Free IIA IIA-CIA-Part2 Practice Questions 2026 - Page 2

Timed Practice Test

Ready for IIA-CIA-Part2 Exam?

This practice test is your final exam before the REAL exam
Dare to Take It?




Practice Questions

Which of the following is one of the five basic tnanoal statement assertions when an internal auditor evaluates controls over financial reporting?

A. Reliability or appropriateness

B. Reasonableness

C. Existence or occurrence

D. Relevance

C.   Existence or occurrence

Explanation:

This question tests the auditor's knowledge of the five basic financial statement assertions management makes when preparing financial statements. These assertions guide the auditor in evaluating whether controls over financial reporting adequately support the accuracy and validity of reported information.

βœ… Correct Option:

C. Existence or occurrence
Existence or occurrence is one of the five recognized financial statement assertions, confirming that assets, liabilities, and recorded transactions actually existed or occurred during the reporting period. Auditors evaluate controls designed to support this assertion to ensure that reported figures aren't fictitious or overstated, providing assurance over financial statement validity.

❌ Incorrect options:

A. Reliability or appropriateness
Reliability and appropriateness aren't recognized as one of the five standard financial statement assertions. These terms relate more broadly to information quality characteristics rather than the specific assertions auditors test in financial reporting evaluations.

B. Reasonableness
Reasonableness isn't a formal financial statement assertion. It's a general analytical concept used during reviews but doesn't represent one of the specific assertions management makes regarding financial statement accuracy or completeness.

D. Relevance
Relevance is a qualitative characteristic of useful financial information under accounting frameworks, not one of the five financial statement assertions. It concerns information usefulness rather than the specific claims auditors verify during testing.

πŸ”§ Reference:
β†’ IIA Standards - Internal Audit and Financial Reporting β€” confirms the five financial statement assertions including existence/occurrence, completeness, rights and obligations, valuation, and presentation/disclosure.

During a consulting engagement an internal auditor wants to determine whether all principal stakeholders are involved in a project. Which tool should the auditor use?

A. RACI (responsible, accountable, consult and inform) chart

B. Flowchart

C. SWOT{strengths. weaknesses opportunities, and threats) analysis

D. Workflow analysis

A.   RACI (responsible, accountable, consult and inform) chart

Explanation:

The question focuses on selecting the appropriate tool during a consulting engagement to assess stakeholder involvement in a project. It tests knowledge of common governance and project management tools used by internal auditors.

βœ… Correct Option: A. RACI (responsible, accountable, consult and inform) chart
A RACI chart clearly maps project activities against stakeholders, specifying who is Responsible, Accountable, Consulted, or Informed. This tool directly helps the auditor verify whether all principal stakeholders are appropriately involved.

❌ Incorrect options:

B. Flowchart
A flowchart visually represents process steps and decision points. It is useful for understanding workflows but does not specifically identify stakeholder roles or involvement.

C. SWOT (strengths, weaknesses, opportunities, and threats) analysis
SWOT analysis evaluates strategic factors affecting a project or organization. It does not focus on mapping individual stakeholder responsibilities.

D. Workflow analysis
Workflow analysis examines the sequence and efficiency of tasks. It addresses process flow rather than confirming stakeholder participation.

πŸ”§ Reference:
β†’ IIA Global Internal Audit Standards – Consulting Engagements
Recommends tools like RACI charts for assessing roles, responsibilities, and stakeholder involvement in advisory projects.

An internal auditor is testing the success of the IT support department in meeting the service levels guaranteed to small, medium and large customers. The customer's size classification is based on its annual expenditures with the organization and the nature and extent of services it receives. Which of the following sampling techniques would be the most suitable to select customers for this test?

A. Interval sampling

B. Cluster sampling

C. Stop-and-go sampling

D. Stratified sampling

D.   Stratified sampling

Explanation:

This question tests your understanding of sampling techniques used in internal audit engagements, specifically when the population has distinct subgroups. The customer base is already divided into three size categories (small, medium, and large) based on expenditures and services, making stratified sampling the most appropriate method to ensure each category is adequately represented in the test.

