COSO Internal Control Framework for Accountants Training Course

5 days Accounting Certificate on completion
Course codeSD-A-013
Duration5 days
LevelIntermediate
CategoryAccounting
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Accountants are frequently asked to explain whether financial reporting controls are properly designed, operating as intended, and capable of preventing or detecting material misstatement. Yet many control reviews remain limited to checklists, narrative process descriptions, or isolated testing results. This course equips finance professionals to use the COSO Internal Control—Integrated Framework as a structured method for evaluating entity-level, process-level, and IT-dependent controls across the accounting cycle.

Participants work through COSO’s five components and 17 principles, translating them into practical accounting control activities. They learn to define financial reporting objectives, identify fraud and error risks, document risks and controls in a risk-control matrix, distinguish design effectiveness from operating effectiveness, establish evidence requirements, assess control deficiencies, and prepare remediation plans. The course also addresses segregation of duties, management review controls, journal-entry controls, reconciliations, close-process controls, and controls over spreadsheet-based reporting.

Instructor-led sessions combine technical explanation with accounting scenarios involving revenue, procure-to-pay, payroll, record-to-report, and financial close. Participants analyse control narratives, build a COSO-aligned risk-control matrix in Microsoft Excel, evaluate sample test evidence, and discuss deficiency severity with reference to management and audit reporting needs. Each participant leaves with a completed internal-control assessment pack: a process objective statement, risk assessment, risk-control matrix, test plan, deficiency log, and 90-day control-improvement action plan.

The programme is designed for intermediate accounting and assurance professionals who already understand core financial reporting processes and need a repeatable framework for strengthening internal control, supporting external audit, preparing for SOX-style assessments, or improving finance governance.

Course objectives

By the end of this course, participants will be able to:

  • Apply the COSO five-component model and 17 principles to financial reporting control environments
  • Define accounting process objectives, risk statements, control owners, frequencies, and evidence requirements
  • Build a COSO-aligned risk-control matrix for a record-to-report or transaction-processing process
  • Differentiate preventive, detective, manual, automated, and IT-dependent accounting controls
  • Assess control design effectiveness using walkthroughs, control narratives, and process-flow evidence
  • Develop operating-effectiveness test procedures, sampling logic, and test documentation for key controls
  • Evaluate control deficiencies and draft risk-ranked remediation actions for management review
  • Produce a 90-day internal-control improvement plan linked to COSO principles and finance-process risks

Benefits of attending

For you

  • Gain a defensible method for assessing accounting controls beyond completing generic control checklists
  • Build confidence in discussing control design, operating effectiveness, and deficiencies with auditors
  • Create risk-control matrices and test plans that can be reused across finance process reviews
  • Strengthen readiness for controller, internal audit, compliance, and finance transformation responsibilities
  • Demonstrate practical COSO capability through a completed internal-control assessment pack

For your organisation

  • Improve consistency in how finance teams identify, document, and assess financial reporting controls
  • Reduce the risk of errors, unsupported journal entries, late reconciliations, and weak close evidence
  • Provide external and internal auditors with clearer control narratives, ownership records, and test evidence
  • Prioritise remediation spending by linking deficiencies to financial reporting risks and COSO principles
  • Establish reusable templates for risk-control matrices, control testing, deficiency logs, and action tracking

Target competencies

COSO principle mappingRisk-control matrix designControl design assessmentOperating effectiveness testingDeficiency evaluationRemediation action planning

Who should attend

  • Financial Controllers — who must demonstrate that close, reporting, and reconciliation controls are reliable
  • Senior Accountants — who own accounting processes and prepare evidence for internal or external review
  • Internal Auditors — who assess financial reporting controls against a recognised control framework
  • Finance Managers — who need to identify control gaps across transaction cycles and assign remediation
  • Risk and Compliance Officers — who coordinate COSO, SOX-style, or governance control assessments
  • External Audit Managers — who evaluate client control design and operating evidence during audit planning

Requirements and prerequisites

Participants should have practical experience with accounting processes such as journal entries, reconciliations, accounts payable, revenue, payroll, fixed assets, or financial close. They should understand the purpose of financial statements, material misstatement, audit evidence, and basic segregation-of-duties concepts. Familiarity with Microsoft Excel is assumed because exercises use risk-control matrices and test schedules. Prior internal audit, SOX, COSO, or formal control-testing experience is not required. Participants do not need to be accountants qualified under a particular professional body, nor do they need prior experience with GRC software or programming.

Training methodology

The course is delivered through instructor-led COSO briefings, facilitated accounting-process discussions, and structured workshops using realistic finance documentation. Participants work with process narratives, reconciliation packs, journal-entry reports, approval records, and sample test evidence to identify risks and evaluate controls. Small groups map a transaction cycle to COSO principles, challenge control descriptions, and calibrate deficiency ratings. Daily feedback links each exercise to auditability and management reporting. The final session converts the completed assessment pack into a practical 90-day action plan for the participant’s own finance environment.

Course outline

Day 1: COSO foundations for financial reporting control

  • Purpose and structure of the COSO Internal Control—Integrated Framework
  • The five COSO components and 17 underlying principles
  • Reasonable assurance and limitations of internal control
  • Financial reporting objectives and assertion-level risks
  • Entity-level controls versus process-level controls
  • Control environment indicators in finance functions
  • Mapping accounting risks to COSO principles

Workshop: Participants analyse a finance-function scenario and produce a COSO principle map identifying entity-level and process-level control gaps.

Day 2: Risk assessment and accounting control design

  • Risk identification across record-to-report and financial close
  • Fraud-risk considerations for journal entries and management override
  • Risk and control statement construction
  • Preventive, detective, corrective, and compensating controls
  • Manual, automated, and IT-dependent control classification
  • Segregation-of-duties analysis for accounting transactions
  • Risk-control matrix structure and control attribute definition

Workshop: Participants build a risk-control matrix for a procure-to-pay or record-to-report case, specifying risks, controls, owners, frequencies, and evidence.

Day 3: Information, communication, and control activities

  • Information quality requirements for accounting controls
  • Management review controls and precision criteria
  • Account reconciliation control design
  • Journal-entry approval and post-entry review controls
  • Financial close calendars and close-task controls
  • Spreadsheet controls for financial reporting models
  • IT general controls supporting finance applications

Workshop: Participants redesign a weak month-end close process and produce a control narrative with evidence standards for reconciliations and management reviews.

Day 4: Control testing and deficiency evaluation

  • Walkthrough planning and inquiry-observation-inspection evidence
  • Design-effectiveness testing procedures
  • Operating-effectiveness testing procedures
  • Sampling approaches for recurring accounting controls
  • Test sheets, exceptions, and evidence retention
  • Control deficiency root-cause analysis
  • Deficiency severity and compensating-control evaluation

Workshop: Participants test a sample reconciliation control using provided evidence and produce a completed test sheet, exception log, and deficiency assessment.

Day 5: Monitoring, reporting, and implementation planning

  • COSO monitoring activities and ongoing control evaluation
  • Key control indicators for finance leadership
  • Control owner accountability and remediation governance
  • Deficiency reporting for controllers, audit committees, and auditors
  • Using COSO Illustrative Tools for assessing effectiveness
  • Integrating control assessments with internal audit plans
  • Ninety-day finance control improvement planning

Workshop: Participants assemble and present an internal-control assessment pack containing their matrix, test plan, deficiency log, and prioritised 90-day action plan.

Tools & standards covered

COSO Internal Control—Integrated Framework (2013), COSO Illustrative Tools for Assessing Effectiveness of a System of Internal Control, Microsoft Excel, PCAOB Auditing Standard 2201

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No previous COSO or SOX experience is required. You should, however, understand common accounting processes and be able to interpret financial reporting risks, reconciliations, and supporting documentation.

A laptop with Microsoft Excel is strongly recommended for the risk-control matrix and control-testing exercises. No GRC platform, audit analytics software, or programming capability is required.

Yes. The course is particularly useful for controllers, senior accountants, finance managers, and process owners who must operate and evidence controls, not only audit them.

This programme uses COSO specifically to assess accounting and financial reporting controls, including close, reconciliations, journal entries, management review, and spreadsheet controls. A general audit course typically gives broader coverage of audit planning, reporting, and assurance engagements.

You can use the risk-control matrix, walkthrough approach, testing templates, and deficiency log to review a finance process immediately. The final 90-day action plan helps translate course findings into assigned remediation actions and management reporting.

You leave with a COSO-aligned internal-control assessment pack developed during the course. It includes a process objective, risk assessment, risk-control matrix, test plan, deficiency log, and prioritised improvement plan.

Upcoming sessions

  • 21 – 25 Sep 2026
    Live Online · USD 1,500
    Book
  • 21 – 25 Sep 2026
    Nairobi · USD 3,000
    Book
  • 28 Sep – 02 Oct 2026
    Nairobi · USD 3,000
    Book
  • 28 Sep – 02 Oct 2026
    Live Online · USD 1,500
    Book
  • 28 Sep – 02 Oct 2026
    Dar es Salaam · USD 3,500
    Book
  • 05 – 09 Oct 2026
    Live Online · USD 1,500
    Book
  • 26 – 30 Oct 2026
    Live Online · USD 1,500
    Book
  • 26 – 30 Oct 2026
    Kigali · USD 3,500
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Accounting

5 Days Certificate

Accounts Payable Accounting and Invoice Processing Training Course

Accounts payable officers are expected to pay valid supplier invoices accurately and on time while preventing duplicate payments, coding err…

5 Days Certificate

Hospitality Accounting and Revenue Controls for Hotel Finance Teams Training Course

Hotel finance teams must turn thousands of daily room, food and beverage, spa, parking and ancillary transactions into reliable revenue, cas…

5 Days Certificate

Healthcare Accounting and Patient Revenue Reconciliation Training Course

Healthcare finance teams must reconcile high volumes of patient charges, payments, contractual allowances, denials, refunds and bad-debt adj…

5 Days Certificate

Accounting Controls and Reporting for Internal Auditors Training Course

Internal auditors are expected to assess whether financial reporting can be trusted, but many audit findings stop at identifying exceptions …