Reports
Actions for Internal Controls and Governance 2019
Internal Controls and Governance 2019
This report covers the findings and recommendations from the 2018–19 financial audits that relate to internal controls and governance at 40 of the largest agencies in the NSW public sector. The 40 agencies selected for this report constitute around 84 per cent of total expenditure for all NSW public sector agencies.
The report provides insights into the effectiveness of controls and governance processes across the NSW public sector. It evaluates how agencies identify, mitigate and manage risks related to:
- financial controls
- information technology controls
- gifts and benefits
- internal audit
- contingent labour
- sensitive data.
The Auditor-General recommended that agencies do more to prioritise and address vulnerabilities in their internal controls and governance. The Auditor-General also recommended agencies increase the transparency of their management of gifts and benefits by publishing their registers on their websites.
This report analyses the internal controls and governance of 40 of the largest agencies in the NSW public sector for the year ended 30 June 2019.
1. Internal control trends
New, repeat and high risk findings |
There was an increase in internal control deficiencies of 12 per cent compared to last year. The increase is predominately due to a 100 per cent increase in repeat financial and IT control deficiencies. Some agencies attributed the delay in actioning repeat findings to the diversion of staff from their regular activities to implement and operationalise the recent Machinery of Government changes. As a result, actions to address audit recommendations have been deferred or re prioritised, as the changes are implemented. Agencies need to ensure they are actively managing the risks associated with having these vulnerabilities in internal control systems unaddressed for extended periods of time. |
Common findings |
A number of findings were common to multiple agencies. These findings often related to areas that are fundamental to good internal control environments and effective organisational governance, such as:
|
2. Information technology controls
IT general controls |
We examined information security controls over key financial systems that support the preparation of agency financial statements. We found:
We also found 20 per cent of agencies had deficient IT program change controls, mainly related to segregation of duties in approval and authorisation processes, and user acceptance testing of program changes prior to deployment into production environments. User acceptance testing helps identify potential issues with software incompatibility, operational workflows, absent controls and software issues, as well as areas where training or user support may be required. |
3. Gifts and benefits
Gifts and benefits registers |
All agencies had a gifts and benefits policy and 90 per cent of agencies maintain a gifts and benefits register. However, 51 per cent of the gifts and benefits registers we examined contained incomplete declarations, such as missing details for the approving officer, value of the gift and/or benefit offered and reasons supporting the decision. In some cases, gaps in recorded information meant the basis for decisions around gifts and benefits was not always clear, making it difficult to determine whether decisions in those instances were appropriate, compliant with policy and were not direct or indirect inducements to the recipients to favour suppliers or service providers. Agencies should ensure their gifts and benefits register includes all key fields specified in the Public Service Commission's minimum standards for gifts and benefits. Agencies should also perform regular reviews of the register to ensure completeness and ensure any gift or benefit accepted by a staff member meets the public's expectations for ethical behaviour. |
Managing gifts and benefits |
We found opportunities to improve gifts and benefits processes and enhance transparency. For example, only three per cent of agencies publish their gifts and benefits registers on their websites. Agencies can improve management of gifts and benefits by:
|
Reporting and monitoring |
Only 35 per cent of agencies reported trends in the number and nature of gifts and benefits recorded in their registers to the agency's senior executive management and/or a governance committee. Agencies should regularly report to the agency executive or other governance committee on trends in the offer and acceptance of gifts and benefits. |
4. Internal audit
Obtaining value from the internal audit function |
Agencies have established and maintained internal audit functions to provide assurance on the effectiveness of agency controls and governance systems. However, we identified areas where agencies' internal audit functions could improve their processes to add greater value. For example, only 73 per cent of CAEs regularly attend meetings of the agency board or executive management committee. Internal audit functions can add greater value by involving the CAE more extensively in executive forums as an observer. Internal audit functions should also consider producing an annual report on internal audit. An annual report allows the internal audit function to report on their performance and add value by drawing to the attention of audit and risk committees and senior management strategic issues, thematic trends and emerging risks. |
Role of the Chief Audit Executive |
Forty-five per cent of agencies assigned responsibilities to the Chief Audit Executive (CAE) that were broader than internal audit, but 17 per cent of these had not documented safeguards to protect the independence of the CAE. The reporting lines and status of the CAE at some agencies also needs review. At two agencies, the CAE reported to the CFO. Agencies should ensure:
|
Quality assurance and improvement program |
