Internal Controls Design, Implementation & Testing
Practitioner2 daysGovernance, Assurance & Integrity
Programme overview
The control fundamentals that underpin risk, compliance and audit work. Covers the COSO Internal Control Integrated Framework, control design for the core financial and operational cycles, and how to test whether a control actually operates. Strong emphasis on segregation of duties and control design in small teams where full segregation is impossible.
Who should attend
Finance managers and accountants, internal auditors, risk and compliance officers, process and operations managers, ICT managers, and business owners in growing organisations.
Sectors
All sectors. Particularly useful for public enterprises addressing Auditor General findings and for growing organisations formalising controls.
Modules
- COSO Internal Control Integrated Framework: the five components and seventeen principles
- Control types: preventive, detective, corrective, directive, and manual versus automated
- Entity level controls and the control environment
- Designing controls for the revenue, procurement, payments, payroll and inventory cycles
- Segregation of duties, and compensating controls when the team is too small to segregate
- Authorisation and delegation of authority frameworks
- Reconciliations, exception reporting and management review controls
- IT general controls: access, change management, operations, and why they underpin everything else
- Documenting controls: narratives, flowcharts and risk and control matrices
- Testing control design versus operating effectiveness
- Identifying and reporting control deficiencies, and distinguishing a deficiency from a material weakness
- Remediation, and controls in a change or system implementation environment
Learning outcomes
On completion delegates will be able to:
- Apply the COSO framework to your control environment
- Design proportionate controls for core business cycles
- Address segregation of duties limitations with compensating controls
- Document controls in a risk and control matrix
- Test controls and evaluate deficiencies
- Plan and track control remediation
Tools and templates provided
- Risk and control matrix templates for six business cycles
- Delegation of authority framework template
- Control testing programme
- Deficiency evaluation guide
Assessment and certification
Control design exercise and an assessed testing exercise.
Certificate of Completion.
