Refine search Expand filter

Reports

Published

Actions for Regional NSW 2023

Regional NSW 2023

Industry
Environment
Planning
Whole of Government
Asset valuation
Compliance
Cyber security
Financial reporting
Fraud
Information technology
Infrastructure
Procurement
Regulation
Risk
Service delivery
Shared services and collaboration

What this report is about

Results of the Regional NSW financial statements audits for the year ended 30 June 2023.

What we found

Unqualified audit opinions were issued on all completed audits in the Regional NSW portfolio agencies.

The number of monetary misstatements identified in our audits increased from 28 in 2021–22 to 30 in 2022–23.

What the key issues were

Effective 1 July 2023, staff employed in the Northern Rivers Reconstruction Corporation Division of the Department of Regional NSW transferred to the NSW Reconstruction Authority Staff Agency.

The Regional NSW portfolio agencies were migrated into a new government wide enterprise resourcing planning system.

The total number of audit management letter findings across the portfolio of agencies decreased from 36 to 23.

A high risk matter was raised for the NSW Food Authority to improve the internal controls in the information technology environment including monitoring and managing privilege user access.

What we recommended

Local Land Services should prioritise completing all mandatory early close procedures.

Portfolio agencies should:

  • ensure any changes to employee entitlements are assessed for their potential financial statements impact under the relevant Australian Accounting Standards
  • prioritise and address internal control deficiencies identified in audit management letters.

This report provides Parliament and other users of the Regional NSW portfolio of agencies financial statements with the results of our audits, analysis, conclusions and recommendations in the following areas:

  • financial reporting
  • audit observations.

Financial reporting is an important element of good governance. Confidence and transparency in public sector decision-making are enhanced when financial reporting is accurate and timely.

This chapter outlines our audit observations related to the financial reporting of agencies in the Regional NSW portfolio of agencies (the portfolio) for 2023.

Section highlights

  • Unqualified audit opinions were issued on all completed 30 June 2023 financial statements audits of the portfolio agencies. Two audits are ongoing.
  • The total number of errors (including corrected and uncorrected) in the financial statements increased compared to the prior year.
  • Portfolio agencies met the statutory deadline for submitting their 2022–23 early close financial statements and other mandatory procedures.
  • Portfolio agencies continue to provide financial assistance to communities affected by natural disasters.
  • A change to the NSW paid parental leave scheme, effective October 2023, created a new legal obligation that needed to be recognised by impacted government agencies. Impact to the agencies' financial statements were not material. 

 

Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies. They are essential for quality and timely decision-making.

This chapter outlines our observations and insights from our financial statement audits of agencies in the Regional NSW portfolio.

Section highlights

  • The 2022–23 audits identified one high risk and nine moderate risk issues across the portfolio. Of these, one was a moderate risk repeat issue.
  • The total number of findings decreased from 36 to 23 which mainly related to deficiencies in internal controls.
  • The high risk matter relates to the monitoring and managing of privilege user access at NSW Food Authority. 

 

Appendix one – Misstatements in financial statements submitted for audit

Appendix two – Early close procedures

Appendix three – Timeliness of financial reporting

Appendix four – Financial data

 

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Published

Actions for Customer Service 2023

Customer Service 2023

Finance
Asset valuation
Compliance
Financial reporting
Information technology
Internal controls and governance
Management and administration
Regulation
Risk
Service delivery
Shared services and collaboration

What this report is about

Result of the Customer Service portfolio agencies' financial statement audits for the year ended 30 June 2023.

What we found

Unmodified audit opinions were issued for all completed 30 June 2023 financial statements audits of Customer Service portfolio agencies. Two audits are ongoing.

What the key issues were

The total number of misstatements in the financial statements and findings reported to management decreased compared to the prior year.

For the first time since its establishment in 2015, GovConnect NSW received unqualified audit opinions for business process internal controls and information technology general controls managed by service providers.

The department controls Finance Co Trust (Fin Co), a special purpose trust created as part of its project to replace flammable cladding for eligible residential apartment buildings. Fin Co did not prepare financial statements which is a breach of the Government Sector Finance Act 2018 (GSF Act).

The department's land titling database was overstated by $42.5 million due to errors in the valuation model.

The New South Wales Government Telecommunications Authority corrected a prior period error of $10.2 million overstatement of property, plant and equipment.

A high-risk finding was reported to Service NSW regarding gaps in policies, systems and processes for administering and financial reporting on grant programs.

Recommendations were made to address these deficiencies.

This report provides Parliament and other users of the Customer Service portfolio of agencies’ financial statements with the results of our audits, analysis, conclusions and recommendations in the following areas:

  • financial reporting
  • audit observations.

Financial reporting is an important element of good governance. Confidence and transparency in public sector decision-making are enhanced when financial reporting is accurate and timely.

This chapter outlines our audit observations related to the financial reporting of agencies in the Customer Service portfolio of agencies (the portfolio) for 2023.

Section highlights

  • Unqualified audit opinions were issued on all completed 30 June 2023 financial statements audits of the portfolio agencies. Two audits are ongoing.
  • The total number of errors (including corrected and uncorrected) in the financial statements decreased compared to the prior year.
  • Financial statements were not prepared for Finance Co Trust (Fin Co), a special purpose trust created by the department as part of its project to replace flammable cladding for eligible residential apartment buildings. This is a breach of the Government Sector Finance Act 2018 (GSF Act).
  • The department overstated the value of its land titling database, a service concession asset by $42.5 million. This was due to errors in the valuation data and calculation errors in the valuation model.
  • Service NSW’s late resolution of the accounting assessment of grant programs funding resulted in delays to financial reporting and audit.
  • The New South Wales Government Telecommunications Authority (the authority) corrected a prior period error retrospectively to write off assets that could not be physically verified. 

Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies. They are essential for quality and timely decision-making.

This chapter outlines our observations and insights from our financial statement audits of agencies in the Customer Service portfolio.

Section highlights

  • The 2022–23 audits identified one high risk and 26 moderate risk issues across the portfolio.
  • The high-risk matter was related to Service NSW’s revenue assessment of its grant programs.
  • The total number of findings decreased from 64 to 41, which mainly related to deficiencies in financial reporting, information technology, payroll and purchasing controls.
  • Fifty-one per cent of the issues were repeat issues. Many repeat issues related to weakness in information technology (IT) controls around access to systems and data and disaster recovery testing.
  • For the first time since its establishment in 2015, GovConnect NSW received unqualified audit opinions for business processes internal controls and information technology general controls managed by service providers. 

Appendix one – Misstatements in financial statements submitted for audit 

Appendix two – Early close procedures

Appendix three – Timeliness of financial reporting

Appendix four – Financial data

 

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Published

Actions for Management of the Critical Communications Enhancement Program

Management of the Critical Communications Enhancement Program

Finance
Health
Justice
Whole of Government
Cyber security
Information technology
Infrastructure
Internal controls and governance
Project management
Risk
Service delivery
Shared services and collaboration

What the report is about

Effective radio communications are crucial to NSW's emergency services organisations.

The Critical Communications Enhancement Program (CCEP) aims to deliver an enhanced public safety radio network to serve the five emergency services organisations (ESOs), as well as a range of other users.

This report assesses whether the NSW Telco Authority is effectively managing the CCEP.

What we found

Where it has already been delivered (about 50% of the state), the enhanced network meets most of the requirements of ESOs.

The CCEP will provide additional infrastructure for public safety radio coverage in existing buildings agreed to with ESOs. However, radio coverage inside buildings constructed after the CCEP concludes will be at risk because building and fire regulations do not address the need for in-building public safety radio coverage.

Around 98% of radios connected to the network can be authenticated to protect against cloning, though only 42% are.

The NSW Telco Authority has not settled with ESOs on how call encryption will be used across the network. This creates the risk that radio interoperability between ESOs will not be maximised.

When completed, the public safety radio network will be the only mission critical radio network for ESOs. It is unclear whether governance for the ongoing running of the network will allow ESOs to participate in future network operational decisions.

The current estimated capital cost for the NSW Telco Authority to complete the CCEP is $1.293 billion. This is up from an estimated cost of $400 million in 2016. The estimated capital cost was not publicly disclosed until $1.325 billion was shown in the 2021–22 NSW Budget Papers.

We estimate that the full cost to government, including costs to the ESOs, of implementing the enhanced network is likely to exceed $2 billion.

We made recommendations about

  • The governance of the enhanced Public Safety Network (PSN) to support agency relationships.
  • The need to finalise a Traffic Mitigation Plan for when the network is congested.
  • The need to provide advice to the NSW Government about the regulatory gap for ensuring adequate network reach in future buildings.
  • The need to clarify how encryption and interoperability will work on the enhanced network.
  • The need for the NSW Telco Authority to comply with its policy on Infrastructure Capacity Reservation.
  • Expediting measures to protect against the risk of cloning by unauthenticated radios.

Public safety radio networks are critical for operational communications among Emergency Services Organisations (ESOs), which in New South Wales include:

  • NSW Ambulance
  • Fire and Rescue NSW
  • NSW Police Force
  • NSW Rural Fire Service
  • NSW State Emergency Service.1

Since 1993, these five ESOs have had access to a NSW Government owned and operated radio communications network, the Public Safety Network (PSN), to support their operational communications. Around 60 to 70 other entities also have access to this network, including other NSW government entities, Commonwealth government entities, local councils, community organisations, and utility companies.

Pursuant to the Government Telecommunications Act 2018 ('the Act'), the New South Wales Government Telecommunications Authority ('NSW Telco Authority') is responsible for the establishment, control, management, maintenance and operation of the PSN.2

Separate to the PSN, all ESOs and other government entities have historically maintained their own radio communication capabilities and networks. Accordingly, the PSN has been a supplementary source of operational radio communications for these entities.

These other radio networks maintained by ESOs and other entities are of varying size and capability, with many ageing and nearing their end-of-life. There was generally little or no interoperability between networks, infrastructure was often co-located and duplicative, and there were large gaps in geographic coverage.

In 2016, the NSW Telco Authority received dedicated NSW Government funding to commence the Critical Communications Enhancement Program (CCEP).

According to NSW Telco Authority's 2021–22 annual report, the CCEP is a transformation program for operational communications for NSW government agencies. The CCEP '…aims to deliver greater access to public safety standard radio communications for the State’s first responders and essential service agencies'. The objective of CCEP is to consolidate the large number of separate radio networks that are owned and operated by various NSW government entities and to enhance the state’s existing shared PSN. The program also aims to deliver increased PSN coverage throughout New South Wales.

The former NSW Government intended that as the enhanced PSN was progressively rolled-out across NSW, ESOs would migrate their radio communications to the enhanced network, before closing and decommissioning their own networks.

About this Audit

This audit assessed whether the CCEP is being effectively managed by the NSW Telco Authority to deliver an enhanced PSN that meets ESOs' requirements for operational communications.

We addressed the audit objective by answering the following two questions:

  1. Have agreed ESO user requirements for the enhanced PSN been met under day-to-day and emergency operational conditions?
  2. Has there been adequate transparency to the NSW Government and other stakeholders regarding whole-of-government costs related to the CCEP?

In answering the first question, we also considered how the agreed user requirements were determined. This included whether they were supported by evidence, whether they were sufficient to meet the intent of the CCEP (including in considering any role for new or alternative technologies), and whether they met any relevant technical standards and compliance obligations (including for cyber security resilience).

While other NSW government agencies and entities use the PSN, we focused on the experience of the five primary ESOs because these will be the largest users of the enhanced PSN.

Both the cost and time required to complete the CCEP roll-out have increased since 2016. While it was originally intended to be completed in 2020, this is now forecast to be 2027. Infrastructure NSW has previously assessed the reasons for the increases in time and cost. A summary of the findings made by Infrastructure NSW is presented in Chapter 1 of this report. Accordingly, as these matters had already been assessed, we did not re-examine them in this performance audit.

The auditee for this performance audit is the NSW Telco Authority, which is a statutory authority within the Department of Customer Service portfolio.

In addition to being responsible for the operation of the PSN, section 5 of the Act also prescribes that the NSW Telco Authority is:

  • to identify, develop and deliver upgrades and enhancements to the government telecommunications network to improve operational communications for government sector agencies
  • to develop policies, standards and guidelines for operational communications using telecommunications networks.

The NSW Telco Authority Advisory Board is established under section 10 of the Act. The role of the board is to advise the NSW Telco Authority and the minister on any matter relating to the telecommunications requirements of government sector agencies and on any other matter relating to the functions of the Authority. As of 2 June 2023, the responsible minister is the Minister for Customer Service and Digital Government.

