IT Controls Testing for Internal Auditors Training Course
| Course code | SD-IT-027 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Information Technology |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Internal auditors are increasingly expected to provide assurance over access management, change control, IT operations, cloud services and automated business processes—not simply confirm that policy documents exist. This requires auditors to translate technology risks into testable control objectives, obtain reliable evidence from system owners, and distinguish a design weakness from an operating failure. Without a structured testing approach, audit teams can over-rely on walkthroughs, request excessive evidence, miss control dependencies, or report findings that technology management cannot action.
This five-day course equips internal auditors to plan, perform and report IT controls testing across common technology environments. Participants practise scoping an IT audit, mapping risks to controls, assessing control design, selecting samples, testing operating effectiveness and documenting evidence. The course covers general IT controls (ITGCs), including user access, privileged access, change management, backup and recovery, job scheduling and incident management, alongside automated application controls, interface controls and key report controls. Participants also use COBIT 2019 and NIST SP 800-53 as practical sources for control criteria, and build working papers that support clear audit conclusions.
Delivery combines instructor-led technical sessions with realistic audit files, evidence packs, walkthrough scenarios and team-based testing workshops. Participants review access listings, change tickets, audit logs, configuration extracts and exception reports; identify deficiencies; and draft concise findings with cause, risk, recommendation and management action. Each participant leaves with an IT controls test programme, evidence request list, sample-selection rationale and reporting template that can be adapted for a live audit assignment. The course is particularly suited to auditors who need to challenge technology controls credibly while maintaining a risk-based, business-focused audit approach.
Course objectives
By the end of this course, participants will be able to:
- Define IT audit scope using a risk-and-control matrix for a business process or technology service
- Map technology risks to ITGCs, automated controls and relevant COBIT 2019 control objectives
- Assess control design through walkthroughs, control narratives, process maps and responsibility matrices
- Test operating effectiveness using population validation, sampling logic, reperformance and evidence inspection
- Evaluate user access and privileged-access controls from identity listings, role matrices and system logs
- Test change-management controls using change tickets, approvals, testing records and deployment evidence
- Document defensible IT audit working papers with test steps, evidence references, exceptions and conclusions
- Draft actionable IT control findings using condition, criteria, cause, risk, recommendation and management action
Benefits of attending
For you
- Build confidence to lead IT control interviews with system owners, administrators and process managers
- Produce audit working papers that demonstrate a clear link between risk, test procedure, evidence and conclusion
- Recognise when a business-process audit requires ITGC, automated-control or report-control testing
- Strengthen credibility for internal audit assignments involving ERP systems, cloud platforms and access governance
- Develop reusable test programmes and evidence requests that reduce preparation time on future IT audits
For your organisation
- Improve consistency of IT control testing across audit teams, systems and business units
- Identify access, change and operational-control failures before they create financial, security or compliance exposure
- Reduce weak audit conclusions by improving population validation, sample selection and evidence quality
- Give technology management clearer, evidence-based findings that can be assigned and remediated efficiently
- Create reusable test scripts and working-paper templates for the annual IT audit plan
Target competencies
Who should attend
- Internal Auditors — who need to test technology controls within operational, financial and integrated audits
- IT Auditors — who want a repeatable methodology for ITGC and application-control testing
- Senior Internal Auditors — who supervise audit files and must review the sufficiency of IT control evidence
- Risk Assurance Professionals — who assess technology risks and coordinate assurance across the three lines
- Compliance Auditors — who must evaluate evidence for access, change and operational-control requirements
- Finance Auditors — who rely on IT-dependent controls and system-generated reports in financial audits
Requirements and prerequisites
Participants should have practical experience of internal audit, risk assessment, control evaluation or compliance testing, and understand basic audit concepts such as objectives, evidence, sampling, walkthroughs and findings. Familiarity with common business systems, user access, change requests and audit working papers is helpful. Participants should be able to work confidently with spreadsheets, including filtering, sorting and reviewing data extracts in Microsoft Excel. Prior coding, system-administration, cybersecurity-certification or specialist database knowledge is not required. The course explains technical terminology in an audit context rather than assuming an IT engineering background.
