ET Risk and Compliance - Risk and Controls Governance Analyst
Job description
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
ET Risk & Compliance
ET Risk and Compliance / Risk & Controls Governance Analyst
Finance
Supervising Associate
About EY
At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. We're counting on your unique voice and perspective to help EY become even better. Join us and help build an exceptional experience for yourself and a better working world for all.
Job Summary
Enterprise Technology is a global organization that delivers reliable, secure and resilient technology services and solutions to enable an exceptional technology experience for EY people. As part of the Enterprise Technology Risk & Compliance (ETRC) team, the Finance Governance role will lead the operational governance of the Finance risk and control matrix and support a consistent, integrated control landscape. Reporting to the Risk & Controls Governance Lead, this role will maintain the Finance control inventory, lead control design and impact assessments, coordinate control changes and ownership alignment, and provide risk and control input to Finance technology transformation initiatives.
Responsibilities
The Finance RACM role will provide domain leadership for the Finance control landscape and coordinate delivery of RACM governance activities under the direction of the Risk & Controls Governance Lead.
Key responsibilities include
- Own and maintain the Finance risk and control matrix and related control inventory, ensuring alignment with the ETRC RACM methodology, taxonomy and governance requirements.
- Maintain Finance risk-to-control mappings and support an integrated view of applications, processes, risks, controls, ownership, access, vendors and key technology dependencies.
- Coordinate Finance control additions, updates and removals with control owners, delegates, Operations & Reporting and Assurance & Compliance stakeholders.
- Consolidate Finance control changes and prepare accurate RACM and ISQM updates that reflect approved control design activities.
- Assess Finance applications, processes and technology changes to identify requirements for new or updated controls, including IT general controls, SDLC controls, interfaces, access and segregation of duties.
- Lead control rationalization and control impact assessments, identify duplication or coverage gaps and recommend changes to control design, ownership and accountability.
- Manage the design and readiness process for new or updated Finance controls, including stakeholder consultation, required approvals, sign-offs and readiness for implementation.
- Coordinate Finance input to the annual ET controls certification cycle, review reported exceptions and track remediation actions arising from certification outcomes.
- Provide risk and control governance input to strategic Finance technology initiatives and perform control gap analysis with practical remediation recommendations.
- Monitor changes in control ownership and delegate arrangements, maintain effective stakeholder alignment and escalate unresolved ownership or control design matters.
- Identify recurring control themes and systemic gaps and provide clear management insights and recommendations to support the Finance control environment.
- Partner with the Non-Finance RACM role, Risk & Controls Analyst and other ETRC pillars to support one consistent and integrated ET control landscape.
Analytical / Decision-Making Responsibilities
The role applies sound judgment and strong analytical thinking to assess technology and process changes, evaluate control coverage, identify gaps or duplication and determine when controls require addition, redesign, rationalization or escalation. The individual will balance Finance-specific requirements with the ETRC control framework, prioritize competing governance activities and provide evidence-based recommendations to stakeholders and leadership.
Knowledge and Skills Requirements
The role requires a strong understanding of technology risk and controls, RACM governance, control design and Finance technology environments. The successful candidate will be able to connect business and technology risks to practical controls, challenge unclear ownership or design, and translate complex requirements into clear documentation and actionable recommendations. Strong stakeholder management, organization, attention to detail and written communication skills are essential.
Job Requirements
To qualify, candidates must have
- Bachelor's degree in Information Technology, Business, Accounting, Finance, Risk Management, or a related discipline, or equivalent experience.
- Minimum 6 years of experience in technology risk, internal controls, IT audit, compliance, risk and control matrix management or a related field.
- Demonstrated experience maintaining RACMs, performing control design or impact assessments and translating risks and requirements into clear control activities.
- Strong understanding of IT general controls, technology change, access management, SDLC, interfaces and segregation of duties concepts.
- Experience working with Finance technology platforms, SAP environments, ERP transformation or similar large-scale technology programs is preferred.
- Experience coordinating control owners and senior stakeholders across technology, risk, audit, information security and business functions.
- Strong analytical and problem-solving skills, with the ability to identify control gaps, assess impact and develop practical recommendations.
- Strong organizational and project coordination skills, including the ability to manage multiple priorities, approvals, dependencies and deliverables.
- Excellent verbal and written communication skills, including the ability to prepare clear control documentation, governance materials and management updates.
- Proficiency with Microsoft 365, SharePoint, Power BI and collaboration platforms; experience with GRC or RACM tools is preferred.
- Professional certifications such as CISA, CRISC, CISM, CIA, CPA, ACCA or similar are a plus.
What We Offer You
At EY, we will fuel your extraordinary talents in a diverse and inclusive culture of globally connected teams.
- Career development: At EY, your career is yours to shape! We will develop you with future-focused skills and equip you with world-class experiences.
- Flexible work arrangements: Our flexible work policies empower you to balance your professional and personal life, fostering a culture of trust and autonomy.
- A comprehensive benefits package: need language from Talent/Benefits.
- Compensation: A competitive compensation package will be offered, including salary, benefits, and potential for performance-based incentives.
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.