وصف الوظيفة
الأدوار والمسؤوليات
المسمى الوظيفي: مدير التدقيق الداخلي
التصنيف: مدير
التقارير إلى: تقارير وظيفية إلى لجنة التدقيق والمخاطر إذا كان المجلس الأعلى والادارة إلى الرئيس.
ملف القسم
مكتب التدقيق الداخلي هو وظيفة مستقلة وموضوعية وتأكيدية واستشارية. الغاية منه ليست إدانة الأخطاء بل منح القيادة ومجلس الإدارة الثقة بأن عمليات المؤسسة وعملياتها وأنظمتها والضوابط تعمل كما هو مخطط لها وتلبي الأغراض التي يطلبها استراتيجيات الRise. حيث لا تكون كذلك، يقوم المدير بتحديد الفجوة وتقييم المخاطر وتقديم تحسينات عملية وقابلة للتنفيذ. بشكل حاسم، يركز وظيفة التدقيق الداخلي في AIU على الضمان التشغيلي والعملياتي وليس التدقيق المالي. يتم إجراء التدقيق المالي من قبل المدقق الخارجي الذي يعينه AIU بشكل مستقل. لا يكرر مدير التدقيق الداخلي هذا العمل. بدلاً من ذلك، يغطي هذا الدور الإقليم المؤسسي الذي لا يغطيه المدققون الماليون: نزاهة العمليات الأكاديمية، امتثال عمليات الموارد البشرية والشراء، حوكمة تقنية المعلومات، عمليات شؤون الطلاب، إدارة منح البحث، والدليل التشغيلي الذي تتطلبه اعتمادية WASC.
نطاق العمل
يوفر مدير التدقيق الداخلي ضماناً تشغيلياً مستقلاً قائمًا على المخاطر عبر جميع وظائف المؤسسة. باستخدام خطة تدقيق سنوية منظمة وموافق عليها من قبل لجنة التدقيق والمخاطر بالمجلس، يفحص المدير ما إذا كانت عمليات AIU وضوابطها وآليات الحوكمة تعمل كما هو مقصود، مع تحديد المخاطر وتوصية بالتحسينات وتتبع تنفيذ الإجراءات التصحيحية. يغطي النطاق خمسة مجالات تشغيلية:
- تدقيق العمليات التشغيلية: مراجعة منهجية لتدفقات العمل المؤسسية وإجراءات التشغيل من قبول الطالب وحتى تقييم أعضاء هيئة التدريس وتقييمهم والامتحان، لتقييم ما إذا كانت العمليات فعّالة ومتّبعة بصورة متسقة وتحقق النتائج المقصودة.
- تدقيق الحوكمة والالتزام: تقييم ما إذا كانت هياكل الحوكمة وسياسات المجلس والسياسات المؤسسية تُنفّذ كما كُتبت مع التركيز بشكل خاص على السياسات المطلوبة للاعتماد من WSCUC.
- إدارة المخاطر: تحديد وتقييم ومراقبة مخاطر المؤسسة التشغيلية، تطوير وصيانة سجل مخاطر AIU، تقديم المشورة للرئيس والمجلس حول المخاطر الناشئة وتوصية تدابير التخفيف.
- نزاهة الأكاديمية والبحوث: مراجعة على مستوى العمليات لعمليات الأكاديمية وتوصيل المناهج والتقييم والامتثال لمنح البحث وإدارة أدلة أداء أعضاء هيئة التدريس والاعتماد.
- التحقيقات الخاصة والاستشارات: إجراء تحقيقات في الانحرافات المبلغ عنها أو فشل العمليات أو مخاوف الحوكمة وتقديم الدعم الاستشاري للقيادة المؤسسية في تصميم الضوابط والسياسات والتخفيف من المخاطر.
المسؤوليات الرئيسية
التخطيط التدقيقي وبرنامج التدقيق السنوي
- تطوير والحفاظ وتنفيذ خطة تدقيق سنوية قائمة على المخاطر تغطي جميع المجالات التشغيلية المؤسسية الهامة المعتمدة من لجنة التدقيق والمخاطر بكل مجلس نوفمبر قبل السنة الأكاديمية التي تنطبق عليها
- إعطاء أولوية للانخراطات التدقيقية بناءً على تقييم مخاطر مؤسسي رسمي موثق يجرى سنويًا ويرتب المناطق التشغيلية حسب احتمال وتأثير فشل عملية مادية أو عدم امتثال
- ضمان أن برنامج التدقيق يعالج متطلبات الأدلة التشغيلية لاعتماد WSCUC.
- إدارة تقويم التدقيق لضمان إكمال جميع الانخراطات المخطط لها خلال السنة الأكاديمية وإبلاغ النتائج للإدارة المعنية قبل بداية دورة التدقيق التالية
- مراجعة وتحديث خطة التدقيق خلال العام استجابةً لتغيرات كبيرة في أولويات المؤسسة أو المخاطر المحددة أو توجيه المجلس
تنفيذ تدقيق العمليات والضبط
- إجراء تدقيقات تشغيلية منظمّة لعمليات المؤسسة من تقديم الطلبات والالتحاق الطلاب وحتى التخرج، ومن توظيف وتقييم أعضاء هيئة التدريس وحتى الترقية، ومن طلب الميزانية حتى الموافقة على الإنفاق مع تقييم ما إذا كانت كل عملية موثقة ومطبقة باستمرار وتحقق النتائج المقصودة
- فحص عمليات الشراء وإدارة المورّدين للتأكد من أن المشتريات معتمدة بشكل صحيح، وتُدار بنزاهة عبر مناقصات تنافسية حيث يلزم، وأن العقود مُدارة وفق سياسة AIU ولوائح الكويت للشراء
- مراجعة عمليات الموارد البشرية من حيث التوظيف وإدارة العقود وتقييم الأداء وإدارة الإجازات لضمان تطبيق متسق عبر جميع الأقسام والمدارس
- تدقيق شؤون الطلاب من عمليات القبول واتخاذ القرارات الأكاديمية وتحديد الوضع الأكاديمي والإجراءات التأديبية والتعامل مع الشكاوى لضمان تطبيق السياسات كما وردت وبشكل عادل ومتسق
- مراجعة عمليات حوكمة تكنولوجيا المعلومات وضوابط الوصول إلى النظام وإدارة البيانات وإجراءات إدارة التغيير بالتنسيق مع كبير موظفي المعلومات ومزوداً بطبقة ضمان مستقلة على مخاطر تَكنولوجيا المعلومات التشغيلية
- إعداد تقارير تدقيق واضحة وقابلة للتنفيذ لكل انخراط توضح النطاق والأدلة التي فحصت والنتائج وتقييم المخاطر والتوصيات المحددة ومشاركتها مع عميد أو نائب الرئيس ذي الصلة قبل تقديمها إلى رئيس المجلس ولجنة التدقيق والمخاطر
الامتثال للحوكمة والسياسات
- تقييم ما إذا كانت سياسات AIU تُنفّذ تشغيلياً مع التأكد من أن الالتزامات السياسية تحدث كما تصف السياسات
- مراجعة امتثال المؤسسة لقانون العمل الكويتي والمتطلبات التنظيمية لـ PUC ومعايير حماية البيانات الكويتية، مع تحديد أي فجوات بين الالتزام التنظيمي والممارسة التشغيلية
- تقييم فعالية هياكل الحوكمة المشتركة في AIU، والتأكد من أن مجلس الكلية لديه سلطة تشغيلية حقيقية في الشؤون الأكاديمية وأن قراراته مُسجّلة ومُنفّذة وأن الحوكمة المشتركة ذات محتوى وليست شكلية
- إجراء فحص صحّي للحوكمة بشكل دوري، وهو تقييم سنوي مُنظم لفعالية لجان المجلس، واستكمال عملية التقييم الذاتي للمجلس، وتوثيق التقييم الرئاسي المقدم مباشرة لرئيس المجلس
- مراجعة جميع إفصاحات تضارب المصالح المؤسسية ووثائق المعاملات مع الأطراف ذات العلاقة وتقارير الإبلاغ عن المبلغين لضمان أن هذه العمليات تعمل وأن القضايا المعلنة تُتبع حتى الحل
الملف المرغوب فيه للمرشح
- التعليم درجة ماجستير في المحاسبة أو إدارة الأعمال أو التدقيق الداخلي أو الإدارة العامة مطلوبة. قد تقبل جهة مهنية في التدقيق أو المحاسبة بمستوى يعادل درجة الماجستير بدلاً من الماجستير الأكاديمي.
