COBIT 2019 Control Assessment for IT Auditors Training Course
| Course code | SD-A-068 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Auditing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
IT auditors are increasingly asked to assess whether technology controls support reliable financial reporting, protect regulated data, and provide evidence that stands up to internal audit committees, external auditors, and regulators. Yet many audit teams still rely on generic checklists that do not clearly link observations to governance objectives, control purposes, ownership, or business risk. This course equips auditors to use COBIT 2019 as a structured assessment method, producing findings that are traceable, risk-based, and actionable rather than simply lists of control gaps.
Participants learn how to interpret COBIT 2019 governance and management objectives, select relevant components of a governance system, and translate objectives into auditable control criteria. The programme covers scoping an IT control assessment, mapping risks to COBIT objectives, testing control design and operating effectiveness, evaluating capability levels, documenting evidence, and rating findings. Participants practise applying objectives such as EDM03 Ensured Risk Optimization, APO12 Managed Risk, BAI06 Managed IT Changes, DSS05 Managed Security Services, and MEA02 Monitored System of Internal Control.
Delivery combines instructor-led explanation with audit-file workshops, control-mapping exercises, evidence review, and a multi-stage case study. Working from a realistic finance-system scenario, participants build an assessment plan, risk-and-control matrix, evidence request list, testing workbook, capability assessment, and management-ready report. Each participant leaves with a reusable COBIT 2019 control assessment pack that can be adapted for audits of ERP change management, access controls, cybersecurity governance, outsourced IT services, or financial-reporting systems.
The course is designed for intermediate auditors and assurance professionals who already understand the basics of audit planning, controls, and evidence, and now need a repeatable COBIT 2019 method for evaluating IT governance and controls.
Course objectives
By the end of this course, participants will be able to:
- Map business and technology risks to relevant COBIT 2019 governance and management objectives
- Define audit scope, criteria, control owners, and evidence requirements using a COBIT-based assessment plan
- Construct a risk-and-control matrix linking COBIT objectives, practices, activities, and control tests
- Test control design and operating effectiveness through walkthroughs, inspection, inquiry, and reperformance
- Evaluate governance-system components and capability levels using COBIT 2019 assessment criteria
- Document audit evidence, exceptions, root causes, and compensating controls in a structured testing workbook
- Rate and prioritize control findings using risk impact, likelihood, control maturity, and remediation feasibility
- Produce a management-ready COBIT 2019 control assessment report and corrective-action tracker
Benefits of attending
For you
- Build a reusable COBIT 2019 assessment approach for IT audit assignments
- Strengthen the quality of audit findings with explicit links to governance objectives and risk
- Demonstrate capability in evaluating both control design and operating effectiveness
- Produce clearer audit workpapers, evidence requests, and remediation recommendations
- Increase credibility for IT audit, IT risk, SOX, and technology assurance roles
For your organisation
- Create more consistent IT control assessments across audit teams and business units
- Improve traceability from technology risks to COBIT objectives, tests, findings, and management actions
- Identify governance and control weaknesses before they affect financial reporting or regulatory compliance
- Reduce rework by standardising evidence requests, testing documentation, and finding ratings
- Provide audit committees and control owners with prioritised remediation plans rather than isolated observations
Target competencies
Who should attend
- IT Auditors — who need a defensible method for assessing technology controls against recognised governance objectives
- Internal Auditors — who audit systems supporting financial reporting, operational processes, and regulated data
- IT Risk Managers — who need to translate technology risk exposure into assessable control requirements
- Information Security Auditors — who evaluate security governance, access management, monitoring, and incident controls
- SOX and Financial Controls Specialists — who need to connect IT general controls with financial-reporting assurance
- IT Governance and Compliance Managers — who coordinate control evidence, remediation, and assurance reporting
Requirements and prerequisites
Participants should have practical familiarity with the audit lifecycle: planning, risk assessment, control objectives, evidence collection, testing, findings, and follow-up. Experience reviewing IT general controls, such as user access, change management, backup, incident management, or vendor controls, is strongly recommended. Participants should also be able to work confidently with spreadsheets and read process narratives, policies, system reports, and audit workpapers. Prior COBIT 2019 training or certification is not required; the course introduces the framework elements needed for assessment work. Programming, penetration-testing skills, and specialist ERP configuration knowledge are not required.
