Free IIA IIA-CRMA-ADV Practice Questions 2026 - Page 3

Timed Practice Test

Ready for IIA-CRMA-ADV Exam?

This practice test is your final exam before the REAL exam
Dare to Take It?




Practice Questions

Topic 1: Exam Pool A

Which of the following statements is true regarding the use of non-statistical sampling in auditing control tests?

A. It considers tolerable deviation rate more effectively than does statistical sampling.

B. Sampling risk will be accurately quantified through non-statistical sampling.

C. Non-statistical sample results must be projected to the population.

D. Lesser evidence is required to support a conclusion than for statistical sampling.

C.   Non-statistical sample results must be projected to the population.

Explanation:

The requirement to project sample results to the population is a fundamental step in audit sampling, applicable to both statistical and non-statistical methods. Once a non-statistical sample has been tested and errors or deviations are identified, the auditor cannot simply stop with the sample findings. The results must be projected or extrapolated to the entire population to estimate the total error or deviation rate . This projection allows the auditor to compare the estimated error in the whole population against the pre-defined tolerable error, forming a conclusion on whether the population is materially misstated or if controls are operating effectively .

Why the other options are incorrect:

A. It considers tolerable deviation rate more effectively than does statistical sampling:
Incorrect. Tolerable deviation rate is a key input for determining sample size in both statistical and non-statistical approaches . Neither method is inherently more effective at "considering" it, though statistical methods do so within a quantifiable confidence framework.

B. Sampling risk will be accurately quantified through non-statistical sampling:
Incorrect. The main limitation of non-statistical sampling is that it does not allow for the calculation of accuracy or the quantification of sampling risk . This is the defining advantage of statistical sampling, which uses probability theory to measure and control this risk .

D. Lesser evidence is required to support a conclusion than for statistical sampling:
Incorrect. The sufficiency of evidence required to support an audit conclusion is determined by the engagement objectives and the acceptable level of risk, not by the choice of sampling method. Both statistical and non-statistical approaches require the auditor to select a sample size sufficient to provide a reasonable basis for conclusions . In fact, some guidance suggests that the use of non-statistical sampling does not imply the use of smaller sample sizes .

References:

Standard on Internal Audit (SIA) 5, Sampling: Requires that the internal auditor evaluate sample results, which includes projecting errors to the population, regardless of whether a statistical or non-statistical approach is used .

What is the primary purpose of a fishbone diagram?

A. To depict the areas of responsibility for departments in an organization.

B. To plan and control complex projects, such as internal audits.

C. To represent the frequencies of adverse conditions in a given process.

D. To identify the possible causes of adverse conditions.

D.   To identify the possible causes of adverse conditions.

Explanation:

A fishbone diagram (also known as an Ishikawa or cause-and-effect diagram) is a visual brainstorming tool specifically designed to systematically identify, explore, and display the potential root causes of a specific problem, defect, or adverse condition. The diagram visually organizes causes into categories (typically the 6 Ms: Manpower, Methods, Materials, Machines, Measurements, and Mother Nature/Environment), allowing a team to trace an undesirable outcome back to its possible sources. Its primary purpose is investigative and diagnostic—to help auditors and management move beyond symptoms and uncover the underlying factors contributing to a control failure, operational inefficiency, or quality issue.

Why the other options are incorrect:

A. To depict the areas of responsibility for departments in an organization:
This describes an organizational chart, which shows hierarchical structure and reporting lines, not cause-and-effect relationships.

B. To plan and control complex projects, such as internal audits:
This describes a Gantt chart or PERT chart, which are project management tools for scheduling, tracking timelines, and managing resources.

C. To represent the frequencies of adverse conditions in a given process:
This describes a histogram or Pareto chart, which are quantitative tools used to display frequency distributions and prioritize issues based on their occurrence.

References:

IIA Practice Guide – "Auditing Quality Management Systems": Recommends the use of fishbone diagrams during the planning and fieldwork phases to assist in root cause analysis when investigating quality failures or nonconformities.

IIA GTAG – "Auditing IT Governance": References cause-and-effect analysis as a valuable technique for identifying and structuring risk factors and control weaknesses in IT environments.

Which of the following scenarios would represent the greatest threat to the authority of the internal audit activity (IAA)?

A. A change was implemented requiring the IAA to report administratively to the organization's chief legal counsel rather than the board.

B. Responsibility for risk management processes were removed from the IAA and placed under a newly created chief risk officer.

C. The IAA was denied access to expenditure and budget requirement reports because the reports were considered to be financial administrative matters.

D. An internal auditor was informed by the chief financial officer that client survey results would be unfavorable unless the auditor changed a finding in the report.

C.   The IAA was denied access to expenditure and budget requirement reports because the reports were considered to be financial administrative matters.

Explanation:

This question asks for the scenario that represents the greatest threat to the authority of the internal audit activity (IAA). Authority is fundamentally rooted in the IAA's right of access as defined in the internal audit charter (Standard 1000). Denial of access to any records, personnel, or physical properties—regardless of the reason—directly undermines the IAA's ability to perform its work and fulfill its mandate.

Why the other options are incorrect :

A. Reporting administratively to chief legal counsel:
This is a threat to organizational independence (Standard 1110), not authority. While problematic, the CAE would still retain audit authority per the charter; independence is impaired but can be disclosed and addressed.

B. Risk management responsibilities removed:
This is a threat to scope and role clarity (Standard 2120). It reduces the IAA's involvement in risk management but does not deny its fundamental authority to access information or perform audits in other areas.

D. CFO asking auditor to change a finding:
This is a threat to individual objectivity (Standard 1120) and professional integrity. It is a serious ethical breach, but the auditor can resist, and the CAE can protect the auditor. It does not prevent the IAA from accessing information or exercising its authority.

References:

IIA Standard 1000 – Purpose, Authority, and Responsibility: Requires the charter to define the IAA's purpose, authority, and responsibility, including the right of access.

IIA Standard 1130 – Impairments to Independence or Objectivity: Requires disclosure of impairments, but denial of access is a direct violation of the charter-granted authority.

Which of the following actions does not violate the IIA Code of Ethics or Standards?

A. An internal auditor performing an audit on an operation that they managed less than a year ago.

B. An internal auditor performing an audit on procedures that they were responsible for creating.

C. An internal auditor disclosing details of an audit report to colleagues from a different organization.

D. An internal auditor disclosing confidential information in response to a lawsuit.

D.   An internal auditor disclosing confidential information in response to a lawsuit.

Explanation:

The IIA Code of Ethics strictly mandates that internal auditors must protect the confidentiality of information they acquire in their work and must not disclose confidential information without appropriate authority (which typically means board or audit committee approval) unless there is a legal or professional obligation to do so.

Disclosing confidential information in response to a lawsuit—specifically, when compelled by a valid court order, subpoena, or other legal process—falls under this explicit exception. While the auditor should still exercise caution and ideally seek legal counsel to limit disclosure to only what is legally required, this action does not violate the Code of Ethics or the Standards because it satisfies a legal obligation. It is the only option where the disclosure is mandated by external authority rather than being voluntary or unauthorized.

Why the other options are incorrect:

A. An internal auditor performing an audit on an operation that they managed less than a year ago:
This violates Standard 1130.C1 (Impairments to Independence or Objectivity for Consulting Services), which requires a one-year cooling-off period before providing consulting services for an area previously managed, and Standard 1130.A1 (Assurance) for assurance work, which mandates at least one year before assuming responsibility for an area previously audited.

B. An internal auditor performing an audit on procedures that they were responsible for creating:
This is a clear violation of Standard 1120 (Individual Objectivity) and the Code of Ethics Rule of Conduct for Objectivity. Auditors cannot audit their own work, as this creates an actual conflict of interest and impairs impartiality.

C. An internal auditor disclosing details of an audit report to colleagues from a different organization:
This violates the Confidentiality principle of the IIA Code of Ethics. Internal auditors must not disclose information without appropriate authority (such as board or audit committee approval). Sharing details with external colleagues without authorization is a breach, regardless of intent.

References:

IIA Code of Ethics – Principle IV: Confidentiality: "Internal auditors respect the value and ownership of information they receive and do not disclose information without appropriate authority unless there is a legal or professional obligation to do so."

Which of the following statements best explains why internal auditors map processes?
1. To obtain audit evidence to support auditor's observations.
2. To determine scope and objectives of the audit.
3. To facilitate the identification of ownership and responsibility for key risks.
4. To identify potential efficiency improvements.

