COSO Internal Control Framework for Public Sector Audit Training Course
| Course code | SD-GPS-037 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Government & Public Sector |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Public-sector and humanitarian organisations must demonstrate that funds, assets, procurement decisions, programme data and partner-managed activities are controlled well enough to withstand audit, donor review and parliamentary or board scrutiny. Yet audit findings often describe symptoms—unsupported payments, weak reconciliations, unclear delegations, incomplete risk registers or late corrective actions—without showing how control failures relate to the organisation’s wider system. This course gives audit, finance, programme and assurance professionals a practical way to assess those systems using the COSO Internal Control—Integrated Framework.
Participants work through COSO’s five components and 17 principles in a government and development context: control environment, risk assessment, control activities, information and communication, and monitoring. They learn to translate public-sector mandates, donor conditions and programme delivery risks into auditable control objectives; map key processes; distinguish preventive, detective and corrective controls; test design and operating effectiveness; document evidence; and report deficiencies with clear root causes and corrective actions. Examples cover grant management, cash transfers, procurement, payroll, inventory, implementing partners and safeguarding-related controls.
Delivery combines instructor-led explanation with facilitated audit simulations, control-mapping workshops and case-based working papers. Participants use a COSO-aligned risk-and-control matrix, walkthrough template, control test plan and deficiency-rating approach throughout the week. By the end of the course, each participant produces an application pack for a selected process in their own organisation or a realistic public-sector case: a process narrative, risk-and-control matrix, sample test procedures, evidence requirements and prioritised improvement actions.
The course is designed for professionals moving from compliance checking to structured internal-control assurance, as well as managers who need a consistent basis for strengthening governance across central government entities, local authorities, development programmes and humanitarian operations.
Course objectives
By the end of this course, participants will be able to:
- Interpret the COSO five-component model and 17 principles against public-sector governance, accountability and donor-funded programme requirements
- Define control objectives for procurement, grants, cash management, payroll, partner oversight and programme delivery processes
- Build a COSO-aligned risk-and-control matrix that links risks, control activities, owners, evidence and residual risk
- Map an end-to-end transaction process using walkthrough narratives, flowcharts and key control points
- Differentiate preventive, detective and corrective controls and assess whether each control is suitably designed
- Develop control test procedures, sampling criteria and evidence requests to evaluate operating effectiveness
- Rate internal-control deficiencies using likelihood, impact, root cause and compensating-control analysis
- Prepare a prioritised audit recommendation and management action plan with accountable owners and target dates
Benefits of attending
For you
- Gain a defensible method for explaining why a control failure matters beyond a single transaction or audit exception
- Build practical working papers that can be adapted for procurement, grants, cash, payroll and partner audits
- Improve credibility when challenging control owners by linking findings to COSO principles and documented evidence
- Move from checklist-based compliance reviews to risk-based assessments of control design and effectiveness
- Prepare for broader internal audit, risk, compliance or public financial management responsibilities
For your organisation
- Create a common COSO vocabulary for audit, finance, programme and compliance teams assessing the same control environment
- Improve the quality and consistency of risk-and-control matrices, walkthrough records and audit test plans
- Identify control gaps in high-risk public funds processes before they become donor findings, fraud losses or qualified reports
- Strengthen corrective-action plans by assigning root causes, accountable owners, deadlines and follow-up evidence
- Provide management and oversight bodies with clearer assurance on controls across departments, projects and implementing partners
Target competencies
Who should attend
- Internal Auditors — who need a repeatable COSO basis for planning and documenting public-sector assurance work
- Government Audit Officers — who assess ministries, agencies and local authorities against control and accountability obligations
- Finance Managers — who own financial controls for budgets, payments, reconciliations, advances and donor reporting
- Programme Managers — who must maintain reliable controls across grants, field delivery and implementing partners
- Risk and Compliance Officers — who coordinate enterprise risks, compliance monitoring and remediation tracking
- Procurement and Grant Management Officers — who need to evidence transparent purchasing, award decisions and fund stewardship
Requirements and prerequisites
This is a foundation-to-intermediate course. Participants should be familiar with the basic purpose of internal audit, financial controls or operational procedures in a government, donor-funded, development or humanitarian setting. Experience reading policies, reviewing transactions, preparing reports or working with risk registers is useful, but not essential. Participants should be comfortable using Microsoft Excel for simple tables and filters, as templates are completed during exercises. No prior COSO certification, accountancy qualification, audit software experience or advanced statistical sampling knowledge is required. Complete beginners should expect a structured introduction before progressing to practical control testing and reporting.
Training methodology
The five days combine short instructor-led COSO briefings with public-sector audit cases and structured working-paper exercises. Participants map a grant or government transaction process, identify risks and controls, conduct a simulated walkthrough, select evidence, draft test procedures and assess control deficiencies. Small groups compare judgments on issues such as delegated authority, partner advances and procurement approvals, then defend their conclusions as an audit team would. The final session converts the course templates into an individual application plan for a priority process in the participant’s organisation.
Course outline
Day 1: COSO foundations for public-sector accountability
- Purpose and structure of the COSO Internal Control—Integrated Framework
- The five COSO components and 17 principles
- Public-sector accountability, stewardship and value-for-money obligations
- Internal control versus internal audit, risk management and compliance
- Control environment indicators: integrity, oversight, structure and competence
- Roles of governing bodies, accounting officers, management and internal audit
- Applying COSO to donor-funded and humanitarian operating models
Workshop: Participants diagnose the COSO component gaps in a case involving a government-funded emergency response programme and produce an initial control-environment assessment.
Day 2: Risk assessment and control design
- Defining process objectives, risk appetite and control objectives
- Risk identification for grants, procurement, cash, payroll and implementing partners
- Fraud, corruption, conflict-of-interest and safeguarding control risks
- Risk scoring using likelihood, impact and existing-control assessment
- Preventive, detective, corrective and compensating control types
- Segregation of duties, delegations of authority and approval limits
- Constructing a COSO-aligned risk-and-control matrix
Workshop: Participants build a risk-and-control matrix for a partner cash-advance process, including risks, controls, owners, evidence and residual ratings.
Day 3: Documenting processes and testing controls
- Process narratives, swimlane flowcharts and control-point identification
- Walkthrough interviews and tracing a transaction from initiation to reporting
- Evaluating control design against stated risks and objectives
- Testing operating effectiveness through inspection, observation, inquiry and reperformance
- Defining populations, sampling approaches and sample-selection rationale
- Evidence quality, audit trails, system reports and document retention
- Documenting test results in audit working papers
Workshop: Participants perform a simulated procurement walkthrough and produce a process map, control points, evidence list and draft test procedures.
Day 4: Monitoring, deficiencies and audit reporting
- COSO monitoring activities and separate evaluations
- Management self-assessments, reconciliations, exception reports and supervisory review
- Identifying control deficiencies and distinguishing isolated errors from systemic weaknesses
- Root-cause analysis using the five-whys method and cause categories
- Assessing significance through impact, likelihood, pervasiveness and compensating controls
- Writing evidence-based findings, risks, recommendations and agreed actions
- Tracking remediation through action registers and follow-up testing
Workshop: Participants analyse a set of audit exceptions, classify the deficiencies, determine root causes and draft a prioritised management action plan.
Day 5: Integrated COSO audit application
- Planning a risk-based COSO internal-control review
- Scoping entities, processes, systems, locations and implementing partners
- Linking audit objectives to COSO principles and control assertions
- Coordinating internal audit, external audit, compliance and programme assurance
- Communicating control conclusions to senior management and audit committees
- Using Excel risk-and-control templates for review planning and reporting
- Developing a 90-day internal-control improvement roadmap
Workshop: Participants complete and present a COSO application pack for a selected public-sector process, including a risk-control matrix, test plan, finding and 90-day action roadmap.
Tools & standards covered
COSO Internal Control—Integrated Framework (2013), INTOSAI GOV 9100 Guidelines for Internal Control Standards for the Public Sector, The IIA Global Internal Audit Standards (2024), Microsoft Excel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Government & Public Sector
Education Sector Planning for Government Education Agencies Training Course
Government education agencies must convert political commitments, learning data and fiscal limits into credible sector plans that guide annu…
Justice Sector Court Administration and Caseflow Training Course
Court backlogs, adjournments, incomplete files, uneven courtroom utilisation and weak hearing-date control can erode public confidence and p…
Theory of Change for Government Programme Design Training Course
Government programmes often move from political commitments and broad policy goals directly to activities, budgets and procurement plans wit…
Advanced Government Crisis Management and Continuity Planning Training Course
Government agencies and public-sector partners must sustain essential services while making defensible decisions under severe uncertainty. A…