Refine search Expand filter

Reports

Published

Actions for Industry 2018

Industry 2018

Industry
Asset valuation
Cyber security
Financial reporting
Information technology
Internal controls and governance
Service delivery

The Auditor-General for New South Wales, Margaret Crawford, released her report today on the Industry cluster. The report focuses on key observations and findings from the most recent financial audits of agencies in the cluster. Cluster agencies received unqualified audit opinions for 41 out of the 47 financial statements presented for audit for 30 June 2018. Six audits remain incomplete. 'While it is pleasing to note that unqualified audit opinions have been issued, the timeliness of financial reporting needs to be improved through better oversight, prompt resolution of issues, and an increased focus on early close procedures', the Auditor-General said.

This report analyses the results of our audits of financial statements of the Industry cluster for the year ended 30 June 2018. The table below summarises our key observations.

This report provides parliament and other users of the Industry cluster agencies' financial statements with the results of our audits, including our observations, analysis, conclusions and recommendations in the following areas:

  • financial reporting
  • audit observations
  • service delivery.

The Department of Industry (the Department) is the lead agency in a cluster of 50 agencies. Other significant agencies in the cluster include Local Land Services, New South Wales Rural Assistance Authority, Technical and Further Education Commission (TAFE NSW), various sporting agencies, Forestry Corporation NSW and Water NSW.

The cluster:

Financial reporting is an important element of good governance. Confidence and transparency in public sector decision making are enhanced when financial reporting is accurate and timely.

This chapter outlines our audit observations related to the financial reporting of agencies in the Industry cluster for 2018.
 

Observation Conclusions and recommendations
2.1 Quality of financial reporting
Unqualified audit opinions were issued for 41 out of 47 financial statement audits. Six audits are continuing.

The number of misstatements identified in financial statements submitted for audit increased from 73 in 2016–17 to 92 in 2017–18.
Conclusion: Agencies continue to address financial reporting issues and ensure significant matters that may impact the audit opinion are appropriately dealt with. The increase in the number of misstatements indicates a renewed focus on quality is required.
2.2 Timeliness of financial reporting
Nineteen out of 37 audit opinions were issued within the statutory deadline. Delays occurred due to the time required to resolve issues identified during the audit, or to obtain appropriate evidence to support balances or disclosures in the financial statements. There were also delays in receiving the signed certification from the agency, required before we can issue an audit opinion.

We reviewed the conduct of early close procedures at 17 agencies. Fifteen of these agencies were assessed as not fully addressing mandatory early close procedures.
Recommendation: Timeliness of financial reporting should be improved through better oversight of the preparation of financial statements, prompt resolution of issues, and an increased focus on early close procedures.
2.3 Key financial reporting issues
Information system limitations continue at TAFE NSW. TAFE NSW implemented additional processes to verify the accuracy and completeness of revenue from student fees. Conclusion: Procedures to address system limitations are costly, causing delays in financial reporting and increased resource commitments for staff, contractors and audit.
Misstatements and internal control issues continue to be identified in accounting for Crown land. The information system used to record Crown land was not designed to facilitate efficient financial reporting. These limitations and other control weaknesses impacted the completeness and accuracy of the Department's financial statements.
Recommendation: The Department should address system limitations and control weaknesses to ensure complete and accurate reporting for Crown land.
Unprocessed Aboriginal land claims continue to increase. Recommendation (repeat issue): The Department should reduce unprocessed Aboriginal land claims.
2.4 Financial information and sustainability
Cluster agencies recorded a combined surplus of $58.0 million compared to a combined deficit of $86.0 million in the previous year.

 

We identified five agencies with potential sustainability issues such as low liquidity or negative net assets. Conclusion: Adequate arrangements are in place to mitigate potential sustainability issues. These arrangements include a commitment from the Department to provide financial support if required. 

Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies. They are essential for quality and timely decision making.

This chapter outlines our observations and insights from:

  • our financial statement audits of agencies in the Industry cluster for 2018
  • the areas of focus identified in the Audit Office work program.

The Audit Office Annual Work Program provides a summary of all audits to be conducted within the proposed time period as well as detailed information on the areas of focus for each of the NSW Government clusters.

Observation Conclusions and recommendations
3.1 Internal control
Almost one in three internal control issues identified in 2017–18 were repeat issues. Recommendation (repeat issue): Recommendations to management to address internal control issues from prior years should be addressed promptly to reduce risks and improve processes.
3.2 Information technology controls
User access administration over financial systems remains an area of weakness. Two high risk and 18 moderate risk issues related to user access administration across nine agencies were identified. Recommendation (repeat issue): Agencies' controls over administration of user access to critical systems should:
  • retain documentation of approvals to create, modify and deactivate user access
  • allocate appropriate access rights
  • perform and document regular user access reviews
  • log and monitor privileged/super user account activity
  • deactivate terminated user access on a timely basis.
3.3 Annual work program
Errors continue to be identified in the Crown land database.

Instances were identified where Crown land was not recognised by the appropriate entity, or was recognised by more than one entity.
Recommendation: The Department should ensure the Crown land database is complete and accurate so state agencies and local government councils are better informed about the Crown land they control.
Approximately 700 managers of Crown land do not submit financial statements required by the Public Finance and Audit Act 1983. NSW Treasury and the Department are continuing work to clarify reporting arrangements for these entities.
3.4 Managing maintenance
Some cluster agencies do not monitor their backlog maintenance. Consequently, the total backlog maintenance in the Industry cluster is unknown. This impacts the reliability and consistency of information about assets and their condition. When backlog maintenance is unknown, it is difficult for agencies to develop an accurate and effective maintenance plan that focuses on areas of highest need. It also means agencies' maintenance plans are reactive rather than preventative.
Effective maintenance planning helps agencies to:
  • quantify and budget asset maintenance costs
  • support service delivery at the lowest possible long-term cost
  • reduce service disruptions and losses due to asset failure
  • identify and respond to risks posed by the age and condition of assets.
Recommendation: Cluster agencies should develop an asset maintenance plan and complete an assessment of the condition of their assets to identify any maintenance backlogs. 
Maintenance budgets in some cluster agencies are not set based on actual maintenance needs. Recommendation: Cluster agencies should set their maintenance budgets based on identified maintenance needs to more accurately budget and prioritise expenditure.

Agencies in the Industry cluster provide services across a wide variety of areas. This chapter outlines certain service delivery outcomes for 2017–18 for the Industry cluster. It provides important contextual information about the cluster's operation, but the data on activity levels and performance is provided by Cluster agencies. The Audit Office does not have a specific mandate to audit performance information. Accordingly, the information in this chapter is unaudited. 

In our recent performance audit, Progress and measurement of Premier's Priorities, we identified 12 limitations of performance measurement and performance data. We recommended that the Department of Premier and Cabinet ensure that processes to check and verify data are in place for all agency data sources.

Published

Actions for Family and Community Services 2018

Family and Community Services 2018

Community Services
Compliance
Financial reporting
Information technology
Management and administration
Project management
Risk
Service delivery
Workforce and capability

The Auditor-General for New South Wales, Margaret Crawford released her report today on the Family and Community Services cluster. The report focuses on key observations and findings from the most recent financial audits of agencies in the cluster. Cluster entities received unqualified audit opinions for their 30 June 2018 financial statements. Opportunities to improve the quality of financial reporting were identified and reported to management.

This report analyses the results of our audits of financial statements of the Family and Community Services cluster for the year ended 30 June 2018. The table below summarises our key observations.

This report provides NSW Parliament and other users of the financial statements of Family and Community Services' agencies with the results of our audits, our observations, analysis, conclusions and recommendations in the following areas:

  • financial reporting
  • audit observations
  • service delivery.

Financial reporting is an important element of good governance. Confidence and transparency in public sector decision making are enhanced when financial reporting is accurate and timely.

This chapter outlines our audit observations related to the financial reporting of agencies in the Family and Community Services cluster for 2018.

Observation Conclusions and recommendations
2.1 Quality of financial reporting
Unqualified audit opinions were issued for all cluster agencies' financial statements. Conclusion: Sufficient audit evidence was obtained to conclude the financial statements were free of material misstatement.
Agencies complied with NSW Treasury’s mandatory early close requirements.

Completing other early close procedures was inconsistent and not always supported by adequate evidence.
Conclusion: There are opportunities for agencies to improve the quality of financial reporting by:
  • documenting all significant judgements and assumptions used when preparing the financial statements
  • regularly reconciling inter-agency balances and transactions
  • reconciling key account balances on a timely basis
  • quantifying the impact of new and revised accounting standards.
2.2 Timeliness of financial reporting
Agencies completed revaluations of property, plant and equipment and submitted 31 March 2018 financial statements by the due date as required by NSW Treasury.

Agencies submitted year-end financial statements by the statutory deadline.
Conclusion: Early revaluations of property, plant and equipment contributes to agencies meeting the year-end statutory reporting deadline.

Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies. They are essential for quality and timely decision making.

This chapter outlines our observations and insights from:

  • our financial statement audits of agencies in the Family and Community Services cluster for 2018
  • the areas of focus identified in the Audit Office annual work program.

The Audit Office Annual Work Program provides a summary of all audits to be conducted within the proposed time period as well as detailed information on the areas of focus for each NSW Government cluster.

Observation Conclusions and recommendations
3.1 Internal controls
The 2017–18 audits reported 47 internal control weaknesses. While none were high risk, there were 15 repeat issues.

Conclusion: Management accepted audit findings and advised they are actioning recommendations. Timely action is important to ensure internal controls operate effectively.

Twenty-two of these internal control weaknesses related to information technology processes and control environment. Conclusion: Control weaknesses in information systems may compromise the integrity and security of financial data used for decision making and financial reporting.

Recommendation: Agencies should strengthen user access administration to prevent inappropriate access to key IT systems by:
  • ensuring privileged user access is limited to those requiring access to maintain the IT systems
  • monitoring privileged user access to address risks from unauthorised activity
  • ensuring IT password settings comply with password policies
  • ensuring timely removal of access to business systems for terminated and casual employees.
The Department, NSW Land and Housing Corporation (LAHC) and three other cluster agencies’ contract registers are incomplete and/or inaccurate. Recommendation: Agencies should ensure their contract registers are complete and accurate so they can more effectively govern contracts and manage compliance obligations.
3.2 Audit Office annual work program
Financial impact of the commissioning approach.

The transfer of disability services to the National Disability Insurance Scheme and other commissioning of service delivery has contributed to a 36 per cent decrease in frontline employee numbers since 2015–16. Similarly, corporate services’ employee numbers reduced by 34 per cent.

The Department’s salary costs have reduced by $232 million or 18 per cent from 2016–17.
Conclusion: The ratio of corporate services employee numbers to support frontline and support services has remained at 1:10 since 2015–16, which indicates restructures have been planned to align with the transfer of disability services.
Impact of the new social housing maintenance contract

Maintenance expenses have increased by about 40 per cent since the new maintenance contract commenced in April 2016. LAHC measures the benefits of the new maintenance contract such as improved tenant satisfaction.
Conclusion: The new maintenance contract has contributed to some positive social outcomes such as tenants being employed by the contractors to conduct maintenance, as call centre operators and in administration. However, more can be done to ensure value for money is being achieved.
ChildStory IT Project

Whilst phase one of the ChildStory IT project went 'live' in 2017–18, the planned timetable has not been met and the revised date for full implementation is end of 2018.

