Confidential mandate
Technology Risk Committee Adviser — Automated Control Evidence Reliance
Planned Hiring / New
Technology Risk Committee Adviser mandate in Mumbai, India · Banking Technology Assurance
Advise a banking technology-risk committee for nine months on reliance upon automated control evidence, testing source coverage, freshness and interpretation so directors understand what a consolidated assurance dashboard establishes and which consequential uncertainties remain outside its apparent completeness.
The mandate
A banking technology-risk committee increasingly receives dashboards populated by automated control evidence, but it cannot yet distinguish complete collection from sufficient assurance. Access reviews, change controls and third-party findings enter the same consolidated view despite different source populations and review conditions. The standing question is how much reliance directors should place on that apparent completeness. This nine-month retainer starts on 26 October 2026 and adds an independent GRC and IT-audit perspective to committee challenge, without providing an audit opinion or certifying the bank's entire control environment.
The adviser will test the logic linking source activity, evidence collection, reviewer judgement and the reported control conclusion. A record can be current but cover only part of the population; a closed review can retain an unresolved exception; a scheduled extract can fail without making the dashboard obviously incomplete. You will help directors ask consequential questions about these limits and compare management's proposed safeguards. Control owners remain accountable for their evidence, and internal audit retains independent assurance methodology. The retainer must clarify reliance, not create another executive certification layered over theirs.
Three days monthly cover a preparation session, focused evidence conversations and a written note identifying the committee's decision questions. Quarterly technology-risk committee attendance is included in the retainer in addition to the working days. Complete ad-hoc requests receive a substantive response within two business days; incomplete packs receive an explicit list of missing inputs. The month-nine review may support a chair-sponsored renewal, but the committee must approve its new written scope and term, capped at twelve months, with capacity and price agreed afresh. Additional investigations or attendance require a separate decision rather than expanding this retainer into open-ended assurance work.
The adviser has no line authority within technology or assurance teams and no executive responsibility for control operation, remediation or risk acceptance. This is neither a board appointment nor a transfer of fiduciary duties. Three other non-competing specialist commitments are permitted if the reserved capacity remains available. Relationships with dashboard suppliers, GRC implementers or organisations whose confidential control evidence could conflict must be disclosed before access. The chair determines appropriate information barriers, recusal or termination; compensation is independent of whether the committee adopts management's preferred reliance position.
What you will own
- Challenge dashboard coverage claims against the source population and collection path, asking directors to distinguish a complete extract from evidence that genuinely supports the control conclusion being presented.
- Test freshness assumptions by examining failed feeds, changed populations and review dates, exposing situations where a recently refreshed display still relies on stale or materially incomplete underlying judgement.
- Shape committee questions about reviewer authority and unresolved exceptions, preventing a completed workflow task from being interpreted automatically as proof that the associated technology exposure has been addressed.
- Press management on evidence-reperformance examples for selected consequential controls, recommending demonstrations that reveal whether the reported result remains defensible when its source and review logic are examined independently.
- Review proposed safeguards for collection failures and manual overrides, asking the committee to consider how missing evidence becomes visible before favourable dashboard status influences a material decision.
- Counsel the chair on reliance boundaries and specialist referrals, preserving explicit questions for internal audit or control owners where the available evidence cannot support the assurance management proposes.
- Recommend a concise committee record of accepted limitations, further evidence and review dates, keeping directors' choices distinguishable from the adviser's challenge and management's obligation to execute corrective work.
Candidate qualifications
- Describe a technology-control report whose apparent completeness overstated the assurance it provided. Explain the population, source or review limitation you identified and how that changed an executive question or reliance decision. The required judgement connects GRC evidence with IT-control meaning; it is not satisfied by finding a stale timestamp without understanding whether the underlying conclusion was affected.
- Bring a 22–28-year career in banking GRC technology, IT risk, audit-related transformation or comparable financial-services assurance delivery. MetricStream functional knowledge or equivalent applied GRC expertise should enable informed challenge of evidence workflows. Show how you worked with independent assurance and operational control owners while preserving their different responsibilities, rather than claiming that familiarity with a platform confers an audit opinion.
- Evidence committee or senior stakeholder influence without executive authority, including a case where management resisted disclosure of uncertainty. You must be able to propose a meaningful re-performance or coverage test, explain its limitations and leave a documented decision route. Strong functional and IT-control judgement matters more than an expansive checklist that treats every available system field as equally consequential evidence.
- Reserve three days monthly and quarterly attendance, meeting the two-business-day response commitment for complete requests. Disclose platform, implementation and competing advisory relationships with a workable recusal method. Clear writing and disciplined confidentiality are essential: the committee needs a short, defensible account of what can and cannot be concluded, while control owners retain the detailed operational work needed to improve the evidence.
Application
Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.
There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 15 October 2026. Mandate reference CVU-ADV-2026-IND-136.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.