Course overview
Fraud Control Management Systems (FCMS) Lead Auditor Training
Course Overview
The ISO 37003:2025 Fraud Control Management Systems Lead Auditor Course provides participants with the knowledge and practical auditing skills required to plan, conduct, lead, report and follow up audits of a Fraud Control Management System (FCMS).
The course develops participants' understanding of fraud control and the guidance provided by ISO 37003:2025, together with management system auditing principles based on ISO 19011.
Participants learn how to:
• Understand the principles and guidance of ISO 37003:2025.
• Understand fraud risks and fraud control arrangements.
• Evaluate an organisation's approach to fraud prevention, detection and response.
• Review fraud risk assessments and controls.
• Plan and conduct fraud control management system audits.
• Establish audit objectives, scope and criteria.
• Lead and manage an audit team.
• Interview personnel and gather objective evidence.
• Evaluate the effectiveness of fraud controls.
• Identify weaknesses, gaps and audit findings.
• Prepare clear audit conclusions and reports.
• Evaluate corrective actions and follow-up activities.
• Apply confidentiality, impartiality and professional judgement during audits.
The course combines theoretical knowledge with practical exercises, case studies, workshops and audit simulations.
Course Objectives
By the end of the course, participants should be able to:
1. Explain the purpose and principles of fraud control management.
2. Understand the guidance and framework of ISO 37003:2025.
3. Explain common types and sources of fraud risk.
4. Understand organisational fraud risk and its potential consequences.
5. Evaluate organisational context and fraud risk exposure.
6. Evaluate leadership commitment to fraud control.
7. Review fraud control policies and responsibilities.
8. Evaluate fraud risk assessment processes.
9. Assess fraud prevention controls.
10. Assess fraud detection arrangements.
11. Evaluate fraud reporting and response mechanisms.
12. Understand investigation and response considerations.
13. Evaluate monitoring and continual improvement arrangements.
14. Apply ISO 19011 auditing principles.
15. Establish audit objectives, scope and criteria.
16. Prepare an effective fraud control audit plan.
17. Conduct audit interviews and collect objective evidence.
18. Evaluate evidence against established audit criteria.
19. Identify and document audit findings.
20. Prepare clear and evidence-based audit reports.
21. Lead and manage an audit team.
22. Evaluate corrective actions and conduct audit follow-up.
Learning Outcomes
Successful participants should be able to:
• Explain ISO 37003:2025 fraud control management guidance.
• Understand fraud risks within different organisations.
• Evaluate fraud governance and leadership arrangements.
• Assess fraud risk identification and assessment processes.
• Evaluate fraud prevention and detection controls.
• Assess mechanisms for reporting suspected fraud.
• Evaluate organisational responses to fraud incidents.
• Apply ISO 19011 auditing principles.
• Plan and manage FCMS audits.
• Prepare audit plans and working documents.
• Lead audit opening and closing meetings.
• Conduct effective interviews.
• Gather and verify objective evidence.
• Identify weaknesses and audit findings.
• Prepare professional audit reports.
• Manage an audit team.
• Evaluate corrective actions.
• Conduct effective audit follow-up.
Overall Course Outcome
Understand Fraud Risk → Evaluate Fraud Controls → Plan the Audit → Conduct the Audit → Evaluate Evidence → Report Findings → Follow Up → Lead Fraud Control Audits Effectively.
________________________________________
Target Audience
This course is suitable for:
• Fraud Risk Managers
• Fraud Control Professionals
• Internal Auditors
• External Auditors
• Prospective Lead Auditors
• Risk Managers
• Compliance Managers
• Governance Professionals
• Ethics and Integrity Officers
• Financial Controllers
• Finance Managers
• Forensic Audit Professionals
• Fraud Investigators
• Internal Control Professionals
• Anti-Fraud Specialists
• Anti-Bribery and Compliance Professionals
• Corporate Security Professionals
• Legal and Regulatory Compliance Personnel
• Management System Consultants
• Senior Managers responsible for fraud risk
• Professionals responsible for governance, risk and compliance
Recommended Prior Knowledge
Participants should preferably have basic knowledge of:
• Fraud risks and fraud control;
• Governance, risk and compliance;
• Internal controls;
• Management systems;
• Risk assessment;
• Auditing principles; and
• Organisational processes.