According to the 2014–15 NSW Budget, the budget for ChildStory was $100 million over a four-year period. During the design and implementation stage, this amount was revised to $128 million, with approval of the Expenditure Review Committee. The actual cost incurred over the four years until 30 June 2018, is approximately $131 million.

We identified issues with the data migration from the legacy systems to ChildStory.
Conclusion: To inform future IT projects, we understand the Department is capturing our findings, along with the findings from the Department of Finance, Services and Innovation’s ‘Healthchecks’.

This chapter outlines certain service delivery outcomes for 2017–18. The data on activity levels and performance is provided by Cluster agencies. The Audit Office does not have a specific mandate to audit performance information. Accordingly, the information in this chapter is unaudited.

In our recent performance audit, Progress and measurement of Premier's Priorities, we identified 12 limitations of performance measurement and performance data. We recommended that the Department of Premier and Cabinet ensure that processes to check and verify data are in place for all agency data sources.

Published

Actions for Internal Controls and Governance 2018

Internal Controls and Governance 2018

Education
Community Services
Finance
Health
Industry
Justice
Planning
Premier and Cabinet
Transport
Treasury
Whole of Government
Environment
Compliance
Cyber security
Financial reporting
Fraud
Information technology
Internal controls and governance
Management and administration
Procurement
Project management

The Auditor-General for New South Wales Margaret Crawford found that as NSW state government agencies’ digital footprint increases they need to do more to address new and emerging information technology (IT) risks. This is one of the key findings to emerge from the second stand-alone report on internal controls and governance of the 40 largest NSW state government agencies.

This report analyses the internal controls and governance of the 40 largest agencies in the NSW public sector for the year ended 30 June 2018.

This report covers the findings and recommendations from our 2017–18 financial audits that relate to internal controls and governance at the 40 largest agencies (refer to Appendix three) in the NSW public sector.

This report offers insights into internal controls and governance in the NSW public sector

This is our second report dedicated to internal controls and governance at NSW State Government agencies. The report provides insights into the effectiveness of controls and governance processes in the NSW public sector by:

  • highlighting the potential risks posed by weaknesses in controls and governance processes
  • helping agencies benchmark the adequacy of their processes against their peers
  • focusing on new and emerging risks, and the internal controls and governance processes that might address those risks.

Without strong governance systems and internal controls, agencies increase the risks associated with effectively managing their finances and delivering services to citizens. The way agencies deliver services increasingly relies on contracts and partnerships with the private sector. Many of these arrangements deliver front line services, but others provide less visible back office support. For example, an agency may rely on an IT service provider to manage a key system used to provide services to the community. The contract and service level agreements are only truly effective where they are actively managed to reduce risks to continuous quality service delivery, such as interruptions caused by system outages, cyber security attacks and data security breaches.

Our audits do not review all aspects of internal controls and governance every year. We select a range of measures, and report on those that present heightened risks for agencies to mitigate. This report divides these into the following five areas:

  1. Internal control trends
  2. Information technology (IT), including IT vendor management
  3. Transparency and performance reporting
  4. Management of purchasing cards and taxis
  5. Fraud and corruption control.

The findings in this report should not be used to draw conclusions on the effectiveness of individual agency control environments and governance arrangements. Specific financial reporting, controls and service delivery comments are included in the individual 2018 cluster financial audit reports, which will be tabled in Parliament from November to December 2018.

The focus of the report has changed since last year

Last year's report topics included asset management, ethics and conduct, and risk management. We are reporting on new topics this year. We plan to introduce new topics and re-visit our previous topics in subsequent reports on a cyclical basis. This will provide a baseline against which to measure the NSW public sectors’ progress in implementing appropriate internal controls and governance processes to mitigate existing, new and emerging risks in the public sector.

Agencies selected for the volume account for 95 per cent of the state's expenditure

While we have covered only 40 agencies in this report, those selected are a large enough group to identify common issues and insights. They represent about 95 per cent of total expenditure for all NSW public sector agencies.

Internal controls are processes, policies and procedures that help agencies to:

  • operate effectively and efficiently
  • produce reliable financial reports
  • comply with laws and regulations
  • support ethical government.

This chapter outlines the overall trends for agency controls and governance issues, including the number of findings, level of risk and the most common deficiencies we found across agencies. The rest of this volume presents this year’s controls and governance findings in more detail.

Observation Conclusions and recommendations
2.1 High risk findings
We found six high risk findings (seven in 2016–17), one of which was repeated from both last year and 2015–16. Recommendation: Agencies should reduce risk by addressing high risk internal control deficiencies as a priority.
2.2 Common findings
We found several internal controls and governance findings common to multiple agencies. Conclusion: Central agencies or the lead agency in a cluster can play a lead role in helping ensure agency responses to common findings are consistent, timely, efficient and effective.
2.3 New and repeat findings
Although internal control deficiencies decreased over the last four years, this year has seen a 42 per cent increase in internal control deficiencies. The increase in new IT control deficiencies and repeat IT control deficiencies signifies an emerging risk for agencies.
IT control deficiencies feature in this increase, having risen by 63 per cent since last year. The number of repeat IT control deficiencies has doubled and is driven by the increasing digital footprint left by agencies as government prioritises on-line interfaces with citizens, and the number of transactions conducted through digital channels increases

Recommendation: Agencies should reduce IT risks by:

  • assigning ownership of recommendations to address IT control deficiencies, with timeframes and actions plans for implementation
  • ensuring audit and risk committees and agency management regularly monitor the implementation status of recommendations.

 

Government agencies’ financial reporting is now heavily reliant on information technology (IT). IT is also increasingly important to the delivery of agency services. These systems often provide the data to help monitor the efficiency and effectiveness of agency processes and services they deliver. Our audits reviewed whether agencies have effective controls in place to manage both key financial systems and IT service contracts.

Observation Conclusions and recommendations
3.1 Management of IT vendors
Contract management framework 
Although 87 per cent of agencies have a contract management policy to manage IT vendors, one fifth require review.
 

Conclusion: Agencies can more effectively manage IT vendor contracts by developing policies and procedures to ensure vendor management frameworks are kept up to date, plans are in place to manage vendor performance and risk, and compliance with the framework is monitored by:

  • internal audit focusing on key contracting activities
  • experienced officers who are independent of contract administration performing spot checks or peer reviews
  • targeted analysis of data in contract registers.
Contract risk management
Forty-one per cent of agencies are not using contract management plans and do not assess contract risks. Half of the agencies that did assess contract risks, had not updated the risk assessments since the commencement of the contract.
 
Conclusion: Instead of applying a 'set and forget' approach in relation to management of contract risks, agencies should assess risk regularly and develop a plan to actively manage identified risks throughout the contract lifecycle - from negotiation and commencement, to termination.

Performance management
Eighty-six per cent of agencies meet with vendors to discuss performance. 

Only 24 per cent of agencies sought assurance about the accuracy of vendor reporting against KPIs, yet sixty-seven per cent of the IT contracts allow agencies to determine performance based payments and/or penalise underperformance.

Conclusion: Agencies are monitoring IT vendor performance, but could improve outcomes and more effectively manage under-performance by:

  • a more active, rigorous approach to both risk and performance management
  • checking the accuracy of vendor reporting against those KPIs and where appropriate seeking assurance over their accuracy
  • invoking performance based payments clauses in contracts when performance falls below agreed standards.

Transitioning services
Forty-three per cent of the IT vendor contracts did not contain transitioning-out provisions.

Where IT vendor contracts do make provision for transitioning-out, only 28 per cent of agencies have developed a transitioning-out plan with their IT vendor.

Conclusion: Contract transition/phase out clauses and plans can mitigate risks to service disruption, ensure internal controls remain in place, avoid unnecessary costs and reduce the risk of 'vendor lock-in'.
Contract Registers
Eleven out of forty agencies did not have a contract register, or have registers that are not accurate and/or complete.

Conclusion: A contract register helps to manage an agency’s compliance obligations under the Government Information (Public Access) Act 2009 (the GIPA Act). However, it also helps agencies more effectively manage IT vendors by:

  • monitoring contract end dates and contract extensions, and commence new procurements through their central procurement teams in a timely manner
  • managing their contractual commitments, budgeting and cash flow requirements.

Recommendation: Agencies should ensure their contract registers are complete and accurate so they can more effectively govern contracts and manage compliance obligations.

3.2 IT general controls
Governance
Ninety-five per cent of agencies have established policies to manage key IT processes and functions within the agency, with ten per cent of those due for review.
 
Conclusion: Regular review of IT policies ensures risks are considered and appropriate strategies and procedures are implemented to manage these risks on a consistent basis. An absence of policies can lead to ad-hoc responses to risks, and failure to consider emerging IT risks and changes to agency IT environments. 

User access administration
Seventy-two deficiencies were identified related to user access administration, including:

  • thirty issues related to granting user access across 43 per cent of agencies
  • sixteen issues related to removing user access across 30 per cent of agencies
  • twenty-six issues related to periodic reviews of user access across 50 per cent of agencies.
Recommendation: Agencies should strengthen the administration of user access to prevent inappropriate access to key systems.
Privileged access
Forty per cent of agencies do not periodically review logs of the activities of privileged users to identify suspicious or unauthorised activities.

Recommendation: Agencies should:

  • review the number of, and access granted to privileged users, and assess and document the risks associated with their activities
  • monitor user access to address risks from unauthorised activity.
Password controls
Twenty-three per cent of agencies did not comply with their own policy on password parameters.
Recommendation: Agencies should ensure IT password settings comply with their password policies.
Program changes
Fifteen per cent of agencies had deficient IT program change controls mainly related to segregation of duties and authorisation and testing of IT program changes prior to deployment.
Recommendation: Agencies should maintain appropriate segregation of duties in their IT functions and test system changes before they are deployed.

 

This chapter outlines our audit observations, conclusions and recommendations from our review of how agencies reported their performance in their 2016–17 annual reports. The Annual Reports (Statutory Bodies) Regulation 2015 and Annual Reports (Departments) Regulation 2015 (annual reports regulation) currently prescribes the minimum requirements for agency annual reports.

Observation Conclusion or recommendation
4.1 Reporting on performance

Only 57 per cent of agencies linked reporting on performance to their strategic objectives.

The use of targets and reporting performance over time was limited and applied inconsistently.

Conclusion: There is significant disparity in the quality and consistency of how agencies report on their performance in their annual reports. This limits the reliability and transparency of reported performance information.

Agencies could improve performance reporting by clearly linking strategic objectives to reported outcomes, and reporting on performance against targets over time. NSW Treasury may need to provide more guidance to agencies to support consistent and high-quality performance reporting in annual reports.

There is no independent assurance that the performance metrics agencies report in their annual reports are accurate.

Prior performance audits have noted issues related to the collection of performance information. For example, our 2016 Report on Red Tape Reduction highlighted inaccuracies in how the dollar-value of red tape reduction had been reported.

