ERP Audit and Compliance for Internal Auditors Training Course

10 days ERP Systems Certificate on completion
Course codeSD-ES-021
Duration10 days
LevelIntermediate
CategoryERP Systems
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Internal auditors are expected to assess ERP controls across financial close, procurement, inventory, payroll, user access and system change without relying solely on control narratives or IT specialists. The challenge is to determine whether configured workflows, approval rules, master-data controls, privileged access and system-generated reports actually prevent or detect material error, fraud and non-compliance. This course equips auditors to plan and execute defensible ERP audits that connect business risks to transactions, configuration settings, audit evidence and reportable findings.

Participants examine control design and operating effectiveness in SAP S/4HANA, Oracle Fusion Cloud ERP and Microsoft Dynamics 365 Finance environments. They learn to scope ERP audit engagements; build risk-and-control matrices; test segregation of duties; review identity and access management; assess change-management evidence; validate automated controls; test interfaces and data migrations; and use data analytics to identify duplicate payments, unusual journal entries, inactive vendors and approval overrides. The course also addresses COBIT 2019, IT general controls, key reports and audit documentation standards.

Delivery combines instructor-led technical briefings with realistic ERP audit files, configuration extracts, workflow evidence, user-access listings and transaction datasets. Participants work through an end-to-end audit case, make sampling and testing decisions, document exceptions and present findings to an audit committee audience. Each participant leaves with a tailored ERP Audit Workpaper Pack containing an audit universe, risk assessment, control matrix, test programmes, evidence requests, analytics procedures, issue-writing templates and a 90-day application plan for their own organisation.

Course objectives

By the end of this course, participants will be able to:

  • Scope an ERP audit using a risk-based audit universe covering processes, modules, interfaces and third-party dependencies
  • Build a risk-and-control matrix linking ERP business risks to configurable, automated and manual controls
  • Test segregation-of-duties conflicts using role matrices, sensitive-access criteria and mitigating-control evidence
  • Evaluate IT general controls for user provisioning, privileged access, change management, backups and incident handling
  • Design audit procedures for automated workflow controls, approval tolerances, three-way matching and journal-entry controls
  • Perform transaction analytics to identify duplicate payments, master-data anomalies, approval overrides and unusual journals
  • Assess the reliability of ERP-generated reports used as audit evidence through report logic, parameters and completeness testing
  • Produce an evidence-based ERP audit report with graded findings, root causes, agreed actions and management-ready recommendations

Benefits of attending

For you

  • Gain a repeatable method for auditing ERP controls beyond narrative walkthroughs and policy reviews
  • Build credibility with finance, technology and security stakeholders by discussing configuration, workflows and access risks precisely
  • Create stronger audit workpapers for automated controls, ERP reports and system-generated evidence
  • Develop practical analytics tests that can uncover payment, journal-entry and master-data anomalies
  • Prepare for broader IT audit, ERP assurance and technology-risk responsibilities within internal audit

For your organisation

  • Improve assurance over high-risk ERP processes including payments, financial close, purchasing and user access
  • Identify segregation-of-duties conflicts and privileged-access exposure before they result in fraud or control failure
  • Reduce inconsistent ERP audit practices through standard risk matrices, testing steps and evidence requirements
  • Strengthen remediation decisions by separating configuration defects, operating failures and process-owner accountability
  • Provide audit committees with clearer reporting on ERP control maturity, residual risk and corrective-action priorities

Target competencies

ERP risk assessmentAccess control testingAutomated control assuranceAudit data analyticsConfiguration evidence reviewFinding remediation design

Who should attend

  • Internal Auditors — who need to test ERP-enabled business controls and document findings that withstand challenge
  • IT Auditors — who assess application controls and IT general controls across enterprise finance platforms
  • Audit Managers — who oversee ERP assurance plans, engagement quality and reporting to audit committees
  • Risk and Compliance Officers — who need to evaluate control ownership and regulatory exposure in ERP processes
  • Finance Control Managers — who rely on ERP workflows and reports to maintain financial-control integrity
  • ERP Governance or Security Analysts — who support access reviews, configuration assurance and remediation tracking

Requirements and prerequisites

Participants should have practical experience of internal audit, financial controls, IT audit or ERP process assurance. They should understand basic audit concepts including risk assessment, control objectives, walkthroughs, sampling, evidence and audit findings, plus common procure-to-pay, order-to-cash and record-to-report process steps. Familiarity with one ERP platform, such as SAP, Oracle or Microsoft Dynamics, is useful but not essential. Participants do not need programming skills, system-administrator access, prior certification in COBIT or CISA, or prior experience using data-analytics software. Exercises use guided datasets and templates rather than a live production system.