Thirty-five per cent of agencies did not have a documented quality assurance and improvement program for its internal audit function. The policy and the International Standards for the Professional Practice of Internal Auditing require agencies to have a documented quality assurance and improvement program. The results of this program should be reported annually. Agencies should ensure there is a documented and operational Quality Assurance and Improvement Program for the internal audit function that covers both internal and external assessments. |
5. Managing contingent labour
Obtaining value for money from contingent labour |
According to NSW Procurement data, spend on contingent labour has increased by 75 per cent over the last five years, to $1.5 billion in 2018–19. Improvements in internal processes and a renewed focus on agency monitoring and oversight of contingent labour can help ensure agencies get the best value for money from their contingent workforces. Agencies can improve their management of contingent labour by:
We also found 57 per cent of the 23 agencies we examined with contingent labour spend of more than $5 million in 2018–19 have implemented the government's vendor management system and service provider 'Contractor Central'. |
6. Managing sensitive data
Identifying and assessing sensitive data |
Sixty-eight per cent of agencies maintain an inventory of their sensitive data and where it resides. However, these inventories are not always complete and risks may be overlooked. Agencies can improve processes to manage sensitive data by:
|
Managing data breaches |
Eighty-eight per cent of agencies have established policies to respond to potential data breaches when they are identified and 70 per cent of agencies maintain a register to record key information in relation to identified data breach incidents. Agencies should maintain a data breach register to effectively manage the actions undertaken to contain, evaluate and remediate each data breach. |
This report covers the findings and recommendations from our 2018–19 financial audits that relate to internal controls and governance at 40 of the largest agencies (refer to Appendix three) in the NSW public sector. The 40 agencies selected for this volume constitute around 84 per cent of total expenditure for all NSW public sector agencies.
Although the report includes several agencies that have changed as a result of the Machinery of Government changes that were effective from 1 July 2019, its focus on sector wide issues and insights means that its findings remain relevant to NSW public sector agencies, including newly formed agencies that have assumed the functions of abolished agencies.
This report offers insights into internal controls and governance in the NSW public sector
This is the third report dedicated to internal controls and governance at NSW State Government agencies. The report provides insights into the effectiveness of controls and governance processes in the NSW public sector by:
- highlighting the potential risks posed by weaknesses in controls and governance processes
- helping agencies benchmark the adequacy of their processes against their peers
- focusing on new and emerging risks, and the internal controls and governance processes that might address those risks.
Without strong governance systems and internal controls, agencies increase the risks associated with effectively managing their finances and delivering services to citizens. For example, if they do not have strong information technology controls, sensitive information may be at risk of unauthorised access and misuse.
Areas of specific focus of the report have changed since last year
Last year's report topics included transparency and performance reporting, management of purchasing cards and taxi use, and fraud and corruption control. We are reporting on new topics this year and re-visiting agency management of gifts and benefits, which we first covered in our 2017 report. Re-visiting topics from prior years provides a baseline to show the NSW public sectors’ progress implementing appropriate internal controls and governance processes to mitigate existing, new and emerging risks in the public sector.
Our audits do not review all aspects of internal controls and governance every year. We select a range of measures and report on those that present heightened risks for agencies to mitigate. This year the report focusses on:
- internal control trends
- information technology controls, including access to agency systems
- protecting sensitive information held within agencies
- managing large and diverse workforces (controls around employing and managing contingent workers)
- maintaining an ethical culture (management of gifts and benefits)
- effectiveness of internal audit function and its oversight by Audit and Risk Committees.
The findings in this report should not be used to draw conclusions on the effectiveness of individual agency control environments and governance arrangements. Specific financial reporting, internal controls and audit observations are included in the individual 2019 cluster financial audit reports, which will be tabled in parliament from November to December 2019.
Internal controls are processes, policies and procedures that help agencies to:
- operate effectively and efficiently
- produce reliable financial reports
- comply with laws and regulations
- support ethical government.
This chapter outlines the overall trends for agency controls and governance issues, including the number of audit findings, the degree of risk those deficiencies pose to the agency, and a summary of the most common deficiencies we found across agencies. The rest of this report presents this year’s controls and governance findings in more detail.
Key conclusions and sector wide learnings
- out of date policies or an absence of policies to guide appropriate decisions
- poor record keeping and document retention
- incomplete or inaccurate centralised registers or gaps in these registers.
Policies, procedures and internal controls should be properly designed, be appropriate for the current organisational structure and its business activities, and work effectively.
This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency controls to manage key financial systems.
