Report snapshot
Overview
Internal controls and governance support operations, compliance with legal obligations and reliable financial statements. This report analyses the internal controls and governance arrangements of 26 of the NSW Government’s largest agencies.
Key findings
Repeat findings continue to increase
Interim audits found weaknesses in internal controls and governance at 15 agencies. More findings now relate to high-risk, high-spend areas such as procurement and grants. Repeat findings increased from 33% to 42% of total findings.
Oversight of grant programs by agencies is weak
Most agencies have limited central oversight and monitoring of grants administration, including how they monitor delivery, reporting and financial management.
Some agencies have deficiencies in frameworks for due diligence checks, acquittal controls, evaluations and reconciliations between program records and grant disbursements. This weakens the level of assurance over financial accountability of public funds and limits agencies’ ability to demonstrate that grants were used for their intended purpose.
Agencies are not effectively engaging and reporting on consultants
Agencies did not always document the justification for hiring consultants, assess their performance or obtain conflict of interest declarations. Thirteen percent of sampled engagements did not include clauses relating to confidentiality to protect government information.
Mandatory annual reporting captures only a small share of payments to firms that provide consulting services, as payments for other professional service types are excluded. Agencies omitted at least $18.3 million in consultancy expenditure from their annual report disclosures since 2023–24.
High risk purchasing card transactions require more scrutiny
Purchasing card transactions included vendors that sell gift cards, entertainment, alcohol and tobacco products.
Personal, non-compliant and split purchases were made on purchasing cards. This points to weaknesses in acquittal controls. One in 5 transactions were not acquitted and approved within 30 days, limiting oversight.
Significant gaps remain in compliance with Cyber Security Policy requirements limiting effective oversight
Less than half of agencies reported compliance with requirements to protect and govern their risk exposure. Some agencies did not assess risks from legacy systems that cannot be patched, increasing their exposure to cyber-attack.
Strategic use and assurance of AI is limited
Agencies have limited visibility over AI use as they did not consistently register all AI use cases or centrally track costs. Governance is not keeping pace with the speed at which agencies are adopting AI.
Recommendations
The report makes 4 recommendations for stronger internal controls and governance for grants administration, purchasing cards, cyber security and AI oversight.