Internal Audit Manager
Listed on 2026-07-28
-
Finance & Banking
Financial Compliance, Risk Manager/Analyst -
Management
Risk Manager/Analyst
Internal Audit Manager
Location: 330 Rush Alley, suite 500, Columbus, OH
Job : 1033
Department: Internal Audit
Reports To: Chief Credit and Risk Officer (CCRO)
Formed in 1934, Telhio began as a credit union for Columbus Telephone Company employees. Telhio now serves over 70,000 member‑owners throughout central and southwest Ohio. As one of the largest credit unions in Ohio, Telhio is a strong financial institution that continues to serve its members through extraordinary service, innovative financial solutions and community involvement. After generations of service and growth, we never lose focus of our three core values – Caring, Commitment, and Integrity.
SummaryThe Internal Audit Manager leads the credit union's Internal Audit program, leveraging both internal resources and an external audit provider to deliver a comprehensive, risk‑based audit plan. This role is responsible for enhancing, managing, and maturing the Internal Audit function – developing the audit universe and risk assessment, creating and maintaining Internal Audit methodology and quality practices, coordinating and monitoring audit execution, and reporting results to the Supervisory Committee and executive leadership.
The Internal Audit Manager works in partnership with the Chief Credit and Risk Officer (administrative reporting) and business leaders, while maintaining independence and objectivity and performing select internal audits directly as needed. This role ensures Internal Audit maintains independence, follows the International Standards for the Professional Practice of Internal Auditing (IIA Standards), and provides high‑quality, objective assurance to the Supervisory Committee and executive leadership.
- Oversee a hybrid audit delivery model combining internal audit work with outsourced specialty audits (e.g., IT/cybersecurity, BSA/AML, model risk, ALM).
- Manage relationships, contracts/SLAs, and performance expectations (KPIs) for the external audit provider, including independence and confidentiality requirements.
- Allocate work between internal and external resources based on complexity, risk, and required expertise.
- Lead the annual enterprise‑wide risk assessment process in collaboration with the CCRO and business leaders.
- Develop a risk‑based Internal Audit Plan that includes both internal audits and outsourced audit engagements and provides appropriate coverage across key risk areas (e.g., lending, deposits, payments, financial reporting, IT/cybersecurity, BSA/AML, third‑party risk, and governance/enterprise risk management).
- Present the annual plan to the Supervisory Committee for approval and conduct midyear refreshes as appropriate.
- Perform select internal audits (as capacity and risk dictate), including planning, limited fieldwork/testing, documentation, and reporting, in accordance with IIA Standards.
- Conduct targeted reviews in areas such as:
- Operational processes
- Consumer compliance (as appropriate)
- Payments and branch operations
- Governance, risk management, and internal control frameworks
- Identify control gaps, evaluate root causes, and recommend actionable improvements; coordinate management responses and due dates for tracked issues.
- Review and challenge external providers' audit scopes, methodologies, and timelines.
- Evaluate the accuracy, completeness, and quality of outsourced audit reports.
- Ensure outsourced audits are delivered on time, within budget, and in accordance with IIA Standards.
- Maintain independence by ensuring no conflicts of interest with third‑party providers.
- Prepare clear, concise audit reports summarizing findings, risks, and recommendations for management and the Supervisory Committee.
- Deliver quarterly Internal Audit updates to the Supervisory Committee, including:
- Status of the audit plan
- Significant findings
- Issue aging
- Emerging risk themes
- Support executive sessions between external auditors and the Supervisory Committee.
- Partner with the Risk Team to track management action…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).