Financial Risk Assurance for Internal Auditors Training Course

5 days Risk Management Certificate on completion
Course codeSD-RM-007
Duration5 days
LevelIntermediate
CategoryRisk Management
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Internal auditors are expected to provide assurance that financial risks are identified, measured, controlled and reported before they affect liquidity, profitability, regulatory compliance or the reliability of financial statements. This requires more than checking whether a control exists. Auditors must test whether risk assessments reflect actual exposures, whether control owners understand residual risk, and whether management information supports timely decisions. This course equips internal audit professionals to examine the design and operating effectiveness of financial risk management arrangements across treasury, credit, market, liquidity, fraud and financial reporting processes.

Participants learn to convert enterprise risk information into risk-based audit work. They assess risk appetite and tolerance statements, map financial risk events to processes and controls, define audit criteria using COSO ERM and ISO 31000, and build practical risk-and-control matrices. The course covers control testing, data-led exception analysis, key risk indicators, scenario analysis, residual-risk evaluation and audit reporting. Participants also practise challenging management assumptions, distinguishing control failure from risk acceptance, and writing findings that specify the financial exposure, root cause, control gap and corrective action required.

Delivery combines instructor-led technical sessions with financial risk cases, audit-planning workshops and spreadsheet-based testing exercises. Participants work through a simulated organisation facing covenant pressure, overdue receivables, foreign-exchange exposure and weak journal-entry controls. By the end of the week, each participant produces a financial risk assurance audit pack: a risk universe, risk assessment, audit scope, risk-and-control matrix, testing plan, exception analysis and executive-level assurance report. The course is designed for intermediate auditors who need a repeatable method for providing credible assurance over finance risk management rather than undertaking financial statement audit work.

Course objectives

By the end of this course, participants will be able to:

  • Assess financial risk frameworks against COSO ERM and ISO 31000 criteria
  • Construct a finance-focused risk universe covering liquidity, credit, market, fraud and reporting risks
  • Develop a risk-and-control matrix linking risk events, controls, owners, evidence and residual risk
  • Design risk-based audit scopes using inherent risk, control maturity and materiality indicators
  • Test the design and operating effectiveness of key financial controls
  • Analyse financial data for control exceptions using Excel and CaseWare IDEA techniques
  • Evaluate key risk indicators, risk appetite limits and management escalation thresholds
  • Produce an executive assurance report with root causes, quantified exposure and actionable recommendations

Benefits of attending

For you

  • Build a reusable approach for auditing financial risk management rather than reviewing controls in isolation
  • Strengthen credibility when challenging finance leaders on risk appetite, residual risk and control evidence
  • Create audit reports that quantify exposure and distinguish root causes from symptoms
  • Gain practical experience using risk-and-control matrices and key risk indicators in finance audit assignments
  • Prepare for broader senior audit, risk assurance or financial controls leadership responsibilities

For your organisation

  • Improve the quality and consistency of assurance over liquidity, credit, market and financial reporting risks
  • Identify control weaknesses before they create material misstatements, losses, covenant breaches or compliance failures
  • Produce audit scopes that focus resources on high-exposure finance processes and weak control environments
  • Give audit committees clearer reporting on residual risk, management action and unresolved financial exposures
  • Establish more defensible evidence trails for financial risk governance and internal control assurance

Target competencies

Financial risk assessmentControl effectiveness testingRisk-control mappingAudit data analyticsResidual risk evaluationAssurance reporting

Who should attend

  • Internal Auditors — who need to assess whether finance risks and controls are managed effectively
  • Senior Internal Auditors — who lead risk-based audits of treasury, receivables, reporting and finance operations
  • Internal Audit Managers — who need consistent methods for scoping and reviewing financial risk assurance work
  • Financial Controls Auditors — who test reconciliations, close processes, approvals and reporting controls
  • Risk Assurance Specialists — who translate enterprise risk assessments into auditable control evidence
  • Finance Risk Managers — who need to prepare defensible risk and control documentation for internal audit review

Requirements and prerequisites

Participants should have practical experience of internal audit, financial control testing or finance-process review, and should understand basic audit concepts such as audit evidence, control design, operating effectiveness, sampling and audit findings. Familiarity with core finance processes—accounts receivable, accounts payable, treasury, general ledger close or budgeting—is expected. Participants should be comfortable working with spreadsheets, including filters, formulas and pivot tables. Prior knowledge of COSO ERM, ISO 31000, statistical modelling, programming or specialist audit analytics software is not required; these are introduced and applied during the course.

Training methodology

The course uses short instructor-led briefings to establish the assurance method, followed by structured application to a running finance-risk case. Participants build risk-and-control matrices, assess risk appetite breaches, design control tests and analyse simulated transaction data in Excel and CaseWare IDEA. Small-group review panels challenge audit scope, evidence quality and proposed findings as an audit committee would. Daily exercises create components of an audit file, and the final session converts these into an individual application plan for a live or planned financial risk audit.

Course outline

Day 1: Financial Risk Assurance Foundations

  • Financial risk categories in internal audit planning
  • COSO ERM principles for assurance assessment
  • ISO 31000 risk management process and audit criteria
  • Risk appetite, tolerance and limit structures
  • Three lines model and finance risk accountabilities
  • Inherent risk, residual risk and control maturity
  • Building a finance risk universe

Workshop: Participants map a simulated organisation's treasury, receivables, reporting and fraud exposures into a prioritised financial risk universe.

Day 2: Risk-Based Audit Design for Finance

  • Materiality and financial exposure in audit scoping
  • Risk-and-control matrix construction
  • Preventive, detective and corrective financial controls
  • Control objectives for treasury and cash management
  • Credit risk controls over customer onboarding and collections
  • Financial close and journal-entry control points
  • Audit criteria, evidence sources and test procedures

Workshop: Participants develop a risk-and-control matrix and audit programme for a cash-to-collection process with deteriorating debtor balances.

Day 3: Testing Financial Controls and Data

  • Design effectiveness versus operating effectiveness testing
  • Walkthroughs, reperformance and inspection techniques
  • Sampling approaches for financial control testing
  • Excel pivot tables for exception identification
  • CaseWare IDEA duplicate and gap testing
  • Journal-entry analytics and unusual transaction indicators
  • Evidence evaluation and working-paper documentation

Workshop: Participants test simulated payment and journal-entry data, document exceptions and prepare evidence-supported working-paper conclusions.

Day 4: Evaluating Risk Monitoring and Escalation

  • Key risk indicator design and validation
  • Liquidity risk metrics and covenant monitoring
  • Foreign-exchange and interest-rate exposure controls
  • Credit concentration and ageing analysis
  • Scenario analysis and financial stress testing
  • Risk limit breaches and management escalation
  • Root-cause analysis using the five whys method

Workshop: Participants evaluate a finance dashboard, identify missed escalation triggers and perform root-cause analysis for a covenant-risk incident.

Day 5: Assurance Reporting and Audit Action Planning

  • Quantifying financial risk in audit findings
  • Writing condition, criteria, cause, consequence and recommendation statements
  • Rating findings using impact and likelihood
  • Assessing management action plans and due dates
  • Communicating residual risk to audit committees
  • Follow-up testing and issue closure evidence
  • Building a financial risk assurance audit pack

Workshop: Participants present a completed financial risk assurance audit pack and executive report to a simulated audit committee review panel.

Tools & standards covered

Microsoft Excel, CaseWare IDEA, COSO Enterprise Risk Management Framework, ISO 31000:2018

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand basic internal audit concepts and have some exposure to finance processes or financial control reviews. You do not need prior experience in treasury, quantitative risk modelling or specialist audit analytics software.

A laptop with Microsoft Excel is strongly recommended for the data-analysis exercises. CaseWare IDEA techniques are demonstrated through provided course materials, so participants do not need an existing licence or installation.

The course is designed primarily for internal auditors providing assurance over management's financial risk arrangements. External auditors may benefit from the control-testing content, but the emphasis is on risk governance, residual risk and internal audit reporting rather than financial statement audit opinions.

This course concentrates on how internal audit evaluates and tests financial risk management in operational finance, treasury and reporting processes. General risk courses usually focus on risk ownership and risk registers rather than audit criteria, testing evidence, exception analysis and assurance reporting.

The risk universe, risk-and-control matrix, audit programme and reporting structures can be adapted directly to receivables, cash management, financial close, payroll or expense audits. Participants leave with a practical method for prioritising exposure, selecting tests and documenting conclusions.

You will complete a financial risk assurance audit pack containing a risk assessment, audit scope, risk-and-control matrix, test plan, exception analysis and executive report. You will also prepare an application plan identifying a finance-risk audit or control review to undertake after the course.

Upcoming sessions

  • 21 – 25 Sep 2026
    Nairobi · USD 3,000
    Book
  • 21 – 25 Sep 2026
    Mombasa · USD 3,200
    Book
  • 28 Sep – 02 Oct 2026
    Live Online · USD 1,500
    Book
  • 28 Sep – 02 Oct 2026
    Dubai · USD 4,500
    Book
  • 05 – 09 Oct 2026
    Nairobi · USD 3,000
    Book
  • 05 – 09 Oct 2026
    Live Online · USD 1,500
    Book
  • 05 – 09 Oct 2026
    Mombasa · USD 3,200
    Book
  • 02 – 06 Nov 2026
    Nairobi · USD 3,000
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Risk Management

5 Days Certificate

Financial Risk Management Fundamentals for Finance Professionals Training Course

Finance professionals are routinely asked to explain how interest-rate movements, foreign-exchange exposure, borrower default, liquidity pre…

5 Days Certificate

Advanced Counterparty Risk Analytics and Wrong-Way Risk Training Course

Counterparty exposure can appear controlled under normal market conditions while becoming concentrated precisely when a counterparty is leas…

5 Days Certificate

Banking Risk Management for Commercial Banks Training Course

Commercial banks face risk decisions that cannot be managed through policy documents alone. Credit deterioration, liquidity pressure, intere…

5 Days Certificate

Palisade @RISK Monte Carlo Simulation for Financial Risk Training Course

Financial forecasts, valuations, capital proposals and budget models often present a single “base case” result while the underlying inputs—s…