βœ”οΈ Correct Option: D. Stratified sampling
Stratified sampling divides the population into distinct, non-overlapping subgroups (strata) based on a key characteristicβ€”here, customer size. This ensures that each customer category is proportionally or equally represented, allowing the auditor to draw valid conclusions about service level performance across all groups.

❌ Incorrect Option: A. Interval sampling
Interval sampling selects items at fixed intervals from a population. This method does not account for the natural grouping of customers by size. It could overrepresent or underrepresent certain categories, leading to biased conclusions about service level compliance for specific customer segments.

❌ Incorrect Option: B. Cluster sampling
Cluster sampling divides the population into groups and randomly selects entire clusters for testing. This method is inefficient here because customers are already classified by size, and testing whole clusters would not guarantee balanced representation across all three categories.

❌ Incorrect Option: C. Stop-and-go sampling
Stop-and-go sampling is used for compliance testing when the auditor expects a very low error rate. It allows early termination of testing if no errors are found. This technique is not designed to ensure proportional representation of subgroups and is unsuitable for measuring service levels across distinct customer classifications.

πŸ”§ Reference:
β†’ IIA Global – Practice Guide: Audit Sampling
This guide explains that stratified sampling is appropriate when the population is divided into subpopulations with different characteristics, ensuring that each stratum is adequately represented.

β†’ IIA Global – CIA Part 2 Exam Syllabus (Topic on Sampling Methods)
The syllabus includes "sampling methodologies" under engagement procedures, confirming that auditors must know when to apply different sampling approaches based on population characteristics.

The audit plan requires a review of the testing procedures used in pre-production of a large information system prior to its live launch. If the chief audit executive (CAE) is uncertain that the current audit team has all the required knowledge to conduct the engagement, which of the following would be the most appropriate course of action for the CAE to take to preserve independence?

A. Contract with the software vendor to provide an appropriate resource.

B. Ask for a knowledgeable resource from the IT department.

C. Make use of an external service provider.

D. Request audit resources through the external auditor.

C.   Make use of an external service provider.

Explanation:

This question addresses the chief audit executive's (CAE) responsibility to ensure the internal audit activity has the necessary competence while preserving independence. When the in-house team lacks specific expertise required for an engagement, engaging an external service provider is a standard and appropriate solution that does not compromise the audit function's objectivity, provided proper oversight is maintained .

βœ”οΈ Correct Option: C. Make use of an external service provider.
Engaging an independent external service provider to supply the missing technical expertise is a common and effective approach . This option preserves the CAE's independence and objectivity because the external provider reports to the CAE and does not take on a management role, allowing the CAE to maintain strategic oversight and responsibility for the engagement's results .

❌ Incorrect Option: A. Contract with the software vendor to provide an appropriate resource.
Engaging the software vendor itself creates a significant conflict of interest and impairs objectivity. The vendor designed and implemented the system under review, so they cannot provide an independent, unbiased assessment of its own controls. This arrangement would violate fundamental principles of audit independence.

❌ Incorrect Option: B. Ask for a knowledgeable resource from the IT department.
Borrowing a staff member from the IT department directly violates the IIA's Standard 1130, which prohibits internal auditors from assessing operations for which they were previously responsible . This resource would be auditing their own area, creating an unacceptable impairment to objectivity and independence.

❌ Incorrect Option: D. Request audit resources through the external auditor.
While coordination with external auditors is encouraged, relying on them for resources to staff an engagement can create a "managed audit" arrangement. According to the IIA's Standard 2050, the CAE retains full responsibility for internal audit conclusions and opinions, and while the external auditor's work might be considered, using them as direct resources requires careful oversight to ensure the CAE's independence and the engagement's purpose are not compromised .

