Confidential mandate
Internal Audit and GRC Transformation Principal — Interim
Urgent / Replacement
Internal Audit and GRC Transformation Principal mandate in Bengaluru, India · Financial Services
An interim assurance-principal role requires twelve months of internal audit and GRC cover, restoring risk-to-test evidence and accountable reporting while preserving independent assurance boundaries and transferring a repeatable audit operation to the successor.
The mandate
A methodology leadership gap exists across risk assessments, control records and audit testing. The gap is not an absence of audit activity; it is an absence of consistent judgement about what the activity proves. The interim will hold delegated internal audit and GRC leadership, restoring evidence quality without assuming ownership of the controls it must independently assess.
Twelve months of cover starts on 19 October 2026, with five working days weekly from Bengaluru and agreed assurance-interface sessions. A permanent principal search runs in parallel. The first audit review must identify where risk statements fail to connect to testable controls, where testing does not support a conclusion and which methodology changes are essential before the next committee report.
Handover requires a coherent risk-control-test lineage, documented assurance judgements and audit leads able to explain both findings and coverage limitations. The successor must challenge a fresh audit file and chair a reporting review. Closure is the controlled transfer of assurance leadership, not a promise that all business risks have been eliminated or every finding remediated.
The principal may set audit evidence standards, direct existing programme capacity and approve assurance conclusions within the chief audit executive's delegation. Changes to the audit charter, permanent staffing and acceptance of major residual risk require the appropriate executive or committee decision. Business owners retain control remediation; the interim cannot operate a control and then present its own work as independent assurance.
Enterprise finance leadership, regulatory representation and implementation of business AI systems are excluded. The sponsor provides authorised audit files, risk registers and nominated control owners. The scope requires internal audit, GRC and transformation leadership that preserves independent testing while business owners operate controls and management retains residual-risk acceptance.
What you will own
- Decide assurance-file readiness through risk-to-test evidence, requiring audit leads to explain how the selected procedures support the conclusion rather than count completed workpapers.
- Establish the methodology issue register with materiality, coverage and ownership, separating weak documentation from a test design that cannot assess the stated risk.
- Set delegated audit conclusions that retain contrary evidence and limitations, escalating judgements beyond the chief audit executive's authorised review threshold.
- Reallocate existing audit capacity toward consequential coverage gaps, documenting which planned work is deferred and the assurance exposure accepted by the authorised owner.
- Chair GRC methodology reviews that preserve business control ownership, preventing assurance teams from quietly becoming the operators of the controls they evaluate.
- Direct finding-quality reviews so recommendations address the evidenced cause and risk, not a generic demand for more policy, training or monitoring.
- Transfer the lineage method and judgement archive through fresh-file successor challenge, confirming ownership of unresolved coverage limitations before the interim exits.
Candidate qualifications
- Demonstrate principal or senior internal audit leadership in financial services or a comparable controlled environment. Explain an assurance conclusion you challenged, the risk and test evidence involved and the authority that retained residual-risk acceptance. Candidates must distinguish audit leadership from management ownership of the underlying process.
- Show technical GRC competence through an actual risk-control-test chain. Describe a control that looked relevant but could not be assessed by the planned procedure, how testing changed and why the revised evidence supported a different or more qualified conclusion.
- Evidence transformation judgement that improved audit method without losing independence. Provide a case where automation, data analysis or AI changed assurance work, including the validation needed before outputs could influence a committee conclusion.
- Demonstrate leadership of audit capacity and reporting under pressure. Explain a coverage tradeoff, who authorised the deferral and how the limitation remained visible rather than disappearing from the final report.
- Provide durable transfer proof and appropriate professional accounting or assurance capability. Show how another principal challenged a fresh file using your retained method, how contrary evidence was preserved and how confidential control information was restricted. Explain how the successor distinguished a deficient test from a failed business control, preserved that difference in committee reporting and obtained the authorised decision on any remaining coverage gap.
Application
Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.
There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 12 October 2026. Mandate reference PCT-INT-2026-IND-16.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.