The NSW Auditor-General has tabled a report examining internal controls and governance across 26 of the NSW Government’s largest agencies, finding an increase in repeat issues and weaknesses in oversight across grants, consultancy engagements, purchasing cards, cyber security and artificial intelligence.
The report says interim audits identified weaknesses in internal controls and governance at 15 agencies, with a shift toward “high-risk, high-spend areas such as procurement and grants”. Repeat findings rose from 33% to 42% of total findings.
On grants administration, the report says most agencies have limited central oversight and monitoring, including how they track delivery, reporting and financial management. It also found deficiencies in due diligence checks, acquittal controls, evaluations and reconciliations between program records and grant disbursements, which it says weakens assurance over accountability for public funds and agencies’ ability to demonstrate grants were used for their intended purpose.
The report also raises concerns about how agencies engage and report on consultants. It says agencies did not always document the justification for hiring consultants, assess performance, or obtain conflict of interest declarations. Thirteen per cent of sampled engagements did not include confidentiality clauses to protect government information.
It also says mandatory annual reporting captures only a small share of payments to firms that provide consulting services because other professional services are excluded. The report says agencies omitted at least $18.3 million in consultancy expenditure from annual report disclosures since 2023–24.
Purchasing card use was another focus, with the report noting transactions involving vendors that sell gift cards, entertainment, alcohol and tobacco products. It says personal, non-compliant and split purchases were made on purchasing cards, pointing to weaknesses in acquittal controls. One in five transactions were not acquitted and approved within 30 days, limiting oversight.
In technology governance, the report says there are “significant gaps” in compliance with NSW Cyber Security Policy requirements. Less than half of agencies reported compliance with requirements to protect and govern their risk exposure, and some agencies did not assess risks from legacy systems that cannot be patched, increasing exposure to cyber-attack.
On AI, the report says agencies have limited visibility of AI use, citing inconsistent registration of AI use cases and limited central tracking of costs. It says governance is not keeping pace with the speed at which agencies are adopting AI.
As context for the scale of the issues, the report’s “fast facts” section says the 26 agencies spent $2.3 billion on purchasing cards between 1 July 2023 and 28 February 2026, and reported 128 significant, high and extreme cyber security risks in 2025. It also says 27% of sampled consultancies did not have conflict of interest declarations.
The report makes four recommendations aimed at strengthening internal controls and governance for grants administration, purchasing cards, cyber security and AI oversight.

