Free IIA IIA-CIA-Part2 Practice Questions 2026 - Page 5
Ready for IIA-CIA-Part2 Exam?
This practice test is your final exam before the REAL exam
Dare to Take It?
Practice Questions
An internal auditor concluded that delays in an ongoing construction project have cost the organization $10 million to date. Which documents should be included in the audit workpapers to provide sufficient evidence to support the conclusion?
A. Payment and work milestones
B. Pictures from the construction site
C. Initial sprint planning
D. Project internal rate of return
Explanation:
This question addresses the documentation requirements for supporting audit conclusions, specifically regarding construction project delays. To substantiate a $10 million cost conclusion, the auditor needs evidence that directly links the delay to quantifiable financial losses, which is best documented through payment records and work milestone schedules.
✔️ Correct Option: A. Payment and work milestones
This documentation provides the quantitative evidence needed to support a financial conclusion. Payment records show actual costs incurred, while work milestone schedules document the planned versus actual progress, enabling the auditor to quantify delay costs by calculating additional labor, equipment, overhead expenses, and lost productivity directly attributable to the delays .
❌ Incorrect Option: B. Pictures from the construction site
While photographs can document physical conditions and support qualitative observations, they cannot quantify financial losses. Photos show the existence of delays but provide no monetary data to substantiate the $10 million conclusion. The IIA Standards require information to be "sufficient, reliable, relevant, and useful" —visual evidence alone does not meet the quantitative requirement.
❌ Incorrect Option: C. Initial sprint planning
This is a project management artifact unrelated to the specific delay cost calculation. Sprint planning documents establish initial schedules and task breakdowns but do not record actual costs incurred or demonstrate the financial impact of delays, making them insufficient to support a monetary conclusion .
❌ Incorrect Option: D. Project internal rate of return
IRR is a forward-looking investment metric, not a record of historical costs. While IRR may support a business case, it provides no evidential basis for calculating delay-related costs and cannot substantiate the $10 million conclusion because it does not document actual expenditures or schedule performance .
🔧 Reference:
→ IIA Standard 2330 – Documenting Information. This standard requires auditors to document sufficient, reliable, relevant, and useful information to support engagement conclusions and results .
An internal auditor is assessing whether a vendor onboarding procedure is being followed in all business units. The procedure has been centrally designed and depicts activities and validations that must be performed at every step. Which of the following is the most suitable way to compile an internal control questionnaire?
A. Develop statements that are based on the procedure requirements and ask respondents to select yes or no responses
B. Develop open questions that inquire about the appropriateness and efficacy of the procedure
C. Develop closed questions asking managers to describe the onboarding process in detail
D. Develop multiple response questions where a respondent has to identify one correct answer out of four
Explanation:
This question tests understanding of internal control questionnaires (ICQs) and their use in evaluating control compliance. Since the vendor onboarding procedure already contains defined activities and validations, the questionnaire should be structured to verify whether each required control step is consistently followed across business units.
🟢 Correct Option: A. Develop statements that are based on the procedure requirements and ask respondents to select yes or no responses
Internal control questionnaires commonly use structured yes-or-no responses linked directly to established control requirements. This approach allows auditors to efficiently determine whether required procedures are consistently performed and identify exceptions across business units. Using predefined control statements improves standardization, simplifies comparison of responses, and helps detect potential control gaps or noncompliance.
🔴 Incorrect options:
B. Develop open questions that inquire about the appropriateness and efficacy of the procedure
Open questions provide broader opinions and qualitative feedback, but they are less effective for confirming compliance with a predefined procedure because responses may vary significantly and become difficult to compare.
C. Develop closed questions asking managers to describe the onboarding process in detail
Although process descriptions may improve understanding, requiring detailed narrative responses does not efficiently verify whether required control activities are consistently performed.
D. Develop multiple response questions where a respondent has to identify one correct answer out of four
Multiple-choice questions are more appropriate for testing knowledge or training effectiveness. They do not directly determine whether actual control procedures are being followed in practice.
🔧 Reference:
⇒ IIA – International Professional Practices Framework (IPPF) Engagement Planning Guidance
Confirms the use of appropriate techniques for evaluating internal controls.
