Attachment_A_Statement_of_Work_Audit_Management_Software.docx
DOCX document 117 KB Posted
- Attached to
- new, purchase Audit Documentation Software Federal contract opportunity
- Solicitation number
- 89603018Q0085
About this file
89603018Q0085 0001 Attachment A Statement of Work_Audit Management Software.docx
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 89603018Q0085_0002.docx | DOCX document | |
| Vendor_Questions_OE_a7_27_18.docx | DOCX document | |
| 89603018Q0085_0002_1.docx | DOCX document | |
| Appendix_A__Audit_Management_Software_Detailed_Requirements.xlsx | XLSX spreadsheet | |
| 89603018Q0085_0001_1.docx | DOCX document | |
| Attachment_B_Bid_Model.xlsx | XLSX spreadsheet | |
| GPAT-Audit_Software.pdf | ||
| 89603018Q0085_0001.docx | DOCX document | |
| 89603018Q0085.docx | DOCX document | |
| 89603018Q0085_1.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Statement of Work (SOW)
FERC Audit Documentation Software March 8, 2018
1. BACKGROUND
The Federal Energy Regulatory Commission (FERC) is an independent agency that regulates the interstate transmission of electricity, natural gas, and oil. In 2005, in response to revelations about Enron and the California power crisis, Congress significantly enhanced FERC’s authority to investigate and impose civil penalties on those who manipulate the nation’s wholesale natural gas and power markets. The Division of Audits and Accounting (DAA) within the Office of Enforcement administers the Commission’s audit and accounting programs. These programs enable the Commission to maintain effective and appropriate oversight over jurisdictional entities while ensuring transparency, accountability, and compliance.
Helping jurisdictional companies achieve robust compliance is the cornerstone of DAA’s audit and accounting programs. This is primarily accomplished by reviewing jurisdictional entities’ compliance programs related to specific audit scope areas. These audits often involve some of the largest and most sophisticated companies in the world. Part of the necessary process of auditing is to collect and analyze large sets of data, which can include a company’s trading and financial data—often covering multi-years of data—as well as millions and sometimes tens of millions of pages of internal reports and studies, emails, instant messages, and other electronic documents. DAA currently does not have an electronic audit system to help manage the audit process which includes the accumulation of large data sets, documentation of audit analysis and steps, testing and tracking of audit conclusions.
Therefore, DAA is seeking a configurable commercial-off-the-shelf (COTS) audit management software to assist the division in all phases of the audit life cycle including planning, performing, reporting, and knowledge management of audits of jurisdictional companies in the electric power, natural gas and oil pipeline industries. This software will facilitate the reporting of the audit findings to both the Commission and the affected companies. It will also assist DAA with identifying recommendations for corrective actions in cases of error, and with identifying potential preventive measures to assist with avoiding problems in the future. Software selection will be based on vendor ability to demonstrate the capabilities and functionalities described in this statement of work and detailed requirement matrix.
2. OBJECTIVE
The objective of this statement of work is to license and deploy a COTS audit management software solution to support DAA’s audit and accounting program.
Audits performed by DAA vary in nature, type, scope, and objectives across all aspects of the energy industry. The overall objective of most DAA audits is to evaluate whether, and how well, a jurisdictional company complies with Commission statutes, orders, rules, and regulations. In performing this function, DAA is not limited in the types of audits it can conduct. If noncompliance is discovered during an audit, then the Commission will require a jurisdictional company to take recommended corrective measures to bring it into compliance with Commission requirements.
There are multiple distinct phases of the audit process that guide DAA as it conducts audits of jurisdictional companies. DAA performs an annual audit planning to identify audit universe and develop risk profiles. Once audit candidates are selected, the following four phases are applied in conducting full scope audits. First, audit planning involves research of public documents, trade press, and Commission orders and other actions, and other relevant material. It also involves issuing a public letter to the jurisdictional company informing it of audit commencement. Second, audit fieldwork is the collection of evidence to support his/her conclusions, such as interviewing, data analysis, review of e-mails and voice recordings, data requests, and site visits. Third, audit reporting entails status reporting, briefings, the crafting of draft and final audit reports, and issuance of Commission orders. Finally, post-audit implementation involves reviewing a company’s implementation plans and quarterly compliance filings. Figure 1 - Audit Process illustrates the process for a typical audit.
Figure 1 - Audit Process
DAA requires a solution that will support all phases of the audit process, and allow for accurate data collection, review, documentation and reporting as well as knowledge management. In addition, DAA requires the following functions that will further enhance the overall management of the audit process and ensure it accomplishes its mission objectives. Specifically, DAA requires a COTS that can be configured to address the following:
· Separate but integrated application that facilities all phases of audit life cycle starting with the annual audit plan (AAP).
· Desktop application that allows auditors to complete all phases of the audit process.
· A function that allows for maintenance of knowledge and can facilitate methodological inventory of current and emerging risks, audit steps and prior audit issues.
