Vice President & Chief Audit Executive
Stockholm, Stockholm County, Se
Internal controls and compliance don't need to be boring and stiff! Done right, and with the company's culture in mind, internal controls will give you the confidence to move faster and take greater risks. Effective risk management and controls need to be meaningful and helpful to the business. If it slows us down, we're doing something wrong.I led Spotify's Internal Audit team, comprised of a truly international team of internal audit, risk, governance, and internal control professionals. For SOX, we advised management on the design and implementation of controls and performed controls testing. We provided advisory and assurance services for the business, ranging from collaborating with our user fraud and metrics teams, reviewing our data privacy practices, to advising on cyber security risk and response. And finally, we also created and led Spotify's ERM program to enable the identification and holistic management of risks to our enterprise.Some of the other areas our IA team worked on:- Operational effectiveness and efficiency, including finance automation- Data governance- Risk Management policies and processes (Whistleblowing, Crisis Management, Conflicts of Interest)- People (Employee branding and Culture, Travel and Expense policies) and Finance policies- Trust and Safety, platform fraud- Legal compliance audits and processes (e.g., Anti-bribery and corruption, GDPR/Data privacy)- Security policies and processes (Information security, Cyber security, Security Operations, Site Security)- Business Partners and Vendor policies (Vendor due diligence, vendor code of conduct, agents, trading partners, contractors)Before we went public in 2018, I led the ERP selection process and implemented key financial processes to ensure that our finance operations were capable of supporting a public company.