Certified Internal Auditor (CIA) — Questions and Answers
Question 1: Which of the following BEST explains why the IIA requires external quality assessments in addition to internal self-assessments?
- External assessors have authority to require organizational changes that internal auditors lack
- External assessors can perform audit work that internal auditors are not qualified to perform
- Internal self-assessments are too costly to perform more frequently
- External assessments provide an independent perspective that mitigates self-assessment bias (Correct answer)
Correct answer: External assessments provide an independent perspective that mitigates self-assessment bias
External assessments are required because they provide an objective, independent view that reduces the inherent bias risk present when an activity evaluates itself.
Question 2: A senior internal auditor is asked by the CEO to omit an unfavorable finding from the audit report to avoid embarrassing a key executive. The auditor should:
- Omit the finding if it is below a pre-established materiality threshold
- Summarize the finding in a separate management letter instead of the formal report
- Delay issuance of the report until the issue is remediated
- Include the finding regardless of management pressure, as integrity requires honest reporting (Correct answer)
Correct answer: Include the finding regardless of management pressure, as integrity requires honest reporting
The integrity principle of the Code of Ethics requires auditors to report truthfully; suppressing findings at management's request violates both integrity and the reporting standards.
Question 3: According to IIA Standards, what is the recommended reporting relationship for the chief audit executive (CAE)?
- Functionally to the audit committee and administratively to senior management (Correct answer)
- Functionally to the CFO and administratively to the CEO
- Functionally to the external auditors and administratively to the board chair
- Exclusively to the CEO for all reporting purposes
Correct answer: Functionally to the audit committee and administratively to senior management
IIA Standards recommend the CAE report functionally to the audit committee to preserve independence and administratively to senior management for operational support.
Question 4: When using regression analysis to evaluate procurement spend, a high R-squared value indicates:
- All procurement transactions comply with policy
- The model has detected fraud in the dataset
- The sample size is too small to be reliable
- A large proportion of variation in spend is explained by the selected variables (Correct answer)
Correct answer: A large proportion of variation in spend is explained by the selected variables
R-squared (coefficient of determination) measures the proportion of variance in the dependent variable explained by the independent variables in the regression model.
Question 5: The IIA Standards require an external quality assessment of the internal audit function at least once every:
- Two years
- Five years (Correct answer)
- Three years
- Seven years
Correct answer: Five years
Standard 1312 requires external assessments to be conducted at least once every five years by a qualified, independent assessor or assessment team.
Question 6: Which type of malware encrypts an organization's files and demands payment for the decryption key?
- Adware
- Ransomware (Correct answer)
- Rootkit
- Spyware
Correct answer: Ransomware
Ransomware encrypts victim files or systems and extorts payment in exchange for providing the decryption key.
Question 7: Which metric best measures the effectiveness of an organization's patch management program?
- Percentage of critical vulnerabilities remediated within defined SLAs (Correct answer)
- Total cost of patch deployment activities
- Number of IT staff responsible for patching
- Frequency of vendor-released security updates
Correct answer: Percentage of critical vulnerabilities remediated within defined SLAs
Measuring the percentage of critical vulnerabilities patched within SLAs directly assesses whether the patch management program is timely and effective.
Question 8: What role does peer review play in Certified Internal Auditor practice?
- It creates unnecessary competition
- It provides quality assurance and professional development through collegial evaluation (Correct answer)
- It replaces formal certification
- It is only for beginners
Correct answer: It provides quality assurance and professional development through collegial evaluation
This is fundamental to Certified Internal Auditor practice. It provides quality assurance and professional development through collegial evaluation represents the professional standard for professional standards in the Certified Internal Auditor certification framework.
Question 9: Which type of engagement provides independent assessments of conformance with plans, policies, and regulations?
- Assurance engagement (Correct answer)
- Advisory engagement
- Consulting engagement
- Facilitation engagement
Correct answer: Assurance engagement
Assurance engagements involve objective assessments of evidence to provide independent opinions on governance, risk, and control processes.
Question 10: Which statistical concept is MOST relevant when an auditor wants to determine whether a difference in error rates between two departments is statistically meaningful?
- Regression to the mean
- Hypothesis testing with significance testing (Correct answer)
- Stratified random sampling
- Confidence interval estimation
Correct answer: Hypothesis testing with significance testing
Hypothesis testing with significance testing (e.g., t-tests or chi-square tests) determines whether observed differences are statistically significant or likely due to chance.
Question 11: An independent board director is best characterized as someone who:
- Has no material relationship with the company that could influence their judgment (Correct answer)
- Holds a significant equity ownership stake in the company
- Serves simultaneously on all standing board committees
- Is appointed directly by the chief executive officer
Correct answer: Has no material relationship with the company that could influence their judgment
Board independence requires that a director have no material relationship with the company—financial, personal, or professional—that could impair their objective judgment, as defined by stock exchange listing standards.
Question 12: Which audit approach involves embedding continuous monitoring routines directly within an application to report exceptions in near real time?
- Control self-assessment
- IT general control testing
- Substantive analytical procedures
- Embedded audit modules (Correct answer)
Correct answer: Embedded audit modules
Embedded audit modules are routines inserted into application systems that automatically capture and report exception transactions for auditor review.
Question 13: An internal auditor who accepts a significant gift from a vendor whose contract the auditor is currently reviewing violates which Code of Ethics rule?
- Competency – by failing to apply due professional care
- Confidentiality – by sharing engagement information with the vendor
- Integrity – by performing acts that discredit the profession
- Both integrity and objectivity rules (Correct answer)
Correct answer: Both integrity and objectivity rules
Accepting a gift from an auditee violates both integrity (discrediting behavior) and objectivity (creating a personal interest that impairs impartial assessment).
Question 14: Which engagement planning step requires the auditor to obtain background information about the processes and risks of the area under review?
- Final communication
- Preliminary survey (Correct answer)
- Fieldwork
- Follow-up
Correct answer: Preliminary survey
A preliminary survey gathers background information about the auditable unit to help the auditor understand risks and focus the engagement.
Question 15: Which of the following is the MOST important factor in determining audit universe prioritization during risk-based audit planning?
- Requests from senior management
- Results of the organization's risk assessment (Correct answer)
- Availability of audit staff
- Prior year audit findings
Correct answer: Results of the organization's risk assessment
Risk-based audit planning aligns audit resources with areas of highest risk as identified through the organization's risk assessment process.
