World Food Programme

Non-profit + 1 more

Programme Policy Officer Assurance Coordinator CST II

Job details

Contract Type

Description

Qualifications and Experience

Education:

  • Advanced university degree in risk management, internal audit, compliance, finance, accounting, governance, operations management or a related field. Relevant professional certification is desirable.

Experience:

  • 5–7 years of relevant experience in assurance, audit, compliance, risk management, internal controls or oversight. Experience with NGOs, implementing partners, humanitarian operations or audit readiness is desirable.


Key Accountabilities and Responsibilities

CP governance and internal controls

  • Assess the design and operating effectiveness of key CP governance and internal control arrangements, using documented criteria and sufficient appropriate evidence.
  • Identify control gaps, ineffective or inconsistently applied controls, segregation-of-duties weaknesses, recurring process failures and other control deficiencies.
  • Assess whether identified controls address the relevant risks and whether control owners can demonstrate that controls operated during the period under review.
  • Recommend practical corrective actions that address root causes and assignable control weaknesses.

Risk assessment and due diligence oversight

  • Independently review CP due diligence, capacity assessments, risk ratings and mitigation measures for completeness, consistency, evidence and alignment with applicable requirements.
  • Maintain a consolidated view of high-risk CP engagements within the assigned portfolio, including material risk exposures, mitigation status and overdue actions.
  • Provide documented constructive challenge where risk assessments, ratings or mitigation plans are weak, incomplete, outdated or unsupported by evidence.
  • Escalate material changes in CP risk exposure through established governance channels.

Risk-based assurance planning

  • Develop and maintain a documented, risk-based CP assurance plan for the assigned Area Office portfolio, subject to management approval through established governance arrangements.
  • Prioritize assurance activity using defined risk factors, including risk rating, funding/materiality, donor sensitivity, geography, operational complexity, prior audit or assurance history, control maturity and unresolved findings.
  • Maintain sufficient assurance coverage of high-risk engagements and periodically reassess the plan in response to significant changes in risk exposure.
  • Align CP assurance activities with the Country Office assurance plan, risk register, audit readiness priorities and relevant governance forums.

Assurance reviews, testing and independent verification

  • Conduct assurance reviews, spot checks, walkthroughs, sample-based testing and independent verification for selected high-risk CP engagements or locations.
  • Define the objective, scope, criteria, sampling approach, evidence requirements and review period for each assurance exercise.
  • Assess evidence for relevance, reliability, completeness and traceability, and retain sufficient working papers to support conclusions.
  • Document exceptions and control deficiencies clearly, including the condition observed, applicable criterion, risk/impact, root cause where established, supporting evidence and agreed management action.
  • Prepare concise assurance reports with findings, risk implications, recommendations, responsible owners and agreed target dates.

Audit readiness and oversight follow-up

  • Support preparedness for internal audits, external audits and CP-related oversight reviews by maintaining an up to-date evidence trail and status of material findings.
  • Maintain a consolidated tracker of audit observations, assurance findings, investigation-related actions where applicable, spot-check findings and management actions.
  • Validate, on a risk basis, evidence submitted to close or remediate findings before closure is reported.
  • Monitor overdue, recurring or high-risk findings and escalate significant unresolved matters through established governance channels.
  • Coordinate factual inputs and evidence retrieval for oversight responses without assuming management ownership of the response.

Risk monitoring, data analytics and reporting

  • Analyse Partner Connect, UN Partner Portal, monitoring, audit, assurance and other available data to identify trends, anomalies, concentration risks and early warning indicators.
  • Maintain a portfolio-level dashboard covering high-risk CPs, assurance coverage, material findings, overdue actions, repeat findings and audit-readiness indicators.
  • Provide periodic assurance updates to management and contribute evidence-based CP risk inputs to the Country Office risk register and management briefings.
  • Escalate systemic or cross-cutting control weaknesses where remediation requires management action beyond an individual CP or Area Office.

Continuous improvement

  • Strengthen assurance tools, checklists, templates, sampling approaches and review methodologies based on lessons learned and emerging risks.
  • Promote consistent documentation and assurance practices across Area Offices.
  • Support cross-functional learning on CP risk and controls while maintaining the distinction between second-line assurance and first-line management.

Methodology and Minimum Evidence Standards

All assurance work shall be documented sufficiently to permit an independent reviewer to understand what was reviewed, against which criteria, using what evidence, with what sampling or testing approach, how exceptions were evaluated, and how the conclusion was reached.

  • Each review shall have a defined objective, scope, criteria, period under review and risk rationale.
  • Testing shall be risk-based and proportionate to the significance of the control and the exposure under review.
  • Evidence shall be sufficiently appropriate, relevant, reliable and traceable to the conclusion reached.
  • Working papers shall identify the population reviewed, sample selected where applicable, tests performed, evidence obtained, exceptions identified and conclusion reached.
  • Findings shall distinguish clearly between fact/evidence, applicable requirement or control criterion, risk/impact, root cause where supported, and recommended corrective action.
  • Management actions shall have a clearly identified owner and target completion date and shall be tracked to closure.
  • Where evidence is insufficient to support closure or an assurance conclusion, the matter shall remain open or be explicitly qualified and escalated as appropriate.

Reporting, Escalation and Governance

The Assurance Coordinator reports functionally to the Risk and Compliance Unit and coordinates with Area Office management and relevant technical units for planning, evidence gathering and follow-up.

  • Significant control deficiencies, material compliance concerns, suspected systemic weaknesses and overdue high-risk actions shall be escalated promptly through established governance channels.
  • Assurance reports shall be factual, evidence-based, balanced and sufficiently documented to withstand management, audit and oversight scrutiny.
  • The Coordinator shall maintain professional objectivity and shall not approve, own or implement controls that are subsequently subject to the Coordinator’s assurance assessment.
  • Access to relevant records, systems, personnel and locations shall be obtained through established Country Office arrangements and in accordance with applicable confidentiality, data protection and access requirements.
  • Role boundaries and independence The Assurance Coordinator will not:
    • manage CP contracts or administer Field Level Agreements (FLAs);
    • lead routine CP onboarding or manage day-to-day CP relationships;
    • perform first-line programme, finance, supply chain, monitoring or CP management functions;
    • approve CP risk ratings, management actions or control decisions on behalf of first-line owners;
    • assume ownership for implementing corrective actions arising from assurance work; or
    • provide assurance over controls for which the Coordinator has direct operational responsibility.

The role provides independent second-line assurance, constructive challenge, verification, reporting and escalation. Management retains responsibility for risk acceptance, control operation, corrective action and achievement of programme objectives.


Start hiring with Fuzu

Recruit better talent faster - on your own or with our support.

Explore recruitment platform

Don’t miss your chance to work at World Food Programme. Enter your email to start your application now