Developing, implementing and continuously improving an internal control system under COSO IC IF-2013

Duration 2 days

The seminar can be held online on the official International Business Academy platform. On completion of the training you will be given a link to the recording, which will be available for one month.
*dates are subject to additional confirmation

Seminar dates

Schedule: 10:00 to 17:30
Cost 296 500 tenge

excluding VAT

* VAT of 16% will be added to the invoice

The price includes:

  • Seminar
  • Exclusive handout materials
  • IBA certificates
  • Notepads, pens
  • Lunches and 2 coffee breaks
Register

Programme goal:

Training managers and specialists in the principles of developing, implementing and continually improving an internal control system (ICS) in accordance with the international COSO IC IF-2013 framework. The programme aims to build practical skills in integrating the ICS into business processes, increasing the transparency of corporate governance and strengthening the risk management culture.

Objectives:

  • Study the principles of COSO IC IF-2013 and their relationship with COSO ERM
  • Master methods of risk assessment and identification (in conjunction with ISO 31000)
  • Learn to develop and test control procedures (taking into account the requirements of ISO 27001, ISO 37001, ISO 37301)
  • Master tools for drawing up and implementing the ICS policy and regulation
  • Learn to build a system of communication and monitoring within the ICS
  • Work through practical cases on building a risk and control matrix, developing KRIs and conducting an internal audit of the ICS

Skills developed:

  • Command of the COSO IC IF tools and their integration into corporate governance
  • Risk assessment and management using ISO 31000
  • Developing and implementing control procedures
  • Building a risk and control matrix
  • Skills in planning and conducting an internal audit of the ICS (based on ISO 19011)
  • Working with the three lines of defence and diagnosing barriers to the functioning of the ICS
  • Using AI and ready-made prompts for analysing, documenting and visualising ICS elements

Criteria for participation in the programme:

Target audience and the value of participation for each group:

  • Top managers and members of the Board of Directors — understanding the role of the ICS in managing the company and increasing transparency
  • Heads of structural units — integrating control procedures and risk management in their area of responsibility
  • Key employees of units — practical identification of risks and performance of control procedures within the internal control system
  • Risk managers — using ICS data for analysis and integration into the corporate risk register
  • Internal auditors and corporate governance specialists — conducting comprehensive reviews of the ICS and preparing reports for certification bodies

Key Account Manager

Natalya Batukhtina
ns@iba.kz +7 702 777 44 11 WhatsApp

Key Account Manager

Юлия Копцева
manager@iba.kz +7 702 777 44 11 WhatsApp
Seminar programme Download programme as PDF
Get a personalised commercial proposal in PDF format
Download proposal as PDF

Programme

Day 1

Getting acquainted/ Introduction/ Course overview/ Participants introduce themselves

I. Component – Control environment

Introduction

Terminology on risks and the ICS. Brief information about COSO, the Enron case and the Big 5

What is new in COSO IC IF:2013

The relationship between COSO ERM & COSO IC IF

Risk management and internal control

Where is the boundary between risk management and the ICS? ICS objectives

Control environment

COSO IC IF:2013 principles 1-5. Explanations, examples

The Corporate Governance Code. HR policy. Organisational structure

Responsibility and authority, common mistakes in developing Regulations on units

Distribution of ICS functions in the company. ICS Policy. ICS Regulation

The relationship of the «control environment» component with ISO 9001 – how to build this ICS block correctly using the tools of ISO 9001

 

II. Component – Risk assessment

Risk assessment

COSO IC IF:2013 principles 6-9. Explanations, examples

The relationship of the «risk assessment» component with ISO 31000 – how to carry out this ICS block correctly using the tools of ISO 31000

«Myths» in the field of risk management and the ICS, and «debunking them»

System 1 and System 2 and the concept of «mental traps»

Setting objectives, defining the mission, vision and values

BSC – the Balanced Scorecard

Decision trees – as a tool for defining Strategy

Risk-based analysis of the company's strategy and KPIs

Risk identification

Mental traps at the risk identification stage

Group game on mental traps

Defining risk criteria

Risk appetite. Examples of calculating risk appetite

Examples of defining financial and non-financial indicators of the consequences of risk materialising

Identifying risk using methods from ISO 31000

Risk identification methods:

Risk analysis

Mental traps at the risk analysis stage. Group game on mental traps

Risk analysis. Examples of risk analysis and compiling the Risk Register

 

Risk evaluation

Mental traps at the risk evaluation stage

Group game on mental traps

Different options for evaluating risk (qualitative and quantitative)

Assessing and analysing the influence of risks on the decision being made

Ways of visualising the results of evaluation (Risk maps)

Practical group work: determining the level of risk

Day 2

III. Component – Control activities

Control activities

COSO IC IF:2013 principles 10-12. Explanations, examples

Types and selection of control procedures

The organisational level of control procedures

Classification of types of control. Types and means of control

Timing of control. Characteristics of effective controls

The risk and control matrix. Examples of control procedures

Typical mistakes in control procedures

The relationship of the «control activities» component with ISO 27001 – how to carry out this ICS block correctly using the tools of ISO 27001

Developing control procedures in accordance with ISO 37001 and ISO 37301

IV. Component – Information and communication

Information and communication

COSO IC IF:2013 principles 13-15. Explanations, examples

ICS components and examples of communication channels for them

Information quality requirements and examples of them: accessibility; correctness; relevance; security; retainability; sufficiency; timeliness; reliability; verifiability

External and internal communication about objectives and responsibility for internal controls

Common mistakes and best practices

V. Component – Monitoring activities

Monitoring activities

COSO IC IF:2013 principles 16-17. Explanations, examples

Methodology and criteria for evaluating the ICS

The three lines of defence: problems and ways of solving them

Testing control procedures. Key risk indicators

Barriers to establishing the ICS in the company and ways of removing them

Ways of improving the risk management culture – recommendations and examples

Conducting internal audits of the ICS in accordance with ISO 9001, ISO 27001, ISO 37001 and ISO 37301

Questions

Course completion

All areas