Muhammad Saad Khan, MBA, CISA

Assistant Manager at EY MENA | IT Audit | Technology Assurance

Karāchi, Sindh, Pakistan

About

I am an experienced Certified Information Systems Auditor (CISA) with MBA Finance qualification, skilled in performing IS Audits, implementation of risk monitoring tools, General IT Controls and IT Application Controls. I have enjoyed myself as a team leader of groups of 2-3 individuals, providing training to my team and communicating the status of assessments. I hold an ability to communicate findings in a clear and accurate manner, and offer advice on controls to introduce to mitigate associated risks. I have a strong time management and interpersonal skills and an ability to prepare and complete IT audit testing. I am a dedicated individual ready to bring value to business by providing committed professional services of highest standard.

Experience

  • Assistant Manager at EY MENA | IT Audit | Technology Assurance at EY
    Oct 2023 - Present · 3 yrs 1 mo

  • Assistant Manager IS Audit at Bank Alfalah Limited
    Mar 2022 - Oct 2023 · 1 yr 8 mos

    Timely Execution of IS Audits:  Perform the regular audits of bank’s Technological Systems and infrastructure along with their Operational activities in accordance with annual audit plan approved by BAC and ensure effective & timely completion of audit engagements to determine whether the information systems are safeguarding assets, maintaining data integrity, and operating effectively to achieve the organization & objective. Joint Testing Signoff:  Perform the Joint Testing and Signoff activities of banks Technological Systems and infrastructure deployment in accordance with the Board approved Joint Testing and Review policy and ensure effective & timely completion of review. Documentation Review:  Perform Documentation review (BRD, FSD, PPG, SOP, etc.) to assist bank into deployment of necessary controls at design phase of any Information System Product/Project. Evaluation of Controls:  Assess the design and operating effectiveness of financial, operational, and regulatory controls as part of Audit/Joint Testing/FSD review engagements to evaluate CIA (Confidentiality, Integrity & Availability) of information systems and data. Maintenance of Audit Evidence:  Responsible to obtain evidence to determine whether the information systems are safeguarding assets, maintaining data integrity, and operating effectively to achieve the organization & objective. Quality of Audit report:  Prepare/draft the IS audit reports to provide reasonable assurance regarding compliance of applicable SBP regulations / IT standards / Bank’s policies & instructions submission of ES Timely.  Prepare and submit executive summary of units audited to Department Head for perusal and onward submission to GH-AIG and Board Audit Committee.  Continuous improvement as per best audit practices, initiatives and improvisation.

  • Senior Associate Consultant at PwC
    Nov 2019 - Mar 2022 · 2 yrs 5 mos

     Performing and reviewing IT Application Controls. (Interface Testing, Segregation of Duties, System Configuration).  Internal Controls over Financial Reporting.  Information Technology Risk Assessment.  Information Technology Governance, Policies and Procedures.  BCP Maturity Assessment.  Vendor Assessment Selection.  Information Technology General Controls.  Drafting IT management letter after completion of audit engagement.  Provide Assistance and support to Bank’s IT for the management, validation / revalidation of audit findings.  Auditing/Security review of in scope Operating Systems, Application, and Database.  Assessment of IT governance, Access security, Program change and data center.

  • IT Governance & Audit Coordinator at United Bank Limited
    Feb 2019 - Nov 2019 · 10 mos

     Coordinate and manage Information Technology (SBP, external, internal) and Information Security assignments.  Meet and collect responses from SMEs all observed issues and follow up on all corrective actions.  Ensure timely closure of the exceptions as per corrective action plan.  Review evidences and provide advice for closure of the audit issues.  Maintain and update the tracking sheets of all IT Audit and IS Reports.  Assist processes and systems by coordinating, gathering and analyzing relevant information and make recommendations to improve them based on Bank’s Policy.  Complete all task within a time frame assign by Manager.  Maintain internal and external communication i.e. State Bank of Pakistan, Bank’s senior management and external auditors etc.

  • Associate Consultant at EY
    Jan 2016 - Feb 2019 · 3 yrs 2 mos

     Manage clients and conduct preliminary assessment of performances including understanding business nature, planning assignment, execution approach and timelines.  Gather knowledge on various inherent and control risks related to possible irregularities and frauds.  Examine the business transactions, processes, and other accounts related documents to validate compliance.  Provide feedback to clients for improving the internal controls & audit practices.  Analysis of IT Policies and Procedures.  Creating value in business processes and adding effectiveness in internal controls as part of internal audit engagements.  Understand and evaluate IT General Controls (IT Governance, Manage Changes, Manage Access, Manage IT Operations and Security and Patch Management) making combined Risk Assessments.  Analytical Modeling & Journal Entries testing (JE Testing) using EY Global Analytics & ACL.