- Location
- Jersey, Channel Islands
- Type
- Internship
- Department
- Finance
- Seniority
- Internship
Description
Head of Internal Audit and Risk
Application Deadline: 22 October 2026
Department: Internal Audit
Employment Type: Permanent
Location: Jersey, Channel Islands
Reporting To: Katy McBride
Description
Key Responsibilities
- Lead the internal audit function, providing clear direction, day-to-day oversight and technical leadership to the team.
- Own the implementation of the approved Internal Audit Plan, prioritising activity where necessary to reflect emerging risks and business priorities.
- Act as the primary escalation point for significant audit issues, judgements and matters affecting the independence or effectiveness of Internal Audit.
- Manage the Internal Audit methodology and Charter, ensuring work is risk-based, consistently delivered and aligned with the Global Internal Audit Standards (2024).
- Review and challenge audit scopes, working papers and reports to ensure findings are well evidenced, clearly communicated and focused on delivering valuable assurance and recommendations.
- Provide regular updates and formal reports to the Finance Director and the Audit and Risk Committee regarding delivery, findings, management actions and high-risk or overdue items.
- Meet privately with the Chair of the Audit and Risk Committee at each committee cycle. Report annually on the adequacy of Internal Audit resources, skills and capacity.
- Lead Internal Audit’s contribution to the Board’s Provision 29 declaration process, including material controls testing and liaison with the Company Secretary and external auditor.
- Lead the Risk Management function and develop an enterprise risk management framework aligned with recognised practice, including COSO ERM and the Three Lines Model.
- Own the Group risk documentation and ensure principal, emerging, operational resilience and other material risks are clearly assessed, assigned and monitored.
- Lead the annual Board Risk Session and provide clear reporting to Executive Management and the Audit and Risk Committee on risk exposure, appetite, trends and mitigation.
- Partner with senior leaders to strengthen first-line risk ownership while balancing risk management with commercial and operational objectives.
- Integrate risk insights into internal audit planning so assurance activity remains focused on the areas of greatest importance to the Group.
- Promote a strong risk-aware culture through practical mentoring, training and ongoing engagement with risk and control owners.
- Own assurance planning for sustainability and ESG disclosures within the Annual Report, working with the Sustainability Reporting team.
- Lead, mentor and develop the teams responsible for Internal Control and Risk Oversight, setting clear objectives and supporting professional growth.
- Oversee team capacity, availability and working arrangements to maintain effective delivery.
- Own relationships with co-source providers, including scope, quality, cost, performance and value for money.
- Propose the annual budget for Internal Audit and Risk Management and approve relevant co-source arrangements, expenses and invoices within delegated authority.
- Oversee the whistleblowing framework across the organisation, ensuring policies, reporting routes and investigation processes are effective.
- Ensure concerns are handled confidentially, investigated appropriately and resolved within policy timescales.
- Monitor outcomes and management actions so root causes are addressed and lessons are embedded.
- Promote a speak-up culture and report activity, themes and significant matters to the Executive Leadership Team and the Audit and Risk Committee.
Skills, Knowledge & Expertise
- Substantial senior leadership experience across areas such as internal audit, risk management or control functions, including responsibility for leading a multidisciplinary team.
- Demonstrable experience leading an internal audit function and managing co-source or outsourced providers.
- Strong understanding of the 2024 Global Internal Audit Standards framework and practical application of risk-based audit methodology.
- Experience developing and delivering an audit plan aligned to principal risks, with direct reporting to an Audit and Risk Committee and engagement with a Board.
- Sound knowledge of risk management frameworks used in organisations, such as COSO ERM or ISO 31000, and the Three Lines Model.
- Experience maintaining risk registers and producing clear, decision-useful risk reporting for senior leaders and committees.
- Strong understanding of financial processes and controls, including the ability to assess control design and operating effectiveness.
- Solid understanding of the UK Corporate Governance Code, particularly Provision 29, together with IT General Controls, ERP and core finance systems, fraud risk and anti-fraud controls.
- Excellent judgement, communication and stakeholder management skills, with the confidence to provide independent challenge at Executive and Board level.
- Professional qualification related to internal auditing or risk management, such as CIA, or equivalent demonstrable leadership experience.
- Qualified accountant status, such as ACA, ACCA or CIMA, particularly where the role supports financial controls and sustainability or Annual Report assurance.
- Broader IT audit experience across application controls, cyber security or data governance.
- Experience providing assurance over major IT projects, ERP implementations, system changes or data migrations.
- Experience using data analytics or audit tools, such as ACL, IDEA or Power BI.
- Experience delivering training related to risk management or internal controls and managing multiple complex workstreams.
- Typically, 10 or more years’ proven experience in organisational review, risk management or controls, including several years at senior leadership level.
- Significant experience in a listed or regulated environment.
- A minimum of three years’ relevant post-qualification experience where a professional qualification is held.
- Practical expertise in audit functions related to internal processes, internal controls or SOX-style compliance environments.