Booking options
€130
+ VAT
€130
+ VATLive Online
3 CPD Units | 3 Hours
The EIMF Live Online Learning Experience
Participants will receive access to the recorded sessions of the course.
EIMF subject-matter experts deliver engaging and interactive courses across a broad spectrum of areas, that can be enjoyed in the comfort of your own chosen environment. Read more
Course Overview
Audit findings should lead to measurable risk reduction and stronger control environments—not vague action plans, recurring due-date extensions, unverified closure, or policy changes that fail to alter behaviour.
This practical workshop equips participants to turn audit findings into credible, sustainable improvement plans. Participants learn how to identify recurring and systemic weaknesses, distinguish symptoms from evidenced causes, challenge weak management actions, design proportionate remediation, monitor delivery, validate results, and decide whether a matter should be closed, extended, escalated, re-opened, or subject to formal residual-risk acceptance.
The workshop follows one disciplined cycle:
Finding → evidence → cause analysis → remediation → interim protection → validation → sustainable closure or formal risk acceptance.
Training Objectives
By the end of the programme, participants will be able to:
Acknowledge the difference between a finding, condition, criteria, control deficiency, symptom, immediate cause, contributory factor, evidenced root cause, risk, management action, and residual-risk acceptance.
Understand why findings recur and become systemic, including weaknesses in design, ownership, systems, process, data, monitoring, governance, capability, incentives, and culture.
Recognise the principles of effective remediation governance, interim risk protection, action tracking, validation, closure, escalation, and risk acceptance.
Assess whether a finding is isolated, repeated, thematic, or systemic.
Draft or evaluate an evidence-based audit finding using the GRADE framework.
Apply root-cause analysis without overstating causal certainty or attributing unsupported blame.
Distinguish design deficiencies, implementation gaps, operating-effectiveness failures, and monitoring weaknesses.
Challenge vague, incomplete, or symptom-based management actions.
Contribute to a risk-based remediation plan with appropriate ownership, authority, milestones, resources, interim controls, evidence requirements, and validation criteria.
Assess whether an action should remain open, be extended, escalated, validated, re-opened, or closed with formally authorised residual-risk acceptance.
Communicate audit findings, overdue actions, residual risks, and remediation expectations objectively and constructively.
Develop a professional scepticism towards unsupported causal explanations, generic action plans, repeated extensions, and unverified closure claims.
Develop a collaborative but appropriately challenging approach that supports management improvement while protecting accountability, independence, evidence quality, and sound governance.
Training Outline
Why Findings Recur
Difference between administrative closure and genuine risk reduction.
Common failure patterns: vague actions, unsupported closure, repeated extensions, ineffective controls, weak accountability, and delayed escalation.
Diagnostic poll and facilitated discussion.
Building a High-Quality Finding
Condition, criteria, evidence, scope, deficiency, risk, severity, and management decision.
Introduction to GRADE.
Participants strengthen a vague audit observation into a defensible finding.
Root-Cause Analysis Without False Certainty
Symptoms, immediate causes, contributory factors, evidenced root causes, alternative explanations, Five Whys, process mapping, and control-failure classification.
Progressive case exercise: causal map with evidence and confidence levels.
Recurring Findings, Severity and Systemic Risk
Isolated, repeated, thematic, and systemic issues. Severity assessment, escalation triggers, recurring exceptions, weak management response, and systemic-control implications.
Participants assess recurrence, severity, and escalation needs.
Designing Remediation That Reduces Risk
RAVEN framework; corrective, preventive, detective, and compensating controls; interim protection; resources; milestones; dependencies; evidence; and risk-reduction measures.
Weak-action challenge: redesign insufficient management actions into a credible remediation plan.
Monitoring, Validation, Closure and Risk Acceptance
Multi-status issue trackers, due-date extensions, validation levels, residual-risk acceptance, re-opening, audit trails, confidentiality, and governance reporting.
