COSO Internal Control Assessment Training Course

5 days Auditing Certificate on completion
Course codeSD-A-041
Duration5 days
LevelIntermediate
CategoryAuditing
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Finance, audit, compliance and control professionals are often asked to assess whether internal controls are designed effectively and operating as intended, yet findings can be inconsistent when teams rely on checklists without a common framework. This creates avoidable exposure: controls may not address the right risks, evidence may be insufficient to support conclusions, and management may receive reports that identify symptoms rather than root causes. This course provides a disciplined method for planning, performing and reporting internal control assessments using the COSO Internal Control—Integrated Framework.

Participants work through the five COSO components and 17 principles, translating them into practical assessment criteria for governance, risk assessment, control activities, information and communication, and monitoring. They learn how to define an auditable control objective, map risks to controls, distinguish design effectiveness from operating effectiveness, select samples, evaluate evidence, rate deficiencies, and formulate remediation recommendations. The course also addresses entity-level controls, process-level controls, management assertions, control documentation and the relationship between COSO assessments, internal audit plans and external audit requirements.

Instruction combines facilitator-led analysis with a multi-day case involving a finance and procurement process. Participants build a COSO-aligned risk and control matrix, develop test procedures, assess control evidence, document findings and present a management-ready conclusion. Each participant leaves with a completed internal control assessment pack: a scoping document, risk and control matrix, testing workpaper, deficiency evaluation and corrective-action tracker that can be adapted for use in their organisation.

The course is designed for professionals who already work with financial processes, risk, compliance, assurance or audit documentation and need a repeatable framework for evaluating internal control systems.

Course objectives

By the end of this course, participants will be able to:

  • Apply the COSO Internal Control—Integrated Framework and its 17 principles to an internal control assessment
  • Define control objectives, risks and management assertions for a selected business process
  • Construct a risk and control matrix linking process risks, key controls, owners, evidence and COSO principles
  • Evaluate control design effectiveness using walkthroughs, flowcharts and control-attribute criteria
  • Test operating effectiveness through sample selection, evidence inspection, reperformance and inquiry
  • Classify control deficiencies by severity, root cause, likelihood, impact and compensating controls
  • Prepare audit-ready workpapers that document scope, testing procedures, evidence, conclusions and reviewer sign-off
  • Present a COSO-based assessment report with prioritised remediation actions and accountable action owners

Benefits of attending

For you

  • Gain a defensible method for concluding on control design and operating effectiveness
  • Produce clearer audit workpapers and control-testing documentation for reviewer scrutiny
  • Build confidence applying the 17 COSO principles beyond a compliance checklist
  • Strengthen readiness for internal audit, controls assurance, financial control and risk roles
  • Learn to turn control failures into prioritised, practical remediation recommendations

For your organisation

  • Establish a common COSO-based vocabulary for control owners, risk teams and assurance functions
  • Improve consistency in risk and control matrices, walkthroughs, testing workpapers and findings reports
  • Identify weak or undocumented controls before they become financial, compliance or operational incidents
  • Focus remediation funding on deficiencies with the greatest risk exposure and weakest compensating controls
  • Create reusable assessment templates that support audit planning, management assurance and external audit coordination

Target competencies

COSO principle mappingControl design testingOperating effectiveness testingRisk control matricesDeficiency evaluationAudit workpaper drafting

Who should attend

  • Internal Auditors — who need a consistent framework for assessing and reporting control effectiveness
  • Financial Controllers — who oversee financial reporting controls and must evidence their reliability
  • Risk Managers — who connect enterprise and process risks to control responses and assurance activities
  • Compliance Managers — who evaluate whether operational controls meet policy and regulatory expectations
  • External Audit Seniors — who assess controls and coordinate evidence requests with client management
  • Process Owners — who are accountable for key controls and corrective actions within finance or operational processes

Requirements and prerequisites

Participants should have working familiarity with business-process documentation, basic risk concepts and the purpose of internal controls. Experience in finance, accounting, compliance, internal audit, external audit or operational risk is expected, including the ability to read procedures, invoices, reconciliations, approvals or similar control evidence. Participants should be comfortable using spreadsheets for simple tables and filters; Microsoft Excel is used in exercises. Prior knowledge of the COSO framework, statistical sampling, audit software, SOX compliance or Power BI is not required. This is an intermediate course because it assumes participants can relate controls to real business processes.

Training methodology

The instructor uses short COSO framework briefings followed by structured application to a finance and procurement case. Participants conduct a process walkthrough, identify risks and key controls, map controls to COSO principles and build testing procedures in an Excel-based workpaper. Small groups inspect simulated evidence, challenge control-design assumptions, rate deficiencies and compare conclusions against a facilitator model answer. Daily review sessions connect the case to participants’ own control environments. On the final day, each participant prepares an application plan for one assessment or control review they will undertake after the course.

Course outline

Day 1: COSO framework and assessment scoping

  • Purpose and structure of the COSO Internal Control—Integrated Framework
  • The five COSO components and 17 principles
  • Reasonable assurance and inherent limitations of internal control
  • Control objectives, risk appetite and management assertions
  • Entity-level controls versus process-level controls
  • Assessment scope, boundaries, materiality and control populations
  • Internal control assessment charter and stakeholder responsibilities

Workshop: Participants scope a COSO assessment for a procure-to-pay process and produce an assessment objective, boundary statement and stakeholder map.

