1. JOB DESCRIPTION – INTERNAL AUDITOR
Job Title: Internal Auditor
Department: Internal Audit
Reports To: The Board Audit, Risk & Compliance Committee / Board
Location: Kampala, Uganda
1. JOB PURPOSE
The Internal Auditor is responsible for providing independent and objective assurance on the adequacy and effectiveness of Savanna PayPulse Limited’s governance, risk management, internal controls and operational processes.
The role will independently assess whether the Company’s operations, systems, financial activities and regulatory obligations are being managed effectively and in accordance with applicable laws, regulations, Bank of Uganda requirements, internal policies, approved procedures and industry standards applicable to Payment Service Providers.
The Internal Auditor will identify control weaknesses, assess risks, recommend practical corrective actions and independently monitor the implementation of agreed audit recommendations.
2. KEY RESPONSIBILITIES
A. Internal Audit Planning and Risk Assessment
- Develop and maintain a risk-based internal audit plan covering all material business, operational, financial, technology and regulatory risks.
- Conduct periodic risk assessments to determine audit priorities.
- Perform audits in accordance with the approved annual internal audit plan.
- Review emerging risks and recommend additional audit reviews where necessary.
- Ensure audit coverage is appropriate for the Company’s risk profile and regulatory obligations.
B. Governance and Internal Controls
- Assess the adequacy and effectiveness of the Company’s internal control framework.
- Review segregation of duties, authorisation controls, access controls and approval processes.
- Assess whether policies and procedures are properly implemented and operating effectively.
- Review governance arrangements and adherence to approved delegations and Board decisions.
- Identify control gaps and recommend appropriate remediation measures.
C. Financial and Operational Audits
- Conduct audits of financial processes, reconciliations, payments, revenue, expenditure and financial controls.
- Review operational processes for efficiency, accuracy, compliance and control effectiveness.
- Review customer funds and Trust Account safeguarding arrangements, including reconciliation and segregation of customer funds from operational funds.
- Assess the adequacy of controls over bank accounts, settlement processes and transaction processing.
- Review management of operational incidents, losses and exceptions.
D. Technology and Systems Audit
- Assess the effectiveness of IT general controls, system access and user management.
- Review system change management, system availability, backups and disaster recovery controls.
- Assess transaction processing controls and system audit trails.
- Review cybersecurity and information-security controls.
- Conduct audits of critical fintech systems, APIs, integrations and technology service providers.
- Assess the effectiveness of automated controls and system-generated reports.
E. KYC, AML/CFT and Financial Crime
- Independently assess the effectiveness of KYC and Customer Due Diligence controls.
- Review AML/CFT controls, transaction monitoring and sanctions/PEP screening.
- Assess controls relating to suspicious transaction identification and reporting.
- Review fraud prevention, detection and investigation controls.
- Test customer onboarding, account modification, transaction and account closure processes.
- Assess compliance with applicable AML/CFT and financial-crime requirements.
F. Regulatory Compliance Audits
- Conduct independent reviews of compliance with applicable laws, regulations and regulatory directives.
- Assess compliance with Bank of Uganda requirements applicable to the Company’s licensed activities.
- Review compliance with National Payment Systems requirements and other applicable regulatory obligations.
- Assess regulatory reporting processes for completeness, accuracy and timeliness.
- Review implementation of regulatory inspection and audit recommendations.
- Identify and escalate material regulatory breaches.
G. Customer Protection and Complaints
- Review controls over customer onboarding, transaction processing and customer information.
- Assess the effectiveness of customer complaint and dispute-resolution processes.
- Review adherence to approved customer service standards and SLAs.
- Test controls over reversals, refunds, chargebacks and disputed transactions.
- Assess whether customer-facing processes operate in accordance with approved terms and regulatory requirements.
H. Audit Execution and Reporting
- Develop audit programmes, working papers and testing procedures.
- Conduct interviews, walkthroughs, sample testing and control testing.
- Document audit findings based on sufficient and appropriate evidence.
- Rate findings according to their risk and potential impact.
- Prepare clear and objective audit reports for management and the Board Audit, Risk & Compliance Committee.
- Present significant findings and recommendations to relevant governance committees.
- Maintain complete and confidential audit working papers.
I. Audit Recommendations and Remediation
- Agree corrective actions and implementation timelines with responsible process owners.
- Maintain an Audit Issues and Recommendations Register.
