Free IIA IIA-CIA-Part2 Practice Questions 2026 - Page 8
Ready for IIA-CIA-Part2 Exam?
This practice test is your final exam before the REAL exam
Dare to Take It?
Practice Questions
Which of the following statements about assurance maps is correct?
A. An assurance map is used by the chief audit executive to coordinate assurance activities with other internal and external assurance providers
B. An assurance map is a picture of all assurance engagements performed by the internal audit activity across the organization
C. An assurance map is used by the engagement supervisor to coordinate the roles of various internal audit team members assigned to assurance engagements
D. An assurance map lists the procedures and testing activities performed by an internal audit team during an assurance engagement
Explanation:
This question tests understanding of what an assurance map is and how it supports the chief audit executive's coordination responsibilities. It distinguishes the assurance map's true purpose from other engagement-level or internal-audit-only documentation.
✅ Correct Option:
A. An assurance map is used by the chief audit executive to coordinate assurance activities with other internal and external assurance providers
An assurance map is a matrix linking key organizational risks to all internal and external providers covering those risks, including risk management, compliance, and external auditors. The CAE uses this visual tool to identify coverage gaps and duplications, then coordinates timing and scope with other providers, supporting Standard 2050 requirements for coordination and reliance across the organization's assurance functions.
❌ Incorrect Options:
B. An assurance map is a picture of all assurance engagements performed by the internal audit activity across the organization
This describes only the internal audit activity's own engagements, which understates the tool's actual scope. An assurance map extends beyond internal audit to include other internal and external assurance providers, making this option incomplete.
C. An assurance map is used by the engagement supervisor to coordinate the roles of various internal audit team members assigned to assurance engagements
This describes engagement-level staffing and supervision, which is unrelated to assurance mapping. Assurance maps operate at the organizational level, addressing risk coverage across multiple providers rather than individual team member assignments within a single engagement.
D. An assurance map lists the procedures and testing activities performed by an internal audit team during an assurance engagement
This describes an audit program or engagement work plan, not an assurance map. Assurance maps focus on risk coverage across assurance providers organization-wide, not the specific testing steps performed during a single engagement.
🔧 Reference:
→ IIA Practice Guide: Coordination and Reliance – Developing an Assurance Map — confirms an assurance map is a matrix of organizational risks and all internal and external assurance providers covering those risks, used to coordinate activities and expose coverage gaps.
Which of the following best demonstrates that the internal audit activity is using due professional care?
A. The internal audit activity reports directly to the board on the engagements it performs.
B. Internal auditors undertake the necessary training to complete their audit work.
C. The completion of engagements is based on the assumption that fraudulent activities may exist.
D. Internal auditors consider the use of technology-based audit and other data analysis techniques
Explanation:
The question tests understanding of due professional care as defined in IIA Standards. Due professional care requires applying the care and skill expected of a reasonably prudent and competent internal auditor.
✅ Correct Option:
D. Internal auditors consider the use of technology-based audit and other data analysis techniques
This demonstrates due professional care by leveraging appropriate tools and methods to enhance efficiency, effectiveness, and coverage of audit work, aligning with the requirement to use suitable techniques based on the engagement’s nature and risks.
❌ Incorrect options:
A. The internal audit activity reports directly to the board on the engagements it performs.
This reflects organizational independence and reporting lines but does not specifically demonstrate due professional care in performing engagements.
B. Internal auditors undertake the necessary training to complete their audit work.
Training supports proficiency but is only one element; due professional care encompasses broader application of skills and judgment during engagements.
C. The completion of engagements is based on the assumption that fraudulent activities may exist.
Assuming fraud in all engagements goes beyond reasonable professional skepticism and is not a requirement of due professional care.
🔧 Reference:
→ IIA Global Internal Audit Standards – Due Professional Care – Requires using appropriate audit techniques, including technology where suitable.
→ IIA Practice Guide on Due Professional Care – Emphasizes application of competent methods and tools.
An organization facing financial hardships is planning to reduce its internal audit function size without a reduction in workload. The organization plans to aid internal auditors by providing a generative artificial intelligence application that will process written responses from the activity under review to identify high-risk areas on which the remaining auditors will concentrate. Which of the following would be the most significant concern in this process?
A. Slight variations in answers can result in very different risk assessments
B. Generative artificial intelligence cannot make inferences out of free text responses
C. Replacing auditor judgment with machine judgment is contrary to the Global Internal Audit Standards
D. Poor acceptance of the new system by the activity under review will impact engagement outcomes
Explanation:
This question assesses the most significant risk when integrating generative AI into internal audit processes to compensate for staff reductions. The core issue is maintaining the fundamental principles of the internal audit profession when technology is used to automate critical analysis. While several options present valid concerns, the most severe risk is the fundamental erosion of professional judgment, which is a cornerstone of the Global Internal Audit Standards.
