Course overview
Compliance and internal audit are separate by design. Compliance sits in the second line, writes the policies, trains the business and monitors adherence. Internal audit sits in the third line and independently tests whether any of that is working. The separation matters, but in many organizations it has hardened into a wall: compliance monitoring results never reach the audit plan, audit findings on control weaknesses never reach the compliance risk assessment, and the board receives two reports that disagree about how exposed the company is.
This course examines how the two functions can be run as complementary parts of one control system without compromising audit independence. It works through compliance frameworks such as ISO 37301 and the elements regulators look for in a compliance function, then turns to the internal audit side, covering the IIA International Professional Practices Framework, control testing, and the treatment of fraud and misconduct.
Why this is under pressure now
Enforcement guidance in several jurisdictions now asks whether a compliance function was adequately resourced, whether it had genuine access to data, and whether its findings were acted on. A written policy is no longer treated as evidence of anything on its own. The practical consequence is that both compliance monitoring and internal audit are expected to produce testable evidence: which control, which population, which sample, which exceptions, which remediation, which retest.
Meanwhile the compliance perimeter keeps widening. Data protection, sanctions screening, anti-bribery, competition, supply chain due diligence and ESG disclosure all land in the same function, often with the same headcount as five years ago. Prioritizing that work with a defensible risk assessment, and letting audit test the areas that matter most, is now a survival skill.
Course objectives
By the end of the course, participants will be able to:
- Draft a standard short enough that people actually follow it.
- Delimit what compliance may stop and what it may only flag.
- Document independence and objectivity in the charter wording.
- Split functional from administrative reporting when they conflict.
- Record sampling and review notes a successor can retrace.
- Authorize spending through limits reset for current prices.
- Retain evidence and confidentiality once an allegation arrives.
- Consolidate audit and compliance coverage into one board view.
Course outline
Unit 1: Corporate compliance frameworks
- The ninety-page policy nobody opens.
- Documented power for compliance to halt a payment.
- Recorded reasons behind each compliance risk rating.
- Policy architecture that separates a rule from guidance.
Unit 2: Internal audit principles and practices
- Dual lines to the audit committee and to the executive.
- A charter that names who can dismiss the head of audit.
- Written grounds for leaving an area uncovered.
- Audit working papers that stand without their author.
Unit 3: Strengthening internal controls
- Control ownership named in the procedure, not assumed.
- Duty conflicts that a small finance team cannot avoid.
- Delegated authority and approval limits set long ago.
- Screenshots with no date, and evidence that carries one.
Unit 4: Detecting and preventing fraud
- The invoice approved by the person who raised it.
- Expense, payroll, and journal entry patterns that repeat.
- Logging an allegation from receipt to written conclusion.
- Legal counsel called before the first interview.
Unit 5: Best practices for audit and compliance integration
- Scope wording that keeps two teams off the same control.
- Two reports describing the same weakness differently.
- Analytics that shrink sample-based testing.
- Residual risk and overdue actions in one board paper.
How the course is delivered
Sessions are discussion-led and built around documented case material: enforcement cases, control matrices, compliance risk registers and anonymized audit findings that participants read and critique. Worked examples take control tests and fraud analytics through step by step. Participants bring their own compliance and audit questions, and time is reserved for those. The course is educational. It does not certify participants, does not assess any organization's compliance status, and is not legal advice. A useful companion for the governance side of the picture is Governance Risk and Compliance (GRC) Best Practices.
Who should attend
- Compliance officers and compliance managers who work alongside an internal audit function.
- Internal auditors who audit compliance processes and want a sharper grasp of the obligations behind them.
- Risk managers and internal control specialists responsible for control design and monitoring.
- Finance, legal and governance professionals who sit on the receiving end of audit and compliance reports.
About EuroQuest International Training
EuroQuest International Training was founded in 2015 by a team with more than 25 years of experience in professional development. We run over 1,000 courses and have trained more than 15,000 participants. Our head office is in Bratislava, Slovakia, with delivery hubs in Dubai, London, Barcelona, Istanbul, Vienna, Paris and Geneva. Our courses are developed and reviewed by practitioners working in the fields they teach.
Frequently asked questions
Is this course aimed at compliance officers or at auditors?
Both, deliberately. The two groups spend the sessions looking at the same controls from different sides, which is usually where the useful conversations start. No prior audit qualification is assumed.
Does the course cover a specific national regulation?
It works from frameworks that travel across jurisdictions, such as ISO 37301 and COSO, and uses named regulations only as illustrations. Your own regulatory obligations still need to be assessed with qualified counsel.
Will I receive a compliance certification at the end?
No. EuroQuest issues a course attendance certificate. The course is educational and does not provide a professional certification, nor does it verify that your organization meets any standard.
Related courses
- Best Practices in Internal and External Auditing
- Creating a Culture of Compliance and Accountability
- Fraud Detection and Prevention Strategies
- Auditing Risk and Compliance Practices
Register for this course
Pick a city and date from the schedule above to register, or contact the EuroQuest team to arrange in-house delivery for a compliance and audit team working together.
All Course Dates & Locations
29 dates · 17 cities · Oct 2026 – Jun 2027