Question 16: An internal auditor is assessing IT governance. Which framework is MOST widely used as a reference for IT governance and management of enterprise IT?
- ITIL
- COBIT (Correct answer)
- ISO 27001
- NIST Cybersecurity Framework
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is the most widely recognized framework specifically designed for IT governance and management.
Question 17: Which of the following best describes the concept of 'reasonable assurance' in internal auditing?
- Assurance provided only on financial controls
- Absolute certainty that all risks have been eliminated
- A high level of confidence that objectives are being met, though not a guarantee (Correct answer)
- Confirmation that no fraud exists within the organization
Correct answer: A high level of confidence that objectives are being met, though not a guarantee
Reasonable assurance is a high but not absolute level of confidence that controls are functioning and objectives are being achieved.
Question 18: What is the primary purpose of a data loss prevention (DLP) solution?
- Monitoring and preventing unauthorized transfer of sensitive data (Correct answer)
- Encrypting data at rest
- Detecting malware on endpoints
- Backing up critical business data automatically
Correct answer: Monitoring and preventing unauthorized transfer of sensitive data
DLP solutions monitor, detect, and block unauthorized transmission of sensitive data outside the organization.
Question 19: During a risk assessment, an internal auditor determines that a control exists but has not been tested. How should this control be classified in the risk assessment?
- As an unverified control that should not reduce the assessed risk until tested (Correct answer)
- As an effective control that reduces inherent risk
- As a compensating control with full credit
- As an ineffective control requiring immediate remediation
Correct answer: As an unverified control that should not reduce the assessed risk until tested
Untested controls cannot be credited for risk reduction because their operating effectiveness has not been confirmed.
Question 20: An internal audit activity uses a balanced scorecard approach in its QAIP. Which perspective would MOST directly measure audit quality from the auditee's viewpoint?
- Financial perspective tracking cost per audit hour
- Internal process perspective measuring workpaper completion timeliness
- Learning perspective measuring staff training hours completed
- Customer perspective measuring auditee satisfaction and perceived value (Correct answer)
Correct answer: Customer perspective measuring auditee satisfaction and perceived value
The customer perspective of a balanced scorecard captures how stakeholders and auditees perceive the quality and value of internal audit services.
Question 21: When evaluating the design effectiveness of a compliance control, an internal auditor should ask:
- Is the control capable of preventing or detecting the targeted compliance risk? (Correct answer)
- Who is responsible for executing the control?
- How long has the control been in place?
- Has the control ever failed in the past?
Correct answer: Is the control capable of preventing or detecting the targeted compliance risk?
Design effectiveness testing determines whether a control, if operating as designed, can adequately address the identified compliance risk.
Question 22: An internal audit engagement is planned for an area with high inherent risk and weak controls. How should this affect the engagement approach?
- Expand the scope and increase testing depth to obtain sufficient evidence (Correct answer)
- Defer the engagement to the next audit cycle when controls may improve
- Reduce the sample size to finish faster and escalate findings quickly
- Limit procedures to inquiry and observation to avoid disturbing operations
Correct answer: Expand the scope and increase testing depth to obtain sufficient evidence
High inherent risk combined with weak controls requires expanded scope and more rigorous testing to gather sufficient, reliable evidence.
Question 23: Which situation would most likely impair an internal auditor's objectivity?
- Auditing a function the auditor's spouse currently manages (Correct answer)
- Auditing a department the auditor supervised two years ago
- Auditing a new business unit the auditor has never reviewed
- Auditing a process the auditor helped design five years ago
Correct answer: Auditing a function the auditor's spouse currently manages
A current family relationship with the process owner creates a direct conflict of interest that impairs objectivity, unlike historical associations which may require only a one-year cooling-off period.
Question 24: An auditor discovers that an organization consistently records revenue one day before shipment occurs to meet quarterly targets. Under GAAP, this is most likely a violation of which accounting principle?
- Conservatism
- Revenue recognition / matching principle (Correct answer)
- Consistency
- Full disclosure
Correct answer: Revenue recognition / matching principle
Under GAAP/ASC 606, revenue must be recognized when performance obligations are satisfied (delivery), not before shipment is complete.
Question 25: When evaluating an organization's digital transformation initiative, an internal auditor should FIRST assess which of the following?
- The project manager's credentials and experience
- The technical architecture of new digital platforms
- Cost savings projected from automation technologies
- Alignment of the initiative with the organization's strategic objectives and risk appetite (Correct answer)
Correct answer: Alignment of the initiative with the organization's strategic objectives and risk appetite
Auditors should first confirm that the digital transformation initiative aligns with organizational strategy and fits within the defined risk appetite before evaluating technical details.
Question 26: An auditor is testing controls over financial statement close. She finds that journal entries posted after period-end cutoff lack supporting documentation 40% of the time. Management says this is due to time pressure. What is the primary audit concern?
- Whether the close timeline should be extended
- Risk of unsupported or fraudulent manual journal entries manipulating reported results (Correct answer)
- Whether the auditor's sample size was large enough
- Staff training on documentation requirements
Correct answer: Risk of unsupported or fraudulent manual journal entries manipulating reported results
Unsupported post-close journal entries represent a high risk for earnings manipulation and are a key fraud indicator in financial reporting audits.
Question 27: Computer-assisted audit techniques (CAATs) are PRIMARILY used to:
- Communicate findings to the audit committee
- Test large volumes of data efficiently and identify anomalies (Correct answer)
- Replace the need for professional judgment
- Prepare the auditor's working papers automatically
Correct answer: Test large volumes of data efficiently and identify anomalies
CAATs allow auditors to analyze entire populations of data, perform calculations, and detect exceptions that would be impractical to identify manually.
Question 28: How should an Certified Internal Auditor professional handle an outcome that differs from expectations?
- Analyze contributing factors, document findings, and adjust approach based on lessons learned (Correct answer)
- Blame external factors
- Ignore the discrepancy
- Repeat the same approach
Correct answer: Analyze contributing factors, document findings, and adjust approach based on lessons learned
This is fundamental to Certified Internal Auditor practice. Analyze contributing factors, document findings, and adjust approach based on lessons learned represents the professional standard for practical in the Certified Internal Auditor certification framework.
Question 29: Which research methodology is MOST appropriate when an auditor wants to explore the root cause of a recurring control failure with no pre-existing hypothesis?