Training methodology
The instructor demonstrates each testing method using a simulated audit engagement, then participants apply it to evidence files modelled on real audit artefacts. Short technical briefings establish the control objective and risk; individual and small-group exercises then use access extracts, change records, incident logs and report parameters to perform test steps and record exceptions. Teams compare conclusions during facilitated audit-review discussions. On the final day, participants convert the course work into an application plan, selecting an upcoming audit area and tailoring a test programme, evidence request and reporting approach.
Course outline
Day 1: IT audit planning and control foundations
- Technology risk categories and the internal audit assurance role
- IT general controls, automated controls and IT-dependent manual controls
- Business-process mapping and identification of system touchpoints
- Risk-and-control matrix construction for technology-enabled processes
- Control objectives, control activities and control owners
- Using COBIT 2019 to establish audit criteria
- Scoping material systems, interfaces, reports and outsourced services
Workshop: Participants build a risk-and-control matrix for an order-to-cash process and define the IT controls requiring audit coverage.
Day 2: Testing access and security-related controls
- Logical access control objectives and identity lifecycle risks
- Joiner, mover and leaver access provisioning tests
- User access recertification and reviewer-evidence evaluation
- Privileged-access governance and emergency-access procedures
- Role matrices, segregation-of-duties conflicts and compensating controls
- Population completeness and accuracy testing for user listings
- Audit-log inspection and exception follow-up techniques
Workshop: Participants test a user-access population, select samples, assess termination exceptions and complete an access-control working paper.
Day 3: Testing change, operations and resilience controls
- Change-management lifecycle from request through deployment
- Testing approvals, impact assessments and segregation of environments
- Evaluating user acceptance testing and release evidence
- Emergency-change controls and retrospective approval testing
- Batch processing, job scheduling and interface monitoring controls
- Incident management, problem management and root-cause records
- Backup, restoration and disaster-recovery test evidence
Workshop: Participants examine a change-ticket and operations evidence pack, identify test exceptions and draft a conclusion on operating effectiveness.
Day 4: Application controls, data and audit evidence
- Input, processing and output control objectives
- Configuration testing for automated application controls
- Interface completeness, reconciliation and error-handling controls
- System-generated report controls and report-parameter validation
- Walkthroughs, inquiry, observation, inspection and reperformance
- Sampling approaches for control testing and exception evaluation
- Working-paper structure, cross-referencing and evidence retention
Workshop: Participants test an automated approval control and a system-generated exception report, documenting procedures, evidence and conclusions.
Day 5: Conclusions, reporting and audit application
- Design-deficiency versus operating-effectiveness failure analysis
- Evaluating control dependencies and compensating controls
- Rating IT control findings by likelihood, impact and exposure
- Writing condition, criteria, cause, consequence and recommendation
- Discussing technical findings with technology management
- Using NIST SP 800-53 to strengthen control criteria
- Building a risk-based IT controls test programme for a live audit
Workshop: Participants produce a mini IT audit file containing a test programme, completed working paper, finding draft and action plan for an upcoming engagement.
Tools & standards covered
COBIT 2019, NIST SP 800-53, Microsoft Excel, TeamMate+
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Information Technology
Microsoft Azure Cloud Administration Training Course
Organisations depend on Azure administrators to provision reliable services, control cloud spend, protect identities and data, and resolve i…
Microsoft Intune Endpoint Management Training Course
Managing Windows, macOS, iOS and Android endpoints through Microsoft Intune requires more than creating a few compliance policies. IT teams …
Cisco Meraki Network Management Training Course
Cisco Meraki simplifies the administration of wireless, switching, security appliances, SD-WAN and endpoint environments, but the dashboard …
Advanced IT Strategy and Governance Training Course
Technology leaders are expected to defend investment decisions, govern risk, and show how platforms, data, sourcing, and delivery programmes…