Reports
Actions for Internal Controls and Governance 2017
Internal Controls and Governance 2017
Agencies need to do more to address risks posed by information technology (IT).
Effective internal controls and governance systems help agencies to operate efficiently and effectively and comply with relevant laws, standards and policies. We assessed how well agencies are implementing these systems, and highlighted opportunities for improvement.
1. Overall trends
New and repeat findings |
The number of reported financial and IT control deficiencies has fallen, but many previously reported findings remain unresolved. |
High risk findings |
Poor systems implementations contributed to the seven high risk internal control deficiencies that could affect agencies. |
Common findings |
Poor IT controls are the most commonly reported deficiency across agencies, followed by governance issues relating to cyber security, capital projects, continuous disclosure, shared services, ethics and risk management maturity. |
2. Information Technology
IT security |
Only two-thirds of agencies are complying with their own policies on IT security. Agencies need to tighten user access and password controls. |
Cyber security |
Agencies do not have a common view on what constitutes a cyber attack, which limits understanding the extent of the cyber security threat. |
Other IT systems |
Agencies can improve their disaster recovery plans and the change control processes they use when updating IT systems. |
3. Asset Management
Capital investment |
Agencies report delays delivering against the significant increase in their budgets for capital projects. |
Capital projects |
Agencies are underspending their capital budgets and some can improve capital project governance. |
Asset disposals |
Eleven per cent of agencies were required to sell their real property through Property NSW but didn’t. And eight per cent of agencies can improve their asset disposal processes. |
4. Governance
Governance arrangements |
Sixty-four per cent of agencies’ disclosure policies support communication of key performance information and prompt public reporting of significant issues. |
Shared services |
Fifty-nine per cent of agencies use shared services, yet 14 per cent do not have service level agreements in place and 20 per cent can strengthen the performance standards they set. |
5. Ethics and Conduct
Ethical framework |
Agencies can reinforce their ethical frameworks by updating code‑of‑conduct policies and publishing a Statement of Business Ethics. |
Conflicts of interest |
All agencies we reviewed have a code of conduct, but they can still improve the way they update and manage their codes to reduce the risk of fraud and unethical behaviour. |
6. Risk Management
Risk management maturity |
All agencies have implemented risk management frameworks, but with varying levels of maturity. |
Risk management elements |
Many agencies can improve risk registers and strengthen their risk culture, particularly in the way that they report risks to their lead agency. |
This report covers the findings and recommendations from our 2016–17 financial audits related to the internal controls and governance of the 39 largest agencies (refer to Appendix three) in the NSW public sector. These agencies represent about 95 per cent of total expenditure for all NSW agencies and were considered to be a large enough group to identify common issues and insights.
The findings in this report should not be used to draw conclusions on the effectiveness of individual agency control environments and governance arrangements. Specific financial reporting, controls and service delivery comments are included in the individual 2017 cluster financial audit reports tabled in Parliament from October to December 2017.
This new report offers strategic insight on the public sector as a whole
In previous years, we have commented on internal control and governance issues in the volumes we published on each ‘cluster’ or agency sector, generally between October and December. To add further value, we then commented more broadly about the issues identified for the public sector as a whole at the start of the following year.
This year, we have created this report dedicated to internal controls and governance. This will help Parliament to understand broad issues affecting the public sector, and help agencies to compare their own performance against that of their peers.
Without strong control measures and governance systems, agencies face increased risks in their financial management and service delivery. If they do not, for example, properly authorise payments or manage conflicts of interest, they are at greater risk of fraud. If they do not have strong information technology (IT) systems, sensitive and trusted information may be at risk of unauthorised access and misuse.
These problems can in turn reduce the efficiency of agency operations, increase their costs and reduce the quality of the services they deliver.
Our audits do not review every control or governance measure every year. We select a range of measures, and report on those that present the most significant risks that agencies should mitigate. This report divides these into the following six areas:
- Overall trends
- Information technology
- Asset management
- Governance
- Ethics and conduct
- Risk management.
Internal controls are processes, policies and procedures that help agencies to:
- operate effectively and efficiently
- produce reliable financial reports
- comply with laws and regulations.
