Refine search Expand filter

Reports

Published

Actions for Internal Controls and Governance 2018

Internal Controls and Governance 2018

Education
Community Services
Finance
Health
Industry
Justice
Planning
Premier and Cabinet
Transport
Treasury
Whole of Government
Environment
Compliance
Cyber security
Financial reporting
Fraud
Information technology
Internal controls and governance
Management and administration
Procurement
Project management

The Auditor-General for New South Wales Margaret Crawford found that as NSW state government agencies’ digital footprint increases they need to do more to address new and emerging information technology (IT) risks. This is one of the key findings to emerge from the second stand-alone report on internal controls and governance of the 40 largest NSW state government agencies.

This report analyses the internal controls and governance of the 40 largest agencies in the NSW public sector for the year ended 30 June 2018.

This report covers the findings and recommendations from our 2017–18 financial audits that relate to internal controls and governance at the 40 largest agencies (refer to Appendix three) in the NSW public sector.

This report offers insights into internal controls and governance in the NSW public sector

This is our second report dedicated to internal controls and governance at NSW State Government agencies. The report provides insights into the effectiveness of controls and governance processes in the NSW public sector by:

  • highlighting the potential risks posed by weaknesses in controls and governance processes
  • helping agencies benchmark the adequacy of their processes against their peers
  • focusing on new and emerging risks, and the internal controls and governance processes that might address those risks.

Without strong governance systems and internal controls, agencies increase the risks associated with effectively managing their finances and delivering services to citizens. The way agencies deliver services increasingly relies on contracts and partnerships with the private sector. Many of these arrangements deliver front line services, but others provide less visible back office support. For example, an agency may rely on an IT service provider to manage a key system used to provide services to the community. The contract and service level agreements are only truly effective where they are actively managed to reduce risks to continuous quality service delivery, such as interruptions caused by system outages, cyber security attacks and data security breaches.

Our audits do not review all aspects of internal controls and governance every year. We select a range of measures, and report on those that present heightened risks for agencies to mitigate. This report divides these into the following five areas:

  1. Internal control trends
  2. Information technology (IT), including IT vendor management
  3. Transparency and performance reporting
  4. Management of purchasing cards and taxis
  5. Fraud and corruption control.

The findings in this report should not be used to draw conclusions on the effectiveness of individual agency control environments and governance arrangements. Specific financial reporting, controls and service delivery comments are included in the individual 2018 cluster financial audit reports, which will be tabled in Parliament from November to December 2018.

The focus of the report has changed since last year

Last year's report topics included asset management, ethics and conduct, and risk management. We are reporting on new topics this year. We plan to introduce new topics and re-visit our previous topics in subsequent reports on a cyclical basis. This will provide a baseline against which to measure the NSW public sectors’ progress in implementing appropriate internal controls and governance processes to mitigate existing, new and emerging risks in the public sector.

Agencies selected for the volume account for 95 per cent of the state's expenditure

While we have covered only 40 agencies in this report, those selected are a large enough group to identify common issues and insights. They represent about 95 per cent of total expenditure for all NSW public sector agencies.

Internal controls are processes, policies and procedures that help agencies to:

  • operate effectively and efficiently
  • produce reliable financial reports
  • comply with laws and regulations
  • support ethical government.

This chapter outlines the overall trends for agency controls and governance issues, including the number of findings, level of risk and the most common deficiencies we found across agencies. The rest of this volume presents this year’s controls and governance findings in more detail.

Observation Conclusions and recommendations
2.1 High risk findings
We found six high risk findings (seven in 2016–17), one of which was repeated from both last year and 2015–16. Recommendation: Agencies should reduce risk by addressing high risk internal control deficiencies as a priority.
2.2 Common findings
We found several internal controls and governance findings common to multiple agencies. Conclusion: Central agencies or the lead agency in a cluster can play a lead role in helping ensure agency responses to common findings are consistent, timely, efficient and effective.
2.3 New and repeat findings
Although internal control deficiencies decreased over the last four years, this year has seen a 42 per cent increase in internal control deficiencies. The increase in new IT control deficiencies and repeat IT control deficiencies signifies an emerging risk for agencies.
IT control deficiencies feature in this increase, having risen by 63 per cent since last year. The number of repeat IT control deficiencies has doubled and is driven by the increasing digital footprint left by agencies as government prioritises on-line interfaces with citizens, and the number of transactions conducted through digital channels increases

Recommendation: Agencies should reduce IT risks by:

  • assigning ownership of recommendations to address IT control deficiencies, with timeframes and actions plans for implementation
  • ensuring audit and risk committees and agency management regularly monitor the implementation status of recommendations.

 

Government agencies’ financial reporting is now heavily reliant on information technology (IT). IT is also increasingly important to the delivery of agency services. These systems often provide the data to help monitor the efficiency and effectiveness of agency processes and services they deliver. Our audits reviewed whether agencies have effective controls in place to manage both key financial systems and IT service contracts.

Observation Conclusions and recommendations
3.1 Management of IT vendors
Contract management framework 
Although 87 per cent of agencies have a contract management policy to manage IT vendors, one fifth require review.
 

Conclusion: Agencies can more effectively manage IT vendor contracts by developing policies and procedures to ensure vendor management frameworks are kept up to date, plans are in place to manage vendor performance and risk, and compliance with the framework is monitored by:

  • internal audit focusing on key contracting activities
  • experienced officers who are independent of contract administration performing spot checks or peer reviews
  • targeted analysis of data in contract registers.
Contract risk management
Forty-one per cent of agencies are not using contract management plans and do not assess contract risks. Half of the agencies that did assess contract risks, had not updated the risk assessments since the commencement of the contract.
 
Conclusion: Instead of applying a 'set and forget' approach in relation to management of contract risks, agencies should assess risk regularly and develop a plan to actively manage identified risks throughout the contract lifecycle - from negotiation and commencement, to termination.

Performance management
Eighty-six per cent of agencies meet with vendors to discuss performance. 

Only 24 per cent of agencies sought assurance about the accuracy of vendor reporting against KPIs, yet sixty-seven per cent of the IT contracts allow agencies to determine performance based payments and/or penalise underperformance.

Conclusion: Agencies are monitoring IT vendor performance, but could improve outcomes and more effectively manage under-performance by:

  • a more active, rigorous approach to both risk and performance management
  • checking the accuracy of vendor reporting against those KPIs and where appropriate seeking assurance over their accuracy
  • invoking performance based payments clauses in contracts when performance falls below agreed standards.

Transitioning services
Forty-three per cent of the IT vendor contracts did not contain transitioning-out provisions.

Where IT vendor contracts do make provision for transitioning-out, only 28 per cent of agencies have developed a transitioning-out plan with their IT vendor.

Conclusion: Contract transition/phase out clauses and plans can mitigate risks to service disruption, ensure internal controls remain in place, avoid unnecessary costs and reduce the risk of 'vendor lock-in'.
Contract Registers
Eleven out of forty agencies did not have a contract register, or have registers that are not accurate and/or complete.

Conclusion: A contract register helps to manage an agency’s compliance obligations under the Government Information (Public Access) Act 2009 (the GIPA Act). However, it also helps agencies more effectively manage IT vendors by:

  • monitoring contract end dates and contract extensions, and commence new procurements through their central procurement teams in a timely manner
  • managing their contractual commitments, budgeting and cash flow requirements.

Recommendation: Agencies should ensure their contract registers are complete and accurate so they can more effectively govern contracts and manage compliance obligations.

3.2 IT general controls
Governance
Ninety-five per cent of agencies have established policies to manage key IT processes and functions within the agency, with ten per cent of those due for review.
 
Conclusion: Regular review of IT policies ensures risks are considered and appropriate strategies and procedures are implemented to manage these risks on a consistent basis. An absence of policies can lead to ad-hoc responses to risks, and failure to consider emerging IT risks and changes to agency IT environments. 

User access administration
Seventy-two deficiencies were identified related to user access administration, including:

  • thirty issues related to granting user access across 43 per cent of agencies
  • sixteen issues related to removing user access across 30 per cent of agencies
  • twenty-six issues related to periodic reviews of user access across 50 per cent of agencies.
Recommendation: Agencies should strengthen the administration of user access to prevent inappropriate access to key systems.
Privileged access
Forty per cent of agencies do not periodically review logs of the activities of privileged users to identify suspicious or unauthorised activities.

Recommendation: Agencies should:

  • review the number of, and access granted to privileged users, and assess and document the risks associated with their activities
  • monitor user access to address risks from unauthorised activity.
Password controls
Twenty-three per cent of agencies did not comply with their own policy on password parameters.
Recommendation: Agencies should ensure IT password settings comply with their password policies.
Program changes
Fifteen per cent of agencies had deficient IT program change controls mainly related to segregation of duties and authorisation and testing of IT program changes prior to deployment.
Recommendation: Agencies should maintain appropriate segregation of duties in their IT functions and test system changes before they are deployed.

 

This chapter outlines our audit observations, conclusions and recommendations from our review of how agencies reported their performance in their 2016–17 annual reports. The Annual Reports (Statutory Bodies) Regulation 2015 and Annual Reports (Departments) Regulation 2015 (annual reports regulation) currently prescribes the minimum requirements for agency annual reports.

Observation Conclusion or recommendation
4.1 Reporting on performance

Only 57 per cent of agencies linked reporting on performance to their strategic objectives.

The use of targets and reporting performance over time was limited and applied inconsistently.

Conclusion: There is significant disparity in the quality and consistency of how agencies report on their performance in their annual reports. This limits the reliability and transparency of reported performance information.

Agencies could improve performance reporting by clearly linking strategic objectives to reported outcomes, and reporting on performance against targets over time. NSW Treasury may need to provide more guidance to agencies to support consistent and high-quality performance reporting in annual reports.

There is no independent assurance that the performance metrics agencies report in their annual reports are accurate.

Prior performance audits have noted issues related to the collection of performance information. For example, our 2016 Report on Red Tape Reduction highlighted inaccuracies in how the dollar-value of red tape reduction had been reported.

Conclusion: The ability of Parliament and the public to rely on reported information as a relevant and accurate reflection of an agency's performance is limited.

The relevance and accuracy of performance information is enhanced when:

  • policies and guidance support the consistent and accurate collection of data
  • internal review processes and management oversight are effective
  • independent review processes are established to provide effective challenge to the assumptions, judgements and methodology used to collect the reported performance information.
4.2 Reporting on reports

Agency reporting on major projects does not meet the requirements of the annual reports regulation.

Forty-seven per cent of agencies did not report on costs to date and estimated completion dates for major works in progress. Of the 47 per cent of agencies that reported on major works, only one agency reported detail about significant cost overruns, delays, amendments, deferments or cancellations.

NSW Treasury produce an annual report checklist to help agencies comply with their annual report obligations.

Recommendation: Agencies should comply with the annual reports regulation and report on all mandatory fields, including significant cost overruns and delays, for their major works in progress.

The information the annual reports regulation requires agencies to report deals only with major works in progress. There is no requirement to report on completed works.

Sixteen of 30 agencies reported some information on completed major works.

Conclusion: Agencies could improve their transparency if they reported, or were required to report:

  • on both works in progress and projects completed during the year
  • actual costs and completion dates, and forecast completion dates for major works, against original and revised budgets and original expected completion dates
  • explanations for significant cost overruns, delays and key project performance metrics.

 

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency preventative and detective controls over purchasing card and taxi use for 2017–18.

Observation Conclusion or recommendation
5.1 Management of purchasing cards
Volume of credit card spend
Purchasing card expenditure has increased by 76 per cent over the last four years in response to a government review into the cost savings possible from using purchasing cards for low value, high volume procurement.
 
Conclusion: The increasing use of purchasing cards highlights the importance of an effective framework for the use and management of purchasing cards.
Policy framework
We found all agencies that held purchasing cards had a policy in place, but 26 per cent of agencies have not reviewed their purchasing card policy by the scheduled date, or do not have a scheduled revision date stated within their policy.
Recommendation: Agencies should mitigate the risks associated with increased purchasing card use by ensuring policies and purchasing card frameworks remain current and compliant with the core requirements of TPP 17–09 'Use and Management of NSW Government Purchasing Cards'.
Preventative controls
We found that:
  • all agencies maintained purchasing card registers
  • seventy-six per cent provided training to cardholders prior to being issued with a card
  • eighty-nine per cent appointed a program administrator, but only half of these had clearly defined roles and responsibilities
  • thirty-two per cent of agencies place merchant blocks on purchasing cards
  • forty-seven per cent of agencies place geographic restrictions on purchasing cards.

Agencies have designed and implemented preventative controls aimed at deterring the potential misuse of purchasing cards.

Conclusion: Further opportunities exist for agencies to better control the use of purchasing cards, such as:

  • updating purchasing card registers to contain all mandatory fields required by TPP17–09
  • appointing a program administrator for the agency's purchasing card framework and defining their role and responsibility for the function
  • strengthening preventive controls to prevent misuse.

Detective controls
Ninety-two per cent of agencies have designed and implemented at least one control to monitor purchasing card activity.

Major reviews, such as data analytics (29 per cent of agencies) and independent spot checks (49 per cent of agencies) are not widely used.

Agencies have designed and implemented detective controls aimed at identifying potential misuse of purchasing cards.

Conclusion: More effective monitoring using purchasing card data can provide better visibility over spending activity and can be used to:

  • detect misuse and investigate exceptions
  • analyse trends to highlight cost saving opportunities.
5.2 Management of taxis
Policy framework
Thirteen per cent of agencies have not developed and implemented a policy to manage taxi use. In addition:
  • a further 41 per cent of agencies have not reviewed their policies by the scheduled revision date, or do not have a scheduled revision date
  • more than half of all agencies’ policies do not offer alternative travel options. For example, only 36 per cent of policies promoted the use of general Opal cards.
Conclusion: Agencies can promote savings and provide more options to staff where their taxi use policies:
  • limit the circumstances where taxi use is appropriate
  • offer alternate, lower cost options to using taxis, such as general Opal cards and rideshare.
Detective controls
All agencies approve taxi expenditure by expense reimbursement, purchasing card and Cabcharge, and have implemented controls around this approval process. However, beyond this there is minimal monitoring and review activity, such as data monitoring, independent spot checks or internal audit reviews.
Conclusion: Taxi spend at agencies is not significant in terms of its dollar value, but it is significant from a probity perspective. Agencies can better address the probity risk by incorporating taxi use into a broader purchasing card or fraud monitoring program.

 

Fraud and corruption control is one of the 17 key elements of our governance lighthouse. Recent reports from ICAC into state agencies and local government councils highlight the need for effective fraud control and ethical frameworks. Effective frameworks can help protect an agency from events that risk serious reputational damage and financial loss.

Our 2016 Fraud Survey found the NSW Government agencies we surveyed reported 1,077 frauds over the three year period to 30 June 2015. For those frauds where an estimate of losses was made, the reported value exceeded $10.0 million. The report also highlighted that the full extent of fraud in the NSW public sector could be higher than reported because:

  • unreported frauds in organisations can be almost three times the number of reported frauds
  • our 2015 survey did not include all NSW public sector agencies, nor did it include any NSW universities or local councils
  • fraud committed by citizens such as fare evasion and fraudulent state tax self-assessments was not within the scope of our 2015 survey
  • agencies did not estimate a value for 599 of the 1,077 (56 per cent) reported frauds.

Commissioning and outsourcing of services to the private sector and the advancement of digital technology are changing the fraud and corruption risks agencies face. Fraud risk assessments should be updated regularly and in particular where there are changes in agency business models. NSW Treasury Circular TC18-02 NSW Fraud and Corruption Control Policy now requires agencies develop, implement and maintain a fraud and corruption control framework, effective from 1 July 2018. 

Our Fraud Control Improvement Kit provides guidance and practical advice to help organisations implement an effective fraud control framework. The kit is divided into ten attributes. Three key attributes have been assessed below; prevention, detection and notification systems.

This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency fraud and corruption controls for 2017–18.

Observation Conclusion or recommendation
6.1 Prevention systems

Prevention systems
Ninety-two per cent of agencies have a fraud control plan in place, 81 per cent maintain a fraud database and 79 per cent report fraud and corruption matters as a standing item on audit and risk committee agendas.

Only 54 per cent of agencies have an employment screening policy and all agencies have IT security policies, but gaps in IT security controls could undermine their policies.

Conclusion: Most agencies have implemented fraud prevention systems to reduce the risk of fraud. However poor IT security along with other gaps in agency prevention systems, such as employment screening practices heightens the risk of fraud and inappropriate use of data.