⇒ IIA – Standard 2240 Engagement Work Program
Confirms that audit procedures should be designed to achieve engagement objectives.
Which of the following is the advantage of using internal control questionnaires (ICQs) as part of a preliminary survey for an engagement?
A. ICQs provide testimonial evidence.
B. ICQs are efficient.
C. ICQs provide tangible evidence to be quantified.
D. ICQs put observations into perspective.
Explanation:
This question tests your understanding of audit tools and techniques used during the preliminary survey phase of an engagement. Internal Control Questionnaires (ICQs) are a standard tool for gathering information about an organization's control environment quickly and systematically, and their primary advantage in this context is efficiency.
✔️ Correct Option: B. ICQs are efficient.
ICQs allow for efficient gathering of information from a large number of respondents at once, whereas interviews would require a much longer time or many more auditors to administer. They are easy to administer and cost-effective, providing a structured way to identify potential control weaknesses during the preliminary survey stage. This efficiency helps the auditor focus engagement planning on key risk areas.
❌ Incorrect Option: A. ICQs provide testimonial evidence.
This is incorrect. Testimonial evidence is obtained through interviews and inquiries with personnel, not from written questionnaires. ICQs provide documentary evidence in the form of completed forms, but the responses themselves are not considered testimonial evidence in the audit evidence framework.
❌ Incorrect Option: C. ICQs provide tangible evidence to be quantified.
This is incorrect. ICQs typically use yes/no or scaled responses and are designed to identify the existence or absence of controls, not to provide quantifiable, tangible evidence. While responses can be aggregated for analysis, the tool itself does not produce the kind of measurable, physical evidence that would be obtained through inspection or observation.
❌ Incorrect Option: D. ICQs put observations into perspective.
This is incorrect and misstates the purpose of ICQs. While ICQs can help structure the auditor's understanding of a process, "putting observations into perspective" is more characteristic of the overall analytical and judgmental process an auditor performs after gathering evidence, not a specific advantage of the ICQ tool itself.
🔧 Reference:
→ IIA Learning System – Internal Control Questionnaires. This official IIA source confirms that internal control questionnaires are "efficient and easy to administer" and allow for "efficient gathering of information from large numbers of respondents at once" during preliminary surveys and control self-assessments.
Which of the following is the most appropriate reason for a chief audit executive to conduct an external assessment more frequently than five years?
A. Significant changes in the organization's accounting policies or procedures would warrant timely analysis and feedback.
B. More frequent external assessments can serve as an equivalent substitute for internal assessments.
C. The parent organization's internal audit activity agreed to perform biennial reciprocal external assessments to provide greater assurance at a reduced cost.
D. A change in senior management or internal audit leadership may change expectations and commitment to conformance
Explanation:
This question tests the auditor's understanding of the IIA's Quality Assurance and Improvement Program requirements, specifically circumstances warranting more frequent external assessments than the standard five-year cycle. It focuses on factors affecting the internal audit activity's conformance and standing within the organization.
✅ Correct Option:
D. A change in senior management or internal audit leadership may change expectations and commitment to conformance
Leadership transitions can shift organizational priorities, support, and commitment toward internal audit standards conformance. A more frequent external assessment helps verify that the internal audit activity continues meeting required standards despite changes in senior management or audit leadership, ensuring sustained quality and stakeholder confidence in the function's performance.
❌ Incorrect options:
A. Significant changes in the organization's accounting policies or procedures would warrant timely analysis and feedback
Accounting policy changes typically require internal audit's attention through engagement planning and risk assessment updates, not necessarily an accelerated external quality assessment of the internal audit activity itself.
B. More frequent external assessments can serve as an equivalent substitute for internal assessments
External and internal assessments serve complementary, not interchangeable, purposes within the Quality Assurance and Improvement Program. One can't substitute for the other regardless of frequency, as both are required components.
C. The parent organization's internal audit activity agreed to perform biennial reciprocal external assessments to provide greater assurance at a reduced cost
Reciprocal arrangements raise independence and objectivity concerns under IIA standards. Cost reduction through reciprocal agreements isn't an appropriate justification for assessment frequency decisions.
🔧 Reference:
→ IIA Standards - Quality Assurance and Improvement Program — confirms external assessments should occur at least once every five years, with more frequent assessments warranted by factors like leadership changes.