Conclusion: The ability of Parliament and the public to rely on reported information as a relevant and accurate reflection of an agency's performance is limited.

The relevance and accuracy of performance information is enhanced when:

  • policies and guidance support the consistent and accurate collection of data
  • internal review processes and management oversight are effective
  • independent review processes are established to provide effective challenge to the assumptions, judgements and methodology used to collect the reported performance information.
4.2 Reporting on reports

Agency reporting on major projects does not meet the requirements of the annual reports regulation.

Forty-seven per cent of agencies did not report on costs to date and estimated completion dates for major works in progress. Of the 47 per cent of agencies that reported on major works, only one agency reported detail about significant cost overruns, delays, amendments, deferments or cancellations.

NSW Treasury produce an annual report checklist to help agencies comply with their annual report obligations.

Recommendation: Agencies should comply with the annual reports regulation and report on all mandatory fields, including significant cost overruns and delays, for their major works in progress.

The information the annual reports regulation requires agencies to report deals only with major works in progress. There is no requirement to report on completed works.

Sixteen of 30 agencies reported some information on completed major works.

Conclusion: Agencies could improve their transparency if they reported, or were required to report:

  • on both works in progress and projects completed during the year
  • actual costs and completion dates, and forecast completion dates for major works, against original and revised budgets and original expected completion dates
  • explanations for significant cost overruns, delays and key project performance metrics.

 

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency preventative and detective controls over purchasing card and taxi use for 2017–18.

Observation Conclusion or recommendation
5.1 Management of purchasing cards
Volume of credit card spend
Purchasing card expenditure has increased by 76 per cent over the last four years in response to a government review into the cost savings possible from using purchasing cards for low value, high volume procurement.
 
Conclusion: The increasing use of purchasing cards highlights the importance of an effective framework for the use and management of purchasing cards.
Policy framework
We found all agencies that held purchasing cards had a policy in place, but 26 per cent of agencies have not reviewed their purchasing card policy by the scheduled date, or do not have a scheduled revision date stated within their policy.
Recommendation: Agencies should mitigate the risks associated with increased purchasing card use by ensuring policies and purchasing card frameworks remain current and compliant with the core requirements of TPP 17–09 'Use and Management of NSW Government Purchasing Cards'.
Preventative controls
We found that:
  • all agencies maintained purchasing card registers
  • seventy-six per cent provided training to cardholders prior to being issued with a card
  • eighty-nine per cent appointed a program administrator, but only half of these had clearly defined roles and responsibilities
  • thirty-two per cent of agencies place merchant blocks on purchasing cards
  • forty-seven per cent of agencies place geographic restrictions on purchasing cards.

Agencies have designed and implemented preventative controls aimed at deterring the potential misuse of purchasing cards.

Conclusion: Further opportunities exist for agencies to better control the use of purchasing cards, such as:

  • updating purchasing card registers to contain all mandatory fields required by TPP17–09
  • appointing a program administrator for the agency's purchasing card framework and defining their role and responsibility for the function
  • strengthening preventive controls to prevent misuse.

Detective controls
Ninety-two per cent of agencies have designed and implemented at least one control to monitor purchasing card activity.

Major reviews, such as data analytics (29 per cent of agencies) and independent spot checks (49 per cent of agencies) are not widely used.

Agencies have designed and implemented detective controls aimed at identifying potential misuse of purchasing cards.

Conclusion: More effective monitoring using purchasing card data can provide better visibility over spending activity and can be used to:

  • detect misuse and investigate exceptions
  • analyse trends to highlight cost saving opportunities.
5.2 Management of taxis
Policy framework
Thirteen per cent of agencies have not developed and implemented a policy to manage taxi use. In addition:
  • a further 41 per cent of agencies have not reviewed their policies by the scheduled revision date, or do not have a scheduled revision date
  • more than half of all agencies’ policies do not offer alternative travel options. For example, only 36 per cent of policies promoted the use of general Opal cards.
Conclusion: Agencies can promote savings and provide more options to staff where their taxi use policies:
  • limit the circumstances where taxi use is appropriate
  • offer alternate, lower cost options to using taxis, such as general Opal cards and rideshare.
Detective controls
All agencies approve taxi expenditure by expense reimbursement, purchasing card and Cabcharge, and have implemented controls around this approval process. However, beyond this there is minimal monitoring and review activity, such as data monitoring, independent spot checks or internal audit reviews.
Conclusion: Taxi spend at agencies is not significant in terms of its dollar value, but it is significant from a probity perspective. Agencies can better address the probity risk by incorporating taxi use into a broader purchasing card or fraud monitoring program.

 

Fraud and corruption control is one of the 17 key elements of our governance lighthouse. Recent reports from ICAC into state agencies and local government councils highlight the need for effective fraud control and ethical frameworks. Effective frameworks can help protect an agency from events that risk serious reputational damage and financial loss.

Our 2016 Fraud Survey found the NSW Government agencies we surveyed reported 1,077 frauds over the three year period to 30 June 2015. For those frauds where an estimate of losses was made, the reported value exceeded $10.0 million. The report also highlighted that the full extent of fraud in the NSW public sector could be higher than reported because:

  • unreported frauds in organisations can be almost three times the number of reported frauds
  • our 2015 survey did not include all NSW public sector agencies, nor did it include any NSW universities or local councils
  • fraud committed by citizens such as fare evasion and fraudulent state tax self-assessments was not within the scope of our 2015 survey
  • agencies did not estimate a value for 599 of the 1,077 (56 per cent) reported frauds.

Commissioning and outsourcing of services to the private sector and the advancement of digital technology are changing the fraud and corruption risks agencies face. Fraud risk assessments should be updated regularly and in particular where there are changes in agency business models. NSW Treasury Circular TC18-02 NSW Fraud and Corruption Control Policy now requires agencies develop, implement and maintain a fraud and corruption control framework, effective from 1 July 2018. 

Our Fraud Control Improvement Kit provides guidance and practical advice to help organisations implement an effective fraud control framework. The kit is divided into ten attributes. Three key attributes have been assessed below; prevention, detection and notification systems.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency fraud and corruption controls for 2017–18.

Observation Conclusion or recommendation
6.1 Prevention systems

Prevention systems
Ninety-two per cent of agencies have a fraud control plan in place, 81 per cent maintain a fraud database and 79 per cent report fraud and corruption matters as a standing item on audit and risk committee agendas.

Only 54 per cent of agencies have an employment screening policy and all agencies have IT security policies, but gaps in IT security controls could undermine their policies.

Conclusion: Most agencies have implemented fraud prevention systems to reduce the risk of fraud. However poor IT security along with other gaps in agency prevention systems, such as employment screening practices heightens the risk of fraud and inappropriate use of data.

Agencies can improve their fraud prevention systems by:

  • completing regular fraud risk assessments, embedding fraud risk assessment into their enterprise risk management process and reporting the results of the assessment to the audit and risk committee
  • maintaining a fraud database and reviewing it regularly for systemic issues and reporting a redacted version of the database on the agency's website to inform corruption prevention networks
  • developing policies and procedures for employee screening and benchmarking their current processes against ICAC's publication ‘Strengthening Employment Screening Practices in the NSW Public Sector’
  • developing and maintaining up to date IT security policies and monitoring compliance with the policy.
Twenty-three per cent of agencies were not performing fraud risk assessments and some agency fraud risk assessments may not be as robust as they could be.  Conclusion: Agencies' systems of internal controls may be less effective where new and emerging fraud risks have been overlooked, or known weaknesses have not been rectified.
6.2 Detection systems
Detection systems
Several agencies reported they were developing a data monitoring program, but only 38 per cent of agencies had already implemented a program.
 

Studies have shown data monitoring, whereby entire populations of transactional data are analysed for indicators of fraudulent activity, is one of the most effective methods of early detection. Early detection decreases the duration a fraud remains undetected thereby limiting the extent of losses.

Conclusion: Data monitoring is an effective tool for early detection of fraud and is more effective when informed by a comprehensive fraud risk assessment.

6.3 Notification systems
Notification system
All agencies have notification systems for reporting actual or suspected fraud and corruption. Most agencies provide multiple reporting lines, provide training and publicise options for staff to report actual or suspected fraud and corruption.
Conclusion: Training staff about their obligations and the use of fraud notification systems promotes a fraud-aware culture

 

Published

Actions for Managing Antisocial behaviour in public housing

Managing Antisocial behaviour in public housing

Community Services
Asset valuation
Infrastructure
Regulation
Service delivery
Workforce and capability

The Department of Family and Community Services (FACS) has not adequately supported or resourced its staff to manage antisocial behaviour in public housing according to a report released today by the Deputy Auditor-General for New South Wales, Ian Goodwin. 

In recent decades, policy makers and legislators in Australian states and territories have developed and implemented initiatives to manage antisocial behaviour in public housing environments. All jurisdictions now have some form of legislation or policy to encourage public housing tenants to comply with rules and obligations of ‘good neighbourliness’. In November 2015, the NSW Parliament changed legislation to introduce a new approach to manage antisocial behaviour in public housing. This approach is commonly described as the ‘strikes’ approach. 

When introduced in the NSW Parliament, the ‘strikes’ approach was described as a means to:

  • improve the behaviour of a minority of tenants engaging in antisocial behaviour 
  • create better, safer communities for law abiding tenants, including those who are ageing and vulnerable.

FACS has a number of tasks as a landlord, including a responsibility to collect rent and organise housing maintenance. FACS also has a role to support tenants with complex needs and manage antisocial behaviour. These roles have some inherent tensions. The FACS antisocial behaviour management policy aims are: 

to balance the responsibilities of tenants, the rights of their neighbours in social housing, private residents and the broader community with the need to support tenants to sustain their public housing tenancies.

This audit assessed the efficiency and effectiveness of the ‘strikes’ approach to managing antisocial behaviour in public housing environments.

We examined whether:

  • the approach is being implemented as intended and leading to improved safety and security in social housing environments
  • FACS and its partner agencies have the capability and capacity to implement the approach
  • there are effective mechanisms to monitor, report and progressively improve the approach.
Conclusion

FACS has not adequately supported or resourced its staff to implement the antisocial behaviour policy. FACS antisocial behaviour data is incomplete and unreliable. Accordingly, there is insufficient data to determine the nature and extent of the problem and whether the implementation of the policy is leading to improved safety and security

FACS management of minor and moderate incidents of antisocial behaviour is poor. FACS has not dedicated sufficient training to equip frontline housing staff with the relevant skills to apply the antisocial behaviour management policy. At more than half of the housing offices we visited, staff had not been trained to:

  • conduct effective interviews to determine whether an antisocial behaviour complaint can be substantiated

  • de escalate conflict and manage complex behaviours when required

  • properly manage the safety of staff and tenants

  • establish information sharing arrangements with police

  • collect evidence that meets requirements at the NSW Civil and Administrative Tribunal

  • record and manage antisocial behaviour incidents using the information management system HOMES ASB.

When frontline housing staff are informed about serious and severe illegal antisocial behaviour incidents, they generally refer them to the FACS Legal Division. Staff in the Legal Division are trained and proficient in managing antisocial behaviour in compliance with the policy and therefore, the more serious incidents are managed effectively using HOMES ASB. 


