Las Vegas In-Person CPE Week: Five Days to Build Serious Audit, Cybersecurity, Internal Control and Assurance Skills
- John C. Blackshire, Jr.

- Aug 16
- 8 min read
Las Vegas Strip Area • September 28–October 2, 2026
Las Vegas may be known for entertainment, but during the week of September 28–October 2, 2026, Corporate Compliance Seminars is giving auditors, accountants, compliance professionals, IT auditors, and risk professionals another reason to come to
Las Vegas:
Concentrated, multi-day, in-person professional education.
Corporate Compliance Seminars (CCS) is bringing a substantial portfolio of in-person CPE programs to the Las Vegas Strip area, with courses ranging from 8 to 40 CPE credits. Attendees can select programs covering Internal Audit, cybersecurity, ITGCs, SOC audits, COSO, SOX, GAO standards, fraud and forensic accounting, banking, external audit and assurance, and ISO 9001.
Why Use Las Vegas for a Professional Development Week?
There is a significant difference between collecting CPE hours and developing a professional competency.
A two-hour webinar can be excellent for learning about a new standard or getting a focused technical update.
But developing expertise in areas such as:
Internal Audit
Audit leadership
Cybersecurity
IT General Controls
SOC reporting
COSO
Fraud investigation
Government auditing
External audit and assurance
often requires more time.
CCS's Las Vegas model allows professionals to step away from everyday interruptions and spend two, three, or even five consecutive days concentrating on a subject.
The current CCS calendar identifies Las Vegas as one of its multi-day CPE locations for September 28–October 2, 2026.
Internal Auditing: Basic to Advanced — 40 CPEs
One of the most comprehensive programs available during the week is Internal Auditing: Basic to Advanced, presented Monday through Friday for 40 CPE credits.
Five days creates an opportunity to move beyond isolated auditing concepts and look at the entire audit life cycle:
Risk Assessment
↓
Audit Planning
↓
Walkthroughs
↓
Internal Controls
↓
Fieldwork
↓
Audit Evidence
↓
Workpapers
↓
Findings
↓
Reporting
↓
Corrective Action
This type of intensive program can be particularly valuable for auditors who have learned primarily through on-the-job experience and want to put a more complete methodology around what they do.
It can also be valuable for organizations building or strengthening an Internal Audit department.
Becoming an Awesome New Auditor — 24 CPEs
New auditors face an unusual problem.
They are expected to evaluate experienced managers and complicated business processes while they are still learning how auditing actually works.
CCS lists Becoming an Awesome New Auditor as a 24-CPE Monday-through-Wednesday program during the Las Vegas week.
A new auditor needs more than technical terminology.
They need to learn how to:
Prepare for an interview
Conduct a walkthrough
Ask follow-up questions
Separate facts from explanations
Recognize control weaknesses
Obtain evidence
Document conclusions
Communicate professionally
The objective should not merely be producing an auditor who can complete a checklist.
It should be developing an auditor who knows how to think like an auditor.
Being an Audit Leader — 24 CPEs
The skills that make someone a strong auditor are not necessarily the skills that make someone a strong audit leader.
CCS also lists Being an Audit Leader as a Monday-through-Wednesday, 24-CPE program.
Audit leaders have to manage:
People + Risk + Methodology + Quality + Stakeholders + Resources
A staff auditor may be judged primarily on the quality of their own work.
An audit leader must create an environment in which the entire team produces quality work.
That means developing capabilities involving:
Coaching
Supervision
Risk-based planning
Workpaper review
Difficult conversations
Resource allocation
Executive communication
Audit quality
Those are leadership competencies—not merely advanced auditing techniques.
Auditing and Improving Your Cybersecurity Program — 24 CPEs
Cybersecurity is no longer an issue that Internal Audit can simply hand to the IT department.
CCS lists Auditing and Improving Your Cybersecurity Program as another 24-CPE Monday-through-Wednesday option.
Modern organizations depend upon technology for:
Financial reporting
Banking
Customer information
Operations
Communications
Supply chains
Regulatory compliance
Cybersecurity therefore represents enterprise risk.
