Purpose of the Position
The General Internal Control and Audit Advisor will provide senior-level, independent advice and assurance to strengthen ASLO’s governance, risk management, accountability, compliance and internal control environment. The post holder will lead the design and continuous improvement of organization-wide control systems; advise the Board, General Director and senior management on major risks; develop risk-based audit and advisory plans; and assess financial, operational, programme, procurement, human resources, logistics, safeguarding and compliance processes.
The Advisor will combine strategic internal-control guidance with objective audit assurance. The position must remain independent from day-to-day operational and financial decision-making and will have authorized access to relevant records, systems, premises and personnel, subject to ASLO’s confidentiality, data-protection and safeguarding requirements.
Reporting, Independence and Authority
• Report functionally to the Board of Trustees or its designated Audit Committee and administratively to the General Director.
• Communicate significant or urgent risks directly and confidentially through the approved functional reporting line.
• Maintain independence, objectivity and professional scepticism and disclose any actual, potential or perceived conflict of interest before accepting an assignment.
• Avoid auditing activities for which the post holder recently held direct operational responsibility.
• Obtain unrestricted, timely access to records, staff, assets, systems and project locations required for approved audit work.
• Protect confidential information and use audit evidence only for authorized organizational purposes.
Key Duties and Responsibilities
Internal Control Framework and Strategic Advisory
• Design, document and periodically review an organization-wide internal control framework aligned with ASLO’s structure, risks, policies, donor obligations and operational context.
• Lead risk and control self-assessments with departments and field offices and maintain a consolidated risk and control matrix.
• Advise the Board, General Director and senior management on governance, delegation of authority, segregation of duties, control ownership and risk acceptance.
• Review new or revised policies, SOPs, systems and workflows and recommend proportionate preventive, detective and corrective controls before approval.
• Develop a prioritized internal-control strengthening roadmap and monitor implementation without assuming management ownership of the controls.
• Promote consistent control standards across headquarters, provincial offices, projects and implementing arrangements.
Enterprise Risk Management and Audit Planning
• Develop and regularly update ASLO’s audit universe and organization-wide risk assessment, including strategic, financial, operational, compliance, safeguarding, fraud, information and reputational risks.
• Prepare a risk-based annual internal audit and advisory plan, resource estimate and schedule for approval by the Board/Audit Committee.
• Define clear objectives, scope, criteria, methodology, sampling approach and work programmes for each audit or advisory engagement.
• Adjust the plan when material changes in funding, programmes, systems, regulations or risk exposure occur.
• Identify emerging and cross-cutting risks and provide timely options for senior-management and governance decisions.
• Coordinate assignment timing with management while preserving the independence and scope of the internal audit function.
Financial, Grant and Donor Compliance
• Review accounting records, bank and cash controls, reconciliations, advances, payroll, taxes, supporting documents, budget controls and financial reporting.
• Assess the accuracy, completeness, authorization, eligibility, allowability and allocability of project expenditures.
• Verify compliance with approved budgets, donor agreements, project documents, ASLO policies, delegation of authority and applicable Afghan laws and regulations.
• Evaluate segregation of duties, approval workflows, system access, document retention and controls within financial and management information systems.
• Review partner, sub-grantee and field-office financial controls where included in approved assignments.
• Advise management on recurring audit, spot-check and donor-compliance findings and on sustainable corrective measures.
Operational and Programme Assurance
• Review procurement planning, solicitation, bid evaluation, vendor due diligence, contracting, delivery, payment and procurement-file completeness.
• Assess value for money, competition, conflicts of interest, sanctions screening, asset management, inventory, fleet, fuel, travel and administrative controls.
• Review recruitment, personnel files, contracts, attendance, leave, timesheets, payroll changes, staff benefits, system access and staff-separation processes.
• Review whether project activities, outputs and beneficiary records are supported by reliable evidence and aligned with approved project documents, workplans and budgets.
• Assess controls over beneficiary selection, distribution, attendance, activity reporting, data quality, complaints and feedback mechanisms, and monitoring records.
• Conduct field visits, site observations, document verification and interviews using appropriate sampling and confidentiality safeguards.
• Review compliance with safeguarding, PSEA, child protection, data protection, anti-fraud and accountability commitments within the approved audit scope.
• Identify systemic operational risks and recommend practical controls that protect programme quality and affected communities.
Audit, Special Reviews and Fraud Risk
• Lead or conduct approved risk-based internal audits and advisory reviews in accordance with professional standards and ASLO procedures.
• Assess fraud and corruption risks and test the design and operation of preventive and detective controls.
• Immediately escalate credible indicators of fraud, corruption, diversion, retaliation, safeguarding concerns or serious misconduct through ASLO’s approved confidential reporting mechanisms.
• Conduct or support authorized special reviews and investigations only when formally assigned and in accordance with due process, confidentiality and evidence-handling requirements.
• Preserve records and maintain clear, complete and secure evidence files and working papers for all authorized reviews.
• Do not make final disciplinary, employment or legal determinations; provide evidence-based findings to the authorized decision-makers.
Reporting, Follow-Up and Capacity Strengthening
• Discuss preliminary findings with responsible managers and verify factual accuracy before finalization.
• Prepare clear, concise and evidence-based reports that classify risks, explain root causes and impacts, and propose practical recommendations.
• Agree responsible persons and realistic completion dates for management actions while preserving the auditor’s independent assessment.
• Maintain a centralized recommendation tracker and validate closure evidence for outstanding actions.
• Provide quarterly advice and reporting to the Board/Audit Committee and General Director on high-risk findings, overdue actions, emerging risks and recurring control weaknesses.
• Develop practical guidance, tools and targeted training on internal controls, ethics, donor compliance, risk management and audit readiness.
• Coach departmental control owners and relevant staff while maintaining clear boundaries between advisory support and management responsibility.
Key Deliverables
|
No.
|
Required Deliverable
|
Timing/Frequency
|
|
1
|
Organization-wide internal control framework, risk and control matrix, and improvement roadmap
|
Initial; reviewed annually
|
|
2
|
Risk-based annual internal audit and advisory plan
|
Annually; updated when risks change
|
|
3
|
Engagement terms, audit programme, evidence file, working papers and reports
|
For each assignment
|
|
4
|
Policy, SOP and control-design advisory notes
|
As required
|
|
5
|
Management action and control-improvement tracker
|
Updated monthly and reported quarterly
|
|
6
|
Quarterly governance, risk, compliance and internal control report
|
Quarterly
|
|
7
|
Annual independent opinion on governance, risk management and internal controls
|
Annually
|
|
8
|
Immediate confidential alert on critical fraud, safeguarding, financial or compliance risks
|
As required
|