| |
|
Risk Management at the Department of Management and Finance (DMF) at the OSCE is part of the Integrated Internal Control Framework that includes, in addition to the Risk Management process, the support of executive management, the OSCE ethical framework, the Common Regulatory Management System (CRMS) and established automated and manual control and monitoring activities. Internal Control is designed to reduce and manage the risk of failure to achieve an organization’s aims, objectives and related policies.
Therefore, for a system of internal control to provide the assurance on its effectiveness, the OSCE officials are required to understand and mitigate risks that OSCE faces to an acceptable level, both internally and externally and manage the risks efficiently, effectively and economically. The OSCE’s approach is to be risk aware but not risk averse. Risks are identified and managed rather than merely avoided.
The OSCE is looking to acquire the services of a suitable qualified consultant to:
Develop (2.5 days) and facilitate (2.5 days) a tailor-made training course for the OSCE Risk Management Focal Points. The goal is to improve understanding of risk management concepts and Risk Management framework consolidating in the areas of administrative risk with an increased focus on control verification targeted at strengthening the underlying assurance processes and focusing on fraud prevention through:
- Understanding of risk as an effect of uncertainty on the objectives (positive and negative, opportunities and threats);
- Ability within key administrative business processes to identify risks, categorize, assess and map them to the business objectives in line with the OSCE Guidance on Administrative Risk Management,
- Understanding of mechanisms supporting development of relevant controls with the view to provide reasonable assurance on fraud prevention;
- Awareness about risk reporting tools and mechanisms.
Based, on the above, the scope of the training shall cover the following non-exhaustive list of the key focus areas:
- Risk identification (including compliance and fraud related risks);
- Risk Assessment and risk ratings;
- Risk Evaluation;
- Risk prioritization and ranking, treatment options;
- Risk Controls;
- Control strategies, control effectiveness;
- Implementation;
- Managing specific actions of control measures;
- Use and maintenance of risk registers;
- Implementing risk monitoring and reporting processes ;
- Format and frequency of risk reporting;
- Incident reporting.
Please note that this is a consultancy assignment of a temporary nature, with an expected duration of approximately 5 working days.
|
| |
|
- Liaising with the OSCE Information Security and Co-ordination Unit to determine the detailed presentation and training tasks;
- Training the OSCE Risk Management Focal Points on risks identification and assessment;
- Training the OSCE Risk Management Focal Points on development of adequate control mechanisms and their strength evaluation;
- Familiarizing the OSCE Risk Management Focal Points with risk reporting tools and mechanisms;
- Providing all training materials required, including handouts, PowerPoint presentation, case studies, role plays, etc.;
- Evaluating the training and share feedback and recommendations with the OSCE Information Security and Co-ordination Unit.
Expected Output/Deliverable:
- Development of the tailor-made training for the OSCE Risk Management Focal Points (2.5 days);
- Delivery of a 2.5 day training for the OSCE Risk Management Focal Points;
- The OSCE Risk Management Focal Points are equipped with skills and knowledge on identification, categorization and assessment of risks within the administrative business processes;
- The OSCE Risk Management Focal Points are able to define relevant and adequate control mechanisms for administrative risks identified within the administrative business processes;
- Training materials (including handouts, PowerPoint presentation, assessment questionnaires, etc.);
- Evaluation of the training.
|
| |
|
Interested candidates with the above experience/competencies are required to apply by submitting a draft training programme which includes the following:
- Learning objectives for achieving the specified expected outcomes/deliverables;
- Outline of the programme and guiding principles;
- Individual topics to be covered;
- Evaluation methods.
Please use the OSCE's online application link found under https://jobs.osce.org/vacancies.
If you are not a national of a participating State, you must apply by submitting an offline application form which can be found under https://jobs.osce.org/resources/document/offline-application-form.
The OSCE retains the discretion to re-advertise the vacancy, to cancel the recruitment or to offer an appointment with a modified job description or for a different duration.
Only shortlisted applicants will be contacted.
The OSCE is committed to diversity and inclusion within its workforce, and encourages qualified female and male candidates from all religious, ethnic and social backgrounds to apply to become a part of the Organization.
Please be aware that the OSCE does not request payment at any stage of the application and review process.
|