COSO Internal Control Framework for Board Oversight Training Course
| Course code | SD-CG-010 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Corporate Governance |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Boards and their committees are expected to oversee internal control without duplicating management’s role or relying on broad assurances that controls are “in place.” Directors, company secretaries, internal audit leaders and governance professionals need a disciplined way to ask whether controls support reliable reporting, lawful conduct, operational resilience and timely escalation of significant deficiencies. This course addresses the practical gap between knowing the COSO framework and using it to structure credible board oversight, committee agendas, management reporting and remediation decisions.
Participants work through the COSO Internal Control—Integrated Framework’s five components and 17 principles from a board-level perspective. They learn to translate control concepts into oversight questions; distinguish entity-level, process-level and information-technology controls; assess control deficiencies by severity; interpret management’s control evaluation; and challenge remediation plans. The programme also covers risk appetite, delegation, whistleblowing, third-party controls, financial reporting controls, cyber-related control considerations and the relationship between COSO Internal Control and enterprise risk management.
Instruction combines focused faculty input with board-paper reviews, committee simulations, control-mapping workshops and a multi-day case involving a listed company facing reporting errors, procurement misconduct and weak incident escalation. Participants build a Board Internal Control Oversight Pack containing a committee dashboard, control-question bank, deficiency escalation criteria, annual assurance calendar and action-tracking template. This practical deliverable can be adapted for use in their own board, audit committee or governance function.
The course is designed for experienced governance and assurance professionals who already participate in board or committee processes and need a consistent COSO-based method for evaluating management’s internal control claims.
Course objectives
By the end of this course, participants will be able to:
- Apply the COSO five-component model and 17 principles to a board oversight scenario
- Construct a board-level internal control dashboard using leading, lagging and assurance indicators
- Map entity-level controls, process controls and IT general controls against material risks
- Formulate audit committee challenge questions for management control attestations and assurance reports
- Classify control deficiencies and determine escalation thresholds using severity and pervasiveness criteria
- Evaluate remediation plans for ownership, root cause, milestones, validation evidence and residual risk
- Design an annual internal control assurance calendar aligned to board and committee decisions
- Produce a Board Internal Control Oversight Pack for use in a live governance setting
Benefits of attending
For you
- Gain a repeatable COSO-based method for challenging management assurance without stepping into operational management
- Build credibility in audit committee and board discussions by using recognised control principles and deficiency language
- Improve the quality of board papers, dashboards and committee questions prepared for internal control oversight
- Strengthen readiness for governance, internal audit, risk leadership and non-executive director responsibilities
- Leave with an adaptable oversight pack that demonstrates practical capability beyond theoretical COSO knowledge
For your organisation
- Create more consistent board and audit committee scrutiny of internal control across financial, operational and compliance risks
- Improve escalation of significant control deficiencies before they become reporting failures, losses or regulatory issues
- Strengthen management remediation plans through clearer ownership, evidence requirements and completion validation
- Reduce duplication between board, risk, compliance and internal audit assurance activities through a shared COSO vocabulary
- Provide decision-makers with concise control dashboards and annual assurance calendars tied to governance actions
Target competencies
Who should attend
- Non-Executive Directors and Board Members — who must oversee internal control while preserving management accountability
- Audit Committee Chairs and Members — who review control assurance, deficiencies and remediation progress
- Chief Audit Executives and Internal Audit Directors — who need to align assurance reporting with COSO principles
- Company Secretaries and Governance Directors — who prepare board processes, papers and committee action tracking
- Chief Risk Officers and Risk Managers — who connect risk reporting with internal control design and monitoring
- Finance Directors and Financial Controllers — who support control attestations and reliable financial reporting
Requirements and prerequisites
Participants should have practical familiarity with board or committee reporting, organisational risk registers, audit findings, policy frameworks or management assurance processes. They should understand basic governance terms such as risk appetite, control owner, delegation of authority, internal audit, remediation and materiality. Prior exposure to COSO is useful but not essential; the course introduces the framework before applying it. Participants do not need accounting qualifications, coding skills, audit software expertise or prior experience as a director. Bringing a recent anonymised board paper, control report or audit issue log is helpful but not required.
Training methodology
The five-day programme uses instructor-led COSO interpretation sessions followed by applied board-oversight work. Participants annotate sample audit committee papers, map controls to material risks in Excel, test management assertions against COSO principles and role-play a committee discussion on a significant deficiency. Small groups work on a continuing corporate case, receiving new evidence each day: audit findings, whistleblowing reports, control test results and remediation updates. On day five, each participant completes an application plan and presents the key elements of a Board Internal Control Oversight Pack for peer and faculty challenge.
Course outline
Day 1: COSO foundations for board accountability
- Purpose and architecture of the COSO Internal Control—Integrated Framework
- The five COSO components and 17 principles
- Board, audit committee and management accountabilities for internal control
- Entity-level controls and governance culture
- Reasonable assurance and limitations of internal control
- Linking organisational objectives, risks and controls
- Reading management control assertions through a COSO lens
Workshop: Participants diagnose a board assurance paper against the five COSO components and produce a list of evidence gaps and challenge questions.
Day 2: Control design, risk linkage and information flows
- Control objectives, risks, activities and evidence chains
- Preventive, detective, corrective and directive control types
- Risk and control matrices for board-relevant processes
- Segregation of duties and delegation of authority controls
- Information and communication principles in board reporting
- Data quality, management information and reporting controls
- IT general controls and cyber-related oversight questions
Workshop: Working from a procurement and financial-close case, participants create a risk and control matrix and identify the controls requiring board-level visibility.
Day 3: Monitoring, assurance and deficiency escalation
- COSO monitoring activities and separate evaluations
- Three lines model and coordinated assurance mapping
- Management self-assessment and control attestation methods
- Internal audit testing results and assurance ratings
- Control deficiency classification, severity and pervasiveness
- Root-cause analysis using the five whys and cause-and-effect mapping
- Escalation protocols for significant deficiencies and incidents
Workshop: Participants assess a set of audit findings, classify deficiency severity and produce an escalation recommendation for an audit committee chair.
Day 4: Board challenge and remediation governance
- Designing effective audit committee agendas for control oversight
- Board-level internal control dashboards and key risk indicators
- Questioning management without assuming executive responsibilities
- Remediation plan quality criteria and milestone design
- Action ownership, overdue actions and closure validation
- Whistleblowing, fraud indicators and conduct-control signals
- Third-party and outsourced service control assurance
Workshop: In a simulated audit committee meeting, participants challenge management’s remediation proposal and produce a revised action-tracking and assurance request.
Day 5: Embedding a COSO-based oversight cycle
- Annual board and committee internal control assurance calendar
- Integrating COSO Internal Control with COSO ERM reporting
- Control oversight for strategic change, acquisitions and transformation
- Financial reporting control considerations and disclosure support
- Evidence packs for board conclusions and minutes
- Maturity assessment for internal control oversight practices
- Ninety-day implementation planning and stakeholder engagement
Workshop: Participants assemble and present their Board Internal Control Oversight Pack, including a dashboard, challenge questions, escalation criteria, assurance calendar and 90-day plan.
Tools & standards covered
COSO Internal Control—Integrated Framework (2013), COSO Enterprise Risk Management—Integrating with Strategy and Performance (2017), Microsoft Excel, Microsoft Power BI
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Live Online · USD 1,500 -
21 – 25 Sep 2026Book
Nairobi · USD 3,000 -
28 Sep – 02 Oct 2026Book
Nairobi · USD 3,000 -
12 – 16 Oct 2026Book
Kigali · USD 3,500 -
12 – 16 Oct 2026Book
Mombasa · USD 3,200 -
19 – 23 Oct 2026Book
Live Online · USD 1,500 -
19 – 23 Oct 2026Book
Cape Town · USD 4,200 -
02 – 06 Nov 2026Book
Dubai · USD 4,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Corporate Governance
Corporate Governance for Risk Managers Training Course
Risk managers are expected to provide boards and executive committees with a clear view of material exposures, control effectiveness and eme…
Diligent Boards Software for Board Governance Training Course
Board and governance teams must deliver secure, accurate meeting materials while giving directors enough time and context to make defensible…
Corporate Governance for Audit Committee Chairs Training Course
Audit committee chairs must turn board oversight into disciplined challenge, not retrospective review. They are expected to interrogate fina…
Board Intelligence Board Portal Administration for Governance Training Course
Board and committee administrators are expected to deliver secure, accurate papers under tight reporting timetables while protecting confide…