Certified Internal Auditor Professional Standards & Competencies 4 — Questions and Answers
Question 1: When an internal auditor's scope or resources are restricted by management in a way that limits the engagement, the CAE must:
- Accept the restriction and adjust the engagement objectives accordingly
- Immediately resign from the engagement
- Communicate the impact of the limitation to senior management and the board (Correct answer)
- Expand testing in unrestricted areas to compensate
Correct answer: Communicate the impact of the limitation to senior management and the board
Standard 1110 requires the CAE to communicate resource and scope limitations that impair independence to senior management and the board so they can make informed governance decisions.
Question 2: The 'confidentiality' principle in the IIA Code of Ethics prohibits internal auditors from disclosing information EXCEPT when:
- A regulatory authority subpoenas the information or disclosure is legally or professionally obligated (Correct answer)
- The information is requested by senior management of the audited entity
- The auditor believes the information would improve organizational performance
- Another auditor working on a related engagement requests access
Correct answer: A regulatory authority subpoenas the information or disclosure is legally or professionally obligated
The confidentiality rule permits disclosure only when there is a legal or professional obligation to do so, such as a lawful subpoena or mandatory reporting requirement.
Question 3: Which of the following best illustrates 'impairment to independence or objectivity' as described in the IIA Standards?
- An auditor who has not yet passed the CIA exam performing an engagement
- An auditor auditing a process they designed and implemented two years ago (Correct answer)
- An audit team that has not received training in data analytics
- A CAE who reports to both the CFO and the audit committee
Correct answer: An auditor auditing a process they designed and implemented two years ago
Auditing a process the auditor personally designed creates a self-review threat—a direct impairment to objectivity because auditors cannot objectively assess their own work.
Question 4: An internal audit charter must be approved by:
- The Chief Executive Officer and the external audit firm
- Senior management and the board (Correct answer)
- The CAE and the engagement client
- The IIA's regional chapter upon membership renewal
Correct answer: Senior management and the board
Standard 1000 requires the internal audit charter to be approved by senior management and the board, formalizing the function's purpose, authority, and responsibility.
Question 5: A 'reasonable assurance' standard in internal auditing means that:
- Auditors guarantee that all material misstatements will be detected
- Assurance is high but not absolute, acknowledging inherent limitations of the audit process (Correct answer)
- Only controls rated as high-risk are subject to testing
- The audit opinion is conditioned on management's cooperation
Correct answer: Assurance is high but not absolute, acknowledging inherent limitations of the audit process
Reasonable assurance is a high—but not absolute—level of assurance, recognizing that audits have inherent limitations such as sampling, judgment, and the possibility of collusion.
Question 6: Under the IIA Standards, which type of engagement is NOT within the typical scope of internal audit work?
- Assurance engagements
- Consulting engagements
- Compliance audits
- Preparation of financial statements for management (Correct answer)
Correct answer: Preparation of financial statements for management
Preparing financial statements is a management function and would create a self-review threat; internal auditors provide assurance and consulting services, not accounting preparation services.
Question 7: Which element distinguishes a 'consulting engagement' from an 'assurance engagement' under the IIA Standards?
- Consulting engagements require a written report; assurance engagements do not
- In consulting, the nature and scope are agreed upon with the client; in assurance, a third party receives the output (Correct answer)
- Assurance engagements are always initiated by the board; consulting by management
- Consulting engagements cannot involve the same areas as prior assurance work
Correct answer: In consulting, the nature and scope are agreed upon with the client; in assurance, a third party receives the output
Assurance engagements provide an independent opinion to a third-party stakeholder, while consulting engagements are advisory in nature with scope and objectives agreed upon with the requesting client.
When an internal auditor's scope or resources are restricted by management in a way that limits the engagement, the CAE must: