NSW Audit Office grades schools information management

The NSW Audit Office has recommended the NSW Department of Education review its allocation of responsibilities to principals, improve guidance and supports for schools, and strengthen the controls for managing the access to and use of student information.

In its recent audit, the Office assessed how effectively the Department and NSW public schools protect the security and privacy of student information.

It found the Department had established a range of controls to manage the security and privacy of student information

“Over the last three years, the department has strengthened its controls by uplifting cyber security capability, centrally contracting key third-party IT vendors, developing specific policy frameworks, and providing professional learning and centralised supports for schools,” the Office stated in its report.

However, it also found the Department has allocated technical responsibilities to school principals without sufficient departmental oversight.

“The department does not clearly define the specific risks to student information that schools must manage, nor provide clear operational guidance or proactive support to monitor how legislative and policy requirements are met in practice at the school level. With principals relying on their own judgement and capacity, practices are inconsistent and in some cases non-compliant,” it stated.

The Office also found “gaps” in how schools apply the department’s staff access controls to systems, saying the department’s controls do not ensure that access to student information is limited to staff who need it for their role.

“Schools apply access controls inconsistently, and some staff access more information than they need or retain access after they leave a school. The department does not oversee or control staff access to third‑party school administration systems, which hold large amounts of student information.”

Some schools also use third-party digital products without departmental oversight, the audit found.

“The department’s marketplaces give schools a range of approved third-party digital products for school administration and online learning. It centrally manages contracts with third-party vendors, including terms to protect the security and privacy of student information. However, some schools use third-party products outside of these marketplaces and without departmental oversight or controls to protect student information.”

The Office also stated the Department failed to independently assure third-party digital products in its marketplaces, saying “while third-party vendors of digital products in department’s marketplaces are subject to contractual security and privacy controls, the department does not routinely verify vendor compliance.”

The Department also only recently identified key third-party systems as ‘crown jewels’.

“The department did not classify Compass, SchoolBytes and Sentral – the third-party systems used by more than 98% of schools to manage student information – as ‘crown jewels’ until early 2026,” the Office said.

The department is now implementing the higher levels of oversight, assurance and protective controls that apply to crown jewels, it said.

Read the full 55-page report here.

Latest Articles