Refine search Expand filter

Reports

Published

Actions for Integrity of data in the Births, Deaths and Marriages Register

Integrity of data in the Births, Deaths and Marriages Register

Justice
Premier and Cabinet
Whole of Government
Cyber security
Fraud
Information technology
Internal controls and governance
Management and administration

This report outlines whether the Department of Customer Service (the department) has effective controls in place to ensure the integrity of data in the Births, Deaths and Marriages Register (the register), and to prevent unauthorised access and misuse.

The audit found that the department has processes in place to ensure that the information entered in the register is accurate and that any changes to it are validated. Although there are controls in place to prevent and detect unauthorised access to, and activity in the register, there were significant gaps in these controls. Addressing these gaps is necessary to ensure the integrity of information in the register.

The Auditor-General made nine recommendations to the department, aimed at strengthening controls to prevent and detect unauthorised access to, and activity in the register. These included increased monitoring of individuals who have access to the register and strengthening security controls around the databases that contain the information in the register.

The NSW Registry of Births Deaths and Marriages is responsible for maintaining registers of births, deaths and marriages in New South Wales as well as registering adoptions, changes of names, changes of sex and relationships. Maintaining the integrity of this information is important as it is used to confirm people’s identity and unauthorised access to it can lead to fraud or identity theft.

Read full report (PDF)

The NSW Registry of Births Deaths and Marriages (BD&M) is responsible for maintaining registers of births, deaths and marriages in New South Wales. BD&M is also responsible for registering adoptions, changes of name, changes of sex and relationships. These records are collectively referred to as 'the Register'. The Births, Deaths and Marriages Registration Act 1995 (the BD&M Act) makes the Registrar (the head of BD&M) responsible for maintaining the integrity of the Register and preventing fraud associated with the Register. Maintaining the integrity of the information held in the Register is important as it is used to confirm people's identity. Unauthorised access to, or misuse of the information in the Register can lead to fraud or identity theft. For these reasons it is important that there are sufficient controls in place to protect the information.

BD&M staff access, add to and amend the Register through the LifeLink application. While BD&M is part of the Department of Customer Service, the Department of Communities and Justice (DCJ) manages the databases that contain the Register and sit behind LifeLink and is responsible for the security of these databases.

This audit assessed whether BD&M has effective controls in place to ensure the integrity of data in the Births, Deaths and Marriages Register, and to prevent unauthorised access and misuse. It addressed the following:

  • Are relevant process and IT controls in place and effective to ensure the integrity of data in the Register and the authenticity of records and documents?
  • Are security controls in place and effective to prevent unauthorised access to, and modification of, data in the Register?

Conclusion

BD&M has processes and controls in place to ensure that the information entered in the Register is accurate and that amendments to the Register are validated. BD&M also has controls in place to prevent and detect unauthorised access to, and activity in the Register. However, there are significant gaps in these controls. Addressing these gaps is necessary to ensure the integrity of the information in the Register.

BD&M has detailed procedures for all registrations and amendments to the Register, which include processes for entering, assessing and checking the validity and adequacy of source documents. Where BD&M staff have directly input all the data and for amendments to the Register, a second person is required to check all information that has been input before an event can be registered or an amendment can be made. BD&M carries out regular internal audits of all registration processes to check whether procedures are being followed and to address non-compliance where required.

BD&M authorises access to the Register and carries out regular access reviews to ensure that users are current and have the appropriate level of access. There are audit trails of all user activity, but BD&M does not routinely monitor these. At the time of the audit, BD&M also did not monitor activity by privileged users who could make unauthorised changes to the Register. Not monitoring this activity created a risk that unauthorised activity in the Register would not be detected.

BD&M has no direct oversight of the database environment which houses the Register and relies on DCJ's management of a third-party vendor to provide the assurance it needs over database security. The vendor operates an Information Security Management System that complies with international standards, but neither BD&M nor DCJ has undertaken independent assurance of the effectiveness of the vendor's IT controls.

Appendix one – Response from agency

Appendix two – About the audit

Appendix three – Performance auditing

 

Copyright notice

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

 

Parliamentary reference - Report number #330 - released 7 April 2020.

Published

Actions for Justice 2016

Justice 2016

Justice
Asset valuation
Compliance
Financial reporting
Fraud
Information technology
Internal controls and governance
Procurement
Project management
Risk

Overcrowding in the NSW prison system continues to worsen along with the backlog of cases in the District Court, according to a report released by the New South Wales Auditor-General, Margaret Crawford on the annual financial statements audits in the Justice cluster.