Agencies can improve their fraud prevention systems by:

  • completing regular fraud risk assessments, embedding fraud risk assessment into their enterprise risk management process and reporting the results of the assessment to the audit and risk committee
  • maintaining a fraud database and reviewing it regularly for systemic issues and reporting a redacted version of the database on the agency's website to inform corruption prevention networks
  • developing policies and procedures for employee screening and benchmarking their current processes against ICAC's publication ‘Strengthening Employment Screening Practices in the NSW Public Sector’
  • developing and maintaining up to date IT security policies and monitoring compliance with the policy.
Twenty-three per cent of agencies were not performing fraud risk assessments and some agency fraud risk assessments may not be as robust as they could be.  Conclusion: Agencies' systems of internal controls may be less effective where new and emerging fraud risks have been overlooked, or known weaknesses have not been rectified.
6.2 Detection systems
Detection systems
Several agencies reported they were developing a data monitoring program, but only 38 per cent of agencies had already implemented a program.
 

Studies have shown data monitoring, whereby entire populations of transactional data are analysed for indicators of fraudulent activity, is one of the most effective methods of early detection. Early detection decreases the duration a fraud remains undetected thereby limiting the extent of losses.

Conclusion: Data monitoring is an effective tool for early detection of fraud and is more effective when informed by a comprehensive fraud risk assessment.

6.3 Notification systems
Notification system
All agencies have notification systems for reporting actual or suspected fraud and corruption. Most agencies provide multiple reporting lines, provide training and publicise options for staff to report actual or suspected fraud and corruption.
Conclusion: Training staff about their obligations and the use of fraud notification systems promotes a fraud-aware culture

 

Published

Actions for Managing risks in the NSW public sector: risk culture and capability

Managing risks in the NSW public sector: risk culture and capability

Finance
Health
Justice
Treasury
Internal controls and governance
Management and administration
Risk
Workforce and capability

The Ministry of Health, NSW Fair Trading, NSW Police Force, and NSW Treasury Corporation are taking steps to strengthen their risk culture, according to a report released today by the Auditor-General, Margaret Crawford. 'Senior management communicates the importance of managing risk to their staff, and there are many examples of risk management being integrated into daily activities', the Auditor-General said.

We did find that three of the agencies we examined could strengthen their culture so that all employees feel comfortable speaking openly about risks. To support innovation, senior management could also do better at communicating to their staff the levels of risk they are willing to accept.

Effective risk management is essential to good governance, and supports staff at all levels to make informed judgements and decisions. At a time when government is encouraging innovation and exploring new service delivery models, effective risk management is about seizing opportunities as well as managing threats.

Over the past decade, governments and regulators around the world have increasingly turned their attention to risk culture. It is now widely accepted that organisational culture is a key element of risk management because it influences how people recognise and engage with risk. Neglecting this ‘soft’ side of risk management can prevent institutions from managing risks that threaten their success and lead to missed opportunities for change, improvement or innovation.

This audit assessed how effectively NSW Government agencies are building risk management capabilities and embedding a sound risk culture throughout their organisations. To do this we examined whether:

  • agencies can demonstrate that senior management is committed to risk management
  • information about risk is communicated effectively throughout agencies
  • agencies are building risk management capabilities.

The audit examined four agencies: the Ministry of Health, the NSW Fair Trading function within the Department of Finance, Services and Innovation, NSW Police Force and NSW Treasury Corporation (TCorp). NSW Treasury was also included as the agency responsible for the NSW Government's risk management framework.

Conclusion
All four agencies examined in the audit are taking steps to strengthen their risk culture. In these agencies, senior management communicates the importance of managing risk to their staff. They have risk management policies and funded central functions to oversee risk management. We also found many examples of risk management being integrated into daily activities.
That said, three of the four case study agencies could do more to understand their existing risk culture. As good practice, agencies should monitor their employees’ attitude to risk. Without a clear understanding of how employees identify and engage with risk, it is difficult to tell whether the 'tone' set by the executive and management is aligned with employee behaviours.
Our survey of risk culture found that three agencies could strengthen a culture of open communication, so that all employees feel comfortable speaking openly about risks. To support innovation, senior management could also do better at communicating to their staff the levels of risk they are willing to accept.
Some agencies are performing better than others in building their risk capabilities. Three case study agencies have reviewed the risk-related skills and knowledge of their workforce, but only one agency has addressed the gaps the review identified. In three agencies, staff also need more practical guidance on how to manage risks that are relevant to their day-to-day responsibilities.
NSW Treasury provides agencies with direction and guidance on risk management through policy and guidelines. Its principles-based approach to risk management is consistent with better practice. Nevertheless, there is scope for NSW Treasury to develop additional practical guidance and tools to support a better risk culture in the NSW public sector. NSW Treasury should encourage agency heads to form a view on the current risk culture in their agencies, identify desirable changes to that risk culture, and take steps to address those changes. 

In assessing an agency’s risk culture, we focused on four key areas:

Executive sponsorship (tone at the top)

In the four agencies we reviewed, senior management is communicating the importance of managing risk. They have endorsed risk management frameworks and funded central functions tasked with overseeing risk management within their agencies.

That said, we found that three case study agencies do not measure their existing risk culture. Without clear measures of how employees identify and engage with risk, it is difficult for agencies to tell whether employee's behaviours are aligned with the 'tone' set by the executive and management.

For example, in some agencies we examined we found a disconnect between risk tolerances espoused by senior management and how these concepts were understood by staff.

Employee perceptions of risk management

Our survey of staff indicated that while senior leaders have communicated the importance of managing risk, more could be done to strengthen a culture of open communication so that all employees feel comfortable speaking openly about risks. We found that senior management could better communicate to their staff the levels of risk they should be willing to accept.

Integration of risk management into daily activities and links to decision-making

We found examples of risk management being integrated into daily activities. On the other hand, we also identified areas where risk management deviated from good practice. For example, we found that corporate risk registers are not consistently used as a tool to support decision-making.

Support and guidance to help staff manage risks

Most case study agencies are monitoring risk-related skills and knowledge of their workforce, but only one agency has addressed the gaps it identified. While agencies are providing risk management training, surveyed staff in three case study agencies reported that risk management training is not adequate.

NSW Treasury provides agencies with direction and guidance on risk management through policy and guidelines. In line with better practice, NSW Treasury's principles-based policy acknowledges that individual agencies are in a better position to understand their own risks and design risk management frameworks that address those risks. Nevertheless, there is scope for NSW Treasury to refine its guidance material to support a better risk culture in the NSW public sector.

Recommendation

By May 2019, NSW Treasury should:

  • Review the scope of its risk management guidance, and identify additional guidance, training or activities to improve risk culture across the NSW public sector. This should focus on encouraging agency heads to form a view on the current risk culture in their agencies, identify desirable changes to that risk culture, and take steps to address those changes.

Published

Actions for Internal Controls and Governance 2017

Internal Controls and Governance 2017

Finance
Education
Community Services
Health
Justice
Whole of Government
Asset valuation
Compliance
Cyber security
Information technology
Internal controls and governance
Project management
Risk

Agencies need to do more to address risks posed by information technology (IT).

Effective internal controls and governance systems help agencies to operate efficiently and effectively and comply with relevant laws, standards and policies. We assessed how well agencies are implementing these systems, and highlighted opportunities for improvement.
 

1. Overall trends

New and repeat findings

The number of reported financial and IT control deficiencies has fallen, but many previously reported findings remain unresolved.

High risk findings

Poor systems implementations contributed to the seven high risk internal control deficiencies that could affect agencies.

Common findings

Poor IT controls are the most commonly reported deficiency across agencies, followed by governance issues relating to cyber security, capital projects, continuous disclosure, shared services, ethics and risk management maturity.

2. Information Technology

IT security

Only two-thirds of agencies are complying with their own policies on IT security. Agencies need to tighten user access and password controls.

Cyber security

Agencies do not have a common view on what constitutes a cyber attack, which limits understanding the extent of the cyber security threat.

Other IT systems

Agencies can improve their disaster recovery plans and the change control processes they use when updating IT systems.

3. Asset Management

Capital investment

Agencies report delays delivering against the significant increase in their budgets for capital projects.

Capital projects

Agencies are underspending their capital budgets and some can improve capital project governance.

Asset disposals

Eleven per cent of agencies were required to sell their real property through Property NSW but didn’t. And eight per cent of agencies can improve their asset disposal processes.

4. Governance

Governance arrangements

Sixty-four per cent of agencies’ disclosure policies support communication of key performance information and prompt public reporting of significant issues.

Shared services

Fifty-nine per cent of agencies use shared services, yet 14 per cent do not have service level agreements in place and 20 per cent can strengthen the performance standards they set.

5. Ethics and Conduct

Ethical framework

Agencies can reinforce their ethical frameworks by updating code‑of‑conduct policies and publishing a Statement of Business Ethics.

Conflicts of interest

All agencies we reviewed have a code of conduct, but they can still improve the way they update and manage their codes to reduce the risk of fraud and unethical behaviour.

6. Risk Management 

Risk management maturity

All agencies have implemented risk management frameworks, but with varying levels of maturity.

Risk management elements

Many agencies can improve risk registers and strengthen their risk culture, particularly in the way that they report risks to their lead agency.

This report covers the findings and recommendations from our 2016–17 financial audits related to the internal controls and governance of the 39 largest agencies (refer to Appendix three) in the NSW public sector. These agencies represent about 95 per cent of total expenditure for all NSW agencies and were considered to be a large enough group to identify common issues and insights.

The findings in this report should not be used to draw conclusions on the effectiveness of individual agency control environments and governance arrangements. Specific financial reporting, controls and service delivery comments are included in the individual 2017 cluster financial audit reports tabled in Parliament from October to December 2017.

This new report offers strategic insight on the public sector as a whole

In previous years, we have commented on internal control and governance issues in the volumes we published on each ‘cluster’ or agency sector, generally between October and December. To add further value, we then commented more broadly about the issues identified for the public sector as a whole at the start of the following year.

This year, we have created this report dedicated to internal controls and governance. This will help Parliament to understand broad issues affecting the public sector, and help agencies to compare their own performance against that of their peers.

Without strong control measures and governance systems, agencies face increased risks in their financial management and service delivery. If they do not, for example, properly authorise payments or manage conflicts of interest, they are at greater risk of fraud. If they do not have strong information technology (IT) systems, sensitive and trusted information may be at risk of unauthorised access and misuse.

These problems can in turn reduce the efficiency of agency operations, increase their costs and reduce the quality of the services they deliver.

Our audits do not review every control or governance measure every year. We select a range of measures, and report on those that present the most significant risks that agencies should mitigate. This report divides these into the following six areas:

  1. Overall trends
  2. Information technology
  3. Asset management
  4. Governance
  5. Ethics and conduct
  6. Risk management.

Internal controls are processes, policies and procedures that help agencies to:

  • operate effectively and efficiently
  • produce reliable financial reports
  • comply with laws and regulations.

This chapter outlines the overall trends for agency controls and governance issues, including the number of findings, level of risk and the most common deficiencies we found across agencies. The rest of this volume then illustrates this year’s controls and governance findings in more detail.

Issues

Recommendations

1.1 New and repeat findings

The number of internal control deficiencies reduced over the past three years, but new higher-risk information technology (IT) control deficiencies were reported in 2016–17.

Deficiencies repeated from previous years still make up a sizeable proportion of all internal control deficiencies.

Recommendation

Agencies should focus on emerging IT risks, but also manage new IT risks, reduce existing IT control deficiencies, and address repeat internal control deficiencies on a more timely basis.

1.2 High risk findings

We found seven high risk internal control deficiencies, which might significantly affect agencies.

Recommendation

Agencies should rectify high risk internal control deficiencies as a priority

1.3 Common findings

The most common internal control deficiencies related to poor or absent IT controls.

We found some common governance deficiencies across multiple agencies.

Recommendation

Agencies should coordinate actions and resources to help rectify common IT control and governance deficiencies.

Information technology (IT) has become increasingly important for government agencies’ financial reporting and to deliver their services efficiently and effectively. Our audits reviewed whether agencies have effective controls in place over their IT systems. We found that IT security remains the source of many control weakness in agencies.

Issues Recommendations

2.1 IT security

User access administration

While 95 per cent of agencies have policies about user access, about two-thirds were compliant with these policies. Agencies can improve how they grant, change and end user access to their systems.

Recommendation

Agencies should strengthen user access administration to prevent inappropriate access to sensitive systems. Agencies should:

  • establish and enforce clear policies and procedures
  • review user access regularly
  • remove user access for terminated staff promptly
  • change user access for transferred staff promptly.

Privileged access

Sixty-eight per cent of agencies do not adequately manage who can access their information systems, and many do not sufficiently monitor or restrict privileged access.

Recommendation

Agencies should tighten privileged user access to protect their information systems and reduce the risks of data misuse and fraud. Agencies should ensure they:

  • only grant privileged access in line with the responsibilities of a position
  • review the level of access regularly
  • limit privileged access to necessary functions and data
  • monitor privileged user account activity on a regular basis.

Password controls

Forty-one per cent of agencies did not meet either their own standards or minimum standards for password controls.

Recommendation

Agencies should review and enforce password controls to strengthen security over sensitive systems. As a minimum, password parameters should include:

  • minimum password lengths and complexity requirements
  • limits on the number of failed log-in attempts
  • password history (such as the number of passwords remembered)
  • maximum and minimum password ages.

2.2 Cyber Security

Cyber security framework

Agencies do not have a common view on what constitutes a cyber attack, which limits understanding the extent of the cyber security threat.

Recommendation

The Department of Finance, Services and Innovation should revisit its existing framework to develop a shared cyber security terminology and strengthen the current reporting requirements for cyber incidents.

Cyber security strategies

While 82 per cent of agencies have dedicated resources to address cyber security, they can strengthen their strategies, expertise and staff awareness.

Recommendations

The Department of Finance, Services and Innovation should:

  • mandate minimum standards and require agencies to regularly assess and report on how well they mitigate cyber security risks against these standards
  • develop a framework that provides for cyber security training.

Agencies should ensure they adequately resource staff dedicated to cyber security.

2.3 Other IT systems

Change control processes

Some agencies need to improve change control processes to avoid unauthorised or inaccurate system changes.

Recommendation

Agencies should consistently perform user acceptance testing before system upgrades and changes. They should also properly approve and document changes to IT systems.

Disaster recovery planning

Agencies can do more to adequately assess critical business systems to enforce effective disaster recovery plans. This includes reviewing and testing their plans on a timely basis.

Recommendation

Agencies should complete business impact analyses to strengthen disaster recovery plans, then regularly test and update their plans.

Agency service delivery relies on developing and renewing infrastructure assets such as schools, hospitals, roads, or public housing. Agencies are currently investing significantly in new assets. Agencies need to manage the scale and volume of current capital projects in order to deliver new infrastructure on time, on budget and realise the intended benefits. We found agencies can improve how they:

  • manage their major capital projects
  • dispose of existing assets.
Issues Recommendations or conclusions

3.1 Capital investment

Capital asset investment ratios

Most agencies report high capital investment ratios, but one-third of agencies’ capital investment ratios are less than one.

Recommendation

Agencies with high capital asset investment ratios should ensure their project management and delivery functions have the capacity to deliver their current and forward work programs.

Volume of capital spending

Most agencies have significant forward spending commitments for capital projects. However, agencies’ actual capital expenditure has been below budget for the last three years.

Conclusion

The significant increase in capital budget underspends warrant investigation, particularly where this has resulted from slower than expected delivery of projects from previous years.

3.2 Capital projects

Major capital projects

Agencies’ major capital projects were underspent by 13 percent against their budgets.

Conclusion

The causes of agency budget underspends warrant investigation to ensure the NSW Government’s infrastructure commitment is delivered on time.

Capital project governance

Agencies do not consistently prepare business cases or use project steering committees to oversee major capital projects.

Conclusion

Agencies that have project management processes that include robust business cases and regular updates to their steering committees (or equivalent) are better able to provide those projects with strategic direction and oversight.

3.3. Asset disposals

Asset disposal procedures

Agencies need to strengthen their asset disposal procedures.

Recommendations

Agencies should have formal processes for disposing of surplus properties.

Agencies should use Property NSW to manage real property sales unless, as in the case for State owned corporations, they have been granted an exemption.

Governance refers to the high-level frameworks, processes and behaviours that help an organisation to achieve its objectives, comply with legal and other requirements, and meet a high standard of probity, accountability and transparency.

This chapter sets out the governance lighthouse model the Audit Office developed to help agencies reach best practice. It then focuses on two key areas: continuous disclosure and shared services arrangements. The following two chapters look at findings related to ethics and risk management.

Issues Recommendations or conclusions

4.1 Governance arrangements

Continuous disclosure

Continuous disclosure promotes improved performance and public trust and aides better decision-making. Continuous disclosure is only mandatory for NSW Government Businesses such as State owned corporations.

