Internal Auditing for Banking Professionals Training Course
| Course code | SD-A-036 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Auditing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Bank internal audit functions are expected to provide credible, evidence-based assurance over credit, treasury, operations, technology, conduct, financial crime controls and regulatory obligations. Auditors must test whether controls operate effectively, identify root causes rather than isolated exceptions, and report issues in terms that senior management, risk committees and regulators can act on. This course addresses the practical challenge of planning and executing risk-based audits in a regulated banking environment while maintaining independence, professional scepticism and a defensible audit trail.
Participants work through the full internal audit cycle for banking activities: translating the audit universe into a risk-based plan; scoping an engagement; mapping processes, risks and controls; designing walkthroughs and test procedures; selecting samples; evaluating control design and operating effectiveness; documenting working papers; and grading findings. The programme covers banking-specific risk themes including credit underwriting, loan monitoring, liquidity, payments, AML/CFT, operational resilience, model risk and regulatory reporting. Participants learn to use risk-control matrices, audit programmes, issue-rating criteria, root-cause analysis and management action tracking.
Delivery combines instructor-led technical sessions with practical audit-file workshops built around realistic bank scenarios. Teams review loan files, payment exceptions, access-control evidence and remediation plans; challenge control owners; and draft audit observations for an audit committee audience. Each participant leaves with a reusable banking internal audit toolkit containing an engagement planning pack, risk-control matrix, testing template, sample working paper, issue write-up and 90-day application plan.
The course is designed for experienced internal auditors and banking risk, compliance or control professionals moving into assurance roles. It also suits audit managers seeking a more consistent approach to risk assessment, audit evidence, reporting and follow-up across their teams.
Course objectives
By the end of this course, participants will be able to:
- Develop a risk-based audit plan using a banking audit universe, inherent-risk assessment and assurance coverage map
- Scope a banking audit engagement by defining objectives, risks, control boundaries, materiality considerations and resource requirements
- Construct a risk-control matrix for a credit, payments, AML/CFT or treasury process
- Perform walkthroughs and document process narratives, control owners, evidence sources and control gaps
- Design control tests for design effectiveness and operating effectiveness, including sampling criteria and expected evidence
- Evaluate audit evidence and produce review-ready working papers that support a defensible audit conclusion
- Write graded audit findings using condition, criteria, cause, consequence, risk rating and agreed management action
- Build an issue follow-up tracker that tests remediation evidence and escalates overdue or ineffective actions
Benefits of attending
For you
- Gain a repeatable method for leading banking audit engagements from annual planning through remediation follow-up
- Produce clearer risk-control matrices and test plans that withstand manager, quality assurance and regulator scrutiny
- Build credibility when challenging credit, operations, treasury and compliance control owners with evidence-based observations
- Strengthen readiness for senior internal auditor, audit manager, assurance or risk advisory responsibilities
- Learn to communicate control failures in business-risk language suitable for executive management and audit committees
For your organisation
- Improve consistency of audit scoping, testing documentation and issue ratings across banking audit assignments
- Reduce the risk of missed control failures in high-exposure areas such as lending, payments, AML/CFT and access management
- Create more actionable audit reports by linking findings to root causes, customer impact, regulatory exposure and ownership
- Increase the quality of remediation validation so closed issues are supported by evidence rather than management assertion
- Strengthen audit committee assurance through clearer risk coverage, defensible conclusions and transparent escalation
Target competencies
Who should attend
- Internal Auditors — who need to plan and deliver risk-based audits across banking products, processes and control functions
- Internal Audit Managers — who must improve engagement quality, evidence standards and reporting consistency across audit teams
- Risk Managers — who move into second- or third-line assurance roles and need to test control effectiveness
- Compliance Officers — who need to assess regulatory control frameworks and prepare evidence for internal audit review
- Operational Risk Professionals — who need to audit incident management, RCSA, resilience and control remediation processes
- Credit, Operations or Treasury Control Managers — who need to understand how auditors assess their controls and evidence
Requirements and prerequisites
Participants should have practical exposure to banking operations, risk, compliance, finance control or internal audit, and be comfortable reading process documents, policies, management information and transaction records. Familiarity with the three lines model, key banking risks, basic control concepts, and spreadsheet use is assumed. Prior experience of leading an audit is helpful but not essential. Participants do not need accounting qualifications, data-science skills, specialist audit software licences or prior knowledge of every banking product. Those new to internal audit should expect a demanding programme and should first understand their bank’s governance structure and core processes.
