New — Free Risk Maturity Assessment. Start now →
All training programmes
TVA/GA/03Assurance & Integrity

Internal Controls Design, Implementation & Testing

Practitioner2 daysGovernance, Assurance & Integrity

Programme overview

The control fundamentals that underpin risk, compliance and audit work. Covers the COSO Internal Control Integrated Framework, control design for the core financial and operational cycles, and how to test whether a control actually operates. Strong emphasis on segregation of duties and control design in small teams where full segregation is impossible.

Who should attend

Finance managers and accountants, internal auditors, risk and compliance officers, process and operations managers, ICT managers, and business owners in growing organisations.

Sectors

All sectors. Particularly useful for public enterprises addressing Auditor General findings and for growing organisations formalising controls.

Modules

  1. COSO Internal Control Integrated Framework: the five components and seventeen principles
  2. Control types: preventive, detective, corrective, directive, and manual versus automated
  3. Entity level controls and the control environment
  4. Designing controls for the revenue, procurement, payments, payroll and inventory cycles
  5. Segregation of duties, and compensating controls when the team is too small to segregate
  6. Authorisation and delegation of authority frameworks
  7. Reconciliations, exception reporting and management review controls
  8. IT general controls: access, change management, operations, and why they underpin everything else
  9. Documenting controls: narratives, flowcharts and risk and control matrices
  10. Testing control design versus operating effectiveness
  11. Identifying and reporting control deficiencies, and distinguishing a deficiency from a material weakness
  12. Remediation, and controls in a change or system implementation environment

Learning outcomes

On completion delegates will be able to:

  • Apply the COSO framework to your control environment
  • Design proportionate controls for core business cycles
  • Address segregation of duties limitations with compensating controls
  • Document controls in a risk and control matrix
  • Test controls and evaluate deficiencies
  • Plan and track control remediation

Tools and templates provided

  • Risk and control matrix templates for six business cycles
  • Delegation of authority framework template
  • Control testing programme
  • Deficiency evaluation guide

Assessment and certification

Control design exercise and an assessed testing exercise.

Certificate of Completion.