SLOVENIA: Audit insights from a project to modernize a core public finance information system
The Court of Audit of the Republic of Slovenia recently completed a comprehensive performance audit assessing the efficiency of the Ministry of Finance in carrying out the project to modernize the key information system supporting public finance in Slovenia, known as MFERAC. The findings shed light on the challenges of planning and managing large-scale upgrades of mission-critical public-sector information systems, where old and new systems must operate simultaneously while frequent updates are needed to support both technical changes, evolving regulatory and other requirements. This raised several audit-related challenges, including how to assess planning quality, evaluate the management of relationships with external provider, and examine whether the project is being properly managed.
About the audit
The audit considered the project of a modernization of an information system that was first introduced in 1998 and was subsequently partially upgraded many times. The audit covered the period from January 2017 to September 2025. The audited information system, MFERAC, is used, among others, for planning and managing public finances, public accounting, human resources management, and labour cost management. It is used by the entire state-level public administration, as well as by judicial authorities and many other public-sector entities. The information system has more than 6,000 users. To carry out the modernization project, the Ministry conducted four public tenders and concluded four contracts with the same external provider for modernization and maintenance of information system.

Findings: Strengths and Gaps
The Court of Audit found that the Ministry was partially efficient in carrying out the modernization project. The audit showed that the project was, at least to some extent, based on adopted strategic documents. However, the project objectives were not defined in a measurable way, and the Ministry selected an option expected to be more cost-efficient but associated with higher risks, without sufficiently defining how these risks would be managed. The audit also found that time and cost planning were not based on a clearly defined methodology.
A key finding concerns the management of contractual relationships in outsourced development. The Ministry ordered a certain number of programming hours, but the contracts did not clearly define what the provider had to deliver within those hours. The content of individual deliverables, the required number of hours, and the related price were determined later through individual orders. In practice, the external provider usually estimated the required number of programming hours, while the Ministry’s ability to reject orders was limited, especially in cases where changes were necessary for legal compliance or further project implementation.

The audit also identified challenges in project governance and scope control. The project content evolved through individual orders, increasing the risk of scope creep. At the same time, the Ministry did not fully ensure the achievement of all project objectives and did not manage financial resources and time efficiently.
By the end of the audited period, the modernization project had not yet been completed, and some important updates remained unimplemented. Its planned value increased from less than EUR 9 million to EUR 28 million, while the planned completion date was postponed from 2020 to 2027.
Despite the shortcomings mentioned above, the audit also recognised positive elements. The Ministry established appropriate administrative controls and quality control over delivered programme solutions. In addition, the Ministry implemented some improvement measures during the audit process. To enhance efficiency, the Court of Audit provided the Ministry with several recommendations, including recommendations on project management, scope control, and reducing dependency on the external provider.
For peer auditors, the case highlights the importance of examining not only whether an IT project has a formal strategy and procurement procedure, but also whether objectives are measurable, risks are actively mitigated, relationships with external providers is being properly managed, and scope, cost and time remain under effective control throughout implementation.
Full report (in Slovene language):
Link to English infographics: