Head of Internal Audit and Risk
2026-08-26T07:01:29+00:00
Q-Sourcing
https://cdn.greatugandajobs.com/jsjobsdata/data/employer/comp_7433/logo/Q-Sourcing.png
https://www.qsourcing.com/
FULL_TIME
East Africa
Kampala
00256
Uganda
Consulting
Management,Accounting & Finance,Business Operations
2026-09-01T17:00:00+00:00
8
Q-Sourcing Servtec Group (QSSG) is a pan-East African workforce solutions platform operating across Uganda, Kenya, Rwanda, Tanzania and South Sudan. The Group delivers recruitment, payroll, outsourcing, training, productivity and managed services to organisations at scale, and is ISO 9001:2015 certified. As QSSG advances its continental growth agenda, the Office of the Group CEO is being reinforced with a coordinated slate of senior appointments.
With a strong commitment to growth, QSSG has a vision to expand its impact across the African continent, establishing itself as the partner of choice in human capital solutions. We are looking for a commercially astute Head of Internal Audit and Risk to join our team.
Role Purpose
The Head of Internal Audit and Risk leads an independent, risk-based assurance function across QSSG and all subsidiaries. The role provides the Board, the Audit Committee and the Group CEO with objective assurance on the adequacy of the Group’s risk management, governance and internal control environment. It serves as a trusted advisory resource on governance and fraud risk without assuming ownership of the functions it audits, operating strictly as the Third Line of Defence per the IIA Three Lines Model. The role sits administratively within the Office of the Group CEO for coordination and Group-executive reach; functional independence to the Board Audit Committee is preserved absolutely.
Strategic Mandate
- Board Confidence: Give the Board and its Audit Committee an evidence-based view of the Group’s governance, risk and control environment.
- Risk-Based Assurance: Design and execute an annual audit plan calibrated to the Group’s real risk universe, not a checklist.
- Fraud Vigilance: Establish the Group’s fraud risk oversight backbone, from proactive detection to confidential reporting.
- Governance Discipline: Audit governance frameworks across all subsidiaries and report gaps the Board can act on.
- Independence: Hold the Third Line boundary at all times; advise on controls without assuming ownership.
- Control Environment Uplift: Track the maturity of the Group’s internal control framework year on year against a stated baseline.
Key Responsibilities
- 01 Risk-Based Audit Planning
Develop and maintain the Internal Audit Charter. Prepare and secure Audit Committee approval of a risk-based Group-wide Annual Audit Plan aligned to the Group’s risk universe.
- 02 Governance & Compliance Audits
Audit governance frameworks across all subsidiaries. Provide independent assurance that all entities comply with statutory, regulatory and contractual obligations across jurisdictions.
- 03 Financial & Operational Audits
Audit financial processes (treasury, payroll, procurement, expenditure) and operational processes (client delivery, contract management, HR, supply chain) across all Group entities.
- 04 Internal Control Evaluation
Assess design and effectiveness of the Group’s internal control framework against COSO. Manage Management Action Plans. Report deficiencies to the Audit Committee.
- 05 Fraud Risk & IT Audit
Evaluate the Group’s fraud risk framework and coordinate confidential investigations. Incorporate IT general controls, cybersecurity and data integrity reviews into the annual plan.
- 06 Audit Reporting & Board Engagement
Issue evidence-based audit reports within ten working days of fieldwork. Present quarterly and annual reports to the Audit Committee. Provide an annual opinion on the Group’s governance, risk and control environment.
Mandatory Qualifications, Experience & Competencies
Education
- Bachelor’s degree in Accounting, Finance or a related discipline.
- Postgraduate qualification (MBA or MSc) is an advantage.
Professional Qualifications
- CIA, CPA or ACCA required (at least one).
- CISA and IIA membership desirable.
Experience
- 10+ years in internal or external audit.
- Last 5+ years in a senior Group or multi-country leadership role with Board or Audit Committee exposure.
- Risk-based audit experience across financial, operational, governance, compliance and IT domains.
- African multi-jurisdictional exposure strongly preferred.
Core Competencies
- Independence & Integrity : Absolute professional independence and ethical standing under pressure.
- Risk-Based Judgement: Expertise in COSO, ISO 31000, IIA Standards and the Three Lines Model.
- Analytical Rigour: Identifies root causes across complex multi-entity organisations.
- Board Communication: Reports and presentation calibrated to Board and Audit Committee register.
- Stakeholder Credibility: Confident engagement with Board, Audit Committee, Group CEO and Country Managers.
- Professional Scepticism: Sound judgement when management narratives and evidence diverge.
- Executive Presence: Holds the Third Line boundary in rooms where the pressure is to blur it.
- Operational Discipline: Structured, consistent and accountable execution across a multi-country plan.
What Success Looks Like in the First 12 Months
The appointee will be measured against verified outcomes, not activity. The targets below are the bar. They are also the standard against which the Strategic Brief submitted with this application will be assessed.
- 01 Internal Audit Charter approved: Charter approved by the Audit Committee, dated, published to Board and Group Executive Committee. Reviewed annually.
