Internal Audit & Risk Manager
Tavevo Water and Sewerage
Quick Take
Lead the internal audit and risk management function, conducting risk-based audits, managing ICT controls, investigating compliance issues, and advising the Board and Management on governance and operational efficiency.
Senior audit experience in a regulated utility or public sector environment, expertise in risk-based audit planning and ICT controls, and proven ability to lead audit teams and influence senior leadership.
A competitive mid-to-senior salary (KES 200–350k/mo), a strategic advisory role with direct Board exposure, and meaningful impact on governance in Kenya's water utility sector.
Job Description
Tavevo Water and Sewerage Company is seeking a seasoned Internal Audit & Risk Manager to lead its internal audit and risk management function. In this critical role, you will provide independent, objective assurance and advisory services that strengthen the company's governance framework, internal controls, and enterprise risk management processes. You will serve as a key advisor to both Management and the Board of Directors, ensuring the organization operates within regulatory and statutory requirements while continuously improving operational efficiency.
This is a senior leadership position that requires a hands-on professional who can design and execute risk-based audit plans, oversee ICT control environments, conduct investigations, and drive the implementation of audit recommendations across all departments. You will play a pivotal role in safeguarding the company's assets, reputation, and long-term sustainability within Kenya's water and sewerage sector.
- Coordinate the timely preparation of risk-based internal audit work plans and budget estimates, outlining key activities required to achieve departmental targets.
- Monitor the administration and application of internal audit policies and procedures; recommend updates to ensure compliance with regulatory, statutory, and best practice requirements.
- Conduct business process risk assessments to identify high-risk areas and inform audit focus areas for Audit Committee approval.
- Execute approved audit plans and thoroughly document audit observations, findings, and actionable recommendations.
- Examine, evaluate, and report on the adequacy of internal controls, providing strategic advice to Management and the Board.
- Lead special audits and investigations, preparing comprehensive written reports on observations and recommendations.
- Provide regular updates to the Audit Committee on planned reviews, ongoing investigations, and ad-hoc audit activities.
- Track and follow up on audit recommendations to ensure timely implementation of approved action points.
- Perform control reviews for ICT systems security, application development, maintenance, disaster recovery, and cybersecurity matters.
- Evaluate the ICT control environment against emerging technologies and recommend control measures to mitigate risk exposures.
- Establish, monitor, and report on the progress of Action Plans, including performance impact and institutional uptake and maturity.
- Periodically update the Board of Directors on the company's overall performance and risk posture.
- Assist Management in presenting and discussing performance results and potential adaptations across all departments.
- Perform any other duties as assigned by the supervisor.
- Demonstrates ability to design and execute risk-based audit plans aligned with organizational strategy and regulatory requirements.
- Proven track record of leading audit teams and managing complex audit engagements in a water utility, public sector, or regulated industry environment.
- Ability to conduct thorough business process risk assessments and translate findings into practical, prioritized recommendations.
- Competent in reviewing and assessing ICT control environments, including cybersecurity risks, disaster recovery planning, and emerging technology risks.
- Capable of preparing clear, concise, and comprehensive audit reports for senior management and board-level audiences.
- Demonstrates strong analytical and critical thinking skills to identify control weaknesses and systemic issues.
- Effective communicator who can influence stakeholders at all levels and drive accountability for audit findings.
- Proficient in accounting software and MS Office Suite, with ability to leverage technology in audit processes.
- Holds a Bachelor's degree in Finance, Accounting, or a related field from a recognized institution.
- Holds a CPA (K) qualification and is a member of ICPAK in good standing.
- A Master's degree in Finance, Economics, Strategic Management, or a related business field is an added advantage.
- Brings at least 5 years of relevant experience, with a minimum of 3 years in a managerial or supervisory role.
- Meets the integrity and ethics requirements under Chapter Six of the Kenyan Constitution, including obtaining clearance certificates from relevant bodies (KRA, HELB, EACC, CRB, DCI).
Tavevo Water and Sewerage Company offers a competitive remuneration package commensurate with qualifications and experience. Based on Kenyan market benchmarks for this seniority level and sector, the estimated monthly gross salary ranges between KES 200,000 and KES 350,000. The company provides benefits in line with public water utility standards, which may include medical cover, pension/NSSF contributions, and statutory leave entitlements. Specific package details will be communicated to shortlisted candidates.
This role is ideal for a CPA (K)-qualified audit professional with demonstrated managerial experience who thrives in a structured, compliance-driven environment. You are a strategic thinker with strong ethics, exceptional report-writing skills, and the ability to engage confidently with board-level stakeholders. You have a genuine interest in public sector accountability and improving governance in Kenya's water and sanitation sector.
Please do not apply if you have fewer than 5 years of relevant audit experience, lack CPA (K) qualification or active ICPAK membership, or cannot meet Chapter Six constitutional requirements. Candidates without managerial or supervisory experience will not be considered for this role.
- Prepare an updated CV and a cover letter addressed to the Managing Director, Tavevo Water and Sewerage Company.
- Attach copies of your academic and professional certificates, including CPA (K) certificate and ICPAK membership certificate.
- Include Chapter Six compliance documents: certificates of clearance from KRA, HELB, EACC, CRB, and DCI (Certificate of Good Conduct).
- Submit your application through the official Tavevo Water and Sewerage Company application channel or as directed in the original job advertisement.
- Only shortlisted candidates will be contacted for interviews. Canvassing in any form will lead to automatic disqualification.
Requirements Breakdown
Must Have
- Proven experience designing and executing risk-based audit plans in a water utility, public sector, or regulated industry
- Leadership experience managing audit teams and complex audit engagements
- Deep knowledge of internal controls, ICT audit, cybersecurity, and enterprise risk management frameworks
- Professional audit qualification (CIA, ACCA, or equivalent) or significant equivalent audit experience
- Strong understanding of regulatory and statutory compliance requirements in Kenya's water/utilities sector
Nice to Have
- Experience with Audit Committee reporting and Board-level advisory work
- Familiarity with ISO 31000 or other enterprise risk management standards
- Knowledge of disaster recovery, business continuity, and application development controls
- Exposure to fraud investigation or forensic audit work
Don't meet every requirement? Tailor your CV to close the gap →
Salary Context
Competitive mid-to-senior salary for Internal Audit & Risk Manager in a regulated utility; above entry-level but modest for Nairobi comparables.
KES 200–350k/mo is reasonable for a senior audit leadership role in a regional water utility in Voi, though Nairobi-based Internal Audit & Risk Managers at larger financial institutions or multinational corporates typically earn 30–50% higher. Salary in this sector is driven by company size, profitability, and regulatory complexity.
About Tavevo Water and Sewerage
Tavevo Water and Sewerage Company is a utility service provider operating in the Voi region of Kenya, responsible for delivering critical water and sanitation services to households and businesses. As a regulated utility, the company operates under strict compliance and governance frameworks, making internal audit and risk management essential to operational integrity and public trust. Working here offers exposure to infrastructure challenges and the chance to improve governance in a sector vital to Kenya's development.
Likely Interview Questions
- 1
Walk us through a risk-based audit plan you've designed: how did you prioritize audit focus areas, and what was the outcome?
- 2
Describe your experience auditing ICT controls and cybersecurity in a utility or similar regulated environment. What frameworks or standards did you use?
- 3
Tell us about a time you identified a significant control weakness or compliance gap and had to influence senior management or the Board to implement your recommendation. How did you approach it?
- 4
What is your experience with fraud investigations or forensic audit work, and how have you handled sensitive findings?
- 5
How do you stay current with emerging risks in water utilities, ICT, and the broader regulatory landscape in Kenya?
Application Tips
Highlight specific audit engagements you've led in water, utilities, or public sector—mention company size, audit scope, and tangible outcomes (e.g., controls implemented, recommendations accepted by Board).
Emphasise your ICT audit and cybersecurity experience, especially if you've assessed cloud systems, data protection, or disaster recovery controls—this is a key responsibility in the job description.
Showcase evidence of Board or Audit Committee interaction: present examples of reports you've written, audits you've presented, or advisory recommendations that directly influenced strategic decisions.
Career Path
Roles that lead here
Where this leads
Skills & Keywords
Honest Assessment
Green Flags
- Clear, detailed responsibility list with strategic scope—from audit planning through Board reporting—indicating a well-defined, senior-level role.
- Explicit focus on ICT controls and cybersecurity, reflecting modern risk priorities and demand for relevant expertise.
- Direct Board of Directors interface and Audit Committee engagement—a hallmark of genuine influence and strategic responsibility.
- Competitive salary range (KES 200–350k/mo) for a regional utility role, with sufficient spread to reward experience and performance.
Watch Out
- The job description cuts off mid-sentence under 'Required Skills & Experience'—the posting appears incomplete, which may indicate rushed recruitment or lack of clarity around qualifications.
- No mention of benefits, leave, professional development support, or training budget—typical for senior roles to outline these.
- Voi is a regional location; relocation support or remote work flexibility is not mentioned, which could be a barrier for candidates from Nairobi or other urban centers.
A Day in the Life
Your week balances strategic planning and hands-on audit work: you might start Monday reviewing draft audit plans with your team before an Audit Committee meeting, then spend Tuesday–Wednesday conducting control assessments on financial systems or conducting cyber-security reviews of the company's ICT infrastructure. By Thursday, you're drafting findings and recommendations from an active audit, and Friday involves tracking follow-up on previously issued recommendations and meeting with a department head to discuss implementation. You're constantly juggling active audits, regulatory compliance updates, and Board-level reporting while mentoring junior auditors and staying alert to emerging risks in water utility operations.
Frequently Asked Questions
What qualifications do I need to be an Internal Audit & Risk Manager at Tavevo Water and Sewerage?
You should have a professional audit qualification (CIA, ACCA, or equivalent) or 8–12 years of senior audit experience in a regulated industry. Deep knowledge of internal controls, ICT audit, and enterprise risk management is essential; water utility or public sector experience is highly valued.
Is the Internal Audit & Risk Manager role at Tavevo Water and Sewerage remote?
The job description does not mention remote work options. Given the location (Voi) and the need for regular Board and Audit Committee meetings, on-site presence is likely expected; relocation or relocation support should be clarified during recruitment.
How much does an Internal Audit & Risk Manager earn at Tavevo Water and Sewerage?
The salary range is KES 200,000–350,000 per month, which is competitive for a mid-to-senior audit leadership role in a regional utility but modest compared to similar roles in larger Nairobi-based organizations.
What are the career growth opportunities for this role?
This role is a gateway to Chief Audit Executive (CAE) or Head of Internal Audit positions at larger utilities, or to broader governance and risk leadership roles (e.g., Finance Director, Group Risk Manager) in multi-utility or financial organizations.
Free Match Score
See how well you match this job
Upload your CV and get an instant AI score showing exactly how well your experience matches this Internal Audit & Risk Manager role. Free, takes 30 seconds.
Get My Match Score — FreeNo credit card needed
Boost your chances
AI-tailored for: Internal Audit & Risk Manager at Tavevo Water and Sewerage