course

Internal Audit & Controls Key Concepts

444 Enrolled
37.5 Hours (On-Demand)
37.5 CPE  
Not currently accepting new students

Led by Lynn Fountain, Former Chief Audit Executive for two global companies and expert in SOX, COSO, ERM and corporate governance framework, this course begins with a look at enterprise risk management, followed by a look at internal controls. We then move to an overview of Sarbanes-Oxley (SOX) general controls and the COSO 2013 Framework.

Next, we explore segregation of duties and core business processes. Then we discuss the proper documentation methods for internal control. Then we move on to a look at the fraud triangle, how to maintain objectivity, and real world ethics scenarios for professionals in audit.

We then take a deeper look at the types of fraud, as well as fraud evaluations and fraud schemes. That leads into a discussion on IT and cyber threats, and the course concludes with a look at service organization controls.

Please note that this is a 'compilation' course. Thus, it is very long and has an equally long final exam. In order to provide CPE credit en masse, that long final exam is necessary. The courses that make up this 'mega-course' all exist separately on Illumeo, and if you prefer you can take them one-at-a-time in order to learn (and earn CPE) in a more measured fashion.

Learning Objectives
  • Discover the purpose and definitions of Enterprise Risk Management (ERM) and how to establish a Framework, and identify the right sized ERM to meet company objectives and the roles, responsibilities, and accountabilities for ERM.
  • Identify controls to evaluate as it relates to Information Technology (IT) and Sarbanes-Oxley (SOX) and Information Technology General Controls (ITGC) that are specific to Financial Reporting (FR), and explore the IT Control Framework, and recognize how to approach IT evaluation, IT Entity controls and application Controls (AC) vs. General Controls (GC).
  • Explore the definition of Internal Control (IC) and its importance in today’s business, the reason for COSO update and dissect key changes, and how to perform a needs impact assessment and compliance plan, discover the basic tenants of Internal Control (IC), and recognize the keys to the COSO 17 principles.
  • Recognize the criticality of segregation of duties (SOD) principles for finance, accounting and the office of the CFO when attesting to a positive control environment and the SOD responsibilities that are critical in information technology, discover the concept of SOD and fraud considerations, and identify methods for maintaining proper SOD when resources are limited and critical SOD for specific processes and IT areas.
  • Explore the definition of segregation of duties (SOD), and recognize how it applies to roles and processes, identify risks of inadequate SOD and SOD opportunities in role assignments, recognize how SOD applies to individual business processes, and discover control mechanisms.
  • Explore the responsibilities for internal control (IC), what to document, how to establish a defined documentation process, and steps to sufficient documentation, identify documentation types, discover relevant methods of flowcharting.
  • Recognize symptoms of the fraud triangle and how the three sides of the fraud triangle work together, identify how to address symptoms of pressure, opportunity and rationalization, explore types of fraudulent crimes, and evaluate the profile of the fraudster.
  • Explore the requirements of professional skepticism, the rules defining independent roles, the top five techniques to execute independence, and the top five techniques to assist when employing objectivity, identify the difference between legality and ethics, and recognize what to do when management challenges you.
  • Recognize what to do in a situation when you are being asked to record entries that you know are not appropriate, what to do when you are made aware of a questionable issue, and what to do when put in an awkward position after observing unusual behavior by a manager, and Discover how you would handle a boss who uses intimidation and threatening tactics.
  • Identify some of the various challenges internal audit may face when attempting to execute upon risk based auditing, explore alternatives to identifying risk appetite and risk tolerance to utilize within risk based auditing, evaluate the development and usage of a variety of risk management characteristics when identifying risk tolerance, explore sample scoring techniques to apply to risk based auditing, and learn how to conclude your assessment for risk based auditing.
  • Explore financial statement fraud related to the concept of timing, discover specific timing types of financial statement schemes and identify procedures used to mitigate potential fraud, recognize fraud schemes related to bill and hold, sales with special terms, and documentation, and explore types of financial statement (FS) schemes and mitigation techniques for accounting entries.
  • Explore the internal control connection to fraud, the most successful detection methods for fraud, anti-fraud methods at victim organizations, and the importance of fraud awareness, recognize the characteristics of organizations that fall victim to fraud, and identify the most frequently used fraud controls.
  • Identify the attributes of fraud and the 5 Control Environment principles that can be connected to the need to evaluate for fraud, as well as recognize how to utilize professional skepticism when evaluating for fraud
  • Explore top fraud schemes per the Association of Certified Fraud Examiners (ACFE), top corruption schemes, top financial statement schemes, and top asset misappropriation schemes, and identify industries who suffer the highest number of frauds and industries who suffer the highest median loss due to frauds.
  • Discover the benefits and risks of Information Technology (IT) systems, explore COSO’s link to Information Technology as it relates to the Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring, and identify categories and examples of IT General Controls (GC).
  • Identify the elements required of a cyber program, the top 10 vulnerabilities per the Open Web Application Security Project (OWASP), the roles in a cyber risk management program, and the focus areas for cyber programs, and explore the categories of cyber security, the types/categories of cyber threats, and the basic components of the National Institute of Standards and Technology (NIST) framework.
  • Examine recent cyber incidents and their impact on business, identify types and methods of the most proliferate cyber threats, explore the meaning and impact of data breaches and the actions professionals and organizations can take towards prevention of cyber threats.
  • Recognize the various types of service and subservice organizations, the requirements to prepare for a SOC engagement and the requirements for user entities, and explore procedures to conduct a SOC (Service Organization Control) 1 engagement, develop proper control objectives and determine specific reporting methods, the procedures to conduct and report on a SOC 2 engagement, and the SOC cybersecurity requirements.
Last updated/reviewed: March 7, 2024
44 Reviews (139 ratings)

