COSO Internal Control Assessment Training Course
| Course code | SD-A-041 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Auditing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Finance, audit, compliance and control professionals are often asked to assess whether internal controls are designed effectively and operating as intended, yet findings can be inconsistent when teams rely on checklists without a common framework. This creates avoidable exposure: controls may not address the right risks, evidence may be insufficient to support conclusions, and management may receive reports that identify symptoms rather than root causes. This course provides a disciplined method for planning, performing and reporting internal control assessments using the COSO Internal Control—Integrated Framework.
Participants work through the five COSO components and 17 principles, translating them into practical assessment criteria for governance, risk assessment, control activities, information and communication, and monitoring. They learn how to define an auditable control objective, map risks to controls, distinguish design effectiveness from operating effectiveness, select samples, evaluate evidence, rate deficiencies, and formulate remediation recommendations. The course also addresses entity-level controls, process-level controls, management assertions, control documentation and the relationship between COSO assessments, internal audit plans and external audit requirements.
Instruction combines facilitator-led analysis with a multi-day case involving a finance and procurement process. Participants build a COSO-aligned risk and control matrix, develop test procedures, assess control evidence, document findings and present a management-ready conclusion. Each participant leaves with a completed internal control assessment pack: a scoping document, risk and control matrix, testing workpaper, deficiency evaluation and corrective-action tracker that can be adapted for use in their organisation.
The course is designed for professionals who already work with financial processes, risk, compliance, assurance or audit documentation and need a repeatable framework for evaluating internal control systems.
Course objectives
By the end of this course, participants will be able to:
- Apply the COSO Internal Control—Integrated Framework and its 17 principles to an internal control assessment
- Define control objectives, risks and management assertions for a selected business process
- Construct a risk and control matrix linking process risks, key controls, owners, evidence and COSO principles
- Evaluate control design effectiveness using walkthroughs, flowcharts and control-attribute criteria
- Test operating effectiveness through sample selection, evidence inspection, reperformance and inquiry
- Classify control deficiencies by severity, root cause, likelihood, impact and compensating controls
- Prepare audit-ready workpapers that document scope, testing procedures, evidence, conclusions and reviewer sign-off
- Present a COSO-based assessment report with prioritised remediation actions and accountable action owners
Benefits of attending
For you
- Gain a defensible method for concluding on control design and operating effectiveness
- Produce clearer audit workpapers and control-testing documentation for reviewer scrutiny
- Build confidence applying the 17 COSO principles beyond a compliance checklist
- Strengthen readiness for internal audit, controls assurance, financial control and risk roles
- Learn to turn control failures into prioritised, practical remediation recommendations
For your organisation
- Establish a common COSO-based vocabulary for control owners, risk teams and assurance functions
- Improve consistency in risk and control matrices, walkthroughs, testing workpapers and findings reports
- Identify weak or undocumented controls before they become financial, compliance or operational incidents
- Focus remediation funding on deficiencies with the greatest risk exposure and weakest compensating controls
- Create reusable assessment templates that support audit planning, management assurance and external audit coordination
Target competencies
Who should attend
- Internal Auditors — who need a consistent framework for assessing and reporting control effectiveness
- Financial Controllers — who oversee financial reporting controls and must evidence their reliability
- Risk Managers — who connect enterprise and process risks to control responses and assurance activities
- Compliance Managers — who evaluate whether operational controls meet policy and regulatory expectations
- External Audit Seniors — who assess controls and coordinate evidence requests with client management
- Process Owners — who are accountable for key controls and corrective actions within finance or operational processes
Requirements and prerequisites
Participants should have working familiarity with business-process documentation, basic risk concepts and the purpose of internal controls. Experience in finance, accounting, compliance, internal audit, external audit or operational risk is expected, including the ability to read procedures, invoices, reconciliations, approvals or similar control evidence. Participants should be comfortable using spreadsheets for simple tables and filters; Microsoft Excel is used in exercises. Prior knowledge of the COSO framework, statistical sampling, audit software, SOX compliance or Power BI is not required. This is an intermediate course because it assumes participants can relate controls to real business processes.
Training methodology
The instructor uses short COSO framework briefings followed by structured application to a finance and procurement case. Participants conduct a process walkthrough, identify risks and key controls, map controls to COSO principles and build testing procedures in an Excel-based workpaper. Small groups inspect simulated evidence, challenge control-design assumptions, rate deficiencies and compare conclusions against a facilitator model answer. Daily review sessions connect the case to participants’ own control environments. On the final day, each participant prepares an application plan for one assessment or control review they will undertake after the course.
Course outline
Day 1: COSO framework and assessment scoping
- Purpose and structure of the COSO Internal Control—Integrated Framework
- The five COSO components and 17 principles
- Reasonable assurance and inherent limitations of internal control
- Control objectives, risk appetite and management assertions
- Entity-level controls versus process-level controls
- Assessment scope, boundaries, materiality and control populations
- Internal control assessment charter and stakeholder responsibilities
Workshop: Participants scope a COSO assessment for a procure-to-pay process and produce an assessment objective, boundary statement and stakeholder map.
Day 2: Risk and control design evaluation
- Business-process walkthrough techniques and narrative documentation
- Swimlane flowcharts for control points and handoffs
- Risk identification using process failure scenarios
- Key control identification and control-attribute analysis
- Risk and control matrix construction in Microsoft Excel
- Control design effectiveness criteria and gap identification
- Mapping controls to relevant COSO principles
Workshop: Participants create a process flow and COSO-aligned risk and control matrix for purchasing, vendor setup and invoice approval.
Day 3: Operating effectiveness testing and evidence
- Testing objectives for operating effectiveness conclusions
- Inquiry, observation, inspection and reperformance methods
- Population definition and risk-based sample selection
- Test procedure design and expected-evidence criteria
- Evaluating system reports, approvals and reconciliations as audit evidence
- Exceptions, deviations and compensating control evaluation
- Workpaper indexing, cross-referencing and reviewer sign-off
Workshop: Participants test a simulated sample of invoice approvals and vendor changes, then complete evidence-based testing workpapers.
Day 4: Deficiency evaluation and reporting
- Design deficiencies, operating deficiencies and control gaps
- Root-cause analysis using the five whys method
- Likelihood and impact assessment for control failures
- Deficiency severity rating and escalation criteria
- Linking findings to COSO principles and business risks
- Corrective-action design, ownership and target dates
- Management report writing and executive-level finding summaries
Workshop: Participants assess case-study exceptions, determine deficiency severity and draft a finding with root cause, risk statement and remediation action.
Day 5: Integrated COSO assessment and action planning
- Integrating entity-level and process-level assessment results
- Reaching an overall internal control conclusion
- Management representations and control-owner validation
- Monitoring activities and remediation follow-up testing
- Using Microsoft Power BI for control issue trend reporting
- Alignment with IIA Global Internal Audit Standards
- Assessment planning for the participant’s own organisation
Workshop: Participants assemble and present a complete COSO assessment pack, including conclusion, priority findings, remediation tracker and 90-day application plan.
Tools & standards covered
COSO Internal Control—Integrated Framework (2013), IIA Global Internal Audit Standards (2024), Microsoft Excel, Microsoft Power BI
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Kigali · USD 3,500 -
28 Sep – 02 Oct 2026Book
Live Online · USD 1,500 -
28 Sep – 02 Oct 2026Book
Cape Town · USD 4,200 -
05 – 09 Oct 2026Book
Live Online · USD 1,500 -
05 – 09 Oct 2026Book
Nairobi · USD 3,000 -
05 – 09 Oct 2026Book
Mombasa · USD 3,200 -
12 – 16 Oct 2026Book
Cape Town · USD 4,200 -
19 – 23 Oct 2026Book
Nairobi · USD 3,000
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Auditing
Microfinance Internal Audit and Control Testing Training Course
Microfinance institutions operate through dispersed branches, high-volume loan transactions, field collections, group lending arrangements, …
Strategic Internal Audit Leadership for Chief Audit Executives Training Course
Chief Audit Executives are expected to provide more than assurance over completed transactions. They must help the board and executive team …
IIA Global Internal Audit Standards Implementation Training Course
The 2024 IIA Global Internal Audit Standards raise the bar for how internal audit functions are governed, planned, performed, communicated a…
SAP Audit Management Reporting and Workflow Training Course
Internal audit teams need timely, defensible reporting without relying on disconnected spreadsheets, email-based review cycles, or manual st…