We’re here to Assure, Explain and Inspire.
The Auditor General is the statutory external auditor of most of the Welsh public sector.
Our key strength is our wide range of skills and knowledge that has arisen from our position as the the statutory external auditor
See our current and previous consultations
This section sets out how you may request information from us and provides some direct links to information of wider public interest.
Governance and oversight at Audit Wales
Our accounts are audited by an independent firm appointed by the Welsh Parliament.
Our Executive Leadership Team is responsible for directing the organisation
The Auditor General is responsible for auditing most of the public money spent in Wales.
Audit Services has a reach of over 800 public bodies across Wales covering financial and performance audit
Our programme of shared learning events focusses on topics that are common across public services
Our forward work programme for performance audit
The NFI matches data across organisations and systems to help public bodies identify fraud and overpayments.
We work with others from across the Welsh public sector and beyond
See our latest news, blogs, events and more
Find out the latest news
See our blogs on many different topics
Access our data tools and useful data sources
View our videos on our YouTube channel
Our events bring together individuals from across the Welsh public sector
Access all the resources from our shared learning events
We have installed ReadSpeaker’s webReader, which allows visitors to instantly convert online content to audio on our website.
Click on the icon above to try this out, and take advantage of the full range of useful webReader features by clicking the link below.
Readspeaker website
This accessibility statement applies to www.audit.wales. This website is run by Audit Wales. We want as many people as possible to be able to use this website.
View accessibility statement
We’re always looking to improve the accessibility of this website. If you find any problems not listed on this page or think we’re not meeting accessibility requirements, contact:
info@audit.wales
Taking the chance to reflect on the impact of our work
The recent release of The Beatles’ documentary ‘Get Back’ was great for anyone interested in the band (pretty much everybody) because it revisited the good work they produced over the years.
We’ve taken the band’s lead, and for anyone with an interest in cyber resilience (should be pretty much everybody) we’ve been revisiting our work on the subject from last year. We are not claiming to be anything like The Beatles, but we did want to reflect on the impact our work had, and to re-emphasise our main messages to those with an interest.
The work we did was a call to arms. We targeted senior decision makers at public bodies, to raise awareness of the critical importance of cyber resilience and to encourage them to reflect on their personal responsibilities, and their organisational arrangements.
We feel like we achieved this – we’ve had feedback that we helped to bring the topic into the consciousness of Boards and leadership teams. We also hope we provided a high-level overview of cyber resilience within Welsh public bodies that was not there before.
Since we started our work, cyber threats have continued to grow. The National Cyber Security Centre (NCSC) reports that cyber vulnerabilities have increased in relation to COVID-19 [opens in new window], through hackers trying to steal medical research about vaccines, and because of growth in the number of people homeworking [opens in new window] and using personal devices. In the first four months of 2021, the NCSC handled the same number of ransomware incidents as for the whole of 2020. And public bodies in Wales have been among those hit by recent cyber-attacks, which just goes to show these threats are real and are close to home. The National Audit Office talks more about the current cyber threats facing public bodies in their blog [opens in new window].
There is still much work to be done but it has been pleasing to see the actions that some public bodies in Wales have been taking since we reported. These have included:
The Welsh Government has been taking action too, including:
It has also been pleasing to receive interest in our work from outside of Wales, with other public audit organisations contacting us to share knowledge and good practice.
We know it’s a work in progress for Welsh public bodies, and there is still much more to be done. Areas for concern recently highlighted to us by our contacts in the Welsh Government and the NCSC include:
So, let’s get back to the key point of this blog. We want to keep the awareness of good cyber resilience high, but we also want public bodies to continue to speak to us, and to each other. There can be a stigma attached to being the victim of a successful cyber-attack, but without coming together to share lessons, there is a risk of history repeating itself, and failing to learn from experiences.
The End.
[Find out more about our work on cyber resilience by reading our blog or by watching our webinar.]
Gareth Lewis is a Senior Auditor in the IM&T audit team, and works on projects across both financial and performance, covering all sectors. He has been part of Audit Wales and its predecessor organisations since 2004.