Audit Finds Over-Decade Delay, ₹11.88 Crore Central Assistance Loss; Cybersecurity, Data Integrity and Disaster Recovery Controls Under Scanner
SRINAGAR, OCTOBER 3 :
The Comptroller and Auditor General of India (CAG) has called for a comprehensive overhaul of Jammu and Kashmir’s Integrated Financial Management System (IFMS), flagging serious deficiencies in its implementation, cybersecurity, financial controls, data validation, infrastructure and institutional oversight.
The findings form part of the CAG Report for the period ended March 2023, which was tabled during the Autumn Session of the Jammu and Kashmir Legislative Assembly. The audit highlighted that the implementation of IFMS had suffered a delay of more than a decade, with only four of the 12 proposed modules fully operational as of March 2023.
According to the audit findings, the prolonged delay also resulted in the loss of ₹11.88 crore in Central assistance, which the CAG attributed to the failure to revise the Detailed Project Report (DPR) as directed by the Government of India and non-achievement of prescribed milestones under the Mission Mode Project-Treasury Computerisation guidelines.
The CAG further observed that the Government had not constituted a Core Consultant Group by March 2023 to incorporate user requirements into the implementation of the system.
SERIOUS CYBERSECURITY GAPS FLAGGED
The audit raised significant concerns over security and access-control mechanisms within the financial management system.
The CAG recommended implementation of role-based access controls and Multi-Factor Authentication (MFA) along with strict compliance with prescribed authentication, data submission and financial transaction protocols.
The audit found that Maker and Checker functions were being operated through the same user IDs with different passwords, raising concerns regarding segregation of duties and internal financial controls.
It further noted that passwords of 1,010 TreasuryNet users had not been changed as of January 2024, while Multi-Factor Authentication had not been implemented.
The CAG recommended strengthening password-management mechanisms through automatic password expiry, password recovery facilities and comprehensive audit trails covering transactions and modifications to financial data.
BEAMS, JKPAYSYS DATA VALIDATION UNDER CLOUD
The audit also identified shortcomings in BEAMS and JKPaySys, particularly inadequate client-side and server-side validation.
According to the findings, these deficiencies allowed erroneous or incomplete information to be submitted into the system.
Poor integration between BEAMS and TreasuryNet also affected seamless transfer of data and created vulnerabilities concerning unauthorised modification of bill particulars, including bill amounts, DDO codes, Major Heads, Detailed Heads, scheme codes and treasury voucher numbers.
The CAG observed that the system did not maintain a complete record identifying who had inserted or modified particular records, thereby creating risks relating to unauthorised access and manipulation of sensitive financial information.
DISASTER RECOVERY MECHANISM FOUND INADEQUATE
The CAG also flagged the absence of a comprehensive Disaster Recovery and Business Continuity mechanism for IFMS.
It recommended preparation of a formal Disaster Recovery Plan incorporating backup arrangements, Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) to ensure continuity of critical financial services during system failures or other disruptions.
DATA CENTRE INFRASTRUCTURE ALSO FLAGGED
The infrastructure supporting IFMS also came under scrutiny.
Instead of upgrading the State Data Centre for hosting and storage of IFMS applications, the applications were hosted by NIC at its Mini Data Centre in Jammu without a supporting backup site, while funds earmarked for the proposed infrastructure upgrade remained misutilised, according to the audit.
The CAG also pointed out that User Acceptance Testing (UAT) had not been conducted, raising questions over whether the software adequately met user requirements and performed as intended.
QUALITY CERTIFICATION NOT OBTAINED
The department had also failed to obtain certification from the Standardisation Testing and Quality Certification (STQC) agency.
The CAG observed that the absence of such certification indicated shortcomings in adherence to prescribed industry standards relating to quality assurance, risk assessment and management certification.
CAG SEEKS BUSINESS PROCESS RE-ENGINEERING
The audit has recommended comprehensive Business Process Re-engineering and Requirements Analysis, timely integration of IFMS applications and preparation of a clear roadmap for completing the remaining eight modules.
It has also called for constitution of a dedicated task force and prescribed timelines to ensure completion of the pending components.
The CAG stressed that end-users and other stakeholders should be actively involved in the design and development of the remaining modules so that the system adequately reflects operational requirements.
ADMINISTRATIVE CONTROL STILL PENDING
The audit further noted that administrative control of IFMS had not been taken over by the Director General of Accounts and Treasuries (DGAT) even after more than 12 years, leaving sensitive financial information exposed to continued institutional and security risks.
The CAG’s observations cover multiple aspects of the IFMS project, including planning, implementation, financial management, cybersecurity, data integrity, system integration, infrastructure, quality assurance, disaster preparedness and institutional accountability.
The audit has consequently called for a comprehensive corrective framework to strengthen the system, improve financial controls, protect sensitive government data and ensure timely completion and effective operationalisation of the remaining IFMS modules.(KNC)
