Control Testing Execution
Plan, execute, and document control testing activities across operational or tech risk domains — covering both design and operating effectiveness
Perform periodic assessments of high-risk business areas including customer onboarding, AML processes, payment operations, financial promotions, and data protection
Identify control gaps, weaknesses, and process failures through structured walkthroughs, sample testing, and review of evidence
Produce clear, well-evidenced test workpapers that meet internal quality standards and can withstand regulatory scrutiny
Issue Management & Remediation
Document findings and communicate them clearly to control owners and senior stakeholders
Work with first-line teams to agree root cause analysis and develop practical, time-bound remediation plans
Track open issues through to closure, conducting follow-up testing to validate that corrective actions have been implemented effectively
Maintain the issues register and provide regular status updates to the Head of Control Testing
Risk Culture & Stakeholder Engagement
Act as a visible, credible presence across business functions — building relationships that make control testing a collaborative process rather than an adversarial one
Support the development of risk and control awareness across the organisation, helping first-line teams understand why controls matter and how to own them effectively
Deliver guidance and informal coaching to control owners on control design, evidence requirements, and good practice
Represent the Control Testing function in cross-functional forums, risk committees, and working groups as required
Reporting & Framework Support
Contribute to the preparation of control testing reports and dashboards for senior management and risk committees
Support the maintenance and development of the control library, ensuring controls are accurately mapped to risks and business processes
Assist in preparing documentation for regulatory audits and examinations
Provide input to the annual Control Testing Plan, drawing on knowledge of operational risk areas and business change
Experience
5–8 years of proven experience in control testing, operational risk, tech risk or internal audit within financial services or regulated FinTech
Proven ability to execute tests of controls independently, from planning through to final report
Experience engaging with first-line business teams in a second-line capacity
Familiarity with multi-jurisdiction regulatory requirements — experience across FCA, CySEC, or ASIC environments is advantageous
Experience supporting or preparing for regulatory audits and examinations
Knowledge
Sound understanding of operational risk frameworks (e.g., COSO, ISO 31000) and how they apply in a regulated financial services context
Knowledge of key regulatory obligations relevant to a financial institution — including Consumer Duty, AML, GDPR, and best execution
Familiarity with control testing methodologies and issue management processes
Comfortable using GRC tools, Excel, and reporting platforms to manage and present testing output
Personal Attributes
Strong interpersonal and communication skills — able to engage at all levels, from operational staff to senior management
Self-starter with the confidence to manage workload independently and take ownership of outcomes
Methodical and detail-oriented, with a natural instinct to question and verify
Genuine interest in building a risk-aware culture, not just completing a testing checklist
Adaptable and resilient — comfortable working in a function that is still being built and where the scope will evolve
Desirable Qualifications
Bachelor's degree in Finance, Business, Risk Management, Law, or a related field
Professional certification such as IRM, ICA, CIA, or equivalent