Microfinance Internal Audit and Control Testing Training Course
| Course code | SD-A-074 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Auditing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Microfinance institutions operate through dispersed branches, high-volume loan transactions, field collections, group lending arrangements, mobile money channels and decentralised approvals. These conditions create control failures that conventional audit programmes can miss: fictitious borrowers, loan recycling, unauthorised rescheduling, delayed deposit of collections, duplicate client records, override of credit limits and weak follow-up on overdue loans. Internal auditors need to test whether controls work in practice, not merely confirm that policies exist.
This five-day course equips participants to plan and execute risk-based internal audits across the microfinance loan lifecycle. Participants map processes from client onboarding to disbursement, repayment, restructuring, write-off and recovery; identify key risks and controls; develop risk-control matrices; select samples; test control design and operating effectiveness; and document defensible findings. The programme addresses branch operations, credit administration, cash and treasury controls, portfolio quality, fraud indicators, management information systems and audit reporting. Participants also use Excel and IDEA Data Analysis techniques to investigate exceptions in loan and collection data.
Instruction combines auditor-led technical sessions with a realistic microfinance case involving branch irregularities, delinquency manipulation and cash collection discrepancies. Each participant builds an audit working-paper pack: a scoped audit plan, risk-control matrix, control-testing sheets, data-analytics exception log, evidence index and prioritised audit report. This gives both the participant and their manager a practical set of templates that can be adapted for the institution's next branch, credit or operations audit.
The course is designed for practitioners who already understand microfinance operations and now need stronger assurance, testing and reporting capability. It is particularly valuable for teams moving from checklist-based branch inspections to disciplined, risk-based internal audit work.
Course objectives
By the end of this course, participants will be able to:
- Construct a microfinance loan-lifecycle risk and control matrix covering onboarding, appraisal, disbursement, collections, rescheduling and write-offs
- Plan a risk-based branch audit using scoping criteria, materiality considerations, audit objectives and resource estimates
- Test the design and operating effectiveness of credit, cash, collections and portfolio-management controls
- Select and document statistical and judgemental samples for loan-file, repayment and cash-control testing
- Perform Excel and IDEA Data Analysis exception tests for duplicate clients, unusual rescheduling, dormant accounts and collection anomalies
- Evaluate segregation of duties, system access and approval-limit controls across branch and head-office processes
- Prepare audit working papers that link criteria, procedures, evidence, exceptions, root causes and conclusions
- Draft prioritised internal audit findings and management action plans using risk ratings, owners and due dates
Benefits of attending
For you
- Gain a repeatable method for auditing microfinance branches, credit operations and collection processes
- Build confidence to challenge unsupported loan restructurings, cash discrepancies and control overrides with evidence
- Produce audit work papers and findings that meet professional review standards
- Develop practical data-testing capability for identifying high-risk loan and repayment exceptions
- Strengthen credibility for internal audit, operational risk, credit control and branch-assurance roles
For your organisation
- Improve detection of fictitious lending, duplicate borrower records, unauthorised rescheduling and collection leakage
- Create more consistent branch audit programmes, testing sheets and evidence standards across the audit team
- Reduce exposure to weak segregation of duties, approval-limit overrides and inappropriate system access
- Provide management with better-targeted findings linked to root causes, risk ratings and accountable action owners
- Support earlier intervention on portfolio-quality deterioration through stronger testing of arrears and recovery controls
Target competencies
Who should attend
- Internal Auditors — who need to test branch and loan-process controls with evidence rather than inspection checklists
- Internal Audit Managers — who must build risk-based audit programmes and review the quality of fieldwork
- Microfinance Operations Managers — who oversee branch processes and need to remediate recurring control failures
- Credit Risk Managers — who need assurance over appraisal, approval, disbursement and loan-monitoring controls
- Compliance and Risk Officers — who monitor operational risk, fraud exposure and corrective-action closure
- Branch Managers — who are accountable for cash, collections, client records and portfolio-quality controls
Requirements and prerequisites
Participants should have working experience in a microfinance institution, bank, SACCO or lending operation and be familiar with basic loan terms such as appraisal, disbursement, arrears, rescheduling, provisioning and write-off. They should understand the purpose of internal controls and be able to work with spreadsheets, including sorting, filtering and simple formulas in Microsoft Excel. Prior audit experience is helpful but not essential; the course explains audit planning, sampling and working-paper conventions before applying them. No accounting qualification, programming knowledge, statistical software expertise or prior use of IDEA Data Analysis is required.
Training methodology
The course is delivered through instructor-led briefings, guided demonstrations and structured workshops using a single microfinance institution case. Participants review loan files, branch cash records, approval logs, repayment data and exception reports to practise audit procedures rather than discuss controls only in theory. Small groups build risk-control matrices, design samples, test simulated evidence and calibrate finding ratings. Excel and IDEA Data Analysis exercises demonstrate practical exception testing. On the final day, each participant converts the case work into a tailored application plan for an upcoming audit in their own institution.
Course outline
Day 1: Microfinance audit risk and audit planning
- Microfinance business model risks across branches, field officers and digital channels
- Loan lifecycle mapping from client onboarding to recovery and write-off
- IIA Global Internal Audit Standards and risk-based assurance expectations
- COSO Internal Control—Integrated Framework applied to lending operations
- Audit universe development for credit, operations, finance and information systems
- Branch audit scoping using portfolio, cash, fraud and conduct risk indicators
- Risk assessment, audit objectives and engagement work-programme design
Workshop: Participants map a microfinance branch loan process and produce a risk-ranked audit scope and engagement objective statement.
Day 2: Credit and portfolio control testing
- Client identification, know-your-customer and duplicate-borrower control risks
- Credit appraisal evidence and debt-capacity verification tests
- Loan approval authorities, committee minutes and limit-override testing
- Disbursement controls for bank transfers, cash payments and mobile wallets
- Collateral, guarantor and group-lending documentation verification
- Arrears ageing, delinquency classification and portfolio-at-risk control tests
- Rescheduling, refinancing, provisioning and write-off approval testing
Workshop: Participants create a risk-control matrix and detailed test steps for a loan-origination and rescheduling audit.
Day 3: Branch cash, collections and fraud controls
- Cash receipt, teller, vault and end-of-day reconciliation controls
- Field collection controls and timely deposit verification
- Mobile money collection reconciliation and settlement exception review
- Segregation of duties between loan officers, cashiers, supervisors and system administrators
- Surprise cash counts and physical verification procedures
- Fraud red flags including ghost clients, kiting, loan cycling and receipt suppression
- Whistleblowing, investigation referral and fraud-loss documentation
Workshop: Participants conduct a simulated branch cash and collections audit, producing a cash-count sheet, reconciliation exceptions and fraud-risk observations.
Day 4: Sampling, data analytics and audit evidence
- Audit population definition and completeness checks for core banking extracts
- Judgemental, random, systematic and risk-based sample selection methods
- Test-of-controls versus substantive procedures and evidence requirements
- Excel filters, pivot tables and conditional formatting for loan exception analysis
- IDEA Data Analysis tests for duplicates, gaps, sequence breaks and unusual transactions
- Exception testing for repeated rescheduling, zero repayments and staff-linked accounts
- Working-paper indexing, cross-referencing and evidence retention standards
Workshop: Participants analyse a loan and repayments data set in Excel and IDEA Data Analysis, then produce an exception log and documented sample-testing file.
Day 5: Findings, reporting and corrective-action assurance
- Evaluating control deficiencies by likelihood, impact and control failure type
- Root-cause analysis using five whys and cause-and-effect mapping
- Writing condition, criteria, cause, consequence and recommendation statements
- Audit finding ratings for credit, cash, fraud and operational-risk issues
- Management action plans with owners, deadlines and measurable remediation evidence
- Exit meeting techniques for challenging disputed audit findings
- Follow-up testing and dashboard reporting for overdue audit actions
Workshop: Participants prepare and present a prioritised branch audit report, corrective-action tracker and 90-day follow-up plan based on the full case.
Tools & standards covered
Microsoft Excel, IDEA Data Analysis, IIA Global Internal Audit Standards, COSO Internal Control—Integrated Framework
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Auditing
IIA Global Internal Audit Standards Implementation Training Course
The 2024 IIA Global Internal Audit Standards raise the bar for how internal audit functions are governed, planned, performed, communicated a…
Healthcare Compliance Auditing Training Course
Healthcare organisations face overlapping audit pressures: inaccurate claims, unsupported charges, duplicate payments, weak vendor controls,…
Diligent HighBond Audit Management Training Course
Internal audit teams need more than a repository for workpapers: they need a controlled audit workflow that links risk assessment, audit pla…
Grant Compliance Auditing for NGO Finance Teams Training Course
NGO finance teams must demonstrate that restricted funds were spent for the approved purpose, charged to the correct grant, supported by rel…