This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency controls to manage gifts and benefits.
Key conclusions and sector wide learnings
We found most agencies have implemented the Public Service Commission's minimum standards for gifts and benefits. All agencies had a gifts and benefits policy and 90 per cent of agencies maintained a gifts and benefits register and provided some form of training to employees on the treatment of gifts and benefits.
Based on our analysis of agency registers, we found some areas where opportunities existed to make processes more effective. In some cases, gaps in recorded information meant the basis for decisions around gifts and benefits was not always clear, making it difficult to determine whether decisions in those instances were appropriate and compliant with policy. Fifty-one per cent of the gifts and benefits registers reviewed contained declarations where not all fields of information had been completed. Seventy-seven per cent of agencies that maintained a gifts and benefits register did not include all key fields suggested by the minimum standards.
Areas where agencies can improve their management of gifts and benefits include:
- ensuring agency policies comprehensively cover the elements necessary to make it effective in an operational environment, such as identifying risks specific to the agency and actions that will be taken in the event of a policy breach
- establishing and publishing a statement of business ethics on the agency's website to clearly communicate expected behaviours to clients, customers,suppliers and contractors
- updating gifts and benefits registers to include all key fields suggested by the minimum standards, as well as performing regular reviews of the register to ensure completeness
- providing on-going training, awareness activities and support to employees, not just at induction
- regularly reporting gifts and benefits to executive management and/or a governance committee such as the audit and risk committee, focussing on trends in the number and types of gifts and benefits offered to and accepted by agency staff
- publishing their gifts and benefits registers on their websites to demonstrate a commitment to a transparently ethical environment.
This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency internal audit functions.
Key conclusions and sector wide learnings
We found agencies have established and maintained internal audit functions to provide assurance on the effectiveness of agency controls and governance systems as required by TPP15-03 'Internal Audit and Risk Management Policy for the NSW Public Sector'. However, we identified areas where agencies' internal audit functions could improve their processes to add greater value, including:
- documenting and implementing safeguards to address conflicting roles performed by the Chief Audit Executive (CAE)
- ensuring the reporting lines for the CAE comply with the NSW Treasury policy, and the CAE reports neither functionally or administratively to the finance function or other significant recipients of internal audit services
- involving the CAE more extensively in executive forums as an observer
- documenting a Quality Assurance and Improvement Program for the internal audit function and performing both internal and external performance assessments to identify opportunities for continuous improvement
- reporting against key performance indicators or a balanced scorecard and producing an annual report on internal audit to bring to the attention of the audit and risk committee and senior management strategic issues, thematic trends and emerging risks that may require further attention or resources.
This chapter outlines our audit observations, conclusions and recommendations, arising from our review of agency controls to on-board, manage and off-board contingent labour.
Key conclusions and sector wide learnings
Agencies have implemented controls to manage contingent labour and most agencies have some level of reporting and oversight of contingent labour at an executive level. However, the increasing trend in spend on contingent labour warrants a renewed focus on agency monitoring and oversight of their use of contingent labour. Over the last five years spend on contingent labour has increased by 75 per cent, to $1.5 billion in 2018–19.
There are also some key gaps that limit the ability of agencies to effectively manage contingent labour. Key areas where agencies can improve their management of contingent labour include:
- preparing workforce plans to inform their resourcing strategy, and confirm prior to engaging contingent labour, that this solution aligns with the strategy and best meets business needs
- involving agency human resources units in decisions about engaging contingent labour
- regularly reporting on contingent labour use to agency executive teams, particularly in terms of trends in agency spend, tenure and compliance with policies and procedures
- strengthening on-boarding and off-boarding processes, including establishing checklists to on-board and off-board contingent labour, making provisions for knowledge transfer, and assessing, documenting and capturing performance information.
This chapter outlines our audit observations, conclusions and recommendations, arising from our review of governance and processes in relation to the management of sensitive data.
Key conclusions and sector wide learnings
Information technology risks are rapidly increasing. More interfaces between agencies and greater connectivity means the amounts of data agencies generate, access, store and share continue to increase. Some of this information is sensitive information, which is protected by the Privacy Act 1988.
It is important that agencies understand what sensitive data they hold, the risks associated with the inadvertent release of this information and how they are mitigating those risks. We found that agencies need to continue to identify and record their sensitive data, as well as expand the methods they use to identify sensitive data. This includes data held in unstructured repositories, such as network shared drives and by agency service providers.
