Job Purpose:
- The role holder is responsible for delivering the annual Information Systems (IS) audit plan, with a focus on integrity, confidentiality, and availability of information. This includes evaluating the effectiveness of security controls and ensuring compliance with both internal policies and external regulatory requirements.
- The role also ensures adequate assurance coverage of IS-related risks across the bank’s entire technology infrastructure, in alignment with Governance, Risk, and Compliance (GRC) frameworks. The role holder also advises the Deputy General Manager, Internal Audit, on audit coverage, emerging risk trends, and the maturity of control environments.
Key Responsibilities:
- Provide input to the Deputy General Manager, Internal Audit, in preparing the annual audit plan for approval by the BAC. This is through review of prior audit reports, incidents within the consulting areas, financial performance, risk areas in projects, products, strategy, and areas specially requested by process owners.
- Review work done by the team in planning, such as document review, prior reports, data analysis, walkthroughs, risk assessments, and all related planning items.
- Review the audit planning memo for target assignments to determine that all relevant planning bases have been covered as per the audit planning manual.
- Prepare an audit planning memorandum and obtain agreement from the Deputy General Manager, Internal Audit, on the audit objectives, audit methodology, and scope of work, and key risk areas for review on each assignment.
- Evaluate audit tests prepared and ensure they address identified risks and will achieve the desired audit objectives. Continuously monitor the tests for efficiency and effectiveness.
- Perform quality assurance to ensure that all evidence and working papers meet the standards required to support audit findings, root causes, risks, recommendations, and conclusions.
- Monitor the audit progress and timescale per the planning memo. Assess with the team, areas of improvement on the effectiveness and efficiency of the audit procedures.
- Lead / Conduct special audits, including reviews of functions undergoing significant change, and draft suitable audit reports.
- Ensure that key weaknesses and existing or potential risks are highlighted and well-presented before final report approval and issuance.
- Engage audit clients to establish correct root causes and establish relevant management actions.
- Present IS audit findings and assurance reports to relevant stakeholders, coordinate post-audit surveys, and support special audits involving information systems.
- Lead the follow-up on post-exit clarifications and status of management actions.
- Assess training needs in consultation with the team and with agreement with the Deputy General Manager, Internal Audit, assign appropriate learning programs.
- Serve as an ongoing subject matter expert on information security controls and technologies.
Academic Qualifications:
- Bachelor's in information systems / computer science / IT / Business-related field, or equivalent.
- Master’s (MBA, MSc Information Systems/ Information Security / IT/ IT-related field (added advantage).
Professional Qualifications / Membership to professional bodies/ Publication:
Professional Qualifications:
- Certified Information Systems Auditor (CISA) – required.
- One (1) of: CISM/ CRISC/ CGEIT /CIA /ISO/IEC 27001 Lead Auditor or Lead Implementer/ CISSP.
- CIAQA / CCNA/ CPA /CEH / CHFI (added advantage).
Membership Affiliations:
- Information Systems Audit and Control Association (ISACA).
- Institute of Internal Auditors (IIA).
Work Experience Required:
Over Seven (7) years’ relevant experience with over a year in a management role in a similar-sized organization.
Competencies:
- Planning & Organizational skills.
- Analytical skills and attention to detail.
- Strong oral and written communication skills.
- Interpersonal skills to manage stakeholders at all levels.
- Ethics and integrity.
- Excellent judgment and analytical abilities, and impeccable integrity.
- Strong commercial awareness and an ability to connect to business goals.
- Banking Knowledge.
- Strong understanding of enterprise, technology, and operational risk management.
If you believe you meet the above requirements log onto our www.imbankgroup.com/ke and click on careers and apply for the position. Your application should reach us as soon as possible but not later than 6th February 2026.
Top Skills
What We Do
I&M Bank is a wholly owned subsidiary of I&M Group PLC, a publicly quoted company at the Nairobi Securities Exchange (NSE). The bank possesses a rich heritage in banking. Started in 1974, it evolved from a community financial institution to a publicly listed major regional commercial bank offering a full range of corporate and retail banking services, over 50 branches in Kenya and international operations in 3 other countries.
I&M Bank is a dominant player in the Kenyan market that has been consistently growing, and is innovative in terms of the type and range of products and services it offers.
CDC Group plc, a development finance institution wholly owned by the government of the United Kingdom owns approximately 10.68% of I&M Group. In addition, I&M Bank has a technical support agreement with International Finance Corporation for staff training, product development and risk management. I&M Bank also enjoys medium term foreign currency credit facilities from European Development Financial Institutions - Proparco, DEG and FMO.
I&M Bank’s international correspondent banks include major multinational banks such as Bank One Ltd, Citibank NA, CommerzBank AG, Deutsche Bank AG, ICICI Limited Mumbai, Mashreq Bank PLC, Standard Bank of South Africa and Standard Chartered Bank NY.
I&M Bank’s international network includes Bank One Limited (Mauritius), I&M Bank Tanzania Limited, I&M Bank Rwanda and I&M Bank Uganda








