• Assessing and managing risks associated with third-party vendors and service providers that involve
evaluating IT General Controls (ITGCs) and IT Application Controls (ITACs) to ensure compliance with
regulatory requirements and internal policies, ultimately enhancing the overall risk management
framework for our clients.
• Preparing comprehensive audit-ready documentation on the key controls, identification of control
gaps, and collaboration on risk mitigation strategies.
o Access Controls, Change Management, Data Backup and Recovery, System Development Life
Cycle (SDLC), Input and Output Controls, Processing Controls, and Testing Documentation
• Conducting walkthroughs and direct queries to the clients, and business team to perform and obtain
audit resources, and analyze the deficiency of the controls’ evidence materials.
• Simultaneously delivering audit related tasks and business ad-hoc to multiple clients, and cross-
functional teams while supporting the audit lifecycle to serve within a guided timeframe.
• Performing Due Diligence Questionnaires (DDQ) for the third-party risk assessment involving the initial
preparation of the audit process.