Free IIA IIA-CIA-Part2 Practice Questions 2026 - Page 9
Ready for IIA-CIA-Part2 Exam?
This practice test is your final exam before the REAL exam
Dare to Take It?
Practice Questions
Which of the following is not a primary purpose for conducting a walk-through during the initial stages of an assurance engagement?
A. To help develop process maps.
B. To determine segregation of duties.
C. To identify residual risks.
D. To test the adequacy of controls.
Explanation:
This question tests the purpose of a walk-through during the early planning phase of an assurance engagement. A walk-through helps auditors understand how a process operates, identify key activities, and recognize possible risks and control points. It is mainly a process-understanding activity rather than detailed control testing.
🟢 Correct Option:
D. To test the adequacy of controls.
A walk-through is not primarily designed to determine whether controls are adequate or effective. Its purpose is to help auditors understand process flow, identify control points, and gain knowledge of operations before detailed testing begins. Actual control adequacy testing normally occurs later through substantive procedures and control testing activities during fieldwork.
đź”´ Incorrect options:
A. To help develop process maps.
Walk-throughs assist auditors in understanding how transactions and activities move through a process. This understanding helps create process maps and document workflows accurately.
B. To determine segregation of duties.
Walk-throughs can help identify whether responsibilities are separated appropriately among employees. Auditors may recognize incompatible duties and potential control weaknesses.
C. To identify residual risks.
Walk-throughs help auditors understand processes and recognize areas where risks may remain after existing controls are applied. This information supports engagement planning and risk assessment.
đź”§ Reference:
⇒ IIA Standards – Planning and Performing Internal Audit Engagements
Confirms that auditors obtain an understanding of processes and risks during engagement planning.
⇒ IIA Practice Guide – Engagement Planning
Confirms that walk-through activities support process understanding and risk identification.
According to IIA guidance, which of the following strategies would add the least value to the achievement of the internal audit activity's (IAA's) objectives?
A. Align organizational activities to internal audit activities and measure according to the approved IAA performance measures.
B. Establish a periodic review of monitoring and reporting processes to help ensure relevant IAA reporting.
C. Use the results of IAA engagement and advisory reporting to guide current and future internal audit activities.
D. Establish a format and frequency for IAA reporting that is appropriate and aligns with the organization's governance structure.
Explanation:
This question tests which strategy contributes the least to achieving the internal audit activity’s objectives. The most useful strategies are those that improve reporting quality, guide future audit work, and align communication with governance needs. Linking organizational activities to internal audit measures is less directly useful because it is broader and less focused on audit activity performance.
✔️ Correct Option:
A. Align organizational activities to internal audit activities and measure according to the approved IAA performance measures.
This adds the least value because it is too broad and does not directly improve the internal audit activity’s own objectives. Internal audit strategies should focus on reporting, monitoring, communication, and using audit results to guide future work. Measuring organizational activities against internal audit measures does not clearly strengthen the internal audit function itself.
❌ Incorrect options:
B. Establish a periodic review of monitoring and reporting processes to help ensure relevant IAA reporting.
This supports the internal audit activity because it helps maintain timely, relevant, and useful reporting. Regular review of reporting processes directly improves how the IAA communicates results and tracks progress.
C. Use the results of IAA engagement and advisory reporting to guide current and future internal audit activities.
This is valuable because audit results should inform future planning and focus areas. Using engagement and advisory outcomes helps the internal audit activity stay risk-based and responsive to stakeholder needs.
D. Establish a format and frequency for IAA reporting that is appropriate and aligns with the organization's governance structure.
This is important because reporting should match the governance structure and stakeholder expectations. Clear reporting format and timing improve communication and support oversight.
đź”§ Reference:
→ The IIA —
Performance Standards
— confirms that internal audit adds value through strategy, objectives, risk focus, and useful reporting.
→ The IIA —
Developing the Internal Audit Strategy
— supports aligning internal audit strategy with reporting, stakeholder needs, and future activities.
Besides a chief audit executive's professional experience what determines the frequency and approach to assessing residual risk?
A. The frequency of executing the internal audit engagements
B. The frequency of changes in the organization environment
C. The expectations set by the board and senior management
D. The expectations set by operating management and senior management
Explanation:
This question tests understanding of what shapes the CAE's approach to assessing residual risk beyond personal professional judgment. It focuses on the governance relationship between internal audit and its key oversight stakeholders in shaping risk assessment practices.
âś… Correct Option:
C. The expectations set by the board and senior management
The board and senior management set the tone for risk appetite, reporting expectations, and the depth of assurance required across the organization. Their expectations directly influence how often and how thoroughly the CAE assesses residual risk, since internal audit's risk assessment approach must align with governance priorities and the level of oversight these stakeholders expect from the internal audit function.
