Role Overview
The incumbent will support the Head of Internal Audit in leading the regional internal audit function, with a strong focus on technology, IT controls and technology-related risks across multiple jurisdictions. The role will oversee audit planning, execution and reporting across regional entities, covering both business and technology risks. This includes IT audits across enterprise systems, IT General Controls (ITGC), cybersecurity, network vulnerabilities, application controls and technology-related regulatory compliance. The incumbent will provide independent assurance on the effectiveness of internal controls and identify key risk areas, control gaps and opportunities for improvement, while ensuring alignment with regulatory requirements, company policies, industry best practices and internal audit standards.
Key Responsibilities
Audit Strategy & Planning
- Support the Head of Internal Audit in developing the regional risk-based audit plan, incorporating both business and technology risks.
- Conduct enterprise-wide risk assessments across regional operations, including assessment of technology and IT-related risks.
- Identify and prioritise key technology risk areas based on business, regulatory and cybersecurity exposures.
- Develop audit coverage across IT infrastructure, enterprise systems, applications, cybersecurity, ITGC, data and technology operations.
- Ensure audit plans align with group audit strategy, regulatory expectations and Board/Audit Committee priorities.
IT Audit & Technology Risk
- Lead and oversee IT audits across regional entities, business units and enterprise systems.
- Evaluate the design and effectiveness of IT General Controls (ITGC), including:
- Access and user management
- Change management
- IT operations and system controls
- Backup and recovery
- System development and implementation
- Conduct reviews of cybersecurity, information security and network vulnerabilities to identify control gaps and potential areas of exposure.
- Assess internal controls over enterprise applications and technology platforms to ensure appropriate security, reliability and integrity.
- Evaluate technology controls against regulatory requirements, company security policies and industry best practices.
- Assess risks relating to data governance, data security and access to sensitive information.
- Identify emerging technology risks and recommend enhancements to the organisation's technology control environment.
- Oversee follow-up and tracking of technology-related audit findings and remediation efforts through to closure.
Integrated Audit Execution & Oversight
- Oversee the execution of regional internal audits across business units and subsidiaries.
- Lead integrated audits combining business process, financial and IT controls to assess end-to-end risks.
- Review audit workpapers, findings and reports to ensure issues are appropriately identified, risk-rated and supported by practical recommendations.
- Ensure audits comply with IIA standards, internal audit methodologies and relevant technology audit practices.
- Monitor audit quality and consistency across the region.
Regional Governance & Reporting
- Prepare audit reports and provide clear insights on key control weaknesses, emerging risks and governance issues.
- Present significant technology, cybersecurity and IT control risks to senior management and the Audit Committee.
- Track management action plans and remediation progress, ensuring significant findings are appropriately addressed and closed.
- Support the Head of Internal Audit in presenting key audit matters to the Audit Committee and Board where required.
- Liaise with external auditors, regulators and compliance functions on relevant technology and control matters.
Stakeholder Management
- Partner with senior management, regional leadership, IT/Technology, Information Security, Risk, Compliance and functional heads.
- Build effective relationships with technology stakeholders while maintaining appropriate internal audit independence and objectivity.
- Provide constructive insights and recommendations to strengthen the overall technology and internal control environment.
- Act as the delegate for the Head of Internal Audit when required.
Team Leadership
- Lead and mentor the internal audit team, including providing guidance on IT audit, technology risk and internal control assessments.
- Provide guidance on audit methodology, risk assessment, control testing and investigation techniques.
- Support recruitment, training and professional development of audit staff.
- Promote consistent audit practices across regional teams.
Continuous Improvement
- Drive improvements in audit analytics, continuous monitoring, automation and technology-enabled audit techniques.
- Identify opportunities to improve the efficiency and effectiveness of IT audit and internal audit processes.
- Keep abreast of emerging technology, cybersecurity and regulatory risks and ass