Refine search Expand filter

Reports

Published

Actions for Planning, Industry and Environment 2019

Planning, Industry and Environment 2019

Planning
Industry
Environment
Asset valuation
Cyber security
Financial reporting
Information technology
Infrastructure
Internal controls and governance
Management and administration
Service delivery
Workforce and capability

This report outlines the results of audits of the financial statements of agencies now grouped in the NSW Planning, Industry and Environment cluster.

Unqualified audit opinions were issued for 56 of the 66 cluster agencies’ 30 June 2019 financial statements. Ten audits remain incomplete. The cluster agencies need to improve the timeliness of financial reporting. 

The Audit Office continued to identify issues regarding unprocessed Aboriginal land claims and the recognition of Crown land. ‘Auditor-General’s reports to parliament have recommended action to reduce the level of unprocessed land claims since 2007. However, the number of unprocessed claims continued to increase’, Margaret Crawford said.

One in five internal control findings were repeat issues. Key themes included information technology, asset management and improvements required to expense and payroll controls.

The report makes several recommendations including:

  • Property NSW should urgently address the deficiencies in the lease data used to calculate the impact of the new leasing standard effective from 1 July 2019
  • the Department of Planning, Industry and Environment should prioritise action to reduce unprocessed Aboriginal land claims
  • the Department of Planning, Industry and Environment should ensure the Crown land database is complete and accurate so state agencies and local government councils are better informed about the Crown land they control.

This report analyses the results of our audits of financial statements of the Planning, Industry and Environment cluster agencies for the year ended 30 June 2019. The table below summarises our key observations.

1. Machinery of Government changes

Creation of the Planning, Industry and Environment cluster

The Machinery of Government (MoG) changes abolished the former Planning and Environment cluster and former Industry cluster, and created the Planning, Industry and Environment cluster on 1 July 2019.

The Department of Planning and Environment (DPE), the Department of Industry (DOI), the Office of Environment and Heritage, and the Office of Local Government were abolished and the majority of their functions were transferred to the new Department of Planning, Industry and Environment (DPIE).

The Department of Planning, Industry and Environment is still in the process of implementing changes

The MoG changes bring risks and challenges to the cluster. A MoG Steering Committee, with the support of various project control groups and working groups, identified and developed responses to key risks arising from the changes.

However, the DPIE will take some time to fully integrate the policies, systems and processes of the abolished Departments and agencies.

2. Financial reporting

Audit opinions Unqualified audit opinions were issued for 56 of the 66 cluster agencies' 30 June 2019 financial statements audits. Ten financial statements audits are still ongoing.
Timeliness of financial reporting

Fifty-five of the 57 agencies subject to statutory deadlines submitted their financial statements on time.

Due to issues identified during the audit, 13 financial statements audits were not completed and audit opinions issued by the statutory deadline.

Agencies prepared and submitted their early close procedures in accordance with the mandatory timeframe set by NSW Treasury. However, 17 of the 49 agencies where we reviewed early close procedures were assessed as either partially addressing or not addressing one or more of the mandatory requirements. The cluster agencies could benefit from an increased focus on early close procedures.

Introduction of AASB 16 'Leases'

We noted errors in the lease data used in Property NSW's AASB 16 impact calculations, which affect both Property NSW and other government agencies. These errors were significant enough to present a risk of material misstatements to the financial statements of Property NSW and other government agencies in future reporting periods.

We had similar findings in our recent performance audit on 'Property Asset Utilisation', which highlighted issues with the quality of Property NSW's records.

Recommendation: Property NSW should urgently address the deficiencies in the lease data used to calculate the impact of the new leasing standard effective from 1 July 2019.

Unprocessed Aboriginal land claims have continued to increase

Despite an increase in the number of claims resolved, the number of unprocessed Aboriginal land claims increased by 7.2 per cent from the prior year to 35,855 at 30 June 2019. Claims can be made over Crown land assets of the DPIE or other government agencies. Until claims are resolved, there is an uncertainty over who is entitled to the land and the uses and activities that can be carried out on the land. We first recommended action to address unprocessed claims in 2007.

Recommendation (repeat issue): The DPIE should prioritise action to reduce unprocessed Aboriginal land claims.

3. Audit observations

Internal controls

One in five internal control issues identified and reported to management in 2018–19 were repeat issues.

The lack of user access review was the most common IT general control issue in the cluster.

Drought relief

The NSW Government announced an emergency drought relief package of $500 million in 2018, in addition to other financial assistance measures already in place.

Limited documentation and written agreements between relevant delivery agencies resulted in a $31.0 million misstatement relating to grant revenue.

Recognition of Crown land

Crown land is an important asset of the state. Management and recognition of Crown land assets is weakened when there is confusion over who is responsible for a particular Crown land parcel. Last year we recommended the DOI should ensure the database of Crown land is complete and accurate. While the DOI has commenced actions to improve the database, this continued to be an issue in 2018–19.

Recommendation (repeat issue): The DPIE should ensure the Crown land database is complete and accurate so state agencies and local government councils are better informed about the Crown land they control.

Developer contributions The former DPE continued to accumulate more developer contributions revenues than it spent on infrastructure projects. Total unspent funds increased to $274 million at 30 June 2019.

 

This report provides parliament and other users of the Planning, Industry and Environment cluster agencies financial statements with the results of our audits, our observations, analysis, conclusions and recommendations in the following areas:

  • financial reporting
  • audit observations.

This cluster was created by the Machinery of Government changes on 1 July 2019. This report is focused on agencies in the Planning, Industry and Environment cluster from 1 July 2019. However, these agencies were all in other clusters during 2018–19. Please refer to the section on Machinery of Government changes for more details.

Machinery of Government (MoG) refers to how the government organises the structures and functions of the public service. MoG changes are where the government reorganises these structures and functions that are given effect by Administrative orders.

The MoG changes, announced following the NSW State election on 23 March 2019, created the Planning, Industry and Environment (PIE) cluster. The Administrative Changes Orders issued on 2 April 2019, 1 May 2019 and 28 June 2019 gave effect to these changes. These orders became effective on 1 July 2019.

Section highlights

The 2019 MoG changes significantly impacted the former Planning and Environment, and Industry clusters and agencies.

  • The PIE cluster combines most of the functions and agencies of the former Planning and Environment and Industry clusters from 1 July 2019.
  • The Department of Planning, Industry and Environment is the principal agency in the PIE cluster.
  • The MoG changes bring risks and challenges to the PIE cluster.
  • A MoG Steering Committee was established to oversee the transitional processes.
  • The full integration of the systems and processes will not be completed in the near future.

Financial reporting is an important element of good governance. Confidence and transparency in public sector decision making are enhanced when financial reporting is accurate and timely.

This chapter outlines our audit observations related to the financial reporting of agencies in the Planning, Industry and Environment (PIE) cluster for 2019. In this chapter, the Department of Planning, Industry and Environment is referred to as DPIE, the former Department of Planning and Environment as DPE, and the former Department of Industry as DOI.

Section highlights

  • Unqualified audit opinions were issued for all completed 30 June 2019 financial statements audits. However, some cluster agencies can further enhance the quality of financial reporting.
  • Timeliness of financial reporting remains an issue for 13 agencies.
  • Deficiencies were identified in the data used to calculate the impact of AASB 16 ‘Leases’ effective from 1 July 2019. Property NSW should urgently address these deficiencies.
  • Unprocessed Aboriginal land claims continue to increase. DPIE should prioritise action to reduce unprocessed Aboriginal land claims.

Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies. They are essential for quality and timely decision making.

This chapter outlines our audit observations and insights from our financial statement audits of agencies in the Planning, Industry and Environment (PIE) cluster for 2019. In this chapter, the Department of Planning, Industry and Environment is referred to as DPIE, the former Department of Planning and Environment as DPE, and the former Department of Industry as DOI.

Section highlights

  • One in five issues identified and reported to management in 2018–19 were repeat issues.
  • The lack of user access review was the most common IT general control issue in the PIE cluster.
  • The PIE cluster provided significant financial assistance for drought relief.
  • There continues to be significant deficiencies in Crown land records. The DPIE should ensure the Crown land database is complete and accurate.
  • Unspent developer contributions funds continued to build up in 2018–19. 

Appendix one – List of 2019 recommendations

Appendix two – Status of 2018 recommendations

Appendix three – Cluster agencies

Appendix four – Financial data

Appendix five – Management letter findings

Appendix six – Timeliness of financial reporting

 

Copyright notice

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Published

Actions for Health 2019

Health 2019

Health
Asset valuation
Compliance
Financial reporting
Fraud
Information technology
Internal controls and governance
Management and administration
Procurement
Project management

This report focuses on key observations and findings from the most recent financial audits of the Ministry of Health, local health districts, specialty health networks, health corporations and independent health agencies in New South Wales. The report also summarises self-reported performance measures across the network.

The number and value of adjustments to financial statements of entities in the Health Cluster decreased from the prior year. And unqualified audit opinions were issued for all heath entities’ financial statements.

Audit findings relating to internal controls deficiencies increased across health entities. Contributing to this increase were deficiencies in information system controls, which accounted for nearly a quarter of all control deficiencies. Repeat audit findings also accounted for more than a quarter of all control deficiencies.

The report notes health entities continued to experience challenges with managing employees’ excessive annual leave and time recording practices. The Ambulance Service of New South Wales continued to report high overtime payments to its employees. 

Download Health 2019 report (PDF).

This report analyses the results of our audits of financial statements of the agencies comprising the Health cluster for the year ended 30 June 2019. The table below summarises our key observations.

1. Machinery of Government changes

Cluster changes Machinery of Government (MoG) changes refer to how the government reorganises agency structures and functions and realigns ministerial responsibilities. The Health cluster was not impacted by the MoG changes.

2. Financial reporting

Financial reporting

The financial statements of NSW Health and its controlled entities received unqualified audit opinions before the legislative deadline.

The number of corrected and uncorrected misstatements decreased from the prior year.

Management implemented more robust processes for its oversight of complex asset revaluations in 2018–19. We found no significant errors in 2018–19.

Financial performance Overall, NSW Health recorded an operating surplus of $1.1 billion in 2018–19, an increase of $699 million from 2017–18. This was the result of additional funding received for capital expenditure on the construction of new facilities, upgrades and redevelopments.

Budgeted expense for the 15 local health districts and two speciality networks increased from $18.3 billion to $19.4 billion in 2018–19. The 15 health entities recorded unfavourable variances between actual and budgeted expenses.
Excess annual leave

Managing excess annual leave remains a challenge for NSW Health, 36.9 per cent of the workforce have excess annual leave balances.

Recommendation: Health entities should further review their approach to managing excess annual leave in 2019–20, and:

  • monitor current and projected leave balances to the end of the financial year on a monthly basis
  • agree formal leave plans with employees to reduce leave balances over an acceptable timeframe
  • encourage staff who perform key control functions to take at least two consecutive weeks’ leave a year to mitigate fraud risks.
Overtime payments NSW Health entities generally manage overtime well. The Ambulance Service of NSW’s overtime payments of $83.1 million (9.8 per cent of total salaries and wages), remain significantly higher than other health entities.

Recommendation: The Ambulance Service of NSW should further review the effectiveness of its rostering practices to identify strategies to reduce overtime payments.

3. Audit observations

Internal control deficiencies We identified more internal control deficiencies in 2018–19. The number of repeat issues from prior years also remains high with more than one quarter of issues having been previously reported. More than a quarter of deficiencies related to information system controls.
Infrastructure delivery NSW Health defines projects with a budgeted cost greater than $50.0 million as 'major projects'. There were significant revisions to planned financial completion dates and budgeted costs of these projects. The revised total budgets for the 30 ongoing major capital projects at 30 June 2019 is $10.2 billion, $2.2 billion more than the original budget.
Health Infrastructure completed three major capital projects during 2018–19.
Asset maintenance The total cost of maintaining the health entities’ $19.8 billion of assets was $635 million for 2018–19. Health entities' approaches to setting maintenance budgets vary. Most entities are addressing their backlog maintenance, although many were not able to quantify the full extent of their backlog maintenance. Although health entities continue to use fully depreciated assets, the replacement cost of these assets is decreasing.

