Browse our range of reports and publications including performance and financial statement audit reports, assurance review reports, information reports and annual reports.
- When procuring a major ICT system that will contain sensitive information, undertaking a thorough risk assessment prior to putting the system into production provides greater assurance that information will be appropriately protected.
- Store system recovery tools used to restore ICT services across multiple systems.
The audit objective was to re-assess the three entities' compliance with the 'Top Four' mandatory strategies in the Australian Government Information Security Manual (ISM). The audit also aims to examine the typical challenges faced by entities to achieve and maintain their desired ICT security posture.
Please direct enquiries relating to reports through our contact page.
- Define service commitments for online services, including the availability of ICT systems, and specify equivalent maximum acceptable system outage tolerances in ICT service contracts.
- Planning for a major ICT investment that will realise specific savings or business benefits requires early identification and management of system operating risks and timely transition planning, to deliver ICT redevelopment within the planned schedule and scope.
- With the increasing reliance on contracted ICT service providers to deliver services, entities should review their ICT governance arrangements to:
- monitor the performance of systems, ideally with active monitoring systems;
- assess the delivery of contracted services using reliable data;
- establish ICT procurement guidelines to accommodate a changing digital environment, including the transition towards new technology and service providers; and
- ensure that the entity, as the service integrator, provides effective oversight and control of the outsourced environment.
- ICT improvement programs should establish measurable outcomes and end-states prior to implementation to support effective oversight and accountability.
Government entities continue to commission and deploy major ICT systems to improve service delivery, financial management, regulatory capability, or operational efficiency. Effective design, implementation, and management of residual risks and issues is important in ensuring investment in new systems is effective and achieves outcomes. The ANAO could examine whether selected entities have effectively planned and implemented new ICT systems, including ensuring risks are identified and managed, data governance arrangements are adequate, and appropriate assurance is obtained regarding the effective operation of the system prior to commissioning.
Please direct enquiries through our contact page.
The ANAO could assess the Department of Health, Disability and Ageing’s design, procurement or operationalisation of digital systems to support implementation of the Aged Care Act 2024 (the Act). The 2024–25 Federal Budget included $1.2 billion over five years from 2023–24 for the digital systems required to support the introduction of the Act. In March 2025, the Digital Transformation Agency (DTA) gave three aged care ICT projects delivery confidence assessments of low to medium, and identified two projects had been escalated to resolve delivery challenges. In March 2026, the DTA gave two tier one aged care ICT projects with a combined budget of over $900 million, delivery confidence assessments of medium-high.
Please direct enquiries through our contact page.
- Controls over ICT systems provide assurance that digital tools are being used as intended. Reviews of these controls should occur regularly to ensure that controls continue to address risks.