Course overview
Auditing a warehouse is straightforward: count the stock, test the process, report the variance. Auditing risk management and compliance is harder, because the subject of the audit is itself a control function. The risk register looks complete. The compliance monitoring plan looks thorough. The question the audit committee actually wants answered is whether these documents describe anything that happens in the business, and whether the residual risk positions the board relies on are supported by evidence.
This course sets out how to audit risk and compliance practices with the same discipline applied to any other process. It covers risk-based auditing, evaluation of compliance frameworks, internal control and fraud detection, and reporting that the board and regulators can rely on. Reference points include ISO 31000, the COSO enterprise risk framework, ISO 19011 for auditing management systems, and the IIA International Professional Practices Framework.
The gap between the framework and the floor
Risk and compliance functions have grown quickly and, in many organizations, formalized faster than they have matured. The artifacts are impressive: taxonomies, appetite statements, monitoring calendars, dashboards. Underneath, three problems recur. Risk appetite is stated at a level too abstract to constrain any actual decision. Monitoring is performed as a completeness check instead of a test of whether the control worked. And residual risk ratings are adjusted downward to reflect planned actions that have not been implemented.
An auditor who tests the plumbing rather than admiring the diagram finds these quickly. That is uncomfortable work, since it means giving a critical opinion on colleagues in adjacent functions, which is precisely why the evidence has to be watertight.
Course objectives
By the end of the course, participants will be able to:
- Audit a risk framework against ISO 31000 and COSO criteria.
- Corroborate a conformity conclusion with the evidence behind it.
- Contest a tolerance limit that no recorded breach ever crossed.
- Judge the distortion a coarse scoring scale introduces.
- Grade a compliance program by what its findings changed.
- Weigh what an attestation proves against what it merely records.
- Scrutinize the exceptions a compliance team has quietly let stand.
- Conclude on the overall maturity of both assurance functions.
Course outline
Unit 1: Principles of auditing risk and compliance
- The second line as the auditee rather than the auditor.
- Criteria drawn from ISO 31000, COSO, and internal policy.
- Auditing a management system with ISO 19011 techniques.
- Independence and objectivity when the auditee sits nearby.
Unit 2: Risk-based auditing practices
- Testing which emerging risks never got recorded at all.
- Risk appetite tested by a limit, a breach, and an approval.
- Two different exposures in one five-by-five matrix square.
- Residual risk rated against an action still on a slide.
Unit 3: Evaluating compliance programs
- Obligation ownership and the rule that changed unnoticed.
- Compliance monitoring findings that led precisely nowhere.
- Measuring understanding, not attestations nobody read.
- Breach reports and the remediation promised to a regulator.
Unit 4: Internal controls and fraud detection
- Design of the key controls risk and compliance rely on.
- Access that lets one person suppress a compliance alert.
- Waived checks and dormant alerts inside the second line.
- Outlier tests over every case the compliance team cleared.
Unit 5: Strengthening audit reporting and readiness
- Findings precise enough for the second line to act on.
- Aggregating a maturity view for the audit committee.
- Documents that will not survive a regulator's request.
- Follow-up that proves a fixed framework changed a decision.
How the course is delivered
The course is discussion-driven and built on documented material: risk registers, appetite statements, monitoring plans and audit findings that participants critique in the room. Worked examples trace a single risk from the register through the limit, the breach and the approval, which is where the framework usually falls apart. Participants are invited to bring anonymized examples from their own organizations. The course is educational, does not certify participants, and does not assess or validate any organization's compliance status. Those looking to build the frameworks themselves rather than audit them will find Developing Risk Management Frameworks the better starting point.
Who should attend
- Internal auditors who audit risk, compliance and control functions.
- Risk managers and compliance officers who want to understand how their work will be tested.
- Internal control specialists and second-line monitoring staff.
- Governance professionals and audit committee members who read assurance reports on the second line.
About EuroQuest International Training
EuroQuest International Training was founded in 2015 by a team with more than 25 years of experience in professional development. We run over 1,000 courses and have trained more than 15,000 participants. Our head office is in Bratislava, Slovakia, and we deliver through hubs in Dubai, London, Barcelona, Istanbul, Vienna, Paris and Geneva. Course content is written and reviewed by practitioners from the fields it covers.
Frequently asked questions
How is this different from a general internal audit course?
The subject of the audit is the assurance machinery itself: the risk framework, the appetite statement, the monitoring plan. The techniques overlap with any audit, but the criteria, the evidence and the political dynamics are quite different.
Do I need to know ISO 31000 or COSO before attending?
No. Both are introduced and used as audit criteria during the course. Prior familiarity helps but is not assumed.
Will this course certify me to audit a management system?
No. Certification audits are performed by certification bodies with their own recognized auditor schemes. This course is educational and does not certify participants or organizations.
Related courses
- Auditing Techniques for Effective Risk Management
- Governance, Risk, and Compliance (GRC) Frameworks
- Best Practices in Internal and External Auditing
- Financial Auditing and Regulatory Compliance
Register for this course
Choose a city and date from the schedule above to register, or contact EuroQuest for in-house delivery to an audit, risk or compliance team.
All Course Dates & Locations
28 dates · 15 cities · Oct 2026 – Jun 2027