Australian Cyber Aware Audit Report Listing
Government audit reports provide one of the clearest, most independent views of how organisations are managing cyber security, AI, privacy, and information risk. Unlike vendor-led advice or internal reporting, these audits are designed to identify systemic weaknesses, governance gaps, and areas where controls are not operating effectively.
For executives, directors, and practitioners, regularly reviewing these reports is a practical way to focus effort where it matters most. The findings are not theoretical—they reflect real environments, real control failures, and real consequences observed across government and critical sectors.
Government audit reports can support internal audit planning by highlighting common control weaknesses and risk areas observed across organisations. By factoring these insights into planning, internal audit teams can better prioritise focus areas, align audit scope to higher-risk processes, and concentrate testing on controls that are more likely to require improvement—resulting in a more targeted and risk-informed audit approach.
July 2026
22-Jul-26 AU NT
NTAGO Multiple Agencies
Results of Financial Audits – 30 June and 31 December 2025
Key finding: Strong audit outcomes for the public tertiary sector; however, timeliness and control weaknesses require continued attention. Recurring weaknesses in information technology user access controls remain a common theme.
June 2026
29-Jun-26 AU FED
ANAO IP Australia
Artificial Intelligence Use in IP Australia
“Artificial intelligence (AI) is increasingly becoming a part of the Australian Public Service. AI offers the promise of better services, enhanced productivity and efficiency — but has the potential for increased risk and unintended consequences.
The ANAO made two recommendations to IP Australia aimed at improving management of cyber security risks and improving strategic oversight of AI implementation. “
29-Jun-26 AU NSW
AONSW, Education
Security and privacy of student information
This audit assessed how effectively the NSW Department of Education (the department) and NSW public schools (schools) protect the security and privacy of student information. The audit made recommendations for the department to review the allocation of responsibilities to principals, improve the guidance and supports for schools, and strengthen the controls for managing the access to and use of student information.
24-Jun-26 AU FED
ANAO Department of the Treasury’s
Department of the Treasury’s Readiness to Implement the Scams Prevention Framework
Treasury has largely appropriate implementation and monitoring arrangements to support its readiness to implement the SPF, up to the point where the SPF becomes operational. To position Treasury to provide impactful, informed and influential advice about the SPF in operation, it will need to develop monitoring, reporting and evaluation arrangements.
18-Jun-26 AU QLD
QAO, Education
Education 2025
Weaknesses in the security of information systems at universities continue to account for most of the deficiencies we identified. Despite this, we have been able to rely on the systems and processes they used to prepare financial statements. This year, we identified 25 deficiencies – including one significant deficiency – relating to weaknesses in information systems controls at universities. Of the 48 deficiencies we identified last year, 14 remain unresolved as at 31 December 2025
16-Jun-26 AU SA
AOSA Government
Review of legacy ICT systems
We found weaknesses in how some agencies manage legacy system risks, including incomplete asset inventories, limited formal risk assessments, gaps in risk register documents and inconsistent reporting to governance bodies. These gaps reduce visibility of risks and can delay action to remediate or replace systems.
11-Jun-26 AU FED
ANAO, Department of Parliamentary Services, Government
Management of Cyber Security in the Department of Parliamentary Services
The ANAO audit assessed whether the Department of Parliamentary Services (DPS) had an effective baseline of cyber security controls, focusing on its assessment of cyber risks, implementation of the Essential Eight mitigation strategies, and assurance over control effectiveness in alignment with the Protective Security Policy Framework (PSPF) and Information Security Manual (ISM). It found that while governance structures existed, the overall cyber security posture was only partly effective due to gaps in risk assessment, incomplete implementation of controls, reliance on compensating measures, and weaknesses in asset inventories, policy frameworks, and assurance processes.
11-Jun-26 AU NSW
AONSW Education
Universities 2025
“Control deficiencies were most common in IT/cyber security, governance and payroll
There were 94 reported audit findings and most related to poor monitoring of IT/cyber security risks, inadequate governance oversight and deficiencies in payroll management. One university has no processes to manage IT legacy systems, and 6 universities have not formally assessed legacy system risks.
Three universities still do not have a formalised AI policy. Only 2 universities had procurement guidance in place for AI-related procurement.”
04-Jun-26 AU VIC
VAGO, Higher Education
Results of 2025 Audits: TAFEs and Universities
Weaknesses in IT controls continue to require attention in both sectors. Issues with their management and monitoring of system access increase the risk that errors or fraud occur and go undetected.
May 2026
27-May-26 AU WA
WAOAG Higher Education
Universities and TAFEs 2025 – Financial Audit Results
This year we reported 73 control weaknesses compared to 883 last year. Despite a slight reduction, the proportion of significant and moderate weaknesses increased, and most of the weaknesses (64%) remained unresolved from prior years. Three per cent of weaknesses were rated significant, 74% moderate and 23% minor. Although the majority of weaknesses were moderate, entities should promptly address them to reduce their overall exposure to cyber and other information system threats.