- Exploratory qualitative case study (Correct answer)
- Benchmarking against industry averages
- Deductive quantitative analysis
- Confirmatory statistical testing
Correct answer: Exploratory qualitative case study
Exploratory qualitative methods such as case studies are appropriate when the goal is to understand a phenomenon and generate hypotheses rather than test pre-defined ones.
Question 30: Which statement best describes the concept of 'organizational independence' for an internal audit function?
- The internal audit budget must be approved directly by external auditors
- The CAE must report to a level within the organization that allows the function to fulfill its responsibilities (Correct answer)
- Auditors cannot audit any area where they previously worked
- Each auditor must be free from any bias when performing fieldwork
Correct answer: The CAE must report to a level within the organization that allows the function to fulfill its responsibilities
Organizational independence requires the CAE to report to a level—typically the board or audit committee—that enables the function to accomplish its mandate without management interference.
Question 31: Which type of evidence is considered MOST persuasive when evaluating internal control effectiveness?
- Oral representations from management
- Auditor observations recorded in working papers
- Internal memos prepared by the auditee
- Externally generated documentation obtained directly by the auditor (Correct answer)
Correct answer: Externally generated documentation obtained directly by the auditor
Externally generated evidence obtained directly by the auditor is most persuasive because it is independent of the auditee and obtained through the auditor's own procedures.
Question 32: What is a compliance management system in Certified Internal Auditor practice?
- A government reporting requirement
- A software application only
- A structured framework of policies, procedures, and controls that ensure regulatory adherence (Correct answer)
- An optional business tool
Correct answer: A structured framework of policies, procedures, and controls that ensure regulatory adherence
This is fundamental to Certified Internal Auditor practice. A structured framework of policies, procedures, and controls that ensure regulatory adherence represents the professional standard for regulatory in the Certified Internal Auditor certification framework.
Question 33: Under Sarbanes-Oxley and stock exchange rules, an audit committee should be composed of:
- A majority of independent directors, with at least one member qualifying as a financial expert (Correct answer)
- Equal representation of management nominees and major shareholders
- Exclusively members of the external audit firm
- At least one internal auditor and two senior executives
Correct answer: A majority of independent directors, with at least one member qualifying as a financial expert
SOX Section 301 and NYSE/NASDAQ listing rules require audit committees to consist entirely of independent directors, with at least one member designated as a financial expert.
Question 34: Standard 2010 requires the CAE to establish a risk-based audit plan. Which factor should be the PRIMARY driver of this plan?
- The organization's risk assessment (Correct answer)
- Prior year's audit findings
- Management's requested areas for review
- Available internal audit resources
Correct answer: The organization's risk assessment
Standard 2010 requires the audit plan to be based on a documented risk assessment, ensuring coverage is aligned with the organization's highest risks.
Question 35: Under the Dodd-Frank Act, which agency was created to oversee consumer financial protection?
- CFTC
- CFPB (Correct answer)
- OCC
- FDIC
Correct answer: CFPB
The Consumer Financial Protection Bureau (CFPB) was established by Dodd-Frank to regulate consumer financial products and enforce consumer protection laws.
Question 36: An internal auditor using analytical procedures compares current-year expense ratios to the prior year. This technique is BEST categorized as:
- Confirmation
- Reperformance
- Inquiry
- Trend analysis (Correct answer)
Correct answer: Trend analysis
Comparing financial or operational data over time periods is a form of trend analysis, a subset of analytical procedures.
Question 37: An internal auditor is reviewing a third-party vendor contract. Which risk is MOST unique to outsourced activities compared to in-house operations?
- Operational risk from process failures
- Lack of direct control over the vendor's internal controls and activities (Correct answer)
- Risk of financial misstatement
- Reputational risk from product quality issues
Correct answer: Lack of direct control over the vendor's internal controls and activities
Outsourcing creates unique risk because the organization cannot directly oversee or enforce controls over the third party's processes.
Question 38: Which of the following is an example of a risk response strategy known as 'risk sharing'?
- Discontinuing a high-risk product line
- Accepting the potential loss from minor fraud
- Installing fire suppression systems
- Purchasing insurance for property damage (Correct answer)
Correct answer: Purchasing insurance for property damage
Insurance transfers a portion of financial risk to a third party, which is the essence of the risk sharing (transfer) response.
Question 39: A 'reasonable assurance' standard in internal auditing means that:
- The audit opinion is conditioned on management's cooperation
- Auditors guarantee that all material misstatements will be detected
- Only controls rated as high-risk are subject to testing
- Assurance is high but not absolute, acknowledging inherent limitations of the audit process (Correct answer)
Correct answer: Assurance is high but not absolute, acknowledging inherent limitations of the audit process
Reasonable assurance is a high—but not absolute—level of assurance, recognizing that audits have inherent limitations such as sampling, judgment, and the possibility of collusion.
Question 40: An auditor uses process mining software to analyze event logs from an ERP system. The PRIMARY research advantage of this approach is:
- It eliminates the need for auditor professional judgment
- It provides an objective, data-driven reconstruction of actual process flows (Correct answer)
- It replaces the need for any manual testing procedures
- It guarantees detection of all control exceptions
Correct answer: It provides an objective, data-driven reconstruction of actual process flows
Process mining reconstructs actual process flows from system event logs, providing objective evidence of how processes were executed versus how they were designed.
Question 41: In the context of internal audit quality, 'conformance' with the IIA Standards is best understood as:
- Having policies and practices that meet the requirements of the Standards in substance (Correct answer)
- Complying with local laws that incorporate IIA Standards by reference
- Receiving a passing grade on a written examination administered by the IIA
- Achieving a perfect score on all assessment criteria
Correct answer: Having policies and practices that meet the requirements of the Standards in substance
Conformance means the internal audit activity's policies and practices substantively satisfy the requirements of the IIA Standards, not necessarily perfect compliance on every point.
Question 42: What is the primary purpose of the International Standards for the Professional Practice of Internal Auditing?
- To provide a framework for performing and promoting internal audit activities (Correct answer)
- To establish tax filing requirements for corporations
- To regulate external financial reporting
- To set accounting standards for publicly traded companies
Correct answer: To provide a framework for performing and promoting internal audit activities
The IIA Standards provide a framework for conducting internal audits consistently, ensuring quality, and promoting the value of internal auditing to organizations worldwide.
