Title: Head of Internal Audit
Company Name: Grameen Healthtech Limited
Vacancy: 01
Age: 25 to 45 years
Job Location: Dhaka
Salary: Negotiable
Experience:
Educational Requirements:
Master's degree in Accounting, Finance, Business Administration, Economics, or a related discipline from a reputed university.
Professional qualification preferred (CA, ACCA, CISA, CMA)
Additional certifications in Risk Management, Fraud Examination, Data Analytics, or Information Security are advantageous.
Experience: Minimum 12–15 years of relevant experience in Internal Audit, Risk Management, Finance, or Compliance.
At least 5 years in a senior leadership role.
Experience in digital platforms, healthcare, financial services, e-commerce, or technology-driven organizations is highly preferred.
Proven experience presenting to Board Audit Committees and leading enterprise-wide audits.
Technical Competencies
Risk-Based Internal Auditing, Enterprise Risk Management (ERM), Internal Control Frameworks (COSO), IT Audit & Cyber Security, Data Analytics (Power BI, ACL, IDEA, SQL or similar tools), Financial Analysis, Regulatory Compliance, Fraud Investigation, Process Improvement, Governance Audit Software, ERP Systems, Microsoft Excel (Advanced)
Behavioral Competencies
Unquestionable integrity and ethics, Independence and objectivity, Strong analytical thinking, Strategic mindset, Sound business judgment, Excellent communication and report writing, Leadership and people development, Influencing and stakeholder management, Attention to detail, Professional skepticism, Decision-making under pressure
Authority:
The Head of Internal Audit is authorized to:
Access all records, systems, assets, and personnel necessary to perform audit responsibilities.
Conduct independent reviews across all functions.
Report directly to the CEO on matters affecting governance, internal controls, fraud, or significant risks.
Recommend corrective actions and monitor implementation.
Independence:
To preserve independence:
Functional reporting shall be directly to the Audit Committee of the Board.
Administrative reporting shall be to the Chief Executive Officer.
The Head of Internal Audit shall have unrestricted access to the Chairman of the Audit Committee and the Board whenever necessary.
Working Relationships
Internal
Board of Directors ,Audit Committee, CEO, CFO, COO, CTO, CMO, CHRO, Company Secretary, Business Unit Heads
External
External Auditors
Regulatory Authorities
Consultants
Technology Partners
Legal Advisors
• Develop and implement an annual risk-based Internal Audit plan.
• Establish Internal Audit policies, manuals, methodologies, and quality standards aligned with the International Professional Practices Framework.
• Introduce continuous auditing, automated control testing, and data-driven assurance.
• Align Internal Audit activities with organizational strategy, major risks, and Audit Committee expectations.
• Present audit plans, findings, risk assessments, and progress reports to the Audit Committee.
• Report significant control weaknesses, governance concerns, regulatory risks, and unresolved audit issues.
• Track and monitor the implementation of Audit Committee decisions.
• Perform the responsibilities of Audit Committee Secretary, where assigned.
Lead financial, operational, compliance, and technology audits covering:
• Corporate governance and regulatory compliance
• Financial reporting, treasury, and banking operations
• Procurement, inventory, warehouse, and logistics
• Pharmacy, diagnostics, telemedicine, and health commerce
• Digital payments, SaaS platforms, and mobile applications
• Information technology, cybersecurity, and data privacy
• Human resources, payroll, marketing, and customer service
• Vendor management, strategic partnerships, and business continuity
Evaluate controls relating to:
• Revenue recognition and collection
• Cash and banking operations
• Accounts payable and receivable
• Vendor and doctor payments
• General ledger and financial reporting
• Budget utilization and capital expenditure
• Fixed assets and working capital
• Internal Control over Financial Reporting
• Segregation of duties, approval authority, and payment controls
Assess the efficiency and effectiveness of:
• Project ALO, including Shukhee Sheba Kendras, Shukhee Bondhu, and field operations
• Warehouse and inventory operations
• Online and offline healthcare service delivery
• Third-party service providers
• Customer onboarding and order fulfilment
• Refund and settlement processes
• Procurement and vendor-management cycles
• Service quality, productivity, and resource utilization
Provide practical and measurable recommendations for operational improvement.
Conduct audits of:
• ERP and business applications
• Mobile applications and API integrations
• Cloud infrastructure
• User access and identity management
• IT General Controls and application controls
• Cybersecurity and vulnerability management
• Change management and system implementation
• Disaster recovery and business continuity
• Data integrity, privacy, and information security
Coordinate vulnerability assessments and specialist technology reviews when required.
• Develop and maintain a fraud-risk assessment framework.
• Investigate suspected fraud, misconduct, financial irregularities, and control breaches.
• Conduct forensic reviews where required.
• Recommend preventive and detective controls.
• Maintain confidential whistleblower investigation and reporting protocols.
Assess compliance with applicable:
• Companies Act requirements
• Income Tax and VAT regulations
• Labour laws and employment requirements
• Board policies and internal SOPs
• Contracts, agreements, and service-level commitments
• Digital healthcare and financial-partnership regulations
Implement continuous assurance through:
• Audit dashboards
• Exception and unusual-transaction reporting
• Automated control testing
• KPI and early-warning indicator monitoring
• Revenue and payment analytics
• Inventory and procurement analytics
Use data analytics to identify revenue leakage, duplicate payments, pricing inconsistencies, inventory anomalies, procurement irregularities, fraud indicators, and unusual customer or transaction behaviour.
Prepare clear and decision-focused:
• Internal Audit reports
• Executive summaries
• Risk heat maps
• Control assessment reports
• Root-cause analyses
• Recommendation matrices
• Audit Committee papers
Monitor agreed corrective actions until their proper implementation and closure.
Provide independent control and risk advice on:
• New business initiatives
• Digital transformation projects
• Product and service launches
• Process redesign
• Technology implementation
• Major investments and strategic partnerships
All advisory activities must be performed without compromising Internal Audit independence.