Internal Audit Manager
Decorpot · Karnataka, India
FULL TIME
Job Description
Designation :Manager – Internal Audit Function: Internal Audit & Risk Location: Decorpot HQ, Bengaluru Role Overview Key Responsibilities A. Internal Audit Plan & Execution • Build and execute the annual risk-based internal audit plan, covering all group entities, all ECs, the factory, FurnitureOne stores, and key corporate processes. • Lead end-to-end audits — planning, fieldwork, sampling, walkthroughs, testing, exception logging, root-cause analysis, and reporting. • Produce CFO-grade audit reports with clear findings, risk ratings, and time-bound management action points. • Track closure of audit findings; escalate ageing items to the CEO and Audit Committee. B. Process & Control Reviews • Procure-to-Pay: vendor onboarding, bank account change controls, PO discipline, three-way match, payment release controls (including HDFC Snorkel integration). • Order-to-Cash: customer onboarding, milestone billing, advance liability mapping, refunds, write-offs, CP commission integrity, and channel-partner controls. • Hire-to-Retire: payroll, full-and-final, reimbursements (Keka), incentive payouts, statutory deductions. • Factory / Inventory: BOM accuracy, GRN-vs-PO, scrap / yield, physical verification, stock valuation, fixed asset register. • EC operations: cash collection (where applicable), site visit logging, design-cost discipline, and customer-facing controls. • IT general controls: access reviews, segregation of duties in ERP, change management, master data integrity. C. Forensic & Special Investigations • Lead forensic investigations on suspected fraud, vendor / CP collusion, payment anomalies, and revenue leakage. • Run analytics-led continuous monitoring on payments, GST input claims, vendor master changes, and CP commission patterns. • Present findings to the CEO and Audit Committee with documented evidence. D. Policy, Risk & Compliance Framework • Co-own the policy stack with AGM – Finance — procurement, vendor management, petty cash, reimbursement, capex, treasury, IT, code of conduct. • Maintain a live group risk register; refresh quarterly. • Coordinate with statutory auditors, tax consultants, and external IA firms for assurance work; avoid duplication of effort. E. Audit Committee Engagement • Prepare quarterly Audit Committee material — IA plan progress, findings, ageing of open items, risk register updates. • Attend Audit Committee meetings; present IA reports directly. • Manage the whistleblower / ethics hotline process and report material matters to the Committee. First 90 Days – Specific Deliverables • Publish the FY27 risk-based internal audit plan, approved by the CEO and the Audit Committee. • Complete the first two audits — recommended: Procure-to-Pay (Decorpot HO) and Factory Inventory / BOM (Ekaansh). • Refresh the group policy stack (procurement, vendor onboarding, petty cash, reimbursement). • Stand up a quarterly Audit Committee reporting format. • Build the analytics-led continuous monitoring rules for high-risk payments and vendor master changes. Qualifications & Experience • Chartered Accountant (CA) — mandatory. CIA (Certified Internal Auditor) is a plus. • 2–5 years of post-qualification experience (PQE). • At least 2 years in Internal Audit / Risk Advisory at a Big 4 (Deloitte, EY, KPMG, PwC) or top-tier IA firm (Grant Thornton, BDO, Protiviti, Mazars) — preferred. • Strong preference for candidates with manufacturing / retail / multi-site exposure. • Experience leading audits independently and presenting to senior management / Audit Committees. Skills & Competencies • Sharp process and controls mindset — ability to dismantle a process into risks, controls, and tests. • Strong data analytics skills — advanced Excel, SQL or similar, audit analytics tools (ACL / IDEA / equivalent). Comfort with AI-led audit automation is a strong plus. • Excellent written communication — audit reports must be precise, evidence-backed, and actionable. • Independence, integrity, and the spine to disagree with senior business leaders when controls demand it.
