AuditBoard SOX Compliance and Audit Workflow Training Course

5 days Auditing Certificate on completion
Course codeSD-A-054
Duration5 days
LevelIntermediate to Advanced
CategoryAuditing
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

SOX teams need more than a control inventory and annual testing calendar. They must coordinate control owners, testers, reviewers, external auditors, and remediation owners while preserving a defensible evidence trail. When requests, narratives, testing workpapers, certifications, and issues are managed in email or disconnected spreadsheets, teams lose visibility over overdue work, duplicate evidence requests, changing control populations, and unresolved deficiencies. This course addresses the practical challenge of running a controlled, auditable SOX programme in AuditBoard.

Participants learn how to configure and operate AuditBoard SOXHUB workflows for a risk-based SOX compliance cycle. The course covers process and control documentation, risk-control matrices, scoping, entity and account mapping, walkthrough support, test plans, sample selection, evidence requests, review workflows, issue management, remediation tracking, and management reporting. Participants also learn to apply COSO principles and PCAOB-informed documentation expectations when designing controls and evaluating evidence.

Instruction combines live platform demonstrations with structured hands-on work in an AuditBoard training environment. Participants build and test a sample SOX programme based on a realistic financial-close process, assign owners and reviewers, route evidence requests, document testing conclusions, raise deficiencies, and produce status reporting. Each participant leaves with a reusable SOX workflow blueprint containing a control-testing plan, evidence-request design, issue workflow, reporting structure, and implementation actions for their own organisation.

The course is designed for experienced internal audit, SOX, controllership, and risk professionals who already understand the purpose of internal controls and now need to administer, improve, or scale the work in AuditBoard.

Course objectives

By the end of this course, participants will be able to:

  • Configure an AuditBoard SOXHUB project structure for processes, entities, accounts, risks, controls, and testing periods
  • Build a risk-control matrix that links financial-statement assertions, COSO principles, key risks, and control activities
  • Create control narratives and walkthrough documentation with owners, evidence sources, frequency, and review points
  • Design risk-based test plans with test attributes, populations, sampling criteria, evidence requirements, and reviewer sign-offs
  • Route evidence requests and certifications through AuditBoard workflows while maintaining a complete audit trail
  • Evaluate control-test exceptions and document deficiency conclusions using severity, likelihood, compensating-control, and remediation analysis
  • Manage remediation plans, issue owners, due dates, validation testing, and escalation status within AuditBoard
  • Produce SOX status dashboards and management reports showing testing progress, overdue evidence, exceptions, and unresolved issues

Benefits of attending

For you

  • Build credible hands-on experience operating AuditBoard SOXHUB workflows rather than only understanding SOX theory
  • Improve your ability to translate control narratives and risk assessments into structured, testable AuditBoard records
  • Strengthen your judgement when documenting exceptions, deficiencies, compensating controls, and remediation evidence
  • Create repeatable evidence-request and review processes that reduce time spent chasing control owners
  • Gain a practical SOX workflow blueprint you can use to lead an AuditBoard rollout, optimisation, or annual-cycle refresh

For your organisation

  • Establish more consistent control documentation, testing methods, review evidence, and issue records across SOX processes
  • Reduce missed deadlines and manual follow-up through assigned owners, automated workflow stages, and status visibility
  • Improve audit readiness by maintaining traceable links between risks, controls, test procedures, evidence, conclusions, and remediation
  • Provide controllers and audit leaders with clearer reporting on testing completion, exceptions, overdue requests, and open deficiencies
  • Reduce duplicate evidence collection and spreadsheet rework by organising requests and workpapers in a controlled AuditBoard environment

Target competencies

SOX workflow configurationRisk-control mappingControl test designEvidence request managementDeficiency evaluationRemediation status reporting

Who should attend

  • SOX Managers and Directors — who need to standardise control testing, certification, review, and reporting across the compliance cycle
  • Internal Audit Managers — who oversee assurance work and require traceable workpapers, issue workflows, and audit-ready evidence
  • SOX Analysts and Compliance Specialists — who administer control inventories, testing schedules, evidence requests, and remediation tracking
  • Financial Controllers — who coordinate process owners and need reliable visibility of financial-reporting control performance
  • Risk and Controls Managers — who map risks to controls and maintain consistent control documentation across business processes
  • External Audit Liaison Leads — who prepare organised support, testing evidence, and issue-status information for external auditors

Requirements and prerequisites

Participants should have working knowledge of SOX compliance, internal-control concepts, and the annual controls-testing cycle. They should understand terms such as process narrative, risk-control matrix, key control, control owner, walkthrough, population, sample, exception, deficiency, and remediation. Experience using spreadsheets to manage SOX testing or prior exposure to an audit-management platform is helpful. Participants should be comfortable navigating web-based business software and reviewing control evidence. Prior AuditBoard administration experience, coding skills, data analytics expertise, or external-audit credentials are not required; the course teaches the relevant AuditBoard configuration and workflow practices.

Training methodology

The course is delivered through instructor-led demonstrations, guided configuration exercises, and a five-day SOX case study built around a financial-close process. Participants work in an AuditBoard training environment to create controls, assign workflow roles, issue evidence requests, perform test steps, review workpapers, and track deficiencies. Short group reviews compare documentation and deficiency decisions against COSO and audit-evidence expectations. Each day closes with a practical output that is added to an end-of-course AuditBoard SOX workflow blueprint and implementation plan.

