Certified Internal Auditor (CIA) — Questions and Answers
Question 1: An organization's risk appetite differs from its risk tolerance in that risk appetite represents:
- The residual risk after mitigation is applied
- The specific variance permitted around individual risk targets
- The broad level of risk an entity is willing to accept in pursuit of objectives (Correct answer)
- The maximum loss acceptable before controls fail
Correct answer: The broad level of risk an entity is willing to accept in pursuit of objectives
Risk appetite is the overall amount of risk an entity is willing to accept, while risk tolerance is the acceptable deviation around specific objectives.
Question 2: Which of the following best describes 'inherent risk' in an audit context?
- Risk that cannot be mitigated under any circumstances
- The gross risk exposure before any controls are applied (Correct answer)
- Risk identified only through substantive testing
- Risk remaining after management applies controls
Correct answer: The gross risk exposure before any controls are applied
Inherent risk is the level of risk that exists in the absence of any management controls or mitigating actions.
Question 3: An organization's code of ethics is most effective when:
- It is consistently enforced with visible and proportionate consequences for violations at all levels (Correct answer)
- It is distributed electronically once per year with an acknowledgment requirement
- It contains the maximum possible number of specific rules and prohibitions
- It is drafted exclusively by the legal department without operational input
Correct answer: It is consistently enforced with visible and proportionate consequences for violations at all levels
A code of ethics achieves maximum effectiveness when senior leadership visibly enforces it consistently, including at leadership levels, demonstrating genuine organizational commitment.
Question 4: How should an Certified Internal Auditor professional approach a novel situation not covered by standard procedures?
- Apply foundational principles, assess risks, consult resources, and document the rationale for decisions (Correct answer)
- Follow the closest standard procedure exactly
- Refuse to proceed
- Improvise without documentation
Correct answer: Apply foundational principles, assess risks, consult resources, and document the rationale for decisions
This is fundamental to Certified Internal Auditor practice. Apply foundational principles, assess risks, consult resources, and document the rationale for decisions represents the professional standard for practical in the Certified Internal Auditor certification framework.
Question 5: In a containerized application environment, which security risk is MOST specific to container technology?
- SQL injection in application code
- Container escape allowing access to the host system (Correct answer)
- Cross-site scripting in web interfaces
- Weak password policies for user accounts
Correct answer: Container escape allowing access to the host system
Container escape vulnerabilities allow malicious processes to break out of the container sandbox and gain access to the underlying host system.
Question 6: Which of the following BEST illustrates the use of deductive reasoning in an audit?
- Reviewing historical data to generate a new risk hypothesis
- Observing many transactions and concluding a pattern of fraud exists
- Interviewing staff to discover undocumented processes
- Applying a known control standard to assess whether a specific control meets requirements (Correct answer)
Correct answer: Applying a known control standard to assess whether a specific control meets requirements
Deductive reasoning moves from a general principle (the standard) to a specific conclusion (whether this control meets it), which is a top-down logical process.
Question 7: An internal auditor discovers that a close personal friend works in a department being audited. The auditor should FIRST:
- Limit their testing to areas not involving the friend
- Recuse themselves and disclose the conflict to the CAE (Correct answer)
- Complete the audit but document the relationship in workpapers
- Obtain written consent from the friend before proceeding
Correct answer: Recuse themselves and disclose the conflict to the CAE
When a personal relationship creates a potential independence impairment, the auditor must immediately disclose the conflict to the CAE for reassignment or other resolution.
Question 8: Which scenario represents a violation of the IIA's principle of 'Integrity'?
- Omitting an unfavorable finding from a report to avoid conflict (Correct answer)
- Declining to audit a department managed by a close relative
- Seeking additional training before performing an IT audit
- Consulting with legal counsel on a sensitive finding
Correct answer: Omitting an unfavorable finding from a report to avoid conflict
Integrity requires auditors to be honest and not suppress findings; omitting an unfavorable finding directly violates this principle.
Question 9: An internal auditor who accepts a significant gift from a vendor whose contract the auditor is currently reviewing violates which Code of Ethics rule?
- Competency – by failing to apply due professional care
- Integrity – by performing acts that discredit the profession
- Both integrity and objectivity rules (Correct answer)
- Confidentiality – by sharing engagement information with the vendor
Correct answer: Both integrity and objectivity rules
Accepting a gift from an auditee violates both integrity (discrediting behavior) and objectivity (creating a personal interest that impairs impartial assessment).
Question 10: What is organizational independence in the context of internal auditing?
- The internal audit department operates as a separate legal entity
- Internal auditors work from home independently
- The internal audit function reports to a level that allows it to fulfill responsibilities without interference (Correct answer)
- The audit team has no interaction with management
Correct answer: The internal audit function reports to a level that allows it to fulfill responsibilities without interference
Organizational independence means the internal audit function reports functionally to the board or audit committee, ensuring it can perform its work without management interference or undue influence.
Question 11: Under the IIA's International Standards, an internal audit function must be independent from the activities it audits. This independence is primarily achieved through:
- Limiting audit scope to financial matters
- Organizational reporting relationships (Correct answer)
- Rotating audit staff annually
- Using external consultants
Correct answer: Organizational reporting relationships
Organizational independence is achieved when the chief audit executive reports functionally to the board (or audit committee), free from management interference.
Question 12: During a QAIP review, an internal auditor notes that engagement objectives were not clearly linked to the risks identified in the planning phase. This finding MOST likely indicates a deficiency in:
- Engagement planning quality controls (Correct answer)
- External assessment procedures
- Workpaper retention policies
- Audit report formatting standards
Correct answer: Engagement planning quality controls
Failure to align engagement objectives with identified risks reflects a weakness in engagement planning quality controls, a core QAIP component.
Question 13: According to the IIA Standards, who is responsible for maintaining a quality assurance and improvement program (QAIP) for the internal audit activity?
- The external auditor
- The chief audit executive (Correct answer)
- The audit committee
- The board of directors
Correct answer: The chief audit executive
Standard 1300 requires the chief audit executive to develop and maintain a QAIP that covers all aspects of the internal audit activity.
Question 14: Which of the following BEST describes a 'key risk indicator' (KRI)?
- A forward-looking metric that provides early warning of increasing risk exposure (Correct answer)
- A historical report of past losses and control failures
- A measure that signals the effectiveness of a completed audit
- A benchmark comparing the company's risk to industry peers
Correct answer: A forward-looking metric that provides early warning of increasing risk exposure
KRIs are forward-looking metrics used to signal rising risk levels before they materialize into losses or control failures.
Question 15: The primary purpose of a literature review in an audit research project is to:
- Replace primary data collection with secondary sources
- Demonstrate the auditor's academic credentials
- Identify existing knowledge, frameworks, and gaps relevant to the audit topic (Correct answer)
- Satisfy documentation requirements in the working papers
Correct answer: Identify existing knowledge, frameworks, and gaps relevant to the audit topic
A literature review establishes what is already known, identifies relevant frameworks, and reveals gaps that the current research aims to address.
Question 16: What is the primary purpose of the International Standards for the Professional Practice of Internal Auditing?
- To regulate external financial reporting
- To provide a framework for performing and promoting internal audit activities (Correct answer)
- To set accounting standards for publicly traded companies
- To establish tax filing requirements for corporations
Correct answer: To provide a framework for performing and promoting internal audit activities
The IIA Standards provide a framework for conducting internal audits consistently, ensuring quality, and promoting the value of internal auditing to organizations worldwide.
Question 17: An auditor reviewing capital project management finds that a $5M construction project has no change order log, and the final cost was $7.2M. What is the primary audit finding?
- The project manager exceeded authority
- Lack of change order controls, preventing proper authorization and tracking of scope/cost changes (Correct answer)
- The budget was inadequately set at project initiation
- The project cost overrun itself is the finding
Correct answer: Lack of change order controls, preventing proper authorization and tracking of scope/cost changes
The absence of a change order log is a control deficiency that prevented proper oversight of the $2.2M cost increase.
Question 18: How do continuing education requirements benefit Certified Internal Auditor certified professionals?
- They ensure professionals stay current with evolving industry practices and knowledge (Correct answer)
- They only benefit training providers
- They reduce practical skills
- They are unnecessary formalities
Correct answer: They ensure professionals stay current with evolving industry practices and knowledge
This is fundamental to Certified Internal Auditor practice. They ensure professionals stay current with evolving industry practices and knowledge represents the professional standard for professional standards in the Certified Internal Auditor certification framework.
Question 19: When evaluating the sufficiency of audit evidence, an auditor should consider:
- The quantity of evidence needed to support each audit conclusion (Correct answer)
- Whether management agrees with the evidence collected
- Whether the evidence was gathered by the most senior team member
- The cost of evidence relative to the audit fee
Correct answer: The quantity of evidence needed to support each audit conclusion
Sufficiency refers to the quantity of evidence needed; IIA Standards require that evidence be sufficient, meaning enough to support the auditor's conclusions.
Question 20: How do Certified Internal Auditor professionals contribute to advancing their field?
- By conducting research, sharing outcomes, mentoring others, and participating in professional forums (Correct answer)
- By competing with colleagues
- By maintaining current practices
- Individual contribution is not possible
Correct answer: By conducting research, sharing outcomes, mentoring others, and participating in professional forums
This is fundamental to Certified Internal Auditor practice. By conducting research, sharing outcomes, mentoring others, and participating in professional forums represents the professional standard for research in the Certified Internal Auditor certification framework.
