Purpose of the Position
The Internal Audit Officer will provide independent, objective assurance and advisory services designed to strengthen ASLO’s governance, risk management, accountability and internal control systems. The post holder will conduct risk-based reviews of financial, operational, programme, procurement, human resources, logistics, safeguarding and compliance processes; identify control gaps; recommend practical corrective actions; and follow up management implementation.
The position must remain independent from day-to-day operational and financial decision-making. The Internal Audit Officer will have authorized access to relevant records, systems, premises and personnel, subject to ASLO’s confidentiality, data-protection and safeguarding requirements.
Reporting, Independence and Authority
• Report functionally to the Board of Trustees or its designated Audit Committee and administratively to the General Director.
• Communicate significant or urgent risks directly and confidentially through the approved functional reporting line.
• Maintain independence, objectivity and professional scepticism and disclose any actual, potential or perceived conflict of interest before accepting an assignment.
• Avoid auditing activities for which the post holder recently held direct operational responsibility.
• Obtain unrestricted, timely access to records, staff, assets, systems and project locations required for approved audit work.
• Protect confidential information and use audit evidence only for authorized organizational purposes.
Key Duties and Responsibilities
Risk-Based Audit Planning
• Develop and regularly update ASLO’s audit universe and organization-wide risk assessment.
• Prepare a risk-based annual internal audit plan, resource estimate and audit schedule for approval by the Board/Audit Committee.
• Define clear objectives, scope, criteria, methodology and work programmes for each audit engagement.
• Adjust the audit plan when material changes in funding, programmes, operations, systems or risk exposure occur.
• Coordinate audit timing with management while preserving the independence and scope of the internal audit function.
Financial, Grant and Donor Compliance
• Review accounting records, bank and cash controls, reconciliations, advances, payroll, taxes, supporting documents, budget controls and financial reporting.
• Assess the accuracy, completeness, authorization, eligibility, allowability and allocability of project expenditures.
• Verify compliance with approved budgets, donor agreements, project documents, ASLO policies, delegation of authority and applicable Afghan laws and regulations.
• Test segregation of duties, approval workflows, user access, document retention and controls within financial and management information systems.
• Review partner, sub-grantee and field-office financial controls where included in approved audit assignments.
• Support organizational readiness for external audits, donor spot checks and assurance reviews without assuming management responsibility for the processes being audited.
Procurement, Logistics, Assets and Human Resources
• Review procurement planning, solicitation, bid evaluation, vendor due diligence, contracting, delivery, payment and procurement-file completeness.
• Assess value for money, competition, conflict-of-interest controls, sanctions screening and compliance with procurement thresholds and donor requirements.
• Verify asset registration, tagging, custody, physical existence, movement, maintenance and disposal records.
• Review warehouse, inventory, fleet, fuel, travel and administrative controls, including periodic physical verification.
• Review recruitment, personnel files, contracts, attendance, leave, timesheets, payroll changes, staff benefits and separation processes.
• Check whether access rights, assets, advances and records are properly transferred or closed when staff change roles or leave ASLO.
Programme, MEAL, Safeguarding and Field Operations
• Review whether project activities, outputs and beneficiary records are supported by reliable evidence and aligned with approved project documents, workplans and budgets.
• Assess controls over beneficiary selection, distribution, attendance, activity reporting, data quality, complaints and feedback mechanisms, and monitoring records.
• Conduct field visits, site observations, document verification and interviews using appropriate sampling and confidentiality safeguards.
• Review compliance with safeguarding, PSEA, child protection, data protection, anti-fraud and accountability commitments within the approved audit scope.
• Confirm that sensitive personal data and audit evidence are collected, stored, shared and retained securely and only when necessary.
• Identify systemic operational risks and recommend practical controls that protect programme quality and affected communities.
Fraud Risk, Misconduct and Special Reviews
• Assess fraud and corruption risks and test the design and operation of preventive and detective controls.
• Immediately escalate credible indicators of fraud, corruption, diversion, retaliation, safeguarding concerns or serious misconduct through ASLO’s approved confidential reporting mechanisms.
• Conduct or support authorized special reviews and investigations only when formally assigned and in accordance with due process, confidentiality and evidence-handling requirements.
• Preserve records and maintain clear, complete and secure working papers for all authorized reviews.
• Do not make final disciplinary, employment or legal determinations; provide evidence-based findings to the authorized decision-makers.
Audit Reporting and Follow-Up
• Discuss preliminary findings with responsible managers and verify factual accuracy before finalization.
• Prepare clear, concise and evidence-based reports that classify risks, explain root causes and impacts, and propose practical recommendations.
• Agree responsible persons and realistic completion dates for management actions while preserving the auditor’s independent assessment.
• Maintain a centralized recommendation tracker and validate closure evidence for outstanding actions.
• Provide quarterly updates to the Board/Audit Committee and General Director on high-risk findings, overdue actions, emerging risks and recurring control weaknesses.
• Identify lessons and provide targeted orientation on controls, ethics, donor compliance and risk management without taking ownership of management controls.
Key Deliverables
|
No.
|
Required Deliverable
|
Timing/Frequency
|
|
1
|
Risk-based annual internal audit plan and audit universe
|
Annually; updated when risks change
|
|
2
|
Engagement terms, audit programme, evidence file and working papers
|
For each audit assignment
|
|
3
|
Draft and final internal audit reports with agreed management actions
|
For each audit assignment
|
|
4
|
Management action follow-up tracker
|
Updated monthly and reported quarterly
|
|
5
|
Quarterly internal audit and risk summary
|
Quarterly
|
|
6
|
Annual opinion on governance, risk management and internal controls
|
Annually
|
|
7
|
Immediate confidential alert on critical fraud, safeguarding, financial or compliance risks
|
As required
|