Group Head of Internal Audit
Lead and own the Group Internal Audit function for Capital.com, providing independent, risk-based assurance across all regulated entities, business lines, and geographic markets. The Group Head of Internal Audit is responsible for setting the strategic direction of the audit function, designing and operating a hybrid audit framework, and providing the Group Board, Audit Committee, and senior leadership with timely, credible assurance on the adequacy and effectiveness of governance, risk management, and internal controls across the group.
The role has an unconditional duty to escalate material control failures, significant audit findings, and regulatory concerns directly to the Group Audit Committee, independent of any instruction from executive management or any group function.
The role operates at the intersection of group governance and local regulatory accountability, requiring both strategic thinking and deep knowledge of multi-jurisdictional financial services regulation. The postholder works in close coordination with the Global Head of Compliance and other key stakeholders to ensure alignment between audit and compliance risk assessments, while maintaining the independence required of an effective third-line function.
Strategic Leadership
-
Develop and own the multi-year internal audit strategy aligned to group growth plans, regulatory expectations across all six entities, and the evolving risk landscape of a digital CFD and trading business.
-
Build and lead a high-performing, independent internal audit function capable of providing credible assurance across a complex, multi-jurisdictional group.
-
Act as a trusted adviser to the Group Board, Audit Committee, and CEO on control environment quality, emerging risks, and regulatory developments with audit implications.
-
Develop, maintain, and execute the annual group audit plan, covering all entities, material business processes, technology infrastructure, regulated activities, and outsourced functions.
-
Lead and oversee audit fieldwork and reporting across operations, trading systems, technology and cyber, AML/KYC, financial crime, market abuse surveillance, conduct risk, Consumer Duty (UK), product governance, third-party and outsourcing arrangements, model risk, and financial controls.
-
Assess the adequacy and effectiveness of internal controls, identify control weaknesses and gaps, and provide actionable, proportionate recommendations.
-
Ensure audit reports are clear, accurate, evidence-based, and issued within agreed timescales.
-
Maintain a group-wide audit issue log, tracking the status of all open findings across entities, escalating overdue or high-risk items to the Audit Committee as appropriate.
-
Challenge and validate management remediation responses and closure evidence to ensure issues are genuinely resolved rather than administratively closed.
-
Ensure the audit programme addresses the regulatory expectations of all relevant regulators: FCA (UK), CySEC (Cyprus), ASIC (Australia), SCB (Bahamas), SCA (UAE), and CNMV (Spain).
-
Provide independent assurance on material business change programmes, new product launches, strategic outsourcing decisions, and regulatory change implementation across the group.
-
Liaise constructively with external auditors and regulators, coordinating audit coverage where appropriate and providing regulators with access to audit documentation as required.
Audit Planning and Delivery
Issue Management and Follow-Up
Regulatory and Governance Alignment
-
Significant internal audit leadership experience within a multi-jurisdictional financial services group, broker, or investment firm — ideally including FCA-regulated and CySEC-regulated entities.
-
Strong working knowledge of FCA requirements for investment firms (MIFIDPRU, SYSC, COBS, PROD, DISP, AML/CTF, Consumer Duty) and familiarity with CySEC, ASIC, and other regulatory frameworks relevant to Capital.com's operational footprint.
-
Proven experience designing and operating a hybrid or co-sourced internal audit model at group level, including methodology ownership, panel governance, and quality assurance of specialist providers.
-
Experience auditing trading platforms, CFD or derivative products, technology infrastructure, financial crime controls, AML/KYC processes, and outsourced services.
-
Demonstrated ability to build and sustain productive relationships with Boards, Audit Committees, and senior management while maintaining audit independence.
-
Track record of preparing clear, compelling assurance opinions and presenting findings at Board and Audit Committee level.
-
Experience managing or developing an internal audit team across multiple locations or entities.
-
Professional audit qualification (CIA, ACCA, ACA, CISA, CPA or equivalent) — CIA strongly preferred.
-
IIA membership or equivalent professional body membership.
-
Strong knowledge of the IIA International Professional Practices Framework (IPPF) and its application in a multi-jurisdiction financial services context.
-
Familiarity with UK SMCR and equivalent senior manager/controlled function regimes across relevant jurisdictions.