Training methodology
The programme uses instructor-led briefings to establish standards and methods, followed by progressive workshops built around a simulated bank. Participants map a lending or payments process, create a risk-control matrix, conduct a walkthrough from supplied evidence, design sample-based tests and assess exceptions. Small groups calibrate risk ratings and challenge draft findings as audit managers would. The final day uses an audit committee reporting simulation and individual application planning, enabling each participant to adapt the templates and techniques to a live audit area in their own institution.
Course outline
Day 1: Bank Internal Audit Foundations and Risk-Based Planning
- The internal audit mandate, independence and objectivity in a bank
- IIA Global Internal Audit Standards and engagement-level quality requirements
- Three lines model and coordination with risk, compliance and external audit
- Banking audit universe design across products, legal entities and control functions
- Inherent risk, residual risk and assurance coverage assessment
- Annual audit planning criteria, prioritisation and resource allocation
- Engagement scoping using objectives, boundaries, risks and materiality
Workshop: Participants build a risk-ranked audit universe and prepare a one-page engagement planning memorandum for a selected banking process.
Day 2: Process Understanding, Risk Assessment and Control Design
- End-to-end process mapping for lending, payments and customer onboarding
- Walkthrough techniques and interview questions for control owners
- Risk and control taxonomy for credit, liquidity, operational, conduct and financial crime risk
- Risk-control matrix construction and control objective definition
- Preventive, detective, manual, automated and IT-dependent controls
- Control design effectiveness criteria and segregation-of-duties analysis
- Regulatory obligations as audit criteria, including Basel governance expectations
Workshop: Teams conduct a simulated loan-origination walkthrough and produce a process map and risk-control matrix with identified design gaps.
Day 3: Audit Testing, Sampling and Working Papers
- Translating control objectives into audit procedures and test steps
- Testing design effectiveness versus operating effectiveness
- Population definition, sampling approaches and sample-size rationale
- Inspection, observation, inquiry, reperformance and data-analytics evidence
- Testing loan approvals, covenant monitoring and collateral controls
- Testing payment authorisation, exception handling and user-access controls
- Working paper structure, cross-referencing, review notes and audit trail standards
Workshop: Participants test a supplied sample of loan and payment records, document exceptions and complete a review-ready audit working paper.
Day 4: Findings, Root Causes and Remediation Assurance
- Exception evaluation and aggregation of control test results
- Condition, criteria, cause, consequence and recommendation writing method
- Root-cause analysis using the five whys and cause-and-effect mapping
- Risk rating models based on impact, likelihood, control weakness and regulatory exposure
- Management action design, ownership, due dates and success measures
- Challenge meetings with auditees and handling disputed findings
- Issue follow-up testing and validation of remediation effectiveness
Workshop: Participants convert test exceptions into a graded audit finding, conduct a root-cause workshop and create an evidence-based remediation tracker.
Day 5: Reporting, Governance and Applied Audit Leadership
- Executive audit report structure and concise assurance conclusions
- Audit committee reporting for themes, trends and overdue high-risk issues
- Communicating credit, AML/CFT, operational resilience and technology control risks
- Quality assurance reviews and common audit-file deficiencies
- Fraud indicators, professional scepticism and escalation responsibilities
- Using Microsoft Excel to analyse exceptions, ageing and remediation status
- Ninety-day action planning for a live banking audit assignment
Workshop: Participants present an audit committee briefing based on their case file and complete a personal 90-day plan for applying the course toolkit.
Tools & standards covered
IIA Global Internal Audit Standards, COSO Internal Control—Integrated Framework, Basel Committee Corporate Governance Principles for Banks, Microsoft Excel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Nairobi · USD 3,000 -
28 Sep – 02 Oct 2026Book
Nairobi · USD 3,000 -
05 – 09 Oct 2026Book
Dubai · USD 4,500 -
05 – 09 Oct 2026Book
Live Online · USD 1,500 -
05 – 09 Oct 2026Book
Nairobi · USD 3,000 -
12 – 16 Oct 2026Book
Live Online · USD 1,500 -
19 – 23 Oct 2026Book
Live Online · USD 1,500 -
26 – 30 Oct 2026Book
Cape Town · USD 4,200
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Auditing
Advanced Forensic Audit Investigation and Interviewing Training Course
Suspected fraud, financial misconduct, and control override require more than routine audit testing. Investigators must turn an allegation, …
Healthcare Compliance Auditing Training Course
Healthcare organisations face overlapping audit pressures: inaccurate claims, unsupported charges, duplicate payments, weak vendor controls,…
Auditing Fundamentals for Finance Professionals Training Course
Finance professionals are frequently expected to provide assurance over account balances, reconciliations, controls, and management reports …
Advanced Audit Planning and Evidence Evaluation Training Course
Audit teams are increasingly expected to justify why each planned procedure addresses a defined risk, how evidence supports the audit conclu…