Course outline

Day 1: SOX programme structure and AuditBoard foundations

  • SOX lifecycle roles, deliverables, and annual compliance calendar
  • AuditBoard SOXHUB navigation, project hierarchy, permissions, and role assignments
  • Process, sub-process, entity, account, and location scoping structures
  • COSO Internal Control—Integrated Framework principles for financial-reporting controls
  • Financial-statement assertions and their use in risk assessment
  • Risk-control matrix design and key-control identification
  • Control metadata, ownership, frequency, evidence, and dependency fields

Workshop: Participants configure a sample financial-close SOX project and produce a risk-control matrix linking assertions, risks, controls, owners, and evidence sources.

Day 2: Control documentation, walkthroughs, and testing design

  • Process narratives and flowchart requirements for SOX documentation
  • Control objective, risk statement, and control-activity writing standards
  • Walkthrough planning and documentation of design and implementation evidence
  • Control rationalisation and duplicate-control analysis
  • Test attributes for manual, automated, and IT-dependent controls
  • Population definition, completeness validation, and sample-selection methods
  • AuditBoard test plans, workpaper templates, and reviewer sign-off workflows

Workshop: Participants document a walkthrough and build a test plan for a journal-entry review control, including procedures, population criteria, samples, and evidence requirements.

Day 3: Evidence collection and control testing workflow

  • Evidence-request creation, ownership, due dates, and reminder workflows
  • Evidence quality criteria for precision, completeness, retention, and reviewer attribution
  • Testing operating effectiveness in AuditBoard workpapers
  • Manual-control testing and reperformance documentation
  • Automated-control and report-dependency evidence considerations
  • Reviewer notes, coaching points, clearance, and workpaper version control
  • Testing-status monitoring and overdue-evidence escalation

Workshop: Participants issue and manage evidence requests, test selected samples in AuditBoard workpapers, and produce a reviewed testing file with documented conclusions.

Day 4: Exceptions, deficiencies, and remediation management

  • Distinguishing test exceptions, control failures, deficiencies, significant deficiencies, and material weaknesses
  • Root-cause analysis using people, process, system, data, and governance categories
  • Likelihood and magnitude considerations in deficiency evaluation
  • Compensating-control assessment and residual-risk documentation
  • Issue creation, severity classification, ownership, target dates, and action plans
  • Remediation-evidence requirements and validation-testing workflows
  • Escalation paths for overdue, repeated, and high-severity issues

Workshop: Participants assess a set of testing exceptions, create deficiency records, assign remediation actions, and produce a validation-testing plan for the highest-risk issue.

Day 5: Reporting, governance, and deployment planning

  • SOX testing-progress dashboards and milestone reporting
  • Management reporting for overdue evidence, exceptions, deficiencies, and remediation status
  • External-auditor support packages and controlled evidence sharing
  • AuditBoard CrossComply considerations for broader regulatory control coordination
  • User-access governance, role segregation, and workflow approval controls
  • Annual rollover, control-change management, and archive practices
  • AuditBoard implementation roadmap, adoption measures, and operating procedures

Workshop: Participants build a management status report and complete an implementation roadmap for applying their AuditBoard SOX workflow blueprint in their own organisation.

Tools & standards covered

AuditBoard SOXHUB, AuditBoard CrossComply, Microsoft Excel, COSO Internal Control—Integrated Framework

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No previous AuditBoard experience is required. You should, however, understand basic SOX and internal-control terminology, including controls, testing, evidence, exceptions, and remediation.

Bring a laptop for the live online or classroom exercises. Training uses a guided AuditBoard environment and case materials, so access to your organisation's production instance is not required.

It is most directly designed for in-house SOX, internal audit, controllership, and risk professionals who operate or govern AuditBoard workflows. External-audit liaison staff and external auditors who need to understand client-produced AuditBoard support will also benefit.

A general SOX course focuses primarily on regulation, control concepts, and testing principles. This course applies those principles inside AuditBoard through configuration, evidence workflow, workpapers, issue management, dashboards, and implementation planning.

You can use the workflow blueprint to review your control inventory, standardise test templates, define evidence-request rules, and improve issue escalation before planning begins. The methods also support in-cycle improvements to overdue evidence and remediation tracking.

Participants leave with a completed sample risk-control matrix, test-plan structure, evidence-request design, deficiency and remediation workflow, management-reporting model, and implementation action plan. These deliverables can be adapted to the participant's own processes and AuditBoard configuration.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Auditing

5 Days Certificate

International Standards on Auditing ISA Application Training Course

Audit teams are expected to demonstrate not only that they reached an appropriate opinion, but also that their work was planned, performed, …

5 Days Certificate

Advanced Forensic Audit Investigation and Interviewing Training Course

Suspected fraud, financial misconduct, and control override require more than routine audit testing. Investigators must turn an allegation, …

5 Days Certificate

ISO 19011 Management System Auditing Training Course

Finance and accounting teams depend on controlled processes for close, reconciliations, expense approvals, revenue recognition, master-data …

5 Days Certificate

ISACA ITAF Audit Framework Application Training Course

Technology audit teams are expected to produce work that is defensible to audit committees, regulators, external auditors and senior managem…