The NSW Audit Office is building a central platform to collect general ledger, journal and payroll data directly from state agencies. Around 180 agencies are due to be onboarded by 30 June 2027.
The plan is set out in the Audit Office of New South Wales Annual Report 2025-26, signed by Auditor-General Bola Oyetunji on 8 October. Forty-eight agencies are already on the platform.
The report says the platform "gives auditors central access to financial data and standardised audit solutions for general ledger, journals and payroll audits". It provides controlled access to key datasets, dashboards and assurance outputs.
A separate proof of concept is under way to standardise how data is acquired from local councils. The office says this lays a foundation for more automated and scalable financial audit analytics.
The project is a capital investment. The office capitalised $234,000 of staff time worked on the Data Platform Project in 2025-26, up from nil the year before.
From samples to whole populations
The shift changes how agencies' records are examined. Rather than testing small samples of transactions, auditors are analysing full datasets.
The Oversight of Visiting Medical Officers performance audit is the office's showcase example. Auditors analysed around 5 million approved claims, more than $3.5 billion in expenses and 8.3 million clinical hours over three years.
"By analysing large amounts of data, we were able to identify patterns and risks that would have been difficult to detect using traditional audit methods," Oyetunji wrote.
The office completed 488 financial audits of state, local government and university entities in 2025-26. It tabled 18 performance audits, including Cyber security in Local Health Districts and Security and privacy of student information.
AI use is now routine inside the office
The report also shows how far AI has moved into the auditor's own work. Ninety per cent of staff have completed a core digital literacy curriculum that gives them access to enterprise AI tools.
The report says 86 per cent use them multiple times a day. Staff share new use cases at regular drop-in sessions.
The office introduced an AI tool organisation-wide during the year. It says this came with a risk assessment, policy development, staff guidance and training, and technical controls "to reduce the risk of AI processing sensitive information".
It has also developed an application register to improve visibility of AI use. AI and agent governance arrangements were progressed, and AI tools were assessed against government assurance expectations.
A detailed AI risk assessment produced an action plan covering both technical and people controls. AI now sits on the same risk list as privacy, cyber security and third-party management.
The auditor audits itself
Several of the office's own internal audits concluded during the year touch directly on information governance.
One tested conformance with ISO/IEC 27001:2022, with a focus on the implementation of an AI tool. Another examined the design compliance and operating effectiveness of the office's records management system.
A third reviewed compliance with the NSW Cyber Security Policy. It focused on the office's self-assessment and its retention of evidence to support the annual assurance statement and attestation.
The report does not publish findings from these internal audits. The office maintained its ISO/IEC 27001 certification during the year.
Data governance work included updated policy and organisation-wide training on labelling and handling sensitive information. The office also removed duplicate and unnecessary data through system clean-ups, backed by technical controls.
CSIRO partnership and integrity matters
In October 2025 the office entered a strategic partnership with CSIRO to pilot generative AI and machine learning in public sector audits. The Auditor-General also chairs the Australasian Council of Auditors-General AI Working Group.
"While positioning ourselves to tap into the opportunities AI provides, we remain vigilant to the significant risks that may arise," Oyetunji wrote.
The report also discloses an internal review into suspected breaches of the Code of Conduct by staff. It resulted in formal warnings to several staff members.
The nature of the breaches is not described. The office says it issued reminders to all staff, obtained additional attestations and implemented further preventative and detective controls.
No matters required external notification as reportable allegations or substantiated misconduct. The office's public register of eligible data breaches under the NSW Mandatory Data Breach Notification Scheme is nil.
The office received two access applications under the GIPA Act during the year. Both were invalid because they sought audit information, which is excluded information under the Act.
In 2026-27, the office plans to expand the data platform and its use of analytics and AI. It will also roll out a new public sector audit methodology.