- الخبرة خبرة لا تقل عن سبع (7) سنوات في التدقيق الداخلي أو التدقيق التشغيلي أو إدارة المخاطر مع ثلاث (3) سنوات على الأقل في مستوى إشرافي أو إداري
- خبرة مثبتة في إجراء تدقيقات تشغيلية وعملياتية وليست حصرية في التدقيق المالي مع خبرة موثقة في فحص سير العمل المؤسسي والامتثال الحوكمي وعمليات الموارد البشرية والشراء
- أن تكون له خبرة سابقة في مؤسسة تعليم عالي أو قطاع عام أو مؤسسة تحكمها مشابهة هو ميزة كبيرة؛ يجب أن يفهم بيئة الحوكمة في الجامعة بما في ذلك الحوكمة المشتركة والإشراف من المجلس
- خبرة العمل مع أو الإبلاغ إلى لجنة التدقيق على مستوى المجلس يجب أن يكون المرشحون مرتاحين لإعداد وتقديم تقارير التدقيق على مستوى الحوكمة بلغة غير تقنية
- خبرة في تطوير والحفاظ على سجل مخاطر مؤسسي وإجراء تقييمات مخاطر منظمة
- الخبرة في الخليج العربي أو الكويت ميزة؛ الإلمام بقانون العمل الكويتي ومتطلبات تنظيم PUC والبيئة التشغيلية لمؤسسة خاصة في الكويت قيمة
- يفضل بشدة شهادات CIA وCRMA.
- المهارات والكفاءات التقارير التدقيقية المكتوبة الاستثنائية هي المنتج الأساسي لهذه الدائرة؛ يجب على المدير أن يكتب بشكل واضح ودقيق وخال من المصطلحات
- الاستقلالية المهنية والموضوعية يجب أن يحافظ المدير على الحياد في جميع الانخراطات، وأن يقاوم الضغط من الإدارة لتليين النتائج، وإبلاغ لجنة التدقيق والمخاطر في المجلس عند وجود صراعات مصالح
- الصرامة التحليلية القدرة على فحص عمليات مؤسسية معقدة، وتحديد نقطة فشل التحكم، والتمييز بين الأعراض وأسباب الجذر، وتقديم حلول تعالج السبب الجذري لا مظهره
- الذكاء العلاجي الشخصي يتطلب ثقة؛ يجب على المدير بناء علاقات بناءة مع من يخضع للتدقيق، موقّعًا وظيفة التدقيق كشريك في التحسين وليس أداة للعقاب
- التقدير والسرية يتعامل المدير مع معلومات مؤسسية حساسة، وكشوف المبلغين، ونتائج التحقيقات؛ السرية المطلقة غير قابلة للتفاوض
- الإلمام بمعايير الاعتماد WASC أو ما يماثلها ميزة مادية في هذا الدور
Job Description
Roles & Responsibilities
Position: Director of Internal Audit
Classification: Director
Reports To: Functional reporting to the Audit & Risk Committee if the BoT and Administrative to the President.
Department Profile
The Office of Internal Audit is an independent, objective assurance and advisory function. Its purpose is not to find fault it is to give AIU's leadership and Board the confidence that the institution's operations, processes, and controls are functioning as intended and are fit for the purposes the RISE Strategy demands. Where they are not, the Director identifies the gap, quantifies the risk, and recommends practical, implementable improvements. Critically, AIU's internal audit function focuses on operational and process assurance not financial audit. Financial auditing is conducted by AIU's independently appointed external auditor. The Director of Internal Audit does not duplicate that work. Instead, this role covers the institutional territory that financial auditors do not: academic process integrity, HR and procurement process compliance, IT governance, student affairs operations, research grant management, and the operational evidence that WASC accreditation requires.
Scope of Work
The Director of Internal Audit provides independent, risk-based operational assurance across all institutional functions. Using a structured annual audit plan approved by the Board Audit & Risk Committee, the Director examines whether AIU's processes, controls, and governance mechanisms are working as intended identifying risks, recommending improvements, and tracking implementation of corrective actions. The scope spans five operational domains:
- Operational Process Audit: Systematic review of institutional workflows and operating procedures from student admissions to faculty evaluation assessing whether processes are efficient, consistently followed, and producing intended outcomes.
- Governance & Compliance Audit: Assessment of whether AIU's governance structures, Board policies, and institutional policies are being implemented as written with particular focus on the policies required for WSCUC accreditation.
- Risk Management: Identification, assessment, and monitoring of institutional operational risks developing and maintaining AIU's risk register, advising the President and Board on emerging risks, and recommending mitigation measures.
- Academic & Research Integrity Audit: Process-level review of academic operations curriculum delivery, assessment practices, research grant compliance, faculty performance documentation, and accreditation evidence management to confirm that stated practices are actual practices.
- Special Investigations & Advisory: Conducting investigations into reported irregularities, process failures, or governance concerns and providing advisory support to institutional leaders on internal control design, policy development, and risk mitigation.