Question 43: In a qualitative audit study, 'saturation' refers to the point at which:
- The auditor has reviewed 100% of the transaction population
- The audit budget has been fully expended
- All employees in the organization have been interviewed
- Additional data collection no longer produces new themes or insights (Correct answer)
Correct answer: Additional data collection no longer produces new themes or insights
Data saturation in qualitative research occurs when additional data gathering yields no new themes, indicating sufficient depth of understanding has been achieved.
Question 44: What is the purpose of a quality audit in Certified Internal Auditor practice?
- To systematically evaluate processes against standards and identify improvement opportunities (Correct answer)
- To satisfy external requirements only
- To find fault with employees
- To reduce staffing
Correct answer: To systematically evaluate processes against standards and identify improvement opportunities
This is fundamental to Certified Internal Auditor practice. To systematically evaluate processes against standards and identify improvement opportunities represents the professional standard for quality in the Certified Internal Auditor certification framework.
Question 45: What is the significance of a code of conduct for Certified Internal Auditor professionals?
- It limits professional freedom
- It applies only to new practitioners
- It establishes expected behaviors and ethical standards that protect the public and profession (Correct answer)
- It is merely symbolic
Correct answer: It establishes expected behaviors and ethical standards that protect the public and profession
This is fundamental to Certified Internal Auditor practice. It establishes expected behaviors and ethical standards that protect the public and profession represents the professional standard for professional standards in the Certified Internal Auditor certification framework.
Question 46: An auditor reviewing a vendor's SOC 2 Type II report is primarily evaluating which aspect of third-party risk?
- The vendor's regulatory compliance in all jurisdictions
- Effectiveness of the vendor's controls over a period of time (Correct answer)
- Financial stability of the vendor
- Vendor pricing and contract terms
Correct answer: Effectiveness of the vendor's controls over a period of time
A SOC 2 Type II report provides an independent assessment of whether a service organization's controls operated effectively over a specified review period.
Question 47: When assessing enterprise risk management (ERM), internal auditors should PRIMARILY evaluate:
- Whether external auditors have approved the ERM framework
- Whether the ERM process aligns with the organization's risk appetite and objectives (Correct answer)
- The number of risk categories monitored by management
- Whether all identified risks have been eliminated
Correct answer: Whether the ERM process aligns with the organization's risk appetite and objectives
The key ERM assessment is whether the process is designed and operating to manage risks within the organization's stated risk appetite and support its objectives.
Question 48: What is the PRIMARY purpose of network segmentation from an information security perspective?
- Improving network speed and bandwidth
- Simplifying network administration tasks
- Reducing hardware costs through virtualization
- Limiting lateral movement by containing breaches to isolated segments (Correct answer)
Correct answer: Limiting lateral movement by containing breaches to isolated segments
Network segmentation limits an attacker's ability to move laterally through the environment by isolating systems into separate network zones.
Question 49: How do Certified Internal Auditor professionals establish measurable quality objectives?
- Using vague goals
- By defining specific, measurable, achievable, relevant, and time-bound quality targets (Correct answer)
- By comparing to competitors only
- Through subjective assessment
Correct answer: By defining specific, measurable, achievable, relevant, and time-bound quality targets
This is fundamental to Certified Internal Auditor practice. By defining specific, measurable, achievable, relevant, and time-bound quality targets represents the professional standard for quality in the Certified Internal Auditor certification framework.
Question 50: What is organizational independence in the context of internal auditing?
- The internal audit department operates as a separate legal entity
- The internal audit function reports to a level that allows it to fulfill responsibilities without interference (Correct answer)
- Internal auditors work from home independently
- The audit team has no interaction with management
Correct answer: The internal audit function reports to a level that allows it to fulfill responsibilities without interference
Organizational independence means the internal audit function reports functionally to the board or audit committee, ensuring it can perform its work without management interference or undue influence.
Question 51: How should internal auditors assess fraud risk?
- By interviewing only senior management
- By evaluating the fraud triangle elements: opportunity, pressure/incentive, and rationalization (Correct answer)
- By only checking for missing cash
- Fraud risk assessment is not an internal audit responsibility
Correct answer: By evaluating the fraud triangle elements: opportunity, pressure/incentive, and rationalization
Internal auditors assess fraud risk by evaluating the three elements of the fraud triangle — opportunity (weak controls), pressure (financial or personal), and rationalization (justification) — during all engagements.
Question 52: A company stores sensitive customer data in a public cloud. Which shared responsibility model concept is MOST critical for the auditor to understand?
- The cloud provider's compliance certifications cover all customer data
- The customer has no security responsibilities in the cloud
- The cloud provider is responsible for all data security
- Security responsibilities are divided between the provider and the customer (Correct answer)
Correct answer: Security responsibilities are divided between the provider and the customer
The shared responsibility model divides security obligations between the cloud provider and the customer, and customers retain responsibility for their data and access controls.
Question 53: An internal auditor is offered a substantial gift by a vendor being audited. Under the Code of Ethics, the auditor should:
- Accept the gift after the audit is completed
- Decline the gift to avoid compromising objectivity and integrity (Correct answer)
- Accept the gift if it is below the organization's materiality threshold
- Accept the gift and disclose it to the CAE
Correct answer: Decline the gift to avoid compromising objectivity and integrity
The Code of Ethics requires auditors to avoid accepting gifts that could impair or appear to impair their professional judgment, regardless of value.
Question 54: An auditor reviewing a bank's loan approval process finds that the same officer who approves loans also performs the annual credit reviews. What control deficiency does this represent?
- Non-compliance with loan-to-value ratio requirements
- Lack of segregation of duties, creating a self-review threat (Correct answer)
- Inadequate loan documentation standards
- Insufficient training for loan officers
Correct answer: Lack of segregation of duties, creating a self-review threat
Allowing the originating officer to also conduct credit reviews eliminates an independent check on the quality of lending decisions.
Question 55: Which statement best describes 'impairment' to internal audit independence under the IIA Standards?
- Any situation in which the auditor disagrees with management
- Receiving audit fees from the organization being audited
- Conditions that prevent the internal audit activity from fulfilling its responsibilities impartially (Correct answer)
- The auditor's lack of technical knowledge in a subject area
Correct answer: Conditions that prevent the internal audit activity from fulfilling its responsibilities impartially
Impairment refers to conditions — whether actual, potential, or perceived — that prevent internal auditors from fulfilling their responsibilities without bias or undue influence.
Question 56: How do Certified Internal Auditor professionals evaluate research quality?