· A function that facilitates audit risk assessment to determine what to audit based on developed risk profiles and using the risk profile to build an audit plan.
· A function that allows for audit management to schedule projects and assign resources and at the same time assess any scheduling conflicts.
· A function for data mining and producing various reports for day to day management of the audit function , monitoring of specific projects, tasks, exceptions across audits and lastly, producing monthly, quarterly and annual reports (Enforcement Report).
· A function that allows for time tracking and expense reporting across the division.
FERC requires a modern user interface utilizing the latest technologies that is acceptable for government agencies to provide common sense and simple experience for the end user. The solution should be intuitive, browser-based and logical, with a minimal couple of hours training needed by the larger user base for user acceptance.
The selected solution will offer industry standard audit management software capabilities including electronic working paper functionality, cross-referencing, hyperlinking, tick-marks, issues tracking, progress monitoring and annotations. It should fully integrate with the Microsoft Office suite of products and provide well documented application program interfaces and/or web services to allow for integration with FERC systems.
User access and permissions are of paramount importance. The selected solution should enforce role based access permissions (RBAC) for specified functionality, audits and work papers. In addition to RBAC, the selection solution should provide provisioning capabilities for granting granular permissions to specific users and groups, and provide the capability to control user and group access on a case by case basis.
The selected solution should streamline the collection of information and promote collaboration across DAA. Users should have the opportunity to share information and resources (templates, libraries, findings and reports), and lessons learned within a specific audit, across a specified group of users, across the entire division and the Commission. The software should also facilitate communication within your audit teams and enhance review process and follow-up through threaded discussions, invitations to multiple recipients, assignment of due dates and confidentiality options. Collaboration within a single audit, across audits or with your entire Audit team.
DAA anticipates that the solution will need to manage and store 1.5 TB of audit data. The solution should be appropriately configured to manage this amount of data without impacting user performance. To assess performance capabilities, the Vendor shall provide computing performance metrics on for the Windows platforms on which the software is certified.
The solution must meet a number of additional FERC specific requirements. These may be found in Appendix A – Audit Management Software Detailed Requirements.
3. SCOPE
The work will include the installation, configuration, testing, deployment, and maintenance of an audit management software solution. This includes all patches, updates, infrastructure sizing, and configuration. The contractor will also need to ensure integration between the proposed solution and how DAA audit process evolves. Further, the contractor will provide Tier 3 help desk support.
The contractor shall perform the following activities throughout the course of the contract:
1. Management and implementation of an audit management solution for the enterprise.
2. Infrastructure setup, configuration and tuning for the recommended solution.
3. Security assessment configuration and review to validate solutions complies with FERC security guidelines and all FISMA policies, procedures, and mandates.
4. TASKS
The contractor shall coordinate and work with FERC personnel and/or other applicable contractors and may require interaction with other stakeholders outside of FERC in the execution of all required tasks.
The contractor shall complete the tasks described below.
Task 1: Project Management
Activity 1.1 Kick-off meeting: After contract award, a kickoff meeting will be held with the contractor at the FERC Headquarters Office in Washington, D.C. Arrangements for this meeting shall be coordinated with the COR. The contractor shall prepare notes of this meeting, highlighting all agreements made with FERC staff on any technical decisions made during the meeting, the details of project execution, follow-up actions, etc. The timing of this meeting will be held at the discretion of the COR.
Task 2: Implementation Activity 2.1: Requirements Review: The contractor shall review and assess the current audit business and workflow processes. The contractor is not expected to re-engineer the processes, but must ensure they understand it sufficiently to design an implementation that best supports it. Where necessary, the contractor may recommend improvements to improve process efficiencies. To that end, the contractor will review existing process baselines and may conduct a limited number of interviews with business offices within FERC to supplement their understanding.
The contractor shall utilize industry best practices to architect an enterprise class implementation that supports FERCs auditing requirements. The implementation needs to be scalable and sufficiently robust to meet user-driven demands and ease of access and needs to support the use of mobile devices. Implementation needs to accommodate dozens of simultaneous connections with little latency. The implementation must consider the existing network topology and the contractor should provide recommendations where opportunities for improvement are identified.
Activity 2.2: Security: The proposed shall conform to all applicable federal and industry security standards. In addition, the contractor shall work closely with the FERC Security Team to ensure the proposed implementation comports with FERC’s internal security requirements in order to ensure the overall protection of data due to loss, disaster or malicious attack.
Activity 2.3: Transition Planning: The contractor shall develop a transition plan detailing how the implementation and transition will be performed. The plan should include but not be limited to:
• System Deployment
• User Acceptance Testing
• Training
• Support and Upgrades
The contractor will provide a draft transition plan 90 days prior to the planned transition. At that time the contractor will meet with FERC to review and discuss the transition plan, and FERC IT Operations personnel will provide input. The contractor will finalize the plan within seven business days receipt of input from FERC IT Operations personnel. Items to address in the transition plan include technical issues such as user account creation and authentication as well as processes and procedures such as switchover and contingency back out plans.