 

 

This report provides parliament and other users of the financial statements of agencies within the Health cluster with the results of our audits, our observations, analysis, conclusions and recommendations in the following areas for the year ended 30 June 2019:

  • financial reporting
  • audit observations. 

 The Health cluster was not impacted by the Machinery of Government changes on 1 July 2019. 

Financial reporting is an important element of good governance. Confidence and transparency in public sector decision making are enhanced when financial reporting is accurate and timely.

This chapter outlines our audit observations related to the financial reporting of agencies in the health cluster for 2019.

Section highlights

  • We issued unqualified audit opinions for all health entities’ financial statements and identified fewer misstatement than last year. Health entities continue to meet statutory deadlines.
  • The Ministry of Health sets significant accounting policies centrally and provides a template for the preparation of health entities’ financial statements. These processes promote consistent quality in the financial reports of health entities and reduce the number of misstatements we identify.
  • NSW Health recorded an operating surplus of $1.1 billion, an increase of $699 million from 2017–18. This is because of additional capital grants for new facilities, upgrades and redevelopments. The capital replacement ratio (investment in new assets divided by depreciation) for NSW Health is 2.6.
  • NSW Health’s expenses increased by 7.0 per cent in 2018–19 (5.5 per cent in 2017–18). This is one percentage point higher than the projected long-term annual expense growth rate of six per cent. The primary causes for the growth in expenses are increased:
    • employee related expenses because provisions for employee benefits increased when the discount rate decreased
    • operating expenses associated with the opening of Northern Beaches Hospital.
  • Excess annual leave balances continue to increase for the NSW Health workforce, with excess annual leave balances impacting 37 per cent of employees (34 per cent in 2017–18).
  • Health entities should further review their approach to managing excess annual leave in 2019–20 by monitoring current and projected leave balances on a regular basis, agreeing formal leave plans with employees and encouraging staff that perform key control functions to take a minimum of two consecutive weeks’ leave a year as a fraud mitigation strategy.
  • The Ambulance Services continued to report overtime payments higher than other health entities. The Ambulance Service paid its employees $83.1 million in overtime payments in 2018–19 ($74.8 million in 2017–18).
  • We issued a qualified audit opinion for the Ministry of Health's Annual Prudential Compliance Statement for aged care facilities operated by NSW Health. We identified 40 instances of material non-compliance with the Fees and Payments Principles 2014 (No. 2) (the Principles) in 2018–19 (17 in 2017–18).

Audit opinions 

We issued unqualified audit opinions for all health entities and quality of financial reporting continues to improve

We identified fewer misstatements this year, and the errors were less significant. In 2018–19 no errors exceeded $5.0 million (eight errors recorded in 2017–18). Ten health entities conducted a full revaluation of their land, buildings and infrastructure systems in 2018–19, but more robust processes avoided the errors identified in the previous year.

Number of misstatements
Year ended 30 June 2019 2018 2017
  green circle with white tick red circle with white exclamation mark green circle with white tick red circle with white exclamation mark green circle with white tick red circle with white exclamation mark
Less than $50,000 -- -- -- 6 3 3
$50,000 to $249,999 -- 1 -- -- 2 3
$250,000 to $999,999 1 -- -- -- 1 3
$1 million to $4,999,999 -- 2 -- 2 1 5
$5 million and greater -- -- 6 2 1 2
Total number of misstatements 1 3 6 10 8 16

green circle white tick Corrected mistatements. red circle white exclamation mark Uncorrected statements.
Source: Statutory Audit Reports issued by the Audit Office.

We issued a qualified audit opinion for our compliance audit of the Ministry of Health's Annual Prudential Compliance Statement

The Ministry of Health operates eight aged care facilities in NSW and is required to comply with the Fees and Payments Principles 2014 (No. 2) (the Principles) when entering into agreements with and managing payments to and from care recipients. The Principles are set by the Commonwealth Assistant Minister for Social Services. We identified 40 instances of material non-compliance in 2018–19, including:

  • not agreeing maximum accommodation amounts payable with aged care recipients before they entered the residential care services
  • not entering into accommodation agreements with care recipients within the specified period
  • charging incorrect fees for activities or services to one care recipient
  • not refunding two bond balances within the statutory framework
  • not paying the correct amount of interest for 14 care recipients’ bonds refunded during the year.

Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies. They are essential for quality and timely decision making.

This chapter outlines our observations and insights from our financial statement audits of agencies in the health cluster.

Section highlights

  • The number of internal control deficiencies has increased since 2017–18. More than a quarter of control deficiencies are repeat issues and almost a quarter relate to information system controls. Both employee time recording and leave management remain as repeat issues in 2018–19.
  • Control deficiencies that relate to managing employees' leave, employees’ time recording or information system limitations can be difficult for entities to resolve in a timely manner.
  • Agreements for the treatment of New South Wales residents while they are interstate, and interstate residents while they are in New South Wales, are unsigned for Queensland, Victoria and the Australian Capital Territory for 2016–17, 2017–18 and 2018–19.
  • NSW Health recorded $113.6 million in revenue from fees charged to Medicare ineligible patients during 2018–19 but has received payment for less than half of this.
  • NSW Health reported that they completed three major capital projects during 2018–19.
  • As at 30 June 2019 there were 30 ongoing major capital health projects in NSW. The revised capital budget for these projects in total was $2.2 billion more than the original budget of $8.0 billion.
  • Health entities spent $635 million maintaining assets with a fair value of $19.8 billion of assets. Almost all entities were working through backlog maintenance during 2018–19, although several were unable to quantify the backlog.
  • While entities are now regularly reassessing the useful lives of their assets, entities are still using a high volume of assets that are fully depreciated. Due to the age and nature of these assets the impact was not material.

Appendix one – List of 2019 recommendations

Appendix two – Status of 2018 recommendations

Appendix three – Financial data 

Appendix four – Analysis of financial indicators

Appendix five – Analysis of performance against budget

 

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Published

Actions for Internal Controls and Governance 2019

Internal Controls and Governance 2019

Education
Community Services
Finance
Health
Industry
Justice
Planning
Premier and Cabinet
Transport
Treasury
Whole of Government
Compliance
Cyber security
Fraud
Information technology
Internal controls and governance
Management and administration
Procurement
Project management

This report covers the findings and recommendations from the 2018–19 financial audits that relate to internal controls and governance at 40 of the largest agencies in the NSW public sector. The 40 agencies selected for this report constitute around 84 per cent of total expenditure for all NSW public sector agencies.

The report provides insights into the effectiveness of controls and governance processes across the NSW public sector. It evaluates how agencies identify, mitigate and manage risks related to:

  • financial controls
  • information technology controls
  • gifts and benefits
  • internal audit
  • contingent labour
  • sensitive data.

The Auditor-General recommended that agencies do more to prioritise and address vulnerabilities in their internal controls and governance. The Auditor-General also recommended agencies increase the transparency of their management of gifts and benefits by publishing their registers on their websites.

This report analyses the internal controls and governance of 40 of the largest agencies in the NSW public sector for the year ended 30 June 2019.

1. Internal control trends

New, repeat and high risk findings

There was an increase in internal control deficiencies of 12 per cent compared to last year. The increase is predominately due to a 100 per cent increase in repeat financial and IT control deficiencies.

Some agencies attributed the delay in actioning repeat findings to the diversion of staff from their regular activities to implement and operationalise the recent Machinery of Government changes. As a result, actions to address audit recommendations have been deferred or re prioritised, as the changes are implemented.

Agencies need to ensure they are actively managing the risks associated with having these vulnerabilities in internal control systems unaddressed for extended periods of time.

Common findings

A number of findings were common to multiple agencies. These findings often related to areas that are fundamental to good internal control environments and effective organisational governance, such as:

  • out of date policies or an absence of policies to guide appropriate decisions
  • poor record keeping and document retention
  • incomplete or inaccurate centralised registers or gaps in these registers
  • policies, procedures or controls no longer suited to the current organisational structure or business activities.

2. Information technology controls

IT general controls

We examined information security controls over key financial systems that support the preparation of agency financial statements. We found:

  • user access administration deficiencies at 58 per cent of agencies related to granting, review and removal of user access
  • an absence of privileged user activity reviews at 35 per cent of agencies
  • password controls that did not align to password policies at 20 per cent of agencies.

We also found 20 per cent of agencies had deficient IT program change controls, mainly related to segregation of duties in approval and authorisation processes, and user acceptance testing of program changes prior to deployment into production environments. User acceptance testing helps identify potential issues with software incompatibility, operational workflows, absent controls and software issues, as well as areas where training or user support may be required.

3. Gifts and benefits

Gifts and benefits registers

All agencies had a gifts and benefits policy and 90 per cent of agencies maintain a gifts and benefits register. However, 51 per cent of the gifts and benefits registers we examined contained incomplete declarations, such as missing details for the approving officer, value of the gift and/or benefit offered and reasons supporting the decision.

In some cases, gaps in recorded information meant the basis for decisions around gifts and benefits was not always clear, making it difficult to determine whether decisions in those instances were appropriate, compliant with policy and were not direct or indirect inducements to the recipients to favour suppliers or service providers.

Agencies should ensure their gifts and benefits register includes all key fields specified in the Public Service Commission's minimum standards for gifts and benefits. Agencies should also perform regular reviews of the register to ensure completeness and ensure any gift or benefit accepted by a staff member meets the public's expectations for ethical behaviour.

Managing gifts and benefits

We found opportunities to improve gifts and benefits processes and enhance transparency. For example, only three per cent of agencies publish their gifts and benefits registers on their websites.

Agencies can improve management of gifts and benefits by:

  • ensuring agency policies comprehensively cover the elements necessary to make it effective in an operational environment, such as identifying risks specific to the agency and actions that will be taken in the event of a policy breach
  • establishing and publishing a statement of business ethics on the agency's website to clearly communicate expected behaviours to clients, customers, suppliers and contractors
  • providing on-going training, awareness activities and support to employees, not just at induction
  • publishing their gifts and benefits registers on their websites to demonstrate a commitment to a transparently ethical environment.
Reporting and monitoring

Only 35 per cent of agencies reported trends in the number and nature of gifts and benefits recorded in their registers to the agency's senior executive management and/or a governance committee.

Agencies should regularly report to the agency executive or other governance committee on trends in the offer and acceptance of gifts and benefits.

4. Internal audit

Obtaining value from the internal audit function

Agencies have established and maintained internal audit functions to provide assurance on the effectiveness of agency controls and governance systems. However, we identified areas where agencies' internal audit functions could improve their processes to add greater value. For example, only 73 per cent of CAEs regularly attend meetings of the agency board or executive management committee.

Internal audit functions can add greater value by involving the CAE more extensively in executive forums as an observer.

Internal audit functions should also consider producing an annual report on internal audit. An annual report allows the internal audit function to report on their performance and add value by drawing to the attention of audit and risk committees and senior management strategic issues, thematic trends and emerging risks.

Role of the Chief Audit Executive

Forty-five per cent of agencies assigned responsibilities to the Chief Audit Executive (CAE) that were broader than internal audit, but 17 per cent of these had not documented safeguards to protect the independence of the CAE.

The reporting lines and status of the CAE at some agencies also needs review. At two agencies, the CAE reported to the CFO.

