|
Audit Planning:
- Assist and support the development of the annual internal audit plan for Whitbread, using risk, assurance and business change inputs, including risk assessments and engagement with key stakeholders, to shape a targeted IT audit plan aligned to the highest priority technology and data risks;
- Plan and scope IT internal audit reviews, including meeting key stakeholders, drafting audit Terms of Reference. Audits may include programme assurance reviews as well.
Audit Fieldwork:
- Develop RACM which includes designed and operating effectiveness testing procedures, as well as use of data analytics.
- Meet with stakeholders to understand the design of key information system controls and carry out detailed testing to identify control gaps;
- Manage relationships with key stakeholders, both business and IT, to ensure they are aware of the issues being identified through the audit;
- Where required, manage co-source resource to deliver audit fieldwork, ensuring audit evidence, testing rationale and issue traceability are clearly documented to support quality assurance and audit defensibility.
Audit Reporting:
- Draft high-quality, clear and concise audit reports which clearly distinguish between issues, root cause, risk impact, management actions and agreed ownership to support accountability and effective decision-making.
Audit Action Tracking:
- Monitor implementation of control recommendations, and assist in reporting status to the Board and Audit Committee.
Data Analytics and AI Enablement:
- Maintain and enhance existing data analytics use cases, models and dashboards, including Power BI outputs where relevant, while consistently identifying opportunities to apply data analytics and AI-enabled approaches responsibly, with appropriate data quality checks, validation and documented limitations, to improve audit planning, fieldwork, insight generation and reporting.
IT Risk Management:
- Provide guidance to stakeholders to assess and manage IT risks, including emerging technology, cyber, data, resilience and third-party risks, and understand where processes could go wrong, where key controls are IT enabled and what improvements could be made.
Programme Assurance:
- Work with the business to provide assurance on, and governance of, key IT projects and critical change activities, including consideration of delivery risk, control readiness, benefits realisation and governance effectiveness for major technology and data change programmes.
Internal Audit Best Practices:
- Develop the Internal Audit function by suggesting and driving improvements to auditing practices, methods, procedures and documentation, specifically around data analytics and integrated audits.
ExCo and Audit Committee Reporting:
- Coordinate and draft ExCo and Audit Committee reports, ensuring key messages, issue updates and supporting information are accurate, complete and issued in line with agreed reporting timelines.
|
- Feedback from IA Management
- IA KPI metrics - Timely completion of assigned audits to highest standards with positive feedback from key stakeholders; audit reports are valued by the Audit Committee & Management;
- QAIP internal review with minimal comments
- Audit work is thoroughly documented, there is robust tracking of open audit issues, and audit outputs demonstrate clear linkage between risk assessment, testing performed, evidence obtained, findings raised and final audit opinion.
- ExCo and Audit Committee reporting packs are accurate, complete and issued in line with agreed governance timelines.
- Committee reporting clearly reflects key risks, issue status, management actions and agreed decisions, with minimal rework required following review.
- Existing data analytics use cases, models and dashboards remain accurate, relevant and maintained in line with audit requirements.
- Data analytics implemented in all audits, driving insight to stakeholders
|