PURPOSE OF POST:
The Compliance Auditor will be responsible for taking the lead role across a range of data protection audit activity tasks and delivering associated quality products in line with the audit methodology.
KEY OUTCOMES
The following outcomes will be expected to be achieved by the post holder
• The conduct of adequacy audit reviews of organisations’ policies, procedures, guidance and training material and assessing their fitness for purpose in respect of data protection compliance.
• Improving the effectiveness of audits by researching and disseminating information which will inform audits of identified issues and organisational background details.
• Developing audit questionnaires and checklists to ensure that interviews adequately cover all the relevant matters.
• Leading and supporting streams of audit interviews of staff, operating at all levels within a ‘business’ hierarchy, to establish whether working practices are in compliance with the data protection act and recognised best practice.
• Examining data records and processing facilities organisations’ premises to establish evidence which supports compliance assessments.
• Preparing audit compliance reports which document audit observations, provide an evaluation of the processing and identifies recommendations and acting as a key contact point in respect of feedback on the report.
• Leading short audit / inspections such as might be required to validate actions taken by organisations following written undertakings and reporting findings.
• Supporting enforcement or follow up audit activity as determined by line managers.
• Supporting the Audit Team Manager regarding liaison with internal data protection departments before audits to develop background information and after audits to disseminate the audit results and likely outcomes.
• Developing key areas of sectoral or technical expertise ensuring that audits are engaged with the latest guidance and best practice.
PERSON SPECIFICATION
Essential Criteria:
Education and Qualification
Educated to degree level or equivalent graduate level work experience.
Work Experience
3 years compliance assessment experience and a knowledge / understanding of audit.
Knowledge, skills and ability.
Intellectual and analytical ability in order to be able to apply complex legislation to a variety of practical circumstances and differentiate between good and bad practice.
Ability to communicate at all levels with internal and external stakeholders.
Ability to undertake a range of audit related activities across both public and private organisations.
Ability to work to tight deadlines.
Strong team player.
Knowledge of IT and its use in the management and security of personal data.
A knowledge of general business processes with specific reference to the management and handling of personal data.