Financial Risk Assurance for Internal Auditors Training Course
| Course code | SD-RM-007 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Risk Management |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Internal auditors are expected to provide assurance that financial risks are identified, measured, controlled and reported before they affect liquidity, profitability, regulatory compliance or the reliability of financial statements. This requires more than checking whether a control exists. Auditors must test whether risk assessments reflect actual exposures, whether control owners understand residual risk, and whether management information supports timely decisions. This course equips internal audit professionals to examine the design and operating effectiveness of financial risk management arrangements across treasury, credit, market, liquidity, fraud and financial reporting processes.
Participants learn to convert enterprise risk information into risk-based audit work. They assess risk appetite and tolerance statements, map financial risk events to processes and controls, define audit criteria using COSO ERM and ISO 31000, and build practical risk-and-control matrices. The course covers control testing, data-led exception analysis, key risk indicators, scenario analysis, residual-risk evaluation and audit reporting. Participants also practise challenging management assumptions, distinguishing control failure from risk acceptance, and writing findings that specify the financial exposure, root cause, control gap and corrective action required.
Delivery combines instructor-led technical sessions with financial risk cases, audit-planning workshops and spreadsheet-based testing exercises. Participants work through a simulated organisation facing covenant pressure, overdue receivables, foreign-exchange exposure and weak journal-entry controls. By the end of the week, each participant produces a financial risk assurance audit pack: a risk universe, risk assessment, audit scope, risk-and-control matrix, testing plan, exception analysis and executive-level assurance report. The course is designed for intermediate auditors who need a repeatable method for providing credible assurance over finance risk management rather than undertaking financial statement audit work.
Course objectives
By the end of this course, participants will be able to:
- Assess financial risk frameworks against COSO ERM and ISO 31000 criteria
- Construct a finance-focused risk universe covering liquidity, credit, market, fraud and reporting risks
- Develop a risk-and-control matrix linking risk events, controls, owners, evidence and residual risk
- Design risk-based audit scopes using inherent risk, control maturity and materiality indicators
- Test the design and operating effectiveness of key financial controls
- Analyse financial data for control exceptions using Excel and CaseWare IDEA techniques
- Evaluate key risk indicators, risk appetite limits and management escalation thresholds
- Produce an executive assurance report with root causes, quantified exposure and actionable recommendations
Benefits of attending
For you
- Build a reusable approach for auditing financial risk management rather than reviewing controls in isolation
- Strengthen credibility when challenging finance leaders on risk appetite, residual risk and control evidence
- Create audit reports that quantify exposure and distinguish root causes from symptoms
- Gain practical experience using risk-and-control matrices and key risk indicators in finance audit assignments
- Prepare for broader senior audit, risk assurance or financial controls leadership responsibilities
For your organisation
- Improve the quality and consistency of assurance over liquidity, credit, market and financial reporting risks
- Identify control weaknesses before they create material misstatements, losses, covenant breaches or compliance failures
- Produce audit scopes that focus resources on high-exposure finance processes and weak control environments
- Give audit committees clearer reporting on residual risk, management action and unresolved financial exposures
- Establish more defensible evidence trails for financial risk governance and internal control assurance
Target competencies
Who should attend
- Internal Auditors — who need to assess whether finance risks and controls are managed effectively
- Senior Internal Auditors — who lead risk-based audits of treasury, receivables, reporting and finance operations
- Internal Audit Managers — who need consistent methods for scoping and reviewing financial risk assurance work
- Financial Controls Auditors — who test reconciliations, close processes, approvals and reporting controls
- Risk Assurance Specialists — who translate enterprise risk assessments into auditable control evidence
- Finance Risk Managers — who need to prepare defensible risk and control documentation for internal audit review
Requirements and prerequisites
Participants should have practical experience of internal audit, financial control testing or finance-process review, and should understand basic audit concepts such as audit evidence, control design, operating effectiveness, sampling and audit findings. Familiarity with core finance processes—accounts receivable, accounts payable, treasury, general ledger close or budgeting—is expected. Participants should be comfortable working with spreadsheets, including filters, formulas and pivot tables. Prior knowledge of COSO ERM, ISO 31000, statistical modelling, programming or specialist audit analytics software is not required; these are introduced and applied during the course.
Training methodology
The course uses short instructor-led briefings to establish the assurance method, followed by structured application to a running finance-risk case. Participants build risk-and-control matrices, assess risk appetite breaches, design control tests and analyse simulated transaction data in Excel and CaseWare IDEA. Small-group review panels challenge audit scope, evidence quality and proposed findings as an audit committee would. Daily exercises create components of an audit file, and the final session converts these into an individual application plan for a live or planned financial risk audit.
Course outline
Day 1: Financial Risk Assurance Foundations
- Financial risk categories in internal audit planning
- COSO ERM principles for assurance assessment
- ISO 31000 risk management process and audit criteria
- Risk appetite, tolerance and limit structures
- Three lines model and finance risk accountabilities
- Inherent risk, residual risk and control maturity
- Building a finance risk universe
Workshop: Participants map a simulated organisation's treasury, receivables, reporting and fraud exposures into a prioritised financial risk universe.
Day 2: Risk-Based Audit Design for Finance
- Materiality and financial exposure in audit scoping
- Risk-and-control matrix construction
- Preventive, detective and corrective financial controls
- Control objectives for treasury and cash management
- Credit risk controls over customer onboarding and collections
- Financial close and journal-entry control points
- Audit criteria, evidence sources and test procedures
Workshop: Participants develop a risk-and-control matrix and audit programme for a cash-to-collection process with deteriorating debtor balances.
Day 3: Testing Financial Controls and Data
- Design effectiveness versus operating effectiveness testing
- Walkthroughs, reperformance and inspection techniques
- Sampling approaches for financial control testing
- Excel pivot tables for exception identification
- CaseWare IDEA duplicate and gap testing
- Journal-entry analytics and unusual transaction indicators
- Evidence evaluation and working-paper documentation
Workshop: Participants test simulated payment and journal-entry data, document exceptions and prepare evidence-supported working-paper conclusions.
Day 4: Evaluating Risk Monitoring and Escalation
- Key risk indicator design and validation
- Liquidity risk metrics and covenant monitoring
- Foreign-exchange and interest-rate exposure controls
- Credit concentration and ageing analysis
- Scenario analysis and financial stress testing
- Risk limit breaches and management escalation
- Root-cause analysis using the five whys method
Workshop: Participants evaluate a finance dashboard, identify missed escalation triggers and perform root-cause analysis for a covenant-risk incident.
Day 5: Assurance Reporting and Audit Action Planning
- Quantifying financial risk in audit findings
- Writing condition, criteria, cause, consequence and recommendation statements
- Rating findings using impact and likelihood
- Assessing management action plans and due dates
- Communicating residual risk to audit committees
- Follow-up testing and issue closure evidence
- Building a financial risk assurance audit pack
Workshop: Participants present a completed financial risk assurance audit pack and executive report to a simulated audit committee review panel.
Tools & standards covered
Microsoft Excel, CaseWare IDEA, COSO Enterprise Risk Management Framework, ISO 31000:2018
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Nairobi · USD 3,000 -
21 – 25 Sep 2026Book
Mombasa · USD 3,200 -
28 Sep – 02 Oct 2026Book
Live Online · USD 1,500 -
28 Sep – 02 Oct 2026Book
Dubai · USD 4,500 -
05 – 09 Oct 2026Book
Nairobi · USD 3,000 -
05 – 09 Oct 2026Book
Live Online · USD 1,500 -
05 – 09 Oct 2026Book
Mombasa · USD 3,200 -
02 – 06 Nov 2026Book
Nairobi · USD 3,000
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Risk Management
Financial Risk Management Fundamentals for Finance Professionals Training Course
Finance professionals are routinely asked to explain how interest-rate movements, foreign-exchange exposure, borrower default, liquidity pre…
Advanced Counterparty Risk Analytics and Wrong-Way Risk Training Course
Counterparty exposure can appear controlled under normal market conditions while becoming concentrated precisely when a counterparty is leas…
Banking Risk Management for Commercial Banks Training Course
Commercial banks face risk decisions that cannot be managed through policy documents alone. Credit deterioration, liquidity pressure, intere…
Palisade @RISK Monte Carlo Simulation for Financial Risk Training Course
Financial forecasts, valuations, capital proposals and budget models often present a single “base case” result while the underlying inputs—s…