HamburgerMenu
iimjobs

Posted by

Job Views:  
23
Applications:  4
Recruiter Actions:  1

Job Code

1730498

Manager - Internal Audit - eCommerce

Careernet.8 - 12 yrs.
rupee39-70 LPA
.Bangalore
Posted today
Posted today

1. Strategic Audit Program Management:

- Audit Lifecycle Oversight: Design and lead the Internal Audit (IA) framework commensurate with the entity's size, scale, and complexity to provide assurance to the Board and regulators.

- Third-Party (3P) Management: Program manage external audit firms (e.g., Big 4) to execute specialized audits while maintaining ultimate ownership of audit reports and findings.

- Risk-Based Roadmap: Develop and execute an audit roadmap that addresses key strategic questions (KSQs) regarding regulatory compliance and adherence and risk management.

- Emerging risk identification: Proactively monitor the evolving fintech landscape to identify new areas for audit, ensuring the audit plan remains dynamic and addresses size, scale, and complexity as the entity grows.

- Issue Resolution: Drive timely resolution of audit observations.

- Liaising with Internal and external Stakeholders: To meet the expectations, he/she should maintain the relationship with other governance functions within the organisation. Also, to meet the expectation from external regulated bodies (RBI etc.).

2. Regulatory and Statutory Mandates:

- KYC and AML Assurance: Conduct internal audits to review compliance with the RBI (Know Your Customer) Directions, 2025, covering customer sourcing, onboarding, credit underwriting, AML framework, policy and procedures.

- Outsourcing Risk Management: Conduct regular audits of service providers and sub-contractors to assess risk management adequacy (including contractual review), concentration risk, with RBI Outsourcing Directions, 2025 and in line with Service arrangements with the third-party vendors.

- Related Party Reviews: Implement quarterly reviews to monitor adherence to guidelines for all transactions and loans, including disbursement and repayment processes.

- Digital Lending Compliance: Audit the adherence to Digital Lending Guidelines (DLG), ensuring the integrity and compliance in digital customer journeys.

- Financial Policy and Disclosure etc. - Review the accounting policy adopted by FFPL and to ensure that all disclosure and reporting requirements meet the regulatory expectations.

- Other mandates: Perform end-to-end review of lending lifecycle, collateral and NPA management to align with income recognition norms.

3. IT, Cyber Security and Data Privacy Governance:

- IT General Controls (ITGC) Auditing: Review Identity and Access Management (IAM) specifically checking for multi-factor authentication and privileged access roles. Review of change management, backup and restoration controls.

- IT Applications Controls (ITAC) Auditing: Review of ITACs controls implemented for automating business processes. Review of APIs in use for data transfer among various applications.

- IPE Reports testing: Audit of IPE reports used for financial reporting purpose from accuracy and completeness perspective.

- Cyber Incident Auditing: Audit the physical facilities of the Security Operations Centre (SOC) and test the reporting protocol of cyber incidents between the vendor, NBFC, and RBI as per internal timelines. Also, assess if the NBFC has unambiguous ownership of the rule definitions and analytics used by the outsourced SOC.

- Cloud Security Oversight: Verify the existence and implementation of the Cloud Adoption Policy, multi-factor authentication, and data portability and secure purge processes for cloud services.

- Cybersecurity Auditing: Verify the cybersecurity controls related to network security, application security, vulnerability management.

- Tech Continuity: Audit Business Continuity Plans (BCP), including joint testing and recovery exercises between FFPL and its service providers.

- Data Privacy: Review data privacy controls in place like data encryption and masking to ensure any PII is not compromised.

4. Board and Audit Committee (AC) Liaison:

- Direct Reporting and Independence: Maintain a direct reporting line to the Audit Committee and the Board to ensure functional independence.

- Director Assurance: Provide the necessary audit reports and oversight to enable Directors to confidently sign the mandatory Deed of Covenant confirming internal control compliance.

- Statutory Auditor Coordination: Act as the primary bridge for Statutory Auditors (under CARO 2020) to ensure the IA system is viewed as commensurate with the business nature and that all IA reports are adequately considered.

Didn’t find the job appropriate? Report this Job

Similar jobs that you might be interested in

Posted by

Job Views:  
23
Applications:  4
Recruiter Actions:  1

Job Code

1730498

Loading chat...