Conclusion

Some agencies promote transparency and accountability by publishing on their websites a continuous disclosure policy that provides for, and encourages:

  • regular public disclosure of key performance information
  • disclosure of both positive and negative information
  • prompt reporting of significant issues.

4.2 Shared services

Service level agreements

Some agencies do not have service level agreements for their shared service arrangements.

Many of the agreements that do exist do not adequately specify controls, performance or reporting requirements. This reduces the effectiveness of shared services arrangements.

Conclusion

Agencies are better able to manage the quality and timeliness of shared service arrangements where they have a service level agreement in place. Ideally, the terms of service should be agreed before services are transferred to the service provider and:

  • specify the controls a provider must maintain
  • specify key performance targets
  • include penalties for non-compliance.

Shared service performance

Some agencies do not set performance standards for their shared service providers or regularly review performance results.

Conclusion

Agencies can achieve better results from shared service arrangements when they regularly monitor the performance of shared service providers using key measures for the benefits realised, costs saved and quality of services received.

Before agencies extend or renegotiate a contract, they should comprehensively assess the services received and test the market to maximise value for money.

All government sector employees must demonstrate the highest levels of ethical conduct, in line with standards set by The Code of Ethics and Conduct for NSW government sector employees.

This chapter looks at how well agencies are managing these requirements, and where they can improve their policies and processes.

We found that agencies mostly have the appropriate codes, frameworks and policies in place. But we have highlighted opportunities to improve the way they manage those systems to reduce the risks of unethical conduct.

Issues Recommendations or conclusions

5.1 Ethical framework

Code of conduct

All agencies we reviewed have a code of conduct, but they can still improve the way they update and manage their codes to reduce the risk of fraud and unethical behaviour.

Recommendation

Agencies should regularly review their code-of-conduct policies and ensure they keep their codes of conduct up-to-date.

Statement of business ethics

Most agencies maintain an ethical framework, but some can enhance their related processes, particularly when dealing with external clients, customers, suppliers and contractors.

Conclusion

Agencies can enhance their ethical frameworks by publishing a Statement of Business Ethics, which communicates their values and culture.

5.2 Potential conflicts of interest

Conflicts of interest

All agencies have a conflicts-of-interest policy, but most can improve how they identify, manage and avoid conflicts of interest.

Recommendation

Agencies should improve the way they manage conflicts of interest, particularly by:

  • requiring senior executives to make a conflict-of-interest declaration at least annually
  • implementing processes to identify and address outstanding declarations
  • providing annual training to staff
  • maintaining current registers of conflicts of interest.

Gifts and benefits

While all agencies already have a formal gifts-and-benefits policy, we found gaps in the management of gifts and benefits by some that increase the risk of unethical conduct.

Recommendation

Agencies should improve the way they manage gifts and benefits by promptly updating registers and providing annual training to staff.

Risk management is an integral part of effective corporate governance. It helps agencies to identify, assess and prioritise the risks they face and in turn minimise, monitor and control the impact of unforeseen events. It also means agencies can respond to opportunities that may emerge and improve their services and activities.

This year we looked at the overall maturity of the risk management frameworks that agencies use, along with two important risk management elements: risk culture and risk registers.

Issues Recommendations or conclusions

6.1 Risk management maturity

All agencies have implemented risk management frameworks, but with varying levels of maturity in their application.

Agencies’ averaged a score of 3.1 out of five across five critical assessment criteria for risk management. While strategy and governance fared best, the areas that most need to improve are risk culture, and systems and intelligence.

Conclusion

Agencies have introduced risk management frameworks and practices as required by the Treasury’s:

  • 'Risk Management Toolkit for the NSW Public Sector'
  • 'Internal Audit and Risk Management Policy for the NSW Public Sector'.

However, more can be done to progress risk management maturity and embed risk management in agency culture.

6.2 Risk management elements

Risk culture

Most agencies have started to embed risk management into the culture of their organisation. But only some have successfully done so, and most agencies can improve their risk culture.

 

 

Conclusion

Agencies can improve their risk culture by:

  • setting an appropriate tone from the top
  • training all staff in effective risk management
  • ensuring desired risk behaviours and culture are supported, monitored, and reinforced through business plans, or the equivalent and employees' performance assessments.

Risk registers and reporting

Some agencies do not report their significant risks to their lead agency, which may impair the way resources are allocated in their cluster. Some agencies do not integrate risk registers at a divisional and whole-of-enterprise level.

Conclusion

Agencies not reporting significant risks at the cluster level increases the likelihood that significant risks are not being mitigated appropriately.

Effective risk management can improve agency decision-making, protect reputations and lead to significant efficiencies and cost savings. By embedding risk management directly into their operations, agencies can also derive extra value for their activities and services.

Published

Actions for Government Advertising: Campaigns for 2015–16 and 2016–17

Government Advertising: Campaigns for 2015–16 and 2016–17

Premier and Cabinet
Justice
Local Government
Compliance
Internal controls and governance
Management and administration
Procurement

The 'Stronger Councils, Stronger Communities' and the 'Dogs deserve better' government advertising campaigns complied with the Government Advertising Act and most elements of the Government Advertising Guidelines.

However, some advertisements were designed to build support for government policy and used subjective or emotive messages. This is inconsistent with the requirement in the Government Advertising Guidelines for 'objective presentation in a fair and accessible manner'.

Advertisements in the 'Stronger Councils, Stronger Communities' campaign used subjective statements such as 'the system is broken' and 'brighter future'. While advertisements in the 'Dogs deserve better' campaign used confronting imagery such as gun targets, blood smears and gravestones.

The Government Advertising Act 2011 (the Act) requires the Auditor-General to conduct a performance audit in relation to at least one government advertising campaign in each financial year. The performance audit assesses whether advertising campaigns were carried out effectively, economically and efficiently and in compliance with the Act, the regulations, other laws and the Government Advertising Guidelines (the Guidelines). In this audit, we examined two campaigns:

  • the ‘Stronger Councils, Stronger Communities’ campaign run by the Office of Local Government and the Department of Premier and Cabinet
  • the ‘Dogs deserve better’ campaign run by the Department of Justice.    

Section 6 of the Act details the specific prohibitions on political advertising. Under this section, material that is part of a government advertising campaign must not contain the name, voice or image of a minister, member of parliament or a candidate nominated for election to parliament or the name, logo or any slogan of a political party. Further, a campaign must not be designed so as to influence (directly or indirectly) support for a political party.

The ‘Stronger Councils, Stronger Communities’ government advertising campaign was run by the Office of Local Government and the Department of Premier and Cabinet in four phases from August 2015 to May 2016. The total cost of the campaign was over $4.5 million. See Appendix 2 for more details on this campaign.

The ‘Stronger Councils, Stronger Communities’ advertising campaign has not breached the specific provisions of Section 6 of the Act which prohibits political advertising.

Two factors potentially compromised value for money for the campaign. The request for quotes for the design of the Phase 1 advertisement did not reflect the full scale of work to be undertaken, which was substantially greater than initially quoted. Further, the department did not meet all recommended timeframes to minimise media booking costs for all phases of the campaign.

The campaign did not comply with all administrative requirements in all phases. Advertising for Phase 1 commenced before the compliance certificate was signed. There was no evidence that a compliance certificate was signed for Phase 2 extension. The cost benefit analyses for Phase 2 and Phase 2 extension did not sufficiently consider alternatives to advertising, as is required by the Government Advertising Guidelines.

Advertisements adopted subjective messages designed to build public support for council mergers and directed audiences to websites for more detailed information. Campaign research identified statements that were most likely to reduce resistance to mergers. Some advertising content used subjective language, which we consider inconsistent with the requirement for ‘objective presentation’. Evaluations of advertising effectiveness also measured the success of the advertisements in increasing public support for council mergers.

No breach of specific prohibitions in the Act

Section 6 of the Act prohibits the use of government advertising for political advertising. A government advertising campaign must not:

  • be designed to influence (directly or indirectly) support for a political party
  • contain the name, voice or image of a minister, any other member of parliament or a candidate nominated for election to parliament
  • contain the name, logo or any slogan of, or any other reference relating to, a political party.

We did not identify any breach of the specific prohibitions listed above in the advertising content of this campaign.

Request for quotes to design advertisement did not reflect the full scope required

The request for quotes for the design of the Phase 1 advertisement did not reflect the full scale of work that was to be undertaken, and this created a risk to achieving value for money. The Office of Local Government sought quotes for design of a television advertisement only. It did not request an estimate for radio, online advertisements, or translation for linguistically diverse audiences, which were ultimately required for the campaign.
 

A full and fair assessment of which supplier could provide the best value for money could not be made given that the quotes obtained did not reflect the full scope of work. The final amount paid for the design of Phase 1 was 2.7 times the original quote. It is possible that another supplier that provided a quote could have provided overall better value for money.

The Office of Local Government continued to use the Phase 1 supplier for Phase 2 and Phase 2 extension (Exhibit 4). Where there are other suppliers that could feasibly compete for a contract, direct negotiation increases the risk the agency has not obtained the best value for money. The department advised that it continued with the same agency to avoid costs involved in briefing a new agency on the campaign.

The ‘Dogs deserve better’ government advertising campaign was run by the Department of Justice from August 2016, after the government announced its decision to prohibit greyhound racing, and was terminated in October 2016 after a change of government policy. The campaign had a budget of $1.6 million, with an actual spend of $1.3 million. See Appendix 2 for more details on this campaign.

The ‘Dogs deserve better’ advertising campaign has not breached the specific provisions of Section 6 of the Act which prohibits political advertising.

The Secretary of the department determined that urgent circumstances existed that required advertising to commence prior to completing a cost benefit analysis and peer review. There was a concern that industry participants may make impulse decisions to destroy greyhounds without further information on support services; there was also an identified need to promote public greyhound adoptions.

Phase 1 advertisements focused on explaining the reasons for the prohibition on greyhound racing with a reference to a website for further information. While industry participants were identified as the primary audience, media expenditure was not specifically targeted to this group. Phase 2 advertisements more effectively addressed the originally identified ‘urgent needs’ of providing information on support services for greyhound owners and information on how the public could adopt a greyhound.

The urgency to advertise potentially compromised value for money. The department did not use price competition when selecting a creative supplier due to a concern this would add to timeframes. Further, the department did not meet recommended timeframes to minimise media booking costs.

We identified three other areas in Phase 1 advertisements that were inconsistent with government advertising requirements. Advertisements used provocative language and confronting imagery, which we consider to be inconsistent with the requirement for ‘objective presentation’. Two statements presented as fact based on the Special Commission’s Inquiry report were inaccurate; one of these was due to a calculation error. Radio advertisements did not clearly identify that they were authorised by the New South Wales Government for the first few days of the campaign.

No breach of specific prohibitions in the Act

Section 6 of the Act prohibits the use of government advertising for political advertising. A government advertising campaign must not:

  • be designed to influence (directly or indirectly) support for a political party
  • contain the name, voice or image of a minister, any other member of parliament or a candidate nominated for election to parliament
  • contain the name, logo or any slogan of, or any other reference relating to, a political party.

We did not identify any breach of the specific prohibitions listed above in the advertising content of this campaign.
 

Animal welfare concerns were identified as the reason for urgent advertising

A brief prepared by the department in July 2016 raised concerns about the welfare of greyhounds following the NSW Premier’s announcement that the government would prohibit greyhound racing. The brief raised the risk that industry members may make impulse decisions to destroy their greyhounds without information on support that was being offered.

The department used the provisions in Sections 7(4) and 8(3) of the Act to expedite the release of advertising due to ‘other urgent circumstances’. This provision allows advertising to commence prior to completing the peer review process and cost benefit analysis.

In introducing the Government Advertising Bill to parliament in 2011, the then Premier noted that exceptional circumstances would cover situations ‘such as a civil emergency or sudden health epidemic’. There is no other guidance on when it is appropriate to use this section. It is at the discretion of a government agency head to determine whether a campaign is urgent.
 

Phase 1 advertisements did not focus on the urgent needs

This advertising campaign had three overarching objectives:

  • to increase public awareness of the animal welfare reasons for the closure of the greyhound racing industry
  • to change the behaviour of dog owners from potentially harming their greyhounds to treating them humanely, by accessing the support options and packages available
  • to promote greyhound adoptions by the public.

Alongside advertising, the department took other steps to engage with the greyhound racing industry. This included direct mail, face to face meetings around the State, setting up a call centre and community consultation through an online survey. Other government agencies and animal welfare agencies were also engaged to reach out to affected stakeholders.

Phase 1 advertising content focused on providing information about the reasons for the closure of the industry. The department’s radio and television advertisements did not refer to support packages or encourage the public to adopt a greyhound. While print advertisements did mention these things, this was only presented in fine print. In all advertisements, audiences were referred to a website for further information.

The focus of advertisements on the reasons for industry closure was not consistent with the identified needs to urgently commence advertising to influence the behaviour of dog owners and encourage the public to adopt a greyhound.

The content in Phase 2 advertisements, which began around four weeks after the first phase, was more explicit in highlighting the services and support for industry members such as offering business and retraining advice. These advertisements also referred audiences to a call centre number as well as the website.

Peer review process limited to influencing second phase of advertisements

In urgent circumstances, the Act allows for peer review to be completed after advertising has commenced. For this campaign, the peer review process was completed on 19 August 2016, two weeks after advertising had commenced. Where advertising commences before the peer review process is completed, the usefulness of peer reviewers’ recommendations is limited to informing subsequent phases of advertising and the post-campaign evaluation.

The peer review report found the messages in Phase 1 advertisements were not clearly defined, and the role of advertising was not clearly defined amongst other campaign activities. These recommendations informed the second phase of advertising, which ran from 27 August 2016 until the campaign was terminated in October 2016.
 

The department could not demonstrate value for money was achieved for creative work

The department provided a fixed budget for creative work when requesting quotes from creative agencies to develop advertising material. This is not consistent with the quotation requirements in the government’s Guidelines for Advertising and Digital Communication Services. This approach creates risks to achieving value for money as creative agencies are not required to compete on price for their services. The department advised that it had pre-set the creative costs based on a comparative government campaign of a similar size. This was done due to a concern that requiring agencies to compete on price would affect the short timeframe given to develop creative material.

Three creative agencies accepted the opportunity to present design ideas for the campaign. The department was unable to provide evidence of how it chose the preferred supplier out of these three agencies. Records are important for accountability and allow a procurement decision to be audited after an urgent decision.     
 

Short notice did not allow for cost-efficient media booking for all phases

Placement of advertisements in various media channels was done through the State’s Media Agency Services contract. This contract achieves savings as the government can use its aggregated media spend to gain discounts from the media supplier.

The Department of Premier and Cabinet provides guidance to ensure cost efficient media booking. For example, media time for a television advertisement should be booked at least 6 to 12 weeks in advance. Radio advertisements should be booked at least 2 to 8 weeks in advance.

The peer review report noted that the department did not have adequate time to look for the most cost-efficient way to advertise. In its response to the peer reviewers, the department acknowledged this to be due to the urgency to start advertising. The media booking authority was signed by the department one day before the campaign commenced.
 

The department used a wide public campaign for a narrow target audience

The campaign identified greyhound industry participants as the primary target audience. In 201516 there were 1,342 greyhound trainers, 1,695 owner/trainers, 983 attendants and 1,247 breeders in New South Wales. The department’s advertising submission identified ‘concerns that industry members could make impulsive decisions, potentially jeopardising the welfare of a large number of dogs, prior to the shutdown of the industry’.

The submission’s evidence of advertising effectiveness focused on increasing the level of wider community support for the ban rather than stopping industry members from making impulse decisions. It used an early opinion poll to show that total support for the ban on greyhound racing rises by 17 points and opposition drops by four points following explanation of the findings of the Special Commission of Inquiry report.

The peer review report noted that the role of advertising was not clearly defined amongst the department’s range of other direct and targeted communications and consultations held with industry members.

No demonstrated basis for use of confronting imagery and provocative language

The Guidelines require ‘objective presentation in a fair and accessible manner’. Neither the Guidelines or Handbook further explain what objective presentation means. We have used an ordinary definition of this term as ‘not influenced by personal feelings or opinions in considering and representing facts’. This is synonymous with terms like ‘impartial’, ‘neutral’, and ‘dispassionate’ and opposite to ‘subjective’. We consider that to meet the current requirements in the Guidelines for objectivity, advertising content should contain accurate statements or facts, and avoid subjective language.

Phase 1 focussed on the ongoing consequences if no action was taken to close the industry. The advertisements used provocative language, for example ‘Up to 70 per cent of dogs are deemed wastage by their own industry. Wastage! Slaughtered just for being slow’. Advertisements used confronting imagery like gravestones, blood smears and gun targets.

