Agencies' Governance and Controls Get Qualified Tick
- 11 October, 2007 15:53
- Comments
By Sue Bushell
The Australian National Audit Office (ANAO) has given General Government Sector (GGS) agencies a cautious tick, finding that over the last 12 months agencies have noticeably improved their management of business continuity risks and IT systems.
The ANAO also says the majority of agencies have adequately addressed the areas of IT governance, security, system delivery, and Financial Management Information System (FMIS) and Human Resources Management Information System (HRMIS) application systems in 2006-07.
However, The Auditor-General's Annual Report 2006-2007 notes the ANAO has identified a range of control-related issues requiring attention by agency management, after its annual audits of governance of financial management responsibilities and internal controls, including IT systems.
All agencies have established key elements of control environments which provide a sound basis for effective financial management, and audit committees continue to positively influence the effectiveness of agencies' control environment, particularly in the areas of risk assessment, legislative compliance and financial system controls.
They also all have fraud control plans in place, although a small number of agencies needed to improve aspects of their fraud control arrangements.
"Overall there has been noticeable improvement in the management of business continuity risks," the report says.
However the report finds there is room for improvement in the areas of appropriations management' revenue and receivables' cash management' purchases and payables' human resource management processes' and asset management, although controls over business and accounting processes have been generally effective.
The ANAO rates its financial statement audit findings according to a risk scale, with audit findings which pose a significant business or financial risk, or financial reporting risk, to the entity and which must be addressed as a matter of urgency rated as 'A' findings. Findings that pose a moderate business or financial risk, or financial reporting risk, are rated as 'B' findings.
"Most agencies had areas of their control environment that required attention, although our interim audits found that there had been an overall improvement in agencies' financial and related controls. This has resulted in a reduction in the number of 'A' and 'B' findings compared with 2005-06," the report says.
There were three agencies with 'A' category audit findings in both 2006-07 and 2005-06; while the total number of 'A' category issues (excluding the Defence and Defence Materiel Organisation) was two in 2006-07 compared to nine in 2005-06. Meanwhile the report indicates that over the course of the year the ANAO issued 242 audit opinions of which 87 percent were issued within two days of signing the financial statements, and made 192 recommendations in its performance audit reports directed at improving agency performance and accountability.
"These recommendations were well received overall, with 99 percent agreed or agreed with qualification," the report says.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Australia's first 4G smartphone is the HTC Velocity 4G
-
Swedish e-commerce startup's execs linked to NYC sex crime
-
Face Time - Interview with John Brennan and Robert DiStefano
-
How to implement next-generation storage infrastructure for Big Data
-
Pfizer's Future Depends on IT Transformation
-
The State of Privacy & Data Security Compliance
With the plethora of new privacy and data security regulations, we believe it is time to ask whether regulations help or hinder an organization’s ability not only to protect sensitive and confidential information assets, but to be competitive in the global marketplace. Further, how difficult is it to be in compliance, who is the typical person or functional leader accountable for compliance? What is the value to the organization? Finally, what differences (if any) exist in security practices between compliant and non-compliant organizations? -
Shedding Light on Backup and Availability Challenges in Virtual Environments
This IDG white paper explores specific backup and availability challenges organisations must surmount as they move to virtualise their business-critical applications. It then shows how attaining proper service levels for these applications requires a high degree of visibility into the VMware virtual environment. -
Case Study: Svenska Kraftnät safeguards web and ensures communication security with Clearswift
Energy producers from surrounding countries load power onto the Swedish National Grid’s network, with energy suppliers then paying the Swedish National Grid to load onto their grids for them to sell-on to customers. Using Clearswift’s Email Appliance, and MIMEsweeper for SMTP means that the organisation has safe and resilient email helping them to meet their goal of providing a safe, robust, cost-effective and environmentally sound energy transmission system.
-
Storage Security
-
Linux for Windows Administrators
-
The Garageband Book
-
Introduction to Programming and Object-oriented Design Using Java 2E Java 5.0 Version Wileyplus/WebCT Standalone Card
-
Final Cut Pro 3 for Dummies
-
Mac® OS X Bible, Jaguar Edition
-
Macromedia Flash 8 for Dummies
-
Learning Maya 5
-
Access 2003 All-In-One Desk Reference for Dummies®








Comments
Post new comment