Browse our range of reports and publications including performance and financial statement audit reports, assurance review reports, information reports and annual reports.
Audit Matters 7 — September 2026
Please direct enquiries through our contact page or subscribe to receive the email version of Audit Matters in the future.
Welcome to the latest edition of Audit Matters — my first since being appointed Deputy Auditor-General in July.
Having spent more than 28 years working across public sector auditing, governance and organisational leadership, including leading both the ANAO’s financial statements and performance audit services groups, it is a privilege to take on this role. I look forward to continuing to work with entities across the Australian Government sector to support transparency, accountability and improved public sector performance.
I’d also like to acknowledge my predecessor, Rona Mellor, for her leadership and contribution to the ANAO and the wider public sector. I was fortunate to work closely with Rona and wish her all the best in retirement.
Audit Matters provides an important opportunity for us to share practical lessons from our work and highlight issues that may warrant attention across the sector. In this edition, we reflect on the 125th anniversary of the legislation that established the position of the Commonwealth Auditor-General, and share lessons from our latest reports and insights products, including the importance of integrity and ethical behaviour in auditing. We also outline developments in our strategic planning and look more closely at what makes performance information meaningful.
I hope you find this edition useful.
Carla Jago
Deputy Auditor-General
Celebrating 125 years of Commonwealth auditing
Last month, we marked 125 years since the Audit Act 1901 received Royal Assent on 7 August 1901, establishing the role of the Commonwealth Auditor-General. The Audit Act was the fourth Act passed by the new Commonwealth Parliament — reflecting that, from the earliest days of Federation, collecting and spending public money needed to be accompanied by independent scrutiny and a strong line of accountability to the Parliament.
A great deal has changed since 1901. Auditors are no longer required to check every transaction (and nor could we) or physically weigh gold and other precious metals held in government vaults. Yet some aspects of our history remain familiar, including the need to continually adapt audit practices and procedures as our context and environment evolves. We also continue to face the challenge of how we direct and target our finite audit resources across the breadth of Commonwealth activity.
Throughout those 125 years, the central principle of public audit has endured: the use of public resources and powers must be open to examination, and the Parliament and Australian community should be able to rely on independent, evidence-based audit to hold government to account.
That principle is as important now as it was in 1901. Government administration and service delivery are increasingly complex, supported by rapidly evolving technology and delivered through networks of entities, jurisdictions, contractors and other partners. At the same time, fiscal pressures and community expectations reinforce the need for government activity to be transparent, accountable and demonstrably effective.
Our strategic direction and work program
In July, we published our latest corporate plan, setting out how we intend to deliver against our purpose over the next four years. Our strategic priorities remain impact where it matters, performance through innovation, and inspire and develop our people. The new plan builds on these priorities with a clearer vision for the ANAO: to be the leading audit institution, known for integrity, impact and insight — driving public value and trust for Australians.
The plan establishes seven organisational programs that will help us pursue that vision. These cover how we engage for impact; design our business processes; plan and deliver our external products; use technology and data; build workforce capability; strengthen our financial sustainability; and reform our governance. While much of this work is internal to the ANAO, it will shape how we engage with entities and deliver audit and assurance work that is timely, relevant and responsive to emerging risks.
Our annual audit work program (AAWP) sits alongside the corporate plan and sets out our planned audit coverage. This year, we have introduced a multi-year approach, grouping potential topics into those that may commence during 2026–27 and those that may commence during 2027–29. This provides greater visibility of areas we may examine over the forward years while allowing the Auditor-General to respond to changing risks, parliamentary priorities and developments across government.
We have also adopted a more integrated and flexible approach to potential audit activity. Potential areas of audit activity are presented as potential topics, rather than as potential performance audit topics as we have previously done. Depending on the issue and level of assurance required, a topic may be examined through a performance audit or be addressed through other ANAO products. This might include being examined through existing financial statements audit or performance statements audit work.
Not every topic in the AAWP will proceed, new topics may be added, and the Auditor-General will continue to determine the most appropriate work based on risk, parliamentary priorities, materiality, auditability and available resources. I’d encourage you to read the Overview to our AAWP to find out more.
We also published our Quality Management Framework and Plan 2026–27, which sets out how we manage quality risks. Priorities under the framework and plan include supporting innovation and risk-based audit approaches while maintaining audit quality, the responsible adoption of emerging technologies where appropriate, implementing a sustainability assurance methodology and strengthening our workforce capability.
