Free IIA IIA-CRMA-ADV Practice Questions 2026 - Page 10
Ready for IIA-CRMA-ADV Exam?
This practice test is your final exam before the REAL exam
Dare to Take It?
Practice Questions
Topic 1: Exam Pool A
This chief audit executive (CAE) engaged an internal auditor to consult on an organization's complex information technology system. Shortly after beginning the engagement, the auditor unexpectedly resigned. Unfortunately, this auditor was the only available auditor with the necessary expertise. The CAE will not be able to hire someone with similar expertise in time to meet a regulatory deadline. Which of the following would be the best course of action for the CAE to take?
A. Continue with the engagement in order to meet the regulatory deadline, but highlight areas in the final report that might need to be revised in the future.
B. Ask that a senior member of the organization's IT department with the required systems expertise join the audit team to assist in completing the engagement.
C. Delay the engagement and inform the board of the situation, asking them to provide acceptable alternatives for completing the engagement.
D. Remove the planned engagement from the audit plan and explain to senior management the problems with moving forward without an auditor with the necessary expertise.
Explanation:
This scenario presents a direct conflict between a regulatory deadline and the internal audit activity’s (IAA) proficiency requirements. Standard 1210 – Proficiency mandates that internal auditors must possess the knowledge, skills, and competencies needed to perform their responsibilities. When this expertise is lacking, Standard 1210.A1 requires the CAE to “obtain competent advice and assistance”. If this cannot be achieved, Implementation Standard 1210.C1 explicitly states that the CAE must decline the consulting engagement if the internal auditors lack the necessary competencies.
Why Other Options Are Incorrect:
A. Continue with the engagement but highlight areas needing revision:
Proceeding with an audit when the IAA lacks the required proficiency violates the Standards and risks producing unreliable results. The CAE has a duty to ensure proficiency, not to deliver work with known deficiencies.
B. Ask a senior member of the IT department to join the audit team:
While the Standards allow for using experts from within the organization to fill gaps, this option fails to address the core problem. The IT staff member is not an internal auditor and would not have the audit competencies required for the engagement, likely leading to an impaired assessment.
C. Delay the engagement and ask the board for alternatives:
While the CAE must communicate significant issues to the board, the immediate decision to remove the engagement due to a deficiency in expertise lies with the CAE. The CAE then informs senior management and the board of the impact of this resource limitation.
References:
IIA Standard 1210 – Proficiency:Internal auditors must possess the knowledge, skills, and other competencies needed to perform their individual responsibilities.
IIA Standard 1210.A1: The CAE must obtain competent advice and assistance if the internal auditors lack the knowledge, skills, or other competencies needed to perform all or part of the engagement.
According to the Standards, which of the following best describes why initial audit test results should be reported to the auditor-in-charge prior to advising management?
A. It increases the likelihood of obtaining the audit client's agreement with the results.
B. It ensures that an appropriate chain of evidence is maintained through the workpapers.
C. It helps ensure that appropriate professional judgments and conclusions are made.
D. It is required to demonstrate that effective engagement supervision has occurred.
Explanation:
The primary reason for reporting initial audit test results to the auditor-in-charge before advising management is rooted in the principle of engagement supervision. This process is designed to ensure that the work performed is of high quality and that the conclusions drawn are sound.
Quality Assurance and Professional Judgment: The core purpose of supervision, as defined by IIA Standard 2340, is to ensure objectives are achieved, quality is assured, and staff is developed . The supervisor, typically the auditor-in-charge, evaluates whether the information, testing, and results are sufficient and reliable to support the engagement conclusions . This includes reviewing preliminary conclusions to confirm they are logical, supported by evidence, and free from bias . Reporting results to the supervisor first allows for an objective review, ensuring that the final advice given to management is based on appropriate professional judgment .
Why Other Options Are Incorrect:
A. Increases the likelihood of client agreement:
While a supervisor's review might strengthen the report, obtaining client agreement is not the primary objective of this standard. The goal is to ensure the results themselves are correct and properly supported.
B. Ensures an appropriate chain of evidence:
The chain of evidence is maintained through the proper documentation of workpapers (Standard 2330), not specifically by reporting results to a supervisor before talking to management .
D. Required to demonstrate effective supervision:
While the supervisor's review is a key part of demonstrating effective supervision (e.g., through initials on workpapers), the reason the review is required is to ensure the quality and accuracy of the auditor's judgments and conclusions, not just to check a box for compliance .
References:
IIA Standard 2340 – Engagement Supervision: Engagements must be properly supervised to ensure objectives are achieved, quality is assured, and staff is developed .
Implementation Guide 2340: The supervisor evaluates whether the information, testing, and results are sufficient, reliable, and relevant to support conclusions. The CAE is responsible for all significant professional judgments made during engagements .