- By assessing methodology, sample size, peer review status, and relevance to practice (Correct answer)
- By publication date only
- By the reputation of the author only
- Research quality cannot be evaluated
Correct answer: By assessing methodology, sample size, peer review status, and relevance to practice
This is fundamental to Certified Internal Auditor practice. By assessing methodology, sample size, peer review status, and relevance to practice represents the professional standard for research in the Certified Internal Auditor certification framework.
Question 57: Which element is NOT typically included in a regulatory change management process?
- Filing comments on proposed regulations (Correct answer)
- Updating policies and controls to address new requirements
- Monitoring regulatory publications and updates
- Assessing impact of new requirements on current processes
Correct answer: Filing comments on proposed regulations
Filing comments on proposed regulations is a lobbying/advocacy activity, not a standard element of an internal regulatory change management process.
Question 58: A Quality Assurance and Improvement Program (QAIP) must include which two types of assessments?
- Management surveys and board evaluations
- Ongoing monitoring and periodic self-assessments or external assessments (Correct answer)
- Benchmarking studies and client satisfaction surveys
- Peer reviews and regulatory inspections
Correct answer: Ongoing monitoring and periodic self-assessments or external assessments
Standard 1300 requires the QAIP to include ongoing internal monitoring and periodic internal and external assessments to evaluate conformance with the Standards.
Question 59: Which framework is MOST widely used to guide IT governance and management of enterprise IT?
- ISO 27001
- NIST CSF
- COBIT (Correct answer)
- COSO
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is the leading framework specifically designed for IT governance and management.
Question 60: What is the primary value of case study analysis in Certified Internal Auditor training?
- Learning only from failures
- Developing critical thinking by applying theory to realistic professional scenarios (Correct answer)
- Memorizing specific outcomes
- Replacing hands-on experience
Correct answer: Developing critical thinking by applying theory to realistic professional scenarios
This is fundamental to Certified Internal Auditor practice. Developing critical thinking by applying theory to realistic professional scenarios represents the professional standard for practical in the Certified Internal Auditor certification framework.
Question 61: Which governance body does the CAE primarily report functionally to?
- The Board or Audit Committee (Correct answer)
- Chief Executive Officer
- Chief Financial Officer
- External auditors
Correct answer: The Board or Audit Committee
To maintain independence, the CAE has a functional reporting relationship to the board or audit committee, which oversees the internal audit activity.
Question 62: An internal auditor discovers that a regional manager has been approving vendor invoices that exceed her authorization limit by routing them through a subordinate with higher limits. What should the auditor do first?
- Inform the subordinate they are violating policy
- Close the finding since the invoices were ultimately approved by someone with authority
- Immediately report the manager to law enforcement
- Document the finding and assess whether it constitutes a control override requiring escalation (Correct answer)
Correct answer: Document the finding and assess whether it constitutes a control override requiring escalation
The auditor should document the control override finding and evaluate its significance before determining the appropriate escalation path per IIA standards.
Question 63: What does the term 'data integrity' mean in an IT audit context?
- Data is encrypted to prevent unauthorized disclosure
- Data is accurate, complete, and unaltered during processing (Correct answer)
- Data is accessible only to authorized users
- Data is available whenever needed by users
Correct answer: Data is accurate, complete, and unaltered during processing
Data integrity ensures that data remains accurate, complete, and consistent throughout its lifecycle and is not improperly modified.
Question 64: An internal auditor reviews academic journals and professional publications before beginning a fraud risk assessment. This practice PRIMARILY supports:
- Development of an informed, evidence-based audit program (Correct answer)
- Compliance with continuing education requirements
- Reduction of the overall audit budget
- Satisfying peer review requirements
Correct answer: Development of an informed, evidence-based audit program
Reviewing current research and professional literature before fieldwork ensures the audit program is grounded in the latest knowledge about fraud schemes, red flags, and effective procedures.
Question 65: In a survey used to gather audit evidence, which factor MOST threatens the validity of responses?
- Leading questions that suggest a desired answer (Correct answer)
- High response rate from the target population
- Keeping the survey anonymous
- Using a Likert scale for attitude measurement
Correct answer: Leading questions that suggest a desired answer
Leading questions bias respondents toward a particular answer, undermining the validity and objectivity of the data collected.
Question 66: Which cloud deployment model provides dedicated infrastructure exclusively for a single organization?
- Community cloud
- Public cloud
- Private cloud (Correct answer)
- Hybrid cloud
Correct answer: Private cloud
A private cloud provides dedicated infrastructure exclusively for one organization, offering greater control and security.
Question 67: How should an Certified Internal Auditor professional approach a novel situation not covered by standard procedures?
- Improvise without documentation
- Refuse to proceed
- Apply foundational principles, assess risks, consult resources, and document the rationale for decisions (Correct answer)
- Follow the closest standard procedure exactly
Correct answer: Apply foundational principles, assess risks, consult resources, and document the rationale for decisions
This is fundamental to Certified Internal Auditor practice. Apply foundational principles, assess risks, consult resources, and document the rationale for decisions represents the professional standard for practical in the Certified Internal Auditor certification framework.
Question 68: An internal auditor discovers that a company's compliance program lacks a formal process for employees to report violations anonymously. Which framework element is most deficient?
- Risk Assessment
- Whistleblower Mechanisms (Correct answer)
- Tone at the Top
- Control Activities
Correct answer: Whistleblower Mechanisms
An anonymous reporting mechanism (whistleblower hotline) is a fundamental element of an effective compliance program under DOJ/OIG guidance.
Question 69: During an audit, an internal auditor discovers that a senior manager is circumventing established controls. The auditor should FIRST:
- Inform the chief audit executive and consider escalation to the audit committee (Correct answer)
- Close the engagement without reporting to avoid conflict
- Immediately report the finding to external regulators
- Confront the manager directly and demand an explanation
Correct answer: Inform the chief audit executive and consider escalation to the audit committee
The auditor should escalate findings involving senior management misconduct to the CAE, who may then communicate with the audit committee.
Question 70: The Sarbanes-Oxley Act of 2002 imposed which of the following penalties for CFOs and CEOs if the financial statements misled investors?
- Fines up to the amount of the misstatement
- Being barred from holding the position of CEO
- Prison time (Correct answer)
- We provide free consulting services in their areas of expertise for the community
Correct answer: Prison time
The Sarbanes-Oxley Act of 2002 (SOX) significantly increased the accountability of corporate executives. Section 906 of SOX, in particular, introduced severe criminal penalties, including substantial prison time, for CEOs and CFOs who knowingly sign off on false or misleading financial statements. This provision aimed to deter corporate fraud and restore investor confidence.