Our literature review into this area highlighted mixed findings on the effectiveness of confrontational advertising materials. In some cases, shock campaigns may cause an audience to reject or ignore the message, and may even encourage people to do the opposite of the intended behaviour. In other cases, such as in road safety campaigns, this style of advertising can be successful. This shows the importance of conducting pre-campaign research before adopting a confrontational or emotive approach in advertising.

The Government Advertising Handbook recommends that an agency explain the rationale and the evidence for their chosen advertising approach. There was no evidence that the department researched the effectiveness of its advertising approach with its target audience. The department had planned to undertake creative concept testing as part of a strategy to ensure the creative material was understood by its audience. The department advised that due to the urgency of the campaign, it did not have time to conduct this testing.

Not all Phase 1 radio advertisements clearly identified that they were authorised by the New South Wales Government

For the first few days on air, Phase 1 radio advertisements ended by referring the audience to a government website, instead of clearly identifying that it had been authorised by the New South Wales Government. Government authorisations and logos ensure the work and the programs of the NSW Government are easily identifiable by the community.    

The department’s cost benefit analysis did not consider alternatives to advertising

For government advertising campaigns that cost over $1.0 million, the Act requires the advertising agency to carry out a cost benefit analysis and obtain approval from the Cabinet Standing Committee on Communications, prior to commencing the campaign.

The department engaged with audiences through direct mail, face to face forums, and a telephone helpline in addition to advertising. However, the department’s cost benefit analysis did not meet the requirements in the Guidelines to specify the extent to which expected benefits could be achieved without advertising, and to compare costs of options other than advertising that could be used to successfully implement the program (see Exhibit 6).

The cost benefit analysis made optimistic assumptions about the impact of the campaign on greyhound adoptions. It estimated that 2,360 greyhounds would be adopted if the campaign was run. This is significantly higher than the ‘most optimistic outcome’ of re-homing in the Special Commission Inquiry report (we calculated this to be 1,467 greyhounds). There was insufficient evidence to support the higher number of adoptions in the cost benefit analysis.

The sensitivity analysis shows that using the Special Commission’s ‘most optimistic outcome’ figure of re-homing would reduce the net present value of advertising to be negative. Further, the cost benefit analysis also assumed that increased government funding would be made available to animal welfare and rehoming organisations to support more adoptions, but did not estimate or include this cost when calculating the net present value of advertising.
 

There were two factual inaccuracies in key messages used for Phase 1 advertisements

Section 8(2) of the Act requires the head of a government agency to certify that the proposed campaign ‘contains accurate information’. The Secretary of the Department of Justice signed the compliance certificate on 29 July 2016, before advertisements commenced.

We examined the accuracy of factual claims in this advertising campaign, by comparing the key statements to the report of Special Commission of Inquiry into the Greyhound Racing Industry (the Commissioner report). The Commissioner report was quoted by the NSW Government as the basis for its policy to transition the greyhound racing industry to closure.

We identified that two of the key statements used in Phase 1 advertisements to support the animal welfare reasons for industry closure were inaccurate (Exhibit 7).    

Published

Actions for Therapeutic programs in prisons

Therapeutic programs in prisons

Justice
Management and administration
Service delivery

Corrective Services NSW should ensure eligible prisoners receive timely programs to reduce the risk they will reoffend on release.

This report found that in 2015−16, 75 per cent of prisoners who needed a prison-based therapeutic program did not receive one before the earliest date they could be released. Timely access to prison-based therapeutic programs can be a factor in parole refusal and can potentially exacerbate overcrowding in the prison system. The audit looked at a selection of moderate and high intensity programs that aim to reduce reoffending by addressing addiction, violence, domestic abuse, sex offending and general offending.

When a prisoner enters custody in New South Wales, there is an expectation that they will be offered therapeutic programs that reduce their risk of reoffending. Relative to the costs of providing them, these programs have wide-ranging benefits for prisoners and the broader community, and provide significant savings to the justice system. Corrective Services NSW has lead responsibility for ensuring relevant and effective programs are provided, and for the Premier’s Priority of reducing reoffending by five per cent by 2019.

In New South Wales, a significant majority of people convicted of an offence will eventually be reconvicted. Of those convicted of an offence in 2004, 79 per cent had been reconvicted of another offence by 2014 – half within the first year of their initial offence. The total cost to the community of reoffending is difficult to fully quantify. However, the potential to reduce costs to the prisons system alone by reducing reoffending is significant given the average costs of a prison stay is $167 per prisoner per day over an average 218 day sentence. Total prison system costs in New South Wales were $720 million in 2016.  

To help achieve its mandate to reduce reoffending, Corrective Services NSW delivers therapeutic programs in prison and the community, along with a range of vocational, education, supervision, case management and health and wellbeing general services. These programs and services contribute to the central goal of reducing the likelihood that prisoners will return to prison. This audit assessed whether selected therapeutic programs are available, accessible and effective in reducing the risk of reoffending. More detailed information on the programs selected is in Appendix 3.

Conclusion

Corrective Services NSW does not ensure that eligible prisoners receive timely programs to reduce the risk they will reoffend on release. Most prisoners who need programs do not receive one before their earliest release date. These prisoners can be released with no intervention or held in prison longer awaiting a program. Additionally, programs have not been systematically evaluated to confirm they are helping to reduce reoffending in NSW.


In 2015–16, 75 per cent of prisoners who needed programs reached their earliest release date without receiving one. These prisoners are often released with incomplete or no intervention in prison, or are refused parole and held in custody for longer than their minimum term. Corrective Services NSW prioritises prisoners for programs based on their risk of reoffending. However, the 20 per cent increase in the prison population between 2011–12 and 2015–16 has put a significant strain on program resources. While program staffing has increased by 20 per cent over the past two years, the overall proportion of prisoners receiving programs before release has not.  

Since 2015, there has been increased roll out of moderate-intensity EQUIPS programs, which reach greater numbers of prisoners. However, over the same period, the number of programs to meet the higher-intensity therapeutic needs of sex offenders and serious violent offenders has decreased or remained the same despite increased numbers of prisoners entering custody that may benefit from them. Corrective Services NSW does not collect and act on information to ensure that coverage of specific program needs among sex offenders and serious violent offenders is sufficient given the increases in these prisoner types.

Corrective Services NSW bases its programs on international evidence and has worked in partnership with independent evaluators to evaluate some programs. However, these evaluations have mostly been inconclusive due to small sample sizes and data quality issues. Further evaluations are proposed, including as a result of an additional $237 million investment in reducing reoffending, which will also see the role out of additional programs and case management initiatives.  

75 per cent of prisoners who needed programs did not complete them before the earliest date they could have been released for parole 

In 2015–16, 75 per cent of prisoners with an identified program need did not complete a program prior to the earliest date they could have been paroled. If prisoners do not complete programs before their earliest parole date, they can be released having had no, or incomplete, interventions while in prison to address their offending. They can also be refused parole by the State Parole Authority, adding unnecessary length to the time spent in jail and exacerbating overcrowding. Parole refusal data from the State Parole Authority indicates that non-completion of programs was a factor in 84 per cent of 302 parole refusals in 2015. 

Program resourcing at the prison level is inadequate to meet increased demand

Lack of availability of programs to meet demand is a key factor preventing prisoners from completing programs in time for release. The 20 per cent increase in the prison population between 2011–12 and 2015–16 has placed a significant strain on resources. While more programs are being delivered, the overall proportion of prisoners receiving them before release has not. Prisoner case management is not performed in a timely and consistent way, resulting in prisoners missing opportunities to be referred to programs, particularly if they have shorter sentences. For example, 27 per cent of prisoners with more than six months to serve had not completed an assessment required to determine eligibility for an EQUIPS program in the past four years.

The mix of available programs may be out of step with the needs of some prisoners

Since 2012, Corrective Services NSW has increased the number of moderate-intensity EQUIPS domestic violence and aggression programs provided and more prisoners overall are now able to participate in programs. Over the same period, the number of intensive programs delivered for sex offenders has decreased and the number of intensive programs for serious violent offenders has remained the same. This is despite increasing proportions of prisoners sentenced for sexual assault and related offences, and serious violent offences.

Corrective Services NSW uses a risk-assessment model to determine which prisoners are eligible for existing programs, but does not regularly review whether there are gaps or insufficient program coverage of some therapeutic needs.

Corrective Services NSW does not collect robust and comparable information on program quality and outcomes 

Program performance reporting at the prison level focuses on program throughput, such as the number of programs delivered and the number of prisoners participating. Corrective Services NSW does not routinely collect information on program implementation that would provide insights at the prison level into whether programs are being run effectively, and are achieving their intended goals.

Corrective Services NSW has not systematically evaluated its therapeutic programs to confirm they are effective in reducing reoffending

Programs being delivered in New South Wales prisons are based on international evidence about the success of the specific methods and approaches used. This is a good foundation, but Corrective Services NSW is unable to show that its programs are effective in the New South Wales context, and that they are having an impact in achieving the Premier’s target of reducing reoffending by five per cent. Evaluations of some programs have been conducted, but these were mostly inconclusive because of challenges with data collection, such as developing significant enough sample sizes. A lack of consistent forward planning has also affected the rigour of some evaluations.  

With the roll out of an additional $237 million investment in reducing reoffending, Corrective Services NSW proposes to focus efforts on evaluating the effectiveness of its programs by engaging external experts and increasing resourcing in its own evaluation unit. A systematic forward program for independent evaluation, which identifies solutions to existing data gaps and builds on past studies, is needed to support this.  

Challenges for Corrective Services NSW

Corrective Services NSW, a division of the Department of Justice, operates 34 custodial correctional centres across New South Wales, including two that are managed by private companies. It is responsible for delivering correctional services and programs that reduce reoffending and enhance community safety. Corrective Services NSW has lead responsibility for the Premier’s Priority of reducing adult reoffending by five per cent by 2019. To assist in achieving this target, Corrective Services NSW delivers therapeutic programs in prisons that aim to reduce the likelihood that prisoners will reoffend once released.  

Prison overcrowding

Prior to 2011, the prison population had been decreasing, which resulted in the closure of Berrima, Parramatta and Kirkconnell Correctional Centres, the downsizing of Grafton Correctional Centre, and a reduction in total capacity of 900 beds. However, since 2011–12 the prison population has increased by approximately 30 per cent, reaching a record of around 12,900 prisoners in March 2017 (latest available data).  

Corrective Services NSW should by December 2017:

1.  Implement a systematic approach to the use of convictions, sentencing and case management data to ensure that gaps in program offerings can be identified and addressed.

By June 2018:

2.  Clearly establish program delivery staff resourcing benchmarks, based on individual prison profiles, that would meet demand and ensure prisoners receive timely assessments, comprehensive case management and relevant programs before the earliest date they can be released.

3.  Establish consistent program quality and outcomes performance indicators at the prison-level, and monitor and respond to these quarterly.

4.  Develop and implement a detailed forward program of independent evaluations for all prison-based therapeutic programs, that includes identified data requirements for prisons to collect and provide.

Published

Actions for 2016 - An overview

2016 - An overview

Education
Community Services
Finance
Health
Industry
Justice
Local Government
Planning
Premier and Cabinet
Transport
Treasury
Universities
Whole of Government
Environment
Asset valuation
Compliance
Cyber security
Financial reporting
Fraud
Information technology
Infrastructure
Internal controls and governance
Management and administration
Procurement
Project management
Regulation
Risk
Service delivery
Shared services and collaboration
Workforce and capability

This report focuses on key observations and findings from 2016 audits and highlights key areas of focus for financial and performance audits in 2017.

The quality and timeliness of financial reporting continued to improve across the NSW public sector in 2016. Only one qualified audit opinion was issued and most agencies signed their financial statements on time.

We found the Government’s cluster governance arrangements were unclear and inconsistently implemented across the sector in 2016. Clearer arrangements would improve cooperation and coordination amongst cluster agencies and help deliver government priorities that cut across agencies.

This report focuses on key observations and common issues identified from our financial, performance and compliance audits in 2016, and identifies examples of good practice. It also looks forward to where we will focus our efforts in 2017.

We have summarised our observations and findings for 2016 in four chapters:

  • Financial Performance and Reporting
  • Financial Controls
  • Governance
  • Service Delivery.

Key observations and common issues identified across several agencies will often apply more broadly across the NSW public sector. For this reason, we hope this report is a useful tool for agency management and Audit and Risk Committees to assess our observations and common issues and consider the impact on their agencies. The report provides links to other reports and refers to other useful reference material.

Our financial audits provide independent opinions on NSW agencies’ financial statements. They consider whether agencies have complied with accounting standards, relevant laws, regulations and government directions. They also identify and report internal control weaknesses and matters of governance interest, and make recommendations to address deficiencies.

Our performance and compliance audits build on the financial audits by reviewing and concluding on whether taxpayers’ money is being spent efficiently, effectively, economically and in accordance with the law.

Financial Reporting
Financial Reporting The quality and timeliness of financial reporting
continued to improve across the NSW public sector.
NSW Treasury’s early close procedures helped
facilitate this.
Financial Controls
Internal Controls More needs to be done to implement audit
recommendations on a timely basis.
Information Technology Agencies continue to face challenges in managing information security.
Internal controls at shared service providers Clients of ServiceFirst and GovConnect were unable to rely on the service providers’ internal controls increasing the risks of fraud, error and inappropriate access to data.
Governance
Cluster governance Cluster governance arrangements that support cluster accountability, performance monitoring, risk and compliance management are unclear.
Management oversight We identified deficiencies in the oversight and management of Crown Land, specifically sale and lease transactions.
Project governance Project cost and time overruns continue to occur.
Service Delivery
Premiers and State Priorities

According to agency data, which we have not audited, some Premier's and State Priorities are at risk of not being achieved.

A comprehensive report of performance against the State Priorities is not published.

Delivering Government Services The NSW Government's program evaluation initiative has been largely ineffective. We found government decision makers are not always receiving enough information to make evidence based decisions.
Reporting on Performance We found agencies’ performance was not routinely measured, evaluated or publicly reported.

Financial performance and reporting

The quality and timeliness of financial reporting continues to improve

Only one qualified opinion was issued on the 2015–16 financial statements of NSW public sector agencies, compared to two in 2014–15. The audit opinion for the Office of the NSW State Emergency Service was qualified because effective controls over fundraising activities did not operate for the entire year.

Since NSW Treasury introduced its ‘early close procedures’ initiative in 2011–12, the number of reported misstatements and significant matters have fallen considerably across the NSW public sector. The number of misstatements has fallen from 1,077 in 2011–12 to 298 in  2015–16.

Most agencies submitted and signed their financial statements on time, which enabled more audits to be completed within three months of year end. In 2015–16, 204 of 286 agencies’ financial statements and audit opinions were signed within three months of the year end, compared to only 67 in 2010–11.  

NSW Treasury has narrowed the scope of mandatory early close procedures 

NSW Treasury’s early close procedures in 2015–16 were again successful in improving the quality and timeliness of financial reporting, largely facilitated by the early resolution of accounting issues. For 2016–17, NSW Treasury has narrowed the scope of mandatory early close procedures, which may diminish the good performance achieved in recent years.   

To mitigate this risk, NSW Treasury has mandated that agencies perform non-financial asset valuations and prepare proforma financial statements in their early close procedures. It also encourages them to continue with the good practices embedded in recent years. These include:

  • resolving all past audit issues
  • performing key account reconciliations
  • agreeing and confirming inter and intra (cluster) agency balances and transactions
  • identifying material, complex and one-off transactions
  • preparing quality workpapers to support balances with variance analysis and meaningful explanations for movements
  • adequate review by management and Audit and Risk Committees.

Financial controls

More needs to be done to implement audit recommendations

More needs to be done to implement audit recommendations on a timely basis. Internal control issues were identified in previous audits, but had not been adequately addressed. Delays in implementing audit recommendations can impact the quality of financial information and the effectiveness of decision making. Agencies need to ensure they have action plans, timeframes and assigned responsibilities to address recommendations in a timely manner.

Agencies continue to face challenges managing information security

Our financial audits identified opportunities to improve IT control environments, with most information technology issues relating to information security. We also found service level arrangements with IT service providers did not always adequately address information security risks.

Agencies should ensure information security controls and contractual arrangements with IT service providers adequately protect their data.

Internal controls at GovConnect were ineffective in 2015–16

GovConnect provides information technology and transactional services to agencies within the NSW Public Sector. Service levels fell during the transition of shared services from ServiceFirst to GovConnect and NSW public sector agencies using these services were unable to rely on controls over financial transactions and information. We found mitigating actions taken to manage transition risks from ServiceFirst to GovConnect did not ensure effective control over client transactions and data. This increased the risk of fraud and error, and inappropriate access to information.

