COBIT 2019 ERP Governance and Controls Training Course
| Course code | SD-ES-026 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | ERP Systems |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
ERP platforms concentrate high-value financial, customer, supply-chain and workforce data in a small number of business-critical processes. When governance is weak, common failures include incompatible segregation-of-duties roles, uncontrolled configuration changes, incomplete interface monitoring, weak master-data ownership and control evidence that cannot satisfy auditors. This course helps participants translate COBIT 2019 into practical governance and control decisions for ERP environments, whether operating SAP, Oracle Fusion Cloud, Microsoft Dynamics 365 or a comparable platform.
Participants learn to use COBIT 2019 governance and management objectives, design factors and goals cascade to define an ERP governance system proportionate to enterprise priorities and risk appetite. The course connects objectives such as EDM03 Ensured Risk Optimization, APO12 Managed Risk, APO13 Managed Security, BAI06 Managed IT Changes, DSS05 Managed Security Services and MEA02 Managed System of Internal Control to ERP access, change, interface, data and operational controls. Participants practise defining control objectives, assigning RACI accountability, assessing control design and selecting meaningful performance indicators.
Instructor-led sessions combine COBIT 2019 interpretation with an ERP governance case study, control workshops and facilitated peer review. Participants work from an ERP risk scenario to build a governance design, control matrix, evidence plan and improvement roadmap. They leave with a practical ERP Governance and Controls Pack containing a goals cascade, priority COBIT objectives, role-accountability model, risk-and-control register, sample KRIs/KPIs and a 90-day implementation plan that can be adapted to their organisation.
The course is suited to professionals who bridge ERP operations, internal control, IT risk, audit, security and business process ownership. It starts at foundation level but develops intermediate capability in applying COBIT 2019 to real control decisions rather than simply recalling framework terminology.
Course objectives
By the end of this course, participants will be able to:
- Apply the COBIT 2019 goals cascade to connect enterprise priorities with ERP governance objectives
- Use COBIT 2019 design factors to scope a proportionate ERP governance system
- Map ERP access, change, interface and master-data risks to relevant COBIT governance and management objectives
- Develop an ERP risk-and-control matrix with control owners, frequencies, evidence and test procedures
- Design segregation-of-duties control requirements using role, privilege and compensating-control analysis
- Assign ERP governance accountability through a RACI model for process owners, IT, security, risk and audit
- Define ERP control KPIs, KRIs and capability measures for management reporting
- Produce a prioritised 90-day COBIT 2019 ERP governance improvement roadmap
Benefits of attending
For you
- Build the ability to justify ERP control priorities using COBIT 2019 design factors rather than generic checklists
- Gain a reusable method for linking ERP risks to accountable control owners and retained evidence
- Strengthen credibility in audit, risk and steering-committee discussions about ERP control investment
- Learn to assess segregation-of-duties and change-control issues beyond a purely technical or business-process view
- Leave with an ERP Governance and Controls Pack that can support a workplace improvement proposal
For your organisation
- Creates a consistent COBIT 2019 basis for governing ERP access, changes, interfaces and data controls
- Reduces exposure to fraud and processing errors through clearer segregation-of-duties and compensating-control design
- Improves audit readiness by defining control evidence, ownership, testing expectations and remediation records
- Enables management to prioritise ERP control improvements using documented risks, design factors and performance measures
- Clarifies accountability between business process owners, ERP teams, security, risk and internal audit
Target competencies
Who should attend
- ERP Managers — who must govern configuration, access, releases and operational performance across the platform
- IT Risk Managers — who need to translate enterprise risk requirements into measurable ERP control activities
- Internal Auditors — who assess ERP controls and need a structured COBIT 2019 basis for audit planning
- ERP Process Owners — who are accountable for finance, procurement, inventory or HR process controls
- Information Security Managers — who oversee privileged access, identity controls and security monitoring in ERP systems
- GRC and Compliance Analysts — who maintain control registers, evidence requirements and remediation tracking
Requirements and prerequisites
Participants should understand the purpose of an ERP system and recognise common business processes such as procure-to-pay, order-to-cash, record-to-report or hire-to-retire. Familiarity with basic IT controls, user access, change management, audit evidence or risk registers is useful, but prior COBIT training is not required. Participants should be comfortable reading process maps, control descriptions and simple RACI charts. No programming, ERP configuration experience, formal audit qualification or access to SAP, Oracle or Dynamics is required. Complete beginners should expect to learn COBIT terminology alongside practical ERP control examples.
Training methodology
The course uses instructor-led COBIT 2019 briefings followed by ERP-specific application work each day. Participants analyse a realistic ERP scenario involving finance-process access, configuration releases, interfaces and master data; map issues to COBIT objectives; and make governance decisions in small groups. Workshops use sample role listings, change records, control evidence and audit findings to build a risk-and-control matrix. Facilitated reviews challenge the rationale for each control and measure. The final session converts the group analysis into an individual 90-day application plan for the participant’s own ERP environment.
Course outline
Day 1: COBIT 2019 foundations for ERP governance
- ERP governance challenges across finance, supply chain, HR and customer processes
- COBIT 2019 governance system principles and governance framework principles
- Governance objectives versus management objectives in COBIT 2019
- The COBIT core model and the EDM, APO, BAI, DSS and MEA domains
- ERP governance stakeholders, decision rights and accountability boundaries
- Governance components including processes, organisational structures and information flows
- ERP risk scenarios involving access, configuration, interfaces and master data
Workshop: Participants analyse an ERP failure scenario and produce an initial stakeholder map and list of governance concerns.
Day 2: Designing an ERP governance system
- Using the COBIT 2019 goals cascade from enterprise goals to alignment goals
- Mapping ERP business priorities to governance and management objectives
- Applying COBIT 2019 design factors to an ERP environment
- Enterprise strategy, risk profile and compliance requirements as design inputs
- Threat landscape, sourcing model and technology adoption strategy
- Selecting priority objectives including EDM03, APO12, APO13 and MEA02
- Setting target capability levels and governance system priorities
Workshop: Participants complete a COBIT design-factor assessment and produce a prioritised ERP governance objective profile.
Day 3: ERP risk and control design
- ERP risk assessment methods for business process, application and integration risks
- Segregation-of-duties analysis for roles, privileged access and emergency access
- Access governance controls aligned to DSS05 Managed Security Services
- Configuration and release controls aligned to BAI06 Managed IT Changes
- Interface, batch-job and exception-monitoring control design
- Master-data governance, approval workflows and data-quality controls
- Risk-and-control matrix fields for owner, frequency, evidence and test approach
Workshop: Participants build an ERP risk-and-control matrix for a procure-to-pay process, including access and change controls.
Day 4: Assurance, monitoring and control evidence
- MEA02 Managed System of Internal Control for ERP assurance
- Control evidence requirements for automated, manual and hybrid ERP controls
- Control design effectiveness versus operating effectiveness assessment
- ERP control testing procedures and sampling considerations
- KPI and KRI design for access, changes, interfaces and data quality
- Issue management, root-cause analysis and remediation tracking
- Management reporting dashboards and escalation thresholds
Workshop: Participants assess a set of ERP control evidence and produce a control test result, KRI set and remediation escalation note.
Day 5: Implementing and sustaining COBIT-based ERP controls
- COBIT 2019 implementation lifecycle applied to ERP governance improvements
- Prioritising control remediation by risk exposure, dependency and business impact
- ERP governance RACI models for business, IT, security, risk and audit
- Control-owner operating procedures and evidence-retention practices
- Integrating COBIT controls with SAP GRC, Oracle controls or equivalent ERP tooling
- Change adoption, governance forums and stakeholder communications
- Ninety-day roadmap milestones, resource assumptions and success measures
Workshop: Participants assemble and present an ERP Governance and Controls Pack with a RACI model, control roadmap and 90-day action plan.
Tools & standards covered
COBIT 2019 Framework: Governance and Management Objectives, COBIT 2019 Design Toolkit, SAP GRC Access Control, Microsoft Excel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in ERP Systems
ERP Change Management for Project Managers Training Course
ERP programmes fail to deliver value when technically sound deployments are treated as technology projects rather than changes to roles, con…
ERP Systems for Public Sector Financial Management Training Course
Public-sector finance teams must account for appropriations, commitments, grants, assets, payroll interfaces and statutory reporting while m…
ERP Audit and Compliance for Internal Auditors Training Course
Internal auditors are expected to assess ERP controls across financial close, procurement, inventory, payroll, user access and system change…
ERP Systems Fundamentals for Business Users Training Course
ERP initiatives often fail to deliver expected value because business users can complete transactions without understanding the upstream dat…