Refine search Expand filter

Reports

Published

Actions for Planning, Industry and Environment 2019

Planning, Industry and Environment 2019

Planning
Industry
Environment
Asset valuation
Cyber security
Financial reporting
Information technology
Infrastructure
Internal controls and governance
Management and administration
Service delivery
Workforce and capability

This report outlines the results of audits of the financial statements of agencies now grouped in the NSW Planning, Industry and Environment cluster.

Unqualified audit opinions were issued for 56 of the 66 cluster agencies’ 30 June 2019 financial statements. Ten audits remain incomplete. The cluster agencies need to improve the timeliness of financial reporting. 

The Audit Office continued to identify issues regarding unprocessed Aboriginal land claims and the recognition of Crown land. ‘Auditor-General’s reports to parliament have recommended action to reduce the level of unprocessed land claims since 2007. However, the number of unprocessed claims continued to increase’, Margaret Crawford said.

One in five internal control findings were repeat issues. Key themes included information technology, asset management and improvements required to expense and payroll controls.

The report makes several recommendations including:

  • Property NSW should urgently address the deficiencies in the lease data used to calculate the impact of the new leasing standard effective from 1 July 2019
  • the Department of Planning, Industry and Environment should prioritise action to reduce unprocessed Aboriginal land claims
  • the Department of Planning, Industry and Environment should ensure the Crown land database is complete and accurate so state agencies and local government councils are better informed about the Crown land they control.

This report analyses the results of our audits of financial statements of the Planning, Industry and Environment cluster agencies for the year ended 30 June 2019. The table below summarises our key observations.

1. Machinery of Government changes

Creation of the Planning, Industry and Environment cluster

The Machinery of Government (MoG) changes abolished the former Planning and Environment cluster and former Industry cluster, and created the Planning, Industry and Environment cluster on 1 July 2019.

The Department of Planning and Environment (DPE), the Department of Industry (DOI), the Office of Environment and Heritage, and the Office of Local Government were abolished and the majority of their functions were transferred to the new Department of Planning, Industry and Environment (DPIE).

The Department of Planning, Industry and Environment is still in the process of implementing changes

The MoG changes bring risks and challenges to the cluster. A MoG Steering Committee, with the support of various project control groups and working groups, identified and developed responses to key risks arising from the changes.

However, the DPIE will take some time to fully integrate the policies, systems and processes of the abolished Departments and agencies.

2. Financial reporting

Audit opinions Unqualified audit opinions were issued for 56 of the 66 cluster agencies' 30 June 2019 financial statements audits. Ten financial statements audits are still ongoing.
Timeliness of financial reporting

Fifty-five of the 57 agencies subject to statutory deadlines submitted their financial statements on time.

Due to issues identified during the audit, 13 financial statements audits were not completed and audit opinions issued by the statutory deadline.

Agencies prepared and submitted their early close procedures in accordance with the mandatory timeframe set by NSW Treasury. However, 17 of the 49 agencies where we reviewed early close procedures were assessed as either partially addressing or not addressing one or more of the mandatory requirements. The cluster agencies could benefit from an increased focus on early close procedures.

Introduction of AASB 16 'Leases'

We noted errors in the lease data used in Property NSW's AASB 16 impact calculations, which affect both Property NSW and other government agencies. These errors were significant enough to present a risk of material misstatements to the financial statements of Property NSW and other government agencies in future reporting periods.

We had similar findings in our recent performance audit on 'Property Asset Utilisation', which highlighted issues with the quality of Property NSW's records.

Recommendation: Property NSW should urgently address the deficiencies in the lease data used to calculate the impact of the new leasing standard effective from 1 July 2019.

Unprocessed Aboriginal land claims have continued to increase

Despite an increase in the number of claims resolved, the number of unprocessed Aboriginal land claims increased by 7.2 per cent from the prior year to 35,855 at 30 June 2019. Claims can be made over Crown land assets of the DPIE or other government agencies. Until claims are resolved, there is an uncertainty over who is entitled to the land and the uses and activities that can be carried out on the land. We first recommended action to address unprocessed claims in 2007.

Recommendation (repeat issue): The DPIE should prioritise action to reduce unprocessed Aboriginal land claims.

3. Audit observations

Internal controls

One in five internal control issues identified and reported to management in 2018–19 were repeat issues.

The lack of user access review was the most common IT general control issue in the cluster.

Drought relief

The NSW Government announced an emergency drought relief package of $500 million in 2018, in addition to other financial assistance measures already in place.

Limited documentation and written agreements between relevant delivery agencies resulted in a $31.0 million misstatement relating to grant revenue.

Recognition of Crown land

Crown land is an important asset of the state. Management and recognition of Crown land assets is weakened when there is confusion over who is responsible for a particular Crown land parcel. Last year we recommended the DOI should ensure the database of Crown land is complete and accurate. While the DOI has commenced actions to improve the database, this continued to be an issue in 2018–19.

Recommendation (repeat issue): The DPIE should ensure the Crown land database is complete and accurate so state agencies and local government councils are better informed about the Crown land they control.

Developer contributions The former DPE continued to accumulate more developer contributions revenues than it spent on infrastructure projects. Total unspent funds increased to $274 million at 30 June 2019.

 

This report provides parliament and other users of the Planning, Industry and Environment cluster agencies financial statements with the results of our audits, our observations, analysis, conclusions and recommendations in the following areas:

  • financial reporting
  • audit observations.

This cluster was created by the Machinery of Government changes on 1 July 2019. This report is focused on agencies in the Planning, Industry and Environment cluster from 1 July 2019. However, these agencies were all in other clusters during 2018–19. Please refer to the section on Machinery of Government changes for more details.

Machinery of Government (MoG) refers to how the government organises the structures and functions of the public service. MoG changes are where the government reorganises these structures and functions that are given effect by Administrative orders.

The MoG changes, announced following the NSW State election on 23 March 2019, created the Planning, Industry and Environment (PIE) cluster. The Administrative Changes Orders issued on 2 April 2019, 1 May 2019 and 28 June 2019 gave effect to these changes. These orders became effective on 1 July 2019.

Section highlights

The 2019 MoG changes significantly impacted the former Planning and Environment, and Industry clusters and agencies.

  • The PIE cluster combines most of the functions and agencies of the former Planning and Environment and Industry clusters from 1 July 2019.
  • The Department of Planning, Industry and Environment is the principal agency in the PIE cluster.
  • The MoG changes bring risks and challenges to the PIE cluster.
  • A MoG Steering Committee was established to oversee the transitional processes.
  • The full integration of the systems and processes will not be completed in the near future.

Financial reporting is an important element of good governance. Confidence and transparency in public sector decision making are enhanced when financial reporting is accurate and timely.

This chapter outlines our audit observations related to the financial reporting of agencies in the Planning, Industry and Environment (PIE) cluster for 2019. In this chapter, the Department of Planning, Industry and Environment is referred to as DPIE, the former Department of Planning and Environment as DPE, and the former Department of Industry as DOI.

Section highlights

  • Unqualified audit opinions were issued for all completed 30 June 2019 financial statements audits. However, some cluster agencies can further enhance the quality of financial reporting.
  • Timeliness of financial reporting remains an issue for 13 agencies.
  • Deficiencies were identified in the data used to calculate the impact of AASB 16 ‘Leases’ effective from 1 July 2019. Property NSW should urgently address these deficiencies.
  • Unprocessed Aboriginal land claims continue to increase. DPIE should prioritise action to reduce unprocessed Aboriginal land claims.

Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies. They are essential for quality and timely decision making.

This chapter outlines our audit observations and insights from our financial statement audits of agencies in the Planning, Industry and Environment (PIE) cluster for 2019. In this chapter, the Department of Planning, Industry and Environment is referred to as DPIE, the former Department of Planning and Environment as DPE, and the former Department of Industry as DOI.

Section highlights

  • One in five issues identified and reported to management in 2018–19 were repeat issues.
  • The lack of user access review was the most common IT general control issue in the PIE cluster.
  • The PIE cluster provided significant financial assistance for drought relief.
  • There continues to be significant deficiencies in Crown land records. The DPIE should ensure the Crown land database is complete and accurate.
  • Unspent developer contributions funds continued to build up in 2018–19. 

Appendix one – List of 2019 recommendations

Appendix two – Status of 2018 recommendations

Appendix three – Cluster agencies

Appendix four – Financial data

Appendix five – Management letter findings

Appendix six – Timeliness of financial reporting

 

Copyright notice

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Published

Actions for Transport 2019

Transport 2019

Transport
Asset valuation
Financial reporting
Infrastructure
Internal controls and governance
Management and administration
Service delivery
Workforce and capability

This report details the results of the financial audits of NSW Government's Transport cluster for the financial year ended 30 June 2019. The report focuses on key observations and findings from the most recent financial statement audits of agencies in the Transport cluster.

Unqualified audit opinions were issued for all agencies' financial statements. However, valuations of assets continue to create challenges across the cluster. The Audit Office identified some deficiencies in relation to asset valuations at Transport for NSW, Roads and Maritime Services, Rail Corporation New South Wales and Sydney Metro.

The Audit Office noted an increase in findings on internal controls across the Transport cluster. Key themes related to information technology, asset management and employee leave entitlements. The report also highlights the status of significant infrastructure projects across the Transport cluster.

The report makes several recommendations including:

  • agency finance teams need to be consulted on major business decisions and commercial transactions at the time of their execution to assess the financial reporting impacts
  • the Department of Transport should ensure consistent accounting policies are applied across its controlled entities.

Download the Transport 2019 report (PDF)

This report analyses the results of our audits of financial statements of the Transport cluster for the year ended 30 June 2019. The table below summarises our key observations.

1. Machinery of Government changes
Transport for NSW, as the
lead agency, will absorb the
functions of Roads and
Maritime Services

The NSW Government announced its intention to integrate Roads and Maritime Services (RMS) into Transport for NSW (TfNSW) as part of the Machinery of Government changes.

This change was not included in the Administrative Orders as the Transport Administration Act 1988 No. 109 governs the composition of the Transport cluster. The Transport Administration Amendment (RMS Dissolution) Act 2019 (the Act) received assent on 22 November 2019. The Act dissolves RMS and transfers the assets, rights and liabilities of RMS to TfNSW. As at the date of this Report, the Act is not yet in force.

Transport is considering the impact of the changes on its operating model and financial reporting.

2. Financial reporting
Audit opinions

Unqualified audit opinions were issued on the 2018–19 financial statements of all agencies in the Transport cluster.

TfNSW and Sydney Metro obtained a three-week extension from NSW Treasury to submit their financial statements for audit to resolve accounting issues surrounding the valuation of property, plant and equipment.

The Department of Transport reported total consolidated property, plant and equipment of $158 billion at 30 June 2019. In 2018–19, there were issues with asset valuations at TfNSW, RMS, Sydney Metro and Rail Corporation New South Wales (RailCorp), resulting in adjustments after the submission of financial statements for audit and the correction of a prior period error.

There was also a prior period error resulting from an agreement between TfNSW and the former UrbanGrowth Development Corporation due to a lack of assessment of the financial reporting implications at the time of signing the agreement.

Recommendation: Agency finance teams need to be consulted on major business decisions and commercial transactions to assess their accounting impacts at the time of their execution, rather than at the end of a financial year. Agencies also need to resolve all key accounting issues such as valuations as part of the early close procedures.

This would improve the quality of financial reporting and avoid the need for extensions for agencies to submit their financial statements for audit.

Preparedness for new
accounting standards
Agencies across the cluster are progressing in their implementation of the new accounting standards.

Transport cluster agencies need to improve their contracts registers to ensure they have a complete list of contracts and agreements to assess the impact of the new accounting standards.
Valuation of assets remains
a challenge in the
Transport cluster

Whilst agencies complied with the requirements of the accounting standards and NSW Treasury policies on valuations, the Audit Office identified some deficiencies in relation to asset valuations across the cluster.

TfNSW reported a retrospective correction of a prior period error at 1 July 2017 which resulted in a reduction in the valuation of its Country Rail Network earthworks by $2.1 billion. This was due to survey results which identified the earthworks were flatter and lower than estimated in the valuation at 30 June 2017.

RMS made several adjustments during the year to correct asset values due to changes to valuation assumptions or data improvements. This included:

  • reduction of $318 million in the value of land under roads
  • decrease of $84.9 million to the value of land and buildings
  • changes to the value of traffic control and traffic signal network assets, due to data improvements.

Sydney Metro North West officially opened in May 2019 and reported total assets of $9.1 billion. Sydney Metro derecognised $322 million in assets constructed to facilitate its operation but transferred to councils and utilities.

Inconsistent accounting
policies across the
Transport cluster

There was an inconsistency identified in the cluster relating to the valuation of substratum land. In 2018–19, RailCorp derecognised $109 million of substratum land to ensure consistency in its approach with other Transport agencies.

As the parent entity, the Department of Transport needs to ensure accounting policies are consistently applied across all controlled entities for consolidation purposes. Inconsistencies in the application of accounting standards across agencies will impact comparability of financial reporting and decision making across the Transport cluster.

Recommendation: The Department of Transport should ensure consistent accounting policies are applied across its controlled entities.

Revenue growth

Public transport passenger revenue increased by $89.0 million (5.9 per cent) in 2018–19, and patronage increased by 37.8 million (4.9 per cent) across all modes of transport based on data provided by TfNSW.

The increase in revenue is mainly due to an increase in patronage as well as the annual increase in fares.

Negative Opal cards

Negative balance Opal cards resulted in $2.9 million in revenue not collected in 2018–19 ($10.4 million since the introduction of Opal).

In January 2019, Transport made a change to the Sydney Airport stations to prevent customers with high negative balances exiting the station. In addition, in late 2018, Transport increased the minimum top up values for new cards at the airport stations.

Recommendation (repeat): TfNSW should implement further measures to prevent the loss of revenue from passengers tapping off with negative balance Opal cards.

3. Audit observations
Internal controls There was an increase in findings on internal controls across the Transport cluster. Key themes relate to information technology, employee leave entitlements and asset management.

Twenty-nine per cent of all issues were repeat issues. The majority of the repeat issues related to information technology controls.
Write-off of assets In addition to a $322 million derecognition of assets transferred to councils and utilities by Sydney Metro and a $109 million derecognition of substratum land at RailCorp, the Transport cluster wrote-off $278 million of assets related to roads, bridges, maritime assets, traffic signals and controls network.

These mainly related to roads, bridges, maritime assets, traffic signals and the control network where new infrastructure assets substantially replaced an existing asset as part of construction activities.
Transport Asset Holding
Entity (TAHE)
TAHE was established to be a dedicated asset manager for the delivery of public transport asset management. The Transport Administration Amendment (Transport Entities) Act 2017 will transition RailCorp into TAHE. RailCorp is now expected to transition to TAHE from 1 July 2020 (previously 1 July 2019). Several working groups have been considering various aspects of the TAHE transition including its status as a for profit Public Trading Enterprise, the operating model and the impact of the new accounting standards AASB 16 'Leases' and AASB 1059 'Service Concession Arrangements: Grantors'. The considerations of these aspects identified several challenges in the implementation of TAHE which has led to the revised transition date. Given the delays in implementation, it is important to clarify the intent of the TAHE model.
Excess annual leave

Twenty-six per cent of Transport employees have annual leave balances exceeding 30 days. Of the employees with excess leave balances, 732 (10.3 per cent) did not take any annual leave in 2018–19.

Recommendation (repeat): Transport entities should further review the approach to managing excess annual leave in 2019–20. They should:

  • monitor current and projected leave balances to the end of the financial year each month
  • agree formal leave plans with employees to reduce leave balances over an acceptable timeframe
  • ensure leave plans are actioned appropriately
  • encourage all staff with excess leave balances take a minimum two-week period of leave per year.
Completeness and
accuracy of contracts
registers

There are no centralised processes to record all significant contracts and agreements in a register across the Transport cluster.

Across the Transport cluster, contracts and agreements are maintained by the individual agencies using disparate registers. Agencies must perform detailed assessments of their existing contracts and agreements to quantify the impact of the new accounting standards (AASB 16 ‘Leases’, AASB 15 ‘Revenue from Contracts with Customers’, AASB 1058 ‘Income of Not-for-Profit Entities’ and AASB 1059 'Service Concession Arrangements: Grantors').

In 2018–19, there was also a prior period error resulting from an agreement between TfNSW and another government agency due to a lack of assessment of the financial reporting implications at the time of signing the agreement.

A lack of a complete register of all contracts and agreements increases the risk that agencies may not be able to assess the full impact of the new accounting standards, as well as perform a complete assessment of the financial reporting implications of contracts and agreements.

Recommendation: Transport agencies should implement a process to centrally capture all significant contracts and agreements entered. This will ensure:

  • agencies are fully aware of contractual and other obligations
  • appropriate assessment of financial reporting implications
  • assessment of new accounting standards, in particular AASB 16 ‘Leases’, AASB 15 'Revenue from Contract with Customers', AASB 1058 'Income of Not-for-Profit Entities ' and AASB 1059 'Service Concession Arrangements: Grantors' are accurate and complete.

 

This report provides parliament and other users of the Transport cluster’s financial statements with the results of our audits, our observations, analysis, conclusions and recommendations in the following areas:

  • financial reporting
  • audit observations.

This cluster was impacted by the Machinery of Government changes on 1 July 2019. The NSW Government announced its intention to integrate Roads and Maritime Services (RMS) into Transport for NSW (TfNSW). This report is focused on the Transport cluster prior to these changes. Please refer to the section on Machinery of Government changes for more details.

Machinery of Government refers to how the government organises the structures and functions of the public service. Machinery of Government changes are where the government reorganises these structures and functions, and are given effect by Administrative orders.

The Transport cluster was impacted by recent Machinery of Government changes. These changes were announced by the Department of Premier and Cabinet but were not included in the Administrative Orders as the Transport Administration Act 1988 No. 109 governs the composition of the Transport cluster. It was the intention of government to transfer the functions of the RMS into TfNSW. This requires legislative changes to the Transport Administration Act 1988 No. 109.

Section highlights

Under the Machinery of Government changes, the NSW Government will transfer the functions of RMS into TfNSW.

  • The Transport Administration Amendment (RMS Dissolution) Act 2019 (the Act) received assent on 22 November 2019.
  • The Act will dissolve RMS and transfer its functions, assets, rights and liabilities to TfNSW.
  • As at the date of this report, the Act is not yet in force.
  • There are risks and challenges for asset and liability transfers, governance and retention of knowledge.
  • As of 1 July 2019, administrative arrangements (delegations and reporting line changes) were put in place to enable TfNSW and RMS to operate within a single management structure, while still remaining as separate legal entities.
  • Transport is working on a number of options as to how to implement the changes. 

Financial reporting is an important element of good governance. Confidence and transparency in public sector decision making are enhanced when financial reporting is accurate and timely.

This chapter outlines our audit observations related to the financial reporting of agencies in the Transport cluster for 2019.

Section highlights

  • Unqualified audit opinions were issued on all agencies' financial statements.
  • RMS required an extension from NSW Treasury for their early close procedures.
  • TfNSW and Sydney Metro required extensions to submit their year-end financial statements.
  • Valuation of assets remains a challenge across the cluster.
  • There remains Opal cards with negative balances.
  • Sydney Metro derecognised assets of $322 million in relation to assets constructed for third parties.
  • Inconsistencies in the application of accounting policies across cluster agencies impact comparability of financial reporting across the Transport cluster.

Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies. They are essential for quality and timely decision making.

This chapter outlines our observations and insights from our financial statement audits of agencies in the Transport cluster.

Section highlights

  • There was an increase in findings on internal controls across the Transport cluster. Twenty-nine per cent of all issues were repeat issues.
  • Transport entities wrote-off over $278 million of assets which were replaced by new assets or technology.
  • Twenty-six per cent of Transport employees have excess annual leave.
  • There are no processes to ensure all significant contracts and agreements are captured by agencies in a centralised register.

Appendix one – Timeliness of financial reporting by agency 

Appendix two – Management letter findings by agency 

Appendix three – List of 2019 recommendations 

Appendix four – Status of 2017 and 2018 recommendations 

Appendix five – Cluster agencies 

 

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Published

Actions for Internal Controls and Governance 2019

Internal Controls and Governance 2019

Education
Community Services
Finance
Health
Industry
Justice
Planning
Premier and Cabinet
Transport
Treasury
Whole of Government
Compliance
Cyber security
Fraud
Information technology
Internal controls and governance
Management and administration
Procurement
Project management

This report covers the findings and recommendations from the 2018–19 financial audits that relate to internal controls and governance at 40 of the largest agencies in the NSW public sector. The 40 agencies selected for this report constitute around 84 per cent of total expenditure for all NSW public sector agencies.

The report provides insights into the effectiveness of controls and governance processes across the NSW public sector. It evaluates how agencies identify, mitigate and manage risks related to:

  • financial controls
  • information technology controls
  • gifts and benefits
  • internal audit
  • contingent labour
  • sensitive data.

The Auditor-General recommended that agencies do more to prioritise and address vulnerabilities in their internal controls and governance. The Auditor-General also recommended agencies increase the transparency of their management of gifts and benefits by publishing their registers on their websites.

This report analyses the internal controls and governance of 40 of the largest agencies in the NSW public sector for the year ended 30 June 2019.

1. Internal control trends

New, repeat and high risk findings

There was an increase in internal control deficiencies of 12 per cent compared to last year. The increase is predominately due to a 100 per cent increase in repeat financial and IT control deficiencies.

Some agencies attributed the delay in actioning repeat findings to the diversion of staff from their regular activities to implement and operationalise the recent Machinery of Government changes. As a result, actions to address audit recommendations have been deferred or re prioritised, as the changes are implemented.

Agencies need to ensure they are actively managing the risks associated with having these vulnerabilities in internal control systems unaddressed for extended periods of time.

Common findings

A number of findings were common to multiple agencies. These findings often related to areas that are fundamental to good internal control environments and effective organisational governance, such as:

  • out of date policies or an absence of policies to guide appropriate decisions
  • poor record keeping and document retention
  • incomplete or inaccurate centralised registers or gaps in these registers
  • policies, procedures or controls no longer suited to the current organisational structure or business activities.

2. Information technology controls

IT general controls

We examined information security controls over key financial systems that support the preparation of agency financial statements. We found:

  • user access administration deficiencies at 58 per cent of agencies related to granting, review and removal of user access
  • an absence of privileged user activity reviews at 35 per cent of agencies
  • password controls that did not align to password policies at 20 per cent of agencies.

We also found 20 per cent of agencies had deficient IT program change controls, mainly related to segregation of duties in approval and authorisation processes, and user acceptance testing of program changes prior to deployment into production environments. User acceptance testing helps identify potential issues with software incompatibility, operational workflows, absent controls and software issues, as well as areas where training or user support may be required.

3. Gifts and benefits

Gifts and benefits registers

All agencies had a gifts and benefits policy and 90 per cent of agencies maintain a gifts and benefits register. However, 51 per cent of the gifts and benefits registers we examined contained incomplete declarations, such as missing details for the approving officer, value of the gift and/or benefit offered and reasons supporting the decision.

In some cases, gaps in recorded information meant the basis for decisions around gifts and benefits was not always clear, making it difficult to determine whether decisions in those instances were appropriate, compliant with policy and were not direct or indirect inducements to the recipients to favour suppliers or service providers.

Agencies should ensure their gifts and benefits register includes all key fields specified in the Public Service Commission's minimum standards for gifts and benefits. Agencies should also perform regular reviews of the register to ensure completeness and ensure any gift or benefit accepted by a staff member meets the public's expectations for ethical behaviour.

Managing gifts and benefits

We found opportunities to improve gifts and benefits processes and enhance transparency. For example, only three per cent of agencies publish their gifts and benefits registers on their websites.

Agencies can improve management of gifts and benefits by:

  • ensuring agency policies comprehensively cover the elements necessary to make it effective in an operational environment, such as identifying risks specific to the agency and actions that will be taken in the event of a policy breach
  • establishing and publishing a statement of business ethics on the agency's website to clearly communicate expected behaviours to clients, customers, suppliers and contractors
  • providing on-going training, awareness activities and support to employees, not just at induction
  • publishing their gifts and benefits registers on their websites to demonstrate a commitment to a transparently ethical environment.
Reporting and monitoring

Only 35 per cent of agencies reported trends in the number and nature of gifts and benefits recorded in their registers to the agency's senior executive management and/or a governance committee.

Agencies should regularly report to the agency executive or other governance committee on trends in the offer and acceptance of gifts and benefits.

4. Internal audit

Obtaining value from the internal audit function

Agencies have established and maintained internal audit functions to provide assurance on the effectiveness of agency controls and governance systems. However, we identified areas where agencies' internal audit functions could improve their processes to add greater value. For example, only 73 per cent of CAEs regularly attend meetings of the agency board or executive management committee.

Internal audit functions can add greater value by involving the CAE more extensively in executive forums as an observer.

Internal audit functions should also consider producing an annual report on internal audit. An annual report allows the internal audit function to report on their performance and add value by drawing to the attention of audit and risk committees and senior management strategic issues, thematic trends and emerging risks.

Role of the Chief Audit Executive

Forty-five per cent of agencies assigned responsibilities to the Chief Audit Executive (CAE) that were broader than internal audit, but 17 per cent of these had not documented safeguards to protect the independence of the CAE.

The reporting lines and status of the CAE at some agencies also needs review. At two agencies, the CAE reported to the CFO.

Agencies should ensure:

  • the reporting lines for the CAE comply with the NSW Treasury policy, and the CAE does not report functionally or administratively to the finance function or other significant recipients of internal audit services
  • the CAE's duties are compatible with preserving their independence and where threats to independence exist, safeguards are documented and approved.
Quality assurance and improvement program

Thirty-five per cent of agencies did not have a documented quality assurance and improvement program for its internal audit function.

The policy and the International Standards for the Professional Practice of Internal Auditing require agencies to have a documented quality assurance and improvement program. The results of this program should be reported annually.

Agencies should ensure there is a documented and operational Quality Assurance and Improvement Program for the internal audit function that covers both internal and external assessments.

5. Managing contingent labour

Obtaining value for money from contingent labour

According to NSW Procurement data, spend on contingent labour has increased by 75 per cent over the last five years, to $1.5 billion in 2018–19. Improvements in internal processes and a renewed focus on agency monitoring and oversight of contingent labour can help ensure agencies get the best value for money from their contingent workforces.

Agencies can improve their management of contingent labour by:

  • preparing workforce plans to inform their resourcing strategy and ensure that engaging contingent labour aligns with the strategy and best meets business needs
  • involving agency human resources units in decisions about engaging contingent labour
  • regularly reporting on contingent labour use and tenure to agency executive teams
  • strengthening on-boarding and off-boarding processes.

We also found 57 per cent of the 23 agencies we examined with contingent labour spend of more than $5 million in 2018–19 have implemented the government's vendor management system and service provider 'Contractor Central'.

6. Managing sensitive data

Identifying and assessing sensitive data

Sixty-eight per cent of agencies maintain an inventory of their sensitive data and where it resides. However, these inventories are not always complete and risks may be overlooked.

Agencies can improve processes to manage sensitive data by:

  • identifying and maintaining an inventory of sensitive data through a comprehensive and structured process
  • assessing the criticality and sensitivity of the data so that protection of high risk data can be prioritised.
Managing data breaches

Eighty-eight per cent of agencies have established policies to respond to potential data breaches when they are identified and 70 per cent of agencies maintain a register to record key information in relation to identified data breach incidents.

Agencies should maintain a data breach register to effectively manage the actions undertaken to contain, evaluate and remediate each data breach.

 

This report covers the findings and recommendations from our 2018–19 financial audits that relate to internal controls and governance at 40 of the largest agencies (refer to Appendix three) in the NSW public sector. The 40 agencies selected for this volume constitute around 84 per cent of total expenditure for all NSW public sector agencies.

Although the report includes several agencies that have changed as a result of the Machinery of Government changes that were effective from 1 July 2019, its focus on sector wide issues and insights means that its findings remain relevant to NSW public sector agencies, including newly formed agencies that have assumed the functions of abolished agencies.

This report offers insights into internal controls and governance in the NSW public sector

This is the third report dedicated to internal controls and governance at NSW State Government agencies. The report provides insights into the effectiveness of controls and governance processes in the NSW public sector by:

  • highlighting the potential risks posed by weaknesses in controls and governance processes
  • helping agencies benchmark the adequacy of their processes against their peers
  • focusing on new and emerging risks, and the internal controls and governance processes that might address those risks.

Without strong governance systems and internal controls, agencies increase the risks associated with effectively managing their finances and delivering services to citizens. For example, if they do not have strong information technology controls, sensitive information may be at risk of unauthorised access and misuse.

Areas of specific focus of the report have changed since last year

Last year's report topics included transparency and performance reporting, management of purchasing cards and taxi use, and fraud and corruption control. We are reporting on new topics this year and re-visiting agency management of gifts and benefits, which we first covered in our 2017 report. Re-visiting topics from prior years provides a baseline to show the NSW public sectors’ progress implementing appropriate internal controls and governance processes to mitigate existing, new and emerging risks in the public sector.

Our audits do not review all aspects of internal controls and governance every year. We select a range of measures and report on those that present heightened risks for agencies to mitigate. This year the report focusses on:

  • internal control trends
  • information technology controls, including access to agency systems
  • protecting sensitive information held within agencies
  • managing large and diverse workforces (controls around employing and managing contingent workers)
  • maintaining an ethical culture (management of gifts and benefits)
  • effectiveness of internal audit function and its oversight by Audit and Risk Committees.

The findings in this report should not be used to draw conclusions on the effectiveness of individual agency control environments and governance arrangements. Specific financial reporting, internal controls and audit observations are included in the individual 2019 cluster financial audit reports, which will be tabled in parliament from November to December 2019.

Internal controls are processes, policies and procedures that help agencies to:

  • operate effectively and efficiently
  • produce reliable financial reports
  • comply with laws and regulations
  • support ethical government.

This chapter outlines the overall trends for agency controls and governance issues, including the number of audit findings, the degree of risk those deficiencies pose to the agency, and a summary of the most common deficiencies we found across agencies. The rest of this report presents this year’s controls and governance findings in more detail.

Key conclusions and sector wide learnings

We identified four high risk findings, compared to six last year. None of the findings are common with those in the previous year. There was an overall increase of 12 per cent in the number of internal control deficiencies compared to last year. The increase is predominately due to a 100 per cent increase in the number of repeat financial and IT control deficiencies.
 
Some agencies attributed the delay in actioning repeat findings to the diversion of staff from their regular activities to implement and operationalise the recent Machinery of Government changes. As a result, actions to address audit recommendations have been deferred or re-prioritised, as the changes are implemented. Agencies need to ensure they are actively managing the risks associated with having these vulnerabilities in internal control systems unaddressed for extended periods of time.
 
We also identified a number of findings that were common to multiple agencies. These common findings often related to areas that are fundamental to good internal control environments and effective organisational governance. Examples include:
  • out of date policies or an absence of policies to guide appropriate decisions
  • poor record keeping and document retention
  • incomplete or inaccurate centralised registers or gaps in these registers.

Policies, procedures and internal controls should be properly designed, be appropriate for the current organisational structure and its business activities, and work effectively.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency controls to manage key financial systems.

Key conclusions and sector wide learnings
Government agencies’ financial reporting is heavily reliant on information technology (IT). We continue to see a high number of deficiencies related to IT general controls, particularly those related to user access administration. These controls are key in adequately protecting IT systems from inappropriate access and misuse.
IT is also important to the delivery of agency services. These systems often provide the data to help monitor the efficiency and effectiveness of agency processes and services they deliver. Our financial audits do not review all agency IT systems. For example, IT systems used to support agency service delivery are generally outside the scope of our financial audit. However, agencies should also consider the relevance of our findings to these systems.
Agencies need to continue to focus on assessing the risks of inappropriate access and misuse and the implementation of controls to adequately protect their systems, focussing on the processes in place to grant, remove and monitor user access, particularly privileged user access.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency controls to manage gifts and benefits. 

Key conclusions and sector wide learnings

We found most agencies have implemented the Public Service Commission's minimum standards for gifts and benefits. All agencies had a gifts and benefits policy and 90 per cent of agencies maintained a gifts and benefits register and provided some form of training to employees on the treatment of gifts and benefits.

Based on our analysis of agency registers, we found some areas where opportunities existed to make processes more effective. In some cases, gaps in recorded information meant the basis for decisions around gifts and benefits was not always clear, making it difficult to determine whether decisions in those instances were appropriate and compliant with policy. Fifty-one per cent of the gifts and benefits registers reviewed contained declarations where not all fields of information had been completed. Seventy-seven per cent of agencies that maintained a gifts and benefits register did not include all key fields suggested by the minimum standards.

Areas where agencies can improve their management of gifts and benefits include:

  • ensuring agency policies comprehensively cover the elements necessary to make it effective in an operational environment, such as identifying risks specific to the agency and actions that will be taken in the event of a policy breach
  • establishing and publishing a statement of business ethics on the agency's website to clearly communicate expected behaviours to clients, customers,suppliers and contractors
  • updating gifts and benefits registers to include all key fields suggested by the minimum standards, as well as performing regular reviews of the register to ensure completeness
  • providing on-going training, awareness activities and support to employees, not just at induction
  • regularly reporting gifts and benefits to executive management and/or a governance committee such as the audit and risk committee, focussing on trends in the number and types of gifts and benefits offered to and accepted by agency staff
  • publishing their gifts and benefits registers on their websites to demonstrate a commitment to a transparently ethical environment.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency internal audit functions.

Key conclusions and sector wide learnings 

We found agencies have established and maintained internal audit functions to provide assurance on the effectiveness of agency controls and governance systems as required by TPP15-03 'Internal Audit and Risk Management Policy for the NSW Public Sector'. However, we identified areas where agencies' internal audit functions could improve their processes to add greater value, including: 

  • documenting and implementing safeguards to address conflicting roles performed by the Chief Audit Executive (CAE)
  • ensuring the reporting lines for the CAE comply with the NSW Treasury policy, and the CAE reports neither functionally or administratively to the finance function or other significant recipients of internal audit services
  • involving the CAE more extensively in executive forums as an observer
  • documenting a Quality Assurance and Improvement Program for the internal audit function and performing both internal and external performance assessments to identify opportunities for continuous improvement
  • reporting against key performance indicators or a balanced scorecard and producing an annual report on internal audit to bring to the attention of the audit and risk committee and senior management strategic issues, thematic trends and emerging risks that may require further attention or resources.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency controls to on-board, manage and off-board contingent labour.

Key conclusions and sector wide learnings

Agencies have implemented controls to manage contingent labour and most agencies have some level of reporting and oversight of contingent labour at an executive level. However, the increasing trend in spend on contingent labour warrants a renewed focus on agency monitoring and oversight of their use of contingent labour. Over the last five years spend on contingent labour has increased by 75 per cent, to $1.5 billion in 2018–19.

There are also some key gaps that limit the ability of agencies to effectively manage contingent labour. Key areas where agencies can improve their management of contingent labour include: 

  • preparing workforce plans to inform their resourcing strategy, and confirm prior to engaging contingent labour, that this solution aligns with the strategy and best meets business needs
  • involving agency human resources units in decisions about engaging contingent labour
  • regularly reporting on contingent labour use to agency executive teams, particularly in terms of trends in agency spend, tenure and compliance with policies and procedures
  • strengthening on-boarding and off-boarding processes, including establishing checklists to on-board and off-board contingent labour, making provisions for knowledge transfer, and assessing, documenting and capturing performance information.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of governance and processes in relation to the management of sensitive data.

Key conclusions and sector wide learnings

Information technology risks are rapidly increasing. More interfaces between agencies and greater connectivity means the amounts of data agencies generate, access, store and share continue to increase. Some of this information is sensitive information, which is protected by the Privacy Act 1988.

It is important that agencies understand what sensitive data they hold, the risks associated with the inadvertent release of this information and how they are mitigating those risks. We found that agencies need to continue to identify and record their sensitive data, as well as expand the methods they use to identify sensitive data. This includes data held in unstructured repositories, such as network shared drives and by agency service providers.

Eighty-eight per cent of agencies have established policies to respond to potential data breaches when they are identified and 70 per cent of agencies maintain a register to record key information in relation to identified data breach incidents.

Key areas where agencies can improve their management of sensitive data include:

  • identifying sensitive data, based on a comprehensive and structured process and maintaining an inventory of the data
  • assessing the criticality and sensitivity of the data so that the protection of high risk data can be prioritised
  • developing comprehensive data breach management policies to ensure data breaches are appropriately managed
  • maintaining a data breach incident register to record key information in relation to identified data breaches incidents, including the estimated cost of the breach
  • providing on-going training and awareness activities to employees in relation to sensitive data and managing data breaches.

Appendix one – List of 2019 recommendations 

Appendix two – Status of 2018 recommendations

Appendix three – In-scope agencies

 

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Published

Actions for Managing growth in the NSW prison population

Managing growth in the NSW prison population

Justice
Infrastructure
Management and administration
Project management
Service delivery
Workforce and capability

The Department of Justice has relied heavily on temporary responses to accommodate growing prisoner numbers according to a report released today by the Acting Auditor-General for New South Wales, Ian Goodwin.

At the time of this audit, the NSW Department of Justice (DOJ) was responsible for delivering custodial corrections services in New South Wales through its Corrective Services NSW division (Corrective Services NSW). From 1 July 2019, the Department of Family and Community Services and Justice will be responsible for these functions. 

Within DOJ, Corrective Services NSW is responsible for administering sentences and legal orders through custodial and community-based management of adult offenders. Its key priorities are:

  • providing safe, secure and humane management of prisoners
  • reducing reoffending
  • improving community safety and confidence in the justice system. 

The prison population in New South Wales grew by around 40 per cent between 2012 to 2018, from 9,602 to 13,630 inmates. This rate of growth was higher than experienced prior to 2012. DOJ forecasts growth to continue over the short and longer-term. 

DOJ has responded to inmate population growth by doubling-up and tripling-up the number of prison beds in cells, reactivating previously closed prisons, and a $3.8 billion program of new prison capacity. DOJ has also developed a long-term prison infrastructure strategy that projects long-term needs and recommended investments to meet these needs. 

This audit assessed how efficiently and effectively DOJ is responding to growth in the NSW prison population. In this report, we have not analysed the sources of demand or recommended ways that custody may be avoided. These are largely government policy issues. 

Conclusion
The DOJ has relied heavily on temporary responses to accommodate growth in the NSW prison population. Sustained reliance on these responses is inefficient and creates risks to safety, and timely access to prisoner support services.
DOJ has experienced significant growth in the prison population since 2012. To meet demand, it has relied on temporary responses that are not designed to be sustained, including doubling-up or tripling-up the number of beds in cells, reopening previously closed facilities and using obsolete facilities. DOJ has also regularly moved inmates between its facilities to accommodate the increasing need for beds in metropolitan Sydney. 
Relying on temporary approaches over a long period contributes to prison crowding and has affected DOJ's ability to manage inmates in line with its correctional principles. It has increased risks to staff and prisoner safety, and timely inmate access to prisoner support services and programs. In addition, the cost per prisoner per day increased over the past two years.
DOJ is progressively delivering new capacity to address the growing prison population.
In response to continuing and projected growth in the prison population, the NSW Government announced a one-off $3.8 billion program to deliver around 6,100 beds by May 2021. Under the program, DOJ developed and delivered two rapid build dormitory style prisons within 18 months. DOJ’s capability to deliver the program, including implementation of new beds and new prisons, governance, project management, risk assessment and commissioning has improved over time. Most new capacity will be delivered on existing DOJ sites, mainly in regional New South Wales. 
DOJ has developed a strategy to respond to long-term projected growth in the prison population, but it has yet to be funded. 
The Corrective Services NSW Infrastructure Strategy (CSIS) sets out challenges, strategic priorities, and planned actions to respond to projected growth over the next 20 years and improve overall system efficiency and effectiveness. But, proposed actions are subject to individual business cases and funding decisions. Three versions of the CSIS have been provided to, and endorsed by, the NSW Government. The key challenge identified in the CSIS is to overcome demand for prison beds in the Sydney metropolitan region. DOJ advised that it is developing a final business case to address metropolitan capacity needs, but this is subject to government approval and funding. DOJ should continue to highlight the urgency of this issue until it is addressed, as it prevents planned actions to improve system efficiency and effectiveness.
 

The Productivity Commission’s Report on Government Services outlines the performance indicator framework for corrective services in Australia (Appendix three). We have used measures from this framework to assess the efficiency and effectiveness of DOJ’s responses to prison bed capacity needs. 

In this section, we analyse system-wide indicators as DOJ has not consistently published or reported data for individual correctional centres over the period of review.
 

Published

Actions for Transport Access Program

Transport Access Program

Transport
Infrastructure
Project management
Service delivery

The following report is available in an Easy English version that is intended to meet the needs of some people with lower literacy skills, some people with an intellectual disability and some people from different cultural backgrounds.

View the Easy English version of the Transport Access Program report

Transport for NSW’s process for selecting and prioritising projects for the third stage of its Transport Access Program balanced compliance with national disability standards with broader customer outcomes. Demographics, deliverability and value for money were also considered. However, Transport for NSW does not know the complete scope of work required for full compliance, limiting its ability to demonstrate that its approach is effective, according to a report released today by the Auditor-General for New South Wales, Margaret Crawford.

Access to transport is critical to ensuring that people can engage in all aspects of community life, including education, employment and recreation. People with disability can encounter barriers when accessing public transport services. In 2015, there were 1.37 million people living with disability in New South Wales.

Accessible public transport is about more than physical accessibility. It also means barrier-free access for people who have vision, hearing or cognitive impairments. All users, not just people with disability, benefit from improvements to the accessibility and inclusiveness of transport services. 

Transport for NSW has an obligation under Australian Government legislation to provide accessible services to people with disabilities in a manner which is not discriminatory. Under the Disability Standards for Accessible Public Transport 2002 (the DSAPT - an instrument of the Disability Discrimination Act 1992 (the Act) (Commonwealth)), there is a requirement to modify and develop new infrastructure, means of transport and services to provide access for people with disabilities. All public transport operators are required to ensure that at least 90 per cent of their networks met DSAPT by December 2017 and the networks will need to be 100 per cent compliant with all parts of the standards by 31 December 2022. Trains are not required to be fully compliant with DSAPT until December 2032. 

The Transport Access Program (TAP) is Transport for NSW's largest program with a specific focus on improving access to public transport for people with disability. The TAP is a series of projects to upgrade existing public transport infrastructure across four networks: Sydney Trains, Intercity Trains, Regional Trains and Sydney Ferries. Transport for NSW established the TAP as a rolling program and, to date, it has delivered the first tranche of TAP (TAP 1) and is completing the final projects for the second tranche (TAP 2). NSW budget papers estimate that by 30 June 2018, Transport for NSW had spent $1.2 billion in the TAP since its commencement in 2011-12.

After the completion of TAP 1 and TAP 2 (as well as through other transport infrastructure programs), Transport for NSW estimates that 58.5 per cent of the Sydney Trains, Regional Trains and Intercity Trains networks, and 66 per cent of the Sydney Ferries network, will be accessible. To close the significant gap in compliance with the DSAPT target, the objective for TAP 3 is ‘to contribute to Disability Discrimination Act 1992 related targets through DSAPT compliance upgrades’. 

The audit assessed whether Transport for NSW has an effective process to select and prioritise projects as part of the TAP, with a specific focus on the third tranche of TAP funding.

In August 2018, at the commencement of this audit, Transport for NSW intended to complete the selection of projects for the TAP 3 final business case in December 2018. Transport for NSW advise that it now intends to complete the development stage and final business case in the first quarter of 2019, prior to the final investment decision of the TAP program. This report is based on the TAP 3 strategic business case and information provided by Transport for NSW up to December 2018.

Conclusion
Transport for NSW’s process for selecting and prioritising projects for TAP 3 balanced DSAPT compliance goals with broader customer outcomes. It also considered demographics, deliverability and value for money. However, Transport for NSW does not know the complete scope of work required for full DSAPT compliance, and this limits its ability to demonstrate that its approach is effective. 
Transport for NSW has applied most of the external review recommendations from previous funding rounds to the implementation of the third round of TAP funding (TAP3), with positive results. Changes made include a clear objective for TAP 3 to focus on improving compliance, improved governance arrangements, and better consideration of deliverability and design during project planning. 
Through TAP 3, Transport for NSW is also trying to better address disability access in a way that balances DSAPT compliance with other considerations - such as population demographics, access to services and value for money. Transport for NSW developed an objective prioritisation and selection methodology to assess projects for TAP 3 funding. 
Transport for NSW cannot quantify the work needed to meet DSAPT compliance targets across the rail and ferry networks as it has not completed a comprehensive audit of compliance. This information is needed to ensure the effective targeting of funding, and to measure the contribution of TAP 3 work to meeting the DSAPT compliance targets. Instead, Transport for NSW has undertaken a phased approach to completing a comprehensive audit of compliance across the networks, with a focus on first assessing compliance at locations that are not wheelchair accessible. This creates two problems. First, Transport for NSW does not know the complete scope of work required to achieve DSAPT compliance. Second, not all wheelchair accessible locations fully meet DSAPT standards.
Transport for NSW's proposed communication plan for the schedule of TAP 3 funded works does not align with its Disability Inclusion Action Plan 2018-2022. The Disability Inclusion Action Plan commits Transport for NSW to providing a full list of stations and wharves to be upgraded with their estimated time of construction when the next round of funding, TAP 3, is announced. Given the long timeframes associated with improving transport infrastructure, this information is important as it allows people to make informed decisions about where they live, work or study. Instead, Transport for NSW plans to communicate information to customers on a project by project basis.

In 2015, there were 1.37 million people living with disability in New South Wales. Access to transport is critical to ensuring that people can engage in all aspects of community life, including education, employment and recreation. People with disability can encounter barriers when accessing public transport services. 

The social model of disability, outlined in the United Nations Convention on the Rights of Persons with Disabilities, views people with disability as not disabled by their impairment but by the barriers in the community and environment that restrict their full and effective participation in society on an equal basis with others. 

Accessible public transport is more than the provision of physical access to premises and conveyances, it provides barrier-free access for people who have vision, hearing or cognitive impairments. All users, not just people with disability, benefit from improvements to the accessibility and inclusiveness of transport services.

According to the Australian Bureau of Statistics, the main types of difficulties experienced by people with disability when using public transport relate to steps (39.9 per cent), difficulty getting to stops and stations (25 per cent), fear and anxiety (23.3 per cent) and lack of seating or difficulty standing (20.7 per cent).

Transport for NSW has a Disability Inclusion Action Plan (the Action Plan) 2018-2022 that sets an overall framework for planning, delivering and reporting on initiatives to increase accessibility of the transport network. It covers all elements of the journey experienced when using public transport, including journey planning, staff training, customer services and interaction between the physical environment and modes of transport. Appendix five outlines the guiding principles of the Action Plan.

Transport for NSW's Transport Social Policy branch developed the Action Plan in consultation with internal and external stakeholders. The director of the Transport Social Policy branch is a member of the TAP executive steering committee, which supports alignment between the Action Plan and TAP.

Transport for NSW's Disability Inclusion Action Plan describes a customer focussed approach to accessibility

One of the guiding principles of the Action Plan is ‘intelligent compliance’. Transport for NSW describes this as compliance that prioritises customer-focused outcomes over a narrow focus on legal compliance with accessibility standards. As well as being compliant, infrastructure should be practical, usable, fit for purpose and convenient. 

The TAP prioritisation and selection methodology reflects Transport for NSW’s focus on intelligent compliance. We consider this a reasonable approach as had Transport for NSW focussed exclusively on achieving compliance with the DSAPT targets by upgrading the most affordable infrastructure, some locations, that are used by more customers, would remain inaccessible to people with disability. However, this approach should not be seen as an alternative to Transport for NSW meeting its DSAPT compliance obligations.

TAP program staff consult with the Accessible Transport Advisory Committee

The Accessible Transport Advisory Committee (ATAC) has representatives from disability and ageing organisations, who provide expert guidance to Transport for NSW on access and inclusion. The ATAC provide guidance and feedback on projects and project solutions, including user testing where appropriate. TAP program staff provide regular updates at ATAC meetings, which include briefings on progress. The ATAC also provides feedback and suggestions to TAP program staff, which is considered and sometimes included in current and future projects.For example, in March 2017 the TAP program team briefed the ATAC on the challenges with respect to a number of ferry wharves and sought support for DSAPT exemptions proposed in the TAP 3 strategic business case.

