Refine search Expand filter

Reports

Published

Actions for Internal Controls and Governance 2018

Internal Controls and Governance 2018

Education
Community Services
Finance
Health
Industry
Justice
Planning
Premier and Cabinet
Transport
Treasury
Whole of Government
Environment
Compliance
Cyber security
Financial reporting
Fraud
Information technology
Internal controls and governance
Management and administration
Procurement
Project management

The Auditor-General for New South Wales Margaret Crawford found that as NSW state government agencies’ digital footprint increases they need to do more to address new and emerging information technology (IT) risks. This is one of the key findings to emerge from the second stand-alone report on internal controls and governance of the 40 largest NSW state government agencies.

This report analyses the internal controls and governance of the 40 largest agencies in the NSW public sector for the year ended 30 June 2018.

This report covers the findings and recommendations from our 2017–18 financial audits that relate to internal controls and governance at the 40 largest agencies (refer to Appendix three) in the NSW public sector.

This report offers insights into internal controls and governance in the NSW public sector

This is our second report dedicated to internal controls and governance at NSW State Government agencies. The report provides insights into the effectiveness of controls and governance processes in the NSW public sector by:

  • highlighting the potential risks posed by weaknesses in controls and governance processes
  • helping agencies benchmark the adequacy of their processes against their peers
  • focusing on new and emerging risks, and the internal controls and governance processes that might address those risks.

Without strong governance systems and internal controls, agencies increase the risks associated with effectively managing their finances and delivering services to citizens. The way agencies deliver services increasingly relies on contracts and partnerships with the private sector. Many of these arrangements deliver front line services, but others provide less visible back office support. For example, an agency may rely on an IT service provider to manage a key system used to provide services to the community. The contract and service level agreements are only truly effective where they are actively managed to reduce risks to continuous quality service delivery, such as interruptions caused by system outages, cyber security attacks and data security breaches.

Our audits do not review all aspects of internal controls and governance every year. We select a range of measures, and report on those that present heightened risks for agencies to mitigate. This report divides these into the following five areas:

  1. Internal control trends
  2. Information technology (IT), including IT vendor management
  3. Transparency and performance reporting
  4. Management of purchasing cards and taxis
  5. Fraud and corruption control.

The findings in this report should not be used to draw conclusions on the effectiveness of individual agency control environments and governance arrangements. Specific financial reporting, controls and service delivery comments are included in the individual 2018 cluster financial audit reports, which will be tabled in Parliament from November to December 2018.

The focus of the report has changed since last year

Last year's report topics included asset management, ethics and conduct, and risk management. We are reporting on new topics this year. We plan to introduce new topics and re-visit our previous topics in subsequent reports on a cyclical basis. This will provide a baseline against which to measure the NSW public sectors’ progress in implementing appropriate internal controls and governance processes to mitigate existing, new and emerging risks in the public sector.

Agencies selected for the volume account for 95 per cent of the state's expenditure

While we have covered only 40 agencies in this report, those selected are a large enough group to identify common issues and insights. They represent about 95 per cent of total expenditure for all NSW public sector agencies.

Internal controls are processes, policies and procedures that help agencies to:

  • operate effectively and efficiently
  • produce reliable financial reports
  • comply with laws and regulations
  • support ethical government.

This chapter outlines the overall trends for agency controls and governance issues, including the number of findings, level of risk and the most common deficiencies we found across agencies. The rest of this volume presents this year’s controls and governance findings in more detail.

Observation Conclusions and recommendations
2.1 High risk findings
We found six high risk findings (seven in 2016–17), one of which was repeated from both last year and 2015–16. Recommendation: Agencies should reduce risk by addressing high risk internal control deficiencies as a priority.
2.2 Common findings
We found several internal controls and governance findings common to multiple agencies. Conclusion: Central agencies or the lead agency in a cluster can play a lead role in helping ensure agency responses to common findings are consistent, timely, efficient and effective.
2.3 New and repeat findings
Although internal control deficiencies decreased over the last four years, this year has seen a 42 per cent increase in internal control deficiencies. The increase in new IT control deficiencies and repeat IT control deficiencies signifies an emerging risk for agencies.
IT control deficiencies feature in this increase, having risen by 63 per cent since last year. The number of repeat IT control deficiencies has doubled and is driven by the increasing digital footprint left by agencies as government prioritises on-line interfaces with citizens, and the number of transactions conducted through digital channels increases

Recommendation: Agencies should reduce IT risks by:

  • assigning ownership of recommendations to address IT control deficiencies, with timeframes and actions plans for implementation
  • ensuring audit and risk committees and agency management regularly monitor the implementation status of recommendations.

 

Government agencies’ financial reporting is now heavily reliant on information technology (IT). IT is also increasingly important to the delivery of agency services. These systems often provide the data to help monitor the efficiency and effectiveness of agency processes and services they deliver. Our audits reviewed whether agencies have effective controls in place to manage both key financial systems and IT service contracts.

Observation Conclusions and recommendations
3.1 Management of IT vendors
Contract management framework 
Although 87 per cent of agencies have a contract management policy to manage IT vendors, one fifth require review.
 

Conclusion: Agencies can more effectively manage IT vendor contracts by developing policies and procedures to ensure vendor management frameworks are kept up to date, plans are in place to manage vendor performance and risk, and compliance with the framework is monitored by:

  • internal audit focusing on key contracting activities
  • experienced officers who are independent of contract administration performing spot checks or peer reviews
  • targeted analysis of data in contract registers.
Contract risk management
Forty-one per cent of agencies are not using contract management plans and do not assess contract risks. Half of the agencies that did assess contract risks, had not updated the risk assessments since the commencement of the contract.
 
Conclusion: Instead of applying a 'set and forget' approach in relation to management of contract risks, agencies should assess risk regularly and develop a plan to actively manage identified risks throughout the contract lifecycle - from negotiation and commencement, to termination.

Performance management
Eighty-six per cent of agencies meet with vendors to discuss performance. 

Only 24 per cent of agencies sought assurance about the accuracy of vendor reporting against KPIs, yet sixty-seven per cent of the IT contracts allow agencies to determine performance based payments and/or penalise underperformance.

Conclusion: Agencies are monitoring IT vendor performance, but could improve outcomes and more effectively manage under-performance by:

  • a more active, rigorous approach to both risk and performance management
  • checking the accuracy of vendor reporting against those KPIs and where appropriate seeking assurance over their accuracy
  • invoking performance based payments clauses in contracts when performance falls below agreed standards.

Transitioning services
Forty-three per cent of the IT vendor contracts did not contain transitioning-out provisions.

Where IT vendor contracts do make provision for transitioning-out, only 28 per cent of agencies have developed a transitioning-out plan with their IT vendor.

Conclusion: Contract transition/phase out clauses and plans can mitigate risks to service disruption, ensure internal controls remain in place, avoid unnecessary costs and reduce the risk of 'vendor lock-in'.
Contract Registers
Eleven out of forty agencies did not have a contract register, or have registers that are not accurate and/or complete.

Conclusion: A contract register helps to manage an agency’s compliance obligations under the Government Information (Public Access) Act 2009 (the GIPA Act). However, it also helps agencies more effectively manage IT vendors by:

  • monitoring contract end dates and contract extensions, and commence new procurements through their central procurement teams in a timely manner
  • managing their contractual commitments, budgeting and cash flow requirements.

Recommendation: Agencies should ensure their contract registers are complete and accurate so they can more effectively govern contracts and manage compliance obligations.

3.2 IT general controls
Governance
Ninety-five per cent of agencies have established policies to manage key IT processes and functions within the agency, with ten per cent of those due for review.
 
Conclusion: Regular review of IT policies ensures risks are considered and appropriate strategies and procedures are implemented to manage these risks on a consistent basis. An absence of policies can lead to ad-hoc responses to risks, and failure to consider emerging IT risks and changes to agency IT environments. 

User access administration
Seventy-two deficiencies were identified related to user access administration, including:

  • thirty issues related to granting user access across 43 per cent of agencies
  • sixteen issues related to removing user access across 30 per cent of agencies
  • twenty-six issues related to periodic reviews of user access across 50 per cent of agencies.
Recommendation: Agencies should strengthen the administration of user access to prevent inappropriate access to key systems.
Privileged access
Forty per cent of agencies do not periodically review logs of the activities of privileged users to identify suspicious or unauthorised activities.

Recommendation: Agencies should:

  • review the number of, and access granted to privileged users, and assess and document the risks associated with their activities
  • monitor user access to address risks from unauthorised activity.
Password controls
Twenty-three per cent of agencies did not comply with their own policy on password parameters.
Recommendation: Agencies should ensure IT password settings comply with their password policies.
Program changes
Fifteen per cent of agencies had deficient IT program change controls mainly related to segregation of duties and authorisation and testing of IT program changes prior to deployment.
Recommendation: Agencies should maintain appropriate segregation of duties in their IT functions and test system changes before they are deployed.

 

This chapter outlines our audit observations, conclusions and recommendations from our review of how agencies reported their performance in their 2016–17 annual reports. The Annual Reports (Statutory Bodies) Regulation 2015 and Annual Reports (Departments) Regulation 2015 (annual reports regulation) currently prescribes the minimum requirements for agency annual reports.

Observation Conclusion or recommendation
4.1 Reporting on performance

Only 57 per cent of agencies linked reporting on performance to their strategic objectives.

The use of targets and reporting performance over time was limited and applied inconsistently.

Conclusion: There is significant disparity in the quality and consistency of how agencies report on their performance in their annual reports. This limits the reliability and transparency of reported performance information.

Agencies could improve performance reporting by clearly linking strategic objectives to reported outcomes, and reporting on performance against targets over time. NSW Treasury may need to provide more guidance to agencies to support consistent and high-quality performance reporting in annual reports.

There is no independent assurance that the performance metrics agencies report in their annual reports are accurate.

Prior performance audits have noted issues related to the collection of performance information. For example, our 2016 Report on Red Tape Reduction highlighted inaccuracies in how the dollar-value of red tape reduction had been reported.

Conclusion: The ability of Parliament and the public to rely on reported information as a relevant and accurate reflection of an agency's performance is limited.

The relevance and accuracy of performance information is enhanced when:

  • policies and guidance support the consistent and accurate collection of data
  • internal review processes and management oversight are effective
  • independent review processes are established to provide effective challenge to the assumptions, judgements and methodology used to collect the reported performance information.
4.2 Reporting on reports

Agency reporting on major projects does not meet the requirements of the annual reports regulation.

Forty-seven per cent of agencies did not report on costs to date and estimated completion dates for major works in progress. Of the 47 per cent of agencies that reported on major works, only one agency reported detail about significant cost overruns, delays, amendments, deferments or cancellations.

NSW Treasury produce an annual report checklist to help agencies comply with their annual report obligations.

Recommendation: Agencies should comply with the annual reports regulation and report on all mandatory fields, including significant cost overruns and delays, for their major works in progress.

The information the annual reports regulation requires agencies to report deals only with major works in progress. There is no requirement to report on completed works.

Sixteen of 30 agencies reported some information on completed major works.

Conclusion: Agencies could improve their transparency if they reported, or were required to report:

  • on both works in progress and projects completed during the year
  • actual costs and completion dates, and forecast completion dates for major works, against original and revised budgets and original expected completion dates
  • explanations for significant cost overruns, delays and key project performance metrics.

 

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency preventative and detective controls over purchasing card and taxi use for 2017–18.

