Head of Internal Audit
Tokiye Integrated Medical Services (TIMS) Ltd
Remote
Company Description
Invealth (a subsidiary of Tokiye Integrated Medical Services) is a private investment and management firm focused on identifying and optimizing key opportunities within its target sectors to create value for communities and returns for investors. The firm connects private and institutional investors with opportunities that align with a mid- to long-term perspective. Invealth is committed to enhancing efficiency and viability in its sectors of interest by attracting strategic investment and deploying robust management structures. Each asset in the portfolio is managed for sustainable growth, with a clear focus on positive impact for people and stakeholders.
Role Description
The Head of Internal Audit is a full-time, on-site role based in Port Harcourt, responsible for leading the internal audit function and ensuring a strong control environment across the firm. This role oversees risk-based audit planning, execution, and reporting, including the review of financial processes, internal controls, and compliance with policies, regulations, and industry standards. The individual will design and implement independent audit methodologies, evaluate the effectiveness of internal controls, and recommend improvements to enhance efficiency, risk management, and governance.
The Head of Internal Audit will provide the Board and Management with evidence-based assessments of the Bank's control environment, identify weaknesses and emerging risks, investigate suspected control failures or fraud, and monitor the implementation of agreed corrective actions.
The role must maintain appropriate independence from all operational and management responsibilities.
Key Responsibilities
1. Internal Audit Strategy & Planning
- Develop a risk-based annual internal audit plan for approval by the Board Audit Committee.
- Conduct periodic risk assessments to identify areas requiring audit attention.
- Align audit coverage with the Bank's strategic objectives, risk profile, regulatory requirements and emerging risks.
- Review and update the audit plan where significant changes in the Bank's risk environment occur.
- Maintain appropriate audit methodologies, procedures and documentation.
2. Financial & Operational Audits
- Conduct independent reviews of the Bank's financial and operational processes.
- Audit cash operations, vault controls, teller activities and cash movements.
- Review customer account opening, KYC documentation and transaction processing controls.
- Audit credit files, loan approval processes, documentation, disbursement and portfolio controls.
- Review reconciliations, suspense accounts, expenses, procurement and payment processes.
- Assess compliance with approved policies, delegated authorities and internal procedures.
3. Treasury & Investment Audit
- Audit treasury transactions from initiation through authorisation, confirmation, settlement and accounting.
- Review compliance with approved counterparty, investment, tenor, concentration and liquidity limits.
- Test segregation of duties between treasury dealing, approval, confirmation, settlement and accounting.
- Review treasury reconciliations and maturity records.
- Identify unauthorised, unusual or inadequately controlled treasury transactions and escalate appropriately.
4. Technology & Digital Audit
- Review the effectiveness of IT general controls, access management and system security.
- Audit digital banking channels, technology processes and relevant third-party integrations.
- Review user access rights, privileged access and segregation of duties within critical systems.
- Assess the effectiveness of technology change management, backup and disaster recovery controls.
- Work with relevant specialists where technical or cybersecurity expertise is required.
- Report material technology control weaknesses to the appropriate governance body.
5. Risk & Compliance Assurance
- Assess the effectiveness of the Bank's risk management framework and internal control environment.
- Review the effectiveness of the Compliance and AML/CFT functions without assuming responsibility for their operational activities.
- Evaluate adherence to regulatory requirements and internal policies.
- Review the effectiveness of controls designed to prevent and detect fraud, error and financial misconduct.
- Provide independent assurance on the adequacy of management's response to identified risks.
6. Fraud & Special Investigations
- Conduct investigations into suspected fraud, financial irregularities, control failures and other reported concerns as authorised.
- Gather, preserve and evaluate relevant evidence in accordance with appropriate investigation procedures.
- Identify root causes of control failures and recommend corrective measures.
- Escalate significant findings promptly to the appropriate Management and Board authorities.
- Maintain appropriate confidentiality and documentation throughout investigations.
7. Audit Reporting
- Prepare clear, objective and evidence-based audit reports highlighting findings, root causes, risks and recommended actions.
- Present significant findings and audit reports directly to the Board Audit Committee.
- Communicate material control weaknesses to Management promptly.
- Obtain and document Management responses and agreed remediation timelines.
- Provide periodic reports on the overall control environment and outstanding audit issues.
8. Remediation & Follow-Up
- Maintain a central register of audit findings and agreed management actions.
- Track implementation of corrective actions to closure.
- Conduct follow-up reviews to verify that remediation has been effectively implemented.
- Escalate overdue or inadequately addressed high-risk findings to the Board Audit Committee.
- Identify recurring findings and recommend systemic improvements.
9. Governance & Independence
- Maintain functional independence from all operational and management functions.
- Have unrestricted and appropriate access to records, systems, personnel and information required to perform approved audit activities.
- Maintain professional objectivity and avoid involvement in operational decision-making.
- Escalate any matter that could compromise audit independence to the Board Audit Committee.
- Ensure the internal audit function operates in accordance with applicable professional standards and regulatory expectations.
Qualifications
- Bachelor's degree in accounting, Finance, Economics or another relevant discipline.
- Professional certification such as ICAN, ACA, ACCA, CIA etc. is required.
- CISA certification is desirable, particularly given the Bank's technology-enabled operating model.
- A relevant postgraduate qualification is an advantage.
- Strong analytical skills with the ability to interpret complex data, identify trends, and provide actionable insights.
- Solid background in finance and accounting, including knowledge of financial reporting, budgeting, and investment-related processes.
- Experience in financial risk management, including assessment, monitoring, and mitigation of operational and investment risks.
- Expertise in designing, implementing, and evaluating internal controls across financial and operational processes.
- Professional certification such as ACA, ACCA, CIA, or equivalent is highly desirable.
- Proven experience leading internal audit functions or teams, preferably in investment, asset management, or financial services.
- Strong communication and report-writing skills, with the ability to present findings to senior leadership and stakeholders.
- High level of integrity, independence, and sound judgment, with the ability to work on-site in Port Harcourt and collaborate across functions.
- Minimum of 12 years' relevant professional experience, with atleast 3 years in a senior internal audit, external audit, risk assurance or related control role within financial services.
- Experience in banking or Microfinance Banking is strongly preferred.
- Demonstrable experience auditing financial controls, credit operations, treasury, technology, digital channels and regulatory compliance is an advantage.
Core Competencies
- Risk-based internal auditing
- Financial and operational controls
- Banking and financial services audit
- Credit and treasury audit
- IT and digital channel audit
- Fraud investigation
- Internal control testing
- Risk assessment
- Evidence-based analysis and reporting
- Regulatory and governance awareness
- Professional scepticism and objectivity
- Independence and ethical judgement
- Strong communication and stakeholder management
Benefits
An opportunity to establish an independent assurance function at the foundation of a growing Microfinance Bank and provide meaningful oversight of its governance, risk management and internal control environment. The role offers direct exposure to the Board Audit Committee and broad visibility across the Bank's financial, operational, technology and risk functions, together with a competitive compensation package aligned with the responsibilities and independence required of the position.