Agencies should ensure:

  • the reporting lines for the CAE comply with the NSW Treasury policy, and the CAE does not report functionally or administratively to the finance function or other significant recipients of internal audit services
  • the CAE's duties are compatible with preserving their independence and where threats to independence exist, safeguards are documented and approved.
Quality assurance and improvement program

Thirty-five per cent of agencies did not have a documented quality assurance and improvement program for its internal audit function.

The policy and the International Standards for the Professional Practice of Internal Auditing require agencies to have a documented quality assurance and improvement program. The results of this program should be reported annually.

Agencies should ensure there is a documented and operational Quality Assurance and Improvement Program for the internal audit function that covers both internal and external assessments.

5. Managing contingent labour

Obtaining value for money from contingent labour

According to NSW Procurement data, spend on contingent labour has increased by 75 per cent over the last five years, to $1.5 billion in 2018–19. Improvements in internal processes and a renewed focus on agency monitoring and oversight of contingent labour can help ensure agencies get the best value for money from their contingent workforces.

Agencies can improve their management of contingent labour by:

  • preparing workforce plans to inform their resourcing strategy and ensure that engaging contingent labour aligns with the strategy and best meets business needs
  • involving agency human resources units in decisions about engaging contingent labour
  • regularly reporting on contingent labour use and tenure to agency executive teams
  • strengthening on-boarding and off-boarding processes.

We also found 57 per cent of the 23 agencies we examined with contingent labour spend of more than $5 million in 2018–19 have implemented the government's vendor management system and service provider 'Contractor Central'.

6. Managing sensitive data

Identifying and assessing sensitive data

Sixty-eight per cent of agencies maintain an inventory of their sensitive data and where it resides. However, these inventories are not always complete and risks may be overlooked.

Agencies can improve processes to manage sensitive data by:

  • identifying and maintaining an inventory of sensitive data through a comprehensive and structured process
  • assessing the criticality and sensitivity of the data so that protection of high risk data can be prioritised.
Managing data breaches

Eighty-eight per cent of agencies have established policies to respond to potential data breaches when they are identified and 70 per cent of agencies maintain a register to record key information in relation to identified data breach incidents.

Agencies should maintain a data breach register to effectively manage the actions undertaken to contain, evaluate and remediate each data breach.

 

This report covers the findings and recommendations from our 2018–19 financial audits that relate to internal controls and governance at 40 of the largest agencies (refer to Appendix three) in the NSW public sector. The 40 agencies selected for this volume constitute around 84 per cent of total expenditure for all NSW public sector agencies.

Although the report includes several agencies that have changed as a result of the Machinery of Government changes that were effective from 1 July 2019, its focus on sector wide issues and insights means that its findings remain relevant to NSW public sector agencies, including newly formed agencies that have assumed the functions of abolished agencies.

This report offers insights into internal controls and governance in the NSW public sector

This is the third report dedicated to internal controls and governance at NSW State Government agencies. The report provides insights into the effectiveness of controls and governance processes in the NSW public sector by:

  • highlighting the potential risks posed by weaknesses in controls and governance processes
  • helping agencies benchmark the adequacy of their processes against their peers
  • focusing on new and emerging risks, and the internal controls and governance processes that might address those risks.

Without strong governance systems and internal controls, agencies increase the risks associated with effectively managing their finances and delivering services to citizens. For example, if they do not have strong information technology controls, sensitive information may be at risk of unauthorised access and misuse.

Areas of specific focus of the report have changed since last year

Last year's report topics included transparency and performance reporting, management of purchasing cards and taxi use, and fraud and corruption control. We are reporting on new topics this year and re-visiting agency management of gifts and benefits, which we first covered in our 2017 report. Re-visiting topics from prior years provides a baseline to show the NSW public sectors’ progress implementing appropriate internal controls and governance processes to mitigate existing, new and emerging risks in the public sector.

Our audits do not review all aspects of internal controls and governance every year. We select a range of measures and report on those that present heightened risks for agencies to mitigate. This year the report focusses on:

  • internal control trends
  • information technology controls, including access to agency systems
  • protecting sensitive information held within agencies
  • managing large and diverse workforces (controls around employing and managing contingent workers)
  • maintaining an ethical culture (management of gifts and benefits)
  • effectiveness of internal audit function and its oversight by Audit and Risk Committees.

The findings in this report should not be used to draw conclusions on the effectiveness of individual agency control environments and governance arrangements. Specific financial reporting, internal controls and audit observations are included in the individual 2019 cluster financial audit reports, which will be tabled in parliament from November to December 2019.

Internal controls are processes, policies and procedures that help agencies to:

  • operate effectively and efficiently
  • produce reliable financial reports
  • comply with laws and regulations
  • support ethical government.

This chapter outlines the overall trends for agency controls and governance issues, including the number of audit findings, the degree of risk those deficiencies pose to the agency, and a summary of the most common deficiencies we found across agencies. The rest of this report presents this year’s controls and governance findings in more detail.

Key conclusions and sector wide learnings

We identified four high risk findings, compared to six last year. None of the findings are common with those in the previous year. There was an overall increase of 12 per cent in the number of internal control deficiencies compared to last year. The increase is predominately due to a 100 per cent increase in the number of repeat financial and IT control deficiencies.
 
Some agencies attributed the delay in actioning repeat findings to the diversion of staff from their regular activities to implement and operationalise the recent Machinery of Government changes. As a result, actions to address audit recommendations have been deferred or re-prioritised, as the changes are implemented. Agencies need to ensure they are actively managing the risks associated with having these vulnerabilities in internal control systems unaddressed for extended periods of time.
 
We also identified a number of findings that were common to multiple agencies. These common findings often related to areas that are fundamental to good internal control environments and effective organisational governance. Examples include:
  • out of date policies or an absence of policies to guide appropriate decisions
  • poor record keeping and document retention
  • incomplete or inaccurate centralised registers or gaps in these registers.

Policies, procedures and internal controls should be properly designed, be appropriate for the current organisational structure and its business activities, and work effectively.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency controls to manage key financial systems.

Key conclusions and sector wide learnings
Government agencies’ financial reporting is heavily reliant on information technology (IT). We continue to see a high number of deficiencies related to IT general controls, particularly those related to user access administration. These controls are key in adequately protecting IT systems from inappropriate access and misuse.
IT is also important to the delivery of agency services. These systems often provide the data to help monitor the efficiency and effectiveness of agency processes and services they deliver. Our financial audits do not review all agency IT systems. For example, IT systems used to support agency service delivery are generally outside the scope of our financial audit. However, agencies should also consider the relevance of our findings to these systems.
Agencies need to continue to focus on assessing the risks of inappropriate access and misuse and the implementation of controls to adequately protect their systems, focussing on the processes in place to grant, remove and monitor user access, particularly privileged user access.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency controls to manage gifts and benefits. 

Key conclusions and sector wide learnings

We found most agencies have implemented the Public Service Commission's minimum standards for gifts and benefits. All agencies had a gifts and benefits policy and 90 per cent of agencies maintained a gifts and benefits register and provided some form of training to employees on the treatment of gifts and benefits.

Based on our analysis of agency registers, we found some areas where opportunities existed to make processes more effective. In some cases, gaps in recorded information meant the basis for decisions around gifts and benefits was not always clear, making it difficult to determine whether decisions in those instances were appropriate and compliant with policy. Fifty-one per cent of the gifts and benefits registers reviewed contained declarations where not all fields of information had been completed. Seventy-seven per cent of agencies that maintained a gifts and benefits register did not include all key fields suggested by the minimum standards.

Areas where agencies can improve their management of gifts and benefits include:

  • ensuring agency policies comprehensively cover the elements necessary to make it effective in an operational environment, such as identifying risks specific to the agency and actions that will be taken in the event of a policy breach
  • establishing and publishing a statement of business ethics on the agency's website to clearly communicate expected behaviours to clients, customers,suppliers and contractors
  • updating gifts and benefits registers to include all key fields suggested by the minimum standards, as well as performing regular reviews of the register to ensure completeness
  • providing on-going training, awareness activities and support to employees, not just at induction
  • regularly reporting gifts and benefits to executive management and/or a governance committee such as the audit and risk committee, focussing on trends in the number and types of gifts and benefits offered to and accepted by agency staff
  • publishing their gifts and benefits registers on their websites to demonstrate a commitment to a transparently ethical environment.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency internal audit functions.

Key conclusions and sector wide learnings 

We found agencies have established and maintained internal audit functions to provide assurance on the effectiveness of agency controls and governance systems as required by TPP15-03 'Internal Audit and Risk Management Policy for the NSW Public Sector'. However, we identified areas where agencies' internal audit functions could improve their processes to add greater value, including: 

  • documenting and implementing safeguards to address conflicting roles performed by the Chief Audit Executive (CAE)
  • ensuring the reporting lines for the CAE comply with the NSW Treasury policy, and the CAE reports neither functionally or administratively to the finance function or other significant recipients of internal audit services
  • involving the CAE more extensively in executive forums as an observer
  • documenting a Quality Assurance and Improvement Program for the internal audit function and performing both internal and external performance assessments to identify opportunities for continuous improvement
  • reporting against key performance indicators or a balanced scorecard and producing an annual report on internal audit to bring to the attention of the audit and risk committee and senior management strategic issues, thematic trends and emerging risks that may require further attention or resources.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency controls to on-board, manage and off-board contingent labour.

Key conclusions and sector wide learnings

Agencies have implemented controls to manage contingent labour and most agencies have some level of reporting and oversight of contingent labour at an executive level. However, the increasing trend in spend on contingent labour warrants a renewed focus on agency monitoring and oversight of their use of contingent labour. Over the last five years spend on contingent labour has increased by 75 per cent, to $1.5 billion in 2018–19.

There are also some key gaps that limit the ability of agencies to effectively manage contingent labour. Key areas where agencies can improve their management of contingent labour include: 

  • preparing workforce plans to inform their resourcing strategy, and confirm prior to engaging contingent labour, that this solution aligns with the strategy and best meets business needs
  • involving agency human resources units in decisions about engaging contingent labour
  • regularly reporting on contingent labour use to agency executive teams, particularly in terms of trends in agency spend, tenure and compliance with policies and procedures
  • strengthening on-boarding and off-boarding processes, including establishing checklists to on-board and off-board contingent labour, making provisions for knowledge transfer, and assessing, documenting and capturing performance information.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of governance and processes in relation to the management of sensitive data.

Key conclusions and sector wide learnings

Information technology risks are rapidly increasing. More interfaces between agencies and greater connectivity means the amounts of data agencies generate, access, store and share continue to increase. Some of this information is sensitive information, which is protected by the Privacy Act 1988.

It is important that agencies understand what sensitive data they hold, the risks associated with the inadvertent release of this information and how they are mitigating those risks. We found that agencies need to continue to identify and record their sensitive data, as well as expand the methods they use to identify sensitive data. This includes data held in unstructured repositories, such as network shared drives and by agency service providers.

Eighty-eight per cent of agencies have established policies to respond to potential data breaches when they are identified and 70 per cent of agencies maintain a register to record key information in relation to identified data breach incidents.

Key areas where agencies can improve their management of sensitive data include:

  • identifying sensitive data, based on a comprehensive and structured process and maintaining an inventory of the data
  • assessing the criticality and sensitivity of the data so that the protection of high risk data can be prioritised
  • developing comprehensive data breach management policies to ensure data breaches are appropriately managed
  • maintaining a data breach incident register to record key information in relation to identified data breaches incidents, including the estimated cost of the breach
  • providing on-going training and awareness activities to employees in relation to sensitive data and managing data breaches.

Appendix one – List of 2019 recommendations 

Appendix two – Status of 2018 recommendations

Appendix three – In-scope agencies

 

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Published

Actions for Ensuring contract management capability in government - HealthShare NSW

Ensuring contract management capability in government - HealthShare NSW

Health
Management and administration
Procurement
Project management

This report examined whether HealthShare NSW, a part of NSW Health, has the required contract management capability to effectively manage goods and services contracts valued over $250,000. 