The five identified ESOs are critical stakeholders of the CCEP and therefore they were consulted during this audit. However, the ESOs were not auditees for this performance audit.

Conclusion

In areas of New South Wales where the enhanced Public Safety Network has been implemented under the Critical Communications Enhancement Program, the NSW Telco Authority has delivered a radio network that meets most of the agreed requirements of Emergency Services Organisations for routine and emergency operations.
In April 2023, the enhanced Public Safety Network (PSN) was approximately 50% completed. In areas where it is used by Emergency Services Organisations (ESOs), the PSN generally meets agreed user requirements. This is demonstrated through extensive performance monitoring and reporting, which shows that agreed performance standards are generally achieved. Reviews by the NSW Government and the NSW Telco Authority found that the PSN performed effectively during major flood events in 2021 and 2022.

Where it is completed, PSN coverage is generally equal to or better than each ESO's individual pre-existing coverage. The NSW Telco Authority has a dedicated work program to address localised coverage gaps (or 'blackspots') in those areas where coverage has otherwise been substantively delivered. Available call capacity on the network far exceeds demand in everyday use. Any operational issues that may occur with the PSN are transparent to ESOs in real time.

The NSW Telco Authority consulted extensively with ESOs on requirements for the enhanced PSN, with relatively few ESO requirements not being included in the specifications for the enhanced PSN. Lessons from previous events, including the 2019–20 summer bushfires, have informed the design and implementation of the enhanced PSN (such as the need to ensure adequate backup power supply to inaccessible sites). The network is based on the Project 25 technical standards for mission-critical radio communications, which is widely-accepted in the public safety radio community throughout Australia and internationally.

There is no mechanism to ensure adequate radio coverage within new building infrastructure after the CCEP concludes, but the NSW Telco Authority and ESOs have agreed an approach to prioritise existing in-building sites for coverage for the duration of the CCEP.
The extent to which the PSN works within buildings and other built structures (such as railway tunnels) is of crucial importance to ESOs, especially the NSW Police Force, NSW Ambulance, and Fire and Rescue NSW. This is because a large proportion of their operational communications occurs within buildings.

There is no mechanism to ensure the adequacy of future in-building coverage for the PSN in new or refurbished buildings after the CCEP concludes. Planning, building, and fire regulations are silent on this issue. We note there are examples in the United States of how in-building coverage for public safety radio networks can be incorporated into building or fire safety codes.

In regard to existing buildings, it is not possible to know whether a building requires its own in-building PSN infrastructure until nearby outside radio sites, including towers and antennae, have been commissioned into the network. Only then can it be determined whether their radio transmissions are capable of penetrating inside nearby buildings. Accordingly, much of this work for in-building coverage cannot be done until outside radio sites are finished and operating.

In March 2023, the NSW Telco Authority and ESOs agreed on a list of 906 mandatory and 7,086

non-mandatory sites for in-building PSN coverage. Most of these sites will likely be able to receive radio coverage via external antennae and towers, however this cannot be confirmed until those nearby external PSN sites are completed. The parties also agreed on an approach to prioritising those sites where coverage is needed but not provided by antennae and towers. Available funding will likely only extend to ensuring coverage in sites deemed mandatory, which is nonetheless expected to meet the overall benchmark of achieving 'same or better' coverage than what ESOs had previously.

There is a risk that radio interoperability between ESOs will not be maximised because the NSW Telco Authority has not settled with ESOs how encryption will be used across the enhanced PSN.
End-to-end encryption of radio transmissions is a security feature that prevents radio transmissions being intercepted or listened to by people who are not meant to. The ability of the PSN to provide end-to-end encryption of operational communications is of critical importance to the two largest prospective users of the PSN: the NSW Police Force and NSW Ambulance. Given that encryption excludes other parties that do not have the requisite encryption keys, its use creates an obstacle to achieving a key intended benefit of the CCEP, that is a more interoperable PSN, where first responders are better able to communicate with other ESOs.

Further planning and collaboration between PSN participants are necessary to consider how these dual benefits can be achieved, including in what operational circumstances encrypted interoperability is necessary or appropriate.

The capital cost to the NSW Telco Authority of the CCEP, originally estimated at $400 million in 2016, was not made public until the 2021–22 NSW Budget disclosed an estimate of $1.325 billon.
The estimated capital cost to complete all stages of the CCEP increased over time. This increasing cost was progressively disclosed to the NSW Government through Cabinet processes between 2015–16 and 2021–22.

In 2016, the full capital cost to the NSW Telco Authority of completing the CCEP was estimated to be $400 million. This estimated cost was not publicly disclosed, nor were subsequent increases, until the cost of $1.325 billion was publicly disclosed in the 2021–22 NSW Budget (revised down in the 2022–23 NSW Budget to $1.293 billion).

There has been no transparency about the whole-of-government cost of implementing the enhanced PSN through the CCEP.
In addition to the capital costs incurred directly by the NSW Telco Authority for the CCEP, ESOs have incurred costs to maintain their own networks due to the delay in implementing the CCEP. The ESOs will continue to incur these costs until they are able to fully migrate to the enhanced PSN, which is expected to be in 2027. These costs have not been tracked or reported as part of transparently accounting for the whole-of-government cost of the enhanced PSN. This is despite Infrastructure NSW in 2019 recommending to the NSW Telco Authority that it conduct a stocktake of such costs so that a whole-of-government cost impact is available to the NSW Government.

1 The definition of 'emergency services organisation' is set out in the State Emergency and Rescue Management Act 1989 (NSW). In addition to the five ESOs discussed in this report, the definition also includes: Surf Life Saving New South Wales; New South Wales Volunteer Rescue Association Inc; Volunteer Marine Rescue NSW; an agency that manages or controls an accredited rescue unit; and a non-government agency that is prescribed by the regulations for the purposes of this definition.
2 Section 15(1) of the Government Telecommunications Act 2018 (NSW).

The NSW Telco Authority established and tracked its own costs for the CCEP

Over the course of the program from 2016, the NSW Telco Authority prepared a series of business cases and program reviews that estimated its cost of implementing the program in full, including those shown in Exhibit 6 below.

Exhibit 6: Estimated costs to fully implement the CCEP
Source Capital cost ($ million) Operating cost
($ million)
Completion date
March 2016 business case 400 37.3 2020
November 2017 internal review 476.7 41.7 2022
March 2020 business case 950–1,050 -- 2025
October 2020 business case 1,263.1 56.1 2026

Source: CCEP business cases as identified.

In response to the 2016 CCEP business case, the then NSW Government approved the NSW Telco Authority implementing the CCEP in full, with funding provided in stages. The NSW Telco Authority tracked its costs against approved funding, with monthly reports provided to the multi-agency Program Steering Committee

Throughout the program, the NSW Government was informed of increasing costs being incurred by the NSW Telco Authority for the CCEP

The various business cases, program updates, and program reviews prepared by the NSW Telco Authority were provided to the NSW Government through the required Cabinet process when seeking approval for the program proceeding and requests for both capital and operational funding. These provided clear indication of the changing overall cost of the CCEP to the NSW Telco Authority, as well as the delays that were being experienced.

There was no transparency to the Parliament and community about changes in the capital cost of the CCEP until the 2021–22 NSW Budget

As the business cases for the CCEP were not publicly available, the only sources of information about capital cost were NSW Budget papers and media releases. The information provided in the annual Budget papers prior to the 2021–22 NSW Budget provided no visibility of the estimated full capital cost to complete all stages of the CCEP. As shown in Exhibit 7 below, this information was fragmented and complex.

Media releases about the progress of the CCEP did not provide the estimated total cost to the NSW Telco Authority of $1.325 billion to complete all stages of the CCEP until June 2021. Prior to this date, media releases only provided funding for the initial stages of the program or for the stages subject to a funding announcement.

Even during the September 2019 and March 2020 Parliamentary Estimate Committee hearings where the costings and delays to the CCEP were raised, the estimated full cost of the CCEP was not revealed.

Exhibit 7: CCEP funding in NSW Budget papers from 2015–16 to 2022–23
Financial year Type of major work Description of expenditure Forecast estimate to complete ($ million) Estimated duration
2015–16 New work Infrastructure Rationalisation Program: Planning and Pilot 18.3 2015–16
2016–17 Work in progress CCEP Planning and Pilot 18.3 2015–17
New work CCEP 45 2016–17
2017–18 New work CCEP 190.75 2017–21
2018–19 Work in progress CCEP North Coast and State-wide Detailed Design 190.75 2017–21
New work CCEP Greater Metropolitan Area 236 2018–22
2019–20 Work in progress CCEP 426.9 2018–22
2020–21 Work in progress CCEP 664.8 2018–22
2021–22 Work in progress CCEP 1,325 2018–26
2022–23 Work in progress CCEP 1,292.8 2018–26

Source: NSW Treasury, Annual State Budget Papers.

The original business case for the CCEP included estimated ESO costs, though these costs were not tracked throughout the program

Estimates for ESO costs for operating and maintaining their own radio networks over the four years from 2016–17 were included in the original March 2016 business case. They included $75.2 million for capital expenditure and $95 million for one-off operating costs. These costs, as well as costs incurred by ESOs due to the delay in the program, were not subsequently tracked by the NSW Telco Authority.

In January 2017, Infrastructure NSW reviewed the CCEP business case of March 2016. In this review, Infrastructure NSW recommended that the NSW Telco Authority identify combined and apportioned costs and cashflow for all ESOs over the CCEP funding period reflecting all associated costs to deliver the CCEP. These to include additional incidental capital costs accruing to ESOs, transition and migration to the new network and the cost (capital and operational) of maintaining existing networks. This recommendation was implemented in the November 2017 program review, with ESO capital costs estimated as $183 million.

In 2019, Infrastructure NSW conducted a Deep Dive Review on the progress of the CCEP. In this review, Infrastructure NSW made what it described as a 'critical recommendation' that the NSW Telco Authority:

…coordinate a stocktake of the costs of operational bridging solutions implemented by PSAs [ESOs] as a result of the 18-month delay, so that a whole-of-government cost impact is available to the NSW Government.  

It should be noted that the delay to CCEP completion now is seven years and that further ‘operational bridging solutions’ have been needed by the ESOs.

'Stay Safe and Keep Operational' costs incurred by ESOs will be significantly higher than originally estimated

Stay Safe and Keep Operational (SSKO) funding was established to provide funding to ESOs to maintain their legacy networks while the CCEP was refreshing and enhancing the PSN. This recognised that much of the network infrastructure relied on by ESOs had reached – or was reaching – obsolescence and would either require extensive maintenance or replacement before the PSN was available for ESOs to migrate to it. ESOs may apply to NSW Treasury for SSKO funding, with their specific proposals being reviewed (and endorsed, where appropriate) by the NSW Telco Authority. Accordingly, SSKO expenditure does not fall within the CCEP budget allocation.

As shown in the table below, extracted from the March 2016 CCEP business case, the total expected cost for SSKO purposes over the course of the CCEP was originally $40 million, assuming the enhanced PSN would be fully available by 2020.

Exhibit 8: Stay Safe and Keep Operational forecast costs, 2017 to 2020
Year 2017 2018 2019 2020 Total
SSKO forecast ($ million) 12.5 15 10 2.5 40

Source: March 2016 CCEP business case.

In October 2022, the expected completion date for the CCEP was re-baselined to August 2027. Accordingly, ESOs will be required to continue to maintain their radio networks using legacy equipment for seven years longer than the original 2020 forecast. This will likely become progressively more expensive and require additional SSKO funding. For example, NSW Telco Authority endorsed SSKO bids for 2022–23 exceeded $35 million for that year alone.

Compared to the original forecast made in the March 2016 CCEP business case of $40 million, we found ESOs had estimated SSKO spending to 2027 will be $292.5 million.

A refresh of paging network used by ESOs and the decommissioning of redundant sites were both removed from the original 2016 scope of the CCEP

Paging

A paging network is considered an important user requirement by the Fire and Rescue NSW, NSW Rural Fire Service, and NSW State Emergency Service. The 2016 CCEP business case included a paging network refresh within the program scope of works. This was reiterated in the November 2017 internal review of the program. These documents did not estimate a cost for this refresh. The March 2020 and October 2020 business cases excluded paging from the program scope. The audit is unable to identify when, why or by whom the decision was made to remove paging from the program scope, something that was also not well communicated to the affected ESOs.

