
A NSW Audit Office assessment of the internal controls and governance of 26 of the NSW Government’s largest agencies has found weaknesses in more than half.
The new report includes an overview of interim financial audits for 2025–26 – accounting for 91% of budgeted expenditure for 2025–26; analysis of the effectiveness of internal controls and governance in a selection of important areas of public administration; and key areas of improvement and practical lessons for agencies.
Each year, the Office selects different areas – aligned with the Auditor-General’s Audit Work Plan of internal controls and governance – to focus on. In 2025–26, it selected grants administration, consultants, purchasing cards and technology, including cyber security and artificial intelligence.
Releasing the latest report, the Office said more findings now relate to high-risk, high-spend areas such as procurement and grants – an increase from 33% to 42% of total findings.
The Audit Office report found that oversight of grant programs by agencies was generally weak.
“Most agencies have limited central oversight and monitoring of grants administration, including how they monitor delivery, reporting and financial management,” the Office said in a statement.
“Some agencies have deficiencies in frameworks for due diligence checks, acquittal controls, evaluations and reconciliations between program records and grant disbursements. This weakens the level of assurance over financial accountability of public funds and limits agencies’ ability to demonstrate that grants were used for their intended purpose.”
The Office also found that the majority of agencies were not effectively engaging and reporting on consultant use.
The NSW Procurement Board require agencies to disclose consulting engagements greater than $50,000 in their annual reports. The Auditor-General’s previous performance audit NSW Government agencies’ use of consultants found that agencies inconsistently applied the definition of consulting engagements.
The Audit Office analysis identified at least $18.3 million in expenditure was for consultancy engagements but was not reported as such by agencies in their 2024 and 2025 annual reports.
It also found some agencies did not comply with mandatory requirements when engaging consultants.
Forty-eight contracts were selected for analysis, and 27% were found to have no conflict-of-interest disclosures completed by the consultants. Further, 13% of contracts did not include enforceable confidentiality provisions, increasing the risks around the use of sensitive government data.
“Agencies did not demonstrate that they considered alternatives, including using internal capability, for 17% of engagements sampled. For 40% of contracts, agencies did not monitor or evaluate the performance of the consultant,” the Office stated.
“Consultants are often engaged in direct source procurements. This included some instances where agencies applied exemptions from their policy requirements or where consultants were directly approached without a procurement process. Taken together, these deficiencies heighten the risk of unnecessary costs and reduced value for money.”
The Office said high-risk purchasing card transactions by agencies also required more scrutiny.
For the 26 agencies examined, there were 5.7 million transactions on purchasing cards with a value of $2.3 billion for the period 1 July 2023 to 28 February 2026.
The analysis indicated that purchasing cards are typically used for low-value purchases (such as office supplies, food and travel) and rely on cardholders exercising judgement to ensure expenditure is appropriate.
Expenditure across all 26 agencies was analysed, and the internal controls and governance of six selected agencies were examined in more detail as part of interim audits.
Auditors found approximately $18 million in transactions were identified that may indicate purchasing card misuse or raise questions about their business purpose. These included purchases from vendors that retail in gift cards, entertainment, alcohol and tobacco products.
It also found purchase card oversight was weak, with one-in-five transactions not acquitted within the required 30 days.
“Almost 21% of acquittals and approvals (to a value of approximately $350 million) took place a month or more after the expenditure was incurred, exceeding NSW Treasury’s recommended timeframe. Around 7.4% took place after more than 60 days. Delays in acquittals reduce the assurance that agencies have over the appropriate use of public funds.”
“NSW Treasury policy indicates that purchasing cards should only be used for low-value, high- volume payments less than $10,000. There were approximately 9,350 transactions totalling $137 million that exceeded the $10,000 threshold. Purchases above this threshold increase the risk that expenditure bypasses or circumvents established procurement and payment controls. Analysis of some agencies’
policies indicate that card limits are not subject to regular review,” the Office stated.
The Audit also established that significant gaps remain in Cyber Security Policy requirement compliance, along with limited strategic use and assurance of artificial intelligence (AI).
The audit found 128 significant, high and extreme cyber security risks were reported by agencies in 2025.
“Less than half of agencies reported compliance with requirements to protect and govern their risk exposure. Some agencies did not assess risks from legacy systems that cannot be patched, increasing their exposure to cyber-attack.”
“Agencies have limited visibility over AI use as they did not consistently register all AI use cases or centrally track costs. Governance is not keeping pace with the speed at which agencies are adopting AI.”
Analysis of 2024–25 annual agency reporting by the 71 agencies that report to Cyber Security NSW shows most did not comply with the policy. Over half of agencies have also not implemented the ‘govern and identify’ and ‘protect’ mandatory requirements.
“Some agencies have remediation strategies in place to meet requirements, though some are at least four years from achieving compliance. Reported cyber risks remain elevated across the sector, with 33 agencies reporting 128 significant, high and extreme residual cyber security risks.”
It said gaps in reporting on the implementation of policy requirements continue to reduce the reliability of the data.
“Aggregated attestation reporting arrangements, where 71 reports cover 189 agencies, limits visibility of entity-specific issues. Agencies are not required to report compliance with policy requirements where services are delivered by third parties, increasing the risk that deficiencies in third party controls are not identified.”
Management of legacy systems was also found to be inconsistent.
Of the 10 agencies examined, the audit found three had not formally assessed the risks associated with each legacy system, and two had not implemented compensating controls to mitigate risks from legacy systems that can no longer be updated or patched.
Visibility of the use of AI and tracking of costs was described as ‘limited’.
While all 10 selected agencies have AI registers, only four capture AI use that is assessed under the NSW AI Assurance Framework, increasing the risk of unmanaged and unidentified AI use, said the Audit Office.
“Most agencies did not centrally track the costs of AI initiatives, limiting transparency and effective resource management. AI cost models tend to be more volatile than traditional software licensing costs.”
The Office said governance was not keeping pace with the speed at which agencies are adopting AI.
“AI is not consistently embedded as a strategic capability. Only half of the selected agencies have a formal AI strategy to guide adoption and maximise benefits. Agencies’ governance arrangements for AI are immature and inconsistent and half have not fully embedded AI-specific risks into their existing governance frameworks.”
“A focused approach to the strategic use of AI could maximise benefits so that AI use better aligns with agencies’ objectives.”
The Office identified instances where agencies had not completed NSW Government AI Assurance Framework assessments or cyber security risk assessments, particularly for projects established before the framework’s introduction.
“While retrospective application is not required, current guidance requires agencies to apply the framework across the solution lifecycle. Agencies need to assess existing AI solutions against the current guidance,” it said.
The report makes four recommendations, saying that by 30 June 2027, agencies should:
- Put in place policies, procedures and quality assurance processes to ensure that grants are administered consistently with the Grants Administration Guide, which includes:
a) a process for demonstrating at the planning and design stage how grant opportunities will
deliver value for money by identifying benefits and costs
b) developing a monitoring and evaluation framework for grant opportunities, including defined
performance measures and financial acquittal requirements
c) a framework to identify and manage risks for all grants
d) establishing centralised oversight and reporting arrangements to enable timely and effective
monitoring of all grants across the entire grant life cycle.
- Apply data analytics to identify and investigate high-risk, potentially inappropriate, and noncompliant transactions to strengthen monitoring and oversight of the use of purchasing cards.
- Formally assess the risks associated with legacy systems and implementing appropriate compensating controls to strengthen the governance of Artificial Intelligence.
- Assessing all required AI solutions against the NSW AI Assurance Framework and use that framework to assist in the lifecycle management of AI to strengthen the governance of Artificial Intelligence.
Read the full report here.

