Role: Manager – Internal Audit (Business Audit & IT Audit)
Department: Internal Audit
Location: Mumbai The Role The Auditor is responsible for leading risk-based audit activities across business and technology functions within CRISIL. The role involves partnering with the internal audit service provider to execute the internal audit plan, conduct business process and IT audits, support Enterprise Risk Management (ERM) governance, and drive risk-related projects.
The ideal candidate should be a qualified Chartered Accountant with strong experience in internal audit, risk management and technology /cybersecurity audits, along with the ability to assess complex business processes, control environments, and technology risks.
Key Responsibilities
- Partner with the internal audit service provider to plan and execute the internal audit program.
- Lead and execute risk-based audits covering operational, financial, regulatory, and technology risks.
- Conduct integrated audits across business processes and IT environments, including cybersecurity, ITGC, data privacy, and cloud governance reviews.
- Evaluate internal controls, identify control gaps, and provide recommendations for process improvements and risk mitigation.
- Support ERM governance, including risk identification, assessment, monitoring, and reporting.
- Lead risk-related projects and drive timely closure of audit observations.
- Engage with senior stakeholders and provide insights to strengthen governance, risk management,
and control frameworks.
- Monitor regulatory developments and emerging business and technology risks.
- Support automation and data analytics initiatives to enhance audit effectiveness and efficiency.
What We're Looking For
- Strong understanding of internal audit methodologies, risk-based auditing, and internal control frameworks.
- Experience in business process audits, operational audits, and risk management.
- Hands-on experience in IT Audit, Cybersecurity Audit, ITGC reviews, technology risk, cloud governance, and data privacy.
- Strong analytical, problem-solving, and stakeholder management skills.
- Excellent written and verbal communication skills.
- Knowledge of risk and control frameworks such as COSO, COBIT, NIST, and ISO 27001.
Basic Qualifications
- Qualified Chartered Accountant (CA) – Mandatory.
- Possession of at least one recognized audit, risk or technology assurance certification such as CISA, CIA, CRMA, CISM, CISSP, ISO 27001 Lead Auditor or an equivalent certification – Mandatory.
- CISA certification will be strongly preferred.
- 7-10 years of experience in Internal Audit, Risk Management, Business Audit, IT Audit, or related assurance functions.
- Experience in financial services, consulting, or other regulated industries preferred.
- Experience conducting integrated business and technology audits.
- Robust academic and professional credentials.
📌 Manager – Internal Audit (Business Audit & IT Audit) (Mumbai)
🏢 Crisil
📍 Mumbai