An internal audit manager of a furniture manufacturing organization is planning an audit of the procurement process for kiln-dried wood. The procurement department maintains six procurement officers to manage 24 different suppliers used by the organization. Which of the following controls would best mitigate the risk of employees receiving kickbacks from suppliers?
A. The periodic rotation of procurement officers' assignments to supplier accounts.
B. A pre-award financial capacity analysis of suppliers.
C. An automated computer report, organized by supplier, of any invoices for the same amount.
D. Periodic inventories of kiln-dried wood at the organization's warehouse.
Explanation:
The risk of employees receiving kickbacks from suppliers is a significant fraud risk in procurement. Kickbacks typically occur when a procurement officer develops a close, long-term relationship with a supplier and begins to favor them (e.g., awarding contracts, approving inflated prices, or accepting substandard goods) in exchange for personal benefits. By periodically rotating procurement officers' assignments to different supplier accounts, the organization reduces the opportunity for such relationships to develop and persist. Rotation disrupts the familiarity and collusive environment that enables kickbacks, making it harder for a procurement officer to establish and maintain an ongoing corrupt arrangement with a specific supplier. This is a key preventive control.
Why the other options are incorrect:
B. A pre-award financial capacity analysis of suppliers:
This is a control to assess a supplier's ability to perform under a contract, not to detect or prevent kickbacks. It addresses supplier reliability, not employee integrity.
C. An automated computer report, organized by supplier, of any invoices for the same amount:
While this can identify duplicate invoices or unusual patterns, it is not specifically designed to detect kickbacks. Kickbacks are typically not reflected in identical invoice amounts; they involve inflated prices, fictitious services, or preferential treatment. This is a detective control that may catch some anomalies but does not address the root collusion risk.
D. Periodic inventories of kiln-dried wood at the organization's warehouse:
This is a control over the existence and condition of inventory, not over procurement relationships. It detects theft or misappropriation of physical assets, not kickbacks or vendor collusion.
References:
IIA Standard 2130 – Control: Requires internal auditors to evaluate the effectiveness of controls, including those designed to prevent and detect fraud.
IIA Practice Guide – "Auditing Procurement and Vendor Management": Recommends rotation of procurement staff as a control to reduce the risk of collusion and kickbacks.
Which of the following does not need to be defined in the internal audit charter?
A. The audit engagements to be performed during the upcoming year.
B. The internal audit activity's position within the organization.
C. The scope of internal audit activities.
D. Management and the board of directors' agreement regarding the roles and responsibilities of the internal audit activity.
Explanation:
The internal audit charter is a formal, high-level document that defines the activity's purpose, authority, and responsibility . Its role is to establish the internal audit activity's position within the organization and define the broad scope of its work . The upcoming year's specific audit engagements are detailed in a separate, dynamic annual audit plan, not the foundational charter .
Why the other options are incorrect
The charter provides the foundational framework and establishes the "rules of engagement." Here is why the other options are essential elements of that framework:
B. The internal audit activity's position within the organization: The charter must establish the activity's standing, including its reporting lines and access to records and personnel .
C. The scope of internal audit activities: The charter defines the scope and nature of the audit work, including the types of assurance and consulting services to be provided .
D. Agreement regarding roles and responsibilities: The charter acts as a formal, board-approved agreement on the roles and responsibilities of the internal audit activity, management, and the board .
References:
IIA Standard 1000 – Purpose, Authority, and Responsibility: The charter defines the activity's purpose, authority, and responsibility .
IIA Implementation Guide 1000: The charter establishes the activity's position and defines the scope of its work .
Why is a code of ethics for the internal audit profession necessary?
A. It ensures that all members of the profession possess the same level of competence.
B. It provides auditors with protection from lawsuits.
C. It guides internal auditors in their service to others.
D. It requires auditors to exhibit loyalty to their organizations.
Explanation:
A code of ethics is essential for the internal audit profession because it provides a framework of principles and rules that guide internal auditors in their professional conduct and decision-making. The IIA's Code of Ethics establishes the foundational principles of Integrity, Objectivity, Confidentiality, and Competency. These principles are designed to guide auditors in serving the interests of their organizations, stakeholders, and the public by ensuring their work is performed with honesty, impartiality, and professionalism. The code serves as a moral compass, helping auditors navigate complex situations and maintain trust in the profession.
Why the other options are incorrect:
A. It ensures that all members of the profession possess the same level of competence:
Incorrect. The Code of Ethics sets standards for professional conduct, not for technical competence. Competence is addressed through professional certifications, continuing education, and proficiency standards (Standard 1210).
B. It provides auditors with protection from lawsuits:
Incorrect. A code of ethics does not protect auditors from legal liability. It establishes standards of behavior, not legal immunity.