FACS provides housing services to most remote townships via outreach visits from the Dubbo office. In remote townships, the policy is not being fully implemented due to insufficient frontline housing staff. There is very limited knowledge of the policy in these areas and FACS data shows few recorded antisocial behaviour incidents in remote regions. 


The FACS information management system (HOMES ASB) is poorly designed and has significant functional limitations that impede the ability of staff to record and manage antisocial behaviour. Staff at most of the housing offices we visited were unable to accurately record antisocial behaviour matters in HOMES ASB, making the data incorrect and unreliable.

Published

Actions for Matching skills training with market needs

Matching skills training with market needs

Industry
Compliance
Internal controls and governance
Management and administration
Risk
Service delivery
Workforce and capability

The NSW Department of Industry targets subsidies towards training programs delivering skills most needed in New South Wales. However, the Department still provides subsidies to qualifications that the market may no longer need, according to a report released by Margaret Crawford, Auditor-General for New South Wales. 

In 2012, governments across Australia entered into the National Partnership Agreement on Skills Reform. Under the National Partnership Agreement, the Australian Government provided incentive payments to States and Territories to move towards a more contestable Vocational Education and Training (VET) market. The aim of the National Partnership Agreement was to foster a more accessible, transparent, efficient and high quality training sector that is responsive to the needs of students and industry. 

The New South Wales Government introduced the Smart and Skilled program in response to the National Partnership Agreement. Through Smart and Skilled, students can choose a vocational course from a list of approved qualifications and training providers. Students pay the same fee for their chosen qualification regardless of the selected training provider and the government covers the gap between the student fee and the fixed price of the qualification through a subsidy paid to their training provider. 

Smart and Skilled commenced in January 2015, with the then Department of Education and Communities having primary responsibility for its implementation. Since July 2015, the NSW Department of Industry (the Department) has been responsible for VET in New South Wales and the implementation of Smart and Skilled. 

The NSW Skills Board, comprising nine part-time members appointed by the Minister for Skills, provides independent strategic advice on VET reform and funding. In line with most other States and Territories, the Department maintains a 'Skills List' which contains government subsidised qualifications to address identified priority skill needs in New South Wales.

This audit assessed the effectiveness of the Department in identifying, prioritising, and aligning course subsidies to the skill needs of NSW. To do this we examined whether:

  • the Department effectively identifies and prioritises present and future skill needs 
  • Smart and Skilled funding is aligned with the priority skill areas
  • skill needs and available VET courses are effectively communicated to potential participants and training providers.

Smart and Skilled is a relatively new and complex program, and is being delivered in the context of significant reform to VET nationally and in New South Wales. A large scale government funded contestable market was not present in the VET sector in New South Wales before the introduction of Smart and Skilled. This audit's findings should be considered in that context.
 

Conclusion
The Department effectively consults with industry, training providers and government departments to identify skill needs, and targets subsidies to meet those needs. However, the Department does not have a robust, data driven process to remove subsidies from qualifications which are no longer a priority. There is a risk that some qualifications are being subsidised which do not reflect the skill needs of New South Wales. 
The Department needs to better use the data it has, and collect additional data, to support its analysis of priority skill needs in New South Wales, and direct funding accordingly.
In addition to subsidising priority qualifications, the Department promotes engagement in skills training by:
  • funding scholarships and support for disadvantaged students
  • funding training in regional and remote areas
  • providing additional support to deliver some qualifications that the market is not providing.

The Department needs to evaluate these funding strategies to ensure they are achieving their goals. It should also explore why training providers are not delivering some priority qualifications through Smart and Skilled.

Training providers compete for funding allocations based on their capacity to deliver. The Department successfully manages the budget by capping funding allocated to each Smart and Skilled training provider. However, training providers have only one year of funding certainty at present. Training providers that are performing well are not rewarded with greater certainty.

The Department needs to improve its communication with prospective students to ensure they can make informed decisions in the VET market.

The Department also needs to communicate more transparently to training providers about its funding allocations and decisions about changes to the NSW Skills List. 

The NSW Skills List is unlikely to be missing high priority qualifications, but may include lower priority qualifications because the Department does not have a robust process to identify and remove these qualifications from the list. The Department needs to better use available data, and collect further data, to support decisions about which qualifications should be on the NSW Skills List.

The Department relies on stakeholder proposals to update the NSW Skills List. Stakeholders include industry, training providers and government departments. These stakeholders, particularly industry, are likely to be aware of skill needs, and have a strong incentive to propose qualifications that address these needs. The Department’s process of collecting stakeholder proposals helps to ensure that it can identify qualifications needed to address material skill needs. 

It is also important that the Department ensures the NSW Skills List only includes priority qualifications that need to be subsidised by government. The Department does not have robust processes in place to remove qualifications from the NSW Skills List. As a result, there is a risk that the list may include lower priority skill areas. Since the NSW Skills List was first created, new additions to the list have outnumbered those removed by five to one.

The Department does not always validate information gathered from stakeholder proposals, even when it has data to do so. Further, its decision making about what to include on, or delete from, the NSW Skills List is not transparent because the rationale for decisions is not adequately documented. 

The Department is undertaking projects to better use data to support its decisions about what should be on the NSW Skills List. Some of these projects should deliver useful data soon, but some can only provide useful information when sufficient trend data is available. 

Recommendation

The Department should: 

  • by June 2019, increase transparency of decisions about proposed changes to the NSW Skills List and improve record-keeping of deliberations regarding these changes
  • by December 2019, use data more effectively and consistently to ensure that the NSW Skills List only includes high priority qualifications
The Department funds training providers that deliver qualifications on the NSW Skills List. Alignment of funding to skill needs relies on the accuracy of the NSW Skills List, which may include some lower priority qualifications.

Only qualifications on the NSW Skills List are eligible for subsidies under Smart and Skilled. As the Department does not have a robust process for removing low priority qualifications from the NSW Skills list, some low priority qualifications may be subsidised. 

The Department allocates the Smart and Skilled budget through contracts with Smart and Skilled training providers. Training providers that meet contractual obligations and perform well in terms of enrolments and completion rates are rewarded with renewed contracts and more funding for increased enrolments, but these decisions are not based on student outcomes. The Department reduces or removes funding from training providers that do not meet quality standards, breach contract conditions or that are unable to spend their allocated funding effectively. Contracts are for only one year, offering training providers little funding certainty. 

Smart and Skilled provides additional funding for scholarships and for training providers in locations where the cost of delivery is high or to those that cater to students with disabilities. The Department has not yet evaluated whether this additional funding is achieving its intended outcomes. 

Eight per cent of the qualifications that have been on the NSW Skills List since 2015 are not delivered under Smart and Skilled anywhere in New South Wales. A further 14 per cent of the qualifications that are offered by training providers have had no student commencements. The Department is yet to identify the reasons that these high priority qualifications are either not offered or not taken up by students.

Recommendation

The Department should:

  • by June 2019, investigate why training providers do not offer, and prospective students do not enrol in, some Smart and Skilled subsidised qualifications 
  • by December 2019, evaluate the effectiveness of Smart and Skilled funding which supplements standard subsidies for qualifications on the NSW Skills List, to determine whether it is achieving its objectives
  • by December 2019, provide longer term funding certainty to high performing training providers, while retaining incentives for them to continue to perform well.
The Department needs to improve its communication, particularly with prospective students.

In a contestable market, it is important for consumers to have sufficient information to make informed decisions. The Department does not provide some key information to prospective VET students to support their decisions, such as measures of provider quality and examples of employment and further education outcomes of students completing particular courses. Existing information is spread across numerous channels and is not presented in a user friendly manner. This is a potential barrier to participation in VET for those less engaged with the system or less ICT literate.

The Department conveys relevant information about the program to training providers through its websites and its regional offices. However, it could better communicate some specific information directly to individual Smart and Skilled training providers, such as reasons their proposals to include new qualifications on the NSW Skills List are accepted or rejected. 

While the Department is implementing a communication strategy for VET in New South Wales, it does not have a specific communications strategy for Smart and Skilled which comprehensively identifies the needs of different stakeholders and how these can be addressed. 

Recommendation

By December 2019, the Department should develop and implement a specific communications strategy for Smart and Skilled to:

  • support prospective student engagement and informed decision making
  • meet the information needs of training providers 

Appendix one - Response from agency

Appendix two - About the audit

Appendix three - Performance auditing

 

Parliamentary reference - Report number #305 - released 26 July 2018

Published

Actions for Internal Controls and Governance 2017

Internal Controls and Governance 2017

Finance
Education
Community Services
Health
Justice
Whole of Government
Asset valuation
Compliance
Cyber security
Information technology
Internal controls and governance
Project management
Risk

Agencies need to do more to address risks posed by information technology (IT).

Effective internal controls and governance systems help agencies to operate efficiently and effectively and comply with relevant laws, standards and policies. We assessed how well agencies are implementing these systems, and highlighted opportunities for improvement.
 

1. Overall trends

New and repeat findings

The number of reported financial and IT control deficiencies has fallen, but many previously reported findings remain unresolved.

High risk findings

Poor systems implementations contributed to the seven high risk internal control deficiencies that could affect agencies.

Common findings

Poor IT controls are the most commonly reported deficiency across agencies, followed by governance issues relating to cyber security, capital projects, continuous disclosure, shared services, ethics and risk management maturity.

2. Information Technology

IT security

Only two-thirds of agencies are complying with their own policies on IT security. Agencies need to tighten user access and password controls.

Cyber security

Agencies do not have a common view on what constitutes a cyber attack, which limits understanding the extent of the cyber security threat.

Other IT systems

Agencies can improve their disaster recovery plans and the change control processes they use when updating IT systems.

3. Asset Management

Capital investment

Agencies report delays delivering against the significant increase in their budgets for capital projects.

Capital projects

Agencies are underspending their capital budgets and some can improve capital project governance.

Asset disposals

Eleven per cent of agencies were required to sell their real property through Property NSW but didn’t. And eight per cent of agencies can improve their asset disposal processes.

4. Governance

Governance arrangements

Sixty-four per cent of agencies’ disclosure policies support communication of key performance information and prompt public reporting of significant issues.

Shared services

Fifty-nine per cent of agencies use shared services, yet 14 per cent do not have service level agreements in place and 20 per cent can strengthen the performance standards they set.

5. Ethics and Conduct

Ethical framework

Agencies can reinforce their ethical frameworks by updating code‑of‑conduct policies and publishing a Statement of Business Ethics.

Conflicts of interest

All agencies we reviewed have a code of conduct, but they can still improve the way they update and manage their codes to reduce the risk of fraud and unethical behaviour.

6. Risk Management 

Risk management maturity

All agencies have implemented risk management frameworks, but with varying levels of maturity.

Risk management elements

Many agencies can improve risk registers and strengthen their risk culture, particularly in the way that they report risks to their lead agency.

This report covers the findings and recommendations from our 2016–17 financial audits related to the internal controls and governance of the 39 largest agencies (refer to Appendix three) in the NSW public sector. These agencies represent about 95 per cent of total expenditure for all NSW agencies and were considered to be a large enough group to identify common issues and insights.

The findings in this report should not be used to draw conclusions on the effectiveness of individual agency control environments and governance arrangements. Specific financial reporting, controls and service delivery comments are included in the individual 2017 cluster financial audit reports tabled in Parliament from October to December 2017.

This new report offers strategic insight on the public sector as a whole

In previous years, we have commented on internal control and governance issues in the volumes we published on each ‘cluster’ or agency sector, generally between October and December. To add further value, we then commented more broadly about the issues identified for the public sector as a whole at the start of the following year.

This year, we have created this report dedicated to internal controls and governance. This will help Parliament to understand broad issues affecting the public sector, and help agencies to compare their own performance against that of their peers.

Without strong control measures and governance systems, agencies face increased risks in their financial management and service delivery. If they do not, for example, properly authorise payments or manage conflicts of interest, they are at greater risk of fraud. If they do not have strong information technology (IT) systems, sensitive and trusted information may be at risk of unauthorised access and misuse.

These problems can in turn reduce the efficiency of agency operations, increase their costs and reduce the quality of the services they deliver.

Our audits do not review every control or governance measure every year. We select a range of measures, and report on those that present the most significant risks that agencies should mitigate. This report divides these into the following six areas:

  1. Overall trends
  2. Information technology
  3. Asset management
  4. Governance
  5. Ethics and conduct
  6. Risk management.

Internal controls are processes, policies and procedures that help agencies to:

  • operate effectively and efficiently
  • produce reliable financial reports
  • comply with laws and regulations.

This chapter outlines the overall trends for agency controls and governance issues, including the number of findings, level of risk and the most common deficiencies we found across agencies. The rest of this volume then illustrates this year’s controls and governance findings in more detail.

Issues

Recommendations

1.1 New and repeat findings

The number of internal control deficiencies reduced over the past three years, but new higher-risk information technology (IT) control deficiencies were reported in 2016–17.

Deficiencies repeated from previous years still make up a sizeable proportion of all internal control deficiencies.

Recommendation

Agencies should focus on emerging IT risks, but also manage new IT risks, reduce existing IT control deficiencies, and address repeat internal control deficiencies on a more timely basis.

1.2 High risk findings

We found seven high risk internal control deficiencies, which might significantly affect agencies.

Recommendation

Agencies should rectify high risk internal control deficiencies as a priority

1.3 Common findings

The most common internal control deficiencies related to poor or absent IT controls.

We found some common governance deficiencies across multiple agencies.

Recommendation

Agencies should coordinate actions and resources to help rectify common IT control and governance deficiencies.

Information technology (IT) has become increasingly important for government agencies’ financial reporting and to deliver their services efficiently and effectively. Our audits reviewed whether agencies have effective controls in place over their IT systems. We found that IT security remains the source of many control weakness in agencies.

Issues Recommendations

2.1 IT security

User access administration

While 95 per cent of agencies have policies about user access, about two-thirds were compliant with these policies. Agencies can improve how they grant, change and end user access to their systems.

Recommendation

Agencies should strengthen user access administration to prevent inappropriate access to sensitive systems. Agencies should:

  • establish and enforce clear policies and procedures
  • review user access regularly
  • remove user access for terminated staff promptly
  • change user access for transferred staff promptly.

Privileged access

Sixty-eight per cent of agencies do not adequately manage who can access their information systems, and many do not sufficiently monitor or restrict privileged access.

Recommendation

Agencies should tighten privileged user access to protect their information systems and reduce the risks of data misuse and fraud. Agencies should ensure they:

  • only grant privileged access in line with the responsibilities of a position
  • review the level of access regularly
  • limit privileged access to necessary functions and data
  • monitor privileged user account activity on a regular basis.

Password controls

Forty-one per cent of agencies did not meet either their own standards or minimum standards for password controls.

Recommendation

Agencies should review and enforce password controls to strengthen security over sensitive systems. As a minimum, password parameters should include:

  • minimum password lengths and complexity requirements
  • limits on the number of failed log-in attempts
  • password history (such as the number of passwords remembered)
  • maximum and minimum password ages.

2.2 Cyber Security

Cyber security framework

Agencies do not have a common view on what constitutes a cyber attack, which limits understanding the extent of the cyber security threat.

Recommendation

The Department of Finance, Services and Innovation should revisit its existing framework to develop a shared cyber security terminology and strengthen the current reporting requirements for cyber incidents.

Cyber security strategies

While 82 per cent of agencies have dedicated resources to address cyber security, they can strengthen their strategies, expertise and staff awareness.

Recommendations

The Department of Finance, Services and Innovation should:

  • mandate minimum standards and require agencies to regularly assess and report on how well they mitigate cyber security risks against these standards
  • develop a framework that provides for cyber security training.

Agencies should ensure they adequately resource staff dedicated to cyber security.

2.3 Other IT systems

Change control processes

Some agencies need to improve change control processes to avoid unauthorised or inaccurate system changes.

Recommendation

Agencies should consistently perform user acceptance testing before system upgrades and changes. They should also properly approve and document changes to IT systems.

Disaster recovery planning

Agencies can do more to adequately assess critical business systems to enforce effective disaster recovery plans. This includes reviewing and testing their plans on a timely basis.

Recommendation

Agencies should complete business impact analyses to strengthen disaster recovery plans, then regularly test and update their plans.

Agency service delivery relies on developing and renewing infrastructure assets such as schools, hospitals, roads, or public housing. Agencies are currently investing significantly in new assets. Agencies need to manage the scale and volume of current capital projects in order to deliver new infrastructure on time, on budget and realise the intended benefits. We found agencies can improve how they:

  • manage their major capital projects
  • dispose of existing assets.
Issues Recommendations or conclusions

3.1 Capital investment

Capital asset investment ratios

Most agencies report high capital investment ratios, but one-third of agencies’ capital investment ratios are less than one.

Recommendation

Agencies with high capital asset investment ratios should ensure their project management and delivery functions have the capacity to deliver their current and forward work programs.

Volume of capital spending

Most agencies have significant forward spending commitments for capital projects. However, agencies’ actual capital expenditure has been below budget for the last three years.

Conclusion

The significant increase in capital budget underspends warrant investigation, particularly where this has resulted from slower than expected delivery of projects from previous years.

3.2 Capital projects

Major capital projects

Agencies’ major capital projects were underspent by 13 percent against their budgets.

Conclusion

The causes of agency budget underspends warrant investigation to ensure the NSW Government’s infrastructure commitment is delivered on time.

Capital project governance

Agencies do not consistently prepare business cases or use project steering committees to oversee major capital projects.

Conclusion

Agencies that have project management processes that include robust business cases and regular updates to their steering committees (or equivalent) are better able to provide those projects with strategic direction and oversight.

3.3. Asset disposals

Asset disposal procedures

Agencies need to strengthen their asset disposal procedures.

Recommendations

Agencies should have formal processes for disposing of surplus properties.

Agencies should use Property NSW to manage real property sales unless, as in the case for State owned corporations, they have been granted an exemption.

Governance refers to the high-level frameworks, processes and behaviours that help an organisation to achieve its objectives, comply with legal and other requirements, and meet a high standard of probity, accountability and transparency.

This chapter sets out the governance lighthouse model the Audit Office developed to help agencies reach best practice. It then focuses on two key areas: continuous disclosure and shared services arrangements. The following two chapters look at findings related to ethics and risk management.

Issues Recommendations or conclusions

4.1 Governance arrangements

Continuous disclosure

Continuous disclosure promotes improved performance and public trust and aides better decision-making. Continuous disclosure is only mandatory for NSW Government Businesses such as State owned corporations.

Conclusion

Some agencies promote transparency and accountability by publishing on their websites a continuous disclosure policy that provides for, and encourages:

  • regular public disclosure of key performance information
  • disclosure of both positive and negative information
  • prompt reporting of significant issues.

4.2 Shared services

Service level agreements

Some agencies do not have service level agreements for their shared service arrangements.

Many of the agreements that do exist do not adequately specify controls, performance or reporting requirements. This reduces the effectiveness of shared services arrangements.

Conclusion

Agencies are better able to manage the quality and timeliness of shared service arrangements where they have a service level agreement in place. Ideally, the terms of service should be agreed before services are transferred to the service provider and:

  • specify the controls a provider must maintain
  • specify key performance targets
  • include penalties for non-compliance.

Shared service performance

Some agencies do not set performance standards for their shared service providers or regularly review performance results.

Conclusion

Agencies can achieve better results from shared service arrangements when they regularly monitor the performance of shared service providers using key measures for the benefits realised, costs saved and quality of services received.

Before agencies extend or renegotiate a contract, they should comprehensively assess the services received and test the market to maximise value for money.

All government sector employees must demonstrate the highest levels of ethical conduct, in line with standards set by The Code of Ethics and Conduct for NSW government sector employees.

This chapter looks at how well agencies are managing these requirements, and where they can improve their policies and processes.

We found that agencies mostly have the appropriate codes, frameworks and policies in place. But we have highlighted opportunities to improve the way they manage those systems to reduce the risks of unethical conduct.

Issues Recommendations or conclusions

5.1 Ethical framework

Code of conduct

All agencies we reviewed have a code of conduct, but they can still improve the way they update and manage their codes to reduce the risk of fraud and unethical behaviour.

Recommendation

Agencies should regularly review their code-of-conduct policies and ensure they keep their codes of conduct up-to-date.

Statement of business ethics

Most agencies maintain an ethical framework, but some can enhance their related processes, particularly when dealing with external clients, customers, suppliers and contractors.

Conclusion

Agencies can enhance their ethical frameworks by publishing a Statement of Business Ethics, which communicates their values and culture.

5.2 Potential conflicts of interest

Conflicts of interest

All agencies have a conflicts-of-interest policy, but most can improve how they identify, manage and avoid conflicts of interest.

Recommendation

Agencies should improve the way they manage conflicts of interest, particularly by:

  • requiring senior executives to make a conflict-of-interest declaration at least annually
  • implementing processes to identify and address outstanding declarations
  • providing annual training to staff
  • maintaining current registers of conflicts of interest.

Gifts and benefits

While all agencies already have a formal gifts-and-benefits policy, we found gaps in the management of gifts and benefits by some that increase the risk of unethical conduct.

Recommendation

Agencies should improve the way they manage gifts and benefits by promptly updating registers and providing annual training to staff.

Risk management is an integral part of effective corporate governance. It helps agencies to identify, assess and prioritise the risks they face and in turn minimise, monitor and control the impact of unforeseen events. It also means agencies can respond to opportunities that may emerge and improve their services and activities.

This year we looked at the overall maturity of the risk management frameworks that agencies use, along with two important risk management elements: risk culture and risk registers.

Issues Recommendations or conclusions

6.1 Risk management maturity

All agencies have implemented risk management frameworks, but with varying levels of maturity in their application.

Agencies’ averaged a score of 3.1 out of five across five critical assessment criteria for risk management. While strategy and governance fared best, the areas that most need to improve are risk culture, and systems and intelligence.

Conclusion

Agencies have introduced risk management frameworks and practices as required by the Treasury’s:

  • 'Risk Management Toolkit for the NSW Public Sector'
  • 'Internal Audit and Risk Management Policy for the NSW Public Sector'.