Training methodology
The five-day programme uses short instructor-led COBIT 2019 briefings followed by structured audit workshops. Participants work through a finance-system case involving privileged access, application changes, interfaces, incident handling, and control monitoring. They map risks to objectives, review sample evidence, conduct simulated walkthroughs, complete testing sheets, and debate finding ratings in audit teams. The instructor provides worked examples and feedback on workpaper quality. On the final day, each participant adapts the assessment pack into a practical application plan for an upcoming or current audit.
Course outline
Day 1: COBIT 2019 foundations for audit assessment
- COBIT 2019 principles and governance-system architecture
- Governance objectives versus management objectives
- COBIT components: processes, structures, policies, information, culture, people, and services
- Purpose statements and objective design factors
- Mapping enterprise goals to alignment goals and objectives
- COBIT performance management and capability concepts
- Positioning COBIT 2019 within risk-based IT audit planning
Workshop: Participants map a finance-system audit mandate to enterprise goals, alignment goals, and a prioritised set of COBIT 2019 objectives.
Day 2: Scoping and designing the control assessment
- Defining auditable entities, systems, processes, and control boundaries
- Risk scenario development for financial-reporting technology
- Selecting objectives using the COBIT 2019 Design Toolkit
- Translating COBIT practices into audit criteria
- Building a COBIT-based risk-and-control matrix
- Assigning control ownership and identifying assurance sources
- Preparing evidence request lists and walkthrough agendas
Workshop: Participants create a scoped assessment plan, risk-and-control matrix, and evidence request list for an ERP change and access-management review.
Day 3: Testing COBIT-aligned controls
- Control design effectiveness versus operating effectiveness
- Walkthrough techniques for IT-enabled business processes
- Inspection of policies, configurations, logs, tickets, and approvals
- Inquiry, observation, reperformance, and sample selection methods
- Testing BAI06 Managed IT Changes controls
- Testing DSS05 Managed Security Services controls
- Documenting test steps, populations, samples, exceptions, and conclusions
Workshop: Participants test a set of access-review and emergency-change evidence samples and complete a documented audit testing workbook.
Day 4: Capability evaluation and finding development
- Assessing governance-system component adequacy
- Applying COBIT capability and performance criteria
- Evaluating EDM03 Ensured Risk Optimization
- Evaluating APO12 Managed Risk and risk treatment
- Identifying root causes and control dependency failures
- Assessing compensating controls and residual risk
- Writing condition, criteria, cause, consequence, and recommendation statements
Workshop: Participants evaluate a case organisation's control capability, identify root causes for three exceptions, and draft risk-rated findings.
Day 5: Reporting, remediation, and audit application
- Finding rating models for impact, likelihood, and urgency
- Linking findings to COBIT objectives and business consequences
- Developing practical corrective-action recommendations
- Establishing remediation owners, milestones, and validation evidence
- Designing dashboards for control status and audit follow-up
- Presenting COBIT-based conclusions to management and audit committees
- Creating a personal COBIT 2019 audit application plan
Workshop: Participants assemble and present a management-ready COBIT 2019 control assessment report, corrective-action tracker, and application plan.
Tools & standards covered
COBIT 2019 Framework: Governance and Management Objectives, COBIT 2019 Design Toolkit, COSO Internal Control—Integrated Framework, Microsoft Excel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Auditing
Arbutus Analyzer Audit Data Testing Techniques Training Course
Audit teams often hold complete populations of transactions but test only small samples because extracting, joining, profiling and documenti…
Oil and Gas Revenue Auditing Training Course
Oil and gas revenue errors rarely arise from one ledger entry alone. They emerge where production volumes, custody-transfer measurements, sa…
Public Sector Internal Auditing Training Course
Public-sector organisations must demonstrate that public money, assets, programmes and services are managed lawfully, economically and trans…
Construction Project Cost Auditing Training Course
Construction projects generate large volumes of cost data across contracts, change orders, progress claims, purchase orders, timesheets, pla…