Course overview
Audit and risk management are often described as separate disciplines that happen to share a vocabulary. In practice, audit technique is how risk management gets tested. A risk register that has never been challenged by evidence is a list of opinions. A control that has never been reperformed is an assumption. Every serious statement an organization makes about its residual risk rests, somewhere underneath, on somebody having tested something and documented what they found.
This course works through the technique in depth across twelve units. It moves from the foundations of auditing and risk assessment, through internal control evaluation, compliance and regulatory auditing, fraud detection, planning and execution, reporting, digital audit tools, governance and ethics, and into sustainability auditing, closing with an integrated case that pulls the techniques together. Reference points include ISO 31000, the COSO frameworks, ISO 19011 and the IIA International Professional Practices Framework.
Why technique is the thing that transfers
Frameworks change. Regulations change faster. What holds its value across a career is the ability to look at a process and know what evidence would prove it works, how much of it you need, and what your conclusion can honestly claim. That is technique, and it is what separates an auditor who produces findings from one who produces a report nobody can argue with.
The tooling has moved too. Full-population testing, continuous monitoring and analytics have shifted the auditor's job from selecting samples to designing exception logic and interpreting what the exceptions mean. And the subject matter has widened: sustainability data, algorithmic decisions and third-party dependencies now sit inside audit scopes that used to stop at the company's own ledger.
Course objectives
By the end of the course, participants will be able to:
- Plan audit coverage from a risk assessment and a clear mandate.
- Scope the work and fix the criteria before any testing.
- Inspect key controls and judge whether they are adequate.
- Follow an obligation through to the control that covers it.
- Investigate fraud risk with analytics rather than intuition.
- Sample a population and stand behind the projection.
- Draft findings that carry a clear consequence for the business.
- Extract a full population from a system and test all of it.
- Escalate an ethical conflict and keep the record intact.
- Verify sustainability data before assurance is given.
Course outline
Unit 1: Introduction to auditing and risk management
- The Three Lines Model and where audit sits inside it.
- ISO 31000 principles as the shared risk language.
- The mandate that lets an auditor reach any part of the firm.
- Advisory work and the objectivity it puts at risk.
Unit 2: Risk assessment for audit planning
- Building an audit universe that reflects real exposure.
- Testing the blind spots in the enterprise risk register.
- Inherent exposure in third parties and technology change.
- Translating risk into scope, objectives and audit criteria.
Unit 3: Internal control evaluation
- COSO and the difference between entity and process control.
- Walkthroughs that trace a control back to its risk.
- Showing a control ran, not merely that it was designed.
- Aggregating deficiencies into a defensible conclusion.
Unit 4: Compliance and regulatory auditing
- Tracing each obligation to a control and an owner.
- Applying ISO 19011 technique to any audit, financial or not.
- Judging whether monitoring surfaces real nonconformity.
- Regulatory breach records an inspector will accept.
Unit 5: Fraud detection and prevention
- The fraud triangle and ACFE scheme categories by process.
- Analytics that surface payments no one can explain.
- Benford analysis and what it does not prove.
- Segregation of duties, master data and override monitoring.
Unit 6: Audit planning and execution
- Scope agreed in writing and defended when challenged.
- Materiality and the sample size it justifies.
- Evidence a reviewer accepts and evidence they question.
- Writing working papers and clearing review notes properly.
Unit 7: Audit reporting and communication
- The finding that survives a challenge from management.
- Agreeing corrective actions with named owners and dates.
- Conclusion-first writing in the reader's own currency.
- Closing meetings and recording a disagreement in full.
Unit 8: Digital tools in auditing
- Full-population testing versus sampling.
- Audit analytics in IDEA, ACL and spreadsheet routines.
- Continuous auditing thresholds and alert fatigue.
- Extracting ERP data and validating its completeness.
Unit 9: Governance and ethical considerations in auditing
- Reporting to a committee rather than to the audited.
- Familiarity and self-review threats with their safeguards.
- Professional skepticism as documented behavior.
- Ethical dilemmas around a finding management wants removed.
Unit 10: ESG and sustainability auditing
- Sustainability reporting standards and their data trail.
- Auditing estimation methods and conversion factors.
- Limited versus reasonable assurance under ISAE 3000.
- Reporting greenwashing where the data does not hold.
Unit 11: Global best practices in auditing
- Coverage overlap between the second and third lines.
- External review of how well the function performs.
- Measures of audit value beyond reports issued.
- Co-sourcing skills the audit function does not hold.
Unit 12: Integrated audit and risk case study
- A documented case carried through every technique taught.
- Control testing and analytics over the case data.
- Drafting findings and defending them against challenge.
- Taking residual exposure and late actions to the committee.
How the course is delivered
The course runs on documented case material and guided analysis: risk registers, control matrices, working papers, transaction extracts and real audit reports that participants examine and debate. Worked examples take sampling, evidence evaluation and analytics decisions through step by step, and the final unit runs as an extended case discussion. There is no live software environment; the tools are explained through their outputs and logic. The course is educational and does not certify participants or assess any organization's audit function. Auditors who want to push further into data technique should look at Data Analytics for Risk Identification.
Who should attend
- Internal auditors and audit seniors who want a complete grounding in audit technique.
- Risk managers who need to understand how their frameworks will be tested.
- Internal control and compliance specialists responsible for control testing.
- Heads of audit building capability and consistency across a team.
About EuroQuest International Training
EuroQuest International Training was founded in 2015 by a team with more than 25 years of experience in professional development. We deliver over 1,000 courses and have trained more than 15,000 participants. Our head office is in Bratislava, Slovakia, with hubs in Dubai, London, Barcelona, Istanbul, Vienna, Paris and Geneva. Courses are written and reviewed by practitioners from the fields they teach.
Frequently asked questions
Is this course too long if I already audit for a living?
Experienced auditors tend to use the longer format to fill specific gaps: sampling defensibility, analytics logic, sustainability data, and reporting that survives challenge. The twelve units are sequenced so each can stand on its own within the whole.
Does the course include a live lab?
No. Analytics and audit tools are taught through their logic and outputs, using documented data extracts and worked examples. There is no software environment to log into.
Will I be certified as an auditor at the end?
No. You receive a EuroQuest attendance certificate. The course is educational and does not provide a professional audit certification or authorize any regulated activity.
Related courses
- Enterprise Risk Management Strategies
- Developing and Managing an Effective Audit Plan
- Auditing Risk and Compliance Practices
- Auditing AI and Digital Transformation Risks
Register for this course
Select a city and date from the schedule above and register online, or contact the EuroQuest team about in-house delivery for an audit function that wants one shared standard of technique.
All Course Dates & Locations
19 dates · 14 cities · Sep 2026 – Jun 2027