Published

Actions for Fraud Survey

Fraud Survey

Education
Community Services
Finance
Health
Industry
Justice
Local Government
Planning
Premier and Cabinet
Transport
Treasury
Universities
Whole of Government
Environment
Fraud
Information technology
Internal controls and governance
Procurement
Risk

In a report released today, the NSW Auditor-General, Margaret Crawford provides a snapshot of reported fraud in the NSW public sector and an analysis of NSW Government agencies’ fraud controls based on a survey of 102 agencies.

Published

Actions for Implementation of the NSW Government’s program evaluation initiative

Implementation of the NSW Government’s program evaluation initiative

Industry
Justice
Planning
Premier and Cabinet
Treasury
Environment
Financial reporting
Internal controls and governance
Management and administration
Risk
Service delivery
Shared services and collaboration
Workforce and capability

The NSW Government’s ‘program evaluation initiative’, introduced to assess whether service delivery programs achieve expected outcomes and value for money, is largely ineffective according to a report released today by NSW Auditor-General, Margaret Crawford.

Government services, in areas such as public order and safety, health and education, are delivered by agencies through a variety of programs. In 2016–17, the NSW Government estimates that it will spend over $73 billion on programs to deliver services.

 

Parliamentary reference - Report number #277 - released 3 November 2016

Published

Actions for Preventing and managing worker injuries

Preventing and managing worker injuries

Justice
Management and administration
Risk
Workforce and capability

Police officers and firefighters in NSW are benefiting from an improved focus on preventing and managing injuries, according to a report released today by the NSW Auditor-General. However, the audit found these gains may not be enough to offset risks associated with increasing common law claims, and death and disability scheme costs.

‘Emergency service workers face dangerous situations and traumatic scenes’ said the Auditor-General ‘and are at a significant risk of injury and illness. While the NSW Police Force and Fire & Rescue NSW have made positive shifts towards more proactive injury prevention and better return to work programs and practices, both face significant cost issues.’

 

Parliamentary reference - Report number #275 - released 13 October 2016

Published

Actions for Performance frameworks in custodial centre operations

Performance frameworks in custodial centre operations

Justice
Management and administration
Risk
Service delivery

The effectiveness of Corrective Services NSW’s performance framework is limited because organisational key performance indicators (KPIs) do not cascade to public correctional centres, according to a report released today by the Acting New South Wales Auditor-General, Tony Whitfield.

'As a result, individual public correctional centres could not be assessed on how well they are contributing to overall Corrective Service objectives, and it is difficult to vary performance expectations in response to changing operating environments', said Mr Whitfield. 'Its commissioning and contestability project is designed to address these issues', he added.

 

Parliamentary reference - Report number #267 - released 3 March 2016

Published

Actions for Volume Seven 2012 focusing on Law, Order and Emergency Services

Volume Seven 2012 focusing on Law, Order and Emergency Services

Justice
Compliance
Fraud
Internal controls and governance
Management and administration
Procurement
Project management
Workforce and capability

Since the Victims’ Compensation Scheme started in 1989, $1.6 billion has been paid to victims of crime, but only $57.4 million or nearly four per cent has been recovered from convicted offenders. The remaining 96 per cent has been funded by the taxpayer.

Published

Actions for Volume Two 2012 focusing on Universities

Volume Two 2012 focusing on Universities

Universities
Financial reporting
Fraud
Management and administration
Regulation
Workforce and capability

The Members tested substantially complied with the requirements of the Parliamentary Remuneration Tribunal’s (PRT) Determination for the year ended 30 June 2011. Findings note that the Department of Parliamentary Services should remind Members that they should not approve additional temporary staff claim forms before staff have worked the hours.

Published

Actions for Managing IT Services Contracts

Managing IT Services Contracts

Finance
Health
Justice
Compliance
Information technology
Internal controls and governance
Procurement
Project management
Risk

Neither agency (NSW Ministry of Health and NSW Police Force) demonstrated that they continued to get value for money over the life of these long term contracts or that they had effectively managed all critical elements of the three contracts we reviewed post award. This is because both agencies treated contract extensions or renewals as simply continuing previous contractual arrangements, rather than as establishing a new contract and financial commitment. Consequently, there was not a robust analysis of the continuing need for the mix and quantity of services being provided or an assessment of value for money in terms of the prices being paid.

 

Parliamentary reference - Report number #220 - released 1 February 2012