Our new Integrity Framework 2026–27 provides the overarching structure for our integrity control system and supports ethical decision-making and the management of integrity, fraud and misconduct risks. Importantly, the expectations it sets apply to both ANAO employees and personnel contracted to deliver work on the Auditor-General’s behalf. Recent issues concerning the misuse of confidential information within the audit sector have received significant parliamentary and media attention. They go to the heart of the trust that must underpin audit and assurance work. Auditors are entrusted with access to sensitive information, systems and decision-making processes. With that access comes a responsibility to handle information appropriately, exercise sound professional judgement and act in the public interest.
What meaningful performance information looks like
In our last edition of Audit Matters, we discussed the findings from the fifth year of our performance statements audit program. This time, we’ll look more closely at what good performance information looks like and how it can help entities understand what is working, what is not and where they need to improve.
The ANAO and the Department of Finance have established a joint working group to identify practical reforms to the Commonwealth Performance Framework and the performance statements audit program. The group will consider opportunities to reduce unnecessary regulatory and administrative burden and support a more risk-based and proportionate approach to performance reporting and audit.
Making the preparation and audit of performance statements as efficient as possible is important. However, the greatest contribution performance reporting can make to fiscal management and the delivery of outcomes comes from entities actively using it to manage their business. Performance information should be more than a year-end compliance exercise: it should provide relevant, credible and useful data that helps leaders understand whether public resources are producing the intended results.
Chapter 2 of Performance Statements of Major Australian Government Entities — Outcomes from the 2024–25 Audit Program identifies eight factors that indicate whether performance information is meaningful. Meaningful performance information:
- complies with the requirements of the PGPA Rule
- is complete and measures what matters most to users, rather than only what is easiest to measure
- relates directly or clearly links to the entity’s purposes or key activities, including both what the entity controls and where it contributes to results
- goes beyond tracking activities and outputs to capture outcomes and, where possible, contributions to longer-term impact
- presents a clear, accurate and balanced picture of the entity’s performance
- is useful for accountability, improvement and decision-making
- aligns with how the entity measures and assesses its performance internally
- meets the needs of key stakeholders, particularly the Parliament and the public.
Compliance with minimum requirements does not necessarily produce meaningful information. Our audits continue to find that entities can default to measures that are easy to quantify and audit, even where those measures do not adequately demonstrate the outcomes or impact of their activities.
The Auditor-General recently provided an update to audit committee chairs on what they should consider in their review of performance statements before finalisation. These were the three broad areas identified for focus:
- The performance story: Do the performance statements tell a clear, balanced, credible and complete story about what the entity achieved? What would a critical reader consider missing, weak or insufficiently explained?
- The evidence: Are the main messages consistent with what the audit committee has heard through internal performance reporting, risk reporting and executive updates during the year? Which results or disclosures are most likely to attract audit, parliamentary or public interest and scrutiny, and are they properly evidenced and explained?
- The assurance: If the Parliament asks why a target was missed or exceeded, do the performance statements provide a credible and convincing answer? Does the accountable authority have sufficient assurance to sign the statements confidently?
These questions are particularly timely as entities finalise their annual reports in the lead up to Senate estimates in October. For entities that report on a financial year basis, annual reports are required to be given to the responsible Minister by 15 October. Normally annual report should be tabled on or before 31 October so they’re available for the relevant estimates hearing, in support of effective parliamentary scrutiny. Senate estimates committees are increasingly asking questions about entity performance statements and the results of our audits, making it especially important that reported results are meaningful, well evidenced and capable of withstanding scrutiny.
Recently tabled reports
Effectiveness of the Commonwealth Home Support Program
Our audit of the Effectiveness of the Commonwealth Home Support Program examined one of the Australian Government’s largest grant programs. In 2024–25, the program provided $3.1 billion to 1,273 providers and delivered entry-level aged care services to more than 800,000 older Australians.
We concluded that the program was partly effective. While it delivers services to a large number of people and most clients surveyed were satisfied with their overall experience, weaknesses in its administration meant the Department of Health, Disability and Ageing lacked assurance that services were being delivered effectively, to eligible people, according to need and in a timely manner. Limited monitoring, assurance, evaluation and stakeholder engagement also reduced the department’s ability to identify and implement improvements. Poor assurance over the current program affected its preparedness for the planned transition into Support at Home.
We made nine recommendations addressing planning, monitoring, stakeholder engagement, assurance, performance measurement and evaluation. The broader lesson is that assurance over expenditure is not enough: program owners also need reliable information about who is receiving services, whether services meet community need, the quality and timeliness of delivery, and whether the program is achieving its objectives.
This audit was also the first time we’ve tabled a report at a glance alongside the full report. The shorter version uses plain language to explain what the audit examined, what we concluded and the key findings. It is part of our work to make our reporting more accessible while retaining the evidence and analysis contained in the full report.
Administration of the Freedom of Information Act 1982 by Selected Entities
The Administration of the Freedom of Information Act 1982 by Selected Entities was a cross-entity audit of the Department of the Prime Minister and Cabinet; the Department of the Treasury; and the Department of Infrastructure, Transport, Regional Development, Communications, Sports and the Arts. In light of preliminary audit findings and potential recommendations, the audit also engaged with the Office of the Australian Information Commissioner.
We concluded that the administration of freedom of information (FOI) requests by the audited entities was partly effective in giving the community access to government information. Some documents were provided to applicants for 43 per cent of the requests examined, and decision-making was not consistently transparent and accountable. The audit identified shortcomings that were inconsistent with the pro-disclosure objects of the FOI Act.
We made six recommendations to the audited entities which included:
- reviewing, updating and finalising complete FOI policies and procedures and ensuring they remain accurate and up to date;
- introducing monitoring and assurance frameworks to ensure searches for documents — and decisions that records cannot be found or do not exist — are consistently recorded;
- complying with the object of the FOI Act, including reviewing the extent and timeliness of information released under the act to assess whether organisational culture, policies and practices support the act’s pro-disclosure objectives;
- implementing monitoring and assurance frameworks to ensure FOI decisions are made in accordance with established policies and procedures;
- strengthening recordkeeping for decisions about exemptions and redactions, and promoting a pro-disclosure approach in decision-making supported by monitoring the frequency and use of exemptions and redactions; and
- developing and implementing assurance frameworks over data extracted from case management systems that gets reported to the Office of the Australian Information Commissioner.
We also made three recommendations to the Office of the Australian Information Commissioner. These recommendations addressed:
- examining the merits of a Commonwealth-wide FOI case management system to support the administration, monitoring and reporting of FOI requests across government;
- improving guidance by identifying better practices for good FOI decision-making, including ensuring all decisions and considerations of a decision maker are recorded and evidenced; and
- strengthening the FOI guidelines to address courtesy consultations and imminent release notification processes, including how entities are to manage independence risks to decision making that arise from those processes.
The FOI system is recognised as a critical pillar of open government and robust democracy in Australia. Australian Government information is a national resource that should be available for community access and use. Entities should administer their responsibility with sound systems, complete records, defensible decisions and a culture that supports lawful and timely access to information.
Australian National University financial management
Our report on Australian National University Financial Management was tabled in an environment of heightened scrutiny of the ANU, and had a focus on the Renew ANU cost-saving and restructuring initiative. This was what we call an ‘other report’ tabled under section 25 of the Auditor-General Act 1997, rather than a performance audit, but it applied the same procedures to collect and corroborate evidence and the same level of professional scepticism.
In August 2024, the ANU Council endorsed a target to reduce the university’s recurring annual cost base by $250 million by January 2026. We found that the target was approved without clear evidence that savings of this scale were needed, achievable, urgently required or likely to have the intended impact. The information provided to the Council did not adequately bring together the problem to be addressed, realistic options, implementation risks and dependencies, or the likely effects on the university’s purpose, financial sustainability and people.
Before approving a major financial or organisational change, a governing body should require a documented business case that brings together the evidence base, alternative options, meaningful consultation with those affected, implementation risks and clear oversight and reporting arrangements. Members of collective accountable authorities should also seek further information and assurance from management when targets are not being achieved or when the evidence supporting a proposal is incomplete.
The report’s three recommendations focused on applying these lessons to future major change proposals, improving the quality and completeness of financial advice to the Council, and establishing an approved methodology for non-audited financial measures.
