Lighthouse AdvisorySLED AI Adoption Intelligence
← Back to results

From the Campus Operations edition of September 13, 2026

Government auditCautionaryNewly relevant · May 2026

Western Australian audit finds fewer IT weaknesses but persistent remediation and maturity problems

Office of the Auditor General Western Australia · Public tertiary education IT and cybersecurity · Western Australia; four universities and five TAFEs

Publisher
Western Australian Auditor General
Original publication
May 22, 2026
Source retrieved
2026-09-14
Read original source

What happened

The audit reports that a lower finding count coexists with persistent control weaknesses and declining maturity.

Why it matters

Relevant scrutiny of the IT foundations campus AI services inherit. Mixed university/TAFE results and Australian criteria cannot be generalized to U.S. prevalence.

Evidence and measured results

Annual general-computer-control audits covered four universities and five TAFEs for the year ending December 31, 2025. Findings fell from 87 to 73; 64% were unresolved from prior years. Capability assessments used ten categories and a 0–5 scale, with three the benchmark.

Limitations and uncertainty

This is not an AI effectiveness audit and does not demonstrate AI caused the findings. Current remediation is unknown. Image-only appendix detail could not be inspected because PDF screenshots failed; claims rely on substantive HTML and extracted PDF prose.

Put this evidence to work

Lighthouse Advisory interpretation, grounded in this source. Enriched 2026-09-14; this does not change the original publication date. Labels below come from the analysis itself.

Sales

Role takeaway

Ask the CISO, CIO and audit committee whether open control findings affect a proposed AI service's dependencies. A bounded engagement could map one assistant's access path to unresolved institutional issues and prepare a prioritized validation plan. The value hypothesis is better-informed readiness decisions, not a guaranteed reduction in breaches. Ask which deficiencies have been retested and who funds closure. Do not use this Australian sector report to imply a named U.S. prospect has the same weaknesses or that an AI security product would resolve ordinary IT problems.

Pre-sales engineering

Role takeaway

Draw the complete service boundary across endpoints, identity, retrieval stores, logs and third-party interfaces. Validate a limited set of synthetic user and contractor lifecycle cases before connecting sensitive campus records. Check revocation propagation, least privilege and monitoring under both normal and failure conditions. Include a shutdown path for autonomous actions. Prerequisites are an accurate asset inventory and permission owners. Proposed proof of value should demonstrate correction and retest of scoped failures; a policy document or architecture diagram alone cannot establish operating effectiveness.

Delivery

Role takeaway

Make the institutional IT control owner accountable for remediation, with audit providing independent closure review. Sequence fixes around service dependencies, coordinate change windows and train administrators on the revised process. Proposed acceptance requires traceable evidence for each scoped correction, a successful retest and an assigned recurring check. Maintain accessible support during changes and measure disruption. Risks include closing findings on paper, drifting account permissions and understaffed maintenance. Reassess AI expansion when its underlying service changes rather than treating the initial review as permanent assurance.

Implementation considerations

Lighthouse Advisory interpretation across the operating dimensions a public-sector buyer must settle before this evidence becomes a design. Each note answers the question under its heading for this specific source.

Architecture and integration

What must connect, and where does the AI sit in the workflow?

Include identity lifecycle and endpoint dependencies when designing assistants or agents.

Governance

Who approves, reviews and stays accountable for outcomes?

Require retest evidence before closing a control issue.

Security and privacy

What data, permissions and controls need testing?

Evaluate existing access and patching weaknesses before adding sensitive retrieval or automated actions.

Accessibility and workforce

Who is affected, and what skills or accommodations follow?

Budget skilled remediation capacity without removing accessible routes to essential services.

Procurement

What should contracts, pricing and exit terms secure?

Require assurance that covers the actual service and identified institutional dependencies.

Operating model

Which teams own the service once it runs?

Separate declining finding counts from verified risk reduction and sustained control operation.

What changed

New URL and PDF across the full archive. Fills the prior edition's independent operational-security scrutiny gap with accessible audit prose; historical findings are not current incident claims.

Publication history

  1. 2026-09-13Campus Operations · Issue 083 resources
Read preserved resource versions (JSON)

Stable resource ID: wa-tertiary-it-controls-audit-2025-results