Role purpose
Provide advisory or independent-assurance services over client data governance, security and control environments in line with the engagement's agreed independence model.
Key responsibilities
- Deliver QDKC-aligned client work using the official guides, templates and frameworks relevant to the engagement.
- Assess client evidence, facilitate workshops and produce traceable recommendations or implementation deliverables.
- For client engagements, plan risk-based audits of data policies, processes, systems and evidence.
- For client engagements, test control design and operating effectiveness.
- For client engagements, assess governance, access, quality, lifecycle, sharing and resilience practices.
- For client engagements, document findings, root causes, risk and agreed actions.
- Transfer knowledge to client personnel and document decisions, assumptions, dependencies and handover requirements.
- Respect client governance: consultants advise, facilitate and deliver, but do not replace the client's accountable owners, approvers or governance bodies.
Recommended minimum requirements
Education: Bachelor's degree in audit, accounting, information systems, cybersecurity or a related field.
Experience: Typically 4-8 years in internal audit, technology audit, risk or assurance.
Core competencies: Risk-based auditing, Control testing, Evidence evaluation, Report writing, Technology and data risk, Professional independence
Preferred certifications
Preferred, but not mandatory:
- Certified Internal Auditor (CIA)
- CISA preferred for technology-focused roles
Focus areas
Risk-based auditingControl testingEvidence evaluation
Ready to apply for this role?
Apply for Data Governance & Controls Assurance ConsultantDon't see the perfect fit?
We're always looking for exceptional people. Send us your CV and tell us how you'd contribute to the DAI mission.