Question 71: According to the IIA Standards, which attribute standard addresses the organizational independence of the internal audit function?
- Standard 1200 – Proficiency and Due Professional Care
- Standard 1300 – Quality Assurance and Improvement Program
- Standard 1100 – Independence and Objectivity (Correct answer)
- Standard 1000 – Purpose, Authority, and Responsibility
Correct answer: Standard 1100 – Independence and Objectivity
Standard 1100 – Independence and Objectivity requires the internal audit function to be independent and auditors to be objective in performing their work.
Question 72: A QAIP metric showing that 40% of audit recommendations go unimplemented after 12 months PRIMARILY signals a problem with:
- The CAE's ability to obtain board approval for the audit plan
- Staff competency in performing fieldwork procedures
- The quality and relevance of audit findings and recommendations (Correct answer)
- The accuracy of workpaper documentation standards
Correct answer: The quality and relevance of audit findings and recommendations
A high rate of unimplemented recommendations suggests the recommendations may not be practical, relevant, or sufficiently persuasive, indicating a quality issue in findings and reporting.
Question 73: An internal auditor reviewing IT general controls (ITGCs) would primarily focus on which of the following?
- Change management, access controls, and IT operations (Correct answer)
- User interface design and usability
- Application-level business logic validation
- Network bandwidth and latency metrics
Correct answer: Change management, access controls, and IT operations
ITGCs encompass change management, logical access controls, and IT operations that underpin all application controls.
Question 74: Which Internet of Things (IoT) security risk is MOST challenging for organizations to manage?
- Incompatibility between IoT platforms and cloud services
- Large volumes of unmanaged devices with limited security capabilities running on corporate networks (Correct answer)
- Slow data transmission speeds from IoT sensors
- High cost of IoT device procurement
Correct answer: Large volumes of unmanaged devices with limited security capabilities running on corporate networks
Many IoT devices lack robust security features and cannot be easily patched, making it difficult for organizations to manage the large attack surface they create.
Question 75: What is a risk appetite statement?
- A financial report showing risk-related expenses
- A menu for the audit department's lunch meetings
- A list of risks the organization wants to take on
- A board-level declaration of the amount of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
Correct answer: A board-level declaration of the amount of risk an organization is willing to accept in pursuit of its objectives
A risk appetite statement, set by the board, defines the types and levels of risk the organization is willing to accept, providing guidance for management decision-making.
Question 76: Which of the following is a primary responsibility of the audit committee within corporate governance?
- Oversight of financial reporting integrity, internal controls, and external auditors (Correct answer)
- Setting product pricing strategies and revenue targets
- Day-to-day operational management of finance department activities
- Directly managing the internal audit department's budget and staffing
Correct answer: Oversight of financial reporting integrity, internal controls, and external auditors
The audit committee's primary responsibility is overseeing financial reporting processes, the adequacy of internal controls, and the relationship with and work of external auditors.
Question 77: A company implements a new ERP system and the internal audit team is asked to assess implementation controls. The auditor finds that parallel testing was skipped due to go-live timeline pressure. What risk does this create?
- Data migration errors and system configuration issues may not be detected before the system goes live, compromising data integrity (Correct answer)
- Staff training costs will increase post-implementation
- The ERP system may not integrate with existing applications
- The ERP vendor may void the support contract
Correct answer: Data migration errors and system configuration issues may not be detected before the system goes live, compromising data integrity
Skipping parallel testing removes the primary detective control for identifying data migration errors and misconfigured processes before they affect production operations.
Question 78: Why is evidence-based practice important in Certified Internal Auditor?
- It replaces experience
- It is a theoretical concept only
- It only applies to academic settings
- It integrates best available evidence with professional expertise for optimal outcomes (Correct answer)
Correct answer: It integrates best available evidence with professional expertise for optimal outcomes
This is fundamental to Certified Internal Auditor practice. It integrates best available evidence with professional expertise for optimal outcomes represents the professional standard for research in the Certified Internal Auditor certification framework.
Question 79: The THREE lines of defense model assigns which role to internal audit?
- Fourth line — external audit
- First line — operational management
- Third line — independent assurance (Correct answer)
- Second line — risk and compliance functions
Correct answer: Third line — independent assurance
Internal audit serves as the third line of defense by providing independent assurance on the effectiveness of governance, risk management, and controls.
Question 80: Which metric is MOST useful for measuring the efficiency of the internal audit activity as part of a QAIP?
- Number of audit committee meetings attended by the CAE
- Ratio of planned audit hours to actual hours incurred per engagement (Correct answer)
- Percentage of staff holding advanced degrees
- Total number of recommendations issued across all engagements
Correct answer: Ratio of planned audit hours to actual hours incurred per engagement
Comparing planned versus actual hours per engagement measures scheduling accuracy and resource efficiency, both key QAIP efficiency metrics.
Question 81: A self-assessment with independent validation (SAIV) differs from a full external assessment primarily because:
- It is conducted entirely by internal staff without any external involvement
- An external reviewer validates the self-assessment work performed internally (Correct answer)
- It is performed less frequently than a full external assessment
- It does not result in a conformance opinion
Correct answer: An external reviewer validates the self-assessment work performed internally
In SAIV, the internal audit activity performs the self-assessment, and a qualified external reviewer validates the process and conclusions.
Question 82: When an internal audit finding lacks sufficient evidential support, the MOST appropriate action is to:
- Issue the finding with a disclaimer
- Rely on management's verbal confirmation
- Reduce the severity rating and include the finding anyway
- Perform additional procedures to gather corroborating evidence (Correct answer)
Correct answer: Perform additional procedures to gather corroborating evidence
Audit findings must be supported by sufficient, reliable evidence; if evidence is lacking, the auditor must perform additional procedures before including the finding in the report.
Question 83: The competency element of the IIA Code of Ethics requires internal auditors to:
- Engage only in services for which they have necessary knowledge and skills (Correct answer)
- Avoid engagements outside their primary industry experience
- Hold the CIA certification within three years of employment
- Complete 80 hours of CPE every two years
Correct answer: Engage only in services for which they have necessary knowledge and skills
The Competency rule requires auditors to engage only in services for which they possess sufficient knowledge, skills, and experience.
