Avis d’appel à manifestation d’intérêt pour une Assistance en matière de risques informatiques et cybernétiques pour la gestion du risque opérationnel, Abidjan, Cote d’Ivoire
REQUEST FOR EXPRESSIONS OF INTEREST
FOR AN INDIVIDUAL CONSULTANT
AFRICAN DEVELOPMENT BANK GROUP
Rue Joseph Anoma, 01 BP 1387
Abidjan 01, Cote d’Ivoire
Group Risk Management Function
Operational Risk Management Unit
Subject: Assistance in IT and Cyber Risks for Operational Risk Management
- The African Development Bank (the “Bank”) hereby invites Individual Consultants to indicate their interest to provide assistance in Information Technology (IT) and Cyber Risks in the Operational Risk Management Unit at the African Development Bank.
- The assignment is with the Operational Risk Management Unit and will entail:
- Assist the unit to proactively identify, analyze, and prioritize IT and cybersecurity risks for new and legacy systems and processes in the Bank. Review supporting documentation for IT and cyber risks and mitigation, to identify gaps and propose process and control improvements
- Contribute to IT and cyber risk awareness and sensitization on emerging risks and technologies for staff within the unit. Recommend risk areas and scenarios for consideration in the unit’s risk assessment and testing programs
- Participate in Risk and Control Self-Assessment (RCSA) sessions across the different departments of the Bank and incorporate IT and cyber risk assessment (including identification and assessment of key IT systems and controls) and Key Risk Indicators in risk registers where applicable. Propose ranking criteria to support risk and control assessments
- Contribute to IT and cyber risk incident review to analyze root causes and propose recommendations and improvement opportunities
- Contribute to ICFR process mapping, review and documentation of information systems focusing on IT General Controls (ITGC) and IT Application controls (ITACs). Support the design of risk and control matrices and test scripts for key ITGCs and ITACs which will form a basis for determining key controls to be periodically tested and the methodology for testing. Support the testing of ITGCs and ITACs for simple to complex information systems and contribute to scheduled exercises including penetration tests
- Train the operational risk unit on relevant IT controls and assessment methodologies, and key areas to look out for in second line review of IT and Cyber related policy and process documentation
- Conduct ad hoc studies and prepare presentations at the request of the Head of the Unit.
- Any other task of a similar nature assigned by the supervisor Given the aforementioned scope, the consultant is expected to demonstrate good knowledge and experience in IT and cyber risk management and practical experience in conducting information systems risk and control assessment in accordance with best practices.
Key skills necessary for this assignment include proficiency in the use of Enterprise Resource Planning (ERP) systems e.g., SAP or Oracle systems, Microsoft Office suite, strong communication skills, strong knowledge of methodologies and frameworks for IT and cyber risk identification, assessment, and mitigation, knowledge and experience with auditing principles and standards, internal control frameworks including COSO and SOX, and interest in operational risk activities. A minimum of five (5) years of professional experience in IT audit/risk management and a master’s degree in Computer Science, Accounting/Audit or related field are essential. Relevant certifications including CISA, CRISC, CISSP, CISM, ISO 27001, ISO 22301, CIA, ACCA, CIMA, CPA etc., and proficiency in both English and French will be of added advantage. The consultant will be expected to submit their technical and financial proposals.
- The Operational Risk Unit invites individual Consultants to indicate their interest in providing the above-described services. Interested Consultants shall provide information on their qualifications and experience demonstrating their ability to undertake this Assignment (CV, documents, reference to similar services, experience in similar assignments, references, etc.).
- The eligibility criteria, the establishment of a short list and the selection procedure shall be in conformity with the Bank’s Procurement Policy for Recruitment of Corporate Consultants. Please note that interest expressed by a Consultant does not imply any obligation on the part of the Bank to include him/her in the shortlist. It is expected that interested Individual Consultants shall already be registered or register in the Bank’s DACON System for consultants. The link to the relevant registration website is https://econsultant.afdb.org/
- A shortlist of three to six individual consultants will be established at the end of the request of expressions of interest.
- The estimated duration of service is six (6) months, and the estimated starting date is in second half of November 2023. The consultant will carry out the assignment remotely in line with the Bank’s current working arrangement.
- Interested Individual Consultants may obtain further information and clarifications from mensah@afdb.org during the Bank’s working hours between 8:00 to 17:00 GMT.
- Expressions of interest must be received via email to mensah@afdb.org with a copy to s.jain@afdb.org no later than 20 October 2023 (Friday) at 15:00 GMT and specifically mentioning “Assistance in IT and Cyber Risk for Operational Risk Management” in the subject of the email.

















