JOB PURPOSE
The job holder will provide an independent, objective assurance on the adequacy and effectiveness of the bank’s IT governance, risk management, compliance, and internal control environment. He/she will lead and oversee the planning, execution, reporting, and follow-up of complex audit assignments in line with Information Technology Assurance Frameworks(ITAF) and Standards, CBK Prudential Guidelines, and the bank’s policies and internal audit methodology.
KEY RESPONSIBILITIES
Audit Planning
- Lead comprehensive, risk-based planning for assigned audits by analyzing enterprise risks, regulatory expectations, historical audit results, emerging risks, and strategic priorities.
- Define audit objectives, scope, and detailed test procedures that directly address inherent, residual, and emerging risks, ensuring alignment with the annual audit plan.
- Conduct in-depth process understanding through system walkthroughs, Logs analysis, policy reviews, and stakeholder interviews to identify control gaps or vulnerabilities early.
- Determine the appropriate audit approach, sampling methodology, nature, timing, and extent of testing using risk-based and data-driven criteria.
Audit Execution
- Review core banking systems, payment platforms and IT infrastructure controls.
- Conduct vulnerability assessments and penetration tests.
- Assess cybersecurity controls, access management and incident response.
- Evaluate IT governance, policies, and regulatory compliance.
- Evaluate vendor management processes, including IT service provider oversight, contract compliance, and SLA performance.
- Review the Bank’s Business Continuity Management (BCM) framework, including disaster recovery testing.
- Perform audits in accordance with Global Internal Audit Standards (GIAS) and ISACA guidelines.
- Provide Quality assurance on ICT projects before Go-Live.
- Script and schedule continuous audit reports by use of CAATs.
- Conduct forensic reviews from time to time where need arises as directed by Head Of Internal Audit.
- Perform all other related duties as assigned from time to time
Audit Reporting, Monitoring & Follow-Up
- Prepare high-impact, concise, and well-supported audit reports that clearly articulate issues, underlying root causes, associated risks, and practical recommendations.
- Present audit findings confidently to departmental heads, senior management, and governance committees where required.
- Track and monitor management action plans, validate remediation, and perform follow-up reviews to ensure the effectiveness and sustainability of corrective actions.
Risk & Compliance
- Provide independent and objective assurance on the effectiveness of the bank’s IT risk management, compliance, and governance frameworks.
- Evaluate the adequacy and operating effectiveness of controls in key risk areas and across risk types (Cyber security, Access Controls, Business continuity and System related AML risks).
- Review and challenge the quality, completeness, and accuracy of risk assessments, KRIs, RCSAs, and mitigation plans developed by business units and second-line functions.
- Test compliance with relevant laws, regulatory requirements, CBK guidelines, internal policies, and industry best practices.
- Document and escalate control weaknesses, non-compliance, unethical conduct, and emerging risks promptly and in accordance with escalation protocols.
- Provide advisory insight on new regulatory developments and business initiatives while preserving audit independence.
- Maintain up-to-date professional knowledge on emerging ICT risks.
DECISION MAKING AUTHORITY
- Determine the audit approach, depth of testing, and sampling strategies for assigned engagements based on risk assessment and professional judgment.
- Evaluate the adequacy and effectiveness of internal controls and assign issue ratings consistent with the bank’s methodology and regulatory expectations.
- Recommend improvements and control enhancements aligned with business realities and regulatory requirements.
- Escalate material risks, control failures, fraud indicators, or non-compliance without delay.
- Exercise sound judgment in balancing audit rigor, business impact, and operational practicality.
ACADEMIC BACKGROUND
- Bachelor’s degree in IT, Computer Science, or related field.
- Minimum of 3 years’ experience in IS audit, risk, forensics and security preferably in banking.
WORK EXPERIENCE
- Minimum of three (3) years’ experience in IS audit, risk, forensics and security preferably in banking
- Proven exposure to ICT banking operations audits and regulatory compliance requirements.
- Experience in using audit management systems and data analytics tools.
SKILLS & COMPETENCIES
- Advanced analytical, critical thinking, and problem-solving capabilities.
- Strong report-writing and communication skills with the ability to articulate complex issues clearly.
- High professional skepticism, attention to detail, and ability to challenge status quo effectively.
PROFESSIONAL CERTIFICATION
- CISA certification (mandatory); CISM, CEH, or ISO 27001 Lead Auditor an advantage.