Course overview
Financial institutions are audited more often, by more people, against more rules than almost any other kind of business. Internal audit reports to the audit committee. External audit signs the statements. The prudential regulator inspects capital, liquidity and governance. The conduct regulator looks at customer outcomes. The financial intelligence unit expects suspicious activity reports. Each has its own evidence expectations, and the same underlying control is often tested by all of them in different words.
This course sets out how audit and compliance function inside that environment. It covers the regulatory frameworks that shape the sector, risk-based audit practices adapted to financial services, compliance monitoring and internal control, financial crime and fraud detection, and how to prepare for a regulatory inspection without theater.
What makes this sector different
Two things. First, the rules are prescriptive and they move. Capital and liquidity requirements under the Basel framework, anti-money laundering obligations shaped by FATF recommendations, sanctions regimes that change with the news, conduct rules on selling practices and complaints, data protection duties over customer records: an obligation register in a bank is a living document, not an annual exercise.
Second, the consequences are personal and immediate. Regulators impose remediation deadlines, restrict business lines, and in serious cases hold named individuals accountable. That shifts the internal dynamic: audit findings in a financial institution are not suggestions, and a control weakness reported and left unremediated becomes evidence against the institution when the inspection arrives.
Course objectives
By the end of the course, participants will be able to:
- Cover the areas that draw the most supervisory attention.
- File a defensible statement of what was not audited this year.
- Test controls across credit, treasury, and payments.
- Reconcile a policy claim with how the control actually runs.
- Substantiate an alert backlog as an audit finding.
- Prepare the document trail an inspection will actually test.
- Close a remediation commitment with evidence a regulator accepts.
- Track a finding across cycles until it stays closed.
Course outline
Unit 1: Regulatory frameworks for financial institutions
- Supervisory attention as the driver of audit coverage.
- Expectations a supervisor holds beyond the written rule.
- Personal consequences that change how a finding lands.
- Prior regulator correspondence as an input to scoping.
Unit 2: Risk-based audit practices
- The audit universe of a bank and the deliberate gaps.
- Risk scoring driven by regulatory sensitivity, not revenue.
- Auditing a credit file from approval limit to collateral.
- Auditing treasury payments a single person can release.
Unit 3: Compliance monitoring and internal controls
- Escalation of a disputed finding to the audit committee.
- Dual authorization and the limit that stopped applying.
- Compliance monitoring evidence an auditor retests.
- Notifying a breach inside the deadline it carries.
Unit 4: Fraud detection and prevention
- Customer onboarding files sampled for the skipped check.
- Unworked alert queues sized and dated for the report.
- Dormant accounts nobody reviews and the access they carry.
- Exceptions approved by the person who requested them.
Unit 5: Preparing for regulatory reviews and inspections
- Evidence an inspection tests rather than written policy.
- Building a remediation plan a regulator will accept.
- Tracking a commitment that closed on paper and came back.
- Committee packs that state the honest position on exposure.
How the course is delivered
Sessions use documented case material from the sector: enforcement notices, published inspection themes, monitoring reports and anonymized audit findings that participants read and dissect. Worked examples take transaction monitoring alerts and credit files through the assessment step by step. Discussion is central, and participants bring their own regulatory questions to the group. The course is educational. It does not certify participants, does not assess any institution's regulatory compliance, and is not legal or financial advice. Teams that need depth on the financial crime side should also consider Anti-Money Laundering (AML) and Compliance.
Who should attend
- Internal auditors in banks, insurers, payment firms and other regulated institutions.
- Compliance officers, AML officers and monitoring staff in financial services.
- Risk managers and internal control specialists in regulated firms.
- Finance, operations and governance professionals who deal with regulators and inspections.
About EuroQuest International Training
EuroQuest International Training was founded in 2015 by a team with more than 25 years of experience in professional development. We run over 1,000 courses and have trained more than 15,000 participants. Our head office is in Bratislava, Slovakia, with delivery hubs in Dubai, London, Barcelona, Istanbul, Vienna, Paris and Geneva. Our courses are developed and reviewed by practitioners from the fields they teach.
Frequently asked questions
Which jurisdiction's rules does the course follow?
It works from international frameworks such as Basel and the FATF recommendations, using national rules as illustrations. Your own regulator's requirements must be confirmed locally with qualified advisers.
Is the course suitable for insurers and payment firms, not just banks?
Yes. The prudential detail is heaviest for banks, but the audit method, compliance monitoring, financial crime controls and inspection readiness apply across regulated financial institutions.
Does the course provide regulatory advice for my institution?
No. It is educational. It does not assess your institution's compliance position, does not certify participants, and is not a substitute for legal or regulatory advice.
Related courses
- Financial Auditing and Regulatory Compliance
- Corporate Governance in Financial Institutions
- Financial Crime Prevention and Regulatory Compliance
- Fraud Detection and Prevention Strategies
Register for this course
Choose a city and date from the schedule above to register, or contact the EuroQuest team about in-house delivery for an audit or compliance team in a regulated institution.
All Course Dates & Locations
27 dates · 15 cities · Sep 2026 – Jun 2027