Refine search Expand filter

Reports

Published

Actions for Integrity of data in the Births, Deaths and Marriages Register

Integrity of data in the Births, Deaths and Marriages Register

Justice
Premier and Cabinet
Whole of Government
Cyber security
Fraud
Information technology
Internal controls and governance
Management and administration

This report outlines whether the Department of Customer Service (the department) has effective controls in place to ensure the integrity of data in the Births, Deaths and Marriages Register (the register), and to prevent unauthorised access and misuse.

The audit found that the department has processes in place to ensure that the information entered in the register is accurate and that any changes to it are validated. Although there are controls in place to prevent and detect unauthorised access to, and activity in the register, there were significant gaps in these controls. Addressing these gaps is necessary to ensure the integrity of information in the register.

The Auditor-General made nine recommendations to the department, aimed at strengthening controls to prevent and detect unauthorised access to, and activity in the register. These included increased monitoring of individuals who have access to the register and strengthening security controls around the databases that contain the information in the register.

The NSW Registry of Births Deaths and Marriages is responsible for maintaining registers of births, deaths and marriages in New South Wales as well as registering adoptions, changes of names, changes of sex and relationships. Maintaining the integrity of this information is important as it is used to confirm people’s identity and unauthorised access to it can lead to fraud or identity theft.

Read full report (PDF)

The NSW Registry of Births Deaths and Marriages (BD&M) is responsible for maintaining registers of births, deaths and marriages in New South Wales. BD&M is also responsible for registering adoptions, changes of name, changes of sex and relationships. These records are collectively referred to as 'the Register'. The Births, Deaths and Marriages Registration Act 1995 (the BD&M Act) makes the Registrar (the head of BD&M) responsible for maintaining the integrity of the Register and preventing fraud associated with the Register. Maintaining the integrity of the information held in the Register is important as it is used to confirm people's identity. Unauthorised access to, or misuse of the information in the Register can lead to fraud or identity theft. For these reasons it is important that there are sufficient controls in place to protect the information.

BD&M staff access, add to and amend the Register through the LifeLink application. While BD&M is part of the Department of Customer Service, the Department of Communities and Justice (DCJ) manages the databases that contain the Register and sit behind LifeLink and is responsible for the security of these databases.

This audit assessed whether BD&M has effective controls in place to ensure the integrity of data in the Births, Deaths and Marriages Register, and to prevent unauthorised access and misuse. It addressed the following:

  • Are relevant process and IT controls in place and effective to ensure the integrity of data in the Register and the authenticity of records and documents?
  • Are security controls in place and effective to prevent unauthorised access to, and modification of, data in the Register?

Conclusion

BD&M has processes and controls in place to ensure that the information entered in the Register is accurate and that amendments to the Register are validated. BD&M also has controls in place to prevent and detect unauthorised access to, and activity in the Register. However, there are significant gaps in these controls. Addressing these gaps is necessary to ensure the integrity of the information in the Register.

BD&M has detailed procedures for all registrations and amendments to the Register, which include processes for entering, assessing and checking the validity and adequacy of source documents. Where BD&M staff have directly input all the data and for amendments to the Register, a second person is required to check all information that has been input before an event can be registered or an amendment can be made. BD&M carries out regular internal audits of all registration processes to check whether procedures are being followed and to address non-compliance where required.

BD&M authorises access to the Register and carries out regular access reviews to ensure that users are current and have the appropriate level of access. There are audit trails of all user activity, but BD&M does not routinely monitor these. At the time of the audit, BD&M also did not monitor activity by privileged users who could make unauthorised changes to the Register. Not monitoring this activity created a risk that unauthorised activity in the Register would not be detected.

BD&M has no direct oversight of the database environment which houses the Register and relies on DCJ's management of a third-party vendor to provide the assurance it needs over database security. The vendor operates an Information Security Management System that complies with international standards, but neither BD&M nor DCJ has undertaken independent assurance of the effectiveness of the vendor's IT controls.

Appendix one – Response from agency

Appendix two – About the audit

Appendix three – Performance auditing

 

Copyright notice

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

 

Parliamentary reference - Report number #330 - released 7 April 2020.

Published

Actions for Volume Nine 2011 focus on Education and Communities

Volume Nine 2011 focus on Education and Communities

Education
Community Services
Asset valuation
Internal controls and governance
Management and administration
Project management
Workforce and capability

The report includes comments on financial audits of government agencies in the Education and Communities sectors. The audits of the above entities’ financial statements for the year ended 30 June 2011 resulted in unmodified audit opinions within the Independent Auditor’s Reports. A key finding was that Treasury should consider issuing further guidance to arts and cultural bodies on collection valuation methodologies due to the significance of these assets to the State’s asset base.

Published

Actions for Volume Eight 2011 Focus on Transport and Ports

Volume Eight 2011 Focus on Transport and Ports

Transport
Industry
Asset valuation
Financial reporting
Fraud
Information technology
Infrastructure
Internal controls and governance
Management and administration
Procurement
Project management
Workforce and capability

The report includes comments on financial audits of government agencies in the Transport and Ports sectors. The audit of corporations’ financial statements for the year ended 30 June 2011 resulted in unmodified audit opinions within the Independent Auditor’s Reports. A key recommendation from the report is that Sydney Ports Corporation should continue working with other government authorities and industry stakeholders to improve the effectiveness of program initiatives for increasing container freight movements by rail. The Corporation should review the underlying causes hindering growth in the rail mode and develop and implement strategies to address the unfavourable trend.