In 2021, after representations from the affected ESOs, the NSW Telco Authority prepared a separate business case for a refresh of the paging network at an estimated capital cost of $60.31 million. This program was subsequently approved by the NSW Government and included in the 2022–23 NSW Budget.

In determining an estimated full whole-of-government cost of delivering the enhanced PSN, we have included the budgeted cost of the paging network refresh on the basis that:

  • it was expressly included in the original approved March 2016 business case
  • the capability is deemed essential to the needs of three ESOs.

Decommissioning costs

The 2016 CCEP business case included cost estimates for decommissioning surplus sites (whether ‘old’ GRN sites or sites belonging to ESOs’ own networks). These estimates were provided for both the NSW Telco Authority ($38 million) and for the ESOs ($55 million). However, while these estimates were described, they were not included as part of the NSW Telco Authority's estimated capital cost ($400 million) or (more relevantly) operating cost ($37.3 million) for the CCEP. This is despite decommissioning being included as one of eight planned activities for the rollout of the program.

In the October 2020 business case, an estimate of $201 million was included for decommissioning agency networks based on a model whereby:

  • funding would be coordinated by the NSW Telco Authority
  • scheduling and reporting through an inter-agency working group and
  • where appropriate, agencies would be appointed as the most appropriate decommissioning party.

This estimated cost is not included in the CCEP budget.

In determining an estimated full whole-of-government cost of the enhanced PSN, we have included the estimated cost of decommissioning on the basis that:

  • decommissioning was included in the 2016 CCEP business case as one of eight 'planned activities for the rollout of the program'
  • effective decommissioning of surplus sites and equipment (including as described in the business case as incorporating asset decommissioning, asset re-use, and site make-good) is an inherent part of the program management for an enhanced PSN
  • costs incurred in decommissioning are entirely a consequence of the CCEP program.

The estimated minimum cost of building an enhanced PSN consistent with the original proposal is over $2 billion

We have derived two estimated minimum whole-of-government costs for delivering an enhanced PSN. These are:

  • $2.04 billion when calculated from NSW Telco Authority data – shown as estimate A in Exhibit 9 below.
  • $2.26 billion when calculated from ESO supplied data – shown as estimate B in Exhibit 9.

Both totals include:

  • budgeted amounts for both CCEP capital expenditure ($1,292.8 million) and operating expenditure ($139 million)
  • the NSW Telco Authority's 2020 estimated cost for decommissioning ($201 million)
  • the NSW Telco Authority's approved funding for paging refresh ($60.3 million).

The two estimated totals primarily vary around the capital expenditure of ESOs (particularly SSKO funding). To determine these costs, we used ESO provided actual SSKO costs to date, as well as their estimates for maintaining their legacy radio networks through to 2027.

The equivalent cost estimates from the NSW Telco Authority were sourced from the November 2017 internal review and the October 2020 business case for CCEP. It should be noted that the amounts for both estimates are not audited, or verified, but do provide an indication of how whole-of-government costs have grown over the course of the program.

The increase in and reasons for the increase in total CCEP costs (capital and one-off operating) incurred or forecast by the NSW Telco Authority (from $437.3 million in 2016 to $1,431.8 million in 2022) have been provided to the NSW Government through various business cases and reviews prepared by the NSW Telco Authority, as well as by reviews conducted by Infrastructure NSW as part of its project assurance responsibilities.

However, the growth in ESO costs and other consequential costs, such as paging and decommissioning, from around $263 million in the 2016 CCEP business case to between $600 million and $800 million, has to a large degree remained invisible and unexplained to the NSW Government and other stakeholders

Exhibit 9: Estimated whole-of-government costs of the enhanced PSN
  Estimated whole-of-government cost, over time
Cost type 20161 20172 20203 2023–Estimate A4 2023–Estimate B5
$ million $ million $ million $ million $ million
CCEP capital expenditure 400a 476.7b 1,263.1c 1,292.8d 1,292.8d
CCEP operating expenditure 37.3a 41.7b 41.5e 139d 139d
CCEP total 437.3 518.4 1,304.6 1,431.8 1,431.8
ESO capital expenditure 75.2a,f 183b,e 75.4e 258.4g 292.5
ESO one-off operating expenditure 93a n.a.l 86.5e 86.5h 273
ESO total 168.2 183 161.9 344.9 565.5
Paging n.a.i n.a.i n.a.j 60.3k 60.3k
Decommissioning 93 n.a.l 201.0 201h 201
Paging and decommissioning total 93 n.a. 201 261.3 261.3
Whole-of-government total 698.5 701.4 1,667.5 2,038 2,258.6

Notes:
  1. Financial year 2016 to Financial year 2020.
  2. Financial year 2016 to Financial year 2021.
  3. Financial year 2016 to Financial year 2025.
  4. Financial year 2016 to Financial year 2026.
  5. Financial year 2022 to Financial year 2025.
  6. Stay Safe and Keep Operational (SSKO) costs plus terminals costs.
  7. November 2017 internal review and October 2020 Business case.
  8. October 2020 Business case.
  9. Included in CCEP capital expenditure at that time.
  10. By 2020, a refresh of the paging network had been removed from the CCEP scope.
  11. A separate business case for a refresh of the paging network was approved by government in 2022.
  12. Figure not included in the source document.
Sources:
  1. March 2016 CCEP business case.
  2. November 2017 Internal Review conducted by the NSW Telco Authority.
  3. October 2020 CCEP business case.
  4. Derived from business cases, with ESO costs drawn from NSW Telco Authority data.
  5. Derived from business cases, with ESO costs based on data provided to the Audit Office of New South Wales by each of the five ESOs.

Appendix one – Response from agency

Appendix two – Trunked public safety radio networks

Appendix three – About the audit

Appendix four – Performance auditing

 

 

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

 

Parliamentary reference - Report number #383 - released 23 June 2023

 

Published

Actions for Regulation of public native forestry

Regulation of public native forestry

Environment
Industry
Compliance
Management and administration
Regulation
Risk

What this report is about

The Forestry Corporation of NSW (FCNSW) is a state-owned corporation that manages over two million hectares of public native forests and plantations supplying timber to sawmills across NSW.

The NSW Environment Protection Authority (EPA) is responsible for regulating the native forestry industry in NSW.

FCNSW must comply with Integrated Forestry Operations Approvals (IFOAs), which set out rules for how timber harvesting may occur.

Most harvesting is undertaken under the Coastal IFOA, which commenced in 2018.

This audit assessed how effectively Forestry Corporation of NSW manages its public native forestry activities to ensure compliance, and how effectively the Environment Protection Authority regulates these activities.

What we found

Forestry Corporation of NSW (FCNSW) clearly articulates its compliance obligations.

While FCNSW undertakes monitoring of its contractors, it does not do so consistently and does not target its monitoring activities on a risk basis.

FCNSW has largely fulfilled mandatory Coastal IFOA training requirements, but has not yet trained other staff who would also benefit from the training.

Contractor compliance appears to be improving, but there are gaps and inconsistencies in FCNSW's documentation of this.

FCNSW is not measuring its overall compliance to determine how it is tracking against its target.

The EPA undertakes proactive inspections of Coastal IFOA harvesting operations on a risk basis. However, it does not assess the risk at harvest sites covered by other IFOAs.

Most EPA compliance staff have received basic training, but few have received more advanced training required to effectively undertake forestry inspections.

Some EPA offices do not have the necessary equipment to undertake forestry inspections.

The EPA and FCNSW are not implementing all elements of a Memorandum of Understanding that aims to promote a cooperative relationship between the agencies.

What we recommended

The report made recommendations to FCNSW which aim to improve:

  • staff training
  • consistency of compliance reviews and data capture
  • targeting of compliance activities
  • measurement of performance.

The report made recommendations to the EPA which aim to improve:

  • risk-assessments
  • staff training
  • staff equipment.

The report also recommended that FCNSW and EPA should fully implement their Memorandum of Understanding.

The Forestry Corporation of NSW (FCNSW) is a state-owned corporation that supplies timber to sawmills in New South Wales, including timber harvested from public native forests. FCNSW is responsible for the management of around two million hectares of public native forests and plantations. Around half the area of native forests is permanently set aside for conservation.

Public native forestry is regulated through the Forestry Act 2012, Biodiversity Conservation Act 2016, Protection of the Environment Operations Act 1997 and associated regulations. Under the Forestry Act 2012, the objectives of FCNSW include, where its activities affect the environment, to conduct its operations in compliance with the principles of ecologically sustainable development contained in section 6(2) of the Protection of the Environment Administration Act 1991. This involves the integration of social, economic and environmental considerations in decision-making processes.

In undertaking its native forestry operations, FCNSW must comply with Integrated Forestry Operations Approvals (IFOA), issued jointly by the Minister for the Environment and the Minister for Agriculture, which set out rules to protect species and ecosystems where timber harvesting is occurring, and aim to ensure forests are managed in an ecologically sustainable way. FCNSW must also ensure that its contractors undertake forestry operations in line with IFOAs. The Coastal IFOA, developed in 2018, consolidated the four IFOAs for the Eden, Southern, Upper and Lower North East coastal regions of New South Wales into a single IFOA. The other three current IFOAs are Brigalow Nandewar, South Western Cypress and Riverina Redgum (the Western IFOAs).

The NSW Environment Protection Authority (EPA) is responsible for regulating native forestry in New South Wales. Under the Protection of the Environment Administration Act 1991, one of the objectives of the EPA is to protect, restore and enhance the quality of the environment in New South Wales, having regard to the need to maintain ecologically sustainable development. This includes monitoring FCNSW’s compliance with IFOA conditions, including by maintaining and enforcing a compliance program.

The Coastal IFOA also introduced a new structure and regulatory approach for IFOAs, establishing outcomes, conditions and protocols. The conditions set mandatory actions and controls intended to protect threatened plants, animals, habitats, soils and water. The protocols, referenced in the conditions, set out additional enforceable actions and controls intended to support the effective implementation of the conditions.

Public native forestry is the largest component of hardwood supply in New South Wales. The 2019–20 bushfires had a major impact on regional communities, and large areas of native forest. This heightened environmental risks and challenges in public native forestry. Five million hectares of New South Wales was impacted, including more than 890,000 hectares of native State Forests. This is over 40% of the coastal and tablelands native State Forests in New South Wales.

In addition to effective compliance activities, the success of the regulatory approach to public native forestry operations depends on how wood supply yields are modelled, and ensuring that harvested volumes do not exceed these yields. This is of particular importance in areas where forests have been severely damaged by fire. This audit did not consider sustainable yields. Recent reviews of this include an independent review of the FCNSW sustainable yield model and a Natural Resources Commission review in 2021.

This audit assessed how effectively Forestry Corporation of NSW manages its public native forestry activities to ensure compliance, and how effectively the Environment Protection Authority regulates these activities.

Conclusion

Forestry Corporation of NSW (FCNSW) clearly articulates its compliance obligations at the corporate level and for each harvest site. However, there are deficiencies in FCNSW’s compliance approach. While FCNSW undertakes monitoring of its contractors in a number of ways, it does not consistently monitor compliance across its contractors and does not target its monitoring activities on a risk basis. This increases the risk that non-compliant practices will not be identified, potentially leading to environmental harm.

FCNSW has a compliance strategy and program that sets out its compliance obligations and how they will be managed. FCNSW’s Compliance Policy outlines compliance requirements, actions to ensure compliance, and responsibilities for staff, supervisors, senior management and board members. FCNSW also has a compliance monitoring system manual that outlines its monitoring program, and its risk-assessment and incident reporting procedures. These corporate documents set out FCNSW’s overall approach to managing compliance.

Harvesting in State Forests is undertaken by contractors or sub-contractors. FCNSW provides training to its staff and contractors and undertakes monitoring to identify contractor compliance with relevant requirements through a variety of means, including its quality assurance assessment (QAA) program. FCNSW also communicates compliance obligations to contractors in harvest plans.

FCNSW is not undertaking its monitoring activities on a risk basis. The frequency of contractor supervision is inconsistent and is not tied to the contractor’s past performance, meaning that monitoring resources are not necessarily being targeted at the areas of highest -risk.

FCNSW also does not target its QAAs on a risk basis. FCNSW does not have procedures for how QAAs should occur outside the North Coast region. QAAs are conducted inconsistently, with some reviews occurring in only part of the harvest site while others cover the whole harvest site. In addition, some QAAs do not meet FCNSW’s minimum standards. FCNSW’s record keeping of QAAs is also inconsistent, making it difficult to determine true levels of compliance and the cause of identified potential non-compliances.

