Refine search Expand filter

Reports

Published

Actions for Central Agencies 2019

Central Agencies 2019

Treasury
Premier and Cabinet
Financial reporting
Internal controls and governance
Management and administration
Risk

The Auditor-General for New South Wales, Margaret Crawford, released her report today on the results of the financial audits of NSW Government central agencies, namely the Premier and Cabinet, Treasury and Customer Service clusters. There are 191 agencies in these clusters, including government financial, superannuation and insurance entities.

Unqualified audit opinions were issued on the financial statements for all agencies in the clusters. There were two high risk and 99 moderate risk audit findings on internal controls. Of these, 31 percent were repeat issues, and most related to weaknesses in information technology access controls.

The report notes a number of audit observations including:

  • a qualified opinion on information technology internal controls at an outsourced service provider
  • self-insurance losses of $1.4 billion partly due to unfavourable movements in the risk free discount rate, and increases in workers compensation claims, including psychological injury claims
  • a shortfall (unfunded liability) of $637 million at 30 June 2019 in the Home Building Compensation Fund, due to premiums not being sufficient to meet costs of the scheme
  • agencies self-assessed against the Australian Cyber Security Centre’s ‘Essential 8’ cyber risk mitigation strategies for the first time in 2018-19. Based on their own self assessments, more work needs to be done to improve cyber security resilience.

This report analyses the results of our financial statement audits of the Treasury, Premier and Cabinet and Customer Service clusters for the year ended 30 June 2019. Our key observations are summarised below.

This report provides parliament and other users of the NSW Government's central agencies and their cluster agencies financial statements with the results of our audits, observations, analysis, conclusions and recommendations in the following areas:

  • financial reporting
  • audit observations
  • government financial services.

Central agency clusters were significantly impacted by Machinery of Government changes which took effect on 1 July 2019. This report is focussed on agencies now in the Treasury, Premier and Cabinet and Customer Service clusters. Some of these agencies may have been in another cluster during 2018–19. Please refer to the section on Machinery of Government changes for more details.

Central agencies and their key responsibilities are set out below.

Machinery of Government (MoG) refers to how the government organises the structures and functions of the public service. MoG changes are where the government reorganises these structures and functions and they are given effect by Administrative orders.

The MoG changes announced following the NSW State election on 23 March 2019 significantly impacted Central Agencies’ clusters through Administrative Changes Orders issued on 2 April 2019 and 1 May 2019. These orders took effect on 1 July 2019.

Section highlights

Significant impacts of the 2019 MoG changes included:

  • abolishing the former Department of Finance, Services and Innovation, and creating the Department of Customer Service as the principal agency within the newly established Customer Service cluster
  • transferring Jobs for NSW, Destination NSW and the Western City and Aerotropolis Authority into the Treasury cluster
  • transferring Arts and Culture entities and Aboriginal Affairs NSW into the Premier and Cabinet cluster
  • new responsibilities, risks and challenges for each cluster

Financial reporting is an important element of good governance. Confidence and transparency in public sector decision making are enhanced when financial reporting is accurate and timely.

This chapter outlines our audit observations on the 2019 financial reporting of agencies in the Treasury, Premier and Cabinet, and Customer Service clusters.

Section highlights

  • Unqualified audit opinions were issued on the 30 June 2019 financial statements of all agencies within the three clusters, and the Legislature.
  • The NSW Self Insurance Corporation (Corporation) 2018–19 financial statements did not include an estimate of the liability for unreported incidents of abuse that have occurred within NSW Government institutions. This is because the Corporation’s financial exposure could not be reliably measured at 30 June 2019. The exposure was instead disclosed as an unquantified contingent liability in the financial statement notes. This liability may be material to the Corporation and the Total State Sector financial statements.
  • We recommend management and those charged with governance review instructions provided to management experts each year, along with other significant accounting judgements.
  • Agencies will be implementing the requirements of new accounting standards shortly. These could significantly impact their financial positions and operating results. We noted instances where agencies need to do more work on their impact assessments to minimise the risk of errors in the 2019–20 financial statements. 

Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies. They are essential for quality and timely decision making.

This chapter outlines our observations and insights from our financial statement audits of agencies in the Treasury, Premier and Cabinet and Customer Service clusters.

Section highlights

  • The 2018–19 audits found two high risk and 99 moderate risk issues across the agencies. Of these, 31 per cent were repeat issues. The most common repeat issue related to weaknesses in controls over information technology user access administration.
  • NSW Government agency self-assessment results show that the NSW Public Sector's cyber security resilience needs urgent attention.
  • GovConnect received a qualified opinion from the auditor of their service provider, Unisys, over weaknesses in information technology controls.
  • Crown revenues from taxes, fines and fees continued to increase, but this was offset by decreases in stamp duty on property sales.
  • The CTP reform resulted in green slip refunds of $198 million to vehicle owners. Unclaimed refunds are to be returned to motorists through a reduction in green slip premiums.

Background

This chapter outlines our audit observations, conclusions and recommendations specific to NSW Government agencies providing financial services.

Section highlights

  • Last year's Auditor-General's Report to Parliament recommended Treasury consult with STC Pooled Fund and PCS Fund Trustees to prescribe prudential standards and requirements. Treasury has not taken specific action to address this recommendation.
    We recommend Treasury formally assess the merits of implementing prudential standards and supervision arrangements, after considering the risks, benefits and costs to scheme members.
  • The NSW Self Insurance Corporation did not include an estimate of the liability for unreported incidents of abuse that have occurred within NSW Government institutions because it could not be reliably measured at 30 June 2019. The amounts involved could be material to the Corporation's and Total State Sector's financial statements.
  • Insurance scheme liabilities were significantly impacted by unfavourable movements in economic assumptions, including a decrease in the risk free discount rate, and adverse changes in non-economic assumptions, such as higher medical costs. 

Appendix one – Timeliness of financial reporting by agency

Appendix two – Management letter findings by agency

Appendix three – Status of 2018 recommendations

Appendix four – Cluster agencies

Appendix five – Financial data

 

Copyright notice

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Published

Actions for Planning, Industry and Environment 2019

Planning, Industry and Environment 2019

Planning
Industry
Environment
Asset valuation
Cyber security
Financial reporting
Information technology
Infrastructure
Internal controls and governance
Management and administration
Service delivery
Workforce and capability

This report outlines the results of audits of the financial statements of agencies now grouped in the NSW Planning, Industry and Environment cluster.

Unqualified audit opinions were issued for 56 of the 66 cluster agencies’ 30 June 2019 financial statements. Ten audits remain incomplete. The cluster agencies need to improve the timeliness of financial reporting. 

The Audit Office continued to identify issues regarding unprocessed Aboriginal land claims and the recognition of Crown land. ‘Auditor-General’s reports to parliament have recommended action to reduce the level of unprocessed land claims since 2007. However, the number of unprocessed claims continued to increase’, Margaret Crawford said.

One in five internal control findings were repeat issues. Key themes included information technology, asset management and improvements required to expense and payroll controls.

The report makes several recommendations including:

  • Property NSW should urgently address the deficiencies in the lease data used to calculate the impact of the new leasing standard effective from 1 July 2019
  • the Department of Planning, Industry and Environment should prioritise action to reduce unprocessed Aboriginal land claims
  • the Department of Planning, Industry and Environment should ensure the Crown land database is complete and accurate so state agencies and local government councils are better informed about the Crown land they control.

This report analyses the results of our audits of financial statements of the Planning, Industry and Environment cluster agencies for the year ended 30 June 2019. The table below summarises our key observations.

1. Machinery of Government changes

Creation of the Planning, Industry and Environment cluster

The Machinery of Government (MoG) changes abolished the former Planning and Environment cluster and former Industry cluster, and created the Planning, Industry and Environment cluster on 1 July 2019.

The Department of Planning and Environment (DPE), the Department of Industry (DOI), the Office of Environment and Heritage, and the Office of Local Government were abolished and the majority of their functions were transferred to the new Department of Planning, Industry and Environment (DPIE).

The Department of Planning, Industry and Environment is still in the process of implementing changes

The MoG changes bring risks and challenges to the cluster. A MoG Steering Committee, with the support of various project control groups and working groups, identified and developed responses to key risks arising from the changes.

However, the DPIE will take some time to fully integrate the policies, systems and processes of the abolished Departments and agencies.

2. Financial reporting

Audit opinions Unqualified audit opinions were issued for 56 of the 66 cluster agencies' 30 June 2019 financial statements audits. Ten financial statements audits are still ongoing.
Timeliness of financial reporting

Fifty-five of the 57 agencies subject to statutory deadlines submitted their financial statements on time.

Due to issues identified during the audit, 13 financial statements audits were not completed and audit opinions issued by the statutory deadline.

Agencies prepared and submitted their early close procedures in accordance with the mandatory timeframe set by NSW Treasury. However, 17 of the 49 agencies where we reviewed early close procedures were assessed as either partially addressing or not addressing one or more of the mandatory requirements. The cluster agencies could benefit from an increased focus on early close procedures.

Introduction of AASB 16 'Leases'

We noted errors in the lease data used in Property NSW's AASB 16 impact calculations, which affect both Property NSW and other government agencies. These errors were significant enough to present a risk of material misstatements to the financial statements of Property NSW and other government agencies in future reporting periods.

We had similar findings in our recent performance audit on 'Property Asset Utilisation', which highlighted issues with the quality of Property NSW's records.

Recommendation: Property NSW should urgently address the deficiencies in the lease data used to calculate the impact of the new leasing standard effective from 1 July 2019.

Unprocessed Aboriginal land claims have continued to increase

Despite an increase in the number of claims resolved, the number of unprocessed Aboriginal land claims increased by 7.2 per cent from the prior year to 35,855 at 30 June 2019. Claims can be made over Crown land assets of the DPIE or other government agencies. Until claims are resolved, there is an uncertainty over who is entitled to the land and the uses and activities that can be carried out on the land. We first recommended action to address unprocessed claims in 2007.

Recommendation (repeat issue): The DPIE should prioritise action to reduce unprocessed Aboriginal land claims.

3. Audit observations

Internal controls

One in five internal control issues identified and reported to management in 2018–19 were repeat issues.

The lack of user access review was the most common IT general control issue in the cluster.

Drought relief

The NSW Government announced an emergency drought relief package of $500 million in 2018, in addition to other financial assistance measures already in place.

Limited documentation and written agreements between relevant delivery agencies resulted in a $31.0 million misstatement relating to grant revenue.

Recognition of Crown land

Crown land is an important asset of the state. Management and recognition of Crown land assets is weakened when there is confusion over who is responsible for a particular Crown land parcel. Last year we recommended the DOI should ensure the database of Crown land is complete and accurate. While the DOI has commenced actions to improve the database, this continued to be an issue in 2018–19.

Recommendation (repeat issue): The DPIE should ensure the Crown land database is complete and accurate so state agencies and local government councils are better informed about the Crown land they control.

Developer contributions The former DPE continued to accumulate more developer contributions revenues than it spent on infrastructure projects. Total unspent funds increased to $274 million at 30 June 2019.

 

This report provides parliament and other users of the Planning, Industry and Environment cluster agencies financial statements with the results of our audits, our observations, analysis, conclusions and recommendations in the following areas:

  • financial reporting
  • audit observations.

This cluster was created by the Machinery of Government changes on 1 July 2019. This report is focused on agencies in the Planning, Industry and Environment cluster from 1 July 2019. However, these agencies were all in other clusters during 2018–19. Please refer to the section on Machinery of Government changes for more details.

Machinery of Government (MoG) refers to how the government organises the structures and functions of the public service. MoG changes are where the government reorganises these structures and functions that are given effect by Administrative orders.

