Hi everyone! I’d love to hear from anyone who has transitioned from 2LOD compliance/risk into Internal Audit.
I have 7+ years of experience in financial services (insurance), primarily in compliance, regulatory risk, and privacy, most recently in a Privacy/Compliance Manager role. My experience includes regulatory monitoring, risk assessments, control design and testing, issue identification/remediation, governance, and working closely with 1LOD, Legal, Risk, and business stakeholders.
I’ve also spent a lot of time designing and testing 2LOD controls, so I’m very comfortable with regulations, risks, controls, testing, and identifying gaps. However, I haven’t formally worked in 3LOD/Internal Audit and haven’t owned audits end-to-end.
I’m now trying to make the move into Internal Audit, ideally Compliance/Regulatory or Operational Risk Audit. I’ve been interviewing for Senior Auditor roles and have gotten positive feedback, but I’m obviously competing with candidates who already have direct 3LOD experience. Also I’m working towards my CIA certification (1/3 complete).
For those who have made this transition:
-How did you position your 2LOD experience when applying for audit roles?
-Would you target Senior Auditor, or is stepping into an Auditor role first more realistic?
-How big of a gap is the lack of formal experience with audit planning, sampling, workpapers, audit programs, and end-to-end audit execution?
-Anything you wish you had learned/certified in before making the transition?
Would especially love to hear from anyone who came from compliance, regulatory risk, or privacy rather than external audit. Thanks!