This chapter outlines the overall trends for agency controls and governance issues, including the number of findings, level of risk and the most common deficiencies we found across agencies. The rest of this volume then illustrates this year’s controls and governance findings in more detail.
Issues |
Recommendations |
1.1 New and repeat findings |
|
The number of internal control deficiencies reduced over the past three years, but new higher-risk information technology (IT) control deficiencies were reported in 2016–17. Deficiencies repeated from previous years still make up a sizeable proportion of all internal control deficiencies. |
Recommendation Agencies should focus on emerging IT risks, but also manage new IT risks, reduce existing IT control deficiencies, and address repeat internal control deficiencies on a more timely basis. |
1.2 High risk findings |
|
We found seven high risk internal control deficiencies, which might significantly affect agencies. |
Recommendation Agencies should rectify high risk internal control deficiencies as a priority |
1.3 Common findings |
|
The most common internal control deficiencies related to poor or absent IT controls. We found some common governance deficiencies across multiple agencies. |
Recommendation Agencies should coordinate actions and resources to help rectify common IT control and governance deficiencies. |
Information technology (IT) has become increasingly important for government agencies’ financial reporting and to deliver their services efficiently and effectively. Our audits reviewed whether agencies have effective controls in place over their IT systems. We found that IT security remains the source of many control weakness in agencies.
Issues | Recommendations |
2.1 IT security |
|
User access administration While 95 per cent of agencies have policies about user access, about two-thirds were compliant with these policies. Agencies can improve how they grant, change and end user access to their systems. |
Recommendation Agencies should strengthen user access administration to prevent inappropriate access to sensitive systems. Agencies should:
|
Privileged access Sixty-eight per cent of agencies do not adequately manage who can access their information systems, and many do not sufficiently monitor or restrict privileged access. |
Recommendation Agencies should tighten privileged user access to protect their information systems and reduce the risks of data misuse and fraud. Agencies should ensure they:
|
Password controls Forty-one per cent of agencies did not meet either their own standards or minimum standards for password controls. |
Recommendation Agencies should review and enforce password controls to strengthen security over sensitive systems. As a minimum, password parameters should include:
|
2.2 Cyber Security |
|
Cyber security framework Agencies do not have a common view on what constitutes a cyber attack, which limits understanding the extent of the cyber security threat. |
Recommendation The Department of Finance, Services and Innovation should revisit its existing framework to develop a shared cyber security terminology and strengthen the current reporting requirements for cyber incidents. |
Cyber security strategies While 82 per cent of agencies have dedicated resources to address cyber security, they can strengthen their strategies, expertise and staff awareness. |
Recommendations The Department of Finance, Services and Innovation should:
Agencies should ensure they adequately resource staff dedicated to cyber security. |
2.3 Other IT systems |
|
Change control processes Some agencies need to improve change control processes to avoid unauthorised or inaccurate system changes. |
Recommendation Agencies should consistently perform user acceptance testing before system upgrades and changes. They should also properly approve and document changes to IT systems. |
Disaster recovery planning Agencies can do more to adequately assess critical business systems to enforce effective disaster recovery plans. This includes reviewing and testing their plans on a timely basis. |
Recommendation Agencies should complete business impact analyses to strengthen disaster recovery plans, then regularly test and update their plans. |
Agency service delivery relies on developing and renewing infrastructure assets such as schools, hospitals, roads, or public housing. Agencies are currently investing significantly in new assets. Agencies need to manage the scale and volume of current capital projects in order to deliver new infrastructure on time, on budget and realise the intended benefits. We found agencies can improve how they:
- manage their major capital projects
- dispose of existing assets.
Issues | Recommendations or conclusions |
3.1 Capital investment |
|
Capital asset investment ratios Most agencies report high capital investment ratios, but one-third of agencies’ capital investment ratios are less than one. |
Recommendation Agencies with high capital asset investment ratios should ensure their project management and delivery functions have the capacity to deliver their current and forward work programs. |
Volume of capital spending Most agencies have significant forward spending commitments for capital projects. However, agencies’ actual capital expenditure has been below budget for the last three years. |
Conclusion The significant increase in capital budget underspends warrant investigation, particularly where this has resulted from slower than expected delivery of projects from previous years. |
3.2 Capital projects |
|
Major capital projects Agencies’ major capital projects were underspent by 13 percent against their budgets. |
Conclusion The causes of agency budget underspends warrant investigation to ensure the NSW Government’s infrastructure commitment is delivered on time. |
Capital project governance Agencies do not consistently prepare business cases or use project steering committees to oversee major capital projects. |
Conclusion Agencies that have project management processes that include robust business cases and regular updates to their steering committees (or equivalent) are better able to provide those projects with strategic direction and oversight. |
3.3. Asset disposals |
|
Asset disposal procedures Agencies need to strengthen their asset disposal procedures. |
Recommendations Agencies should have formal processes for disposing of surplus properties. Agencies should use Property NSW to manage real property sales unless, as in the case for State owned corporations, they have been granted an exemption. |
Governance refers to the high-level frameworks, processes and behaviours that help an organisation to achieve its objectives, comply with legal and other requirements, and meet a high standard of probity, accountability and transparency.
This chapter sets out the governance lighthouse model the Audit Office developed to help agencies reach best practice. It then focuses on two key areas: continuous disclosure and shared services arrangements. The following two chapters look at findings related to ethics and risk management.
Issues | Recommendations or conclusions |
4.1 Governance arrangements |
|
Continuous disclosure Continuous disclosure promotes improved performance and public trust and aides better decision-making. Continuous disclosure is only mandatory for NSW Government Businesses such as State owned corporations. |
Conclusion Some agencies promote transparency and accountability by publishing on their websites a continuous disclosure policy that provides for, and encourages:
|
4.2 Shared services |
|
Service level agreements Some agencies do not have service level agreements for their shared service arrangements. Many of the agreements that do exist do not adequately specify controls, performance or reporting requirements. This reduces the effectiveness of shared services arrangements. |
Conclusion Agencies are better able to manage the quality and timeliness of shared service arrangements where they have a service level agreement in place. Ideally, the terms of service should be agreed before services are transferred to the service provider and:
|
Shared service performance Some agencies do not set performance standards for their shared service providers or regularly review performance results. |
Conclusion Agencies can achieve better results from shared service arrangements when they regularly monitor the performance of shared service providers using key measures for the benefits realised, costs saved and quality of services received. Before agencies extend or renegotiate a contract, they should comprehensively assess the services received and test the market to maximise value for money. |
All government sector employees must demonstrate the highest levels of ethical conduct, in line with standards set by The Code of Ethics and Conduct for NSW government sector employees.
This chapter looks at how well agencies are managing these requirements, and where they can improve their policies and processes.
We found that agencies mostly have the appropriate codes, frameworks and policies in place. But we have highlighted opportunities to improve the way they manage those systems to reduce the risks of unethical conduct.
Issues | Recommendations or conclusions |
5.1 Ethical framework |
|
Code of conduct All agencies we reviewed have a code of conduct, but they can still improve the way they update and manage their codes to reduce the risk of fraud and unethical behaviour. |
Recommendation Agencies should regularly review their code-of-conduct policies and ensure they keep their codes of conduct up-to-date. |
Statement of business ethics Most agencies maintain an ethical framework, but some can enhance their related processes, particularly when dealing with external clients, customers, suppliers and contractors. |
Conclusion Agencies can enhance their ethical frameworks by publishing a Statement of Business Ethics, which communicates their values and culture. |
5.2 Potential conflicts of interest |
|
Conflicts of interest All agencies have a conflicts-of-interest policy, but most can improve how they identify, manage and avoid conflicts of interest. |
Recommendation Agencies should improve the way they manage conflicts of interest, particularly by:
|
Gifts and benefits While all agencies already have a formal gifts-and-benefits policy, we found gaps in the management of gifts and benefits by some that increase the risk of unethical conduct. |
Recommendation Agencies should improve the way they manage gifts and benefits by promptly updating registers and providing annual training to staff. |
Risk management is an integral part of effective corporate governance. It helps agencies to identify, assess and prioritise the risks they face and in turn minimise, monitor and control the impact of unforeseen events. It also means agencies can respond to opportunities that may emerge and improve their services and activities.
This year we looked at the overall maturity of the risk management frameworks that agencies use, along with two important risk management elements: risk culture and risk registers.
Issues | Recommendations or conclusions |
6.1 Risk management maturity |
|
All agencies have implemented risk management frameworks, but with varying levels of maturity in their application. Agencies’ averaged a score of 3.1 out of five across five critical assessment criteria for risk management. While strategy and governance fared best, the areas that most need to improve are risk culture, and systems and intelligence. |
Conclusion Agencies have introduced risk management frameworks and practices as required by the Treasury’s:
However, more can be done to progress risk management maturity and embed risk management in agency culture. |
6.2 Risk management elements |
|
Risk culture Most agencies have started to embed risk management into the culture of their organisation. But only some have successfully done so, and most agencies can improve their risk culture.
|
Conclusion Agencies can improve their risk culture by:
|
Risk registers and reporting Some agencies do not report their significant risks to their lead agency, which may impair the way resources are allocated in their cluster. Some agencies do not integrate risk registers at a divisional and whole-of-enterprise level. |
Conclusion Agencies not reporting significant risks at the cluster level increases the likelihood that significant risks are not being mitigated appropriately. |
Effective risk management can improve agency decision-making, protect reputations and lead to significant efficiencies and cost savings. By embedding risk management directly into their operations, agencies can also derive extra value for their activities and services.
Actions for Planning and Environment 2017
Planning and Environment 2017
The following report highlights results of financial audits of agencies in the Planning and Environment cluster. The report focuses on key observations and findings from the most recent audits of these agencies.
The audits were completed for most agencies in the cluster and unqualified audit opinions issued. Issues identified during the financial statement audits of seven small agencies delayed their finalisation beyond the statutory deadline, and six of these remain incomplete. Apart from these small agencies, the quality of financial reporting across the cluster remained at a high standard.
This report provides Parliament and others with the audit results, observations and recommendations for Planning and Environment cluster agencies. The report has been structured into two chapters focussing on financial reporting and controls and service delivery.
The Planning and Environment cluster plays a role in ensuring each community across New South Wales receives the services and infrastructure it needs.
This chapter outlines our audit observations and recommendations related to financial reporting and controls of Planning and Environment cluster agencies for 2016–17.
Observation | Conclusion or recommendation |
2.1 Quality of financial reporting |
|
Unqualified audit opinions were issued for 39 of the 45 cluster agencies' financial statements. |
Issues identified during the financial statement audits of seven smaller agencies delayed their completion. Six audits remain incomplete at the date of this report. Apart from these seven small agency audits, the quality of financial reporting across the cluster remained at a high standard. |
2.2 Timeliness of financial reporting |
|
Seven agencies' financial statement audits were not completed by the statutory deadline with six audits incomplete at the date of this report. |
Issues identified during the financial statement audits of seven smaller agencies delayed their finalisation beyond the statutory deadline. These agencies would benefit from performing additional early close procedures in future reporting periods. |
2.3 Financial and sustainability analysis |
|
Water and Electricity utility agencies continue to operate with low liquidity ratios. |
A liquidity ratio below one is an indicator that an entity may not be able to pay its debts as and when they fall due. Whilst liquidity ratios were below one, utility agencies demonstrated they can continue to support ongoing operations due to:
|
2.5 Internal controls |
|
One in six internal control weaknesses reported in 2016–17 were repeat issues. |
Delays in implementing audit recommendations can prolong the risk of fraud and error. Recommendation (repeat issue): anagement letter recommendations to address internal control weaknesses should be actioned promptly, with a focus on addressing repeat issues. |
Nine of these internal control weaknesses related to the creation, modification, deletion and review of user access to financial systems. |
These control weaknesses may compromise the integrity and security of financial data. Recommendation (repeat issue): Management of user administration over financial systems should be strengthened to prevent inappropriate access to financial information. |
This chapter outlines our audit observations, conclusions and recommendations relating to service delivery for 2016–17.
Observation | Conclusion or recommendation |
3.1 Premier's and State priorities |
|
The Planning and Environment cluster is responsible for delivering five Premier's and State priorities. |
One priority target was achieved in 2016–17, two targets are on track to be achieved and progress towards one target slowed. Progress against one target cannot be determined. |
3.2 Planning |
|
Housing Completion |
|
There were 63,506 housing completions in 2016–17. This was 4.1 per cent above the Premier’s priority target of delivering 61,000 housing completions per year. |
The Australian Bureau of Statistics data shows the housing completions target was achieved in 2016–17. |
Housing supply |
|
The number of approvals for new houses in 2016–17 was 72,472 against the State priority target of more than 50,000 approvals per year. |
The Australian Bureau of Statistics data indicates the housing approvals target was achieved in 2016–17. |
Major project assessment |
|
State significant developments are not clearly defined for the purposes of reporting against the State priority target. | The Department of Planning and Environment will clarify with the Department of Premier and Cabinet which developments are captured by the State priority target. |
The Department of Planning and Environment’s data shows the time taken to assess complex State significant developments increased by 16 per cent in 2016–17 while the time taken to assess less complex developments reduced by 20 per cent. | The Department of Planning and Environment considers it is on track to meet the State priority target of halving the time taken to assess State significant developments, despite uncertainty over the target measure. |
Housing acceleration fund |
|
Program business cases were not developed for projects in Housing Acceleration Fund Rounds 1 to 4. The Department advised a program business case will be developed for Housing Acceleration Fund Round 5 projects. |
A program business case is necessary to ensure related projects are evaluated, managed and coordinated effectively. |
A benefit realisation review process has not yet been approved for Housing Acceleration Fund projects. The Department of Planning and Environment advised it is developing a benefit realisation review process. |
A benefit realisation review process is necessary to determine whether funded projects achieved intended outcomes. |
Greater Sydney Commission |
|
The Greater Sydney Commission forecasts a further 725,000 dwellings in the greater Sydney region will be required up to 2036 to meet housing demand. | In response to population growth, the Commission has set a five-year housing supply target of 189,100 houses across the five Greater Sydney Commission districts. |
ePlanning system |
|
The Department of Planning and Environment did not perform a benefit realisation review for phase one of the ePlanning project. It has committed to performing a benefit realisation review after completion of phase two in 2018. | It cannot be determined if phase one of the project delivered expected outcomes as a benefit realisation review was not performed. |
3.3. Environment and Heritage |
|
Litter volume in New South Wales was 6.6 litres per 1,000 square metres in 2016–17, an increase of 16 per cent from the prior year. This is above the Premier's priority litter volume target of 4.2 litres per 1,000 square metres by 2020. | The Environment Protection Authority's data indicates the progress towards the target of reducing the volume of litter by 40 per cent by 2020 has slowed. |
The NSW Government plans to invest $240 million to facilitate strategic biodiversity conservation on private land. | Performance measures have not yet been developed for the private land conservation program. |
3.4 Water |
|
IPART reduced water usage charges for most Sydney Water Corporation customers in 2016–17. | Water usage prices in New South Wales compare favourably to larger water utilities in other jurisdictions. |
Hunter Water Corporation's water recycling and water conservation performance has been stable over recent years. The volume of Sydney Water Corporation’s recycled water reduced by 12 per cent in 2016–17 compared to the previous year. |
Sydney Water Corporation experienced reduced industry demand for recycled water. Several large industrial customers relocated away from Sydney. |
3.5 Arts and culture |
|
A State priority target is to increase overall attendance at cultural venues and events in New South Wales by 15 per cent from 2014–15 levels by 2019. | The Department of Planning and Environment's data indicates overall attendance increased by 16 per cent in 2015–16, although attendance fluctuated across individual venues and events. This indicates progress towards achieving the overall target by 2019. |
Actions for Family and Community Services 2017
Family and Community Services 2017
The following report focuses on key observations and findings from the most recent audits of agencies in the Family and Community Services cluster.
The report includes a range of findings on service delivery. The Department of Family and Community Services' data indicates that family preservation programs are having a positive impact on children and young people entering statutory care. On the other hand, waiting times for social housing applicants increased in 2016-17.
1. Financial reporting and controls
Quality of financial reporting | Unqualified audit opinions were issued for all cluster agencies' financial statements. |
Timeliness of financial reporting | Agencies completed mandatory early close procedures and all but one agency submitted financial statements by the statutory deadline. |
Internal controls | The 2016–17 audits reported 29 internal control improvements to cluster agencies’ management. None of these findings were high risk. Eleven related to information technology control weaknesses in key financial business systems. |
2. Service Delivery
Commissioning | Non-government organisations (NGOs) received $2.6 billion in 2016–17 to deliver services. |
Children and young people |
The Department of Family and Community Services data indicates that family preservation programs are reducing the number of children and young people entering statutory care. The Department's data shows 86 per cent of children and young people in statutory care had their placements reviewed in the 12 months to 30 June 2017. Legislation requires all placements are reviewed at least every 12 months. |
Social Housing | The Department's data shows waiting times for social housing applicants are longer than last year. |
People with disability | Under the current timetable for implementing the National Disability Insurance Scheme, the Department plans to transfer direct disability services to NGOs by 30 June 2018. |
This report provides Parliament and others with the audit results, observations, conclusions and recommendations for Family and Community Services cluster agencies. The report has been structured into two chapters focusing on financial reporting and controls and service delivery.
The Family and Community Services cluster works with children, adults, families and communities to improve lives and help people realise their potential.
This chapter outlines audit observations, conclusions and recommendations related to the financial reporting and controls of agencies in the Family and Community Services cluster for 2016–17.
Financial reporting is an important element of good governance. Confidence in public sector decision making and transparency is enhanced when financial reporting is accurate and timely.
Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies. They are essential for quality and timely decision making.
Observation | Conclusion or recommendation |
2.1 Quality of financial reporting | |
Unqualified audit opinions were issued for all cluster agencies' financial statements. | The quality of financial reporting remains high across the cluster. |
2.2 Timeliness of financial reporting | |
Agencies completed mandatory early close procedures and all but one submitted financial statements by the deadline. | Early close procedures continue to allow issues and financial reporting risk areas to be addressed early in the audit process. There are opportunities to improve effectiveness of early close procedures. |
2.3 Internal controls | |
The 2016–17 audits reported 29 internal control weaknesses. While none were high risk, the Department had five repeat issues. |
Management accepted the audit findings and advised they are actioning recommendations. Timely action is important to ensure internal controls operate effectively. |
Eleven of these internal control weaknesses were related to IT system user access administration and security over financial systems. |
Controls weaknesses may compromise the integrity and security of financial data. Recommendation Agencies should:
|
Government outcomes can be improved by delivering the right mix of services, whether from the public, private or not for profit sectors. Service delivery reform will be most successful if there is clear accountability for service delivery outcomes, decisions are aligned to strategic direction and performance is monitored and evaluated.
This chapter outlines our audit observations, conclusions and recommendations related to service delivery by agencies in the Family and Community Services cluster for 2016–17.
Observation | Conclusion or recommendation |
3.1 Commissioning |
|
Non-government organisations (NGOs) received $2.6 billion funding in 2016–17 to deliver services. | Commissioning of service delivery can change the profile of risks that need to be managed. The Department has established a Commissioning Division and developed its ‘Commissioning for Better Outcomes Framework’. |
3.2 Children and young people |
|
All the Department's Districts are accredited to provide out-of-home care services. The Department's data indicates 66 more children and young people were in statutory care at 30 June 2017 compared to 30 June 2016. This contrasts to the previous year where 1,150 more children were in statutory care at 30 June 2016 than at 30 June 2015. |
The Department is complying with out-of-home care service standards, but one District has an additional condition attached to its accreditation. Department’s data indicates that family preservation programs are having a positive impact.. |
The Department's data shows 86 per cent of children and young people in statutory care had their placement reviewed at 30 June 2017. The Department’s data shows, at 30 June 2017, 41 per cent of children and young people with closed case plans for the 12 months ended 30 June 2016 were re-reported at risk of significant harm. |
The Department did not meet the legislative requirement to review the placement of all children and young people in statutory care annually. The number of children being re-reported at risk of significant harm is above the Premier’s Priority target of 34 per cent by June 2019. |
3.3. Social Housing |
|
Waiting time for priority and non-priority social housing applicants increased in 2016–17, by 19 per cent and 3 per cent respectively. | Some factors impacting waiting time for social housing applicants are outside the control of the Department. |
3.4 People with disability |
|
A Bilateral Agreement between the Australian and NSW Governments sets out how eligible persons access the National Disability Insurance Scheme (NDIS) between 1 July 2016 and 30 June 2018. |
Under the timetable for the NDIS, the Department plans to transfer direct disability services to NGOs. |