- 02 Annual Audit Plan executed: Coverage across financial, operational, governance, compliance and IT. Risk-universe map underpinning it. At least 80% of planned audits closed on cadence.
- 03 Annual assurance opinion issued: A formal, written annual opinion on the Group’s governance, risk and control environment, delivered to the Audit Committee.
- 04 Quarterly Audit Committee reports: Four reports issued on cadence, evidence-based, with tracked Management Action Plans and closure status.
- 05 Fraud risk framework operational: Documented Group fraud risk framework in place, with a confidential reporting channel live and at least one full-cycle investigation completed.
- 06 Control environment strengthened : Documented uplift in the Group’s internal control maturity, measured against a Year Zero baseline established in Q1.
- 01 Risk-Based Audit Planning
Develop and maintain the Internal Audit Charter. Prepare and secure Audit Committee approval of a risk-based Group-wide Annual Audit Plan aligned to the Group’s risk universe. - 02 Governance & Compliance Audits
Audit governance frameworks across all subsidiaries. Provide independent assurance that all entities comply with statutory, regulatory and contractual obligations across jurisdictions. - 03 Financial & Operational Audits
Audit financial processes (treasury, payroll, procurement, expenditure) and operational processes (client delivery, contract management, HR, supply chain) across all Group entities. - 04 Internal Control Evaluation
Assess design and effectiveness of the Group’s internal control framework against COSO. Manage Management Action Plans. Report deficiencies to the Audit Committee. - 05 Fraud Risk & IT Audit
Evaluate the Group’s fraud risk framework and coordinate confidential investigations. Incorporate IT general controls, cybersecurity and data integrity reviews into the annual plan. - 06 Audit Reporting & Board Engagement
Issue evidence-based audit reports within ten working days of fieldwork. Present quarterly and annual reports to the Audit Committee. Provide an annual opinion on the Group’s governance, risk and control environment.
- Absolute professional independence and ethical standing under pressure.
- Expertise in COSO, ISO 31000, IIA Standards and the Three Lines Model.
- Identifies root causes across complex multi-entity organisations.
- Reports and presentation calibrated to Board and Audit Committee register.
- Confident engagement with Board, Audit Committee, Group CEO and Country Managers.
- Sound judgement when management narratives and evidence diverge.
- Holds the Third Line boundary in rooms where the pressure is to blur it.
- Structured, consistent and accountable execution across a multi-country plan.
- Bachelor’s degree in Accounting, Finance or a related discipline.
- Postgraduate qualification (MBA or MSc) is an advantage.
- CIA, CPA or ACCA required (at least one).
- CISA and IIA membership desirable.
JOB-6a8e8f49938c9
Vacancy title:
Head of Internal Audit and Risk
[Type: FULL_TIME, Industry: Consulting, Category: Management,Accounting & Finance,Business Operations]
Jobs at:
Q-Sourcing
Deadline of this Job:
Tuesday, September 1 2026
Duty Station:
East Africa | Kampala
Summary
Date Posted: Wednesday, August 26 2026, Base Salary: Not Disclosed
Similar Jobs in Uganda
Learn more about Q-Sourcing
Q-Sourcing jobs in Uganda
JOB DETAILS:
Q-Sourcing Servtec Group (QSSG) is a pan-East African workforce solutions platform operating across Uganda, Kenya, Rwanda, Tanzania and South Sudan. The Group delivers recruitment, payroll, outsourcing, training, productivity and managed services to organisations at scale, and is ISO 9001:2015 certified. As QSSG advances its continental growth agenda, the Office of the Group CEO is being reinforced with a coordinated slate of senior appointments.
With a strong commitment to growth, QSSG has a vision to expand its impact across the African continent, establishing itself as the partner of choice in human capital solutions. We are looking for a commercially astute Head of Internal Audit and Risk to join our team.
Role Purpose
The Head of Internal Audit and Risk leads an independent, risk-based assurance function across QSSG and all subsidiaries. The role provides the Board, the Audit Committee and the Group CEO with objective assurance on the adequacy of the Group’s risk management, governance and internal control environment. It serves as a trusted advisory resource on governance and fraud risk without assuming ownership of the functions it audits, operating strictly as the Third Line of Defence per the IIA Three Lines Model. The role sits administratively within the Office of the Group CEO for coordination and Group-executive reach; functional independence to the Board Audit Committee is preserved absolutely.
Strategic Mandate
- Board Confidence: Give the Board and its Audit Committee an evidence-based view of the Group’s governance, risk and control environment.
- Risk-Based Assurance: Design and execute an annual audit plan calibrated to the Group’s real risk universe, not a checklist.
- Fraud Vigilance: Establish the Group’s fraud risk oversight backbone, from proactive detection to confidential reporting.
- Governance Discipline: Audit governance frameworks across all subsidiaries and report gaps the Board can act on.
- Independence: Hold the Third Line boundary at all times; advise on controls without assuming ownership.
- Control Environment Uplift: Track the maturity of the Group’s internal control framework year on year against a stated baseline.
