“Module 3’s evidence architecture stopped our habit of filing pretty PDFs without the population source. Walkthroughs got shorter.”
Flagship course
Control Bridge Assurance
Financial auditing guidance for IT-dependent manual controls in finance teams — from naming the bridge to testing it without inventing theater.
Who it is for
Controllers, SOX and internal control coordinators, internal auditors, and external engagement staff who review Korean finance processes that still rely on human steps after the system produces a report, queue, or export.
Learning outcomes
- Classify controls as automated, IT-dependent manual, or purely manual with defendable language
- Write populations, criteria, and frequency that match the actual report or queue
- Design evidence packs a second person can re-perform
- Sample for design and operating effectiveness when ITGC reliance is partial
- Document compensating steps without overstating system assurance
- Brief reviewers on known limitations instead of hiding them
Modules
- Module 1 — Naming the bridge Inventory patterns: approvals on workflow, reconciliations on exports, exception clearances, spreadsheet gates. Practice rewriting vague control titles.
- Module 2 — Risk and assertion links Connect each bridge to assertions and process risks. Separate ITGC gaps you cannot own from residual manual risk you must.
- Module 3 — Evidence architecture Population sources, timestamps, identity of the performer, criteria applied, and retention. Includes the 14-template workbook set.
- Module 4 — Operating tests that respect dependency Sampling approaches when configuration is incomplete, when dual control is claimed but not enforced, and when overrides exist.
- Module 5 — Walkthrough narrative lab Draft a walkthrough that an external reviewer in Korea can follow. Peer critique on clarity and overclaim.
- Module 6 — Capstone rewrite Rewrite one live control from your environment (sanitized). Cohort Seat includes instructor feedback.
Instructor
Minji Han
Former internal audit lead and finance systems liaison. Focuses on ERP-adjacent manual controls and evidence design for teams closing under Korean statutory calendars. Teaches in English with Korea-context examples.
Informational pricing
Cohort Seat for this flagship path is listed at ₩1,150,000 on our pricing page. Practice Alliance bundles start from ₩4,800,000. No payment is processed on this website — contact us to enroll.
FAQ
Do I need deep ITGC expertise first?
No. You need enough fluency to know when a control leans on application configuration versus a person. Module 2 covers how to escalate ITGC gaps without pretending you own them.
Is this a substitute for your external auditor’s methodology?
No. We teach practitioner craft for describing and testing bridges. Firm methodology, industry guides, and engagement partner judgment still govern your file.
What is a real limitation of this course?
We cannot remediate broken master data, missing privileged-access monitoring, or political blocks that prevent sample access. If IT will not stabilize an export, your rewritten control may still fail operating tests — and we will say so rather than sell a workaround as a cure.
What language and delivery format?
All materials are in English. Live office hours are scheduled for Korea evening slots unless a Practice Alliance agrees otherwise.
Reviews tied to this course
Useful overall. Capstone feedback was candid that our override language was still soft. I would have liked one more ERP-specific lab for our stack — accepted that a general course cannot cover every vendor.