In addition, FCNSW does not collate and analyse the results of its compliance monitoring to target its compliance audits. Undertaking these audits on a risk basis would allow FCNSW to apply its resources to the highest-risk harvest sites and contractors.

The EPA identifies native forestry as a high priority regulatory activity and undertakes proactive inspections of Coastal IFOA harvest sites on a risk basis. However, the EPA does not assess the risk at Western IFOA harvest sites, leaving a significant gap in its inspection regime. This means that the EPA may not be inspecting all high-risk harvest sites to ensure compliance with regulations across those sites. The EPA has started to train more of its staff in conducting forestry inspections, but it currently has a limited number of trained and experienced staff to undertake this work.

The EPA has developed a Regulatory and Compliance Priorities Statement 2022–23 which identifies native forestry as a key risk. This statement identifies that forestry is a priority area for its compliance activities because of the increased environmental risk and sensitivity in forests following the 2019–20 bushfires. A divisional plan for its regulatory operations contains specific actions for forestry, including ensuring that the EPA has a consistent approach to recording regulatory actions undertaken and identifying priority areas for assurance over State Forests.

As part of its compliance activities, the EPA responds to complaints received, or reports of non-compliance, across all four IFOA areas and also carries out proactive inspections in the Coastal IFOA area. To guide these inspections, the EPA determines the level of risk posed by each harvest site in the Coastal IFOA area using information it gathers from FCNSW. The EPA prioritises inspections of sites rated as high and medium-risk, but the EPA has not undertaken risk-assessments for the three Western IFOAs. By not determining the risks in these areas, the EPA does not have assurance that it is checking FCNSW compliance with regulations across all high-risk sites.

Most EPA staff have basic training in forestry matters, but few staff have the more advanced training required to effectively undertake forestry inspections. In addition, not all EPA officers have access to the technology required to undertake forestry inspections, such as internet-enabled tablets and specialised tapes for measuring tree diameter. This limits the EPA’s ability to determine the level of compliance with regulations and respond effectively to instances of environmental harm in relation to public native forestry.

The Coastal IFOA does not contain provisions which allow the EPA to unilaterally restrict forestry activities in the aftermath of a catastrophic event such as the 2019–20 bushfires. Following the bushfires, FCNSW approached the EPA and asked for additional site-specific operating conditions (SSOC) at some locations to assist it in maintaining compliance. The SSOCs were issued by the EPA and FCNSW was required to carry out forestry operations in accordance with the SSOCs at relevant harvest sites. These SSOCs were in place for 12 months. After a year, FCNSW decided not to renew this approach with the EPA, but implemented its own voluntary measures during harvesting operations. Unlike the SSOCs, the EPA was unable to undertake enforcement activities for breaches of voluntary measures.

Appendix one – Responses from agencies
Appendix two – About the audit
Appendix three – Performance auditing

 

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

 

Parliamentary reference - Report number #382 - released 22 June 2023

Published

Actions for Natural disasters

Natural disasters

Community Services
Environment
Finance
Local Government
Planning
Transport
Treasury
Whole of Government
Asset valuation
Compliance
Financial reporting
Infrastructure
Regulation
Risk
Service delivery

What this report is about

This report draws together the financial impact of natural disasters on agencies integral to the response and impact of natural disasters during 2021–22.

What we found

Over the 2021–22 financial year $1.4 billion from a budget of $1.9 billion was spent by the NSW Government in response to natural disasters.

Total expenses were less than the budget due to underspend in the following areas:

  • clean-up assistance, including council grants
  • anticipated temporary accommodation support
  • payments relating to the Northern Rivers Business Support scheme for small businesses.

Natural disaster events damaged council assets such as roads, bridges, waste collection centres and other facilities used to provide essential services. Additional staff, contractors and experts were engaged to restore and repair damaged assets and minimise disruption to service delivery.

At 30 June 2022, the estimated damage to council infrastructure assets totalled $349 million.

Over the first half of the 2022–23 financial year, councils experienced further damage to infrastructure assets due to natural disasters. NSW Government spending on natural disasters continued with a further $1.1 billion spent over this period.

Thirty-six councils did not identify climate change or natural disaster as a strategic risk despite 22 of these having at least one natural disaster during 2021–22.

Section highlights

  • $1.4 billion from a budget of $1.9 billion was spent by the NSW Government in response to natural disasters during 2021–22.
  • Budget underspent for temporary housing and small business support as lower than expected need.

Section highlights

  • 83 local council areas were impacted by natural disasters during 2021–22, with 58 being impacted by more than one type of natural disaster.
  • $349 million damage to council infrastructure assets at 30 June 2022.

 

Published

Actions for Government advertising 2021–22

Government advertising 2021–22

Finance
Education
Whole of Government
Compliance
Management and administration
Procurement

What the report is about

The Government Advertising Act 2011 requires the Auditor-General to undertake a performance audit on government advertising activities each financial year.

This audit examined whether TAFE NSW's annual advertising campaign in 2021–22:

  1. was carried out effectively, economically, and efficiently
  2. complied with regulatory requirements and the Government Advertising Guidelines.

What we found

TAFE NSW complied with Section 6 of the Act, prohibiting political content.

It also complied with most other advertising requirements.
 
An important exception was that the Managing Director certified that the campaign complied with regulatory requirements and was an efficient and cost-effective means of achieving its public purpose, before a cost-benefit analysis (CBA) was completed.

We have found issues with agencies complying with CBA requirements in previous government advertising audits. This includes the failure to complete them before signing compliance certificates.

The policy owner, the Department of Customer Service (DCS), does not consider oversight of CBAs to be within the scope of their peer review process.  

TAFE NSW evaluated this advertising campaign by surveying a population significantly broader than the target audience. As such, survey results may not accurately reflect the views of the intended audience.

What we recommended

By 30 June 2023, TAFE NSW should:

  1. implement processes that ensure:
    1. CBAs are completed before the launch of campaigns over $1 million
    2. compliance certificates are completed only after all regulatory requirements are met
  2. consider adding to its current evaluation methods by surveying a population which closely reflects the age profile of its intended target audience.

By June 2023, DCS should:

  1. improve whole‑of‑government reporting and monitoring processes to provide the NSW Government with a central view of compliance, including the completion of CBAs by agencies.

The Government Advertising Act 2011 (the Act) sets out requirements that must be followed by a government agency when it carries out a government advertising campaign. The requirements include an explicit prohibition on political advertising, as well as a need to complete a peer review and cost-benefit analysis before the campaign commences. The accompanying Government Advertising Regulation 2018 (the Regulation) and Government Advertising Guidelines (the Guidelines) address further matters of detail.

The Act also requires the Auditor-General to conduct a performance audit on the activities of one or more government agencies in relation to government advertising campaigns in each financial year. The performance audit must assess whether a government agency (or agencies) has carried out activities in relation to government advertising campaigns in an effective, economical and efficient manner. It also assesses compliance with the Act, the Regulation, other laws and the Guidelines.

This audit examined TAFE NSW's advertising campaign for the 2021–22 financial year. TAFE NSW is the NSW Government's public provider of vocational education and training. TAFE NSW carries out an advertising campaign every year. In 2021–22, it spent $15.16 million on developing and implementing advertising. TAFE NSW used channels such as television, radio, internet and social media, press, and out of home advertising in public settings such as bus stops. The advertising aimed to increase the percentage of people considering TAFE NSW for training or education, grow the percentage of people who consider TAFE NSW to be the preferred education provider in NSW, and maintain the proportion of people who are aware of TAFE NSW more generally.

There are a range of private service providers helping to deliver vocational education and training in NSW.

Conclusion

TAFE NSW’s advertising campaign for 2021–22 was for an allowed purpose under the Act and did not include political advertising. TAFE NSW complied with most of the requirements set out in the Act, the Regulation, and the Guidelines, but it failed to complete a cost-benefit analysis for the campaign or provide sufficient support for the compliance certificate signed by TAFE NSW's Managing Director.

TAFE NSW complied with the requirement to complete a peer review of its campaign, but it did not meet the requirement to complete a cost-benefit analysis, either before it launched the campaign or during its implementation throughout 2021–22. Some of TAFE NSW's advertising did not meet the requirement for statements to be clearly supported by evidence.

The Act requires the head of an agency to sign a compliance certificate stating that, among other things, the campaign complies with the Act, the Regulation, and the Guidelines, and that the campaign is an efficient and cost-effective means of achieving the public purpose. TAFE NSW's Managing Director signed a compliance certificate in May 2021. However, TAFE NSW had not prepared a cost-benefit analysis as required under the Act and therefore TAFE NSW's Managing Director could not validly sign the compliance certificate. TAFE NSW did not subsequently complete a cost-benefit analysis during the campaign.

The campaign achieved many of its objectives and other performance measures and is likely to have been impactful. It is also likely that TAFE NSW’s advertising campaign in 2021–22 represented economical, efficient, and effective spend. However, the lack of a cost-benefit analysis meant that this could not be confidently demonstrated by TAFE NSW.

TAFE NSW used internal resources to create its advertising content, such as videos, radio scripts and press advertising, and relied upon a specialist partner to arrange and place its media in the appropriate advertising channel. TAFE NSW also adjusted the advertising campaign in response to performance data and in response to changes in the educational and advertising marketplaces.

TAFE NSW evaluated the impact of its advertising and tracked its brand performance using a survey which reflected the New South Wales general population aged between 16 and 60. However, this evaluation did not match TAFE NSW's advertising spend as TAFE NSW directed significantly more of its campaign budget to influencing younger people in this cohort.

This part of the report sets out key aspects of TAFE NSW's compliance with the government advertising regulatory framework. It considers whether TAFE NSW complied with the:

  • Government Advertising Act 2011
  • Government Advertising Regulation 2018
  • NSW Government Advertising Guidelines 2012 and other relevant policy.

This part of the report considers whether TAFE NSW's advertising program for 2021–22 was carried out in an effective, efficient, and economical manner.

Appendix one – Responses from agencies

Appendix two – About the campaign

Appendix three – About the audit

Appendix four – Performance auditing

 

Copyright notice

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

 

Parliamentary reference - Report number #377 - released 28 February 2023

Published

Actions for Government's acquisition of private property: Sydney Metro project

Government's acquisition of private property: Sydney Metro project

Transport
Planning
Whole of Government
Compliance
Infrastructure
Internal controls and governance
Project management
Risk

What the report is about

Sydney Metro is Australia’s largest public transport project. It requires the acquisition of many private properties, including residential and business properties.

This audit assessed the effectiveness of the acquisition of private properties for the Sydney Metro project. The audited agencies were Sydney Metro, the Department of Planning and Environment (Valuer General NSW) and Transport for NSW (the Centre for Property Acquisition).

The audit assessed agencies against the framework for property acquisitions in New South Wales. It did not re-perform the valuations done for individual properties that were acquired by Sydney Metro.

What we found

Acquisitions of private property for the Sydney Metro project were mostly effective in the sample of acquisitions we assessed. We found Sydney Metro:

  • complied with legislative and policy requirements for compensation and communication with people subject to property acquisitions
  • kept accurate records of its acquisitions and applied probity controls consistently
  • did not complete detailed plans or negotiation strategies for the high-risk and high-value acquisitions we reviewed
  • did not comply with legislative timelines for most compulsory acquisitions because of delays in receiving the required information from the Valuer General in these cases.

The Centre for Property Acquisition has overseen the implementation of reforms to residential acquisition processes, but its assessment of the effectiveness of these reforms has not been comprehensive.

What we recommended

The audit made four recommendations to the audited agencies to improve:

  • plans and strategies for the acquisition of high-risk and high-value properties
  • timeliness of issuing compensation determinations for compulsory acquisitions
  • data quality on the experience of people subject to property acquisitions.

The NSW Government has the power to acquire land that is owned or leased by individuals or businesses, if it is needed for a public purpose. The power arises from the Land Acquisition (Just Terms Compensation) Act 1991 (the Just Terms Act). Government agencies that have the power to compulsorily acquire private property are referred to as ‘acquiring authorities’. People who are subject to acquisitions are referred to as ‘affected parties’ and include property owners (business or residential), businesses with a commercial lease on a property, or individuals with residential tenancy leases. In recent years, the vast majority of acquisitions by the NSW Government have been for public transport or road projects.

