Romania – Auditing services – Technical and financial auditing services within the “Migration of applications and information systems to the cloud (MAS IC)” project
The subject of the procurement concerns technical and financial auditing services. The subject of this procurement is the provision of technical and financial auditing services within the “Migration of applications and information systems to the cloud
Opportunity description
The subject of the procurement concerns technical and financial auditing services. The subject of this procurement is the provision of technical and financial auditing services within the “Migration of applications and information systems to the cloud (MAS IC)” project, financed through the National Recovery and Resilience Plan (PNRR). For LOT 1 - Technical auditing services: The requested services consist of auditing the activities of the MAS IC Project from a technical perspective, for the purpose of meeting the auditing requirements provided for in the PNRR Institutional Development Framework (CID) and in the Operational Arrangements. Specific objective: Obtaining the necessary assurance that the technical specifications of the migrated applications are consistent with the description of the investment in the analysis prepared under milestone 143 and in the Council Implementing Decision, and that the ICT technical requirements provided for in the funding application and tender specifications are fully met through the implementation of the activities for which expenditure is claimed by the Beneficiary in the Transfer Requests (CT) / Statements of Use of Transfer Requests for the investment financed under the MAS-IC Project. For LOT 2 - Financial auditing services: The requested services consist of auditing all expenditure and activities of the MAS IC project. Specific objective: Verification by the Financial Auditor that the amounts claimed by the Beneficiary in the Transfer Requests (CT) / Statements of Use of Transfer Requests for the investment financed under the MAS-IC Project relate to expenditure that was actually incurred and is evidenced by original documents, and is legal, accurate and eligible. Tenders must be submitted for: 2 lots. Maximum number of lots that may be awarded to a single tenderer: 2 Tenderers may submit a tender for one or more lots. Provisions applicable only to lot 1: To avoid a potential conflict of interest, the Contracting Authority does not allow economic operators having the status of prospective service providers, signatories to the framework agreement awarded under the public procurement procedure initiated through CN1077543, to participate as tenderers for lot 1 under this public procurement procedure. Furthermore, the Contracting Authority does not allow economic operators that will have the status of prospective service providers, signatories to the framework agreement to be awarded under the public procurement procedure initiated through CN1083774, also to have the status of prospective service providers for lot 1 under this public procurement procedure. The subject of the Framework Agreement/subsequent contracts to be concluded under Lot 1 consists of the provision of technical auditing services, namely auditing the activities of the MAS IC Project from a technical perspective, for the purpose of meeting the auditing requirements provided for in the PNRR CID and in the Operational Arrangements. The Contracting Authority will provide potential Service Providers with information regarding the applications/information systems to be audited in the Invitation to Sign the Subsequent Contract that will be sent for the purpose of awarding a Subsequent Contract. The technical auditor will be required to familiarize themselves with the entire project documentation and will present opinions on all technical deliverables falling within the scope of the Transfer Request for which the audit is being conducted. The technical audit engagement will be conducted both on the technical documentation and on site, where applicable. The contracting authority defines the complexity of the technical audit reports according to their scope. Technical auditing services constitute the activity of collecting and evaluating the necessary and sufficient evidence to determine whether: ▶ the migration of the application/information system was carried out according to the established strategy and the obligations undertaken under the migration services contract were complied with; ▶ the application/information system is operational and the functionalities specific to the government cloud are being used in full; . ▶ the configurations relating to interoperability between the application/information system and other systems of the institution that owns the migrated application/system or, as applicable, with other institutions with which the migrated system exchanges data, have been correctly implemented; ▶ the security assessments were carried out in compliance with the relevant standards and the requirements of the tender specifications, and the migrated application/information system is secure and the integrity of the processed and stored data is maintained. Security aspects relating to the communications component and access to the migrated application/information system will also be analyzed; Activities that must be carried out by an independent Technical Auditor in the audit engagement for each application/information system included within the scope of the subsequent contract: 1) Compliance of the technical implementation 2) Compliance with technical standards and good practices 3) Verification of the quality of the technical deliverables 4) Validation of the migration process to the Government Private Cloud (CPG) In accordance with the provisions of the tender specifications, the technical auditing services will NOT include technical activities involving the provision of cybersecurity assessment services, such as: - Penetration tests or vulnerability assessments - DAST/CAST/SCA security assessments - Analysis of hardware/software components of migrated applications and systems These services are the subject of a separate procurement and will be performed by a service provider specializing in cybersecurity. The subject of the Framework Agreement/subsequent contracts to be concluded under Lot 2 consists of the provision of financial auditing services, namely auditing all expenditure and activities of the MAS IC project. The contracting authority defines the complexity of the financial audit reports according to their scope. The financial auditor will perform this engagement both in accordance with the technical specifications in these tender specifications and in accordance with: - International Standard on Related Services 4400 (“ISRS”), Engagements to Perform Agreed-Upon Procedures Regarding Financial Information, issued by IFAC and adopted by CAFR; - The Code of Ethics issued by IFAC and adopted by CAFR. Although ISRS 4400 provides that independence is not a requirement for agreed-upon procedures engagements, the Reform and/or Investment Coordinator / Intermediate Body requires the Auditor also to comply with the independence requirements provided for in the Code of Ethics. Financial auditing services constitute the activity of collecting and evaluating the necessary and sufficient evidence to determine whether the expenditure incurred corresponds to the specifications in the approved funding application and the project budget, including: 1. The reality of the expenditure, by reference to the original supporting documents. 2. The legality of the expenditure, by reference to the national and European legislation applicable to the PNRR. 3. The accuracy of the amounts recorded, by reference to the provisions of the approved budget. 4. The eligibility of the expenditure, by reference to the provisions of the financing contract and any other applicable regulations. The financial auditor will assess the quality and completeness of all financial documents produced within the project, including: 1) accounting records (automatically generated in electronic format or manual) from the Beneficiary’s accounting system, such as the General Journal, account ledgers and payroll records, fixed-asset registers and other relevant accounting information; 2) evidence of commitments (contracts and order forms); 3) evidence of the provision of services (approved reports, timesheets, evidence of participation in various activities within the project, etc.); 4) evidence of the receipt and commissioning of goods (delivery documents from suppliers/ acceptance reports/ commissioning reports); 5) proof of purchase (invoices, receipts, fiscal receipts); 6) proof of payment (payment orders, bank statements, payment notices, etc.). Procedure: open. Estimated value: 6,806,724.3 RON. Review the original TED notice for the complete requirement, lots, amendments and attachments.
Business details are available after sign in
Codes, capabilities, evidence, buyer details and marketplace actions are withheld from the public HTML and API response.