Johnny Fong
Head of Internal Audit @ AIA Hong Kong and Macau
About
Johnny has over twenty years of experience in Big 4 consultancy and audit as well as internal audit departments for life and general insurers in APAC, responsible for delivering audits, internal control governance projects, business process improvements and core system implementations that have true business impact. In advisory roles, Johnny managed delivery of global system rollouts and post-merger streamlining. In the capacity of Head of Internal Audit, Johnny drove board-level discussions at both BUs and Group on governance, risk and internal controls under complex regulatory environments, and actively advocated control automation and data analytics. Combining experience in IT and audit, Johnny enhanced audit efficiencies through use of data analytics, enterprise data lakes and data visualization, as well as automatic and continuous testing using emerging technologies such as AI and robotics (RPA).
Hong Kong SAR
Hong Kong
Insurance
分析技巧, 公司實用資訊, 解析, 資訊科學, M&A Due Diligence, Project Risk Assessment, IT Risk Management, Data Visualization, Data Analytics, Robotic Process Automation (RPA), Artificial Intelligence for Business, Auditing, IT Strategy, Governance, Program Management, Management Consulting, Business Process Improvement, Change Management, Business Transformation, Strategy
Experience

Head of Internal Audit
Hong Kong SAR
Deploying emerging technologies in audit work • Lead development of AI module to analyse welcome call voice records and match against standard call scripts. Analyse customer sentiments and match against management decisions. • Advocate data analytics to identify risk patterns and high risk areas for focused audit efforts, including treating customers fairly, sales conduct and fraud detection. • Internal audit dashboards on enterprise data lake (Databricks) to visualize data analytics results for key processes including agency sales, AML/CFT, new business and claims. • Deploy Robotic Process Automation (RPA) tools for streamlining and automating data collection from external sources and across internal systems. • Advocate use of Copilot to streamline and automate data collection for audit planning. • Information Security assessment for GL20 compliance on newly acquired Blue Cross (GI) Internal Audit Leadership Achievements • Advise Exco members including CEO and CRO on strategic initiatives and projects, new regulations, emerging risks etc. Join as observer in the steering committees for strategic projects and provided advisory services on project management risks. • Forge close working relationships and discussion forums with external auditors, second line and first line governance and control teams (1.5 line of defence) to share information for agile audit planning. Become trusted advisor of first line in implementing new control processes. • Support ad-hoc requests from regulators and independent reviewers at onsite inspections and regulator-led independent reviews, on topics such as AML/CFT, market conduct, FATCA/CRS and sales quality. Help management prepare for regulatory inspections through health checks and management action validations. • Represent internal audit at Board Committees and Working Committees including Operational and Financial Risk Committees, Audit Committees, local Exco Meetings and at external audit profession forums

Director, Corporate Audit, AIA Group Limited
Hong Kong SAR
Collaborated between Group, three AMCs and 18 BUs on a wide range of topics such as reinsurance, senior expenses, unit pricing, ERM, investment information controls and restricted dealing, investment accounting and valuation. Provide data analytics and visualization support for standardising BU audit execution and driving group-wide audit insights. Collaborate between Group Office and Asset Management Companies in Hong Kong and Singapore to establish the third line of defence, investment audit specialist team, audit programme standard templates, and collaboration protocol with BU investment functions. Advisory Engagements - Advocate use of data analytics to identify risk patterns and high risk areas for focused audit efforts, including treating customers fairly, sales conduct and fraud detection. - Assess use of latest technology in business operations, including data analytics, control automation, RPA and Artificial Intelligence. - Understand Group strategic initiatives and investments, new regulations affecting AIA Group (e.g., IFRS 9, GWS, ESG), and emerging business risks, and assess impact to internal control environment and audit plan. - Participate in project steering committees for new process and system implementation and challenge business leadership on business initiatives (products, compliance, digitalisation, group strategic projects, etc) - Due diligence (internal audit workstream) for merge and acquisition transactions at AIA Group