Key Responsibilities
Audit Planning and Annual Audit Programme
- Develop, maintain, and execute a risk-based Annual Audit Plan covering all significant institutional operational areas approved by the Board Audit & Risk Committee each November before the academic year to which it applies
- Prioritise audit engagements based on a formal, documented institutional risk assessment conducted annually ranking operational areas by likelihood and impact of material process failure or non-compliance
- Ensure the audit programme addresses the operational evidence requirements of WSCUC accreditation.
- Manage the audit calendar to ensure that all planned engagements are completed within the academic year and that findings are reported to relevant management before the next audit cycle begins
- Review and update the audit plan during the year in response to significant changes in institutional priorities, identified risks, or Board direction
Operational and Process Audit Execution
- Conduct structured operational audits of institutional processes from student application and enrolment through graduation, from faculty recruitment and evaluation through promotion, from budget request through expenditure approval assessing whether each process is documented, consistently applied, and producing intended outcomes
- Examine procurement and vendor management processes to confirm that purchases are properly authorized, competitively tendered where required, and that contracts are managed in accordance with AIU policy and Kuwait procurement regulations
- Review HR processes recruitment, contract management, performance evaluation, leave management to confirm consistent application across all departments and schools
- Audit student affairs operations admissions decisions, academic standing determinations, disciplinary processes, grievance handling to confirm that stated policies are applied equitably and consistently
- Review IT governance processes system access controls, data management, change management procedures in coordination with the CIO and providing an independent assurance layer over IT operational risk
- Prepare clear, actionable audit reports for every engagement stating the scope, the evidence examined, the findings, the risk rating, and specific recommendations shared with the relevant Dean or VP before submission to the President and Board Audit & Risk Committee
Governance and Policy Compliance
- Assess whether AIU's Policies are being operationally implemented confirming that policy commitments are happening as the policies describe
- Review the institution's compliance with Kuwait Labour Law, PUC regulatory requirements, and Kuwait data protection standards identifying any gaps between regulatory obligation and operational practice
- Evaluate the effectiveness of AIU's shared governance structures confirming that the Faculty Council has genuine operational authority in academic matters, that its decisions are recorded and implemented, and that shared governance is substantive rather than performative
- Conduct a periodic Governance Health Check an annual structured assessment of Board Committee effectiveness, Board self-evaluation process completion, and Presidential evaluation documentation reported directly to the Board Chair
- Review all institutional conflicts of interest disclosures, related-party transaction documentation, and whistleblower reports ensuring these processes are functioning and that issues raised are tracked to resolution
Desired Candidate Profile
- Education Master's degree in Accounting, Business Administration, Internal Auditing, or Public Administration is required. A professional audit or accounting qualification at a level equivalent to a master's degree may be accepted in place of an academic master's.
- Experience Minimum seven (7) years of progressive experience in internal auditing, operational auditing, or risk management with at least three (3) years at a supervisory or management level
- Demonstrated experience conducting operational and process audits not exclusively financial audits with documented experience examining institutional workflows, governance compliance, and HR and procurement processes
- Prior experience in a higher education, public sector, or comparably governed institution is a significant advantage candidates must understand the governance environment of a university, including shared governance and Board oversight
- Experience working with or reporting to a Board-level Audit Committee candidates must be comfortable preparing and presenting audit reports at governance level, in non-technical language
- Experience developing and maintaining an institutional risk register and conducting structured risk assessments
- GCC or Kuwait experience is an advantage familiarity with Kuwait Labor Law, PUC regulatory requirements, and the operating context of a private institution in Kuwait is valued
- CIA and CRMA Certifications are strongly preferred.
- Skills and Competencies Exceptional written communication audit reports are the primary product of this office; the Director must write clearly, precisely, and without jargon.
- Professional independence and objectivity the Director must maintain impartiality in all engagements, resist pressure from management to soften findings, and escalate conflicts of interest to the Board Audit & Risk Committee without hesitation
- Analytical rigor the ability to examine complex institutional processes, identify the point of control failure, distinguish symptoms from root causes, and recommend solutions that address the root cause rather than its manifestation
- Interpersonal intelligence effective internal auditing requires trust; the Director must build constructive relationships with the people being audited, positioning the audit function as a partner in improvement rather than an instrument of sanction
- Discretion and confidentiality the Director handles sensitive institutional information, whistleblower disclosures, and investigation findings; absolute discretion is non-negotiable
- Familiarity with WASC or comparable accreditation standards is a material advantage in this role