Reviews

3
Member's Profile
Some of the issues noticed during the Final Exam.  General – the language and sentence structuring of questions and several answer options is quite confusing (or incomplete at times).  General – several questions refer to material without specific information. This works fine for Review Questions because there we go topic-by-topic. However, in the Final Exams, proper context should be included in the question itself.  Q # 41 to 50 are a repetition of Q # 31 to 40  Q # 74 is a repetition of Q # 69  Answer Options for Q# 99, Q# 100 and Q#101 are copied from those for Q# 98 and have NO correlation to these questions.  Q# 140 to Q# 145 – no scenarios or background information is provided, other than mere references to the preparation material.  Q# 173 and Q# 183 are the same (duplicated). You may contact me at Muhammad.Baig77@gmail.com to further discuss these comments.

4
Anonymous Author
It's a long course to take at one time. Illumeo mentions that courses are available separately, but I wasn't able to easily identify them in the system. Many of the final exam questions got into the weeds...for example, several questions on survey results from a particular year.

5
Anonymous Author
Very comprehensive course with quite a smooth delivery by Lynn Fountain. The course was very useful to me as it provided quite a good foundation in the concepts of internal audit and controls and complemented what I already knew. It is definitely a worth while course to take.

5
Anonymous Author
Great course. Source materials do a great job supporting the presentation. Only drawback is that my browser crashed in the midst of the exam (241 questions)which ended up causing my original submission to be invalid and I had to re-enter all my answers.

3
Member's Profile
This course was informative in some ways. It is a little repetitive in some sections. It is a lot of information in one course. Final test had repeat questions, so if you got it wrong once, there is a chance that you will get it wrong again.

5
Member's Profile
The course covers a lot of information but is organized in a way that is understandable. The only issue is that the exam is so long and it does not give you the ability to save the test if you have to start it and exit before you finish it.

5
Member's Profile
This was an informative and helpful session for the overall audit process. The topics covered such as management IC essentials, SOX guidance, COSO framework, segregation of duties, etc will help me in the overall audit process.

5
Anonymous Author
Very comprehensive Internal Audit training. I am excited to take some of these concepts into practice for evolving my risk based internal audit impact and likelihood considerations. Very helpful examples throughout as well.

4
Member's Profile
This was a very lengthy course combo, but glad to just knock everything out at once (although not required). The test was lengthy. Took me a few hours to take with a few challenging "best answer" type questions.

3
Anonymous Author
The course itself is really good; however, the exam has a bunch of repeat questions, unclear questions and questions where the answers cut out mid-sentence. That definitely needs to be looked at and fixed.

4
Anonymous Author
the course was actually fantastic and I plan to go back and review specific sections often. I was disappointed that the test had several multiple choice answers that were incomplete or ambiguous.