Governance

Cluster governance arrangements are unclear

Currently, cluster governance arrangements are unclear and inconsistently implemented across the NSW public sector. Implementing cluster governance frameworks is complex because clusters bring together entities with different enabling legislation, organisational and legal structures, information systems and processes, risk profiles and governance frameworks.  

Clear cluster governance arrangements would improve cooperation and coordination amongst cluster agencies, help deliver government priorities that cut across agencies and improve service delivery outcomes.  

We recommended the Department of Premier and Cabinet release a revised NSW Public Sector Governance Framework that clearly articulates cluster governance arrangements, the role of the cluster Secretary, Chief Finance Officer, Chief Information Officer and Chief Risk Officer. The Department of Premier and Cabinet has indicated the framework will be updated to provide guidance on cluster governance, and how accountability and performance information are monitored and reported.  

The sale and lease of Crown land is not being managed effectively

Our 2016 performance audit found limited oversight of sales and leases of Crown land by the Department of Industry - Lands. The Department has only just started monitoring whether tenants are complying with lease conditions, and does not have a clear view of what is happening on most leased Crown land.  

Most guidance to staff had not been updated for a decade, contributing to staff sometimes incorrectly implementing policies on rental rebates, unpaid rent, rent redeterminations and the direct negotiation of sales and leases on Crown land. Between 2012 and 2015, 97 per cent of leases and 50 per cent of sales were negotiated directly between the Department and individuals, without a public expression of interest process.  

Project cost and time overruns continue to occur

Our audits continue to highlight project management, cost and time issues. The Government’s 2016–17 Infrastructure Statement forecasts a $73.3 billion investment program to 2019–20. Good governance of individual projects is critical to ensure the investment program delivers the intended outcomes to the desired quality, on time and on budget.   

A strong risk culture is fundamental to successful risk management

Our assessment of a sample of 33 agencies found that while agencies have risk management governance structures in place, they need to focus on developing stronger risk cultures and fit-for-purpose systems to capture risks and incidents.

Agencies are not fully complying with the GIPA Act

Our review of 13 agencies from across each cluster found varying degrees of non-compliance with recording and disclosure aspects of the GIPA Act by each agency. Our 2016 Special Report 'Compliance with the GIPA Act' details our findings and makes recommendations to help agencies comply with the requirements of the Act.

Service delivery

Some Premier's and State Priorities at risk of not being achieved

Agency data, which we have not audited, indicates some Premier's and State Priorities are at risk of not being achieved. We found that although performance reporting against the Premier’s Priorities is publicly reported, comprehensive performance reporting against the 18 State Priorities is not.  

We will continue to report on performance against the targets to assess whether agency initiatives are delivering intended outcomes.

Government does not always get enough information for evidence-based decisions 

The NSW Government’s program evaluation initiative has been largely ineffective. A performance audit looked at the Justice, Industry, Skills and Regional Development, Planning and Environment, Premier and Cabinet and Treasury clusters and made recommendations for improvements to program evaluation.

Performance is not always measured, evaluated or publicly reported

Inadequate performance measures and reporting that is primarily internal reduces the transparency of agency performance and makes it hard for the public to assess if the agencies are doing a good job. Our audits found instances where performance outcomes were not being measured, evaluated or publicly reported.  

Agencies need to consider whether their performance measurement frameworks adequately measure performance and outcomes so they can make evidence-based decisions and be publicly accountable.

Commissioning and contestability continues to increase

New ways of delivering services across NSW Government are being developed and implemented, including commissioning and contestability arrangements. Commissioning services and introducing new systems can be challenging and it is important for this to be managed well. The learnings from decommissioning ServiceFirst and commissioning GovConnect should be applied to future commissioning arrangements.

NSW Treasury has developed a 'Government Commissioning and Contestability Policy', which is supported by the 'NSW Government Commissioning and Contestability Practice Guide'.

In 2017, we will build on our 2016 financial audits and continue to report our observations and findings as they relate to financial performance and reporting, financial controls, governance and service delivery. We also plan to review agencies' compliance with government travel policies at key agencies in each cluster.

In 2017, we will restructure our financial audit volumes to report our observations and findings on agencies’ financial controls and governance in one cross-sector report to Parliament in September. This will provide the Parliament with more timely reporting on these aspects of our audits. Our observations and findings on agencies’ financial performance and reporting, and service delivery will continue to be reported on a cluster by cluster basis through November and early December.

Our 2017 performance audits will have regard to what we see as key risks and opportunities for the NSW Government, and the Premier's and State Priorities. The program will aim to cover each NSW Government cluster, and focus on how efficiently, effectively and economically they deliver services and other outcomes.

Legislative reforms in the Local Government Amendment (Governance and Planning) Act 2016 have extended the Auditor-General's mandate to the Local Government sector. The expanded mandate includes auditing all NSW local council financial statements and conducting performance audits across the local government sector. The reforms generally bring NSW in line with most other Australian States.

We will report financial audit outcomes and our observations after the 30 June 2017 council audits are completed. Most are expected to complete by the end of October 2017. Our 2017 performance audits will examine and report on whether councils are operating efficiently, effectively, economically and in accordance with the law. In 2017–18, our performance audits will consider how councils are reporting on service delivery, managing shared services and the risk of fraud.

2017 – Issues, risks and opportunities impacting the NSW Government

Our 2017 audits will consider some of the following issues, risks and opportunities impacting the NSW Government.

In mid-2017, we will publish our rolling three-year performance audit program. This will include the performance audits we expect to perform in 2017–18 and the next two financial years. The program can be located at http://www.audit.nsw.gov.au/audit-program

Area of focus  Considerations Audit Office response
Ensuring services meet citizen needs The primary role of state and local government is to provide services to citizens. Today's society is less satisfied with one-size-fits-all services and its citizens want to have a say on the services they need and how they are delivered. This challenges governments to improve engagement with citizens, design services with them and support them in selecting the services that best meet their needs. At the same time, governments have to provide the services within constrained financial environments, and cater for ageing populations and strong population growth, particularly in metropolitan areas.

We will:

  • focus our work on services that are important to citizens
  • keep abreast of best practice and strategies used elsewhere to create more citizen centric services
  • develop our understanding of the key trends putting pressure on government service delivery
  • seek opportunities to engage with citizens in undertaking our work.
Leveraging digital opportunities We live in a digital world, and government is no exception. Digital technologies and the mass of data now available to governments presents opportunities to deliver better services more efficiently and economically. Services can be delivered through digital channels, and data analytics can inform demand, the supply of services and identify potential efficiencies. These opportunities come with risks, including cyber-attacks and privacy breaches.

We will:

  • examine how well state agencies and councils are taking advantage of digital opportunities and managing risks
  • use data analytics to enhance the quality of our audit work
  • use technology to improve how we communicate our key messages.
Having good checks and balances Citizens put faith in government agencies to make decisions in their best interests. It is imperative for government agencies to be clear about what they are trying to achieve and inform citizens on how they are meeting these objectives. While ethics, transparency, and effective governance and stewardship are critical, it is important for the checks and balances not to be so directive or cumbersome they hamper innovation, efficiency and agility.

We will consider the usual issues in our financial audits of agencies and councils. New areas and areas of focus will include:

  • asset management processes,including quality and timeliness of asset valuations and the management of surplus land and property assets
  • oversight and administration of significant grant programs
  • standby assets, the cost to maintain them and their readiness for use
  • benefits realisation for major projects and programs
  • the financial and administrative impact of machinery of government changes
  • engaging with state agencies and councils through workshops and seminars to promote good practices
  • examining governance and internal controls
  • publishing better practice guidance and promoting our Governance Lighthouse.
Getting value from commissioning

Governments, including the NSW Government, are increasingly outsourcing to or partnering with private and non-government organisations to deliver government services. Because outsourced service providers are not directly accountable to the NSW Parliament for their use of public resources, independent assurance that they are using tax payers’ funds efficiently and effectively would improve accountability. In other jurisdictions Auditors-General have been given powers to ‘go beyond’ the boundaries of agencies commissioning services and into the entities providing the services (‘follow the dollar’ powers). This is not the case in New South Wales.

Commissioning brings with it new challenges needing different skills, such as developing and nurturing markets, and transitioning services into and out of government. The NSW Government's recently released Commissioning and Contestability Policy supports agencies entering into commissioning arrangements.

We will:

  • audit agency and council commissioning arrangements and assess whether they are delivering the intended outcomes
  • assess the capability of agencies entering into commissioning arrangements to manage them effectively.
  • report the impact of not being able to provide assurance on the use of taxpayers’ dollars by non-government organisations
  • identify and communicate lessons identified in our audits
  • apply commissioning to our own activities.
Breaking down the silos Government agencies working in silos can diminish service quality through inefficient duplication and overlap. Silos also increase the risk of people falling through the cracks. To achieve best value, silos can be broken down through a clear focus on outcomes and better collaboration, coordination, partnerships, shared services and joined-up government. This has been recognised for many years, but now with both the commitment and tools, inroads can be made to improve citizens' experiences. Governance arrangements, incentives and culture are critical to success.

We will:

  • focus our efforts on areas where there are opportunities to break down silos
  • identify barriers and enablers to joined-up-government, partnerships and collaboration
  • promote good practice and publicise the benefits, both potential and realised
  • work collaboratively and constructively with those we audit
  • partner with and learn from private sector organisations we engage to provide audit services on our behalf.
Looking after future generations and the vulnerable Governments need to plan for the long-term and consider future generations. They have an important stewardship role. Their decisions need to ensure inter-generational equity and prevent environmental degradation.
A core role of government is to look after the vulnerable. Governments intervene in various ways to provide a social safety net. When they do so, it is critical that these interventions are equitable and deliver desired outcomes at a reasonable cost. Increasingly, it is about giving vulnerable people a bigger say in the services they receive.

We will:

  • review the efficacy of projections upon which services are planned
  • adopt a future focus in our work to identify emerging risks and encourage action before they materialise
  • examine the effectiveness and efficiency of interventions designed to address disadvantage and improve equity
  • identify emerging trends and good practice in designing and delivering services to the vulnerable.
A capable and diverse public sector The public sector's lifeblood is its workforce. The effectiveness and efficiency of organisations comes directly from the good ideas, effort, commitment and ethics of the people they employ. Workforce management and succession planning, constructive and respected leaders, and diverse backgrounds and thoughts can enhance agency and council performance and customers' experiences. These attributes require good frameworks to develop key capabilities, manage staff performance and clarify responsibilities and accountabilities.

We will:

  • monitor progress in delivering the NSW Government’s priority to have a diverse workforce
  • examine strategies and programs designed to enhance key capabilities in councils and agencies
  • identify areas where capability and diversity are lagging or are at risk,and offer practical improvement opportunities
  • promote diversity in our own organisation through our diversity and inclusion plan, which includes strategies to increase female representation at all levels and participation in an Aboriginal internship program.
Investing in infrastructure to meet the needs of a growing population

The Government’s 2016–17 Infrastructure Statement forecasts a $73.3 billion investment program to 2019–20. Infrastructure investments of this magnitude carry significant risks. In light of weaknesses we identified in the past with the management of significant infrastructure projects, the Government needs to ensure it has the capability to manage project risks effectively.

Governments also need to make sure infrastructure built today will meet future needs without creating an ongoing burden for future generations.

We will:

  • review infrastructure planning and approval processes
  • examine alternative financing and partnership models, including philanthropic and private sector involvement through vehicles such as social benefit bonds
  • assess risk frameworks and project governance arrangements
  • monitor maintenance spending and asset management practices
  • identify and promote good practice and innovation.
Improving performance through transparency and accountability

NSW Treasury is implementing its Financial Management Transformation (FMT) program to replace ‘service group’ budgeting and reporting with program based budgeting and reporting. A project of this scale and complexity has many risks, which need to be carefully managed if the desired benefits are to be realised.

The NSW Government's move to program budgeting and performance measurement will require appropriate key performance measures and indicators to track whether the programs are delivering the intended outcomes.

Independent assurance over the appropriateness and accuracy of agency key performance measures and indicators would improve confidence in the reliability of the NSW Government performance data.

We will:

  • review and assess the implementation and report on the impact of NSW Treasury's Financial Management Transformation program
  • encourage transparency in reporting,and be transparent in our own practices, performance and reporting.
Preparing for changes to Australian Accounting Standards

For the first time, not-for-profit entities in the NSW public sector need to make disclosures about related parties in their 2017 financial statements. Identifying who the related parties are, and collecting and collating relevant information will be challenging.

Other imminent changes to accounting standards have significant financial reporting implications for Government entities. Entities will need to plan and implement changes to systems and processes well in advance of the new requirements becoming effective.

We will:

  • review and assess policies, systems and processes entities use to identify related parties and transactions, and the completeness and accuracy of the disclosures in the financial statements of agencies and councils
  • work with NSW Treasury, the Office of Local Government, agencies and councils to determine the implications of the accounting standard changes and assess entities’ preparedness to implement them
  • work with the Office of Local Government to streamline the Code of Accounting Practice.
Working together with local councils Legislative reforms have resulted in significant changes to the Local Government sector. These include merging certain councils and extending the Auditor-General's mandate to audit all NSW local council financial statements and conduct performance audits across the Local Government sector.

We will:

  • use our mandate to encourage consistency and promote learnings that enhance financial management,fiscal responsibility and public accountability across the local government sector
  • use findings from our financial audits to inform our performance audit program
  • work alongside councils and their audit committees as they implement changes to governance structures and business planning processes
  • build our internal capacity, capability and knowledge of the Local Government sector to deliver a valuable and cost-effective service.

Financial performance and reporting are important elements of good governance. Confidence in public sector decision making and transparency is enhanced when financial and performance reporting are accurate and timely.  

The preparation of accurate and timely financial statements by agencies is an important tool to ensure accountability and transparency in the use of public resources. As the NSW Government moves to program budgeting with a greater focus on performance and outcomes it will need to ensure the key performance indicators and data used to measure the outcomes are relevant, accurate and reliable. The NSW Government’s Financial Management Transformation (FMT) program aims to address this.

In 2015–16, our audit teams made the following key observations on the financial reporting of NSW public sector agencies.

 

Financial reporting
Observation Conclusion
Only one qualified audit opinion was issued on the 2015–16 financial statements of NSW public sector agencies, compared to two in 2014–15. The quality of financial reporting continued to improve across the NSW public sector.
More 2015–16 financial statements and audit opinions were signed within three months of the year end. Timely financial reporting was facilitated by more agencies resolving significant accounting issues early, completing asset valuations on time and compiling sufficient evidence to support financial statement balances.

NSW Treasury’s early close procedures in 2015–16 were again successful in improving the quality and timeliness of financial reporting, largely facilitated by the early resolution of accounting issues.

For 2016–17, NSW Treasury has narrowed the scope of mandatory early close procedures.

The narrowed scope of mandatory early close procedures may diminish the good performance in ensuring the quality and timeliness of financial reporting achieved in recent years.

To mitigate this risk, NSW Treasury has mandated that agencies perform non-financial asset valuations and prepare proforma financial statements in their early close procedures. It also encourages them to continue with the good practices embedded in recent years.

Although most agencies complied with NSW Treasury’s early close asset revaluation procedures we identified areas where they can improve. Asset revaluations need to commence early enough to ensure all assets are identified and the results are analysed, recorded and reflected accurately in the early close financial statements.

Financial reporting

The quality and timeliness of financial reporting continues to improve across the NSW public sector.

Quality of financial reporting

Only one qualified audit opinion was issued on 2015–16 financial statements

Only one qualified opinion was issued on the 2015–16 financial statements of NSW public sector agencies, down from two in 2014–15. The audit opinion for the Office of the NSW State Emergency Service was qualified because effective controls over fundraising activities did not operate for the entire year. For further details, refer to page 16 in our Report on Law and Order, Emergency Services and the Arts.

Unqualified audit opinion issued for TAFE NSW after remediation

TAFE NSW’s audit opinion on its financial statements was qualified in 2014–15 due to system limitations, which prevented it from providing sufficient evidence to support its student revenue, student receivables, accrued income and unearned revenue balances. TAFE NSW dedicated considerable resources to address this issue in the short term.

Management resolved over 250,000 data exceptions and found revenue had been understated by $138 million in 2014–15. This was recorded as a prior-period error in the 2015–16 financial statements. For further details, refer to pages 17–18 in our Report on Industry, Skills, Electricity and Water.

The quality of financial reporting continues to improve

Since NSW Treasury introduced its mandatory ‘early close procedures’ initiative in 2011–12, the number of reported misstatements and significant matters in agency financial statements submitted for audit have fallen considerably across the NSW public sector. This is largely attributed to the early resolution of accounting issues, which helps agencies meet earlier reporting deadlines and improve the quality and accuracy of financial reporting. Whilst the quality and timeliness of financial reporting has continued to improve, the NSW Government will need to continue focusing on strong financial management across the NSW public sector to maximise performance and effectively manage assets and liabilities.

The table below shows the fall in misstatements over five years across NSW public sector agencies since mandatory early close procedures were introduced in 2011–12.

Number of misstatements
Year ended 30 June 2015-16 2014-15 2013-14 2012-13 2011-12
Total reported misstatements 298 396 459 661 1,077

All material misstatements identified by agencies and audit teams were corrected before the financial statements and audit opinions were signed. A material misstatement relates to an incorrect amount, classification, presentation or disclosure in the financial statements that could reasonably be expected to influence the economic decisions of users.  

Significant matters reported to the portfolio Minister, Treasurer and Agency Head

In 2015–16, we reported the following significant matters to the portfolio Minister, Treasurer and agency head in our Statutory Audit Reports:

  • Transport for NSW needs to assess whether a $179 million fall in the carrying value of the bus fleet leased from the State Transit Authority has similar implications for the value of the bus fleet leased from private operators
  •  issues were identified with how the Northern NSW Local Health District implemented its new rostering system, including rosters being 'force approved' by the system administrator, users having inappropriate access, no review of payroll exceptions and inadequate project governance over the system’s rollout
  • the Aboriginal and Torres Strait Islander Health Practice Council of New South Wales’ financial statements were not prepared on a ‘going concern’ basis because it had insufficient funding to continue operating
  • the Department of Industry, Skills and Regional Development needs to improve the recording and accounting for Crown Land (repeat issue)
  • the financial reporting requirements for Local Land Services local boards, established under the Local Land Service Act 2013, need to be clarified (repeat issue)
  • significant limitations exist in TAFE NSW’s student administration system (repeat issue)
  • Hunter Water Corporation contracted to sell Kooragang Island Advanced Water Treatment Plant, which is conditional on the purchaser obtaining a water licence for use of the plant, for $35.5 million. This resulted in a $20.5 million decrease in the revaluation reserve
  • Hunter Water Corporation received $28.1 million from the sale of land impacted by the NSW Government’s decision not to construct Tillegra Dam. This was $62.4 million less than the carrying value of the land
  • Sydney Water Corporation needs to ensure it has robust governance over the development and implementation of a new customer billing system and an integrated enterprise resource planning system, budgeted to cost $184 million and $54.5 million respectively.

Timeliness of financial reporting

More financial statements and audit opinions signed within three months of year end

Most agencies submitted and signed their financial statements on time, which enabled more audits to be completed within three months of year end.

In 2015–16, 204 of 286 agencies’ financial statements and audit opinions were signed within three months of the year end. This compares to only 67 in 2010–11, the year before NSW Treasury introduced mandatory early close procedures.

Early close procedures improved the timeliness of financial reporting

Agencies were broadly successful in performing early close procedures in 2015–16. However, we did identify opportunities for improvement across the NSW public sector.  

The timeliness of financial reporting can be improved further if agencies:

  • resolve all significant accounting issues during the early close process, or document a clear path towards timely resolution
  • establish internal timetables and work with their service providers to ensure supporting work papers are prepared on time
  • assess and document the impact of new and revised accounting standards effective in the current or future years
  • prepare reconciliations, which are properly supported and reviewed
  • analyse and clear suspense accounts on a timely basis
  • complete asset valuations on time (also refer below).

Agencies will not always be able to fully resolve significant and complex accounting issues as part of the early close process. If this is the case, it is important they document a clear path towards timely resolution and ensure relevant stakeholders, including NSW Treasury, are kept informed. The documentation should set out the issue, status, key aspects needing resolution, and who is responsible for the expected deliverables.

Changes in accounting standards can materially impact agencies’ financial statements. Agencies will need to ensure they review the impact of, and have appropriate systems and processes in place to address these changes. Because of the lead time required, agencies need to start preparing for imminent changes now. The more significant changes that will come into effect over the next two years include:

  • service concession arrangements - where private sector entities design, build, finance and/or operate infrastructure to provide public services, such as toll roads, utilities, prisons and hospitals
  • the classification, measurement, recognition and de-recognition of financial instruments
  • leasing arrangements - lessees will no longer classify leases as operating or finance leases; leases will be ‘capitalised’ with financial liabilities being recognised for future lease payments.

NSW Treasury has narrowed the scope of mandatory early close procedures

NSW Treasury Circular 16-13 'Agency guidelines for the 2016–17 Mandatory Early Close' has narrowed the scope of mandatory early close procedures to non-financial asset valuations and proforma financial statements. Early close procedures that are no longer mandatory, but considered to be good practice by NSW Treasury, include:

  • resolving all past audit issues
  • performing key account reconciliations
  • agreeing and confirming inter and intra (cluster) agency balances and transactions
  • identifying material, complex and one-off transactions
  • preparing quality workpapers to support balances with variance analysis and meaningful explanations for movements
  • adequate review by management and Audit and Risk Committees.

If agencies do not perform the good practice procedures, the early close process may not be as effective in ensuring the quality and timeliness of financial reporting. We will monitor and report on the impact of this change on the timeliness and quality of the 2016–17 financial statements.

NSW Treasury piloted a hard-close initiative

NSW Treasury conducted a ‘hard-close pilot’ with nine agencies in 2015–16 to assess the benefits, and whether they should be applied more widely across the NSW public sector. While NSW Treasury has evaluated the results of the pilot, it has not mandated agencies complete hard close procedures in 2016–17. NSW Treasury Circular 16–13 gives agencies the option to complete hard close procedures.  

Hard close procedures involve applying year-end procedures to the fullest extent practicable at a preliminary month end date to further improve the quality and timeliness of financial reporting.

Processes for asset valuations can be improved

Although most agencies complied with NSW Treasury’s early close asset revaluation procedures, we identified areas where they can be improved.  

Asset valuations can be complex. They can involve the valuation of a large, geographically dispersed asset base, require significant judgement to estimate fair value and require substantial resources to complete.

Asset revaluations are successful when:

  • revaluation projects commence early enough to obtain the results and to reflect this in the early close pro forma financial statements, fixed asset register and general ledger
  • all assets are identified, recorded and reconciled before being provided to the valuer and the valuation methodology is agreed and documented
  • quality work papers are prepared setting out management’s proposed accounting treatments, judgements and assumptions
  • management engages with the valuers and interrogates the valuation results with scepticism
  • valuation issues are resolved before preparing the year-end financial statements.

NSW Treasury Policy Paper TPP14-01 also provides guidance to agencies to help manage the revaluation process.

Performance reporting

In 2017 and 2018, NSW Treasury is implementing its Financial Management Transformation (FMT) program. The program will replace the current ‘service group’ budgeting and reporting structure with program based budgeting and reporting. The program expects to have the legislation, policy framework and financial reporting system rolled out for the 2017–18 financial year.  

The program will implement a modern IT system, PRIME, as NSW Treasury's key tool to support whole-of-government budgeting and reporting. PRIME is expected to give the NSW Government strategic, relevant and timely information to plan and deliver its policy priorities and the Budget. It is expected to capture and monitor financial and non-financial performance data, and provide business intelligence and analytics. The roll-out of PRIME commenced in November 2016 and the 2017–18 Budget will be delivered using PRIME.

A project of this scale and complexity has many risks, which need to be carefully managed if the desired benefits are to be realised. To manage the risks, NSW Treasury is running PRIME in parallel with the existing IT systems for an extended period that covers preparation of the 2017–18 budget.

Independent assurance over the appropriateness and accuracy of agency key performance measures and indicators would improve confidence in the reliability of the NSW Government performance data.

Monitoring and guiding program performance will mean:

  • developing and implementing high level frameworks, policies and guidance
  • establishing measures and setting targets for performance
  • ensuring the availability of and access to high quality data and other information
  • obtaining independent assurance over the quality of the data.

The FMT program aims to achieve:

  • better performance and outcomes management
  • improved management of the State’s balance sheet, revenues and expenditures
  • stronger interagency collaboration
  • clearer accountabilities
  • better reporting of performance and outcomes.

This should give the NSW Government greater visibility on whether programs are delivering value for money, with emphasis not just on whether they are meeting compliance requirements, but whether they are also meeting performance expectations. This will require agencies to have the expertise they need to analyse how programs are performing and meeting expected outcomes.

 Appropriate financial controls help ensure the efficient and effective use of resources and the implementation and administration of agency policies. They are essential for quality and timely decision making.  

In 2015–16, our audit teams made the following key observations on the financial controls of NSW public sector agencies.

Financial controls
Observation Conclusion
More needs to be done to implement audit recommendations on a timely basis. We found 212 internal control issues identified in previous audits had not been adequately addressed by 30 June 2016.

Delays in implementing audit recommendations can impact the quality of financial information and the effectiveness of decision making.

Agencies need to ensure they have action plans, timeframes and assigned responsibilities to address recommendations in a timely manner.

Agencies continue to face challenges managing information security. Most information technology issues we identified related to poor IT user administration in areas like password controls and inappropriate access. Agencies should review the design and effectiveness of information security controls to ensure data is adequately protected.

We found shared service provider agreements did not always adequately address information security requirements.

Where agencies use shared service providers they should consider whether the service level arrangements adequately address information security.

Thirteen of 108 agencies required to attest to having a minimum set of information security controls did not do so in their 2015 annual reports. The 'NSW Government Digital Information Security Policy' recognises the growing need for effective information security. With cyber security threats continuing to increase as digital services expand we plan to look at cyber security as part of our 2017–18 performance audit program.
We identified instances where service level agreements with shared service providers were outdated, signed too late or did not exist. Corporate and shared service arrangements are more effective when service level arrangements are negotiated and signed in time, clearly detail rights and responsibilities and include meaningful KPIs, fee arrangements and dispute resolution processes.
Internal controls at GovConnect, the private sector provider of transactional and information technology services to many NSW public sector agencies were ineffective in 2015–16. We found mitigating actions taken to manage transition risks from ServiceFirst to GovConnect were ineffective in ensuring effective control over client transactions and data. The Department of Finance, Services and Innovation should ensure GovConnect addresses the control deficiencies. It should also examine the breakdowns in the transition of the shared service arrangements and apply the learnings to other services being transitioned to the private sector.
Maintenance backlogs exist in several NSW public sector agencies, including Roads and Maritime Services, Sydney Trains, NSW Health, the Department of Education and the Department of Justice. To address backlog maintenance it is important for agencies to have asset lifecycle planning strategies that ensure newly built and existing assets are funded and maintained to a desired service level.

Internal controls

Agency internal controls

We report deficiencies in internal controls, matters of governance interest and unresolved issues identified during our audits to management and those charged with governance of the agencies. We do this through management letters, which include our observations, related implications, recommendations and risk ratings.

We identified and reported 837 issues during our 30 June 2016 audits. Common internal control weaknesses identified during these audits included: 

  • non-compliance with processes and legislation
  • incomplete and inaccurate central registers, such as those for managing conflicts of interest, legislative compliance and contract management
  • weaknesses in information technology controls (see further details below)
  • financial performance and reporting issues, such as inadequate review of manual journals and poor quality and review of general ledger account reconciliations
  • deficiencies in purchasing and payables processes, such as poor review of vendor master file changes, limited use of purchase orders and inadequate payment approval processes.

Fewer internal control weaknesses were assessed as being high risk than in previous years. High risk internal control deficiencies should be addressed by the relevant agencies as a matter of urgency.

More needs to be done to implement audit recommendations

More needs to be done to implement audit recommendations on a timely basis. We found 212 internal control issues identified in previous audits had not been adequately addressed by 30 June 2016. The highest proportion of these issues were in the following clusters:

  • Family and Community Services cluster - 11 of 31 issues were repeat issues.
  • Planning and Environment cluster - 26 of 88 issues were repeat issues
  • Finance, Services and Innovation cluster - 31 of 111 issues were repeat issues
  • Justice cluster - 33 of 124 issues were repeat issues
  • Transport cluster - 18 of 68 issues were repeat issues
  • Health cluster - 33 of 126 issues were repeat issues.

Two of the 212 issues were classified as high risk and related to:

  • an agency’s lack of effective controls over fundraising activities
  • recognition of a loan and the agency’s capacity to repay the loan

Of the remainder, 126 were classified as moderate risk and 84 as low risk. Delays in implementing audit recommendations can impact the quality of financial information and the effectiveness of decision making. They expose agencies to reputational risks and financial loss.

Some issues can take longer to address due to resource constraints and/or the complexity of the issue. Agencies need to ensure they have action plans, timeframes and assigned responsibilities to address recommendations in a timely manner. Audit and Risk Committees play an important role in monitoring and advising agency heads on how agencies are implementing measures to address audit findings and recommendations.

Internal controls at shared service providers

Cluster corporate and shared service models are common across NSW Government

Corporate and shared service models are common across NSW Government, with most clusters having moved to or planning to move to some form of shared service arrangement. Shared service arrangements are designed to achieve efficiencies and reduce costs by centralising service delivery in areas such as human resources, governance and risk, procurement, finance and information technology. Corporate and shared service models can:

  • consolidate information systems and standardise processes through common policies and procedures. This should provide greater transparency to the cluster lead agency of agencies' and cluster-wide performance
  • deliver better information management and decision support services
  • increase efficiencies and reduce costs.

Agencies need to carefully manage the risks associated with these arrangements, such as:

  • failing to deliver integrated systems and processes across the cluster
  • limiting flexibility, which may hinder agencies from implementing fit for purpose frameworks, such as those for governance and risk
  • sub-optimal performance by service providers and/or ineffective controls at the service provider
  • poor governance, strategic leadership and direction over shared service arrangements.

The NSW Commission of Audit, in its May 2012 report on ‘Government Expenditure’, recommended improvements in the delivery of corporate and shared services across the NSW Government sector.

Service level arrangements are not always in place or are signed too late

We found instances where service level agreements with shared service providers were outdated, signed too late or did not exist. For example:

  • service agreements, which include performance requirements for safety and quality, service access and patient flow, finance and activity, population health and people between the Secretary of NSW Health and local health districts/specialty networks, need to be signed earlier to clarify roles, responsibilities, performance measures, budgets and service volumes and levels
  •  the NSW Department of Industry, Skills and Regional Development and the Department of Justice did not always have service agreements in place with agencies to which they provide financial and corporate services.

Corporate and shared service agreements are more effective when:

  • Service level agreements are negotiated and signed on time
  • the services provided and the rights and responsibilities of each party are clear
  • meaningful KPIs are agreed and there is a process to monitor performance against the KPIs
  • security over data and information is maintained and rights of access to information are established
  • fee arrangements are agreed
  • dispute resolution processes are in place

Agencies need to seek internal control certifications from service providers

NSW Treasury Policy TPP 14–05 'Certifying the Effectiveness of Internal Controls Over Financial Information' requires agencies to obtain certification on the effectiveness of internal controls from outsourced service providers. We found:

  • agencies using the services of GovConnect were unable to rely on controls over financial transactions and information (further details below), which negated the certification process over controls at the service provider. This required the impacted agencies to implement controls to mitigate the control deficiencies at the service provider
  • the Department of Justice did not always provide written certifications on the design and effectiveness of internal controls to client agencies
  • some private sector service providers do not provide independent certifications on the effectiveness of their controls to agencies.

The NSW Treasury Policy notes that, in some instances, client agencies may consider it appropriate to seek additional assurance in the form of an independent opinion on the design and operating effectiveness of controls in the service organisation. Agencies should consider the nature and extent of the services provided by their service provider when determining whether independent assurance is required.

Internal controls at GovConnect were ineffective in 2015–16

GovConnect provides information technology and transactional services to agencies within the NSW Public Sector. Service levels fell during the transition of shared services from ServiceFirst to GovConnect and NSW public sector agencies using these services were unable to rely on controls over financial transactions and information.  

We found mitigating actions taken to manage transition risks from ServiceFirst to GovConnect were ineffective in ensuring effective control over client transactions and data. This increased the risk of fraud and error, and inappropriate access to information.  

The Department of Finance, Services and Innovation should ensure GovConnect addresses the control deficiencies identified in GovConnect’s Independent Auditor’s Assurance reports. It should also examine the breakdowns in the transition of the shared service arrangements and apply the learnings to other services being transitioned to the private sector. Refer to pages 19-20 in our Report on Finance, Services and Innovation for further details.

Information technology

Digital Information Security

Agencies continue to face challenges managing information security

We audited the information systems of 72 agencies in 2016. The audits focused on the information technology (IT) processes and controls supporting the integrity, availability and security of financial data used to prepare the financial statements.

The audits identified opportunities to improve IT control environments, with a large proportion of our findings relating to information security. We recommended agencies review and strengthen information security controls. The key control weaknesses we found related to user administration, password parameters and privileged access.

Over the last three years the number of information systems issues we identified has improved, as shown below: 

  • 2015–16: 72 audits - 121 issues reported
  • 2014–15: 73 audits - 169 issues reported
  • 2013–14: 77 audits - 198 issues reported.

Of the 121 issues reported in 2015–16, two were classified as high risk, 80 as moderate risk and 39 as low risk. The two high risk issues related to:

  • poor password configuration management
  • inappropriate user access accounts and inadequate review of users’ access to the agency’s network, finance applications, database and servers.

Twenty-three per cent of the issues reported in 2014–15 were repeated in 2015–16. The percentage of repeat issues has fallen compared to 2013–14. 

Governance refers to the high-level frameworks, processes and behaviours established to ensure an entity meets its intended purpose, conforms with legislative and other requirements, and meets the expectations of probity, accountability and transparency.  

Governance models need to be adapted for the specific goals and outcomes required for different situations; one size does not fit all. High standards of public sector governance and accountability enable effective and efficient use of public resources. They also help to ensure agencies act impartially and lawfully, deliver program/project benefits within expected costs and timeframes and provide useful information about their activities and achievements.

In 2015–16, our audit teams made the following key observations on governance in NSW public sector agencies

Governance
Observation Conclusion
Cluster governance arrangements that support cluster accountability, performance monitoring, risk and compliance management are unclear.

Currently, cluster governance arrangements are unclear and inconsistently implemented across the NSW public sector. Implementing cluster governance frameworks is complex.

The Department of Premier and Cabinet (DPC) has indicated the NSW Public Sector Governance Framework will be updated to give guidance on cluster governance and how accountability and performance are monitored and reported.

The ‘whole-of-government’ does not have a dedicated audit and risk committee. NSW Government agencies would benefit from a dedicated independent audit and risk committee for the ‘whole-of-government’ that focuses on common issues and risks across the NSW public sector, and recommends and oversights coordinated responses to sector wide issues.

We identified many deficiencies in the oversight and management of Crown Land, including the sale and lease of such land.

We recommended the Department of Industry-Lands improve its processes for the sale and lease of Crown Land.

Our assessment of a sample of 33 agencies found that agencies have risk management governance structures in place, but need to focus on developing stronger risk cultures and fit-for-purpose systems to capture risks and incidents. Agencies need to focus on developing strong risk cultures and fit-for-purpose systems to capture risks and incidents.
We found project cost and time overruns continue to occur. In 2016–17, we will assess risk management maturity and processes focusing on effective risk management in project governance.
Our 2015–16 fraud survey indicates fraud controls are improving, but highlighted areas where agencies can do more. Agencies can review their fraud control measures against our Fraud Control Improvement Kit.
Our review of 13 agencies’ compliance with reporting and disclosure aspects of the GIPA Act found varying degrees of non-compliance at each. Our 2016 Special Report 'Compliance with the GIPA Act' makes recommendations to help agencies comply with the requirements of the Act.

Governance and Accountability

With the NSW public sector changing and becoming more complex, good governance becomes more important so the public's confidence in government and its agencies is maintained. Governance across the NSW public sector is complex and needs to accommodate risks arising from:

  • the Government’s cluster arrangements having no legal basis
  • many agencies not having conventional board structures
  • agencies only being able to do what their enabling legislation allows
  • agencies having for profit or not-for-profit objectives, and/or only being established to achieve a particular purpose
  • capability limitations that may exist in governing bodies
  • stakeholders having high expectations around accountability, transparency and conflicts of interest in public sector agencies.

Adding to this complexity is the continually changing nature of the public sector and the way it delivers services. Often, governance arrangements are impacted by:

  • changes in service delivery models, such as commissioning and contestability arrangements
  • machinery of government changes, leading to agencies being formed, amalgamated or abolished
  • complex financing and other contractual arrangements, such as public private partnerships impacting the structure and risks agencies face.

Those charged with governance are accountable for the decisions they make and need relevant, accurate and up-to-date information on which to base their decisions. Consequently, they need to satisfy themselves the governance frameworks, and the design and effectiveness of internal systems and controls provides sufficient assurance the agency’s activities are in line with expectations and comply with standards and legal requirements.  

Our audits identified deficiencies in some agencies’ governance frameworks, including:

  • not having frameworks to manage and ensure compliance with legislation
  • outdated policies and procedures, including those for fraud and corruption
  • inconsistent risk management frameworks
  • not having effective internal audit functions
  • some smaller agencies not having an Audit and Risk Committee
  • poor frameworks for identifying and managing conflicts of interest and gifts and benefits.

Agencies can assess their governance frameworks against our Governance Lighthouse.

Effective cluster/agency and program/project governance is characterised by:

  • leaders who set the right tone from the top, that shapes the culture and demonstrates the desired values and ethics through the behaviours they model when working with management and external stakeholders
  • a clear strategic purpose and direction, based on a clear understanding of stakeholder expectations, realistic medium and long-term outcomes, short-term priorities and expenditure/investment choices and budgets
  • a shared and strong understanding of the strategy to inform decisions
    strong oversight of progress against the strategy, significant deviations from it, emerging risks and planned benefits from change programs
  • regular reviews of and updates to the strategy to adapt to changing circumstances
    a clear purpose at specific project/program levels
  • charters with structures that include clearly distinct governance and management roles, principles, and processes
  • clearly defined roles and responsibilities that make differing interests transparent and improve decision-making – these should be revisited periodically
  • visible leadership when agencies/projects/programs face difficult issues
    clearly allocated and delegated decision-making for governance and management
  • different people in the roles of chair, project sponsor, manager of the division responsible for delivering a project, the line manager of the project director
  • the right mix of people with different perspectives and skills, who robustly debate issues, but support agreed decisions
  • independent quality assurance 
  • effective risk management that identifies, analyses, mitigates, monitors and communicates risks
  • a defined risk management framework and register that is widely understood and aligned to the agency’s strategy, risk appetite, objectives, business plan and stakeholder expectations
  • a mature risk management culture and reporting structure that is built into the agency or project governance framework
  • clear roles for Audit and Risk Committees, with competent and independent members who have a clear purpose
  • governance arrangements and practices that continually evolve to manage risk and conflicts of interest.

Cluster governance

Cluster governance arrangements, including accountability, are unclear

Currently, cluster governance arrangements are unclear and inconsistently implemented across the NSW public sector. Implementing cluster governance frameworks is complex because clusters bring together entities with different enabling legislation, organisational and legal structures, information systems and processes, risk profiles and governance frameworks. They require Ministers, boards, department Secretaries, agency heads and management to work together to ensure effective cluster governance and accountability arrangements are in place.

Clear cluster governance arrangements would improve cooperation and coordination amongst cluster agencies, help deliver government priorities that cut across agencies and improve service delivery outcomes. We recommended DPC release a revised NSW Public Sector Governance Framework that clearly articulates cluster governance arrangements, the role of the cluster Secretary, Chief Finance Officer, Chief Information Officer and Chief Risk Officer.

DPC has indicated the framework will be updated shortly to provide guidance on governance at a cluster level, including how cluster-level accountability and performance information is monitored and reported. We understand DPC will work with NSW Treasury to revise the framework by mid-2017. It is important for these agencies to collaborate and ensure the outcomes of NSW Treasury's Financial Management Transformation (FMT) program are considered when updating the framework.

The FMT program aims to revise financial governance, budgeting and reporting arrangements in the NSW public sector, and clarify the administrative and accountability arrangements for cluster operations. Further information on FMT is included in the Financial Performance and Reporting and Service Delivery chapters.  

Management oversight and capability

Those charged with governance are ultimately responsible for establishing an appropriate governance framework and system of internal control. However, management is accountable to those charged with governance and their oversight plays an important role in ensuring appropriate policies, procedures and internal controls are designed and working properly.

Sale and lease of Crown land is not being managed effectively

Our 2016 performance audit found limited oversight of sales and leases of Crown land by the Department of Industry - Lands. The Department has only just started monitoring whether tenants were complying with lease conditions, and does not have a clear view of what is happening on most leased Crown land. Most guidance to staff had not been updated for a decade, contributing to staff sometimes incorrectly implementing policies on rental rebates, unpaid rent, rent redeterminations and the direct negotiation of sales and leases on Crown land.  

Decisions on the sale and lease of Crown land were not transparent to the public and the Department has not provided consistent opportunities for the public and interested parties to participate in decisions about Crown land. Between 2012 and 2015, 97 per cent of leases and 50 per cent of sales were negotiated directly between the Department and individuals, without a public expression of interest process.  

Adding to this, our financial audit findings have identified significant deficiencies for several years in recording and accounting for Crown land assets in the Crown Land Information Database and the Department’s general ledger.

A key objective of the Department of Industry - Lands is for Crown land to be occupied, used, sold, leased, licensed or otherwise dealt with in the best interests of the State. A major part of the State’s land holding is Crown land, which had an estimated value of $12 billion in  2015–16. Crown land comprises approximately 42 per cent of all land in New South Wales and supports a wide range of important environmental, economic, social and community activities.  

The Crown Land Management Act 2016 (the Act) received assent from Parliament on 14 November 2016. The Act consolidated eight pieces of legislation. Most of the Act is expected to commence in early 2018. It is expected to reduce complexity and duplication, deliver better social, environmental and economic outcomes and facilitate community involvement in Crown land.

Good progress is being made on implementing public sector management reforms

Our performance audit on ‘Public Sector Management Reforms' found the Public Service Commission was making good progress leading the implementation of public sector management reforms. The Commission developed a sound evidence base for the reforms and gained wide public sector support by engaging with agency heads and using public sector working groups to develop options.  

The Commission needs to do more to report on how the reforms are contributing to better public services and to issue its guidance material to agencies promptly. The audit noted that the capacity and capability of human resource units in some agencies remains an impediment to the successful implementation of the reforms.

In early 2012, the NSW Commission of Audit Interim report identified a range of issues with workforce management in New South Wales. The Public Service Commission (PSC), which was established in late 2011, was tasked to address some of these issues and build the capability of the public sector. The Government Sector Employment Act 2013 (GSE Act), which provides the legislative basis for reforms, commenced in February 2014.

The public sector management reforms are ambitious, covering a substantial workforce and requiring a lot to be done in a short time. To achieve the intended outcomes, the reforms needed to be supported by sound evidence, have clear objectives and performance indicators, and be evaluated at appropriate stages.

Risk Management

The increasing complexity of government business transactions reinforces the need for whole of government approaches to deal with inter-related and inter-dependent risks across government agencies. It is important that safeguards in place to manage these risks are commensurate to the risk posed.

Findings from some of our 2016 performance audits, which looked at how areas of high risk are managed across NSW Government, are detailed below:

Our performance audit on managing unsolicited proposals in New South Wales concluded that governance arrangements for unsolicited proposals were adequate, but greater transparency and public reporting is needed. Unsolicited proposals warrant greater scrutiny and disclosure as they pose a greater risk to value for money than open, competitive and transparent tender processes.

 

Our performance audit on government advertising concluded the peer review process provides sufficient assurance that government advertising programs are needed and are cost effective. Government advertising is an activity that is high risk because of the potential for it to be used for political purposes. In NSW, the Government Advertising Act 2011 requires government advertising campaigns estimated to cost over $50,000 to be independently peer reviewed before launch.  

Cluster-wide risk management

Cluster wide risk management is inconsistent

Agencies within clusters have their own risk profiles and risk management frameworks. We found varying approaches and levels of maturity on how agency risks are captured and escalated to a cluster level so cluster heads can assess how they are being managed, treated and reported. We recommended some clusters review how agency level risks are escalated and reported at a cluster level.

Enterprise-wide risk management

Agency enterprise-wide risk management across the public sector is improving

In 2016, we assessed risk management processes at 33 agencies across the NSW public sector against the criteria in our Risk Assessment Tool. In 2015, we asked 77 agencies to perform a self-assessment of their risk management maturity. The table below compares the overall results of our assessment against the agencies self-assessments. The comparison indicates that risk management is improving.

Our assessments found that agencies have risk management governance structures in place, but need to focus on developing stronger risk cultures and fit-for-purpose systems to capture risks and incidents.

The environment in which services are delivered to the people of NSW is constantly changing. Services need to remain relevant and support the public's changing needs and expectations. People expect high quality services to be delivered in cost effective ways. To do this, agencies need to determine how best to deliver the services. Governments can deliver their services through agencies or through commissioning the right mix of services from public, private and not for profit sector providers.  

Agencies also need to consider how they collaborate with each other to improve the quality of their services and help drive down costs. Changes in innovation and technology can help agencies adapt to changing circumstances and to deliver better services in different ways.

In 2015–16, our audit teams made the following key observations on service delivery by NSW public sector agencies.

Service delivery
Observation Conclusion
New ways of delivering services across NSW Government are being identified, with commissioning and contestability arrangements being introduced or considered.

It is important for accountability to be maintained when services are outsourced.

Commissioning services and introducing new systems can be challenging. It is important for this to be managed well through:

  • strong project governance and leadership to manage risks
  • entering into binding commitments with clear accountabilities
  • good preparation, including adequate training and support for staff
  • sound financial management to control costs.
We found government decision makers are not always receiving enough information to make evidence-based investment decisions. The NSW Government’s program evaluation initiative has been largely ineffective. A performance audit looked at the Justice, Industry, Skills and Regional Development, Planning and Environment, Premier and Cabinet and Treasury clusters and recommended improvements to program evaluation.
We found agencies' performance is not routinely measured, evaluated or publicly reported. Agencies can improve transparency over their performance with a stronger focus on measuring performance and outcomes so they can make evidence-based decisions and maintain public accountability.
According to unaudited agency data, some Premier's and State Priorities are at risk of not being achieved. Independent assurance over the reliability and accuracy of the data would increase confidence in the performance indicators used to measure achievement of the Government’s priorities.
A comprehensive report of performance against the State Priorities is not published. We understand the NSW Government is considering public reporting against the State Priorities and developing reporting options.

Commissioning and Contesting the Delivery of Services

The publics' rising expectations, and rapidly changing and increasingly complex needs mean agencies cannot be complacent even when they deliver good services. To meet changing expectations and needs, agencies need to build on their strengths and leverage opportunities a modern, technology driven and information rich environment provides.

Government outcomes can be achieved through the effective commissioning of the right mix of services from the public, private and not-for-profit sectors. Commissioning involves agencies assessing citizens’ needs, determining priorities, designing and sourcing appropriate services, and monitoring and evaluating performance. NSW Treasury's 'Government Commissioning and Contestability Policy', published in November 2016, aims to provide a clear and consistent policy direction, definition and set of principles to guide NSW Government agencies when commissioning and contesting services.

It is important for agencies to understand the Government's strategic direction and objectives when partnering with others or commissioning the delivery of services. They must be prepared and able to work together and with others in different ways to deliver the best quality public services possible. Agencies face challenges and opportunities when commissioning services. These include:
 
  • determining the size, variety and location of services needed to meet customer needs and expectations
  • doing things differently to ensure public services are delivered efficiently and effectively
  • developing and nurturing markets, and transitioning services into and out of government
  • partnering with other public and private sector entities, and non-government organisations (NGOs)
  • establishing and maintaining clear accountabilities for jointly delivered services
  • using new approaches that leverage improvements in technology
  • involving the people of NSW in designing, planning, and delivering services
  • using, sharing and communicating information about service delivery
  • building agencies' capacity and capability
  • measuring and benchmarking service performance.

Effective commissioning can be achieved through:

  • strong governance and leadership to manage relationships and risks effectively within risk appetite levels
  • good information systems and tools 
  • being well prepared with the right capability and number of employees who are well trained and supported
  • adopting approaches that best fit the circumstances
  • regularly monitoring and assessing if expected outcomes are being achieved 
  • having a common purpose with clear outcomes
  •  being flexible and prepared to make trade-offs
  •  binding commitments with clear accountabilities
  •  sound financial management to control costs
  •  adequate development and testing of new systems before going live.

Commissioning and contestability continues to increase

We continue to see new ways of delivering services across NSW Government agencies. Some examples of commissioning and contestability include:

  • commissioning of GovConnect to provide information technology and transactional services to several agencies within the NSW Public Sector (refer Financial Controls chapter for further detail)
  • contestability testing within NSW Health, including linen services, non-emergency patient transport, warehousing, hospital support services, pathology and radiology
  • commissioning NGOs to provide some services traditionally provided by the Department of Family and Community Services ($2.8 billion received by NGOs in 2015–16 for the delivery of these services).

Our performance audit on franchising of the Sydney Ferries network found the decision to do so was justified and Transport for NSW’s management of the franchise was largely effective. The franchising has resulted in cost savings, good service performance and effective risk transfer from Government to the private sector operator. Scheduled ferry services are now provided under a seven-year contract managed by Transport for NSW.

Our 2016–17 performance audit program includes a review of Roads and Maritime Services' (RMS) Sydney region road maintenance contracts to assess whether RMS has realised the expected benefits of outsourcing road maintenance for the Sydney Region West and South zones under its Stewardship Maintenance Contracts. We also recently tabled a performance audit report, which focused on the Department of Family and Community Services work to build the readiness of the non-government sector for the National Disability Insurance Scheme.

Accountability needs to be maintained when services are outsourced

Generally, contractual arrangements allow an agency that is outsourcing services to review and assess the performance of the service provider. However, outsourced service providers are not directly accountable to the NSW Parliament for their use of public resources.

Governments are increasingly outsourcing to or partnering with private and NGO providers to deliver government services. Consequently, many parliaments now have legislation that enables Auditors-General to ‘go beyond’ the boundaries of the agencies commissioning services and into the entities providing the services to examine how effectively and efficiently they are providing the services (‘follow the money’ powers). New South Wales legislation does not currently provide the Auditor–General with such powers.

Delivering Government Services

Evidence-based decision making

Government services are being delivered by agencies through a variety of programs

To do this effectively agencies need to be able to make evidence based decisions. In August 2013, the NSW Government commenced a program evaluation initiative, which required agencies to periodically evaluate their programs. Since then, NSW Treasury and DPC have worked with agencies to implement the initiative. Agencies are required to prioritise programs for evaluation based on size, strategic significance and degree of risk, recognising their available capability and resources to conduct evaluations.

Our performance audit on 'Implementation of the NSW Government’s program evaluation initiative' showed the initiative was largely ineffective and government decision makers were not receiving enough information to make evidence-based investment decisions. The audit looked at the Justice, Industry, Skills and Regional Development, Planning and Environment, Premier and Cabinet and Treasury clusters.

Our performance audit also recommended NSW Treasury develop an evaluation framework to support the program budgeting and reporting component of the Financial Management Transformation (FMT) program, and ensure the program evaluation initiative is integrated into the new framework.

The FMT program budgeting, reporting and evaluation initiative aims to provide evidence-based information to inform investment decisions on programs. Adopting program budgeting and reporting as a key component of the FMT program requires a proven and systematic evidence-based methodology for measuring the efficiency and effectiveness of the programs.

Service delivery performance

Our performance audits found mixed service delivery performance

Performance audits build on our financial audits by reviewing whether taxpayers' money is spent efficiently, effectively, economically and in accordance with the law. Many of our performance audits focus on whether agencies are delivering good services to citizens at a reasonable cost. Findings from some of our 2016 audits, which focused on service delivery performance, are outlined below:

New South Wales has a lower rate of foodborne illness than the national average. This reflects some good practices in the NSW Food Authority’s approach to monitoring food safety standards. To ensure foodborne illnesses remain low, the Authority needs to better monitor its arrangements with local councils that inspect retail food businesses on its behalf, and receive additional and more timely information from them on compliance with food safety standards.

 

The Department of Education is doing a reasonable job of managing how well students with a disability transition to new schools and in supporting teachers to improve the students’ educational outcomes. We found enrolments in quality early childhood education were increasing, but were still below benchmark and funding could be better targeted to disadvantaged children in long day care.

 

Juvenile Justice NSW prepares and helps young people reintegrate into the community reasonably well after detention, given their complex needs, but access to post-release services is problematic.

 

Citizens will benefit if red tape is reduced. Overall, NSW Government initiatives and processes to prevent and reduce red tape have not been effective. In the absence of an accurate red tape savings figure and a stocktake of regulation, the NSW Government does not have a clear view of the impact its reported savings had on the overall net burden of red tape in New South Wales. Its ‘one-on, two-off’ initiative to reduce legislative regulatory burden achieved its numerical target, but the cost of the total legislative burden increased by $16.1 million over the same period.

Reporting on Service Delivery Performance

As agencies partner and collaborate more, measuring performance becomes more important. Sharing, using and making information available enables agencies to collectively understand and improve their service performance. This also gives agencies an opportunity to achieve efficiencies in collating and using research and performance data within privacy and legislative constraints. Where appropriate, agencies should consider obtaining independent assurance over the reliability and accuracy of the performance data they use.

Complaints are an important and free source of information that can provide valuable insights into poor service, systemic errors or problems with specific processes. How agencies manage and respond to complaints demonstrates their commitment to high standards of service delivery. Complaints also give agencies an opportunity to understand the expectations and experiences of people using their services. Government agencies need to ensure complaints are easy to make, consistently recorded and analysed, and openly reported and actioned.

Transparency over performance

Performance is not always measured, evaluated or publicly reported

A key objective of public sector reform is to improve performance and create a culture of accountability. Inadequate performance measures and primarily internal reporting, reduces transparency of agency performance and makes it hard for the public to assess if agencies are doing a good job. A sample of our audits found:
 
  • the effectiveness of Corrective Services NSWs performance framework was limited because performance information was not readily available to correctional centres to make more informed decisions on how best to manage their centres
  • red tape savings figures were not accurate and there was no central oversight of red tape reduction strategies
  • a lack of detailed costings meant we could not be sure regulation of early childhood education was efficient even though processes appeared to be good
  • while the Department of Family and Community Services has transparent performance reporting which is regularly published, the use and reporting of targets and benchmarks is limited
  • while icare collects performance information it does not use this information to assess the success of the return to work program. The return to work rate has increased from 85.5 per cent to 88.3 per cent since the workers’ compensation reforms were introduced in 2012, but there was no benchmark to assess if this result is meeting the desired objectives of the reforms
  •  the Environment Protection Authority has not developed measures and targets to assess achievement of outcomes associated with illegal dumping initiatives.

Agencies should consider whether their performance measurement frameworks:

  • measure the right things, focus on outcomes and integrate with decision making processes
  • set baselines and establish targets and timeframes for key performance indicators
  • require the use of reliable, up to date and accurate information
  • require information to be publicly reported to increase transparency.

The Government will not get the same level of reliance on performance information as it does for financial statements if that information is not independently assured. We will continue to focus on how well agencies assess and report the performance of their initiatives in achieving desired outcomes.

Premier's and State Priorities

The NSW Government released State Priorities 'NSW: Making it Happen' in September 2015. It includes 12 Premier's Priorities and 18 State Priorities with measures and targets to track the Government's performance in key priority areas.

The Premier's Priorities are detailed below.

  • Protecting our kids
  • Improving service levels in hospitals
  • Improving education results
  • Driving public sector diversity
  • Keeping our environment clear
  • Faster housing approvals
  • Reducing domestic violence
  • Tackling childhood obesity
  • Reducing youth homelessness
  • Improving government services
  • Creating jobs
  • Building infrastructure

Performance against the Premier's and State Priorities is not audited

The Premier's and State Priorities have not been independently audited to provide assurance the performance information is accurate. The Commonwealth, Victorian and Western Australian Auditors-General have varying powers that provide for auditing the appropriateness of agency key performance indicators and determine whether they fairly represent actual performance. NSW legislation does not currently provide the Auditor-General with such powers.

Premier's Priorities

Some Premier's Priorities are at risk of not being achieved

Our 2015–16 reports commented on the Government's performance against some of the Premier’s and State Priorities. Published data, which we have not audited, indicates the following Premier's Priorities may be at risk of not being achieved:

  • the proportion of domestic violence perpetrators re-offending within 12 months was 15.9 per cent, which is 6.7 percentage points higher than the target of 9.2 per cent (refer page 52–53 in Report on Law and Order, Emergency Services and the Arts for further details)
  • the percentage of children and young people re-reported at risk of significant harm was 40 per cent, which is 5.6 percentage points higher than the target of 34.4 per cent (refer page 31–32 in Report on Family and Community Services)
  • in 2015–16, 32.5 per cent of students achieved results in in the top two NAPLAN bands for reading and numeracy, marginally below the baseline of 32.7 per cent and below the 2019 target of 35.2 per cent (refer page 40–41 in Report on Education for further details)
  • the rate of patients leaving emergency departments within four hours was 74.2 per cent, 6.8 percentage points below the target of 81 per cent (refer page 53 in Report on Health for further details).

Published data, which we have not audited, indicates the following Premiers Priorities have been achieved or are on track to be achieved:

Progress against all 12 priorities can be found at https://www.nsw.gov.au/improving-nsw/premiers-priorities.

State Priorities

Some State Priorities at risk of not being achieved

Data, which we have not audited, indicates the following State Priorities may be at risk of not being achieved:

  • journey time reliability was 86 per cent in 2015–16, four percentage points below the 90 per cent target for peak travel on key routes being on time (refer page 48 in Report on Transport for further details)
  • in 2015–16, 9.1 per cent of Aboriginal and Torres Strait Islander students achieved results in the top two NAPLAN bands for reading and numeracy, which shows no improvement on the baseline of 9.1 per cent and is below the 2019 target of 11.6 per cent (refer page 42–43 in Report on Education for further details)
  • reducing the rate of adult re-offending by five per cent by 2019 – the rate increased 2.3 percentage points over the five years since 2010 to 36.7 per cent for the year ended 31 December 2014 (refer page 53–54 in Report on Law and Order, Emergency Services and the Arts for further details).

Data, which we have not audited, indicates the following State Priorities have been achieved or are on track to be achieved:

  • the State maintained its AAA credit rating (refer page 25 in Report on State Finances for further details)
  • general government expenditure growth was 4.4 per cent in 2015–16 and continued to be below long term revenue growth of 5.6 per cent (refer page 25 in Report on State Finances for further details)
  • 70,077 new dwelling approvals were granted in 2015–16, higher than the target of 50,000 approvals (refer page 35 in Report on Planning and Environment for further details)
  • the time taken to assess planning applications for complex state significant developments fell 46 per cent in 2015–16 from the 2013–14 baseline. A further four percentage point reduction is required to meet the target of halving the time to perform these assessments (refer page 35 in Report on Planning and Environment for further details)

A comprehensive report of performance against the State Priorities is not published

The Department of Premier and Cabinet has defined targets and measures in ‘NSW: Making it Happen’ so Ministers and individual agencies know which targets they are accountable for and how they will be measured. While some measures are publicly reported through agency annual reports or other sources, a comprehensive report of performance against the 18 State priorities is not published. We understand the NSW Government is considering this matter and developing reporting options.

Agencies are responsible for the priorities and they report progress at least bi-annually to the Department of Premier and Cabinet for reporting to the Premier. We will continue to report performance against the targets set in the Premier's and State Priorities.

Contract Management

Our audits identified deficiencies in contract management processes

Our audits continue to identify deficiencies in contract management processes, including:

  • agencies not having central contract registers detailing key contractual obligations and commitments
  • incomplete and inaccurate contract registers and/or no policy or procedures to update and maintain contract registers
  • no monitoring of contract performance.

We recommended agencies in the Family and Community Services and Planning and Environment clusters improve contract management processes. A robust contract management framework helps ensure all parties meet their obligations, contractual relationships are well managed, value for money is achieved and deliverables meet the required standards and agreed timeframes.

A 2014 performance audit ‘'Making the most of government purchasing power – telecommunications' developed a Better Practice Contract Management Framework (Framework) with nine key elements. Agencies can refer to this framework when assessing the adequacy of their contract management framework.

Benefits realisation

Benefits realisation approach for the Service NSW initiative is not as effective as it could be

Effective benefits realisation is critical to achieving intended outcomes expected from investments.  

Our performance audit on 'Realising the benefits of the Service NSW initiative' found the benefits realisation approach for the Service NSW initiative is not as effective as it could be. While customers think Service NSW provides a convenient and practical way to access all government transaction services:  

  • it was unclear who should monitor and report on the achievement of whole-of-government benefits and savings anticipated from the initiative
  • there was insufficient data to fully value or identify individual agency and whole-of-government savings and benefits.

This makes it difficult for the NSW Government to demonstrate the expected economic benefits of Service NSW will outweigh costs by the estimated five to one, and that savings will accrue after 2016–17.

The Department of Finance, Services and Innovation has developed a benefits realisation management framework, which can be found at www.finance.nsw.gov.au/publication-and-resources/benefits-realisation-management-framework. The Department of Education has established a benefits realisation plan for the Learning Management and Business Reform Program (LMBR) following our performance audit on the LMBR program. The Department of Planning and Environment is planning a benefits realisation review on the implementation of stage one of the ePlanning system.  

We will continue to review whether agencies have implemented effective benefit realisation frameworks for major projects and programs and examine the outcomes of benefit realisation reviews.

Published

Actions for Implementing Asset Management Reforms

Implementing Asset Management Reforms

Justice
Planning
Finance
Treasury
Asset valuation
Financial reporting
Infrastructure
Internal controls and governance
Management and administration
Project management

Hospitals, schools, public housing, roads, bridges, buses and trains are just some of the assets used by government in providing services to citizens.

The NSW Government’s asset base is impressive in size - with a value of around $167 billion and with government plans to spend around $8 billion acquiring or replacing assets in the current year. Another $2 billion is spent each year on maintenance.

Good asset management is very important to government; even a small efficiency gain in this area can provide significant returns. Good practice by those responsible for managing assets can improve reliability, extend asset life, save on maintenance costs and aid in identifying and disposing of unnecessary or non-performing assets.

Improving the NSW public sector’s approach to asset management has been on the reform agenda for at least a decade. Changes in practice have been accelerated more recently by integrating asset management policy with the budget process.

In this audit we examined NSW Treasury’s efforts to improve asset management practices in the public sector and the progress made by 3 agencies - the Department of Corrective Services, NSW Fire Brigades and the Powerhouse Museum - towards better managing their asset portfolios.

This report informs Parliament and the community on progress to date and what more needs to be done to ensure that agencies manage assets effectively and achieve best value.

 

Parliamentary reference - Report number #143 - released 12 October 2005

Published

Actions for Managing and Measuring Success: Department of Juvenile Justice

Managing and Measuring Success: Department of Juvenile Justice

Justice
Compliance
Internal controls and governance
Management and administration
Service delivery

Criminal or anti-social juvenile behaviour affects us all. Some of us may be victims of juvenile crime, some may be apprehensive about their personal safety, while others may know of young people who have been in trouble with the law. And, as taxpayers, all of us contribute to the costs of juvenile justice.

Currently about one in every 200 young people in NSW is convicted of a crime each year. The Department of Juvenile Justice works with these young offenders to help them fit back into society and lead a life free of crime.

This is not an easy task. Young offenders are often difficult to help. Many come from disadvantaged backgrounds and may have had poor parental supervision. They may have achieved little at school, have poor work prospects and psychological problems, and be part of an anti-social peer group.

While the Department of Juvenile Justice has prime responsibility, agencies in the justice and welfare systems need to work closely together to tackle these complex and diverse issues. They ultimately desire the same result for young offenders – progression to a well-adjusted, crime-free adulthood.

The report highlights the challenges facing all those who work with young offenders - youth workers, police officers, magistrates, health workers and teachers. Achieving the best possible outcome for these young people will help bring about safer and more harmonious communities for us all.

This is the first of two audits in our current performance audit program that deals with young offenders. We examined how the Department of Juvenile Justice measures performance, and whether staff have adequate information to make sound planning decisions and recommend appropriate interventions for young offenders.

Our next audit, starting later in 2005, will review whether relevant government agencies effectively coordinate the management of young offenders.

 

Parliamentary reference - Report number #142 - released 14 September 2005

Published

Actions for Coordination of Rescue Services

Coordination of Rescue Services

Justice
Internal controls and governance
Management and administration
Regulation
Service delivery
Workforce and capability

Nearly 11,000 rescues are carried out each year in New South Wales, the majority involving motor vehicle accidents.

In metropolitan areas we have three emergency services providing general land rescue - NSW Police, the Ambulance Service and the NSW Fire Brigades. The two volunteer services, the State Emergency Service and the Volunteer Rescue Association, generally cover the remainder of the State.

Rescue arrangements in NSW are different to all other mainland states. Elsewhere, the trend in metropolitan areas has been towards consolidation with only one provider of rescue services.

The State Rescue Board of NSW was set up in 1989. Its primary role is to ensure efficient and effective rescue services are maintained throughout the State.

In this audit we examined how well placed the Board was to provide assurance to Parliament and the community that the organisation of rescue services in NSW best serves those in need of rescuing.

NSW deserves a clear and unequivocal answer on such an important issue. However, the issues are complex, often strongly argued, and generally there is insufficient relevant information upon which to make judgements about performance and value. This report outlines a way forward.

 

Parliamentary reference - Report number #140 - released 20 July 2005