❌ Incorrect Options:
A. The frequency of executing the internal audit engagements
Engagement frequency is an outcome of the risk assessment process, not a driver of it. The internal audit plan is built based on residual risk ratings, so this option reverses the actual relationship between risk assessment and audit scheduling.
B. The frequency of changes in the organization environment
While organizational change can prompt a reassessment of risk, this factor is more about triggering updates rather than shaping the overall frequency and approach. It is a contributing input rather than the primary driver referenced in IIA guidance on residual risk assessment.
D. The expectations set by operating management and senior management
Operating management is responsible for managing risk at the process level, not setting the oversight expectations that shape internal audit's assessment approach. This governance responsibility belongs to the board and senior management, not operating management.
đź”§ Reference:
→ IIA Practice Guide: Developing a Risk-based Internal Audit Plan — confirms that the CAE communicates with senior management and the board to align expectations, which shapes how internal audit prioritizes and assesses residual risk.
A chief audit executive (CAE) reviews the supervision of an internal audit engagement Which of the following would most likely assure the CAE that the engagement had adequate supervision?
A. The engagement supervisor has an open door pokey for audit team members to discuss concerns
B. The supervisor reviews weekly progress reports from the audit team members
C. The supervisor reviews and initials internal audit workpapers for the engagement
D. The supervisor meets periodically with management in the reviewed area to get feedback during the engagement.
Explanation:
The question evaluates indicators of effective engagement supervision per IIA Standards. Supervision ensures work quality, adherence to standards, and achievement of objectives.
âś… Correct Option:
C. The supervisor reviews and initials internal audit workpapers for the engagement
Reviewing and initialing workpapers is a primary supervisory activity. It provides direct evidence that the supervisor evaluated the sufficiency of evidence, appropriateness of conclusions, and compliance with engagement standards.
❌ Incorrect options:
A. The engagement supervisor has an open door pokey for audit team members to discuss concerns
An open-door policy supports communication but does not demonstrate active supervision of work quality or documentation.
B. The supervisor reviews weekly progress reports from the audit team members
Progress reports are helpful for monitoring but are indirect and do not verify the detailed quality of audit evidence and conclusions.
D. The supervisor meets periodically with management in the reviewed area to get feedback during the engagement.
Management feedback is valuable for engagement outcomes but is not a core element of supervising the internal audit team’s work.
đź”§ Reference:
→ IIA Global Internal Audit Standards – Engagement Supervision – Requires supervisors to review workpapers to ensure quality and support conclusions.
→ IIA Practice Guide on Engagement Supervision – Emphasizes workpaper review as key evidence of adequate supervision.
Which of the following is a true statement regarding the use of flowcharts as an audit tool?
A. Flowcharts are typically not well suited to support information provided by a risk and control matrix.
B. Flowcharts are preferred to narratives, as they can provide much greater detail on the design and operation of a process.
C. Flowcharts are best applied to linear process flows but cannot address all risks related to the process.
D. Flowcharts describe process steps but cannot provide the level of detail needed to adequately assess the design of the process.
Explanation:
This question evaluates your understanding of the practical strengths and inherent limitations of flowcharts as a process-mapping tool used during internal audit engagements. While flowcharts are excellent for visually documenting linear sequences, they are not a standalone solution for comprehensive risk identification.
✔️ Correct Option:
C. Flowcharts are best applied to linear process flows but cannot address all risks related to the process.
This statement is accurate because flowcharts visually map sequential steps and decision points but do not inherently analyze or flag risks such as fraud, control gaps, or human errors. They are a diagnostic starting point, not a complete risk-assessment solution.
❌ Incorrect options:
A. Flowcharts are typically not well suited to support information provided by a risk and control matrix.
This is false. Flowcharts directly support risk and control matrices by visually mapping where controls are located, making them highly complementary and useful tools.
B. Flowcharts are preferred to narratives, as they can provide much greater detail on the design and operation of a process.
This is misleading. Narratives often provide richer descriptive detail, especially for complex processes with exceptions, while flowcharts offer visual clarity but not necessarily greater detail.
D. Flowcharts describe process steps but cannot provide the level of detail needed to adequately assess the design of the process.
This is incorrect. Flowcharts can provide sufficient detail—including decision points, documents, and handoffs—to effectively assess process design; they are a standard and accepted tool for this purpose.
đź”§ Reference:
→ Institute of Internal Auditors (IIA) Practice Guide: Flowcharting – Confirms flowcharts are used to document process flows and identify control points but are not a substitute for risk analysis.
A new internal auditor is overwhelmed by the number of tasks they need to complete at the engagement planning stage. Which of the following could support the auditor’s organization and delivery of planned work?
A. Review the auditor's job description
B. Create a checklist
C. Develop a control questionnaire
D. Prepare a fishbone diagram
Explanation:
This question tests the auditor's understanding of engagement planning tools used to manage workload and ensure operational efficiency. It requires identifying the most practical tool to help an individual auditor organize multiple required tasks and track the completion of planned work without omitting key steps.
âś… Correct Option:
B. Create a checklist
A checklist is a highly effective, practical tool that breaks down complex processes into discrete, actionable steps. For a new auditor managing a heavy workload during engagement planning, a checklist provides immediate structure, helps prioritize activities (such as scheduling interviews, gathering policies, and executing walk-throughs), and ensures all mandatory standards are consistently met.
❌ Incorrect options:
A. Review the auditor's job description
A job description outlines broad professional roles, general responsibilities, performance expectations, and organizational reporting hierarchies. While it defines the auditor's long-term function within the company, it does not provide the specific, tactical, or step-by-step task tracking required to execute and organize a localized audit planning phase.
C. Develop a control questionnaire
An internal control questionnaire is a specialized diagnostic tool used by auditors to gather information directly from the auditee regarding the design of business unit controls. While it is an important planning document for evaluating the risk environment under review, it does not organize or track the auditor's personal task list.
D. Prepare a fishbone diagram
A fishbone (or Ishikawa) diagram is a structured cause-and-effect visualization tool used during problem-solving to brainstorm and categorize the root causes of a specific operational failure. It is an analytical tool used during the fieldwork or reporting phases, not an organization tool for an auditor's daily planning tasks.
đź”§ Reference:
→ The IIA Standards Guidance on Engagement Planning Tools confirms that standardized templates and task checklists are essential for ensuring the completeness, consistency, and proper organization of preliminary audit activities.
A draft internal audit report that cites deficient conditions generally should be reviewed with
which of the following groups?
1. The client manager and her superior.
2. Anyone who may object to the report’s validity.
3. Anyone required to take action.
4. The same individuals who receive the final report.
A. 1 only
B. 1 and 2 only
C. 1, 2, and 3
D. 1, 2, and 4
Explanation:
This question tests communication practices during the reporting stage of an internal audit engagement. Draft reports are typically reviewed with appropriate parties before issuing the final report to verify accuracy, obtain management responses, and resolve disagreements. This process helps ensure findings are complete, fair, and supported by sufficient evidence.
🟢 Correct Option:
C. 1, 2, and 3
Draft reports should generally be reviewed with the client manager and management representatives responsible for the area being audited. Individuals who may challenge the report can provide clarification and supporting information, while persons responsible for corrective actions should participate because they will implement recommendations. This review process improves report accuracy and increases agreement on findings before final issuance.
đź”´ Incorrect options:
A. 1 only
Reviewing only with the client manager and superior is too limited. Other relevant parties, especially those who may provide clarification or take corrective action, may need involvement.
B. 1 and 2 only
This option excludes individuals responsible for corrective actions. Their involvement is important because they help develop realistic responses and implementation plans.
D. 1, 2, and 4
The same individuals who receive the final report do not necessarily need to participate in draft review discussions. Final report recipients can include broader audiences not directly involved in issue resolution.
đź”§ Reference:
⇒ IIA Standards – Communicating Results
Confirms that engagement communications should be accurate, complete, and discussed with appropriate parties.
⇒ IIA Practice Guide – Audit Reporting
Confirms the importance of discussing draft findings with relevant management before final report issuance.
Which of The following best describes a risk that is deemed "unacceptable" to the organization?
A. A risk where likelihood and impact are high
B. A risk where inherent risk exceeds its residual risk
C. A risk where inherent risk exceeds the tolerance level
D. A risk where residual risk exceeds the tolerance level
Explanation:
This question tests the difference between inherent risk, residual risk, and risk tolerance. A risk becomes unacceptable when the amount of risk left after controls are applied is still above the organization’s tolerance level. That means the organization cannot reasonably accept it without further treatment.
✔️ Correct Option:
D. A risk where residual risk exceeds the tolerance level
Residual risk is what remains after controls are in place. If that remaining risk is still above the organization’s tolerance level, then the organization considers it unacceptable because the exposure is still too high. In practice, this means management must take additional action such as strengthening controls, transferring the risk, or avoiding the activity.
❌ Incorrect options:
A. A risk where likelihood and impact are high
High likelihood and high impact may indicate a serious risk, but that alone does not define it as unacceptable. The key test is whether the risk exceeds the organization’s tolerance after controls are applied.