5
Anonymous Author
This class included extensive relevant data. Although some information was duplicated presentation was excellent. Instructor was knowledgeable and provided many real-life examples.

5
Member's Profile
what should i say its really comprehensive course have a lot and important information and very useful and i will for sure review again and again while working. Thank you.

4
Anonymous Author
ERM was explained at a high level yet peppered with lower level recommendations. This made my Christmas very AAAAWEEEEESSOMMMME! Thank you! Smiley emjoy :)

5
Anonymous Author
Very good in-depth course that covers a wide array of topics associated with Internal Audit and Risk. I will be coming back to refer to these modules.

5
Member's Profile
This course had such valuable information on so many areas of COSO. I will continue to use this information as I perform my audit responsibilities.

5
Anonymous Author
Excellent course and great refresher on some key concepts and applications. I found the IT portion of this course to be especially interesting.

5
Anonymous Author
Very informative and detailed. The final exam was very challenging, but having access to the materials will be useful for future reference.

5
Anonymous Author
I liked how the course covered a wide variety of material. There was some memorization that was required that made the exam difficult.

3
Member's Profile
Test is way to detailed and makes you remember industry median dollars and %. That really doesn't ensure you understand the concepts.

5
Anonymous Author
Course was long but very helpful. It was a great refresher on everything related to internal controls, fraud risk, etc. Great!!

5
Anonymous Author
Great review of the Internal Auditing knowledge! Interesting lectures to listen, valuable materials available for a download.

5
Anonymous Author
Great course with valuable information. It never gets boring on the opposite you stay excited to learn more and more.

4
Anonymous Author
I noted that this is a combination of different topics. Presentation is ok. The exam is tiresome and very lengthy

5
Member's Profile
Material was very very good and was easy to read. The test had multiple questions that repeated or included not.

1
Anonymous Author
Unreasonably long and tedious. The exam by itself is 241 questions, as if the course wasn't already long enough.

5
Member's Profile
I really enjoyed taking this course, I learned a lot and it helped me earn my CPE credits for the year. Thanks!

4
Member's Profile
some sections could be refreshed --ie) using 2016 acfe report to the nations versus more current report.

4
Anonymous Author
The course was very comprehensive, and contents can be leveraged to help articulate real-world examples.

5
Anonymous Author
This was much harder than expected, but a great test of one's ability to refresh/learn the concepts.

5
Anonymous Author
Big pile od knowledge. Perfect to study and review. Some questions on an exam were repeated.

5
Member's Profile
This is a very through course with a lot of great information. It was very interesting.

5
Anonymous Author
Excellent course! I love how so much material is covered especially the case examples.

4
Anonymous Author
Very informative and well structured materials. Good Job. The test was a bit lengthy.

5
Anonymous Author
Well designed course with comprehensive guide to control and fraud considerations.

5
Member's Profile
Good and comprehensive ..... but need more details and examples to some points

5
Anonymous Author
Great content, succinctly summarized, great presenter with a lot of insight.

5
Member's Profile
Great you did a great job. Loved it. Happy to take it. No bad feedback.

5
Member's Profile
This is great course. One can definitely benefit a lot from this course.

4
Member's Profile
Very extensive well laid out course; concise; easy to understand etc.

5
Member's Profile
Exam questions too many! they should be broken to three or four parts!

4
Anonymous Author
Excellent course. Refreshed all internal controls related knowledge.

5
Member's Profile
Very comprehensive and detailed. Great course on SOX and controls.

4
Member's Profile
The course is too cumbersome . The exam was also extremely much.

Prerequisites
Course Complexity: Intermediate

No advanced preparation or prerequisites are required for this course.

Education Provider Information
Company: Illumeo, Inc., 75 East Santa Clara St., Suite 1215, San Jose, CA 95113
Contact: For more information regarding this course, including complaint and cancellation policies, please contact our offices at (408) 400- 3993 or send an e-mail to .
Course Questions and Answers( Questions)
Member's Profile

May I please get a copy of the powerpoint and class materials?

Member's Profile

Hi Jacqueline! you can get the course slides and course materials under the title: SUPPORTING MATERIALS.