Case study: Feedback on Braille lettering for lift buttons
In June 2018, the Program team sought feedback on a variety of lift button options to improve accessibility on future TAP projects. In September 2018, during the ATAC meeting attended by the Audit Office, the program team sought feedback on the standard designs for TAP 3. Some ATAC members noted that the standard design included Braille lettering on the lift buttons, and that this was not good practice because people can accidently press the button while reading it. As a result, Transport for NSW are incorporating this feedback into design requirements for the lifts for TAP 3, which will consider larger buttons, clearer Braille and Braille signage adjacent to the button.

Transport for NSW has not briefed the Advisory Committee on the outcome of the prioritisation and selection process

TAP program staff briefed the Advisory Committee about the prioritisation and selection methodology, after the Minister approved it in 2016. However, Transport for NSW have not briefed or consulted the Advisory Committee on the outcome of the prioritisation process. Infrastructure NSW noted this issue during its review of the strategic business case. 

Transport for NSW advised us that it established the ATAC as an advisory group, and that Transport for NSW does not disclose sensitive information to it. Transport for NSW intends to share the outcome of the prioritisation process following the completion of the TAP 3 development stage and final investment decision.

The TAP communication plan does not fully meet the requirements of the Disability Inclusion Action Plan

The Disability Inclusion Action Plan includes an action item to ‘provide a listing of stations and wharves to be upgraded with estimated time of construction as each new tranche of the Transport Access Program is announced’ The TAP Communication Plan that we reviewed does not include this provision instead focussing on communication on a per project basis. Given the long timeframes associated with improving transport infrastructure, this information is important as it allows people to make informed decisions about where they live, work or study.

Published

Actions for Internal Controls and Governance 2017

Internal Controls and Governance 2017

Finance
Education
Community Services
Health
Justice
Whole of Government
Asset valuation
Compliance
Cyber security
Information technology
Internal controls and governance
Project management
Risk

Agencies need to do more to address risks posed by information technology (IT).

Effective internal controls and governance systems help agencies to operate efficiently and effectively and comply with relevant laws, standards and policies. We assessed how well agencies are implementing these systems, and highlighted opportunities for improvement.
 

1. Overall trends

New and repeat findings

The number of reported financial and IT control deficiencies has fallen, but many previously reported findings remain unresolved.

High risk findings

Poor systems implementations contributed to the seven high risk internal control deficiencies that could affect agencies.

Common findings

Poor IT controls are the most commonly reported deficiency across agencies, followed by governance issues relating to cyber security, capital projects, continuous disclosure, shared services, ethics and risk management maturity.

2. Information Technology

IT security

Only two-thirds of agencies are complying with their own policies on IT security. Agencies need to tighten user access and password controls.

Cyber security

Agencies do not have a common view on what constitutes a cyber attack, which limits understanding the extent of the cyber security threat.

Other IT systems

Agencies can improve their disaster recovery plans and the change control processes they use when updating IT systems.

3. Asset Management

Capital investment

Agencies report delays delivering against the significant increase in their budgets for capital projects.

Capital projects

Agencies are underspending their capital budgets and some can improve capital project governance.

Asset disposals

Eleven per cent of agencies were required to sell their real property through Property NSW but didn’t. And eight per cent of agencies can improve their asset disposal processes.

4. Governance

Governance arrangements

Sixty-four per cent of agencies’ disclosure policies support communication of key performance information and prompt public reporting of significant issues.

Shared services

Fifty-nine per cent of agencies use shared services, yet 14 per cent do not have service level agreements in place and 20 per cent can strengthen the performance standards they set.

5. Ethics and Conduct

Ethical framework

Agencies can reinforce their ethical frameworks by updating code‑of‑conduct policies and publishing a Statement of Business Ethics.

Conflicts of interest

All agencies we reviewed have a code of conduct, but they can still improve the way they update and manage their codes to reduce the risk of fraud and unethical behaviour.

6. Risk Management 

Risk management maturity

All agencies have implemented risk management frameworks, but with varying levels of maturity.

Risk management elements

Many agencies can improve risk registers and strengthen their risk culture, particularly in the way that they report risks to their lead agency.

This report covers the findings and recommendations from our 2016–17 financial audits related to the internal controls and governance of the 39 largest agencies (refer to Appendix three) in the NSW public sector. These agencies represent about 95 per cent of total expenditure for all NSW agencies and were considered to be a large enough group to identify common issues and insights.

The findings in this report should not be used to draw conclusions on the effectiveness of individual agency control environments and governance arrangements. Specific financial reporting, controls and service delivery comments are included in the individual 2017 cluster financial audit reports tabled in Parliament from October to December 2017.

This new report offers strategic insight on the public sector as a whole

In previous years, we have commented on internal control and governance issues in the volumes we published on each ‘cluster’ or agency sector, generally between October and December. To add further value, we then commented more broadly about the issues identified for the public sector as a whole at the start of the following year.

This year, we have created this report dedicated to internal controls and governance. This will help Parliament to understand broad issues affecting the public sector, and help agencies to compare their own performance against that of their peers.

Without strong control measures and governance systems, agencies face increased risks in their financial management and service delivery. If they do not, for example, properly authorise payments or manage conflicts of interest, they are at greater risk of fraud. If they do not have strong information technology (IT) systems, sensitive and trusted information may be at risk of unauthorised access and misuse.

These problems can in turn reduce the efficiency of agency operations, increase their costs and reduce the quality of the services they deliver.

Our audits do not review every control or governance measure every year. We select a range of measures, and report on those that present the most significant risks that agencies should mitigate. This report divides these into the following six areas:

  1. Overall trends
  2. Information technology
  3. Asset management
  4. Governance
  5. Ethics and conduct
  6. Risk management.

Internal controls are processes, policies and procedures that help agencies to:

  • operate effectively and efficiently
  • produce reliable financial reports
  • comply with laws and regulations.

This chapter outlines the overall trends for agency controls and governance issues, including the number of findings, level of risk and the most common deficiencies we found across agencies. The rest of this volume then illustrates this year’s controls and governance findings in more detail.

Issues

Recommendations

1.1 New and repeat findings

The number of internal control deficiencies reduced over the past three years, but new higher-risk information technology (IT) control deficiencies were reported in 2016–17.

Deficiencies repeated from previous years still make up a sizeable proportion of all internal control deficiencies.

Recommendation

Agencies should focus on emerging IT risks, but also manage new IT risks, reduce existing IT control deficiencies, and address repeat internal control deficiencies on a more timely basis.

1.2 High risk findings

We found seven high risk internal control deficiencies, which might significantly affect agencies.

Recommendation

Agencies should rectify high risk internal control deficiencies as a priority

1.3 Common findings

The most common internal control deficiencies related to poor or absent IT controls.

We found some common governance deficiencies across multiple agencies.

Recommendation

Agencies should coordinate actions and resources to help rectify common IT control and governance deficiencies.

Information technology (IT) has become increasingly important for government agencies’ financial reporting and to deliver their services efficiently and effectively. Our audits reviewed whether agencies have effective controls in place over their IT systems. We found that IT security remains the source of many control weakness in agencies.

Issues Recommendations

2.1 IT security

User access administration

While 95 per cent of agencies have policies about user access, about two-thirds were compliant with these policies. Agencies can improve how they grant, change and end user access to their systems.

Recommendation

Agencies should strengthen user access administration to prevent inappropriate access to sensitive systems. Agencies should:

  • establish and enforce clear policies and procedures
  • review user access regularly
  • remove user access for terminated staff promptly
  • change user access for transferred staff promptly.

Privileged access

Sixty-eight per cent of agencies do not adequately manage who can access their information systems, and many do not sufficiently monitor or restrict privileged access.

Recommendation

Agencies should tighten privileged user access to protect their information systems and reduce the risks of data misuse and fraud. Agencies should ensure they:

  • only grant privileged access in line with the responsibilities of a position
  • review the level of access regularly
  • limit privileged access to necessary functions and data
  • monitor privileged user account activity on a regular basis.

Password controls

Forty-one per cent of agencies did not meet either their own standards or minimum standards for password controls.

Recommendation

Agencies should review and enforce password controls to strengthen security over sensitive systems. As a minimum, password parameters should include:

  • minimum password lengths and complexity requirements
  • limits on the number of failed log-in attempts
  • password history (such as the number of passwords remembered)
  • maximum and minimum password ages.

2.2 Cyber Security

Cyber security framework

Agencies do not have a common view on what constitutes a cyber attack, which limits understanding the extent of the cyber security threat.

Recommendation

The Department of Finance, Services and Innovation should revisit its existing framework to develop a shared cyber security terminology and strengthen the current reporting requirements for cyber incidents.

Cyber security strategies

While 82 per cent of agencies have dedicated resources to address cyber security, they can strengthen their strategies, expertise and staff awareness.

Recommendations

The Department of Finance, Services and Innovation should:

  • mandate minimum standards and require agencies to regularly assess and report on how well they mitigate cyber security risks against these standards
  • develop a framework that provides for cyber security training.

Agencies should ensure they adequately resource staff dedicated to cyber security.

2.3 Other IT systems

Change control processes

Some agencies need to improve change control processes to avoid unauthorised or inaccurate system changes.

Recommendation

Agencies should consistently perform user acceptance testing before system upgrades and changes. They should also properly approve and document changes to IT systems.

Disaster recovery planning

Agencies can do more to adequately assess critical business systems to enforce effective disaster recovery plans. This includes reviewing and testing their plans on a timely basis.

Recommendation

Agencies should complete business impact analyses to strengthen disaster recovery plans, then regularly test and update their plans.

Agency service delivery relies on developing and renewing infrastructure assets such as schools, hospitals, roads, or public housing. Agencies are currently investing significantly in new assets. Agencies need to manage the scale and volume of current capital projects in order to deliver new infrastructure on time, on budget and realise the intended benefits. We found agencies can improve how they:

  • manage their major capital projects
  • dispose of existing assets.
Issues Recommendations or conclusions

3.1 Capital investment

Capital asset investment ratios

Most agencies report high capital investment ratios, but one-third of agencies’ capital investment ratios are less than one.

Recommendation

Agencies with high capital asset investment ratios should ensure their project management and delivery functions have the capacity to deliver their current and forward work programs.

Volume of capital spending

Most agencies have significant forward spending commitments for capital projects. However, agencies’ actual capital expenditure has been below budget for the last three years.

Conclusion

The significant increase in capital budget underspends warrant investigation, particularly where this has resulted from slower than expected delivery of projects from previous years.

3.2 Capital projects

Major capital projects

Agencies’ major capital projects were underspent by 13 percent against their budgets.

Conclusion

The causes of agency budget underspends warrant investigation to ensure the NSW Government’s infrastructure commitment is delivered on time.

Capital project governance

Agencies do not consistently prepare business cases or use project steering committees to oversee major capital projects.

Conclusion

Agencies that have project management processes that include robust business cases and regular updates to their steering committees (or equivalent) are better able to provide those projects with strategic direction and oversight.

3.3. Asset disposals

Asset disposal procedures

Agencies need to strengthen their asset disposal procedures.

Recommendations

Agencies should have formal processes for disposing of surplus properties.

Agencies should use Property NSW to manage real property sales unless, as in the case for State owned corporations, they have been granted an exemption.

Governance refers to the high-level frameworks, processes and behaviours that help an organisation to achieve its objectives, comply with legal and other requirements, and meet a high standard of probity, accountability and transparency.

This chapter sets out the governance lighthouse model the Audit Office developed to help agencies reach best practice. It then focuses on two key areas: continuous disclosure and shared services arrangements. The following two chapters look at findings related to ethics and risk management.

Issues Recommendations or conclusions

4.1 Governance arrangements

Continuous disclosure

Continuous disclosure promotes improved performance and public trust and aides better decision-making. Continuous disclosure is only mandatory for NSW Government Businesses such as State owned corporations.

Conclusion

Some agencies promote transparency and accountability by publishing on their websites a continuous disclosure policy that provides for, and encourages:

  • regular public disclosure of key performance information
  • disclosure of both positive and negative information
  • prompt reporting of significant issues.

4.2 Shared services

Service level agreements

Some agencies do not have service level agreements for their shared service arrangements.

Many of the agreements that do exist do not adequately specify controls, performance or reporting requirements. This reduces the effectiveness of shared services arrangements.

Conclusion

Agencies are better able to manage the quality and timeliness of shared service arrangements where they have a service level agreement in place. Ideally, the terms of service should be agreed before services are transferred to the service provider and:

  • specify the controls a provider must maintain
  • specify key performance targets
  • include penalties for non-compliance.

