Opportunity
University Of Central Arkansas Uark #RFP261007
Co-sourced IT internal audit and advisory services for the University of Arkansas System
Posted
October 07, 2026
Respond By
November 10, 2026
Identifier
RFP261007
NAICS
541611, 541512
The University of Arkansas System is seeking a firm to augment its Internal Audit Department with IT audit and advisory expertise. - Government buyer: University of Arkansas System Board of Trustees, acting for the Audit and Fiscal Responsibility Committee (AFRC) and Internal Audit Department (IAD). - Services requested: Co-sourced internal IT audits and advisory projects covering IT governance, cybersecurity, cloud, data governance, privacy, general IT controls, enterprise applications, and other IT risks. - Estimated workload: Approximately 1,500–2,000 audit hours annually; the IAD does not guarantee a specific number of audits. - Delivery and reporting: Coordinate planning and engagements with the Chief Audit Executive and IAD; communicate risks and preliminary observations; prepare reports with recommendations and management responses; report results to the AFRC. IAD staff handle follow-up and validation of recommendations. - Key qualifications and standards: Demonstrated higher-education IT audit experience, familiarity with Arkansas law, and compliance with the Institute of Internal Auditors' Global Internal Audit Standards, Topical Requirements, and Global Practice Guides. - OEMs and named vendors: No product manufacturers, prospective service providers, or audit firms are named. The Institute of Internal Auditors is referenced as the standards publisher, not as a service vendor. - Contract term: Work may begin in fiscal year 2027, with an initial two-year term and options for up to five additional years, for a maximum of seven years, subject to agreement and approval. - Products and quantities: No products or part-numbered items are requested.
Description
The University of Arkansas System is requesting proposals from qualified audit firms to provide co-sourced internal information technology audit services, including audits and advisory projects. Services may cover IT governance, cybersecurity, cloud, data governance, privacy, general IT controls, enterprise applications, and other IT audits as needed. Work is expected to begin in fiscal year 2027 and may continue for up to seven years depending on provider performance; the solicitation estimates approximately 1,500 to 2,000 audit hours annually, with no guaranteed number of audits. Proposals are due November 10, 2026, at 2:30 PM CST.