Report of the Parliamentary Standing Committee of Public Accounts (No. 9 of 2026) – Follow-Up of Report of the Auditor-General ICT Strategy, Critical Systems and Investment (No. 4 of 2-220-21) – Consideration and Noting
Legislative Council, Tuesday 1 September 2026
Ms FORREST (Murchison) – I move:
To consider and note the report from the Public Accounts Committee, which is a follow up with the Auditor General’s Report No. 4 of 2020-2021, ICT Strategy, Critical Systems and Investment.
Mr President, this is one of the pieces of work that the Public Accounts Committee does off the side of our desks almost with all the other things we’re doing, but it’s really important work. By way of information for members that every year we meet with the Auditor‑General, and we discuss what reports should be followed up. Some of them clearly require follow-up, some of them perhaps not so much. Some of them are better followed up by the Auditor‑General who has some data analytics capability. Some of them require more qualitative rather than quantitative, perhaps follow up. Have the relevant departments or entities adopted the recommendations of the Auditor General. If they have, show us evidence of how they’ve done that. We always want to see some evidence not just saying yes, we’ve done it. Also, if they haven’t done it, like why they haven’t done it and sometimes there are some good reasons why a particular recommendation may not have been followed according to the Auditor‑General’s recommendation, but it’s been delivered through a different mechanism and that was a bit the case in this in this report.
It is the case that the Public Accounts Committee try to review and follow up three of the Auditor‑General’s reports each year. The reports from the Auditor‑General do date back a little bit, as this one does, but sometimes you need time for the work to be done in the department to actually enable them to show evidence of adoption of the recommendations.
This report follows the follow up review, the committee undertook to establish what has actually happened five years on to the recommendations by the Auditor‑General and in this review or examination that he undertook of the government’s approach to ICT strategy, critical systems and investment. I thank the Auditor‑General and his office for their work. Some may see performance auditing as a bit of a tedious job to do, but it’s really critically important work to do because it’s only when some of these things are really looked at specifically and sometimes perhaps a little bit narrowly, that you can see where some of the problems may occur. We know in the past, many years ago, when the Auditor‑General has looked at ICT related matters, they have found significant gaps. There was one report a number of years ago where the Auditor‑General delayed the release of that report to give our government departments time to actually fix some of the gaping holes in their cybersecurity. Now, that was a decision taken by the Auditor‑General because he was very aware of the risk of putting out a report that showed where all the problems might be. Any hacker having a look could see, there’s an easy doorway to go straight through, for example. But this was not the case here so much, this is more about the strategy. There were also critical systems and investment in that, which is obviously critical to ensure, as best as we can, we have a secure and safe IT system.
The original audit by the Auditor‑General was a significant one, in this case as well. It found real gaps in the whole of government ICT governance, in asset management and in investment prioritisation. The Auditor‑General made seven recommendations directed at the Department of Premier and Cabinet, the Digital Services Board and agencies across government.
The committee wrote to the responsible minister in May last year after we resolved to undertake this review, seeking a written account of the implementation of these recommendations and received a detailed submission from DPAC in July. We then tested that submission in a public hearing on 5 February this year with the Minister for Innovation, Science and the Digital Economy, the Chief Information Officer, Dr Justin Thurley, who’s in the Chamber, and the Deputy Secretary, Ms Noelene Kelly.
The committee made 16 findings and four recommendations related to the responses to the recommendations of the Auditor‑General. I want to be fair to to the government about what has genuinely improved, because there has been genuine improvement. Government ICT investment has more than tripled since 2020‑21 from $26.5 million to $93.8 million in the previous budget, or from roughly 2.5 per cent to 11 per cent of the relevant investment based on the minister’s own figures given in evidence.
We were informed in the committee that the digital services board has been replaced by the data and digital subcommittees of the Secretary’s Board, meets monthly, reports up through the Secretary’s Board, and runs an annual work plan across 5 active work streams. Each agency now maintains a critical ICT asset register, a whole of government digital strategy, Our Digital Future and its accompanying strategic action plan exist and are reviewed.
None of that is a small task in itself, and this is clearly outlined in the executive summary of the report, and throughout the report. Obviously, the executive summary references the evidence in the report.
But I do note that we should not mistake this activity and outcomes for the things the Auditor‑General actually asked for. The Auditor‑General’s recommendation (1) asked for a whole of government ICT vision informed by an understanding of each agency’s key assets, their age profile, their risks, their interdependencies and a replacement timetable to be delivered within 18 months of the original report.
That would have meant completion by around April 2022. The committee reported in March 2026, nearly four years past that mark, and the committee’s finding (1) records, there is still work to do to get there.
As started in the executive summary the committee also found that consolidation of asset information of whole of government level remains incomplete. The comprehensive view of critical ICT assets encompassing age profile, interdependencies, risk exposure and replacement timelines across all agencies had not yet been achieved. There may be up to date information the Leader may provide on some of this, because it is a little while ago since this report was tabled. Work to establish a whole of government critical systems register had only just been initiated, so it’d be interesting to hear from the Leader whether that’s actually been completed.
I make some of these points because we’re seeing such large investments now in digital transformation projects where we’re seeing some pretty odd behaviour. The Bluegum Transformation Project, which we’ve talked about. The member for Elwick put more questions on the notice paper again today with regard to this.
The Human Resources Transformation Project that was formerly the Human Information Resource Information System that was subject to an audit review by the Auditor‑General as well. It showed problems. We’ve seen many IT systems rolled out across various government departments and GBEs that haven’t worked as intended and cost millions and millions of dollars. W do need to get this right.
Shiny glossy brochures with nice pictures don’t do it. I’m not suggesting that’s all that’s been done, but that’s what we tend to see.
Additionally, the outcomes of the whole of state ICT vision and strategy were not systematically measured or publicly reported, but to their credit, neither Dr Thurley nor Ms Kelly tried to dress this up in the hearing. When we asked directly whether government had confidence in the whole of government oversight of key assets, their age and a replacement schedule, Ms Kelly told the committee: we don’t have a document that would say here is 100 systems that government has, and this is the order of priority. They weren’t trying to claim they’d sorted the problems out. That was refreshing, and whilst maybe a little bit disappointing we haven’t seen more progress, at least it wasn’t being glossed over. Dr Thurley put a number on where that work has to go, describing the current critical assets mapping exercises as about 85 per cent through. So, hopefully the Leader can provide a bit of an update on this as to where we are now.
Honesty about the progress is useful and appreciated, but it also means that the single most consequential recommendation in the original audit, the one that everything else in the report effectively hangs off remains. On the department’s own account, this recommendation was still incomplete after the six-years. The government’s explanation for this is that it took what Dr Thurley described as a more modern and contemporary approach than the one the Auditor-General envisaged in 2020. We know that things happened in 2021 that threw things up in the air a bit. COVID happened. There was a whole heap of pressure and requirements to perhaps do a lot more things digitally than we had prior to that. I do accept that there was a different approach taken. This was built around the data and digital subcommittee, rather than a single consolidate asset document.
Mr President, I appreciate there is something to that. Technology and the government’s understanding of it have moved on since 2020, and a static document would likely already be out-of-date if one had been created. But a contemporary government’s model is not a substitute for the underlying question the Auditor-General actually asked: does government today know what its critical ICT assets are, how old they are, what they depend on, and when they need replacing? Now, there are set areas where they do know these things, because there is actually work in progress, under development now, but that question couldn’t be answered. On the evidence before the committee, the honest answer is not yet at least not fully. I appreciate the of people of power being really frank and open with the committee, it’s a bit disappointing that six-years on this is still a matter that was on-foot.
The second gap the committee identified is around measurement and public accountability. Finding seven records that is unclear how the outcome of the whole of government ICT vision and strategy are being measured or will be reported. When we put this to Dr Thurley quoting the Auditor-General’s own observation that investment evaluation can only be effective when it is based on a vision that has been clearly defined, with key deliverables and outcomes which can be measured. His answer described an evolving, largely internal tracking process. Not a published set of outcomes measures. When we ask whether this information is available publicly or reported in DPAC’s annual report, Dr Thurley’s answer was quite direct, no. I think this is the sort of information we should be seeing. Dr Thurley indicated an intention to do so through a highlights report, and that intention is welcome. But Mr President, if people knew it was going to be in the DPAC annual report, and you want to go and see what what the progress is, and where to find that information, you would actually think it would be the annual report, not necessarily some other report.
The committee has accordingly recommended, in recommendation two, that DPAC report these outcomes publicly through its annual report. It makes it far more accessible, in my view and the view of the committee, to have these, particularly outcomes measures, and reports of outcomes in an annual report.
On the matter of asset registers, recommendation seven of the original audit is one of only two recommendations accepted in full, rather than in principle. It is the one where the committee can point to a genuinely promising model. While we’ve had lots of complaints about the Department’s of Health’s handling of ICT projects, the example here was in the Department of Health and the work there they’ve done. Since 2024, mapping interlinked asset dependencies, which the Data and Digital Committee had resolved, could be extended across all of government. Credit where credit’s due, the Department of Health had put in place a good system of mapping interlinked asset dependencies. It would be interesting to hear whether it has been rolled out across all other areas of government, as was suggested during the committee’s inquiry into this matter. That is a sound, practical approach and I’d rather see the government build on something that already works in one agency than invent something new from scratch and potentially duplicate effort. But, Ms Kelly’s response to a question on notice from the committee was candid that the form and structure of these registers are not yet fully consistent across government. So, as I said, maybe there will be some further update from the Leader on this matter.