Sydney Metro is a NSW Government agency with responsibility for building the Sydney Metro railway project. Sydney Metro is Australia’s largest public transport project. The project requires the acquisition of a large number of private properties. Sydney Metro has been one of the largest acquirers of private property in recent years, completing over 500 acquisitions between 2020 and mid-2022, with a total acquisition value of over $2 billion. Other agencies and statutory officers involved in the acquisition of property for the Sydney Metro project include:

  • the Department of Planning and Environment (DPE), which supports the minister responsible for the Just Terms Act. DPE also provides staff to the Valuer General of NSW
  • the Valuer General of NSW, an independent statutory officer that determines compensation in cases where the acquiring authority and the affected party cannot agree on compensation for property that has been acquired
  • Transport for NSW, which includes the Centre for Property Acquisition (CPA). The CPA does not have a direct role in acquiring properties, but its responsibilities include developing guidance for acquiring agencies and monitoring and reporting on their activities.

About this audit

The objective of this audit was to assess the effectiveness of acquisitions of private properties for Sydney Metro projects. The audit assessed agencies against the legislative and policy requirements in place for government acquisitions of private property in New South Wales. In line with the Audit Office's legislative mandate, the audit does not comment on the merits of the policy objectives reflected in the Just Terms Act.

The audit examined a sample of 20 property acquisitions. This was not a statistically representative sample. While our report provides comments on Sydney Metro’s overall acquisition processes, it does not provide assurance regarding the acquisitions that were not examined for this audit.

The audit did not re-perform the valuations done for individual properties that were acquired by Sydney Metro. Affected parties who disagree with the valuation of their property have the right to seek independent assessment of this via the Valuer General and the Land and Environment Court.

Conclusion

Acquisitions of property for the Sydney Metro project were mostly effective in the sample of acquisitions we assessed. Sydney Metro followed requirements for communication with affected parties. Compensation processes were conducted in compliance with legislative requirements, but compensation determinations for compulsory acquisitions were not completed within legislated time frames due to delays in receiving these from the Valuer General. Governance and probity processes were followed consistently, with some relatively minor exceptions. 

Sydney Metro has detailed guidelines for acquisitions that are based on relevant legislation and government policy. In the 20 acquisitions we assessed for this audit, these procedures were followed consistently. This included adhering to minimum timelines for negotiation periods, engaging independent valuers and other experts when needed, and complying with governance and probity processes.

Sydney Metro staff followed requirements for communication and support for residential acquisitions by assigning ‘personal managers’ and providing additional support to affected parties when needed. The Centre for Property Acquisition (CPA) has overseen reforms to the residential property acquisition process in recent years. These reforms include the introduction of the NSW Property Acquisition Standards and the use of personal managers, in addition to the existing acquisition managers, for residential acquisitions. However, the CPA has not assessed the impact of these changes on the experiences on people affected by property acquisitions.

Sydney Metro did not comply with the legislative requirement to provide a formal compensation notice to the affected party within 45 days of a compulsory acquisition starting in any of the eight relevant acquisitions in our sample. This was because Sydney Metro must wait for the Valuer General to complete a compensation determination before Sydney Metro can send the compensation notice, and the Valuer General did not do this within 45 days. We acknowledge that Sydney Metro does not have full control over this process, and that it has taken steps to mitigate the impact of delays on affected parties. 

This chapter presents our findings on Sydney Metro's acquisition of industrial and commercial properties. Industrial properties include construction businesses and manufacturing facilities. Commercial properties were mostly properties such as shopping centres and office towers. Many of these acquisitions involve businesses and properties that are relatively complex and have high values. This means the valuation process can require multiple experts and can be lengthy and contested. Adherence to governance and probity requirements is important for these acquisitions in order to demonstrate that the acquiring authority has achieved value for money.

This chapter presents our findings on Sydney Metro's acquisition of residential properties, which include apartments and houses, and small business leases, which mostly affected businesses in small shopping centres or arcades. Most of these acquisitions were lower value compared to industrial and commercial property acquisitions and did not require as much expert advice on complex technical issues. However, residential property acquisitions can be personally distressing for the affected parties and require staff from the acquiring authority to provide support and show empathy while ensuring legislative compliance and value for money.

Appendix one – Responses from agencies

Appendix two – About the audit 

Appendix three – Performance auditing 

 

Copyright notice

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

 

Parliamentary reference - Report number #375 - released 9 February 2023

Published

Actions for Cyber Security NSW: governance, roles, and responsibilities

Cyber Security NSW: governance, roles, and responsibilities

Local Government
Whole of Government
Finance
Cyber security
Information technology
Internal controls and governance
Management and administration

What the report is about

Cyber Security NSW is part of the Department of Customer Service, and aims to provide the NSW Government with an integrated approach to preventing and responding to cyber security threats.

This audit assessed the effectiveness of Cyber Security NSW's arrangements in contributing to the NSW Government's commitments under the NSW Cyber Security Strategy, in particular, increasing the NSW Government's cyber resiliency. The audit asked:

  • Are internal planning and governance processes in place to support Cyber Security NSW meet its objectives? 
  • Are Cyber Security NSW's roles and responsibilities defined and understood across the public sector?

What we found

Cyber Security NSW has a clear purpose that is in line with wider government policy and objectives. However, it does not clearly and consistently communicate its key objectives, with too few reliable and meaningful ways of measuring progress toward those objectives.

Cyber Security NSW does not provide adequate assurance of the cyber security maturity self assessments performed by NSW Government agencies. Department heads are accountable for ensuring their agency's compliance with NSW government policy.

Cyber Security NSW has a remit to assist local government to improve cyber resilience. However, it cannot mandate action and does not have a strategic approach guiding its efforts.

What we recommended

By 30 June 2023 the Department of Customer Service should:

  1. implement an approach that provides reasonable assurance that NSW government agencies are assessing and reporting their compliance with the NSW Government Cyber Security Policy in a manner that is consistent and accurate
  2. ensure that Cyber Security NSW has a strategic plan that clearly demonstrates how the functions and services provided by Cyber Security NSW contribute to meeting its purpose and achieving NSW government outcomes
  3. ensure that Cyber Security NSW has a detailed, complete and accessible catalogue of services available to agencies and councils
  4. develop a comprehensive engagement strategy and plan for the local government sector, including councils, government bodies, and other relevant stakeholders. 

The NSW Cyber Security Strategy details a vision for ‘…NSW to become a world leader in cyber security, protecting, growing, and advancing our digital economy’. Cyber Security NSW, located within the Department of Customer Service, has lead responsibility for one of the four commitments in the strategy: to increase the NSW Government’s cyber resilience.

Cyber Security NSW ‘aims to provide the NSW Government with an integrated approach to preventing and responding to cyber security threats’. It does not provide broader consumer-focused services.

In August 2020, the NSW Government approved a business case to enhance the funding and remit of Cyber Security NSW to include a broader range of services and functions. As a result, Cyber Security NSW is receiving $60 million in funding from 2020–21 to 2022–23, an increase from its previous funding of around $5 million per year (which had been sourced from contributions from each NSW Government department).

The objective of this performance audit was to assess the effectiveness of Cyber Security NSW’s arrangements in contributing to the NSW Government’s commitments under the NSW Cyber Security Strategy, in particular, to increase the NSW Government’s cyber resilience.

We assessed this objective through two lines of inquiry:

  1. Are internal planning and governance processes in place to support Cyber Security NSW meet its objectives?
  2. Are Cyber Security NSW roles and responsibilities defined and understood across the public sector?

The Audit Office of New South Wales has reported on the topic of cyber security previously. Most recently, the Internal Controls and Governance 2022 report included findings and recommendations relating to cyber security internal controls and governance at 25 of the largest agencies in the NSW public sector. While that report is multi-agency and sought to assess the level of cyber security attained in selected agencies, this current performance audit report focuses specifically on Cyber Security NSW and how well-equipped it is to meet its whole-of-government cyber security leadership and coordination roles.

Conclusion

Cyber Security NSW has a clear purpose that is aligned with wider government policy and objectives, but it cannot effectively demonstrate its progress toward improving cyber resilience

Cyber Security NSW's high-level purpose is to support the NSW Government’s delivery of digitised services that are protected, connected, and trusted. This purpose is consistent with broader NSW Government and Australian Government policy and builds on the purpose of the previous NSW Office of the Government Chief Information Security Officer, which was itself informed by external research and previous Audit Office of New South Wales recommendations.

In delivering its purpose, Cyber Security NSW provides a wide range of services to NSW government agencies and the local government sector. The majority of agencies and councils consulted during this audit reported that the services they received contributed to improving their individual cyber security.

However, Cyber Security NSW does not clearly and consistently communicate its key objectives to ensure that its efforts are effectively and efficiently targeted, prioritised, planned, and reported. This is despite it receiving enhanced funding to expand the scope of services it provides. It currently has many sets of objectives across a range of sources, including the Cyber Security Strategy, business plans, corporate material, and public communications. It has too few reliable and meaningful ways of measuring progress toward its objectives, and no overall workplan or roadmap to show how the objectives will be achieved.

Without a clear and consistent program logic, it is difficult to determine whether the functions and services delivered by Cyber Security NSW are helping to achieve the level of cyber resilience required to meet the increasing cyber threats faced by the NSW public sector.

Cyber Security NSW does not provide assurance of the cyber security maturity self-assessments performed by individual NSW Government agencies

The NSW Government has a devolved model for cyber security assurance. Cyber Security NSW administers the whole-of-government policy settings, and agency heads are responsible for ensuring compliance with policy requirements.

Cyber Security NSW has a remit to carry out audits of agencies’ self-assessments, but it has not carried out these audits and does not seek its own assurance of the results of these self-assessments. It is not sufficiently addressing previously identified inconsistencies and inaccuracies in how those self-assessments are performed and reported.

This form of auditing would be an important assurance that self-assessment and reporting is reliable. This is important given that maturity reporting is the main source of knowledge about the cyber security maturity and resilience of NSW Government agencies to cyber threats. If these self-assessments are unreliable, then it creates the risk that knowledge of the potential resilience of the NSW public sector to cyber security incidents is similarly unreliable. There is no other body in NSW with the mandate to routinely provide this form of assurance.

Cyber Security NSW has a remit to assist local government improve cyber resilience, however it cannot mandate action, and does not have a strategic approach guiding its efforts

Consistent with the expectations that accompanied its 2020 funding enhancement, Cyber Security NSW has engaged with the local government sector, albeit with mixed results. While these mixed results are partly a consequence of it not being provided a formal mandate in the sector, it has also been impacted by the fact that Cyber Security NSW has not established an engagement plan or strategy to guide its engagement with the local government sector.

Cyber security is an evolving landscape where the nature and scale of threats are increasing. The Australian Cyber Security Centre (ACSC), the Australian Government lead agency for cyber security, reported in its in 2020–21 annual report that it received over 67,500 cybercrime reports, equating to one report of a cyber attack every eight minutes, with no sector of the economy or type of government agency immune.

Citizens of NSW are increasingly accessing online government services in this context, providing different types of sensitive personal information. This reliance and transition to digital services has increased in recent times, particularly during the COVID-19 pandemic. The NSW Legislative Council’s Portfolio Committee (the Committee) noted in the March 2021 inquiry report into cyber security in NSW that ‘a failure to get cyber security right in New South Wales represents a significant risk to the State’s economy, business and community, and will affect public trust in government’.

The Committee noted that sound cyber security practices across NSW Government agencies, which Cyber Security NSW was established to drive, will enable the State and community to leverage opportunities from the digital world. Indeed, NSW aims to become a world leader in cyber security by protecting, growing and advancing the digital economy.

Establishment of Cyber Security NSW

Prior to the establishment of Cyber Security NSW, the Office of the Government Chief Information Security Officer was responsible for cyber security across the NSW government sector. This role was announced in March 2017 and was tasked with ‘identifying areas of high risk of attack, and working across NSW agencies to share intelligence, facilitate minimum security standards, and ultimately ensure that citizens can trust in the NSW Government’s delivery of digital transformation’. At the time of this appointment, the Minister for Customer Service and Digital Government stated that ‘cyber security and risk has emerged as one of the most high-profile, borderless and rapidly evolving risks facing government’.