Internal Audit needs enough cybersecurity knowledge to ask management:
What are our critical information assets?
What threats could affect them?
What controls mitigate those risks?
Are those controls properly designed?
Do we have evidence they are operating?
That is a fundamentally different conversation from simply asking whether the organization has antivirus software.
Auditing Business Applications — 24 CPEs
CCS also lists Auditing Business Applications as a Tuesday-through-Thursday, 24-CPE program.
Business processes increasingly exist inside applications.
Procure-to-pay, order-to-cash, payroll, financial reporting, inventory, and other processes can depend heavily upon automated controls.
That means auditors need to understand the relationship between:
Business Process Controls
and
Information Technology Controls
An automated control is only as reliable as the environment supporting it.
ITGC Audit Planning Through Reporting — 16 CPEs
For professionals wanting a concentrated IT audit program, CCS lists ITGC Audit Planning Through Reporting for Thursday and Friday, providing 16 CPE credits.
This is particularly important because ITGC auditing should not end with a generic checklist.
The auditor needs to understand how to move from:
IT Risk
↓
Audit Objective
↓
Control
↓
Audit Procedure
↓
Evidence
↓
Exception
↓
Finding
↓
Report
Areas such as logical access, privileged access, change management, security, and computer operations can directly affect the reliability of systems supporting financial and operational controls.
SSAE SOC Audits: Auditee – Auditor – Assessor Training — 24 CPEs
The Las Vegas schedule includes SSAE SOC Audits: Auditee – Auditor – Assessor Training, presented Monday through Wednesday for 24 CPE credits.
SOC reports have become increasingly important as organizations outsource critical services.
But there are several perspectives involved:
The service organization preparing for the examination.
The auditor performing the examination.
The user organization relying on the report.
Each has different responsibilities.
That makes understanding SOC reports valuable for external auditors, internal auditors, IT auditors, risk professionals, vendor-management personnel, and service organizations themselves.
COSO and SOX Training
Internal-control professionals also have substantial options during the Las Vegas week.
CCS lists Using the COSO Framework for Compliance and SOX as a 24-CPE Monday-through-Wednesday program and Effective Use of the COSO Framework as a 16-CPE Thursday-through-Friday program.
Effective internal control requires much more than maintaining a control matrix.
A mature approach connects:
Objectives → Risks → Controls → Design → Operation → Evidence → Deficiencies → Remediation
One of the biggest mistakes in SOX and internal-control programs is assuming:
“The control was performed, therefore the control is effective.”
That conclusion may be wrong.
A control can operate exactly as management designed it and still fail to address the underlying risk.
That is why professionals need to understand both design effectiveness and operating effectiveness.
GAO Green Book Compliance Academy — 24 CPEs
Government internal-control professionals have another substantial option.
CCS lists the GAO Green Book Compliance Academy as a Monday-through-Wednesday, 24-CPE program.
The Green Book provides the federal internal-control framework organized around the familiar five components:
Control Environment
Risk Assessment
Control Activities
Information and Communication
Monitoring
For professionals working in federal agencies or organizations applying Green Book concepts, the challenge is moving from understanding those five components to determining whether the organization's system of internal control is actually functioning effectively.
GAO Yellow Book Training — 24 CPEs
CCS separately lists Using the GAO Yellow Book for the Government Auditor as a 24-CPE Monday-through-Wednesday program.
The distinction matters.
The Green Book addresses internal control.
The Yellow Book addresses government auditing standards.
Government auditors may need substantial knowledge of both, but the two should not be confused.
Forensic and Investigative Accounting — 24 CPEs
CCS also lists Forensic and Investigative Accounting for Monday through Wednesday, providing 24 CPE credits.
Fraud-oriented work requires a different mindset from ordinary compliance testing.
The conventional auditor asks:
“Was the control performed?”
The forensic professional may need to ask:
“How could someone intentionally defeat this control and conceal what they did?”
That involves understanding:
Fraud schemes
Evidence
Human behavior
Internal controls
Data
Interviews
Documentation
It is the difference between auditing for error and thinking deliberately about deception.