Senior Audit Manager, Aegon Asia B.V.
Hong Kong
Advisory Engagements - Due diligence and tendering for change in shareholder for Aegon Joint Venture in China from China National Offshore Oil Corporation (CNOOC) to Tsinghua Tongfang (THTF) - Acquisition of a brokerage firm in Guangdong, with duties including coordinating documentation requests, due diligence and onsite interviews. - Market segmentation and product analysis for Japan SSI market (Small Amount and Short Term Insurance, 日本少額短期保険会社). - Market segmentation, competitor analysis and cost-benefit analysis for Australian insurance direct marketing campaign advisory services of former Aegon Direct & Affinity Marketing Services Co. Ltd. (now Aegon Insights). - Project assurance for large scale IT projects. Internal Audit Leadership Achievements - Deliver reviews on emerging risks such as digital distribution and eSales, premium financing arrangements (Transamerica Life Bermuda), country-specific sales practices and commission structure. - Data analytics, expense reviews and forensic investigations on suspicious transactions and incidents. - Was assigned to a five-month secondment in the Group Office in the Hague, working with Corporate Center audit team for group audits surrounding asset management and investment systems. - Supervised audit portfolio and administrative affairs including annual audit planning, budgeting, methodology development, quality assurance and staff capability development, with a team of 4-6 staff. - Liaised with local audit teams in China, India and Japan, Regional Office management and Corporate Center in the Netherlands. - Represented Asia in global audit committees such as Information Technology Audit Group and Professional Practice Group. - Closely worked with operational risk and compliance teams on areas such as data privacy, fairness to customers, know your customers and FATCA.

Manager
IT Advisory, Management Consulting
Business Transformation and Target Operating Models - Feasibility study for consolidating accounting transaction processes under one CoE, propose target operating models and conduct cost-benefit analysis for a life insurance player. - IT service catalog and service model redesign for offshore software development house in Guangzhou, with goals to lower development costs, respond swiftly to business needs, while reinforcing conformity and reuseability in IT architecture. - Offshore software development strategy repositioning and target operating models for a major investment bank, with stakeholders in Hong Kong, APAC and Switzerland. - Feasibility study for offshore software development house in China for an optical instrument manufacturer. Scorecard on criteria such as human capital, infrastructure, real estate prices, business environment, quality of life and accessibility. Project Management - Gap analysis for implementation of SAP Financial Asset Management module, for investment administration and accounting functions across APAC locations of a European insurer. - Pre-implementation review for infrastructure upgrade of automated matching system and related satellite systems for Hong Kong Exchanges and Clearing Ltd. All ITIL IT Services are covered, including Service Design, Service Transition and Service Operations. Managing Information Security and Application Audits - Systems assessments to meet eBanking regulations, Deposit Protection Scheme Ordinance, JSOX and other regulatory requirements from local regulators (SFC, HKMA). - Information security assessment for major gaming industry player in Macau. Review areas include regulatory compliance, information leakage, infrastructure review and penetration testing. Managed 5 workstreams involving 20+ client stakeholders from business and IT departments. Clients: AIA, Zurich, UBS, Bank of East Asia, Wing Hang Bank, Hong Kong Exchanges and Clearing Ltd., Galaxy Hotel Management Group

Senior Consultant, Strategy and Operations
- IT risk analysis, action plan prioritization and IT governance consulting. Align IT services against business priorities, and device improvement roadmap with short/mid/long term improvement goals. - Coordinate vendor selection process for policy administration system, from requirement collection, RFP, evaluation matrices, demonstrations, business case to vendor selection and contracting. - Streamline post-merger financial closing and reporting procedures in a P&C insurance firm, successfully shortening financial closing from 15 workdays to 7 workdays. - Identify and prioritize improvement opportunities on core insurance processes such as channel management, product development and claims handling, using Six Sigma methodology. - Clients: AIG, MSIG Mingtai

Senior Consultant, International Client Services
Tokyo, Japan
- US-SOX, ISO17799, COBIT compliance in insurance firms. - Manage changes, new process rollout and core system implementation from headquarters in Japan to local entities, with special attention to cross-culture communication issues. - Devise project management communication cycles, reporting templates and performance matrices for large scale core system implementation. - Clients: ING Life Japan, ING Antai (Taiwan), Mitsubishi FUSO, MSIG

Co-op intern, Regulatory IT
- Development and worldwide rollout of an online collateral disclosure portal for satisfying FAS140 disclosure requirements. - Migration of legacy programs from UNIX to Solaris. - Duties include functional specification design, development, and testing. - Investigation on legacy program dependencies and reporting to Project Manager.
Johnny Fong's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.


