Free IIA IIA-CIA-Part2 Practice Questions 2026 - Page 4
Ready for IIA-CIA-Part2 Exam?
This practice test is your final exam before the REAL exam
Dare to Take It?
Practice Questions
Which of the following risk assessment approaches involves gathering data from work team representing different levels of an organisation?
A. Surveys
B. Management produced analysis 0
C. Facilitated team workshops
D. Weighted risk factors
Explanation:
The question tests different risk assessment approaches used during engagement planning or enterprise risk assessment.
✅ Correct Option: C. Facilitated team workshops
Facilitated team workshops bring together representatives from various organizational levels and functions. The auditor guides discussions to identify, assess, and prioritize risks collaboratively, leveraging diverse perspectives.
❌ Incorrect options:
A. Surveys
Surveys collect input from many individuals but do not involve interactive group discussion or real-time collaboration across levels.
B. Management produced analysis
This relies on management’s own assessment and documentation, typically without broad cross-level team participation.
D. Weighted risk factors
This is a quantitative scoring method applied to identified risks. It does not involve gathering data through team interaction.
🔧 Reference:
→ IIA Global Internal Audit Standards – Risk Assessment
Recommends facilitated workshops as an effective method for collaborative risk identification involving multiple organizational levels.
Which of the following audit steps would an internal auditor perform when reviewing cash disbursements to satisfy IIA guidance on due professional care?
A. The calculated statistical sample size is 50 however the internal auditor believes errors exist so he decides to increase the sample size to 80
B. The internal auditor traces serial numbers of computer equipment listed on an invoice to the fixed asset inventory
C. The internal auditor reviews the accounts payable manager's petty cash fund and vouchers
D. The internal auditor reviews the related invoice purchase order and receiving report for each sample selection
Explanation:
This question evaluates your understanding of "due professional care" as defined in IIA Standard 1220. This standard requires an internal auditor to apply the care and skill of a reasonably prudent and competent professional, which includes considering the extent of work needed and the probability of significant errors or fraud . Option D directly describes a fundamental, prudent control test for cash disbursements—the "three-way match"—which provides reliable evidence that a payment is valid and authorized.
✔️ Correct Option: D. The internal auditor reviews the related invoice, purchase order, and receiving report for each sample selection.
This procedure directly satisfies the requirements of due professional care. By performing a "three-way match" on a sample of disbursements, the auditor is exercising reasonable care and skepticism to confirm that a legitimate obligation exists before payment . This step is a cornerstone of prudent auditing to detect errors or fraud.
❌ Incorrect Option: A. The calculated statistical sample size is 50; however, the internal auditor believes errors exist, so he decides to increase the sample size to 80.
While due professional care does require the auditor to consider the probability of errors, unilaterally increasing a sample size based on a vague "belief" rather than a clear, objective risk assessment is not a methodical approach to gathering evidence and does not, by itself, represent a specific, prudent audit step .
❌ Incorrect Option: B. The internal auditor traces serial numbers of computer equipment listed on an invoice to the fixed asset inventory.
This is a valid audit procedure, but it is specific to verifying the existence of fixed assets, not the review of cash disbursements. While it demonstrates care in that specific context, it does not address the fundamental controls for a cash payment transaction.
❌ Incorrect Option: C. The internal auditor reviews the accounts payable manager's petty cash fund and vouchers.
Reviewing the petty cash fund is a separate, specific audit step for a different process (petty cash). While it could be done with due professional care, it is not the procedure that most directly constitutes due care when reviewing the broader population of cash disbursements.
🔧 Reference:
→ IIA Standard 1220 – Due Professional Care
This standard defines due professional care and outlines the key considerations for internal auditors, such as the extent of work needed and the probability of significant errors or fraud, which are satisfied by a prudent review of supporting documentation.
Which of the following would most likely cause an internal auditor to consider adding fraud work steps to the audit program?
A. Improper segregation of duties.
B. Incentives and bonus programs.
C. An employee's reported concerns.
D. Lack of an ethics policy.
Explanation:
This question tests understanding of fraud indicators and when auditors should expand procedures to address potential fraud risks. Internal auditors normally consider fraud risk during planning, but additional fraud work steps are more likely when specific information or warning signs indicate a higher possibility of fraudulent activity.
🟢 Correct Option: C. An employee's reported concerns
Employee-reported concerns can provide direct indications of potential misconduct, suspicious behavior, or control weaknesses. Such reports may represent a specific fraud indicator rather than a general risk factor. Due professional care requires auditors to consider the reliability and significance of the information and determine whether additional fraud-related procedures should be incorporated into the audit program to investigate the concern further.
🔴 Incorrect options:
A. Improper segregation of duties
Weak segregation of duties creates an opportunity for fraud and represents a control deficiency. However, it is a general fraud risk factor and by itself may not automatically require additional fraud work steps unless supporting evidence suggests possible misconduct.
