Reports
Actions for Integrity of data in the Births, Deaths and Marriages Register
Integrity of data in the Births, Deaths and Marriages Register
This report outlines whether the Department of Customer Service (the department) has effective controls in place to ensure the integrity of data in the Births, Deaths and Marriages Register (the register), and to prevent unauthorised access and misuse.
The audit found that the department has processes in place to ensure that the information entered in the register is accurate and that any changes to it are validated. Although there are controls in place to prevent and detect unauthorised access to, and activity in the register, there were significant gaps in these controls. Addressing these gaps is necessary to ensure the integrity of information in the register.
The Auditor-General made nine recommendations to the department, aimed at strengthening controls to prevent and detect unauthorised access to, and activity in the register. These included increased monitoring of individuals who have access to the register and strengthening security controls around the databases that contain the information in the register.
The NSW Registry of Births Deaths and Marriages is responsible for maintaining registers of births, deaths and marriages in New South Wales as well as registering adoptions, changes of names, changes of sex and relationships. Maintaining the integrity of this information is important as it is used to confirm people’s identity and unauthorised access to it can lead to fraud or identity theft.
The NSW Registry of Births Deaths and Marriages (BD&M) is responsible for maintaining registers of births, deaths and marriages in New South Wales. BD&M is also responsible for registering adoptions, changes of name, changes of sex and relationships. These records are collectively referred to as 'the Register'. The Births, Deaths and Marriages Registration Act 1995 (the BD&M Act) makes the Registrar (the head of BD&M) responsible for maintaining the integrity of the Register and preventing fraud associated with the Register. Maintaining the integrity of the information held in the Register is important as it is used to confirm people's identity. Unauthorised access to, or misuse of the information in the Register can lead to fraud or identity theft. For these reasons it is important that there are sufficient controls in place to protect the information.
BD&M staff access, add to and amend the Register through the LifeLink application. While BD&M is part of the Department of Customer Service, the Department of Communities and Justice (DCJ) manages the databases that contain the Register and sit behind LifeLink and is responsible for the security of these databases.
This audit assessed whether BD&M has effective controls in place to ensure the integrity of data in the Births, Deaths and Marriages Register, and to prevent unauthorised access and misuse. It addressed the following:
- Are relevant process and IT controls in place and effective to ensure the integrity of data in the Register and the authenticity of records and documents?
- Are security controls in place and effective to prevent unauthorised access to, and modification of, data in the Register?
ConclusionBD&M has processes and controls in place to ensure that the information entered in the Register is accurate and that amendments to the Register are validated. BD&M also has controls in place to prevent and detect unauthorised access to, and activity in the Register. However, there are significant gaps in these controls. Addressing these gaps is necessary to ensure the integrity of the information in the Register. BD&M has detailed procedures for all registrations and amendments to the Register, which include processes for entering, assessing and checking the validity and adequacy of source documents. Where BD&M staff have directly input all the data and for amendments to the Register, a second person is required to check all information that has been input before an event can be registered or an amendment can be made. BD&M carries out regular internal audits of all registration processes to check whether procedures are being followed and to address non-compliance where required. BD&M authorises access to the Register and carries out regular access reviews to ensure that users are current and have the appropriate level of access. There are audit trails of all user activity, but BD&M does not routinely monitor these. At the time of the audit, BD&M also did not monitor activity by privileged users who could make unauthorised changes to the Register. Not monitoring this activity created a risk that unauthorised activity in the Register would not be detected. BD&M has no direct oversight of the database environment which houses the Register and relies on DCJ's management of a third-party vendor to provide the assurance it needs over database security. The vendor operates an Information Security Management System that complies with international standards, but neither BD&M nor DCJ has undertaken independent assurance of the effectiveness of the vendor's IT controls. |
Appendix one – Response from agency
Appendix two – About the audit
Appendix three – Performance auditing
Copyright notice
© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.
Parliamentary reference - Report number #330 - released 7 April 2020.
Actions for Industry, Skills, Electricity and Water 2016
Industry, Skills, Electricity and Water 2016
The Auditor-General, Margaret Crawford released a report today highlighting a decline in net profits of electricity agencies and the distributions the government received from these agencies. The report also details continuing issues in the management of Crown Land and TAFE NSW's student administration system.
Actions for Planning and Environment 2016
Planning and Environment 2016
Auditor-General, Margaret Crawford released a report on the planning and environment cluster today, concluding that the quality of financial reporting is improving. However, the cluster can improve its financial controls and governance framework.
Actions for Transport 2016
Transport 2016
Financial reporting within the Transport Cluster continues to improve with reported misstatements down 96 per cent since 2011-12 to just three in 2015-16, according to a report released today by the NSW Auditor-General, Margaret Crawford.
Actions for Justice 2016
Justice 2016
Overcrowding in the NSW prison system continues to worsen along with the backlog of cases in the District Court, according to a report released by the New South Wales Auditor-General, Margaret Crawford on the annual financial statements audits in the Justice cluster.
Actions for Fraud Survey
Fraud Survey
In a report released today, the NSW Auditor-General, Margaret Crawford provides a snapshot of reported fraud in the NSW public sector and an analysis of NSW Government agencies’ fraud controls based on a survey of 102 agencies.
Actions for Sale and lease of Crown land
Sale and lease of Crown land
The management of the sale and lease of Crown land is not effective because oversight of decision-making is inadequate and community involvement is limited, according to a report released today by NSW Auditor-General, Margaret Crawford.
The audit found limited oversight of sales and leases of Crown land by the Department of Industry - Lands. The Department has only just started monitoring whether tenants are complying with lease conditions, and does not have a clear view of what is happening on most leased Crown land. The majority of guidance provided to staff has not been updated in the past decade, contributing to staff not correctly implementing policies on rental rebates, unpaid rent, rent redeterminations and the direct negotiation of sales and leases on Crown land.
Parliamentary reference - Report number #273 - released 8 September 2016
Actions for Volume Eight 2011 Focus on Transport and Ports
Volume Eight 2011 Focus on Transport and Ports
The report includes comments on financial audits of government agencies in the Transport and Ports sectors. The audit of corporations’ financial statements for the year ended 30 June 2011 resulted in unmodified audit opinions within the Independent Auditor’s Reports. A key recommendation from the report is that Sydney Ports Corporation should continue working with other government authorities and industry stakeholders to improve the effectiveness of program initiatives for increasing container freight movements by rail. The Corporation should review the underlying causes hindering growth in the rail mode and develop and implement strategies to address the unfavourable trend.
Actions for Volume Two 2011 focusing on Universities
Volume Two 2011 focusing on Universities
New South Wales’ ten universities recorded a combined operating surplus of $582 million in 2010, similar to last year’s surplus of $494 million.Capital works expenditure increased by 16 per cent from $874 million in 2009 to $1,015 million in 2010. Despite this, financial and reputational issues continue for universities.
Actions for Volume One 2011
Volume One 2011
The level of non compliance with the requirements of this Premier’s Memorandum is concerning, particularly considering the NSW Procurement Reforms were effective since 2006. The implementation strategy for procurement reform was announced as early as 2001. We recommend the governing bodies of agencies and management review, not only the processes their agencies have in place to comply with procurement reforms and requirements, but also more broadly how agencies identify and comply with laws, regulations, Treasury policy pronouncements, Premier’s memoranda and other obligations.