This document has been labelled as Confidential Internal
GROUP SENIOR IT INTERNAL AUDITOR
|
Job Title: |
Senior IT Auditor |
Brand/ Function: |
Group Internal Audit |
|
Job Holder |
Vacancy |
Reports to: |
Sally King IA and Risk Director |
|
JD Completed By: |
Kubashni Sannasy |
Direct reports |
- |
|
Date: |
01/07/2026 |
||
|
What is the main purpose of the job? |
To provide independent, objective assurance to the Audit Committee on the effectiveness of Whitbread’s system of Technology & Data risk management and internal control environment across all business units in the UK and internationally. The role supports Whitbread in accomplishing its objectives by bringing a systematic, disciplined approach to evaluating and improving the effectiveness of risk management, control and governance, while providing consulting advice that adds value and improves operations. It also acts as a trusted advisor and critical friend to business and IT stakeholders by translating complex technology, cyber and data risks into clear business impacts for senior stakeholders and governance forums. The role is integral in delivering the strategic objectives of the Internal Audit and Risk function. The role involves working with senior stakeholders across Whitbread and therefore requires excellent interpersonal skills, strong influencing and negotiation skills, and the ability to work effectively with diverse groups. Working in small teams across all Whitbread operations, this role requires a team player with strong planning and organisational skills to carry out efficient and effective IS audits. It will involve the use of data analytics tools such as Power BI, and AI tools such as Microsoft Copilot and Claude throughout the audit lifecycle. Strong data analysis, report writing, and communication skills are required. |
||
|
Who are the Job holder main customers? |
The role will support the IA & Risk Director, working with Technology and Business stakeholders across all business areas (up to Director level), external auditors, and any relevant third parties, including internal audit co-source providers. |
||
|
Main Tasks and Activities |
Measures
|
|
Audit Planning: - Assist and support the development of the annual internal audit plan for Whitbread, using risk, assurance and business change inputs, including risk assessments and engagement with key stakeholders, to shape a targeted IT audit plan aligned to the highest priority technology and data risks; - Plan and scope IT internal audit reviews, including meeting key stakeholders, drafting audit Terms of Reference. Audits may include programme assurance reviews as well.
Audit Fieldwork: - Develop RACM which includes designed and operating effectiveness testing procedures, as well as use of data analytics. - Meet with stakeholders to understand the design of key information system controls and carry out detailed testing to identify control gaps; - Manage relationships with key stakeholders, both business and IT, to ensure they are aware of the issues being identified through the audit; - Where required, manage co-source resource to deliver audit fieldwork, ensuring audit evidence, testing rationale and issue traceability are clearly documented to support quality assurance and audit defensibility.
Audit Reporting: - Draft high-quality, clear and concise audit reports which clearly distinguish between issues, root cause, risk impact, management actions and agreed ownership to support accountability and effective decision-making.
Audit Action Tracking: - Monitor implementation of control recommendations, and assist in reporting status to the Board and Audit Committee.
Data Analytics and AI Enablement: - Maintain and enhance existing data analytics use cases, models and dashboards, including Power BI outputs where relevant, while consistently identifying opportunities to apply data analytics and AI-enabled approaches responsibly, with appropriate data quality checks, validation and documented limitations, to improve audit planning, fieldwork, insight generation and reporting.
IT Risk Management: - Provide guidance to stakeholders to assess and manage IT risks, including emerging technology, cyber, data, resilience and third-party risks, and understand where processes could go wrong, where key controls are IT enabled and what improvements could be made.
Programme Assurance: - Work with the business to provide assurance on, and governance of, key IT projects and critical change activities, including consideration of delivery risk, control readiness, benefits realisation and governance effectiveness for major technology and data change programmes.
Internal Audit Best Practices: - Develop the Internal Audit function by suggesting and driving improvements to auditing practices, methods, procedures and documentation, specifically around data analytics and integrated audits.
ExCo and Audit Committee Reporting: - Coordinate and draft ExCo and Audit Committee reports, ensuring key messages, issue updates and supporting information are accurate, complete and issued in line with agreed reporting timelines. |
|
|
Qualifications |
Skills (Expert ability) |
Experience (Proven expertise) |
|
Essential:
|
Essential:
|
Essential:
|
|
Desirable:
|
Desirable:
|
Desirable:
|