Course Images

Internal & External Audits for Investment Firms - Turning Findings into Action

Internal & External Audits for Investment Firms - Turning Findings into Action

  • 20% Discount Across All Autumn 2026 Programmes | Register by 4 September 2026

Dates

  • November 2026
      to   (2 sessions)
    Delivered Online
    €240+ VAT
    Book
    View Dates Hide Dates
    • to
      Delivered Online
    • to
      Delivered Online

Highlights

  • Live Online

  • 5 CPD Units | 5 Hours


The EIMF Live Online Learning Experience

Participants will receive access to the recorded sessions of the course.

EIMF subject-matter experts deliver engaging and interactive courses across a broad spectrum of areas, that can be enjoyed in the comfort of your own chosen environment. Read more


Course Overview

This programme is designed for Cyprus Investment Firms that want to convert Internal Audit, External Audit and CySEC inspection findings into measurable control improvements. It updates the audit lifecycle with current EU and Cyprus requirements, including MiFID II, Law 87(I)/2017 as amended, Commission Delegated Regulation (EU) 2017/565, IFD/IFR, Law 165(I)/2021, DORA, GDPR, the EU AI Act and the MiFID II/MiFIR Review. The course focuses on audit scoping, fieldwork, evidence standards, root cause analysis, action plan ownership, C-level reporting, Board challenge, and closure validation. It also explains how audit functions should test areas such as safeguarding, best execution, product governance, complaints, AML interfaces, DORA resilience, outsourcing and AI-assisted controls. Participants receive a practical methodology for building findings registers, remediation trackers and inspection-ready data rooms that demonstrate an effective three-lines-of-defence environment.


Training Objectives

By the end of the webinar, participants will be able to:

  • Explain the roles and boundaries of Internal Audit, External Audit, Compliance, Risk Management, Finance, Operations, C-level management and the Board.

  • Translate audit and inspection findings into risk-rated, time-bound and evidence-driven remediation plans.

  • Design an annual Internal Audit plan aligned with the firm’s risk profile, business model, regulatory obligations and CySEC supervisory priorities.

  • Assess audit evidence quality for safeguarding, best execution, product governance, AML interfaces, complaints, prudential reporting, DORA and outsourcing.

  • Use root-cause analysis to distinguish policy gaps, operating failures, data defects, ownership gaps and governance weaknesses.

  • Build a defensible Audit Findings Register, Remediation Tracker and Board/Committee reporting pack.

  • Integrate DORA, AI Act and data-governance risks into audit universe planning and assurance testing.

  • Prepare for CySEC onsite/offsite inspections through data-room discipline, consistent responses, interview readiness and closure evidence.


Training Outline

Governance, Audit Roles and Regulatory Expectations

  • Three lines of defence in Cyprus Investment Firms: business ownership, Compliance/Risk challenge and Internal Audit assurance.

  • MiFID II, Delegated Regulation (EU) 2017/565 and Law 87(I)/2017 organisational requirements.

  • IFD/IFR and Law 165(I)/2021: prudential governance, reporting and internal control implications.

  • Board and C-level accountability for audit findings, risk acceptance and remediation.

  • Internal Audit Planning and Fieldwork

  • Risk-based audit universe: safeguarding, best execution, product governance, complaints, AML interfaces, data quality, outsourcing and prudential reporting.

  • Audit scoping, sampling, walkthroughs, control design testing and operating effectiveness testing.

  • Evidence standards: contemporaneous records, system logs, reconciliations, approvals, MI and minutes.

  • How to write findings that are accurate, defensible and actionable.

External Audit, Specialist Reviews and Assurance Engagements

  • Interaction with statutory auditors, specialist compliance reviews and independent expert assessments.

  • Handling audit queries, management representations and supporting evidence.

  • Using external audit outputs to strengthen control design and governance rather than treating them as isolated findings.

  • Alignment between external audit observations, internal audit plan and Board risk appetite.

  • DORA, AI Act and Technology Assurance

  • DORA audit coverage: ICT risk management, incident response, business continuity, third-party ICT providers and resilience testing.

  • AI Act audit relevance: AI inventory, intended use, human oversight, data quality, explainability, logs and accountability.

