Najwyższa Izba Kontroli NIK

Ensuring universal access to broadband internet under the Digital Poland Development Funds programme (FERC), Action 1.1

2025 PL2025broadbandAccessFERC — Categorised against INTOSAI ICS (GuidICS)
SCALE
  • 61/118 operators (51.7%) still active by end-2025
  • EU allocation cut 59%: PLN 4.5bn → PLN 1.8bn (Jul 2025)
  • 29 agreements terminated (32.2%), >PLN 1.02bn
  • Contracting: max 42 days, vs. 137 days under POPC
PERFORMANCE ASPECT

Economy

  • Flat unit-cost rates, not actual project costs

Efficiency

  • 5.9% of funds disbursed at ~60% of timeline elapsed
  • 9.7% of planned network km built

Effectiveness

  • 25.6% of address points reached; 76.5% of audited projects not yet offering service
1. Operator withdrawals cut planned coverage nearly in half ChangeBenefit

"Despite a positive evaluation of their applications for FERC funding, telecom operators frequently withdrew from project implementation after further technical, economic and legal analyses pointed to limited investment profitability [...] By the end of 2025, only 61 of the 118 operators (51.7%) whose applications had received a positive evaluation were still implementing their projects."
p.10

  • Change — Operators frequently withdrew mid-implementation after re-assessing profitability, forcing CPPC to renegotiate scope and cut the programme's EU allocation by 59% Adequate resources and competences
  • Benefit — The programme's expected benefit (universal broadband coverage) shrinks in direct proportion to the withdrawals Cost control and value for money
2. Faulty address-point data forced repeated project rescoping DataResponsibility

"Incorrect and incomplete address-point data weakened the effectiveness of FERC support [...] CPPC did not own this data, but should have identified the impact of its insufficient quality on project implementation and reported such risks to the relevant institutions."
p.11

  • Data — Address-point eligibility data comes from two external systems (PIT, SIDUSIS) outside CPPC's control, yet its quality directly determines which addresses projects must cover Reliable, integrated information base
  • Responsibility — CPPC did not own the data but, per NIK, should still have identified and reported the risk its poor quality posed
3. Low disbursement and construction lag behind contracted schedules MonitoringProcedures

"By 30 September 2025, CPPC had settled expenditure of PLN 110.6 million, i.e. 5.9% of the value of funding granted under the agreements [...] 1,530 km of the planned 15,819 km of network had been built (approx. 9.7%), and coverage had reached 20,684 of 80,706 address points (25.6%)."
p.12

  • Monitoring — Only 5.9% of granted funding had actually been disbursed against a timeline roughly 60% elapsed, a gap CPPC's own progress tracking should have surfaced earlier Functioning oversight and governance
  • Procedures — Physical build-out (9.7% of planned km) and address-point coverage (25.6%) lag the financial disbursement figures even further
4. A 2023 recommendation on unified infrastructure data still hasn't been acted on ResponsibilityGuidanceChange

"NIK notes that the findings of this audit confirm that incomplete and outdated broadband-infrastructure data [...] the recommendation addressed to the Minister of Digital Affairs following NIK's audit P/23/005 on the National Broadband Plan [...] remains valid and still unimplemented."
p.24

  • Responsibility — The Minister of Digital Affairs was the addressee of NIK's original 2023 recommendation and remains accountable for it two years on Functioning oversight and governance
  • Guidance — No updated direction was issued to fix the same infrastructure-data weakness the predecessor programme's audit had already flagged Reliable, integrated information base
  • Change — The underlying data problem recurs unchanged across two programme generations, rather than being resolved as a one-off
5. No documented check of whether existing infrastructure could be upgraded instead of newly built AnalysisGuidance

"It was established that CPPC did not have a documented analysis of the impact of this change in regulations on the intervention areas [...] and the regulatory risk associated with the amendment was not included in the risk-management system."
p.37

  • Analysis — CPPC had no documented analysis of whether a regulatory change could have been met by upgrading existing infrastructure rather than building new networks Sound risk management
  • Guidance — Absent that analysis, front-line implementation had no direction on the regulatory risk, which went untracked in the risk-management system
Which cases draw on which control elements
CASES CONTROL ELEMENTS (osie/control_ICS-AuditingIC.xml) 1 · Operator withdrawals 2 · Address-point data 3 · Disbursement lag 4 · Unimplemented 2023 recommendation 5 · No upgrade analysis Change ×2 Responsibility ×2 Guidance ×2 Analysis Benefit Data Monitoring Procedures

Change, Responsibility and Guidance each recur across two of the five findings, pointing to a shared weakness in how CPPC manages and oversees change and follow-up on prior recommendations, rather than five unrelated incidents. Standalone copy: graph/draft_broadbandAccessFERC.svg.

Control focus
ICS phase Control function Cases
Organic elements of each processChange1. Operator withdrawals cut planned coverage nearly in half
4. A 2023 recommendation on unified infrastructure data still hasn't been acted on
Data2. Faulty address-point data forced repeated project rescoping
Analysis5. No documented check of whether existing infrastructure could be upgraded instead of newly built
Initial phaseResponsibility2. Faulty address-point data forced repeated project rescoping
4. A 2023 recommendation on unified infrastructure data still hasn't been acted on
Guidance4. A 2023 recommendation on unified infrastructure data still hasn't been acted on
5. No documented check of whether existing infrastructure could be upgraded instead of newly built
Production phase (work processes)Monitoring3. Low disbursement and construction lag behind contracted schedules
Procedures3. Low disbursement and construction lag behind contracted schedules
Completion of processBenefit1. Operator withdrawals cut planned coverage nearly in half
Quality-condition frequency

Functioning oversight and governance × 2   Reliable, integrated information base × 2   Cost control and value for money × 1   Adequate resources and competences × 1   Sound risk management × 1

Compliance focus
  • EU state-aid rules.
  • Funding agreement terms (schedules, coverage targets).
  • Telecoms infrastructure reporting obligations.
  • EU cohesion-fund financial management rules.
This page presents an analysis prepared by Paweł Banaś (NIK — Najwyższa Izba Kontroli, Poland) on the basis of the publicly available report of Najwyższa Izba Kontroli (NIK), Zapewnienie powszechnego dostępu do internetu szerokopasmowego w ramach programu Fundusze Europejskie na Rozwój Cyfrowy (FERC), Działanie 1.1 (P/25/006, Warsaw, June 2026), categorised against the CUBE controlled vocabularies (osie/domains_publicActivities.xml, osie/portfolio_CUBE.xml, osie/control_ICS-AuditingIC.xml, osie/functions_organizational.xml, osie/qualityConditions.xml) and the internal-control terminology of INTOSAI's Guidance on Auditing Internal Control (ICS), drafted by the Internal Control Standards Subcommittee, which NIK (Poland) chairs. Underlying data: alg_broadbandAccessFERC.xml (dokAAPp.xsd instance). All readers are encouraged to consult the original report (linked above).