Confidential mandate

Third-Party Risk Audit Framework Director

Planned Hiring / New

Third-Party Risk Audit Framework Director mandate in Paris, France

Confidential Third-Party Risk Audit Framework Director in Paris, France, reporting to the Internal Audit Methodology Sponsor. Consulting Internal & Statutory Audit appointment at Director level, a 7-month mandate horizon; four days a week.

The mandate

This project will create an internal-audit framework for third-party risk across the relationship lifecycle without exposing any supplier, service or concentration detail. The commission is methodological and pilot-based. It must connect enterprise dependency to audit scope, distinguish management monitoring from independent assurance and address nth-party limitations honestly.

Six artifacts define delivery: third-party auditable universe, risk-and-dependency taxonomy, audit programme library, two-engagement pilot, evidence-quality report, and governance-and-transfer handbook. The framework must scale audit effort by criticality and uncertainty rather than apply one questionnaire depth to every relationship.

Milestones occur at weeks four, eight, thirteen, nineteen, twenty-four and twenty-eight. The Methodology Sponsor accepts universe and taxonomy; the Audit Quality Head accepts programmes and pilot; the Chief Audit Executive delegate accepts quality report and transfer. Acceptance requires population reconciliation, traceable scope, sufficient evidence and internal replication.

Client inputs include approved third-party inventories, ownership definitions, contract-control summaries, management monitoring, incident themes and two pilot populations. The consultant will not contact providers, renegotiate contracts, perform due diligence or operate monitoring. Missing population evidence is itself recorded as an audit limitation and project dependency.

What you will own

  • Reconcile third-party populations across approved sources and classify relationships by service criticality, access, substitution and concentration.
  • Define lifecycle risks spanning selection, contracting, access, performance, resilience, compliance, change and exit.
  • Design audit programmes that test management's governance and evidence rather than duplicate supplier-assessment questionnaires.
  • Establish scope for subcontractor and nth-party exposure, including limitations where contractual or information rights are absent.
  • Pilot one lifecycle audit and one thematic dependency review, recording evidence gaps and methodology changes.
  • Create reliance criteria for certifications, reports and management monitoring, with independent evaluation of scope and currency.
  • Define finding, rating and root-cause conventions that distinguish individual-provider weakness from enterprise governance failure.
  • Transfer the framework through internal scoping and review of a third engagement without consultant correction.

Candidate qualifications

  • At least 15 years in internal audit, third-party risk or external assurance, including Director-level methodology work.
  • Current French CPA equivalent, ACA, ACCA or comparable recognised audit qualification, supported by CIA or CISA where relevant.
  • Evidence of finding a material nth-party or concentration risk absent from the direct-provider assessment.
  • Expertise in population completeness, lifecycle governance, contractual audit rights, assurance reliance, resilience and exit.
  • A case where management monitoring appeared extensive but could not support independent assurance.
  • Experience separating audit from procurement, due diligence, contract management and operational monitoring.
  • Demonstrated transfer through internal completion of a new third-party audit scope and file review.

Working terms and boundaries

  • The seven-month project is delivered four days weekly, with scheduled Paris travel around design, pilot and transfer.
  • Deliverables include framework, two pilots and handover; provider contact, procurement, due diligence and monitoring are excluded.
  • The consultant recommends audit design but cannot issue final findings or alter supplier relationships.
  • Approved inventories, ownership, contract summaries, monitoring and pilot populations are required client inputs.
  • Completion requires reconciled populations, accepted pilot files, resolved critical methodology defects and internal replication.

Application

Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.

There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 12 October 2026. Mandate reference AUD-CON-2026-PAR-33.

More seats like this one

Every live mandate, by seat →

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.