Free IIA IIA-CIA-Part2 Practice Questions 2026 - Page 6

Timed Practice Test

Ready for IIA-CIA-Part2 Exam?

This practice test is your final exam before the REAL exam
Dare to Take It?




Practice Questions

Which of the following represents a ratio that measures short-term debt-paying ability?

A. Debt-to-equity ratio

B. Profit margin

C. Current ratio

D. Times interest earned

C.   Current ratio

Explanation:

This question tests knowledge of financial ratio analysis used in internal audit engagements. Auditors evaluate ratios to assess an organization's financial condition and risk exposure. Short-term debt-paying ability refers to liquidity, which measures whether a company can meet obligations due within a short period using current resources.

🟢 Correct Option:

C. Current ratio
The current ratio measures an organization's short-term liquidity by comparing current assets with current liabilities. It determines whether the company has enough resources that are expected to be converted into cash within a year to satisfy obligations due in the same period. Internal auditors use this ratio to assess liquidity risk and evaluate an entity’s ability to meet short-term financial commitments.

🔴 Incorrect options:

A. Debt-to-equity ratio
This ratio evaluates the relationship between total debt and shareholders' equity. It measures financial leverage and capital structure rather than determining whether sufficient short-term assets exist to satisfy current obligations.

B. Profit margin
Profit margin measures how efficiently a company converts revenue into profit. It reflects profitability and operating performance but does not indicate the ability to pay short-term liabilities.

D. Times interest earned
This ratio evaluates an organization's ability to pay interest expenses using operating income. It focuses on debt-servicing capacity and financial strength rather than short-term liquidity.

🔧 Reference:
⇒ IIA CIA Exam Syllabus
Confirms that financial management and financial analysis concepts are included within CIA examination content.

⇒ International Professional Practices Framework (IPPF) – IIA
Confirms the framework used by internal auditors when evaluating financial information and organizational performance.

An internal auditor developed a list of internal and external risk considerations across the organization's processes, developed a scale to assess each risk and allocated the relative importance of each risk. When of the following approaches did the auditor take?

A. Top-down approach

B. Process-Metrix approach

C. Risk-factor approach

D. Bottom up approach

C.   Risk-factor approach

Explanation:

The question targets the specific methodology used by an internal auditor when assigning scores and weights to specific risk criteria across different business cycles.

✅ C. Risk-factor approach:
The risk-factor approach involves identifying a defined set of internal and external criteria (such as complexity, liquidity of assets, date of last audit, or management stability), creating a standard rating scale for each factor, and assigning relative weights (importance) to each. This mathematical weighting allows the internal audit activity to objectively calculate cumulative risk scores across various auditable entities to prioritize the audit universe.

❌ A. Top-down approach:
A top-down approach begins at the highest entity level—analyzing major corporate strategic objectives and enterprise-wide risks—before drilling down into the processes that support those goals. It focuses on executive alignment rather than systematically scaling and weighting criteria across individual operational processes.

❌ B. Process-Matrix approach:
A process-matrix approach (or risk-by-process matrix) is a structural tool used to map or correlate specific processes directly against established risk categories. While it visually shows connections or intersections between workflows and threats, it does not inherently mean creating weighted assessment scales or allocating mathematical importance values to general factors.

❌ D. Bottom up approach:
A bottom-up approach starts at the foundational, transactional level—identifying localized risks within specific micro-activities and aggregating them upward to form a process-level view. It emphasizes granular operational discovery rather than applying a structured, top-level mathematical scoring system across the organization's macro-processes.

🔧 Reference:
→ IIA Guidance on Risk Assessment in Audit Planning outlines that the risk-factor approach relies on identifying general risk indicators, quantifying them via scaling, and applying weights to establish a defensible, risk-prioritized internal audit schedule.

An internal auditor is preparing an internal control questionnaire for the procurement department as part of a preliminary survey. Which of the following would provide the best source of information for questions?

A. A relevant procurement law or regulation.

B. A list of the company's vendors.

C. A review of a sample of tenders during the audited period.

D. A summary of the company's expenditures and their categories.

A.   A relevant procurement law or regulation.

Explanation:

This question tests the auditor's understanding of preliminary survey procedures, specifically the most appropriate source for developing internal control questionnaire content. It focuses on using authoritative criteria, such as applicable laws and regulations, to establish meaningful control benchmarks for the procurement function.

✅ Correct Option:

A. A relevant procurement law or regulation.
Procurement laws and regulations establish the authoritative criteria against which controls should be designed and evaluated. Using these as a basis for ICQ questions ensures the questionnaire addresses legally mandated requirements, helping the auditor assess whether the department's controls support compliance with applicable procurement standards and obligations.

❌ Incorrect options:

B. A list of the company's vendors
A vendor list provides factual data about procurement relationships but doesn't offer insight into control requirements or criteria. It supports sampling decisions later but isn't a foundational source for developing control-related questions.

C. A review of a sample of tenders during the audited period
Reviewing sample tenders is a substantive testing activity performed during fieldwork, not a preliminary survey step for designing questionnaire content. This comes later, after controls and criteria have already been identified.

D. A summary of the company's expenditures and their categories
Expenditure summaries provide financial context and help with risk assessment or scoping, but they don't establish the control criteria or regulatory requirements needed to formulate meaningful internal control questions.

🔧 Reference:
→ IIA Standards - Engagement Planning — confirms internal auditors should consider applicable laws, regulations, and other criteria when planning engagements and developing assessment tools.

If observed during fieldwork by an internal auditor, which of the following activities is least important to communicate formally to the chief audit executive?

A. Acts that may endanger the health or safety of individuals.

B. Acts that favor one party to the detriment of another.

C. Acts that damage or have an adverse effect on the environment.

D. Acts that conceal inappropriate activities in the organization.

B.   Acts that favor one party to the detriment of another.

Explanation:

The question evaluates which observed activity during an internal audit engagement has the lowest priority for formal escalation to the CAE. It tests understanding of reporting thresholds under IIA Standards for significant risks, ethics, and communication responsibilities.

✅ Correct Option:

B. Acts that favor one party to the detriment of another.
Acts favoring one party represent potential bias or conflict of interest but lack the immediate severity of harm to individuals, environmental damage, or concealment of wrongdoing. Such matters can typically be addressed locally or noted in engagement documentation without formal CAE notification unless they indicate systemic issues.

❌ Incorrect options:

A. Acts that may endanger the health or safety of individuals.
This involves serious risks to people and demands prompt formal escalation due to potential legal, regulatory, and ethical implications.

C. Acts that damage or have an adverse effect on the environment.
This carries regulatory, reputational, and sustainability consequences that require formal communication to the CAE for proper oversight and response.

D. Acts that conceal inappropriate activities in the organization.
This suggests fraud or misconduct and must be formally reported as it undermines controls and governance.

🔧 Reference:
→ IIA Global Internal Audit Standards (Ethics & Professionalism) – Confirms escalation of significant risks and impairments.

→ IIA Global Internal Audit Standards (Communicating Results) – Addresses criteria for formal reporting based on impact.

In which of the following populations would the internal auditor most likely choose to use a stratified sampling approach?

A. Inventory comprised of the same items stored in different warehouses

B. Batches of materials that must be confirmed as meeting quality standards

C. Revenue that is earned by an organization through cash receipts or as receivable.

D. Tax reports submitted to meet the requirements of the local taxation authority

C.   Revenue that is earned by an organization through cash receipts or as receivable.

Explanation:

This question tests the internal auditor's knowledge of when to apply stratified sampling. Stratification divides a heterogeneous population into homogeneous subgroups (strata) to reduce variance and improve sampling efficiency . The correct population is one with inherent variability, such as revenue transactions with a wide range of values, which makes stratification beneficial.

✔️ Correct Option:

C. Revenue that is earned by an organization through cash receipts or as receivable.
Revenue transactions typically have significant dollar-value variation, from small cash sales to large receivable invoices. Stratification allows the auditor to focus more sampling effort on high-value items and less on low-value ones, improving precision in estimating misstatements . This heterogeneous population is ideal for stratification.

❌ Incorrect Options:

A. Inventory comprised of the same items stored in different warehouses.
This population is homogeneous in nature (same items), making stratification unnecessary . Variance is low, so simple random sampling would suffice. Stratification adds complexity without meaningful benefit when items share similar characteristics.

B. Batches of materials that must be confirmed as meeting quality standards.
Quality testing typically uses attributes sampling (pass/fail) rather than stratified sampling. The population is reasonably uniform, and stratification offers no clear advantage for binary quality decisions.

D. Tax reports submitted to meet the requirements of the local taxation authority.
Tax reports are usually uniform in format and regulatory requirements. The population lacks the heterogeneous characteristics needed to justify stratification, as variation between submissions is minimal.

🔧 Reference:
→ IIA Practice Guide: Audit Sampling: Confirms that stratified sampling is most effective when a population can be divided into relatively uniform strata based on criteria that affect the variable being studied, such as monetary value, to reduce variance and improve precision .

When auditing an organization's purchasing function, which of the following appropriately matches an engagement objective and the resulting audit procedure?

A. Determine whether the purchasing department complies with policy by examining a random selection of purchase orders.

B. Evaluate whether purchasing requests are properly approved by authorized staff by obtaining independent verification from the vendors.

C. Ascertain whether material receipts are recorded on a timely basis by reviewing physical inventory stock counts.

D. Determine whether prices charged for goods received are correct by reviewing the appropriate accounts payable record by vendor.

A.   Determine whether the purchasing department complies with policy by examining a random selection of purchase orders.

Explanation:

This question tests the auditor's ability to align an internal audit engagement objective with a relevant and effective audit procedure. A proper match requires that the selected procedure directly gathers sufficient, reliable evidence to achieve the stated objective.

✅ Correct Option:

A. Determine whether the purchasing department complies with policy by examining a random selection of purchase orders.
This matches perfectly because checking compliance with established internal purchasing policies requires evaluating the actual operational output of the department. By examining a randomly selected sample of finalized purchase orders, the auditor can directly verify if essential elements, like authorized competitive bidding or required operational thresholds, were properly executed according to policy.

❌ Incorrect options:

B. Evaluate whether purchasing requests are properly approved by authorized staff by obtaining independent verification from the vendors.
Vendor documentation or confirmation will not prove internal authorization validity. External vendors only see the final, issued purchase orders; they have no visibility into whether the internal, preliminary purchase requests were reviewed and approved by the organization's properly authorized personnel.

C. Ascertain whether material receipts are recorded on a timely basis by reviewing physical inventory stock counts.
Physical inventory stock counts only confirm the existence and quantity of items currently sitting in the warehouse. They do not provide timestamps or date logs necessary to verify if the receiving department recorded those materials promptly upon arrival.

D. Determine whether prices charged for goods received are correct by reviewing the appropriate accounts payable record by vendor.
Reviewing accounts payable records only shows the amounts recorded in the system, not whether those figures are correct. To verify price accuracy, the auditor must perform a three-way match, comparing the invoice prices against the approved purchase order and receiving report.

🔧 Reference:
→ The IIA Guidance on Auditing Procurement confirms that internal compliance objectives must be verified through the direct inspection of internal control documents like purchase orders.

Which of the following statements is true regarding the final assurance engagement report issued to management?

A. Ratings are only used to assess the condition of an observation made by an internal auditor.

B. Audit findings may be communicated to management prior to issuance of the final approved audit report.

C. Communications must be relevant logical, and free from errors before they are disseminated.

D. The audit report must present the information in the following order (1) audit scope, (2) engagement objectives, and (3) engagement results

B.   Audit findings may be communicated to management prior to issuance of the final approved audit report.

Explanation:

This question tests knowledge of internal audit reporting and communication practices during an assurance engagement. Internal auditors do not always wait for the final report to communicate significant observations. Important issues are often discussed with management during the engagement so clarification, corrective actions, or additional information can be obtained before the final report is issued.

🟢 Correct Option:

B. Audit findings may be communicated to management prior to issuance of the final approved audit report.
Internal auditors commonly discuss findings with management during fieldwork and before the final report is released. Early communication helps validate facts, reduce misunderstandings, and allows management to begin corrective actions sooner. This process improves the quality and usefulness of the final assurance engagement report and supports effective communication between auditors and management.

🔴 Incorrect options:

A. Ratings are only used to assess the condition of an observation made by an internal auditor.
Ratings are not limited to evaluating only the condition of an observation. They may also be used to assess risk level, significance, impact, control effectiveness, or the overall engagement result.

C. Communications must be relevant logical, and free from errors before they are disseminated.
These characteristics alone do not fully represent the required communication standards. Internal audit communications should also be accurate, objective, clear, concise, constructive, complete, and timely.

D. The audit report must present the information in the following order (1) audit scope, (2) engagement objectives, and (3) engagement results.
IIA standards do not require a specific sequence or structure for presenting report sections. Organizations may use different report formats as long as required information is appropriately communicated.

🔧 Reference:
⇒ IIA Standards – Communicating Results
Confirms requirements for communicating engagement results and discussions with management.

⇒ IIA Standards – Quality of Communications
Confirms characteristics of effective internal audit communications.

A chief audit executive is preparing interview questions for the upcoming recruitment of a senior internal auditor. According to IIA guidance, which of the following attributes shows a candidate's ability to probe further when reviewing incidents that have the appearance of misbehavior?

A. Integrity.

B. Flexibility.

C. Initiative.

D. Curiosity.

D.   Curiosity.

Explanation:

This question is testing the personal trait that helps an internal auditor investigate suspicious incidents beyond the first explanation. The best answer is the attribute that reflects an inquisitive mindset, because probing further requires asking follow-up questions and checking for hidden facts. The IIA’s materials emphasize professionalism, ethics, and the value of curiosity in internal audit work.

✔️ Correct Option:

D. Curiosity
Curiosity is the attribute that most directly shows a candidate’s ability to probe further when something has the appearance of misbehavior. A curious auditor does not accept a shallow explanation; instead, they ask follow-up questions, look for inconsistencies, and test what they are told. This helps uncover whether the issue is an error, control weakness, or actual misconduct.

