Public Sector Internal Auditing Training Course
| Course code | SD-A-037 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Auditing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Public-sector organisations must demonstrate that public money, assets, programmes and services are managed lawfully, economically and transparently. Internal auditors face a distinct challenge: they must provide independent assurance while working across complex governance structures, politically visible priorities, grant conditions, procurement rules and service-delivery risks. This course equips participants to plan and perform audits that give audit committees and senior accountable officers evidence they can act on, rather than reports that merely describe control gaps.
Participants learn the full public-sector internal audit cycle, from translating strategic objectives into a risk-based audit universe through to scoping engagements, testing controls, evaluating evidence and reporting recommendations. The course applies the Global Internal Audit Standards, COSO internal control principles and public-sector accountability requirements to practical assignments. Participants practise documenting process walkthroughs, building risk-control matrices, selecting samples, testing procurement and payment controls, assessing fraud indicators, rating findings and writing recommendations with clear owners and due dates.
Delivery combines instructor-led technical sessions with a continuing public-sector case study involving procurement, grants administration and programme expenditure. Participants work with audit planning templates, working-paper structures and report-writing tools, receiving structured feedback on their analysis and professional judgement. They leave with a completed risk-based audit plan, a risk-control matrix, sample audit working papers and an action-oriented audit report that can be adapted for their own organisation.
The course is suited to new and developing internal auditors, finance and compliance staff moving into assurance work, and managers who need a disciplined way to oversee public funds, controls and governance arrangements.
Course objectives
By the end of this course, participants will be able to:
- Construct a risk-based public-sector audit universe using organisational objectives, budget data and service-delivery risks
- Apply the Global Internal Audit Standards when planning, conducting and documenting assurance engagements
- Develop an audit scope, objective, criteria and test programme for a public-sector control process
- Create a risk-control matrix linking process risks, controls, control owners and audit procedures
- Perform walkthroughs and control tests for procurement, payroll, grants and expenditure transactions
- Select and document defensible audit samples using judgemental and risk-based sampling methods
- Evaluate audit evidence and formulate findings using condition, criteria, cause, consequence and recommendation
- Produce a concise audit report and management action tracker for senior management and the audit committee
Benefits of attending
For you
- Build a defensible audit file using risk assessments, test programmes, evidence records and review-ready working papers
- Gain confidence challenging weak controls and documenting findings without relying on vague observations
- Learn to audit high-exposure public-sector areas including procurement, grants, payroll and delegated expenditure
- Produce clearer recommendations that identify accountable owners, practical corrective actions and target dates
- Demonstrate capability for internal audit, risk assurance and governance roles through a completed audit portfolio
For your organisation
- Strengthen the quality and consistency of audit planning, fieldwork documentation and reporting across the assurance function
- Identify control failures earlier in procurement, payments, grants and programme expenditure before they become reportable issues
- Provide audit committees with evidence-based findings, prioritised risk ratings and trackable management actions
- Improve assurance over compliance with public-sector policies, delegated authority limits and funding conditions
- Create a repeatable risk-based approach that directs limited audit resources toward material service and financial risks
Target competencies
Who should attend
- Internal Auditors — who need to plan and deliver assurance engagements across public services and public funds
- Senior Internal Auditors — who supervise fieldwork and need consistent working papers, testing and reporting methods
- Finance Managers — who oversee financial controls, delegated authority and budget accountability
- Risk and Compliance Officers — who need to assess whether governance and control arrangements operate as designed
- Public Procurement Officers — who must identify and evidence control risks in tendering, contract award and supplier management
- Programme and Grant Managers — who administer funded activities and must demonstrate eligible, controlled expenditure
Requirements and prerequisites
This course is accessible to participants new to internal auditing, but it assumes confidence reading basic financial information such as budgets, invoices, purchase orders and expenditure reports. Participants should understand how their organisation delivers services, approves spending and assigns managerial responsibilities. Familiarity with Microsoft Excel is helpful for reviewing data and documenting tests, although advanced formulas or data analytics experience are not required. No prior internal audit qualification, previous audit engagement experience, accounting degree or specialist audit software knowledge is required. Complete beginners should expect a structured introduction followed by supervised practice using realistic public-sector audit scenarios.
Training methodology
The five days combine short instructor-led explanations with progressively more demanding audit work on a realistic public-sector case. Participants map a process, identify risks and controls, build a risk-control matrix, draft test procedures, inspect simulated records and evaluate exceptions. Small groups compare evidence and challenge each other's findings as an audit review team would. The instructor uses worked examples drawn from procurement, grants and expenditure controls, then gives feedback on working papers and report language. The final session converts the case work into an individual application plan for a live audit area.
Course outline
Day 1: Public-sector internal audit foundations
- Public accountability, stewardship and the three lines model
- Global Internal Audit Standards and the internal audit mandate
- Independence, objectivity and conflicts of interest in public bodies
- Audit committee, senior accountable officer and management responsibilities
- Audit universe construction across functions, programmes and funded activities
- Strategic, operational, financial and compliance risk categories
- Annual audit planning and risk-based assurance coverage
Workshop: Participants build a draft audit universe and prioritise candidate engagements for a fictional public-service organisation.
Day 2: Planning auditable engagements
- Engagement objectives, scope boundaries and audit criteria
- Process mapping through narratives, flowcharts and walkthroughs
- Risk identification using cause-event-impact statements
- Preventive, detective and corrective control classifications
- Risk-control matrix design and control-owner identification
- Materiality, significance and public-interest considerations
- Audit programmes, resource estimates and engagement planning memoranda
Workshop: Participants map a grants administration process and produce a risk-control matrix and scoped audit programme.
Day 3: Fieldwork, evidence and control testing
- Audit evidence attributes: relevance, reliability, sufficiency and source
- Interview planning and walkthrough documentation
- Inspection, observation, reperformance and analytical review techniques
- Judgemental, random and risk-based sampling approaches
- Testing procurement approvals, competitive tendering and contract variations
- Testing payroll, payment authorisation and segregation of duties controls
- Working-paper indexing, cross-referencing and supervisory review notes
Workshop: Participants test a sample of procurement transactions, document exceptions and prepare review-ready working papers.
Day 4: Assessing findings and reporting assurance
- Evaluating control design versus operating effectiveness
- Root-cause analysis using the five whys and cause-and-effect logic
- Finding development using condition, criteria, cause, consequence and recommendation
- Risk rating frameworks and escalation thresholds
- Fraud risk indicators in procurement, grants and expense claims
- Writing balanced recommendations and agreeing management actions
- Audit report structure for management, audit committees and oversight bodies
Workshop: Participants turn tested exceptions into rated findings and draft an executive-ready audit report for the case organisation.
Day 5: Follow-up, quality and workplace application
- Management action plans, owners, deadlines and evidence of completion
- Follow-up testing and closure criteria for audit recommendations
- Quality assurance and improvement programme requirements
- Internal audit performance measures and stakeholder feedback
- Using Excel to analyse expenditure populations and flag anomalies
- Communicating difficult findings with auditees and senior managers
- Personal audit application planning for a current organisational risk
Workshop: Participants complete a 90-day application plan and present their audit approach, action tracker and reporting priorities for peer review.
Tools & standards covered
Microsoft Excel, TeamMate+, IIA Global Internal Audit Standards, COSO Internal Control—Integrated Framework
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
28 Sep – 02 Oct 2026Book
Live Online · USD 1,500 -
28 Sep – 02 Oct 2026Book
Mombasa · USD 3,200 -
19 – 23 Oct 2026Book
Live Online · USD 1,500 -
19 – 23 Oct 2026Book
Kigali · USD 3,500 -
26 – 30 Oct 2026Book
Dubai · USD 4,500 -
02 – 06 Nov 2026Book
Live Online · USD 1,500 -
02 – 06 Nov 2026Book
Cape Town · USD 4,200 -
02 – 06 Nov 2026Book
Dar es Salaam · USD 3,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Auditing
Cybersecurity Audit Evidence for Information Security Auditors Training Course
Information security auditors are expected to substantiate conclusions about access control, logging, vulnerability management, change contr…
ACL Analytics Continuous Auditing Techniques Training Course
Continuous auditing fails when audit teams rely on periodic spreadsheet extracts, undocumented tests, and exception reports that cannot be r…
International Standards on Auditing ISA Application Training Course
Audit teams are expected to demonstrate not only that they reached an appropriate opinion, but also that their work was planned, performed, …
Manufacturing Inventory Audit Controls Training Course
Manufacturing inventory is vulnerable to errors and loss at every hand-off: goods receipt, put-away, production issue, scrap booking, subcon…