Microfinance Internal Audit and Control Testing Training Course

5 days Auditing Certificate on completion
Course codeSD-A-074
Duration5 days
LevelIntermediate to Advanced
CategoryAuditing
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Microfinance institutions operate through dispersed branches, high-volume loan transactions, field collections, group lending arrangements, mobile money channels and decentralised approvals. These conditions create control failures that conventional audit programmes can miss: fictitious borrowers, loan recycling, unauthorised rescheduling, delayed deposit of collections, duplicate client records, override of credit limits and weak follow-up on overdue loans. Internal auditors need to test whether controls work in practice, not merely confirm that policies exist.

This five-day course equips participants to plan and execute risk-based internal audits across the microfinance loan lifecycle. Participants map processes from client onboarding to disbursement, repayment, restructuring, write-off and recovery; identify key risks and controls; develop risk-control matrices; select samples; test control design and operating effectiveness; and document defensible findings. The programme addresses branch operations, credit administration, cash and treasury controls, portfolio quality, fraud indicators, management information systems and audit reporting. Participants also use Excel and IDEA Data Analysis techniques to investigate exceptions in loan and collection data.

Instruction combines auditor-led technical sessions with a realistic microfinance case involving branch irregularities, delinquency manipulation and cash collection discrepancies. Each participant builds an audit working-paper pack: a scoped audit plan, risk-control matrix, control-testing sheets, data-analytics exception log, evidence index and prioritised audit report. This gives both the participant and their manager a practical set of templates that can be adapted for the institution's next branch, credit or operations audit.

The course is designed for practitioners who already understand microfinance operations and now need stronger assurance, testing and reporting capability. It is particularly valuable for teams moving from checklist-based branch inspections to disciplined, risk-based internal audit work.

Course objectives

By the end of this course, participants will be able to:

  • Construct a microfinance loan-lifecycle risk and control matrix covering onboarding, appraisal, disbursement, collections, rescheduling and write-offs
  • Plan a risk-based branch audit using scoping criteria, materiality considerations, audit objectives and resource estimates
  • Test the design and operating effectiveness of credit, cash, collections and portfolio-management controls
  • Select and document statistical and judgemental samples for loan-file, repayment and cash-control testing
  • Perform Excel and IDEA Data Analysis exception tests for duplicate clients, unusual rescheduling, dormant accounts and collection anomalies
  • Evaluate segregation of duties, system access and approval-limit controls across branch and head-office processes
  • Prepare audit working papers that link criteria, procedures, evidence, exceptions, root causes and conclusions
  • Draft prioritised internal audit findings and management action plans using risk ratings, owners and due dates

Benefits of attending

For you

  • Gain a repeatable method for auditing microfinance branches, credit operations and collection processes
  • Build confidence to challenge unsupported loan restructurings, cash discrepancies and control overrides with evidence
  • Produce audit work papers and findings that meet professional review standards
  • Develop practical data-testing capability for identifying high-risk loan and repayment exceptions
  • Strengthen credibility for internal audit, operational risk, credit control and branch-assurance roles

For your organisation

  • Improve detection of fictitious lending, duplicate borrower records, unauthorised rescheduling and collection leakage
  • Create more consistent branch audit programmes, testing sheets and evidence standards across the audit team
  • Reduce exposure to weak segregation of duties, approval-limit overrides and inappropriate system access
  • Provide management with better-targeted findings linked to root causes, risk ratings and accountable action owners
  • Support earlier intervention on portfolio-quality deterioration through stronger testing of arrears and recovery controls

Target competencies

Risk-based audit planningLoan control testingBranch cash assuranceAudit data analyticsWorking-paper documentationFinding root-cause analysis

Who should attend

  • Internal Auditors — who need to test branch and loan-process controls with evidence rather than inspection checklists
  • Internal Audit Managers — who must build risk-based audit programmes and review the quality of fieldwork
  • Microfinance Operations Managers — who oversee branch processes and need to remediate recurring control failures
  • Credit Risk Managers — who need assurance over appraisal, approval, disbursement and loan-monitoring controls
  • Compliance and Risk Officers — who monitor operational risk, fraud exposure and corrective-action closure
  • Branch Managers — who are accountable for cash, collections, client records and portfolio-quality controls

Requirements and prerequisites

Participants should have working experience in a microfinance institution, bank, SACCO or lending operation and be familiar with basic loan terms such as appraisal, disbursement, arrears, rescheduling, provisioning and write-off. They should understand the purpose of internal controls and be able to work with spreadsheets, including sorting, filtering and simple formulas in Microsoft Excel. Prior audit experience is helpful but not essential; the course explains audit planning, sampling and working-paper conventions before applying them. No accounting qualification, programming knowledge, statistical software expertise or prior use of IDEA Data Analysis is required.

Training methodology

The course is delivered through instructor-led briefings, guided demonstrations and structured workshops using a single microfinance institution case. Participants review loan files, branch cash records, approval logs, repayment data and exception reports to practise audit procedures rather than discuss controls only in theory. Small groups build risk-control matrices, design samples, test simulated evidence and calibrate finding ratings. Excel and IDEA Data Analysis exercises demonstrate practical exception testing. On the final day, each participant converts the case work into a tailored application plan for an upcoming audit in their own institution.