Training methodology

The course uses instructor-led workshops built around a simulated multinational ERP audit. Short technical sessions establish the control concepts, followed by hands-on review of role listings, workflow configurations, change tickets, audit logs, report extracts and transaction data. Participants work in audit teams to conduct walkthroughs, define test attributes, evaluate exceptions and challenge management responses. SAP, Oracle and Dynamics examples show how the same control objective appears across platforms. The final day is an audit-committee simulation and individual application-planning workshop using each participant’s ERP environment.

Course outline

Day 1: ERP audit foundations and engagement scoping

  • ERP architecture, modules, databases and integration points
  • Business-process risks in procure-to-pay, order-to-cash and record-to-report
  • ERP audit universe development by process, module and legal entity
  • Risk-based scoping of applications, interfaces, reports and customisations
  • Control categories: preventive, detective, automated and manual
  • The three-lines model and internal audit responsibilities for ERP assurance
  • Engagement planning, materiality and audit objective definition

Workshop: Participants build an ERP audit universe and engagement scope for a company replacing its legacy finance system.

Day 2: Process walkthroughs and risk-control matrices

  • Walkthrough planning with process owners and system administrators
  • Documenting end-to-end transaction flows and control handoffs
  • Risk-and-control matrix design for ERP-enabled processes
  • Control objectives for completeness, accuracy, validity and authorisation
  • Key control identification and reliance decisions
  • Manual versus configurable control dependencies
  • Control ownership, frequency and evidence requirements

Workshop: Participants conduct a procure-to-pay walkthrough and produce a completed risk-and-control matrix with key controls marked.

Day 3: IT general controls in ERP environments

  • IT general controls and their relationship to application-control reliance
  • Joiner-mover-leaver access provisioning controls
  • Privileged-access management and emergency-access procedures
  • Password, multifactor authentication and authentication-log evidence
  • ERP change-management lifecycle from request through deployment
  • Backup, recovery, batch scheduling and operational monitoring controls
  • Incident management and problem-management evidence testing

Workshop: Participants test a sample of access and change-management records and write workpaper conclusions on IT general control effectiveness.

Day 4: Segregation of duties and user-access assurance

  • Segregation-of-duties principles for finance and supply-chain transactions
  • Role-based access control and ERP security-role design
  • Toxic combinations in vendor maintenance, purchasing, payments and journals
  • Sensitive-access criteria for configuration and master-data maintenance
  • SAP S/4HANA role and authorisation review concepts
  • Oracle Fusion Cloud ERP role hierarchy and data-access concepts
  • Mitigating controls, compensating reviews and remediation tracking

Workshop: Participants analyse a user-role extract, identify toxic access combinations and create a remediation register with compensating controls.

Day 5: Automated business controls and configuration testing

  • Configured workflow approvals and delegation controls
  • Purchase-order approval thresholds and tolerance settings
  • Three-way matching for purchase orders, goods receipts and invoices
  • Duplicate-invoice prevention and payment-block controls
  • Journal-entry approval, posting-period and reversal controls
  • Vendor and customer master-data change controls
  • Testing configuration evidence against stated control objectives

Workshop: Participants inspect configuration extracts and workflow evidence to design and perform tests of three automated procure-to-pay controls.

Day 6: ERP reports, interfaces and data migration risks

  • Reliance on system-generated reports in internal audit
  • Report completeness and accuracy testing using parameters and report logic
  • Interface controls for inbound and outbound data feeds
  • Batch totals, reconciliations and error-handling procedures
  • Data migration risks during ERP implementation and upgrade projects
  • Conversion reconciliation and data-cleansing evidence
  • Custom reports, extensions and spreadsheet-dependent controls

Workshop: Participants test the reliability of an aged-payables report and identify control gaps in an interface reconciliation process.

Day 7: Audit analytics for ERP transactions

  • Data-request specifications and field-level data validation
  • Population completeness testing and record-count reconciliation
  • Duplicate-payment detection using invoice, vendor and amount fields
  • Benford analysis and outlier testing for journal entries
  • Vendor-master analytics for bank-account and address anomalies
  • Approval-override and after-hours transaction analysis
  • Analytics documentation, reproducibility and evidence retention

Workshop: Participants run guided analytics on a payments and journal dataset and produce an exception log with investigation priorities.

