COSO Internal Control Framework
Many organisations have documented controls, yet still suffer errors, fraud and audit findings because controls are not linked to risks, are not operating as designed, or are not monitored. This programme gives finance, audit, risk and compliance practitioners a practical method to design, assess and improve internal control using the COSO Internal Control Integrated Framework.
Internal control is often treated as a compliance exercise: a set of procedures written for the auditors, a controls matrix that is rarely updated and testing that focuses on documents rather than on whether risks are actually managed. The control environment and tone at the top are discussed but not assessed, IT controls are left to the IT department, and deficiencies are reported without a clear view of their severity. Newer areas such as sustainability data, outsourced services and automation are often outside the control system altogether.
This programme applies the COSO framework as a working tool. It moves through five stages: understanding the framework and its objectives, building the control environment and assessing risk, designing control activities including IT controls, managing information, communication and monitoring, and evaluating the system and reporting deficiencies.
Built on recognised practice. The programme is built on the COSO Internal Control Integrated Framework (2013) with its five components and 17 principles, and references COSO Enterprise Risk Management: Integrating with Strategy and Performance, COSO guidance on achieving effective internal control over sustainability reporting (2023), COSO fraud risk management guidance, the IIA Three Lines Model and the IIA Global Internal Audit Standards. They are used to show how internal control connects to governance, risk management and assurance.
Decisions this programme improves. Which risks need key controls and which controls add little value; whether a control is designed well and operating effectively; how to balance preventive, detective, manual and automated controls; how serious a deficiency is and who needs to know; and how to extend internal control to new reporting areas and technologies.
How it is delivered. Twenty hours across five sessions, built around one running case: a government entity or company with procurement, payments, payroll and financial reporting processes. Participants map risks to the 17 principles, build a risk and control matrix, design test steps, evaluate deficiencies and prepare a summary for an audit committee.
In-house option. For organisations, the programme can be tailored to your own processes, control frameworks, ERP systems and regulatory requirements, and delivered to finance, internal audit, risk and compliance teams together so that all three lines work from the same framework.
Who Should Attend
Objectives
Course Outline
Competencies
Live Online
Related Topics
Errors and misstatements in financial reports usually start in the underlying data: unsupported journal entries, weak cut-off, poor estimates and revenue or expenditure recorded in the wrong period. This programme gives auditors and finance professionals a structured, risk-based approach to auditing financial data and financial statements, from planning and materiality to evidence, fraud risk and reporting.
An audit can find the right issues and still fail if management does not accept the findings or act on them. This programme gives internal auditors practical communication skills for every stage of an engagement: opening meetings, interviews, handling resistance, writing clear findings and reports, and presenting results to management and audit committees.
Public money is most exposed at the point of payment: duplicate or unsupported invoices, payments to ineligible beneficiaries, weak segregation of duties and approvals that exist only on paper. This programme gives public sector auditors a structured approach to the audit cycle and to reviewing government payments, from planning and risk assessment to evidence, findings and follow-up.
