Opportunity

SAM #70FA3126I00000007

FEMA Internal Control, Compliance, and Audit Remediation Support Services

Buyer

FEMA Support Services Section

Posted

September 09, 2026

Respond By

September 30, 2026

Identifier

70FA3126I00000007

NAICS

541611, 541211

FEMA’s Office of the Chief Financial Officer (OCFO), Risk Management and Compliance Division is seeking contractor support for specialized internal control and compliance services. - Government Buyer: - Department of Homeland Security - Federal Emergency Management Agency (FEMA) - Office of the Chief Financial Officer, Risk Management and Compliance Division - OEMs and Vendors: - No specific OEMs or commercial vendors are named in the solicitation - Services Requested: - Internal control assessment and compliance monitoring - Control documentation and testing - Risk analysis and insurance management controls - Data analysis and information technology (IT) control testing - Financial management support across FEMA’s financial management, disaster assistance, grants, flood insurance, IT, financial reporting, and mission support processes - Corrective action and audit remediation support (separate requirement) - Includes corrective action planning, remediation, testing, reporting, stakeholder coordination, and knowledge transfer - Unique/Notable Requirements: - Contractor must support compliance with OMB Circular A-123 and GAO Standards - Remediation and corrective action implementation are handled separately from routine internal control support - Services span both routine internal control activities and post-audit remediation - Period of Performance: - One 12-month base period plus four 12-month option periods (total up to five years) - Remediation support anticipated to start in January 2026 - No hardware, software, or product part numbers are specified; all requirements are for professional services

Description

The Federal Emergency Management Agency (FEMA), Office of the Chief Financial Officer (OCFO), Financial Management Division (FMD), Risk Management and Compliance (RMC) Branch, is seeking information from qualified contractors capable of providing specialized support services to assist with internal control assessment, compliance monitoring, control documentation, control testing, risk analysis, insurance management controls, data analysis, information technology control testing, and financial management support.

The purpose of this effort is to help FEMA maintain and strengthen its internal control and compliance environment in accordance with applicable federal requirements, including Office of Management and Budget (OMB) Circular A-123, the Government Accountability Office (GAO) Standards for Internal Control in the Federal Government, federal financial management requirements, information technology control guidance, Department of Homeland Security (DHS) policy, and FEMA guidance. The contractor shall provide technical, analytical, documentation, reporting, and advisory support to assist FEMA in evaluating control design, testing control operating effectiveness, monitoring compliance activities, identifying risks and control gaps, assessing compliance requirements, and providing management insight.

The anticipated scope of support may span FEMA’s financial management, disaster assistance, grants, flood insurance, information technology, financial reporting, and mission support processes. Specific support may include internal control assessments, compliance monitoring, control documentation, control testing, risk assessments, data analysis, flood insurance controls, information technology general control and application control testing, and general financial management support. Through these activities, the contractor may identify findings, risks, deficiencies, control gaps, and compliance issues and recommend improvements based on assessment, testing, monitoring, and analysis.

Corrective action implementation, remediation execution, and closure support for identified deficiencies are outside the primary scope of this requirement and are expected to be addressed under a separate Corrective Action and Audit Remediation Support Services requirement. This separation is intended to preserve clarity of roles, reduce overlap between assessment and remediation activities, and ensure objectivity in FEMA’s internal control and compliance environment.

View original listing