The Office of the Government Chief Information Security Officer was renamed on 20 May 2019 to Cyber Security NSW. Governance updates at the time note that this was undertaken to ‘better reflect the leadership and coordination role required to uplift cyber security and decision-making across NSW Government’. The establishment of Cyber Security NSW was also partly in response to the Audit Office of New South Wales 2018 performance audit report on ‘Detecting and Responding to Cyber Security Incidents’. That audit found that there was no whole-of-government capability to detect and respond effectively to cyber security incidents. Cyber Security NSW is relatively new and is established as a branch within the Department of Customer Service (DCS).

The Office of the Government Chief Information Security Officer, and subsequently Cyber Security NSW, was initially funded through a levy imposed on clusters. Funding arrangements for Cyber Security NSW changed with the announcement in August 2020 of $240 million over three years for the stated purpose of bolstering the NSW Government’s cyber security capability and creating a world leading cyber industry. This funding included direct investment of $60 million from 2020–21 to 2022–23 for Cyber Security NSW to increase its capability and capacity, with the size of the team at the time expected to grow from 25 to 100 staff. In announcing this funding, the Minister for Customer Service and Digital Government stated that ‘…this is the biggest single cyber security investment in national history and will strengthen the government's capacity to detect and respond to the fast-moving cyber threat landscape’.

Cyber Security NSW is divided into two directorates, with one directorate having a focus on operations, and the other on policy and awareness. In turn, there are seven teams within the two directorates. As at March 2022, Cyber Security NSW had 76 ongoing positions filled, five contractors and 22 vacancies.

Cyber Security NSW states that its aim ‘…is to provide the NSW Government with an integrated approach to preventing and responding to cyber security threats. By building a stronger cyber resilience across whole-of-government, Cyber Security NSW is able to support the economic growth prosperity and efficiency of NSW’.

NSW Government Cyber Security Strategy

The NSW Government Cyber Security Strategy was released in September 2018 to ‘…guide and inform the safe management of government’s growing cyber footprint’. The 2018 Cyber Security Strategy also set out an action plan with success criteria against each of the six themes of the NSW cyber security framework. Based on a framework from the US National Institute of Standards and Technology (NIST), these themes are:

  • lead
  • prepare
  • prevent
  • detect 
  • respond 
  • recover.

The Strategy was revised in 2021 and combined with the Cyber Security Industry Development Strategy. The aim of this current strategy is to ‘…outline the key strategic objectives, guiding principles, and high-level focus areas that the NSW Government will use to align existing and future programs of work’. The strategy includes four NSW Government commitments to:

  • increase NSW Government cyber resiliency
  • help NSW cyber security businesses grow
  • enhance cyber security skills and workforce 
  • support cyber security research and innovation.

Cyber Security NSW has responsibility as ‘lead agency’ on the first commitment. This role requires it to set commitment objectives and focus areas for the strategy and provide central leadership and coordination of programs and initiatives.

NSW Government Cyber Security Policy

The NSW Government’s Cyber Security Policy was released in February 2019, replacing the former Digital Information Security Policy. All NSW Government agencies must comply with the Cyber Security Policy, and it was recommended for adoption by State Owned Corporations (SOC), local councils, and universities.

The current version of the Cyber Security Policy sets out a range of mandatory requirements for agencies, including: 

  • annual reporting of their self-assessed levels of maturity against all the mandatory requirements of the Policy and the Australian Cyber Security Centre’s ‘Essential Eight’ requirements 
  • that agencies must provide a list of their ‘crown jewels’ and high and extreme risks to their cluster Chief Information Security Officer (CISO).

The Policy sets out that Cyber Security NSW:

  • may assist agencies with their implementation of the Policy with an FAQ document and guidelines on several cyber security topics
  • will summarise the maturity reports provided by agencies and provide the results to the relevant governance bodies including the Cyber Security Steering Group, Secretaries’ Board, relevant committees of Cabinet, Cyber Security Senior Officers’ Group, and the ICT and Digital Leadership Group, as well as use these reports to identify common themes and areas for improvement across NSW Government.

As discussed further in Chapter 3, a mandatory guideline issued by the Secretary of the Department of Customer Service in 2020 established that departments and agencies will be subject to audits by Cyber Security NSW. This is to test compliance with the Cyber Security Policy and report these outcomes to the Secretaries’ Board.

This chapter considers whether the Department of Customer Service has a strategic plan for Cyber Security NSW that includes a consistent hierarchy of priorities, which are then reflected in workplans, and inform decisions about specific functions and activities. It also considers whether:

  • there was a sound, evidence-based rationale for why Cyber Security NSW was established
  • the specific services and functions Cyber Security NSW provides are adequately targeted to agency and council needs
  •  there is adequate performance assessment of how the services and functions performed by Cyber Security NSW contribute to uplifting cyber maturity and increasing cyber resilience.

This chapter considers the distribution of responsibility for cyber security in the NSW public sector, as well as whether the responsibilities and roles of Cyber Security NSW are clear and understood by agencies and councils. It also considers whether Cyber Security NSW has sufficient authority and mandate to fulfill its responsibilities for both NSW Government agencies and the local government sector.

Appendix one – Response from agency

Appendix two – About the audit

Appendix three – Performance auditing

 

Copyright notice

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

 

Parliamentary reference - Report number #374 - released 8 February 2023

Published

Actions for Bushfire recovery grants

Bushfire recovery grants

Environment
Industry
Compliance
Internal controls and governance
Management and administration
Service delivery

What the report is about

The Bushfire Local Economic Recovery (BLER) program was created after the 2019–20 bushfires, and commits $541.8 million to bushfire affected areas in New South Wales. It is co-funded by the Commonwealth and NSW governments.

This audit assessed how effectively the Department of Regional NSW (the department) and Resilience NSW administered rounds one and two of the BLER program. These rounds were:

  • Round one: early co-funding, split between two streams:
    • ­Fast-Tracked projects 
    • ­Sector Development Grants (SDG)
  • Round two: open round.

What we found

The Department of Regional NSW did not effectively administer the Fast-Tracked stream of the BLER. 

The administration process lacked integrity, given it did not have sufficiently detailed guidelines and the assessment process for projects lacked transparency and consistency. 

At the request of the Deputy Premier's office, a $1 million threshold was applied, below which projects were not approved for funding. The department advises that some of the projects excluded were subsequently funded from other programs. 

This threshold resulted in a number of shortlisted projects in areas highly impacted by the bushfires being excluded, including all shortlisted projects located in Labor Party-held electorates.

The department's administration of the SDG stream had a detailed and transparent assessment process. However, conflicts of interest were not effectively managed. 

The department's administration of the open round included a clearly documented, detailed and transparent assessment framework. Some weaknesses in the approach to conflicts of interest remained.

What we recommended

The Department of Regional NSW should ensure that for all future grant programs it:

  1. establishes and follows guidelines that align with relevant good practice guidance 
  2. ensures a communications plan is in place, including the communication of guidelines to potential applicants
  3. ensures staff declare conflicts of interest prior to the commencement of a grants stream, and that these conflicts of interest are recorded and managed
  4. ensures regular monitoring is in place as part of funding deeds 
  5. documents all key decisions and approvals in line with record keeping obligations.

This audit assessed how effectively the Department of Regional NSW and Resilience NSW administered rounds one and two of the Bushfire Local Economic Recovery (BLER) program.

As noted in this report, Resilience NSW was involved in the set-up and ongoing administration and monitoring of the BLER program. During the audited period, Resilience NSW was tasked with working with the Department of Regional NSW to create program objectives, guidelines and criteria. Their role also involved liaising with the Commonwealth Government, which provided co-funding for the program. Resilience NSW also had an ongoing role in quality assurance and compliance to ensure agencies administering disaster assistance did so in accordance with relevant guidelines. On 16 December 2022, the NSW Government abolished Resilience NSW.

Our work for this performance audit was completed on 3 November 2022, when we issued the final report to the two audited agencies. The audit report does not make specific recommendations to Resilience NSW. On 24 November 2022, the then Commissioner of Resilience NSW provided a response to the final report, which we include as it is the formal response from the audited entity at the time the audit was conducted.

During the 2019–20 bushfire season, New South Wales experienced 11,774 fire incidents, burning 5.5 million hectares of the state. There were 26 fatalities and 2,476 homes destroyed. The agriculture sector was heavily impacted with 601,858 hectares of pasture damaged.

Due to the widespread impacts of these fires on the state, the NSW and Commonwealth governments committed $4.4 billion toward bushfire response, recovery, and preparedness. This included the establishment of the Bushfire Local Economic Recovery (BLER) program, with $541.8 million committed to support job retention and creation in areas impacted by bushfires. The program also aims to strengthen community resilience and reduce the impact of future natural disasters. The BLER program is co-funded, with the Commonwealth and NSW governments funding 50% each.

The BLER program is comprised of three funding rounds:

  • round one early co-funding, split between
    • Fast-Tracked projects
    • Sector Development Grants (SDG)
  • round two: open round
  • round three: final projects and initiatives.

Resilience NSW was involved in setting up the BLER program and the Department of Regional NSW (the department) is responsible for administering it. The Commonwealth National Recovery and Resilience Agency must also endorse any projects proposed by the NSW Government for funding as part of the funding agreement between the State and Commonwealth governments.

Successful projects under the SDG stream were announced in September 2020 and projects funded through the Fast-Tracked stream were announced in October 2020. Round two (the open round) was administered after these two streams and successful projects were announced in June 2021.

The Department of Premier and Cabinet established the 'Good Practice Guide to Grants Administration' (the Good Practice Guide) in 2010 to assist the NSW Government in ensuring grants administration was performed consistently across all NSW Government grants programs. Compliance with the Good Practice Guide was not compulsory, but provided an outline of best practice covering the entire lifecycle of a grants program. This guide was in place at the time these grants were designed and administered.

The design and delivery of round one of the program occurred quickly, as part of the response to the 2019–20 bushfires, and was responding to a request from the Commonwealth Government for rapid project identification.

The objective of this audit was to assess how effectively the Department of Regional NSW and Resilience NSW administered rounds one and two of the BLER program. Round three was excluded from this audit because it had not been announced at the time of the audit.

We addressed this objective by examining whether the audited agencies:

  • effectively planned administration of the BLER program and established appropriate guidelines
  • implemented an effective assessment process for the BLER program
  • are effectively monitoring implementation of projects and program outcomes.

Conclusion

The Department of Regional NSW did not effectively administer the Fast-Tracked stream of the Bushfire Local Economic Recovery program. The administration process lacked integrity, given it did not have sufficiently detailed guidelines, and the assessment process for projects lacked transparency and consistency.

There were significant gaps in the documentation of decision-making throughout this funding stream. At the request of the Deputy Premier's office, a $1 million threshold was applied, below which projects were not approved for funding. This threshold was applied without a documented reason and was not part of the program guidelines. The department advises that some of the projects excluded through application of the threshold were subsequently funded from other programs.

The department's administration of the Sector Development Grants stream had a detailed and transparent assessment process. That said, conflicts of interest were not effectively managed, and the department did not effectively engage with stakeholders during the grants process.

The department's administration of the open round included a clearly documented, detailed and transparent assessment framework that it followed throughout. The department also implemented probity arrangements in the open round, although some weaknesses in the department's approach to conflicts of interest remained.

Fast-Tracked stream

Following requests from the Commonwealth Government in May and June 2020 to identify projects rapidly and as soon as practical, the department used an expedited process to identify relevant projects that had applied for other grants programs but had not received funding or which were identified as local priority projects. The department developed a set of guidelines for the Fast-Tracked stream based on draft Commonwealth funding criteria, but the department's guidelines lacked sufficient detail to ensure transparent and consistent decision-making. The guidelines also did not contain detailed information on how the assessment and approval processes would work. The department did not implement conflict of interest declarations for staff involved in the assessment process.

The assessment process implemented for the Fast-Tracked stream deviated from the guidelines. For example, the guidelines did not set out a role for the then Deputy Premier or his office in the assessment process, but the Deputy Premier's office played a key role in project selection. At the direction of the Deputy Premier's office, a $1 million minimum threshold, not mentioned in the guidelines, was applied to projects, below which, projects would not be funded. This resulted in a number of shortlisted projects in areas highly impacted by the bushfires, including all shortlisted projects located in Labor Party-held electorates, being excluded without a rationale being documented at the time. The department advised that some of these projects were subsequently funded through other funding streams.