27-May-26 AU FED
ANAO Australian Bureau of Statistics
Cyber Security Readiness for the 2026 Census
“There were four recommendations to the ABS regarding: Census risk management arrangements; early establishment of cyber security advisory arrangements; preparation, approval and review of security architecture documentation; and addressing risks stemming from the broader ABS ICT environment. The ABS agreed to the recommendations.”
22-May-26 AU WA
WAOAG Higher Education
Universities and TAFEs 2025 – Information Systems Audit Results
Information and cyber security controls is the most significant area of concern, accounting for 82% of all weaknesses identified. These controls are critical to protecting sensitive information and maintaining the integrity and availability of key systems.
11-May-26 AU NSW
AONSW NSW Police Force
Upgrades to core policing technology
While essential technology infrastructure and the forensics and exhibits system have been upgraded, other core systems identified in the original business case remain dependent on legacy platforms. This requires ongoing funding, increases technology risk and reduces operational effectiveness. In the 2025 updated business case, the NSW Police Force noted escalating risks to service continuity, cyber security and public safety.
April 2026
15-Apr-26 AU WA
WAOAG Local Government
Local Government 2025 – Financial Audit Results
For the 2025 financial year, we reported 333 general computer control weaknesses to 68 entities, compared to 360 control findings to 89 entities in 2024. Over half of these weaknesses (60%) were unaddressed prior year issues. Nine percent of findings were rated significant, 69% moderate and 22% minor.
March 2026
30-Mar-26 AU VIC
VAGO Local Government
Results of 2024–25 Audits: Local Government
Councils can strengthen their internal controls to better support the preparation of reliable reporting. Each year, we continue to identify weaknesses in financial reporting controls, IT controls and asset management and valuation. A large number of high and moderate‑risk issues identified in past audits also remain unresolved.
26-Mar-26 AU QLD
QAO Multiple
Managing third-party cyber security risks
“While the entities had implemented some policies, processes, and controls to identify and manage third party cyber security risks, gaps remained. In isolation, many of the gaps or issues may seem relatively minor. However, collectively they created vulnerabilities that unnecessarily exposed the entities to third party cyber attack – compromising their systems, data, and sensitive information.
The Department of Customer Services, Open Data and Small and Family Business (CDSB) and the Department of Housing and Public Works (DHPW) are not effectively building capability across the public sector to manage third-party cyber security risks.”
25-Mar-26 AU WA
WAOAG Local Government
Local Government 2025 – Information Systems Audit Results
Our 2025 audits highlight ongoing challenges for entities to strengthen their IT governance and security. While it was positive to see the number of entities that had control weaknesses reduce to 68 this year (89 in the prior year), 60% of our findings were unresolved issues from prior years. Entities need to address these persistent control weaknesses to safeguard their important systems, information and service delivery.
19-Mar-26 AU QLD
QAO Local Government
Local government 2025
This report summarises the audit results of Queensland’s 77 local government entities (councils) and the entities they control. In 2024–25, there were 263 significant internal control deficiencies that were either new or unresolved – the highest number of high risk matters we have found in the sector in the last 5 financial years.
This year, we identified 98 new information systems weaknesses across 49 councils (2023–24: 77 new weaknesses across 49 councils).
06-Mar-26 AU WA
WAOAG Multiple
Microsoft 365 Security Controls – State Entities
The audit found weaknesses in governance, identity and access management, information protection, logging and monitoring, and threat protection controls. These weaknesses heighten the risk of cyber incidents, data breaches and operational disruptions.
January 2026
28-Jan-26 AU NSW
AONSW Local Government
Local government 2025
“This report presents key findings and recommendations from financial audits of local councils, joint organisations and county councils for the year ended 30 June 2025. It also comments on the sector’s financial sustainability, internal controls and governance, major capital projects, artificial intelligence (AI) and cyber security.
Councils are in the early stages of adopting AI. Fewer than half have a strategy or governance framework, limiting oversight and opportunities to leverage benefits and mitigate AI risks.
Deficiencies in internal controls and governance were identified at most councils, mainly associated with asset management, information technology (IT) and fraud control.
Councils have critical weaknesses in managing supply chain risks. Policies and processes for assessing the cyber security exposure of technology assets are inadequate, and monitoring of cyber security investments and their associated benefits is limited.”
20-Jan-26 AU QLD
QAO Queensland Health
Health 2025
Health sector entities’ financial statements are reliable and their internal controls are also generally effective. However, we continue to find deficiencies in information technology (IT) access and security controls. Health entities are considered attractive targets by cyber criminals, due to the personal information they hold and the potential for profit. We therefore consider these access control deficiencies as significant. While management is working to address these complex issues, they need to take more timely action to resolve the deficiencies.