✔️ Correct Option:
C. Replacing auditor judgment with machine judgment is contrary to the Global Internal Audit Standards
This is the most significant concern because the profession's standards are built on the principle of reasonable assurance, which depends on professional judgment and skepticism. The Global Internal Audit Standards emphasize performance, which relies on human interpretation and oversight. The ethical use of AI in internal audit requires that technology enhances, not replaces, human judgment to maintain objectivity. All guidance on AI in internal audit stresses that AI tools should support auditors, not make autonomous decisions, to uphold audit independence and credibility.
❌ Incorrect Options:
A. Slight variations in answers can result in very different risk assessments
While this is a recognized risk of using generative AI, particularly with free-text prompts, it is a technical challenge of implementation. This issue can be managed through careful prompt engineering, verification, and testing of results. It is a significant concern but does not undermine the foundational principles of the audit profession as fundamentally as option C does.
B. Generative artificial intelligence cannot make inferences out of free text responses
This is factually incorrect. Generative AI models are specifically designed to process natural language and identify patterns, which is the exact capability the organization intends to leverage. The inability to process free text is not a limitation of the technology, making this a poor choice.
D. Poor acceptance of the new system by the activity under review will impact engagement outcomes
While stakeholder engagement is vital for audit performance, lack of acceptance is a change management issue that can be addressed through training and communication. This is a practical, manageable challenge and does not pose the same existential risk to the auditor's professional role and the validity of the audit as replacing human judgment.
🔧 Reference:
→ The IIA's Artificial Intelligence Auditing Framework: Provides structured guidance that emphasizes the need for internal auditors to audit AI risks and maintain reasonable assurance, which depends on human judgment, objectivity, and transparency.
An organization invests excess short-term cash in trading securities Which of the following actions should an internal auditor take to test the valuation of those securities
A. Use the equity method to recalculate the investment carrying value
B. Confirm the securities held by the broker.
C. Perform a calculation of premium or discount amortization.
D. Compare the carrying value with current market quotations
Explanation:
This question tests the auditor's knowledge of substantive testing procedures for financial instruments. Specifically, it requires identifying the appropriate audit procedure to verify the valuation of trading securities, which must be reported at fair value under standard accounting frameworks.
✅ Correct Option:
D. Compare the carrying value with current market quotations
Trading securities are short-term investments held for active buying and selling, and accounting standards mandate that they be recorded at fair value on the balance sheet. To test their valuation, the auditor must independently verify their year-end market prices by comparing the recorded carrying value against active, publicly available current market quotations or official exchange listings.
❌ Incorrect options:
A. Use the equity method to recalculate the investment carrying value
The equity method is used only when an investor exerts significant influence over an investee, typically holding between 20% to 50% of the voting stock. Short-term trading securities represent minor, passive investments, making the equity method completely inapplicable for their valuation.
B. Confirm the securities held by the broker.
Sending a confirmation to an external broker is an effective audit procedure, but it primarily tests the assertions of existence and rights/obligations. It proves that the organization actually owns the investments, not that the market valuation recorded in the ledger is accurate.
C. Perform a calculation of premium or discount amortization.
Amortization of premiums or discounts applies strictly to held-to-maturity debt securities, where the investment is held long-term to collect contractual cash flows. Trading securities are focused on short-term capital gains, so amortized cost tracking is not used.
🔧 Reference:
→ The IIA Global Financial Auditing Guidance confirms that substantive testing for the valuation of liquid investment securities requires comparing recorded book values to independent third-party market price feeds.
Which of the following actions should the chief audit executive take when senior management decides to accept risks by choosing to do business with a questionable vendor?
A. Persuade senior management to take appropriate action.
B. Cancel issuing the engagement report due to the assumed risks.
C. Accept senior management’s assumption of the risks.
D. Discuss the issue with the board for them to take appropriate action.
Explanation:
This question tests the chief audit executive’s (CAE) responsibility when management accepts a level of risk that may be unacceptable to the organization. According to IIA guidance, if the CAE believes management has accepted a risk beyond the organization's risk tolerance, the matter should be escalated to the board for resolution.
🟢 Correct Option:
D. Discuss the issue with the board for them to take appropriate action.
When senior management accepts a risk that the CAE believes exceeds the organization’s risk appetite or tolerance, the CAE should elevate the issue to the board. The board provides oversight of risk management and governance activities. Escalation ensures that significant risks receive appropriate review and allows the board to determine whether the accepted risk aligns with organizational objectives.
🔴 Incorrect options:
A. Persuade senior management to take appropriate action.
The CAE may discuss concerns with management, but persuasion alone is not the required action if management still chooses to accept an unacceptable level of risk.