Eighty-eight per cent of agencies have established policies to respond to potential data breaches when they are identified and 70 per cent of agencies maintain a register to record key information in relation to identified data breach incidents.
Key areas where agencies can improve their management of sensitive data include:
- identifying sensitive data, based on a comprehensive and structured process and maintaining an inventory of the data
- assessing the criticality and sensitivity of the data so that the protection of high risk data can be prioritised
- developing comprehensive data breach management policies to ensure data breaches are appropriately managed
- maintaining a data breach incident register to record key information in relation to identified data breaches incidents, including the estimated cost of the breach
- providing on-going training and awareness activities to employees in relation to sensitive data and managing data breaches.
Appendix one – List of 2019 recommendations
Appendix two – Status of 2018 recommendations
Appendix three – In-scope agencies
© Copyright reserved by the Audit Office of New South Wales. All rights reserved. No part of this publication may be reproduced without prior consent of the Audit Office of New South Wales. The Audit Office does not accept responsibility for loss or damage suffered by any person acting on or refraining from action as a result of any of this material.
Actions for Agency compliance with NSW Government travel policies
Agency compliance with NSW Government travel policies
Overall, agencies materially complied with NSW Government travel policies.
However, the Auditor-General found some agencies:
- did not always book official travel through the approved supplier
- had weaknesses in their travel approval processes
- had travel policies that were inconsistent with the NSW Government policy
- did not adequately manage their travel records.
We asked the 15 participating agencies to complete a self assessment of the processes they have implemented to comply with the new policy. The key observations are summarised below.
Actions for Office of Strategic Lands
Office of Strategic Lands
The Office of Strategic Lands effectively fulfils most aspects of its defined role, however, it could do more to support strategic land planning by identifying and acquiring land for future public use proactively rather than waiting for agencies or landholders to approach it. It may also have greater impact if it expanded its activities beyond greater Sydney.
The Office of Strategic Lands (OSL) was established under the Environmental Planning and Assessment Act 1979 (EP&A Act) to identify, acquire, manage and divest land required for long-term planning by the NSW Government, particularly for open space and public purposes.
OSL is a Corporation Sole acting on behalf of the Minister for Planning and is run within the Department of Planning and Environment (DPE). OSL is a self-funding entity, and is responsible for administering the Sydney Region Development Fund (SRDF), a statutory fund used for ongoing land acquisition and management. OSL currently only operates within greater Sydney and holds over a billion dollars in land assets in this region.
This audit assessed whether OSL effectively fulfils its role to identify, acquire, manage and dispose of land, and whether OSL ensures it is sustainable over the long-term to meet its objectives.
Conclusion:
OSL effectively fulfils most aspects of its defined role, but is not supporting strategic land planning through proactive identification and acquisition of land for future public use. OSL is diligent in its financial management over the short and medium terms. However, it has identified that relying on the sale of surplus land to continue funding its ongoing operations is not sustainable, and it is yet to finalise a strategy to address this.
OSL does not currently have a strategic or proactive focus to improve land planning outcomes. This is primarily due to the lack of a clear strategy and business plan to direct its work which defines OSL’s purpose, objectives, goals and performance targets.
OSL expects to finalise and implement a Strategic Business Plan to guide its future direction and long-term sustainability, in late 2017.
OSL has three primary sources of funding. The largest source is Treasury loans which it needs to repay. The next most significant source of funding is from sales of land no longer required for government’s long-term needs. OSL has identified that it is likely to run out of surplus land within ten years. This is a significant financial risk for OSL, which should be addressed through a long-term financial strategy.
Contributions by Sydney councils into the SRDF are OSL’s only regular and consistent income stream. The formula to calculate these contributions has not been reviewed for over 25 years, and recent council mergers and border changes have increased the need to review the formula.
OSL is not used as extensively as it could be by other NSW Government agencies. It has the potential to play a much bigger role in assisting NSW Government agencies with longer term planning by partnering with them to identify, acquire, hold and manage land for future needs. For example, it could acquire land in future residential growth areas for needed public services such as schools, hospitals and transport corridors. There is also potential for OSL to expand its operations beyond the greater Sydney region into other parts of NSW to provide a statewide benefit from its unique role in government.
OSL has a unique role amongst government agencies, and could be used across NSW
NSW Government agencies we spoke with consider OSL fulfils an important role for the state that no other government agency performs. As a self-funding long-term land holder and manager, OSL can acquire and manage land beyond the four-year budget cycle that other government agencies face. Consideration should be given to expanding to other growth areas in NSW, where its unique role could assist in longer term land planning.
