Free IIA IIA-CIA-Part2 Practice Questions 2026 - Page 7

Timed Practice Test

Ready for IIA-CIA-Part2 Exam?

This practice test is your final exam before the REAL exam
Dare to Take It?




Practice Questions

According to IIA guidance, which of the following would not be a consideration for the internal audit activity (IAA) when determining the need to follow-up on recommendations?

A. Degree of effort and cost needed to correct the reported condition.

B. Complexity of the corrective action.

C. Impact that may result should the corrective action fail.

D. Amount of resources required to conduct the follow-up activities.

D.   Amount of resources required to conduct the follow-up activities.

Explanation:

This question evaluates the internal auditor's understanding of the key criteria for determining the need to follow up on audit recommendations. According to IIA guidance, the decision should be based on the significance of the risk and the nature of the corrective action, not on the internal audit activity's administrative capacity. The focus should remain on the importance of the issue, as resource constraints should not undermine the follow-up of critical findings .

βœ”οΈ Correct Option:

D. Amount of resources required to conduct the follow-up activities.
This is not a primary consideration when deciding whether to follow up. The IIA guidance emphasizes that resource limitations should not be the determining factor for a necessary follow-up; the significance of the issue and potential risks take precedence. Therefore, resource availability should not be a reason to forgo monitoring progress .

❌ Incorrect Options:

A. Degree of effort and cost needed to correct the reported condition.
This is a valid consideration. The effort and cost required by management to implement a corrective action directly influence the need for follow-up to ensure the agreed-upon actions are indeed taken. This factor is specifically listed in the IIA guidance .

B. Complexity of the corrective action.
This is a valid consideration. More complex corrective actions are more likely to encounter unforeseen problems or implementation delays, thus warranting a more diligent and structured follow-up to verify their effectiveness .

C. Impact that may result should the corrective action fail.
This is a valid consideration. The potential severity of the impact if a recommendation is not implemented is fundamental to the IIA risk-based approach. The higher the risk of failure, the greater the need for follow-up to ensure the risk is mitigated .

πŸ”§ Reference:
β†’ IIA Standard 2500: Monitoring Progress: Confirms that the CAE must establish a follow-up process to monitor management actions; the determination of which recommendations to follow up on is based on their significance.

β†’ IIA Practice Advisory 2500.A1-1: Details the specific factors for scheduling follow-up, including degree of effort, complexity, and potential impact.

A regional entertainment organization is in the process of developing a corporate social responsibility (CSR) policy. Management invites ideas from employees when developing the CSR policy Which of the following is the most appropriate idea to include?

A. Management has overall responsibility for the effectiveness of governance, risk management, and internal control processes associated with CSR.

B. The board Is responsible for ensuring that CSR objectives are established, risks are managed, performance is measured, and activities are appropriately monitored and reported

C. Management is responsible for ensuring that the organization's CSR principles are communicated, understood, and integrated into decision-making processes.

D. Generally, CSR activities are limited to the management of the organization, thus, employees do not have a responsibility for ensuring the success of CSR objectives.

C.   Management is responsible for ensuring that the organization's CSR principles are communicated, understood, and integrated into decision-making processes.

Explanation:

This question tests the understanding of governance roles and responsibilities within Corporate Social Responsibility (CSR). It requires identifying the correct operational duty assigned to management to successfully embed CSR principles across the organization's day-to-day activities.

βœ… Correct Option:

C. Management is responsible for ensuring that the organization's CSR principles are communicated, understood, and integrated into decision-making processes.
Management is operationally responsible for executing CSR policies. This includes driving awareness throughout the workforce, establishing daily operational procedures that align with CSR goals, and ensuring that sustainable, ethical, and socially responsible principles are actively factored into strategic business decisions and organizational workflows.

❌ Incorrect options:

A. Management has overall responsibility for the effectiveness of governance, risk management, and internal control processes associated with CSR.
This statement incorrectly assigns overall responsibility. In corporate governance frameworks, the board of directorsβ€”not managementβ€”holds the ultimate, oversight responsibility for the overall effectiveness of the organization's governance, risk management frameworks, and internal control systems.

B. The board Is responsible for ensuring that CSR objectives are established, risks are managed, performance is measured, and activities are appropriately monitored and reported
While the board oversees governance, the operational tasks of establishing specific targets, managing day-to-day risks, measuring performance, and reporting activities are management duties. The board reviews and guides these elements but does not directly execute them.

D. Generally, CSR activities are limited to the management of the organization, thus, employees do not have a responsibility for ensuring the success of CSR objectives.
CSR is an organization-wide commitment that relies heavily on employee engagement. Frontline employees are responsible for adhering to CSR guidelines, identifying compliance issues, and executing sustainable practices, making their involvement vital to achieving CSR objectives.

πŸ”§ Reference:
β†’ The IIA Practice Guide on Corporate Social Responsibility confirms that while the board provides oversight, management is responsible for implementing CSR policies and communicating them throughout the workforce.

An audit reveals that a manager's spouse is receiving paychecks, but is not employed by the organization. According to IIA guidance, which of the following actions should the internal auditor take?

A. Contact the external auditor and provide all relevant documentation.

B. Report the finding to senior management in a timely manner, following the normal chain of command.

C. Meet with the local manager to obtain more information on the finding before taking further action.

D. Bypass the normal chain of command and contact the board directly to report the finding.

B.   Report the finding to senior management in a timely manner, following the normal chain of command.

Explanation:

This question tests the internal auditor’s responsibilities when identifying possible fraud or misconduct. Internal auditors should communicate significant findings through established reporting procedures and organizational protocols. Unless circumstances require escalation, findings are normally reported through the appropriate management channels.

🟒 Correct Option:

B. Report the finding to senior management in a timely manner, following the normal chain of command.
The finding suggests possible payroll fraud because an individual is receiving compensation without being employed by the organization. Internal auditors should promptly communicate such matters using established reporting channels. Following the normal chain of command ensures proper investigation and maintains organizational procedures unless management involvement creates a conflict or prevents objective handling of the issue.

πŸ”΄ Incorrect options:

A. Contact the external auditor and provide all relevant documentation.
External auditors are not the first reporting point for suspected internal fraud findings. Internal auditors should initially report issues according to internal reporting structures and organizational procedures.

C. Meet with the local manager to obtain more information on the finding before taking further action.
Directly approaching the local manager may create risks if that individual is involved in the suspected misconduct. Internal auditors should avoid actions that could compromise evidence or interfere with an investigation.

D. Bypass the normal chain of command and contact the board directly to report the finding.
Direct communication with the board is generally used when normal reporting channels are compromised or when senior management involvement creates a conflict. There is no indication that bypassing management is necessary in this situation.

πŸ”§ Reference:
β‡’ IIA Standards – Communicating Results and Significant Risks
Confirms that significant findings should be communicated through appropriate reporting processes.

β‡’ IIA Code of Ethics
Confirms responsibilities related to integrity, objectivity, and appropriate handling of findings.

An internal auditor uses a data query tool in the purchasing process to review the vendor master file for authorizations Which of the following describes the control objective likely being tested?

A. Effectiveness

B. Response

C. Efficiency

D. Mitigation.

A.   Effectiveness

Explanation:

This question is testing whether the audit procedure is aimed at verifying that a control is working as intended. Reviewing the vendor master file for authorizations checks whether only approved vendor records exist, which is a control designed to prevent unauthorized entries and changes. That points to effectiveness, not speed or response actions.

βœ”οΈ Correct Option:

A. Effectiveness
Effectiveness measures whether a control achieves its intended purpose. By using a data query tool to inspect authorizations in the vendor master file, the auditor is testing whether the purchasing process control is properly preventing unauthorized vendor setup or changes. This confirms that the control is functioning as designed and protecting the process from invalid vendors.

❌ Incorrect options:

B. Response
Response refers to how management reacts after a risk or issue has been identified. The procedure described is not about responding to a problem; it is about testing whether the authorization control is actually in place and working.

C. Efficiency
Efficiency focuses on achieving an objective with minimal waste of time, money, or effort. Reviewing vendor authorizations is not mainly about doing the process faster or cheaper; it is about checking whether the control is operating properly.

D. Mitigation
Mitigation is the reduction of risk through controls or other actions. While the vendor authorization control does help reduce risk, the audit test itself is evaluating whether that control is effective, not simply identifying risk reduction in general.