Observation Conclusion or recommendation
5.1 Management of purchasing cards
Volume of credit card spend
Purchasing card expenditure has increased by 76 per cent over the last four years in response to a government review into the cost savings possible from using purchasing cards for low value, high volume procurement.
 
Conclusion: The increasing use of purchasing cards highlights the importance of an effective framework for the use and management of purchasing cards.
Policy framework
We found all agencies that held purchasing cards had a policy in place, but 26 per cent of agencies have not reviewed their purchasing card policy by the scheduled date, or do not have a scheduled revision date stated within their policy.
Recommendation: Agencies should mitigate the risks associated with increased purchasing card use by ensuring policies and purchasing card frameworks remain current and compliant with the core requirements of TPP 17–09 'Use and Management of NSW Government Purchasing Cards'.
Preventative controls
We found that:
  • all agencies maintained purchasing card registers
  • seventy-six per cent provided training to cardholders prior to being issued with a card
  • eighty-nine per cent appointed a program administrator, but only half of these had clearly defined roles and responsibilities
  • thirty-two per cent of agencies place merchant blocks on purchasing cards
  • forty-seven per cent of agencies place geographic restrictions on purchasing cards.

Agencies have designed and implemented preventative controls aimed at deterring the potential misuse of purchasing cards.

Conclusion: Further opportunities exist for agencies to better control the use of purchasing cards, such as:

  • updating purchasing card registers to contain all mandatory fields required by TPP17–09
  • appointing a program administrator for the agency's purchasing card framework and defining their role and responsibility for the function
  • strengthening preventive controls to prevent misuse.

Detective controls
Ninety-two per cent of agencies have designed and implemented at least one control to monitor purchasing card activity.

Major reviews, such as data analytics (29 per cent of agencies) and independent spot checks (49 per cent of agencies) are not widely used.

Agencies have designed and implemented detective controls aimed at identifying potential misuse of purchasing cards.

Conclusion: More effective monitoring using purchasing card data can provide better visibility over spending activity and can be used to:

  • detect misuse and investigate exceptions
  • analyse trends to highlight cost saving opportunities.
5.2 Management of taxis
Policy framework
Thirteen per cent of agencies have not developed and implemented a policy to manage taxi use. In addition:
  • a further 41 per cent of agencies have not reviewed their policies by the scheduled revision date, or do not have a scheduled revision date
  • more than half of all agencies’ policies do not offer alternative travel options. For example, only 36 per cent of policies promoted the use of general Opal cards.
Conclusion: Agencies can promote savings and provide more options to staff where their taxi use policies:
  • limit the circumstances where taxi use is appropriate
  • offer alternate, lower cost options to using taxis, such as general Opal cards and rideshare.
Detective controls
All agencies approve taxi expenditure by expense reimbursement, purchasing card and Cabcharge, and have implemented controls around this approval process. However, beyond this there is minimal monitoring and review activity, such as data monitoring, independent spot checks or internal audit reviews.
Conclusion: Taxi spend at agencies is not significant in terms of its dollar value, but it is significant from a probity perspective. Agencies can better address the probity risk by incorporating taxi use into a broader purchasing card or fraud monitoring program.

 

Fraud and corruption control is one of the 17 key elements of our governance lighthouse. Recent reports from ICAC into state agencies and local government councils highlight the need for effective fraud control and ethical frameworks. Effective frameworks can help protect an agency from events that risk serious reputational damage and financial loss.

Our 2016 Fraud Survey found the NSW Government agencies we surveyed reported 1,077 frauds over the three year period to 30 June 2015. For those frauds where an estimate of losses was made, the reported value exceeded $10.0 million. The report also highlighted that the full extent of fraud in the NSW public sector could be higher than reported because:

  • unreported frauds in organisations can be almost three times the number of reported frauds
  • our 2015 survey did not include all NSW public sector agencies, nor did it include any NSW universities or local councils
  • fraud committed by citizens such as fare evasion and fraudulent state tax self-assessments was not within the scope of our 2015 survey
  • agencies did not estimate a value for 599 of the 1,077 (56 per cent) reported frauds.

Commissioning and outsourcing of services to the private sector and the advancement of digital technology are changing the fraud and corruption risks agencies face. Fraud risk assessments should be updated regularly and in particular where there are changes in agency business models. NSW Treasury Circular TC18-02 NSW Fraud and Corruption Control Policy now requires agencies develop, implement and maintain a fraud and corruption control framework, effective from 1 July 2018. 

Our Fraud Control Improvement Kit provides guidance and practical advice to help organisations implement an effective fraud control framework. The kit is divided into ten attributes. Three key attributes have been assessed below; prevention, detection and notification systems.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency fraud and corruption controls for 2017–18.

Observation Conclusion or recommendation
6.1 Prevention systems

Prevention systems
Ninety-two per cent of agencies have a fraud control plan in place, 81 per cent maintain a fraud database and 79 per cent report fraud and corruption matters as a standing item on audit and risk committee agendas.

Only 54 per cent of agencies have an employment screening policy and all agencies have IT security policies, but gaps in IT security controls could undermine their policies.

Conclusion: Most agencies have implemented fraud prevention systems to reduce the risk of fraud. However poor IT security along with other gaps in agency prevention systems, such as employment screening practices heightens the risk of fraud and inappropriate use of data.

Agencies can improve their fraud prevention systems by:

  • completing regular fraud risk assessments, embedding fraud risk assessment into their enterprise risk management process and reporting the results of the assessment to the audit and risk committee
  • maintaining a fraud database and reviewing it regularly for systemic issues and reporting a redacted version of the database on the agency's website to inform corruption prevention networks
  • developing policies and procedures for employee screening and benchmarking their current processes against ICAC's publication ‘Strengthening Employment Screening Practices in the NSW Public Sector’
  • developing and maintaining up to date IT security policies and monitoring compliance with the policy.
Twenty-three per cent of agencies were not performing fraud risk assessments and some agency fraud risk assessments may not be as robust as they could be.  Conclusion: Agencies' systems of internal controls may be less effective where new and emerging fraud risks have been overlooked, or known weaknesses have not been rectified.
6.2 Detection systems
Detection systems
Several agencies reported they were developing a data monitoring program, but only 38 per cent of agencies had already implemented a program.
 

Studies have shown data monitoring, whereby entire populations of transactional data are analysed for indicators of fraudulent activity, is one of the most effective methods of early detection. Early detection decreases the duration a fraud remains undetected thereby limiting the extent of losses.

Conclusion: Data monitoring is an effective tool for early detection of fraud and is more effective when informed by a comprehensive fraud risk assessment.

6.3 Notification systems
Notification system
All agencies have notification systems for reporting actual or suspected fraud and corruption. Most agencies provide multiple reporting lines, provide training and publicise options for staff to report actual or suspected fraud and corruption.
Conclusion: Training staff about their obligations and the use of fraud notification systems promotes a fraud-aware culture

 

Published

Actions for State Finances 2018

State Finances 2018

Education
Finance
Community Services
Health
Justice
Industry
Planning
Premier and Cabinet
Transport
Treasury
Whole of Government
Environment
Financial reporting

Pursuant to the Public Finance and Audit Act 1983, I present my Report on State Finances 2018.

I am pleased to once again report that I issued a clear audit opinion on the State’s consolidated financial statements. This demonstrates the Government’s focus on preparing high quality information on the State’s financial position and performance for use by stakeholders.

However, there are two key areas I would like to see addressed to further support the preparation of the State’s financial statements.
Firstly, some complex accounting matters are not being resolved until late in the financial reporting cycle. This has contributed to an increase in the number of errors in the financial statements key agencies are submitting for audit, particularly around assessing the value of physical assets. Better planning and earlier resolution of these matters would lead to more efficient processes.

Secondly, the State needs to implement five new accounting standards over the next two years. Agencies will need to devote significant resources and effort to collect the necessary information and assess the impact at the whole of government level. I will work with Treasury and relevant agencies to help them improve quality assurance controls over their financial reporting.

Throughout 2017-18 my office worked with Treasury on reforms to improve financial governance, budgeting and reporting arrangements across the sector.

The Government Sector Finance Bill 2018 passed both houses of Parliament in June 2018. However, the Legislative Council returned other proposed changes to the Public Finance and Audit Act 1983 to the Legislative Assembly for further consideration. Most of these changes relate to the Public Accounts Committee. At the time of writing, the cognate Bill had not been debated.

The budget result was a $4.2 billion surplus. The consolidated financial statements at 30 June 2018 do not reflect the sale of 51 per cent of the State’s investment in Sydney Motorway Corporation for which it received $9.3 billion. The sale was announced on 31 August 2018.

Finally, I would like to thank the staff of Treasury for the way they approached the audit. Our partnership is critical to ensuring the quality of financial management and reporting.

Margaret Crawford
Auditor-General
19 October 2018

 

The State's financial statements given a clear audit opinion


Timely and accurate financial reporting enables informed decision making, effective management of public funds and enhances public accountability.

Since the introduction of mandatory ‘early close procedures’ in 2011-12, the number of significant errors in financial statements of agencies had fallen largely due to identifying and resolving complex accounting issues early.

In 2016-17, Treasury narrowed the scope of mandatory procedures to focus on physical asset valuations and pro-forma financial statements. Despite being broadened for 2017-18, we have observed an increase in the number of errors in agency financial statements.

In 2017-18, twenty-three errors exceeding $20 million were found in agencies’ financial statements that make up the State’s consolidated financial statements. This compares to only five in 2015-16.

The errors identified this year were the result of:

  • incorrectly applying Australian Accounting Standards
  • deficiencies in assessing the value of physical assets
  • using inappropriate and inaccurate assumptions when measuring liabilities
  • inaccurately reflecting inter-agency payables and receivables.

Quality financial reporting would be enhanced by responding to key accounting issues as soon as they are identified, and preparing accounting position papers for consideration by Treasury, agency Audit and Risk Committees and the Audit Office.

Key accounting matters addressed by the State in 2017-18.


Restatement of some of the State’s previously reported asset and liability values.

The state corrected the previously reported values of some long-term liabilities ($2 billion).

Accounting standards require the State to measure its long-term liabilities at the best estimate of the expenditures required to settle the obligations. The affected liabilities include claims liabilities of the Lifetime Care and Support Authority of NSW and the NSW Self Insurance Corporation, and scheme liabilities of the Long Service Corporation. The liabilities are adjusted by what is referred to as the ‘discount rate’ to reflect the decreasing value of money over time.

In the past, agencies used a variety of rates to discount these liabilities. Some liabilities were discounted using the estimated long-term fair value of 10-year TCorp bond yields while others were discounted using the expected
return on investments. These discount rates did not comply with the requirements of Australian Accounting Standards and underestimated liabilities by $2.0 billion.

In 2017-18, the State assessed the discount rates previously used in the Sector. It determined the market yield on Commonwealth Bonds best met the Accounting Standard requirements and used this rate to discount similar liabilities in relevant agencies. This resulted in a $2.0 billion increase in the previously reported values of these liabilities and a similar decrease in retained earnings at 1 July 2016.

The State corrected previously reported values of certain Library assets ($1.1 billion).

The value of the Pictorial Collection of the Library Council of NSW (the Library) was reassessed at 31 January 2018. During the valuation process the Library identified three errors in the 2015 valuations which overstated the previously reported asset values. The errors included:

  • inconsistencies in the sampling technique ($583m)
  • double counting of some assets ($376m)
  • errors in population sizes ($164m).

This resulted in a $1.1 billion decrease in previously reported asset values and a corresponding decrease in the asset revaluation reserve at 1 July 2016.

 

Information system limitations continue at TAFE NSW.