An internal audit report includes a recommendation to remove inappropriate user access to an IT application. Which of the following does the recommendation represent?
A. An agreed action adopted by management.
B. A condition-based recommendation as an interim solution to correct a current condition.
C. A cause-based recommendation to prevent inappropriate access being granted again.
D. A management action plan.
Explanation:
This question tests understanding of audit recommendations and the distinction between condition-based and cause-based actions. Condition-based recommendations address an identified issue that currently exists, while cause-based recommendations focus on eliminating the root cause to prevent recurrence.
🟢 Correct Option: B. A condition-based recommendation as an interim solution to correct a current condition
The recommendation to remove inappropriate user access addresses an existing problem that has already been identified. It corrects the current condition by eliminating unauthorized access rights but does not address the underlying reason why the inappropriate access was granted. Therefore, it is considered a condition-based recommendation intended to resolve an immediate issue rather than prevent future occurrences.
🔴 Incorrect options:
A. An agreed action adopted by management
An audit recommendation itself is not automatically an agreed management action. Management must review the recommendation and decide whether to accept, modify, or implement it through a formal action plan.
C. A cause-based recommendation to prevent inappropriate access being granted again
A cause-based recommendation would focus on correcting the underlying reason for the issue, such as weak access approval processes or inadequate segregation of duties. Simply removing access does not prevent the problem from recurring.
D. A management action plan
A management action plan represents management's response describing how and when corrective actions will be implemented. An audit recommendation alone does not constitute a management action plan.
🔧 Reference:
⇒ IIA – Standard 2410 Criteria for Communicating
Confirms that audit communications include observations and recommendations addressing identified conditions.
⇒ IIA – International Professional Practices Framework (IPPF)
Confirms guidance on communicating findings and recommending corrective actions.
An internal auditor wants to examine the intensity of correlation between electricity price and wind speed. Which of the following analytical approaches would be most appropriate for this purpose?
A. A Gantt chart
B. A scatter diagram
C. A RACI chart
D. A SIPOC diagram
Explanation:
The question asks for the best tool to analyze and visualize the strength and direction of a relationship (correlation) between two continuous variables: electricity price and wind speed.
✅ B. A scatter diagram:
A scatter diagram (or scatter plot) is a mathematical tool that plots pairs of numerical data on an $X$ and $Y$ axis to visually demonstrate the relationship or correlation between two variables. By looking at the pattern and tightness of the plotted data points, an auditor can easily determine the intensity and direction (positive, negative, or linear/non-linear) of the correlation.
❌ A. A Gantt chart:
A Gantt chart is a project management tool used to illustrate a project schedule. It displays timelines, start and end dates of activities, and dependencies between tasks over time, which has no application for calculating statistical correlation between data sets.
❌ C. A RACI chart:
A RACI chart (Responsible, Accountable, Consulted, Informed) is a responsibility assignment matrix used in organizational governance. It clarifies roles and responsibilities for business tasks, milestones, or decisions across different organizational positions.
❌ D. A SIPOC diagram:
A SIPOC diagram (Suppliers, Inputs, Process, Outputs, Customers) is a high-level process mapping tool used in Six Sigma and process improvements. It summarizes the inputs and outputs of one or more processes but cannot measure or analyze numeric correlation.
🔧 Reference:
→ IIA Guidance on Data Analytics and Root Cause Analysis Tools highlights scatter diagrams as a fundamental visual analytics tool used by internal auditors to identify and evaluate patterns, dependencies, and statistical correlations between variables during risk assessment or testing phases.
An internal auditor discovered a control weakness that needs to be communicated to management. Which of the following is the best method for first communicating the weakness?
A. Draft report, to be reviewed by management just prior to final report issuance.
B. Preliminary observation document, discussed during the engagement.
C. Final report, after review by audit management.
D. Verbal communication during the engagement, followed by the final report issuance.
Explanation:
This question tests the auditor's understanding of best practices for timely communication of control weaknesses during an audit engagement. It emphasizes the value of addressing issues early, allowing management to respond and clarify before formal reporting stages.