Published

Actions for Responding to Domestic and Family Violence

Responding to Domestic and Family Violence

Community Services
Justice
Health
Internal controls and governance
Management and administration
Service delivery

Organisations generally work together to improve the safety of victims when there is an overt and serious crisis, particularly where children are involved. There are no standard ways for victims and perpetrators to access help that might prevent ongoing violence and address underlying issues. This is particularly problematic where there are repeat victims and perpetrators, many of whom have complex mental health, drug and alcohol problems and are difficult to work with. New South Wales has trialled a number of projects to improve the way that organisations work together to support vulnerable people in particular communities.

 

Parliamentary reference - Report number #218 - released 8 November 2011

Published

Actions for Solar Bonus Scheme

Solar Bonus Scheme

Premier and Cabinet
Compliance
Infrastructure
Management and administration
Project management
Regulation
Risk
Service delivery

A NSW Auditor General’s Report has found that the NSW Government and its agencies grossly underestimated the cost and number of people that would install systems under the Solar Bonus Scheme.

By October 2010, the estimated cost of the Scheme, if it continued the way it was going, would have reached $3.988 billion. More than ten times the original estimate of $362 million. In response to the increased cost, the gross tariff for new applicants was reduced from 60 to 20 cents reducing the estimated cost to $1.954 billion.

It was a statutory requirement that when 50 mega watts of installed capacity was reached, the Government would review the Scheme. By the time the review was completed the installed capacity had reached 101 mega watts.

Published

Actions for Prequalification Scheme: Performance and Management Services

Prequalification Scheme: Performance and Management Services

Premier and Cabinet
Finance
Compliance
Internal controls and governance
Management and administration
Regulation
Risk
Workforce and capability

There have been tangible improvements in the time it takes NSW Government agencies to engage consultants through the Government’s Prequalification Scheme. The Scheme was introduced in February 2008 to improve agencies’ procurement of consultants. More than 300 service providers have been prequalified and over $300 million worth of consultancy services have been provided. Ideally agencies should know what assignments each consultant has won, for what services, what their rates are and how well they have performed. Agencies should then be free to contact other agencies before engaging a consultant.

 

Parliamentary reference - Report number #216 - released 28 September 2011

Published

Actions for Government expenditure and transport planning in relation to implementing Barangaroo

Government expenditure and transport planning in relation to implementing Barangaroo

Industry
Treasury
Transport
Compliance
Internal controls and governance
Management and administration
Project management
Service delivery

Barangaroo is an ambitious and significant development on Government-owned Sydney Harbour foreshore. Construction on the 22 hectare CBD site is expected to take 12 years to 2023. Developer contributions to Government of $1 billion are to provide for public domain and other Government development costs, including a six hectare Headland Park. When completed the precinct is to service an anticipated 26,000 workers and residents and up to 33,000 visitors a day. The Auditor-General concluded that while there was extensive transport planning and extensive documentation supporting Government financial forecasts, considerable risks remain for the implementation of the Barangaroo project. 

 

Parliamentary reference - Report number #214 - released 15 June 2011

Published

Actions for Two Ways Together - NSW Aboriginal Affairs Plan

Two Ways Together - NSW Aboriginal Affairs Plan

Community Services
Premier and Cabinet
Internal controls and governance
Management and administration
Project management
Service delivery

To date the Two Ways Together Plan (the Plan) has not delivered the improvement in overall outcomes for Aboriginal people that was intended. Stronger partnerships between the government and Aboriginal people are only beginning to emerge. The disadvantage still experienced by some of the estimated 160,000 Aboriginal people in NSW is substantial. For example, the unemployment rate for Aboriginal people is at least three times higher than the rate for all NSW residents and hospital admissions for diabetes are also around three times higher.

 

Parliamentary reference - Report number #213 - released 18 May 2011

Published

Actions for Helping older people access a residential aged care facility

Helping older people access a residential aged care facility

Health
Community Services
Compliance
Internal controls and governance
Management and administration
Risk
Service delivery
Shared services and collaboration
Workforce and capability

Assessment processes for older people needing to go to an Residential Aged Care Facility (RACF) vary depending on the processes of the Aged Care Assessement Teams (ACAT) they see and whether or not they are in hospital. The data collected on ACAT performance was significantly revised during 2004 making comparisons with subsequent years problematic. ACATs have more responsibilities than assessing older people for residential care. It is not clear whether they have sufficient resources for this additional workload.

 

Parliamentary reference - Report number #160 - released 5 December 2006

Published

Actions for Condition of State Roads

Condition of State Roads

Transport
Infrastructure
Internal controls and governance
Management and administration
Procurement
Project management
Service delivery

The Roads and Traffic Authority (RTA) has improved the overall surface condition of State Roads in the last decade. Country road surfaces are now generally much better. Ride quality has improved and cracking has been reduced. The RTA has also achieved a substantial reduction in the number of structurally deficient bridges over the same period. 

Despite a significant increase in the State’s contribution to maintenance since 1999-2000, the RTA has deferred road rebuilding projects. The RTA is rebuilding at less than half its long term target, and has not met this target at any time this decade. The RTA has not identified how it will address deferred rebuilding, although it advises it is developing a new road network management plan which will address this.

 

Parliamentary reference - Report number #157 - released 16 August 2006