TAFE NSW has experienced ongoing issues with its student administration system.

TAFE NSW has again implemented additional processes to verify the accuracy and completeness of revenue from student fees.

TAFE NSW expects to spend up to $89 million on a new information system to address these issues. Modules of the new student enrolment system are planned to be in place by May 2019

Risks to the quality and timeliness of financial reporting.


Challenges associated with valuing the State's physical assets.

When we audit financial statements we focus on areas we consider higher risk. These areas often require the use of estimates and judgements.

The valuation of the State’s physical assets is one such area. Fair value estimates are inherently complex and sensitive to assumptions and judgements. In the public sector, this may be exacerbated by the unique nature of its assets, such as land under roads, preserved plant specimens, cultural collections and other heritage assets.

In 2017-18, valuations of physical assets added $24.5 billion to the value of the State’s balance sheet. These assets are now valued at $339.2 billion. Our audits of these valuations identified:

The Library Council of NSW had three errors in the methodology previously used to value their pictorial assets ($1.1 billion error).
The Royal Botanic Gardens and Domain Trust did not previously recognise a value for their Herbarium assets ($284 million error).
Some revaluations within the Ministry of Health did not meet the requirements of Australian Accounting Standards or Treasury requirements ($159 million error).
The Department of Justice used an incorrect valuation
methodology ($83 million error).

Some important matters agencies should consider when planning/conducting asset valuations include:


STARTING OUT

  • Planning is important
  • Most effective revaluations include early engagement with all stakeholders, including auditors.
  • Determine who needs to be involved and advised of progress with the revaluation – e.g. finance, internal audit, audit and risk committee.
  • Ensure asset registers are complete and there is evidence to demonstrate the agency controls the assets.
  • The effective date of the valuation can be any date after the financial year commences, but well before year end.

MANAGEMENT'S ROLE

  • For large mass valuations consider using a suitable project management methodology to ensure the process remains ‘on track’ with sufficient oversight.
  • Consider engaging an expert to perform the valuation, but maintain responsibility for the outcomes. Ensure the outcomes are reasonable and quality review the results, including the appropriateness of inputs and key assumptions.
  • Compare pre and post valuation results on an individual asset basis. Where changes are significant and/or unexpected, document explanations from the valuer.
  • Start revaluations early so they are completed by early close (around March). The timetable must allow time for a quality review of results and for the results to be recorded in the financial records.
  • Revaluation workpapers must include the revaluation source data provided to the valuer and a reconciliation of the source data to the general ledger.

USING EXPERTS

  • The terms of engagement should be documented in an engagement letter, which clearly details the proposed valuation methodology. It’s important the valuer knows what is required from a policy perspective and clearly understands the accounting framework used to prepare the financial statements.
  • Valuation reports should detail the key assumptions used, explain why the valuation approach was adopted and how the use of relevant observable input was maximised.
  • Valuation reports should clearly differentiate between assets revalued using a cost approach and those using an income or market approach. They should explain why the approach used was the most relevant for the asset type.
  • Consider using representative/statistical sampling for mass valuations and determine the extent of physical inspections that may be required.
  • If a sampling technique is used, it should provide sufficient confidence that the sample is representative of the population.
  • Significant judgements should be supported by relevant benchmark data or other analysis and observations. A common example in the public sector is to discount asset values to reflect restrictions on use.
  • Ensure the valuer has considered the age and condition of the assets, and heritage/cultural aspects and/or other special factors.

WHAT ABOUT INTERVENING YEARS?

  • Perform revaluations with sufficient regularity to ensure asset carrying values in the financial statements reflect fair value.
  • Indexation alone is not normally a substitute for a full revaluation. A full revaluation may be needed to accurately establish fair values if asset values move significantly when indices are applied to them.
  • Where indexation is used between full revaluations, the indices should be appropriate for the type of asset being assessed.
  • Indexing can be unreliable in assessing whether the fair value of assets has moved over time. For example, some assets are valued based on re- collection cost estimates, which may fall over time due to improved re-collection methods and technology.

COMMUNICATION

  • For mass or complex valuations, key stakeholders, including auditors, should be involved at the scoping stage and invited to planning meetings with valuers.
  • Management should meet with the auditors regularly to discuss progress and outcomes.
  • When issues are identified, management should consult with and seek advice from Treasury.

 

The state will need to implement five new accounting standards over the next two years.

The State has started developing processes it considers necessary to effectively implement the requirements of five new accounting standards. The changes are significant and will impact the financial position and results of agencies and the State.

The new requirements increase the risk of errors in the financial statements. To minimise this risk, agencies will need to devote resources and effort to collect the necessary information and assess the impact of the accounting changes at the whole of government level.

Treasury is liaising with and obtaining information from agencies to assess the impact of the new standards at the whole of government level. Treasury is also liaising with other Treasuries throughout Australia on common implementation issues. To help agencies implement the new standards, Treasury is developing guidance, preparing position papers on proposed accounting treatments, and mandating options within the new standards that agencies need to adopt on transition.


 

A $4.2 billion surplus, $1.5 billion more than was budgeted


The Total State Sector comprises 304 entities controlled by NSW Government

The General Government Sector, which comprises 212 entities, generally provides goods and services funded centrally by the State.

The non-General Government Sector, which comprises 92 Government businesses, generally provides goods and services, such as water, electricity and financial services that consumers pay for directly.

A principal measure of a Government’s overall performance is its Net Operating Balance (Budget Result). This is the difference between the cost of General Government service delivery and the revenue earned to fund these sectors.

WHAT CHANGED FROM 2017 TO 2018?

$4.2b

2017-18 General Government Budget Result

Changes in revenues compared to 2016-17

   
Financial_performance_red_10x10cm_0.pngDividends and distributions

 

Due to: 

  • Increases in dividends from Sydney Water ($255 million), Water NSW ($60 million) and the Port Authority of NSW ($195 million).
  • An increase in the dividend from Landcom ($200 million) as profits retained in prior years to fund certain projects were not spent.
  • Returns from investments in managed funds increased by $649 million as the State increased the value of its investment using proceeds from the lease of Ausgrid and Endeavour Energy assets
2016-2017 Change 2017-2018

2.4b

+1.3b

3.7b

 

   
Financial_performance_red_10x10cm_0.pngTaxation

 

Due to: 

  • Increases in land tax ($564 million) driven by land valuations used to calculate land tax assessments.
  • Increases in payroll tax ($553 million) and other taxes ($419 million).
  • Stamp duty receipts were $1.0 billion lower largely due to additional duty in the prior year of $718 million relating to the lease of Ausgrid and Endeavour Energy assets.
2016-2017 Change 2017-2018

30.8b

+537m

31.3b

 

   
Greek pantheon style front of building Grants & Subsidies

 

 Due to:

  • Increase in the receipt of general purpose grants relating to GST collected by the Australian Government ($753 million).
  • Decreases in national partnerships and specific purpose payments received from the Australian Government ($305 million), mainly due to the timing of major road projects.
  • An increase in Commonwealth Health Reform funding ($338 million).
  • An increase in grants associated with the National Education Reform Agreement for Education ($233 million).
2016-2017 Change 2017-2018

31.4b

+509m

31.9b

 

   
red shopping tagsSale of Goods and services

 

Includes: 

  • Increases in education revenue ($133 million).
  • Higher fees for services in transport to produce property plant and equipment ($89 million).
2016-2017 Change 2017-2018

8.2b

+349m

8.5b

5.5b

-185m

5.3b

Other revenues

Changes to expenses compared to 2016-17

   
institution_red_10x10cm_0.pngRecurrent Grants & Subsidies

 

Due to: 

  • A $613 million increase in grants for the delivery of aging, disability (including NDIS), homecare, community and public housing services.
  • Increase in grants paid to local government sector ($342 million).
2016-2017 Change 2017-2018

12.6b

+1.3b

13.9b

 

   
group_red_10x10cm_0.pngEmployee costs

 

Due to: 

  • Wage inflation increases ($701 million).
  • Increased workers' compensation and long service leave costs ($337 million). 
2016-2017 Change 2017-2018

34.9b

+1.2b

36.1b

 

   
red cogs with a dollar sign in the middleOther operating expenses

 

Includes: 

  • Increased expenditure by Transport for NSW ($283 million) for major rail projects and the new rail timetable.
  • Increased expenditure by the Department of Education ($165 million) to address the maintenance backlog, and higher school operating expenses.
2016-2017 Change 2017-2018

18.3b

+1.4b

19.7b

6.8b

+103m

6.9b

Other expenses

 

$5.7b

2016-17 General Government Budget Result

The State maintained its AAA credit rating.


The object of the Fiscal Responsibility Act 2012 is to maintain the State’s AAA credit rating.

The Government manages NSW’s finances in alignment with the Fiscal Responsibility Act 2012 (the Act).

The Act establishes the framework for fiscal responsibility and the strategy to protect the State’s AAA credit rating and service delivery
to the people of NSW.

The legislation sets out targets and principles for financial management to achieve this.

New South Wales has credit ratings of AAA/ Stable from Standard & Poor’s and Aaa/ Stable from Moody’s Investors Service.

THE FISCAL TARGETS FOR ACHIEVING THIS OBJECTIVE ARE:

General Government annual expenditure growth is lower than long term average revenue growth.

General Government expenditure grew by 5.4 per cent in 2017-18. This was lower than the long-term revenue growth rate of 5.6 per cent.

Eliminating unfunded superannuation liabilities by 2030.

The Act sets a target to eliminate unfunded superannuation liabilities by 2030.

The State’s funding plan is to contribute amounts escalated by five per cent each year so the schemes will be fully funded by 2030. In 2017-18, the State made employer contributions of $1.7 billion, which is largely consistent with contributions over the past five years. Treasury expects superannuation liabilities will be fully funded by 2030 based on the funding program at the last triennial review (December 2015).

For fiscal responsibility purposes, the State uses AASB 1056: Superannuation Entities. This standard discounts superannuation liabilities using the expected return on assets backing the liability.

Using this method, the State’s unfunded superannuation liability was $14.0 billion at 30 June 2018 ($15.0 billion at 30 June 2017). The unfunded liability is $3.4 billion less than it was when the Act was introduced.


 

Revenues increased by $3.2 billion to $86.7 billion in 2017-18.


Revenues were underpinned by growth in taxation and Australian Government grant revenues, but stamp duties fell.

Tax revenue for the Total State Sector increased by $746 million, or 2.5 per cent compared to 2016-17, primarily due to a:

  • $582 million increase in land tax from growth in land values
  • $562 million increase in payroll tax from NSW employment and wages growth
  • $1 billion decrease in stamp duty due to lower than expected growth in property market transactions, volumes and prices. In 2016-17, stamp duty included $718 million from the leases of Ausgrid and Endeavour Energy assets.

The State expects total stamp duties will fall to $9.5 billion in 2018-19, a decrease of almost $2.0 billion from 2016-17.

The State received Australian Government grants and subsidies of $30.9 billion in 2017-18.
The State received $444 million more in grants and subsidies from the Australian Government than it did in 2016-17. This was due to increases in GST revenues ($753 million) and special purpose payments ($683 million).
There was a decrease in National Partnership payments ($992 million), mainly due to the timing of major road projects including the Pacific Highway (Woolgoolga to Ballina), WestConnex and Western Sydney Infrastructure Program.

In 2017-18, sales of goods and services were $1.1 billion higher than in 2016-17. This reflected increased transaction revenue at Sydney Water ($139 million), the Department of Education ($133 million), WestConnex ($145 million), Department of Finance, Services and Innovation ($111 million) and Sydney Trains ($83 million).