✅ Correct Option:
B. Preliminary observation document, discussed during the engagement
Communicating a preliminary observation document during the engagement allows management to review and discuss the weakness promptly, while details are fresh and context is available. This early dialogue supports accuracy, allows management to provide feedback or corrective action plans, and prevents surprises at later reporting stages.
❌ Incorrect options:
A. Draft report, to be reviewed by management just prior to final report issuance
Waiting until the draft report stage delays communication significantly, reducing management's opportunity to respond early. This approach increases the risk of unresolved disagreements surfacing late in the process, close to final reporting.
C. Final report, after review by audit management
Communicating only through the final report is far too late, as management has no opportunity for preliminary discussion or clarification. This approach removes the collaborative dialogue needed before formal documentation.
D. Verbal communication during the engagement, followed by the final report issuance
While verbal communication during the engagement is helpful, it lacks the documented, structured format of a preliminary observation document, which provides clearer reference and accountability for both parties involved.
🔧 Reference:
→ IIA Standards - Communicating Results — confirms internal auditors should communicate engagement results, including timely preliminary observations, to support effective resolution.
An internal auditor wants to determine whether employees are complying with the information security policy, which prohibits leaving sensitive information on employee desks overnight. The auditor checked a sample of 90 desks and found eight that contained sensitive information. How should this observation be reported, if the organization tolerates 4 percent noncompliance?
A. The matter does not need to be reported, because the noncompliant findings fall within the acceptable tolerance limit.
B. The deviations are within the acceptable tolerance limit, so the matter only needs to be reported to the information security manager.
C. The incidents of noncompliance fall outside the acceptable tolerance limit and require immediate corrective action, as opposed to reporting.
D. The incidents of noncompliance exceed the tolerance level and should be included in the final engagement report.
Explanation:
This question tests your understanding of how to evaluate and report audit findings against established tolerance levels, which is a key concept in engagement reporting under the IIA Standards. The auditor found a noncompliance rate of approximately 8.9% (8 out of 90 desks), which exceeds the organization's tolerance level of 4%. Findings that exceed acceptable tolerance limits must be reported to the appropriate levels of management, as they represent a significant deviation from policy that requires attention.
✔️ Correct Option: D. The incidents of noncompliance exceed the tolerance level and should be included in the final engagement report.
The observed noncompliance rate of 8.9% (8/90) clearly exceeds the 4% tolerance level. This constitutes a significant finding that must be reported in the final engagement communication. The IIA Standards require that significant observations be included in final reports to ensure management and the board are aware of issues that could impact the organization's risk profile.
❌ Incorrect Option: A. The matter does not need to be reported, because the noncompliant findings fall within the acceptable tolerance limit.
This is incorrect because the noncompliance rate (8.9%) exceeds the 4% tolerance limit, not falls within it. Even if it were within tolerance, the IIA Standards generally require reporting of all significant observations, regardless of tolerance levels.
❌ Incorrect Option: B. The deviations are within the acceptable tolerance limit, so the matter only needs to be reported to the information security manager.
This option contains two errors: the deviations exceed the tolerance limit, and even if they were within tolerance, the IIA Standards require appropriate reporting to ensure management is informed of risks, not limiting communication to a single manager without justification.
❌ Incorrect Option: C. The incidents of noncompliance fall outside the acceptable tolerance limit and require immediate corrective action, as opposed to reporting.
While immediate corrective action may be appropriate, it does not replace the need for formal reporting. The IIA Standards require that significant observations be communicated in final reports; corrective action and reporting are complementary, not mutually exclusive.
🔧 Reference:
→ IIA Standard 2440 – Disseminating Results. This standard requires that the chief audit executive communicates results to the appropriate parties, which includes reporting significant findings in final engagement reports.
→ IIA Practice Guide: Audit Report Writing. This guide emphasizes that findings exceeding acceptable tolerance levels should be included in final reports to ensure management has complete information for decision-making.
Which of the following statements is true regarding the chief audit executive's (CAT$) responsibilities after completing an assurance or consulting engagement?
A. The CAE must establish a follow-up process tor both assurance and consulting engagements to monitor that management actions have been effectively implemented to address observations
B. The CAE must communicate the results of assurance and consulting engagements lo whoever can ensure that the results are given due consideration.
