Strategic Internal Audit Leadership for Chief Audit Executives Training Course

5 days Auditing Certificate on completion
Course codeSD-A-058
Duration5 days
LevelFoundation to Intermediate
CategoryAuditing
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Chief Audit Executives are expected to provide more than assurance over completed transactions. They must help the board and executive team understand whether the organisation’s most material risks are governed, monitored and responded to effectively. This requires an audit function that can translate strategy, risk appetite, regulatory obligations and emerging threats into a focused audit plan, credible reporting and measurable improvement. Without this leadership discipline, internal audit can become a cycle of low-value reviews, unresolved findings and reports that do not influence management decisions.

This five-day course equips participants to lead an internal audit function as a strategic business partner while preserving independence and objectivity. Participants learn to build a risk-based audit universe, assess enterprise risks using COSO ERM concepts, develop a multi-year and annual audit plan, set engagement priorities, direct quality assurance, and communicate significant issues to audit committees. They also practise defining audit performance measures, managing stakeholder expectations, escalating themes from audit findings and using data analytics to strengthen assurance coverage.

Delivery combines instructor-led technical sessions with board-reporting scenarios, audit planning workshops, peer review and case-based decision making. Participants work through a simulated organisation to create a board-ready internal audit strategy pack containing an audit universe, risk assessment, annual plan, stakeholder map, key performance indicators and reporting outline. The course is suited to current and aspiring CAEs, heads of internal audit and senior audit leaders who need to improve the relevance, visibility and governance impact of their function.

Course objectives

By the end of this course, participants will be able to:

  • Construct a risk-based audit universe linked to strategic objectives, processes, legal entities and emerging risks
  • Apply COSO ERM risk assessment criteria to prioritise auditable areas and justify assurance coverage
  • Develop a multi-year internal audit strategy and annual audit plan using risk, resource and capability assumptions
  • Design an audit committee reporting pack that communicates assurance ratings, thematic findings and unresolved risks
  • Establish internal audit performance measures using KPIs, quality indicators and stakeholder feedback mechanisms
  • Map key stakeholders and plan engagement approaches that protect independence while improving audit influence
  • Evaluate internal audit conformance against the IIA Global Internal Audit Standards and define improvement actions
  • Produce a practical chief audit executive action plan for strengthening governance, audit delivery and team capability

Benefits of attending

For you

  • Gain a defensible method for presenting risk-based audit priorities to boards, audit committees and executive management
  • Build confidence in moving from engagement oversight to enterprise-level internal audit leadership
  • Create evidence of CAE-readiness through a completed internal audit strategy and audit planning portfolio
  • Improve the ability to challenge management constructively while maintaining audit independence and professional credibility
  • Develop practical measures for demonstrating internal audit value through coverage, finding quality, timeliness and stakeholder insight

For your organisation

  • Improves alignment between internal audit coverage, strategic objectives, enterprise risks and regulatory obligations
  • Reduces assurance gaps and duplicated reviews through a structured audit universe and coordinated assurance planning
  • Strengthens audit committee decision making with clearer reporting of risk themes, overdue actions and residual exposure
  • Raises the consistency and value of audit work through defined quality measures, review practices and capability priorities
  • Provides a usable action plan for improving internal audit governance, resource deployment and stakeholder engagement

Target competencies

Risk-based audit planningAudit committee reportingAssurance mappingStakeholder engagementAudit quality managementStrategic audit leadership

Who should attend

  • Chief Audit Executives — who need to align internal audit strategy, board reporting and assurance coverage with enterprise risk
  • Heads of Internal Audit — who are responsible for directing audit portfolios, teams and audit committee relationships
  • Deputy Chief Audit Executives — who are preparing to assume enterprise-wide audit leadership responsibilities
  • Internal Audit Directors — who must convert strategic risks into coordinated audit plans and consistent engagement delivery
  • Senior Internal Audit Managers — who lead complex audits and need to present themes and assurance conclusions to executives
  • Risk and Assurance Leaders — who coordinate second- and third-line activities and need clearer assurance mapping

Requirements and prerequisites

Participants should have working experience in internal audit, risk management, compliance, finance, or operational assurance. They should understand basic audit concepts such as audit objectives, controls, evidence, findings, risk ratings and reporting, and be able to read a process map, risk register or management report. Familiarity with the Three Lines Model and basic spreadsheet use is helpful. No prior Chief Audit Executive role, audit software licence, data analytics programming, accounting qualification or detailed knowledge of the IIA Global Internal Audit Standards is required. Complete beginners to auditing should first take a fundamentals-level internal audit course.

Training methodology

The course uses short instructor-led briefings to establish the standards and leadership methods, followed by practical work on a simulated organisation with changing strategic, operational and regulatory risks. Participants build and challenge an audit universe, score risks, allocate audit resources and prepare audit committee messages. Small-group workshops test alternative coverage decisions and escalation responses, while facilitated peer reviews assess the clarity of plans and reports. Each participant consolidates the work into an end-of-course action plan tailored to their own internal audit function or leadership role.

Course outline

Day 1: Positioning Internal Audit as Strategic Assurance

  • Chief Audit Executive mandate, authority and accountability
  • IIA Global Internal Audit Standards leadership requirements
  • Internal audit independence, objectivity and organisational positioning
  • The Three Lines Model and assurance role boundaries
  • Board, audit committee and executive stakeholder expectations
  • Internal audit value proposition and service catalogue design
  • Strategic objectives, risk appetite and audit relevance

Workshop: Participants diagnose the mandate and stakeholder expectations of a simulated audit function and produce a CAE stakeholder map with engagement priorities.

Day 2: Building the Risk-Based Audit Strategy

  • Audit universe design across entities, processes, programmes and technology
  • COSO ERM risk categories and risk appetite translation
  • Inherent risk, control maturity and residual risk scoring
  • Emerging risk identification and horizon-scanning techniques
  • Assurance mapping across risk, compliance and external assurance providers
  • Multi-year audit strategy development and coverage rationales
  • Annual audit plan prioritisation under resource constraints

Workshop: Participants construct an audit universe, complete a risk-scoring matrix and produce a prioritised annual audit plan for the case organisation.

Day 3: Directing High-Value Audit Delivery

  • Engagement portfolio governance and audit plan execution tracking
  • Scoping audits around risk statements, controls and root causes
  • Audit rating frameworks and consistent issue severity criteria
  • Root cause analysis using the five whys and cause-and-effect logic
  • Thematic analysis of recurring findings and systemic control failures
  • Data analytics use cases for continuous auditing and risk sensing
  • Audit workpaper quality review and evidence sufficiency

Workshop: Participants review a set of audit findings, identify root causes and themes, and produce an executive issue escalation brief.

Day 4: Influencing Governance and Reporting Insight

  • Audit committee reporting structures and decision-focused narratives
  • Assurance ratings, risk heat maps and dashboard design principles
  • Communicating uncertainty, limitations and scope exclusions
  • Managing disagreement with management over findings and action plans
  • Follow-up governance for overdue and ineffective remediation
  • Executive communication techniques for significant control failures
  • Crisis, fraud and regulatory escalation protocols

Workshop: Participants prepare and deliver a concise audit committee update on a major control failure, receiving structured peer and instructor feedback.

Day 5: Leading Quality, Capability and Continuous Improvement

  • Internal audit quality assurance and improvement programme design
  • Internal and external quality assessment preparation
  • Audit function KPIs for coverage, quality, efficiency and impact
  • Capability assessment, succession planning and skills matrices
  • Audit technology roadmap using AuditBoard, TeamMate+ and Power BI
  • Budgeting, resource models and co-sourcing decisions
  • Ninety-day CAE action planning and implementation governance

Workshop: Participants assemble and present a board-ready internal audit strategy pack and a 90-day implementation plan for their own or the case organisation.

Tools & standards covered

IIA Global Internal Audit Standards, COSO Enterprise Risk Management Framework, AuditBoard, Microsoft Power BI

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand core internal audit or assurance concepts, including controls, audit findings, risk ratings and reporting. The course assumes professional exposure to audit, risk, compliance, finance or operational assurance, but it does not require previous CAE experience.

A laptop is recommended for the planning templates, risk-scoring exercises and action-plan work. You do not need licences for AuditBoard, TeamMate+ or Power BI; demonstrations and course materials focus on the leadership decisions and outputs these tools support.

Yes. It is designed for newly appointed CAEs as well as experienced heads of audit who need a structured approach to strategy, audit committee reporting and quality leadership. Deputy CAEs and senior audit managers preparing for the role will also benefit.

Fundamentals courses focus on conducting individual audit engagements, testing controls and documenting workpapers. This course focuses on leading the whole function: setting risk-based coverage, directing portfolios, reporting to governance bodies and improving audit performance.

Participants leave with templates and a completed strategy pack that can be adapted to their own audit universe, risk assessment and annual planning cycle. The 90-day action plan identifies practical priorities for stakeholder engagement, reporting, quality and team capability.

You will leave with a risk-based audit universe, prioritised audit plan, stakeholder map, audit committee reporting outline, KPI set and CAE action plan. These deliverables are developed through the case work and can be tailored after the course to your organisation’s governance structure.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Auditing

5 Days Certificate

SAP Audit Management Reporting and Workflow Training Course

Internal audit teams need timely, defensible reporting without relying on disconnected spreadsheets, email-based review cycles, or manual st…

5 Days Certificate

Auditing Fundamentals for Finance Professionals Training Course

Finance professionals are frequently expected to provide assurance over account balances, reconciliations, controls, and management reports …

5 Days Certificate

AuditBoard SOX Compliance and Audit Workflow Training Course

SOX teams need more than a control inventory and annual testing calendar. They must coordinate control owners, testers, reviewers, external …

5 Days Certificate

IIA Global Internal Audit Standards Implementation Training Course

The 2024 IIA Global Internal Audit Standards raise the bar for how internal audit functions are governed, planned, performed, communicated a…