The Audit
2026-07-15
When assurance finds the risk
The NSW Audit Office's IPOS report records warnings, mitigations, contract termination and later reset. Assurance can identify unresolved delivery risk, but governance decides whether the next decision changes in response.
In May 2026 the Audit Office of New South Wales assessed NSW Police's programme to upgrade core policing technology. The programme, known as IPOS from 2018 until 2024 and then renamed the Police Technology Program, covered COPS, computer aided dispatch, forensics and exhibits management, custody management, and major investigations and intelligence gathering. The audit conclusion was direct. NSW Police had not efficiently or effectively planned and sourced key components of the upgrade.
By December 2025, NSW Police had spent more than $155 million, or 47% of the $328 million allocated programme budget. One of the five core systems had been delivered. Full delivery was not expected until 2031, four years later than the original end date.
According to the audit, NSW Police estimated that replacing the COPS mainframe hardware and systems would cost at least $400 million, and pursued a software-as-a-service option using a commercial off-the-shelf product. The audit says the procurement was comprehensive and competitive, and included scenario testing, site visits, probity advice and gateway reviews.
The audit records the procurement process in detail. NSW Police received 23 submissions. Thirteen organisations received full RFP materials. Six complying tenders were submitted. Three vendors progressed after scenario demonstrations and value-for-money assessments. The preferred proposal was later described as Supplier A as prime contractor and Supplier B as consortium partner. Supplier B was the product vendor that ultimately entered the delivery contract.
The warning came before final contract award. In July 2019, a combined Gate 3A/4A procurement and tendering review rated delivery confidence low. The review found that the programme plan lacked sufficient resources, had overly ambitious timeframes, and did not yet have adequate resourcing or clear prioritisation from the broader organisation. It also raised concern that NSW Police planned to select the preferred provider before agreeing core commercial terms.
The supplier concerns came from several sources. The audit refers to gateway reviews and external advisers warning decision-makers about delivery optimism, resourcing constraints and supplier capability risks. It separately says NSW Police's legal and procurement advisers raised concerns about the preferred company's financial position, its limited experience delivering systems at comparable scale, and the absence of key capabilities such as forensics and exhibits.
The detailed procurement chapter refers to external reviewers and evaluators identifying risks in contracting with an overseas start-up firm with current and forecast losses. In the audit's later chronology, the delivery contract was with Supplier B and the termination was triggered by Supplier B's non-delivery.
The audit does not say the gateway review caused the later outcome. The more useful PM reading is the sequence the audit records. A low-confidence review in July 2019. Supplier and commercial risks before contract. Contract mitigations. Supplier non-delivery in 2022. Termination. A later programme reset. On this reading, the warning was not the control. The unresolved issue was the supplier, resourcing, commercial and governance risk carried into delivery.
According to the audit, the final contract included several risk treatments. These included a bank guarantee, milestone-based payment for actual deliverables, NSW Police ICT staff learning the programming code, quarterly financial health checks, supplier staff relocating to Australia and five exit points with go/no-go decisions. The risk was visible, and the contract included measures to manage it.
But the delivery structure also changed materially. During due diligence, Supplier A resigned from the prime contractor role. The audit says this reduced Supplier A's responsibilities and accountability for IPOS delivery and increased risk for NSW Police because Supplier A would no longer be responsible for Supplier B's performance. NSW Police then removed Supplier A as systems integrator and took on that role itself. Supplier B also had to vary its standard approach, including Australian data hosting, local staff and stronger alignment with government security requirements.
In June 2022, Supplier B advised that it could not deliver the forensics and exhibits system. It also advised that the minimum viable computer aided dispatch product could not be delivered until 2029, six years later than the original contract date for that capability. NSW Police terminated the contract. Payments to Supplier B had reached $15 million, and the audit says the total lost investment from the contract was almost $20 million once project management costs were included.
From 2022 to 2024, the audit says the programme lacked direction and coordination. Project teams worked largely in silos and the steering committee did not maintain sufficient oversight of timelines or budgets.
The audit records a different position after the mid-2024 reset. NSW Police began implementing recommendations from the gateway review and project management report, moved to a single sponsor, and changed governance arrangements. It later strengthened governance through the PTP steering committee. From April 2025 the steering committee received more consistent and structured reporting covering delivery status, financials, risks, issues, dependencies, benefits realisation and change management. Later health checks rated overall delivery confidence as medium.
In IPOS, the record shows warnings, mitigations, contract termination and later reset. The PM lesson is that assurance can identify unresolved delivery risk, but governance decides whether the next decision changes in response. When the warning is low delivery confidence, the next decision needs to show what changed: supplier confidence, scope, schedule, resourcing, commercial terms, governance authority or exit rights. If those conditions do not change, the programme has not treated the risk. It has documented it.