OSL has established good processes and procedures for most aspects of its role. This includes governance processes that we found to have been applied effectively. There was also adequate oversight and approvals for land transactions.
OSL has yet to finalise a business strategy to ensure long-term sustainability
OSL has shown that it is financially and operationally viable in the short to medium term. However, it does not have an overarching business strategy to guide its operations and ensure it is financially sustainable for the long-term. With a unique role in government, it is important for OSL to clarify its direction and implement a strategic business plan to drive its progress.
While there is no overarching long-term strategy, OSL has documented operating plans which guide its land acquisition and land divestment activities over the short to medium term. It has not developed a plan for its ongoing land management activities.
OSL advised that its Strategic Business Plan will be finalised and implemented in late 2017. This Plan should clarify OSL’s long-term direction, and guide its business to ensure it is financially sustainable.
OSL does not have adequate performance targets and measures
OSL has four key deliverables as part of DPE’s business plan. These deliverables cover land management, working with other agencies, and ensuring the SRDF is sustainable. There was no evidence that OSL or DPE monitor whether OSL achieves all key deliverables.
Currently, OSL’s performance targets are limited to meeting dollar values. OSL does not have any measures to demonstrate the achievement of outcomes that align with its core business, such as its success in land management or in working with other agencies. OSL staff also said that dollar targets were not always adequate or appropriate to measure its business performance.
With the development of its Strategic Business Plan, OSL has the opportunity to clarify its future business direction. This includes ensuring it has a range of relevant goals and performance measures that will support it becoming a strategic land planning partner with NSW Government agencies and local councils, and a land holder for the long-term.
OSL’s current financial management approach may impact long-term sustainability
OSL has valued the land that it needs to purchase on behalf of government to meet long-term strategic land needs in the Greater Sydney region, at $1.2 billion. However, OSLs annual budget for purchasing land is only between $40 million and $50 million until 2021. Also, in each of the last four years, OSL has not spent more than $30 million on land purchases because it relies on landowners to initiate contact when they are ready to sell their land.
Without a more proactive approach, it is not possible for OSL to make needed purchases in a timely manner. OSL acknowledges the substantial gap between these values, but has not established a budget or plan for how it will purchase all the identified land.
OSL has developed a Divestment Strategy which provides a five-year schedule of planned divestments. This is land OSL owns which has been identified as no longer required for government purposes. OSL has established an approach to generate the best and highest price for these sales. While funds are generated through the sale of surplus land, it also means that OSL holds fewer land assets to sell. OSL has identified it will run out of surplus land within ten years.
OSL needs to finalise and implement a business model to ensure it is financially and operationally capable to sustain and grow its business for the long-term.
OSL is working to improve transparency and engagement with key stakeholders
To deliver on its role, OSL needs to be able to effectively engage and work with its stakeholders, including NSW Government agencies, local councils, and people selling or buying land.
NSW Government agencies we spoke with are generally satisfied with OSL’s level of engagement and consultation. However, it would be beneficial for all parties to clarify and document their expectations of each other through a formal arrangement. OSL could also be more proactive in promoting its services, and working with additional NSW Government agencies to identify strategic lands.
The local councils in the Sydney region we spoke with are not as satisfied with OSL’s engagement and communication. The councils advised that they do not consider they are well-informed of OSL’s plans for their area, or how their contributions to the SRDF are spent.
More broadly, the activities of OSL are not reported transparently to stakeholders or the general public. OSL is developing a communication package for local councils and the community. This is an opportunity for OSL to improve the transparency of its role, operations, projects, and the SRDF, as well as promote its services and achievements.
The Office of Strategic Lands (OSL) was established in 1951 to identify, acquire, manage and divest land required for the NSW Government's long term planning purposes. OSL acts on behalf of the Minister for Planning, as a Corporation Sole, under the Environmental Planning and Assessment Act 1979 (EP&A Act).
OSL acquires and manages land identified for long-term strategic needs, and then transfers or sells it to other government agencies for ultimate use. It also sells land identified as surplus to government’s long term strategic requirements. Surplus land can also be transferred to local councils. OSL operates only in the greater Sydney region (from Wyong in the north, to the base of the Blue Mountains in the west, and south to Wollondilly). OSL has 20 staff who manage over 6,000 parcels of land.
