Plan and execute assigned activities within the Company’s SOX 404 compliance program, ensuring work is completed accurately, on time, and in alignment with internal methodology and external-auditor expectations.
Risk and Control Matrices (RCMs): Maintain and update RCMs for relevant business processes and IT applications. Confirm that risks are appropriately addressed, control descriptions are clear and complete, and changes in processes, systems, ownership, or risk are reflected promptly.
Walkthroughs and scoping: Conduct process and control walkthroughs, assess annual scope and key-control coverage, document process flows, and identify changes that may affect control design or testing strategy.
Business-process controls: Evaluate the design, implementation, and operating effectiveness of controls across key cycles, including Procure-to-Pay, Order-to-Cash, Financial Close and Consolidation, Human Resources and Payroll, Property, Plant and Equipment, Treasury, Inventory, and other in-scope processes.
IT application controls (ITACs): Identify and test automated and semi-automated controls within enterprise applications, including automated calculations, workflow approvals, three-way matching, system configurations, and interfaces between internal systems and external service providers.
Key reports and information produced by the entity (IPE): Identify reports, queries, spreadsheets, and other information used in control performance. Test completeness and accuracy through report logic, parameters, configuration, source-to-output reconciliation, access, change management, and, where applicable, SQL or code review.
Testing and documentation: Prepare clear, complete, and reproducible workpapers that document procedures performed, evidence examined, samples selected, conclusions reached, and reviewer follow-up. Record testing results and findings in the designated audit and SOX management system.
Deficiency evaluation and remediation: Identify control gaps, perform root-cause analysis with stakeholders, assess deficiency severity in accordance with the Company’s framework, agree practical remediation actions, monitor milestones, and retest completed remediation.
External-auditor coordination: Act as a primary point of coordination for assigned SOX areas, facilitate walkthroughs and evidence requests, resolve questions, and maintain alignment on scope, testing status, deficiencies, and remediation.
Control-owner training: Provide onboarding and periodic refresher training to control owners and performers on control objectives, evidence standards, documentation requirements, and changes to the SOX program.
Business-process and operational audits: Support risk assessments, develop audit programs, perform interviews and testing, analyze root causes and business impact, and prepare practical recommendations. Assignments may cover financial, operational, compliance, technology-enabled, and cross-functional processes.
Audit reporting and communication: Prepare concise status updates, findings, risk statements, and recommendations for management reports and presentations. Maintain regular communication with process owners, Internal Audit leadership, IT, and external auditors; escalate significant issues or delays promptly.
Issue follow-up: Maintain accurate records of open actions, validate remediation evidence, confirm sustainable closure, and report overdue or unresolved matters to appropriate stakeholders.
Control advisory and continuous improvement: Advise stakeholders on process and control improvements while preserving Internal Audit independence. Promote standardized, efficient, and sustainable controls that comply with Company policies and regulatory requirements.
Data analytics: Use data analysis to identify unusual transactions, process exceptions, control failures, operational bottlenecks, and indicators of error or potential fraud.
Use of AI: Use Company-approved AI and audit-automation tools to support audit planning, SOX control testing, evidence analysis, workpaper preparation, and identification of control gaps. Validate all AI-generated outputs against source evidence, apply professional judgment and human oversight, and comply with the Company’s confidentiality, data-privacy, information-security, and responsible-AI requirements.
Other assignments: Support investigations, inventory cycle counts, year-end physical counts, and other Internal Audit priorities as assigned. Travel to Company locations is required.