Day 8: ERP governance, compliance and assurance mapping

  • COBIT 2019 governance and management objectives for ERP assurance
  • Mapping ERP controls to SOX-style financial reporting requirements
  • Privacy, retention and audit-trail considerations for ERP data
  • Third-party cloud ERP responsibilities and shared-responsibility models
  • ERP implementation governance and project-assurance checkpoints
  • Control self-assessments and continuous-control monitoring
  • Coordinating work with external audit, security and compliance teams

Workshop: Participants map identified ERP controls to COBIT 2019 objectives and define assurance ownership across the three lines.

Day 9: Findings, remediation and audit reporting

  • Distinguishing design deficiencies from operating-effectiveness failures
  • Root-cause analysis using the five-whys method
  • Risk rating based on likelihood, impact and control dependency
  • Writing clear condition, criteria, cause, consequence and recommendation statements
  • Evaluating management action plans for feasibility and control sustainability
  • Issue ageing, validation testing and remediation closure
  • Communicating ERP risk to executives and audit committees

Workshop: Participants draft, peer-review and prioritise three ERP audit findings from case evidence for an audit committee report.

Day 10: Integrated ERP audit simulation and application planning

  • End-to-end audit planning from risk assessment to final report
  • Evidence selection, sampling rationale and workpaper quality review
  • Integrating access, configuration, interface and analytics results
  • Professional challenge during management-response meetings
  • Audit-committee presentation of significant ERP risks
  • Ninety-day ERP audit implementation roadmap
  • Personal ERP Audit Workpaper Pack finalisation

Workshop: Participants complete an integrated ERP audit case and present their findings, remediation priorities and 90-day application plan to a simulated audit committee.

Tools & standards covered

SAP S/4HANA, Oracle Fusion Cloud ERP, Microsoft Dynamics 365 Finance, COBIT 2019

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You need working knowledge of audit and control concepts, plus familiarity with common finance or operational processes such as purchasing, payments or financial close. Prior hands-on use of SAP, Oracle or Dynamics is helpful but not required; the course explains platform-specific examples in an auditor-focused way.

A laptop is recommended for the data-analysis exercises and completion of the audit templates. You do not need access to your organisation’s ERP system, administrator credentials or production data because guided datasets, extracts and workpapers are provided.

It is designed primarily for internal auditors, IT auditors and audit managers who must assess ERP risk and controls. Technical administrators can benefit, but the emphasis is on audit planning, evidence evaluation, testing and reporting rather than system configuration administration.

General IT audit courses typically cover controls across many technology environments, while this course focuses on how ERP transactions, roles, workflows, reports, interfaces and configurations affect audit conclusions. COBIT 2019 is used as an assurance framework, but participants spend substantial time testing ERP-specific evidence and cases.

You can use the risk-and-control matrix, access-review steps, automated-control test programmes and analytics procedures directly when planning an ERP engagement. The course also shows how to request usable evidence from finance, IT and ERP support teams and how to translate results into actionable findings.

Participants leave with a tailored ERP Audit Workpaper Pack containing audit-universe templates, risk matrices, walkthrough guides, access-review procedures, configuration test steps, analytics tests, finding templates and a 90-day action plan. These materials are designed to be adapted to SAP, Oracle Fusion Cloud ERP or Microsoft Dynamics 365 Finance environments.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in ERP Systems

10 Days Certificate

SAP Activate Implementation Methodology Training Course

SAP S/4HANA programmes lose time and control when teams treat implementation as a sequence of technical tasks rather than a managed business…

5 Days Certificate

Epicor Kinetic Manufacturing Planning Training Course

Manufacturing planners using Epicor Kinetic must turn changing sales demand, inventory positions, supplier lead times and shop capacity into…

5 Days Certificate

ERP Systems for Oil and Gas Maintenance Operations Training Course

Oil and gas maintenance organisations depend on accurate asset records, disciplined work management and timely materials availability to pro…

5 Days Certificate

COBIT 2019 ERP Governance and Controls Training Course

ERP platforms concentrate high-value financial, customer, supply-chain and workforce data in a small number of business-critical processes. …