Appendices

Appendix A: Process and data collection

Data collection

Each quarterly reporting cycle involved collecting seller data, compiling entity-published data from the websites of 113 entities, reconciling and validating the data with entities, and sharing insights with the APSC.

The purpose of the process was not to investigate individual APS/SES employees or sellers, but to test whether seller-reported offers broadly aligned with entity-published registers and to identify any systemic issues that could affect transparency, integrity or public confidence. The work also provided practical evidence to inform the APSC’s refreshed gifts and benefits guidance.

The data collection focused on the period 1 April 2025 to 31 March 2026. Sellers were asked to provide details of gifts, benefits and hospitality offered to APS/SES employees, including accepted and declined offers. Entity data was drawn from publicly available gifts and benefits registers and reviewed against seller-reported information.

Because the collection relied on seller records and publicly available entity registers, the analysis was strongest as a system-level assurance activity. It was not designed to produce a complete audit of every interaction between ICT sellers and Commonwealth officials.

Scope of suppliers

The 9 sellers in scope were selected because of their material role in Commonwealth digital and ICT procurement. AWS, IBM, Microsoft, Oracle, Rimini Street and SAP were included as whole-of-government providers. Salesforce and ServiceNow were included as model contract holders. Data#3 was included because of its role as a major reseller and Microsoft’s dedicated distributor.

The entity review covered 113 entities’ publicly available gifts and benefits registers. The review considered whether relevant entries appeared on entity registers, whether registers were accessible, and whether publication practices supported meaningful transparency.

Transparency, reporting mechanisms and comparability

The Commonwealth Supplier Code of Conduct outlines high-level expectations for ethical behaviour and governance but does not prescribe supplier reporting mechanisms for gifts and benefits. Sellers used different internal methods and thresholds, but all provided the minimum information requested. Most relied on expense-management data, though system capability and governance arrangements varied.

Appendix B: Seller reporting thresholds and mechanisms

Sellers used different reporting thresholds and internal mechanisms to identify reportable offers. This affected comparability but did not prevent the DTA from identifying the main patterns in the data. The analysis therefore distinguished between offers above the $100 threshold and the broader set of offers captured by individual seller reporting practices.

In aggregate, sellers reported 3,662 gifts and benefits offered to APS/SES employees at various thresholds; 539 were accepted and 3,123 were declined. Across gifts and benefits valued above the $100 threshold, sellers reported 3,085 offers to APS/SES employees; 188 were accepted and 2,897 were declined. 

Most sellers relied on expense-management systems, internal approval processes or governance records to identify gifts, benefits and hospitality. Differences in system configuration, field structure and internal thresholds meant some seller data required interpretation before it could be compared with entity registers.

ServiceNow had a distinct effect on the data because it used bulk distribution lists and frequent conference-style invitations. It reported 3,153 offers, of which 148 were accepted, accounting for around 94% of the value of all offered gifts and benefits captured through the broader collection.

Appendix C: Entity register review and reconciliation observations

The DTA compared seller-reported data with publicly available entity gifts and benefits registers. Where entries were unclear, missing or difficult to match, the DTA considered whether the issue reflected a substantive discrepancy or a reporting, timing or publication difference.

The analysis of the data collected for the reporting period did not identify significant divergence, systemic concern or information that justified referring an APS/SES employee from another entity for investigation. Some offers that would generally be unacceptable, such as sporting match tickets, were identified in seller data, but all relevant reported cases were declined.

The reconciliation process highlighted several practical issues with public reporting. Some registers were difficult to locate, some did not clearly identify the cohort covered, some did not retain earlier reporting periods publicly, and some did not make nil declarations obvious. These issues did not change the overall result, but they reduced transparency and increased the effort required to interpret the data.

The review also showed that accepted offers were mainly associated with conferences, industry events, professional development, training or hospitality connected to legitimate business engagement. The risk profile depended on the value, timing, purpose, recipient role, procurement context and whether acceptance could reasonably be perceived to influence official duties.

Appendix D: Interpretation and implications for implementation

The data suggests the most effective response is not a new investigative process, but clearer expectations, better public reporting and stronger prompts at the point where officials and sellers make decisions. The findings support the retention of the $100 public reporting threshold while reinforcing the need for risk-based management of lower-value or repeated offers.

The DTA can support implementation by using BuyICT.gov.au to remind buyers to consider gifts and benefits obligations during procurements, publishing practical guidance for sellers and entities, and using the Digital Sourcing Network to communicate expectations across the Commonwealth ICT procurement community.

Sellers should be encouraged to disclose the value of gifts, benefits and hospitality at the point of offer. This would help APS/SES employees assess whether an offer should be accepted, declined or recorded, and would reduce ambiguity during subsequent reporting.

Appendix E: Key data from the reporting periods

This appendix contains 15 tables, which draw out the key data for each quarter and the 12-‍month reporting period overall. These tables are a summary, building on the raw data collected. Numbers in the tables have been rounded to the nearest dollar. Estimated and mean values are in Australian dollars (AUD).

Appendix F: Entity participation scope

The entity participation scope for the DTA’s data collection process aligned with the list of agencies from the APSC’s webpage containing the list with links to entities’ gifts and benefits registers. The flow-on effects from this decision included leveraging an existing approach that permits exemptions for staff from national intelligence community (NIC) entities from reporting their gifts and benefits registers publicly. NIC entities that choose to publish a gifts and benefits register were kept in scope.

Some entities which publish gifts and benefits registers were excluded from scope. An applicable example is the Australian Federal Police (AFP). The AFP is a NIC entity which publishes a gifts and benefits register, and its website refers to the AFP’s alignment with the APSC’s guidance. This is a positive example of an entity, which does not employ staff under the Public Service Act 1999, referring to the APSC’s guidance. Nevertheless, for the purpose of the DTA’s data collection process, the AFP was outside of scope because it is also out of scope to be listed on the APSC’s website.

Next page

Tables

Connect with the digital community

Share, build or learn digital experience and skills with training and events, and collaborate with peers across government.