Question 21: A researcher uses purposive sampling to select interview subjects for an audit. This approach is BEST suited when:
- Statistical generalization to the full population is required
- Specific knowledge-holders relevant to the audit objective are targeted (Correct answer)
- Random representation of all employees is the goal
- Large sample sizes are available and needed
Correct answer: Specific knowledge-holders relevant to the audit objective are targeted
Purposive sampling deliberately selects subjects based on specific characteristics or knowledge relevant to the research question, making it ideal when expertise matters more than statistical representation.
Question 22: The IIA Code of Ethics applies to:
- External auditors who rely on internal audit work
- All individuals and entities that provide internal audit services (Correct answer)
- Only members of the IIA
- Only CIA-certified professionals
Correct answer: All individuals and entities that provide internal audit services
The Code of Ethics applies to all individuals and entities that provide internal audit services, whether or not they are IIA members or hold IIA certifications.
Question 23: Which element is NOT typically included in a regulatory change management process?
- Filing comments on proposed regulations (Correct answer)
- Updating policies and controls to address new requirements
- Monitoring regulatory publications and updates
- Assessing impact of new requirements on current processes
Correct answer: Filing comments on proposed regulations
Filing comments on proposed regulations is a lobbying/advocacy activity, not a standard element of an internal regulatory change management process.
Question 24: An auditor is reviewing expense reimbursements and notices that a senior executive submitted $12,000 in meal receipts over three months, all just below the $500 per-event threshold requiring additional approval. What fraud scheme does this pattern suggest?
- Structuring (threshold avoidance) (Correct answer)
- Ghost employee fraud
- Lapping
- Skimming
Correct answer: Structuring (threshold avoidance)
Consistently submitting expenses just below approval thresholds is a classic structuring scheme designed to avoid control triggers.
Question 25: An auditor uses regression analysis during an engagement. This is an example of which type of audit procedure?
- Compliance testing
- Substantive testing
- Walk-through procedure
- Analytical procedure (Correct answer)
Correct answer: Analytical procedure
Regression analysis is an analytical procedure used to identify relationships and unusual variations in data.
Question 26: An auditor reviewing a government contractor's cost accounting finds that the company is allocating 100% of executive salaries to government contracts. The executives also work on commercial contracts. What is the primary concern?
- Unallowable cost allocation that inflates charges to the government by attributing costs not exclusively incurred for government work (Correct answer)
- The allocation method was not pre-approved by the DCAA
- Executive compensation is not an allowable cost category under any government contract
- The salaries exceed the compensation cap under FAR
Correct answer: Unallowable cost allocation that inflates charges to the government by attributing costs not exclusively incurred for government work
Allocating shared costs entirely to government contracts when executives support commercial work violates cost accounting standards and FAR, constituting potential false claims.
Question 27: An auditor applies a 95% confidence interval to sampling results. This means:
- The auditor is 95% certain that all errors have been detected
- The sample size represents 95% of the total population
- 5% of transactions in the population are erroneous
- There is a 5% risk that the true population value falls outside the interval (Correct answer)
Correct answer: There is a 5% risk that the true population value falls outside the interval
A 95% confidence interval means there is a 5% risk (alpha risk) that the true population parameter lies outside the calculated interval.
Question 28: The IIA's Code of Ethics applies to which individuals?
- Only Certified Internal Auditors (CIAs) who hold an active certification
- External auditors who perform co-sourced internal audit work
- All individuals and entities that provide internal audit services, including IIA members and CIA candidates (Correct answer)
- Employees of organizations that have adopted the IIA Standards
Correct answer: All individuals and entities that provide internal audit services, including IIA members and CIA candidates
The Code of Ethics applies to IIA members, individuals holding IIA certifications, and those applying for certifications—essentially all who provide internal audit services under the IIA umbrella.
Question 29: Which of the following is an example of a detective control?
- Encrypting sensitive data files
- Conducting monthly bank reconciliations (Correct answer)
- Performing background checks on new employees
- Requiring dual authorization before processing payments
Correct answer: Conducting monthly bank reconciliations
Bank reconciliations detect discrepancies after they occur, making them detective controls rather than preventive or corrective controls.
Question 30: A CIA candidate is reviewing IT general controls (ITGCs). Which of the following is an example of an ITGC?
- User access management and periodic access recertification (Correct answer)
- Automated calculation of depreciation in the ERP system
- Three-way matching of purchase orders, receiving reports, and vendor invoices
- Segregation of duties in the cash receipts process
Correct answer: User access management and periodic access recertification
User access management and recertification are IT general controls that provide a foundation for the reliability of all application controls.
Certified Internal Auditor (CIA)
The CIA is the only globally accepted certification for internal auditors, awarded by The IIA. It validates knowledge across internal audit fundamentals, the practice of internal auditing, and business knowledge including IT, security, and financial management.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds