Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Government recordkeeping failing

Audit office finds holes in government agencies

An audit of Australian government agencies has found standards around digital and physical recordkeeping lacking, with each agency audited failing to manage an electronic corporate recordkeeping system in accordance with established policy.

The Australian National Audit Office (ANAO) report "Recordkeeping including the Management of Electronic Records", released on October 12, audited the recordkeeping systems and processes in the Attorney-General's Department, the Australian Electoral Commission and the Department of the Prime Minister and Cabinet.

The report states none of the agencies had given adequate consideration to recordkeeping risks and the agencies should assess these risks in the context of a broader risk management framework.

"Another common issue identified was the need for entities to identify, in the context of business continuity planning, their vital records and to take steps designed to ensure these records are accessible and usable within specified timeframes in the event of a disaster," the report states.

"Each agency was found to use an electronic corporate recordkeeping system that in most cases did not recognize and manage these systems as part of the corporate recordkeeping framework and as a consequence the records held in the majority of the electronic systems reviewed as part of the audit were not being managed in accordance with the entity's recordkeeping policy.

"The ANAO considered that none of the entities had given adequate consideration to their recordkeeping risks ...Another common issue identified was the need for entities to identify, in the context of business continuity planning, their vital records and to take steps designed to ensure these records are accessible and usable within specified timeframes in the event of a disaster."

As a result of the audit the National Archives of Australia has been recommended to define minimum recordkeeping requirements agencies should comply with to meet both legal and business requirements, develop guidance as a reference for agencies when developing their own "entity-specific recordkeeping material" and coordinate and publish legislation, policies, standards and advice on agency recordkeeping responsibilities.

In response to the audit the Department of the Prime Minister and Cabinet agreed minimum standards developed by the National Archives of Australia will allow agencies to better focus on specific requirements and improve consistency of policy and practice across the Australian Public Service.

The Attorney-General's department stated the National Archives will have to use a managed and sustainable program to ensure agencies "are engaged in an effective and consultative manner", however recommended the National Archives "needs to adopt an approach that meets the practical recordkeeping needs of agencies, not high-level statements, if its advice is to be of value or use".

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: ANAO, Attorney-General, Australian Electoral Commission, Australian National Audit Office, National Audit Office

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Latest Blog Posts
Whitepapers
  • Why Hackers have Turned to Malicious JavaScript Attacks
    Website attacks have become a serious business proposition. In the past, hackers may have infected websites to gain notoriety or just to prove they could—but today, it’s all about the money. Reaching unsuspecting users through the web is easy and effective. Hackers now use sophisticated techniques—like injecting inline JavaScript—to spread malware through the web. Learn about the threat of malicious JavaScript attacks, and how they work. Understand how cybercriminals make money with these types of attacks and why IT managers should be vigilant.
    Learn more »
  • Securing Vital Infrastructure
    A unified approach to information security can help modern vital infrastructure providers deal with evolving IT threats without compromising on communications or the demands of an increasingly mobile workforce. Flexible policies, combined with quality inbound threat detection, deep content inspection and encryption capabilities can help organisations to mitigate the risks – not just from outside the organisation, but also within it. Read this whitepaper.
    Learn more »
  • Server and Storage Optimization Techniques
    By meeting the requirements to deploy new applications and support a larger number of internal and external customers, IT organizations are facing a space, power, and cooling crunch. Read on.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.