A. 1 and 2.

B. 1 and 3.

C. 2 and 4.

D. 3 and 4.

D.   3 and 4.

Explanation:

Process mapping (often in the form of flowcharts or narratives) is a foundational diagnostic tool used during the planning and preliminary survey phases of an audit. Its primary purposes are to help the auditor understand the flow of transactions, identify key control points, and pinpoint areas of risk. The two best explanations for why internal auditors map processes are:

To facilitate the identification of ownership and responsibility for key risks (Statement 3): By visually depicting each step in a process, a map clearly shows who performs which action, where handoffs occur, and where decisions are made. This allows the auditor to identify the specific individuals or departments responsible for managing risks at each critical control point, which is essential for evaluating control design and assigning accountability.

To identify potential efficiency improvements (Statement 4): A process map provides a clear, end-to-end view of the workflow. This allows the auditor to spot redundancies, bottlenecks, unnecessary approvals, rework loops, or duplicated efforts that indicate operational inefficiencies—an important aspect of both assurance and consulting engagements.

Why the other options are incorrect:

Statement 1 – To obtain audit evidence to support auditor's observations:
Incorrect. A process map is a documentation tool that helps the auditor understand a process; it is not itself audit evidence. Evidence is obtained through testing (inspection, observation, recalculation, etc.) that confirms whether the mapped process is actually operating as described. The map supports planning and understanding, not direct evidentiary support for conclusions.

Statement 2 – To determine scope and objectives of the audit:
Incorrect. The scope and objectives of an engagement are determined primarily through a risk assessment, not by process mapping. While process mapping may inform the risk assessment by highlighting areas of complexity, the scope and objectives are set based on identified risks, materiality, and management's concerns—not by the map itself.

References:

IIA Standard 2210.A1 – Engagement Objectives: Requires internal auditors to consider the probability of significant errors, fraud, and noncompliance. Process mapping is a recognized technique used during the preliminary survey to gain an understanding of the process and identify control points.

A candidate has applied for an entry level internal audit position. The candidate holds a CISA (Certified Information Systems Auditor) designation, and has six months of audit experience, but limited knowledge of accounting principles and techniques. According to the IIA guidance, which of the following is the most relevant reason for the chief audit executive to consider this candidate?

A. Other internal auditors possess sufficient knowledge of accounting principles and techniques.

B. The candidate's information systems knowledge and real-world experience in internal auditing.

C. Accounting skills can be learned over time with appropriate training.

D. An entry level position does not require expertise in any particular area.

A.   Other internal auditors possess sufficient knowledge of accounting principles and techniques.

Explanation:

This question addresses the principle of collective proficiency within an internal audit activity. The fundamental requirement for an internal audit activity is to collectively possess the knowledge and skills needed to perform its responsibilities . Standard 1210 specifies that "The internal audit activity collectively must possess or obtain the knowledge, skills, and other competencies needed to perform its responsibilities" .

Why the other options are incorrect:

B. The candidate's information systems knowledge and real-world experience:
While a strong resume point for an entry-level role, this alone is not the most relevant reason. The key decision hinges on whether the specific skill is needed by the team, not its inherent value. Without considering the team's collective gaps, this reason is less strategic .

C. Accounting skills can be learned over time:
This is a passive justification that overlooks the candidate's immediate value and the core IIA guidance on proficiency. It focuses on a future potential, rather than a current strategic fit.

D. An entry level position does not require expertise in any particular area:
This is incorrect. While entry-level roles don't demand mastery, the IIA Competency Framework specifies foundational skills are expected. Candidates must demonstrate a baseline of knowledge, skills, and abilities . The CAE has a responsibility to ensure every position meets the professional requirements for proficiency.

References:

IIA Standard 1210 – Proficiency: "Internal auditors must possess the knowledge, skills, and other competencies needed to perform their individual responsibilities. The internal audit activity collectively must possess or obtain the knowledge, skills, and other competencies needed to perform its responsibilities."

Which of the following is not one of the 10 core competencies identified in the IIA Competency Framework?

A. Governance, risk, and control.

B. Performance management.

C. Business acumen.

D. Internal audit delivery.

B.   Performance management.

Explanation:

The IIA's Competency Framework is structured around four broad knowledge areas: Internal Auditing Competencies, Professional Competencies, Governance and Risk Management Competencies, and Operational Area Competencies. Under these, the framework identifies a set of core competencies that define the knowledge, skills, and abilities required for effective internal auditors at various career levels.