D. It requires auditors to exhibit loyalty to their organizations:
Incorrect. While internal auditors serve their organizations, the Code of Ethics emphasizes objectivity, integrity, and professional responsibility—not blind loyalty. Auditors must remain independent and report facts truthfully, even if it is unfavorable to management.
References
IIA Code of Ethics – Preamble:States that the Code is necessary for the internal audit profession because it "provides guidance and promotes ethical behavior" and "describes the expectations of stakeholders."
IIA Code of Ethics – Principles: Defines the four principles—Integrity, Objectivity, Confidentiality, and Competency—as the foundation for professional conduct.
In which of the following scenarios would a customer service hotline receive a high volume of complaints regarding payments not being applied to customers’ accounts?
A. Invoices are not being mailed to customers.
B. An employee is tampering with customer checks.
C. Employees are submitting fraudulent expense reports.
D. The customer service department is not forwarding complaints to the accounts receivable department.
Explanation:
The scenario describes a high volume of customer complaints specifically about payments not being applied to their accounts. When customers pay their bills, they expect their accounts to be credited. If payments are not being applied, customers will call to inquire or complain.
Why the other options are incorrect:
B. An employee is tampering with customer checks:
This would result in theft of cash, but it would typically lead to complaints about missing payments or checks being cashed incorrectly, not about "payments not being applied." The customer's check would be processed but stolen, leading to a different type of complaint.
C. Employees are submitting fraudulent expense reports:
This is a scheme involving internal employees, not customer accounts. It would not generate complaints from external customers about their payments not being applied.
D. The customer service department is not forwarding complaints:
This would mean complaints are not reaching accounts receivable, but it does not explain why payments are not being applied. If payments are not being applied but complaints are not forwarded, the number of complaints reaching AR would be low—the opposite of the "high volume" described.
References:
IIA Standard 2130 – Control: Requires internal auditors to evaluate the effectiveness of controls, including billing and accounts receivable processes.
IIA Practice Guide – "Auditing Accounts Receivable": Identifies failure to send invoices as a key control deficiency that can lead to unapplied cash, customer disputes, and revenue misstatement.
While attending a conference, an internal auditor won an all-expense paid trip sponsored
by a vendor of the internal auditor's organization.
Which of the following actions are most appropriate for the auditor to take?
A. Consult with an immediate supervisor and notify the organization's audit committee.
B. Consult with an immediate supervisor and review the organization's ethics policy.
C. Give the prize to a friend or family member and notitfy the organization's audit committee.
D. Give the prize to a friend or family member and review the organization's ethics policy.
Explanation:
Accepting gifts or prizes from a vendor creates a potential conflict of interest and may impair the auditor's objectivity. The auditor must not accept anything that could be perceived as influencing their professional judgment. The most appropriate first step is to consult with an immediate supervisor to discuss the situation and seek guidance, while simultaneously reviewing the organization's ethics policy to understand any specific rules regarding gifts from vendors. This ensures the auditor acts transparently, seeks proper advice, and complies with both the IIA's Code of Ethics and the organization's internal policies.
Why the other options are incorrect:
A. Consult with supervisor and notify audit committee:
Notifying the audit committee is premature. The issue should first be discussed internally with the supervisor and evaluated against the organization's policy. The audit committee is not involved in routine conflict-of-interest matters unless they are significant or unresolved.
C. Give the prize to a friend/family member and notify audit committee:
This is inappropriate. Transferring the prize to a friend or family member does not eliminate the ethical dilemma; it may be seen as attempting to circumvent the rules. Additionally, the audit committee should not be the first point of contact.
D. Give the prize to a friend/family member and review policy:
Giving the prize away does not resolve the underlying conflict of interest. The auditor must first seek guidance from their supervisor and determine the proper course of action in accordance with the organization's policy.
References:
IIA Code of Ethics – Principle II:
Objectivity: Internal auditors shall not accept anything that may impair or be presumed to impair their professional judgment.
IIA Code of Ethics – Rule of Conduct (Objectivity): Internal auditors shall not accept anything that may impair or be presumed to impair their professional judgment.
While reviewing first quarter sales transactions, an internal auditor discovered that 10 invoices for a new customer had not been posted into the accounts receivable subsidiary ledger. Those 10 invoices were listed in an error report automatically generated by the sales processing system. The system had rejected the invoices because the customer's account number was not found in the customer master file. In this scenario, which of the following controls was lacking?
A. Corrective control.
B. Preventive control.
C. Detective control.
D. Directive control.
Explanation:
This question asks about a missing control that allowed a failure to occur. The scenario describes a situation where ten invoices were rejected by the system because the customer's account number was not in the master file. This is a failure of a preventive control.