πŸ”§ Reference:
β†’ IIA Global – Standard 2070: External Service Provider and Organizational Responsibility for Internal Auditing
This standard clarifies that when an external service provider is used, the organization retains full responsibility for directing, managing, and overseeing the internal audit activity, and the CAE remains accountable for the conclusions and opinions reached.

An engagement work program o of greatest value to audit management when which of the following is true?

A. The work program provides more detailed support for the audit report

B. The work program helps determined the required amount of audit resources

C. The work program helps ensure tie achievement of the engagement objectives

D. The work program assists the auditor n developing and managing audit tests

C.   The work program helps ensure tie achievement of the engagement objectives

Explanation:

This question tests understanding of the purpose and value of an engagement work program in internal auditing. A work program acts as a structured plan that guides audit activities, procedures, and testing. Its primary purpose is to ensure audit work remains aligned with objectives and that the engagement effectively addresses identified risks.

🟒 Correct Option: C. The work program helps ensure the achievement of the engagement objectives
An engagement work program provides a systematic framework for conducting audit procedures that directly support the objectives of the engagement. It identifies required tasks, testing procedures, and areas of focus so that auditors perform sufficient work to address risks and reach valid conclusions. This alignment makes the work program most valuable to audit management because it supports successful completion of the engagement purpose.

πŸ”΄ Incorrect options:

A. The work program provides more detailed support for the audit report
Although work programs contribute supporting documentation for audit conclusions, their primary purpose is not to provide detailed support for the report. Supporting evidence mainly comes from workpapers and audit findings developed during fieldwork.

B. The work program helps determine the required amount of audit resources
Resource requirements can be estimated during planning activities, but determining staffing needs is not the main value of the work program. Its focus is directing engagement activities rather than primarily allocating resources.

D. The work program assists the auditor in developing and managing audit tests
A work program does help organize audit procedures and testing activities, but this is a supporting function. Its broader and more important purpose is ensuring that engagement objectives are achieved.

πŸ”§ Reference:
β‡’ IIA – Standard 2240 Engagement Work Program
Confirms that work programs must achieve engagement objectives.

β‡’ IIA – International Professional Practices Framework (IPPF)
Confirms requirements for planning and executing audit engagements.

Which of the following situations would justify the removal of a finding from the final audit report?

A. Management disagrees with the report findings and conclusions in their responses.

B. Management has already satisfactorily completed the recommended corrective action.

C. Management has provided additional information that contradicts the findings.

D. Management believes that the finding is insignificant and unfairly included in the report.

C.   Management has provided additional information that contradicts the findings.

Explanation:

The question assesses the conditions under which an internal audit finding can be validly removed from a final report. It tests the auditor's commitment to objective truth, accuracy, and evidence over administrative disagreements or post-audit remediation.

βœ… C. Management has provided additional information that contradicts the findings:
If management provides new, reliable information or documentation that directly refutes the auditor's initial observations, the finding loses its evidentiary support and is no longer valid. Internal audit communications must always be accurate and objective, justifying the immediate removal of any finding proven incorrect by subsequent evidence.

❌ A. Management disagrees with the report findings and conclusions in their responses:
Management's disagreement alone does not invalidate a factually correct and well-supported audit finding. When a difference of opinion exists regarding risk severity or conclusions, the standard professional practice is to include management's formal dissenting response in the final report alongside internal audit’s verified position.

❌ B. Management has already satisfactorily completed the recommended corrective action:
Completing corrective action before the final report is published does not erase the historical fact that the deficiency existed during the review period. The appropriate approach is to keep the finding in the report to document the control environment accurately, while noting that management has already resolved it.

❌ D. Management believes that the finding is insignificant and unfairly included in the report:
Management's subjective belief regarding the fairness or insignificance of a finding is not a valid reason for removal. The chief audit executive and the audit team retain independent professional judgment to determine which control vulnerabilities pose a material risk and warrant inclusion in final communications.

πŸ”§ Reference:
β†’ IIA Performance Standard 2410 on Criteria for Communicating confirms that final engagement communications must be accurate, objective, and clear, meaning they must be revised or retracted if the underlying evidence supporting a finding is discredited.

An internal auditor e assessing the design of a control and has identified a potential significant weakness. The auditor shared his concern with management however management does not agree that the weakness is significant. What should the internet auditor do next?

A. Perform additional audit work to better articulate the risk

B. Report the finding that management has accepted a level of risk that is unacceptable.

C. Proceed to testing how effectively the control is opening

D. Because the design weakness has been identified no additional audit work is needed

A.   Perform additional audit work to better articulate the risk

Explanation:

This question tests the auditor's understanding of proper escalation procedures when there's disagreement with management over a control weakness. It focuses on the principle that auditors must build a well-supported case before reporting significant risk disagreements, rather than jumping to conclusions or halting work prematurely.

βœ… Correct Option:

A. Perform additional audit work to better articulate the risk
When management disagrees on the significance of a weakness, the auditor should gather further evidence to strengthen and clarify the risk assessment. This additional work helps build a more defensible, well-supported position, ensuring conclusions are based on sufficient evidence before escalating disagreements or finalizing the audit finding.

❌ Incorrect options:

B. Report the finding that management has accepted a level of risk that is unacceptable
Reporting this conclusion is premature without first strengthening the risk articulation through additional work. Jumping straight to this judgment risks an unsupported or weak finding, undermining the credibility of the audit conclusion and the escalation process.

C. Proceed to testing how effectively the control is operating
Moving to operating effectiveness testing skips resolving the disagreement over design adequacy. Testing an inadequately designed control's operation provides limited value if the design itself remains contested and unresolved between the auditor and management.

D. Because the design weakness has been identified no additional audit work is needed
This assumes the initial assessment is conclusive despite management's disagreement. Stopping audit work here ignores the need to substantiate findings adequately, especially when the significance of the weakness is being challenged by management.

πŸ”§ Reference:
β†’ IIA Standards - Communicating Results β€” confirms auditors must gather sufficient, reliable evidence to support conclusions before communicating significant findings, especially when disputed by management.

An internal auditor plans to conduct a walk-through to evaluate the control design of a process. Which of the following techniques is the auditor most likely to use?

A. Observation and inspection.

B. Inquiry and observation.

C. Inspection and reperformance.

D. Inquiry and reperformance.

B.   Inquiry and observation.

Explanation:

The question tests the primary techniques used in a walkthrough to evaluate control design. A walkthrough traces a transaction or process from initiation to completion to confirm the auditor’s understanding of how controls are intended to operate.

βœ… Correct Option: B. Inquiry and observation.
During a walkthrough, the auditor primarily uses inquiry (asking process owners about steps and controls) and observation (watching the process in action). This combination effectively reveals whether the design includes necessary controls and how they function in practice.

❌ Incorrect options:

A. Observation and inspection.
Observation and inspection are useful but insufficient alone for a full walkthrough, as they do not capture the reasoning or explanations behind process steps.

C. Inspection and reperformance.
Inspection and reperformance are more relevant for testing the operating effectiveness of controls rather than initially evaluating design through a walkthrough.

D. Inquiry and reperformance.
Reperformance (independently executing control procedures) goes beyond design evaluation and is typically used later for substantive testing of operating effectiveness.

πŸ”§ Reference:
β†’ IIA Global Internal Audit Standards – Performing the Engagement
Walkthroughs rely heavily on inquiry and observation to understand and evaluate control design.

Which of the following internal audit procedures commonly involves sampling?

A. Confirmation and financial statement analysis

B. Reperformance and inspection

C. Vouching and tracing

D. Trend analysis and benchmarking

C.   Vouching and tracing

Explanation:

This question tests your understanding of audit procedures and when sampling is typically applied. Vouching and tracing are both substantive procedures that involve selecting a subset of transactions or documents to verify their accuracy, validity, or completeness, making sampling an inherent and necessary part of these techniques.

βœ”οΈ Correct Option: C. Vouching and tracing
Vouching involves taking a sample of recorded transactions and obtaining source documents to verify they actually occurred (existence assertion). Tracing involves taking a sample of source documents and ensuring transactions have been properly recorded in journals and ledgers (completeness assertion). Both require sampling when populations are large.

❌ Incorrect Option: A. Confirmation and financial statement analysis
Confirmation involves sending requests to third parties to verify account balancesβ€”this may or may not involve sampling depending on population size. Financial statement analysis is an analytical procedure that does not typically use sampling; it reviews entire financial data sets for trends and relationships.

❌ Incorrect Option: B. Reperformance and inspection
Reperformance involves independently re-executing a control or calculation to verify accuracy, typically done on individual high-risk items. Inspection involves examining documents and recordsβ€”while it can involve sampling, neither procedure inherently requires it as a defining characteristic.

❌ Incorrect Option: D. Trend analysis and benchmarking
Both are analytical procedures that compare data across periods or against industry standards to identify unusual patterns. These procedures do not involve sampling because they typically analyze entire data sets rather than selecting a subset of transactions.

πŸ”§ Reference:
β†’ IIA Global – Standards and Guidance on Audit Evidence
The IIA framework confirms that sampling is used when testing entire populations is impractical, particularly for procedures like vouching and tracing that examine individual transactions.

Which of the following reasonably represents best practices regarding what should be the level of internal audit resource investment in monitoring and following up on engagement outcomes?

A. Limited resources should be employed since the actual engagement is already completed and the onus of corrective actions rests with management

B. No resources should be exclusively deployed for that at all rather it should be planned as part of future engagements in the same area

C. Resources should only be provided towards this if doing so does not result in depletion of resources for new engagements planned in the current period

D. Resources should be allocated to this without conditions as long as doing so meets the expectations of management and the judgment of the chief audit executive.

D.   Resources should be allocated to this without conditions as long as doing so meets the expectations of management and the judgment of the chief audit executive.

Explanation:

This question tests understanding of internal audit follow-up responsibilities after engagement completion. Monitoring and follow-up are important parts of the audit process because they help determine whether management has effectively implemented corrective actions and whether identified risks have been properly addressed.

🟒 Correct Option: D. Resources should be allocated to this without conditions as long as doing so meets the expectations of management and the judgment of the chief audit executive
The chief audit executive is responsible for establishing an effective follow-up process and determining the level of resources required. Appropriate resources should be assigned based on management expectations, risk significance, and professional judgment. Follow-up activities help ensure agreed corrective actions are implemented and that unresolved risks receive appropriate attention rather than being overlooked after the engagement concludes.

πŸ”΄ Incorrect options:

A. Limited resources should be employed since the actual engagement is already completed and the onus of corrective actions rests with management
Although management is responsible for implementing corrective actions, internal audit maintains responsibility for monitoring outcomes. Restricting resources simply because fieldwork ended may reduce the effectiveness of the audit process and leave significant issues unresolved.

B. No resources should be exclusively deployed for that at all rather it should be planned as part of future engagements in the same area
Waiting for future engagements may delay verification of corrective actions and leave important risks unaddressed. Follow-up activities should occur according to organizational needs rather than only during future audit work.

C. Resources should only be provided towards this if doing so does not result in depletion of resources for new engagements planned in the current period
This approach improperly places new engagements above follow-up responsibilities. Resource allocation should depend on risk and audit priorities, not solely on preserving capacity for planned future engagements.

πŸ”§ Reference:
β‡’ IIA – Standard 2500 Monitoring Progress
Confirms that the chief audit executive must establish a process to monitor engagement outcomes and corrective actions.

β‡’ IIA – International Professional Practices Framework (IPPF)
Confirms responsibilities related to monitoring and follow-up activities.

Page 2 out of 72 Pages