The MoG changes, announced following the NSW State election on 23 March 2019, created the Planning, Industry and Environment (PIE) cluster. The Administrative Changes Orders issued on 2 April 2019, 1 May 2019 and 28 June 2019 gave effect to these changes. These orders became effective on 1 July 2019.

Section highlights

The 2019 MoG changes significantly impacted the former Planning and Environment, and Industry clusters and agencies.

  • The PIE cluster combines most of the functions and agencies of the former Planning and Environment and Industry clusters from 1 July 2019.
  • The Department of Planning, Industry and Environment is the principal agency in the PIE cluster.
  • The MoG changes bring risks and challenges to the PIE cluster.
  • A MoG Steering Committee was established to oversee the transitional processes.
  • The full integration of the systems and processes will not be completed in the near future.

Financial reporting is an important element of good governance. Confidence and transparency in public sector decision making are enhanced when financial reporting is accurate and timely.

This chapter outlines our audit observations related to the financial reporting of agencies in the Planning, Industry and Environment (PIE) cluster for 2019. In this chapter, the Department of Planning, Industry and Environment is referred to as DPIE, the former Department of Planning and Environment as DPE, and the former Department of Industry as DOI.

Section highlights

  • Unqualified audit opinions were issued for all completed 30 June 2019 financial statements audits. However, some cluster agencies can further enhance the quality of financial reporting.
  • Timeliness of financial reporting remains an issue for 13 agencies.
  • Deficiencies were identified in the data used to calculate the impact of AASB 16 ‘Leases’ effective from 1 July 2019. Property NSW should urgently address these deficiencies.
  • Unprocessed Aboriginal land claims continue to increase. DPIE should prioritise action to reduce unprocessed Aboriginal land claims.

Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies. They are essential for quality and timely decision making.

This chapter outlines our audit observations and insights from our financial statement audits of agencies in the Planning, Industry and Environment (PIE) cluster for 2019. In this chapter, the Department of Planning, Industry and Environment is referred to as DPIE, the former Department of Planning and Environment as DPE, and the former Department of Industry as DOI.

Section highlights

  • One in five issues identified and reported to management in 2018–19 were repeat issues.
  • The lack of user access review was the most common IT general control issue in the PIE cluster.
  • The PIE cluster provided significant financial assistance for drought relief.
  • There continues to be significant deficiencies in Crown land records. The DPIE should ensure the Crown land database is complete and accurate.
  • Unspent developer contributions funds continued to build up in 2018–19. 

Appendix one – List of 2019 recommendations

Appendix two – Status of 2018 recommendations

Appendix three – Cluster agencies

Appendix four – Financial data

Appendix five – Management letter findings

Appendix six – Timeliness of financial reporting

 

Copyright notice

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Published

Actions for Education 2019

Education 2019

Education
Financial reporting
Information technology
Internal controls and governance
Management and administration
Shared services and collaboration
Workforce and capability

This report focuses on key observations and findings from the most recent financial audits of agencies in the Education cluster. From 1 July 2019, the Technical and Further Education Commission, the NSW Skills Board and the functions and activities associated with vocational training and skills form part of the Education cluster.

Unqualified audit opinions were issued for all cluster agencies’ financial statements. However, internal control deficiencies were identified across the cluster agencies, including 14 findings that were repeated from the previous year. Control deficiencies were also identified in a sample of the state’s 2,200 schools. Schools did not always apply the guidance in the Department of Education's ‘Finance in Schools Handbook’, resulting in control weaknesses in key areas such as governance, cash management and procurement.

'In addition, we continue to observe inconsistencies in the employee leave data reported from the Department of Education’s payroll system, which impact the reliability of estimates of the Department’s liability for employee benefits. The robustness of the Department's quality assurance over leave liability data should be improved', the Auditor-General said.

Download the Education 2019 report (PDF)

This report analyses the results of our audits of financial statements of entities within the Education cluster for the year ended 30 June 2019. The table below summarises our key observations.

1. Machinery of Government changes

The Education cluster has expanded From 1 July 2019, the Technical and Further Education Commission, the NSW Skills Board and the functions and activities associated with vocational training and skills now form part of the Education cluster.

2. Financial reporting

Audit opinions

Unqualified audit opinions were issued for all cluster agencies' 30 June 2019 financial statements audits.

The number of corrections to disclosures in the financial statements, which increased this year, could have been reduced by a more thorough quality assurance over the information underpinning the financial statements.

Recommendation: Cluster agencies should improve their quality assurance processes for financial reporting to improve the accuracy of financial statements presented for audit.

Preparedness for new accounting standards

Agencies will implement four new accounting standards shortly. Three are effective from 1 July 2019 and the fourth is effective from 1 July 2020. Cluster agencies needed to do more work on their impact assessments to better prepare for their implementation from 1 July 2019.

Recommendation: Cluster agencies should finalise their plans to implement the new accounting standards as soon as possible.

Timeliness of financial reporting

All cluster agencies met the statutory deadline for completing early close procedures and submitting their financial statements for audit.

The Department of Education (the Department) delays tabling its financial statements in parliament so it can report its operational outcomes, which are aligned to the calendar year, in a single report. This reduces transparency over the Department's financial statements as they are tabled more than ten months after the end of the financial year.

Recommendation: The Department should table its financial statements in parliament earlier, in line with other NSW Government agencies.

Inconsistencies in the employee leave data We continue to observe inconsistencies in the employee leave data reported from the Department’s payroll system, which impacts the reliability of estimates of the Department's liability for employee benefits. The robustness of the Department's quality assurance over leave liability data should be improved.

3. Audit observations

Internal control deficiencies

We identified 55 internal control issues, including 14 findings that were repeated from the previous year.

Issues were identified with user access administration, segregation of duties in the Department's key application system and timely preparation and review of key reconciliations.

Recommendation: Cluster agencies should prioritise and action recommendations to address internal control weaknesses.

Schools review 2018

Our review of a selection of NSW schools identified deficiencies in how they applied the Department of Education's ‘Finance in Schools Handbook’, resulting in control weaknesses in key areas such as governance, cash management and procurement.

Recommendation: The Department should ensure all schools apply the Department’s ‘Finance in Schools Handbook’ as it is a key internal control.

 

This report provides parliament and other users of the Education cluster’s financial statements with the results of our audits, our observations, analysis, conclusions and recommendations in the following areas:

  • financial reporting
  • audit observations.

This cluster was significantly impacted by the Machinery of Government changes. The Technical and Further Education Commission and the NSW Skills Board, part of the former Industry cluster, were transferred on 1 July 2019. This report focuses on agencies in the Education cluster from 1 July 2019. Please refer to the section on Machinery of Government changes for more details.

Machinery of Government refers to how the government organises the structures and functions of the public service. Machinery of Government changes are where the government reorganises these structures and functions, and the changes are given effect by Administrative Arrangements Orders.

Section highlights

The 2019 Machinery of Government changes significantly impacted the Education cluster. From 1 July 2019, the functions and activities associated with the administration of legislation allocated to the Minister for Skills and Tertiary Education were transferred from the former Industry cluster to the Education cluster. Aboriginal Affairs NSW was transferred from the Department of Education (the Department) to the Department of Premier and Cabinet.

The Department is the principal agency in the cluster. The Machinery of Government changes bring new responsibilities, risks and challenges to the cluster.

Financial reporting is an important element of good governance. Confidence and transparency in public sector decision making are enhanced when financial reporting is accurate and timely.

This chapter outlines our audit observations related to the financial reporting of agencies in the Education cluster for 2019.

Section highlights

Unqualified audit opinions were issued on the financial statements of cluster agencies. However, a more thorough quality review process of the financial statements submitted for audit would help reduce the number of corrections to those statements.

All cluster agencies met the statutory deadlines for completing the early close procedures and submitting the financial statements.

We continue to observe inconsistencies in the employee leave data reported from the Department of Education’s (the Department) payroll system. The robustness of the Department's quality assurance over leave liability data should be improved.

Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies. They are essential for quality and timely decision making.

This chapter outlines our observations and insights from our financial statement audits of agencies in the Education cluster. It also comments on our review of the financial control framework applied by 70 schools in NSW whose financial results form part of the Department of Education's (the Department) financial statements.

Section highlights

  • Audit Office management letter recommendations to address internal control weaknesses should be actioned promptly, with a focus on addressing repeat issues. The 2018–19 financial audits of cluster agencies identified 55 internal control issues, including 14 that were carried forward from the previous year.
  • Application controls are procedures that operate at a business process level designed to ensure the integrity of accounting records. The Department can mitigate the risk of fraud or error in preparing its financial statements if segregation of duties are appropriately configured in their key application system.
  • Our review of a selection of schools across NSW identified deficiencies in how schools apply the Department’s financial management practices and governance arrangements.

Appendix one – List of 2019 recommendations

Appendix two – Status of 2018 recommendations

Appendix three – Cluster agencies

Appendix four – Financial data

 

Copyright notice

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Published

Actions for Stronger Communities 2019

Stronger Communities 2019

Justice
Community Services
Compliance
Financial reporting
Internal controls and governance
Management and administration
Project management
Service delivery
Shared services and collaboration
Workforce and capability

A report has been released on the NSW Stronger Communities cluster.

From 1 July 2019, the functions of the former Department of Justice, the former Department of Family and Community Services and many of the cluster agencies moved to the new Stronger Communities cluster. The Department of Communities and Justice is the principal agency in the new Stronger Communities cluster.

The report focuses on key observations and findings from the most recent financial audits of agencies in the Stronger Communities cluster.

Unqualified audit opinions were issued on the financial statements for all agencies in the cluster.  

There were 157 audit findings on internal controls. Two of these were high risk and 59 were repeat findings from previous financial audits. ‘Cluster agencies should prioritise actions to address internal control weaknesses promptly with particular focus given to issues that are assessed as high risk’, the Auditor-General said.

The report notes that the NSW Government’s new workers' compensation legislation, which gave eligible firefighters presumptive rights to workers' compensation, cost emergency services agencies $180 million in 2018–19, mostly in increased premiums.

Download the PDF version of report

This report analyses the results of our audits of financial statements of the agencies comprising the Stronger Communities cluster for the year ended 30 June 2019. The table below summarises our key observations.

This report provides parliament and other users of the financial statements of agencies in the Stronger Communities cluster with the results of our audits, our observations, analyses, conclusions and recommendations in the following areas:

  • financial reporting
  • audit observations.

This cluster was significantly impacted by the Machinery of Government (MoG) changes on 1 July 2019. This report focuses on the agencies that from 1 July 2019, comprised the Stronger Communities cluster. The MoG changes moved some agencies from the clusters to which they belonged in 2018–19 to the Stronger Communities cluster. Conversely, the MoG also moved some agencies formerly in the Family and Community Services cluster and Justice cluster elsewhere. Please refer to the section on Machinery of Government changes for more details.

The Department of Communities and Justice is the principal agency of the cluster. The newly created department combines functions of the former Department of Justice and the Department of Family and Community Services.

Machinery of Government (MoG) refers to how the government organises the structures and functions of the public service. MoG changes occur when the government reorganises these structures and functions and those changes are given effect by Administrative Orders.

The MoG changes announced following the NSW State election on 23 March 2019 significantly impacted the Stronger Communities cluster through Administrative Changes Orders issued on 2 April 2019 and 1 May 2019. These orders took effect on 1 July 2019.

Section highlights

The 2019 MoG changes significantly impacted the former Justice and Family and Community Services (FACS) departments and clusters.

  • The Stronger Communities cluster combines most of the functions and agencies of the former Justice and FACS clusters from 1 July 2019.
  • The Department of Communities and Justice is now the principal agency in the new cluster.
  • The MoG changes bring new responsibilities, risks and challenges to the cluster.
  • A temporary office has been established by the Department of Communities and Justice to support the cluster in the planning, delivery and reporting associated with implementing the changes.

Financial reporting is an important element of good governance. Confidence and transparency in public sector decision making are enhanced when financial reporting is accurate and timely.

This chapter outlines our audit observations relating to the financial reporting of agencies in the Stronger Communities cluster for 2019.

Section highlights
  • Unqualified audit opinions were issued for all agencies' 30 June 2019 financial statements. However, further actions can be taken by some cluster agencies to enhance the quality of their financial reporting.
  • In November 2018, the Department of Justice implemented a new Victims Support Services system called VS Connect. Significant data quality issues arising from the VS Connect system implementation impacted the Department's ability to reliably estimate its Victims Support Scheme claims liabilities at 30 June 2019.
    We recommend the Department of Communities and Justice resolves the data quality issues in the new VS Connect System before 30 June 2020 and capture and apply lessons learned from recent project implementations, including LifeLink, Justice SAP and VS Connect, in any relevant future implementations.
  • Our audits found some cluster agencies needed to do more work on their impact assessments and preparedness to implement the new accounting standards, to minimise the risk of errors in their 2019–20 financial statements.
  • Cluster agencies with annual leave balances exceeding the State's target should further review their approach to managing leave balances.

Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies. They are essential for quality and timely decision making.

This chapter outlines our observations and insights from our financial statement audits of agencies in the Stronger Communities cluster.

Section highlights

  • Cluster agencies should action recommendations to address internal control weaknesses promptly. Particular focus should be given to prioritising high risk issues. The 2018–19 financial audits of cluster agencies identified 157 internal control issues. Of these, two were high risk and 37.6 per cent were repeat findings from previous audits.
  • Data from the Department of Justice shows the inmate population reached a maximum of 13,798, compared to an operational capacity of 14,626 beds on 31 August 2019. This equates to an operational vacancy rate of 5.7 per cent, which is more than the recommended 5.0 per cent buffer. This is the first time the vacancy rate has exceeded the target over the last five years. Growth in the NSW prison population is being managed through the NSW Government's $3.8 billion Prison Bed Capacity Program.
  • In September 2018, the NSW Government introduced new workers' compensation legislation, which gives eligible firefighters presumptive rights to workers' compensation when diagnosed with one of 12 prescribed cancers. The new legislation cost emergency services agencies $180 million in 2018–19, mainly through additional workers' compensation premiums.

Appendix one – Timeliness of financial reporting by agency

Appendix two – Management letter findings by agency

Appendix three – List of 2019 recommendations 

Appendix four – Status of 2018 recommendations 

Appendix five – Cluster agencies 

Appendix six – Financial data 

 

Copyright notice

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Published

Actions for Internal Controls and Governance 2019

Internal Controls and Governance 2019

Education
Community Services
Finance
Health
Industry
Justice
Planning
Premier and Cabinet
Transport
Treasury
Whole of Government
Compliance
Cyber security
Fraud
Information technology
Internal controls and governance
Management and administration
Procurement
Project management

This report covers the findings and recommendations from the 2018–19 financial audits that relate to internal controls and governance at 40 of the largest agencies in the NSW public sector. The 40 agencies selected for this report constitute around 84 per cent of total expenditure for all NSW public sector agencies.

The report provides insights into the effectiveness of controls and governance processes across the NSW public sector. It evaluates how agencies identify, mitigate and manage risks related to:

  • financial controls
  • information technology controls
  • gifts and benefits
  • internal audit
  • contingent labour
  • sensitive data.

The Auditor-General recommended that agencies do more to prioritise and address vulnerabilities in their internal controls and governance. The Auditor-General also recommended agencies increase the transparency of their management of gifts and benefits by publishing their registers on their websites.

This report analyses the internal controls and governance of 40 of the largest agencies in the NSW public sector for the year ended 30 June 2019.

1. Internal control trends

New, repeat and high risk findings

There was an increase in internal control deficiencies of 12 per cent compared to last year. The increase is predominately due to a 100 per cent increase in repeat financial and IT control deficiencies.

Some agencies attributed the delay in actioning repeat findings to the diversion of staff from their regular activities to implement and operationalise the recent Machinery of Government changes. As a result, actions to address audit recommendations have been deferred or re prioritised, as the changes are implemented.

Agencies need to ensure they are actively managing the risks associated with having these vulnerabilities in internal control systems unaddressed for extended periods of time.

Common findings

A number of findings were common to multiple agencies. These findings often related to areas that are fundamental to good internal control environments and effective organisational governance, such as:

  • out of date policies or an absence of policies to guide appropriate decisions
  • poor record keeping and document retention
  • incomplete or inaccurate centralised registers or gaps in these registers
  • policies, procedures or controls no longer suited to the current organisational structure or business activities.

2. Information technology controls

IT general controls

We examined information security controls over key financial systems that support the preparation of agency financial statements. We found:

  • user access administration deficiencies at 58 per cent of agencies related to granting, review and removal of user access
  • an absence of privileged user activity reviews at 35 per cent of agencies
  • password controls that did not align to password policies at 20 per cent of agencies.

We also found 20 per cent of agencies had deficient IT program change controls, mainly related to segregation of duties in approval and authorisation processes, and user acceptance testing of program changes prior to deployment into production environments. User acceptance testing helps identify potential issues with software incompatibility, operational workflows, absent controls and software issues, as well as areas where training or user support may be required.

3. Gifts and benefits

Gifts and benefits registers

All agencies had a gifts and benefits policy and 90 per cent of agencies maintain a gifts and benefits register. However, 51 per cent of the gifts and benefits registers we examined contained incomplete declarations, such as missing details for the approving officer, value of the gift and/or benefit offered and reasons supporting the decision.

In some cases, gaps in recorded information meant the basis for decisions around gifts and benefits was not always clear, making it difficult to determine whether decisions in those instances were appropriate, compliant with policy and were not direct or indirect inducements to the recipients to favour suppliers or service providers.

Agencies should ensure their gifts and benefits register includes all key fields specified in the Public Service Commission's minimum standards for gifts and benefits. Agencies should also perform regular reviews of the register to ensure completeness and ensure any gift or benefit accepted by a staff member meets the public's expectations for ethical behaviour.

Managing gifts and benefits

We found opportunities to improve gifts and benefits processes and enhance transparency. For example, only three per cent of agencies publish their gifts and benefits registers on their websites.

Agencies can improve management of gifts and benefits by:

  • ensuring agency policies comprehensively cover the elements necessary to make it effective in an operational environment, such as identifying risks specific to the agency and actions that will be taken in the event of a policy breach
  • establishing and publishing a statement of business ethics on the agency's website to clearly communicate expected behaviours to clients, customers, suppliers and contractors
  • providing on-going training, awareness activities and support to employees, not just at induction
  • publishing their gifts and benefits registers on their websites to demonstrate a commitment to a transparently ethical environment.
Reporting and monitoring

Only 35 per cent of agencies reported trends in the number and nature of gifts and benefits recorded in their registers to the agency's senior executive management and/or a governance committee.

Agencies should regularly report to the agency executive or other governance committee on trends in the offer and acceptance of gifts and benefits.

4. Internal audit

Obtaining value from the internal audit function

Agencies have established and maintained internal audit functions to provide assurance on the effectiveness of agency controls and governance systems. However, we identified areas where agencies' internal audit functions could improve their processes to add greater value. For example, only 73 per cent of CAEs regularly attend meetings of the agency board or executive management committee.

Internal audit functions can add greater value by involving the CAE more extensively in executive forums as an observer.

Internal audit functions should also consider producing an annual report on internal audit. An annual report allows the internal audit function to report on their performance and add value by drawing to the attention of audit and risk committees and senior management strategic issues, thematic trends and emerging risks.

Role of the Chief Audit Executive

Forty-five per cent of agencies assigned responsibilities to the Chief Audit Executive (CAE) that were broader than internal audit, but 17 per cent of these had not documented safeguards to protect the independence of the CAE.

The reporting lines and status of the CAE at some agencies also needs review. At two agencies, the CAE reported to the CFO.

Agencies should ensure:

  • the reporting lines for the CAE comply with the NSW Treasury policy, and the CAE does not report functionally or administratively to the finance function or other significant recipients of internal audit services
  • the CAE's duties are compatible with preserving their independence and where threats to independence exist, safeguards are documented and approved.
Quality assurance and improvement program

Thirty-five per cent of agencies did not have a documented quality assurance and improvement program for its internal audit function.

The policy and the International Standards for the Professional Practice of Internal Auditing require agencies to have a documented quality assurance and improvement program. The results of this program should be reported annually.

Agencies should ensure there is a documented and operational Quality Assurance and Improvement Program for the internal audit function that covers both internal and external assessments.

5. Managing contingent labour

Obtaining value for money from contingent labour

According to NSW Procurement data, spend on contingent labour has increased by 75 per cent over the last five years, to $1.5 billion in 2018–19. Improvements in internal processes and a renewed focus on agency monitoring and oversight of contingent labour can help ensure agencies get the best value for money from their contingent workforces.

Agencies can improve their management of contingent labour by:

  • preparing workforce plans to inform their resourcing strategy and ensure that engaging contingent labour aligns with the strategy and best meets business needs
  • involving agency human resources units in decisions about engaging contingent labour
  • regularly reporting on contingent labour use and tenure to agency executive teams
  • strengthening on-boarding and off-boarding processes.

We also found 57 per cent of the 23 agencies we examined with contingent labour spend of more than $5 million in 2018–19 have implemented the government's vendor management system and service provider 'Contractor Central'.

6. Managing sensitive data

Identifying and assessing sensitive data

Sixty-eight per cent of agencies maintain an inventory of their sensitive data and where it resides. However, these inventories are not always complete and risks may be overlooked.

Agencies can improve processes to manage sensitive data by:

  • identifying and maintaining an inventory of sensitive data through a comprehensive and structured process
  • assessing the criticality and sensitivity of the data so that protection of high risk data can be prioritised.
Managing data breaches

Eighty-eight per cent of agencies have established policies to respond to potential data breaches when they are identified and 70 per cent of agencies maintain a register to record key information in relation to identified data breach incidents.

Agencies should maintain a data breach register to effectively manage the actions undertaken to contain, evaluate and remediate each data breach.

 

This report covers the findings and recommendations from our 2018–19 financial audits that relate to internal controls and governance at 40 of the largest agencies (refer to Appendix three) in the NSW public sector. The 40 agencies selected for this volume constitute around 84 per cent of total expenditure for all NSW public sector agencies.

Although the report includes several agencies that have changed as a result of the Machinery of Government changes that were effective from 1 July 2019, its focus on sector wide issues and insights means that its findings remain relevant to NSW public sector agencies, including newly formed agencies that have assumed the functions of abolished agencies.

This report offers insights into internal controls and governance in the NSW public sector

This is the third report dedicated to internal controls and governance at NSW State Government agencies. The report provides insights into the effectiveness of controls and governance processes in the NSW public sector by:

  • highlighting the potential risks posed by weaknesses in controls and governance processes
  • helping agencies benchmark the adequacy of their processes against their peers
  • focusing on new and emerging risks, and the internal controls and governance processes that might address those risks.

Without strong governance systems and internal controls, agencies increase the risks associated with effectively managing their finances and delivering services to citizens. For example, if they do not have strong information technology controls, sensitive information may be at risk of unauthorised access and misuse.

Areas of specific focus of the report have changed since last year

Last year's report topics included transparency and performance reporting, management of purchasing cards and taxi use, and fraud and corruption control. We are reporting on new topics this year and re-visiting agency management of gifts and benefits, which we first covered in our 2017 report. Re-visiting topics from prior years provides a baseline to show the NSW public sectors’ progress implementing appropriate internal controls and governance processes to mitigate existing, new and emerging risks in the public sector.

Our audits do not review all aspects of internal controls and governance every year. We select a range of measures and report on those that present heightened risks for agencies to mitigate. This year the report focusses on:

  • internal control trends
  • information technology controls, including access to agency systems
  • protecting sensitive information held within agencies
  • managing large and diverse workforces (controls around employing and managing contingent workers)
  • maintaining an ethical culture (management of gifts and benefits)
  • effectiveness of internal audit function and its oversight by Audit and Risk Committees.

The findings in this report should not be used to draw conclusions on the effectiveness of individual agency control environments and governance arrangements. Specific financial reporting, internal controls and audit observations are included in the individual 2019 cluster financial audit reports, which will be tabled in parliament from November to December 2019.

Internal controls are processes, policies and procedures that help agencies to:

  • operate effectively and efficiently
  • produce reliable financial reports
  • comply with laws and regulations
  • support ethical government.

This chapter outlines the overall trends for agency controls and governance issues, including the number of audit findings, the degree of risk those deficiencies pose to the agency, and a summary of the most common deficiencies we found across agencies. The rest of this report presents this year’s controls and governance findings in more detail.

Key conclusions and sector wide learnings

We identified four high risk findings, compared to six last year. None of the findings are common with those in the previous year. There was an overall increase of 12 per cent in the number of internal control deficiencies compared to last year. The increase is predominately due to a 100 per cent increase in the number of repeat financial and IT control deficiencies.
 
Some agencies attributed the delay in actioning repeat findings to the diversion of staff from their regular activities to implement and operationalise the recent Machinery of Government changes. As a result, actions to address audit recommendations have been deferred or re-prioritised, as the changes are implemented. Agencies need to ensure they are actively managing the risks associated with having these vulnerabilities in internal control systems unaddressed for extended periods of time.
 
We also identified a number of findings that were common to multiple agencies. These common findings often related to areas that are fundamental to good internal control environments and effective organisational governance. Examples include:
  • out of date policies or an absence of policies to guide appropriate decisions
  • poor record keeping and document retention
  • incomplete or inaccurate centralised registers or gaps in these registers.

Policies, procedures and internal controls should be properly designed, be appropriate for the current organisational structure and its business activities, and work effectively.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency controls to manage key financial systems.

Key conclusions and sector wide learnings
Government agencies’ financial reporting is heavily reliant on information technology (IT). We continue to see a high number of deficiencies related to IT general controls, particularly those related to user access administration. These controls are key in adequately protecting IT systems from inappropriate access and misuse.
IT is also important to the delivery of agency services. These systems often provide the data to help monitor the efficiency and effectiveness of agency processes and services they deliver. Our financial audits do not review all agency IT systems. For example, IT systems used to support agency service delivery are generally outside the scope of our financial audit. However, agencies should also consider the relevance of our findings to these systems.
Agencies need to continue to focus on assessing the risks of inappropriate access and misuse and the implementation of controls to adequately protect their systems, focussing on the processes in place to grant, remove and monitor user access, particularly privileged user access.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency controls to manage gifts and benefits. 

Key conclusions and sector wide learnings

We found most agencies have implemented the Public Service Commission's minimum standards for gifts and benefits. All agencies had a gifts and benefits policy and 90 per cent of agencies maintained a gifts and benefits register and provided some form of training to employees on the treatment of gifts and benefits.

Based on our analysis of agency registers, we found some areas where opportunities existed to make processes more effective. In some cases, gaps in recorded information meant the basis for decisions around gifts and benefits was not always clear, making it difficult to determine whether decisions in those instances were appropriate and compliant with policy. Fifty-one per cent of the gifts and benefits registers reviewed contained declarations where not all fields of information had been completed. Seventy-seven per cent of agencies that maintained a gifts and benefits register did not include all key fields suggested by the minimum standards.

Areas where agencies can improve their management of gifts and benefits include:

  • ensuring agency policies comprehensively cover the elements necessary to make it effective in an operational environment, such as identifying risks specific to the agency and actions that will be taken in the event of a policy breach
  • establishing and publishing a statement of business ethics on the agency's website to clearly communicate expected behaviours to clients, customers,suppliers and contractors
  • updating gifts and benefits registers to include all key fields suggested by the minimum standards, as well as performing regular reviews of the register to ensure completeness
  • providing on-going training, awareness activities and support to employees, not just at induction
  • regularly reporting gifts and benefits to executive management and/or a governance committee such as the audit and risk committee, focussing on trends in the number and types of gifts and benefits offered to and accepted by agency staff
  • publishing their gifts and benefits registers on their websites to demonstrate a commitment to a transparently ethical environment.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency internal audit functions.

Key conclusions and sector wide learnings 

We found agencies have established and maintained internal audit functions to provide assurance on the effectiveness of agency controls and governance systems as required by TPP15-03 'Internal Audit and Risk Management Policy for the NSW Public Sector'. However, we identified areas where agencies' internal audit functions could improve their processes to add greater value, including: 

  • documenting and implementing safeguards to address conflicting roles performed by the Chief Audit Executive (CAE)
  • ensuring the reporting lines for the CAE comply with the NSW Treasury policy, and the CAE reports neither functionally or administratively to the finance function or other significant recipients of internal audit services
  • involving the CAE more extensively in executive forums as an observer
  • documenting a Quality Assurance and Improvement Program for the internal audit function and performing both internal and external performance assessments to identify opportunities for continuous improvement
  • reporting against key performance indicators or a balanced scorecard and producing an annual report on internal audit to bring to the attention of the audit and risk committee and senior management strategic issues, thematic trends and emerging risks that may require further attention or resources.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency controls to on-board, manage and off-board contingent labour.

Key conclusions and sector wide learnings

Agencies have implemented controls to manage contingent labour and most agencies have some level of reporting and oversight of contingent labour at an executive level. However, the increasing trend in spend on contingent labour warrants a renewed focus on agency monitoring and oversight of their use of contingent labour. Over the last five years spend on contingent labour has increased by 75 per cent, to $1.5 billion in 2018–19.

There are also some key gaps that limit the ability of agencies to effectively manage contingent labour. Key areas where agencies can improve their management of contingent labour include: 

  • preparing workforce plans to inform their resourcing strategy, and confirm prior to engaging contingent labour, that this solution aligns with the strategy and best meets business needs
  • involving agency human resources units in decisions about engaging contingent labour
  • regularly reporting on contingent labour use to agency executive teams, particularly in terms of trends in agency spend, tenure and compliance with policies and procedures
  • strengthening on-boarding and off-boarding processes, including establishing checklists to on-board and off-board contingent labour, making provisions for knowledge transfer, and assessing, documenting and capturing performance information.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of governance and processes in relation to the management of sensitive data.

Key conclusions and sector wide learnings

Information technology risks are rapidly increasing. More interfaces between agencies and greater connectivity means the amounts of data agencies generate, access, store and share continue to increase. Some of this information is sensitive information, which is protected by the Privacy Act 1988.

It is important that agencies understand what sensitive data they hold, the risks associated with the inadvertent release of this information and how they are mitigating those risks. We found that agencies need to continue to identify and record their sensitive data, as well as expand the methods they use to identify sensitive data. This includes data held in unstructured repositories, such as network shared drives and by agency service providers.

Eighty-eight per cent of agencies have established policies to respond to potential data breaches when they are identified and 70 per cent of agencies maintain a register to record key information in relation to identified data breach incidents.

Key areas where agencies can improve their management of sensitive data include:

  • identifying sensitive data, based on a comprehensive and structured process and maintaining an inventory of the data
  • assessing the criticality and sensitivity of the data so that the protection of high risk data can be prioritised
  • developing comprehensive data breach management policies to ensure data breaches are appropriately managed
  • maintaining a data breach incident register to record key information in relation to identified data breaches incidents, including the estimated cost of the breach
  • providing on-going training and awareness activities to employees in relation to sensitive data and managing data breaches.

Appendix one – List of 2019 recommendations 

Appendix two – Status of 2018 recommendations

Appendix three – In-scope agencies

 

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Published

Actions for State Finances 2019

State Finances 2019

Education
Finance
Community Services
Health
Justice
Industry
Planning
Premier and Cabinet
Transport
Treasury
Whole of Government
Financial reporting

The Auditor-General, Margaret Crawford, has released her report on the State Finances for the year ended 30 June 2019.

‘I am pleased to once again report that I issued an unmodified audit opinion on the State’s consolidated financial statements,’ the Auditor-General said.

The report acknowledges NSW Treasury and agency efforts to reduce the number and value of errors compared with the previous year. ‘Strong financial management and transparent reporting are key elements of our system of government. Treasury and agency finance teams need to be consulted on major business decisions at the time of their execution. This will ensure agencies assess the accounting implications earlier and support accurate financial statements being presented for audit on a timely basis,’ said the Auditor-General.

The report summarises the financial audit result of the Total State Sector Accounts. The Total State Sector comprises 304 entities controlled by the NSW Government with total assets of $468 billion and total liabilities of $218 billion.

The General Government sector comprises 212 entities that provide goods and services that are funded centrally by the State. General Government expenditure grew by 5.5 per cent in 2018-19, which was below the long-term revenue growth of 5.6 per cent target established by the Fiscal Responsibility Act 2012.

Download PDF of State Finances 2019 report

Pursuant to the Public Finance and Audit Act 1983, I present my Report on State Finances 2019.

Strong financial management and transparent reporting are key elements of our system of government.

I am pleased to once again report that I issued an unmodified audit opinion on the State’s consolidated financial statements. 

The number of errors in agencies’ 2018–19 financial statements fell to six compared to the 23 recorded in 2017–18. This reflects Treasury’s focus on early close and the resolution of complex accounting matters before submission. Agency finance teams need to be consulted on major business decisions and commercial transactions to assess their accounting impacts at the time of their execution, rather than at the end of a financial year. This would improve the quality of financial reporting and avoid the need for extensions for agencies to submit their financial statements for audit.

To further increase transparency, a Key Audit Matters section was included in my Independent Auditor Report on the Total State Sector Accounts this year. This explains those matters considered most significant to the conduct of the audit and requiring significant management judgement.

Looking forward, certain factors have the potential to impact the accuracy and completeness of the Total State Sector Accounts in coming years. First, three new accounting standards are effective from 1 July 2019 and a fourth from 1 July 2020. Transitioning to new standards requires significant planning and resources to ensure the impacts are appropriately assessed and accounted for. Second, the Government Sector Finance Act 2018 will be implemented in stages over three years to 2020–21. This Act is intended to focus on performance, transparency, accountability, and efficiency of financial management in the government sector. I encourage agencies to build their awareness of this important reform and ensure their alignment with the principles of the Act. 

I want to thank Treasury staff for the way they engaged with my staff in the conduct of the audit. Our partnership is critical to ensuring the quality of financial management and reporting.

Margaret Crawford
Auditor-General, 10 October 2019

Our audit opinion on the State’s 2018–19 financial statements was unmodified. There were fewer reported errors but earlier resolution of accounting matters is still required.

Our audit opinion on the State’s 2018–19 financial statements was unmodified.

This year, six errors exceeding $20 million were found in agencies’ 2018–19 financial statements that make up the State’s consolidated financial statements. The total value of these errors was $927 million compared to $3.8 billion in 2017–18. The errors identified in 2018–19 resulted from:

  • incorrectly applying Australian Accounting Standards and Treasury Policies
  • using inappropriate assumptions and inaccurate data
  • incorrectly assessing the fair value of non-current physical assets.

The introduction of mandatory ‘early close procedures’ in 2011–12, saw the number of errors in agencies’ financial statements fall progressively, to a low of five in 2015–16.