Shared service performance

Some agencies do not set performance standards for their shared service providers or regularly review performance results.

Conclusion

Agencies can achieve better results from shared service arrangements when they regularly monitor the performance of shared service providers using key measures for the benefits realised, costs saved and quality of services received.

Before agencies extend or renegotiate a contract, they should comprehensively assess the services received and test the market to maximise value for money.

All government sector employees must demonstrate the highest levels of ethical conduct, in line with standards set by The Code of Ethics and Conduct for NSW government sector employees.

This chapter looks at how well agencies are managing these requirements, and where they can improve their policies and processes.

We found that agencies mostly have the appropriate codes, frameworks and policies in place. But we have highlighted opportunities to improve the way they manage those systems to reduce the risks of unethical conduct.

Issues Recommendations or conclusions

5.1 Ethical framework

Code of conduct

All agencies we reviewed have a code of conduct, but they can still improve the way they update and manage their codes to reduce the risk of fraud and unethical behaviour.

Recommendation

Agencies should regularly review their code-of-conduct policies and ensure they keep their codes of conduct up-to-date.

Statement of business ethics

Most agencies maintain an ethical framework, but some can enhance their related processes, particularly when dealing with external clients, customers, suppliers and contractors.

Conclusion

Agencies can enhance their ethical frameworks by publishing a Statement of Business Ethics, which communicates their values and culture.

5.2 Potential conflicts of interest

Conflicts of interest

All agencies have a conflicts-of-interest policy, but most can improve how they identify, manage and avoid conflicts of interest.

Recommendation

Agencies should improve the way they manage conflicts of interest, particularly by:

  • requiring senior executives to make a conflict-of-interest declaration at least annually
  • implementing processes to identify and address outstanding declarations
  • providing annual training to staff
  • maintaining current registers of conflicts of interest.

Gifts and benefits

While all agencies already have a formal gifts-and-benefits policy, we found gaps in the management of gifts and benefits by some that increase the risk of unethical conduct.

Recommendation

Agencies should improve the way they manage gifts and benefits by promptly updating registers and providing annual training to staff.

Risk management is an integral part of effective corporate governance. It helps agencies to identify, assess and prioritise the risks they face and in turn minimise, monitor and control the impact of unforeseen events. It also means agencies can respond to opportunities that may emerge and improve their services and activities.

This year we looked at the overall maturity of the risk management frameworks that agencies use, along with two important risk management elements: risk culture and risk registers.

Issues Recommendations or conclusions

6.1 Risk management maturity

All agencies have implemented risk management frameworks, but with varying levels of maturity in their application.

Agencies’ averaged a score of 3.1 out of five across five critical assessment criteria for risk management. While strategy and governance fared best, the areas that most need to improve are risk culture, and systems and intelligence.

Conclusion

Agencies have introduced risk management frameworks and practices as required by the Treasury’s:

  • 'Risk Management Toolkit for the NSW Public Sector'
  • 'Internal Audit and Risk Management Policy for the NSW Public Sector'.

However, more can be done to progress risk management maturity and embed risk management in agency culture.

6.2 Risk management elements

Risk culture

Most agencies have started to embed risk management into the culture of their organisation. But only some have successfully done so, and most agencies can improve their risk culture.

 

 

Conclusion

Agencies can improve their risk culture by:

  • setting an appropriate tone from the top
  • training all staff in effective risk management
  • ensuring desired risk behaviours and culture are supported, monitored, and reinforced through business plans, or the equivalent and employees' performance assessments.

Risk registers and reporting

Some agencies do not report their significant risks to their lead agency, which may impair the way resources are allocated in their cluster. Some agencies do not integrate risk registers at a divisional and whole-of-enterprise level.

Conclusion

Agencies not reporting significant risks at the cluster level increases the likelihood that significant risks are not being mitigated appropriately.

Effective risk management can improve agency decision-making, protect reputations and lead to significant efficiencies and cost savings. By embedding risk management directly into their operations, agencies can also derive extra value for their activities and services.

Published

Actions for Sydney Road Maintenance Contracts

Sydney Road Maintenance Contracts

Transport
Infrastructure
Internal controls and governance
Management and administration
Procurement
Project management

In November 2013, Roads and Maritime Services (RMS) outsourced the maintenance of State roads in the Sydney region south and west zones using an innovative contracting approach called the Stewardship Maintenance Contract (SMC). The SMC links risk to reward, and uses a performance framework where outcomes should drive improved performance over time.

RMS’ SMC contract management includes most elements of good practice, including governance and dispute resolution mechanisms. However, key elements are missing which reduces its effectiveness.

Roads and Maritime Services (RMS) is responsible for the Sydney region State roads network This includes over 2,800 kilometres of roads and associated road corridor infrastructure such as bridges, tunnels and drainage structures. RMS divides the network into three geographical areas: south, west and north zones.

In 1995, RMS first outsourced road corridor infrastructure maintenance for the north zone through a Performance Specified Maintenance Contract (PSMC). The current 10-year PSMC for the north zone will expire in October 2018. Prior to November 2013, RMS maintained roads in the south and west zones through its Road and Fleet Services unit. 

In November 2013, RMS outsourced road maintenance services for the south and west zones using Stewardship Maintenance Contracts (SMC). The contracts run for seven years with an option for a further three years at RMS’ discretion. RMS estimated that the annual cost of these contracts was around $240 million in total. In March 2018, the contract prices are due to be reset by negotiation to reflect the contractors’ experience with, and better information about, the road networks and routine maintenance requirements. 

The SMC model adopted stewardship principles to improve value for money. RMS defined stewardship principles as a broad set of values, attitudes and behaviours, required of the contractor to effectively manage the assets on behalf of RMS. The SMC also includes commercial principles, such as linking risk to reward, and a performance framework where outcomes drive performance.

This audit assessed whether RMS had effectively managed the outsourcing of road maintenance in the Sydney region south and west zones. In making this assessment, we answered the following questions:

  1. Did RMS justify the decision to adopt the SMC model?
  2. Do SMCs include key performance indicators (KPIs) and incentives which promote efficiency and effectiveness? 
  3. Does RMS collect high quality information on contractor performance and take action to correct performance deficiencies?
  4. Are the expected benefits being achieved?

Conclusion

RMS developed an innovative contracting approach with the SMC. RMS has realised some benefits in the first year, including savings, from outsourcing road maintenance in the Sydney region south and west zones using the SMC. However, RMS’ management of the SMC has key elements missing which reduces its effectiveness.

The SMC includes performance measures and incentives to drive efficiency and effectiveness improvements over time.  

RMS has established a contract management framework which includes most elements of good practice, including governance and dispute resolution mechanisms. However, it does not have procedures to guide its contract managers in managing specific provisions of the SMC. Consequently, RMS has not exercised several significant SMC requirements, such as having the contractor account for an efficiency dividend in its pricing at the start of each three-year works period. It also has not done enough to assure itself that the contractor provided performance and financial data are correct. This is important because the data is used to measure performance and calculate contractor payments.  

RMS assessed that it had achieved around 80 per cent of the expected cost benefit in the initial year of the SMC. However, it has not tracked its achievement of benefits since then.

The Stewardship Maintenance Contract

RMS justified adopting the SMC model and included KPIs to drive efficiency and effectiveness

The SMC model includes features that RMS had not previously used for road maintenance contracts. These included adopting stewardship principles and transferring price risk to the contractor over time as the contractor becomes familiar with the assets being maintained.

The SMC model meets RMS’ requirements for flexibility in pricing models, the need for collaboration in asset maintenance planning, promoting innovation and effective performance management.

RMS used many good practices to develop the SMC model, including:

  • preparing a robust business case comparing the SMC model to RMS maintaining the road network itself, as well as assessing whether two other contracting models
    (traditional and alliance) would meet its requirements
  • assessing experiences with similar arrangements in other jurisdictions and identifying elements that worked to get the best outcomes
  • developing a robust performance framework, which included a mix of efficiency and effectiveness KPIs that reflected NSW Government policy and RMS priorities
  • incorporating risk and reward incentives delivered through cost sharing arrangements which change as the contract matures
  • using a contract duration that supports RMS priorities and provides an incentive for better quality outcomes.

RMS uses data provided by the contractor to measure performance and calculate payments to the contractor. The SMC includes a specific sanction if RMS finds that the contractor provided incorrect performance data, but no specific sanction if the contractor provides incorrect financial data. If RMS finds that the contactor provided incorrect performance or financial data, RMS can only recover over-payments which may have been made using the incorrect data.  

To provide a stronger incentive for the contractor to ensure data it provides is accurate, RMS should consider whether to incorporate stronger sanctions when negotiating the commercial reset due in mid-2018 for south and west zones. RMS should also consider this for the new contract for the north zone when the current PSMC contract expires in October 2018.

RMS' contract management approach and benefits realization

RMS can improve the effectiveness of its oversight and management of the SMC

RMS does not have SMC specific contract procedures to guide its contract managers. Consequently, RMS has not exercised several significant SMC requirements, such as having the contractors account for an efficiency dividend in their pricing at the start of each three-year works period. Effective contract management should be supported by contract specific procedures, with explanations of, and allocation of responsibility for, the various interventions that RMS may be required to exercise in the SMC.

Performance and financial reporting under the SMC is based on a mix of RMS and contractor provided data. While there are a range of audits of contractor provided performance and financial data that RMS can conduct each year under the SMC, it does not have a schedule of audits it will conduct and when.  
During the first year of the SMC, RMS commissioned some limited audits of financial data. In the first three years of the SMC, RMS did not conduct any audits of performance data. Had there been SMC specific procedures in place, this would have reduced the risk of RMS not implementing a systematic audit program to give it reasonable assurance on the quality of the data that the contractor has provided. This is important because the data is used to measure performance and calculate contractor payments.

RMS has been aware of data quality issues since 2015. While RMS advised that it commenced addressing some data quality issues in response to a series of reviews conducted in 2015, a recent internal audit report indicates that RMS has not resolved the data quality issues.  

RMS achieved benefits in the first year, but has not tracked benefits since

As part of the business case, RMS agreed to implement a benefits realisation strategy, including a benefits tracking tool. RMS commenced tracking benefits, but did not establish a comparative baseline pre-SMC on non-financial benefits, and has not tracked benefits past year one.

In 2015, a benchmarking study commissioned by RMS found that it had achieved 80 per cent of the expected recurrent cost savings and other benefits, such as improved workplace safety, in the first full year of the SMC. However, there was no clear baseline to measure
non-financial performance. The study was qualified due to gaps in available data. The study also did not reconcile the actual one-off transition costs to the business case estimate.

During the course of the audit, RMS advised that it intends to repeat this type of study to determine whether it has achieved all expected benefits (and their value), and that it would use the results to inform its negotiation with the SMC contractors as part of the commercial reset due in mid-2018.

Roads and Maritime Services is responsible for the State Roads network in the Sydney region

Roads and Maritime Services (RMS) is responsible for the Sydney region State roads network. This includes over 2,800 kilometres of roads and associated road corridor infrastructure such as bridges, tunnels and drainage structures. The network is divided into three geographical areas: south, west and north zones. Prior to November 2013, RMS maintained roads in the Sydney region south and west zones through its Road and Fleet Services unit.  

In 1995, RMS first outsourced road corridor infrastructure maintenance for the north zone through a Performance Specified Maintenance Contract (PSMC). The current 10-year PSMC for the north zone will expire in October 2018. This contract is worth around $35 million per annum.  

NSW Government priorities and road maintenance

Efficient and effective road maintenance contributes to the following NSW Government priorities:

  • improving road travel reliability
  • ensuring on-time running of public transport
  • reducing road fatalities
  • improving government services
  • keeping our environment clean.

The NSW Commission of Audit recommended outsourcing the maintenance of State roads

The NSW Commission of Audit in its Final Report on Government Expenditure (May 2012) recommended contestability as an appropriate strategy to consider for improving road maintenance service delivery for State roads.  

The Commission benchmarked RMS’ road surface quality and cost per lane kilometre against those of Western Australia, Victoria, and Queensland. This showed that New South Wales lagged the other states on both these measures.  

Exhibit 1: Interjurisdictional comparison of road maintenance outcomes 2009–10
  WA VIC QLD NSW
Roads managed (lane kms) 52,659 50,510 71,353 80,348
Estimated spend ($/lane km) 5,000 4,500 6,000 7,000
Road quality measure (%) 99 99 94 91

Source: NSW Commission of Audit Final Report May 2012.

The Commission noted that RMS had conducted two independent reviews to examine the potential for extending road maintenance contestability. The Commission found that there was inadequate and inconclusive benchmarking to establish the efficiency of RMS’ Road and Fleet Services unit when compared to outsourcing. It recommended that RMS bring forward a proposal to conduct a competitive tender for the road maintenance of the Sydney region south zone road network to inform the feasibility of a progressive rollout of road maintenance contestability across other areas of the State. In August 2012, the NSW Government adopted the Commission’s recommendation.

The NSW Government introduced road maintenance contestability through Stewardship Maintenance Contracts

In April 2013, the NSW Government announced that it would introduce road maintenance contestability across the Sydney region, using a Stewardship Maintenance Contract (SMC) model to improve value for money. In doing so, it excluded RMS’ Road and Fleet Services unit from tendering.  

The SMC model is based on the following key commercial and performance principles set by RMS:

  • performance driven by outcomes
  • flexible and adaptable
  • transparent and measurable
  • linking risk to reward
  • continuous improvement
  • criteria for selection of, and transition to, different payment models.

The following key stewardship principles underpin the SMC’s broad set of values, attitudes and behaviours, which are required of the contractor to effectively manage the assets on behalf of RMS:

  • putting RMS’ customers (road users and the general public) first and being responsive to them
  • being responsible and accountable for the outcomes resulting from the management of the assets
  • managing the assets diligently, efficiently and effectively with limited direction from RMS
  • working collaboratively with RMS to deliver services that are tailored to meet RMS’ evolving needs
  • acting with integrity and transparency in performing the services
  • performing the services in the best interests of RMS and asset users.

Other key features of the SMC include:

  • service requirements which describe the scope of the services, and the standards the contractor must meet
  • a commercial framework which defines how payments are structured, how performance assessment will impact on payments and outlines the key commercial principles. SMCs primarily divide payments into two main mechanisms, these being the priced component (or fixed price) and the target cost calculated as follows:
    • fixed price – the contractor is paid a pre-agreed amount for specific services being provided, regardless of the actual costs incurred
    • target cost – RMS and the contractor agree on a target cost for a project, and any cost overruns or underruns are shared between them
  • a performance framework which provides mechanisms for assessing contractor performance. This includes a comprehensive listing of the key result areas (KRAs) and key performance indicators (KPIs) against which RMS measures the contractor’s performance. The framework also outlines the scoring methodology that RMS uses to determine whether the contractor’s bid margin (profit and overheads) is reduced due to less than satisfactory performance or whether a bonus is paid if a threshold performance score is exceeded.

Road maintenance under SMCs for Sydney region south and west zones commenced in November 2013

In November 2013, RMS awarded SMCs to the Leighton Boral Amey consortium, now named Ventia Boral Amey (VBA), for the south zone and the DownerMouchel (DM) consortium for the west zone. The contracts run for seven years with an option for a further three years at RMS’ discretion. In April 2014, full services commenced following a four-month transition period. RMS estimated that the annual cost of these contracts was around $240 million in total. In March 2018, the contract prices are due to be reset by negotiation to reflect the contractors’ experience with, and better information about, the road networks and routine maintenance requirements. 

  1. Roads and Maritime Services should consider whether to incorporate stronger sanctions in the Stewardship Maintenance Contract if the contractor provides incorrect performance or financial data to RMS, when:
     
    1. negotiating the commercial reset for the next works period with the Sydney region south and west zone contractors due in July 2018.
    2. finalising a new SMC contract for the Sydney region north zone, due to commence in October 2018.

Roads and Maritime Services should, by September 2017:

2.  Review its contract management framework for SMCs to ensure that all authorities and accountabilities of
     contract managers are clearly defined, including:

a) accountability and procedures for exercising all operational clauses in the SMC where RMS may opt to, or be required to intervene, or make a decision

b) authority to approve or initiate the interventions RMS is required to, or may, exercise under the SMC

c) the audits that RMS will conduct to systematically validate the performance and financial data that the SMC contractors provide

d) the accountabilities of RMS contract managers to systematically review audits and quality reviews that the SMC contractors must conduct to demonstrate compliance with their service plans

e) the accountabilities of RMS contract managers to check that the monthly and annual reports provided by SMC contractors do not contain errors, omissions or inaccuracies.

3.  Improve its management of benefits realisation by:

a) initiating a further benefits realisation review and record the benefits delivered against those
    estimated following the tender process, including the one-off transition costs

b) identify any benefits, including savings, not yet attained and develop strategies to address any short-falls

c) establish a tool to track the ongoing realisation of benefits.

Published

Actions for NorthConnex

NorthConnex

Premier and Cabinet
Treasury
Transport
Compliance
Infrastructure
Internal controls and governance
Management and administration
Procurement

The processes used to assess NorthConnex adequately considered value for money for taxpayers.This report also found that the impact of tolling concessions on road users and the motorway network was consistent with policy objectives described in the 2012 NSW Long Term Transport Master Plan.

NorthConnex is a nine-kilometre tolled motorway tunnel between the M1 Pacific motorway at Wahroonga and the M2 Hills motorway at West Pennant Hills. The total cost for the project is $3.1 billion. NorthConnex will be funded through toll charges, and contributions from the NSW and Australian Governments of up to $405 million each. In January 2015, the NSW Roads Minister signed the final contracts for NorthConnex.

By December 2017, the Department of Premier and Cabinet should:

1. publish an updated ‘Unsolicited Proposals – Guide for Submission and Assessment’ which clarifies obligations with requirements in other NSW Government policies such as the NSW PPP guideline and Infrastructure Investor Assurance Framework. The update should require:

a) a business case to be prepared, and a business case gateway review completed, as part of the assessment of the detailed proposal (currently stage 2)

b) probity reports must be completed and considered before the decision to proceed to the next stage.
 

The Department of Premier and Cabinet and NSW Treasury should immediately:

2. improve record keeping to ensure compliance with the State Records Act 1998 and the NSW Government Standard on Records Management.

 

Published

Actions for Mining Rehabilitation Security Deposits

Mining Rehabilitation Security Deposits

Planning
Industry
Environment
Infrastructure
Management and administration
Project management

The Department of Planning and Environment requires mining companies to rehabilitate sites according to conditions set in the mining development approval. The Department holds mining rehabilitation security deposits that are meant to cover the full cost of rehabilitation if a mining company defaults on its rehabilitation obligations.

The total value of security deposits held has increased from $500 million in 2005 to around $2.2 billion in 2016, covering around 450 mine sites in New South Wales.

While there have been substantial increases in total deposits held, mine rehabilitation security deposits are still not likely to be sufficient to cover the full costs of each mine's rehabilitation in the event of a default.

This audit was undertaken when the Department of Industry, Skills and Regional Development was responsible for ensuring land disturbed by mining activities is rehabilitated in accordance with the relevant development approval, including the administration of mining rehabilitation security deposits. On 1 April 2017, this responsibility was transferred to the Department of Planning and Environment (the Department).  

This audit assessed whether the Department maintains adequate security deposits to cover the liabilities associated with mine closures, including rehabilitation. Companies authorised by the Department to undertake mining activities must provide a security deposit to cover the full costs of rehabilitation in the event of default by the company. Rehabilitation is the treatment of disturbed land or water to establish a safe, stable, non-polluting and sustainable environment.

Mining companies must provide an estimate of rehabilitation costs for each site. The Department provides a Rehabilitation Cost Calculation tool to assist companies calculate the deposit amount. Companies are also required to ensure that the cost estimate is in accordance with the approved Mining Operations Plan (MOP). The MOP is intended to be a mine rehabilitation and closure plan, and forms the basis for the estimation of the security deposit. The Department reviews the estimates and determines the deposit for each site.  

Security deposits are an option of last resort. The Department has other legislative and regulatory tools which it normally uses to promote compliance with rehabilitation requirements before accessing a security deposit. It can direct action by the mining company, issue fines and even have the Minister revoke a mining lease. To date, the Department has never had to access a security deposit for a state significant development mine site.

Conclusion

The Department holds security deposits for mining rehabilitation consistent with the amounts it has requested from mining companies, and it should be able to claim on a deposit if a mining company defaults on its rehabilitation obligations. The total value of deposits has increased from $500 million in 2005 to around $2.2 billion in 2016, covering around 450 mine sites. The Department’s management of the security deposit process has improved in recent years, and it has well advanced plans for further improvement, including a revised cost calculation tool.

The Department’s policy is that each mine’s security deposit should cover the full costs of rehabilitation for that mine. The security deposits the Department holds are not likely to be sufficient to cover the full costs of each mine’s rehabilitation in the event of a default. The rates and allowances in the current cost calculation tool have not been updated since 2013 and some activities required for effective rehabilitation are not covered, or not covered adequately.

Security deposits also do not include sufficient contingency given the substantial risks and uncertainties associated with mine rehabilitation and closure, particularly in the absence of a detailed closure plan. This risk is exacerbated by the limited independent verification of mining company claims about the size of the outstanding rehabilitation task, which remains the case despite recent improvements to monitoring and review procedures and practices.  

There is also no financial assurance held over the risk of significant unexpected environmental degradation in the long-term after a mine is deemed to be rehabilitated and the security deposit is returned. A security deposit is not an appropriate vehicle for covering this risk.

Security deposits are close to calculated value and should be accessible if needed

The value of securities held by the Department aligns with the latest approved rehabilitation cost estimates. This contrasts with the situation found by investigations in Victoria and Queensland, where deposit amounts held fell below the calculated costs.

The security deposits are usually in the form of a bank guarantee or cash. The Department has obtained legal advice indicating that it should be able to claim on these bank guarantees if the need arises. As the guarantee is between the financial institution and the Department, if a mining company goes into liquidation the Department should still be able to access the funds.  

When the latest estimate of rehabilitation costs is higher than the existing deposit, the Department will request additional security. It has experienced extensive delays in obtaining additional security for some sites, increasing the risk that available funds will be insufficient if needed.

Rehabilitation cost estimates are not yet adequate, but improvements are planned

The Department’s policy is for security deposits to cover the full cost of rehabilitation. No discounts are provided to mining companies for past good behaviour or low likelihood of default, unlike in some other states. Discounting could undermine the policy position.  

Current security deposits are unlikely to cover the full cost of rehabilitation on each mine site. The Department provides a rehabilitation cost calculation tool to help mining companies calculate the cost of rehabilitation and the required deposit amount, but:

  • several activities required to effect closure are not included and others underestimated
  • it does not make provision for industry cost changes over time
  • the rates used in the tool have not been updated since 2013
  • it was not able to provide the basis for the rates and allowances in the tool.

The Department reviews cost estimates provided by mining companies, but its verification of the extent of rehabilitation work on which these estimates are based is limited. It relies instead on section 387C of the Mining Act 1992 which makes it an offence for mining companies to provide false or misleading information. It is not evident how the Department would establish that information provided was false or misleading without more verification work, and six of the 14 cost estimates we reviewed were not signed by the mine manager, making enforcement more difficult.  

The Department has developed a new calculation tool, and recently released it for industry consultation. The new tool should improve rehabilitation estimates. It updates rates and allowances, and includes additional items to better cover required rehabilitation tasks. While a substantial improvement, the new tool could be further improved by providing additional coverage for stakeholder engagement, additional planning approvals, insurance costs, and any additional design, research and verification work required for successful closure.

There is no financial assurance over long-term environmental risks

The Department does not hold any financial assurance to cover the costs associated with mitigating any future environmental degradation once a mine closes and the security deposit is relinquished to the mining company. Security deposits are probably not the appropriate mechanism to cover these long-term risks but the risk of potential post-closure environmental degradation still needs to be costed and covered. A fund to cover the state-wide risk, to which all mines would contribute, is a possible mechanism.

Rehabilitation and closure outcomes are vague, particularly for unplanned closure

Rehabilitation outcomes in the MOPs we reviewed were generally not specific. Any lack of specificity in MOPs translates into uncertainty about rehabilitation work required if a mining company defaults. Part of the problem is that rehabilitation outcomes established in planning approvals are usually not specific and may not address all closure requirements. The Department has recognised there is scope to improve the clarity and specificity of rehabilitation requirements in planning approvals, and has started a review focusing on open-cut mines.