A preventive control is designed to stop an error or irregularity from occurring in the first place. In this case, the system should have prevented the sales transaction from being entered or processed if the customer account number was invalid. The error report is a detective control because it identifies the error after it occurred, but the lack of a control to prevent the entry of a transaction with an invalid account number is the missing preventive control. A proper preventive control would have required the account number to be validated against the master file at the time of data entry, rejecting the invoice immediately and notifying the user.
Why the other options are incorrect
A. Corrective control:
A corrective control fixes an error after it has been discovered. While the error report allows for correction, the fact that the invoices were posted to the system in the first place means the lack was in prevention, not correction.
C. Detective control:
The error report that listed the rejected invoices is a detective control. It exists, so it was not lacking. The missing control is the one that should have prevented the entry of the invalid invoices initially.
D. Directive control:
A directive control encourages or enforces a desired behavior (e.g., written policies). It is not relevant to a specific system validation failure.
References:
IIA Standard 2130 – Control: Requires internal auditors to evaluate the effectiveness of controls, including the classification of controls as preventive, detective, or corrective.
IIA Practice Guide – "Auditing Information Technology Controls": Defines preventive controls as those designed to prevent errors or irregularities from occurring, such as input validation and master file checks.
According to the Standards, for how long should internal auditors who have previously performed or had management responsibility for an operation wait to become involved in future internal audit activity with that same operation?
A. Three months.
B. Six months.
C. One year.
D. Two years.
Explanation:
The International Professional Practices Framework (IPPF) explicitly establishes this cooling-off period to protect the internal auditor's objectivity and prevent self-review threats. According to IIA Standard 1130.A1, "Objectivity is presumed to be impaired if an internal auditor provides assurance services for an activity for which the internal auditor had responsibility within the previous year" .
The one-year period is a mandatory minimum requirement designed to ensure sufficient distance between the auditor and their former responsibilities . This safeguard helps maintain the credibility of the audit activity and prevents actual or perceived conflicts of interest that could arise from auditing one's own work. The standard applies specifically to assurance services, where the auditor is evaluating and reporting on an activity they previously managed.
Why the other options are incorrect:
A. Three months and B. Six months are far too short to overcome the self-review threat. The IIA Standards do not recognize these periods; they are insufficient to ensure the auditor's impartiality.
D. Two years exceeds the IIA's minimum requirement. While some organizations may adopt stricter policies, the Standards only mandate a one-year wait .
References:
IIA Standard 1130.A1: "Internal auditors must refrain from assessing specific operations for which they were previously responsible. Objectivity is presumed to be impaired if an internal auditor provides assurance services for an activity for which the internal auditor had responsibility within the previous year" .
Management has asked the chief audit executive (CAE) to provide assurance on the organization's automated control system related to financial data. The current audit staff does not have the expertise needed to conduct this type of engagement. Which of the following would be the best response by the CAE?
A. Accept the assignment and use control self-assessment to complete the project.
B. Do not accept the assignment because the internal audit activity lacks the competency to perform the engagement with due professional care.
C. Accept the assignment and use an external provider with the necessary knowledge and skills to perform the engagement.
D. Accept the assignment if the engagement is included in the current audit plan, but inform senior management that the current audit staff does not have the knowledge and skills required.
Explanation:
When the internal audit staff lacks the required expertise for an engagement, the Standards do not require the CAE to decline it. Standard 1210.A1 explicitly states that the CAE "must obtain competent advice and assistance" if the internal auditors lack the necessary knowledge or skills. Engaging an external provider is a recognized, appropriate solution that allows the CAE to accept the assignment while ensuring the work is performed with due professional care. The CAE remains responsible for overseeing the external provider and ensuring the engagement meets the Standards.
Why the other options are incorrect:
A. Use control self-assessment (CSA):
CSA is a management technique, not an audit methodology. It cannot substitute for the technical expertise required to evaluate an automated financial control system. Relying on CSA would not address the competency gap and would compromise assurance reliability.
B. Do not accept the assignment:
This is unnecessarily drastic. The Standards provide a clear avenue to address the gap through external assistance. Refusing the engagement would fail to meet management's needs and ignore the permissive language of Standard 1210.A1.
D. Accept but inform management of the skills gap:
While disclosure is appropriate, this option does not address the core problem. Accepting the engagement without ensuring the work is competently performed—by either internal or external resources—would violate due professional care. The CAE must take action to fill the gap, not merely disclose it.
References:
IIA Standard 1210 – Proficiency: The internal audit activity collectively must possess or obtain the knowledge, skills, and other competencies needed to perform its responsibilities.
IIA Standard 1210.A1: The CAE must obtain competent advice and assistance if the internal auditors lack the knowledge, skills, or other competencies needed to perform all or part of the engagement.
| Page 10 out of 29 Pages |