IT Controls Testing for Internal Auditors Training Course

5 days Information Technology Certificate on completion
Course codeSD-IT-027
Duration5 days
LevelIntermediate
CategoryInformation Technology
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Internal auditors are increasingly expected to provide assurance over access management, change control, IT operations, cloud services and automated business processes—not simply confirm that policy documents exist. This requires auditors to translate technology risks into testable control objectives, obtain reliable evidence from system owners, and distinguish a design weakness from an operating failure. Without a structured testing approach, audit teams can over-rely on walkthroughs, request excessive evidence, miss control dependencies, or report findings that technology management cannot action.

This five-day course equips internal auditors to plan, perform and report IT controls testing across common technology environments. Participants practise scoping an IT audit, mapping risks to controls, assessing control design, selecting samples, testing operating effectiveness and documenting evidence. The course covers general IT controls (ITGCs), including user access, privileged access, change management, backup and recovery, job scheduling and incident management, alongside automated application controls, interface controls and key report controls. Participants also use COBIT 2019 and NIST SP 800-53 as practical sources for control criteria, and build working papers that support clear audit conclusions.

Delivery combines instructor-led technical sessions with realistic audit files, evidence packs, walkthrough scenarios and team-based testing workshops. Participants review access listings, change tickets, audit logs, configuration extracts and exception reports; identify deficiencies; and draft concise findings with cause, risk, recommendation and management action. Each participant leaves with an IT controls test programme, evidence request list, sample-selection rationale and reporting template that can be adapted for a live audit assignment. The course is particularly suited to auditors who need to challenge technology controls credibly while maintaining a risk-based, business-focused audit approach.

Course objectives

By the end of this course, participants will be able to:

  • Define IT audit scope using a risk-and-control matrix for a business process or technology service
  • Map technology risks to ITGCs, automated controls and relevant COBIT 2019 control objectives
  • Assess control design through walkthroughs, control narratives, process maps and responsibility matrices
  • Test operating effectiveness using population validation, sampling logic, reperformance and evidence inspection
  • Evaluate user access and privileged-access controls from identity listings, role matrices and system logs
  • Test change-management controls using change tickets, approvals, testing records and deployment evidence
  • Document defensible IT audit working papers with test steps, evidence references, exceptions and conclusions
  • Draft actionable IT control findings using condition, criteria, cause, risk, recommendation and management action

Benefits of attending

For you

  • Build confidence to lead IT control interviews with system owners, administrators and process managers
  • Produce audit working papers that demonstrate a clear link between risk, test procedure, evidence and conclusion
  • Recognise when a business-process audit requires ITGC, automated-control or report-control testing
  • Strengthen credibility for internal audit assignments involving ERP systems, cloud platforms and access governance
  • Develop reusable test programmes and evidence requests that reduce preparation time on future IT audits

For your organisation

  • Improve consistency of IT control testing across audit teams, systems and business units
  • Identify access, change and operational-control failures before they create financial, security or compliance exposure
  • Reduce weak audit conclusions by improving population validation, sample selection and evidence quality
  • Give technology management clearer, evidence-based findings that can be assigned and remediated efficiently
  • Create reusable test scripts and working-paper templates for the annual IT audit plan

Target competencies

ITGC testingControl design assessmentAudit evidence evaluationAccess review testingChange control testingFinding formulation

Who should attend

  • Internal Auditors — who need to test technology controls within operational, financial and integrated audits
  • IT Auditors — who want a repeatable methodology for ITGC and application-control testing
  • Senior Internal Auditors — who supervise audit files and must review the sufficiency of IT control evidence
  • Risk Assurance Professionals — who assess technology risks and coordinate assurance across the three lines
  • Compliance Auditors — who must evaluate evidence for access, change and operational-control requirements
  • Finance Auditors — who rely on IT-dependent controls and system-generated reports in financial audits

Requirements and prerequisites

Participants should have practical experience of internal audit, risk assessment, control evaluation or compliance testing, and understand basic audit concepts such as objectives, evidence, sampling, walkthroughs and findings. Familiarity with common business systems, user access, change requests and audit working papers is helpful. Participants should be able to work confidently with spreadsheets, including filtering, sorting and reviewing data extracts in Microsoft Excel. Prior coding, system-administration, cybersecurity-certification or specialist database knowledge is not required. The course explains technical terminology in an audit context rather than assuming an IT engineering background.

Training methodology

The instructor demonstrates each testing method using a simulated audit engagement, then participants apply it to evidence files modelled on real audit artefacts. Short technical briefings establish the control objective and risk; individual and small-group exercises then use access extracts, change records, incident logs and report parameters to perform test steps and record exceptions. Teams compare conclusions during facilitated audit-review discussions. On the final day, participants convert the course work into an application plan, selecting an upcoming audit area and tailoring a test programme, evidence request and reporting approach.