In 2016–17, Treasury narrowed the scope of its mandatory early close procedures to focus on non-current physical asset valuations and pro-forma financial statements. Following this, the number of significant errors increased to 23 in 2017–18, the

highest number in six years and similar to the numbers identified before mandatory early close procedures were introduced.

In 2018–19, Treasury and agencies’ refocused their efforts around early close procedures and other year-end processes resulting in this year’s lower error total of six.

Errors in agency financial statements exceeding $20m (2015–2019)

Correction of prior year’s reported values    

Correction of earthwork assets ($2.1 billion)

Some of the State’s earthworks were first valued in 2016–17. These included earth excavations and embankments for the Country Rail and Metropolitan Network created before the year 2000 and dating back to the early 1900s.

For many years, the State did not account for earthworks because it believed the value could not be reliably measured. In 2016–17, the State engaged an external valuer who identified a methodology showing the earthworks could be valued. That valuer performed a valuation using topography maps for the Country Rail Network (CRN) because information in this earthworks database was of poor quality and incomplete. The valuation resulted in the State recognising $7.5 billion of earthworks for the first time in 2016–17. This was disclosed as a prior period error.

Over the following years, the State improved the quality of the CRN earthworks database by engaging an engineering firm to perform more detailed earthworks surveys. The work involved the use of technology to survey most of the CRN lines.

In 2018–19, the State once again engaged an external valuer to assess the fair value of the CRN earthworks. The valuer determined that incorrect assumptions were used in the 2016–17 valuation. These primarily related to land elevations, which were corrected in the earthworks database and this resulted in a new fair value of $5.4 billion, $2.1 billion less than the previous valuation. The error reported in the 2017–18 value has been corrected in the 2018–2019 financial statements to reflect the revised value.

Previously reported value for earthworks reduced from $7.5 billion to $5.4 billion.

Correction of museum collection assets ($27 million)

The Australian Museum’s collection assets were restated by $27 million to $800 million in 2017–18.

After the 2017–18 financial statements were published, the Australian Museum identified additional collection assets that were not included in the original valuation. This resulted in a $27 million error relating to collection asset values. As last year’s valuation was based on an incomplete listing of collection assets, the 2017-18 value has been corrected in the 2018–19 financial statements to reflect the revised value.

Correction of lease liability ($46.2 million)

On 1 July 1995, the Department of Justice entered into a 25-year lease arrangement with an option to extend for a further 15 years.

The Department accounted for the arrangement as a finance lease by recognising a building asset and a corresponding finance lease liability for the period of 25 years. The Department depreciated the leased asset based on a useful life of 40 years.

As it was reasonably certain the Department would exercise the lease option at inception, it should have recognised a liability that reflected the entire 40 year lease period. To correct the prior year error and properly reflect the extended lease period, the Department of Justice increased the lease liability and decreased retained earnings by $46.2 million as at 1 July 2017.

Abuse Claims remain a significant contingent liability of the State

The State discloses a contingent liability in its financial statements when the possibility of settling the liability in the future is considered less than probable, but more likely than remote, or the amount of the obligation cannot be measured with sufficient reliability.

If the expected settlement subsequently becomes probable and reliably estimable, a provision is recognised.

The State has numerous contingent liabilities. Some are quantifiable while others are not. As contingent liabilities are potentially material future liabilities of the State, every effort should be made to quantify these as accurately as possible. They also need to be monitored closely to ensure that they are recognised and brought on balance sheet as they crystallise.

At 30 June 2019, NSW Self Insurance Corporation (SiCorp) could not reliably measure the claims liability arising from past incidences of abuse that occurred within NSW Government institutions which have not yet been reported. These are referred to as incurred but not reported claims (IBNR).

Since 1 July 2018, victims of child sexual abuse can opt to claim compensation through the National Redress Scheme, or to lodge a civil claim. Civil claims for incidents that occurred within NSW Government institutions may be covered by SiCorp. An estimate of an IBNR for child abuse claims within SiCorp will be impacted by the extent that victims claim compensation through redress as compared to civil claims.

Recent legislative changes have added further uncertainty to estimating the extent of IBNR claims. SiCorp requires more reliable data on the number of IBNR child abuse claims and the expected average size of the related payments. As such, the liabilities presented in the SiCorp and the State financial statements do not include an allowance for IBNR abuse claims.

As more information becomes available it may be possible for SiCorp to reasonably estimate the value of abuse claim liabilities. It is possible that such an estimate may be material to SiCorp and the State’s financial statements. 

TAFE update

In prior years we reported on information system limitations at TAFE NSW, specifically relating to its student administration system. TAFE NSW continues to implement additional processes to verify the accuracy and completeness of revenue from student fees for the 2018–19 financial year.

In 2017–18 TAFE NSW started implementing a new student management system. Significant delays have occurred in implementing this system, mainly due to the complexity of integrating the vendor solution with the requirements of TAFE. TAFE will now bring the final commissioning and operation of the system in house. Final project delivery timeframes and estimated completion costs are being reviewed. Costs incurred to date amount to $67 million. The original budget for this new system is $89.4 million.

Light Rail settlement

The CBD and South East Light Rail is a new twelve kilometre light rail network for Sydney, currently under construction. Passenger trips are set to begin on the light rail by December between Circular Quay and Randwick. The second stage from Randwick to Kingsford is planned to open in March 2020. The original budget for construction work of $1.6 billion was revised to $2.1 billion in 2014.

The State Government has been in dispute with the firm responsible for delivering and operating the CBD and South East light rail project. In May 2019, the parties reached a Settlement Arrangement resulting in the State agreeing to pay a settlement amount of $576 million, which is in addition to the revised budget. Transport has advised a final cost is still to be determined following project completion.

The Audit Office has commenced a follow up audit on the CBD South East Light Rail. This audit will consider whether recommendations of our previous audit have been implemented. We will also review the current status and budget of this project.

Sydney Metro Northwest project commissioning

The Sydney Metro North West officially opened in May 2019.

In constructing the metro, some assets were built to facilitate its operation. These included pavements, roadworks, and electricity
and water connections.

When the project was completed, the assets and the responsibility for maintaining them transferred to third parties, primarily Councils and utility providers. In 2018–19, the State expensed (derecognised) the assets, valued at $306 million, because it no longer controlled them.

Financial Reporting by Crown Land Reserve Trusts

Approximately 700 reserve trusts, managed by Trust Boards, did not prepare the financial statements at 30 June 2019 as required by the
Public Finance and Audit Act 1983.

These Crown reserves contain showgrounds, cemeteries, racecourses, local parks, and other community facilities and public areas. Some of the Crown reserves have independent streams of revenue from user charges.

In 2016–17, Treasury determined that NSW cemetery trusts and a holiday park reserve trust were controlled entities of the State. As such, the Public Finance and Audit Act 1983 requires them to prepare financial statements and have these audited by the Auditor-General.

In 2017–18, three reserve trusts accepted NSW Treasury’s view, prepared financial statements and had them audited by the Auditor-General.

However, three cemetery reserve trusts continue to maintain they are not controlled by the State and therefore their financial statements are not audited by the Audit Office. These cemeteries shared their unaudited financial statements with Treasury so they could be incorporated into the State’s financial statements. At 30 June 2019, the value of their combined assets and liabilities, which are not audited by the Audit Office, was $564 million.

The State included an additional $319 million in assets that relate to Crown land values of approximately 700 reserve trusts that did not prepare or submit financial statements.

We performed additional audit procedures to obtain some assurance over the value of these crown lands. The nature and extent of the limitations to the scope of these procedures was not significant enough to impact our audit opinion. Treasury should ensure these trusts comply with the requirements of the Public Finance and Audit Act.

Derecognition of investment in City West Housing

In 2017–18, the State had an equity investment of $680 million in a community housing provider, City West Housing Pty Limited (CWH).

During 2018–19, CWH amended its constitution to ensure alignment with its charitable status. The unintended impact of this change was that on windup the net assets would not be distributed to the State. The accounting implications to the State’s investment was not considered by Treasury at the time of approving the amended constitution. Consequently, the State wrote off its $680 million investment in CWH in 2018–19.

It is important that accounting impacts of such changes are discussed and agreed upon early. At the time of approving the decision to change the constitution, all accounting implications should be made available and understood. Such information is relevant when approving decisions. The theme of what is relevant
information will be explored further in our Performance Audit of ‘Advice on Major Decisions’.

Machinery of government (MoG) changes refers to how the government reorganises agency structures and functions and realigns ministerial responsibilities.

Cluster changes

On 2 April 2019, the Government reorganised public sector agencies into eight clusters (ten in 2017–18) with effect from 1 July 2019.

Prior to 30 June 2019, two subsequent administrative arrangement orders were made to amend and finalise the MoG changes.

The key MoG changes included:

  • abolishing the following five departments:
    • Finance, Services and Innovation
    • Industry
    • Planning and Environment
    • Family and Communities
    • Justice
  • transferring their functions into three new departments:
    • Department of Customer Service
    • Department of Planning, Industry and Environment
    • Department of Communities and Justice
The State’s consolidated financial statements at 30 June 2019 were not impacted by the changes, as they were effective from 1 July 2019.

The chart below shows the cluster arrangements before and after the MoG changes to the General Government Sector. It compares total budgeted expenses presented in the 2018–19 and 2019–20 Budget Papers (1).

Each cluster’s share of the General Government Sector’s (GGS) total expenditure remains relatively unchanged after the MoG changes. Further details on other functions transferred between clusters are detailed in the 2019–20 Budget Papers.

Of the clusters, Education is affected most by the MoG changes from the perspective of increased expenditure in the 2019–20 budget. This is because the TAFE Commission transferred into this cluster from the former Department of Industry on 1 July 2019, resulting in a corresponding decrease in the new Planning, Industry and Environment cluster’s expenditure.

(1) The 2018–19 Budget Paper 3 (unaudited) and 2019–20 Budget Paper 3 (unaudited).

Cluster expenses

2018-19
Before MoG Changes

2019-20
After MoG Changes

Industry 6% Planning, Industry and Environment 7%
Planning and Environment 4%
Education 18% Education 21%
Premier and Cabinet 1% Premier and Cabinet 2%
Finance, Service and Innovation 4% Customer Service 3%
Family and Community Services 8% Stronger Communities 18%
Justice 10%
Transport 9% Transport 9%
Treasury 14% Treasury 14%
Health 26% Health 26%

 

$1.2 billion surplus, $0.2 billion below 2018–19 budget of $1.4 billion

The Total State Sector comprises 304 entities controlled by the NSW Government.

The General Government Sector, which comprises 212 entities, generally provides goods and services funded centrally by the State.
The non-General Government Sector, which comprises 92 Government businesses, generally provides goods and services, such as water, electricity and financial services that consumers pay for directly.

A principal measure of a Government’s overall performance is its Net Operating Balance (Budget Result). This is the difference
between the cost of General Government service delivery and the revenue earned to fund these sectors.

What changed from 2018 to 2019?

The State maintained its AAA credit rating.

The object of the Fiscal Responsibility Act 2012 is to maintain the State’s AAA credit rating.

The Government manages NSW’s finances in accordance with the Fiscal Responsibility Act 2012 (the Act).

The Act establishes the framework for fiscal responsibility and the strategy to protect the State’s AAA credit rating and service delivery to the people of New South Wales.

The legislation sets out targets and principles for financial management to achieve this.

New South Wales has credit ratings of AAA/Stable from Standard & Poor’s and Aaa/Stable from Moody’s Investors Service.

The fiscal targets for achieving this objective are:

General Government annual expenditure growth is lower than long term average revenue growth.

General Government expenditure grew by 5.5 per cent in 2018–19 (5.1 per cent in 2017–18 based on restated balances). This was slightly below the long-term revenue growth rate of 5.6 per cent.

