Confidential mandate
Risk, Control and Test Lineage Methodology Lead
Planned Hiring / New
Risk, Control and Test Lineage Methodology Lead mandate in Bengaluru, India · Financial Services
A four-month consulting build will deliver a risk-control-test lineage methodology and two-file pilot, enabling reproducible audit conclusions and visible limitations without operating business controls or assuming the chief audit executive's authority.
The mandate
The defined problem is that audit files do not consistently connect risk, control objective, procedure and conclusion. The consultant will build a lineage methodology and validate it on two agreed files. The project does not perform the entire audit plan or assume ownership of the controls being assessed.
Deliverables are a lineage specification, workpaper guidance and two pilot files with inspectable judgement and limitations. The method must expose when a procedure cannot support the proposed conclusion. It should avoid administrative overengineering: more fields and signatures are not useful unless they improve the reasoning a reviewer can examine.
Methodology work begins on 19 October 2026 for four months, closing on 18 February 2027. The first milestone, 23 November, establishes sampled lineage defects and the design specification. The second, 11 January, delivers the draft method and two-file pilot. The final, 18 February, supplies independent review results, revised guidance and user transfer. Three working days weekly are reserved.
Acceptance is by the chief audit executive and methodology sponsor. Independent reviewers must trace each pilot's conclusion to relevant procedures and evidence, identify coverage limits and use the method on a fresh workpaper. The two files must include different judgement challenges. A method that merely renames existing fields without improving traceability will not satisfy acceptance.
The sponsor supplies authorised files, nominated audit leads and access to control owners for evidence clarification. Bengaluru remains primary with scheduled review sessions. Business remediation, formal external opinions and enterprise GRC-system procurement are excluded. Additional audit families or automated tool build require approved scope control rather than assumption that the project fee covers every methodology request.
What you will own
- Catalogue lineage defects from sampled files, distinguishing irrelevant testing, unsupported conclusions and missing documentation so the design addresses the actual assurance problem.
- Specify the risk-control-test chain with explicit evidence and judgement requirements, preserving the difference between a control objective and a procedure used to assess it.
- Build workpaper guidance that exposes coverage limitations, preventing a completed test list from implying assurance over risks that were not assessed.
- Pilot the method on two files with different judgement challenges, retaining contrary evidence and unresolved questions rather than forcing uniform positive conclusions.
- Arrange independent reviewer tests using fresh workpapers, observing whether the lineage can be understood without explanation from the original audit lead.
- Revise the method from reviewer failures, removing fields that add burden without improving the inspectability of the assurance reasoning, with its specific reporting consequence retained.
- Transfer the specification and maintenance guidance to methodology owners, obtaining observed user evidence and ownership of residual limitations before final acceptance.
Candidate qualifications
- Demonstrate hands-on internal audit or methodology work with risk-control-test design. Explain a procedure that did not assess its stated objective and the change required to support a defensible conclusion.
- Show technical assurance judgement in evaluating evidence relevance and sufficiency. Candidates should describe contrary evidence that affected an audit conclusion rather than merely increasing the size of a workpaper file.
- Provide a methodology pilot tested by reviewers independent of the original preparer. Explain what they could not reproduce and how the design changed before it was accepted.
- Evidence consulting delivery with bounded artifacts, explicit acceptance and internal transfer. Show how additional audit families were handled and how the project avoided becoming the organisation's ongoing quality-review function.
- Demonstrate professional audit or accounting capability and controlled handling of sensitive files. The project does not confer business control ownership or external audit-signing powers. Candidates should explain how a fresh workpaper was processed after transfer, which limitation remained visible and how method changes were governed without silently invalidating previously reviewed conclusions. Show how the method treats a control that is relevant to the risk but lacks an executable test with available data. Candidates should explain the limitation, the decision owner consulted and why adding more routine procedures would not solve the underlying assurance gap.
Application
Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.
There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 14 October 2026. Mandate reference PCT-CON-2026-IND-16.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.