Audit Flashcards
(55 cards)
How are changes to contracts handled (example)?
Contract changes - change notice
E.g add contractor
They specify change required, who requested it, send to us, we fill in the details
Their procurement approve.
How do you report on risks and issues
Engagement RIAD log- common risks, issued every 2 wks - supplier risks, delivery risks on conf
Dependencies raised around resource
How do you track requirements (3)
BDDs - functionality from users pov
Also prototypes and designs
SAD - includes NFRs - period of feedback - approved by CIO
How do we use WAF?
Complete on the engagement, actions regularly reviewed,
What improvements could be made?
Track all the engagements / projects on IS side.
DM mission statement - ensure
Our engagements are delivered according to best practice and the DMF
5 areas of framework
Team Management
Resource and financial management
Commercial and change management
Governance
Solution management
Operating principles…but allowing for…
Consistent, managed delivery approach compliant with core delivery principles and accreditations
Flexibility to intelligently tailor with clients, sectors and operational environments
3 processes
Assignment is initiation
Assignment control
Assignment closure
Audit - accreditations, yrs, by who
ISO9001, 27001…3yrs…independent
Scenarios to consider
Contract - multiple SOWs, each a single piece of work
Contract - multiple SOWs, each with multiple projects within the SIW
Article is called
Managing Legacy Technology
5 types of Legacy Tech
EOL product
Out of support with supplier
Unable to update
Not cost effective
Above acceptable risk threshold
When to migrate (3)
Cost of maintaining old tech becomes greater than replacing with new technology
Supplier support not available
Risk is too great
7 principles
Use cont imp to keep tech up to date
Build data asset reg
Know full extent of your infra
Build skills
Have a responsive and flexible service model which can adapt
Consider org business needs , process and culture
Use Tech code of practice
WAF helps delivery teams (2)
Assure quality
Minimise risks
WAF sets out…for each…via a …
Standards and best practices for each discipline via a framework
WAF overview / flow
Management Systems Team - Defije, govern
WAF (best practices & standards)
Disciplines define standards and best practices
Client engagement self assess compliance
Why have the WAF?
Simple, effective, scalable framework that can cope with growth / different types of contracts
Who is the WAF for (3)?
Everyone
- Staff - understand best practices
- Engagements - Assure client satisfaction
- Discipline Steering - assure standards and best practice
WAF - each engagement determines (2)
Which parts it applies to
Schedule and approach for self assessing
The schedule for self assessment is set at
Engagement initiation
Relationship between WAF / OOM & Policies / DMF
Corp standards - processes and procedures (eg Delivery - assignment or initiation / control / closure)
WAF - ID standards to assure
Client engagement delivery
(e.g that the Damage is in place and followed)
3 types of engagements
Outcome-based
Resource augmentation
Innovation and transformation partnerships