Parliamentary reference - Report number #290 - released 10 August 2017
Actions for 2016 - An overview
2016 - An overview
This report focuses on key observations and findings from 2016 audits and highlights key areas of focus for financial and performance audits in 2017.
Financial reporting | |
Observation | Conclusion |
Only one qualified audit opinion was issued on the 2015–16 financial statements of NSW public sector agencies, compared to two in 2014–15. | The quality of financial reporting continued to improve across the NSW public sector. |
More 2015–16 financial statements and audit opinions were signed within three months of the year end. | Timely financial reporting was facilitated by more agencies resolving significant accounting issues early, completing asset valuations on time and compiling sufficient evidence to support financial statement balances. |
NSW Treasury’s early close procedures in 2015–16 were again successful in improving the quality and timeliness of financial reporting, largely facilitated by the early resolution of accounting issues. For 2016–17, NSW Treasury has narrowed the scope of mandatory early close procedures. |
The narrowed scope of mandatory early close procedures may diminish the good performance in ensuring the quality and timeliness of financial reporting achieved in recent years. To mitigate this risk, NSW Treasury has mandated that agencies perform non-financial asset valuations and prepare proforma financial statements in their early close procedures. It also encourages them to continue with the good practices embedded in recent years. |
Although most agencies complied with NSW Treasury’s early close asset revaluation procedures we identified areas where they can improve. | Asset revaluations need to commence early enough to ensure all assets are identified and the results are analysed, recorded and reflected accurately in the early close financial statements. |
Number of misstatements | |||||
Year ended 30 June | 2015-16 | 2014-15 | 2013-14 | 2012-13 | 2011-12 |
Total reported misstatements | 298 | 396 | 459 | 661 | 1,077 |
All material misstatements identified by agencies and audit teams were corrected before the financial statements and audit opinions were signed. A material misstatement relates to an incorrect amount, classification, presentation or disclosure in the financial statements that could reasonably be expected to influence the economic decisions of users.
Significant matters reported to the portfolio Minister, Treasurer and Agency Head
In 2015–16, we reported the following significant matters to the portfolio Minister, Treasurer and agency head in our Statutory Audit Reports:
Appropriate financial controls help ensure the efficient and effective use of resources and the implementation and administration of agency policies. They are essential for quality and timely decision making.
In 2015–16, our audit teams made the following key observations on the financial controls of NSW public sector agencies.
Financial controls | |
Observation | Conclusion |
More needs to be done to implement audit recommendations on a timely basis. We found 212 internal control issues identified in previous audits had not been adequately addressed by 30 June 2016. |
Delays in implementing audit recommendations can impact the quality of financial information and the effectiveness of decision making. Agencies need to ensure they have action plans, timeframes and assigned responsibilities to address recommendations in a timely manner. |
Agencies continue to face challenges managing information security. Most information technology issues we identified related to poor IT user administration in areas like password controls and inappropriate access. | Agencies should review the design and effectiveness of information security controls to ensure data is adequately protected. |
We found shared service provider agreements did not always adequately address information security requirements. |
Where agencies use shared service providers they should consider whether the service level arrangements adequately address information security. |
Thirteen of 108 agencies required to attest to having a minimum set of information security controls did not do so in their 2015 annual reports. | The 'NSW Government Digital Information Security Policy' recognises the growing need for effective information security. With cyber security threats continuing to increase as digital services expand we plan to look at cyber security as part of our 2017–18 performance audit program. |
We identified instances where service level agreements with shared service providers were outdated, signed too late or did not exist. | Corporate and shared service arrangements are more effective when service level arrangements are negotiated and signed in time, clearly detail rights and responsibilities and include meaningful KPIs, fee arrangements and dispute resolution processes. |
Internal controls at GovConnect, the private sector provider of transactional and information technology services to many NSW public sector agencies were ineffective in 2015–16. We found mitigating actions taken to manage transition risks from ServiceFirst to GovConnect were ineffective in ensuring effective control over client transactions and data. | The Department of Finance, Services and Innovation should ensure GovConnect addresses the control deficiencies. It should also examine the breakdowns in the transition of the shared service arrangements and apply the learnings to other services being transitioned to the private sector. |
Maintenance backlogs exist in several NSW public sector agencies, including Roads and Maritime Services, Sydney Trains, NSW Health, the Department of Education and the Department of Justice. | To address backlog maintenance it is important for agencies to have asset lifecycle planning strategies that ensure newly built and existing assets are funded and maintained to a desired service level. |
Actions for Assessing major development applications
Assessing major development applications
The Planning Assessment Commission (the Commission) has improved its decision-making processes for major development applications in recent years. The Commission has improved how it consults the public and manages conflicts of interest, and now also publishes records of its meetings with applicants and stakeholders.
The Planning Assessment Commission (the Commission) is an independent body established in 2008 under the Environmental Planning and Assessment Act 1979 (the EP&A Act). It makes decisions on major development applications in New South Wales. Along with the Department of Planning and Environment (the Department) and the Land and Environment Court, it is one of three bodies that have a role in making decisions on these applications.
The Department refers development applications to the Commission where 25 or more objections have been received from the community, a local council objects to the proposal, or the applicant has donated to a political party.
These applications are often complex and controversial, and can attract a high level of public interest. This may mean that, regardless of the process, not all stakeholders are satisfied with the outcome.
The Commission is required to take into account section 79C of the EP&A Act when making decisions. Section 79C includes consideration of the likely environmental, social and economic impacts of the development.
This audit assessed the extent to which the Commission’s decisions on major development applications are made in a consistent and transparent manner. To assist us in making this assessment, we asked whether the Commission:
- has sound processes in place to help it make decisions on major development applications that are informed and made in a consistent manner
- ensures its decisions are free from bias and transparent to stakeholders and the public.
Conclusion
Over the last two years, the Commission has improved its decision-making process. It has improved how it consults the public and manages conflicts of interest, and now also publishes records of its meetings with applicants and stakeholders.
However, there are still some vital issues to be addressed to ensure it makes decisions in a consistent and transparent manner. Most importantly, the Commission was not able to show in every decision we reviewed how it met its statutory obligation to consider the matters in section 79C of the EP&A Act.
Despite improved probity measures put in place by the Commission, there is a perception among some stakeholders that it is not independent of the Department. The reasons for some of these concerns are outside of the Commission’s control. For example, the Commission becomes involved after the Department has prepared an assessment report which recommends whether a development should proceed. This creates the perception that the Commission is acting on the recommendation of the Department. The Department’s assessment report should state whether an application meets relevant legislative and policy requirements, but not recommend whether a development should be approved or not.
More can also be done to improve transparency in decision-making and the public’s perception of the independence of Commissioners. The Commission should continue to improve how it communicates the reasons for its decisions and also publish on its website a summary of Commissioners’ conflict of interest declarations for each development application.
Decision-making processes have improved but some key aspects need to be addressed
Although not articulated in one document, there is a framework in place to assist Commissioners make decisions on major development applications. This includes setting out the information to be considered, who to consult, and that a report is to be prepared. The Commission has recently improved how it conducts public meetings and the level of support provided to Commissioners to ensure they understand the decision-making process. The Commissioners we interviewed all showed a good understanding of their role.
As a consent authority, the Commission is required to consider the matters in section 79C of the EP&A Act when making a decision. However, it was not able to show how it met this requirement in every decision we reviewed. We found some evidence of these considerations in six of the nine cases we reviewed, for example in meeting notes or in its report on a decision. Of these six cases, the degree to which the Commission considered all matters under section 79C varied considerably. The larger, more complex applications were more likely to address these considerations. To demonstrate compliance with the EP&A Act, the Commission must be able to show how it considers all matters in section 79C for each decision it makes.
We found that the Commission has access to relevant information to make a decision and consults stakeholders for their views of the development. The level of consultation depends on the size and complexity of an application. If Commissioners decide they need more information to make a decision, they consult local councils, the community, other government agencies and experts as needed.
The Commission’s public meetings are a valuable part of the decision-making process, where new perspectives or issues are often raised. However, some aspects could be improved. For example, many stakeholders thought the five minutes allowed for individual speakers was insufficient. The Commission could be more flexible with this timeframe. Identifying new ways to notify the public of its meetings, other than advertisements on its website and in newspapers, would also ensure it reaches as many interested parties as possible.
Improved transparency and probity but the Commission is not seen by some as impartial
The Commission has sound processes in place to ensure that its decisions are impartial and transparent to the community. It has improved its probity measures over the last two years, following a review by the NSW Ombudsman in 2014. We found that the Commission:
- has probity policies and procedures which are available on its website
- has improved its record keeping of some processes, such as meetings with applicants and stakeholders
- publishes its decision and supporting documentation, such as meeting notes, on its website.
