{"resourceId":"wa-tertiary-it-controls-audit-2025-results","versions":[{"version":"external-839def64c6fd56d699fb49da68cbb0d434a4792160b125aec619588c908b024b","resource":{"id":"wa-tertiary-it-controls-audit-2025-results","title":"Western Australian audit finds fewer IT weaknesses but persistent remediation and maturity problems","organization":"Office of the Auditor General Western Australia","sector":"Public tertiary education IT and cybersecurity","geography":"Western Australia; four universities and five TAFEs","publishedAt":"May 22, 2026","publicationDate":"2026-05-22","eventDate":null,"sourceName":"Western Australian Auditor General","sourceLabel":"Independent government information-systems audit","sourceUrl":"https://audit.wa.gov.au/reports-and-publications/reports/universities-and-tafes-2025-information-systems-audit-results/","evidenceClass":"government-audit","outcomeClass":"cautionary","topics":["infrastructure","data-security","governance-procurement","operating-model"],"finding":"The audit reports that a lower finding count coexists with persistent control weaknesses and declining maturity.","sledRelevance":"Relevant scrutiny of the IT foundations campus AI services inherit. Mixed university/TAFE results and Australian criteria cannot be generalized to U.S. prevalence.","evidence":"Annual general-computer-control audits covered four universities and five TAFEs for the year ending December 31, 2025. Findings fell from 87 to 73; 64% were unresolved from prior years. Capability assessments used ten categories and a 0–5 scale, with three the benchmark.","architectureImplications":"Interpretation: include identity lifecycle and endpoint dependencies when designing assistants or agents.","governanceImplications":"Interpretation: require retest evidence before closing a control issue.","securityPrivacyImplications":"Interpretation: evaluate existing access and patching weaknesses before adding sensitive retrieval or automated actions.","caveats":"This is not an AI effectiveness audit and does not demonstrate AI caused the findings. Current remediation is unknown. Image-only appendix detail could not be inspected because PDF screenshots failed; claims rely on substantive HTML and extracted PDF prose.","streamIds":["campus-operations"],"roles":{"sales":"Interpretation: ask the CISO, CIO and audit committee whether open control findings affect a proposed AI service's dependencies. A bounded engagement could map one assistant's access path to unresolved institutional issues and prepare a prioritized validation plan. The value hypothesis is better-informed readiness decisions, not a guaranteed reduction in breaches. Ask which deficiencies have been retested and who funds closure. Do not use this Australian sector report to imply a named U.S. prospect has the same weaknesses or that an AI security product would resolve ordinary IT problems.","engineering":"Interpretation: draw the complete service boundary across endpoints, identity, retrieval stores, logs and third-party interfaces. Validate a limited set of synthetic user and contractor lifecycle cases before connecting sensitive campus records. Check revocation propagation, least privilege and monitoring under both normal and failure conditions. Include a shutdown path for autonomous actions. Prerequisites are an accurate asset inventory and permission owners. Proposed proof of value should demonstrate correction and retest of scoped failures; a policy document or architecture diagram alone cannot establish operating effectiveness.","delivery":"Interpretation: make the institutional IT control owner accountable for remediation, with audit providing independent closure review. Sequence fixes around service dependencies, coordinate change windows and train administrators on the revised process. Proposed acceptance requires traceable evidence for each scoped correction, a successful retest and an assigned recurring check. Maintain accessible support during changes and measure disruption. Risks include closing findings on paper, drifting account permissions and understaffed maintenance. Reassess AI expansion when its underlying service changes rather than treating the initial review as permanent assurance."},"retrievedAt":"2026-09-14T03:01:10Z","enrichedAt":"2026-09-14T03:03:12Z","enrichmentBasis":"retrieved source","accessibilityWorkforceImplications":"Interpretation: budget skilled remediation capacity without removing accessible routes to essential services.","procurementImplications":"Interpretation: require assurance that covers the actual service and identified institutional dependencies.","operatingModelImplications":"Interpretation: separate declining finding counts from verified risk reduction and sustained control operation.","updateExplanation":"New URL and PDF across the full archive. Fills the prior edition's independent operational-security scrutiny gap with accessible audit prose; historical findings are not current incident claims.","sourceVerification":{"openedUrl":"https://audit.wa.gov.au/reports-and-publications/reports/universities-and-tafes-2025-information-systems-audit-results/","referenceExcerpt":"The majority of the weaknesses (64%) remained unresolved from prior years.","promptVersion":"sled-research-v3.2","model":null,"basis":"agent-reported inspection"}}}]}