About

A result-oriented IT assurance professional with extensive and demonstrable experience in conducting information systems audit and other IT consultancy services (IT compliance reviews, Comprehensive IT audits, IT project post implementation reviews, IT quality assurance reviews, IT security reviews, Automated process reviews amongst other services) for clients in the financial services sector, health sector, non-governmental sector, public sector, and the fast-moving consumer goods sector. He is currently leading a team of IT auditors at Equity Group Holdings and he coordinates thematic IT reviews across the subsidiaries within Equity Group. The tasks carried out involves undertaking IT assurance reviews, Special reviews, Advisory reviews for management and the Board. He previously headed the IT assurance function at National Bank of Kenya. This involved undertaking IT assurance reviews for the Bank, ad hoc advisory reviews for management and the board, tracking remediation of issues from external and internal audits. He has a very good understanding of the leading IT benchmarks, standards and frameworks that have proven valuable in undertaking various IT assurance reviews. These include ISO 27001:2013, CIS Benchmarks, NIST Standards (SP 800-53), NIST Cybersecurity Framework. His accounting qualification has been important in conducting reviews of financial and automated business processes.

Skills

  • IT Audit
    10
  • Data Analysis using IDEA
    10
  • Data Analysis using ACL
    6
  • Macro development skills in excel
    7
  • Python Programming
    8
  • IT Project Assurance
    8
  • Report writing skills
    9
  • Presentation skills
    10
  • TeamMate Administration
    10
  • SQL
    8
  • English and Kiswahili
    10

Experience

Charles Ng'etich

Work experience
  • Undertaking peer internal quality assurance review across the Group Subsidiaries as per the Global Internal Audit Standards.
  • Performing and coordinating thematic IT audits across the Group
  • Planning, executing, and supervising IS audits of critical IT systems and processes, including but not limited to: Application controls; Data security and privacy; Network security; IT operations and infrastructure; Business continuity and disaster recovery; Cloud computing; Cybersecurity. ACL is used extensively to analyze large datasets during the audits.
  • Leading, mentoring and developing a team of IT audit managers in conducting IT audits.
  • Leading the development and execution of the annual IS audit plan, aligned with the overall audit strategy and risk assessment.
  • Conducting risk assessments of IT systems and processes, identifying and prioritizing key areas for audit focus.
  • Developing and implementing audit programs and methodologies for evaluating the effectiveness of IT controls.
  • Follow up on the implementation of audit recommendations and monitor corrective actions.
  • Present audit findings to management, audit committees, and other relevant stakeholders.
  • Maintain a strong understanding of evolving IT risks, threats, and controls.
  • Administration of the audit documentation tool (TeamMate).
  • Participate in the improvement of documentation templates (Audit planning memorandum, Risk control matrix, Work program, Audit notification and Report template).
  • Delivering advisory engagements

Charles Ng'etich

Work experience
  • Led Audit Managers in the audit of ICT and all other related Information Systems in line with approved audit methodology and audit objectives.
  • Offered project assurance over the core banking implementation (T24) project. Assurance was offered across the various project workstreams and phases (Build, Testing, Datawarehouse, Data migration, Dress Rehearsals, Go-Live). IDEA was used to build analysis scripts for specific critical datasets.
  • Carried out internal assessment on Quality Assurance and Improvement Program to ensure continuous improvement of ICT audit processes as per the Institute of Internal Auditors Guidelines.
  • Supervised, coached, mentored and offered leadership to all Audit Managers and in particular those handling ICT audits to maintain a high-performance culture.
  • Performed consulting activities as scheduled or as requested by senior management.
  • Tracked latest IT security innovations, kept abreast of latest cyber security technologies and provided appropriate recommendations for the Bank.
  • Prepared Board Audit Committee papers summarizing significant audit observations arising from ICT audits, central functions, shared services, commercial functions and branch networks audits on a quarterly basis.
  • Championed and raised awareness to internal stakeholders on controls and checks to ensure assurance of IT Assets in the Bank.
  • Planned and performed technical information systems audits on mapped critical areas and processes and highlighting improvement areas in detailed audit reports.
  • Tracked and followed up on relevant audit issues emanating from Internal Audit Reports and other independent external reviews to ensure their timely resolution and closure. As part of this, I developed an excel Macro to automate analysis and preparation of reports on audit issues remediation statistics.
  • Spear-headed the development and review of risk based annual ICT audit plans detailing the scope, nature, and timing of audit activities.
  • Developed and enforced ICT Internal Audit methodology, standards and procedures to ensure effective assurance and functioning of ICT function.
  • Objectively reviewed the systems established within the assigned areas to assess compliance with policies, procedures, laws and regulations and highlighting significant improvement areas.
  • Administered the audit management software and was the champion for the IDEA software within the internal audit division. This included being the liaison with the system vendors to ensure that any challenges / issues with this software were sorted out on time.
  • Co-ordinated internal quality assurance reviews by assessors from the Group team. Following the review, I facilitated improvements to address queries raised by the assessors.
  • Tracked the quality assurance issues raised by the internal assessors to closure. This included guiding team members on the approach to addressing issues raised.
  • Led the team in undertaking annual cybersecurity reviews as per the requirements of the Central Bank of Kenya guidance note on Cybersecurity. Led the team in assessing resolution status of issues raised from red-teaming exercises.

Charles Ng'etich

Work experience
  • Provided leadership to all Audit Managers in the audit of ICT and all other related Information Systems in line with approved audit methodology and audit objectives.
  • Carried out internal assessment on Quality Assurance and Improvement Program to ensure continuous improvement of ICT audit processes as per Institute of Internal Auditors Guidelines and standards.
  • Supervised, coached, mentored, and offered leadership to all Audit managers, and particularly those handling ICT audits to maintain a high-performance culture.
  • Performed consulting activities as scheduled or as requested by senior management or the Board.
  • Tracked latest IT security innovations, kept abreast of latest cyber security technologies, and provided appropriate recommendations for the Bank.
  • Prepared Board Audit Committee papers summarizing significant audit observations arising from ICT audits, central functions, shared services, commercial functions, and branch networks audits on a quarterly basis.
  • Championed and raised awareness to internal stakeholders on controls and checks to ensure assurance of IT Assets in the Bank.
  • Planned and performed technical information systems audits on mapped critical areas and processes highlighting improvement areas in detailed audit reports.
  • Tracked and followed up on audit issues emanating from Internal Audit Reports and other independent external reviews to ensure their timely resolution and closure.
  • Participated in the development and review of risk based annual ICT audit plans detailing the scope, nature, and timing of audit activities.
  • Reviewed current, emerging technology risks and advised management on related controls. Provided assurance on the level of adherence to controls for existing and new technologies including cyber related risks.
  • Developed and enforced ICT Internal Audit methodology, standards, and procedures to ensure effective assurance and functioning of ICT function.
  • Objectively reviewed the systems established within the assigned areas to assess compliance with policies, procedures, laws, and regulations and highlighted significant improvement areas.
  • Administered the audit management software (TeamMate) and championed the use of IDEA software (CAAT) within the internal audit division. This included being the liaison with the system vendors to ensure that any challenges / issues with this software were sorted out on time.
  • Prepared a cyber security assurance strategy to provide a framework for cyber security assurance activities within the Bank by Internal Audit.
  • Conducted other duties as assigned by the Director, Internal Audit from time to time.
  • Co-ordinated internal quality assurance reviews by assessors from the Group team. Following the review, I facilitated improvements to address queries raised by the assessors.

Charles Ng'etich

Work experience
  • January, 2021 - December, 2021
  • Fulltime
  • − Provided expertise in the audit of ICT services operations across the Bank in line with approved Internal Audit methodology, processes, procedures, and timelines.
  • − Participated in the development of risk based IS annual audit plans detailing the scope, nature, and timing of audit activities.
  • − Planned and performed technical information systems audits on all mapped critical areas and processes. This included but not limited to the following.
  • IT governance,
  • IT systems and banking applications,
  • Network and communication infrastructure,
  • IT general controls,
  • Operating systems and databases,
  • Business Continuity and disaster recovery,
  • Major systems acquisition and implementation projects,
  • Data Centre operations among others
  • − Participated from an audit perspective in review of acquisition of new major IS assets by advising project teams on information systems control and security issues and ensuring that set criteria is met.
  • − Interfaced and conducted necessary special integrated audit projects with the Business/Branch Networks and Central/Shared audit functions.
  • − Managed stakeholders and offered expertise on quality recommendations for ICT service and operational controls.
  • − Conducted ad-hoc investigations and reviews, as a liaison subject matter expert, based on requests by Senior Management and/or the Board Audit Committee
  • − Tracked and followed up on relevant IT audit issues emanating from Internal Audit Reports, and other external independent reviews to ensure timely closure.
  • − Supported in raising awareness to staff on ICT service and operational controls, including appreciation of ICT enabled audits on Business/Branch Network and Central/Shared Services.
  • − Coached, mentored, and offered expertise to other staff within the division, including support on IS related areas.
  • − Reviewed the means of safeguarding assets and, as appropriate, verified the existence of such assets.
  • − Discussed audit findings and recommendations with audit clients and prepared management and board papers for reporting significant control issues to the Senior Management and the Board Audit Committee.