However, more can be done to progress risk management maturity and embed risk management in agency culture.

6.2 Risk management elements

Risk culture

Most agencies have started to embed risk management into the culture of their organisation. But only some have successfully done so, and most agencies can improve their risk culture.

 

 

Conclusion

Agencies can improve their risk culture by:

  • setting an appropriate tone from the top
  • training all staff in effective risk management
  • ensuring desired risk behaviours and culture are supported, monitored, and reinforced through business plans, or the equivalent and employees' performance assessments.

Risk registers and reporting

Some agencies do not report their significant risks to their lead agency, which may impair the way resources are allocated in their cluster. Some agencies do not integrate risk registers at a divisional and whole-of-enterprise level.

Conclusion

Agencies not reporting significant risks at the cluster level increases the likelihood that significant risks are not being mitigated appropriately.

Effective risk management can improve agency decision-making, protect reputations and lead to significant efficiencies and cost savings. By embedding risk management directly into their operations, agencies can also derive extra value for their activities and services.

Published

Actions for Industry 2017

Industry 2017

Industry
Asset valuation
Compliance
Internal controls and governance
Procurement
Project management
Risk

The following report highlights the results of the financial audits of NSW Government entities in the Industry cluster. The report focuses on key observations and findings from the most recent audits of these entities.

The report notes that TAFE NSW will continue to incur extra costs each year to produce reliable financial information due to deficiencies in its student administration system. TAFE NSW plans to replace its Student Administration and Learning Management system in 2018-19 at an estimated cost of $89 million.

1. Financial reporting and controls

Financial reporting

Unqualified audit opinions were issued for 44 out of 48 financial statement audits with four audits incomplete. Early close procedures continue to promote earlier and better quality financial reporting.
Financial performance The cluster recorded a net deficit of $107 million in 2016–17 ($78.0 million in 2015–16). Contributing to the overall cluster net deficit was the Department's $226 million net deficit offset by net surpluses at Water NSW and the Forestry Corporation of New South Wales.
TAFE NSW continues to experience system issues TAFE NSW incurs extra costs each year to produce reliable financial information due to deficiencies in its student administration system. TAFE NSW plans to replace its Student Administration and Learning Management system in 2018–19 at an estimated cost of $89 million.
Internal controls

We identified 180 internal control issues, including 61 repeat issues across the cluster. We rated four of these issues as 'high' risk, 98 as ‘moderate’ risk and 78 as ‘low’ risk.

Of the 180 issues raised, 37 related to financial reporting and 52 related to controls over processes such as procurement and fixed assets.

Some internal control issues and recommendations identified in previous years, have been repeated and should be addressed promptly to reduce risks and improve processes.

Deficient user administration access Agencies need to strengthen user access administration to critical financial systems.

2. Service delivery

Premier and State Priorities    

Australian Bureau of Statistics data shows the Premier's priority for job creation has been achieved.

While performance has declined for the State priority to increase the proportion of people completing apprenticeships and traineeships, the Department advises it has initiatives in place to achieve this State priority, and the State priority for New South Wales to lead Australia in business confidence.

Crown land   The Department is working to respond to the recommendations from a Parliamentary Inquiry into Crown Land and to implement the revised framework contained in the Crown Land Management Act 2016.
Aboriginal land claims

Despite a continued focus, the Department has been unsuccessful in reducing the number of unprocessed Aboriginal land claims.

The Department should continue to implement measures to reduce the backlog of unprocessed Aboriginal land claims.

This report focuses on agencies in the Industry cluster. The report focuses on audit results, observations, conclusions and recommendations for financial reporting and controls, and service delivery.

This cluster leads the State's promotion of New South Wales as the place to invest and produce goods and services. Significant cluster agencies deliver services in the following areas:

Confidence in public sector decision-making and transparency is enhanced when financial reporting is accurate and timely. Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies.

This chapter outlines audit observations, conclusions and recommendations for the financial reporting and controls of agencies in the cluster for 2016–17.

Observation Conclusion or recommendation
2.1 Quality of financial reporting
Unqualified audit opinions were issued for 44 out of 48 financial statement audits. Four audits are continuing. Ongoing improvements in the preparation of financial statements helped identify and resolve material issues.
The number of misstatements within the cluster fell from 104 in 2015–16 to 70 in 2016–17. The ‘early close procedures’ initiative introduced by the Treasury in 2011–12 has reduced the number of misstatements each year.
2.2 Timeliness of financial reporting
Most agencies complied with the Treasury’s early close procedures and the timetable for the preparation and audit of financial statements. Greater focus on financial reporting and effective early close procedures has improved the timeliness of financial reporting, but further improvements are required.
2.3 Key financial issues from cluster agencies
The Department of Industry completed a revaluation of Crown land and continues work on improving the accounting for Crown land. The value of Crown land recognised in the Department's financial statements at 30 June 2017 was $5.3 billion. The revaluation was carried out using a revised mass valuation approach which reduced complexity and subjectivity and improved transparency.
There is no process in place to ensure agencies recognise all the Crown land they manage and control. Recommendation: The Department should confirm the completeness and accuracy of the Crown land database with other organisations that manage and control Crown land to improve the reliability of its records.
TAFE NSW incurred approximately $6 million of direct costs to deal with issues in its student administration system and establish the integrity of its financial data for 2016–17. TAFE NSW will continue to incur extra costs each year to produce reliable financial information. TAFE NSW advises it intends to replace the Student Administration and Learning Management system it jointly implemented with the Department of Education three years ago at a cost $40.2 million. TAFE plans to implement the new system in 2018–19 at an estimated cost of $89 million.
 
2.4 Key financial information  
The cluster recorded a net deficit of $107 million in 2016–17 ($78.0 million in 2015–16). The overall cluster net deficit included the Department's $226 million net deficit which was partly offset by net surpluses in a number of other agencies, including Water NSW and the Forestry Corporation of New South Wales. Most agencies in the cluster, including the Department, but excluding the State owned corporations, are dependent on the NSW Government for the majority of their revenue.
 
2.5 Financial performance and sustainability  
We assessed the performance of certain agencies against key financial sustainability indicators. This identified four agencies with adjusted net deficits and two agencies with liquidity ratios below one. Overall, based on our analysis these agencies are not at high risk of sustainability concerns.
2.6 Internal controls  
A significant number of repeat internal control issues were again raised with management for certain agencies in the cluster.
 
Recommendation (repeat issue): Internal control issues and recommendations from previous years should be addressed promptly to reduce risks and improve processes.
User access administration over financial systems needs to be improved. 17 moderate risk issues related to user access administration across nine agencies were identified.

Recommendation: Agencies should ensure administration of user access to critical systems

  • retains documentation of approvals to create, modify and deactivate user access
  • allocates appropriate access rights
  • performs and documents regular user access reviews
  • logs and monitors privileged/super user account activity
  • deactivates terminated user access on a timely basis
  • does not allow shared generic user accounts, instead of unique user accounts for staff performing administration tasks.

Government outcomes can be achieved by delivering services through a mix of the public, private or not-for-profit sectors. Service delivery reform is most successful if there is clear accountability for service delivery outcomes, decisions are aligned to the government's strategic direction, and performance and value for money are monitored and evaluated.

This chapter outlines our audit observations, conclusions and recommendations for the service delivery of agencies in the cluster for 2016–17.

Issues Conclusion or recommendation

3.1 Measuring and reporting on performance

The Department is responsible for two State priorities (increasing apprenticeships and business confidence) and the Premier's priority of creating jobs. The Department also supports four state priorities. Australian Bureau of Statistics data shows the Premier's priority for job creation continues to be achieved. The Department reported that the number of people completing apprenticeships and traineeships had declined to 59 per cent against a 2019 target of 65 per cent, while the State was ranked first or second on a range of business confidence indicators.

3.2 Improvements required in the administration of Crown land

The Department faces many challenges in the administration of Crown land. These challenges range from inadequate systems and processes through to satisfying competing commercial, environmental, and community interests.

The Department has implemented, or is implementing the recommendations from a performance audit on the Sale and Lease of Crown land and the Parliamentary Inquiry into Crown land.

It is also implementing the revised framework for Crown land contained in the Crown Land Management Act 2016.

3.3 Aboriginal land claims over Crown land

The number of unprocessed Aboriginal land claims continues to increase. Work on finalising Aboriginal Land Agreements, which may help address the claims backlog, is continuing. Recommendation (repeat Issue): The Department should continue to implement measures to reduce the number of unprocessed Aboriginal land claims.
 

3.4 Skills development

Eleven contracted Smart and Skilled service providers had their contracts cancelled for quality issues. There were 391 providers of Smart and Skilled qualifications as at October 2017. The Department of Industry spent $1.4 billion on the provision of vocational education and training. The Department has controls in place to monitor the performance of contracted service providers to ensure quality delivery of training.

Published

Actions for Family and Community Services 2017

Family and Community Services 2017

Community Services
Asset valuation
Compliance
Financial reporting
Information technology
Internal controls and governance
Procurement
Project management

The following report focuses on key observations and findings from the most recent audits of agencies in the Family and Community Services cluster.

The report includes a range of findings on service delivery. The Department of Family and Community Services' data indicates that family preservation programs are having a positive impact on children and young people entering statutory care. On the other hand, waiting times for social housing applicants increased in 2016-17.
 

1. Financial reporting and controls

Quality of financial reporting Unqualified audit opinions were issued for all cluster agencies' financial statements.   
Timeliness of financial reporting Agencies completed mandatory early close procedures and all but one agency submitted financial statements by the statutory deadline.
Internal controls The 2016–17 audits reported 29 internal control improvements to cluster agencies’ management. None of these findings were high risk. Eleven related to information technology control weaknesses in key financial business systems.

2. Service Delivery

Commissioning Non-government organisations (NGOs) received $2.6 billion in 2016–17 to deliver services.
Children and young people

The Department of Family and Community Services data indicates that family preservation programs are reducing the number of children and young people entering statutory care.

The Department's data shows 86 per cent of children and young people in statutory care had their placements reviewed in the 12 months to 30 June 2017. Legislation requires all placements are reviewed at least every 12 months.

Social Housing The Department's data shows waiting times for social housing applicants are longer than last year.
People with disability Under the current timetable for implementing the National Disability Insurance Scheme, the Department plans to transfer direct disability services to NGOs by 30 June 2018.

This report provides Parliament and others with the audit results, observations, conclusions and recommendations for Family and Community Services cluster agencies. The report has been structured into two chapters focusing on financial reporting and controls and service delivery.

The Family and Community Services cluster works with children, adults, families and communities to improve lives and help people realise their potential.

This chapter outlines audit observations, conclusions and recommendations related to the financial reporting and controls of agencies in the Family and Community Services cluster for 2016–17.

Financial reporting is an important element of good governance. Confidence in public sector decision making and transparency is enhanced when financial reporting is accurate and timely.

Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies. They are essential for quality and timely decision making.

Observation Conclusion or recommendation
2.1 Quality of financial reporting
Unqualified audit opinions were issued for all cluster agencies' financial statements. The quality of financial reporting remains high across the cluster.
2.2 Timeliness of financial reporting
Agencies completed mandatory early close procedures and all but one submitted financial statements by the deadline. Early close procedures continue to allow issues and financial reporting risk areas to be addressed early in the audit process. There are opportunities to improve effectiveness of early close procedures.
2.3 Internal controls
The 2016–17 audits reported 29 internal control weaknesses. While none were high risk, the Department had five repeat issues.

