Be part of CIBI Information Inc., a purpose-driven company at the forefront of enabling better credit decisions in the Philippines and beyond.
ROLE OVERVIEW:
Senior Manager, Internal Audit will be responsible for providing independent, objective and risk-based assurance to the Audit Committee and senior management regarding CIBI's key business processes, controls and governance arrangements in line with the IIA Global Internal Audit Standards (GIAS). This role involves conducting walkthroughs, performing control testing, transaction sampling, and data analysis to assess process effectiveness, identifying root causes, evaluating business impact, assessing risk severity, and providing practical recommendations to strengthen controls and improve those processes.
KEY RESPONSIBILITIES:
I. Audit Strategy & Planning
- Develop and maintain a riskbased annual Internal Audit plan for Audit Committee approval
- Build and maintain an audit universe covering CIBI's key processes, systems and risk areas
- Continuously reassess emerging risks and adjust audit priorities accordingly
II. Audit Execution
Plan, scope and execute internal audit engagements including but not limited to:
- Operational audits: Service delivery, collections, data processing, customer onboarding
- IT General Controls (ITGC): Access management, change management, system operations (distinct from ISMS/ISO scope)
- Procurement & vendor payments: Vendor selection, PO process, payment controls, contract compliance
- Fixed assets: Asset register accuracy, physical verification, disposal controls
- Financial month end close: Journal entries, reconciliations, cutoff procedures, reporting accuracy
- Revenue & billing integrity: Billing accuracy, collections, write off approvals
- Payroll & HR controls: Payroll master data, ghost employee checks, leave/benefits controls
- Regulatory compliance: Data Privacy Act, NPC circulars, CIC/SAE obligations (spot checks)
III. Reporting & Communication
- Prepare clear, concise, action-oriented audit reports with findings, risk ratings, root causes and agreed management action plans
- Present audit results and key themes to the Audit Committee and senior management
- Provide periodic IA dashboards (audits completed, findings status, overdue actions, emerging risks)
IV. FollowUp & Closure
- Track and validate management action plans to ensure timely and effective implementation
- Escalate overdue or inadequately addressed findings to the Audit Committee
- Monitor repeat findings and drive systemic improvements
V. Governance & Independence
- Maintain professional independence and objectivity per IIA GIAS
- Draft and maintain an Internal Audit Charter for Audit Committee approval
- Ensure all work is supported by structured, evidence-based working papers
VI. Coordination
- Coordinate with ISMS Auditor to avoid duplication and ensure complementary coverage across ISO/ISMS and operational audit domains
- Liaise with external auditors (statutory, ISO, SOC2) to leverage assurance and minimise gaps
- Coordinate with Shareholder Representative for oversight, quality review and Audit Committee support as required
REQUIREMENTS:
- Bachelor's degree in Accounting, Finance, Information Technology or related discipline.
- Minimum 8–10 years of progressive internal audit experience, with at least 3 years in a supervisory or managerial role.
- Professional certification: CIA (Certified Internal Auditor) or CPA (Certified Public Accountant)
- Demonstrated experience across operational, financial and IT audits (not limited to compliance or checklist-based reviews)
- Strong command of risk-based audit methodology and control frameworks (e.g. COSO, COBIT)
- Working knowledge of the IIA Global Internal Audit Standards
- Proven ability to prepare Audit Committee-ready reports and present to senior leadership or board-level stakeholders
- Hands-on executor; willing and able to personally conduct audits
Desirable:
- CISA (Certified Information Systems Auditor)
- Prior experience in financial services, credit bureaus, data-intensive or technology companies
- Familiarity with the Philippine regulatory landscape (Data Privacy Act / NPC, BSP, CIC/SAE framework)
- Exposure to ISO 27001 / SOC2 environments
- Background with Big 4 or reputable boutique IA firms
- Experience with data analytics or CAATs (computer-assisted audit techniques)