About this Control Testing Analyst (Lead) role at Capital
Responsibilities
Control Testing Execution
-
Plan, execute, and document control testing activities across operational or tech risk domains — covering both design and operating effectiveness
-
Perform periodic assessments of high-risk business areas including customer onboarding, AML processes, payment operations, financial promotions, and data protection
-
Identify control gaps, weaknesses, and process failures through structured walkthroughs, sample testing, and review of evidence
-
Produce clear, well-evidenced test workpapers that meet internal quality standards and can withstand regulatory scrutiny
-
Document findings and communicate them clearly to control owners and senior stakeholders
-
Work with first-line teams to agree root cause analysis and develop practical, time-bound remediation plans
-
Track open issues through to closure, conducting follow-up testing to validate that corrective actions have been implemented effectively
-
Maintain the issues register and provide regular status updates to the Head of Control Testing
-
Act as a visible, credible presence across business functions — building relationships that make control testing a collaborative process rather than an adversarial one
-
Support the development of risk and control awareness across the organisation, helping first-line teams understand why controls matter and how to own them effectively
-
Deliver guidance and informal coaching to control owners on control design, evidence requirements, and good practice
-
Represent the Control Testing function in cross-functional forums, risk committees, and working groups as required
-
Contribute to the preparation of control testing reports and dashboards for senior management and risk committees
-
Support the maintenance and development of the control library, ensuring controls are accurately mapped to risks and business processes
-
Assist in preparing documentation for regulatory audits and examinations
-
Provide input to the annual Control Testing Plan, drawing on knowledge of operational risk areas and business change
Issue Management & Remediation
Risk Culture & Stakeholder Engagement
Reporting & Framework Support
Requirements
Experience
-
5–8 years of proven experience in control testing, operational risk, tech risk or internal audit within financial services or regulated FinTech
-
Proven ability to execute tests of controls independently, from planning through to final report
-
Experience engaging with first-line business teams in a second-line capacity
-
Familiarity with multi-jurisdiction regulatory requirements — experience across FCA, CySEC, or ASIC environments is advantageous
-
Experience supporting or preparing for regulatory audits and examinations
-
Sound understanding of operational risk frameworks (e.g., COSO, ISO 31000) and how they apply in a regulated financial services context
-
Knowledge of key regulatory obligations relevant to a financial institution — including Consumer Duty, AML, GDPR, and best execution
-
Familiarity with control testing methodologies and issue management processes
-
Comfortable using GRC tools, Excel, and reporting platforms to manage and present testing output
-
Strong interpersonal and communication skills — able to engage at all levels, from operational staff to senior management
-
Self-starter with the confidence to manage workload independently and take ownership of outcomes
-
Methodical and detail-oriented, with a natural instinct to question and verify
-
Genuine interest in building a risk-aware culture, not just completing a testing checklist
-
Adaptable and resilient — comfortable working in a function that is still being built and where the scope will evolve
-
Bachelor's degree in Finance, Business, Risk Management, Law, or a related field
-
Professional certification such as IRM, ICA, CIA, or equivalent
Knowledge
Personal Attributes
Desirable Qualifications