Strategic Internal Audit Leadership for Chief Audit Executives Training Course
| Course code | SD-A-058 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Auditing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Chief Audit Executives are expected to provide more than assurance over completed transactions. They must help the board and executive team understand whether the organisation’s most material risks are governed, monitored and responded to effectively. This requires an audit function that can translate strategy, risk appetite, regulatory obligations and emerging threats into a focused audit plan, credible reporting and measurable improvement. Without this leadership discipline, internal audit can become a cycle of low-value reviews, unresolved findings and reports that do not influence management decisions.
This five-day course equips participants to lead an internal audit function as a strategic business partner while preserving independence and objectivity. Participants learn to build a risk-based audit universe, assess enterprise risks using COSO ERM concepts, develop a multi-year and annual audit plan, set engagement priorities, direct quality assurance, and communicate significant issues to audit committees. They also practise defining audit performance measures, managing stakeholder expectations, escalating themes from audit findings and using data analytics to strengthen assurance coverage.
Delivery combines instructor-led technical sessions with board-reporting scenarios, audit planning workshops, peer review and case-based decision making. Participants work through a simulated organisation to create a board-ready internal audit strategy pack containing an audit universe, risk assessment, annual plan, stakeholder map, key performance indicators and reporting outline. The course is suited to current and aspiring CAEs, heads of internal audit and senior audit leaders who need to improve the relevance, visibility and governance impact of their function.
Course objectives
By the end of this course, participants will be able to:
- Construct a risk-based audit universe linked to strategic objectives, processes, legal entities and emerging risks
- Apply COSO ERM risk assessment criteria to prioritise auditable areas and justify assurance coverage
- Develop a multi-year internal audit strategy and annual audit plan using risk, resource and capability assumptions
- Design an audit committee reporting pack that communicates assurance ratings, thematic findings and unresolved risks
- Establish internal audit performance measures using KPIs, quality indicators and stakeholder feedback mechanisms
- Map key stakeholders and plan engagement approaches that protect independence while improving audit influence
- Evaluate internal audit conformance against the IIA Global Internal Audit Standards and define improvement actions
- Produce a practical chief audit executive action plan for strengthening governance, audit delivery and team capability
Benefits of attending
For you
- Gain a defensible method for presenting risk-based audit priorities to boards, audit committees and executive management
- Build confidence in moving from engagement oversight to enterprise-level internal audit leadership
- Create evidence of CAE-readiness through a completed internal audit strategy and audit planning portfolio
- Improve the ability to challenge management constructively while maintaining audit independence and professional credibility
- Develop practical measures for demonstrating internal audit value through coverage, finding quality, timeliness and stakeholder insight
For your organisation
- Improves alignment between internal audit coverage, strategic objectives, enterprise risks and regulatory obligations
- Reduces assurance gaps and duplicated reviews through a structured audit universe and coordinated assurance planning
- Strengthens audit committee decision making with clearer reporting of risk themes, overdue actions and residual exposure
- Raises the consistency and value of audit work through defined quality measures, review practices and capability priorities
- Provides a usable action plan for improving internal audit governance, resource deployment and stakeholder engagement
Target competencies
Who should attend
- Chief Audit Executives — who need to align internal audit strategy, board reporting and assurance coverage with enterprise risk
- Heads of Internal Audit — who are responsible for directing audit portfolios, teams and audit committee relationships
- Deputy Chief Audit Executives — who are preparing to assume enterprise-wide audit leadership responsibilities
- Internal Audit Directors — who must convert strategic risks into coordinated audit plans and consistent engagement delivery
- Senior Internal Audit Managers — who lead complex audits and need to present themes and assurance conclusions to executives
- Risk and Assurance Leaders — who coordinate second- and third-line activities and need clearer assurance mapping
Requirements and prerequisites
Participants should have working experience in internal audit, risk management, compliance, finance, or operational assurance. They should understand basic audit concepts such as audit objectives, controls, evidence, findings, risk ratings and reporting, and be able to read a process map, risk register or management report. Familiarity with the Three Lines Model and basic spreadsheet use is helpful. No prior Chief Audit Executive role, audit software licence, data analytics programming, accounting qualification or detailed knowledge of the IIA Global Internal Audit Standards is required. Complete beginners to auditing should first take a fundamentals-level internal audit course.
Training methodology
The course uses short instructor-led briefings to establish the standards and leadership methods, followed by practical work on a simulated organisation with changing strategic, operational and regulatory risks. Participants build and challenge an audit universe, score risks, allocate audit resources and prepare audit committee messages. Small-group workshops test alternative coverage decisions and escalation responses, while facilitated peer reviews assess the clarity of plans and reports. Each participant consolidates the work into an end-of-course action plan tailored to their own internal audit function or leadership role.
Course outline
Day 1: Positioning Internal Audit as Strategic Assurance
- Chief Audit Executive mandate, authority and accountability
- IIA Global Internal Audit Standards leadership requirements
- Internal audit independence, objectivity and organisational positioning
- The Three Lines Model and assurance role boundaries
- Board, audit committee and executive stakeholder expectations
- Internal audit value proposition and service catalogue design
- Strategic objectives, risk appetite and audit relevance
Workshop: Participants diagnose the mandate and stakeholder expectations of a simulated audit function and produce a CAE stakeholder map with engagement priorities.
Day 2: Building the Risk-Based Audit Strategy
- Audit universe design across entities, processes, programmes and technology
- COSO ERM risk categories and risk appetite translation
- Inherent risk, control maturity and residual risk scoring
- Emerging risk identification and horizon-scanning techniques
- Assurance mapping across risk, compliance and external assurance providers
- Multi-year audit strategy development and coverage rationales
- Annual audit plan prioritisation under resource constraints
Workshop: Participants construct an audit universe, complete a risk-scoring matrix and produce a prioritised annual audit plan for the case organisation.
Day 3: Directing High-Value Audit Delivery
- Engagement portfolio governance and audit plan execution tracking
- Scoping audits around risk statements, controls and root causes
- Audit rating frameworks and consistent issue severity criteria
- Root cause analysis using the five whys and cause-and-effect logic
- Thematic analysis of recurring findings and systemic control failures
- Data analytics use cases for continuous auditing and risk sensing
- Audit workpaper quality review and evidence sufficiency
Workshop: Participants review a set of audit findings, identify root causes and themes, and produce an executive issue escalation brief.
Day 4: Influencing Governance and Reporting Insight
- Audit committee reporting structures and decision-focused narratives
- Assurance ratings, risk heat maps and dashboard design principles
- Communicating uncertainty, limitations and scope exclusions
- Managing disagreement with management over findings and action plans
- Follow-up governance for overdue and ineffective remediation
- Executive communication techniques for significant control failures
- Crisis, fraud and regulatory escalation protocols
Workshop: Participants prepare and deliver a concise audit committee update on a major control failure, receiving structured peer and instructor feedback.
Day 5: Leading Quality, Capability and Continuous Improvement
- Internal audit quality assurance and improvement programme design
- Internal and external quality assessment preparation
- Audit function KPIs for coverage, quality, efficiency and impact
- Capability assessment, succession planning and skills matrices
- Audit technology roadmap using AuditBoard, TeamMate+ and Power BI
- Budgeting, resource models and co-sourcing decisions
- Ninety-day CAE action planning and implementation governance
Workshop: Participants assemble and present a board-ready internal audit strategy pack and a 90-day implementation plan for their own or the case organisation.
Tools & standards covered
IIA Global Internal Audit Standards, COSO Enterprise Risk Management Framework, AuditBoard, Microsoft Power BI
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Auditing
SAP Audit Management Reporting and Workflow Training Course
Internal audit teams need timely, defensible reporting without relying on disconnected spreadsheets, email-based review cycles, or manual st…
Auditing Fundamentals for Finance Professionals Training Course
Finance professionals are frequently expected to provide assurance over account balances, reconciliations, controls, and management reports …
AuditBoard SOX Compliance and Audit Workflow Training Course
SOX teams need more than a control inventory and annual testing calendar. They must coordinate control owners, testers, reviewers, external …
IIA Global Internal Audit Standards Implementation Training Course
The 2024 IIA Global Internal Audit Standards raise the bar for how internal audit functions are governed, planned, performed, communicated a…