Key Responsibilities
- 01 Risk-Based Audit Planning
Develop and maintain the Internal Audit Charter. Prepare and secure Audit Committee approval of a risk-based Group-wide Annual Audit Plan aligned to the Group’s risk universe.
- 02 Governance & Compliance Audits
Audit governance frameworks across all subsidiaries. Provide independent assurance that all entities comply with statutory, regulatory and contractual obligations across jurisdictions.
- 03 Financial & Operational Audits
Audit financial processes (treasury, payroll, procurement, expenditure) and operational processes (client delivery, contract management, HR, supply chain) across all Group entities.
- 04 Internal Control Evaluation
Assess design and effectiveness of the Group’s internal control framework against COSO. Manage Management Action Plans. Report deficiencies to the Audit Committee.
- 05 Fraud Risk & IT Audit
Evaluate the Group’s fraud risk framework and coordinate confidential investigations. Incorporate IT general controls, cybersecurity and data integrity reviews into the annual plan.
- 06 Audit Reporting & Board Engagement
Issue evidence-based audit reports within ten working days of fieldwork. Present quarterly and annual reports to the Audit Committee. Provide an annual opinion on the Group’s governance, risk and control environment.
Mandatory Qualifications, Experience & Competencies
Education
- Bachelor’s degree in Accounting, Finance or a related discipline.
- Postgraduate qualification (MBA or MSc) is an advantage.
Professional Qualifications
- CIA, CPA or ACCA required (at least one).
- CISA and IIA membership desirable.
Experience
- 10+ years in internal or external audit.
- Last 5+ years in a senior Group or multi-country leadership role with Board or Audit Committee exposure.
- Risk-based audit experience across financial, operational, governance, compliance and IT domains.
- African multi-jurisdictional exposure strongly preferred.
Core Competencies
- Independence & Integrity : Absolute professional independence and ethical standing under pressure.
- Risk-Based Judgement: Expertise in COSO, ISO 31000, IIA Standards and the Three Lines Model.
- Analytical Rigour: Identifies root causes across complex multi-entity organisations.
- Board Communication: Reports and presentation calibrated to Board and Audit Committee register.
- Stakeholder Credibility: Confident engagement with Board, Audit Committee, Group CEO and Country Managers.
- Professional Scepticism: Sound judgement when management narratives and evidence diverge.
- Executive Presence: Holds the Third Line boundary in rooms where the pressure is to blur it.
- Operational Discipline: Structured, consistent and accountable execution across a multi-country plan.
What Success Looks Like in the First 12 Months
The appointee will be measured against verified outcomes, not activity. The targets below are the bar. They are also the standard against which the Strategic Brief submitted with this application will be assessed.
- 01 Internal Audit Charter approved: Charter approved by the Audit Committee, dated, published to Board and Group Executive Committee. Reviewed annually.
- 02 Annual Audit Plan executed: Coverage across financial, operational, governance, compliance and IT. Risk-universe map underpinning it. At least 80% of planned audits closed on cadence.
- 03 Annual assurance opinion issued: A formal, written annual opinion on the Group’s governance, risk and control environment, delivered to the Audit Committee.
- 04 Quarterly Audit Committee reports: Four reports issued on cadence, evidence-based, with tracked Management Action Plans and closure status.
- 05 Fraud risk framework operational: Documented Group fraud risk framework in place, with a confidential reporting channel live and at least one full-cycle investigation completed.
- 06 Control environment strengthened : Documented uplift in the Group’s internal control maturity, measured against a Year Zero baseline established in Q1.
Work Hours: 8
Experience in Months: 12
Level of Education: bachelor degree
Job application procedure
Interested in applying for this job? Click here to submit your application now.
Submit a CV AND a written Strategic Brief of up to 500 words (PDF or Word), addressing all three questions below. The brief is the primary filter for the interview. It is deliberately short: brevity under constraint is itself a capability test, and compression of judgement is the daily work of this role. Your brief will be assessed against the twelve-month success bar published above. Applications without the brief will not be reviewed.
- Board-level risk framing: Which three material risks should QSSG’s Board Audit Committee prioritise as the Group scales its platform across East Africa and beyond? For each, name the risk, its potential business impact, and one initial assurance action you would take in your first 90 days.
- First 90 days: Describe an initial 90-day assurance plan for this role. Identify three priority audit areas, why each matters at this moment in the Group’s growth, and how you would sequence the work.
- Independence under pressure: Describe a moment where you held the Third Line boundary when the pressure to blur it was material. What did you do, what resistance did you face, and what would you do differently?
Applications, including the CV and Strategic Brief, should be sent Subject line: Application: Head of Internal Audit and Risk, QSSG, [Your Full Name]
Deadline: Tuesday, 1st September 2026, 5:00 PM EAT
Prior applicants: If you have applied for a similar QSSG role in a previous cycle, please reapply. Every submission is reviewed afresh against the current mandate.
Only shortlisted candidates will be contacted.
Applicants must hold the legal right to work in at least one East African country where QSSG operates.
All Jobs | QUICK ALERT SUBSCRIPTION