Refine search Expand filter

Reports

Published

Actions for Integrity of data in the Births, Deaths and Marriages Register

Integrity of data in the Births, Deaths and Marriages Register

Justice
Premier and Cabinet
Whole of Government
Cyber security
Fraud
Information technology
Internal controls and governance
Management and administration

This report outlines whether the Department of Customer Service (the department) has effective controls in place to ensure the integrity of data in the Births, Deaths and Marriages Register (the register), and to prevent unauthorised access and misuse.

The audit found that the department has processes in place to ensure that the information entered in the register is accurate and that any changes to it are validated. Although there are controls in place to prevent and detect unauthorised access to, and activity in the register, there were significant gaps in these controls. Addressing these gaps is necessary to ensure the integrity of information in the register.

The Auditor-General made nine recommendations to the department, aimed at strengthening controls to prevent and detect unauthorised access to, and activity in the register. These included increased monitoring of individuals who have access to the register and strengthening security controls around the databases that contain the information in the register.

The NSW Registry of Births Deaths and Marriages is responsible for maintaining registers of births, deaths and marriages in New South Wales as well as registering adoptions, changes of names, changes of sex and relationships. Maintaining the integrity of this information is important as it is used to confirm people’s identity and unauthorised access to it can lead to fraud or identity theft.

Read full report (PDF)

The NSW Registry of Births Deaths and Marriages (BD&M) is responsible for maintaining registers of births, deaths and marriages in New South Wales. BD&M is also responsible for registering adoptions, changes of name, changes of sex and relationships. These records are collectively referred to as 'the Register'. The Births, Deaths and Marriages Registration Act 1995 (the BD&M Act) makes the Registrar (the head of BD&M) responsible for maintaining the integrity of the Register and preventing fraud associated with the Register. Maintaining the integrity of the information held in the Register is important as it is used to confirm people's identity. Unauthorised access to, or misuse of the information in the Register can lead to fraud or identity theft. For these reasons it is important that there are sufficient controls in place to protect the information.

BD&M staff access, add to and amend the Register through the LifeLink application. While BD&M is part of the Department of Customer Service, the Department of Communities and Justice (DCJ) manages the databases that contain the Register and sit behind LifeLink and is responsible for the security of these databases.

This audit assessed whether BD&M has effective controls in place to ensure the integrity of data in the Births, Deaths and Marriages Register, and to prevent unauthorised access and misuse. It addressed the following:

  • Are relevant process and IT controls in place and effective to ensure the integrity of data in the Register and the authenticity of records and documents?
  • Are security controls in place and effective to prevent unauthorised access to, and modification of, data in the Register?

Conclusion

BD&M has processes and controls in place to ensure that the information entered in the Register is accurate and that amendments to the Register are validated. BD&M also has controls in place to prevent and detect unauthorised access to, and activity in the Register. However, there are significant gaps in these controls. Addressing these gaps is necessary to ensure the integrity of the information in the Register.

BD&M has detailed procedures for all registrations and amendments to the Register, which include processes for entering, assessing and checking the validity and adequacy of source documents. Where BD&M staff have directly input all the data and for amendments to the Register, a second person is required to check all information that has been input before an event can be registered or an amendment can be made. BD&M carries out regular internal audits of all registration processes to check whether procedures are being followed and to address non-compliance where required.

BD&M authorises access to the Register and carries out regular access reviews to ensure that users are current and have the appropriate level of access. There are audit trails of all user activity, but BD&M does not routinely monitor these. At the time of the audit, BD&M also did not monitor activity by privileged users who could make unauthorised changes to the Register. Not monitoring this activity created a risk that unauthorised activity in the Register would not be detected.

BD&M has no direct oversight of the database environment which houses the Register and relies on DCJ's management of a third-party vendor to provide the assurance it needs over database security. The vendor operates an Information Security Management System that complies with international standards, but neither BD&M nor DCJ has undertaken independent assurance of the effectiveness of the vendor's IT controls.

Appendix one – Response from agency

Appendix two – About the audit

Appendix three – Performance auditing

 

Copyright notice

© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.

 

Parliamentary reference - Report number #330 - released 7 April 2020.

Published

Actions for Volume Ten 2011 Focusing on Health

Volume Ten 2011 Focusing on Health

Health
Financial reporting
Information technology
Internal controls and governance
Management and administration
Project management
Workforce and capability

This report includes comments on financial audits of government agencies in the Health sector. In 2010-11, Ambulance Officers spent an extra 77,200 hours waiting at emergency departments for patients to transfer to hospital care. In 2010-11, only 66 per cent of patients were moved from the emergency department to an inpatient bed within eight hours of their arrival. This is significantly down on last year’s 73 per cent and well below the 80 per cent target.

Published

Actions for Visiting medical officers and staff specialists

Visiting medical officers and staff specialists

Health
Management and administration
Service delivery
Workforce and capability

We found that hospitals are generally able to deploy their VMOs and staff specialists to be at the place and time required. However, a hospital’s ability to manage supply and demand at a local level is limited. This limitation will become more critical with the current national health reforms when public hospital funding will depend on their ability to set and meet activity targets and priorities. NSW Health cannot be sure that all payments made to VMOs are for agreed and delivered services. Across the hospitals visited we found limited checking of VMO claims for payment, limited quality information on staff specialist activities and limited hospital-level analysis of trends or inconsistencies in activities and treatments.