Across all three of the above reports, a common message is the importance of evidence and assurance. Whether overseeing a major service-delivery program, administering access to government information or approving significant organisational change, decision-makers need reliable information and documented reasoning that allow them to understand, explain and defend their decisions.
Key financial controls of major entities
In June, we tabled our Interim Report on Key Financial Controls of Major Entities. The report presents findings from the interim phase of our 2025–26 financial statements audits, including our assessment of internal controls in 27 of the largest Australian Government entities. From those 27 interim audits, 13 entities had effective key internal controls, and the remaining 14 entities had generally effective controls — with the exception of specific findings discussed in the report.
IT control environments continue to be the most significant source of audit findings. At the end of the interim phase, there were 61 findings related to IT control environments — representing 71 per cent of all findings reported. IT security accounted for 64 per cent of the IT control environment findings, with recurring issues involving the provision and monitoring of user access. Other findings related to IT governance including making sure that entities have assurance over third-party service providers — there is a risk that entities do not identify or adequately address control deficiencies in third-party environments. While the number of IT control environment findings fell by 21 per cent compared with the 2024–25 interim phase, entities should continue to focus on effective security, governance and change-management controls. These are increasingly important as entities adopt emerging technologies, including artificial intelligence.
85 per cent of all findings reported at the 2025–26 interim phase (73 findings) had been identified in previous years. While the majority were raised the prior year, some date back to 2020–21. Identifying a control weakness is only the first step. Entities can strengthen their control environments by addressing findings in a timely manner, with remediation efforts prioritised according to the level of risk. Effective remediation requires clear ownership, realistic timeframes and active oversight. Where remediation is complex or extends over several years, entities should also ensure that interim controls are operating effectively and that delays and emerging risks are appropriately escalated.
Audit teams are busy working with entities to finalise 2025–26 audits – thank you to you and your teams for your engagement and efforts during this busy time. Outcomes of the audits and themes across the sector will be available in the 2025–26 end-of-year report.
Our latest Insights
In June we published two new Insights products designed to share practical lessons from our work and help entities engage effectively with ANAO audits.
Audit Lessons — Official Travel is aimed at officials who undertake, manage or oversee domestic and international travel arrangements. Official travel is a significant area of public expenditure and one in which sound administration supports value for money, manages integrity risks and builds public confidence in the proper use of public resources.
Drawing on five recent performance audits, the product highlights three lessons:
- Travel policies and procedures should reflect an entity’s particular operating context and risks.
- Approval processes should give delegates enough information to assess whether travel is necessary, represents value for money and complies with relevant requirements.
- Monitoring and reporting should provide meaningful assurance and support continuous improvement.
These lessons are relevant not only to those who manage travel systems and policies, but also to travellers and approving delegates.
Our new Audit Practice — Information-gathering, Confidentiality and Reporting explains our approach to obtaining information, protecting confidential material and reporting to the Parliament. It is intended for officials responsible for activities that may be the subject of an ANAO audit.
Robust, evidence-based auditing depends on timely and complete access to relevant information. Although the Auditor-General Act 1997 provides broad information-gathering and access powers, our preference is to obtain information through cooperation with audited entities without relying on those statutory powers unless necessary. Those powers are balanced by strict confidentiality obligations applying to ANAO personnel, audited entity personnel and others who receive audit material. As an integrity agency, we hold ourselves to a particularly high standard. Maintaining the trust of the Parliament and the entities we audit is critical not only to our ability to conduct our work, but also to its impact. Our reputation for independence, integrity and quality enables us to access the information we need, engage constructively with entities and provide assurance and insights that support better public administration and outcomes for Australians.
The product also provides practical guidance and answers to frequently asked questions about matters including access to Cabinet documents, legally privileged and commercially sensitive information, the handling of draft audit material, and the reporting of sensitive information. Early communication and a cooperative approach between the ANAO and audited entities should help resolve questions about information and access, support an efficient audit process and enable us to provide effective assurance to the Parliament.
Highlights from recent forums
We held our latest Audit Committee Chairs (ACC) Forum and Financial and Performance Reporting (FPR) Forum back in July. You can find out more about these regular events on the ANAO website. At the ACC Forum, the Auditor-General gave an update on key messages for audit committee chairs from recent performance audits, and their relevance for the entire sector.
The first key message is the importance of breaking down silos and taking an enterprise view. Significant risks, issues and lessons need to be communicated beyond the area in which they arise, and reach the right people in time to inform decisions and risk management.
Our recent audit of Defence’s Collins Class Submarines Life of Type Extension illustrates this point. Defence did not ensure that emerging risks to the Attack class submarine program, or the consideration of alternative submarine capabilities, were disclosed to the personnel who were making key decisions about the interdependent Collins class program. Following the cancellation of the Attack class program, Defence did not systematically reassess the Collins project’s delivery approach or advise government of the risks in a timely way.
This prompts a question for all entities: How is significant information communicated across the organisation, and how do you know that it is reaching the right people in time?
The second message is that risk management needs to be active and connected to day-to-day operations. It should not become a compliance exercise centred on traffic-light ratings and matrices. Entities need systematic monitoring that identifies emerging program and organisational risks early, escalates them to the appropriate level and supports timely action.
In the Collins class audit, project risks had been reported to program-level governance bodies but were not escalated in a timely manner, delaying informed, risk-based decision-making. This challenge is not confined to large programs. Significant risks may sit within smaller or more removed parts of an entity or portfolio, particularly where functions operate with a high degree of independence. Risk management can also lose focus as established programs mature.
Entities should therefore ask: Are our key risks being actively monitored and treated? Would an emerging or increasing risk be escalated to the right level soon enough to be handled effectively?
The third message is an enduring one: decisions need to be supported by evidence. Across our audits, we continue to find insufficient records of the rationale for decisions, including decisions about freedom of information requests, official travel, significant savings targets, cost-recovery arrangements and the allocation of risk in major contracts.
Recordkeeping should not be treated as something to tidy up after a decision has been made. Capturing the evidence and rationale at the time helps demonstrate that relevant frameworks and requirements were applied, enables decisions to withstand scrutiny, and brings greater discipline to the decision-making process itself. It also preserves institutional knowledge, allowing those who come later to understand why decisions were made, learn from what worked and avoid repeating past mistakes.
The question is simple: Is there sufficient evidence to explain and defend the decision? Good recordkeeping is fundamental to accountability and reflects the public service values of integrity and stewardship.
We wrapped up the ACC forum with an energising panel session featuring representatives from the Digital Transformation Agency, IP Australia and the Australian Taxation Office on the opportunities and risks presented by artificial intelligence.
A central theme was the need to balance innovation with responsible stewardship. AI offers opportunities to improve productivity, service delivery and public outcomes, but moving too quickly without appropriate governance can create significant risks and undermine public trust. There are also risks in moving too slowly, including missed opportunities to improve services and respond to growing public expectations.
AI should not be treated as a single technology or governed through a one-size-fits-all approach. A personal productivity tool presents different risks from an AI system embedded in a business process or supporting decisions that affect members of the public. Entities should be clear about the problem they are seeking to solve, the expected benefits and the risks of each use case.
Our recent audits reinforce these messages. The ATO’s arrangements to support its adoption of AI were partly effective, with stronger enterprise-wide accountability, visibility, risk assessment and monitoring needed. We subsequently found that IP Australia’s use of AI in the patent rights process was largely effective and its governance had matured over time, although strategic oversight of implementation and benefits was not yet fully established.
As AI moves from experimentation into business-as-usual operations, entities need clear decision points, defined ownership and controls across the full lifecycle. They also need to continue assessing whether AI is delivering its intended value and whether risks have changed. Having a human involved in a process is not, by itself, sufficient assurance: people can become overly reliant on systems they perceive to be accurate. It is also important to ensure that IT controls, especially those related to IT and data security, are in place and remain effective when utilising AI or other emerging technologies.
Ultimately, adopting AI is as much a leadership, workforce and business-design challenge as it is a technology challenge. Realising its benefits will require open engagement with employees, investment in capability and a clear understanding of the services and processes entities are seeking to improve. Whatever the technology, public sector organisations remain accountable for their decisions and for maintaining the transparency, evidence and public trust on which effective administration depends.
Engaging with the ANAO
We’re always happy to share our insights and lessons to help improve public administration and to educate entities about the ANAO’s audit processes. We are observing changes in senior staffing in the sector — it might be a good time to have us visit your entity and explain our work. If you would like senior ANAO staff to come and speak to your executive board, SES cohort or other groups of staff, please discuss this with your ANAO audit contact or reach out to our External Relations team.