  • Testing automated compliance tools, surveillance systems, transaction monitoring, marketing review tools and client profiling systems.

  • Evidence needed for outsourced systems, vendor assurances, access controls and change management.

Turning Findings into Action and CySEC Readiness

  • Root-cause analysis: process, people, data, systems, governance and culture.

  • Findings register: severity, owner, deadline, client impact, regulatory impact, interim controls and validation criteria.

  • Board/Committee MI: open findings, overdue actions, repeated issues, risk acceptance and closure validation.

  • CySEC inspection preparation: data room, interview conduct, consistent narrative, remediation evidence and follow-up.


Who Should Attend

This programme is designed for:

  • Chief Executive Officers, Chief Operating Officers, Chief Financial Officers, Chief Risk Officers, Chief Compliance Officers and other C-level officers of Cyprus Investment Firms.

  • Executive Directors and Non-Executive Directors responsible for governance, control effectiveness and remediation oversight.

  • Internal Auditors, Internal Audit Managers and members of Internal Audit functions within Cyprus Investment Firms.

  • Heads of Compliance, Compliance Officers, Risk Managers and Operational Risk Officers.

  • Finance Managers, Operations Managers, Back-Office Managers and officers responsible for evidence production or external-audit coordination.

  • Heads of Dealing, Portfolio Management, Product Governance, ICT/DORA and Client Operations where their areas are subject to audit or supervisory review.


Training Style

The seminar uses concise technical presentations, short videos, Cyprus investment-firm case studies, audit-report examples, guided root-cause analysis and remediation workshops. Participants practise converting findings into action plans, building Board MI and preparing CySEC-ready evidence files with clear ownership, deadlines and closure criteria.


CPD Recognition

This programme may be approved for up to 5 CPD units in Financial Regulation. Eligibility criteria and CPD Units are verified directly by your association, regulator or other bodies which you hold membership.


In-house Training

For groups within the same organisation, this course may be customized to meet any specific needs and delivered in-house.

Facilitators

  • Panagiotis Nikolaou

    Panagiotis Nikolaou

    GRC Expert and Auditor

    Panagiotis Nikolaou is an accomplished Governance, Risk and Compliance Lead Auditor, strategic advisor, regulatory investigator, approved internal auditor, technical expert, ISQM 1 implementation specialist, and vocational trainer with more than 15 years of experience in the international financial services sector. His professional background encompasses financial technology (FinTech), investment services, financial markets, internal audit, regulatory compliance, risk management, market surveillance, financial crime prevention, quality management, and executive leadership within regulated financial institutions and professional services firms. Since 2018, he has served, during various periods, as a selected Associate Expert in Market Surveillance and Investigations for the Cyprus Securities and Exchange Commission (CySEC) through public tenders awarded to MAP S.Platis Group. In this capacity, he has contributed to complex regulatory investigations, on-site and off-site inspections, compliance assessments, market-conduct reviews, and evaluations of business relationships involving Cyprus Investment Firms, financial institutions, Payment Institutions, Electronic Money Institutions, and other regulated or higher-risk entities. Panagiotis has developed substantial experience in the payments and electronic money sectors, advising and auditing Payment Institutions (PIs) and Electronic Money Institutions (EMIs) in relation to governance, safeguarding of client funds, AML/CTF controls, risk management, outsourcing, operational resilience, regulatory reporting, internal control arrangements, and compliance with the supervisory expectations of the Central Bank of Cyprus. He has been approved by the Central Bank of Cyprus to act as an Internal Auditor for regulated Electronic Money Institutions and Payment Institutions, demonstrating his ability to independently assess governance, regulatory compliance, safeguarding, financial crime, operational, outsourcing, information and communication technology, and risk-management frameworks within Central Bank-supervised entities. In addition, Panagiotis has served as an ISQM 1 standards implementer and advisor for various accounting and audit firms, supporting the design, documentation, implementation, and continuous improvement of their quality management systems. His work includes conducting firm-wide quality risk assessments; identifying quality objectives, risks, and appropriate responses; developing policies and procedures; defining governance and leadership responsibilities; strengthening ethical and independence controls; establishing client acceptance and continuance procedures; enhancing engagement performance and review arrangements; and developing monitoring, remediation, documentation, and annual evaluation processes. He assists accounting and audit firms in translating the principles of the International Standard on Quality Management 1 (ISQM 1) into practical, proportionate, and sustainable control frameworks suited to their size, structure, client portfolio, and regulatory obligations. His experience is further strengthened by previous appointments as Executive Director, Risk Manager, Head of Portfolio Management, broker, technical analyst, and senior dealer within the investment services industry. This combination of supervisory, investigative, audit, advisory, executive, and frontline financial-market experience enables him to assess regulated institutions and professional services firms from both regulatory and operational perspectives. His principal areas of expertise include AML/CTF and sanctions compliance, financial crime and fraud risk, MiFID II and MiFIR, payment services and electronic money regulation, product governance, suitability and appropriateness, best execution, investor protection, safeguarding of client funds and financial instruments, complaint handling, conflicts of interest, financial promotions, internal governance, regulatory remediation, outsourcing, quality management, and operational resilience. He has also developed significant expertise in emerging regulatory areas, including crypto-assets, blockchain-based financial services, virtual-asset risk management, and the Markets in Crypto-Assets Regulation (MiCA). His international advisory work has extended to regulated entities and public authorities in the European Union, Cyprus, Israel, Russia, South Africa, Singapore, Thailand, Seychelles, Vanuatu and other jurisdictions. Panagiotis has also participated as a technical expert in legal proceedings and disputes concerning the investment services sector. His work has included the independent assessment of trading practices, order execution, pricing, best-execution obligations, financial instruments, brokerage operations, liquidity-provider arrangements, transaction costs, rollover and financing charges, and the application of the relevant European and Cyprus regulatory frameworks. Through these engagements, he assists legal professionals, courts, regulated entities, and other stakeholders in understanding complex financial market practices, trading data, and regulatory requirements by presenting technically grounded findings in a clear, evidence-based manner. As a Level 5 Vocational Trainer certified by the Human Resource Development Authority of Cyprus, Panagiotis has designed and delivered specialised professional training to a broad international audience across the financial services, regulatory, law enforcement, and professional services sectors. His training experience includes programmes delivered to personnel from some of the world’s largest internationally operating investment firms, banking institutions, Payment Institutions, Electronic Money Institutions, accounting and audit firms, and other regulated financial organisations. He has also delivered specialised training to the Cyprus Police Academy, as well as to professionals and representatives from Cyprus’s supervisory authorities, regulatory institutions, and self-regulatory and professional bodies. His audiences have included regulators, investigators, compliance officers, internal auditors, risk managers, senior executives, board members, legal professionals, and other specialists responsible for governance, financial crime prevention, investor protection, and regulatory compliance. His programmes combine detailed regulatory analysis with practical case studies, investigative methodologies, risk-based assessments, control-testing procedures, and guidance on operational implementation. The subject matter covered includes AML/CTF, sanctions compliance, bribery and corruption, fraud prevention, MiFID II and MiFIR, product governance, suitability and appropriateness, best execution, safeguarding of client assets, complaints handling, vulnerable-client protection, market conduct, payment services, electronic money, crypto-assets, MiCA, internal audit, corporate governance, and operational resilience. Through these engagements, Panagiotis has developed the ability to adapt complex regulatory and technical content to audiences ranging from supervisory and law-enforcement personnel to board members, senior management, compliance professionals, and operational teams within major international financial institutions. He has also co-authored a professional guide concerning ESMA’s knowledge and competence assessment guidelines in collaboration with the European Institute of Management and Finance and the Chartered Institute for Securities & Investment. Panagiotis holds a Bachelor’s degree in Economics, an MSc in Financial Services, and an MBA, and is currently pursuing a Doctorate in Business Administration in Strategic Management at the University of Limassol. His professional qualifications include the CySEC Advanced and AML certifications, the Certified Governance, Risk and Compliance Auditor designation, ISO 31000 Risk Management Lead Auditor, ISO 9001, ISO/IEC 27001 and ISO 45001 Lead Auditor qualifications, GDPR Lead Auditor and specialised studies in criminology, forensic science, fraud investigation, and identity-theft prevention. He is also a Chartered Member of the Chartered Institute for Securities & Investment and a full member of the Society of Technical Analysts. He is also a member of academic societies such as the Academy of Management, IFERA and others. Combining regulatory insight, investigative discipline, internal audit and quality-management expertise, legal-case support, industry experience, and strategic leadership, Panagiotis assists investment firms, financial institutions, PIs, EMIs, accounting and audit firms, supervisory stakeholders, and professional advisers in strengthening governance arrangements, enhancing regulatory compliance, implementing ISQM 1 systems of quality management, safeguarding client assets, managing financial and operational risks, and establishing practical, proportionate, and sustainable control frameworks.

