Free IIA IIA-CIA-Part2 Practice Questions 2026 - Page 3
Ready for IIA-CIA-Part2 Exam?
This practice test is your final exam before the REAL exam
Dare to Take It?
Practice Questions
Which of the following best describes the four components of a balanced scorecard?
A. Customers, innovation, growth, and internal processes.
B. Business objectives, critical success factors, innovation, and growth.
C. Customers, support, critical success factors, and learning.
D. Financial measures, learning and growth, customers, and internal processes.
Explanation:
This question tests the auditor's knowledge of the balanced scorecard framework, a strategic performance management tool. It requires identifying the four standard perspectives that organizations use to measure performance beyond traditional financial metrics alone.
β
Correct Option:
D. Financial measures, learning and growth, customers, and internal processes
The balanced scorecard framework, developed by Kaplan and Norton, organizes organizational performance into four perspectives: financial, customer, internal business processes, and learning and growth. This structure ensures organizations track both financial outcomes and the underlying drivers of long-term success, including innovation, employee development, and operational efficiency.
β Incorrect options:
A. Customers, innovation, growth, and internal processes
This option omits the financial perspective, which is a core component of the balanced scorecard framework. It also incorrectly separates innovation from growth rather than combining them as "learning and growth," misrepresenting the standard model structure.
B. Business objectives, critical success factors, innovation, and growth
These terms don't represent the four standard balanced scorecard perspectives. Business objectives and critical success factors are planning concepts used within scorecard development, not the framework's core measurement categories themselves.
C. Customers, support, critical success factors, and learning
This combination misrepresents the framework, as "support" and "critical success factors" aren't recognized balanced scorecard perspectives. It also omits the financial and internal process components essential to the standard model.
π§ Reference:
β IIA Internal Audit and Performance Management β confirms the balanced scorecard's four perspectives used to evaluate organizational performance comprehensively.
While planning for an accounts payable audit an internal auditor performs an entity level controls analysis. Which of the following statements is true regarding me approach used by the auditor?
A. It enables the auditor to identify the inherent risks to the effective operation of accounts payable process controls.
B. It enables the auditor to understand the framework of the activities and associated accounts payable subprocesses
C. it enables the auditor to understand the accounts payable process and its flow, including key steps and systems.
D. It enables the auditor to categorize the population of transactions within the accounts payable process
Explanation:
This question evaluates your understanding of the difference between entity-level and process-level controls in an audit context. Entity-level controls are broad, top-down controls that apply to the entire organization, such as governance, ethical culture, and oversight structures. Analyzing them helps the auditor understand the overall framework within which specific activities like accounts payable operate.
βοΈ Correct Option: B. It enables the auditor to understand the framework of the activities and associated accounts payable subprocesses.
Entity-level controls provide the foundational governance and control environment that influences all other controls. Understanding this broad framework allows the auditor to see how these high-level controls impact and shape the design and effectiveness of the subprocesses within the accounts payable process.
β Incorrect Option: A. It enables the auditor to identify the inherent risks to the effective operation of accounts payable process controls.
Identifying inherent risks for a specific process, like accounts payable, is a function of a process-level risk assessment, not an entity-level controls analysis. Entity-level analysis does not directly identify these specific transaction-level risks.
β Incorrect Option: C. It enables the auditor to understand the accounts payable process and its flow, including key steps and systems.
Understanding the specific flow, key steps, and systems of the accounts payable process is the objective of documenting the process-level controls, not analyzing entity-level controls. This option describes mapping the workflow of the activity itself.
β Incorrect Option: D. It enables the auditor to categorize the population of transactions within the accounts payable process.
Categorizing transaction populations is part of sampling or data analytics at the activity level. This is not a purpose or function of performing an analysis of high-level, enterprise-wide controls.
π§ Reference:
β IIA Standard 2100 β Nature of Work
This standard emphasizes that the internal audit activity must evaluate and contribute to the improvement of governance, risk management, and control processes using a systematic and disciplined approach. Understanding entity-level controls is the first step in this evaluation.