The committee’s recommendation 3 asks that all agency registers be brought into line with the Health Template and recommendation 4 asks that the Data and Digital Committee continues the work already underway toward a genuine whole‑of‑government critical systems register. I want to say something on the broader pattern here because the committee has now seen it across several of these follow‑up reviews. The government is generally willing to accept recommendations in principle to put[?] a substantially different and often reasonable alternative mechanism for achieving the same underlying intent then, in many events, some years later they describe that alternative mechanism as having been fully adopted, rather than the actual intent. I think it’s important that we enable the government to respond in the way that most fits the times, but we can’t afford to lose sight of the actual intent of the recommendation. I’m not saying that’s the case in all these instances, but it is a very frequent outcome where we see the recommendation the Auditor-General agreed in principle, but then it’s really hard then to line up whether it’s actually been delivered in a way that responds to that intent or whether it’s something else completely. I believe there can be a legitimate response to a recommendation. I’m not suggesting that we shouldn’t ever see it. Reform pathways do not have to follow the letter of an audit finding to satisfy its purpose, but it does place a particular onus on the government to be able to demonstrate, with evidence, that that intent has in fact been met. Part of the important work that the Public Accounts Committee does in undertaking these follow‑up reviews is to say, ‘Well, if you haven’t delivered it directly, as recommended by the Auditor‑General, tell us how you have and how that meets the intent.’ For this review, the evidence presented to the committee on the central question of whether or not the government knows the state of its own critical ICT assets, shows that that intent has not yet been fully realised, even if some of the architecture to eventually realise this is now much stronger than it was in 2020. One would hope it is, I might add, but there’s still some work. Well, I hope more work has been done. We’ll hear about that from the Leader.
The committee has made four recommendations and, in my view and in the view of the committee, they are not particularly onerous. They ask the government to finish the whole‑of‑government asset assessment that it says was roughly 85 per cent complete; to standardise asset registers on a model in the Department of Health’s approach, which was suggested because the committee was informed it had been successful, and the government’s own Data and Digital Committee has already endorsed it. The third one was to continue the work already scoped toward a whole-of-government critical systems register and to report publicly through the ordinary mechanism of an annual report on outcomes against a strategy the government has already committed itself to. I hope that the Leader can not only update us on the progress on the Auditor-General’s recommendations, but provide a response to the Public Accounts Committee’s recommendations as I believe, when they’re taken together, we’ll see a much more robust and comprehensive understanding of the ICT critical assets. I hope the government can accept and implement all four of the PAC recommendations without too much difficulty, and I’ll be interested to see in due course evidence that they have been.
The Public Accounts Committee has a recommendation tracker on its website, which was found by the Department of Health at one stage, and they said, ‘Oh goodness, we didn’t know this was here’. Well, we just published it and, to date, we have had one very welcome response to two recommendations of a committee report from the minister for Infrastructure. He’s the first and only minister to respond directly to the PAC with regard to recommendations made in good faith by the PAC on any report. I thank him for that. He will get a nice little letter from us thanking him for that, because it’s respectful.
Mr Vincent – I apologise, it might’ve been an error.
Ms FORREST – We don’t do this work for nothing and, whilst the Leader for the Government can stand up and contribute on a debate such as this, we expect a formal response back from the government, which we haven’t had until very recently, when the minister for Infrastructure, minister Vincent, he sits in this Chamber, did that for at least two of the recommendations he’s responsible for. The tracker has been updated to reflect that response. I encourage other departments and responsible ministers to likewise check that and see if they could perhaps update the committee. We will be writing to them in future if we don’t get responses, but I wanted to make that point here and thank the minister.
I welcome the response from the Leader on this and contributions from other members. I know some of these topics are fairly dry and not everyone’s main interest, but it is important work; our ICT infrastructure is critically important, we know what can go wrong. I do acknowledge that the work of Dr Justin Thurley and his team in responding to these matters and being open and honest about the progress that has been made, as well as the reasons for a bit of a change in direction in response to COVID to redirect some of their efforts and take a bit of a fresh approach to it, which was helpful.
I also wanted to thank my committee members; the members in this House, member for Elwick and member for Pembroke. It is a very busy committee and we do work really hard on that committee. So, it’s great to be able to present reports; as we present another one today, another follow‑up review from the Auditor‑General. But also our hard-working Committee Secretary, Simon Scott, who barely raises an eyebrow when yet another thing is added to the agenda. We thank him. I thank members for their hard work, and the lower House members as well. It’s a really hard-working committee and they’re all very attentive and willing to turn up.
