COBIT 2019 Control Assessment for IT Auditors Training Course

5 days Auditing Certificate on completion
Course codeSD-A-068
Duration5 days
LevelIntermediate
CategoryAuditing
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

IT auditors are increasingly asked to assess whether technology controls support reliable financial reporting, protect regulated data, and provide evidence that stands up to internal audit committees, external auditors, and regulators. Yet many audit teams still rely on generic checklists that do not clearly link observations to governance objectives, control purposes, ownership, or business risk. This course equips auditors to use COBIT 2019 as a structured assessment method, producing findings that are traceable, risk-based, and actionable rather than simply lists of control gaps.

Participants learn how to interpret COBIT 2019 governance and management objectives, select relevant components of a governance system, and translate objectives into auditable control criteria. The programme covers scoping an IT control assessment, mapping risks to COBIT objectives, testing control design and operating effectiveness, evaluating capability levels, documenting evidence, and rating findings. Participants practise applying objectives such as EDM03 Ensured Risk Optimization, APO12 Managed Risk, BAI06 Managed IT Changes, DSS05 Managed Security Services, and MEA02 Monitored System of Internal Control.

Delivery combines instructor-led explanation with audit-file workshops, control-mapping exercises, evidence review, and a multi-stage case study. Working from a realistic finance-system scenario, participants build an assessment plan, risk-and-control matrix, evidence request list, testing workbook, capability assessment, and management-ready report. Each participant leaves with a reusable COBIT 2019 control assessment pack that can be adapted for audits of ERP change management, access controls, cybersecurity governance, outsourced IT services, or financial-reporting systems.

The course is designed for intermediate auditors and assurance professionals who already understand the basics of audit planning, controls, and evidence, and now need a repeatable COBIT 2019 method for evaluating IT governance and controls.

Course objectives

By the end of this course, participants will be able to:

  • Map business and technology risks to relevant COBIT 2019 governance and management objectives
  • Define audit scope, criteria, control owners, and evidence requirements using a COBIT-based assessment plan
  • Construct a risk-and-control matrix linking COBIT objectives, practices, activities, and control tests
  • Test control design and operating effectiveness through walkthroughs, inspection, inquiry, and reperformance
  • Evaluate governance-system components and capability levels using COBIT 2019 assessment criteria
  • Document audit evidence, exceptions, root causes, and compensating controls in a structured testing workbook
  • Rate and prioritize control findings using risk impact, likelihood, control maturity, and remediation feasibility
  • Produce a management-ready COBIT 2019 control assessment report and corrective-action tracker

Benefits of attending

For you

  • Build a reusable COBIT 2019 assessment approach for IT audit assignments
  • Strengthen the quality of audit findings with explicit links to governance objectives and risk
  • Demonstrate capability in evaluating both control design and operating effectiveness
  • Produce clearer audit workpapers, evidence requests, and remediation recommendations
  • Increase credibility for IT audit, IT risk, SOX, and technology assurance roles

For your organisation

  • Create more consistent IT control assessments across audit teams and business units
  • Improve traceability from technology risks to COBIT objectives, tests, findings, and management actions
  • Identify governance and control weaknesses before they affect financial reporting or regulatory compliance
  • Reduce rework by standardising evidence requests, testing documentation, and finding ratings
  • Provide audit committees and control owners with prioritised remediation plans rather than isolated observations

Target competencies

COBIT objective mappingControl design testingEvidence evaluationCapability assessmentFinding risk ratingAudit report writing

Who should attend

  • IT Auditors — who need a defensible method for assessing technology controls against recognised governance objectives
  • Internal Auditors — who audit systems supporting financial reporting, operational processes, and regulated data
  • IT Risk Managers — who need to translate technology risk exposure into assessable control requirements
  • Information Security Auditors — who evaluate security governance, access management, monitoring, and incident controls
  • SOX and Financial Controls Specialists — who need to connect IT general controls with financial-reporting assurance
  • IT Governance and Compliance Managers — who coordinate control evidence, remediation, and assurance reporting

Requirements and prerequisites

Participants should have practical familiarity with the audit lifecycle: planning, risk assessment, control objectives, evidence collection, testing, findings, and follow-up. Experience reviewing IT general controls, such as user access, change management, backup, incident management, or vendor controls, is strongly recommended. Participants should also be able to work confidently with spreadsheets and read process narratives, policies, system reports, and audit workpapers. Prior COBIT 2019 training or certification is not required; the course introduces the framework elements needed for assessment work. Programming, penetration-testing skills, and specialist ERP configuration knowledge are not required.

Training methodology

The five-day programme uses short instructor-led COBIT 2019 briefings followed by structured audit workshops. Participants work through a finance-system case involving privileged access, application changes, interfaces, incident handling, and control monitoring. They map risks to objectives, review sample evidence, conduct simulated walkthroughs, complete testing sheets, and debate finding ratings in audit teams. The instructor provides worked examples and feedback on workpaper quality. On the final day, each participant adapts the assessment pack into a practical application plan for an upcoming or current audit.

