About Us
CIC Insurance Group is a leading insurance and financial services organisation with more than five decades of experience helping individuals, families, and organizations achieve financial security.
We have grown into a dynamic Group offering life, general, micro insurance, asset management, and investment solutions, with operations in Kenya, Uganda, South Sudan, and Malawi, and are listed on the Nairobi Securities Exchange.
Our tagline, “We Keep Our Word,” reflects our unwavering commitment to integrity, transparency, and delivering on our promises to our clients, partners, and communities.
CIC Group is passionate about innovation, digital transformation, and inclusive insurance solutions that meet the evolving needs of cooperatives, SMEs, corporates, and individuals. By joining us, you will be part of a team that is shaping the future of financial protection across Africa.
About the Role
Reporting to the Director Internal Audit, the role holder will provide independent and objective assurance and advisory services that strengthen governance, risk management and internal controls across assigned business units. The role supports delivery of the Internal Audit Strategy through risk-based auditing, data-driven assurance, continuous monitoring and practical recommendations that improve business performance and control effectiveness.
Key Responsibilities
- Execute end-to-end risk-based ICT and technology audits in accordance with the approved Internal Audit Plan, Internal Audit methodology, professional standards, regulatory requirements and the organization’s ICT risk profile.
- Participate in enterprise and ICT risk assessments and contribute to the development of the annual Internal Audit work plan, with consideration of emerging technology risks, cybersecurity threats and changes in the organization’s technology landscape.
- Develop audit objectives, scope, risk and control matrices, audit programmes and testing strategies for assigned ICT audit engagements.
- Conduct ICT audits covering IT governance, cybersecurity, information security, IT general controls, application controls, IT infrastructure, networks, databases, cloud services, system development, change management, access management, IT operations, data management, business continuity and disaster recovery, as applicable.
- Assess the design and operating effectiveness of IT General Controls (ITGCs), including logical and physical access controls, privileged access, segregation of duties, change management, backup and recovery, incident management and IT operations.
- Review controls over third-party and outsourced technology services, including vendor due diligence, contractual obligations, service-level agreements, information security requirements, performance monitoring, access to organizational data and exit arrangements.
- Develop data-driven audit tests to identify unauthorized access, unusual user activity, segregation-of-duties conflicts, dormant accounts, duplicate transactions, system overrides, control breaches, anomalies and other indicators of technology or fraud risk.
- Use appropriate audit, data analytics and visualization tools, including advanced Excel, IDEA, Power BI, SQL and other relevant ICT audit or analytics tools, where applicable.
- Contribute to the development and implementation of continuous auditing, continuous monitoring and automated control testing to improve audit efficiency, coverage and early identification of emerging technology risks.
Audit Quality, Professional Standards and Independence
- Perform audit work in accordance with the Internal Audit Charter, approved methodology, policies and applicable professional standards.
- Ensure audit assignments are completed to required quality standards and within agreed timelines.
- Maintain complete, accurate and well-organized audit documentation to support review and quality assurance.
Stakeholder Engagement
- Build effective working relationships with business and functional management while maintaining appropriate audit independence.
- Communicate audit issues clearly and constructively to process owners and senior management.
Who We’re Looking For
Essential Knowledge/Skills and Experience Required:
- Bachelor’s degree in a business-related field.
- CISA
- CPA/ACCA / CIA/ Computer Assisted Audit Techniques is desirable
- Insurance Professional Qualification is desirable
- 3-5 years’ experience. At least 2 years’ experience in the big 4 audit firms or an organization similar in size or larger than CIC Group is an added advantage
- Knowledge of current technological developments/trends in area of expertise and knowledge of software requirements for audit of systems procedures
- Basic knowledge of regulations by AKI and IRA
- Excellent communication skills – written, oral, presentation and report writing
- Ability to maintain highest levels of integrity and objectivity
- Flexibility in mobility