JOB PURPOSE:
To provide independent, risk-based assurance over the group’s technology environment, major IT projects and digital transformation initiatives. The role is responsible for planning and executing IT audit engagements, performing project assurance reviews across the project lifecycle, evaluating technology risks and controls, and providing practical recommendations that strengthen governance, risk management and control.
The role supports the delivery of the Internal Audit Plan while acting as a trusted advisor on technology risk during major business and IT change initiatives.
JOB OBJECTIVES:
- Provide independent assurance over the effectiveness of technology controls by planning and executing risk-based IT audits across key technology domains, including IT general controls, cybersecurity, cloud, infrastructure, data governance, resilience, third-party technology risk, and emerging technologies.
- Performing risk assessments, evaluating control design and effectiveness, leveraging data analytics, identifying control weaknesses and root causes, developing practical recommendations, reporting audit results, and monitoring the implementation of agreed corrective actions.
2. Project Assurance:
- Provide independent assurance over strategic business and technology projects throughout their lifecycle to ensure effective governance, risk management, control execution, implementation readiness, and achievement of intended business outcomes.
- Review project governance, business cases, funding approvals, and accountability structures.
- Assess project planning disciplines, including scope, budget, resources, vendors, risk management, quality management, and change management.
- Evaluate project execution to ensure effective management of risks, controls, testing, security requirements, issue resolution, and key project changes.
- Assess organisational and technical readiness for implementation, including operational preparedness, support models, security approvals, disaster recovery, and business continuity arrangements.
- Conduct post-implementation reviews to confirm project objectives and benefits have been achieved, controls are operating effectively, lessons learned have been captured, and residual risks are acceptable.
- Ensure methodical documentation of risk and control matrices, testing results, conclusions and recommendations. Ensure follow up on findings and corrective actions.
- Provide input and assist with the preparation and review of the various committee packs.
- Continued combined assurance approach to ensure maximum reliance by external audit on the work of internal audit.
- Successful working relationship with the key stakeholders, while providing quality independent audit assurance on the risks that matter.
- Proactively inform senior management of significant risks or exposures related to internal controls, compliance, and/or governance requiring prompt attention.
- Staying abreast of emerging technologies, industry trends and regulatory requirements impacting IT audit practises.
- Any other ad-hoc