The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Senior Audit Operations Specialist
3-5 yearsSkills to master
- Deep expertise in GRC system configuration, advanced data analytics scripting, leading small operational projects, and informal mentorship.
You're ready to move on when
- Consistently delivers complex system configurations and data automations on time and with high quality.
- Proactively identifies and solves operational problems without constant supervision.
- Is the 'go-to' person for technical questions from junior team members and auditors.
- Has successfully led 1-2 small projects (e.g., new dashboard deployment, system module rollout).
- 2
Finance Systems Analyst (with Audit Focus)
5-7 yearsSkills to master
- Strong understanding of ERP systems (SAP, Oracle) from a functional and data perspective, experience with system implementations or upgrades, and a good grasp of financial controls.
You're ready to move on when
- Has successfully supported or led the audit-related aspects of a major finance system implementation.
- Can independently extract and analyse complex financial data from ERPs for audit purposes.
- Has a proven track record of collaborating effectively with both finance and IT teams.
- Demonstrates a keen eye for identifying control weaknesses in financial systems.
- 3
IT Auditor
4-6 yearsSkills to master
- Expertise in IT general controls (ITGCs) and application controls, experience with various operating systems and databases, and strong analytical skills for IT risk assessment.
You're ready to move on when
- Has led multiple IT audit engagements, demonstrating strong technical and analytical skills.
- Can clearly articulate IT risks and control deficiencies to both technical and non-technical audiences.
- Is proficient in using data analytics tools to support IT audit testing.
- Has a good understanding of cybersecurity principles and their application in an audit context.