Activity 2.4 Deployment of Baseline Solution: The contractor will be responsible for the initial setup of the new solution. This includes hardware or hardware provisioning based on industry best practices and FERC baseline configuration. Hardware will include but is not limited to servers, storage and network (or as appropriate using a cloud-based solution). FERC IT Operations personnel will work with the contractor to install and configure essential software and utilities for the maintenance and management of the solution (e.g. antivirus, backups, updates, etc.) and the contractor will perform the initial install of the solution software to meet agreed upon baseline requirements. In the event the solution is to be installed on virtual machines, such virtual machines will be provided and provisioned by FERC in accordance with the specifications provided by the contractor and will include the essential software and utilities (e.g. antivirus, backups) for the maintenance and management of the virtual machines. Appropriate updates should be applied for installed software to ensure proper versioning of software and changes to base install configurations to meet regulatory and industry requirements. A baseline snapshot should be performed at least once during the initial deployment to mitigate potential risks.
Activity 2.5: Configure and Tune: After initial deployment, the contractor will be responsible for overall configuration and fine tuning of the solution software. This should include additional software updates, appropriate configuration of services based on best practices for the solution, installation of tools and utilities for the monitoring and management of the solution and any other key components. The configuration and tuning of the solution should be in line with the preferred configuration based on solution recommendations and following the existing policies and procedures of FERC and any pertinent regulatory or industry requirements.
Task 3: Testing and Acceptance
The Contractor shall use well-defined procedures for Quality Assurance (QA) testing and User Acceptance Testing (UAT) for software deployment and maintenance activities. Each requirement must be testable and documented before deployment to the production environment. The Contractor must develop Test Cases as part of the Test Plan and perform independent activities necessary to assure that all activities managed under this SOW are defect free. The Contractor must prepare UAT Plans as part of the Test Plan and conduct UAT Kick-off meetings to prepare testers and interested stakeholders, recording the agenda and the meeting minutes.
The contractor shall meet, at a minimum, the following acceptance criteria:
• All existing users have logon accounts, can logon, and are granted the correct permissions
• External connectivity is confirmed and working as designed
• Review can be completed both internally and externally
Task 4: Training
Activity 4.1 User Documentation: The contractor shall prepare User’s Guide and Administrator’s Guide User Documentation that support the implemented solution. The Contractor must update all documentation and procedures to reflect changes made to any aspect of the solution. The Contractor must maintain all user documentation, to include artifacts such as system guidelines, quick reference guides, and business process reference materials.
Activity 4.2: Rollout Training: The Contractor shall develop training materials for review and approval by the FERC COR. The training materials must include material suitable for adding to existing PowerPoint presentations used for webinars and classroom training sessions for end users within FERC. Training sessions must include system owners; headquarter users, and regional office users. The Contractor will be expected to host training sessions at FERC HQ and/or at their own facilities, and provide remote access to staff located at FERC regional offices or elsewhere. The contractor shall provide training for FERC-appointed Administrators that supplements Administrator’s Guide User Documentation. The contractor shall also provide “train the trainer” training to select FERC staff and/or contractors to allow them to conduct additional training of staff in the future. This training should include instructional materials.
Task 5: Upgrades & Support
Activity 5.1: FERC Technical Support: The contractor shall provide tools and processes for monitoring the availability of the solution and tools and processes for responding to system and application outages with troubleshooting activities designed to identify and mitigate operational issues.
Activity 5.2: User Support Desk: The contractor must provide Tier 3 support desk services for users from 8am – 8pm EST. Tier 1, and some Tier 2, issues will be addressed by FERC’s existing Help Desk infrastructure. The contractor will need to provide FAQs, scripts, and other guidance to the FERC Help Desk personnel to help them with addressing Tier 1 and some Tier 2 issues. The contractor will support calls and emails from the FERC Help Desk that cannot be answered by FERC Help Desk staff.
5. DELIVERABLES
| Associated Task |
| Deliverable |
| Due Date |
1. Project management
| Project Plan |
| Award + 10 days |
| Kickoff Meeting Notes |
| Award + 15 days |
| 2. Implementation |
| Technical Architecture |
| Dates should be included in project plan |
| Transition Plan Configuration Requirements |
| Dates should be included in project plan |
| 3. Testing |
| Testing Plan and Test Cases |
| Dates should be included in project plan |
4. Training
| Training Plan |
| Dates should be included in project plan |
| User Guide |
| Dates should be included in project plan |
| Training Documents |
| Dates should be included in project plan |
6. PERIOD OF PERFORMANCE
· The period of performance a base year and four, one year options.
7. PLACE OF PERFORMANCE
888 1st, NE, Washington DC 20426
8. Appendix A – Audit Management Software Detailed Requirements image1.png
File details come from the government source that posted it.