Reference Standards and Guidance
The course makes reference to:
• ISO 37003:2025 – Fraud control management systems — Guidance for organizations managing the risk of fraud
• ISO 19011 – Guidelines for auditing management systems
• ISO 31000 – Risk management — Guidelines
• ISO 37001 – Anti-bribery management systems — Requirements with guidance for use
• ISO 37301 – Compliance management systems — Requirements with guidance for use
• Applicable legal, regulatory and organisational fraud-control requirements
• Relevant governance, risk, compliance and internal-control guidance
Important: ISO 37003:2025 is a guidance standard, rather than a management-system requirements standard. Audits should therefore use clearly established audit criteria, such as organisational policies, contractual requirements, legal obligations or other applicable requirements, alongside ISO 37003 guidance.
Course Content
DAY 1 – ISO 37003:2025 and Fraud Control Fundamentals
Module 1: Introduction to Fraud Control
• Meaning and characteristics of fraud.
• Internal and external fraud.
• Occupational and organisational fraud.
• Fraud risks and consequences.
• Fraud risk factors.
• Fraud prevention, detection and response.
• Importance of organisational fraud control.
• Governance and accountability.
• Fraud control culture.
Module 2: Understanding ISO 37003:2025
Participants examine the key elements of fraud control management, including:
• Organisational context.
• Leadership and commitment.
• Fraud control responsibilities.
• Planning.
• Fraud risk assessment.
• Resources and competence.
• Awareness and communication.
• Fraud prevention.
• Fraud detection.
• Reporting mechanisms.
• Responding to suspected fraud.
• Monitoring and review.
• Continual improvement.
Module 3: Fraud Risk Assessment
• Identifying fraud risks.
• Understanding fraud scenarios.
• Sources and causes of fraud risk.
• Assessing likelihood and consequences.
• Existing fraud controls.
• Evaluating control effectiveness.
• Prioritising fraud risks.
• Developing fraud treatment actions.
Exercise: Prepare a basic fraud risk assessment for a sample organisation.
________________________________________
DAY 2 – Fraud Controls and Audit Planning
Module 4: Fraud Prevention and Detection Controls
Participants examine controls including:
• Governance and oversight.
• Policies and procedures.
• Segregation of duties.
• Approval and authorisation controls.
• Financial controls.
• Procurement controls.
• Employee and third-party controls.
• Conflict-of-interest controls.
• Due diligence.
• Fraud awareness and training.
• Reporting and whistleblowing mechanisms.
• Monitoring and detection controls.
• Data and transaction monitoring.
Module 5: Principles of Auditing
• Purpose of an audit.
• Audit terminology.
• ISO 19011 auditing principles.
• Integrity.
• Fair presentation.
• Due professional care.
• Confidentiality.
• Independence.
• Evidence-based approach.
• Risk-based approach.
• Auditor competence and behaviour.
Module 6: Planning the Fraud Control Audit
• Establishing audit objectives.
• Defining audit scope.
• Establishing audit criteria.
• Determining audit feasibility.
• Selecting the audit team.
• Reviewing relevant information.
• Understanding fraud-risk areas.
• Preparing the audit plan.
• Developing audit questions.
• Sampling methods.
• Preparing working documents.
Workshop: Prepare a fraud control audit plan and audit checklist.
________________________________________
DAY 3 – Conducting the Fraud Control Audit
Module 7: Conducting Audit Activities
• Opening meeting.
• Communication during the audit.
• Interview techniques.
• Asking effective audit questions.
• Reviewing policies and procedures.
• Reviewing fraud risk assessments.
• Reviewing financial and operational records.
• Sampling transactions.
• Observing controls.
• Following audit trails.
• Gathering objective evidence.
• Maintaining confidentiality.
Module 8: Auditing Fraud Control Arrangements
Participants practise evaluating:
• Leadership and governance.
• Fraud control policies.
• Roles and responsibilities.
• Fraud risk assessments.
• Prevention controls.
• Detection controls.
• Reporting channels.
• Whistleblowing arrangements.
• Third-party risks.
• Financial controls.
• Fraud awareness and competence.
• Response arrangements.
• Monitoring and review.
Module 9: Evaluating Audit Evidence
• Evidence versus assumption.
• Sufficiency and appropriateness of evidence.
• Comparing evidence with audit criteria.
• Identifying control weaknesses.
• Identifying audit findings.
• Recording objective evidence.
• Developing audit conclusions.
• Handling sensitive information.
Practical Exercise: Auditor-auditee interviews and fraud-control evidence evaluation.
________________________________________
DAY 4 – Reporting, Lead Auditor Skills and Follow-Up
Module 10: Fraud Response and Improvement
• Reporting suspected fraud.
• Escalation arrangements.
• Protecting confidentiality.
• Preserving relevant information and evidence.
• Investigation governance.
• Corrective and preventive measures.
• Control improvements.
• Monitoring effectiveness.
• Lessons learned.
• Continual improvement.
Module 11: Audit Findings and Reporting
• Developing audit findings.
• Supporting findings with evidence.
• Identifying control gaps and weaknesses.
• Linking findings to established audit criteria.
• Reviewing findings with the audit team.
• Developing audit conclusions.
• Conducting the closing meeting.
• Preparing an audit report.
• Communicating sensitive findings appropriately.
Module 12: Lead Auditor Responsibilities
• Role of the Lead Auditor.
• Managing the audit team.
• Assigning audit activities.
• Managing time and resources.
• Maintaining independence and objectivity.
• Protecting confidential information.
• Managing difficult audit situations.
• Resolving differences within the audit team.
• Exercising professional judgement.
• Leading opening and closing meetings.
• Communicating with senior management.
Module 13: Corrective Action and Follow-Up
• Reviewing corrective-action plans.
• Evaluating proposed controls.
• Reviewing implementation evidence.
• Verifying effectiveness.
• Closing audit findings.
• Conducting follow-up audits.
• Supporting continual improvement.
Lead Audit Simulation
Participants undertake a practical audit simulation covering:
1. Audit preparation.
2. Fraud risk review.
3. Audit planning.
4. Opening meeting.
5. Interviews.
6. Evidence gathering.
7. Evaluation of fraud controls.
8. Identification of findings.
9. Audit-team review.
10. Audit conclusions.
11. Closing meeting.
12. Audit reporting.
________________________________________
DAY 5 – MULTIPLE-CHOICE EXAMINATION
Cognicert ISO 37003 Lead Auditor Examination
Day 5 is dedicated to the multiple-choice examination.
The examination may assess participants' knowledge of:
• ISO 37003:2025 guidance.
• Fraud terminology and concepts.
• Fraud risk identification and assessment.
• Fraud prevention controls.
• Fraud detection controls.
• Fraud reporting mechanisms.
• Fraud response arrangements.
• Governance and leadership.
• Internal controls.
• Monitoring and improvement.
• ISO 19011 auditing principles.
• Audit planning and preparation.
• Audit objectives, scope and criteria.
• Interview and evidence-gathering techniques.
• Audit findings.
• Audit reporting.
• Audit follow-up.
• Lead Auditor responsibilities.
• Confidentiality and professional behaviour.
Training Methodologies
The course uses a simple, practical and interactive approach, including:
• Instructor-led presentations.
• Explanation of ISO 37003 guidance.
• Practical fraud scenarios.
• Group discussions.
• Case studies.
• Individual and group exercises.
• Fraud risk assessment exercises.
• Fraud-control evaluation.
• Documentation review.
• Audit planning workshops.
• Audit checklist exercises.
• Auditor-auditee role plays.
• Evidence-gathering exercises.
• Audit finding exercises.
• Opening and closing meeting simulations.
• Lead audit simulation.
• Question-and-answer sessions.
• Daily knowledge reviews.
• Multiple-choice examination.
The emphasis is on learning by doing, allowing participants to apply fraud-control and auditing principles to realistic organisational situations.
Certification
Participants who successfully fulfil Cognicert's applicable training and examination requirements will be awarded the:
Cognicert ISO 37003 Lead Auditor Certificate
Final Course Outcome
On successful completion, participants should have the knowledge and practical foundation required to evaluate fraud-control arrangements and plan, conduct, lead, report and follow up fraud control management system audits professionally and effectively.
Duration : 5 Days