Internal Auditing in the Banking Industry — 16 CPEs
Bank auditors have specialized risks that generic Internal Audit training may not fully address.
CCS lists Internal Auditing in the Banking Industry as a Thursday-through-Friday, 16-CPE program.
Bank auditors need to understand risks involving areas such as:
Deposits
Lending
BSA/AML
Fraud
Information technology
Cybersecurity
Regulatory compliance
Third parties
Internal controls
Internal Audit methodology provides the foundation.
Industry knowledge makes the methodology useful.
External Auditor Staff Development
The Las Vegas week also offers progressive Audit & Assurance staff training.
CCS currently lists Staff One and Staff Three for Tuesday–Wednesday, and Staff Two and Staff Four for Thursday–Friday, with each program providing 16 CPE credits.
That progression recognizes an important reality about external-auditor development:
A fourth-year auditor should not be receiving the same professional development as a first-year auditor.
As experience increases, training should move progressively from performing procedures toward exercising judgment, evaluating evidence, supervising others, identifying issues, and managing engagement responsibilities.
ISO 9001 QMS Compliance & Auditing — 24 CPEs
CCS also lists ISO 9001 QMS Compliance & Auditing as a 24-CPE Monday-through-Wednesday program.
ISO 9001 principles extend beyond manufacturing.
Quality management involves:
Processes
Responsibilities
Risk
Documentation
Performance measurement
Corrective action
Continuous improvement
Those concepts can be valuable across many types of organizations.
Or Build a Shorter Las Vegas Training Schedule
Not everyone can spend three to five days in training.
CCS therefore also has a separate Las Vegas schedule of shorter 2-, 4-, and 8-CPE programs during the same September 28–October 2 week.
Those offerings include subjects such as Information Technology General Controls, continuous auditing, auditor soft skills, audit report writing, fraud controls, COSO ICFR, cybersecurity, managing audit quality and workpapers, conflict resolution, design-effectiveness testing, operating-effectiveness testing, Internal Auditing 101, ethics, audit sampling, and cybersecurity resilience.
That creates considerable flexibility.
Come for half a day.
Come for a day.
Come for two days.
Or use Las Vegas for a full 40-CPE professional-development week.
Why In-Person Training Still Matters
Auditing is a technical discipline, but it is also a human discipline.
Auditors need to learn how to:
Ask difficult questions
Recognize weak explanations
Challenge management respectfully
Evaluate conflicting evidence
Deal with defensiveness
Exercise professional skepticism
Explain risk
Influence corrective action
Those capabilities benefit from interaction.
CCS emphasizes direct instructor engagement, interactive discussion, case studies, peer interaction, and focused learning as advantages of its in-person programs.
A classroom also removes one of the biggest problems with remote professional education:
distraction.
There is no Teams message flashing in the corner.
No second monitor full of email.
No manager walking into the office.
You are there to learn.
Make Las Vegas a CPE Destination
The location adds another advantage.
CCS states that the programs will be presented in the Las Vegas Strip area, with attendees receiving the specific seminar location by email after their seminar is confirmed.
That makes it possible to combine concentrated professional education with the restaurants, entertainment, and attractions available around the Strip.
But during the day, the objective is professional development.
The week gives organizations an opportunity to send different members of their audit, finance, compliance, and IT teams to different programs based upon their responsibilities.
The Bottom Line
The September 28–October 2, 2026 Las Vegas CPE week gives professionals an opportunity to stop treating continuing education as an annual requirement and start treating it as an investment in capability.
You can spend the week becoming a better:
Internal Auditor.
Audit Leader.
IT Auditor.
Cybersecurity Auditor.
SOX Professional.
Government Auditor.
Fraud Investigator.
External Auditor.
Or build a customized combination of shorter programs around the particular skills you need.
CCS has created a week where professionals can select the depth and subject matter that make sense for their careers.
And there is something appropriate about doing it in Las Vegas.
Auditors spend their careers evaluating risk.
Come to Las Vegas and spend a week learning how to do it better.
Comments