Other dividends and distributions were $803 million higher than in 2016-17 mainly reflecting higher investment returns on TCorp investments.

$

83.5b

+3.9%

86.7b

Total Revenue

Key revenues include:

  2016-2017 Change% 2017-2018  
red gavel

35.4b

+2.8

36.3b

Taxation, Fees, Fines, and other
institution_red_10x10cm_0.png

31.4b

+1.6

31.9b

Grants & Subsidies
tags_red_10x10_0.png

14.1b

+8.1

15.2b

Sale of Goods and Services

Expenses increased $4.9 billion to $84.2 billion in 2017-18


Overall expenses increased 6.1 per cent compared to 2016-17. Most of the increase was due to higher employee and operating costs.

$

79.3b

+6.1%

84.2b

Total Expenses

Salaries and wages increased by 3.6 per cent compared to 2016-17.

Salaries and wages increased to $31.1 billion from $30 billion. This was due to inflation linked salary and wage increases and a reported increase in front line staff.

The Government wages policy aims to limit growth in employee remuneration and other employee related costs to no more than 2.5 per cent per annum.

Operating expenses increased by 7.8 per cent from 2016-17.

Within operating expenses, payments for supplies, services and other expenses increased, in part, due to:

  • increased costs of major rail projects, WestConnex, B-Line bus program and a new rail timetable
  • addressing the maintenance backlog and higher school operating expenses of the Department of Education.

Key expenses include:

  2016-2017 Change% 2017-2018  
group_red_10x10cm_0.png

32.8b

+3.8

34.1b

Employee Expenses
Financial_controls_red_10x10cm_0.png

21.6b

+7.8

23.3b

Operating Costs
institution_red_10x10cm_0.png

9.7b

+12.7

10.9b

Grants & Subsidies
down arrow red

7.2b

+6.6

7.6b

Depreciation
red briefcase

4.6b

+2.8

4.7b

Superannuation Expense

Health costs remain the highest expense of the State.

The Australian Bureau of Statistics introduced a revised Classification of the Function of Government Australia Framework (COFOG-A) effective 1 July 2017. This resulted in some re-classification of expenditure between purposes and now shows State expenses are highest in:

  • Health (25.5 per cent)
  • General Public Services (25.0 per cent)
  • Education (19.6 per cent).

General Public Services includes the executive and legislative branches, financial affairs, public debt transactions and general public service transactions.

The graph highlights the annual expenditure by function and the value of assets to deliver those services.

Assets grew by $35.6 billion to $443 billion in 2017-18


Valuing the State’s physical assets.

The State had physical assets with a fair value of $339 billion at 30 June 2018. This includes land and buildings ($161.6b) and Infrastructure ($160.2b).

Our audits assess the reasonableness and appropriateness of assumptions used to value physical assets. This includes obtaining an understanding of the valuation methodologies used and judgements made. We also review the completeness of asset registers and the mathematical accuracy of valuation models.

Net movements between years include additions, disposals, depreciation and valuations. This year, revaluations of physical assets added $24.5 billion to the value of the State’s assets. This was mainly attributable to the following agencies:

  • Department of Education - $8.5 billion
  • Roads and Maritime Services - $7.4 billion.

The State’s financial assets increased by $308 million in 2017-18 ($27.5 billion in 2016-17).

In 2016-17, the significant increase in financial assets was primarily from the sale or lease of the following government assets and businesses:

  • In June 2017, the Government leased 50.4 per cent of Endeavour Energy assets, which followed the long-term lease 50.4 per cent of Ausgrid’s assets in December 2016. The Government received proceeds of $24.0 billion from these transactions.
  • A 35-year concession for providing titling and registry services, effective 30 June 2017, was granted to a private sector operator. The Government received $2.6 billion cash for the concession.

The Government implemented reforms relating to the use the State’s financial assets.

In 2017-18, the Asset and Liability Committee, which advises the Government on balance sheet management, recommended the following policy actions and frameworks to help manage the State’s financial risks and opportunities:

  • expanding the scope of cash management reforms to give the State a whole-of-government view on the use of surplus funds. Treasury advises these reforms have centralised funds management of approximately $3.0 billion
  • endorsing a new whole-of-government Foreign Exchange (FX) Risk Policy (effective 1 July 2018) to effectively manage the State’s FX risk
  • expanding management of the State’s debt portfolio to minimise interest rate risks, reduce interest costs where possible, and extend the average weighted life of the General Government’s debt portfolio towards eight years
  • endorsing establishment of a ‘sustainability bond’ program to further diversify and expand the State’s bond investor base and raise awareness of the Government’s social and environmental initiatives.

The State has established the NSW Generations Fund to maintain debt at sustainable levels.

The State established the NSW Generations Funds (NGF) in June 2018 to support debt retirement and to fund community-focused initiatives. The Government has indicated it will initially capitalise the NGF with $3.0 billion from its reserves.

The NSW Generations Funds Act 2018 requires an audit of each NSW Generations Fund by the Auditor- General (including a report by the Auditor-General on whether payments from the Funds have been made in accordance with the Act). The first audit of the fund will be for the period up to 30 June 2019.
 

$

407b

+8.7%

443b

Total Assets

Key assets include: 

  2016-2017 Change% 2017-2018  
Physical Assets      
road_red_10x10_0.png

147.0b

+9.0

160.2b

Infrastructure
factory red

143.4b

+12.7

161.6b

Land and Buildings
Financial Assets      
scales of justice red

27.7b

- 4.6

26.4b

Equity investments
Financial_performance_red_10x10cm_0.png

20.6b

- 5.2

19.5b

Cash and Recievables
red pillar building - partheon

40.5b

+6.5

41.3b

Investments and Placements

Liabilities increased $5.1 billion to $189 billion in 2017-18


Valuing the State’s liabilities relies on actuarial assessments.

Nearly half of the State’s liabilities relate to its employees. They include unfunded superannuation, and employee benefits, such as long service and recreation leave.

Valuing these obligations involves complex estimation techniques and significant judgements. Small changes in assumptions can materially impact the values and the financial statements.

The State’s superannuation obligations fell $2.2 billion in 2017-18.

The State’s $56.4 billion unfunded superannuation liability represents obligations to past and present employees less the value of assets set aside to meet those obligations. The unfunded superannuation liability fell from $58.6 billion to $56.4 billion in 2017-18.

The State’s borrowings at 30 June 2018 were $700 million higher than they were at 30 June 2017.

The State’s borrowings totalled $71.3 billion at 30 June 2018.

TCorp issues bonds to raise funds for NSW Government agencies. These are actively traded in financial markets, which provides price transparency and liquidity to public sector borrowers and institutional investors. All TCorp bonds are guaranteed by the NSW Government.

The Government manages its debt liabilities through its balance sheet management strategy. The strategy extends to TCorp, which applies an active risk management strategy to the Government’s debt portfolio.

General Government Sector debt has been restructured by replacing shorter-term debt with longer-term debt. This lengthens the portfolio to match liabilities with the funding requirements for infrastructure assets.

$

184b

+2.8%

189b

Total Liabilities

Key liabilities include: 

  2016-2017 Change% 2017-2018  
briefcase_red_10x10cm_0.png

58.6b

- 3.7

56.4b

Unfunded Superannuation
group_red_10x10cm_0.png

18.3b

+4.7

19.1b

Other Employee Benefits
institution red - pantheon style building

70.6b

+1.0

71.3b

Borrowings

Published

Actions for Assessment of the use of a training program

Assessment of the use of a training program

Finance
Internal controls and governance
Management and administration

The Department of Finance, Services and Innovation (DFSI) and Service NSW's use of Franklin Covey's '7 Habits' program (the Program) met identified business needs according to a report released today by the Auditor-General for New South Wales Margaret Crawford. 

This audit assesses the effectiveness and economy of the Department of Finance, Services and Innovation's, including Service NSW's, use of the Franklin Covey ‘7 Habits’ program (the Program). On 15 March 2018, the Hon. Victor Dominello MP, Minister for Finance, Services and Property, requested the Auditor General conduct this audit under section 27(B)(3)(c) of the Public Finance and Audit Act 1983 (the Act).

About the agencies

The Department of Finance, Services and Innovation (the Department) is the lead agency of the Finance, Services and Innovation cluster. The Department has a number of divisions and business units, including: ICT and Digital Government, Property and Advisory Group, Better Regulation, NSW Fair Trading, Government and Corporate Services, and Revenue NSW. At 30 June 2017, the Department (excluding Service NSW) had 5,239 full-time equivalent staff.

Service NSW is a central point of contact for customers accessing NSW Government Services. It is a Division of the Finance, Services and Innovation cluster and operates as an executive agency. As an executive agency, Service NSW is led by a Chief Executive Officer, who is responsible to the Minister for Finance, Services and Property but appointed by the Secretary of the Department of Finance, Services and Innovation. Service NSW was established in 2013 and has operated under the Finance, Services and Innovation cluster since July 2015. At 30 June 2017, Service NSW had 1,989 full-time equivalent staff.

About the Program

The Program that the Department and Service NSW are implementing, and which is the subject of this audit, is a professional development training course which focusses on organisational culture emphasising personal effectiveness, leadership development and change management. All staff in the Department and Service NSW will receive the training, which involves:

  • a 360-degree assessment where every staff member receives feedback from their manager, direct reports, and peers
  • a two-day training workshop, which will be delivered face to face by accredited facilitators
  • 2 years of online access to all training materials created by the provider of the Program.

As part of the licensing arrangement purchased by the agencies, the Program also provides access (at no extra cost) to the full range of the provider's training and development courses that might be useful for other learning and development activities. This includes courses to improve staff capability in communication skills, leadership, productivity and customer engagement. The Department is considering using one of these courses to develop leadership capabilities. Service NSW has integrated three of these courses into its people development curriculum.

Service NSW commenced the first sessions of the Program in May 2017. At 24 April 2018, around 1,000 staff had undertaken the training. Service NSW expects all staff to complete the Program by June 2019.

The Department of Finance, Services and Innovation commenced the first sessions of the Program in August 2017. At 18 April 2018, around 175 staff had undertaken the training. The Department expects all staff to complete the Program by December 2019.

Audit objective and criteria

The audit sought to assess the effectiveness and economy of the Finance, Services and Innovation cluster’s use of the Program. In making this assessment, we considered whether:

  1.  the Program is being used effectively, including whether
    1. there is an identified need for the Program
    2. the use of the Program meets the identified need
    3. Finance, Services and Innovation cluster agencies evaluate the effectiveness of the Program
  2. the Program is economical, including whether:
    1. the procurement complies with all relevant policies and processes
    2. funding and resources allocated to the Program are reasonable.
Conclusion
The Department of Finance, Services and Innovation, and Service NSW developed workforce strategies which identified a business need to improve organisational culture and staff engagement. The Program met the identified business needs and both agencies negotiated value for money contracts for the delivery of the Program when compared to other available options for training all staff.
However, the agencies did not document evidence to show that training all staff members was necessary to meet their business needs, as compared with training fewer staff members at a lower overall cost. As a result, we are unable to form a view on whether the approach to train all staff members was economical. The agency heads have subsequently provided information supporting their decisions to train all staff members. This information indicates their decisions were based on evidence that this would meet the goals of their workforce strategies, including improving employee engagement scores and organisational culture change.
The Department is paying $1,320,700, over three years, for up to 5,600 staff to participate in the Program ($235.84 per person). Service NSW is paying $595,000, over two years, for up to 2,400 staff to participate in the Program ($247.92 per person).
The agencies are collecting the data they need to evaluate the Program and there is some evidence that the Program is achieving its objectives in Service NSW. Due to the timing of this audit, there is not yet enough information available to comment on whether the Program is achieving its objectives in the Department.

Sector-wide learnings

Implementing robust learning and development frameworks

  1. Agencies should evidence decisions about how proposed learning and development opportunities will meet staff and business needs - both in the program design, and through evaluation. In many cases, organisations may have unique needs or circumstances, or may want to trial innovative approaches to improving organisational capability. Innovation should be encouraged, to avoid the risk that agencies are locked into outdated training and development models. However such approaches should be balanced by ensuring that business needs are well scoped and defined.
     
  2. Agencies implementing innovative or new approaches to learning and development should build-in iterative evaluations (such as pulse surveys, or collecting post-participation qualitative feedback) to ensure that the training is delivered on intended benefits, and to inform improvements to ongoing rollout.
     
  3. Agencies implementing innovative or new training programs should ensure they build enough flexibility into contracts so that they can assess how well programs are meeting staff and business needs, and use evidence to inform whether further rollout should occur.

Published

Actions for HealthRoster benefits realisation

HealthRoster benefits realisation

Health
Compliance
Information technology
Management and administration
Project management
Workforce and capability

The HealthRoster system is delivering some business benefits but Local Health Districts are yet to use all of its features, according to a report released today by the Auditor-General for New South Wales,  Margaret Crawford. HealthRoster is an IT system designed to more effectively roster staff to meet the needs of Local Health Districts and other NSW health agencies.

The NSW public health system employs over 100,000 people in clinical and non-clinical roles across the state. With increasing demand for services, it is vital that NSW Health effectively rosters staff to ensure high quality and efficient patient care, while maintaining good workplace practices to support staff in demanding roles.

NSW Health is implementing HealthRoster as its single state-wide rostering system to more effectively roster staff according to the demands of each location. Between 2013–14 and 2016–17, our financial audits of individual LHDs had reported issues with rostering and payroll processes and systems.

NSW Health grouped all Local Health Districts (LHDs), and other NSW Health organisations, into four clusters to manage the implementation of HealthRoster over four years. Refer to Exhibit 4 for a list of the NSW Health entities in each cluster.

  • Cluster 1 implementation commenced in 2014–15 and was completed in 2015–16.
  • Cluster 2 implementation commenced in 2015–16 and was completed in 2016–17.
  • Cluster 3 began implementation in 2016–17 and was underway during the conduct of the audit.
  • Cluster 4 began planning for implementation in 2017–18.

Full implementation, including capability for centralised data and reporting, is planned for completion in 2019.

This audit assessed the effectiveness of the HealthRoster system in delivering business benefits. In making this assessment, we examined whether:

  • expected business benefits of HealthRoster were well-defined
  • HealthRoster is achieving business benefits where implemented.

The HealthRoster project has a timespan from 2009 to 2019. We examined the HealthRoster implementation in LHDs, and other NSW Health organisations, focusing on the period from 2014, when eHealth assumed responsibility for project implementation, to early 2018.

Conclusion
The HealthRoster system is realising functional business benefits in the LHDs where it has been implemented. In these LHDs, financial control of payroll expenditure and rostering compliance with employment award conditions has improved. However, these LHDs are not measuring the value of broader benefits such as better management of staff leave and overtime.
NSW Health has addressed the lessons learned from earlier implementations to improve later implementations. Business benefits identified in the business case were well defined and are consistent with business needs identified by NSW Health. Three of four cluster 1 LHDs have been able to reduce the number of issues with rostering and payroll processes. LHDs in earlier implementations need to use HealthRoster more effectively to ensure they are getting all available benefits from it.
HealthRoster is taking six years longer, and costing $37.2 million more, to fully implement than originally planned. NSW Health attributes the increased cost and extended timeframe to the large scale and complexity of the full implementation of HealthRoster.

Business benefits identified for HealthRoster accurately reflect business needs.

NSW Health has a good understanding of the issues in previous rostering systems and has designed HealthRoster to adequately address these issues. Interviews with frontline staff indicate that HealthRoster facilitates rostering which complies with industrial awards. This is a key business benefit that supports the provision of quality patient care. We saw no evidence that any major business needs or issues with the previous rostering systems are not being addressed by HealthRoster.

In the period examined in this audit since 2015, NSW Health has applied appropriate project management and governance structures to ensure that risks and issues are well managed during HealthRoster implementation.

HealthRoster has had two changes to its budget and timeline. Overall, the capital cost for the project has increased from $88.6 million to $125.6 million (42 per cent) and has delayed expected project completion by four years from 2015 to 2019. NSW Health attributes the increased cost and extended time frame to the large scale and complexity of the full implementation of HealthRoster.

NSW Health has established appropriate governance arrangements to ensure that HealthRoster is successfully implemented and that it will achieve business benefits in the long term. During implementation, local steering committees monitor risks and resolve implementation issues. Risks or issues that cannot be resolved locally are escalated to the state-wide steering committee.

NSW Health has grouped local health districts, and other NSW Health organisations, into four clusters for implementation. This has enabled NSW Health to apply lessons learnt from each implementation to improve future implementations.

NSW Health has a benefits realisation framework, but it is not fully applied to HealthRoster.

NSW Health can demonstrate that HealthRoster has delivered some functional business benefits, including rosters that comply with a wide variety of employment awards.

NSW Health is not yet measuring and tracking the value of business benefits achieved. NSW Health did not have benefits realisation plans with baseline measures defined for LHDs in cluster 1 and 2 before implementation. Without baseline measures NSW Health is unable to quantify business benefits achieved. However, analysis of post-implementation reviews and interviews with frontline staff indicate that benefits are being achieved. As a result, NSW Health now includes defining baseline measures and setting targets as part of LHD implementation planning. It has created a benefits realisation toolkit to assist this process from cluster 3 implementations onwards.

NSW Health conducted post-implementation reviews for clusters 1 and 2 and found that LHDs in these clusters were not using HealthRoster to realise all the benefits that HealthRoster could deliver.

By September 2018, NSW Health should:

  1. Ensure that Local Health Districts undertake benefits realisation planning according to the NSW Health benefits realisation framework
  2. Regularly measure benefits realised, at state and local health district levels, from the statewide implementation of HealthRoster
  3. Review the use of HealthRoster in Local Health Districts in clusters 1 and 2 and assist them to improve their HealthRoster related processes and practices.

By June 2019, NSW Health should:

  1. Ensure that all Local Health Districts are effectively using demand based rostering.

Appendix one - Response from agency

Appendix two - About the audit

Appendix three - Performance auditing

 

Parliamentary reference - Report number #301 - released 7 June 2018

Published

Actions for Grants to non-government schools

Grants to non-government schools

Education
Compliance
Internal controls and governance
Management and administration

The NSW Department of Education could strengthen its management of the $1.2 billion provided to non-government schools annually. This would provide greater accountability for the use of public funds, according to a report released today by the Auditor-General for New South Wales, Margaret Crawford.

Non‑government schools educate 418,000 school children each year, representing 35 per cent of all students in NSW. The NSW Department of Education administers several grant schemes to support these schools, with the aim of improving student learning outcomes and supporting parent choice. To be eligible for NSW Government funding, non‑government schools must be registered with the NSW Education Standards Authority (NESA) and not operate 'for profit' as per section 83C of the NSW Education Act 1990 (the Act). Non‑government schools can either be registered as independent or part of a System Authority.

In 2017–18, non‑government schools in NSW will receive over $1.2 billion from the NSW Government, as well as $3.4 billion from the Australian Government. Recently, the Australian Government has changed the way it funds schools. The NSW Government is assessing how these changes will impact State funding for non‑government schools.

This audit assessed how effectively and efficiently NSW Government grants to non‑government schools are allocated and managed. This audit did not assess the use of NSW Government grants by individual non‑government schools or System Authorities because the Auditor‑General of New South Wales does not have the mandate to assess how government funds are spent by non‑government entities.

Conclusion

The Department of Education effectively and efficiently allocates grants to non‑government schools. Clarifying the objectives of grants, monitoring progress towards these objectives, and improving oversight, would strengthen accountability for the use of public funds by non‑government schools.

We tested a sample of grants provided to non‑government schools under all major schemes, and found that the Department of Education consistently allocates and distributes grants in line with its methodology. The Department has clear processes and procedures to efficiently collect data from schools, calculate the level of funding each school or System should receive, obtain appropriate approvals, and make payments.

We identified three areas where the Department could strengthen its management of grants to provide greater accountability for the use of public funds. First, the Department’s objectives for providing grants to non‑government schools are covered by legislation, intergovernmental agreements and grant guidelines. The Department could consolidate these objectives to allow for more consistent monitoring. Second, the Department relies on schools or System Authorities to engage a registered auditor to certify the accuracy of information on their enrolments and usage of grants. Greater scrutiny of the registration and independence of the auditors would increase confidence in the accuracy of this information. Third, the Department does not monitor how System Authorities reallocate grant funding to their member schools. Further oversight in this area would increase accountability for the use of public funds.

The Department effectively and efficiently allocates grants to non‑government schools. Strengthening its processes would provide greater assurance that the information it collects is accurate.

The Department provides clear guidelines to assist schools to provide the necessary census information to calculate per capita grants. Schools must get an independent external auditor, registered with ASIC, to certify their enrolment figures. The Department checks a sample of the auditors to ensure that they are registered with ASIC. Some other jurisdictions perform additional procedures to increase confidence in the accuracy of the census (for example, independently checking a sample of schools’ census data).

The Department accurately calculates and distributes per capita grants in accordance with its methodology. The previous methodology, used prior to 2018, was not updated frequently enough to reflect changes in schools' circumstances. Over 2014 to 2017, the Department provided additional grants to non‑government schools under the National Education Reform Agreement (NERA), to bring funding more closely in line with the Australian Department of Education and Training's Schooling Resource Standard (SRS). From 2018, the Department has changed the way it calculates per capita grants to more closely align with the Australian Department of Education and Training's approach.

The Department determines eligibility for grants by checking a school's registration status with NESA. However, NESA's approach to monitoring compliance with the registration requirements prioritises student learning and wellbeing requirements over the requirement for policies and procedures for proper governance. Given their importance to the appropriate use of government funding, NESA could increase its monitoring of policies and procedures for proper governance through its program of random inspections. Further, the Department and NESA should enter into a formal agreement to share information to more accurately determine the level of risk of non‑compliance at each school. This may help both agencies more effectively target their monitoring to higher‑risk schools.

By December 2018, the NSW Department of Education should:

  1. Strengthen its processes to provide greater assurance that the enrolment and expenditure information it collects from non‑government schools is accurate. This should build on the work the Australian Government already does in this area.
  2. Establish formal information‑sharing arrangements with the NSW Education Standards Authority to more effectively monitor schools' eligibility to receive funding.
     

By December 2018, the NSW Education Standards Authority should:

  1. Extend its inspection practices to increase coverage of the registration requirement for policies and procedures for the proper governance of schools.
  2. Establish formal information‑sharing arrangements with the NSW Department of Education to more effectively monitor schools' continued compliance with the registration requirements.

The Department’s current approach to managing grants to non‑government schools could be improved to provide greater confidence that funds are being spent in line with the objectives of the grant schemes.

The NSW Government provides funding to non‑government schools to improve student learning outcomes, and to support schooling choices by parents, but does not monitor whether these grants are achieving this. In addition, each grant program has specific objectives. The main objectives for the per capita grant program is to increase the rate of students completing Year 12 (or equivalent), and to improve education outcomes for students. While non‑government schools publicly report on some educational measures via the MySchool website, these measures do not address all the objectives. Strengthened monitoring and reporting of progress towards objectives, at a school level, would increase accountability for public funding. This may require the Department to formalise its access to student level information.

The Department has listed five broad categories of acceptable use for per capita grants, however, provides no further guidance on what expenditure would fit into these categories. Clarifying the appropriate use of grants would increase confidence that funding is being used as intended. Schools must engage an independent auditor, registered with ASIC, to certify that the funding has been spent. The Department could strengthen this approach by improving its processes to check the registration of the auditor, and to verify their independence.

The Department has limited oversight of funding provided to System Authorities (Systems). The Department provides grants to Systems for all their member schools. The Systems can distribute the grants to their schools according to their own methodology. Systems are not required to report to the Department how much of their grant was retained for administrative or centralised expenses. Increased oversight over how the Systems distribute this grant could provide increased transparency for the use of public funds by systems.

By December 2018, the NSW Department of Education should:

  1. Establish and communicate funding conditions that require funded schools to:
    • adhere to conditions of funding, such as the acceptable use of grants, and accounting requirements to demonstrate compliance
    • report their progress towards the objectives of the scheme or wider Government initiatives
    • allow the Department to conduct investigations to verify enrolment and expenditure of funds
    • provide the Department with access to existing student level data to inform policy development and analysis.
  1. Increase its oversight of System Authorities by requiring them to:
    • re‑allocate funds across their system on a needs basis, and report to the Department on this
    • provide a yearly submission with enough detail to demonstrate that each System school has spent their State funding in line with the Department's requirements.

Published

Actions for Managing risks in the NSW public sector: risk culture and capability

Managing risks in the NSW public sector: risk culture and capability

Finance
Health
Justice
Treasury
Internal controls and governance
Management and administration
Risk
Workforce and capability

The Ministry of Health, NSW Fair Trading, NSW Police Force, and NSW Treasury Corporation are taking steps to strengthen their risk culture, according to a report released today by the Auditor-General, Margaret Crawford. 'Senior management communicates the importance of managing risk to their staff, and there are many examples of risk management being integrated into daily activities', the Auditor-General said.

We did find that three of the agencies we examined could strengthen their culture so that all employees feel comfortable speaking openly about risks. To support innovation, senior management could also do better at communicating to their staff the levels of risk they are willing to accept.

Effective risk management is essential to good governance, and supports staff at all levels to make informed judgements and decisions. At a time when government is encouraging innovation and exploring new service delivery models, effective risk management is about seizing opportunities as well as managing threats.

Over the past decade, governments and regulators around the world have increasingly turned their attention to risk culture. It is now widely accepted that organisational culture is a key element of risk management because it influences how people recognise and engage with risk. Neglecting this ‘soft’ side of risk management can prevent institutions from managing risks that threaten their success and lead to missed opportunities for change, improvement or innovation.

This audit assessed how effectively NSW Government agencies are building risk management capabilities and embedding a sound risk culture throughout their organisations. To do this we examined whether:

  • agencies can demonstrate that senior management is committed to risk management
  • information about risk is communicated effectively throughout agencies
  • agencies are building risk management capabilities.

The audit examined four agencies: the Ministry of Health, the NSW Fair Trading function within the Department of Finance, Services and Innovation, NSW Police Force and NSW Treasury Corporation (TCorp). NSW Treasury was also included as the agency responsible for the NSW Government's risk management framework.

Conclusion
All four agencies examined in the audit are taking steps to strengthen their risk culture. In these agencies, senior management communicates the importance of managing risk to their staff. They have risk management policies and funded central functions to oversee risk management. We also found many examples of risk management being integrated into daily activities.
That said, three of the four case study agencies could do more to understand their existing risk culture. As good practice, agencies should monitor their employees’ attitude to risk. Without a clear understanding of how employees identify and engage with risk, it is difficult to tell whether the 'tone' set by the executive and management is aligned with employee behaviours.
Our survey of risk culture found that three agencies could strengthen a culture of open communication, so that all employees feel comfortable speaking openly about risks. To support innovation, senior management could also do better at communicating to their staff the levels of risk they are willing to accept.
Some agencies are performing better than others in building their risk capabilities. Three case study agencies have reviewed the risk-related skills and knowledge of their workforce, but only one agency has addressed the gaps the review identified. In three agencies, staff also need more practical guidance on how to manage risks that are relevant to their day-to-day responsibilities.
NSW Treasury provides agencies with direction and guidance on risk management through policy and guidelines. Its principles-based approach to risk management is consistent with better practice. Nevertheless, there is scope for NSW Treasury to develop additional practical guidance and tools to support a better risk culture in the NSW public sector. NSW Treasury should encourage agency heads to form a view on the current risk culture in their agencies, identify desirable changes to that risk culture, and take steps to address those changes. 

In assessing an agency’s risk culture, we focused on four key areas:

Executive sponsorship (tone at the top)

In the four agencies we reviewed, senior management is communicating the importance of managing risk. They have endorsed risk management frameworks and funded central functions tasked with overseeing risk management within their agencies.

That said, we found that three case study agencies do not measure their existing risk culture. Without clear measures of how employees identify and engage with risk, it is difficult for agencies to tell whether employee's behaviours are aligned with the 'tone' set by the executive and management.

For example, in some agencies we examined we found a disconnect between risk tolerances espoused by senior management and how these concepts were understood by staff.

Employee perceptions of risk management

Our survey of staff indicated that while senior leaders have communicated the importance of managing risk, more could be done to strengthen a culture of open communication so that all employees feel comfortable speaking openly about risks. We found that senior management could better communicate to their staff the levels of risk they should be willing to accept.

Integration of risk management into daily activities and links to decision-making

We found examples of risk management being integrated into daily activities. On the other hand, we also identified areas where risk management deviated from good practice. For example, we found that corporate risk registers are not consistently used as a tool to support decision-making.

Support and guidance to help staff manage risks

Most case study agencies are monitoring risk-related skills and knowledge of their workforce, but only one agency has addressed the gaps it identified. While agencies are providing risk management training, surveyed staff in three case study agencies reported that risk management training is not adequate.

NSW Treasury provides agencies with direction and guidance on risk management through policy and guidelines. In line with better practice, NSW Treasury's principles-based policy acknowledges that individual agencies are in a better position to understand their own risks and design risk management frameworks that address those risks. Nevertheless, there is scope for NSW Treasury to refine its guidance material to support a better risk culture in the NSW public sector.

Recommendation

By May 2019, NSW Treasury should:

  • Review the scope of its risk management guidance, and identify additional guidance, training or activities to improve risk culture across the NSW public sector. This should focus on encouraging agency heads to form a view on the current risk culture in their agencies, identify desirable changes to that risk culture, and take steps to address those changes.

Published

Actions for Detecting and responding to cyber security incidents

Detecting and responding to cyber security incidents

Finance
Cyber security
Information technology
Internal controls and governance
Management and administration
Workforce and capability

A report released today by the Auditor-General for New South Wales, Margaret Crawford, found there is no whole-of-government capability to detect and respond effectively to cyber security incidents. There is very limited sharing of information on incidents amongst agencies, and some agencies have poor detection and response practices and procedures.

The NSW Government relies on digital technology to deliver services, organise and store information, manage business processes, and control critical infrastructure. The increasing global interconnectivity between computer networks has dramatically increased the risk of cyber security incidents. Such incidents can harm government service delivery and may include the theft of information, denial of access to critical technology, or even the hijacking of systems for profit or malicious intent.

This audit examined cyber security incident detection and response in the NSW public sector. It focused on the role of the Department of Finance, Services and Innovation (DFSI), which oversees the Information Security Community of Practice, the Information Security Event Reporting Protocol, and the Digital Information Security Policy (the Policy).

The audit also examined ten case study agencies to develop a perspective on how they detect and respond to incidents. We chose agencies that are collectively responsible for personal data, critical infrastructure, financial information and intellectual property.

Conclusion
There is no whole‑of‑government capability to detect and respond effectively to cyber security incidents. There is limited sharing of information on incidents amongst agencies, and some of the agencies we reviewed have poor detection and response practices and procedures. There is a risk that incidents will go undetected longer than they should, and opportunities to contain and restrict the damage may be lost.
Given current weaknesses, the NSW public sector’s ability to detect and respond to incidents needs to improve significantly and quickly. DFSI has started to address this by appointing a Government Chief Information Security Officer (GCISO) to improve cyber security capability across the public sector. Her role includes coordinating efforts to increase the NSW Government’s ability to respond to and recover from whole‑of‑government threats and attacks.

Some of our case study agencies had strong processes for detection and response to cyber security incidents but others had a low capability to detect and respond in a timely way.

Most agencies have access to an automated tool for analysing logs generated by their IT systems. However, coverage of these tools varies. Some agencies do not have an automated tool and only review logs periodically or on an ad hoc basis, meaning they are less likely to detect incidents.

Few agencies have contractual arrangements in place for IT service providers to report incidents to them. If a service provider elects to not report an incident, it will delay the agency’s response and may result in increased damage.

Most case study agencies had procedures for responding to incidents, although some lack guidance on who to notify and when. Some agencies do not have response procedures, limiting their ability to minimise the business damage that may flow from a cyber security incident. Few agencies could demonstrate that they have trained their staff on either incident detection or response procedures and could provide little information on the role requirements and responsibilities of their staff in doing so.

Most agencies’ incident procedures contain limited information on how to report an incident, who to report it to, when this should occur and what information should be provided. None of our case study agencies’ procedures mentioned reporting to DFSI, highlighting that even though reporting is mandatory for most agencies their procedures do not require it.

Case study agencies provided little evidence to indicate they are learning from incidents, meaning that opportunities to better manage future incidents may be lost.

Recommendations

The Department of Finance, Services and Innovation should:

  • assist agencies by providing:
    • better practice guidelines for incident detection, response and reporting to help agencies develop their own practices and procedures
    • training and awareness programs, including tailored programs for a range of audiences such as cyber professionals, finance staff, and audit and risk committees
    • role requirements and responsibilities for cyber security across government, relevant to size and complexity of each agency
    • a support model for agencies that have limited detection and response capabilities
       
  • revise the Digital Information Security Policy and Information Security Event Reporting Protocol by
    • clarifying what security incidents must be reported to DFSI and when
    • extending mandatory reporting requirements to those NSW Government agencies not currently covered by the policy and protocol, including State owned corporations.

DFSI lacks a clear mandate or capability to provide effective detection and response support to agencies, and there is limited sharing of information on cyber security incidents.

DFSI does not currently have a clear mandate and the necessary resources and systems to detect, receive, share and respond to cyber security incidents across the NSW public sector. It does not have a clear mandate to assess whether agencies have an acceptable detection and response capability. It is aware of deficiencies in agencies and across whole‑of‑government, and has begun to conduct research into this capability.

Intelligence gathering across the public sector is also limited, meaning agencies may not respond to threats in a timely manner. DFSI has not allocated resources for gathering of threat intelligence and communicating it across government, although it has begun to build this capacity.

Incident reporting to DFSI is mandatory for most agencies, however, most of our case study agencies do not report incidents to DFSI, reducing the likelihood of containing an incident if it spreads to other agencies. When incidents have been reported, DFSI has not provided dedicated resources to assess them and coordinate the public sector’s response. There are currently no formal requirements for DFSI to respond to incidents and no guidance on what it is meant to do if an incident is reported. The lack of central coordination in incident response risks delays and increased damage to multiple agencies.