Rehabilitation outcomes are even less specific in the event of an unexpected early closure because they will probably be different from that achievable from a planned closure.  

MOP guidelines do not cover management of some key closure matters, such as the requirements of environment protection licences issued by the Environment Protection Authority and the management of heritage sites during closure.

There were significant variations in quality of MOPs we reviewed and the way closure risks and uncertainties were identified and addressed. The Department plans to improve the quality of rehabilitation programs through enhanced guidance and oversight.

Monitoring is not adequate to effectively gauge rehabilitation progress

The Department was not able to show it has been monitoring operational mine sites effectively to gauge the progress of ongoing site rehabilitation and the management of closure risks. There was no protocol for site inspections and limited evidence of inspections for the sites we reviewed.

The Department receives annual environmental management reports from mining companies, with most describing the areas of disturbance and rehabilitation occurring at each mine site. The Department recently established procedures for reviewing these annual reports, and has developed a risk-based process for prioritising reviews.

Most annual reports we reviewed did not explain environmental changes over time, nor the risks to mine closure and the measures required to mitigate them. For example, analysis of changes to surface water and groundwater quality was limited despite its relevance for assessing future contamination risks.

The Department does not currently have adequate processes in place to effectively verify the reported areas of disturbance and rehabilitation. It is developing geographic information system-based tools to better measure areas of disturbance and rehabilitation, new rehabilitation guidelines, and a procedure for determining whether rehabilitation has been successful. These initiatives should improve the monitoring and reporting of rehabilitation progress at mine sites.

There is no mechanism to prevent a mine being in ‘care and maintenance’ indefinitely

The Department does not have a clear policy on the length of time and circumstances under which a mine can remain in ‘care and maintenance’. Indefinite postponement of rehabilitation and closure is therefore possible. 'Care and maintenance' is the period following temporary cessation of operations when infrastructure remains largely intact and the site continues to be managed. There are a range of valid reasons for a mining company to put a mine in ‘care and maintenance’, but it is also reasonable for the community to expect a limit to how long it has to wait for proper rehabilitation.

Mining operations make a significant contribution to the NSW economy, including over $1.3 billion in royalties each year. Around 400 mine sites throughout NSW provide over 40,000 jobs and are a major source of economic activity for many communities. Despite these benefits, it is important to ensure that mining companies fulfil their obligations to rehabilitate land disturbed as a result of mining activity.

We recommend that the Department should, by January 2018:

1. Improve the quality of rehabilitation and closure plans by:

  • ensuring plans submitted by mining companies include robust mine rehabilitation and closure risk assessments
  • clarifying the level of detail required in plans at each stage of a mine’s operation
  • specifying how requirements set under other legislative instruments (e.g. environment protection licences, heritage assets) should be addressed.

2. Improve assurance that security deposits are sufficient by:

  • ensuring its new cost calculation tool adequately covers all works needed for rehabilitation and closure
  • increasing the contingency for uncertainties associated with mine rehabilitation and closure, at least until the mining company provides a detailed closure plan
  • verifying the cost estimates for a sample of high risk sites annually
  • ensuring that when mining companies are required to provide increased security deposits, they do so with minimal delay.

3. Enhance oversight of mine rehabilitation by:

  • developing a protocol to ensure sufficient and adequate site inspections
  • ensuring mining companies report performance against rehabilitation targets and environmental changes clearly, including an analysis of long-term surface water and groundwater trends in terms of levels, flow and quality
  • improving how it determines the progress and success of mine rehabilitation
  • developing clear policy and procedures for ensuring a mine cannot be put into ‘care and maintenance’ indefinitely.

4. Collaborate with relevant agencies to establish a financial assurance mechanism, such as a sinking fund, to cover the risk of long-term environmental degradation after mines are closed and security deposits returned.

Appendix One - Response from the Department

Appendix Two - About the audit

 

Parliamentary reference - Report number #285 - released 11 May 2017

Published

Actions for Passenger Rail Punctuality

Passenger Rail Punctuality

Transport
Information technology
Infrastructure
Service delivery

Rail agencies are well placed to manage the forecast increase in passengers up to 2019, including joining the Sydney Metro Northwest to the network at Chatswood. Their plans and strategies are evidence-based, and mechanisms to assure effective implementation are sound.

Based on forecast patronage increases, the rail agencies will find it hard to maintain punctuality after 2019 unless the capacity of the network to carry trains and people is increased significantly. If recent higher than forecast patronage growth continues, the network may struggle to maintain punctuality before 2019.

A NSW Government priority is to ‘maintain or improve reliability of public transport services over the next four years’. Punctuality is a key element of reliability, and the level of patronage is a critical factor in the ability to maintain punctuality. Increasing patronage places pressure on the length of time trains need to wait at stations to load and offload passengers which can lead to delays. The NSW Long Term Transport Master Plan forecasts that rail patronage could increase by 26 per cent between 2012 and 2031.  

Passenger rail services in NSW are provided under a purchaser-provider model. Transport for NSW enters contracts with:

  • Sydney Trains for Sydney suburban passenger rail services
  • NSW Trains for services that commence or terminate outside Sydney, including intercity services that operate between Central station and the South Coast, Southern Highlands, Blue Mountains and Central Coast and Newcastle.

Transport for NSW sets performance targets and standards for these services, develops the timetables, procures trains for the service providers, and is responsible for long term planning.

This audit assessed whether these rail agencies have plans and strategies to maintain or improve performance in getting the growing number of suburban and intercity rail passengers to their destinations on time.

Conclusion:

Rail agencies are well placed to manage the forecast increase in passengers up to 2019, including joining the Sydney Metro Northwest to the network at Chatswood. Their plans and strategies are evidence-based, and mechanisms to assure effective implementation are sound.

Based on forecast patronage increases, the rail agencies will find it hard to maintain punctuality after 2019 unless the capacity of the network to carry trains and people is increased significantly. If recent higher than forecast patronage growth continues, the network may struggle to maintain punctuality before 2019.

Transport for NSW has undertaken considerable work on developing strategies to increase capacity and maintain punctuality after 2019, but remains some way from putting a costed plan to the government. There is a significant risk that investments will not be made soon enough to handle future patronage levels. Ideally, planning and investment decisions should have been made already.

Punctuality measurement is satisfactory, but agencies could publish more information

Passenger rail punctuality indicators adopted in NSW are good practice. The key train punctuality indicator is better than indicators used by many other rail operators. It is also better than the on-time-running indicator that it replaced. Unlike the on-time-running indicator, the punctuality indicator classifies trains that have been cancelled or skipped stations as late and results are not adjusted to take account of delays caused by factors such as extreme weather or police operations.

NSW also has a customer delay measure which represents good practice. Work has started on refining and embedding customer delay as a key performance measure for the planned new Rail Operations Centre.

As train frequency approaches a ‘turn up and go’ level of service, rather than running to a timetable, more emphasis will need to be placed on excess waiting time and customer delay when assessing performance.

Measurement of punctuality is reasonably precise. There are some measurement inaccuracies which should be addressed, such as the estimated arrival time of a train being incorrect at some destination stations, but these do not affect punctuality results materially.  

Train punctuality is reported publicly, but not to the detail of the indicators in the contracts between Transport for NSW and Sydney Trains and NSW Trains. There is very limited public reporting of customer delay.

Overall punctuality is good, but some services are relatively poor

System-wide train punctuality has usually exceeded target since 2005, but some services suffer from poor punctuality compared to the rest of the network.  

The part of the network around North Sydney is creating problems for the punctuality of afternoon peak services heading through it and out to Western Sydney and to Hornsby via Strathfield. Transport for NSW and Sydney Trains are well advanced with strategies to address this up to 2019.  

The East Hills express trains in the afternoon peak also performed well below target. The rail agencies recently analysed this issue and believe it relates to the train timetable and signalling which restricts how close trains can run behind each other into Campbelltown. It further advises that this will be corrected over the next three years.  

Intercity train punctuality is below that of suburban trains and there was an extended period of declining punctuality between 2011 and 2014. Transport for NSW suggested that the old age of trains is a factor, and the recently announced intercity fleet acquisition may help address this. Apart from ensuring that train crew and station staff are available and perform their duties adequately, NSW Trains can do little to impact the punctuality of its intercity services directly. Train maintenance, track and signal maintenance, and management of trains on the rail network are performed by Sydney Trains. NSW Trains’ ability to influence improvement is hampered by key indicators in some contracts being undefined. Transport for NSW, Sydney Trains and NSW Trains are now working collaboratively to make improvements to the contracts.

Initiatives are in place or are planned to deliver good punctuality until 2019

Patronage increases, which can lead to overcrowding and trains having to wait longer at stations, are likely to present a significant challenge to maintaining punctuality into the future.

Based on patronage projections, the rail agencies have strategies to maintain punctuality up to and including joining the Sydney Metro Northwest to the network at Chatswood in 2019. These include improving infrastructure at particular parts of the network, increasing staff training, reducing the number of speed restrictions, and a new Rail Operations Centre. The projects are being managed by experienced staff, with good governance arrangements, quality assurance processes and planning systems in place. New timetables should provide more services and cater for more passengers, including off peak. They should increase network efficiency through better utilisation of capacity, but some passengers may face longer journey times and more may need to change trains mid-journey.  

The planned Rail Operations Centre has the potential to make operational decision-making more customer-focussed, by placing more emphasis on minimising customer delay during disruptions. If implemented well, it will also generate information to help agencies better identify the root cause of incidents that delay trains and improve communication with passengers so they can make better real-time travel decisions.

Predicted passenger growth presents a risk to punctuality after 2019

The rail system will struggle to maintain punctuality much beyond 2019 based on current patronage forecasts and system limitations.

From 2024, the Sydney Metro City and Southwest will help by extending the metro network from Chatswood under Sydney Harbour, through the city and out to Bankstown. Announced fleet upgrades will also help. Transport for NSW advises that it is also working with the Greater Sydney Commission to ensure network capacity constraints are considered in future urban planning.

In addition to investment in new metro networks, sustained and substantial investment needs to be made into the existing heavy rail network to meet demand and ensure its ongoing reliability. Transport for NSW has been developing strategies for this purpose, including an Advanced Train Control system. Its aim is to put a costed plan to the government by the third quarter of this (2017) calendar year. Given the likely lead times involved with major infrastructure projects, there remains a significant risk of poor punctuality after 2019.

Punctuality could be at risk sooner if recent patronage growth continues

If patronage continues to increase at a faster rate than forecast, particularly during the morning peak, the network will struggle to cope before 2019. Transport for NSW forecast that between 2011 and 2026 morning peak rail patronage would increase each year by approximately 3.3 per cent. Between 2011 and 2016 the number of passengers travelling to the city during the morning peak grew by an average of 4.4 per cent each year, including annual growth of 6.6 per cent since May 2014.

A good understanding of patronage levels, trends and drivers is critical to effective planning. The audit identified some shortcomings in measurement of peak passenger loads. Transport for NSW advised that measurement approaches have been improved recently, and this will soon flow into improved data quality.  

Given the increasing flexibility in work practices available to many city workers, the relatively new field of behavioural insights may offer opportunities to ‘nudge’ some passengers away from travelling at the height of the peak with benefits for them and the network.

  1. Transport for NSW should ensure that programs to address rail patronage growth over the next five to ten years are provided to the government for Cabinet consideration as soon as possible.
     
  2. Sydney Trains and Transport for NSW should:
    a) maintain effective oversight and resourcing for all strategies designed to address rail patronage growth
    b) adjust strategies for any patronage growth above projection.
     
  3. Sydney Trains, NSW Trains and Transport for NSW should publish Customer Delay results by June 2018.
     
  4. Transport for NSW, Sydney Trains and NSW Trains should agree by December 2017:
    a) specific performance requirements for intercity train, track and signal availability and reliability
    b) guidelines for train priorities during disruptions and indicators of control centre performance in implementing these guidelines.
     
  5. Sydney Trains, NSW Trains and Transport for NSW should by June 2018:
    a) improve the accuracy of patronage measurement and develop a better understanding of patronage growth trends
    b) address small errors in the adjustment factors used for determining a train’s punctuality status
    c) improve their understanding of the factors impacting on intercity punctuality.
     
  6. Transport for NSW should, commencing June 2017, explore the potential to use behavioural insights to encourage more passengers to travel outside the height of the morning peak (8 am to 9 am).