- Conduct follow-up reviews to verify implementation of agreed actions.
- Escalate overdue or inadequately addressed high-risk findings.
- Report recurring control weaknesses to management and the Board Audit, Risk & Compliance Committee.
J. Business Continuity and Operational Resilience
- Review the adequacy of the Business Continuity Plan and Disaster Recovery Plan.
- Assess whether BCP and DR testing is conducted as scheduled.
- Review recovery objectives, backup arrangements and critical system dependencies.
- Assess lessons arising from incidents and continuity tests.
- Verify implementation of identified resilience improvements.
K. Third-Party and Outsourced Service Provider Audits
- Review controls over material third-party service providers, vendors, banks and technology partners.
- Assess contractual control requirements and service-level compliance.
- Review third-party risk assessments and monitoring.
- Where appropriate, review independent assurance reports provided by critical service providers.
3. KEY PERFORMANCE INDICATORS (KPIs)
- Percentage of approved annual audit plan completed on time.
- Timely issuance of audit reports following completion of fieldwork.
- Quality and completeness of audit working papers.
- Percentage of audit recommendations implemented within agreed timelines.
- Timely escalation of overdue high-risk findings.
- Reduction in recurring audit findings.
- Coverage of high-risk business and regulatory areas.
- Timely completion of follow-up audits.
- Number and severity of material control weaknesses identified and appropriately escalated.
- Effectiveness of audit recommendations in addressing root causes.
- Timely reporting to the Board Audit, Risk & Compliance Committee.
4. QUALIFICATIONS & EXPERIENCE
A. Education
- Bachelor’s Degree in Accounting, Finance, Auditing, Risk Management, Business Administration, Economics, Information Systems, Law or a related field.
B. Professional Qualifications
A professional qualification in one or more of the following is desirable:
- CIA – Certified Internal Auditor
- CPA
- ACCA
- CISA – Certified Information Systems Auditor
- CAMS – Certified Anti-Money Laundering Specialist
- CRISC
- Certified Risk Management or Compliance qualification
C. Experience
- Minimum 3–5 years’ relevant internal audit, risk, compliance or assurance experience.
- Experience in one or more of the following sectors is preferred:
- Banking
- Fintech
- Payment Service Providers
- Telecommunications
- Financial Services
- Experience auditing technology-enabled financial services and digital transaction platforms is an advantage.
- Experience with regulatory audits and Bank of Uganda-regulated environments is highly desirable.
5. KEY COMPETENCIES
- Strong knowledge of internal audit, internal controls, risk management and governance.
- Strong understanding of financial, operational, technology and regulatory risks.
- Knowledge of AML/CFT, KYC, Fraud risk and financial-crime controls.
- Ability to audit payment processing, digital financial services and technology environments.
- Strong analytical, investigative and problem-solving skills.
- Ability to identify root causes and develop practical control improvements.
- Strong audit documentation and report-writing skills.
- High level of integrity, independence, confidentiality and professional scepticism.
- Strong communication and stakeholder-management skills.
- Ability to challenge management constructively while maintaining professional independence.
- Strong attention to detail and ability to work independently.
- Proficiency in audit, data-analysis and reporting tools is an advantage.
6. INDEPENDENCE AND AUTHORITY
The Internal Auditor shall maintain independence and objectivity in the performance of all audit activities and shall have unrestricted access, subject to applicable confidentiality and data-protection requirements, to relevant records, systems, personnel and information required to perform assigned audits.
The Internal Auditor shall have direct and unrestricted access to the Board Audit, Risk & Compliance Committee for purposes of reporting material audit matters, significant control weaknesses and issues requiring Board attention.
The Internal Auditor shall not assume operational responsibility for the activities, systems or controls being audited.
7. CORE DELIVERABLES
The Internal Auditor will be responsible for maintaining and producing, as applicable:
- Annual Risk-Based Internal Audit Plan
- Individual Audit Programmes
- Audit Working Papers
- Internal Audit Reports
- Audit Issues and Recommendations Register
- Audit Follow-Up Reports
- Board Audit Committee Reports
- Regulatory/Compliance Assurance Reviews
- Trust Account Assurance Reviews
- IT and Systems Audit Reports
- AML/KYC and Fraud Control Reviews
- Business Continuity and Disaster Recovery Assurance Reviews
- Annual Internal Audit Assurance Report