Course outline

Day 1: IT audit planning and control foundations

  • Technology risk categories and the internal audit assurance role
  • IT general controls, automated controls and IT-dependent manual controls
  • Business-process mapping and identification of system touchpoints
  • Risk-and-control matrix construction for technology-enabled processes
  • Control objectives, control activities and control owners
  • Using COBIT 2019 to establish audit criteria
  • Scoping material systems, interfaces, reports and outsourced services

Workshop: Participants build a risk-and-control matrix for an order-to-cash process and define the IT controls requiring audit coverage.

Day 2: Testing access and security-related controls

  • Logical access control objectives and identity lifecycle risks
  • Joiner, mover and leaver access provisioning tests
  • User access recertification and reviewer-evidence evaluation
  • Privileged-access governance and emergency-access procedures
  • Role matrices, segregation-of-duties conflicts and compensating controls
  • Population completeness and accuracy testing for user listings
  • Audit-log inspection and exception follow-up techniques

Workshop: Participants test a user-access population, select samples, assess termination exceptions and complete an access-control working paper.

Day 3: Testing change, operations and resilience controls

  • Change-management lifecycle from request through deployment
  • Testing approvals, impact assessments and segregation of environments
  • Evaluating user acceptance testing and release evidence
  • Emergency-change controls and retrospective approval testing
  • Batch processing, job scheduling and interface monitoring controls
  • Incident management, problem management and root-cause records
  • Backup, restoration and disaster-recovery test evidence

Workshop: Participants examine a change-ticket and operations evidence pack, identify test exceptions and draft a conclusion on operating effectiveness.

Day 4: Application controls, data and audit evidence

  • Input, processing and output control objectives
  • Configuration testing for automated application controls
  • Interface completeness, reconciliation and error-handling controls
  • System-generated report controls and report-parameter validation
  • Walkthroughs, inquiry, observation, inspection and reperformance
  • Sampling approaches for control testing and exception evaluation
  • Working-paper structure, cross-referencing and evidence retention

Workshop: Participants test an automated approval control and a system-generated exception report, documenting procedures, evidence and conclusions.

Day 5: Conclusions, reporting and audit application

  • Design-deficiency versus operating-effectiveness failure analysis
  • Evaluating control dependencies and compensating controls
  • Rating IT control findings by likelihood, impact and exposure
  • Writing condition, criteria, cause, consequence and recommendation
  • Discussing technical findings with technology management
  • Using NIST SP 800-53 to strengthen control criteria
  • Building a risk-based IT controls test programme for a live audit

Workshop: Participants produce a mini IT audit file containing a test programme, completed working paper, finding draft and action plan for an upcoming engagement.

Tools & standards covered

COBIT 2019, NIST SP 800-53, Microsoft Excel, TeamMate+

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You need working familiarity with internal audit concepts and basic business-system terminology, such as user access, change requests and audit evidence. You do not need to be a programmer, network engineer or cybersecurity specialist; technical concepts are taught through audit scenarios and control evidence.

A laptop with Microsoft Excel is recommended for live online delivery and useful in the classroom for working with sample data extracts and templates. No licence for a specialist audit-management platform is required, because exercises use supplied files and reusable working-paper formats.

It is designed primarily for internal auditors who test technology controls as part of financial, operational, compliance or integrated audits. It also suits IT auditors and risk assurance staff seeking a more disciplined approach to ITGC and application-control testing.

This course focuses on how an internal auditor plans tests, evaluates evidence, documents conclusions and reports deficiencies. It uses cybersecurity and governance frameworks as sources of control criteria, but it does not train participants to configure security tools or design an enterprise technology strategy.

Participants can use the risk-and-control matrix, evidence request list, test scripts and finding structure immediately in audits covering access, changes, operations or system-generated reports. The final application plan is designed around an audit area relevant to the participant's own organisation.

You will leave with a completed IT controls test programme, sample test working papers, an evidence request checklist and a structured finding draft. These materials are designed to be adapted to your audit methodology, systems and risk taxonomy.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Information Technology

5 Days Certificate

Microsoft Azure Cloud Administration Training Course

Organisations depend on Azure administrators to provision reliable services, control cloud spend, protect identities and data, and resolve i…

5 Days Certificate

Microsoft Intune Endpoint Management Training Course

Managing Windows, macOS, iOS and Android endpoints through Microsoft Intune requires more than creating a few compliance policies. IT teams …

5 Days Certificate

Cisco Meraki Network Management Training Course

Cisco Meraki simplifies the administration of wireless, switching, security appliances, SD-WAN and endpoint environments, but the dashboard …

5 Days Certificate

Advanced IT Strategy and Governance Training Course

Technology leaders are expected to defend investment decisions, govern risk, and show how platforms, data, sourcing, and delivery programmes…