- JCF had no IT plan despite technology modernization as stated priority.
- Ministry of Finance lacked an IT Security Manager for critical systems.
- JIS website defacements occurred with no formal incident response plan.
- Privileged user accounts went unmonitored across all three institutions.
- IT policies at government broadcaster existed only in unapproved drafts.
- JIS Computer Services revenue grew 46.7% without matching governance.
Read the full audit report from the Auditor General’s Department →
An audit by Auditor General Pamela Monroe Ellis revealed that three of Jamaica’s most sensitive public institutions — the Jamaica Constabulary Force, the Jamaica Information Service, and the Ministry of Finance and the Public Service — operated for years without the basic information technology safeguards that protect citizens’ data, national financial systems, and public communications infrastructure. The findings, covering the period April 2013 to March 2017, raise profound questions about how government institutions entrusted with the most sensitive information in the country were allowed to accumulate governance deficits of this magnitude without intervention.
When a Jamaican citizen files a police report, pays taxes online, or watches a government broadcast, they are trusting that the institutions behind those services are protecting their personal data with rigour. An Information Technology Audit Report published by the Auditor General of Jamaica in January 2019 suggests that trust was misplaced for years — and that three of the country’s most consequential public entities were operating with IT governance frameworks so thin that they would not meet the baseline requirements of any credible international standard.

The report examined the Jamaica Constabulary Force, the Jamaica Information Service, and the Ministry of Finance and the Public Service across four consecutive financial years, from 2013/2014 through 2016/2017. What the Auditor General, Pamela Monroe Ellis, found was not a matter of isolated technical shortcomings. What she found was a systemic, institution-wide failure of leadership to treat information technology as a serious governance responsibility — at precisely the time when Jamaica’s public sector was deepening its reliance on digital systems to deliver core services.
The Jamaica Constabulary Force stands as perhaps the most striking example. The JCF is Jamaica’s national police service, responsible for maintaining law and order across a country of nearly three million people. It holds some of the most sensitive personal data in the public sector — records of arrests, criminal investigations, witness information, intelligence files. And yet the audit found that the JCF had no IT Oversight Committee, no formal IT Strategic Plan, and no detailed IT risk assessment to identify vulnerabilities in its systems. This is not a question of budgetary constraints preventing cutting-edge cybersecurity tools. These are foundational governance documents — policies, plans, and committees — that cost relatively little to establish and that every credible security framework in the world treats as non-negotiable starting points.
What makes the JCF finding especially difficult to accept is the Force’s own stated priorities. Technology modernization appeared as a declared objective within the JCF’s institutional agenda during the audit period. The organization acknowledged it wanted to use technology to become more effective. And yet no formal plan was produced to govern that technology. Privileged user accounts — the accounts held by system administrators with the highest level of access to sensitive data — were left unmonitored. No formal security training program existed for staff. No independent IT reviews were commissioned to test whether the controls that did exist were actually working. The gap between stated ambition and operational reality was, in the Auditor General’s findings, absolute.
Management at the JCF accepted the findings. In response, they committed to establishing an ICT Steering Committee, though that commitment was deferred to January 2019 — meaning the institution asked for and received years of additional time to form a committee that many private sector companies of far smaller size already operate as a matter of course. Whether that committee was ultimately constituted, and whether it has since driven meaningful change, is a question that deserves continued public scrutiny.
The picture at the Jamaica Information Service carries its own distinct urgency. The JIS is the government’s official public communications agency — the body responsible for managing and distributing official information on behalf of the Jamaican state. Its digital presence is not peripheral to its mandate; it is central to it. And the audit found that the JIS had IT policies that existed only in draft form, had never received formal approval, and in many cases were significantly outdated. A policy framework that lives permanently in draft is, functionally, no policy framework at all. It cannot be enforced, audited, or used as a standard against which staff behaviour can be measured.
Most seriously, the JIS had a documented history of website defacements — incidents in which external actors had broken into the agency’s digital infrastructure and altered its content. That a government communications body had experienced such breaches and yet had no formal security incident response system in place by the time of the audit is a governance failure of a high order. Incident response planning is the basic mechanism by which an organization understands what to do when something goes wrong: who to call, what to isolate, how to restore service, how to document the breach, and how to prevent recurrence. Without it, each incident is addressed reactively, inconsistently, and with no institutional learning.