The report found that HealthShare has a procurement framework that should support effective contract management, but it is not applying it consistently. In particular, the audit found that HealthShare was not applying key contract management elements to over 80 per cent of the high-value contracts it manages. The audit also found that HealthShare’s contract management practices were limited by inadequate performance monitoring.

'Effective contract management is essential to ensure the contracts HealthShare enters into are delivering as expected and ensuring value for money,' said the Auditor-General. 'Without this, the value for money or savings HealthShare achieves when it negotiates these contracts is at risk of being eroded over the life of the contract.'

The report recommends that NSW Health develop a performance improvement plan to ensure HealthShare is fully compliant with procurement policies and that NSW Health meets its obligations under the Government's Accreditation Program for Goods and Services Procurement.

HealthShare is a NSW Health entity responsible for providing shared services, including procurement, to support the delivery of patient care within the NSW health system. In 2018, HealthShare procured high value goods and services contracts with an annual estimated total spend of around $1.8 billion, with most of the contracts of long duration.

NSW Government agencies are increasingly delivering services and projects through contracts with third parties. These contracts can be complex and governments face challenges in negotiating and implementing them effectively. A robust contract management framework helps ensure all parties meet their obligations, contractual relationships are well managed, agencies achieve value for money, and deliverables meet the required standards and agreed timeframes.

Contract management capability is a broad term, which can include aspects of individual staff capability (such as staff knowledge, skills and experience) as well as organisational capability (such as policies, frameworks and processes).

The NSW Procurement Board is responsible for overseeing the Government's procurement system, setting policy and ensuring compliance. It has accredited the Health Administration Corporation (HAC) to procure goods and services with no upper financial limit. Under the terms of this accreditation, the Secretary, NSW Health (as head of HAC) has delegated the procurement of high-value (over $250,000) goods and services contracts within NSW Health to only the Ministry of Health and HealthShare NSW (HealthShare).

HealthShare NSW (HealthShare) is a NSW Health entity responsible for providing shared services, including procurement, to support the delivery of patient care within the NSW health system. In 2018, HealthShare procured high-value goods and services contracts with an annual estimated total spend of around $1.8 billion, with most of the contracts of long duration.

HealthShare’s Contract Management Guide states that, without rigorous contract management, 75 per cent of projected sourcing savings can disappear within 18 months of the contract starting.

This audit examined whether HealthShare has the required capability to effectively manage high-value goods and services contracts. Contracts we examined included critical items such as food services in hospitals, patient transport services, intravenous equipment and kidney dialysis services, where risks include patient safety as well as value for money. We did not examine infrastructure, construction or information communication and technology contracts. We also did not examine HealthShare’s sourcing processes, including identifying business needs, tendering and contract award.

We assessed HealthShare against the following criteria:

  1. HealthShare's systems, policies and procedures support effective contract management and are consistent with relevant frameworks, policies and guidelines.
  2. HealthShare has capable personnel to effectively conduct the monitoring activities throughout the life of the contract.

We included the NSW Public Service Commission and NSW Treasury, through NSW Procurement, as auditees because they administer policies which directly affect contract management capability. These include:

  • NSW Procurement Board Directions and policies
  • NSW Government Procurement Policy Framework
  • Accreditation Program for Goods and Services Procurement
  • the NSW Public Sector Capability Framework.

NSW Procurement was transferred to NSW Treasury from the former Department of Finance, Services and Innovation on 1 July 2019 as part of changes to government administrative arrangements.

Conclusion
HealthShare is not applying the capability needed to effectively manage high-value (over $250,000) goods and services contracts. HealthShare's procurement framework includes elements that should support effective contract management, and it has a systematic approach to managing staff contract management capability. That said, HealthShare is not implementing key contract management elements of its own framework. As such, the value for money or savings it achieves when it negotiates contracts is at risk of being eroded over the life of these contracts.
Effective contract management is essential for HealthShare to ensure contracts it enters into are delivering the goods and services expected and achieving value for money, safety and quality. The Ministry of Health and HealthShare have invested in developing and implementing systems and tools to support effective contract management. In line with its obligations under the Agency Accreditation Program for Goods and Services Procurement (accreditation program), the Ministry of Health mandates the use of contract management plans for high-value contracts. The Ministry of Health also requires that all health entities use the PROcure contract management system for ongoing management of contracts with a value over $150,000. HealthShare is not complying with these directions for over 80 per cent of the contracts it manages.
In the absence of HealthShare following its framework, and the Ministry of Health’s directions, we looked for other evidence that HealthShare was effectively managing high-value contracts. We found that HealthShare’s contract management practices were limited by inadequate performance monitoring.
When Local Health Districts (LHDs) need to procure high-value goods and services, the Ministry of Health’s procurement policy requires that they use HealthShare to source and manage the procurement. This is to manage risk and provide oversight of procurement and contracts across the NSW health system. Despite this policy, HealthShare was only managing the sourcing stage of the procurement and transferring responsibility for contract management to the relevant LHD.

Appendix one – Response from agencies

Appendix two – Contract performance management summary

Appendix three – About the audit

Appendix four – Performance auditing

 

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Parliamentary Reference: Report number #328 - released 31 October 2019

Published

Actions for Mental health service planning for Aboriginal people in New South Wales

Mental health service planning for Aboriginal people in New South Wales

Health
Management and administration
Project management
Service delivery
Workforce and capability

A report released by the Auditor-General for New South Wales, Margaret Crawford, has found that NSW Health is not forming effective partnerships with Aboriginal communities to plan, design and deliver appropriate mental health services. There is limited evidence that NSW Health is using the knowledge and expertise of Aboriginal communities to guide how mental health care is structured and delivered.

Mental illness (including substance use disorders) is the main contributor to lower life expectancy and increased mortality in the Aboriginal population of New South Wales. It contributes to a higher burden of disease and premature death at rates that are 40 per cent higher than the next highest chronic disease group, cardiovascular disease.1 

Aboriginal people have significantly higher rates of mental illness than non Aboriginal people in New South Wales. They are more likely to present at emergency departments in crisis or acute phases of mental illness than the rest of the population and are more likely to be admitted to hospital for mental health treatments.2 

In acknowledgement of the significant health disparities between Aboriginal and non Aboriginal people, NSW Health implemented the NSW Aboriginal Health Plan 2013 2023 (the Aboriginal Health Plan). The overarching message of the Aboriginal Health Plan is ‘to build respectful, trusting and effective partnerships with Aboriginal communities’ and to implement ‘integrated planning and service delivery’ with sector partners. Through the Plan, NSW Health commits to providing culturally appropriate and ‘holistic approaches to the health of Aboriginal people'.

The mental health sector is complex, involving Commonwealth, state and non government service providers. In broad terms, NSW Health has responsibility to support patients requiring higher levels of clinical support for mental illnesses, while the Commonwealth and non government organisations offer non acute care such as assessments, referrals and early intervention treatments.

The NSW Health network includes 15 Local Health Districts and the Justice Health and Forensic Mental Health Network that provide care to patients during acute and severe phases of mental illness in hospitals, prisons and community service environments. This includes care to Aboriginal patients in the community at rates that are more than four times higher than the non Aboriginal population. Community services are usually provided as follow up after acute admissions or interactions with hospital services. The environments where NSW Health delivers mental health care include:

  • hospital emergency departments, for short term assessment and referral
  • inpatient hospital care for patients in acute and sub acute phases of mental illness
  • mental health outpatient services in the community, such as support with medications
  • custodial mental health services in adult prisons and juvenile justice centres.

The NSW Government is reforming its mental health funding model to incrementally shift the balance from hospital care to enhanced community care. In 2018–19, the NSW Government committed $400 million over four years into early intervention and specialist community mental health teams.

This audit assessed the effectiveness of NSW Health’s planning and coordination of mental health services and service pathways for Aboriginal people in New South Wales. We addressed the audit objective by answering three questions: 

  1. Is NSW Health using evidence to plan and inform the availability of mental health services for Aboriginal people in New South Wales?
  2. Is NSW Health collaborating with partners to create accessible mental health service pathways for Aboriginal people?
  3. Is NSW Health collaborating with partners to ensure the appropriateness and quality of mental health services for Aboriginal people?
Conclusion

NSW Health is not meeting the objectives of the NSW Aboriginal Health Plan, to form effective partnerships with Aboriginal Community Controlled Health Services and Aboriginal communities to plan, design and deliver mental health services.

There is limited evidence that existing partnerships between NSW Health and Aboriginal communities meet its own commitment to use the ‘knowledge and expertise of the Aboriginal community (to) guide the health system at every level, including (for) the identification of key issues, the development of policy solutions, the structuring and delivery of services' 3 and the development of culturally appropriate models of mental health care.

NSW Health is planning and coordinating its resources to support Aboriginal people in acute phases of mental illness in hospital environments. However, it is not effectively planning for the supply and delivery of sufficient mental health services to assist Aboriginal patients to manage mental illness in community environments. Existing planning approaches, data and systems are insufficient to guide the $400 million investment into community mental health services announced in the 2018–19 Budget.

NSW Health is not consistently forming partnerships to ensure coordinated care for patients as they move between mental health services. There is no policy to guide this process and practices are not systematised or widespread.

In this report, the term ‘Aboriginal people’ is used to describe both Aboriginal and Torres Strait Islander peoples. The Audit Office of NSW acknowledges the diversity of traditional countries and Aboriginal language groups across the state of New South Wales.


1 Australian Burden of Disease Study: Impact and causes of illness and death in Aboriginal and Torres Strait Islander people 2011 (unaudited).
2 Australian Institute of Health and Welfare data 2016–17 (unaudited).
3 NSW Health, The Aboriginal Health Plan 2013-2023.

In May 2019, the Audit Office of New South Wales invited Aboriginal mental health clinicians and policy experts from government and non-government organisations to attend a one-day workshop. Workshop attendees advised on factors that improve the quality and appropriateness of mental health care for Aboriginal people in New South Wales. They described appropriate mental health care as:

  • culturally safe, allowing Aboriginal people to draw strength in their identity, culture and community
  • person centred and focussed on individual needs
  • delivered by culturally competent staff with no bias
  • holistic, trauma-informed and focussed on early intervention where possible
  • delivered in places that are appropriate including outreach to homes and communities
  • welcoming of the involvement of local Aboriginal community and connected to local knowledge and expertise including totems and kinship structures. 

The definition of 'appropriate' mental health care for Aboriginal people throughout this report is based on this advice.

Aboriginal people access emergency services at much higher rates than non-Aboriginal people

The choices that people make in relation to health service options provide some insight into the suitability and appropriateness of the service to their needs.

Aboriginal people have different mental health service use patterns than non-Aboriginal people. Aboriginal people are much more likely to be in a crisis situation before receiving mental health services, usually in an emergency department of a hospital.

Aboriginal people make up three per cent of the total New South Wales population, but they constitute 11 per cent of emergency department presentations for mental health treatments. In regional areas, Aboriginal people make up 20.5 per cent of presentations at emergency departments for mental health reasons. 

A number of factors help to explain Aboriginal mental health service usage patterns. According to government and non-government mental health organisations:

  • emergency department services are better known to Aboriginal people than other mental health services
  • community-based models of care are not appropriate for Aboriginal people
  • Aboriginal people are reluctant to access community-based mental health services to prevent crisis situations
  • community mental health services are not available for Aboriginal people after hours and during the weekend, so emergency services are the only option.

The statewide proportions of Aboriginal people presenting at emergency departments for mental health treatments has been increasing over time (Exhibit 6).

Appendix one – Response from agency

Appendix two – The NSW Aboriginal Health Plan

Appendix three – About the audit

Appendix four – Performance auditing

 

Parliamentary Reference: Report number #326 - released 29 August 2019

Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

Published

Actions for Engagement of probity advisers and probity auditors

Engagement of probity advisers and probity auditors

Transport
Education
Health
Compliance
Internal controls and governance
Procurement
Project management
Workforce and capability

Three key agencies are not fully complying with the NSW Procurement Board’s Direction for engaging probity practitioners, according to a report released today by the Acting Auditor-General for New South Wales, Ian Goodwin. They also do not have effective processes to achieve compliance or assure that probity engagements achieved value for money.

Probity is defined as the quality of having strong moral principles, honesty and decency. Probity is important for NSW Government agencies as it helps ensure decisions are made with integrity, fairness and accountability, while attaining value for money.

Probity advisers provide guidance on issues concerning integrity, fairness and accountability that may arise throughout asset procurement and disposal processes. Probity auditors verify that agencies' processes are consistent with government laws and legislation, guidelines and best practice principles. 

According to the NSW State Infrastructure Strategy 2018-2038, New South Wales has more infrastructure projects underway than any state or territory in Australia. The scale of the spend on procuring and constructing new public transport networks, roads, schools and hospitals, the complexity of these projects and public scrutiny of aspects of their delivery has increased the focus on probity in the public sector. 

A Procurement Board Direction, 'PBD-2013-05 Engagement of probity advisers and probity auditors' (the Direction), sets out the requirements for NSW Government agencies' use and engagement of probity practitioners. It confirms agencies should routinely take into account probity considerations in their procurement. The Direction also specifies that NSW Government agencies can use probity advisers and probity auditors (probity practitioners) when making decisions on procuring and disposing of assets, but that agencies:

  • should use external probity practitioners as the exception rather than the rule
  • should not use external probity practitioners as an 'insurance policy'
  • must be accountable for decisions made
  • cannot substitute the use of probity practitioners for good management practices
  • not engage the same probity practitioner on an ongoing basis, and ensure the relationship remains robustly independent. 

The scale of probity spend may be small in the context of the NSW Government's spend on projects. However, government agencies remain responsible for probity considerations whether they engage external probity practitioners or not.

The audit assessed whether Transport for NSW, the Department of Education and the Ministry of Health:

  • complied with the requirements of ‘PBD-2013-05 Engagement of Probity Advisers and Probity Auditors’
  • effectively ensured they achieved value for money when they used probity practitioners.

These entities are referred to as 'participating agencies' in this report.

We also surveyed 40 NSW Government agencies with the largest total expenditures (top 40 agencies) to get a cross sector view of their use of probity practitioners. These agencies are listed in Appendix two.

Conclusion

We found instances where each of the three participating agencies had not fully complied with the requirements of the NSW Procurement Board Direction ‘PBD-2013-05 Engagement of Probity Advisers and Probity Auditors’ when they engaged probity practitioners. We also found they did not have effective processes to achieve compliance or assure the engagements achieved value for money.

In the sample of engagements we selected, we found instances where the participating agencies did not always:

  • document detailed terms of reference
  • ensure the practitioner was sufficiently independent
  • manage probity practitioners' independence and conflict of interest issues transparently
  • provide practitioners with full access to records, people and meetings
  • establish independent reporting lines   reporting was limited to project managers
  • evaluate whether value for money was achieved.

We also found:

  • agencies tend to rely on only a limited number of probity service providers, sometimes using them on a continuous basis, which may threaten the actual or perceived independence of probity practitioners
  • the NSW Procurement Board does not effectively monitor agencies' compliance with the Direction's requirements. Our enquiries revealed that the Board has not asked any agency to report on its use of probity practitioners since the Direction's inception in 2013. 

There are no professional standards and capability requirements for probity practitioners

NSW Government agencies use probity practitioners to independently verify that their procurement and asset disposal processes are transparent, fair and accountable in the pursuit of value for money. 

Probity practitioners are not subject to regulations that require them to have professional qualifications, experience and capability. Government agencies in New South Wales have difficulty finding probity standards, regulations or best practice guides to reference, which may diminish the degree of reliance stakeholders can place on practitioners’ work.

The NSW Procurement Board provides direction for the use of probity practitioners

The NSW Procurement Board Direction 'PBD-2013-15 for engagement of probity advisers and probity auditors' outlines the requirements for agencies' use of probity practitioners in the New South Wales public sector. All NSW Government agencies, except local government, state owned corporations and universities, must comply with the Direction when engaging probity practitioners. This is illustrated in Exhibit 1 below.

Published

Actions for Industry 2018

Industry 2018

Industry
Asset valuation
Cyber security
Financial reporting
Information technology
Internal controls and governance
Service delivery

The Auditor-General for New South Wales, Margaret Crawford, released her report today on the Industry cluster. The report focuses on key observations and findings from the most recent financial audits of agencies in the cluster. Cluster agencies received unqualified audit opinions for 41 out of the 47 financial statements presented for audit for 30 June 2018. Six audits remain incomplete. 'While it is pleasing to note that unqualified audit opinions have been issued, the timeliness of financial reporting needs to be improved through better oversight, prompt resolution of issues, and an increased focus on early close procedures', the Auditor-General said.

This report analyses the results of our audits of financial statements of the Industry cluster for the year ended 30 June 2018. The table below summarises our key observations.

This report provides parliament and other users of the Industry cluster agencies' financial statements with the results of our audits, including our observations, analysis, conclusions and recommendations in the following areas:

  • financial reporting
  • audit observations
  • service delivery.

The Department of Industry (the Department) is the lead agency in a cluster of 50 agencies. Other significant agencies in the cluster include Local Land Services, New South Wales Rural Assistance Authority, Technical and Further Education Commission (TAFE NSW), various sporting agencies, Forestry Corporation NSW and Water NSW.

The cluster:

Financial reporting is an important element of good governance. Confidence and transparency in public sector decision making are enhanced when financial reporting is accurate and timely.

This chapter outlines our audit observations related to the financial reporting of agencies in the Industry cluster for 2018.
 

Observation Conclusions and recommendations
2.1 Quality of financial reporting
Unqualified audit opinions were issued for 41 out of 47 financial statement audits. Six audits are continuing.

The number of misstatements identified in financial statements submitted for audit increased from 73 in 2016–17 to 92 in 2017–18.
Conclusion: Agencies continue to address financial reporting issues and ensure significant matters that may impact the audit opinion are appropriately dealt with. The increase in the number of misstatements indicates a renewed focus on quality is required.
2.2 Timeliness of financial reporting
Nineteen out of 37 audit opinions were issued within the statutory deadline. Delays occurred due to the time required to resolve issues identified during the audit, or to obtain appropriate evidence to support balances or disclosures in the financial statements. There were also delays in receiving the signed certification from the agency, required before we can issue an audit opinion.

We reviewed the conduct of early close procedures at 17 agencies. Fifteen of these agencies were assessed as not fully addressing mandatory early close procedures.
Recommendation: Timeliness of financial reporting should be improved through better oversight of the preparation of financial statements, prompt resolution of issues, and an increased focus on early close procedures.
2.3 Key financial reporting issues
Information system limitations continue at TAFE NSW. TAFE NSW implemented additional processes to verify the accuracy and completeness of revenue from student fees. Conclusion: Procedures to address system limitations are costly, causing delays in financial reporting and increased resource commitments for staff, contractors and audit.
Misstatements and internal control issues continue to be identified in accounting for Crown land. The information system used to record Crown land was not designed to facilitate efficient financial reporting. These limitations and other control weaknesses impacted the completeness and accuracy of the Department's financial statements.
Recommendation: The Department should address system limitations and control weaknesses to ensure complete and accurate reporting for Crown land.
Unprocessed Aboriginal land claims continue to increase. Recommendation (repeat issue): The Department should reduce unprocessed Aboriginal land claims.
2.4 Financial information and sustainability
Cluster agencies recorded a combined surplus of $58.0 million compared to a combined deficit of $86.0 million in the previous year.

 

We identified five agencies with potential sustainability issues such as low liquidity or negative net assets. Conclusion: Adequate arrangements are in place to mitigate potential sustainability issues. These arrangements include a commitment from the Department to provide financial support if required. 

Appropriate financial controls help ensure the efficient and effective use of resources and administration of agency policies. They are essential for quality and timely decision making.

This chapter outlines our observations and insights from:

  • our financial statement audits of agencies in the Industry cluster for 2018
  • the areas of focus identified in the Audit Office work program.

The Audit Office Annual Work Program provides a summary of all audits to be conducted within the proposed time period as well as detailed information on the areas of focus for each of the NSW Government clusters.

Observation Conclusions and recommendations
3.1 Internal control
Almost one in three internal control issues identified in 2017–18 were repeat issues. Recommendation (repeat issue): Recommendations to management to address internal control issues from prior years should be addressed promptly to reduce risks and improve processes.
3.2 Information technology controls
User access administration over financial systems remains an area of weakness. Two high risk and 18 moderate risk issues related to user access administration across nine agencies were identified. Recommendation (repeat issue): Agencies' controls over administration of user access to critical systems should:
  • retain documentation of approvals to create, modify and deactivate user access
  • allocate appropriate access rights
  • perform and document regular user access reviews
  • log and monitor privileged/super user account activity
  • deactivate terminated user access on a timely basis.
3.3 Annual work program
Errors continue to be identified in the Crown land database.

Instances were identified where Crown land was not recognised by the appropriate entity, or was recognised by more than one entity.
Recommendation: The Department should ensure the Crown land database is complete and accurate so state agencies and local government councils are better informed about the Crown land they control.
Approximately 700 managers of Crown land do not submit financial statements required by the Public Finance and Audit Act 1983. NSW Treasury and the Department are continuing work to clarify reporting arrangements for these entities.
3.4 Managing maintenance
Some cluster agencies do not monitor their backlog maintenance. Consequently, the total backlog maintenance in the Industry cluster is unknown. This impacts the reliability and consistency of information about assets and their condition. When backlog maintenance is unknown, it is difficult for agencies to develop an accurate and effective maintenance plan that focuses on areas of highest need. It also means agencies' maintenance plans are reactive rather than preventative.
Effective maintenance planning helps agencies to:
  • quantify and budget asset maintenance costs
  • support service delivery at the lowest possible long-term cost
  • reduce service disruptions and losses due to asset failure
  • identify and respond to risks posed by the age and condition of assets.
Recommendation: Cluster agencies should develop an asset maintenance plan and complete an assessment of the condition of their assets to identify any maintenance backlogs. 
Maintenance budgets in some cluster agencies are not set based on actual maintenance needs. Recommendation: Cluster agencies should set their maintenance budgets based on identified maintenance needs to more accurately budget and prioritise expenditure.

Agencies in the Industry cluster provide services across a wide variety of areas. This chapter outlines certain service delivery outcomes for 2017–18 for the Industry cluster. It provides important contextual information about the cluster's operation, but the data on activity levels and performance is provided by Cluster agencies. The Audit Office does not have a specific mandate to audit performance information. Accordingly, the information in this chapter is unaudited. 

In our recent performance audit, Progress and measurement of Premier's Priorities, we identified 12 limitations of performance measurement and performance data. We recommended that the Department of Premier and Cabinet ensure that processes to check and verify data are in place for all agency data sources.

Published

Actions for Internal Controls and Governance 2018

Internal Controls and Governance 2018

Education
Community Services
Finance
Health
Industry
Justice
Planning
Premier and Cabinet
Transport
Treasury
Whole of Government
Environment
Compliance
Cyber security
Financial reporting
Fraud
Information technology
Internal controls and governance
Management and administration
Procurement
Project management

The Auditor-General for New South Wales Margaret Crawford found that as NSW state government agencies’ digital footprint increases they need to do more to address new and emerging information technology (IT) risks. This is one of the key findings to emerge from the second stand-alone report on internal controls and governance of the 40 largest NSW state government agencies.

