Closed tender

RM1043.8-1-National Audit Office-IT Audit automation

Details

Value
GBP 25,000
Published
3 August 2023
Submission
22 September 2023

Tender description

About adding context and requirements test Pre-market engagement We have not undertaken any in depth market engagement. Work done so far We have spoken to individual suppliers of data enabled audit automation tools and so have awareness that the automated tools we are seeking to procure are available in the market place. Which phase the project is in Alpha Existing team Mark Burford (the lead for this procurement), Senior IT Audit Manager, National Audit Office Aftab Ayoob, Senior IT Audit Manager, National Audit Office; Ayo Adekeye, Senior IT Audit Manager, National Audit Office Tasha Lawrence, Audit Technology Services Manager, National Audit Office Dave Timmins, Head of Financial Audit Technology, National Audit Office Address where the work will be done The selected supplier shall be required to perform the Services at its own premises and at the NAO’s offices in London and/or Newcastle as required. The selected supplier may/ will be required to travel to, and sometimes perform the Services at, locations throughout the UK and occasionally outside the UK. The NAO's London Office is at: 157-197 Buckingham Palace Road, London SW1W 9SP The NAO's Newcastle Office is at: Floor 4, The Spark, Drayman’s Way, Newcastle Helix, Newcastle upon Tyne, NE4 5DE​​​​ Working arrangements Hybrid. Our staff work in the office a minimum of 2 weekday per week. The prospective supplier should be prepared to work in office or remotely as needed and to cover their own expenses within any fees. Provide more information about your security requirements: Baseline Personnel Security Standard (BPSS) Provide more information about your security requirements: Counter Terrorist Check (CTC) Provide more information about your security requirements: Security Check (SC) Provide more information about your security requirements (optional): The selected supplier working onsite with us will need BPSS clearance. For some aspects of the work that might require sight of data from our audited bodies SC clearance may be needed. Latest start date 2024-01-31 Enter the expected contract length: 1 year Extension period: 6 months Write the term or acronym: NAO Write the term or acronym: GITC Write the term or acronym: ERP Explain the term or acronym: National Audit Office Explain the term or acronym: General IT Controls Explain the term or acronym: Enterprise Resource and Planning Are you prepared to show your budget details?: Yes Indicative maximum: 40000 Indicative minimum: 10000 Provide further information: We have a maximum annual budget for this tool of £40,000 (net of VAT) to cover licence, training, support and additional consultancy costs. We request new funding annually but cannot guarantee funding will be provided. This is a pilot and success will inform future funding Confirm if you require a contracted out service or supply of resource Supply of resource: the off-payroll rules may apply Summary of work Scope of the requirement A method to extract data in to a standard format from the following ERP systems to which the NAO does not have remote or direct access as a matter of course, with access being usually via a client representative with privileged access: • SAP ECC • SAP Hana • Oracle EBS • Oracle Fusion • Workday Data types to include: User data to enable a “can-do” and if required a “did do” segregation of duties analysis on roles and users for standard business processes such as • Purchase to pay • Order to cash • Record to report • Hire to retire User data to enable the identification and evaluation of user / privileged user access across relevant levels to include as appropriate for ERPs • Profiles • Roles • Authorisation objects / activity levels • T-codes • Security groups • Users • Privileges • Entitlements Configuration data for activity based controls / business process controls and general IT control environment to include but not limited to: • Password configuration • Table / audit logging • Matching configuration • Tolerance configuration • Requisition / PO approval configurations • Supplier creation default configurations Once data is obtained in a standard format, a method to rapidly analyse that data in-tool and present to the auditor an overview / dashboard to help the auditor identify areas for further investigation. A configurable scoring system may help here. Ability to download the data to e.g. MS Excel for further analysis as required. Following analysis, recommendations for what the auditor should follow up on. Configurable reporting for ease of inclusion on the audit file. The supplier will either offer a SaaS solution that meets the NAO InfoSec Team’s requirements, or shall offer an “on premise” (to the NAO’s MS Azure tenant) install which will inherently meet our security requirements. Maintenance / backups Any tools installed will be maintained by the supplier to ensure they remain current with security patching and with changes in the ERP systems the tool is analysing. The supplier will be responsible for supplying and deploying (under NAO supervision) any tools and updates / patches to our dev and test environments. The NAO (under supplier supervision) will be responsible for deploying tools and updates / patches to any “live” system that being systems that contain client data once obtained. On backups – the tool shall be able to have its code, configuration and data backed up periodically and automatically on a weekly basis in to a Test environment. Azure Backup will be ideally the method for this. Backups will conform to NAO data retention schedules. Security • Any tooling shall have username and password access and shall only be accessible by NAO employees using NAO infrastructure. • No access will not be permitted via means other than a Private Endpoint configuration. • Deployment on the NAO’s MS Azure PaaS Platform to ensure inheritance of MS Azure security settings and policies. • Data should be encrypted at rest. • Data shall never leave the tool / MS Azure environment and so all automated / semi-automated external communication links in to or outgoing from the tool shall be terminated / removed with the only access being instigated by the user to upload and download client data from a local machine / machine on the NAO network. • Possibility to move to SSO (using SAML) in the future. We (the NAO) expect to have access to support, guidance and training as required so will conduct periodic meetings between the supplier and the NAO for general feedback and to continue a positive working relationship. Where the supplied staff will work North East England Where the supplied staff will work London Where the supplied staff will work No specific location (for example they can work remotely) Why the work is being done This procurement is part of our long term aim of automating our detailed IT audit testing, with the ambition to deliver greater quality, efficiency, value and insight from our work The business problem you need to solve We are seeking to automate to process of testing IT Application and supporting General IT Controls including segregation of duties testing to allow us to test the whole population of users rather than the current process of testing a sample of items. The expectation is that an automated process will increase the quality, efficiency, value and insight derived from the testing of these controls enabling us to cover more audited bodies with the same human resource. First user type: IT Auditor First user type: IT Auditor Enter more details about this user type: IT Auditor: As an IT Auditor I need to be able to extract and analyse configurations in ERP systems, specifically around access controls such as password configurations, user roles, privileges, entitlements and how those may cause segregation of duties conflicts, so that I can obtain more efficiently and completely assurance over the configuration of accesses within the ERP solution. Enter more details about this user type: IT Auditor: As an IT Auditor, I need to be able to extract and analyse configurations in ERP systems, specifically around configurations of standard business processes e.g. purchase to pay, in order that I can assess those configurations without needing to obtain them directly by observation in the ERP solution itself.

Timeline

  1. Completed: Tender published3 August 2023
    Current notice
  2. Completed: Submission date22 September 2023

About the buyer

National Audit Office is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

Related topics

Topics related to RM1043.8-1-National Audit Office-IT Audit automation, ranked by notice volume.

View all topics

Related buyers

Buyers similar to National Audit Office.

View all buyers

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.