B. A risk where inherent risk exceeds its residual risk
This is normal and expected because controls should reduce risk. It does not mean the risk is unacceptable; it only shows that the controls are having some effect.
C. A risk where inherent risk exceeds the tolerance level
Inherent risk is the starting risk before controls. Organizations usually judge acceptability based on residual risk, not inherent risk alone, because controls are part of the real operating environment.
đź”§ Reference:
→ The IIA — Standard 2600: Communicating the Acceptance of Risks — confirms that internal audit considers whether management accepts risks within tolerance.
→ The IIA — Global Internal Audit Standards — supports evaluating risks in relation to organizational objectives and risk tolerance.
In which scenario might it be considered problematic for the chief audit executive (CAE) to provide assurance services over the payroll function?
A. The CAE previously undertook a consulting assignment in that area to improve processes.
B. A couple of years ago, the CAE performed accounting functions for the payroll department.
C. Prior to becoming the CAE, the CAE was the payroll manager.
D. The assurance review was initiated following issues identified during a consulting assignment requested by management.
Explanation:
This question tests understanding of when a CAE's prior operational role creates an objectivity impairment under IIA guidance. It focuses on identifying which past involvement in the payroll function directly conflicts with the standard that auditors should not review activities for which they previously held responsibility.
âś… Correct Option:
C. Prior to becoming the CAE, the CAE was the payroll manager
Objectivity is presumed impaired when an internal auditor provides assurance over an area they previously managed, particularly in a direct operational capacity. As former payroll manager, the CAE held ownership of the processes and controls now under review, creating a self-review threat and a real risk of biased judgment regarding past decisions and practices within that function.
❌ Incorrect Options:
A. The CAE previously undertook a consulting assignment in that area to improve processes
IIA guidance permits assurance services following prior consulting work, provided the consulting did not impair objectivity and individual objectivity is properly managed. This scenario does not automatically create an impairment, since consulting roles are distinct from direct operational responsibility.
B. A couple of years ago, the CAE performed accounting functions for the payroll department
Objectivity impairment is generally presumed only for responsibilities held within the previous year. Since this involvement occurred a couple of years earlier, sufficient time has passed for the concern to be less significant compared to a direct managerial role held immediately before becoming CAE.
D. The assurance review was initiated following issues identified during a consulting assignment requested by management
This describes a normal, appropriate sequence where consulting work leads to a follow-up assurance review. It does not represent a conflict of interest, since the CAE is responding to management's request rather than reviewing an area of prior personal responsibility.
đź”§ Reference:
→ IIA Attribute Standards – Standard 1130 — confirms objectivity is presumed impaired when providing assurance over an activity for which the auditor had prior direct responsibility.
According to IIA guidance, which of the following statements is true regarding reporting the results of the quality assurance and improvement program?
A. Results of internal assessments need to be reported to the board at least once every five years.
B. The external assessor must present the findings from the external assessment to senior management and the board upon completion.
C. Deficiencies within the internal audit activity must be reported to the board as soon as they are noted
D. Results of ongoing monitoring of the internal audit activity’s performance must be reported to senior management and the board at least annually
Explanation:
This question tests your understanding of the reporting requirements for the Quality Assurance and Improvement Program (QAIP) under IIA guidance. The Standards establish clear timelines for communicating different types of quality assessment results to the board and senior management.
✔️ Correct Option:
D. Results of ongoing monitoring of the internal audit activity's performance must be reported to senior management and the board at least annually.
This is correct per IIA Standard 1320. The interpretation of this standard specifies that "the results of ongoing monitoring are communicated at least annually" to demonstrate conformance with the Standards . Ongoing monitoring is a key component of internal assessments and requires regular reporting .
❌ Incorrect options:
A. Results of internal assessments need to be reported to the board at least once every five years.
This is incorrect. The five-year requirement applies to external assessments, not internal assessments. Internal assessment results must be reported at least annually .
B. The external assessor must present the findings from the external assessment to senior management and the board upon completion.
This is not a mandatory requirement. While the CAE must communicate external assessment results, the Standards do not mandate that the external assessor personally present the findings .
C. Deficiencies within the internal audit activity must be reported to the board as soon as they are noted.
This is incorrect. Only nonconformance that impacts the overall scope or operation of the internal audit activity requires disclosure to the board (Standard 1322). Not all deficiencies trigger immediate reporting .
đź”§ Reference:
→ IIA Standard 1320: Reporting on the Quality Assurance and Improvement Program – Confirms the CAE must communicate QAIP results, with ongoing monitoring results reported at least annually.
| Page 9 out of 72 Pages |