Course overview
Internal control is the machinery that turns a policy into a behavior. A rule that says purchase orders must be approved does nothing on its own; the control is the system configuration that will not process an invoice without a matching order, and the person whose job it is to investigate the exceptions. Organizations rarely fail because they lacked a rule. They fail because the control that was supposed to enforce it was designed around an org chart that changed two years ago.
This course covers internal control and risk mitigation across twelve units, from risk assessment and control design through compliance alignment, fraud prevention, monitoring, governance, digital tooling and crisis response, closing with an integrated case. The reference frameworks are COSO Internal Control, COSO ERM and ISO 31000.
Why control design is where the value sits
Most control effort is spent on testing, which finds problems after they have occurred. Design is cheaper and more effective, and it starts with a question most control libraries never answer: which specific risk does this control address, and would a failure of the control actually let that risk through?
Ask it of a real control library and the results are uncomfortable. Controls accumulate; nobody removes them. Three controls cover the same low-value risk while a material exposure has none. A key control depends on a reconciliation performed by the same person who posts the entries. The exercise of mapping each control to a named risk, an owner and a test is unglamorous and it consistently finds the gaps.
Course objectives
By the end of the course, participants will be able to:
- Design controls that match the risk they exist to stop.
- Segregate duties across authorization, recording and custody.
- Compensate for conflicts a small team cannot remove.
- Test whether a control was designed well and then ran.
- Rate a deficiency by severity and aggregate the total.
- Remediate a failed control and confirm who signs it off.
- Document an obligation, its control and the evidence behind it.
- Justify a treatment choice against what the control costs.
- Tighten controls in the processes where fraud schemes land.
- Automate a control and prove it still works after a change.
- Authorize emergency action and review it afterwards.
- Verify that oversight and assurance stay clear of ownership.
Course outline
Unit 1: Introduction to internal controls and risk mitigation
- Internal control objectives and the trade-offs among them.
- COSO's five components and seventeen principles.
- Cost of preventive, detective and corrective measures.
- The limits of control: collusion and management override.
Unit 2: Risk identification and assessment
- Process-level risk assessment, one step at a time.
- Risk described so the control it needs is obvious.
- Inherent and residual exposure, scored in the right order.
- Risk and control matrices with a named risk and owner.
Unit 3: Designing effective internal controls
- Approval limits and who may authorize beyond them.
- Reconciliation, three-way matching and physical safeguards.
- Automated versus manual controls and IT general controls.
- Compensating controls, and whether they really compensate.
Unit 4: Compliance and regulatory alignment
- Mapping regulatory obligations onto named controls.
- Control over financial reporting and the signed assertion.
- Data protection and sector rules as control requirements.
- What a regulator accepts as proof that a control ran.
Unit 5: Risk mitigation strategies
- Four responses: avoid, reduce, transfer and accept.
- Control cost against the exposure actually reduced.
- Mitigation that costs more than the risk it removes.
- Reduction through control redesign, not more approvals.
Unit 6: Fraud prevention and control systems
- Fraud schemes mapped to procurement, payables and payroll.
- Master data controls, and the standing data nobody reviews.
- Controls over exceptional payments and urgent approvals.
- Analytics for detection: duplicates and off-hours postings.
Unit 7: Monitoring and reporting mechanisms
- Ongoing monitoring versus separate evaluations.
- Exception reporting that ends in a corrected control.
- Control self-assessment and its well-known weakness.
- Reporting a deficiency in terms management can act on.
Unit 8: Governance and ethical oversight
- The Three Lines Model, and the work that falls between.
- Audit committee responsibilities for the control environment.
- Tone at the top as the foundation other controls rest on.
- Speak-up channels as a detective control in their own right.
Unit 9: Digital and AI tools in internal controls
- Continuous control monitoring and the alert volume problem.
- Automation of controls inside enterprise systems.
- Controls that can now be checked on every transaction.
- Control evidence captured by the system, not by hand.
Unit 10: Crisis management through internal controls
- Controls that fail under pressure: approvals and records.
- Emergency authorization and the review that must follow.
- Control gaps in remote work, outages and workarounds.
- Post-incident review of what the testing missed.
Unit 11: Global best practices in internal controls
- Rationalizing a control library down to what carries risk.
- Control owners in the business, not the control function.
- Control owners who accept another function's test evidence.
- Permission to rate a control effective.
Unit 12: Capstone case study
- Building the risk and control matrix from its processes.
- Identifying control design gaps and duplicated controls.
- Designing the mitigation and monitoring, with owners named.
- Rating the control environment and the first three changes.
How the course is delivered
Sessions work from real material: control matrices, process maps, exception reports, audit findings and documented control failures that participants examine and rebuild in discussion. Worked examples take control testing and analytics decisions through step by step. There is no software environment; controls are examined through their design, evidence and outputs. The course is educational and does not certify participants or assess any organization's control framework. Those auditing controls rather than designing them should look at Internal Risk Audits and Control Systems.
Who should attend
- Internal control specialists and risk managers responsible for control design.
- Finance managers and controllers who own key financial controls.
- Internal auditors who test controls and report deficiencies.
- Compliance officers mapping obligations to controls.
About EuroQuest International Training
EuroQuest International Training was founded in 2015 by a team with more than 25 years of experience in professional development. We run over 1,000 courses and have trained more than 15,000 participants. Our head office is in Bratislava, Slovakia, with hubs in Dubai, London, Barcelona, Istanbul, Vienna, Paris and Geneva. Courses are written and reviewed by practitioners from the fields they cover.
Frequently asked questions
Our team is too small for segregation of duties. What then?
Compensating controls carry the weight: independent review of bank detail changes, owner review of exception reports, reconciliation performed by someone who does not post entries. The course spends real time on this, since most organizations face it.
Is the course tied to a specific regulatory certification regime?
No. It uses COSO as the design reference and refers to certification regimes as illustrations. Your specific obligations should be confirmed with qualified advisers.
Does the course include a live lab?
No. There is no system environment. Controls, analytics and monitoring are taught through documented material and worked examples discussed in the room.
Related courses
- Corporate Compliance and Internal Audit Best Practices
- Operational Risk Management in Large Enterprises
- Fraud Detection and Prevention Strategies
- Measuring and Benchmarking Risk Performance
Register for this course
Choose a city and date from the schedule above to register, or contact EuroQuest about in-house delivery for a control, finance or audit team.
All Course Dates & Locations
21 dates · 14 cities · Oct 2026 – Jul 2027