B. Incentives and bonus programs
Compensation incentives may create pressure that contributes to fraud risk. However, incentive structures alone are common business practices and do not necessarily indicate actual fraudulent activity requiring expanded fraud procedures.
D. Lack of an ethics policy
The absence of an ethics policy may weaken the control environment and increase overall fraud risk. However, it is an indirect indicator and does not provide specific evidence suggesting that fraudulent activity may be occurring.
🔧 Reference:
⇒ IIA – Standard 1220 Due Professional Care
Confirms that auditors should consider the probability of significant fraud risks during engagements.
⇒ IIA – Practice Guide: Internal Auditing and Fraud
Confirms that specific indicators and allegations may require additional fraud procedures.
According to IIA guidance, which of the following objectives was most likely formulated for a non-assurance engagement?
A. The internal audit activity will assess the effects of changes in maintenance strategy on the availability of production equipment.
B. The internal audit activity will inform management on the possible risks of moving the data warehouse to a cloud server maintained by a third party.
C. The internal audit activity will ascertain whether the data center security arrangements are compliant with agreed terms.
D. The internal audit activity will ensure equipment downtime risks have been managed in accordance with internal policy.
Explanation:
The question evaluates the understanding of the differences between assurance and non-assurance (consulting) engagement objectives as defined by the International Professional Practices Framework. It tests the auditor's ability to identify advisory-oriented phrasing versus objective verification phrasing.
✅ B. The internal audit activity will inform management on the possible risks of moving the data warehouse to a cloud server maintained by a third party:
An objective focused on informing, advising, or facilitating represents a classic non-assurance or consulting engagement. In this scenario, the internal audit activity is providing expert insight and risk analysis to assist management with future decision-making regarding cloud migration, without providing an official statement of compliance or independent verification.
❌ A. The internal audit activity will assess the effects of changes in maintenance strategy on the availability of production equipment:
An objective designed to assess, evaluate, or measure the actual impact of an operational change represents a formal assurance engagement. This objective requires the auditor to independently collect and evaluate operational data to provide an objective conclusion regarding how maintenance strategies altered equipment availability.
❌ C. The internal audit activity will ascertain whether the data center security arrangements are compliant with agreed terms:
Ascertaining compliance against established criteria, such as a contract or agreed-upon service terms, is a core objective of an assurance engagement. The auditor must systematically test the data center's current physical or logical controls and issue an independent opinion regarding whether those controls meet the legal baseline.
❌ D. The internal audit activity will ensure equipment downtime risks have been managed in accordance with internal policy:
Verifying whether risks are managed in accordance with corporate policies is a governance-focused assurance objective. This type of review requires independent testing of operational management's mitigation activities to provide the board and executive team with objective assurance that policy boundaries were strictly respected.
🔧 Reference:
→ IIA Glossary on Consulting Services confirms that consulting or non-assurance services are advisory in nature, are generally performed at the specific request of an engagement client, and focus on providing insights rather than providing independent assurance over a process.
During an entity-level controls assessment, internal auditors deploy an internal control questionnaire to test the controls. Which of the following is a major drawback of this testing method?
A. Information obtained by this method can be repudiated.
B. Information obtained by this method is difficult to quantify.
C. It is an inefficient method of gathering evidence.
D. Limited information can be gathered with this method.
Explanation:
This question tests the auditor's understanding of limitations associated with internal control questionnaires (ICQs) as a testing method. It focuses on the reliability concerns tied to self-reported responses, particularly the risk that respondents may later deny or distance themselves from their answers.
✅ Correct Option:
A. Information obtained by this method can be repudiated
Since ICQ responses rely on individuals' self-reported answers, respondents can later claim they misunderstood the question or deny providing that specific response. This repudiation risk undermines the reliability of the evidence, making it a significant drawback compared to more objective, independently verifiable testing methods.
❌ Incorrect options:
B. Information obtained by this method is difficult to quantify
ICQs typically use structured yes/no or rating-scale questions, making responses relatively easy to quantify and tabulate. This isn't considered a major drawback, as the format generally supports straightforward analysis and summarization of results.
C. It is an inefficient method of gathering evidence
Questionnaires are actually considered an efficient method for gathering information across many respondents quickly, especially for broad entity-level assessments. Efficiency isn't typically cited as a limitation of this testing approach.
D. Limited information can be gathered with this method
ICQs can be designed to cover extensive control areas and gather substantial information across many topics. The breadth of coverage isn't generally considered a limiting factor compared to other drawbacks like response reliability.
🔧 Reference:
→ IIA Practice Guide - Audit Evidence Gathering Techniques — confirms self-reported testing methods like questionnaires carry reliability risks, including respondent repudiation.
Which of the following would most Holy reflect the best possible engagement objectives?
A. Engagement objectives derived from risk assessment results from a company's risk function experts.
B. Engagement objectives derived from senior management's risk assessment results
C. Engagement objectives derived from the mental audit activity's own risk assessment results
D. Engagement objectives derived from risk assessment results from both senior management and the company's risk function experts
Explanation:
The question examines what constitutes strong engagement objectives in internal auditing. Objectives must be based on a proper risk-based approach.
✅ Correct Option: C. Engagement objectives derived from the internal audit activity's own risk assessment results
The internal audit activity must perform its own independent risk assessment to determine engagement objectives. This ensures objectivity, alignment with the audit charter, and focus on areas of highest risk to the organization.
❌ Incorrect options:
A. Engagement objectives derived from risk assessment results from a company's risk function experts.
Relying solely on the risk function’s assessment lacks the necessary independence required of internal audit.
B. Engagement objectives derived from senior management's risk assessment results
Dependence on senior management’s views may compromise independence and overlook risks management is unwilling to highlight.
D. Engagement objectives derived from risk assessment results from both senior management and the company's risk function experts
Combining management and risk function input is useful but insufficient. Internal audit must conduct and rely on its own assessment to set objectives.
🔧 Reference:
→ IIA Global Internal Audit Standards – Engagement Planning
Requires the chief audit executive and internal auditors to establish engagement objectives based on their own risk assessment.
Which of the following is most likely the subject of a periodic report from the chief audit executive to the board?
A. A complete, accurate, and comprehensive account of engagement observations and recommendations.
B. Oversight of the coordination between the internal audit activity and independent outside auditors
C. The internal audit activity's purpose, authority, responsibility, and performance relative to plan.
D. Management's assertions regarding the system of internal controls.
Explanation:
This question tests your knowledge of the CAE's reporting responsibilities to the board, which is governed by Standard 2060 of the IPPF. This standard explicitly outlines the required content of such periodic reports, and the correct option directly mirrors its primary requirements.
✔️ Correct Option: C. The internal audit activity's purpose, authority, responsibility, and performance relative to plan.
IIA Standard 2060 explicitly requires the CAE to report periodically on the internal audit activity's purpose, authority, responsibility, and performance relative to its plan. This report also includes progress against the audit plan, resource requirements, and conformance with the Standards, making it the comprehensive subject of the board report.
❌ Incorrect Option: A. A complete, accurate, and comprehensive account of engagement observations and recommendations.
This level of detail is characteristic of individual engagement reports, not a summary periodic report to the board. While the CAE may report significant issues, the board report provides a higher-level, consolidated summary of the internal audit activity's overall performance and significant risk exposures.
❌ Incorrect Option: B. Oversight of the coordination between the internal audit activity and independent outside auditors.
Although coordinating with external auditors is part of the CAE's role, specific oversight of this coordination is not the central subject of the CAE's periodic report to the board under Standard 2060. The focus is on the internal audit activity itself and its performance against the plan.
❌ Incorrect Option: D. Management's assertions regarding the system of internal controls.
Management's assertions are not the subject of the CAE's periodic report. The CAE reports on the internal audit activity's work, performance, and opinion regarding controls, not on management's self-assessments. This distinction is a key element of the internal audit function's independence.
🔧 Reference:
→ IIA Standard 2060 – Reporting to Senior Management and the Board. This standard confirms that the CAE's periodic report must cover the internal audit activity's purpose, authority, and responsibility, and its performance relative to the plan.
Which of the following situations is most critical for the chief audit executive to report to the board?
A. The chief audit executive disagreed with the business unit manager's initial decision to accept a particular risk Management ultimately agreed to address the risk only after discussing the issue with senior management.
B. The internal audit activity was restructured, which resulted in a significant change in responsibilities among audit managers and supervisors for some audits
C. A staff internal auditor had difficulties completing a portion of the audit because management of the area under review was unwilling to cooperate and provide information timely.
D. The resignation of an internal audit manager during the year caused the chief audit executive to defer a number of audit engagements to the following year.
Explanation:
This question evaluates the chief audit executive’s responsibility to communicate significant matters to the board. Issues that materially affect the internal audit activity’s ability to execute its approved plan, fulfill responsibilities, or provide assurance require escalation because they can influence governance and organizational risk oversight.
🟢 Correct Option: D. The resignation of an internal audit manager during the year caused the chief audit executive to defer a number of audit engagements to the following year
Deferring planned audit engagements due to staffing limitations directly affects execution of the approved audit plan and may leave significant risks unaddressed. The board has oversight responsibility for the effectiveness and adequacy of the internal audit function. Therefore, resource constraints that materially impact audit coverage are critical matters requiring communication by the chief audit executive.
🔴 Incorrect options:
A. The chief audit executive disagreed with the business unit manager's initial decision to accept a particular risk. Management ultimately agreed to address the risk only after discussing the issue with senior management.
The issue was ultimately resolved through management discussion and corrective action was accepted. Since the risk concern was addressed appropriately, it would not normally require escalation as a critical board matter.
B. The internal audit activity was restructured, which resulted in a significant change in responsibilities among audit managers and supervisors for some audits
Changes in internal organization or responsibilities may affect operations, but they do not necessarily represent a significant issue requiring board attention unless audit effectiveness or independence is materially impaired.
C. A staff internal auditor had difficulties completing a portion of the audit because management of the area under review was unwilling to cooperate and provide information timely.
Although management cooperation issues are important, a difficulty affecting one auditor or one engagement is generally handled operationally unless the restriction materially limits audit scope or becomes widespread.
🔧 Reference:
⇒ IIA – Standard 2060 Reporting to Senior Management and the Board
Confirms that the CAE reports significant issues, resource limitations, and deviations from approved plans.
⇒ IIA – International Professional Practices Framework (IPPF)
Confirms board reporting responsibilities regarding audit activity performance and resource adequacy.
In which of the following situations has an internal audit of obtained physical evidence?
A. An internal auditor made purchases from several of the organization's retail outlets to evaluate customer service
B. An internal auditor interviewed various employees regarding health and safety issues and recorded their answers
C. An internal auditor obtained the current quarterly financial report and computed changes in deb-to-equity ratio
D. An internal auditor received a signed confirmation regarding the terms of a transaction from an independent attorney
Explanation:
The question tests the internal auditor's ability to classify different types of audit evidence (physical, testimonial, analytical, and documentary) based on the specific audit procedures performed.
✅ A. An internal auditor made purchases from several of the organization's retail outlets to evaluate customer service:
Physical evidence is obtained through direct observation, inspection, or participation in an activity. By physically visiting retail outlets, executing transactions, and directly experiencing or observing the service environment, the auditor is gathering firsthand physical and observational evidence regarding operations.
❌ B. An internal auditor interviewed various employees regarding health and safety issues and recorded their answers:
Interviewing personnel and recording their verbal responses yields testimonial evidence. While valuable for understanding employee perceptions or gathering background facts, statements made by individuals do not constitute objective physical or observational evidence.
❌ C. An internal auditor obtained the current quarterly financial report and computed changes in deb-to-equity ratio:
Computing financial ratios and analyzing fluctuations from data tables constitutes analytical evidence. Analytical procedures involve evaluating relationships among financial and non-financial information rather than examining tangible items or direct physical environments.
❌ D. An internal auditor received a signed confirmation regarding the terms of a transaction from an independent attorney:
A signed confirmation letter from an external third party represents documentary evidence. Documentary evidence consists of written or electronic records, agreements, invoices, and certificates used to verify the factual accuracy of financial account assertions.
🔧 Reference:
→ IIA Performance Standard 2330 on Recording Information outlines that internal auditors must identify sufficient, reliable, relevant, and useful information, categorizing it properly into physical, documentary, testimonial, and analytical classifications to support engagement results.
Which of the following methodologies consists of the internal auditor holding individual meetings with different people, asking them the same questions, and aggregating the results?
A. Facilitated workshops.
B. Surveys.
C. Structured interviews.
D. Elicitation.
Explanation:
This question tests the auditor's understanding of different risk and control assessment methodologies. It focuses on distinguishing structured interviews, which use a standardized question set across multiple individual sessions, from group-based or written response techniques.
✅ Correct Option:
C. Structured interviews
Structured interviews involve the auditor meeting individually with different people and asking each of them the same predetermined set of questions. The responses are then aggregated and analyzed for consistency and trends, allowing the auditor to gather comparable insights across multiple perspectives within the organization in a controlled, consistent manner.
❌ Incorrect options:
A. Facilitated workshops
Facilitated workshops involve bringing multiple participants together in a group setting to discuss risks and controls collectively. This differs from structured interviews, which are conducted individually rather than as a group discussion exercise.
B. Surveys
Surveys typically involve distributing written questionnaires to a broad group of respondents who complete them independently. This method lacks the direct, individual meeting format that characterizes structured interviews between the auditor and respondent.
D. Elicitation
Elicitation is a broader term referring to techniques for drawing out information from individuals, but it isn't a specific standardized methodology involving identical questions asked individually and aggregated. It lacks the structured, repeatable format described.
🔧 Reference:
→ IIA Practice Guide - Assessing Organizational Risk — confirms structured interviews as a methodology for gathering consistent, comparable information through individual sessions.
| Page 4 out of 72 Pages |