site uses cookies and other tracking technologies to assist with navigation and your ability to provide feedback, analyse your use of the site and services and assist with our member communication efforts. Privacy Policy. Accept cookies Cookie Settings