Chance with SGS India for the position of Lead Auditor - ISMS and "ISO 42001".
Company Profile: Established in 1878, SGS transformed grain trading in Europe by offering innovative agricultural inspection services. SGS is the world's leading inspection, verification, testing and certification MNC. We are recognized as the global benchmark for quality and integrity. With more than 96,000 employees, we operate a network of more than 2,700 offices and laboratories around the world. We cater quality services to 9 Businesses in India like Consumer & Retail Services, Oil & Gas, Industrial services, AFL, Minerals etc.
Kindly visit our Global Website: www.sgs.com
India Website: www.sgsgroup.in
*Mandatory previous working experience should be from the "Certification Bodies."*
Position - Lead Auditor ISMS & ISO/IEC 42001
Industry - Certification Body / Management Systems Certification
Department - Certification/ Auditing
Educational Qualification
- Bachelor's degree in Computer Science, Information Technology, Engineering, Cybersecurity, Artificial Intelligence, Information Security, or a related discipline.
- Master's degree or relevant professional qualification will be an advantage.
Job Purpose
The Lead Auditor will be responsible for planning, conducting, leading, and reporting third-party management system certification audits for clients against ISO/IEC 27001 Information Security Management Systems (ISMS) and ISO/IEC 42001 Artificial Intelligence Management Systems (AIMS).
The role requires strong knowledge of certification-body processes, audit methodologies, applicable accreditation requirements, and the ability to independently manage audits from planning through reporting and follow-up of corrective actions.
Key Responsibilities
1. Third-Party Certification Audits
- Conduct Stage 1, Stage 2, Surveillance, Recertification, and Special/Follow-up Audits as applicable.
- Lead audit teams and act as the primary point of contact with clients during certification audits.
- Prepare audit plans based on the client's scope, complexity, locations, processes, and applicable requirements.
- Conduct opening and closing meetings with client management and relevant stakeholders.
- Evaluate the client's management system against applicable ISO requirements and certification criteria.
- Collect and evaluate objective evidence through interviews, document review, observation, sampling, and process evaluation.
- Identify and document Non-Conformities, Observations, and Opportunities for Improvement, as permitted by the certification scheme.
- Prepare complete and technically accurate audit reports within defined timelines.
- Review evidence submitted by clients for correction and corrective action and recommend closure based on objective evidence.
2. ISMS ISO/IEC 27001
- Conduct certification audits against ISO/IEC 27001 requirements.
- Evaluate the effectiveness of the client's ISMS and information security risk management process.
- Review information security risk assessment and risk treatment processes.
- Evaluate the Statement of Applicability (SoA) and implementation of applicable controls.
- Assess controls related to information security governance, access control, asset management, incident management, business continuity, supplier relationships, cryptography, physical security, cybersecurity, and information security operations.
- Demonstrate understanding of ISO/IEC 27002 and other relevant information security standards and practices.
3. ISO/IEC 42001 AI Management System
- Conduct certification audits against ISO/IEC 42001 requirements.
- Evaluate the organization's AI Management System and AI governance framework.
- Assess AI-related risks, opportunities, impacts, objectives, policies, and controls.
- Review AI system lifecycle processes, including planning, development, deployment, operation, monitoring, and continual improvement.
- Evaluate controls relating to AI risk management,
data governance, transparency, accountability, explain ability, fairness, privacy, security, reliability, and human oversight.
- Assess relevant AI system documentation, impact assessments, risk assessments, policies, procedures, and records.
- Keep updated with evolving AI governance requirements, standards, regulations, and industry practices.
4. Certification Body Activities
- Ensure audits are conducted in accordance with the Certification Body's documented procedures and applicable accreditation requirements.
- Determine audit time and audit-team requirements in accordance with applicable certification rules and procedures.
- Maintain auditor competence and qualification records.
- Participate in witness audits, technical evaluations, calibration meetings, and auditor competency assessments when required.
- Support technical functions in reviewing audit documentation and resolving technical queries.
- Ensure impartiality, confidentiality, and professional integrity throughout certification activities.
- Escalate technical or certification-related issues to the Technical Manager / Certification Manager when required.
- Participate in internal auditor meetings, training, standard updates, and calibration sessions.
5. Client Management
- Act as the professional representative of the Certification Body during client audits.
- Establish effective communication with client management and process owners.
- Explain audit methodology and findings clearly and objectively.
- Handle client queries regarding audit findings and certification requirements professionally.
- Maintain a strong focus on customer service while ensuring auditor independence and impartiality.
- Manage challenging audit situations while maintaining professional judgment and certification integrity.
Mandatory / Preferred Certifications (IRCA Approved)
- ISO/IEC 27001 Lead Auditor
- ISO/IEC 42001 Lead Auditor
- Third Party Audit Log sheets
Interested candidates kindly share your updated CVs, Certified Irca Approved Schemes Certificate and Audit Log Sheets on
[email protected]
📌 Lead Auditor (Kolkata)
🏢 SGS India
📍 Kolkata