Course outline

Day 1: COBIT 2019 foundations for audit assessment

  • COBIT 2019 principles and governance-system architecture
  • Governance objectives versus management objectives
  • COBIT components: processes, structures, policies, information, culture, people, and services
  • Purpose statements and objective design factors
  • Mapping enterprise goals to alignment goals and objectives
  • COBIT performance management and capability concepts
  • Positioning COBIT 2019 within risk-based IT audit planning

Workshop: Participants map a finance-system audit mandate to enterprise goals, alignment goals, and a prioritised set of COBIT 2019 objectives.

Day 2: Scoping and designing the control assessment

  • Defining auditable entities, systems, processes, and control boundaries
  • Risk scenario development for financial-reporting technology
  • Selecting objectives using the COBIT 2019 Design Toolkit
  • Translating COBIT practices into audit criteria
  • Building a COBIT-based risk-and-control matrix
  • Assigning control ownership and identifying assurance sources
  • Preparing evidence request lists and walkthrough agendas

Workshop: Participants create a scoped assessment plan, risk-and-control matrix, and evidence request list for an ERP change and access-management review.

Day 3: Testing COBIT-aligned controls

  • Control design effectiveness versus operating effectiveness
  • Walkthrough techniques for IT-enabled business processes
  • Inspection of policies, configurations, logs, tickets, and approvals
  • Inquiry, observation, reperformance, and sample selection methods
  • Testing BAI06 Managed IT Changes controls
  • Testing DSS05 Managed Security Services controls
  • Documenting test steps, populations, samples, exceptions, and conclusions

Workshop: Participants test a set of access-review and emergency-change evidence samples and complete a documented audit testing workbook.

Day 4: Capability evaluation and finding development

  • Assessing governance-system component adequacy
  • Applying COBIT capability and performance criteria
  • Evaluating EDM03 Ensured Risk Optimization
  • Evaluating APO12 Managed Risk and risk treatment
  • Identifying root causes and control dependency failures
  • Assessing compensating controls and residual risk
  • Writing condition, criteria, cause, consequence, and recommendation statements

Workshop: Participants evaluate a case organisation's control capability, identify root causes for three exceptions, and draft risk-rated findings.

Day 5: Reporting, remediation, and audit application

  • Finding rating models for impact, likelihood, and urgency
  • Linking findings to COBIT objectives and business consequences
  • Developing practical corrective-action recommendations
  • Establishing remediation owners, milestones, and validation evidence
  • Designing dashboards for control status and audit follow-up
  • Presenting COBIT-based conclusions to management and audit committees
  • Creating a personal COBIT 2019 audit application plan

Workshop: Participants assemble and present a management-ready COBIT 2019 control assessment report, corrective-action tracker, and application plan.

Tools & standards covered

COBIT 2019 Framework: Governance and Management Objectives, COBIT 2019 Design Toolkit, COSO Internal Control—Integrated Framework, Microsoft Excel

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No. The course explains the COBIT 2019 concepts, governance objectives, design factors, and performance concepts needed for control assessment. You will benefit most if you already understand audit evidence, control testing, and common IT general controls.

Bring a laptop with Microsoft Excel or equivalent spreadsheet software so you can complete the risk-and-control matrix, testing workbook, and action tracker. Course case materials and COBIT-based templates are supplied during the programme.

It is intended for IT auditors, internal auditors, IT risk professionals, security auditors, and SOX specialists with some control-assurance experience. It is not a technical configuration course for system administrators or a general introduction to cybersecurity.

A foundation course focuses on framework terminology, principles, and the structure of COBIT 2019. This course uses those elements to perform audit work: scoping reviews, selecting objectives, testing evidence, assessing capability, rating findings, and reporting remediation.

The assessment pack can be adapted to audits of access management, change management, outsourced services, security operations, incident response, and ERP controls. Participants leave with a practical sequence from audit scope through testing, reporting, and remediation follow-up.

You will leave with a COBIT 2019 assessment plan, risk-and-control matrix, evidence request list, audit testing workbook, capability assessment, finding templates, and corrective-action tracker. These are populated through the case study and can be tailored to your organisation's audit methodology.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Auditing

5 Days Certificate

Arbutus Analyzer Audit Data Testing Techniques Training Course

Audit teams often hold complete populations of transactions but test only small samples because extracting, joining, profiling and documenti…

5 Days Certificate

Oil and Gas Revenue Auditing Training Course

Oil and gas revenue errors rarely arise from one ledger entry alone. They emerge where production volumes, custody-transfer measurements, sa…

5 Days Certificate

Public Sector Internal Auditing Training Course

Public-sector organisations must demonstrate that public money, assets, programmes and services are managed lawfully, economically and trans…

5 Days Certificate

Construction Project Cost Auditing Training Course

Construction projects generate large volumes of cost data across contracts, change orders, progress claims, purchase orders, timesheets, pla…