πŸ”§ Reference:
β†’ IIA Internal Audit Standards β€” confirms that internal audit evaluates whether controls are designed and operating effectively.

β†’ IIA Performance Standards β€” supports testing the adequacy and effectiveness of controls in audit engagements.

When auditing an organization's cash-handling activates which of the following is the most reliable form of testimonial evidence an internal auditor can obtain?

A. Testimony from the cashier who performs the processes being reviewed

B. Testimony from me cashier's supervisor who knows how processes should be performed

C. Testimony from a knowledgeable person who is independent of the cashiering duty

D. Testimony from a manager who oversees all cashiering activities being reviewed

C.   Testimony from a knowledgeable person who is independent of the cashiering duty

Explanation:

This question tests the reliability hierarchy of testimonial evidence under IIA guidance. It focuses on how an auditor should weigh source credibility, since testimony from someone with a stake in the process being reviewed carries greater bias risk than testimony from an independent party.

βœ… Correct Option:

C. Testimony from a knowledgeable person who is independent of the cashiering duty
Independence reduces the risk of bias, since the source has no personal stake in how the cash-handling process is perceived. A knowledgeable individual outside the cashiering function can describe how the process works or should work without motivation to conceal weaknesses or misrepresent performance, making this testimony the most objective and reliable source among the options.

❌ Incorrect Options:

A. Testimony from the cashier who performs the processes being reviewed
The cashier has direct involvement in the process under review, creating a self-interest risk. Statements may be shaped by a desire to avoid blame or present performance favorably, reducing objectivity even though the cashier has firsthand operational knowledge.

B. Testimony from the cashier's supervisor who knows how processes should be performed
The supervisor oversees the same process and may share accountability for its effectiveness. This creates a similar bias risk as the cashier, since unfavorable findings could reflect on the supervisor's own oversight responsibilities.

D. Testimony from a manager who oversees all cashiering activities being reviewed
This manager holds direct responsibility for the activities under review, making objectivity a concern. Testimony from someone accountable for the outcome is less reliable than testimony from a party with no vested interest in the audit result.

πŸ”§ Reference:
β†’ IIA Standard 2310 – Identifying Information β€” establishes that internal auditors must gather sufficient, reliable, relevant, and useful information, with reliability strengthened when evidence comes from independent sources.

Which of the following information is most appropriate for the chief audit executive to share when coordinating audit plans with other internal and external assurance providers?

A. Objectives scope and timing at a high level to support coordination while adhering to confidentiality requirements

B. The area and timing of the audit engagement to ensure confidentially and avoid conflict of interest.

C. All plan information, including risk assessments, planned tests and past results to maximize the opportunity for coordination with internal and external providers.

D. No information should be shared with internal and external provider as it could introduce bias into the engagement results.

A.   Objectives scope and timing at a high level to support coordination while adhering to confidentiality requirements

Explanation:

The question addresses coordination responsibilities of the chief audit executive (CAE) with other assurance providers. IIA guidance promotes efficient assurance through collaboration while maintaining confidentiality and independence.

βœ… Correct Option:

A. Objectives scope and timing at a high level to support coordination while adhering to confidentiality requirements
Sharing high-level details enables effective coordination, reduces duplication of effort, and maximizes coverage of key risks without compromising sensitive information or internal audit independence.

❌ Incorrect options:

B. The area and timing of the audit engagement to ensure confidentially and avoid conflict of interest.
While timing is relevant, limiting sharing to only area and timing may be insufficient for meaningful coordination and does not address objectives or scope adequately.

C. All plan information, including risk assessments, planned tests and past results to maximize the opportunity for coordination with internal and external providers.
Sharing detailed information risks breaching confidentiality and could impair internal audit’s independence or objectivity.

D. No information should be shared with internal and external provider as it could introduce bias into the engagement results.
Complete non-disclosure contradicts IIA standards that encourage coordination to enhance overall assurance efficiency.

πŸ”§ Reference:
β†’ IIA Global Internal Audit Standards – Coordination – Requires CAE to coordinate with other providers using appropriate high-level information.

β†’ IIA Practice Guide on Assurance Coordination – Emphasizes sharing necessary details while protecting confidentiality.

