Course overview
An internal risk audit answers a question management cannot answer about itself: do the controls we believe protect us actually work. The answer requires independence, a defensible risk assessment behind the choice of what to audit, and evidence strong enough that the conclusion survives an argument with the process owner.
This course covers internal risk auditing across five units: the principles, risk-based audit planning, control system design and evaluation, fraud risk and investigation, and audit reporting integrated into governance. Reference points are the IIA International Professional Practices Framework, COSO and ISO 31000.
The difference between checking and auditing
Checking asks whether a form was signed. Auditing asks whether the signature meant anything: whether the person had the authority, whether they saw the underlying document, whether the control would have caught the error it exists to catch, and whether the exceptions were investigated or accumulated in a folder.
That distinction determines whether an audit function produces findings management respects or a compliance exercise the business learns to survive. It rests on evidence: reperformance beats inspection, inspection beats observation, and observation beats inquiry, which on its own proves nothing at all.
Course objectives
By the end of the course, participants will be able to:
- Decline consulting work that would compromise audit independence.
- Concede where the evidence runs out before the conclusion.
- Scope a year of coverage to what the team can actually deliver.
- Record in the plan what will deliberately not be examined.
- Sequence a design check ahead of any operating check.
- Select sampling that will carry the conclusion drawn.
- Defend what a tested sample says about everything untested.
- Limit a fraud investigation so the evidence survives it.
- Narrow a finding to what the testing actually proves.
Course outline
Unit 1: Principles of internal risk auditing
- Objectivity, the charter and the access it guarantees.
- An opinion no wider than the working papers support.
- Assurance work, and the advice audit cannot then give.
- The assurance nobody else in the business can give.
Unit 2: Risk-based audit planning
- Deciding what to examine and what to leave alone.
- Boundaries that hold when management pushes back.
- Honest arithmetic on what a small team covers in a year.
- Standing behind the plan when a department objects.
Unit 3: Internal control systems design and evaluation
- Controls sampled over a period the tester chose.
- Testing design before operation, and why the order matters.
- Inquiry, observation and evidence that can be redone.
- Applying an attribute or monetary unit method.
Unit 4: Fraud risk and audit investigations
- Fraud indicators that analytics surface in transactions.
- A sample that returned the same approver each time.
- Holding the evidence intact and escalating in confidence.
- Working with counsel, investigators and HR on the case.
Unit 5: Audit reporting and governance integration
- Conclusions the evidence file can carry on its own.
- Separating what was tested from what was inferred.
- Disagreement written down rather than smoothed over.
- Actions the audit committee will still see next year.
How the course is delivered
The course works from real audit material: risk-control matrices, working papers, sampling decisions and audit findings that participants examine and rework in discussion. Worked examples take control testing and evidence evaluation step by step. The course is educational and does not certify participants or assess any organization's audit function. Those responsible for designing the controls rather than auditing them will find Internal Controls and Risk Mitigation Strategies the better fit.
Who should attend
- Internal auditors and audit seniors running control audits.
- Risk and compliance professionals whose controls are audited.
- Finance and operations managers who own key controls.
- Audit committee members who receive and challenge internal audit reports.
About EuroQuest International Training
EuroQuest International Training was founded in 2015 by a team with more than 25 years of experience in professional development. We deliver over 1,000 courses and have trained more than 15,000 participants, from our head office in Bratislava, Slovakia, with hubs in Dubai, London, Barcelona, Istanbul, Vienna, Paris and Geneva. Courses are developed and reviewed by practitioners from the fields they teach.
Frequently asked questions
Do I need audit experience to attend?
No. The standards, evidence logic and testing technique are built from the ground up. Experienced auditors typically use the sessions to strengthen evidence quality and reporting.
Does the course include a live lab?
No. There is no software environment. Testing and sampling are taught through documented working papers and worked examples analyzed in discussion.
Will I be certified as an internal auditor?
No. You receive a EuroQuest attendance certificate. The course is educational and does not provide a professional audit certification.
Related courses
- Best Practices in Internal and External Auditing
- Performance Audits and Corporate Accountability
- Auditing Risk and Compliance Practices
- Developing and Managing an Effective Audit Plan
Register for this course
Select a city and date from the schedule above to register, or contact EuroQuest about in-house delivery for an internal audit team.
All Course Dates & Locations
29 dates · 14 cities · Sep 2026 – Jul 2027