Question 84: In the context of CIA exam competencies, 'governance' in internal auditing refers to:
- External regulatory requirements imposed on publicly traded companies
- The combination of processes and structures to direct, manage, and oversee organizational activities (Correct answer)
- The audit committee's approval of the internal audit budget
- The IT general controls over financial reporting systems
Correct answer: The combination of processes and structures to direct, manage, and oversee organizational activities
Governance encompasses the processes and structures used by an organization's board and management to direct, oversee, and ensure accountability for the organization's activities.
Question 85: How should Certified Internal Auditor professionals stay current with regulatory changes?
- Rely on colleagues for updates
- Monitor regulatory updates, participate in professional associations, and attend continuing education (Correct answer)
- Wait until audited
- Regulations rarely change
Correct answer: Monitor regulatory updates, participate in professional associations, and attend continuing education
This is fundamental to Certified Internal Auditor practice. Monitor regulatory updates, participate in professional associations, and attend continuing education represents the professional standard for regulatory in the Certified Internal Auditor certification framework.
Question 86: A company migrating its ERP system to the cloud should ensure which control is in place to prevent unauthorized data access during migration?
- Updated software licensing agreements
- Data encryption in transit (Correct answer)
- Increased system performance monitoring
- Employee background checks
Correct answer: Data encryption in transit
Encrypting data in transit protects sensitive information from interception during the cloud migration process.
Question 87: Which type of IT audit procedure would BEST verify that terminated employees' access has been revoked?
- Interviewing the IT security manager about procedures
- Observing the IT team process a new termination
- Comparing active user accounts to current employee records (Correct answer)
- Reviewing the HR termination policy document
Correct answer: Comparing active user accounts to current employee records
Comparing active system accounts against current HR records directly tests whether terminated employee access has actually been removed.
Question 88: An internal auditor discovers that a prior audit engagement did not test a key control that was within scope. This situation BEST represents a failure in:
- Engagement supervision (Correct answer)
- Risk assessment
- External assessment
- Audit committee communication
Correct answer: Engagement supervision
Failure to test a control within scope indicates inadequate engagement supervision, which should catch gaps in audit coverage during workpaper review.
Question 89: When an internal auditor's scope or resources are restricted by management in a way that limits the engagement, the CAE must:
- Communicate the impact of the limitation to senior management and the board (Correct answer)
- Immediately resign from the engagement
- Expand testing in unrestricted areas to compensate
- Accept the restriction and adjust the engagement objectives accordingly
Correct answer: Communicate the impact of the limitation to senior management and the board
Standard 1110 requires the CAE to communicate resource and scope limitations that impair independence to senior management and the board so they can make informed governance decisions.
Question 90: How does continuous improvement apply to Certified Internal Auditor quality management?
- It means constant major changes
- It is a one-time initiative
- It involves ongoing incremental enhancements to processes based on data and feedback (Correct answer)
- It applies only to products
Correct answer: It involves ongoing incremental enhancements to processes based on data and feedback
This is fundamental to Certified Internal Auditor practice. It involves ongoing incremental enhancements to processes based on data and feedback represents the professional standard for quality in the Certified Internal Auditor certification framework.
Question 91: Standard 2600 addresses communicating senior management's acceptance of risk. If the CAE believes the accepted risk level is inappropriate, the CAE must:
- Refuse to issue the final audit report
- Document the disagreement and take no further action
- Escalate the matter to the board (Correct answer)
- Notify external regulators of the unresolved risk
Correct answer: Escalate the matter to the board
Standard 2600 requires the CAE to escalate the matter to the board when management accepts a level of residual risk that the CAE believes is inappropriate.
Question 92: Which principle requires that users receive only the minimum system access needed to perform their job functions?
- Defense in depth
- Segregation of duties
- Least privilege (Correct answer)
- Need to know
Correct answer: Least privilege
The principle of least privilege limits user access rights to only what is necessary, reducing the attack surface and potential for misuse.
Question 93: Under the IIA Standards, 'due professional care' requires internal auditors to consider which of the following during planning?
- The probability of significant errors, fraud, or noncompliance (Correct answer)
- The number of prior engagements performed in the area
- The budget approved by the audit committee
- The personal qualifications of each audit team member
Correct answer: The probability of significant errors, fraud, or noncompliance
Standard 1220 requires auditors to consider the likelihood of significant errors, irregularities, or noncompliance when applying due professional care.
Question 94: The International Standards for the Professional Practice of Internal Auditing are organized into which two main categories?
- Attribute and Performance Standards (Correct answer)
- Mandatory and Recommended Standards
- Assurance and Consulting Standards
- Financial and Operational Standards
Correct answer: Attribute and Performance Standards
The Standards are organized into Attribute Standards (1000 series), which describe characteristics of the audit activity, and Performance Standards (2000 series), which describe the nature of audit work.
Question 95: The IIA Code of Ethics applies to:
- Only members of the IIA
- External auditors who rely on internal audit work
- Only CIA-certified professionals
- All individuals and entities that provide internal audit services (Correct answer)
Correct answer: All individuals and entities that provide internal audit services
The Code of Ethics applies to all individuals and entities that provide internal audit services, whether or not they are IIA members or hold IIA certifications.
Question 96: Which internal control framework is most widely used for compliance evaluations under the Sarbanes-Oxley Act in the United States?
- COBIT 2019
- ISO 31000
- Basel III Capital Framework
- COSO Internal Control – Integrated Framework (Correct answer)
Correct answer: COSO Internal Control – Integrated Framework
The COSO Internal Control – Integrated Framework is the most widely adopted standard for internal control evaluation in the U.S. and is explicitly referenced in SEC/SOX guidance.
Question 97: What role does data analytics play in Certified Internal Auditor practice?
- It creates unnecessary complexity
- It supports evidence-based decision making by identifying patterns and trends in relevant data (Correct answer)
- It replaces professional judgment
- It is only for IT professionals
Correct answer: It supports evidence-based decision making by identifying patterns and trends in relevant data
This is fundamental to Certified Internal Auditor practice. It supports evidence-based decision making by identifying patterns and trends in relevant data represents the professional standard for technology in the Certified Internal Auditor certification framework.
Question 98: What is inherent risk versus residual risk?
- They are the same measurement at different time points
- Inherent risk only applies to financial audits
- Inherent risk exists before controls; residual risk remains after controls are applied (Correct answer)
- Residual risk is always higher than inherent risk
Correct answer: Inherent risk exists before controls; residual risk remains after controls are applied
Inherent risk is the level of risk present before any controls are implemented, while residual risk is the risk remaining after management applies controls and mitigation measures.