This report analyses the internal controls and governance of the 40 largest agencies in the NSW public sector for the year ended 30 June 2018.

This report covers the findings and recommendations from our 2017–18 financial audits that relate to internal controls and governance at the 40 largest agencies (refer to Appendix three) in the NSW public sector.

This report offers insights into internal controls and governance in the NSW public sector

This is our second report dedicated to internal controls and governance at NSW State Government agencies. The report provides insights into the effectiveness of controls and governance processes in the NSW public sector by:

  • highlighting the potential risks posed by weaknesses in controls and governance processes
  • helping agencies benchmark the adequacy of their processes against their peers
  • focusing on new and emerging risks, and the internal controls and governance processes that might address those risks.

Without strong governance systems and internal controls, agencies increase the risks associated with effectively managing their finances and delivering services to citizens. The way agencies deliver services increasingly relies on contracts and partnerships with the private sector. Many of these arrangements deliver front line services, but others provide less visible back office support. For example, an agency may rely on an IT service provider to manage a key system used to provide services to the community. The contract and service level agreements are only truly effective where they are actively managed to reduce risks to continuous quality service delivery, such as interruptions caused by system outages, cyber security attacks and data security breaches.

Our audits do not review all aspects of internal controls and governance every year. We select a range of measures, and report on those that present heightened risks for agencies to mitigate. This report divides these into the following five areas:

  1. Internal control trends
  2. Information technology (IT), including IT vendor management
  3. Transparency and performance reporting
  4. Management of purchasing cards and taxis
  5. Fraud and corruption control.

The findings in this report should not be used to draw conclusions on the effectiveness of individual agency control environments and governance arrangements. Specific financial reporting, controls and service delivery comments are included in the individual 2018 cluster financial audit reports, which will be tabled in Parliament from November to December 2018.

The focus of the report has changed since last year

Last year's report topics included asset management, ethics and conduct, and risk management. We are reporting on new topics this year. We plan to introduce new topics and re-visit our previous topics in subsequent reports on a cyclical basis. This will provide a baseline against which to measure the NSW public sectors’ progress in implementing appropriate internal controls and governance processes to mitigate existing, new and emerging risks in the public sector.

Agencies selected for the volume account for 95 per cent of the state's expenditure

While we have covered only 40 agencies in this report, those selected are a large enough group to identify common issues and insights. They represent about 95 per cent of total expenditure for all NSW public sector agencies.

Internal controls are processes, policies and procedures that help agencies to:

  • operate effectively and efficiently
  • produce reliable financial reports
  • comply with laws and regulations
  • support ethical government.

This chapter outlines the overall trends for agency controls and governance issues, including the number of findings, level of risk and the most common deficiencies we found across agencies. The rest of this volume presents this year’s controls and governance findings in more detail.

Observation Conclusions and recommendations
2.1 High risk findings
We found six high risk findings (seven in 2016–17), one of which was repeated from both last year and 2015–16. Recommendation: Agencies should reduce risk by addressing high risk internal control deficiencies as a priority.
2.2 Common findings
We found several internal controls and governance findings common to multiple agencies. Conclusion: Central agencies or the lead agency in a cluster can play a lead role in helping ensure agency responses to common findings are consistent, timely, efficient and effective.
2.3 New and repeat findings
Although internal control deficiencies decreased over the last four years, this year has seen a 42 per cent increase in internal control deficiencies. The increase in new IT control deficiencies and repeat IT control deficiencies signifies an emerging risk for agencies.
IT control deficiencies feature in this increase, having risen by 63 per cent since last year. The number of repeat IT control deficiencies has doubled and is driven by the increasing digital footprint left by agencies as government prioritises on-line interfaces with citizens, and the number of transactions conducted through digital channels increases

Recommendation: Agencies should reduce IT risks by:

  • assigning ownership of recommendations to address IT control deficiencies, with timeframes and actions plans for implementation
  • ensuring audit and risk committees and agency management regularly monitor the implementation status of recommendations.

 

Government agencies’ financial reporting is now heavily reliant on information technology (IT). IT is also increasingly important to the delivery of agency services. These systems often provide the data to help monitor the efficiency and effectiveness of agency processes and services they deliver. Our audits reviewed whether agencies have effective controls in place to manage both key financial systems and IT service contracts.

Observation Conclusions and recommendations
3.1 Management of IT vendors
Contract management framework 
Although 87 per cent of agencies have a contract management policy to manage IT vendors, one fifth require review.
 

Conclusion: Agencies can more effectively manage IT vendor contracts by developing policies and procedures to ensure vendor management frameworks are kept up to date, plans are in place to manage vendor performance and risk, and compliance with the framework is monitored by:

  • internal audit focusing on key contracting activities
  • experienced officers who are independent of contract administration performing spot checks or peer reviews
  • targeted analysis of data in contract registers.
Contract risk management
Forty-one per cent of agencies are not using contract management plans and do not assess contract risks. Half of the agencies that did assess contract risks, had not updated the risk assessments since the commencement of the contract.
 
Conclusion: Instead of applying a 'set and forget' approach in relation to management of contract risks, agencies should assess risk regularly and develop a plan to actively manage identified risks throughout the contract lifecycle - from negotiation and commencement, to termination.

Performance management
Eighty-six per cent of agencies meet with vendors to discuss performance. 

Only 24 per cent of agencies sought assurance about the accuracy of vendor reporting against KPIs, yet sixty-seven per cent of the IT contracts allow agencies to determine performance based payments and/or penalise underperformance.

Conclusion: Agencies are monitoring IT vendor performance, but could improve outcomes and more effectively manage under-performance by:

  • a more active, rigorous approach to both risk and performance management
  • checking the accuracy of vendor reporting against those KPIs and where appropriate seeking assurance over their accuracy
  • invoking performance based payments clauses in contracts when performance falls below agreed standards.

Transitioning services
Forty-three per cent of the IT vendor contracts did not contain transitioning-out provisions.

Where IT vendor contracts do make provision for transitioning-out, only 28 per cent of agencies have developed a transitioning-out plan with their IT vendor.

Conclusion: Contract transition/phase out clauses and plans can mitigate risks to service disruption, ensure internal controls remain in place, avoid unnecessary costs and reduce the risk of 'vendor lock-in'.
Contract Registers
Eleven out of forty agencies did not have a contract register, or have registers that are not accurate and/or complete.

Conclusion: A contract register helps to manage an agency’s compliance obligations under the Government Information (Public Access) Act 2009 (the GIPA Act). However, it also helps agencies more effectively manage IT vendors by:

  • monitoring contract end dates and contract extensions, and commence new procurements through their central procurement teams in a timely manner
  • managing their contractual commitments, budgeting and cash flow requirements.

Recommendation: Agencies should ensure their contract registers are complete and accurate so they can more effectively govern contracts and manage compliance obligations.

3.2 IT general controls
Governance
Ninety-five per cent of agencies have established policies to manage key IT processes and functions within the agency, with ten per cent of those due for review.
 
Conclusion: Regular review of IT policies ensures risks are considered and appropriate strategies and procedures are implemented to manage these risks on a consistent basis. An absence of policies can lead to ad-hoc responses to risks, and failure to consider emerging IT risks and changes to agency IT environments. 

User access administration
Seventy-two deficiencies were identified related to user access administration, including:

  • thirty issues related to granting user access across 43 per cent of agencies
  • sixteen issues related to removing user access across 30 per cent of agencies
  • twenty-six issues related to periodic reviews of user access across 50 per cent of agencies.
Recommendation: Agencies should strengthen the administration of user access to prevent inappropriate access to key systems.
Privileged access
Forty per cent of agencies do not periodically review logs of the activities of privileged users to identify suspicious or unauthorised activities.

Recommendation: Agencies should:

  • review the number of, and access granted to privileged users, and assess and document the risks associated with their activities
  • monitor user access to address risks from unauthorised activity.
Password controls
Twenty-three per cent of agencies did not comply with their own policy on password parameters.
Recommendation: Agencies should ensure IT password settings comply with their password policies.
Program changes
Fifteen per cent of agencies had deficient IT program change controls mainly related to segregation of duties and authorisation and testing of IT program changes prior to deployment.
Recommendation: Agencies should maintain appropriate segregation of duties in their IT functions and test system changes before they are deployed.

 

This chapter outlines our audit observations, conclusions and recommendations from our review of how agencies reported their performance in their 2016–17 annual reports. The Annual Reports (Statutory Bodies) Regulation 2015 and Annual Reports (Departments) Regulation 2015 (annual reports regulation) currently prescribes the minimum requirements for agency annual reports.

Observation Conclusion or recommendation
4.1 Reporting on performance

Only 57 per cent of agencies linked reporting on performance to their strategic objectives.

The use of targets and reporting performance over time was limited and applied inconsistently.

Conclusion: There is significant disparity in the quality and consistency of how agencies report on their performance in their annual reports. This limits the reliability and transparency of reported performance information.

Agencies could improve performance reporting by clearly linking strategic objectives to reported outcomes, and reporting on performance against targets over time. NSW Treasury may need to provide more guidance to agencies to support consistent and high-quality performance reporting in annual reports.

There is no independent assurance that the performance metrics agencies report in their annual reports are accurate.

Prior performance audits have noted issues related to the collection of performance information. For example, our 2016 Report on Red Tape Reduction highlighted inaccuracies in how the dollar-value of red tape reduction had been reported.

Conclusion: The ability of Parliament and the public to rely on reported information as a relevant and accurate reflection of an agency's performance is limited.

The relevance and accuracy of performance information is enhanced when:

  • policies and guidance support the consistent and accurate collection of data
  • internal review processes and management oversight are effective
  • independent review processes are established to provide effective challenge to the assumptions, judgements and methodology used to collect the reported performance information.
4.2 Reporting on reports

Agency reporting on major projects does not meet the requirements of the annual reports regulation.

Forty-seven per cent of agencies did not report on costs to date and estimated completion dates for major works in progress. Of the 47 per cent of agencies that reported on major works, only one agency reported detail about significant cost overruns, delays, amendments, deferments or cancellations.

NSW Treasury produce an annual report checklist to help agencies comply with their annual report obligations.

Recommendation: Agencies should comply with the annual reports regulation and report on all mandatory fields, including significant cost overruns and delays, for their major works in progress.

The information the annual reports regulation requires agencies to report deals only with major works in progress. There is no requirement to report on completed works.

Sixteen of 30 agencies reported some information on completed major works.

Conclusion: Agencies could improve their transparency if they reported, or were required to report:

  • on both works in progress and projects completed during the year
  • actual costs and completion dates, and forecast completion dates for major works, against original and revised budgets and original expected completion dates
  • explanations for significant cost overruns, delays and key project performance metrics.

 

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency preventative and detective controls over purchasing card and taxi use for 2017–18.

Observation Conclusion or recommendation
5.1 Management of purchasing cards
Volume of credit card spend
Purchasing card expenditure has increased by 76 per cent over the last four years in response to a government review into the cost savings possible from using purchasing cards for low value, high volume procurement.
 
Conclusion: The increasing use of purchasing cards highlights the importance of an effective framework for the use and management of purchasing cards.
Policy framework
We found all agencies that held purchasing cards had a policy in place, but 26 per cent of agencies have not reviewed their purchasing card policy by the scheduled date, or do not have a scheduled revision date stated within their policy.
Recommendation: Agencies should mitigate the risks associated with increased purchasing card use by ensuring policies and purchasing card frameworks remain current and compliant with the core requirements of TPP 17–09 'Use and Management of NSW Government Purchasing Cards'.
Preventative controls
We found that:
  • all agencies maintained purchasing card registers
  • seventy-six per cent provided training to cardholders prior to being issued with a card
  • eighty-nine per cent appointed a program administrator, but only half of these had clearly defined roles and responsibilities
  • thirty-two per cent of agencies place merchant blocks on purchasing cards
  • forty-seven per cent of agencies place geographic restrictions on purchasing cards.

Agencies have designed and implemented preventative controls aimed at deterring the potential misuse of purchasing cards.

Conclusion: Further opportunities exist for agencies to better control the use of purchasing cards, such as:

  • updating purchasing card registers to contain all mandatory fields required by TPP17–09
  • appointing a program administrator for the agency's purchasing card framework and defining their role and responsibility for the function
  • strengthening preventive controls to prevent misuse.

Detective controls
Ninety-two per cent of agencies have designed and implemented at least one control to monitor purchasing card activity.

Major reviews, such as data analytics (29 per cent of agencies) and independent spot checks (49 per cent of agencies) are not widely used.

Agencies have designed and implemented detective controls aimed at identifying potential misuse of purchasing cards.

Conclusion: More effective monitoring using purchasing card data can provide better visibility over spending activity and can be used to:

  • detect misuse and investigate exceptions
  • analyse trends to highlight cost saving opportunities.
5.2 Management of taxis
Policy framework
Thirteen per cent of agencies have not developed and implemented a policy to manage taxi use. In addition:
  • a further 41 per cent of agencies have not reviewed their policies by the scheduled revision date, or do not have a scheduled revision date
  • more than half of all agencies’ policies do not offer alternative travel options. For example, only 36 per cent of policies promoted the use of general Opal cards.
Conclusion: Agencies can promote savings and provide more options to staff where their taxi use policies:
  • limit the circumstances where taxi use is appropriate
  • offer alternate, lower cost options to using taxis, such as general Opal cards and rideshare.
Detective controls
All agencies approve taxi expenditure by expense reimbursement, purchasing card and Cabcharge, and have implemented controls around this approval process. However, beyond this there is minimal monitoring and review activity, such as data monitoring, independent spot checks or internal audit reviews.
Conclusion: Taxi spend at agencies is not significant in terms of its dollar value, but it is significant from a probity perspective. Agencies can better address the probity risk by incorporating taxi use into a broader purchasing card or fraud monitoring program.

 

Fraud and corruption control is one of the 17 key elements of our governance lighthouse. Recent reports from ICAC into state agencies and local government councils highlight the need for effective fraud control and ethical frameworks. Effective frameworks can help protect an agency from events that risk serious reputational damage and financial loss.

Our 2016 Fraud Survey found the NSW Government agencies we surveyed reported 1,077 frauds over the three year period to 30 June 2015. For those frauds where an estimate of losses was made, the reported value exceeded $10.0 million. The report also highlighted that the full extent of fraud in the NSW public sector could be higher than reported because:

  • unreported frauds in organisations can be almost three times the number of reported frauds
  • our 2015 survey did not include all NSW public sector agencies, nor did it include any NSW universities or local councils
  • fraud committed by citizens such as fare evasion and fraudulent state tax self-assessments was not within the scope of our 2015 survey
  • agencies did not estimate a value for 599 of the 1,077 (56 per cent) reported frauds.

Commissioning and outsourcing of services to the private sector and the advancement of digital technology are changing the fraud and corruption risks agencies face. Fraud risk assessments should be updated regularly and in particular where there are changes in agency business models. NSW Treasury Circular TC18-02 NSW Fraud and Corruption Control Policy now requires agencies develop, implement and maintain a fraud and corruption control framework, effective from 1 July 2018. 

Our Fraud Control Improvement Kit provides guidance and practical advice to help organisations implement an effective fraud control framework. The kit is divided into ten attributes. Three key attributes have been assessed below; prevention, detection and notification systems.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency fraud and corruption controls for 2017–18.

Observation Conclusion or recommendation
6.1 Prevention systems

Prevention systems
Ninety-two per cent of agencies have a fraud control plan in place, 81 per cent maintain a fraud database and 79 per cent report fraud and corruption matters as a standing item on audit and risk committee agendas.

Only 54 per cent of agencies have an employment screening policy and all agencies have IT security policies, but gaps in IT security controls could undermine their policies.

Conclusion: Most agencies have implemented fraud prevention systems to reduce the risk of fraud. However poor IT security along with other gaps in agency prevention systems, such as employment screening practices heightens the risk of fraud and inappropriate use of data.

Agencies can improve their fraud prevention systems by:

  • completing regular fraud risk assessments, embedding fraud risk assessment into their enterprise risk management process and reporting the results of the assessment to the audit and risk committee
  • maintaining a fraud database and reviewing it regularly for systemic issues and reporting a redacted version of the database on the agency's website to inform corruption prevention networks
  • developing policies and procedures for employee screening and benchmarking their current processes against ICAC's publication ‘Strengthening Employment Screening Practices in the NSW Public Sector’
  • developing and maintaining up to date IT security policies and monitoring compliance with the policy.
Twenty-three per cent of agencies were not performing fraud risk assessments and some agency fraud risk assessments may not be as robust as they could be.  Conclusion: Agencies' systems of internal controls may be less effective where new and emerging fraud risks have been overlooked, or known weaknesses have not been rectified.
6.2 Detection systems
Detection systems
Several agencies reported they were developing a data monitoring program, but only 38 per cent of agencies had already implemented a program.
 

Studies have shown data monitoring, whereby entire populations of transactional data are analysed for indicators of fraudulent activity, is one of the most effective methods of early detection. Early detection decreases the duration a fraud remains undetected thereby limiting the extent of losses.

Conclusion: Data monitoring is an effective tool for early detection of fraud and is more effective when informed by a comprehensive fraud risk assessment.

6.3 Notification systems
Notification system
All agencies have notification systems for reporting actual or suspected fraud and corruption. Most agencies provide multiple reporting lines, provide training and publicise options for staff to report actual or suspected fraud and corruption.
Conclusion: Training staff about their obligations and the use of fraud notification systems promotes a fraud-aware culture

 

Published

Actions for Matching skills training with market needs

Matching skills training with market needs

Industry
Compliance
Internal controls and governance
Management and administration
Risk
Service delivery
Workforce and capability

The NSW Department of Industry targets subsidies towards training programs delivering skills most needed in New South Wales. However, the Department still provides subsidies to qualifications that the market may no longer need, according to a report released by Margaret Crawford, Auditor-General for New South Wales. 

In 2012, governments across Australia entered into the National Partnership Agreement on Skills Reform. Under the National Partnership Agreement, the Australian Government provided incentive payments to States and Territories to move towards a more contestable Vocational Education and Training (VET) market. The aim of the National Partnership Agreement was to foster a more accessible, transparent, efficient and high quality training sector that is responsive to the needs of students and industry. 

The New South Wales Government introduced the Smart and Skilled program in response to the National Partnership Agreement. Through Smart and Skilled, students can choose a vocational course from a list of approved qualifications and training providers. Students pay the same fee for their chosen qualification regardless of the selected training provider and the government covers the gap between the student fee and the fixed price of the qualification through a subsidy paid to their training provider. 

Smart and Skilled commenced in January 2015, with the then Department of Education and Communities having primary responsibility for its implementation. Since July 2015, the NSW Department of Industry (the Department) has been responsible for VET in New South Wales and the implementation of Smart and Skilled. 

The NSW Skills Board, comprising nine part-time members appointed by the Minister for Skills, provides independent strategic advice on VET reform and funding. In line with most other States and Territories, the Department maintains a 'Skills List' which contains government subsidised qualifications to address identified priority skill needs in New South Wales.

This audit assessed the effectiveness of the Department in identifying, prioritising, and aligning course subsidies to the skill needs of NSW. To do this we examined whether:

  • the Department effectively identifies and prioritises present and future skill needs 
  • Smart and Skilled funding is aligned with the priority skill areas
  • skill needs and available VET courses are effectively communicated to potential participants and training providers.

Smart and Skilled is a relatively new and complex program, and is being delivered in the context of significant reform to VET nationally and in New South Wales. A large scale government funded contestable market was not present in the VET sector in New South Wales before the introduction of Smart and Skilled. This audit's findings should be considered in that context.
 

Conclusion
The Department effectively consults with industry, training providers and government departments to identify skill needs, and targets subsidies to meet those needs. However, the Department does not have a robust, data driven process to remove subsidies from qualifications which are no longer a priority. There is a risk that some qualifications are being subsidised which do not reflect the skill needs of New South Wales. 
The Department needs to better use the data it has, and collect additional data, to support its analysis of priority skill needs in New South Wales, and direct funding accordingly.
In addition to subsidising priority qualifications, the Department promotes engagement in skills training by:
  • funding scholarships and support for disadvantaged students
  • funding training in regional and remote areas
  • providing additional support to deliver some qualifications that the market is not providing.

The Department needs to evaluate these funding strategies to ensure they are achieving their goals. It should also explore why training providers are not delivering some priority qualifications through Smart and Skilled.

Training providers compete for funding allocations based on their capacity to deliver. The Department successfully manages the budget by capping funding allocated to each Smart and Skilled training provider. However, training providers have only one year of funding certainty at present. Training providers that are performing well are not rewarded with greater certainty.

The Department needs to improve its communication with prospective students to ensure they can make informed decisions in the VET market.

The Department also needs to communicate more transparently to training providers about its funding allocations and decisions about changes to the NSW Skills List. 

The NSW Skills List is unlikely to be missing high priority qualifications, but may include lower priority qualifications because the Department does not have a robust process to identify and remove these qualifications from the list. The Department needs to better use available data, and collect further data, to support decisions about which qualifications should be on the NSW Skills List.

The Department relies on stakeholder proposals to update the NSW Skills List. Stakeholders include industry, training providers and government departments. These stakeholders, particularly industry, are likely to be aware of skill needs, and have a strong incentive to propose qualifications that address these needs. The Department’s process of collecting stakeholder proposals helps to ensure that it can identify qualifications needed to address material skill needs. 

It is also important that the Department ensures the NSW Skills List only includes priority qualifications that need to be subsidised by government. The Department does not have robust processes in place to remove qualifications from the NSW Skills List. As a result, there is a risk that the list may include lower priority skill areas. Since the NSW Skills List was first created, new additions to the list have outnumbered those removed by five to one.

The Department does not always validate information gathered from stakeholder proposals, even when it has data to do so. Further, its decision making about what to include on, or delete from, the NSW Skills List is not transparent because the rationale for decisions is not adequately documented. 

The Department is undertaking projects to better use data to support its decisions about what should be on the NSW Skills List. Some of these projects should deliver useful data soon, but some can only provide useful information when sufficient trend data is available. 

Recommendation

The Department should: 

  • by June 2019, increase transparency of decisions about proposed changes to the NSW Skills List and improve record-keeping of deliberations regarding these changes
  • by December 2019, use data more effectively and consistently to ensure that the NSW Skills List only includes high priority qualifications
The Department funds training providers that deliver qualifications on the NSW Skills List. Alignment of funding to skill needs relies on the accuracy of the NSW Skills List, which may include some lower priority qualifications.

Only qualifications on the NSW Skills List are eligible for subsidies under Smart and Skilled. As the Department does not have a robust process for removing low priority qualifications from the NSW Skills list, some low priority qualifications may be subsidised. 

The Department allocates the Smart and Skilled budget through contracts with Smart and Skilled training providers. Training providers that meet contractual obligations and perform well in terms of enrolments and completion rates are rewarded with renewed contracts and more funding for increased enrolments, but these decisions are not based on student outcomes. The Department reduces or removes funding from training providers that do not meet quality standards, breach contract conditions or that are unable to spend their allocated funding effectively. Contracts are for only one year, offering training providers little funding certainty. 

Smart and Skilled provides additional funding for scholarships and for training providers in locations where the cost of delivery is high or to those that cater to students with disabilities. The Department has not yet evaluated whether this additional funding is achieving its intended outcomes. 