The internal audit activity has adopted the balanced scorecard approach to assess its performance According to MA guidance which of the following is a key performance indicator relevant to the audit client?

A. Percentage of recommendations implemented by corrective action date

B. Staff experience

C. Percentage of planned audits completed

D. Conformance with the International Professional Practices Framework

A.   Percentage of recommendations implemented by corrective action date

Explanation:

This question tests the internal auditor's understanding of which Balanced Scorecard KPIs are most relevant to the audit client. The Balanced Scorecard categorizes performance measures across different perspectives (e.g., Stakeholder/Client, Internal Processes, Innovation/Capabilities) . The "audit client" perspective focuses on how the audit function's work is received and acted upon by management, making the implementation of audit recommendations a key client-focused metric .

βœ”οΈ Correct Option:

A. Percentage of recommendations implemented by corrective action date
This KPI directly measures whether management (the audit client) has taken timely action on audit findings, demonstrating the value and impact of the audit work. It reflects how clients respond to audit recommendations, making it a primary indicator of client engagement and the effectiveness of the audit function's influence .

❌ Incorrect Options:

B. Staff experience
While valuable for assessing the audit team's capabilities, this is an internal performance indicator within the "Learning and Growth" or "Innovation and Capabilities" perspective. It measures internal resources rather than client outcomes, making it less relevant to the audit client .

C. Percentage of planned audits completed
This measures the internal audit function's operational efficiency and execution of its work plan. While important for the CAE and audit committee, it does not directly reflect the value or impact perceived by the audit client .

D. Conformance with the International Professional Practices Framework
This is a quality assurance indicator measuring the internal audit activity's adherence to professional standards. It is relevant to the Quality Assurance and Improvement Program and internal governance, but does not directly measure client-focused performance or outcomes .

πŸ”§ Reference:
β†’ The IIA's Practice Guide: Measuring Internal Audit Effectiveness and Efficiency: Confirms that client-focused KPIs include the percentage of recommendations accepted by management and the timeliness of implementation, as these directly demonstrate the value and impact of audit work to stakeholders.

An internal auditor completed a consulting engagement covering a recent advertising campaign. The audit client asked the auditor to forward a copy of the report to one of the three advertising agencies used by the organization. According to IIA guidance, which of the following statements is true regarding this request?

A. The internal auditor may communicate the results to the advertising agency as instructed by the audit client, with approval from the chief audit executive.

B. The internal auditor may not communicate the results to this external party regardless of the engagement client's instruction.

C. The internal auditor may send the report and is required to include instructions for the advertising agency to limit further distribution and the use of results.

D. The internal auditor may only communicate the results verbally to the advertising agency and should not provide a hard copy.

A.   The internal auditor may communicate the results to the advertising agency as instructed by the audit client, with approval from the chief audit executive.

Explanation:

This question tests the auditor's understanding of the communication standards for consulting engagements, specifically regarding the dissemination of results to external parties. It requires identifying the correct authorization protocol required before sharing internal reports outside the organization.

βœ… Correct Option:

A. The internal auditor may communicate the results to the advertising agency as instructed by the audit client, with approval from the chief audit executive.
During consulting engagements, the internal audit activity must establish clear protocols for distributing results to external parties. While the audit client initiates the request, the chief audit executive must ultimately review and approve the dissemination to ensure that confidentiality is maintained, intellectual property is protected, and any potential organizational risks are carefully mitigated before release.

❌ Incorrect options:

B. The internal auditor may not communicate the results to this external party regardless of the engagement client's instruction.
This statement is overly restrictive. Internal auditing standards explicitly allow for the communication of consulting results to external parties, provided that the appropriate permissions are secured, risk assessments are completed, and organizational protocols are strictly followed by the internal audit activity.

C. The internal auditor may send the report and is required to include instructions for the advertising agency to limit further distribution and the use of results.
While limiting distribution is a standard practice when issuing assurance reports to external parties, consulting engagements operate under a different standard. The primary requirement for consulting is that the chief audit executive must explicitly approve the communication and manage the risk of sharing the information.