Question 99: Key Risk Indicators (KRIs) are most useful to internal auditors because they:
- Define the maximum risk the board will accept
- Replace the need for substantive testing
- Signal emerging risk before it materializes into loss (Correct answer)
- Provide a historical record of losses incurred
Correct answer: Signal emerging risk before it materializes into loss
KRIs are forward-looking metrics that alert management and auditors to increasing risk exposure before a loss event occurs.
Question 100: An auditor reviewing capital project management finds that a $5M construction project has no change order log, and the final cost was $7.2M. What is the primary audit finding?
- Lack of change order controls, preventing proper authorization and tracking of scope/cost changes (Correct answer)
- The project cost overrun itself is the finding
- The budget was inadequately set at project initiation
- The project manager exceeded authority
Correct answer: Lack of change order controls, preventing proper authorization and tracking of scope/cost changes
The absence of a change order log is a control deficiency that prevented proper oversight of the $2.2M cost increase.
Question 101: Which type of audit report format is MOST appropriate for communicating high-level results to a board with limited time?
- An executive summary highlighting key findings, risks, and recommended actions (Correct answer)
- A raw data dump of all test results for the board to analyze
- A comprehensive report with detailed methodology and all working paper references
- A technical report written in audit terminology for rigor
Correct answer: An executive summary highlighting key findings, risks, and recommended actions
An executive summary tailored to board members focuses on risk-significant findings and decisions needed, respecting their limited time and strategic focus.
Question 102: Which of the following scenarios represents an inappropriate use of research evidence in internal auditing?
- Citing IIA Standards to support a recommendation
- Using industry loss data to calibrate fraud risk ratings
- Selecting only studies that confirm a predetermined audit conclusion (Correct answer)
- Referencing prior audit findings to assess repeat risk
Correct answer: Selecting only studies that confirm a predetermined audit conclusion
Selectively citing only evidence that supports a pre-existing conclusion is confirmation bias and violates the objectivity principles of evidence-based practice.
Question 103: Standard 1220 (Due Professional Care) requires internal auditors to consider which factor when planning an engagement?
- Probability of significant errors, irregularities, or noncompliance (Correct answer)
- Number of staff days available for fieldwork
- The auditee's satisfaction scores from prior audits
- Cost of audit procedures relative to budget
Correct answer: Probability of significant errors, irregularities, or noncompliance
Standard 1220 requires auditors to consider the probability of significant errors, fraud, or noncompliance when applying due professional care.
Question 104: The IIA's Code of Ethics principle of 'integrity' primarily requires internal auditors to:
- Disclose all material facts known to them in reports
- Maintain confidentiality of information acquired during engagements
- Perform work with honesty and avoid acts that discredit the profession (Correct answer)
- Refrain from accepting gifts of any monetary value
Correct answer: Perform work with honesty and avoid acts that discredit the profession
The integrity principle requires auditors to perform work with honesty, diligence, and responsibility, and to avoid acts that discredit the profession.
Question 105: An internal auditor is asked to consult on the design of a new internal control for a high-risk process. After the consulting engagement, what must the auditor do to preserve objectivity for future assurance work on this area?
- Conduct the future assurance engagement without disclosure since it was consulting, not audit
- Require management to certify that the control was their own design
- Disclose the consulting role and the potential impairment of objectivity to the CAE (Correct answer)
- Refuse all future assignments in the area permanently
Correct answer: Disclose the consulting role and the potential impairment of objectivity to the CAE
Auditors who consulted on a control design must disclose the potential objectivity impairment to the CAE before conducting assurance work on that area.
Question 106: How do Certified Internal Auditor professionals build trust with clients or stakeholders?
- Through marketing only
- By always agreeing with clients
- Through competitive pricing only
- Through consistent competence, transparency, reliability, and ethical behavior (Correct answer)
Correct answer: Through consistent competence, transparency, reliability, and ethical behavior
This is fundamental to Certified Internal Auditor practice. Through consistent competence, transparency, reliability, and ethical behavior represents the professional standard for communication in the Certified Internal Auditor certification framework.
Question 107: Which element distinguishes a 'consulting engagement' from an 'assurance engagement' under the IIA Standards?
- Consulting engagements cannot involve the same areas as prior assurance work
- Assurance engagements are always initiated by the board; consulting by management
- In consulting, the nature and scope are agreed upon with the client; in assurance, a third party receives the output (Correct answer)
- Consulting engagements require a written report; assurance engagements do not
Correct answer: In consulting, the nature and scope are agreed upon with the client; in assurance, a third party receives the output
Assurance engagements provide an independent opinion to a third-party stakeholder, while consulting engagements are advisory in nature with scope and objectives agreed upon with the requesting client.
Question 108: A control self-assessment (CSA) workshop generates data that is BEST classified as:
- Secondary data sourced from published benchmarks
- External quantitative evidence
- Primary qualitative data collected directly by the auditor (Correct answer)
- Conclusive proof of control effectiveness
Correct answer: Primary qualitative data collected directly by the auditor
CSA workshops produce primary qualitative data because the auditor directly facilitates and collects the information from participants, though it requires corroboration.
Question 109: The IIA Code of Ethics rule on 'Confidentiality' prohibits internal auditors from:
- Retaining working papers beyond one audit cycle
- Sharing audit reports with external auditors
- Using electronic communication for sensitive findings
- Disclosing information without appropriate authority unless legally obligated (Correct answer)
Correct answer: Disclosing information without appropriate authority unless legally obligated
The Confidentiality rule prohibits auditors from disclosing information without appropriate authority unless there is a legal or professional obligation to do so.
Question 110: Standard 2340 requires that engagement working papers be:
- Shared with external auditors upon request
- Retained according to the organization's retention policies and applicable regulations (Correct answer)
- Approved by the board audit committee before filing
- Destroyed after the final report is issued
Correct answer: Retained according to the organization's retention policies and applicable regulations
Standard 2340 requires the CAE to develop and maintain record retention policies consistent with organizational guidelines and applicable regulations.
Certified Internal Auditor (CIA)
The CIA is the only globally accepted certification for internal auditors, awarded by The IIA. It validates knowledge across internal audit fundamentals, the practice of internal auditing, and business knowledge including IT, security, and financial management.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds