COSO Internal Control Framework for Public Sector Audit Training Course

5 days Government & Public Sector Certificate on completion
Course codeSD-GPS-037
Duration5 days
LevelFoundation to Intermediate
CategoryGovernment & Public Sector
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Public-sector and humanitarian organisations must demonstrate that funds, assets, procurement decisions, programme data and partner-managed activities are controlled well enough to withstand audit, donor review and parliamentary or board scrutiny. Yet audit findings often describe symptoms—unsupported payments, weak reconciliations, unclear delegations, incomplete risk registers or late corrective actions—without showing how control failures relate to the organisation’s wider system. This course gives audit, finance, programme and assurance professionals a practical way to assess those systems using the COSO Internal Control—Integrated Framework.

Participants work through COSO’s five components and 17 principles in a government and development context: control environment, risk assessment, control activities, information and communication, and monitoring. They learn to translate public-sector mandates, donor conditions and programme delivery risks into auditable control objectives; map key processes; distinguish preventive, detective and corrective controls; test design and operating effectiveness; document evidence; and report deficiencies with clear root causes and corrective actions. Examples cover grant management, cash transfers, procurement, payroll, inventory, implementing partners and safeguarding-related controls.

Delivery combines instructor-led explanation with facilitated audit simulations, control-mapping workshops and case-based working papers. Participants use a COSO-aligned risk-and-control matrix, walkthrough template, control test plan and deficiency-rating approach throughout the week. By the end of the course, each participant produces an application pack for a selected process in their own organisation or a realistic public-sector case: a process narrative, risk-and-control matrix, sample test procedures, evidence requirements and prioritised improvement actions.

The course is designed for professionals moving from compliance checking to structured internal-control assurance, as well as managers who need a consistent basis for strengthening governance across central government entities, local authorities, development programmes and humanitarian operations.

Course objectives

By the end of this course, participants will be able to:

  • Interpret the COSO five-component model and 17 principles against public-sector governance, accountability and donor-funded programme requirements
  • Define control objectives for procurement, grants, cash management, payroll, partner oversight and programme delivery processes
  • Build a COSO-aligned risk-and-control matrix that links risks, control activities, owners, evidence and residual risk
  • Map an end-to-end transaction process using walkthrough narratives, flowcharts and key control points
  • Differentiate preventive, detective and corrective controls and assess whether each control is suitably designed
  • Develop control test procedures, sampling criteria and evidence requests to evaluate operating effectiveness
  • Rate internal-control deficiencies using likelihood, impact, root cause and compensating-control analysis
  • Prepare a prioritised audit recommendation and management action plan with accountable owners and target dates

Benefits of attending

For you

  • Gain a defensible method for explaining why a control failure matters beyond a single transaction or audit exception
  • Build practical working papers that can be adapted for procurement, grants, cash, payroll and partner audits
  • Improve credibility when challenging control owners by linking findings to COSO principles and documented evidence
  • Move from checklist-based compliance reviews to risk-based assessments of control design and effectiveness
  • Prepare for broader internal audit, risk, compliance or public financial management responsibilities

For your organisation

  • Create a common COSO vocabulary for audit, finance, programme and compliance teams assessing the same control environment
  • Improve the quality and consistency of risk-and-control matrices, walkthrough records and audit test plans
  • Identify control gaps in high-risk public funds processes before they become donor findings, fraud losses or qualified reports
  • Strengthen corrective-action plans by assigning root causes, accountable owners, deadlines and follow-up evidence
  • Provide management and oversight bodies with clearer assurance on controls across departments, projects and implementing partners

Target competencies

COSO principle mappingControl design assessmentRisk-control matricesWalkthrough documentationControl effectiveness testingDeficiency action planning

Who should attend

  • Internal Auditors — who need a repeatable COSO basis for planning and documenting public-sector assurance work
  • Government Audit Officers — who assess ministries, agencies and local authorities against control and accountability obligations
  • Finance Managers — who own financial controls for budgets, payments, reconciliations, advances and donor reporting
  • Programme Managers — who must maintain reliable controls across grants, field delivery and implementing partners
  • Risk and Compliance Officers — who coordinate enterprise risks, compliance monitoring and remediation tracking
  • Procurement and Grant Management Officers — who need to evidence transparent purchasing, award decisions and fund stewardship

Requirements and prerequisites

This is a foundation-to-intermediate course. Participants should be familiar with the basic purpose of internal audit, financial controls or operational procedures in a government, donor-funded, development or humanitarian setting. Experience reading policies, reviewing transactions, preparing reports or working with risk registers is useful, but not essential. Participants should be comfortable using Microsoft Excel for simple tables and filters, as templates are completed during exercises. No prior COSO certification, accountancy qualification, audit software experience or advanced statistical sampling knowledge is required. Complete beginners should expect a structured introduction before progressing to practical control testing and reporting.

Training methodology

The five days combine short instructor-led COSO briefings with public-sector audit cases and structured working-paper exercises. Participants map a grant or government transaction process, identify risks and controls, conduct a simulated walkthrough, select evidence, draft test procedures and assess control deficiencies. Small groups compare judgments on issues such as delegated authority, partner advances and procurement approvals, then defend their conclusions as an audit team would. The final session converts the course templates into an individual application plan for a priority process in the participant’s organisation.

Course outline

Day 1: COSO foundations for public-sector accountability

  • Purpose and structure of the COSO Internal Control—Integrated Framework
  • The five COSO components and 17 principles
  • Public-sector accountability, stewardship and value-for-money obligations
  • Internal control versus internal audit, risk management and compliance
  • Control environment indicators: integrity, oversight, structure and competence
  • Roles of governing bodies, accounting officers, management and internal audit
  • Applying COSO to donor-funded and humanitarian operating models

Workshop: Participants diagnose the COSO component gaps in a case involving a government-funded emergency response programme and produce an initial control-environment assessment.

Day 2: Risk assessment and control design

  • Defining process objectives, risk appetite and control objectives
  • Risk identification for grants, procurement, cash, payroll and implementing partners
  • Fraud, corruption, conflict-of-interest and safeguarding control risks
  • Risk scoring using likelihood, impact and existing-control assessment
  • Preventive, detective, corrective and compensating control types
  • Segregation of duties, delegations of authority and approval limits
  • Constructing a COSO-aligned risk-and-control matrix

Workshop: Participants build a risk-and-control matrix for a partner cash-advance process, including risks, controls, owners, evidence and residual ratings.

Day 3: Documenting processes and testing controls

  • Process narratives, swimlane flowcharts and control-point identification
  • Walkthrough interviews and tracing a transaction from initiation to reporting
  • Evaluating control design against stated risks and objectives
  • Testing operating effectiveness through inspection, observation, inquiry and reperformance
  • Defining populations, sampling approaches and sample-selection rationale
  • Evidence quality, audit trails, system reports and document retention
  • Documenting test results in audit working papers

Workshop: Participants perform a simulated procurement walkthrough and produce a process map, control points, evidence list and draft test procedures.

Day 4: Monitoring, deficiencies and audit reporting

  • COSO monitoring activities and separate evaluations
  • Management self-assessments, reconciliations, exception reports and supervisory review
  • Identifying control deficiencies and distinguishing isolated errors from systemic weaknesses
  • Root-cause analysis using the five-whys method and cause categories
  • Assessing significance through impact, likelihood, pervasiveness and compensating controls
  • Writing evidence-based findings, risks, recommendations and agreed actions
  • Tracking remediation through action registers and follow-up testing

Workshop: Participants analyse a set of audit exceptions, classify the deficiencies, determine root causes and draft a prioritised management action plan.

Day 5: Integrated COSO audit application

  • Planning a risk-based COSO internal-control review
  • Scoping entities, processes, systems, locations and implementing partners
  • Linking audit objectives to COSO principles and control assertions
  • Coordinating internal audit, external audit, compliance and programme assurance
  • Communicating control conclusions to senior management and audit committees
  • Using Excel risk-and-control templates for review planning and reporting
  • Developing a 90-day internal-control improvement roadmap

Workshop: Participants complete and present a COSO application pack for a selected public-sector process, including a risk-control matrix, test plan, finding and 90-day action roadmap.

Tools & standards covered

COSO Internal Control—Integrated Framework (2013), INTOSAI GOV 9100 Guidelines for Internal Control Standards for the Public Sector, The IIA Global Internal Audit Standards (2024), Microsoft Excel

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No previous COSO training is required. The course starts with the framework, its components and its 17 principles, then moves into applied audit work; familiarity with organisational procedures or basic financial controls will help you progress faster.

A laptop with Microsoft Excel is strongly recommended because participants complete and adapt risk-and-control matrix and test-plan templates. No specialist audit software is needed, and all case materials are provided.

It is suitable for both assurance professionals and control owners. Finance, procurement, grants and programme staff gain a practical way to design and evidence controls, while auditors learn how to assess them consistently.

The course focuses specifically on the COSO internal-control framework and on testing whether controls are designed and operating effectively. Risk management and fraud are addressed where they affect control objectives, evidence, audit procedures and remediation.

Yes. The cases and templates cover grant conditions, advances, partner reporting, procurement approvals and field-level evidence. Participants can adapt the same COSO logic to a ministry, local authority, NGO, UN programme or partner-managed project.

You leave with a COSO-aligned risk-and-control matrix, process walkthrough template, control test plan, deficiency assessment structure and action-tracking approach. You will also complete an application pack for a selected process or realistic case during the final day.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Government & Public Sector

5 Days Certificate

Education Sector Planning for Government Education Agencies Training Course

Government education agencies must convert political commitments, learning data and fiscal limits into credible sector plans that guide annu…

5 Days Certificate

Justice Sector Court Administration and Caseflow Training Course

Court backlogs, adjournments, incomplete files, uneven courtroom utilisation and weak hearing-date control can erode public confidence and p…

5 Days Certificate

Theory of Change for Government Programme Design Training Course

Government programmes often move from political commitments and broad policy goals directly to activities, budgets and procurement plans wit…

5 Days Certificate

Advanced Government Crisis Management and Continuity Planning Training Course

Government agencies and public-sector partners must sustain essential services while making defensible decisions under severe uncertainty. A…