B. Cancel issuing the engagement report due to the assumed risks.
The presence of accepted risk does not justify canceling or withholding an audit report. Significant findings and concerns should still be communicated appropriately.
C. Accept senior management’s assumption of the risks.
The CAE should not automatically accept management’s decision if the risk level appears to exceed organizational tolerance. Significant concerns require escalation when necessary.
🔧 Reference:
⇒ Global Internal Audit Standards – Escalating Risk Acceptance
Confirms that the CAE should discuss risk matters with the board when management accepts unacceptable risks.
⇒ IIA Position Paper – The Three Lines Model
Confirms the board’s oversight role in governance and risk management activities.
Which is the most appropriate evaluation criterion regarding the quality of audit engagement workpapers?
A. Every workpaper should provide reasonable evidence of work conducted.
B. Every workpaper should result in appropriately worded audit findings.
C. Every workpaper should include a conclusion regarding the likelihood of fraud.
D. Every workpaper should be approved by the engagement client.
Explanation:
This question tests the basic quality standard for audit workpapers. Good workpapers should clearly show what work was performed, support the conclusions reached, and allow another reviewer to understand the audit trail. The main criterion is whether the documentation provides sufficient evidence of the procedures performed.
✔️ Correct Option:
A. Every workpaper should provide reasonable evidence of work conducted.
This is the most appropriate criterion because audit workpapers must document the procedures performed and support the observations and conclusions reached. A strong workpaper should show enough detail for a reviewer to understand what was done, when it was done, and what evidence supports the result. That is the core measure of workpaper quality.
❌ Incorrect options:
B. Every workpaper should result in appropriately worded audit findings.
Workpapers support findings, but not every workpaper must produce a finding. Some workpapers simply document background, planning, sampling, or test results without leading to a formal audit issue.
C. Every workpaper should include a conclusion regarding the likelihood of fraud.
Fraud evaluation is important when relevant, but it is not required in every workpaper. Many workpapers cover routine controls or operational testing and do not need a fraud conclusion.
D. Every workpaper should be approved by the engagement client.
Client approval is not the standard for workpaper quality. Workpapers are prepared for the internal audit function and reviewed by audit management, not validated by the client as a rule.
🔧 Reference:
→ The IIA — Global Internal Audit Standards — confirms the official internal audit standards framework.
During the review of an organization's retail fraud deterrence program, an employee mentions that an expensive fraud surveillance information system is rarely used. The internal auditor concludes that additional staff are required to properly utilize the system to its full potential. According to IIA guidance, which criteria for evidence is most lacking to reach this conclusion?
A. Sufficiency.
B. Reliability.
C. Relevancy.
D. Usefulness.
Explanation:
This question tests understanding of the evidence criteria under IIA guidance — sufficiency, reliability, relevancy, and usefulness — and which one is missing when a conclusion is drawn from a single, uncorroborated source. It focuses on identifying gaps in the evidence-gathering process before reaching a conclusion.
✅ Correct Option:
A. Sufficiency
A single employee's comment is not enough evidence to support the conclusion that additional staff are needed. Sufficiency requires enough factual, adequate evidence for a prudent, informed person to reach the same conclusion. Additional corroboration, such as system usage logs, staffing analysis, or discussions with fraud unit supervisors, would be needed to substantiate the claim before it is deemed sufficient.
❌ Incorrect Options:
B. Reliability
The employee's testimony is a legitimate source of testimonial evidence and is not inherently unreliable in this context. The issue is not that the information cannot be trusted, but that there simply isn't enough of it to support the auditor's specific staffing conclusion.
C. Relevancy
The comment about the surveillance system being underused is directly related to the fraud deterrence program under review. Relevancy is not the concern here, since the information logically connects to the engagement objective; the shortfall lies in the quantity of evidence gathered.
D. Usefulness
Usefulness refers to whether evidence helps the organization meet its goals, which is not the limiting factor in this scenario. The comment could be useful if corroborated, but the auditor's conclusion fails primarily because more evidence is needed, not because the information lacks practical value.
🔧 Reference:
→ IIA Standard 2310 – Identifying Information — requires internal auditors to identify sufficient, reliable, relevant, and useful information to achieve engagement objectives.
An internal auditor conducted interviews with several employees, documented the interviews analyzed the summaries, and drew a number of conclusions. What sort of audit evidence has the internal auditor primarily obtained?
A. Documentary evidence
B. Testimonial evidence
C. Analytical evidence
D. Physical evidence
Explanation:
The question tests classification of audit evidence types. Internal auditors gather various forms of evidence to support conclusions during engagements.
✅ Correct Option:
B. Testimonial evidence
Testimonial evidence consists of statements or information obtained through interviews or inquiries. The auditor’s interviews, documentation of responses, summaries, and derived conclusions are primarily based on oral or written statements from employees.