Closure-decision exercise: close, validate, extend, escalate, re-open, or accept residual risk.
Progressive Integrated Case Study
Northbridge Group case: recurring third-party onboarding and payment-control weaknesses, previously “closed” actions, system overrides, missing evidence, weak review, and management capacity pressure.
Groups synthesise templates built earlier and present one priority issue.
Communication and Individual Professional Judgement
Constructive challenge, management ownership, audit independence, escalation language, confidentiality, and evidence-led communication.
Individual closure-judgement assessment and concise management or audit-committee escalation message.
Training Style
The programme is designed to equip participants with practical knowledge and strengthen their professional capabilities through a highly interactive and application-focused learning approach. Delivery combines short, targeted lectures with case studies, practical examples, facilitated discussions, and realistic workplace simulations.
Through structured discussion, peer exchange, and facilitator feedback, participants will apply the concepts, tools, and techniques introduced throughout the programme while strengthening their analytical thinking, problem-solving, professional judgement, and decision-making skills. By the end of the programme, they will be better equipped to respond confidently and effectively to comparable workplace challenges.
Who Should Attend
This course is designed for professionals involved in identifying, responding to, overseeing, monitoring, validating, or reporting audit and assurance findings, including:
Internal auditors, audit managers, chief audit executives, and audit-committee support teams.
Risk, governance, compliance, quality-assurance, and internal-control professionals.
Finance managers, financial controllers, operational-risk managers, and regulatory-control teams.
Process owners, control owners, risk owners, remediation owners, and senior managers responsible for agreed actions.
Business owners, directors, and executive leaders with governance and control responsibilities.
Consultants and advisers supporting control improvement, remediation, assurance, or governance transformation.
External auditors and other assurance professionals may attend where they communicate control deficiencies or assess management responses. However, the programme is not an external-audit reporting course and does not replace ISA 265 or organisation-specific audit methodology.
Recommended prior knowledge: Basic understanding of internal controls, audit findings, risk assessment, business processes, and management actions.
CPD Recognition
This programme may be approved for up to 3 CPD units in Accounting & Auditing. Eligibility criteria and CPD Units are verified directly by your association, regulator or other bodies which you hold membership.
In-house Training
For groups within the same organisation, this course may be customised to meet any specific needs and delivered in-house.
Marios Mortis
Marios Mortis holds a Bachelor's degree in Business Administration with a focus on Accounting, as well as a Master's degree in Banking and Finance. He is a qualified member of the Association of Certified Chartered Accountants (ACCA). Marios has accumulated valuable experience working in various positions and companies within Cyprus's accounting, audit, advisory, assurance, and banking sectors. In the past seven years, Marios has embarked on a new and fulfilling career path in the field of education, which he finds both challenging and fascinating. He served as a Visitor Academic at a local university in Cyprus, where he taught several courses, including corporate governance and business ethics, corporate finance, corporate risk management, and audit and assurance. Currently, Marios holds the position of Trainer and Accountancy Programmes Leader at EIMF (European Institute of Management and Finance). In this role, he oversees the management of both professional and academic accounting and finance programmes. Marios has successfully designed and delivered professional training courses covering topics such as corporate reporting, tax, AML (Anti-Money Laundering), funds, forensic accounting, financial analysis, auditing, and financial workshops. Furthermore, Marios is entrusted with leading the Department of Accounting & Finance within EIMF's Academic School. He actively engages in research within the domains of finance and accounting, contributing to both academic and professional endeavors in these fields.
The invoice is issued on the day the course starts.
Payments can be made by bank transfer, cheque, or credit card.
Certificates are issued within 7–10 days after the course has been completed, provided that the invoice has been paid.
Once your certificate has been issued, you will receive an automated email from Cademy notifying you that it is available.
Click the Get Your Certificate button in the email to download your certificate.
You can also access it from your Cademy account:
To access the course materials, such as presentations and recordings: