Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Agencies' Governance and Controls Get Qualified Tick

The Australian National Audit Office (ANAO) has given General Government Sector (GGS) agencies a cautious tick, finding that over the last 12 months agencies have noticeably improved their management of business continuity risks and IT systems.

By Sue Bushell

The Australian National Audit Office (ANAO) has given General Government Sector (GGS) agencies a cautious tick, finding that over the last 12 months agencies have noticeably improved their management of business continuity risks and IT systems.

The ANAO also says the majority of agencies have adequately addressed the areas of IT governance, security, system delivery, and Financial Management Information System (FMIS) and Human Resources Management Information System (HRMIS) application systems in 2006-07.

However, The Auditor-General's Annual Report 2006-2007 notes the ANAO has identified a range of control-related issues requiring attention by agency management, after its annual audits of governance of financial management responsibilities and internal controls, including IT systems.

All agencies have established key elements of control environments which provide a sound basis for effective financial management, and audit committees continue to positively influence the effectiveness of agencies' control environment, particularly in the areas of risk assessment, legislative compliance and financial system controls.

They also all have fraud control plans in place, although a small number of agencies needed to improve aspects of their fraud control arrangements.

"Overall there has been noticeable improvement in the management of business continuity risks," the report says.

However the report finds there is room for improvement in the areas of appropriations management' revenue and receivables' cash management' purchases and payables' human resource management processes' and asset management, although controls over business and accounting processes have been generally effective.

The ANAO rates its financial statement audit findings according to a risk scale, with audit findings which pose a significant business or financial risk, or financial reporting risk, to the entity and which must be addressed as a matter of urgency rated as 'A' findings. Findings that pose a moderate business or financial risk, or financial reporting risk, are rated as 'B' findings.

"Most agencies had areas of their control environment that required attention, although our interim audits found that there had been an overall improvement in agencies' financial and related controls. This has resulted in a reduction in the number of 'A' and 'B' findings compared with 2005-06," the report says.

There were three agencies with 'A' category audit findings in both 2006-07 and 2005-06; while the total number of 'A' category issues (excluding the Defence and Defence Materiel Organisation) was two in 2006-07 compared to nine in 2005-06. Meanwhile the report indicates that over the course of the year the ANAO issued 242 audit opinions of which 87 percent were issued within two days of signing the financial statements, and made 192 recommendations in its performance audit reports directed at improving agency performance and accountability.

"These recommendations were well received overall, with 99 percent agreed or agreed with qualification," the report says.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: ANAO, Australian National Audit Office, National Audit Office

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Latest Blog Posts
Whitepapers
  • Migrating from NFSv3 to NFSv4
    In April 2003, the Network File System (NFS) version 4 Protocol was ratified as an Internet standard, described in RFC-35301, which superseded NFS Version 3 (NFSv3, specified in RFC-18132). Since the ratification of NFSv4, further advances have been made to the standard, notably NFSv4.1 (as described in RFC-56613, ratified in January 2010) that includes several new features such as parallel NFS (pNFS).
    Learn more »
  • Book 3 - The Practical Guide to Managing Risks
    Every organisation has a mission. Most, if not all, organisations use information technology (IT) to process their information in support of their missions and reaching their business goals. Managing risks associated with the information and supporting technologies is a critical factor in successful organisational mission realisation. Read on.
    Learn more »
  • Two May Be Better Than One: Why Hard Disk Drives and Flash Belong Together
    This white paper will explore the need for a caching and buffering technology between DRAM and HDDs and why Flash memory can be used to fill this need. We will go on to look at various ways that Flash and HDDs can be combined in a computer storage hierarchy. These technologies to combine Flash memory and HDDs include hybrid HDDs, Flash on the computer motherboard, and a combination of Flash and HDD storage devices in the same computer – paired storage systems.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.

HP and IDG news, product videos and resources