❌ Incorrect options:
A. Documentary evidence
Documentary evidence involves written records, reports, or data files, not information gathered through direct interviews.
C. Analytical evidence
Analytical evidence results from evaluations, comparisons, or calculations of data (e.g., ratios or trends), not from interview summaries.
D. Physical evidence
Physical evidence includes tangible items observed or inspected (e.g., inventory or assets), which was not obtained here.
🔧 Reference:
→ IIA Global Internal Audit Standards – Gathering Information – Classifies testimonial evidence as information from inquiries and interviews.
→ IIA Practice Guide on Engagement Information – Describes types of evidence and their use in forming conclusions.
'Internal policy prohibits employees from entering into contacts with financial obligations
without proper approval.
A project manager signed a change to an important service agreement without obtaining
the proper approval As a result the organization is receiving $5,000 per month less for its
services.’’
Which of the following should be added to the observation?
A. The reason for not following the internal policy
B. A description of what constitutes proper approval
C. The annual impact of the changed agreement on cash flows
D. Details regarding when the change to the agreement was signed
Explanation:
The question asks which information should be added to an audit observation. Observations are structured using the 5C model: Criteria, Condition, Cause, Consequence (Effect), and Corrective Action/Recommendation . The observation currently states the Condition ($5,000 monthly loss) and the Cause (lack of approval). Quantifying the financial impact addresses the Consequence/Effect element, which is considered essential to complete an audit finding and make it persuasive .
✔️ Correct Option:
C. The annual impact of the changed agreement on cash flows.
An observation must include the Effect, which is the risk or exposure caused by the condition . The current observation states a monthly loss of $5,000. Quantifying this as a **$60,000 annual impact** transforms a detail into a compelling consequence that demonstrates materiality and urgency to management, which is essential for persuasive reporting .
❌ Incorrect Options:
A. The reason for not following the internal policy.
This addresses the Cause of the issue. While the Cause is a required element (explaining why the gap exists) , the scenario states "without obtaining approval" but does not imply this reason is unknown. The question is about adding to the observation, and the primary missing element is the quantified impact to strengthen the report .
B. A description of what constitutes proper approval.
This describes the Criteria (what should exist), which is a benchmark against which the condition is evaluated . While necessary for an audit, this is usually set as the basis of the audit (the internal policy) rather than a detail to add to a final observation where the policy has already been cited.
D. Details regarding when the change to the agreement was signed.
This is a contextual detail about the Condition (what happened) . While the date might be recorded in workpapers, it does not help management understand the severity or priority of the issue. Adding the date does not fulfill the requirement to quantify risk or impact as effectively as calculating the annual financial loss .
🔧 Reference:
→ IIA Practice Advisory 2410-1 - Communication Criteria: Confirms that engagement observations must be based on the elements of Criteria, Condition, Cause, and Effect (impact) .
→ IIA Practice Guide - Audit Reports: States observations should include the Effect (risk or exposure) to provide clarity and materiality to the issue. It recommends quantifying the condition where possible .
Which of the following recognized competitive strategies focuses on gaining efficiencies?
A. Focus
B. Cost leadership.
C. Innovation
D. Differentiation
Explanation:
This question tests the understanding of Michael Porter's generic competitive strategies. It requires identifying which strategic approach relies primarily on maximizing operational efficiencies and minimizing production expenses to achieve a competitive advantage in the marketplace.
✅ Correct Option:
B. Cost leadership.
The cost leadership strategy focuses on becoming the lowest-cost producer within an industry. To achieve this, an organization must aggressively pursue operational efficiencies, exploit economies of scale, minimize overhead expenses, and eliminate waste across its entire supply chain, allowing it to maintain profitability while offering highly competitive, low prices to consumers.
❌ Incorrect options:
A. Focus
A focus strategy concentrates entirely on serving a narrow, specialized market niche or specific demographic segment. While a company using this approach can choose to pursue either a cost focus or a differentiation focus within that small niche, the strategy itself is defined by its targeted scope rather than an organization-wide drive for efficiency.
C. Innovation
An innovation strategy focuses on creating completely new products, cutting-edge technologies, or pioneering business models to lead the market. This approach requires heavy investments in research and development and a high tolerance for experimentation, which prioritizes speed-to-market and creativity over driving down day-to-day operational efficiencies.
D. Differentiation
A differentiation strategy aims to create unique products or services that customers perceive as distinct, premium, and superior to competitors' offerings. Because this approach relies heavily on brand building, high-quality materials, and exceptional customer service, companies often incur higher operational costs rather than focusing on strict internal efficiencies.
🔧 Reference:
→ The IIA Business Acumen Guidance confirms that a cost leadership strategy relies fundamentally on maximizing internal process efficiencies and cost controls to maintain a competitive market position.
| Page 8 out of 72 Pages |