Which of the following attribute sampling methods would be most appropriate to use to measure the total misstatement posted to an accounts payable ledger?
A. Stop-or-go sampling
B. Probability to proportional size sampling
C. Classical variable sampling
D. Discovery sampling
Explanation:
The question tests knowledge of sampling methods for estimating the total (projected) monetary misstatement in an account balance, such as accounts payable.
β
Correct Option: C. Classical variable sampling
Classical variable sampling (e.g., mean-per-unit or difference estimation) is designed to estimate the total dollar amount of misstatement in a population. It is the most appropriate method when the objective is to measure the overall monetary impact posted to the ledger.
β Incorrect options:
A. Stop-or-go sampling
Stop-or-go (sequential) sampling is an attribute sampling technique used to determine if the error rate is below a tolerable level. It is not suitable for estimating total monetary misstatement.
B. Probability proportional to size sampling
PPS (monetary unit sampling) is effective for detecting overstatements and projecting misstatements but is a variables sampling method focused on dollar amounts rather than pure attribute sampling.
D. Discovery sampling
Discovery sampling is used to find at least one instance of a rare event (e.g., fraud). It does not measure or project the total misstatement amount.
π§ Reference:
β IIA Global Internal Audit Standards & Sampling Guidance
Classical variable sampling is recommended for estimating total monetary misstatements in account balances.
An internal auditor has been assigned to facilitate a risk and control self-assessment for the finance group. Which of the following is the most appropriate role that she should assume when facilitating the workshop?
A. Express an opinion on the participants' inputs and conclusions as the assessment progresses.
B. Provide appropriate techniques and guidelines on how the exercise should be undertaken.
C. Evaluate and report on all issues that may be uncovered during the exercise.
D. Screen and vet participants so that the most appropriate candidates are selected to participate in the exercise.
Explanation:
This question tests understanding of the internal auditorβs role in a Risk and Control Self-Assessment (RCSA). When facilitating an RCSA workshop, the auditor acts as a neutral facilitator who supports the process without influencing outcomes. The objective is to help participants identify and assess risks and controls independently.
π’ Correct Option: B. Provide appropriate techniques and guidelines on how the exercise should be undertaken
During a risk and control self-assessment workshop, the auditor's role is to guide the process by providing structure, techniques, and facilitation support. The auditor helps participants understand methods for identifying risks, evaluating controls, and documenting outcomes. Maintaining neutrality is essential because participants should develop their own conclusions without influence from the auditor.
π΄ Incorrect options:
A. Express an opinion on the participants' inputs and conclusions as the assessment progresses
Providing opinions during the exercise can influence participants and compromise the auditor's objectivity. The facilitator should avoid directing conclusions and instead support independent discussion and assessment.
C. Evaluate and report on all issues that may be uncovered during the exercise
The purpose of facilitation is to guide the self-assessment process, not perform an independent audit evaluation. Issues identified may later become subjects for audit consideration, but evaluating all findings is not the facilitator's primary role.
D. Screen and vet participants so that the most appropriate candidates are selected to participate in the exercise
Participant selection is generally a management responsibility. The auditor may provide suggestions if needed, but selecting or screening participants is not the main role of a workshop facilitator.
π§ Reference:
β IIA β Control Self-Assessment (CSA) Guidance
Confirms that internal auditors facilitating CSA activities should maintain neutrality and guide the process.
β IIA β International Professional Practices Framework (IPPF)
Confirms objectivity and advisory responsibilities of internal auditors.
Which of the following statements is true regarding risk assessments, including the evaluation and prioritization of risk and control factors?
A. A risk-by-process matrix enables the user to determine associations between any of the processes and the risks.
B. The risk-factor approach for linking business processes and risks is more direct than the use of a risk-by-process matrix.
C. Internal risk factors are built into the environment and the nature of the process itself.
D. A risk map is used primarily to depict which risks will be reduced and which will be shared.
Explanation:
The question focuses on risk assessment methodologies and tools used to link, evaluate, and prioritize organizational risk factors. It tests the internal auditor's knowledge of structured frameworksβlike matrices and heat mapsβused to visualize relationships between business operations and vulnerabilities.
β
A. A risk-by-process matrix enables the user to determine associations between any of the processes and the risks:
A risk-by-process matrix is a highly effective tool that cross-references an organization's business processes against identified risk categories. This structured approach provides audit management with a clear, visual overview of where specific threats intersect with operational workflows, enabling precise scoping and allocation of audit resources to high-risk intersections.
β B. The risk-factor approach for linking business processes and risks is more direct than the use of a risk-by-process matrix:
The risk-by-process matrix is inherently more direct because it maps specific risks directly to defined operational units or sub-processes. In contrast, a general risk-factor approach evaluates broader criteria or weighted metrics across the organization, which must then be indirectly translated down into specific process-level frameworks.
β C. Internal risk factors are built into the environment and the nature of the process itself:
Risk factors built inherently into the environment or nature of a process describe inherent risk, which exists independent of controls. Internal risk factors specifically relate to variables under managementβs direct control, such as personnel competency or operational system configurations, rather than being unalterably fixed within the environment's baseline nature.
β D. A risk map is used primarily to depict which risks will be reduced and which will be shared:
A risk map, or risk heat map, is primarily used to visually plot risks based on their estimated likelihood and potential impact. While it aids management in determining risk responses, its core function is to categorize and prioritize the severity of exposures, not to outline specific mitigation strategies like risk reduction or risk sharing.
π§ Reference:
β IIA Performance Standard 2010 on Planning confirms that the chief audit executive must establish a risk-based plan that aligns internal audit priorities with organizational goals, utilizing risk-by-process frameworks to systematically map exposures.
According to IIA guidance, which of the following provides additional insight into errors, problems, missed opportunities, or noncompliance to improve the effectiveness and efficiency of an organization's control process?
A. Reperformance.
B. Vouching.
C. Independent confirmation.
D. Root cause analysis.
Explanation:
This question tests the auditor's understanding of IIA guidance on identifying underlying causes of control deficiencies. It distinguishes root cause analysis, which drives meaningful process improvement, from standard audit testing techniques used to gather evidence on specific transactions or balances.
β
Correct Option:
D. Root cause analysis
Root cause analysis goes beyond identifying symptoms to uncover the underlying reasons behind errors, problems, missed opportunities, or noncompliance. By addressing these fundamental causes rather than surface-level issues, internal audit provides actionable insight that helps organizations strengthen control processes and prevent recurring deficiencies, improving overall effectiveness and efficiency.
β Incorrect options:
A. Reperformance
Reperformance involves independently executing a control or procedure to verify it operates as intended. While useful for testing control effectiveness, it doesn't analyze underlying causes of deficiencies or provide insight into systemic improvement opportunities.
B. Vouching
Vouching is a substantive testing technique that traces recorded transactions back to supporting documentation. It confirms transaction validity but doesn't investigate why errors or noncompliance occurred, offering no insight into root causes.
C. Independent confirmation
Independent confirmation involves obtaining direct verification from third parties to validate account balances or transactions. This technique provides evidence of accuracy but doesn't explore underlying reasons for control weaknesses or process inefficiencies.
π§ Reference:
β IIA Practice Guide - Root Cause Analysis β confirms root cause analysis helps internal audit provide deeper insight into control deficiencies for process improvement.
The audit committee has asked the chief audit executive (CAE) to conduct an ad hoc forensic investigation of the purchasing department within a month due to the significance and urgency of a recently discovered risk The internal audit activity currently has no available staff with relevant experience or qualifications Which of the following is the CAE's best option for fulfilling the internal audit activity's responsibilities in this case?
