Technology risk is now part of almost every assurance conversation
Yet many audit, risk and compliance professionals have never been shown how to take a technology-focused engagement from risk assessment through planning, evidence evaluation and influential reporting.
Reviewing policies or collecting screenshots is not enough. Credible assurance requires clear scope, traceable testing, professional judgement and conclusions that executives can act on.
This bootcamp gives participants a practical method. Across four live sessions, you will work through the fictional NovaPay Group case, apply HazelGRC templates and practise the decisions that shape a defensible technology assurance engagement.
Move from understanding technology risk to delivering credible technology assurance.
Designed for professionals who need a practical, structured understanding of technology assurance
- Internal auditors whose assignments increasingly include technology risks.
- IT auditors seeking a stronger end-to-end assurance method.
- Risk and compliance professionals who evaluate technology controls.
- Aspiring technology assurance professionals building practical capability.
- Audit managers developing team members beyond checklist-based testing.
- Small corporate teams seeking a shared, repeatable approach.
No engineering or coding background is required. The programme is practitioner-focused and assumes general familiarity with audit, risk, compliance or governance concepts.
What participants will be able to do
- Translate technology dependencies into clear business-risk statements.
- Define a neutral audit objective and a risk-based scope.
- Build a traceable risk and control matrix and work programme.
- Evaluate IT general controls, cybersecurity, cloud and third-party risk evidence.
- Distinguish control design from operating effectiveness.
- Assess whether evidence is relevant, reliable, complete and sufficient.
- Develop balanced findings and proportionate recommendations.
- Write concise executive messages and defend an overall conclusion.
- Use data and AI responsibly while preserving confidentiality, verification and human accountability.
A complete engagement, session by session
- No. 01
Session 1 — Technology risk and assurance lifecycle
Thursday, 8 October
Business objectives, technology dependencies, risk language, controls, evidence and the end-to-end assurance lifecycle.
- No. 02
Session 2 — Scoping and audit planning
Tuesday, 13 October
Engagement objectives, risk-based boundaries, RCM construction, work programmes, evidence and selection planning.
- No. 03
Session 3 — Evaluating controls and evidence
Thursday, 15 October
ITGCs, cyber, cloud, resilience and third parties; design, operation, evidence quality and bounded conclusions.
- No. 04
Session 4 — Findings, reporting and responsible AI
Tuesday, 20 October
Finding construction, ratings, management challenge, executive reporting, responsible AI, case presentation and assessment.
The NovaPay case
NovaPay Group is a fictional, rapidly growing financial-services organisation using cloud services, multiple technology suppliers and AI-supported fraud detection. New information is released as the programme progresses. Participants must identify risks, define scope, build tests, evaluate imperfect evidence, revise judgements and present an executive conclusion.
Why this matters
The case mirrors real assurance work: information is incomplete, evidence can conflict and strong practitioners explain both their conclusion and its limits.
Every registered participant receives the HazelGRC Technology Assurance Practitioner Toolkit for personal professional use
- Participant manual and technology risk universe.
- Technology audit planning template and risk and control matrix.
- Sample work programme and stakeholder interview-question bank.
- Evidence-request list, control-design tool and testing worksheet.
- Finding evaluation and rating tool.
- Audit finding and executive report templates.
- Responsible AI use checklist and quality-review checklist.
- Technology assurance glossary, reading list and 30-day application plan.
These are working resources—not a collection of blank documents. Participants use selected tools during the NovaPay case and can adapt them to their own professional work under the participant licence.
Humphrey Okorie — Founder and Principal Consultant, HazelGRC
Humphrey is a senior technology audit and assurance leader with more than 20 years of experience across technology audit, cybersecurity, risk, governance and privacy. He has worked across complex organisations and regulated sectors and brings a practitioner’s perspective to translating technical risk into clear assurance and executive action.
Credentials: CIA, CISA, CISSP, CRMA and CDPSE; MBA in Technology Management; Bachelor of Technology in Mathematics and Computer Science.
Participants who meet the completion requirements receive a HazelGRC Certificate of Completion stating 12 guided learning hours
- Attend at least three live sessions and complete approved catch-up for any missed session.
- Participate in the NovaPay case and team presentation.
- Achieve at least 70% in the individual assessment.
- Submit a personal 30-day application plan.
Admission options
Founding-cohort early bird
£395
Individual place; available until 13 September 2026.
Standard individual
£595
Individual place from 14 September to registration close.
Africa regional place
£325
Individual regional rate, subject to eligibility and billing/residency validation.
Team of three
£1,350
Three places from one organisation; consolidated invoice.
Team of five
£2,250
Five places, consolidated invoice, private 45-minute team debrief and participation summary.
All fees are shown in GBP. Apply the organisation’s approved tax treatment at checkout or invoice.
Programme timeline
- Registration opens
- 24 August 2026
- Early-bird rate ends
- 13 September 2026 at 23:59 BST
- General registration closes
- 4 October 2026 at 23:59 BST, or earlier if full
- Onboarding
- 5–7 October 2026
- Live sessions
- 8, 13, 15 and 20 October 2026
Before you register
Yes. It teaches how to frame technology risk, ask the right questions, evaluate evidence and report conclusions. It does not require coding or engineering experience.
HazelGRC may make session recordings available to registered participants for 30 days, subject to the published recording and privacy arrangements. Recordings are not transferable.
You must attend at least three sessions live and complete the approved catch-up requirement for any missed session to qualify for the certificate.
No. Successful participants receive a HazelGRC Certificate of Completion for 12 guided learning hours. The programme is not presented as an accredited professional certification.
Yes. Team packages are available for three or five participants. Larger or private cohorts can be discussed with HazelGRC.
The regional rate is intended for eligible participants resident and billed in African markets. HazelGRC may request reasonable information to validate eligibility.
Four live sessions, participant manual, NovaPay learning case, practitioner toolkit, assessment, limited recording access where provided and a certificate for eligible completers.
The HazelGRC Academy Programme Terms apply. Read the HazelGRC Academy Programme Terms.
No workplace data is required. Participants should not disclose client, employer or personal confidential information during activities or in AI tools.
HazelGRC will confirm delivery after the minimum viable cohort is reached. Registered participants will be contacted in accordance with the Academy Programme Terms if the programme cannot proceed.
Ready to deliver technology assurance with greater confidence?
Join the founding cohort of the HazelGRC Technology Assurance Practitioner Bootcamp and work through the complete journey from risk assessment to audit reporting.
By registering, you agree to the HazelGRC Academy Programme Terms and acknowledge the Privacy Policy. Places are subject to availability and programme confirmation.