D. The internal auditor may only communicate the results verbally to the advertising agency and should not provide a hard copy.
There is no standard or restriction within internal auditing frameworks that mandates consulting results be shared only through verbal communication. The format of the shared information can be written or verbal, as long as it has been officially vetted and approved by the chief audit executive.

πŸ”§ Reference:
β†’ The IIA Performance Standard 2440.C2 confirms that during consulting engagements, communication of results to parties outside the organization is permissible only after the chief audit executive has given explicit approval.

An organization's finance manager plans to implement a state-of-the-art management system to better manage the organization's receivables. The finance manager consulted the chief audit executive (CAE) and asked for her assistance in determining whether the organization is able to accommodate this system. How would the CAE proceed to determine the objectives of this engagement

A. Ask the CEO to determine the scope and objectives of the engagement

B. Request that the board disclose its concerns over governance for inclusion in the engagement

C. Discuss the concerns with the finance manager and work together to agree on the engagement objectives

D. Review previous audit reports from the area and develop engagement objectives to address the area's key risks and controls

C.   Discuss the concerns with the finance manager and work together to agree on the engagement objectives

Explanation:

This question tests planning requirements for a consulting engagement. Unlike assurance engagements, consulting engagements are collaborative and are performed at the request of a client. Engagement objectives should be developed jointly with the client so the work addresses the client’s concerns while remaining consistent with organizational goals and internal audit responsibilities.

🟒 Correct Option:

C. Discuss the concerns with the finance manager and work together to agree on the engagement objectives.
For consulting engagements, internal auditors and the engagement client should mutually establish objectives before work begins. Since the finance manager requested assistance regarding the proposed management system, the CAE should discuss the business need, expectations, and concerns with the manager. This collaborative approach ensures the engagement addresses relevant risks and provides useful support without assuming management responsibility.

πŸ”΄ Incorrect options:

A. Ask the CEO to determine the scope and objectives of the engagement.
The CEO does not normally establish objectives for a consulting engagement requested by another manager. Objectives should be determined jointly between the internal audit activity and the engagement client.

B. Request that the board disclose its concerns over governance for inclusion in the engagement.
The board has oversight responsibilities, but it is not typically responsible for defining objectives for a consulting engagement involving operational decisions or system implementation.

D. Review previous audit reports from the area and develop engagement objectives to address the area's key risks and controls.
Reviewing prior reports can provide useful background information, but engagement objectives should not be developed independently without discussing the client's current needs and concerns.

πŸ”§ Reference:
β‡’ IIA Standards – Planning Consulting Engagements
Confirms that consulting engagement objectives should be agreed upon with the engagement client.

β‡’ IIA Practice Guide – Consulting Engagements
Confirms that consulting engagements involve collaboration between internal audit and the client.

Where should internal auditor focus their attention when identify and assessing key risks during the planning stage of an assurance engagement?

A. Sampling risk.

B. Audit risk.

C. Residual risk.

D. Inherent risk

D.   Inherent risk

Explanation:

During the planning stage of an assurance engagement, internal auditors focus on identifying and assessing the key risks that exist before controls are applied. This is the natural starting point for planning because it helps auditors determine where the greatest exposure exists and where engagement efforts should be directed.

βœ”οΈ Correct Option:

D. Inherent risk
Inherent risk is the level of risk that exists before management takes any action to reduce it. When planning an assurance engagement, the auditor should focus on these raw risks first because they show where the organization is most vulnerable. Understanding inherent risk helps the auditor prioritize areas, shape the scope, and design procedures that address the most significant exposures.

❌ Incorrect options:

A. Sampling risk
Sampling risk relates to the possibility that the sample selected is not representative of the population. It is an audit technique concern, not the main risk category the auditor should assess when planning the engagement.

B. Audit risk
Audit risk is the risk that the auditor gives an inappropriate opinion when the financial or control environment is misstated. It is important to audit quality, but it is not the key business risk the auditor is trying to identify at the planning stage.

C. Residual risk
Residual risk is the risk that remains after controls are applied. While it matters in risk assessment, planning starts with inherent risk so the auditor can understand the original exposure before evaluating how controls reduce it.

πŸ”§ Reference:
β†’ IIA Global Internal Audit Standards β€” supports risk-based planning and engagement focus on significant exposures.

Page 7 out of 72 Pages