IT risk assessments at the JIS were described as informal. Independent internal audit reviews were absent because of staffing limitations. Privileged user activities went unmonitored. And all of this occurred during a period in which the JIS Computer Services division was generating growing commercial revenue — rising from $5.85 million in the 2013/2014 financial year to $10.01 million in 2016/2017, a 46.7 percent increase in the final year alone. The JIS was growing its technology-based revenue streams while simultaneously failing to build the governance infrastructure necessary to protect those very systems from compromise. In response to the audit, the JIS hired a Chief Internal Auditor in 2018, installed software to monitor administrator activities, and committed to conducting a formal IT risk assessment by the 2019/2020 financial year.
The findings at the Ministry of Finance and the Public Service carry perhaps the highest potential consequence of all three. The Ministry oversees multiple large-scale government financial systems — platforms through which public funds are managed, processed, and disbursed. Its Information Systems Unit comprised 22 members at the time of the audit. And yet that unit operated without a designated IT Security Manager and without clearly defined security responsibilities across its staff. The audit found no comprehensive IT risk assessment had been conducted and no formal security awareness training program existed.
For ordinary Jamaicans, the Ministry of Finance is not an abstract bureaucracy. It is the institution that manages government payroll, oversees budget allocations that determine whether roads get repaired or schools get built, and administers the financial systems through which public money flows. A compromise of those systems — whether through malicious intrusion or internal misuse — could have consequences that cascade across every area of public life. The absence of a single designated IT Security Manager in an organization managing systems of this sensitivity is not a minor administrative oversight. It is a fundamental structural gap.
The Ministry’s management accepted the audit findings. It committed to recruiting an IT Security Specialist, subject to post approval, and to formalizing a security awareness training program by the 2018/2019 financial year. The dependency on post approval as a precondition for filling a critical security role raises its own question: if the risk was real and acknowledged, why was it allowed to remain contingent on a bureaucratic process rather than addressed as a matter of priority?
Looking across all three institutions, the Auditor General identified a set of failures that were not unique to any single entity but were present in each one to varying degrees. None had functioning IT oversight committees connecting technology strategy to business objectives. None had mature, formal risk management procedures. None had clearly defined and documented information security roles. None had adequate monitoring of administrator accounts. And none had implemented structured user security awareness programs. These are not exotic requirements drawn from the cutting edge of cybersecurity practice. They are the foundational building blocks of any responsible IT governance framework and have been so for decades.
The human cost of these failures is not always visible in the immediate term, but it accumulates. Citizens who interact with government systems — registering property, paying duties, accessing social services, filing reports — have a reasonable expectation that their data is handled with care. Businesses that depend on government digital platforms for compliance, procurement, or financial processing take on unacknowledged risk when the systems they rely on have not been properly assessed, secured, or monitored. And when government systems are defaced, breached, or otherwise compromised, the damage to public trust in institutions is corrosive and lasting.
The recommendations of the Auditor General were clear. All three entities were directed to implement comprehensive IT governance frameworks aligned with their institutional objectives, establish formal Information Security Management Systems supported by detailed risk assessments, create executive-level IT oversight committees, develop and formally approve IT policies and strategic plans, introduce structured user security awareness training, and deploy monitoring controls for administrator activities. All three management teams accepted the findings and offered implementation commitments. But acceptance is not implementation, and timelines set in a government audit response do not guarantee delivery.
What this audit ultimately reveals is a pattern that repeats across Jamaica’s public sector: institutions acknowledge the importance of governance, state their intentions in formal responses to oversight bodies, and then operate on timelines that stretch the definition of urgency. The Auditor General’s office can identify the problem. It can make the recommendation. It cannot compel the pace of change. That compulsion must come from political leadership, from institutional heads, and ultimately from a public that understands what is at stake and demands accountability when commitments are not met.
The three entities examined in this audit are not marginal to public life. They are the national police force, the government’s public information arm, and the ministry that oversees the country’s finances. If Jamaica’s digital future is to rest on a secure foundation, the question raised by this report is not whether stronger IT governance is needed — all parties agreed that it is — but whether the institutions responsible for delivering it have the will, the resources, and the accountability mechanisms to follow through. The Auditor General has done her part. The audit record now belongs to the public.
Jamaica Accountability Watch is an independent editorial series by Jamaica Homes News examining what government audit reports reveal about the management of public money. Source: Auditor General’s Department of Jamaica.
Follow Jamaica Homes on Youtube @jamaicahomes and Instagram @jamaica_homes and on Facebook @jamaicahomesnews Send us a message or email us at onlinefeedback@jamaica-homes.com or editor@jamaica-homes.com


Visit our YouTube Community ↗