Wagwago Business Group logo

TERMS OF REFERENCE (ToR) of Information Technology Audit, Cybersecurity Assurance and Digital Transformation Readiness Assessment Services

Wagwago Business GroupBole

On-siteContractBoleSenior(5-8 years)

Experience

Senior(5-8 years)

Salary

Not specified

Posted

about 5 hours ago

Deadline

in about 1 month

Job Description

  1. Purpose and Objectives

1.1. Overall Objective

The overall objective is to provide independent and professional assurance on the adequacy, effectiveness and maturity of WBG's technology governance, risk management, internal controls, cybersecurity, operational resilience and digital transformation readiness, and to recommend practical improvements aligned with the Group's strategic objectives.

1.2 Specific Objectives

  • Assess IT governance, strategic alignment, accountability, technology investment governance and technology risk management.
  • Evaluate the design and operating effectiveness of IT general controls and key business application controls.
  • Assess cybersecurity governance, preventive and detective controls, vulnerability management, incident response and cyber resilience.
  • Evaluate data governance, privacy, technology infrastructure, cloud services, business continuity and disaster recovery.
  • Assess third-party technology risks and, where applicable, industrial control and operational technology (ICS/OT) environments.
  • Assess the governance, implementation readiness, enterprise architecture, organizational capability and risk management arrangements supporting WBG's Digital Transformation Strategy.
  • Establish a practical digital and technology maturity baseline and identify priority improvement actions.
  • Provide risk-based recommendations and knowledge transfer that strengthen WBG's continuing IT assurance capability.
  1. Scope of the Assignment

The consultant shall perform a Group-wide, risk-based assessment covering WBG and its subsidiaries. The final depth of testing shall be agreed during inception based on materiality, risk, system criticality and available evidence.

2.1 IT Governance and Technology Risk

  • IT strategy and alignment with corporate objectives; governance structures, roles and accountability; policies and standards; resource and investment governance; project/portfolio oversight; performance measurement; and technology risk management.
  • Enterprise technology risk profile covering cybersecurity, infrastructure, applications, cloud, data, third parties, business continuity, emerging technology and digital transformation risks.

2.2 IT General Controls, Infrastructure and Resilience

  • Identity and access management, privileged access, segregation of duties and periodic access review.
  • Change and configuration management, system development lifecycle controls and IT operations.
  • Servers, networks, storage, operating systems, databases, virtualization, backup, recovery, availability and disaster recovery arrangements.
  • Cloud governance, architecture, security, data protection, service arrangements and shared-responsibility controls, where applicable.

2.3 Business Applications and Data

Significant applications may include ERP, courier and delivery platforms, freight and fleet systems, production systems, learning management systems, taxi applications, point-of-sale systems, CRM and e-commerce platforms.

  • Input, processing, output, interface, workflow, master-data, audit-trail, configuration and application-security controls.
  • Data ownership and stewardship, quality, classification, retention, protection, privacy, records management and backup.

2.4 Cybersecurity Assurance

  • Cybersecurity governance, strategy, policies, roles and reporting.
  • Identity and access security, network and endpoint security, remote access and email security.
  • Vulnerability and patch management, security monitoring, threat detection, incident response, user awareness and cyber resilience.
  • Technical testing, including vulnerability assessment, configuration review, security architecture review or penetration testing, only where expressly approved by WBG.

2.5 Third-Party and Operational Technology Risk

  • Technology vendor due diligence, contractual safeguards, service levels, security requirements, access, performance monitoring and exit arrangements.
  • Where applicable, ICS/OT governance and security, including production control systems, PLC environments, network segmentation, remote vendor access, backup, availability, safety and production continuity.

2.6 Digital Transformation Readiness and Maturity

  • Alignment of the Digital Transformation Strategy with WBG's corporate objectives and expected business value.
  • Digital governance, executive oversight, program and project governance, investment prioritization and benefits realization.
  • Current and target enterprise architecture, integration, interoperability, scalability and technology portfolio governance.
  • Cybersecurity-by-design, privacy, data and analytics capability, organizational change, workforce readiness, training and adoption.
  • Digital maturity across agreed domains, with current-state assessment, material gaps, target maturity and prioritized improvement roadmap.
  • Where applicable, governance and risks relating to AI, machine learning, IoT, robotic process automation, advanced analytics and other emerging technologies, including human oversight, ethical use, data quality and cybersecurity implications.

2.7 Data Analytics and Technology-Enabled Audit

The consultant shall use data analytics and technology-enabled audit techniques where appropriate, including access analysis, log and configuration analysis, exception reporting, transaction testing, trend analysis and anomaly detection.

  1. Audit Approach, Methodology and Standards

3.1 Methodology

The engagement shall follow a structured, risk-based, evidence-based and systems-oriented approach. At a minimum, it shall comprise:

  • Planning and inception: understand WBG's business and technology environment, confirm scope, information requirements, resources, timetable and communication arrangements.
  • Risk assessment: identify and prioritize significant technology and transformation risks and refine the detailed audit procedures.
  • Fieldwork and testing: perform document review, interviews, walkthroughs, observation, configuration review, sampling, control testing, data analytics and other approved technical procedures.
  • Evaluation and validation: assess governance, control design and operating effectiveness, maturity, compliance and risk exposure; validate factual accuracy with responsible management without compromising independent professional judgment.
  • Reporting: communicate significant matters promptly, issue draft findings for management response, and submit consolidated draft and final reports to the Chief IA&BA.
  • Knowledge transfer: share key methodologies, lessons and priority capability-building actions with the IA&BA team.and does not transfer IA&BA's accountability or management's responsibilities.

Requirements

The consultant shall apply relevant current editions of internationally recognized standards and good practices, as applicable to the agreed scope, including:

  • IIA Global Internal Audit Standards and relevant IIA guidance;
  • COBIT and ISO/IEC 38500 for IT governance;
  • ISO/IEC 27001 and 27002, NIST Cybersecurity Framework and CIS Critical Security Controls for information security;
  • ITIL for IT service management;
  • ISO 22301 for business continuity;
  • Cloud Security Alliance guidance and relevant cloud-provider good practices;
  • DAMA-DMBOK and applicable data protection/privacy requirements;
  • recognized guidance for AI and emerging-technology governance and risk management; and
  • applicable Ethiopian laws, regulations, directives, contractual obligations and WBG policies.

Consultant Qualifications and Team Requirements

Interested firms shall demonstrate sufficient institutional capacity and relevant experience to perform the assignment. At a minimum, the firm should have:

  • at least seven years of relevant experience in IT audit, cybersecurity assurance, technology risk or closely related consulting;
  • proven experience with enterprise-wide IT audits for large organizations or diversified business groups;
  • demonstrated capability in IT governance, cybersecurity, ERP/application controls, ITGC, cloud, data governance, digital transformation and technology risk management;
  • relevant experience in manufacturing, logistics, transport, trading or comparable environments as an advantage; and
  • access to appropriate specialists for ICS/OT, cloud, cybersecurity, data and emerging technologies where required.

The proposed team should include professionals holding relevant internationally recognized certifications such as CISA, CISM, CISSP, CRISC, CIA, COBIT-related credentials and/or ISO/IEC 27001 Lead Auditor, or equivalent qualifications appropriate to their assigned roles.

Proposal Submission Requirements

Technical Proposals

  • understanding of the assignment and proposed risk-based methodology;
  • work plan, schedule and team composition, including CVs of key personnel;
  • relevant institutional and sector experience with references from comparable assignments;
  • quality assurance, engagement risk management and knowledge-transfer approach; and
  • any proposed scope assumptions, dependencies or exclusions.

Financial Proposal

  • professional fees and reimbursable expenses, if any;
  • applicable taxes;
  • proposed payment schedule; and
  • proposal validity period.

Technical and financial proposals shall be submitted separately in the form specified by WBG's procurement process.

Evaluation and Award

Technical proposals shall be evaluated using the following indicative criteria, subject to the final Request for Proposal (RFP):

Evaluation Criterion

Weight

Understanding of the assignment

15%

Methodology and approach

20%

Relevant institutional experience

20%

Qualifications and experience of key personnel

25%

Work plan and project management

10%

Knowledge transfer approach

5%

Quality assurance approach

5%

Only firms achieving the minimum technical score specified in the RFP shall proceed to financial evaluation. Award shall follow WBG's Procurement Policy, taking into account technical quality, cost-effectiveness and overall value for money.

Required Skills

Strong attention to detail and accuracyInternal audit & controlsAudit Reporting

Level

Senior(5-8 years)

Location

Bole

How to Apply

Application Submission Requirements

Interested individuals or entities should submit the following items before COB 21 September 2026:

  • Technical Proposal: Highlighting understanding of the task, detailed methodology, and operational work plan.
  • Financial Proposal: All-inclusive breakdown of professional fees corresponding to deliverables.
  • Curriculum Vitae (CV): Detailed professional resumes and copy of credentials.
  • References: Proof of at least two people who vouches for the character or a guide used to find information.

 How to Apply

Interested applicants can submit in person or send by email the technical and financial proposals separately with other supporting documents to WWBG HQ within 15 days of this announcement to the following address:

Addis Ababa, Ethiopia

Bole sub city, Woreda 03, Bole Medhanialem Church – Atlas Hotel Road,

Century Executive Building, 7th Floor

Mobile: +251 99 898 3309

Email: wagwagohr@gmail.com

TERMS OF REFERENCE (ToR) of Information Technology Audit, Cybersecurity Assurance and Digital Transformation Readiness Assessment Services at Wagwago Business Group | HojiiNet