Never pay for any notarisation, certificate or assessment as part of any recruitment process. When in doubt, contact us
The World Food Programme is the food assistance branch of the United Nations and the world's largest humanitarian organization addressing hunger and promoting food security.
Assurance Objective
The objective is to provide management with reasonable, evidence-based assurance that material CP-related risks are identified and appropriately managed; key controls are suitably designed and operating as intended; compliance obligations are being met; significant findings are addressed within agreed timelines; and the Country Office maintains adequate evidence to demonstrate effective oversight to internal and external oversight bodies. The assignment will apply a risk-based approach, with assurance effort proportionate to risk exposure, funding and materiality, donor sensitivity, geographic and operational complexity, prior findings, control maturity and other relevant risk indicators.
Scope of Assurance
The assurance scope will cover CP-related governance, risk management, compliance and internal controls across the CP management lifecycle, including, as applicable:
- due diligence, capacity assessment and risk classification;
- partner selection and governance arrangements;
- financial and programme controls relevant to CP implementation;
- segregation of duties and approval controls;
- monitoring, spot checks, verification and supporting evidence;
- implementation of agreed risk mitigation measures and management actions;
- follow-up of audit, investigation, assurance and monitoring findings;
- data quality, record retention and audit trail adequacy;
- compliance with applicable WFP policies, procedures, CP management requirements and donor conditions; and
- emerging or systemic CP-related risks identified through data analysis, field work, management reporting or oversight activity.
The scope of individual reviews will be defined in an approved risk-based assurance work plan or review terms of reference. The coordinator will not provide assurance over matters for which the role has direct operational responsibility.
Key Accountabilities and Responsibilities
CP governance and internal controls
- Assess the design and operating effectiveness of key CP governance and internal control arrangements, using documented criteria and sufficient appropriate evidence.
- Identify control gaps, ineffective or inconsistently applied controls, segregation-of-duties weaknesses, recurring process failures and other control deficiencies.
- Assess whether identified controls address the relevant risks and whether control owners can demonstrate that controls operated during the period under review.
- Recommend practical corrective actions that address root causes and assignable control weaknesses.
Risk assessment and due diligence oversight
- Independently review CP due diligence, capacity assessments, risk ratings and mitigation measures for completeness, consistency, evidence and alignment with applicable requirements.
- Maintain a consolidated view of high-risk CP engagements within the assigned portfolio, including material risk exposures, mitigation status and overdue actions.
- Provide documented constructive challenge where risk assessments, ratings or mitigation plans are weak, incomplete, outdated or unsupported by evidence.
- Escalate material changes in CP risk exposure through established governance channels.
Risk-based assurance planning
- Develop and maintain a documented, risk-based CP assurance plan for the assigned Area Office portfolio, subject to management approval through established governance arrangements.
- Prioritize assurance activity using defined risk factors, including risk rating, funding/materiality, donor sensitivity, geography, operational complexity, prior audit or assurance history, control maturity and unresolved findings.
- Maintain sufficient assurance coverage of high-risk engagements and periodically reassess the plan in response to significant changes in risk exposure.
- Align CP assurance activities with the Country Office assurance plan, risk register, audit readiness priorities and relevant governance forums.
Assurance reviews, testing and independent verification
- Conduct assurance reviews, spot checks, walkthroughs, sample-based testing and independent verification for selected high-risk CP engagements or locations.
- Define the objective, scope, criteria, sampling approach, evidence requirements and review period for each assurance exercise.
- Assess evidence for relevance, reliability, completeness and traceability, and retain sufficient working papers to support conclusions.
- Document exceptions and control deficiencies clearly, including the condition observed, applicable criterion, risk/impact, root cause where established, supporting evidence and agreed management action.
- Prepare concise assurance reports with findings, risk implications, recommendations, responsible owners and agreed target dates.
Audit readiness and oversight follow-up
- Support preparedness for internal audits, external audits and CP-related oversight reviews by maintaining an up to-date evidence trail and status of material findings.
- Maintain a consolidated tracker of audit observations, assurance findings, investigation-related actions where applicable, spot-check findings and management actions.
- Validate, on a risk basis, evidence submitted to close or remediate findings before closure is reported.
- Monitor overdue, recurring or high-risk findings and escalate significant unresolved matters through established governance channels.
- Coordinate factual inputs and evidence retrieval for oversight responses without assuming management ownership of the response.
Risk monitoring, data analytics and reporting
- Analyse Partner Connect, UN Partner Portal, monitoring, audit, assurance and other available data to identify trends, anomalies, concentration risks and early warning indicators.
- Maintain a portfolio-level dashboard covering high-risk CPs, assurance coverage, material findings, overdue actions, repeat findings and audit-readiness indicators.
- Provide periodic assurance updates to management and contribute evidence-based CP risk inputs to the Country Office risk register and management briefings.
- Escalate systemic or cross-cutting control weaknesses where remediation requires management action beyond an individual CP or Area Office.
Continuous improvement
- Strengthen assurance tools, checklists, templates, sampling approaches and review methodologies based on lessons learned and emerging risks.
- Promote consistent documentation and assurance practices across Area Offices.
- Support cross-functional learning on CP risk and controls while maintaining the distinction between second-line assurance and first-line management.
Methodology and Minimum Evidence Standards
All assurance work shall be documented sufficiently to permit an independent reviewer to understand what was reviewed, against which criteria, using what evidence, with what sampling or testing approach, how exceptions were evaluated, and how the conclusion was reached.
- Each review shall have a defined objective, scope, criteria, period under review and risk rationale.
- Testing shall be risk-based and proportionate to the significance of the control and the exposure under review.
- Evidence shall be sufficiently appropriate, relevant, reliable and traceable to the conclusion reached.
- Working papers shall identify the population reviewed, sample selected where applicable, tests performed, evidence obtained, exceptions identified and conclusion reached.
- Findings shall distinguish clearly between fact/evidence, applicable requirement or control criterion, risk/impact, root cause where supported, and recommended corrective action.
- Management actions shall have a clearly identified owner and target completion date and shall be tracked to closure.
- Where evidence is insufficient to support closure or an assurance conclusion, the matter shall remain open or be explicitly qualified and escalated as appropriate.
Reporting, Escalation and Governance
The Assurance Coordinator reports functionally to the Risk and Compliance Unit and coordinates with Area Office management and relevant technical units for planning, evidence gathering and follow-up.
- Significant control deficiencies, material compliance concerns, suspected systemic weaknesses and overdue high-risk actions shall be escalated promptly through established governance channels.
- Assurance reports shall be factual, evidence-based, balanced and sufficiently documented to withstand management, audit and oversight scrutiny.
- The Coordinator shall maintain professional objectivity and shall not approve, own or implement controls that are subsequently subject to the Coordinator’s assurance assessment.
- Access to relevant records, systems, personnel and locations shall be obtained through established Country Office arrangements and in accordance with applicable confidentiality, data protection and access requirements.
- Role boundaries and independence The Assurance Coordinator will not:
- manage CP contracts or administer Field Level Agreements (FLAs);
- lead routine CP onboarding or manage day-to-day CP relationships;
- perform first-line programme, finance, supply chain, monitoring or CP management functions;
- approve CP risk ratings, management actions or control decisions on behalf of first-line owners;
- assume ownership for implementing corrective actions arising from assurance work; or
- provide assurance over controls for which the Coordinator has direct operational responsibility.
The role provides independent second-line assurance, constructive challenge, verification, reporting and escalation. Management retains responsibility for risk acceptance, control operation, corrective action and achievement of programme objectives.
Deliverables and Minimum Outputs
- Risk-Based CP Assurance Plan: approved and periodically refreshed assurance coverage for the assigned portfolio, with documented risk rationale.
- Assurance Review Reports: reports supported by documented criteria, evidence, testing, findings, root-cause analysis where established, risk implications and agreed actions.
- Quarterly CP Assurance Reports: portfolio-level assessment of key risks, control weaknesses, assurance coverage, recurring findings, overdue actions and emerging trends.
- CP Risk and Assurance Dashboard: current view of high-risk CPs, assurance coverage, material findings, overdue actions and audit-readiness status.
- Corrective Action Tracker: consolidated tracking of audit, assurance, monitoring and spot-check actions, including ownership, due dates, status and evidence of closure.
- Audit Readiness File: organized evidence trail supporting material CP assurance activities and follow-up.
- Annual CP Assurance Opinion: concise, evidence-based management assurance statement on the adequacy of CP governance, risk management and key controls within the assigned portfolio, including material limitations or qualifications where applicable
- Risk Register Inputs: documented, evidence-based CP assurance inputs for Country Office risk and assurance reporting.
Performance Indicators
- Percentage of planned risk-based assurance activities completed within the approved assurance cycle.
- Percentage of high-risk CP engagements covered by assurance in accordance with the approved plan.
- Percentage of material findings with documented owners, target dates and evidence-based closure status.
- Ageing and recurrence of overdue or repeat material findings.
- Timeliness and completeness of assurance reports and management updates.
- Percentage of sampled assurance work with complete supporting working papers and traceable evidence.
Qualifications and Experience
Education:
- Advanced university degree in risk management, internal audit, compliance, finance, accounting, governance, operations management or a related field. Relevant professional certification is desirable.
Experience:
- 5–7 years of relevant experience in assurance, audit, compliance, risk management, internal controls or oversight. Experience with NGOs, implementing partners, humanitarian operations or audit readiness is desirable.