Browse our range of reports and publications including performance and financial statement audit reports, assurance review reports, information reports and annual reports.
The aim of Audit Lessons is to communicate lessons from our audit work and to make it easier for people working within the Australian public sector to apply those lessons.
This edition is targeted at security, information communications technology (ICT) and human resources officials responsible for managing ICT system access and the offboarding process for employees and contractors separating from an entity.
Please direct enquiries through our contact page.
The audit objective was to assess the effectiveness of the Department of Defence’s arrangements to manage the security authorisation of its ICT systems.
Please direct enquiries through our contact page.
The objective of this audit was to assess the extent to which entities’ establishment and use of ICT related procurement panels and arrangements supported the achievement of value for money outcomes.
Please direct enquiries through our contact page.
The objective of the audit was to assess the effectiveness of the Digital Transformation Agency’s procurement of ICT-related services.
Please direct enquiries through our contact page.
The Auditor-General responded on 1 July 2021 to correspondence from the Hon Brendan O'Connor MP and Mr Tim Watts MP dated 5 June 2021, requesting that the Auditor-General consider initiating a performance audit into the use of provisional ICT accreditation within Defence.
Please direct enquiries relating to requests through our contact page.
The ANAO could assess Services Australia’s strategic planning for ICT systems. Services Australia administers a range of systems supporting the delivery of government services including: whole of government systems such as myGov and Digital ID; systems supporting the delivery of programs such as welfare payment systems; and ICT supporting corporate shared services. Whole of government and welfare payment systems are considered critical national infrastructure. A key enterprise risk identifies the need for Services Australia to maintain ICT service continuity, while developing and maintaining systems that are fit for purpose, resilient and secure. The Services Australia’s capability review observed that a number of critical systems delivering payments and services are ageing. These systems impede the ability to integrate new technologies, are costly to maintain and are preventing Services Australia implementing efficiencies and innovations to delivering programs and services. Many of these ageing systems rely on staff with specialist programming skills. To address these challenges Services Australia established a cross entity advisory board to develop a 10-year ICT Architecture Strategy and Plan by June 2025. The audit could examine oversight, development and/or implementation of strategic plan for ICT systems.
Please direct enquiries through our contact page.
The objective of this audit is to assess whether the Australian Taxation Office (ATO) has effective arrangements to sustain its business-critical ICT systems.
Please direct enquiries through our contact page.
The audit objective was to assess selected agencies’ compliance with the four mandatory ICT security strategies and related controls in the Australian Government Information Security Manual.
David Gray, Executive Director - Phone (02) 6203 7377
Many Commonwealth entities continue to rely on long-lived, business-critical ICT systems that deliver essential services but can be increasingly costly and difficult to support. These systems often sit on older technology stacks, potentially include end-of-support components, and may carry heightened operational, security and continuity risks. The ANAO could examine whether selected entities appropriately identify, govern, secure and sustain or progressively modernise these established platforms.
Please direct enquiries through our contact page.
The objective of the audit was to assess the development of Defence’s oversight and management of its portfolio of ICT investments and projects. In particular, the audit examined Defence’s:
- governance, strategic processes and decision-making structures that set out, prioritise and coordinate the integrated ICT reform portfolio and programs;
- ICT risk management and capacity to identify and plan to achieve the benefits of its SRP ICT stream reforms (including methodologies to measure the realisation of savings and non-savings benefits);
- level of portfolio and program management maturity; and
- the impact of improvement efforts on Defence’s ability to deliver the ICT services capacity required to support the SRP.