Eight per cent of the qualifications that have been on the NSW Skills List since 2015 are not delivered under Smart and Skilled anywhere in New South Wales. A further 14 per cent of the qualifications that are offered by training providers have had no student commencements. The Department is yet to identify the reasons that these high priority qualifications are either not offered or not taken up by students.

Recommendation

The Department should:

  • by June 2019, investigate why training providers do not offer, and prospective students do not enrol in, some Smart and Skilled subsidised qualifications 
  • by December 2019, evaluate the effectiveness of Smart and Skilled funding which supplements standard subsidies for qualifications on the NSW Skills List, to determine whether it is achieving its objectives
  • by December 2019, provide longer term funding certainty to high performing training providers, while retaining incentives for them to continue to perform well.
The Department needs to improve its communication, particularly with prospective students.

In a contestable market, it is important for consumers to have sufficient information to make informed decisions. The Department does not provide some key information to prospective VET students to support their decisions, such as measures of provider quality and examples of employment and further education outcomes of students completing particular courses. Existing information is spread across numerous channels and is not presented in a user friendly manner. This is a potential barrier to participation in VET for those less engaged with the system or less ICT literate.

The Department conveys relevant information about the program to training providers through its websites and its regional offices. However, it could better communicate some specific information directly to individual Smart and Skilled training providers, such as reasons their proposals to include new qualifications on the NSW Skills List are accepted or rejected. 

While the Department is implementing a communication strategy for VET in New South Wales, it does not have a specific communications strategy for Smart and Skilled which comprehensively identifies the needs of different stakeholders and how these can be addressed. 

Recommendation

By December 2019, the Department should develop and implement a specific communications strategy for Smart and Skilled to:

  • support prospective student engagement and informed decision making
  • meet the information needs of training providers 

Appendix one - Response from agency

Appendix two - About the audit

Appendix three - Performance auditing

 

Parliamentary reference - Report number #305 - released 26 July 2018

Published

Actions for Universities 2017

Universities 2017

Universities
Asset valuation
Compliance
Cyber security
Financial reporting
Information technology
Internal controls and governance

The Auditor-General, Margaret Crawford released her report today on the results of financial audits of NSW universities for the year ended 31 December 2017. No qualified audit opinions were issued for any university and the quality and timeliness of financial reporting continues to improve.

This report analyses the results of our audits of financial statements of the ten NSW universities and their controlled entities for the year ended 31 December 2017. The table below summarises our key observations.

This report focuses on our observations on the common issues identified in our audits of the financial statements of the ten NSW universities and their controlled entities in 2017. The universities and controlled entities are listed in Appendix three and four respectively.

The report provides our analysis of universities’ results and findings in the following areas:

  • Financial reporting and performance
  • Teaching and research
  • Financial controls and governance.

Accurate and timely financial reporting is important for universities to make efficient and effective economic decisions. Sound financial performance provides the platform for universities to deliver high quality teaching and research outcomes. 

This chapter outlines our audit observations on the financial reporting and performance of NSW universities for 2017.

Observation Conclusion or recommendation
3.1 Financial reporting
Audit results
The financial statements of all ten NSW universities and 66 out of 69 of their controlled entities received unmodified audit opinions. Two controlled entities did not fully comply with the financial reporting and audit requirements of the Public Finance and Audit Act 1983 as they did not submit their financial statements to the Auditor-General. One of these entities was audited under the requirements applicable in its foreign jurisdiction. A third controlled entity submitted financial statements, but only after the statutory due date.
Quality and timeliness of financial reporting
The number of uncorrected misstatements continues to decrease. The quality of financial statements of the universities improved in 2017.
Two universities simplified disclosures in their financial statements. The financial statements of the University of Sydney and Macquarie University are more concise, readable and understandable than those of other universities. 
Six universities finalised their financial statements earlier than in previous years. Universities that performed aspects of early close procedures improved the timeliness of their financial reporting and helped us conclude our audits earlier. 
Eight universities are yet to quantify the impact of new accounting standards applicable in future years.  The two universities that have assessed the impact of the new accounting standards believe the impact will be material.
An accounting issue was identified relating to the recognition and measurement of payroll tax liabilities on employees' defined benefit superannuation contributions payable to the superannuation funds. Recommendation: NSW universities should clarify the recognition and measurement of their liability for payroll tax on their defined benefit superannuation obligations before 31 December 2018. 
3.2 Financial performance
Sources of revenue from operations
Government grants as a proportion of total revenue decreased over the past five years by 6.4 per cent.

The Australian Government announced funding freezes to Australian Government grants revenue for the next two years.

Universities are expanding other revenue streams to decrease their reliance on grant funding. The revenue stream that has increased the most significantly over the past five years is overseas student revenue.

Revenue from overseas student course fees increased by 23 per cent in the last year and contributed $2.8 billion to the NSW university sector in 2017. Overseas student revenue exceeded domestic student revenue by 37 per cent, and comprised over a quarter of NSW universities' total revenues in 2017. The growth in overseas student revenue has not been shared equally in the sector. Some universities are more dependent on overseas student revenue than others.
Revenue from overseas students from four countries comprised 37 per cent of total student revenues for all NSW universities.  Recommendation: NSW universities should assess their student market concentration risk where they rely heavily on students from a single country of origin. This increases their sensitivity to economic or political changes in that country.
Universities' data shows as much as 71 per cent of their overseas student revenue comes from a single country of origin. 
Research income of NSW universities was $1.1 billion in 2016 and has grown by 9.8 per cent between 2012 and 2016. Two universities attracted 65.2 per cent of the total research income received by all NSW universities.
Other revenues
Total philanthropic revenue increased by 1.0 per cent to $151 million in 2017.

Philanthropic revenue has been increasing for the past five years.

Two universities attracted 76.8 per cent of the total philanthropic dollars received by all NSW universities.

Average investment returns fell from 7.0 per cent in 2013 to 5.8 per cent in 2017, while total investments grew to $5.4 billion in 2017 from $3.5 billion in 2013.

Universities have structured their investment portfolios between fixed and non-fixed income assets, seeking to optimise their returns in a low interest rate environment within the limits of their risk management strategies.

Investment income is a significant source of revenue for some, but not all universities. Two universities' investment funds represented 52.3 per cent of the total investment funds of all NSW universities combined.

Low interest rates have made investment in fixed income assets less attractive for universities. Over the last five years universities have increased their investment in non-fixed income (or market based) assets by 67.1 per cent.  
Most NSW universities have established investment governance frameworks.  
Financial sustainability indicators
Operating expenditure per equivalent full-time student load (EFTSL) increased by 3.0 per cent in 2017. The universities that have been able to attract international students to grow their operational revenues have been able to leverage economies of scale to maximise their average margin per EFTSL. Other universities have had to rely on containing costs to achieve higher EFTSL margins.
For six universities, the growth in operating expenditure has exceeded the growth in operating revenue, reducing operating margins. The risk associated with narrowing margins is compounded where universities have a high reliance on student revenues from a single source. Sudden changes in demand can challenge the ability of those universities to adjust their cost structures.

As the margin between operating revenue and operating expenditure decreases, operational results are more at risk from unexpected fluctuations, such as Australian Government higher education reforms and reduced overseas student enrolments.

Smaller operating margins reduce the funds available to invest in upgrading infrastructure and implement corporate strategies to meet future challenges.

Eight universities have current ratios greater than one in 2017.    
Controlled entities
Sixteen of the universities' 58 controlled entities that operate business activities reported losses in 2017 (15 in 2016). Overall, the financial performance of controlled entities operating business activities was positive, but results in 2017 were lower than in 2016. 
The total profit of controlled entities operating business activities decreased 5.5 per cent to $77.5 million in 2017 ($82.6 million in 2016). Universities may be able to improve their overall performance by reassessing the viability of business ventures that continue to make losses and/or rely on them for financial support. 
Eighteen controlled entities relied on guarantees of financial support from their parent entity in 2017 (19 in 2016).  

Teaching and research are key objectives of universities and they invest most of their resources in achieving high quality academic and research outcomes to maintain or advance their reputations and rankings in Australia and abroad. Universities have also committed to achieving certain government objectives.

This chapter outlines teaching and research outcomes for NSW universities for 2017.

Observation Conclusion or recommendation
4.1 Teaching outcomes
Achieving Australian Government target
NSW universities met the Australian Government target of having 40 per cent of 25 to 34 year-olds with bachelor degrees ten years earlier than the original target date of 2025.

The proportion of 25 to 34 year-olds in NSW holding a bachelor degree increased to 43.4 per cent in 2017.

In 2009, when the target was originally set, only 35.5 per cent of 25 to 34 year-olds held a bachelor degree.

Graduate employment rates

Seven universities exceeded the national average of 71.8 per cent for the proportion of their undergraduates who obtain full-time employment.

Four universities achieved better than the national average of 86.1 per cent for the proportion of their postgraduates who obtain full-time employment.

Most NSW universities' employment outcomes are better than the national average.
Student enrolments by field of education
NSW universities have increased enrolments in fields of study that align with known skills shortages in NSW identified by the Australian Government for 2016 and 2017. Alignment of student intake with identified shortages helps ensure graduates secure timely employment on completion of their studies. 
Achieving diversity outcomes

NSW universities agreed to targets set by the Australian Government for enrolments of students from low socio economic status (SES) and Aboriginal or Torres Strait Islander backgrounds.

NSW universities can improve outcomes for these students by implementing policies to increase enrolments and support students to graduation.

Three universities exceeded the target of 20 per cent of low SES student enrolments in 2017.

Six universities met their Indigenous student enrolment target in 2017. The target is having a growth rate in the enrolment of Indigenous students that is more than 50 per cent higher than the growth rate of non-Indigenous student enrolments.

At the current rate, it is unlikely most universities will reach the agreed low SES target by 2020.

Appropriate financial controls help ensure efficient and effective use of resources, and the implementation and monitoring of university policies. Governance consists of frameworks, processes and behaviours that enable the universities to operate effectively and comply with relevant laws and policies.

This chapter outlines our audit observations on the financial control and governance of NSW universities for 2017.

Observation Conclusion or recommendation
5.1 Internal controls
Internal control findings

Eighty-three internal control deficiencies were identified during our audits, of which 40 related to Information Technology (IT).
High risk
We identified a high risk finding in relation to storage of unencrypted username and password information on a database without appropriate access restrictions. We performed additional audit procedures to conclude that the control deficiency did not present a risk of material misstatement in the university's financial statements.
Moderate risk
Forty-three moderate risk control deficiencies were identified, of which 22 related to IT and 21 related to governance and financial reporting.

Recommendation: NSW universities should ensure controls, including information technology controls, are properly designed and operate effectively to protect intellectual property, staff and student data, and assets. Universities should rectify identified deficiencies in a timely manner.
Repeat findings
Twenty-four findings were repeat internal control deficiencies, of which 18 related to IT. 
IT issues can take some time to rectify because specialist skill and/or partnering with software suppliers is often required to implement new controls. However, until rectified, the vulnerabilities those control deficiencies present can be significant.
Cyber security
Our audits identified opportunities to improve cyber security controls and processes to reduce risks, including risks relating to financial loss, reputational damage and breaches of privacy laws.

Recommendation: NSW universities should strengthen their cyber security frameworks to manage cyber security risks. This includes developing:

  • procedures, protocols and supporting systems to effectively identify, report and respond to cyber security threats and incidents
     
  • staff awareness training and programs, including programs tailored for a range of audiences.

Use of credit card and work-related travel
All NSW universities had appropriate published policies on the use of credit cards, and have internal controls and processes to implement those policies.

The risks of unauthorised use can be mitigated by regular monitoring, and reporting breaches for investigation and disciplinary action.

Appropriately designed and implemented preventive and detective controls are most effective when enforcement and disciplinary activities are oversighted by university audit and risk committees.