The department's assessment process was inconsistent, poorly documented and lacked transparency. The department initially identified 445 potential projects through consultation with councils and through identifying projects that had been unsuccessful for other grant programs. The department only assessed 164 of these 445 projects for funding against the criteria in the guidelines. The department did not document the rationale for not assessing the remaining 281 projects against the criteria. The department also sought advice from Public Works Advisory (PWA) on whether projects could commence within six months, which was an eligibility criterion for the Fast-Tracked stream. PWA were only asked to assess 25 of the 445 projects, of which 19 were funded through the Fast-Tracked stream. The department also did not consistently follow PWA's advice and funded projects which PWA had advised were unable to commence within six months, which was not in line with the guidelines.

The department monitors 21 of the 22 Fast-Tracked projects on a quarterly basis to ensure projects are on track. Resilience NSW is responsible for the remaining project and does not monitor this on a quarterly basis but has established a project control group that performs a similar function. The agencies advised that this project is being transitioned to the department's management.

Sector Development Grants (SDG)

The department designed and published guidelines for the SDG stream. The guidelines largely align with the Department of Premier and Cabinet's 'Good Practice Guide to Grants Administration', although they could have been strengthened by including more detail on the eligibility of projects and the role of cost benefit analyses in the assessment process. The guidelines included a detailed and transparent assessment process which the department largely followed.

There were gaps in the administration of the SDG stream assessment process. The department did not effectively manage conflicts of interest as it did not ensure all required conflict of interest forms were completed and some forms were completed after the assessment process was finalised. The department also advised that the final version of the conflict of interest register, which contained the declarations for the SDG stream, was lost during a record management system change. The department did not develop guidance for communicating with stakeholders for the SDG stream. Feedback was received from industries which had been excluded from the SDG stream, relaying their concerns, and requesting a broader range of agribusiness sectors be considered for eligibility. A communications plan or strategy could have incorporated guidance on engaging agribusiness stakeholders during the planning stages of the stream, ensuring they were aware of the rationale for the eligible industries selected.

The majority of SDG funding went to areas highly impacted by the bushfires, although some highly impacted areas received less funding than lower impacted areas, and there is no clear reason for this.

The department does not monitor SDG projects on a quarterly basis to ensure that they remain on track but it ensures it has sufficient evidence that milestones have been completed before making funding payments.

Open round

The department designed and implemented a clearly documented and detailed assessment process for the open round. There were some areas where the process could have been improved, for example, the published guidelines did not set out the role of the former Deputy Premier or include reference to consultation with members of Parliament (MP) as part of the process, despite the fact that MPs were consulted as part of this round.

The department improved its management of conflicts of interest compared to the Fast-Tracked and SDG streams by maintaining a conflict of interest register, though not all conflict of interest declarations were collected. The department also developed a communications plan which led to improvements in stakeholder engagement.

One of the purposes of the open round was to distribute funding to local government areas (LGA) which did not receive funding through the Fast-Tracked stream. This intention was not outlined in the guidelines for this funding stream. The majority of funding from the open round went to LGAs which had been highly impacted by the bushfires.

The department monitors the open round projects on a quarterly basis to ensure that they are on track.

1. Recommendations

To promote integrity and transparency, the Department of Regional NSW should ensure that for all future grant programs it:

  1. establishes and follows guidelines that align with relevant good practice guidance including accountabilities, key assessment steps and clear assessment criteria
  2. ensures a communications plan is in place, including the communication of guidelines to potential applicants
  3. ensures staff declare conflicts of interest prior to the commencement of a grants stream, and that these conflicts of interest are recorded and managed
  4. ensures regular monitoring is in place as part of funding deeds
  5. documents all key decisions and approvals in line with record keeping obligations.

Stage one of the BLER program consisted of early co-funded projects valued at a total of $180 million. This included 22 Fast-Tracked priority projects valued at a total of $107.8 million. The purpose of these projects was to deliver immediate and significant economic impacts to high and moderate bushfire-impacted areas.

A timeline of key dates may be found at Exhibit 5.

Fifty-two projects worth a total of $73.2 million were funded through the SDG stream. One grantee withdrew their project from the stream in early 2021, leaving a total of 51 projects (of which 49 are co-funded with the Commonwealth Government).

A timeline of key dates may be found at Exhibit 9.

The department distributed $283 million to 195 successful projects as part of the open round of the BLER program.

A timeline of key dates may be found at Exhibit 11.

The department entered into funding deeds with successful applicants

The Good Practice Guide advises that the agency administering a grant should enter into a formal agreement with each grant recipient which sets out the arrangements under which a grant is provided, received, managed and acquitted. Across all three streams, the department sent out a letter of offer to successful project managers to let them know that they had been successful in receiving funding, and then entered into funding deeds with grantees. The one exception was the project that RNSW managed, discussed below.

The reviewed funding deeds were signed by department staff with the appropriate level of delegation. They contained an appropriate level of information and key clauses that would allow the department to monitor the progress of the grant to ensure its completion as agreed with the grantee. The reviewed funding deeds contained key information, including:

  • total value of the grant
  • key deliverables at each milestone
  • expected completion date of both the overall project and each milestone
  • reporting requirements, including provisions to allow the department to request relevant information
  • variation procedures.

The department only makes payments after confirming that milestones have been reached

The department has provided payments to grantees only after they could demonstrate that they had completed the agreed milestone. To ensure each milestone has been completed, the department requires grantees to provide evidence that they have fulfilled the milestone. Types of evidence provided includes photographs and invoices. Where the grantee provides insufficient evidence to the department, the department follows-up with the grantee to ensure that enough information is provided to justify the milestone payment.

The department also plans to undertake site visits of projects at select milestones and at the completion of most projects. The department has undertaken a risk assessment of each SDG and open round project, and uses this risk assessment to determine the number of milestones for the project, as well as the number of site visits that the department will undertake. Fast-Tracked projects all had PWA providing either project management or assurance and as such oversight is being provided through that mechanism. The milestones and site visits at each level of risk can be seen in Exhibit 15 for SDG and Exhibit 16 for open round.

Exhibit 15: Milestones and site visits for each level of risk - SDG
Risk rating Milestones Site visits
Low Two Zero
Medium Three One
High Four Two
Source: Department of Regional NSW.
 
Exhibit 16: Milestones and site visits for each level of risk - open round
Risk rating Milestones Site visits
Low Three One
Medium Four Two
High Five Three
 Source: Department of Regional NSW.

The department does not monitor quarterly progress for SDG grants

As part of the LER framework, the department reports to the Commonwealth every quarter on the status and financials of each project, including whether there are any risks to project delivery and the mitigations in place for those risks. For projects funded through the Fast-Tracked stream and the open round, the department collects quarterly progress reports from the grantees. These progress reports allow the department to determine if there are project risks, which can then be reported to the Commonwealth. The progress reports also allow the department to determine if a milestone is likely to be met within the next quarter or whether a project variation may be needed.

While the department monitors projects funded through the Fast-Tracked stream and the open round on a quarterly basis, there is no quarterly monitoring of progress for projects funded through the SDG stream. The SDG funding deeds do not include a provision to require quarterly reporting to the department. The department only collects progress reports from grantees when the grantee reports that it has completed a milestone. Quarterly monitoring of the SDG stream would allow the department to determine if projects require corrective action.

Resilience NSW is not collecting quarterly reports for the Fast-Tracked grant it is responsible for administering

One of the projects funded through the Fast-Tracked stream was the rebuilding of three local halls across two LGAs, for a total value of $3 million. RNSW is responsible for managing this grant and entered into funding deeds with the relevant councils. It is not documented why RNSW is responsible for these funding deeds rather than the department, which is the signatory for all of the other Fast-Tracked stream funding deeds. RNSW advised it was due to the responsible RNSW Director having a strong working relationship with the relevant councils.

The funding deeds which RNSW signed with the relevant councils set out a requirement that the councils would report on this project to RNSW every quarter. The second milestone of each of these projects involved the submission of a quarterly report. However, RNSW was unable to provide evidence that it carried out this monitoring of the project. At the time of the audit, no second milestone payment had been made. Undertaking quarterly monitoring would provide RNSW with assurance that the money is being expended for the proper purpose and whether the projects will be completed by the target date.

RNSW and the relevant councils developed project control groups for each project, which allows it to monitor the implementation of the projects. PWA is also represented on these project control groups and provides an advisory role in the implementation of the projects.

RNSW and the department advised that responsibility for this project will be transitioned to the department and it will be monitored on a quarterly basis, in line with the other Fast-Tracked projects.

The department has a consistent approach to validating variations

The department's funding deeds with grantees allow for the variation of contracts at the department's discretion after the grantee has written to the department. It is important for the department to consider the impact of any project variation request on the overall program objectives, because a project which costs more than was originally planned or which takes additional time may put at risk the objectives of the BLER program. To ensure that requests for variation are handled consistently and appropriately, the department's Grants Management Office (GMO) has developed a process document which applies to variation requests across the BLER program.

For the grants reviewed as part of this audit, the GMO applied this variation process consistently and has documented the outcomes. Larger variations are reviewed at a higher level of delegation and sign-off. To determine whether a variation is accepted, the GMO considers the following factors:

  • consistency with BLER program objectives
  • delivery within the timeframes of the BLER program
  • eligibility under the BLER program guidelines
  • financial viability to deliver within the requested budget.

The department is preparing multiple evaluations, but it has delayed its process evaluation

When developing round one of the BLER program, the department developed an evaluation plan. A total of $1.1 million has been reserved for conducting process, outcome, and economic evaluations of the BLER program and two other bushfire recovery grant programs.

To assist with evaluating program outcomes and economic impact, the department is planning a post-completion survey in 2023–24. This timeline will allow most projects to be completed and enough time for project outcomes to be realised. The department advised that the data collected through this survey would allow the department to determine whether the BLER program has achieved its objectives, as it includes information such as the number of jobs created through each project.

The process evaluation was initially planned for March to June 2021. This would have aligned with the announcement of the open round funding and would have allowed for the learnings from rounds one and two of the BLER program to be applied to the development of round three. However, the department did not conduct this evaluation in a timely way. The department advised that this was because funding deed negotiations were still ongoing, and the department was waiting for 50% of funding deeds to be signed. Given this, the department was not in a position to commence its process evaluation. In December 2021, the department revised its evaluation plan and advised that it commenced its process evaluation in April 2022. It is unlikely that this will allow time for the department to apply learnings to round three, which is currently underway.

Appendix one – Responses from agencies

Appendix two – BLER program distribution

Appendix three – About the audit

Appendix four – Performance auditing

 

Copyright notice

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

 

Parliamentary reference - Report number #373 - released 2 February 2023

Published

Actions for Design and implementation of the Transport Asset Holding Entity

Design and implementation of the Transport Asset Holding Entity

Transport
Treasury
Asset valuation
Financial reporting
Infrastructure
Procurement
Risk
Service delivery

What the report is about

The Transport Asset Holding Entity (TAHE) is the State's custodian of rail assets. It is a state owned corporation and commenced operating on 1 July 2020.

This audit assessed the effectiveness of NSW Government agencies' design and implementation of TAHE. We audited TAHE, Transport for NSW (TfNSW) and NSW Treasury.

Separate and related audits on TAHE are reported in 'State Finances 2022', 'State Finances 2021' and 'Transport and Infrastructure 2022' reports.

What we found

The design and implementation of TAHE, which spanned seven years, was not effective.

The process was not cohesive or transparent. It delivered an outcome that is unnecessarily complex in order to support an accounting treatment to meet the NSW Government's short-term Budget objectives, while creating an obligation for future governments.

The benefits of TAHE were claimed in the 2015–16 NSW Budget before the enabling legislation was passed by Parliament in 2017. This committed the agencies to implement a solution that justified the 2015–16 Budget impacts, regardless of any challenges that arose.

Rail safety arrangements were a priority throughout TAHE's design and implementation, and risks were raised and addressed.

Agencies relied heavily on consultants on matters related to the creation of TAHE, but failed to effectively manage these engagements. Agencies failed to ensure that consultancies delivered independent advice as an input to decision-making. A small number of firms were used repeatedly to provide advice on the same topic. The final cost of TAHE-related consultancies was $22.6 million compared to the initial estimated cost of $12.9 million.

What we recommended

We recommended that the audited agencies should:

  • improve accountability and transparency for major new fiscal transformation initiatives
  • ensure entities do not reflect the financial impact of significant initiatives in the Budget when there is uncertainty, or it creates perverse incentives
  • review record keeping practices, systems and policies to ensure compliance with the State Records Act 1998, and the NSW Government Information Classification, Labelling and Handling Guidelines
  • review procurement policies to ensure that consultant use complies with all NSW Government policy requirements.