Course outline

Day 1: Microfinance audit risk and audit planning

  • Microfinance business model risks across branches, field officers and digital channels
  • Loan lifecycle mapping from client onboarding to recovery and write-off
  • IIA Global Internal Audit Standards and risk-based assurance expectations
  • COSO Internal Control—Integrated Framework applied to lending operations
  • Audit universe development for credit, operations, finance and information systems
  • Branch audit scoping using portfolio, cash, fraud and conduct risk indicators
  • Risk assessment, audit objectives and engagement work-programme design

Workshop: Participants map a microfinance branch loan process and produce a risk-ranked audit scope and engagement objective statement.

Day 2: Credit and portfolio control testing

  • Client identification, know-your-customer and duplicate-borrower control risks
  • Credit appraisal evidence and debt-capacity verification tests
  • Loan approval authorities, committee minutes and limit-override testing
  • Disbursement controls for bank transfers, cash payments and mobile wallets
  • Collateral, guarantor and group-lending documentation verification
  • Arrears ageing, delinquency classification and portfolio-at-risk control tests
  • Rescheduling, refinancing, provisioning and write-off approval testing

Workshop: Participants create a risk-control matrix and detailed test steps for a loan-origination and rescheduling audit.

Day 3: Branch cash, collections and fraud controls

  • Cash receipt, teller, vault and end-of-day reconciliation controls
  • Field collection controls and timely deposit verification
  • Mobile money collection reconciliation and settlement exception review
  • Segregation of duties between loan officers, cashiers, supervisors and system administrators
  • Surprise cash counts and physical verification procedures
  • Fraud red flags including ghost clients, kiting, loan cycling and receipt suppression
  • Whistleblowing, investigation referral and fraud-loss documentation

Workshop: Participants conduct a simulated branch cash and collections audit, producing a cash-count sheet, reconciliation exceptions and fraud-risk observations.

Day 4: Sampling, data analytics and audit evidence

  • Audit population definition and completeness checks for core banking extracts
  • Judgemental, random, systematic and risk-based sample selection methods
  • Test-of-controls versus substantive procedures and evidence requirements
  • Excel filters, pivot tables and conditional formatting for loan exception analysis
  • IDEA Data Analysis tests for duplicates, gaps, sequence breaks and unusual transactions
  • Exception testing for repeated rescheduling, zero repayments and staff-linked accounts
  • Working-paper indexing, cross-referencing and evidence retention standards

Workshop: Participants analyse a loan and repayments data set in Excel and IDEA Data Analysis, then produce an exception log and documented sample-testing file.

Day 5: Findings, reporting and corrective-action assurance

  • Evaluating control deficiencies by likelihood, impact and control failure type
  • Root-cause analysis using five whys and cause-and-effect mapping
  • Writing condition, criteria, cause, consequence and recommendation statements
  • Audit finding ratings for credit, cash, fraud and operational-risk issues
  • Management action plans with owners, deadlines and measurable remediation evidence
  • Exit meeting techniques for challenging disputed audit findings
  • Follow-up testing and dashboard reporting for overdue audit actions

Workshop: Participants prepare and present a prioritised branch audit report, corrective-action tracker and 90-day follow-up plan based on the full case.

Tools & standards covered

Microsoft Excel, IDEA Data Analysis, IIA Global Internal Audit Standards, COSO Internal Control—Integrated Framework

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand how a microfinance loan is originated, disbursed, repaid and monitored, and be comfortable using basic Excel functions. Previous internal audit experience is useful but not mandatory because the course teaches the audit-planning and control-testing method from first principles.

A laptop with Microsoft Excel is strongly recommended for the data-testing workshops. Training files and guided exercises are provided; access to IDEA Data Analysis is useful but prior installation or prior product experience is not required.

It is best suited to internal audit, credit risk, compliance, operations and branch-management professionals in microfinance institutions, SACCOs and similar lenders. The content assumes a lending environment with decentralised branches, client records, collections and portfolio monitoring.

This course focuses on microfinance-specific risks such as group lending, field collections, loan cycling, portfolio-at-risk manipulation, rescheduling abuse and mobile money reconciliation. The audit programmes, data tests and case evidence are built around lending and branch operations rather than generic corporate processes.

Participants can adapt the risk-control matrix, test sheets, exception log and audit-report structure for their next branch, credit or collections audit. The final application plan identifies one live audit area, the required data, proposed tests and stakeholders to engage.

You leave with a completed audit working-paper pack developed through the course case, including an audit scope, risk-control matrix, sample-testing documentation, data-exception log and action tracker. These materials are designed as editable models for use within your institution's methodology.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Auditing

5 Days Certificate

IIA Global Internal Audit Standards Implementation Training Course

The 2024 IIA Global Internal Audit Standards raise the bar for how internal audit functions are governed, planned, performed, communicated a…

5 Days Certificate

Healthcare Compliance Auditing Training Course

Healthcare organisations face overlapping audit pressures: inaccurate claims, unsupported charges, duplicate payments, weak vendor controls,…

5 Days Certificate

Diligent HighBond Audit Management Training Course

Internal audit teams need more than a repository for workpapers: they need a controlled audit workflow that links risk assessment, audit pla…

5 Days Certificate

Grant Compliance Auditing for NGO Finance Teams Training Course

NGO finance teams must demonstrate that restricted funds were spent for the approved purpose, charged to the correct grant, supported by rel…