DFSI's reporting protocol is weak and does not clearly specify what agencies should report and when. This makes agencies less likely to report incidents. The lack of a standard format for incident reporting and a consistent method for assessing an incident, including the level of risk associated with it, also make it difficult for DFSI to determine an appropriate response.

There are limited avenues for sharing information amongst agencies after incidents have been resolved, meaning the public sector may be losing valuable opportunities to improve its protection and response.

Recommendations

The Department of Finance, Services and Innovation should:

  • develop whole‑of‑government procedure, protocol and supporting systems to effectively share reported threats and respond to cyber security incidents impacting multiple agencies, including follow-up and communicating lessons learnt
  • develop a means by which agencies can report incidents in a more effective manner, such as a secure online template, that allows for early warnings and standardised details of incidents and remedial advice
  • enhance NSW public sector threat intelligence gathering and sharing including formal links with Australian Government security agencies, other states and the private sector
  • direct agencies to include standard clauses in contracts requiring IT service providers report all cyber security incidents within a reasonable timeframe
  • provide assurance that agencies have appropriate reporting procedures and report to DFSI as required by the policy and protocol by:
    • extending the attestation requirement within the DISP to cover procedures and reporting
    • reviewing a sample of agencies' incident reporting procedures each year.

Published

Actions for Internal Controls and Governance 2017

Internal Controls and Governance 2017

Finance
Education
Community Services
Health
Justice
Whole of Government
Asset valuation
Compliance
Cyber security
Information technology
Internal controls and governance
Project management
Risk

Agencies need to do more to address risks posed by information technology (IT).

Effective internal controls and governance systems help agencies to operate efficiently and effectively and comply with relevant laws, standards and policies. We assessed how well agencies are implementing these systems, and highlighted opportunities for improvement.
 

1. Overall trends

New and repeat findings

The number of reported financial and IT control deficiencies has fallen, but many previously reported findings remain unresolved.

High risk findings

Poor systems implementations contributed to the seven high risk internal control deficiencies that could affect agencies.

Common findings

Poor IT controls are the most commonly reported deficiency across agencies, followed by governance issues relating to cyber security, capital projects, continuous disclosure, shared services, ethics and risk management maturity.

2. Information Technology

IT security

Only two-thirds of agencies are complying with their own policies on IT security. Agencies need to tighten user access and password controls.

Cyber security

Agencies do not have a common view on what constitutes a cyber attack, which limits understanding the extent of the cyber security threat.

Other IT systems

Agencies can improve their disaster recovery plans and the change control processes they use when updating IT systems.

3. Asset Management

Capital investment

Agencies report delays delivering against the significant increase in their budgets for capital projects.

Capital projects

Agencies are underspending their capital budgets and some can improve capital project governance.

Asset disposals

Eleven per cent of agencies were required to sell their real property through Property NSW but didn’t. And eight per cent of agencies can improve their asset disposal processes.

4. Governance

Governance arrangements

Sixty-four per cent of agencies’ disclosure policies support communication of key performance information and prompt public reporting of significant issues.

Shared services

Fifty-nine per cent of agencies use shared services, yet 14 per cent do not have service level agreements in place and 20 per cent can strengthen the performance standards they set.

5. Ethics and Conduct

Ethical framework

Agencies can reinforce their ethical frameworks by updating code‑of‑conduct policies and publishing a Statement of Business Ethics.

Conflicts of interest

All agencies we reviewed have a code of conduct, but they can still improve the way they update and manage their codes to reduce the risk of fraud and unethical behaviour.

6. Risk Management 

Risk management maturity

All agencies have implemented risk management frameworks, but with varying levels of maturity.

Risk management elements

Many agencies can improve risk registers and strengthen their risk culture, particularly in the way that they report risks to their lead agency.

This report covers the findings and recommendations from our 2016–17 financial audits related to the internal controls and governance of the 39 largest agencies (refer to Appendix three) in the NSW public sector. These agencies represent about 95 per cent of total expenditure for all NSW agencies and were considered to be a large enough group to identify common issues and insights.

The findings in this report should not be used to draw conclusions on the effectiveness of individual agency control environments and governance arrangements. Specific financial reporting, controls and service delivery comments are included in the individual 2017 cluster financial audit reports tabled in Parliament from October to December 2017.

This new report offers strategic insight on the public sector as a whole

In previous years, we have commented on internal control and governance issues in the volumes we published on each ‘cluster’ or agency sector, generally between October and December. To add further value, we then commented more broadly about the issues identified for the public sector as a whole at the start of the following year.

This year, we have created this report dedicated to internal controls and governance. This will help Parliament to understand broad issues affecting the public sector, and help agencies to compare their own performance against that of their peers.

Without strong control measures and governance systems, agencies face increased risks in their financial management and service delivery. If they do not, for example, properly authorise payments or manage conflicts of interest, they are at greater risk of fraud. If they do not have strong information technology (IT) systems, sensitive and trusted information may be at risk of unauthorised access and misuse.

These problems can in turn reduce the efficiency of agency operations, increase their costs and reduce the quality of the services they deliver.

Our audits do not review every control or governance measure every year. We select a range of measures, and report on those that present the most significant risks that agencies should mitigate. This report divides these into the following six areas:

  1. Overall trends
  2. Information technology
  3. Asset management
  4. Governance
  5. Ethics and conduct
  6. Risk management.

Internal controls are processes, policies and procedures that help agencies to:

  • operate effectively and efficiently
  • produce reliable financial reports
  • comply with laws and regulations.

This chapter outlines the overall trends for agency controls and governance issues, including the number of findings, level of risk and the most common deficiencies we found across agencies. The rest of this volume then illustrates this year’s controls and governance findings in more detail.

Issues

Recommendations

1.1 New and repeat findings

The number of internal control deficiencies reduced over the past three years, but new higher-risk information technology (IT) control deficiencies were reported in 2016–17.

Deficiencies repeated from previous years still make up a sizeable proportion of all internal control deficiencies.

Recommendation

Agencies should focus on emerging IT risks, but also manage new IT risks, reduce existing IT control deficiencies, and address repeat internal control deficiencies on a more timely basis.

1.2 High risk findings

We found seven high risk internal control deficiencies, which might significantly affect agencies.

Recommendation

Agencies should rectify high risk internal control deficiencies as a priority

1.3 Common findings

The most common internal control deficiencies related to poor or absent IT controls.

We found some common governance deficiencies across multiple agencies.

Recommendation

Agencies should coordinate actions and resources to help rectify common IT control and governance deficiencies.

Information technology (IT) has become increasingly important for government agencies’ financial reporting and to deliver their services efficiently and effectively. Our audits reviewed whether agencies have effective controls in place over their IT systems. We found that IT security remains the source of many control weakness in agencies.

Issues Recommendations

2.1 IT security

User access administration

While 95 per cent of agencies have policies about user access, about two-thirds were compliant with these policies. Agencies can improve how they grant, change and end user access to their systems.

Recommendation

Agencies should strengthen user access administration to prevent inappropriate access to sensitive systems. Agencies should:

  • establish and enforce clear policies and procedures
  • review user access regularly
  • remove user access for terminated staff promptly
  • change user access for transferred staff promptly.

Privileged access

Sixty-eight per cent of agencies do not adequately manage who can access their information systems, and many do not sufficiently monitor or restrict privileged access.

Recommendation

Agencies should tighten privileged user access to protect their information systems and reduce the risks of data misuse and fraud. Agencies should ensure they:

  • only grant privileged access in line with the responsibilities of a position
  • review the level of access regularly
  • limit privileged access to necessary functions and data
  • monitor privileged user account activity on a regular basis.

Password controls

Forty-one per cent of agencies did not meet either their own standards or minimum standards for password controls.

Recommendation

Agencies should review and enforce password controls to strengthen security over sensitive systems. As a minimum, password parameters should include:

  • minimum password lengths and complexity requirements
  • limits on the number of failed log-in attempts
  • password history (such as the number of passwords remembered)
  • maximum and minimum password ages.

2.2 Cyber Security

Cyber security framework

Agencies do not have a common view on what constitutes a cyber attack, which limits understanding the extent of the cyber security threat.

Recommendation

The Department of Finance, Services and Innovation should revisit its existing framework to develop a shared cyber security terminology and strengthen the current reporting requirements for cyber incidents.

Cyber security strategies

While 82 per cent of agencies have dedicated resources to address cyber security, they can strengthen their strategies, expertise and staff awareness.

Recommendations

The Department of Finance, Services and Innovation should:

  • mandate minimum standards and require agencies to regularly assess and report on how well they mitigate cyber security risks against these standards
  • develop a framework that provides for cyber security training.

Agencies should ensure they adequately resource staff dedicated to cyber security.

2.3 Other IT systems

Change control processes

Some agencies need to improve change control processes to avoid unauthorised or inaccurate system changes.

Recommendation

Agencies should consistently perform user acceptance testing before system upgrades and changes. They should also properly approve and document changes to IT systems.

Disaster recovery planning

Agencies can do more to adequately assess critical business systems to enforce effective disaster recovery plans. This includes reviewing and testing their plans on a timely basis.

Recommendation

Agencies should complete business impact analyses to strengthen disaster recovery plans, then regularly test and update their plans.

Agency service delivery relies on developing and renewing infrastructure assets such as schools, hospitals, roads, or public housing. Agencies are currently investing significantly in new assets. Agencies need to manage the scale and volume of current capital projects in order to deliver new infrastructure on time, on budget and realise the intended benefits. We found agencies can improve how they:

  • manage their major capital projects
  • dispose of existing assets.
Issues Recommendations or conclusions

3.1 Capital investment

Capital asset investment ratios

Most agencies report high capital investment ratios, but one-third of agencies’ capital investment ratios are less than one.

Recommendation

Agencies with high capital asset investment ratios should ensure their project management and delivery functions have the capacity to deliver their current and forward work programs.

Volume of capital spending

Most agencies have significant forward spending commitments for capital projects. However, agencies’ actual capital expenditure has been below budget for the last three years.

Conclusion

The significant increase in capital budget underspends warrant investigation, particularly where this has resulted from slower than expected delivery of projects from previous years.

3.2 Capital projects

Major capital projects

Agencies’ major capital projects were underspent by 13 percent against their budgets.

Conclusion

The causes of agency budget underspends warrant investigation to ensure the NSW Government’s infrastructure commitment is delivered on time.

Capital project governance

Agencies do not consistently prepare business cases or use project steering committees to oversee major capital projects.

Conclusion

Agencies that have project management processes that include robust business cases and regular updates to their steering committees (or equivalent) are better able to provide those projects with strategic direction and oversight.

3.3. Asset disposals

Asset disposal procedures

Agencies need to strengthen their asset disposal procedures.

Recommendations

Agencies should have formal processes for disposing of surplus properties.

Agencies should use Property NSW to manage real property sales unless, as in the case for State owned corporations, they have been granted an exemption.

Governance refers to the high-level frameworks, processes and behaviours that help an organisation to achieve its objectives, comply with legal and other requirements, and meet a high standard of probity, accountability and transparency.

This chapter sets out the governance lighthouse model the Audit Office developed to help agencies reach best practice. It then focuses on two key areas: continuous disclosure and shared services arrangements. The following two chapters look at findings related to ethics and risk management.

Issues Recommendations or conclusions

4.1 Governance arrangements

Continuous disclosure

Continuous disclosure promotes improved performance and public trust and aides better decision-making. Continuous disclosure is only mandatory for NSW Government Businesses such as State owned corporations.

Conclusion

Some agencies promote transparency and accountability by publishing on their websites a continuous disclosure policy that provides for, and encourages:

  • regular public disclosure of key performance information
  • disclosure of both positive and negative information
  • prompt reporting of significant issues.

4.2 Shared services

Service level agreements

Some agencies do not have service level agreements for their shared service arrangements.

Many of the agreements that do exist do not adequately specify controls, performance or reporting requirements. This reduces the effectiveness of shared services arrangements.

Conclusion

Agencies are better able to manage the quality and timeliness of shared service arrangements where they have a service level agreement in place. Ideally, the terms of service should be agreed before services are transferred to the service provider and:

  • specify the controls a provider must maintain
  • specify key performance targets
  • include penalties for non-compliance.

Shared service performance

Some agencies do not set performance standards for their shared service providers or regularly review performance results.

Conclusion

Agencies can achieve better results from shared service arrangements when they regularly monitor the performance of shared service providers using key measures for the benefits realised, costs saved and quality of services received.

Before agencies extend or renegotiate a contract, they should comprehensively assess the services received and test the market to maximise value for money.

All government sector employees must demonstrate the highest levels of ethical conduct, in line with standards set by The Code of Ethics and Conduct for NSW government sector employees.

This chapter looks at how well agencies are managing these requirements, and where they can improve their policies and processes.

We found that agencies mostly have the appropriate codes, frameworks and policies in place. But we have highlighted opportunities to improve the way they manage those systems to reduce the risks of unethical conduct.

Issues Recommendations or conclusions

5.1 Ethical framework

Code of conduct

All agencies we reviewed have a code of conduct, but they can still improve the way they update and manage their codes to reduce the risk of fraud and unethical behaviour.

Recommendation

Agencies should regularly review their code-of-conduct policies and ensure they keep their codes of conduct up-to-date.

Statement of business ethics

Most agencies maintain an ethical framework, but some can enhance their related processes, particularly when dealing with external clients, customers, suppliers and contractors.

Conclusion

Agencies can enhance their ethical frameworks by publishing a Statement of Business Ethics, which communicates their values and culture.

5.2 Potential conflicts of interest

Conflicts of interest

All agencies have a conflicts-of-interest policy, but most can improve how they identify, manage and avoid conflicts of interest.

Recommendation

Agencies should improve the way they manage conflicts of interest, particularly by:

  • requiring senior executives to make a conflict-of-interest declaration at least annually
  • implementing processes to identify and address outstanding declarations
  • providing annual training to staff
  • maintaining current registers of conflicts of interest.

Gifts and benefits

While all agencies already have a formal gifts-and-benefits policy, we found gaps in the management of gifts and benefits by some that increase the risk of unethical conduct.

Recommendation

Agencies should improve the way they manage gifts and benefits by promptly updating registers and providing annual training to staff.

Risk management is an integral part of effective corporate governance. It helps agencies to identify, assess and prioritise the risks they face and in turn minimise, monitor and control the impact of unforeseen events. It also means agencies can respond to opportunities that may emerge and improve their services and activities.

This year we looked at the overall maturity of the risk management frameworks that agencies use, along with two important risk management elements: risk culture and risk registers.

Issues Recommendations or conclusions

6.1 Risk management maturity

All agencies have implemented risk management frameworks, but with varying levels of maturity in their application.

Agencies’ averaged a score of 3.1 out of five across five critical assessment criteria for risk management. While strategy and governance fared best, the areas that most need to improve are risk culture, and systems and intelligence.

Conclusion

Agencies have introduced risk management frameworks and practices as required by the Treasury’s:

  • 'Risk Management Toolkit for the NSW Public Sector'
  • 'Internal Audit and Risk Management Policy for the NSW Public Sector'.

However, more can be done to progress risk management maturity and embed risk management in agency culture.

6.2 Risk management elements

Risk culture

Most agencies have started to embed risk management into the culture of their organisation. But only some have successfully done so, and most agencies can improve their risk culture.

 

 

Conclusion

Agencies can improve their risk culture by:

  • setting an appropriate tone from the top
  • training all staff in effective risk management
  • ensuring desired risk behaviours and culture are supported, monitored, and reinforced through business plans, or the equivalent and employees' performance assessments.

Risk registers and reporting

Some agencies do not report their significant risks to their lead agency, which may impair the way resources are allocated in their cluster. Some agencies do not integrate risk registers at a divisional and whole-of-enterprise level.

Conclusion

Agencies not reporting significant risks at the cluster level increases the likelihood that significant risks are not being mitigated appropriately.

Effective risk management can improve agency decision-making, protect reputations and lead to significant efficiencies and cost savings. By embedding risk management directly into their operations, agencies can also derive extra value for their activities and services.

Published

Actions for Report on Education 2017

Report on Education 2017

Education
Financial reporting
Internal controls and governance
Management and administration
Procurement
Project management
Workforce and capability

The Auditor-General, Margaret Crawford released her report on the results of the financial audits of agencies in the Education cluster. The report focuses on key observations and findings from the most recent audits of these agencies.

'I am pleased to report that unqualified audit opinions were issued on the financial statements for all agencies in the Education cluster', the Auditor-General said. 'The quality and timeliness of financial reporting remains strong'.

Published

Actions for Managing demand for ambulance services 2017

Managing demand for ambulance services 2017

Health
Information technology
Management and administration
Risk
Service delivery
Shared services and collaboration
Workforce and capability

NSW Ambulance has introduced several initiatives over the past decade to better manage the number of unnecessary ambulance responses and transports to hospital emergency departments. However, there is no overall strategy to guide the development of these initiatives nor do NSW Ambulance's data systems properly monitor their impact. As a result, the Audit Office was unable to assess whether NSW Ambulance's approach to managing demand is improving the efficiency of ambulance services.

Demand for ambulance services is increasing. Demographic factors including population growth and ageing have contributed to this and ongoing growth in demand is likely. It is important that NSW Ambulance finds ways to respond to this demand more efficiently, while maintaining patient safety standards and meeting community expectations.

Most triple zero calls to NSW Ambulance do not involve medical issues that require an emergency response. NSW Ambulance has introduced a range of initiatives to change the way it manages these less urgent requests for assistance. Its major demand management initiatives include using a telephone advice line, referring some patients to services other than hospital emergency departments and using specialist paramedics to respond to less urgent cases.

The role of NSW Ambulance has changed in recent years. It is aiming to become a ‘mobile health service’ that identifies the needs of patients and provides or refers them to the most appropriate type of care. This change involves a significant expansion of the clinical decision-making role of paramedics. Considerable strategic and organisational efforts are required to make this work. The successful implementation of demand management initiatives is important to NSW Ambulance's ability to continue to meet demand for its services.

This audit assessed NSW Ambulance's major demand management initiatives that aim to reduce unnecessary demand for ambulance responses and unnecessary transport to hospital emergency departments. It aimed to assess the extent to which these initiatives have improved the efficiency of its services.

Conclusion

NSW Ambulance has introduced several initiatives that aim to manage demand for its services from less urgent cases more efficiently. There is no overall strategy for these initiatives and NSW Ambulance’s data systems do not measure their outputs or outcomes. As a result, we are unable to assess the impact of NSW Ambulance's demand management initiatives on the efficiency of ambulance services. More focus is needed to ensure these initiatives achieve the efficiency improvements necessary to help NSW Ambulance meet future increases in demand.

Increasing demand for ambulance services is a key issue for NSW Ambulance. Demand has increased at a faster rate than population growth in recent years and continued growth is expected. NSW Ambulance has introduced several initiatives that aim to manage demand for its services from people with less urgent medical issues more efficiently and align its approach with the rest of the health system in New South Wales.

These individual initiatives lack a broader strategy to guide their development. NSW Ambulance’s demand management initiatives also lack clear goals and performance targets, with insufficient organisational resources allocated to support their implementation. NSW Ambulance does not have a data system that allows it to conduct accurate routine monitoring of the activity and performance of these initiatives.

More effort is required to make demand management initiatives a core part of NSW Ambulance's work. Key relationships with other health services to support demand management initiatives have only recently been established. NSW Ambulance has not communicated proactively with the public about its demand management initiatives. To ensure paramedics are as well prepared as possible for their expanded roles, they need better professional development and up to date technology.

Demand for ambulance services in New South Wales is increasing steadily. Forecast future increases in demand due to population growth and ageing mean that NSW Ambulance must improve its efficiency to maintain its performance.

Demand for ambulance services is growing at a rate higher than population growth. The increase in demand is likely to continue as the population continues to grow and age. NSW Ambulance has made several recent changes to remove large parts of demand for its services, including moving non-emergency patient transport to a separate government agency and changing the way triple zero calls are categorised.

These changes were expected to improve emergency response time performance, but the anticipated improvements have not been achieved. If demand continues to increase as forecast, NSW Ambulance will need to find more efficient ways to manage demand to maintain its performance.

NSW Ambulance has introduced initiatives to change the way it manages demand from patients who have less urgent medical issues. These have the potential to achieve positive results, but we were unable to fully assess their impact because of weaknesses in data systems and monitoring. More needs to be done to demonstrate progress toward the efficiency improvements required.

NSW Ambulance uses a telephone referral system to manage triple zero calls from people with medical issues that do not require an ambulance. This has the potential to achieve efficiency improvements but there are weaknesses in NSW Ambulance's use and monitoring of this system. Paramedics are now able to make decisions about whether patients need transport to a hospital emergency department. NSW Ambulance does not routinely measure or monitor the decisions paramedics make, so it does not know whether these decisions are improving efficiency. Extended Care Paramedics who have additional skills in diagnosing and treating patients with less urgent medical issues were introduced in 2007. NSW Ambulance analysis indicates that these paramedics have the potential to improve efficiency, but have not been used as effectively as possible.

Our 2013 audit of NSW Ambulance found that accurate monitoring of activity and performance was not being conducted. More than four years later, this remains the case. 

NSW Ambulance has recognised the need to change the way it manages demand and has developed initiatives that have the potential to improve efficiency. However, there are significant weaknesses in the strategy for and implementation of its demand management initiatives.

NSW Ambulance has identified the goal of moving from an emergency transport provider to a mobile health service and developed several initiatives to support this. Its demand management initiatives have the potential to contribute to the broader policy directions for the health system in New South Wales. However, there is no clear overall strategy guiding these initiatives and their implementation has been poor.

NSW Ambulance's reasons for changing its approach to demand management have not been communicated proactively to the community. Demand management initiatives that have been operating for over a decade still do not have clear performance measures or targets. Project management of new initiatives has been inadequate, with insufficient organisational resources to oversee them and inadequate engagement with other healthcare providers.

NSW Ambulance uses an in-house Vocational Education and Training course to recruit some paramedics, as well as recruiting paramedics who have completed a university degree. No other Australian ambulance services continue to provide their own Vocational Education and Training qualifications. Paramedics will need more support in several key areas to be able to fulfil their expanded roles in providing a mobile health service. Performance and development systems for paramedics are not used effectively. Up to date technology would help paramedics make better decisions and improve NSW Ambulance's ability to monitor demand management activity.

There are gaps in NSW Ambulance's oversight of the risks of some of the initiatives it has introduced, particularly its lack of information on the outcomes for patients who are not transported to hospital. Weaknesses in the way NSW Ambulance uses its data limit its ability to properly assess the risks of the demand management initiatives it has introduced.

Appendix one - Response from agency

Appendix two - About the audit

Appendix three - Performance auditing

 

Parliamentary reference - Report number #295 - released 13 December 2017