❌ Incorrect options:

A. Integrity
Integrity is important because it means honesty and ethical behavior, but it does not specifically describe the ability to investigate suspicious incidents in depth. A person can be ethical and still not have the inquisitive habit needed to keep digging.

B. Flexibility
Flexibility means adapting to different situations and changing conditions, but it does not focus on probing behavior or asking deeper questions. It is useful in audit work, yet it is not the trait most tied to uncovering possible misbehavior.

C. Initiative
Initiative means taking action without waiting to be told, but it is broader than the specific questioning mindset needed here. An auditor with initiative may start work promptly, but curiosity is what drives further inquiry when something does not seem right.

🔧 Reference:
→ IIA Code of Ethics
— confirms the ethical behavior expected of internal auditors.

According to IIA guidance, which of the following statements is true regarding audit workpapers?

A. Review notes on audit workpapers must be retained to provide a record of questions raised by the reviewer.

B. Audit workpaper documentation policies are reviewed and approved by the audit committee.

C. Management of the department being audited should review the prepared workpapers for accuracy.

D. Audit workpaper preparation contributes to the professional development of the internal audit staff.

D.   Audit workpaper preparation contributes to the professional development of the internal audit staff.

Explanation:

This question tests understanding of the purpose and ownership of audit workpapers, along with who is responsible for approving related policies and reviewing content. It distinguishes accurate practices from common misconceptions about workpaper handling.

✅ Correct Option:

D. Audit workpaper preparation contributes to the professional development of the internal audit staff.
Preparing workpapers requires staff to gather, organize, and document evidence in a structured way, similar to completing a graded assignment. This process builds analytical and documentation skills, and supervisor feedback on workpapers helps auditors identify gaps and improve future performance, making preparation a valuable developmental tool for internal audit staff over time.

❌ Incorrect Options:

A. Review notes on audit workpapers must be retained to provide a record of questions raised by the reviewer.
Review notes are typically used temporarily to communicate reviewer questions or requests for clarification. Once issues are resolved and the workpapers are finalized, review notes are generally cleared rather than permanently retained, since they are not considered part of the formal engagement record.

B. Audit workpaper documentation policies are reviewed and approved by the audit committee.
Workpaper documentation policies and formats are established and approved by the chief audit executive, not the audit committee. The CAE is responsible for setting standardized templates and procedures to ensure consistency across engagements, while the audit committee's oversight role is broader and less operational.

C. Management of the department being audited should review the prepared workpapers for accuracy.
Workpapers are the property of the internal audit activity and remain confidential. Review responsibility rests with internal audit supervisors, not auditee management, since allowing outside review could compromise independence, confidentiality, and the integrity of engagement documentation.

🔧 Reference:
→ IIA Global Knowledge Brief: Effective Workpapers — confirms that properly prepared workpapers build auditor skill and support professional growth, similar to a completed assignment with supervisor feedback.

An organization experiencing staff shortages wants to contract a temporary employee to assist with work in the accounting office. Which of the following controls should be in place to ensure the temporary employee performs the assigned work before payment is issued?

A. A three-way match between the invoice, purchase requisition, and documentation of receipt of services

B. A member of management approves the purchase requisition before the temporary employee begins work

C. A scope of work for the temporary employee is included in the purchase requisition and signed by the organization

D. Payments to the vendor are analyzed monthly to ensure they do not exceed the amount approved on the purchase order

A.   A three-way match between the invoice, purchase requisition, and documentation of receipt of services

Explanation:

This question examines internal controls over procurement and payment for temporary staffing services to prevent payment for unperformed work. It tests understanding of key preventive controls in the procure-to-pay cycle per IIA guidance on governance and risk management.

✅ Correct Option:

A. A three-way match between the invoice, purchase requisition, and documentation of receipt of services
This control verifies that services were actually received and performed before authorizing payment. Matching the invoice against the approved requisition and proof of service delivery (e.g., timesheets or manager confirmation) ensures the temporary employee completed assigned work, reducing the risk of improper payments.

❌ Incorrect options:

B. A member of management approves the purchase requisition before the temporary employee begins work
This provides pre-approval of the need but does not confirm that the work was actually performed before payment.

C. A scope of work for the temporary employee is included in the purchase requisition and signed by the organization
Defining scope is important for clarity but does not provide evidence of completion or support verification prior to payment.

D. Payments to the vendor are analyzed monthly to ensure they do not exceed the amount approved on the purchase order
This is a detective control focused on budget limits after the fact but does not verify that services were delivered.

🔧 Reference:
→ IIA Global Internal Audit Standards – Control – Emphasizes preventive controls like matching for payment authorization.

→ IIA Practice Guide on Procure-to-Pay Processes – Recommends three-way matching to ensure value received before payment.

Page 6 out of 72 Pages