 
Management accepted the audit findings and advised they are actioning recommendations. Timely action is important to ensure internal controls operate effectively.
Eleven of these internal control weaknesses were related to IT system user access administration and security over financial systems.

Controls weaknesses may compromise the integrity and security of financial data.

Recommendation

Agencies should:

  • ensure policies for creating, modifying and deactivating user access are documented
  • enhance the current user access review process
  • log and monitor highly privileged user account activity
  • ensure timely removal of access to business systems for terminated and casual employees
  • ensure password parameters comply with internal policies.

Government outcomes can be improved by delivering the right mix of services, whether from the public, private or not for profit sectors. Service delivery reform will be most successful if there is clear accountability for service delivery outcomes, decisions are aligned to strategic direction and performance is monitored and evaluated.

This chapter outlines our audit observations, conclusions and recommendations related to service delivery by agencies in the Family and Community Services cluster for 2016–17.

Observation Conclusion or recommendation

3.1 Commissioning

Non-government organisations (NGOs) received $2.6 billion funding in 2016–17 to deliver services. Commissioning of service delivery can change the profile of risks that need to be managed. The Department has established a Commissioning Division and developed its ‘Commissioning for Better Outcomes Framework’. 

3.2 Children and young people

All the Department's Districts are accredited to provide out-of-home care services.

The Department's data indicates 66 more children and young people were in statutory care at 30 June 2017 compared to 30 June 2016. This contrasts to the previous year where 1,150 more children were in statutory care at 30 June 2016 than at 30 June 2015.

The Department is complying with out-of-home care service standards, but one District has an additional condition attached to its accreditation.

Department’s data indicates that family preservation programs are having a positive impact..

The Department's data shows 86 per cent of children and young people in statutory care had their placement reviewed at 30 June 2017.

The Department’s data shows, at 30 June 2017, 41 per cent of children and young people with closed case plans for the 12 months ended 30 June 2016 were re-reported at risk of significant harm.

The Department did not meet the legislative requirement to review the placement of all children and young people in statutory care annually.

The number of children being re-reported at risk of significant harm is above the Premier’s Priority target of 34 per cent by June 2019.
 

3.3. Social Housing

Waiting time for priority and non-priority social housing applicants increased in 2016–17, by 19 per cent and 3 per cent respectively. Some factors impacting waiting time for social housing applicants are outside the control of the Department.

3.4 People with disability

A Bilateral Agreement between the Australian and NSW Governments sets out how eligible persons access the National Disability Insurance Scheme (NDIS) between 1 July 2016 and 30 June 2018.
 
Under the timetable for the NDIS, the Department plans to transfer direct disability services to NGOs.
 

Published

Actions for Mining Rehabilitation Security Deposits

Mining Rehabilitation Security Deposits

Planning
Industry
Environment
Infrastructure
Management and administration
Project management

The Department of Planning and Environment requires mining companies to rehabilitate sites according to conditions set in the mining development approval. The Department holds mining rehabilitation security deposits that are meant to cover the full cost of rehabilitation if a mining company defaults on its rehabilitation obligations.

The total value of security deposits held has increased from $500 million in 2005 to around $2.2 billion in 2016, covering around 450 mine sites in New South Wales.

While there have been substantial increases in total deposits held, mine rehabilitation security deposits are still not likely to be sufficient to cover the full costs of each mine's rehabilitation in the event of a default.

This audit was undertaken when the Department of Industry, Skills and Regional Development was responsible for ensuring land disturbed by mining activities is rehabilitated in accordance with the relevant development approval, including the administration of mining rehabilitation security deposits. On 1 April 2017, this responsibility was transferred to the Department of Planning and Environment (the Department).  

This audit assessed whether the Department maintains adequate security deposits to cover the liabilities associated with mine closures, including rehabilitation. Companies authorised by the Department to undertake mining activities must provide a security deposit to cover the full costs of rehabilitation in the event of default by the company. Rehabilitation is the treatment of disturbed land or water to establish a safe, stable, non-polluting and sustainable environment.

Mining companies must provide an estimate of rehabilitation costs for each site. The Department provides a Rehabilitation Cost Calculation tool to assist companies calculate the deposit amount. Companies are also required to ensure that the cost estimate is in accordance with the approved Mining Operations Plan (MOP). The MOP is intended to be a mine rehabilitation and closure plan, and forms the basis for the estimation of the security deposit. The Department reviews the estimates and determines the deposit for each site.  

Security deposits are an option of last resort. The Department has other legislative and regulatory tools which it normally uses to promote compliance with rehabilitation requirements before accessing a security deposit. It can direct action by the mining company, issue fines and even have the Minister revoke a mining lease. To date, the Department has never had to access a security deposit for a state significant development mine site.

Conclusion

The Department holds security deposits for mining rehabilitation consistent with the amounts it has requested from mining companies, and it should be able to claim on a deposit if a mining company defaults on its rehabilitation obligations. The total value of deposits has increased from $500 million in 2005 to around $2.2 billion in 2016, covering around 450 mine sites. The Department’s management of the security deposit process has improved in recent years, and it has well advanced plans for further improvement, including a revised cost calculation tool.

The Department’s policy is that each mine’s security deposit should cover the full costs of rehabilitation for that mine. The security deposits the Department holds are not likely to be sufficient to cover the full costs of each mine’s rehabilitation in the event of a default. The rates and allowances in the current cost calculation tool have not been updated since 2013 and some activities required for effective rehabilitation are not covered, or not covered adequately.

Security deposits also do not include sufficient contingency given the substantial risks and uncertainties associated with mine rehabilitation and closure, particularly in the absence of a detailed closure plan. This risk is exacerbated by the limited independent verification of mining company claims about the size of the outstanding rehabilitation task, which remains the case despite recent improvements to monitoring and review procedures and practices.  

There is also no financial assurance held over the risk of significant unexpected environmental degradation in the long-term after a mine is deemed to be rehabilitated and the security deposit is returned. A security deposit is not an appropriate vehicle for covering this risk.

Security deposits are close to calculated value and should be accessible if needed

The value of securities held by the Department aligns with the latest approved rehabilitation cost estimates. This contrasts with the situation found by investigations in Victoria and Queensland, where deposit amounts held fell below the calculated costs.

The security deposits are usually in the form of a bank guarantee or cash. The Department has obtained legal advice indicating that it should be able to claim on these bank guarantees if the need arises. As the guarantee is between the financial institution and the Department, if a mining company goes into liquidation the Department should still be able to access the funds.  

When the latest estimate of rehabilitation costs is higher than the existing deposit, the Department will request additional security. It has experienced extensive delays in obtaining additional security for some sites, increasing the risk that available funds will be insufficient if needed.

Rehabilitation cost estimates are not yet adequate, but improvements are planned

The Department’s policy is for security deposits to cover the full cost of rehabilitation. No discounts are provided to mining companies for past good behaviour or low likelihood of default, unlike in some other states. Discounting could undermine the policy position.  

Current security deposits are unlikely to cover the full cost of rehabilitation on each mine site. The Department provides a rehabilitation cost calculation tool to help mining companies calculate the cost of rehabilitation and the required deposit amount, but:

  • several activities required to effect closure are not included and others underestimated
  • it does not make provision for industry cost changes over time
  • the rates used in the tool have not been updated since 2013
  • it was not able to provide the basis for the rates and allowances in the tool.

The Department reviews cost estimates provided by mining companies, but its verification of the extent of rehabilitation work on which these estimates are based is limited. It relies instead on section 387C of the Mining Act 1992 which makes it an offence for mining companies to provide false or misleading information. It is not evident how the Department would establish that information provided was false or misleading without more verification work, and six of the 14 cost estimates we reviewed were not signed by the mine manager, making enforcement more difficult.  

The Department has developed a new calculation tool, and recently released it for industry consultation. The new tool should improve rehabilitation estimates. It updates rates and allowances, and includes additional items to better cover required rehabilitation tasks. While a substantial improvement, the new tool could be further improved by providing additional coverage for stakeholder engagement, additional planning approvals, insurance costs, and any additional design, research and verification work required for successful closure.

There is no financial assurance over long-term environmental risks

The Department does not hold any financial assurance to cover the costs associated with mitigating any future environmental degradation once a mine closes and the security deposit is relinquished to the mining company. Security deposits are probably not the appropriate mechanism to cover these long-term risks but the risk of potential post-closure environmental degradation still needs to be costed and covered. A fund to cover the state-wide risk, to which all mines would contribute, is a possible mechanism.

Rehabilitation and closure outcomes are vague, particularly for unplanned closure

Rehabilitation outcomes in the MOPs we reviewed were generally not specific. Any lack of specificity in MOPs translates into uncertainty about rehabilitation work required if a mining company defaults. Part of the problem is that rehabilitation outcomes established in planning approvals are usually not specific and may not address all closure requirements. The Department has recognised there is scope to improve the clarity and specificity of rehabilitation requirements in planning approvals, and has started a review focusing on open-cut mines.

Rehabilitation outcomes are even less specific in the event of an unexpected early closure because they will probably be different from that achievable from a planned closure.  

MOP guidelines do not cover management of some key closure matters, such as the requirements of environment protection licences issued by the Environment Protection Authority and the management of heritage sites during closure.

There were significant variations in quality of MOPs we reviewed and the way closure risks and uncertainties were identified and addressed. The Department plans to improve the quality of rehabilitation programs through enhanced guidance and oversight.

Monitoring is not adequate to effectively gauge rehabilitation progress

The Department was not able to show it has been monitoring operational mine sites effectively to gauge the progress of ongoing site rehabilitation and the management of closure risks. There was no protocol for site inspections and limited evidence of inspections for the sites we reviewed.

The Department receives annual environmental management reports from mining companies, with most describing the areas of disturbance and rehabilitation occurring at each mine site. The Department recently established procedures for reviewing these annual reports, and has developed a risk-based process for prioritising reviews.

Most annual reports we reviewed did not explain environmental changes over time, nor the risks to mine closure and the measures required to mitigate them. For example, analysis of changes to surface water and groundwater quality was limited despite its relevance for assessing future contamination risks.

The Department does not currently have adequate processes in place to effectively verify the reported areas of disturbance and rehabilitation. It is developing geographic information system-based tools to better measure areas of disturbance and rehabilitation, new rehabilitation guidelines, and a procedure for determining whether rehabilitation has been successful. These initiatives should improve the monitoring and reporting of rehabilitation progress at mine sites.

There is no mechanism to prevent a mine being in ‘care and maintenance’ indefinitely

The Department does not have a clear policy on the length of time and circumstances under which a mine can remain in ‘care and maintenance’. Indefinite postponement of rehabilitation and closure is therefore possible. 'Care and maintenance' is the period following temporary cessation of operations when infrastructure remains largely intact and the site continues to be managed. There are a range of valid reasons for a mining company to put a mine in ‘care and maintenance’, but it is also reasonable for the community to expect a limit to how long it has to wait for proper rehabilitation.

Mining operations make a significant contribution to the NSW economy, including over $1.3 billion in royalties each year. Around 400 mine sites throughout NSW provide over 40,000 jobs and are a major source of economic activity for many communities. Despite these benefits, it is important to ensure that mining companies fulfil their obligations to rehabilitate land disturbed as a result of mining activity.

We recommend that the Department should, by January 2018:

1. Improve the quality of rehabilitation and closure plans by:

  • ensuring plans submitted by mining companies include robust mine rehabilitation and closure risk assessments
  • clarifying the level of detail required in plans at each stage of a mine’s operation
  • specifying how requirements set under other legislative instruments (e.g. environment protection licences, heritage assets) should be addressed.

2. Improve assurance that security deposits are sufficient by:

  • ensuring its new cost calculation tool adequately covers all works needed for rehabilitation and closure
  • increasing the contingency for uncertainties associated with mine rehabilitation and closure, at least until the mining company provides a detailed closure plan
  • verifying the cost estimates for a sample of high risk sites annually
  • ensuring that when mining companies are required to provide increased security deposits, they do so with minimal delay.

3. Enhance oversight of mine rehabilitation by:

  • developing a protocol to ensure sufficient and adequate site inspections
  • ensuring mining companies report performance against rehabilitation targets and environmental changes clearly, including an analysis of long-term surface water and groundwater trends in terms of levels, flow and quality
  • improving how it determines the progress and success of mine rehabilitation
  • developing clear policy and procedures for ensuring a mine cannot be put into ‘care and maintenance’ indefinitely.

4. Collaborate with relevant agencies to establish a financial assurance mechanism, such as a sinking fund, to cover the risk of long-term environmental degradation after mines are closed and security deposits returned.

Appendix One - Response from the Department

Appendix Two - About the audit

 

Parliamentary reference - Report number #285 - released 11 May 2017

Published

Actions for Contingent workforce - management and procurement

Contingent workforce - management and procurement

Industry
Management and administration
Procurement
Workforce and capability

The Department of Industry, Transport for NSW and the Department of Education were not able to demonstrate that the use of contingent labour is the best resourcing strategy to meet their business needs or deliver value for money.

NSW Government agencies use contingent labour to help deliver services to the community. The NSW Public Service Commission (PSC) defines contingent labour as people employed by a recruitment agency and hired by government agencies to provide labour or services. Agencies use contingent labour to fill a gap in skills or capability, for example, to fill a position while a staff member is on leave or where specialist knowledge may be needed on a short-term basis. The PSC estimated that in 2016 the contingent workforce represented 2.3 per cent of the public sector workforce, equivalent to 7,571 full-time employees.

The PSC recommends that contingent labour only be used when it is the most efficient and effective option available to respond to an agency’s business needs. It also recommends that agencies’ use of contingent labour be informed by workforce planning. 

Government spending on contingent labour has increased significantly over the last five years, from $503 million in 2011–12 to $1.1 billion in 2015–16. To reduce spend in this area, the NSW Government has introduced the Contingent Workforce Renewal Strategy, overseen by NSW Procurement. The Strategy aims to achieve greater efficiency and effectiveness in the use of contingent labour. It has four pillars:

  • prequalification scheme – a list of approved contingent labour suppliers
  • vendor management system – an information system to manage contingent workers
  • managed service provider – a recruitment agency broker
  • contractor management organisations – organisations that manage a contingent labour database, which agencies can source labour from.

The prequalification scheme is mandatory for public sector agencies. Agencies are progressively rolling out the other pillars. The vendor management system and managed service provider are together called ‘Contractor Central’.

Within the context of sector reform aimed at promoting efficiency and effectiveness, the objective of this audit is to assess whether agencies’ approach to purchasing and managing their contingent workforce meets business needs and delivers value for money. In making this assessment, we reviewed three agencies each at a different stage of the reform:

  • Department of Education (Education) – Contractor Central introduced in August 2015
  • Department of Industry (Industry) – Contractor Central introduced in November 2016, after our review
  • Transport for NSW (Transport) – Contractor Central not in place.
Conclusion

None of the three agencies we reviewed were able to demonstrate that contingent labour is the best resourcing strategy to meet their agencies’ business needs or delivers value for money. There are three reasons for this. First, agencies’ use of contingent labour was not informed by workforce planning at an agency level, with limited work undertaken in this area. Second, two of the three agencies have limited oversight of their contingent workforce. Information is not reliable or accurate, reports are onerous to produce, and there is limited reporting to the agency’s executive. Finally, none of the agencies routinely monitor and centrally document the performance of contingent workers to ensure services are delivered as planned. Together, these factors make it difficult for agencies to ensure contingent labour is engaged only when needed, at reasonable rates, and delivers quality services.

Some of these issues will be addressed by Contractor Central, which had only been introduced at Education at the time of our review. The new software program enables staff to easily obtain real-time reports on its contingent workforce. The recruitment broker also has the potential to improve value through better negotiation and benchmarking of pay rates. However, Contractor Central will only address some of the issues highlighted above. Better workforce planning and performance monitoring are needed to ensure an agencies’ workforce, including contingent workers, meets its business needs and represents value for money.


The use of contingent labour neither informs nor is informed by agency level workforce plans

None of the three agencies we reviewed had an agency level workforce plan in place. Agencies could not demonstrate that they had analysed their use of contingent labour at an agency level, including how it is being used to address any skills gaps. An agency’s executive is responsible for ensuring that an agency level workforce plan is in place. An agency level workforce plan helps hiring managers to make decisions on the best resource strategy to meet their business needs. This is important because contingent labour should only be engaged after considering all other recruitment options and the agency’s workforce plan.

Contingent workforce data is not always reliable or accurate

The accuracy and reliability of contingent workforce data varied significantly across the three agencies we reviewed. In Industry and Transport, information on contingent labour is difficult to obtain because it must be drawn from different data sources, affecting its accuracy, reliability and timeliness. This information is also incomplete, with these agencies not having a full picture of their contingent workforce. Quality data is important because it improves an agency’s capacity to plan and monitor its use of contingent labour to ensure it meets business needs.

At the time of our review, only Education, through Contractor Central, was able to obtain timely and accurate data on its use of contingent labour. Contractor Central has also improved its reporting capability, with the agency’s executive now receiving quarterly reports on its contingent workforce. In contrast, executives in Industry and Transport received ad-hoc reports on the use of contingent labour that only gave them limited oversight of their contingent workforce.

Long tenure of contingent workers is an issue in agencies

We found that the maximum tenure of contingent labour varied across agencies from nine to more than 20 years. In Education and Transport, staff reported that hiring managers assume contingent workers are automatically renewed at the end of their contract, with no formal consideration about whether contingent labour is still needed. Also, contingent labour is used for significant capital projects in the information technology and infrastructure areas where a project may run for several years.

None of the agencies reviewed undertook an analysis to determine how to reduce tenure while ensuring business needs are met. This is particularly important for long-term use of contingent labour for large capital projects. Understanding whether contingent labour represents best value compared to other recruitment options, such as secondments or temporary employment, is essential. Contingent workers are engaged under different working conditions to employees. Long tenure can pose an industrial relations risk to agencies because contingent workers may believe they are entitled to the same working conditions as employees.

On and off-boarding processes could be strengthened

Agencies have processes to engage and release contingent labour, also called on boarding and off-boarding. This includes access to IT systems, building access, and the return of property. However, not all agencies had on boarding or off-boarding checklists with specific requirements for engaging or releasing contingent labour. In addition, agencies’ off boarding guidelines did not always provide for knowledge transfer. This was identified as a key risk by staff because it is important to ensure that critical skills and knowledge are retained.

Risk that agencies are being overcharged when engaging contingent labour

We found that in agencies without Contractor Central, there is limited assurance that recruitment agencies charge in line with the prequalification scheme fees. NSW Procurement estimates that the government was overcharged $1.3 million in 2015–16. In addition, there is a risk that hiring managers do not have sufficient information to benchmark pay rates when negotiating contingent labour engagements. Agencies with Contractor Central may be more likely to get reasonable rates by using a recruitment broker who has specialised market knowledge.

No system in place to monitor the performance of contingent workers

None of the agencies we reviewed had a system in place to monitor the performance of their contingent workforce at an agency level to ensure it delivers value for money. Hiring managers are not required to evaluate whether contingent labour delivers the services for which they are hired. For example, hiring managers do not routinely assess and centrally document the quality of services provided, including whether services are delivered on time and within budget. This means contingent workers who are not performing may be re-hired by other managers or agencies. With the implementation of Contractor Central, there is the means to capture agency-wide information on the performance of contingent workers.

Contractor Central has the potential to improve value for money

Contractor Central has the potential to improve value for money. This is because the recruitment broker has specialised market knowledge and is able to promote competition, and benchmark and negotiate pay rates. In addition, the new software can streamline invoice processing and ensure correct supplier rates are charged. Education reports that it achieved a net saving of $944,600 from August 2015 to May 2016 due to the introduction of Contractor Central. Industry also expects to achieve similar results with Contractor Central, which it advised was implemented in November 2016.

The Department of Industry and Transport for NSW should, by December 2017:

1. improve the accuracy and reliability of their data on contingent labour

2. routinely report the use of contingent labour to agency executive.

The Department of Industry, Department of Education, and Transport for NSW should:

by December 2017:

3. ensure agency-wide on-boarding and off-boarding guidelines or checklists detail the specific requirements for engaging or releasing contingent labour, including provisions for knowledge transfer.

by March 2018

4. ensure that contingent labour informs and is informed by workforce planning, by:

  • analysing agency-wide business needs, staff capability, and skills gaps
  • understanding how gaps are filled by contingent workers or other recruitment options
  • assessing whether long-term contingent worker engagements are the most economical and effective labour option
  • evaluating whether contingent workers meet agency business needs and deliver value for money.

5. assess and centrally document the performance of their contingent workforce to ensure that services are delivered as contracted

6. implement processes to ensure that hiring managers consider other recruitment options prior to engaging or re-engaging contingent workers.
    

Sector-wide learnings

This audit identified learnings that government agencies across the sector should consider when procuring and managing contingent labour:

1. Contingent workforce planning should be part of an agency’s broader workforce planning.

2. Using information systems to manage and procure contingent labour improves the accuracy, reliability and timeliness of contingent labour data. This information enables agencies to consistently assess contingent labour rates and to identify persistent skills gaps in their workforce.

3. Routine reporting of contingent labour to agency executives provides oversight of an agency’s use of contingent labour.

4. Hiring managers should consider all recruitment options, with advice from human resources staff, before engaging contingent labour to ensure that it is the most appropriate solution for a specific need.

5. Regularly assessing long tenure contingent labour engagements helps to ensure that such engagements are still the most economical and effective labour option.

6. Planning the engagement of contingent workers, including provisions for knowledge transfer, maximises the potential to obtain value for money from the use of contingent labour.

7. Assessing and centrally documenting the performance of contingent labour against agreed deliverables helps to ensure services are delivered as planned, including in terms of quality, and timeliness.

Download appendices for report on Contingent workforce

 

Parliamentary reference - Report number #282 - released 27 April 2017