Charles Ng'etich

Work experience
  • October, 2019 - December, 2020
  • Fulltime
  • Managed teams in performing information system audits for clients. This entailed performing application controls review, general IT controls review, business continuity management review, a high- level Cyber maturity assessment review, vulnerability assessment and penetration testing. IDEA (Computer Aided Audit Tool) was used extensively for the application controls section of the assignments for analysis of records and transactions. These assignments were running concurrently.
  • Planned audit approaches and optimized on resource use in concurrently running assignments.
  • Made presentations to Board audit committees and senior management of clients on audit findings.
  • Managed teams in performing comprehensive systems audit of banking sector audit clients as per the Central Bank of Kenya’s directive and Bank of Uganda’s directive; IDEA was used extensively for analysis of transactions and records during application controls review procedures.
  • Motivated team members to meet set engagement deadlines.
  • Led teams in conducting general IT controls and application controls reviews during financials statements audit to give financial auditors assurance of controls around critical applications used by audit clients.
  • Reviewed work papers prepared by team members. Guided team members in conducting IT audits.
  • Monitored progress of engagements against the budgeted time and updated engagement leaders on the progress of the running engagements.
  • Supported the consulting unit during the recruitment process by interviewing candidates during the manager interview stage.
  • Scheduled resources on various projects and monitoring of KPIs.
  • Guided appraisees assigned to me. This entailed monitoring their KPIs, addressing performance issues noted and working with them to improve on their improvement areas.
  • Preparation of proposals and shaping up of opportunities as part of business development initiatives. Guiding team members on preparation of proposals as well.

Charles Ng'etich

Work experience
  • October, 2017 - September, 2019
  • Fulltime
  • Led team members in delivering comprehensive ICT systems review for the Banking, Insurance, and public sector clients. This included performing the following: General IT controls review, application controls review, ICT investment management review, ICT Support & third parties services review, high-level Cyber maturity assessment review vulnerability assessment and penetration testing. IDEA (CAAT) was extensively used to analyze data during application controls review.
  • Led teams in performing comprehensive systems audit of banking sector audit clients as per the Central Bank of Kenya’s directive; IDEA was used extensively for analysis of transactions and records during application controls review procedures.
  • Trained team members on how to conduct IT audits.
  • General IT controls and application controls reviews during financials statements audit to give auditors assurance of controls around critical applications used by audit clients.
  • Review of work papers prepared by team members. Guiding team members in conducting IT audits;
  • Monitoring progress of engagements against the budgeted time and updating engagement leaders on the progress of the engagement.
  • Performed IT due diligence on behalf of potential investors to inform the deal processes across the health and financial sectors.
  • Conducted KEPSS Interface reviews for our Kenyan banking sector clients.
  • Supported the IT Advisory unit during the recruitment process by participating in conducting group interviews.
  • Supported management on scheduling resources on projects and monitoring of KPIs.
  • Prepared proposals in response to consultancy opportunities. Guided and led team members on preparation of proposals as well.

Charles Ng'etich

Work experience
  • September, 2015 - September, 2017
  • Fulltime
  • Led teams in performing information system audits for clients. This entailed performing application controls review, general IT controls review, business continuity management review, vulnerability assessment and penetration testing. IDEA was used extensively for the application controls section of the assignments for analysis of records.
  • Trained team members on how to perform general IT controls review and application controls review.
  • Conducted IT project management and IT project quality assurance over the implementation of general insurance systems for insurance sector clients.
  • Conducted IT project management during the implementation of systems for insurance sector clients.
  • Undertook IT due diligence on health sector and banking sector entities on behalf of potential investors.
  • Conducted General IT controls and application controls reviews during financials statements audit to give auditors assurance of controls around critical applications used by audit clients. Reviewed clients across sectors (banking, insurance, retail and manufacturing).

Charles Ng'etich

Work experience
  • September, 2014 - August, 2015
  • Fulltime
  • Conducted IT audits for clients which entailed general IT controls (GITCs) review and application controls review. These reviews covered the following: logical and physical access security controls; change management controls; business continuity and disaster recovery planning.
  • Undertook KEPSS interface reviews for banking sector clients.
  • Conducted post data migration assurance review for a financial sector client. Reconciliation of data was done using IDEA.
  • IT controls review during financial statements audit to give auditors assurance of controls around systems used by audit clients.
  • IT gap closure which entailed advising clients on the best approach towards addressing root causes of prior year audit observations.

Charles Ng'etich

Work experience
  • Duties were Configuration of switches, Fiber Network Path survey, Fiber Network Termination, assisting in IP related problem solving, Initial Support on IP configuration for link commissioning and implementation in liaison with Network Operation Center (NOC).

Charles Ng'etich

Education

Charles Ng'etich

Education

Related persons

Mutai NicholasAccounting, Administration, Banking