Conflicts of interest are a significant risk for the Commission because they could lead to corruption, abuse of public office, and affect the public’s view of its independence. The Commission manages this risk well. It has a policy in place to address potential, perceived or actual conflicts. Commissioners update their conflicts of interest records annually, and declare any conflicts when the Commission assigns them to a development application. Unlike the Commission’s probity polices, Commissioners’ conflict of interest declarations are not available on its website. Providing a summary of this information on its website when Commissioners are allocated to a development application would further improve transparency around conflicts of interest.
The Commission has been improving how it communicates its decisions to the public. It now produces fact sheets for its decisions on matters that attract a high level of public interest. Its reports on decisions for complex applications also discuss issues raised by the community. However, the level of detail varied in the decisions we reviewed, and it was not always clear how conditions placed on a development would resolve identified issues. Similarly, the reports did not clearly address the matters under section 79C of the EP&A Act. Reporting this would further improve the transparency of its decisions, and clearly demonstrate compliance with the EP&A Act.
While we did not find any issues that would make us question the integrity or independence of Commissioners, there remains a perception among some stakeholders that the Commission is not impartial. Some of these concerns are within the Commission’s control to fix, such as allowing individual speakers at public meetings extra time to discuss their issues, therefore avoiding perceptions of bias.
Other perceptions, such as the Commission being part of the Department and not an independent decision making authority, are outside the Commission’s immediate control. For example, the Commission receives applications at the end of the assessment process, after the Department has prepared an assessment report recommending whether the application should be approved. This means there are effectively two reports on an application; the Department’s assessment report and the Commission’s report on its decision. However, there is only one decision-maker: the Commission. This may cause community confusion about the roles of the Department and the Commission in the decision-making process. Clearer separation of their roles in assessing applications and preparing reports is needed.
To minimise the perception that the Commission is simply ‘rubber stamping’ the Department’s recommendations, assessment reports should not recommend whether or not a project be approved. Instead, they should provide the Department’s views on whether a project meets relevant legislative and policy requirements. The Commission should also be involved earlier in the process, so it can establish key facts and identify relevant issues sooner. It should request that the Department’s assessment report covers matters Commissioners consider particularly important when assessing projects under section 79C. Earlier referral of applications should also help the Commission to plan its work in assessing applications, and may reduce the time taken to reach a decision.
Unless these issues are addressed, stakeholders will continue to believe the Commission does not act in a transparent and impartial manner, which could erode public confidence in the Commission.
The Planning Assessment Commission
The Planning Assessment Commission (the Commission) is a planning authority established in 2008 under the Environmental Planning and Assessment Act 1979 (the EP&A Act). One of its functions is to make decisions on major development applications.
The Commission is independent of the Department of Planning and Environment (the Department) and the Minister for Planning. This means its decisions are not subject to the direction or control of the Department or the Minister.
The Department refers applications for major development to the Commission, including state significant development and infrastructure applications. These projects are generally initiated by the private sector. Applications are referred to the Commission when one or more of the following criteria are met:
- more than 25 objections are received about the proposal
- the local council objects to the proposal
- the applicant has donated $1,000 or more to a political party or member of parliament.
These applications are often controversial and may attract a high level of public interest. Of the 29 development applications the Commission received in 2015–16, almost 40 per cent were in the mining and energy sectors, and another 40 per cent related to urban development.
Section 79C of the EP&A Act outlines the matters the Commission must consider when making decisions about major development applications. These include:
- any relevant environmental and planning instruments
- likely environmental, social and economic impacts of the development
- suitability of the site for the development
- submissions received about the application
- the public interest.
In addition to making decisions about major development applications, the Commission also reviews major developments as part of the planning process, and provides independent expert advice to the government on planning and development matters. Since the Commission’s inception, it has provided advice on 76 matters, conducted 39 reviews, and made 444 decisions on development applications.
Process for approving major development applications
The Commission is one of three bodies that have a role in the planning and approval process for major development applications in New South Wales, as seen in Exhibit 1. The other two bodies are the Department of Planning and Environment, and the Land and Environment Court.
The Department determines the outcomes of major development applications. When an application meets one of the criteria listed above, it refers these to the Commission to make the decision. In certain circumstances, the Land and Environment Court hears appeals against decisions made by either the Department or the Commission.
A Memorandum of Understanding between the Commission and the Department sets out timeframes the Commission must meet when making a decision, specifically:
- two weeks where no stakeholder meetings are required
- three weeks where stakeholder meetings are required
- six weeks when a public meeting is required.
Parliamentary reference - Report number #279 - released 19 January 2017