A. Outsource the investigation to independent professional consultants
B. Select certain internal auditors and remove them from their current assignments so that they can begin a forensic investigation course
C. Recruit additional internal auditors possessing relevant qualification and experience
D. Decline the engagement at this time
Explanation:
The question tests the chief audit executiveβs options when the internal audit activity lacks the required competence for a specialized, time-sensitive engagement.
β
Correct Option: A. Outsource the investigation to independent professional consultants
Outsourcing to qualified external experts allows the CAE to fulfill the audit committeeβs request promptly while maintaining quality and objectivity. IIA standards permit and encourage using external service providers when internal resources are insufficient.
β Incorrect options:
B. Select certain internal auditors and remove them from their current assignments so that they can begin a forensic investigation course
Training staff on the job for a complex forensic investigation within one month is unrealistic and risks compromising quality and timelines.
C. Recruit additional internal auditors possessing relevant qualification and experience
Recruitment takes significant time and cannot realistically meet the one-month deadline for an urgent engagement.
D. Decline the engagement at this time
Declining is not the best option when the audit committee has specifically requested the work. The CAE should seek ways to address the competence gap rather than refuse.
π§ Reference:
β IIA Global Internal Audit Standards β Resource Management & External Service Providers
Supports using external service providers when internal resources lack the necessary knowledge, skills, or competencies.
An internal auditor is asked to determine why the production line for a large manufacturing organization has been experiencing shutdowns due to unavailable pacts The auditor learns that production data used for generating automatic purchases via electronic interchange is collected on personal computers connected by a local area network (LAN) Purchases are made from authorized vendors based on both the production plans for the next month and an authorized materials requirements plan (MRP) that identifies the parts needed per unit of production The auditor suspects the shutdowns are occurring because purchasing requirements have not been updated for changes in production techniques. Which of the following audit procedures should be used to test the auditor's theory?
A. Compare purchase orders generated from test data input into the LAN with purchase orders generated from production data for the most recent period
B. Develop a report of excess inventory and compare the inventory with current production volume
C. Compare the pans needed based on current production estimates and the MRP for the revised production techniques with the purchase orders generated from the system for the same period
D. Select a sample of production estimates and MRPs for several periods and trace them into the system to determine that input is accurate
Explanation:
This question tests your ability to select appropriate audit procedures to validate a specific hypothesis. The auditor suspects that shutdowns are occurring because purchasing requirements have not been updated for changes in production techniques. The most direct way to test this theory is to compare what should have been ordered (based on updated production estimates and the revised MRP) against what the system actually ordered (the purchase orders).
βοΈ Correct Option: C. Compare the parts needed based on current production estimates and the MRP for the revised production techniques with the purchase orders generated from the system for the same period
This procedure directly tests the auditor's theory. By independently calculating the parts required using current production estimates and the updated MRP, and then comparing that calculation to the actual purchase orders generated, the auditor can determine if the system is failing to reflect revised production techniques, causing parts to be unavailable and leading to shutdowns.
β Incorrect Option: A. Compare purchase orders generated from test data input into the LAN with purchase orders generated from production data for the most recent period
Test data verifies system processing logic, not the accuracy of the underlying MRP or production estimates. This procedure would confirm that the system processes orders correctly but would not reveal whether the purchasing requirements themselves are outdated for current production techniques.
β Incorrect Option: B. Develop a report of excess inventory and compare the inventory with current production volume
While excess inventory might indicate over-ordering, it does not directly test whether purchasing requirements have been updated for production technique changes. A lack of parts (shutdowns) suggests under-ordering or incorrect ordering, making this procedure irrelevant to the auditor's specific theory.
β Incorrect Option: D. Select a sample of production estimates and MRPs for several periods and trace them into the system to determine that input is accurate
This procedure tests input accuracy (whether data was correctly entered), but it does not verify that the MRP itself was updated to reflect revised production techniques. The issue is likely with the content of the MRP, not with the data entry process.