C. The CAE must acknowledge satisfactory performance when communicating the results of assurance and consulting engagements
D. The CAE may delegate the responsibility for communicating the results of consulting engagements although this responsibility cannot be delegated for assurance engagements
Explanation:
This question tests understanding of the chief audit executive’s responsibilities after completion of assurance and consulting engagements. Under IIA guidance, engagement results must be communicated to the appropriate parties so corrective actions, risk considerations, and recommendations receive proper attention and response.
🟢 Correct Option: B. The CAE must communicate the results of assurance and consulting engagements to whoever can ensure that the results are given due consideration
The CAE is responsible for ensuring engagement results are communicated to individuals or groups with authority to review and act on the information. Communication should reach stakeholders capable of making decisions, addressing risks, and implementing responses where needed. This requirement applies to both assurance and consulting engagements so that significant matters receive proper attention.
🔴 Incorrect options:
A. The CAE must establish a follow-up process for both assurance and consulting engagements to monitor that management actions have been effectively implemented to address observations
IIA guidance specifically requires a follow-up process for monitoring management actions related to assurance activities. Consulting engagements do not automatically require the same mandatory follow-up process because follow-up depends on engagement terms and objectives.
C. The CAE must acknowledge satisfactory performance when communicating the results of assurance and consulting engagements
Recognizing good performance may be beneficial, but it is not a mandatory requirement for engagement communications under IIA standards.
D. The CAE may delegate the responsibility for communicating the results of consulting engagements although this responsibility cannot be delegated for assurance engagements
The CAE may delegate communication activities in both engagement types while retaining overall responsibility. Delegation itself is not restricted only to consulting engagements.
🔧 Reference:
⇒ IIA – Standard 2400 Communicating Results
Confirms that engagement results should be communicated to appropriate parties.
⇒ IIA – International Professional Practices Framework (IPPF)
Confirms CAE responsibilities for communicating engagement outcomes.
A large investment organization hired a chief risk officer (CRO) to be responsible for the organization's risk management processes. Which of the following people should prioritize risks to be used for the audit plan?
A. Operational management, because they are responsible for the day-to-day management of the operational risks.
B. The CRO, because he is responsible for coordinating and project managing risk activities based on his specialized skills and knowledge.
C. The chief audit executive, although he is not accountable for risk management in the organization.
D. The CEO, because he has ultimate responsibility for ensuring that risks are managed within the agreed tolerance limits set by the board.
Explanation:
The question tests who holds ultimate professional responsibility for prioritizing risks when developing the risk-based internal audit plan, especially in an organization that has established a dedicated risk management function led by a Chief Risk Officer (CRO).
✅ C. The chief audit executive, although he is not accountable for risk management in the organization:
According to IIA standards, the Chief Audit Executive (CAE) is independently responsible for establishing a risk-based audit plan. While the CAE should coordinate with and leverage the risk assessments produced by management and the CRO (the second line of defense), the CAE must independently prioritize these risks for the audit program. This ensures internal audit remains objective, independent, and free from operational biases.
❌ A. Operational management, because they are responsible for the day-to-day management of the operational risks:
Operational management (the first line of defense) is responsible for identifying, managing, and mitigating risks within their own daily workflows. While their input is vital during early risk assessments, they do not possess the independent mandate or structural authority to prioritize risks for the internal audit plan.
❌ B. The CRO, because he is responsible for coordinating and project managing risk activities based on his specialized skills and knowledge:
The CRO leads the enterprise risk management (ERM) framework and helps management monitor exposures across the company. However, the CRO is an operational role within the management hierarchy. Allowing the CRO to prioritize the internal audit plan would compromise the independence of the third line of defense.
❌ D. The CEO, because he has ultimate responsibility for ensuring that risks are managed within the agreed tolerance limits set by the board:
The CEO maintains ultimate executive accountability for organizational operations and risk tolerance alignment. However, if the CEO prioritized the internal audit universe, it would expose the audit function to management override, fundamentally undermining internal audit’s independent reporting relationship to the board.
🔧 Reference:
→ IIA Performance Standard 2010 on Planning explicitly mandates that the chief audit executive must establish a risk-based plan to determine the priorities of the internal audit activity, consistent with the organization's goals, and this responsibility cannot be delegated to management functions.
| Page 5 out of 72 Pages |