Certified Internal Auditor Professional Standards & Competencies 5 β Questions and Answers
Question 1: The IIA Standards state that internal auditors must possess knowledge of 'key information technology risks and controls.' This requirement falls under which standard?
- Standard 1000 β Purpose, Authority, and Responsibility
- Standard 1210 β Proficiency (Correct answer)
- Standard 1310 β Requirements of the Quality Assurance Program
- Standard 2100 β Nature of Work
Correct answer: Standard 1210 β Proficiency
Standard 1210 requires internal auditors to have sufficient knowledge of key IT risks and controls to perform their assigned responsibilities, even if they are not IT specialists.
Question 2: When results of a QAIP indicate that the internal audit function does NOT conform with the IIA Standards, the CAE is required to:
- Suspend all audit activities until conformance is achieved
- Disclose the non-conformance and its impact to senior management and the board (Correct answer)
- Engage an external firm to take over audit operations
- File a formal non-conformance notice with the IIA
Correct answer: Disclose the non-conformance and its impact to senior management and the board
Standard 1322 requires the CAE to disclose non-conformances and their impacts to senior management and the board, allowing governance stakeholders to take remedial action.
Question 3: A senior internal auditor is asked by the CEO to omit an unfavorable finding from the audit report to avoid embarrassing a key executive. The auditor should:
- Omit the finding if it is below a pre-established materiality threshold
- Include the finding regardless of management pressure, as integrity requires honest reporting (Correct answer)
- Summarize the finding in a separate management letter instead of the formal report
- Delay issuance of the report until the issue is remediated
Correct answer: Include the finding regardless of management pressure, as integrity requires honest reporting
The integrity principle of the Code of Ethics requires auditors to report truthfully; suppressing findings at management's request violates both integrity and the reporting standards.
Question 4: In CIA exam context, 'risk-based internal auditing' means that audit resources are allocated based on:
- The number of employees in each auditable unit
- A systematic evaluation of the likelihood and impact of risks across the organization (Correct answer)
- Rotating coverage of all departments on an equal-time basis
- Management's specific requests for audit services
Correct answer: A systematic evaluation of the likelihood and impact of risks across the organization
Risk-based auditing directs resources toward areas with the highest likelihood and potential impact of risk, ensuring the audit plan addresses the organization's most significant exposures.
Question 5: Which of the following actions by a CAE would BEST demonstrate compliance with Standard 1111 (Direct Interaction with the Board)?
- Sending the board a copy of all audit reports prepared for management
- Meeting privately with the audit committee at least quarterly without management present (Correct answer)
- Inviting board members to observe fieldwork on high-risk engagements
- Providing the board with the external auditor's management letter
Correct answer: Meeting privately with the audit committee at least quarterly without management present
Standard 1111 requires the CAE to communicate and interact directly with the board; regular private sessions (executive sessions) with the audit committee ensure unfiltered communication.
Question 6: The IIA's definition of internal auditing emphasizes that the function is designed to:
- Detect and report all instances of fraud to regulatory authorities
- Add value and improve an organization's operations through assurance and consulting (Correct answer)
- Ensure compliance with all applicable laws and regulations
- Provide independent verification of the external audit opinion
Correct answer: Add value and improve an organization's operations through assurance and consulting
The IIA defines internal auditing as an independent, objective assurance and consulting activity designed to add value and improve an organization's operations.
Question 7: An internal auditor who accepts a significant gift from a vendor whose contract the auditor is currently reviewing violates which Code of Ethics rule?
- Confidentiality β by sharing engagement information with the vendor
- Integrity β by performing acts that discredit the profession
- Competency β by failing to apply due professional care
- Both integrity and objectivity rules (Correct answer)
Correct answer: Both integrity and objectivity rules
Accepting a gift from an auditee violates both integrity (discrediting behavior) and objectivity (creating a personal interest that impairs impartial assessment).
The IIA Standards state that internal auditors must possess knowledge of 'key information technology risks and controls.' This requirement falls under which standard?