ERP Audit and Compliance for Internal Auditors Training Course
| Course code | SD-ES-021 |
|---|---|
| Duration | 10 days |
| Level | Intermediate |
| Category | ERP Systems |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Internal auditors are expected to assess ERP controls across financial close, procurement, inventory, payroll, user access and system change without relying solely on control narratives or IT specialists. The challenge is to determine whether configured workflows, approval rules, master-data controls, privileged access and system-generated reports actually prevent or detect material error, fraud and non-compliance. This course equips auditors to plan and execute defensible ERP audits that connect business risks to transactions, configuration settings, audit evidence and reportable findings.
Participants examine control design and operating effectiveness in SAP S/4HANA, Oracle Fusion Cloud ERP and Microsoft Dynamics 365 Finance environments. They learn to scope ERP audit engagements; build risk-and-control matrices; test segregation of duties; review identity and access management; assess change-management evidence; validate automated controls; test interfaces and data migrations; and use data analytics to identify duplicate payments, unusual journal entries, inactive vendors and approval overrides. The course also addresses COBIT 2019, IT general controls, key reports and audit documentation standards.
Delivery combines instructor-led technical briefings with realistic ERP audit files, configuration extracts, workflow evidence, user-access listings and transaction datasets. Participants work through an end-to-end audit case, make sampling and testing decisions, document exceptions and present findings to an audit committee audience. Each participant leaves with a tailored ERP Audit Workpaper Pack containing an audit universe, risk assessment, control matrix, test programmes, evidence requests, analytics procedures, issue-writing templates and a 90-day application plan for their own organisation.
Course objectives
By the end of this course, participants will be able to:
- Scope an ERP audit using a risk-based audit universe covering processes, modules, interfaces and third-party dependencies
- Build a risk-and-control matrix linking ERP business risks to configurable, automated and manual controls
- Test segregation-of-duties conflicts using role matrices, sensitive-access criteria and mitigating-control evidence
- Evaluate IT general controls for user provisioning, privileged access, change management, backups and incident handling
- Design audit procedures for automated workflow controls, approval tolerances, three-way matching and journal-entry controls
- Perform transaction analytics to identify duplicate payments, master-data anomalies, approval overrides and unusual journals
- Assess the reliability of ERP-generated reports used as audit evidence through report logic, parameters and completeness testing
- Produce an evidence-based ERP audit report with graded findings, root causes, agreed actions and management-ready recommendations
Benefits of attending
For you
- Gain a repeatable method for auditing ERP controls beyond narrative walkthroughs and policy reviews
- Build credibility with finance, technology and security stakeholders by discussing configuration, workflows and access risks precisely
- Create stronger audit workpapers for automated controls, ERP reports and system-generated evidence
- Develop practical analytics tests that can uncover payment, journal-entry and master-data anomalies
- Prepare for broader IT audit, ERP assurance and technology-risk responsibilities within internal audit
For your organisation
- Improve assurance over high-risk ERP processes including payments, financial close, purchasing and user access
- Identify segregation-of-duties conflicts and privileged-access exposure before they result in fraud or control failure
- Reduce inconsistent ERP audit practices through standard risk matrices, testing steps and evidence requirements
- Strengthen remediation decisions by separating configuration defects, operating failures and process-owner accountability
- Provide audit committees with clearer reporting on ERP control maturity, residual risk and corrective-action priorities
Target competencies
Who should attend
- Internal Auditors — who need to test ERP-enabled business controls and document findings that withstand challenge
- IT Auditors — who assess application controls and IT general controls across enterprise finance platforms
- Audit Managers — who oversee ERP assurance plans, engagement quality and reporting to audit committees
- Risk and Compliance Officers — who need to evaluate control ownership and regulatory exposure in ERP processes
- Finance Control Managers — who rely on ERP workflows and reports to maintain financial-control integrity
- ERP Governance or Security Analysts — who support access reviews, configuration assurance and remediation tracking
Requirements and prerequisites
Participants should have practical experience of internal audit, financial controls, IT audit or ERP process assurance. They should understand basic audit concepts including risk assessment, control objectives, walkthroughs, sampling, evidence and audit findings, plus common procure-to-pay, order-to-cash and record-to-report process steps. Familiarity with one ERP platform, such as SAP, Oracle or Microsoft Dynamics, is useful but not essential. Participants do not need programming skills, system-administrator access, prior certification in COBIT or CISA, or prior experience using data-analytics software. Exercises use guided datasets and templates rather than a live production system.
Training methodology
The course uses instructor-led workshops built around a simulated multinational ERP audit. Short technical sessions establish the control concepts, followed by hands-on review of role listings, workflow configurations, change tickets, audit logs, report extracts and transaction data. Participants work in audit teams to conduct walkthroughs, define test attributes, evaluate exceptions and challenge management responses. SAP, Oracle and Dynamics examples show how the same control objective appears across platforms. The final day is an audit-committee simulation and individual application-planning workshop using each participant’s ERP environment.
Course outline
Day 1: ERP audit foundations and engagement scoping
- ERP architecture, modules, databases and integration points
- Business-process risks in procure-to-pay, order-to-cash and record-to-report
- ERP audit universe development by process, module and legal entity
- Risk-based scoping of applications, interfaces, reports and customisations
- Control categories: preventive, detective, automated and manual
- The three-lines model and internal audit responsibilities for ERP assurance
- Engagement planning, materiality and audit objective definition
Workshop: Participants build an ERP audit universe and engagement scope for a company replacing its legacy finance system.
Day 2: Process walkthroughs and risk-control matrices
- Walkthrough planning with process owners and system administrators
- Documenting end-to-end transaction flows and control handoffs
- Risk-and-control matrix design for ERP-enabled processes
- Control objectives for completeness, accuracy, validity and authorisation
- Key control identification and reliance decisions
- Manual versus configurable control dependencies
- Control ownership, frequency and evidence requirements
Workshop: Participants conduct a procure-to-pay walkthrough and produce a completed risk-and-control matrix with key controls marked.
Day 3: IT general controls in ERP environments
- IT general controls and their relationship to application-control reliance
- Joiner-mover-leaver access provisioning controls
- Privileged-access management and emergency-access procedures
- Password, multifactor authentication and authentication-log evidence
- ERP change-management lifecycle from request through deployment
- Backup, recovery, batch scheduling and operational monitoring controls
- Incident management and problem-management evidence testing
Workshop: Participants test a sample of access and change-management records and write workpaper conclusions on IT general control effectiveness.
Day 4: Segregation of duties and user-access assurance
- Segregation-of-duties principles for finance and supply-chain transactions
- Role-based access control and ERP security-role design
- Toxic combinations in vendor maintenance, purchasing, payments and journals
- Sensitive-access criteria for configuration and master-data maintenance
- SAP S/4HANA role and authorisation review concepts
- Oracle Fusion Cloud ERP role hierarchy and data-access concepts
- Mitigating controls, compensating reviews and remediation tracking
Workshop: Participants analyse a user-role extract, identify toxic access combinations and create a remediation register with compensating controls.
Day 5: Automated business controls and configuration testing
- Configured workflow approvals and delegation controls
- Purchase-order approval thresholds and tolerance settings
- Three-way matching for purchase orders, goods receipts and invoices
- Duplicate-invoice prevention and payment-block controls
- Journal-entry approval, posting-period and reversal controls
- Vendor and customer master-data change controls
- Testing configuration evidence against stated control objectives
Workshop: Participants inspect configuration extracts and workflow evidence to design and perform tests of three automated procure-to-pay controls.
Day 6: ERP reports, interfaces and data migration risks
- Reliance on system-generated reports in internal audit
- Report completeness and accuracy testing using parameters and report logic
- Interface controls for inbound and outbound data feeds
- Batch totals, reconciliations and error-handling procedures
- Data migration risks during ERP implementation and upgrade projects
- Conversion reconciliation and data-cleansing evidence
- Custom reports, extensions and spreadsheet-dependent controls
Workshop: Participants test the reliability of an aged-payables report and identify control gaps in an interface reconciliation process.
Day 7: Audit analytics for ERP transactions
- Data-request specifications and field-level data validation
- Population completeness testing and record-count reconciliation
- Duplicate-payment detection using invoice, vendor and amount fields
- Benford analysis and outlier testing for journal entries
- Vendor-master analytics for bank-account and address anomalies
- Approval-override and after-hours transaction analysis
- Analytics documentation, reproducibility and evidence retention
Workshop: Participants run guided analytics on a payments and journal dataset and produce an exception log with investigation priorities.
Day 8: ERP governance, compliance and assurance mapping
- COBIT 2019 governance and management objectives for ERP assurance
- Mapping ERP controls to SOX-style financial reporting requirements
- Privacy, retention and audit-trail considerations for ERP data
- Third-party cloud ERP responsibilities and shared-responsibility models
- ERP implementation governance and project-assurance checkpoints
- Control self-assessments and continuous-control monitoring
- Coordinating work with external audit, security and compliance teams
Workshop: Participants map identified ERP controls to COBIT 2019 objectives and define assurance ownership across the three lines.
Day 9: Findings, remediation and audit reporting
- Distinguishing design deficiencies from operating-effectiveness failures
- Root-cause analysis using the five-whys method
- Risk rating based on likelihood, impact and control dependency
- Writing clear condition, criteria, cause, consequence and recommendation statements
- Evaluating management action plans for feasibility and control sustainability
- Issue ageing, validation testing and remediation closure
- Communicating ERP risk to executives and audit committees
Workshop: Participants draft, peer-review and prioritise three ERP audit findings from case evidence for an audit committee report.
Day 10: Integrated ERP audit simulation and application planning
- End-to-end audit planning from risk assessment to final report
- Evidence selection, sampling rationale and workpaper quality review
- Integrating access, configuration, interface and analytics results
- Professional challenge during management-response meetings
- Audit-committee presentation of significant ERP risks
- Ninety-day ERP audit implementation roadmap
- Personal ERP Audit Workpaper Pack finalisation
Workshop: Participants complete an integrated ERP audit case and present their findings, remediation priorities and 90-day application plan to a simulated audit committee.
Tools & standards covered
SAP S/4HANA, Oracle Fusion Cloud ERP, Microsoft Dynamics 365 Finance, COBIT 2019
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in ERP Systems
SAP Activate Implementation Methodology Training Course
SAP S/4HANA programmes lose time and control when teams treat implementation as a sequence of technical tasks rather than a managed business…
Epicor Kinetic Manufacturing Planning Training Course
Manufacturing planners using Epicor Kinetic must turn changing sales demand, inventory positions, supplier lead times and shop capacity into…
ERP Systems for Oil and Gas Maintenance Operations Training Course
Oil and gas maintenance organisations depend on accurate asset records, disciplined work management and timely materials availability to pro…
COBIT 2019 ERP Governance and Controls Training Course
ERP platforms concentrate high-value financial, customer, supply-chain and workforce data in a small number of business-critical processes. …