Instructor for this course
Course Syllabus
  Institute of Internal Auditors Update 20243:22
  Institute Of Internal Auditors Update 202312:45
Enterprise Risk Management 101
  Enterprise Risk Management 1011:24:44
  REVIEW QUESTIONS: Enterprise Risk Management 101quiz
Management Internal Control Essentials
  Management Internal Control Essentials1:15:46
  REVIEW QUESTIONS: Internal Controls: What Every Financial and Accounting Professional Needs to Knowquiz
Sarbanes-Oxley (SOX) General Controls ...
  Sarbanes-Oxley (SOX) General Controls, Applications Controls, and Spreadsheet Controls1:32:57
  REVIEW QUESTIONS: Sarbanes-Oxley (SOX) General Controls, Applications Controls, and Spreadsheet Controlsquiz
COSO 2013 Framework Requirements and ...
  COSO 2013 Framework Requirements and Implementation Overview1:27:43
  REVIEW QUESTIONS: COSO 2013 Framework Requirements and Implementation Overviewquiz
Segregation of Duties for the office of the CFO
  Segregation of Duties for the office of the CFO1:26:28
  REVIEW QUESTIONS: Segregation of Duties for the office of the CFOquiz
Segregation of Duties for Core Business Processes
  Segregation of Duties for Core Business Processes1:34:39
  REVIEW QUESTIONS: Segregation of Duties for Core Business Processesquiz
Proper Documentation Methods for Internal ...
  Proper Documentation Methods for Internal Audit and Internal Controls Processes1:52:25
  REVIEW QUESTIONS: Proper Documentation Methods for Internal Audit and Internal Controls Processesquiz
Dissecting the Fraud Triangle
  Dissecting the Fraud Triangle1:13:48
  REVIEW QUESTIONS: Dissecting the Fraud Trianglequiz
Keys To Maintaining Objectivity and ...
  Keys To Maintaining Objectivity and Professional Skepticism1:10:03
  REVIEW QUESTIONS: Keys To Maintaining Objectivity and Professional Skepticismquiz
Real World Business Ethics Scenarios
  Real World Business Ethics Scenarios49:49
  REVIEW QUESTIONS: Real World Business Ethics Scenariosquiz
Risk Based Auditing – Applying the Methodology
  Risk Based Auditing – Applying the Methodology1:31:16
  REVIEW QUESTIONS: Risk Based Auditing - Applying the Methodologyquiz
Risk Based Auditing - Establishing a Methodology
  Risk Based Auditing - Establishing a Methodology1:34:58
  REVIEW QUESTIONS: Risk Based Auditing - Establishing a Methodologyquiz
Fraud: Focus on Financial Statement Fraud ...
  Fraud: Focus on Financial Statement Fraud – Part one1:21:30
  REVIEW QUESTIONS: Fraud: Focus on Financial Statement Fraud – Part onequiz
Fraud: Focus on Financial Statement Fraud ...
  Fraud: Focus on Financial Statement Fraud – Part Two1:53:12
  REVIEW QUESTIONS: Fraud: Focus on Financial Statement Fraud – Part Twoquiz
Fraud Evaluations: A Guide for The Compliance ...
  Fraud Evaluations: A Guide for The Compliance Professional1:20:18
  REVIEW QUESTIONS: Fraud Evaluations: A Guide for The Compliance Professionalquiz
Top Fraud Schemes
  Top Fraud Schemes50:12
  REVIEW QUESTIONS: Top Fraud Schemesquiz
Information Technology in Today's Digital ...
  Information Technology in Today's Digital World: General Controls Primer1:02:44
  REVIEW QUESTIONS: Information Technology in Today's Digital World: General Controls Primerquiz
A Primer on Cyber Security Programs and Roles
  A Primer on Cyber Security Programs and Roles1:33:48
  REVIEW QUESTIONS: A Primer on Cyber Security Programs and Rolesquiz
Cyber Threat – The Modern-Day Fraud: Breaches ...
  Cyber Threat – The Modern-Day Fraud: Breaches and Actions1:23:40
  REVIEW QUESTIONS: Cyber Threat – The Modern-Day Fraud: Breaches and Actionsquiz
Service Organization Control Reports under SSAE18
  Service Organization Control Reports under SSAE181:09:57
  REVIEW QUESTIONS: Service Organization Control Reports under SSAE18quiz
SUPPORTING MATERIALS
  Slides: Institute Of Internal Auditors UpdatePDF
  Internal Audit & Controls Key ConceptsZIP
REVIEW AND TEST
 FINAL EXAMexam