The NSW Government established the Transport Asset Holding Entity (TAHE), a statutory State Owned Corporation (SOC), on 1 July 2020 to replace the former rail infrastructure owner – RailCorp. It is the State's custodian of rail network assets, including rail tracks and other infrastructure, rolling stock, land, train stations and facilities, retail space, and signal and power systems, within metropolitan and regional New South Wales. It is responsible for $2.8 billion of major capital projects in 2022–23.

TAHE was established under Part 2 of the Transport Administration Act 1988 and is governed by a decision-making board. The Treasurer and the Minister for Finance and Employee Relations are the Shareholding Ministers of TAHE, and they annually agree performance expectations articulated in a Statement of Corporate Intent.

Whereas TAHE is the custodian of rail assets, Sydney Trains and NSW Trains operate public rail services. TAHE does not have responsibility for the operation of the heavy rail network or train services, nor does it have network control functions. TAHE, Sydney Trains and NSW Trains are in the Transport and Infrastructure cluster in the public sector (formerly the Transport cluster and renamed in April 2022), which also includes Sydney Metro and Transport for NSW (TfNSW).

TfNSW leads the Transport and Infrastructure cluster. Its role is to set the strategic direction for transport across the State. This involves the shaping of planning, policy, strategy, regulation, resource allocation and other service and non-service delivery functions for all modes of transport.

TAHE's Operating Licence is granted by the Portfolio Minister and authorises the entity to perform the functions required to acquire, develop, finance, divest and hold assets, pursuant to the Transport Administration Act 1988. The Portfolio Minister also issues a Statement of Expectations which outlines the government’s expectation for the business for the next three to five years.

TAHE's original Portfolio Minister was the Minister for Transport who approved, on 30 June 2020, the issuing of an interim 12-month Operating Licence to enable TAHE to commence operating on 1 July 2020. The Portfolio Minister then granted TAHE's current Operating Licence in 2021. After TAHE requested a 12-month extension to its current Operating Licence, its next Operating Licence is due on 1 July 2024. The current Portfolio Minister is the Minister for Infrastructure, Cities and Active Transport.

About this audit

This audit assessed the effectiveness of NSW Government agencies' design and implementation of TAHE. In making this assessment, we considered whether: 

  • the process of designing and implementing TAHE was cohesive and transparent, and delivered an effective outcome
  • agencies' roles and responsibilities were clear in the planning of TAHE
  • agencies effectively identified and managed certain risks.

Conclusion

The design and implementation of TAHE was not effective. The process was not cohesive or transparent. It delivered an outcome that is unnecessarily complex in order to meet the NSW Government's short-term Budget objectives, while creating an obligation for future governments to sustain TAHE through continuing investment, and funding of the state owned rail operators. The ineffective process to design TAHE delivered a model that entails significant uncertainty as to whether the anticipated longer-term financial improvements to the Budget position can be achieved or sustained.

NSW Treasury and TfNSW had different objectives for TAHE

Up to June 2013, RailCorp had been the owner and operator of rail services and maintainer of the metropolitan rail network for almost a decade. It had been operating as a not-for-profit Public Non-Financial Corporation (PNFC).

In 2012, NSW Treasury (hereafter Treasury) decided there was a risk that the Australian Bureau of Statistics (ABS) would reclassify RailCorp to the General Government Sector (GGS), meaning depreciation expenses of approximately $870 million would be reflected in the GGS Budget. Treasury wanted to avoid this impact on the GGS Budget, and considered the establishment of a transport asset holding entity as a means to do so. Capital grants to RailCorp were being treated as an expense to the GGS Budget.

TfNSW also wanted an asset holding entity – but one that would be a non-trading ‘shell’ company with no staff that would hold and manage all public transport assets. TfNSW's concept envisaged the entity would have a structure that would enable future public transport reforms and strategic directions while ensuring vertical integration of operations between asset owners and the rail operators to maintain rail safety.

However, Treasury pursued its objective to improve the GGS Budget result, and sought to expand on TfNSW's 'shell' asset holding entity concept. Treasury wanted an entity that could generate a return on investment, as this meant that government investment in transport assets could be treated as equity investments, rather than a Budget expense, and in turn improve the GGS Budget position. As an example of the potential impact of creating this new entity, capital grants of $2.3 billion were paid to RailCorp in 2013–14. If Treasury's objective was met, grants of this significance would then be treated as an equity investment, rather than an expense in the GGS Budget.

In 2017, Treasury's preferred option was progressed through legislation, but both agencies' central objectives for the proposed asset holding entity would continue to prove difficult to reconcile. To achieve Treasury's objective to improve the Budget result, the entity would need to generate a return on investment (this is further discussed below). However, TfNSW expressed concerns that the prioritisation of rail safety, and the effective management of governance, regulation and operations would be more complex in an entity with commercial imperatives.

Asset holding entities are a common approach to the management of transport assets in Australia and internationally, and there are a range of approaches to how they are structured and used. Such structures should be driven by the goal of improved asset management. Ultimately, TfNSW's objectives could have been delivered through a simpler entity structure. However, reconciling TfNSW's objectives with Treasury's imperative to deliver and justify a Budget improvement in the short-term resulted in an overly lengthy process and an unnecessarily complex outcome that places an obligation on future governments to sustain. There is still significant uncertainty as to whether the short-term improvements to the Budget can continue to be realised in the longer-term.

The Budget benefits of TAHE were claimed before the entity was legislated, committing the agencies to deliver, regardless of the complexities that subsequently arose

The 2015–16 GGS Budget treated the government's investment in TAHE (still known at this time as RailCorp) as an equity contribution. This had the immediate impact of improving the Budget result by $1.8 billion per annum. However, the legislation to enable the establishment of TAHE had not yet been passed by Parliament, key elements of the operating model were still under development, and imminent changes in accounting standards had the potential to impact TAHE's financial model. The decision to book the benefits in the Budget early committed the involved agencies to implement a solution that justified the 2015–16 Budget impacts, irrespective of the challenges that arose. 

TAHE's financial structure requires circular government investment to work

For the NSW Government to continue to treat its investment in TAHE as an equity contribution, rather than an expense to the Budget, there must be a reasonable expectation that TAHE will generate a sufficient rate of return as required by the Government Finance Statistics (GFS) framework. In doing so, it needs to recover a revaluation loss created by a $20.3 billion reduction in the value of its assets which was incurred in its first full year of operation. This loss occurred as a result of a revaluation of TAHE's assets when RailCorp (a not-for profit entity) became TAHE (a for-profit commercial entity) – and is discussed further in the 'Key findings' below.

TAHE generates a small portion of its income from transactions with the private sector but, as noted in our report 'State Finances 2021', TAHE receives the majority of its revenue (more than 80%) from access and licence fee agreements with Sydney Trains and NSW Trains. Both of these entities are funded by grants (a Budget expense) to TfNSW from the GGS Budget.

Based on Treasury’s correspondence with the ABS in 2015, TAHE was initially expected to pay a return on equity of 7% in 2016–17. The assumption of a 7% return persisted through to 2018, after the legislation enabling the establishment of TAHE was passed by Parliament. However, when the initial access and licence fees were agreed on 1 July 2020, this figure had been revised to an expected rate of return of 1.5% excluding the revaluation loss. This was below the long-term inflation target and did not include the recovery of the revaluation loss – risking the government's ability to treat its investment in TAHE as an equity contribution. Importantly, as TAHE is primarily reliant on fees paid by the state owned rail operators that, in turn, are funded by the GGS Budget (as an expense), the decision to change the returns model from 7% to 1.5% would in its own right have had a positive impact on the GGS Budget. However, the decision to use a 1.5% return would ultimately be problematic as it made it difficult to treat the government's contributions to TAHE as an equity investment, as discussed below.

On 14 December 2021, to avoid a qualified audit opinion, the NSW Government made the decision to increase TAHE's expected rate of return to 2.5%, equal to the Reserve Bank’s long-term inflation target.

In 2021-22, TAHE needed to start charging rail operators higher access and licence fees in order to generate a return of 2.5%, so as to support the government's treatment of its investment in TAHE as an equity contribution in the GGS Budget. This meant the government needed to provide additional grant (expense) funding to the state owned rail operators so they could pay the increased access and licence fees to TAHE. Based on current projections, TAHE is not expected to recover the revaluation loss until 2046.

There remains a risk that TAHE will not be able to generate a sufficient return on the NSW Government's investment without relying on increased funding to state owned rail operators so that they can in turn pay the higher access and licence fees. TAHE's ability to generate returns on government investment from other sources are uncertain and may not be achievable or sustainable. Current modelling highlights that TAHE remains largely reliant, through to 2046, on increasing fees (which are assumed to increase at 2.5% per annum from 2031 onwards when the current 10 year contracts with rail operators expire) paid by the state owned rail operators that remain principally reliant on GGS Budget grants.

The process of designing and implementing TAHE was not transparent to independent scrutiny

Our report 'State Finances 2021' commented that Treasury did not always provide this Office with information relating to TAHE on a timely basis. Similarly, during this performance audit, there were also multiple instances where auditees were unable to provide documentation regarding key activities in the process to deliver TAHE. Agencies also applied higher sensitivity classifications to large tranches of documents than was justified or required by policy. Of particular concern is the incorrect classification of documents as Cabinet sensitive information. The incorrect or over-classification of documentation as Cabinet sensitive delayed this Office's ability to provide scrutiny or independent assurance.

There was a lack of clarity around the roles and responsibilities of governance structures set up to oversee the design and implementation of TAHE

From 2014, multiple workstreams and advisory committees were established to progress the design and implementation of TAHE. For some of these committees and workstreams, there is limited information on what they were tasked to do and what they achieved. Most had ceased meeting by 2018, before significant work needed to deliver TAHE was completed.

The lack of clarity around the roles and responsibilities of these governance structures reduced opportunities for TfNSW and Treasury to reconcile their differing objectives for TAHE, and resolve key questions earlier in the process.

There was a heavy reliance on consulting firms throughout the process to establish TAHE, and the management of consultant engagements failed to ensure that agencies received independent advice to support objective decision-making

In 2020, Treasury and TfNSW failed to prevent, identify, or adequately manage a conflict of interest when they engaged the same 'Big 4' consulting firm to work on separate TAHE-related projects. Both agencies used the firm's work to further their respective views with regard to the financial implications of TAHE's operating model. At this time those views were still unreconciled.

Treasury engaged the firm to provide a fiscal risk management strategy and advice on the impact of changes to accounting standards. TfNSW engaged the same firm to develop operating and financial models for TAHE, which raised concerns regarding the viability of TAHE. Disputes arose around the findings of these reports. Treasury disagreed with some of the outcomes of the work commissioned by TfNSW, relating to accounting treatment and fiscal advice.

The management of this conflict (real or perceived) was left to the 'Big 4' consulting firm when it was more appropriate for it to be managed by Treasury and TfNSW. If these agencies had communicated more effectively, used available governance structures consistently, and shared information openly about their use of the firm and the nature of their respective engagements, these disputes might have been avoided. This issue, coupled with deficiencies in procurement by both agencies, reflected and further perpetuated the lack of cohesion in the design and implementation of TAHE.

More broadly, over the period 2014 – 2021, 16 separate consulting firms were employed to work on 36 contracts, valued at over $22.56 million, relating to TAHE ranging from accounting and legal advice, project management, and the provision of administrative support and secretariat services.

Consultants are legitimately used by agencies to provide advice on how to achieve the outcomes determined by government, including advising agencies on the risks and challenges in achieving those outcomes. Similarly, consultants can provide expert knowledge in the service of achieving those outcomes and managing the risks. However, the heavy reliance on consulting firms during the design and implementation of TAHE heightened the risk that agencies were not receiving value for money, were outsourcing tasks that should be performed by the public service, and did not mitigate the risk that the advice received was not objective and impartial. The risk that the role of consultants could have been blurred between providing independent advice to government on options and facilitating a pre-determined outcome was not effectively treated or mitigated. This risk was amplified because a small number of firms were used repeatedly to provide advice on one topic. The effective procurement and management of consultants is an obligation of government agencies.

Appendix one – Responses from audited agencies, and Audit Office clarification of matters raised in the TAHE formal response 

Appendix two – Classification of government entities 

Appendix three – About the audit 

Appendix four – Performance auditing

 

Copyright notice

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

 

Parliamentary reference - Report number #372 - released 24 January 2023