Day 2: Risk and control design evaluation

  • Business-process walkthrough techniques and narrative documentation
  • Swimlane flowcharts for control points and handoffs
  • Risk identification using process failure scenarios
  • Key control identification and control-attribute analysis
  • Risk and control matrix construction in Microsoft Excel
  • Control design effectiveness criteria and gap identification
  • Mapping controls to relevant COSO principles

Workshop: Participants create a process flow and COSO-aligned risk and control matrix for purchasing, vendor setup and invoice approval.

Day 3: Operating effectiveness testing and evidence

  • Testing objectives for operating effectiveness conclusions
  • Inquiry, observation, inspection and reperformance methods
  • Population definition and risk-based sample selection
  • Test procedure design and expected-evidence criteria
  • Evaluating system reports, approvals and reconciliations as audit evidence
  • Exceptions, deviations and compensating control evaluation
  • Workpaper indexing, cross-referencing and reviewer sign-off

Workshop: Participants test a simulated sample of invoice approvals and vendor changes, then complete evidence-based testing workpapers.

Day 4: Deficiency evaluation and reporting

  • Design deficiencies, operating deficiencies and control gaps
  • Root-cause analysis using the five whys method
  • Likelihood and impact assessment for control failures
  • Deficiency severity rating and escalation criteria
  • Linking findings to COSO principles and business risks
  • Corrective-action design, ownership and target dates
  • Management report writing and executive-level finding summaries

Workshop: Participants assess case-study exceptions, determine deficiency severity and draft a finding with root cause, risk statement and remediation action.

Day 5: Integrated COSO assessment and action planning

  • Integrating entity-level and process-level assessment results
  • Reaching an overall internal control conclusion
  • Management representations and control-owner validation
  • Monitoring activities and remediation follow-up testing
  • Using Microsoft Power BI for control issue trend reporting
  • Alignment with IIA Global Internal Audit Standards
  • Assessment planning for the participant’s own organisation

Workshop: Participants assemble and present a complete COSO assessment pack, including conclusion, priority findings, remediation tracker and 90-day application plan.

Tools & standards covered

COSO Internal Control—Integrated Framework (2013), IIA Global Internal Audit Standards (2024), Microsoft Excel, Microsoft Power BI

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand how a business process works and be familiar with basic control concepts such as approvals, reconciliations, segregation of duties and evidence. You do not need prior COSO training, formal audit qualifications or SOX experience.

A laptop with Microsoft Excel is strongly recommended because participants build risk and control matrices and testing workpapers during the course. No specialist GRC platform or audit management system is required; sample materials are provided.

It is best suited to internal auditors, controllers, risk and compliance professionals, external audit staff and process owners with responsibility for key controls. It is particularly useful for people moving from control operation or documentation into formal control assessment work.

The course concentrates on using COSO as a practical assessment method, from scope and control mapping through testing, deficiency evaluation and reporting. General audit courses often cover audit planning broadly, while this course develops the specific workpapers and judgments needed to conclude on internal control effectiveness.

You can use the assessment pack to review a finance, procurement, payroll, revenue or operational process in your organisation. The templates support a structured walkthrough, risk and control matrix, test plan, finding report and remediation follow-up.

You will leave with completed case-based templates for an assessment scope, process flow, risk and control matrix, control-testing workpaper, deficiency rating and action tracker. These are designed as adaptable working documents rather than generic reference notes.

Upcoming sessions

  • 21 – 25 Sep 2026
    Kigali · USD 3,500
    Book
  • 28 Sep – 02 Oct 2026
    Live Online · USD 1,500
    Book
  • 28 Sep – 02 Oct 2026
    Cape Town · USD 4,200
    Book
  • 05 – 09 Oct 2026
    Live Online · USD 1,500
    Book
  • 05 – 09 Oct 2026
    Nairobi · USD 3,000
    Book
  • 05 – 09 Oct 2026
    Mombasa · USD 3,200
    Book
  • 12 – 16 Oct 2026
    Cape Town · USD 4,200
    Book
  • 19 – 23 Oct 2026
    Nairobi · USD 3,000
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Auditing

5 Days Certificate

Microfinance Internal Audit and Control Testing Training Course

Microfinance institutions operate through dispersed branches, high-volume loan transactions, field collections, group lending arrangements, …

5 Days Certificate

Strategic Internal Audit Leadership for Chief Audit Executives Training Course

Chief Audit Executives are expected to provide more than assurance over completed transactions. They must help the board and executive team …

5 Days Certificate

IIA Global Internal Audit Standards Implementation Training Course

The 2024 IIA Global Internal Audit Standards raise the bar for how internal audit functions are governed, planned, performed, communicated a…

5 Days Certificate

SAP Audit Management Reporting and Workflow Training Course

Internal audit teams need timely, defensible reporting without relying on disconnected spreadsheets, email-based review cycles, or manual st…