π§ Reference:
β IIA Global β Practice Guide: Audit Evidence and Documentation
This guidance emphasizes the need to select audit procedures that directly test the auditor's hypothesis by comparing independent calculations to system outputs.
β IIA Standard 2310 β Identifying Information
This standard requires that internal auditors gather sufficient, reliable, relevant, and useful information to achieve engagement objectives, which includes directly comparing expected and actual data.
An internal auditor receives a document displaying all the steps of a process and the path taken as transactions flow between each step of the process How is the internal auditor most likely to use This document during the engagement?
A. To perform an assessment of the adequacy of process controls.
B. To perform an assessment of the effectiveness of process controls
C. To perform a detailed assessment of process risks
D. To perform an assessment of the sufficiency of residual process risks.
Explanation:
This question tests understanding of process documentation and how auditors use process flow information during an engagement. A document showing process steps and transaction flow is essentially a flowchart or process map. Auditors commonly use it to understand how activities operate and determine whether appropriate controls exist within the process.
π’ Correct Option: A. To perform an assessment of the adequacy of process controls
A process flow document helps auditors understand the sequence of activities, decision points, and movement of transactions through the process. This understanding allows the auditor to identify where controls exist and determine whether the design of those controls appears adequate to address risks. The document mainly supports evaluating whether appropriate controls are built into the process structure.
π΄ Incorrect options:
B. To perform an assessment of the effectiveness of process controls
Control effectiveness requires evidence that controls operate as intended through testing and observation. A process flow document only describes how the process is designed and does not demonstrate whether controls are functioning properly.
C. To perform a detailed assessment of process risks
Although process documentation may help identify risks, it does not by itself provide a detailed risk assessment. Additional analysis and evaluation are necessary to identify and measure specific process risks.
D. To perform an assessment of the sufficiency of residual process risks
Residual risk assessment requires understanding the impact of existing controls and remaining risk exposure after control implementation. A process flow document alone does not provide sufficient information for this determination.
π§ Reference:
β IIA β International Professional Practices Framework (IPPF) Engagement Planning Guidance
Confirms that auditors obtain an understanding of processes and controls during engagement planning.
Which of the following is the best audit procedure to obtain evidence of an organization's legal ownership of a new property?
A. Review documents registered with the appropriate governmental authority.
B. Examine the board of directors' minutes and look for approvals to acquire property.
C. Confirm with senior management and legal counsel concerning property acquisition.
D. Confirm ownership with the title company that handles the escrow account.
Explanation:
This question tests the auditor's understanding of obtaining the most reliable evidence for verifying legal ownership of property. It emphasizes the hierarchy of audit evidence, where independent, externally verifiable documentation carries more weight than internal approvals or inquiries.
β
Correct Option:
A. Review documents registered with the appropriate governmental authority
Government-registered property records, such as deeds or title registrations, provide the most reliable and authoritative evidence of legal ownership. Since these documents are filed with an independent external authority, they offer objective verification that's difficult to manipulate, making this the strongest source of evidence for confirming property ownership.
β Incorrect options:
B. Examine the board of directors' minutes and look for approvals to acquire property
Board minutes confirm that acquisition was approved internally but don't verify that the legal transfer of ownership was actually completed. This evidence shows intent and authorization, not the final legal status of ownership.
C. Confirm with senior management and legal counsel concerning property acquisition
Inquiries with internal management and counsel provide representations rather than independent documentary evidence. While useful for context, this approach relies on internal parties who may lack objectivity compared to external government records.
D. Confirm ownership with the title company that handles the escrow account
While title companies are involved in transactions, confirming with them is less authoritative than reviewing actual government-registered ownership documents, which serve as the definitive legal record establishing ownership status.
π§ Reference:
β IIA Standards - Evidence Gathering β confirms that audit evidence obtained from independent external sources is generally more reliable than internally generated evidence.
| Page 3 out of 72 Pages |