Eliminating unfunded superannuation liabilities by 2030.

The Act sets a target to eliminate unfunded superannuation liabilities by 2030.

The State’s funding plan is to contribute amounts escalated by five per cent each year so the schemes will be fully funded by 2030. In 2018–19, the State made employer contributions of $1.73 billion ($1.67 billion in 2017–18), an increase of $64 million or 3.8 per cent ($52 million or 3.2 per cent in 2017–18). This was under the five per cent target by $19.5 million.

For fiscal responsibility purposes, the State uses AASB 1056: Superannuation Entities. This accounting standard discounts superannuation liabilities using the expected return from the assets backing the liability.

Using this method, the State’s unfunded superannuation liability was $13.2 billion at 30 June 2019 ($14.0 billion).

Superannuation funding position since inception of the Act - AASB 1056 Valuation

State revenues fell $604 million to $86.1 billion in 2018–19    

In the prior years, revenue growth was underpinned by cyclical increases in land tax, payroll tax and one-off large stamp duty receipts from the lease of the State’s electricity network assets. In 2018–19, the State’s revenue fell by $604 million to $86.1 billion ($86.7 million in 2017–18).

Taxation revenue remained relatively stable

Taxation revenue only grew slightly, mainly due to:

  • a $517 million increase in payroll tax from NSW wages growth
  • a $469 million increase in land tax from growth in land values
  • offset by a $1.2 billion decrease in stamp duty due to lower than expected growth in the property market. This decrease would have been higher had the State not received $555 million in stamp duty from the new 51 per cent owner of WestConnex.

The gap between payroll tax and stamp duty reduced significantly in 2018–19. Stamp duty still remains the largest source of revenue for the State at $9.2 billion, only $42 million above payroll tax.

Australian Government grants and subsidies

The State received $31.8 billion in grants and subsidies from the Australian Government, $158 million less than the previous year. This was due to falls in other grants and subsidies of $98 million and GST revenues of $48 million.

GST revenues fell due to weaker growth in national consumption expenditure and a smaller GST pool. The GST pool represents funds made available by the Commonwealth for transfer to the States as untied financial assistance. The allocation of GST is determined by the Commonwealth, not the State.

A $392 million decrease in National Partnership Payments was offset by a $380 million increase in Specific Purpose Payments.
 
In 2018–19, sales of goods and services fell $395 million mainly due to the sale of WestConnex.

Other dividends and distributions fell by $122 million due to lower distributions from associates. This reflected weaker performance in the electricity sector (Ausgrid and Endeavour) resulting in lower distributions paid to the State following changes in the Electricity Network Service Providers regulatory environment and the sale of Snowy Hydro Pty Ltd in 2017–18.

Fines, regulatory fees and other revenues increased by $242 million largely from mineral royalties. The increase was attributed to strong demand across Asian markets for coal exports, which the State expects will continue to experience steady growth.

Expenses increased $4 billion to $87.9 billion in 2018–19    

Overall, the State’s expenses increased 4.8 per cent in 2018–19 compared to 2017–18. Most of the increase was due to higher employee expenses, operating costs and grants and subsidies.

Employee expenses, including superannuation, increased by 3.9 per cent to $40.3 billion.

Salaries and wages increased to $40.3 billion in 2018–19 from $38.8 billion 2017–18. This was mainly due to salary and wage increases. The Government wages policy aims to limit growth in employee remuneration and other employee related costs to no more than 2.5 per cent per annum.

Operating expenses increased 6.1 per cent from 2017–18.

Within operating expenses, payments for supplies, services and other expenses increased due to:

  • increased operating costs associated with the commencement of the new Sydney Metro
  • higher operating activity levels experienced in the Health sector resulting in higher visiting medical officer costs, surgical supplies and information management costs
  • higher school operating expenses in Education, mainly relating to teaching cloud tools and purchase of computer equipment.
Health costs remain the highest expense of the State.

The following clusters have the highest expenses as a percentage of total government expenses:

  • Health - 25.8 per cent (24.6 per cent in 2017–18)
  • Education - 20 per cent (18.5 per cent)
  • Transport - 14.7 per cent (17.6 per cent).

Other, mainly relates to Economic Affairs, Housing and Community, Recreation and Culture functions of the State.

Transport expenses have decreased in 2018–19 mainly due to the sale of WestConnex. This is partially offset by costs associated with the new Sydney Metro, which commenced operations from 1 July 2018. The graph highlights annual expenditure by function in 2018–19 compared to 2017–18.

Grants and subsidies increased by $782 million to $11.7 billion.

This was mainly due to:

  • the $239 million Emergency Drought Relief Package
  • a $226 million increase in funding to the Human Services sector to deliver key election commitments, including 5,000 more nurses and midwives
  • $123 million in funding for sporting facilities and creating NSW Centre's of Excellence.

Assets grew by $26.7 billion to $468 billion in 2018–19    

Overall, the States total assets increased by $26.7 billion to $468 billion in 2018–19. This is a six per cent increase compared to 2017–18. Most of this was due to increases in carrying value of the State’s physical assets and investments.

Valuing the State's physical assets

The State’s physical assets were valued at $352 billion at 30 June 2019.

The State’s physical assets include land and buildings ($166 billion) and infrastructure ($168 billion). The value of the State’s physical assets at 30 June 2018 was restated from $339 billion to $337 billion. The restatement was required to correct errors in the fair value of earthworks previously reported at $7.5 billion and subsequently corrected to $5.4 billion.

Our audits assess the reasonableness and appropriateness of assumptions used to value physical assets. This includes
obtaining an understanding of the valuation methodologies used and judgements made. We also review the completeness of asset registers and the mathematical accuracy of valuation models.

Net movements between years include additions, disposals, depreciation and valuations. The State’s physical assets increased by $15.2 billion compared with 2017–18.

Movement in the State's physical assets

Liabilities increased $28.6 billion to $217.5 billion in 2018–19    

The State relies on actuarial assessments to value its liabilities

Nearly half of the State’s liabilities relate to its employees. They include unfunded superannuation and employee benefits, such as long service and recreation leave.

Valuing these obligations involves complex estimation techniques and significant judgements. Small changes in assumptions can materially impact balances in the financial statements, such as a lower discount rate.

Superannuation obligations rose by $14.3 billion.

The State’s $70.7 billion unfunded superannuation liability represents obligations to past and present employees less the value of assets set aside to meet those obligations. The unfunded superannuation liability rose by $14.3 billion from $56.4 billion at 30 June 2018 to $70.7 billion at 30 June 2019. This was mainly due to a lower discount rate.

Borrowings totalled $79.9 billion at 30 June 2019.

The State’s borrowings of $79.9 billion at 30 June 2019 were $8.6 billion higher than they were at 30 June 2018.

TCorp issues bonds to raise funds for NSW Government agencies. These are actively traded in financial markets, which provides price transparency and liquidity to public sector borrowers and institutional investors. All TCorp bonds are guaranteed by the NSW Government.

The Government manages its debt liabilities through its balance sheet management strategy. The strategy extends to TCorp, which applies an active risk management strategy to the Government’s debt portfolio.

General Government Sector debt has been restructured by replacing shorter-term debt with longer-term debt. This lengthens the portfolio to match liabilities with the funding requirements for infrastructure assets.

Implementing the requirements of new accounting standards will be challenging

Risks to the quality and timeliness of financial reporting

The State and its agencies will be implementing the requirements of new accounting standards shortly. These are likely to have a major impact on the financial positions and operating results of agencies across the sector.

Accounting standards require agencies to assess and disclose where possible, the impact of the new standards in their 2018–19 financial statements.

Our review found agencies needed to do more work on their impact assessments to minimise the risk of errors in the financial statement disclosures. Some agencies disclosed that the new standards would not have a material impact on their reported financial position and performance, but had little evidence to support this.

Each agency is unique and implementing the new standards is not straight forward as many new principles apply. Management judgement is needed to interpret how the principles apply to each agency. As a result, agencies face the following risks and challenges:

  • having the required technical skills in house
  • having accurate data to assess the impacts
  • correctly and consistently interpreting the new requirements
  • adequately planning and preparing for their application
  • implementing new systems to capture the information needed to meet the new reporting obligations.

To help agencies implement the new standards consistently across the sector, Treasury:

  • issued guidance to agencies
  • prepared position papers on proposed accounting treatments
  • provided briefing sessions to agencies
  • mandated which option in the new standards agencies had to adopt on transition.

Key dates

Section 45 of the Public Finance and Audit Act 1983 requires the Auditor-General to perform audits of the financial statements of entities prescribed for the purposes of that section.
The following were prescribed entities as at 30 June 2019:

Entity/Fund Latest financial statements audited Type of audit opinion issued
Agricultural Scientific Collections Trust 30 June 2019 Unmodified
AustLII Foundation Limited 31 December 2018 Unmodified
Belgenny Farm Agricultural Heritage Centre Trust 30 June 2019 Unmodified
The Brett Whiteley Foundation 30 June 2019 Unmodified
Buroba Pty Ltd 30 June 2018* Unmodified
C. B. Alexander Foundation 30 June 2018 Unmodified
City West Housing Pty Ltd 30 June 2019 Unmodified
The Commissioner for Uniform Legal Services Regulation 30 June 2019 N/A (a)
Cowra Japanese Garden Maintenance Foundation Limited 31 March 2019 Unmodified
Cowra Japanese Garden Trust 31 March 2019 Unmodified
Crown Employees (NSW Fire Brigades Firefighting Staff Death and Disability) Superannuation Fund 30 June 2019 Unmodified
Eif Pty Limited 30 June 2019 Unmodified
Energy Investment Fund 30 June 2019 Unmodified
Central Coast Council Water Supply Authority (formerly Gosford City and Wyong City Council Water Supply Authorities) 30 June 2018 Unmodified
Home Building Compensation Fund 30 June 2019 Unmodified
The funds for the time being under the management of the New South Wales Treasury Corporation, as trustee 30 June 2019 Unmodified
The Illawarra Health and Medical Research Institute Limited 30 June 2019 Unmodified
The Legal Services Council 30 June 2019 Unmodified
Macquarie University Professorial Superannuation Scheme 30 June 2019 Unmodified
Planning Ministerial Corporation 30 June 2019 Unmodified
Corporation Sole 'Minister administering the Heritage Act 1977' (a corporation) 30 June 2019 Unmodified
National Art School 31 December 2018 Unmodified
NSW Fire Brigades Superannuation Pty Limited 30 June 2019 Unmodified
Parliamentary Contributory Superannuation Fund 30 June 2019 Unmodified
Sydney Education Broadcasting Limited 31 December 2018 Unmodified
The superannuation fund amalgamated under the Superannuation Administration Act 1991 and continued to be amalgamated under the Superannuation Administration 30 June 2019 Unmodified
Act 1996 (known as the SAS Trustee Corporation Pooled Fund) 30 June 2019 Unmodified
The trustees for the time being of each superannuation scheme established by a trust deed as referred to in section 127 of the Superannuation Administration Act 1996 30 June 2019 Unmodified
The Art Gallery of New South Wales Foundation 30 June 2019 Unmodified
Trustee of the Home Purchase Assistance Fund 30 June 2019 Unmodified
Trustees of the Farrer Memorial Research Scholarship Fund 31 December 2018 Unmodified
United States Studies Centre 31 December 2018 Unmodified
Universities Admissions Centre (NSW and ACT) Pty Limited 30 June 2018 Unmodified
University of Sydney Professorial Superannuation System 31 December 2018 Unmodified
Valley Commerce Pty Ltd 30 June 2018* Unmodified
     
(a) Included as part of the Legal Services Council.
*Entities exempt from preparing financial statements at 30 June 2019.
aa


 

Published

Actions for Contracting non-government organisations

Contracting non-government organisations

Community Services
Compliance
Fraud
Management and administration
Procurement
Regulation
Service delivery

This report found the Department of Family and Community Services (FACS) needs to do more to demonstrate it is effectively and efficiently contracting NGOs to deliver community services in the Permanency Support Program (a component of out-of-home-care services) and Specialist Homelessness Services. It notes that FACS is moving to an outcomes-based commissioning model and recommends this be escalated consistent with government policy.

Government agencies, such as the Department of Family and Community Services (FACS), are increasingly contracting non-government organisations (NGOs) to deliver human services in New South Wales. In doing so, agencies are responsible for ensuring these services are achieving expected outcomes. Since the introduction of the Commissioning and Contestability Policy in 2016, all NSW Government agencies are expected to include plans for customer and community outcomes and look for ways to use contestability to raise standards.

Two of the areas receiving the greatest funding from FACS are the Permanency Support Program and Specialist Homelessness Services. In the financial year 2017–18, nearly 500 organisations received $784 million for out-of-home care programs, including the Permanency Support Program. Across New South Wales, specialist homelessness providers assist more than 54,000 people each year and in the financial year 2017–18, 145 organisations received $243 million for providing short term accommodation and homelessness support, including Specialist Homelessness Services.

In the financial year 2017–18, FACS entered into 230 contracts for out-of-home care, of which 49 were for the Permanency Support Program, representing $322 million. FACS also entered into 157 contracts for the provision of Specialist Homelessness Services which totalled $170 million. We reviewed the Permanency Support Program and Specialist Homelessness Services for this audit.

This audit assessed how effectively and efficiently FACS contracts NGOs to deliver community services. The audit could not assess how NGOs used the funds they received from FACS as the Audit Office does not have a mandate that could provide direct assurance that NGOs are using government funds effectively.

Conclusion
FACS cannot demonstrate it is effectively and efficiently contracting NGOs to deliver community services because it does not always use open tenders to test the market when contracting NGOs, and does not collect adequate performance data to ensure safe and quality services are being provided. While there are some valid reasons for using restricted tenders, it means that new service providers are excluded from consideration - limiting contestability. In the service delivery areas we assessed, FACS does not measure client outcomes as it has not yet moved to outcomes-based contracts. 
FACS' procurement approach sometimes restricts the selection of NGOs for the Permanency Support Program and Specialist Homelessness Services
FACS has a procurement policy and plan which it follows when contracting NGOs for the provision of human services. This includes the option to use restricted tenders, which FACS sometimes uses rather than opening the process to the market. The use of restricted tenders is consistent with its procurement plan where there is a limited number of possible providers and the services are highly specialised. However, this approach perpetuates existing arrangements and makes it very difficult for new service providers to enter the market. The recontracting of existing providers means FACS may miss the opportunity to benchmark existing providers against the whole market. 
FACS does not effectively use client data to monitor the performance of NGOs funded under the Permanency Support Program and Specialist Homelessness Services
FACS' contract management staff monitor individual NGO performance including safety, quality of services and compliance with contract requirements. Although FACS does provide training materials on its intranet, FACS does not provide these staff with sufficient training, support or guidance to monitor NGO performance efficiently or effectively. FACS also requires NGOs to self-report their financial performance and contract compliance annually. FACS verifies the accuracy of the financial data but conducts limited validation of client data reported by NGOs to verify its accuracy. Instead, FACS relies on contract management staff to identify errors or inaccurate reporting by NGOs.
FACS' ongoing monitoring of the performance of providers under the Permanency Support Program is particularly limited due to problems with timely data collection at the program level. This reduces FACS' ability to monitor and analyse NGO performance at the program level as it does not have access to ongoing performance data for monitoring service quality.
In the Specialist Homelessness Services program, FACS and NGOs both provide the data required for the National Minimum Data Set on homelessness and provide it to the Australian Institute of Health and Welfare, as they are required to do. However, this data is not used for NGO performance monitoring or management.
FACS does not yet track outcomes for clients of NGOs
FACS began to develop an approach to outcomes-based contracting in 2015. Despite this, none of the contracts we reviewed are using outcomes as a measure of success. Currently, NGOs are required to demonstrate their performance is consistent with the measures stipulated in their contracts as part of an annual check of their contract compliance and financial accounts. NGOs report against activity-based measures (Key Performance Indicators) and not outcomes.
FACS advises that the transition to outcomes-based contracting will be made with the new rounds of funding which will take place in 2020–2021 for Specialist Homelessness Services and 2023 for the Permanency Support Program. Once these contracts are in place, FACS can transition NGOs to outcomes based reporting.
Incomplete data limits FACS' effectiveness in continuous improvement for the Permanency Support Program and Specialist Homelessness Services
FACS has policies and procedures in place to learn from past experiences and use this to inform future contracting decisions. However, FACS has limited client data related to the Permanency Support Program which restricts the amount of continuous improvement it can undertake. In the Specialist Homelessness Support Program data is collected to inform routine contract management discussions with service providers but FACS is not using this data for continuous improvement. 

Appendix one – Response from agency

Appendix two – About the audit

Appendix three – Performance auditing

 

Parliamentary Reference: Report number #323 - released 26 June 2019

Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Published

Actions for Biosecurity risk management

Biosecurity risk management

Industry
Risk

The report focuses on the Department of Primary Industries’ (DPI) as the lead agency for biosecurity in New South Wales. It examines how well the department responds to biosecurity emergencies and manages compliance activities. DPI’s state partners include NSW Health, the NSW Environment Protection Authority, Local Land Services, and Local Control Authorities to manage biosecurity risks in New South Wales.

Biosecurity is the protection of the economy, environment, and community from the negative impacts of pests, diseases, weeds, and contaminants.

National and State governments have defined roles and responsibilities for biosecurity in Australia, reflecting the allocation of powers in the Australian Constitution. The Australian Government has direct responsibility for biosecurity (quarantine) at the international border, and works jointly with the states and territories to set the legislative framework and policy direction for managing biosecurity nationally. It also works with state and territory governments to ensure there is a national approach to biosecurity. State governments manage their biosecurity activities within the national framework.

The Department of Primary Industries (DPI), within the Department of Industry, is the lead agency for biosecurity in NSW. This audit was conducted with the Department of Industry as the auditee. On 2 April 2019 the NSW Government announced it will abolish the Department of Industry. From 1 July 2019 the Department of Planning, Industry and Environment, will have responsibility for biosecurity activities described in this report.

The NSW Biosecurity Strategy 2013–2021 (the Strategy) articulates the NSW Government’s responsibilities for biosecurity within the national legislative framework. Achieving the outcomes of the strategy relies on DPI fulfilling two key responsibilities. Firstly, undertaking direct actions, such as implementing strong regulatory compliance and licensing activities, and managing biosecurity emergency responses. Secondly, leading the response to biosecurity risks by fostering effective collaboration with stakeholders across government, industry, and the wider community.

In NSW, 11 regional Local Land Services (LLS) are the key partners for DPI in meeting its biosecurity responsibilities. Each LLS develops and implements strategies to manage invasive pests and diseases within their regions. They also investigate new reports of pests or diseases in their regions and staff local emergency control centres when an emergency response is triggered.

Local Control Authorities (LCAs) also have a role in biosecurity management. LCAs include local councils and a small number of specialist regional agencies. Their role focuses on strategies to manage weeds within their local areas.

This audit assessed the effectiveness and economy of DPI’s biosecurity emergency response and prevention activities. It looks at DPI’s emergency response practice and its compliance program as a key prevention activity for which DPI has primary responsibility. DPI sets policy and procedural compliance standards for management of biosecurity risks in NSW and also conducts an annual program of property inspections and investigations that ensure that its compliance policies and procedures are being applied effectively.

Appendix one - Response from agency

Appendix two - Location of selected biosecurity emergency responses

Appendix three - About the audit

Appendix four - Performance auditing

 

Parliamentary Reference: Report number #321 - released 18 June 2019

Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Banner image: ‘Yellow crazy ant’, supplied and permitted for use by NSW Department of Primary Industries under Creative Commons Attribution-ShareAlike 3.0 Unported Licence. Full terms.

Published

Actions for Internal Controls and Governance 2017

Internal Controls and Governance 2017

Finance
Education
Community Services
Health
Justice
Whole of Government
Asset valuation
Compliance
Cyber security
Information technology
Internal controls and governance
Project management
Risk

Agencies need to do more to address risks posed by information technology (IT).

Effective internal controls and governance systems help agencies to operate efficiently and effectively and comply with relevant laws, standards and policies. We assessed how well agencies are implementing these systems, and highlighted opportunities for improvement.
 

1. Overall trends

New and repeat findings

The number of reported financial and IT control deficiencies has fallen, but many previously reported findings remain unresolved.

High risk findings

Poor systems implementations contributed to the seven high risk internal control deficiencies that could affect agencies.

Common findings

Poor IT controls are the most commonly reported deficiency across agencies, followed by governance issues relating to cyber security, capital projects, continuous disclosure, shared services, ethics and risk management maturity.

2. Information Technology

IT security

Only two-thirds of agencies are complying with their own policies on IT security. Agencies need to tighten user access and password controls.

Cyber security

Agencies do not have a common view on what constitutes a cyber attack, which limits understanding the extent of the cyber security threat.

Other IT systems

Agencies can improve their disaster recovery plans and the change control processes they use when updating IT systems.

3. Asset Management

Capital investment

Agencies report delays delivering against the significant increase in their budgets for capital projects.

Capital projects

Agencies are underspending their capital budgets and some can improve capital project governance.

Asset disposals

Eleven per cent of agencies were required to sell their real property through Property NSW but didn’t. And eight per cent of agencies can improve their asset disposal processes.

4. Governance

Governance arrangements

Sixty-four per cent of agencies’ disclosure policies support communication of key performance information and prompt public reporting of significant issues.

Shared services

Fifty-nine per cent of agencies use shared services, yet 14 per cent do not have service level agreements in place and 20 per cent can strengthen the performance standards they set.

5. Ethics and Conduct

Ethical framework

Agencies can reinforce their ethical frameworks by updating code‑of‑conduct policies and publishing a Statement of Business Ethics.

Conflicts of interest

All agencies we reviewed have a code of conduct, but they can still improve the way they update and manage their codes to reduce the risk of fraud and unethical behaviour.

6. Risk Management 

Risk management maturity

All agencies have implemented risk management frameworks, but with varying levels of maturity.

Risk management elements

Many agencies can improve risk registers and strengthen their risk culture, particularly in the way that they report risks to their lead agency.

This report covers the findings and recommendations from our 2016–17 financial audits related to the internal controls and governance of the 39 largest agencies (refer to Appendix three) in the NSW public sector. These agencies represent about 95 per cent of total expenditure for all NSW agencies and were considered to be a large enough group to identify common issues and insights.

The findings in this report should not be used to draw conclusions on the effectiveness of individual agency control environments and governance arrangements. Specific financial reporting, controls and service delivery comments are included in the individual 2017 cluster financial audit reports tabled in Parliament from October to December 2017.

This new report offers strategic insight on the public sector as a whole

In previous years, we have commented on internal control and governance issues in the volumes we published on each ‘cluster’ or agency sector, generally between October and December. To add further value, we then commented more broadly about the issues identified for the public sector as a whole at the start of the following year.

This year, we have created this report dedicated to internal controls and governance. This will help Parliament to understand broad issues affecting the public sector, and help agencies to compare their own performance against that of their peers.

Without strong control measures and governance systems, agencies face increased risks in their financial management and service delivery. If they do not, for example, properly authorise payments or manage conflicts of interest, they are at greater risk of fraud. If they do not have strong information technology (IT) systems, sensitive and trusted information may be at risk of unauthorised access and misuse.

