About this role
Lesaka Technologies
๐ We're Hiring: Manager: SOX & Internal Controls
Location: Johannesburg, South Africa Department: Merchant Division - Finance Reports to: SOX & Internal Control Analyst
- Purpose of the Role
Lesaka Merchant is undertaking a significant programme to strengthen its internal control environment and to remediate identified SOX and internal control deficiencies as and when they are identified.
The Senior Manager: SOX & Internal Controls will lead the Merchant Division's SOX remediation and ongoing internal controls programme. The role will work with Finance, Operations and Technology to identify the root causes of control failures, design practical control improvements, oversee implementation by accountable business owners and monitor whether remediation is sustainable.
The role is the principal Merchant interface between the Merchant CFO and executive management, Merchant business units, Group SOX, Group Internal Audit, external audit, process and control owners, and Technology and IT control teams.
The objective is a control environment that is sustainable, embedded in day-to-day operations, auditable, and able to keep pace with the growth, complexity and pace of change of the Division.
2.Scope and Mandate
- The role covers the South African operations of the Lesaka Merchant Division.
- Scope extends to common, centralised and divisional controls that also operate over the Division's international operations. This includes shared entity-level controls, common ITGCs and application controls, centralised close, consolidation and reporting controls, shared master data and user access processes, and standardised controls operated on a divisional basis.
- Where common or centralised controls depend on inputs or activities from international operations, the role will coordinate the divisional control framework, assess relevant dependencies, monitor identified gaps and escalate unresolved matters. The relevant business and control owners remain accountable for performing and evidencing the underlying controls.
- Scope extends to businesses acquired into or transferred within the Division. The role will coordinate the initial SOX scoping, control environment assessment, documentation and integration of newly acquired businesses into the Merchant SOX programme.
- The role operates as a first-line function. It provides control design guidance, oversight, challenge and monitoring but does not perform, approve or own business controls and is not a substitute for Group Internal Audit.
- The role holds the mandate to require and challenge the appropriateness of remediation plans, dates and owners from Merchant business and functional leadership, and to escalate where those are not delivered or not met.
3.SOX Remediation Programme
- Lead the Merchant SOX remediation programme and maintain clear oversight of identified deficiencies, agreed actions, accountable owners and remediation timelines.
- Assess the nature, underlying financial reporting risk and root causes of control deficiencies and support the development of practical, sustainable remediation plans.
- Support management in preparing clear and technically defensible responses to internal audit and SOX findings as well as external audit findings.
- Work with accountable business owners to agree remediation actions and timelines, monitor implementation and escalate overdue or ineffective actions, as required.
- Define proportionate evidence requirements to demonstrate implementation and sustained control performance.
- Establish and oversee risk-based monitoring of control performance, including post-remediation validation, to assess whether controls are operating as intended, identify recurring issues and support sustainable deficiency closure.
- Drive deficiencies through the agreed governance and closure process and escalate significant, overdue or ineffective remediation promptly to the Merchant CFO.
- Evaluate the significance of identified deficiencies, including recurring and related matters, and support classification conclusions in conjunction with Group SOX.
4.Control Design and Implementation
- Oversee the assessment, design and implementation of controls across significant financial reporting processes, systems and technology-enabled activities.
- Identify gaps in end-to-end processes and advise on the redesign or strengthening of controls that do not adequately address the underlying financial reporting risks.
- Provide control oversight across significant financial reporting areas, including financial close, consolidation and reporting, and relevant technology-enabled processes.
- Ensure that key controls are clearly documented, including ownership, frequency, review criteria, level of precision, exception management and evidence requirements.
- Simplify, standardise and automate controls where this strengthens the environment and improves sustainability across the Merchant Division.
5.Practical Business Implementation
A critical element of the role is ensuring that agreed control improvements are translated into practical, implemented and sustainable solutions. The Manager will provide design guidance, oversee implementation progress and challenge whether proposed solutions adequately address the underlying financial reporting risks. Accountable business and functional management remains responsible for approving, implementing, performing and evidencing process and control changes.
- Facilitate the redesign of reconciliations and advise on appropriate preparation, review, sign-off and exception-management requirements.
- Develop minimum control standards for financial close, journal approval, evidence retention and exception management for implementation by the relevant business owners.
- Restructure access approval, maker and checker, and segregation-of-duties processes and controls.
- Develop standards and templates for management review controls and supporting control documentation and a related control repository for storage of such documents.
- Identify weaknesses in system-generated reporting and define appropriate information-produced-by-the-entity and data-integrity requirements for implementation by the relevant process and system owners.
- Assist teams to resolve control backlogs and coach control owners through correct execution, without assuming ownership or execution of the control.
6.SOX Framework and Documentation
- Own the quality and maintenance of Merchant SOX documentation, including risk and control matrices, process documentation, control descriptions, control-owner registers and remediation records.
- Ensure that SOX documentation and testing records are complete, current and subject to appropriate governance.
- Ensure documented processes reflect what actually happens in the business rather than what policy says should happen.
- Support the annual risk assessment, scoping and identification of key financial reporting risks, processes, systems and controls, together with certification requirements.
7.Testing and Assurance Readiness
- Coordinate the annual SOX programme, including risk assessment, walkthroughs, design and implementation assessments, management testing, remediation and year-end testing readiness.
- Perform risk-based management testing and quality reviews to assess whether controls are appropriately designed, implemented and operating effectively.
- Identify and remediate potential control failures early and ensure that management testing is supported by complete, accurate and appropriately reviewed working papers and evidence.
- Coordinate management's remediation validation and facilitate independent testing by Group SOX, Internal Audit and external audit.
- Design controls and perform first line testing as required by the programme, guided by the Group SOX team & supported by Internal Controls Analyst.
- Maintain appropriate objectivity when allocating, performing and reviewing testing, particularly where members of the Merchant SOX team have assisted with control design or remediation.
8.Specialist and Emerging Control Areas
- Assess and document the financial reporting control implications of outsourced services, third-party processing arrangements and relevant service organizations.
- Design and implementation of appropriate Merchant controls addressing risks arising from third-party services.
- Design and assessment of entity-level controls, fraud risks, management override