Amr Mohamed, Head of Internal Audit

Amr Mohamed

Head of Internal Audit

Fawaz Abdullaziz Al Hokair & Co.

Location
Saudi Arabia
Education
Master's degree, Information System Security
Experience
23 years, 6 Months

Share My Profile

Block User


Work Experience

Total years of experience :23 years, 6 Months

Head of Internal Audit at Fawaz Abdullaziz Al Hokair & Co.
  • Saudi Arabia - Riyadh
  • My current job since May 2016

- Manage the Internal Audit & Advisory Services as integrated audit services includes IT, Financial and Operational audit services to within Al Hokair Retail group such as Retail Key activities (Sales to Cash), Procure to Pay (AP), Build to Retire (Fixed Asset), Plan to Build (Inventory Management); Hire to Retire (HR & Payroll) and Financial Reporting (GL).
- Develop three years Strategic Risk Based Audit Plan and Annual Audit Pan for the Group activities.
- Prepare the Audit Committee Quarterly Reports and Annual Internal Audit Report.
- Develop the Audit Risk Assessment (Audit Universe and Risk Universe).
- Develop Internal Audit methodology, Internal Audit Charter and Audit Committee Charter according to IIA standards.
- Perform Quality Assurance Review (QAR) for IA Function.
- Prepare the Audit Committee Quarterly Reports and Annual Internal Audit Report.
- Review of Group’s polices and procedure such as IT Policies, HR Policies, Retail Policies and Financial Policies and Performing Gap analysis.
- Implement Continues Auditing technology for Revenue Assurance and Retail Operations
- Using ACL (Audit Command Language), IDEA and Teammate Analytics for Technical Review of data integrity and analysis used within various application systems.
- Full responsible of CCH Teammate Audit Management System administration and implementation (Teammate champion).

Internal Audit Mnager at Mohamed Yousuf Naghi Group
  • Saudi Arabia - Jeddah
  • October 2012 to April 2016

- Managing IT, Financial & Assurance / Operational Audit activities for all NAGHI group's automotive sector operations such as Vehicle sales (New vehicles and Used cars), after sales (Workshop and Spare parts) and Financial Services (Leasing and Installment) processes to ensure acceptable performance and compliance levels within NAGHI group.
- Develop Internal Audit methodology and Audit Charter according to IIA standards.
- Develop the annual Risk Assessment and annual audit plan for all business activities.
- Developing Integrated Audit Programs for all types of audit assignments in the group's operations covers Financial, Operational and IT audit and related controls.
- Performing the investigation in case of fraud or irregularities.
- Review and evaluate the IT General Controls and Application System Controls for SAP ERP, ADP Autoline Dealer Management System and AS/400 applications.
- Finalize audit reports and perform Follow up Review for the implementation of corrective action.
- Develop audit staff through proactive career planning and performing staff evaluation.
- Coaching and mentoring the audit staff for developing proactive career path for all staff.

Deputy Manager – IT Advisory at KPMG Egypt
  • Egypt - Cairo
  • February 2011 to October 2012

• IT Risk Consulting
• IT Internal Audit Co/Outsourcing
• IT General Controls Review
• IT Application Risks and Controls Assessment
• Data Analysis and Control Assurance using ACL and IDEA
• IT Compliance and ISMS Implementation (PCI, HIPAA, ISO 27001)
• Cyber Maturity Assessment and IT Capability Assessment (COBIT, KPMG CMA)
• IT Security Policies, Security Strategy and IT Governance
• Contingency planning for Disaster Recovery and Business Continuity Management planning
• Information Security Assessment (Vulnerability Scanning, Penetration Testing and Configuration Review) and Computer Forensics
• IT System Selection and Vendor Selection
• IT due diligence

Internal Audit Supervisor at Abdul Latif Jameel Ltd. Co.
  • Saudi Arabia - Jeddah
  • May 2006 to December 2010

- Performed various Financial Audit, IT audit and Operational audit assignments of various companies & operations of ALJ group such as new vehicle sales and after sales operations (service workshops and spare parts), retail centers, community services, or real estates.
- Reviewed and evaluate the Operating System Controls for Windows, Unix, Novel, OS/400.
- Reviewed the Application System Controls for Oracle Financials & Oracle HRMS and AS/400 application.
- Using ACL (Audit Command Language) and IDEA for Technical Review of data integrity and analysis used within various application systems.
- Involved in turning around the IAD scope from traditional control based to Risk based audit.
- Involved in managing and coordinating the External Quality Assurance Review (QAR) for the department (first time in ALJ history) performed by Deloitte - Dubai office.
- Full responsibility of TeamMate Audit Management System (Responsible for Administration and Technical Implementation).
- Was responsible of develop and manage the website for the IA department.

Auditor at KPMG Egypt
  • Egypt - Cairo
  • October 2003 to May 2006

•Provide risk based audit for KPMG Egypt Clients
•Performing risk-based IS audits, including
1.IT General Controls review to evaluate the design and implementation and test the operating effectiveness of the following:
Access to programs and data
Program Changes
Program Development
Computer Operations
End-User Computing
2.IT Application Controls review to test key application controls supporting business processes. This includes identifying key risks that may affect the business process and evaluate the design and implementation and test the operating effectiveness of the automated controls that mitigate these risks. Mainly we test the following automated controls related to a business application:
System Access and Authorization.
System Interface and Data Migration.
Edit/Exception Reports.
System Configurations and Account Mapping.

•Performing Security audit and evaluated Controls over operating systems, applications and databases

Information System Specialist at ITC
  • Egypt - Cairo
  • October 2000 to September 2003

Information System administartor

Education

Master's degree, Information System Security
  • at Cairo University
  • July 2010
Bachelor's degree, High Diploma in Computer Science and Information Technology
  • at Cairo University
  • June 2002
Bachelor's degree, B.SC in Accounting
  • at Cairo University
  • June 2000

Specialties & Skills

Languages

Arabic
Expert
English
Expert

Training and Certifications

Certified Ethical Hacker (CEH) (Certificate)
Date Attended:
March 2010
Governance, Risk Management and Compliance Auditor (GRCA) (Certificate)
Date Attended:
August 2020
Governance, Risk Management and Compliance Professional (GRCP) (Certificate)
Date Attended:
August 2020
Certified in Risk and Information Systems Control (CRISC) (Certificate)
Date Attended:
June 2011
Certified Information Security Manager (CISM) (Certificate)
Date Attended:
June 2010
Certified Information Systems Auditor (CISA) (Certificate)
Date Attended:
December 2010
Certified Fraud Examiner (CFE) (Certificate)
Date Attended:
June 2021