COSO Internal Control Framework for Accountants Training Course
| Course code | SD-A-013 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Accounting |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Accountants are frequently asked to explain whether financial reporting controls are properly designed, operating as intended, and capable of preventing or detecting material misstatement. Yet many control reviews remain limited to checklists, narrative process descriptions, or isolated testing results. This course equips finance professionals to use the COSO Internal Control—Integrated Framework as a structured method for evaluating entity-level, process-level, and IT-dependent controls across the accounting cycle.
Participants work through COSO’s five components and 17 principles, translating them into practical accounting control activities. They learn to define financial reporting objectives, identify fraud and error risks, document risks and controls in a risk-control matrix, distinguish design effectiveness from operating effectiveness, establish evidence requirements, assess control deficiencies, and prepare remediation plans. The course also addresses segregation of duties, management review controls, journal-entry controls, reconciliations, close-process controls, and controls over spreadsheet-based reporting.
Instructor-led sessions combine technical explanation with accounting scenarios involving revenue, procure-to-pay, payroll, record-to-report, and financial close. Participants analyse control narratives, build a COSO-aligned risk-control matrix in Microsoft Excel, evaluate sample test evidence, and discuss deficiency severity with reference to management and audit reporting needs. Each participant leaves with a completed internal-control assessment pack: a process objective statement, risk assessment, risk-control matrix, test plan, deficiency log, and 90-day control-improvement action plan.
The programme is designed for intermediate accounting and assurance professionals who already understand core financial reporting processes and need a repeatable framework for strengthening internal control, supporting external audit, preparing for SOX-style assessments, or improving finance governance.
Course objectives
By the end of this course, participants will be able to:
- Apply the COSO five-component model and 17 principles to financial reporting control environments
- Define accounting process objectives, risk statements, control owners, frequencies, and evidence requirements
- Build a COSO-aligned risk-control matrix for a record-to-report or transaction-processing process
- Differentiate preventive, detective, manual, automated, and IT-dependent accounting controls
- Assess control design effectiveness using walkthroughs, control narratives, and process-flow evidence
- Develop operating-effectiveness test procedures, sampling logic, and test documentation for key controls
- Evaluate control deficiencies and draft risk-ranked remediation actions for management review
- Produce a 90-day internal-control improvement plan linked to COSO principles and finance-process risks
Benefits of attending
For you
- Gain a defensible method for assessing accounting controls beyond completing generic control checklists
- Build confidence in discussing control design, operating effectiveness, and deficiencies with auditors
- Create risk-control matrices and test plans that can be reused across finance process reviews
- Strengthen readiness for controller, internal audit, compliance, and finance transformation responsibilities
- Demonstrate practical COSO capability through a completed internal-control assessment pack
For your organisation
- Improve consistency in how finance teams identify, document, and assess financial reporting controls
- Reduce the risk of errors, unsupported journal entries, late reconciliations, and weak close evidence
- Provide external and internal auditors with clearer control narratives, ownership records, and test evidence
- Prioritise remediation spending by linking deficiencies to financial reporting risks and COSO principles
- Establish reusable templates for risk-control matrices, control testing, deficiency logs, and action tracking
Target competencies
Who should attend
- Financial Controllers — who must demonstrate that close, reporting, and reconciliation controls are reliable
- Senior Accountants — who own accounting processes and prepare evidence for internal or external review
- Internal Auditors — who assess financial reporting controls against a recognised control framework
- Finance Managers — who need to identify control gaps across transaction cycles and assign remediation
- Risk and Compliance Officers — who coordinate COSO, SOX-style, or governance control assessments
- External Audit Managers — who evaluate client control design and operating evidence during audit planning
Requirements and prerequisites
Participants should have practical experience with accounting processes such as journal entries, reconciliations, accounts payable, revenue, payroll, fixed assets, or financial close. They should understand the purpose of financial statements, material misstatement, audit evidence, and basic segregation-of-duties concepts. Familiarity with Microsoft Excel is assumed because exercises use risk-control matrices and test schedules. Prior internal audit, SOX, COSO, or formal control-testing experience is not required. Participants do not need to be accountants qualified under a particular professional body, nor do they need prior experience with GRC software or programming.
Training methodology
The course is delivered through instructor-led COSO briefings, facilitated accounting-process discussions, and structured workshops using realistic finance documentation. Participants work with process narratives, reconciliation packs, journal-entry reports, approval records, and sample test evidence to identify risks and evaluate controls. Small groups map a transaction cycle to COSO principles, challenge control descriptions, and calibrate deficiency ratings. Daily feedback links each exercise to auditability and management reporting. The final session converts the completed assessment pack into a practical 90-day action plan for the participant’s own finance environment.
Course outline
Day 1: COSO foundations for financial reporting control
- Purpose and structure of the COSO Internal Control—Integrated Framework
- The five COSO components and 17 underlying principles
- Reasonable assurance and limitations of internal control
- Financial reporting objectives and assertion-level risks
- Entity-level controls versus process-level controls
- Control environment indicators in finance functions
- Mapping accounting risks to COSO principles
Workshop: Participants analyse a finance-function scenario and produce a COSO principle map identifying entity-level and process-level control gaps.
Day 2: Risk assessment and accounting control design
- Risk identification across record-to-report and financial close
- Fraud-risk considerations for journal entries and management override
- Risk and control statement construction
- Preventive, detective, corrective, and compensating controls
- Manual, automated, and IT-dependent control classification
- Segregation-of-duties analysis for accounting transactions
- Risk-control matrix structure and control attribute definition
Workshop: Participants build a risk-control matrix for a procure-to-pay or record-to-report case, specifying risks, controls, owners, frequencies, and evidence.
Day 3: Information, communication, and control activities
- Information quality requirements for accounting controls
- Management review controls and precision criteria
- Account reconciliation control design
- Journal-entry approval and post-entry review controls
- Financial close calendars and close-task controls
- Spreadsheet controls for financial reporting models
- IT general controls supporting finance applications
Workshop: Participants redesign a weak month-end close process and produce a control narrative with evidence standards for reconciliations and management reviews.
Day 4: Control testing and deficiency evaluation
- Walkthrough planning and inquiry-observation-inspection evidence
- Design-effectiveness testing procedures
- Operating-effectiveness testing procedures
- Sampling approaches for recurring accounting controls
- Test sheets, exceptions, and evidence retention
- Control deficiency root-cause analysis
- Deficiency severity and compensating-control evaluation
Workshop: Participants test a sample reconciliation control using provided evidence and produce a completed test sheet, exception log, and deficiency assessment.
Day 5: Monitoring, reporting, and implementation planning
- COSO monitoring activities and ongoing control evaluation
- Key control indicators for finance leadership
- Control owner accountability and remediation governance
- Deficiency reporting for controllers, audit committees, and auditors
- Using COSO Illustrative Tools for assessing effectiveness
- Integrating control assessments with internal audit plans
- Ninety-day finance control improvement planning
Workshop: Participants assemble and present an internal-control assessment pack containing their matrix, test plan, deficiency log, and prioritised 90-day action plan.
Tools & standards covered
COSO Internal Control—Integrated Framework (2013), COSO Illustrative Tools for Assessing Effectiveness of a System of Internal Control, Microsoft Excel, PCAOB Auditing Standard 2201
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Live Online · USD 1,500 -
21 – 25 Sep 2026Book
Nairobi · USD 3,000 -
28 Sep – 02 Oct 2026Book
Nairobi · USD 3,000 -
28 Sep – 02 Oct 2026Book
Live Online · USD 1,500 -
28 Sep – 02 Oct 2026Book
Dar es Salaam · USD 3,500 -
05 – 09 Oct 2026Book
Live Online · USD 1,500 -
26 – 30 Oct 2026Book
Live Online · USD 1,500 -
26 – 30 Oct 2026Book
Kigali · USD 3,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Accounting
Accounts Payable Accounting and Invoice Processing Training Course
Accounts payable officers are expected to pay valid supplier invoices accurately and on time while preventing duplicate payments, coding err…
Hospitality Accounting and Revenue Controls for Hotel Finance Teams Training Course
Hotel finance teams must turn thousands of daily room, food and beverage, spa, parking and ancillary transactions into reliable revenue, cas…
Healthcare Accounting and Patient Revenue Reconciliation Training Course
Healthcare finance teams must reconcile high volumes of patient charges, payments, contractual allowances, denials, refunds and bad-debt adj…
Accounting Controls and Reporting for Internal Auditors Training Course
Internal auditors are expected to assess whether financial reporting can be trusted, but many audit findings stop at identifying exceptions …