USA(New York)
IT-0264

RFP Description

The vendor required to provide to develop a multi-year information technology (IT) audit plan and to provide annual IT audit and advisory services, as needed, on a co-sourcing basis with internal audit.
- Requirement:
1. Development of an IT risk assessment and 5-year IT audit plan
•    Develop a detailed IT risk assessment of agency IT universe in a format agreed upon with the director of internal audit and create a five-year, risk-based IT proposed audit plan based on the risk assessment results. 
•    The methodology for assessing risk should be based on a framework that establishes criteria for risk rating using clearly defined qualitative and quantitative factors. 
•    The scope of work is expected to include reviewing, validating, and updating the existing IT risk assessment to reflect current risks and organizational changes.
•    The audit plan should define the scope, risk level, audit frequency and audit hours allocated for each audit engagement outlined. 
•    The approach used to perform the risk assessment and to develop the IT audit plan should be developed in accordance with professional internal audit guidance, including standards issued by the institute or an equivalent recognized framework. 
•    The deliverables shall include both the risk assessment and proposed audit plan.
2. IT audit services
•    Following completion of the IT risk assessment, the firm will perform annual IT audit(s) based on the IT risk assessment results and as requested by internal audit. 
•    Audit will be defined collaboratively with internal audit prior to the start of each engagement.
3. IT advisory services
•    Provide IT advisory services on an as-needed basis, which may include risk assessment support; review of audit work papers, methodologies, control design, and processes; development of recommendations; guidance on industry best practices; and on call and technical advisory support to internal audit.

- Contract Period/Term: 3 years
- Questions/Inquires Deadline: February 13, 2026

Timeline

RFP Posted Date: Wednesday, 04 Feb, 2026
Proposal Meeting/
Conference Date:
NA
NA
Deadline for
Questions/inquiries:
Friday, 13 Feb, 2026
Proposal Due Date: Friday, 27 Feb, 2026
Authority: Government
Acceptable: Only for USA Organization
Work of Performance: Remotely Work
Download Documents

Similar RFPs

CANADA(Alberta)



USA(New York)