Frequently Asked Questions

  • When will I receive my invoice?

    The invoice is issued on the day the course starts.

  • What payment methods are accepted?

    Payments can be made by bank transfer, cheque, or credit card.

  • When will my certificate be issued?

    Certificates are issued within 7–10 days after the course has been completed, provided that the invoice has been paid.

  • How can I access my certificate?

    Once your certificate has been issued, you will receive an automated email from Cademy notifying you that it is available.

    Click the Get Your Certificate button in the email to download your certificate.

    You can also access it from your Cademy account:

    1. Log in to your Cademy account from https://cademy.io
    2. Click on My Account from the top-right corner.
    3. From the drop-down menu select My Courses and Bookings.
    4. Choose the relevant course.
    5. Under Participants, click the three dots located next to your name. 
    6. Select Get Certificate.
  • Where can I access the course material?

    To access the course materials, such as presentations and recordings:

    1. Log in to your Cademy account from https://cademy.io
    2. Click on My Account from the top-right corner.
    3. From the drop-down menu select My Courses and Bookings.
    4. Choose the relevant course.
    5. Under Extra Details, you will find all the available course materials.

Days
Hours
Minutes
Seconds

Early bird discount

13 November 2025

Navigating Conflict for Collaborative Teams: Leading with Confidence

Join us to gain insights from Alana Hill, learn practical strategies for turning conflict into opportunity, and discover how challenges can drive growth and stronger team performance.

Days
Hours
Minutes
Seconds

Limited Time

30% Discount

On All Self-Paced eLearning CPD Courses in Financial Regulation

Days
Hours
Minutes
Seconds

Limited Availability

05 June 2025

Corporate Governance Today: Trends and Challenges

Hosted by the EIMF and the Chartered Governance Institute

Engage with 20+ leading experts and earn 6 CPD units in Financial Regulation.

Get Inspired by Our Head of Accounting

Think. Choose. Grow.

Not sure if it’s right for you? Let’s talk.

Days
Hours
Minutes
Seconds

limited time

PAIR UP AND SAVE

BUY ONE, GET ONE FREE

Short Self-Paced Online Courses

Days
Hours
Minutes
Seconds

Limited time

New Year, new you

10% discount on All Courses

Discount Coupon: NYNY10

Valid until 31 Jan 2025 23:59

EIMF's Christmas Advent Calendar

Unwrap the Gift of Knowledge this Festive Season!

Register now to receive a valuable educational resource each day and be automatically entered into our Grand Christmas Draw on 24th December – Don’t miss out!

Days
Hours
Minutes
Seconds

Limited time

black friday has arrived

up to 40% discount

On Self-Paced eLearning Courses

Days
Hours
Minutes
Seconds

Limited Availability

17 October 2024

Regulatory & AFC Compliance Conference

Hosted by the ACAMS Cyprus Chapter and the EIMF.

Engage with 17 leading experts, explore 12 critical areas, earn 6 CPD units in Financial Regulation, gain 4 ACAMS credits, and receive a Certificate of Participation.

Celebrate 9 Years with EIMF

EIMF Has Assisted 6,000+ Professionals Get Certified

 

Ready for your next professional certification? Choose from 9 self-paced eLearning courses and enjoy a 30% discount!

*complete your purchase before 21 April 2024

Starts 20 February 2024

Master in Governance,
Risk & Compliance

Accredited by the CyQAA, our GRC programme empowers you to navigate complex regulations, manage risks, and fortify governance structures. Dive into a dynamic learning experience that ensures ethical operations, regulatory compliance, and risk reduction.

✅ Explore Scholarships & Financial Aid ✅ Discover the Match Funding Scheme