These problems can in turn reduce the efficiency of agency operations, increase their costs and reduce the quality of the services they deliver.

Our audits do not review every control or governance measure every year. We select a range of measures, and report on those that present the most significant risks that agencies should mitigate. This report divides these into the following six areas:

  1. Overall trends
  2. Information technology
  3. Asset management
  4. Governance
  5. Ethics and conduct
  6. Risk management.

Internal controls are processes, policies and procedures that help agencies to:

  • operate effectively and efficiently
  • produce reliable financial reports
  • comply with laws and regulations.

This chapter outlines the overall trends for agency controls and governance issues, including the number of findings, level of risk and the most common deficiencies we found across agencies. The rest of this volume then illustrates this year’s controls and governance findings in more detail.

Issues

Recommendations

1.1 New and repeat findings

The number of internal control deficiencies reduced over the past three years, but new higher-risk information technology (IT) control deficiencies were reported in 2016–17.

Deficiencies repeated from previous years still make up a sizeable proportion of all internal control deficiencies.

Recommendation

Agencies should focus on emerging IT risks, but also manage new IT risks, reduce existing IT control deficiencies, and address repeat internal control deficiencies on a more timely basis.

1.2 High risk findings

We found seven high risk internal control deficiencies, which might significantly affect agencies.

Recommendation

Agencies should rectify high risk internal control deficiencies as a priority

1.3 Common findings

The most common internal control deficiencies related to poor or absent IT controls.

We found some common governance deficiencies across multiple agencies.

Recommendation

Agencies should coordinate actions and resources to help rectify common IT control and governance deficiencies.

Information technology (IT) has become increasingly important for government agencies’ financial reporting and to deliver their services efficiently and effectively. Our audits reviewed whether agencies have effective controls in place over their IT systems. We found that IT security remains the source of many control weakness in agencies.

Issues Recommendations

2.1 IT security

User access administration

While 95 per cent of agencies have policies about user access, about two-thirds were compliant with these policies. Agencies can improve how they grant, change and end user access to their systems.

Recommendation

Agencies should strengthen user access administration to prevent inappropriate access to sensitive systems. Agencies should:

  • establish and enforce clear policies and procedures
  • review user access regularly
  • remove user access for terminated staff promptly
  • change user access for transferred staff promptly.

Privileged access

Sixty-eight per cent of agencies do not adequately manage who can access their information systems, and many do not sufficiently monitor or restrict privileged access.

Recommendation

Agencies should tighten privileged user access to protect their information systems and reduce the risks of data misuse and fraud. Agencies should ensure they:

  • only grant privileged access in line with the responsibilities of a position
  • review the level of access regularly
  • limit privileged access to necessary functions and data
  • monitor privileged user account activity on a regular basis.

Password controls

Forty-one per cent of agencies did not meet either their own standards or minimum standards for password controls.

Recommendation

Agencies should review and enforce password controls to strengthen security over sensitive systems. As a minimum, password parameters should include:

  • minimum password lengths and complexity requirements
  • limits on the number of failed log-in attempts
  • password history (such as the number of passwords remembered)
  • maximum and minimum password ages.

2.2 Cyber Security

Cyber security framework

Agencies do not have a common view on what constitutes a cyber attack, which limits understanding the extent of the cyber security threat.

Recommendation

The Department of Finance, Services and Innovation should revisit its existing framework to develop a shared cyber security terminology and strengthen the current reporting requirements for cyber incidents.

Cyber security strategies

While 82 per cent of agencies have dedicated resources to address cyber security, they can strengthen their strategies, expertise and staff awareness.

Recommendations

The Department of Finance, Services and Innovation should:

  • mandate minimum standards and require agencies to regularly assess and report on how well they mitigate cyber security risks against these standards
  • develop a framework that provides for cyber security training.

Agencies should ensure they adequately resource staff dedicated to cyber security.

2.3 Other IT systems

Change control processes

Some agencies need to improve change control processes to avoid unauthorised or inaccurate system changes.

Recommendation

Agencies should consistently perform user acceptance testing before system upgrades and changes. They should also properly approve and document changes to IT systems.

Disaster recovery planning

Agencies can do more to adequately assess critical business systems to enforce effective disaster recovery plans. This includes reviewing and testing their plans on a timely basis.

Recommendation

Agencies should complete business impact analyses to strengthen disaster recovery plans, then regularly test and update their plans.

Agency service delivery relies on developing and renewing infrastructure assets such as schools, hospitals, roads, or public housing. Agencies are currently investing significantly in new assets. Agencies need to manage the scale and volume of current capital projects in order to deliver new infrastructure on time, on budget and realise the intended benefits. We found agencies can improve how they:

  • manage their major capital projects
  • dispose of existing assets.
Issues Recommendations or conclusions

3.1 Capital investment

Capital asset investment ratios

Most agencies report high capital investment ratios, but one-third of agencies’ capital investment ratios are less than one.

Recommendation

Agencies with high capital asset investment ratios should ensure their project management and delivery functions have the capacity to deliver their current and forward work programs.

Volume of capital spending

Most agencies have significant forward spending commitments for capital projects. However, agencies’ actual capital expenditure has been below budget for the last three years.

Conclusion

The significant increase in capital budget underspends warrant investigation, particularly where this has resulted from slower than expected delivery of projects from previous years.

3.2 Capital projects

Major capital projects

Agencies’ major capital projects were underspent by 13 percent against their budgets.

Conclusion

The causes of agency budget underspends warrant investigation to ensure the NSW Government’s infrastructure commitment is delivered on time.

Capital project governance

Agencies do not consistently prepare business cases or use project steering committees to oversee major capital projects.

Conclusion

Agencies that have project management processes that include robust business cases and regular updates to their steering committees (or equivalent) are better able to provide those projects with strategic direction and oversight.

3.3. Asset disposals

Asset disposal procedures

Agencies need to strengthen their asset disposal procedures.

Recommendations

Agencies should have formal processes for disposing of surplus properties.

Agencies should use Property NSW to manage real property sales unless, as in the case for State owned corporations, they have been granted an exemption.

Governance refers to the high-level frameworks, processes and behaviours that help an organisation to achieve its objectives, comply with legal and other requirements, and meet a high standard of probity, accountability and transparency.

This chapter sets out the governance lighthouse model the Audit Office developed to help agencies reach best practice. It then focuses on two key areas: continuous disclosure and shared services arrangements. The following two chapters look at findings related to ethics and risk management.

Issues Recommendations or conclusions

4.1 Governance arrangements

Continuous disclosure

Continuous disclosure promotes improved performance and public trust and aides better decision-making. Continuous disclosure is only mandatory for NSW Government Businesses such as State owned corporations.

Conclusion

Some agencies promote transparency and accountability by publishing on their websites a continuous disclosure policy that provides for, and encourages:

  • regular public disclosure of key performance information
  • disclosure of both positive and negative information
  • prompt reporting of significant issues.

4.2 Shared services

Service level agreements

Some agencies do not have service level agreements for their shared service arrangements.

Many of the agreements that do exist do not adequately specify controls, performance or reporting requirements. This reduces the effectiveness of shared services arrangements.

Conclusion

Agencies are better able to manage the quality and timeliness of shared service arrangements where they have a service level agreement in place. Ideally, the terms of service should be agreed before services are transferred to the service provider and:

  • specify the controls a provider must maintain
  • specify key performance targets
  • include penalties for non-compliance.

Shared service performance

Some agencies do not set performance standards for their shared service providers or regularly review performance results.

Conclusion

Agencies can achieve better results from shared service arrangements when they regularly monitor the performance of shared service providers using key measures for the benefits realised, costs saved and quality of services received.

Before agencies extend or renegotiate a contract, they should comprehensively assess the services received and test the market to maximise value for money.

All government sector employees must demonstrate the highest levels of ethical conduct, in line with standards set by The Code of Ethics and Conduct for NSW government sector employees.

This chapter looks at how well agencies are managing these requirements, and where they can improve their policies and processes.

We found that agencies mostly have the appropriate codes, frameworks and policies in place. But we have highlighted opportunities to improve the way they manage those systems to reduce the risks of unethical conduct.

Issues Recommendations or conclusions

5.1 Ethical framework

Code of conduct

All agencies we reviewed have a code of conduct, but they can still improve the way they update and manage their codes to reduce the risk of fraud and unethical behaviour.

Recommendation

Agencies should regularly review their code-of-conduct policies and ensure they keep their codes of conduct up-to-date.

Statement of business ethics

Most agencies maintain an ethical framework, but some can enhance their related processes, particularly when dealing with external clients, customers, suppliers and contractors.

Conclusion

Agencies can enhance their ethical frameworks by publishing a Statement of Business Ethics, which communicates their values and culture.

5.2 Potential conflicts of interest

Conflicts of interest

All agencies have a conflicts-of-interest policy, but most can improve how they identify, manage and avoid conflicts of interest.

Recommendation

Agencies should improve the way they manage conflicts of interest, particularly by:

  • requiring senior executives to make a conflict-of-interest declaration at least annually
  • implementing processes to identify and address outstanding declarations
  • providing annual training to staff
  • maintaining current registers of conflicts of interest.

Gifts and benefits

While all agencies already have a formal gifts-and-benefits policy, we found gaps in the management of gifts and benefits by some that increase the risk of unethical conduct.

Recommendation

Agencies should improve the way they manage gifts and benefits by promptly updating registers and providing annual training to staff.

Risk management is an integral part of effective corporate governance. It helps agencies to identify, assess and prioritise the risks they face and in turn minimise, monitor and control the impact of unforeseen events. It also means agencies can respond to opportunities that may emerge and improve their services and activities.

This year we looked at the overall maturity of the risk management frameworks that agencies use, along with two important risk management elements: risk culture and risk registers.

Issues Recommendations or conclusions

6.1 Risk management maturity

All agencies have implemented risk management frameworks, but with varying levels of maturity in their application.

Agencies’ averaged a score of 3.1 out of five across five critical assessment criteria for risk management. While strategy and governance fared best, the areas that most need to improve are risk culture, and systems and intelligence.

Conclusion

Agencies have introduced risk management frameworks and practices as required by the Treasury’s:

  • 'Risk Management Toolkit for the NSW Public Sector'
  • 'Internal Audit and Risk Management Policy for the NSW Public Sector'.

However, more can be done to progress risk management maturity and embed risk management in agency culture.

6.2 Risk management elements

Risk culture

Most agencies have started to embed risk management into the culture of their organisation. But only some have successfully done so, and most agencies can improve their risk culture.

 

 

Conclusion

Agencies can improve their risk culture by:

  • setting an appropriate tone from the top
  • training all staff in effective risk management
  • ensuring desired risk behaviours and culture are supported, monitored, and reinforced through business plans, or the equivalent and employees' performance assessments.

Risk registers and reporting

Some agencies do not report their significant risks to their lead agency, which may impair the way resources are allocated in their cluster. Some agencies do not integrate risk registers at a divisional and whole-of-enterprise level.

Conclusion

Agencies not reporting significant risks at the cluster level increases the likelihood that significant risks are not being mitigated appropriately.

Effective risk management can improve agency decision-making, protect reputations and lead to significant efficiencies and cost savings. By embedding risk management directly into their operations, agencies can also derive extra value for their activities and services.

Published

Actions for Report on Education 2017

Report on Education 2017

Education
Financial reporting
Internal controls and governance
Management and administration
Procurement
Project management
Workforce and capability

The Auditor-General, Margaret Crawford released her report on the results of the financial audits of agencies in the Education cluster. The report focuses on key observations and findings from the most recent audits of these agencies.

'I am pleased to report that unqualified audit opinions were issued on the financial statements for all agencies in the Education cluster', the Auditor-General said. 'The quality and timeliness of financial reporting remains strong'.