 

Parliamentary reference - Report number #219 - released 14 December 2011

Published

Actions for Responding to Domestic and Family Violence

Responding to Domestic and Family Violence

Community Services
Justice
Health
Internal controls and governance
Management and administration
Service delivery

Organisations generally work together to improve the safety of victims when there is an overt and serious crisis, particularly where children are involved. There are no standard ways for victims and perpetrators to access help that might prevent ongoing violence and address underlying issues. This is particularly problematic where there are repeat victims and perpetrators, many of whom have complex mental health, drug and alcohol problems and are difficult to work with. New South Wales has trialled a number of projects to improve the way that organisations work together to support vulnerable people in particular communities.

 

Parliamentary reference - Report number #218 - released 8 November 2011

Published

Actions for Solar Bonus Scheme

Solar Bonus Scheme

Premier and Cabinet
Compliance
Infrastructure
Management and administration
Project management
Regulation
Risk
Service delivery

A NSW Auditor General’s Report has found that the NSW Government and its agencies grossly underestimated the cost and number of people that would install systems under the Solar Bonus Scheme.

By October 2010, the estimated cost of the Scheme, if it continued the way it was going, would have reached $3.988 billion. More than ten times the original estimate of $362 million. In response to the increased cost, the gross tariff for new applicants was reduced from 60 to 20 cents reducing the estimated cost to $1.954 billion.

It was a statutory requirement that when 50 mega watts of installed capacity was reached, the Government would review the Scheme. By the time the review was completed the installed capacity had reached 101 mega watts.

Published

Actions for Prequalification Scheme: Performance and Management Services

Prequalification Scheme: Performance and Management Services

Premier and Cabinet
Finance
Compliance
Internal controls and governance
Management and administration
Regulation
Risk
Workforce and capability

There have been tangible improvements in the time it takes NSW Government agencies to engage consultants through the Government’s Prequalification Scheme. The Scheme was introduced in February 2008 to improve agencies’ procurement of consultants. More than 300 service providers have been prequalified and over $300 million worth of consultancy services have been provided. Ideally agencies should know what assignments each consultant has won, for what services, what their rates are and how well they have performed. Agencies should then be free to contact other agencies before engaging a consultant.

 

Parliamentary reference - Report number #216 - released 28 September 2011

Published

Actions for Two Ways Together - NSW Aboriginal Affairs Plan

Two Ways Together - NSW Aboriginal Affairs Plan

Community Services
Premier and Cabinet
Internal controls and governance
Management and administration
Project management
Service delivery

To date the Two Ways Together Plan (the Plan) has not delivered the improvement in overall outcomes for Aboriginal people that was intended. Stronger partnerships between the government and Aboriginal people are only beginning to emerge. The disadvantage still experienced by some of the estimated 160,000 Aboriginal people in NSW is substantial. For example, the unemployment rate for Aboriginal people is at least three times higher than the rate for all NSW residents and hospital admissions for diabetes are also around three times higher.

 

Parliamentary reference - Report number #213 - released 18 May 2011

Published

Actions for The effectiveness of cautioning for minor Cannabis offences

The effectiveness of cautioning for minor Cannabis offences

Justice
Health
Project management
Service delivery

Over the last ten years the NSW Police Force (Police) has used cautioning to divert over 39,000 minor cannabis offenders from the courts, saving at least $20 million in court costs. People cautioned for minor cannabis offences are also less likely to reoffend than those dealt with by the courts. Adults are more likely to be cautioned for minor cannabis offences today than when cautioning was introduced ten years ago. However this is not the case for young offenders who are more likely to be charged today. Cautioning may help people think about the consequences of their cannabis use. However few people seek help to reduce it with only 1.6 per cent of offenders contacting the drug helpline under the adult cautioning scheme. And there have been no evaluations yet on whether cautioning reduces drug use in NSW.

 

Parliamentary reference - Report number #211 - released 7 April 2011

Published

Actions for Government Advertising 2009

Government Advertising 2009

Premier and Cabinet
Finance
Treasury
Compliance
Management and administration
Procurement
Regulation

We found that the two NSW Health campaigns had followed the required approval processes and were appropriate. We had some concerns with the two Department of Premier and Cabinet (DPC) campaigns. The revised Guidelines, which incorporate recommendations from earlier audit reports, are a positive step towards reducing the risk that publicly funded advertising could be used inappropriately. But there are still parts of the Guidelines that require a subjective judgement and therefore do little to help manage this risk. While we did not have any concerns with the two NSW Health campaigns, the two DPC campaigns highlighted these risks.

 

Parliamentary reference - Report number #194 - released 9 December 2009

Published

Actions for Helping Aboriginal Defendants through MERIT

Helping Aboriginal Defendants through MERIT

Justice
Health
Management and administration
Service delivery

The Magistrates Early Referral into Treatment program (MERIT) diverts adult defendants with drug problems from the local court into a drug treatment program. Recent studies of MERIT outcomes indicate that MERIT is a highly appropriate intervention program for Aboriginal defendants. It has improved the health of participants, including significant reduction in drug use and significant improvement in mental health. Better justice outcomes include lower rates of imprisonment and reduced rates of reoffending.

Overall, the ability to identify MERIT clients, the eligibility criteria, the location and the ability of MERIT teams to engage with Aboriginal defendants are key factors that limit MERIT’s capacity to treat Aboriginal defendants. MERIT needs to overcome these barriers. If MERIT is to be a truly mainstream program, it must adapt to meet the needs of all who should participate.

 

Parliamentary reference - Report number #189 - released 5 August 2009