Performance management (B), however, is not a core competency category within the IIA Competency Framework. While performance management—such as evaluating staff, providing feedback, and managing team performance—is an important managerial tool, the framework treats it as a mechanism for applying competencies rather than as a distinct competency itself. In fact, the updated 2025 framework explicitly states that it can be used to support individual performance management and professional development planning, but it does not list performance management as one of the core knowledge areas.

Why the other options are incorrect:

A. Governance, risk, and control: Incorrect because this is a foundational competency area in the framework, essential for evaluating organizational governance, risk management, and internal control systems.

C. Business acumen: Incorrect because this is a recognized competency, requiring auditors to understand business models, industry dynamics, and operational processes to provide relevant assurance and advice.

D. Internal audit delivery: Incorrect because this is a core competency covering the entire audit lifecycle—from planning and fieldwork to communication and follow-up.

References:

IIA's Global Internal Audit Competency Framework (Original): Defines four main competency areas: Internal Auditing Competencies, Professional Competencies, Governance and Risk Management Competencies, and Operational Area Competencies. Specific subcategories include Governance, Risk, and Control; Business Acumen; and Internal Audit Delivery.

An internal audit activity (IAA) provided assurance services for an activity it was responsible for during the preceding year.
As a result, which IIA Code of Ethics principle is presumed to be impaired?

A. Competence.

B. Flexibility.

C. Objectivity.

D. Independence.

C.   Objectivity.

Explanation:

The IIA Code of Ethics and the Standards explicitly prohibit internal auditors from auditing an activity or operation for which they had previous responsibility within the last year. This is because they would be placed in a position of evaluating their own work or decisions, which creates an actual or perceived conflict of interest. The principle directly impaired in this scenario is Objectivity—the unbiased mental attitude and avoidance of conflicts that allows auditors to perform engagements impartially.

Why the other options are incorrect:

A. Competence:
This principle requires auditors to possess the knowledge and skills to perform their duties. There is no indication the auditor lacked competence; the issue is the impartiality of their judgment, not their ability.

B. Flexibility:
This is not a principle of the IIA Code of Ethics. The Code has four principles: Integrity, Objectivity, Confidentiality, and Competency.

D. Independence:
Independence (organizational status) refers to the IAA's freedom from interference in determining scope and reporting findings. This scenario concerns an individual auditor's personal bias arising from prior operational responsibilities—this is an impairment to objectivity, not organizational independence. However, note that Standard 1130 treats this as an impairment that must be disclosed, but the underlying principle violated is objectivity.

References:

IIA Code of Ethics – Principle II: Objectivity: "Internal auditors exhibit the highest level of professional objectivity in gathering, evaluating, and communicating information about the activity or process being examined. Internal auditors make a balanced assessment of all the relevant circumstances and are not unduly influenced by their own interests or by others in forming judgments."

Which type of objectives can best be described as broad goals that promote the effective and efficient use of resources?

A. Strategic objectives.

B. Operational objectives.

C. Reporting objectives.

D. Compliance objectives.

B.   Operational objectives.

Explanation:

Operational objectives are specifically concerned with the effective and efficient use of resources. They relate to the accomplishment of an entity's basic mission and goals, ensuring that resources (such as people, materials, technology, and capital) are utilized optimally to achieve performance targets. This includes goals related to profitability, productivity, quality, and safeguarding assets—all of which directly address resource efficiency.

In contrast, strategic objectives are high-level goals aligned with the organization's mission and vision; reporting objectives focus on the reliability, timeliness, and transparency of internal and external reporting; and compliance objectives ensure adherence to laws, regulations, and policies. Only operational objectives directly encompass the broad goal of resource effectiveness and efficiency.

Why the other options are incorrect:

A. Strategic objectives: These are high-level, long-term goals that relate to the organization's overall mission, vision, and stakeholder expectations. They do not specifically address resource efficiency; rather, they set the direction for the entire entity.

C. Reporting objectives:These relate to the reliability, timeliness, and transparency of financial and non-financial reporting. They do not concern resource utilization.

D. Compliance objectives: These concern adherence to applicable laws, regulations, and internal policies. While non-compliance can waste resources, the objectives themselves are not defined by resource efficiency.

References:

COSO Internal Control – Integrated Framework (2013): Defines three categories of objectives: Operations, Reporting, and Compliance. Operations objectives are specifically described as pertaining to "the effective and efficient use of the entity's resources."

During the course of an audit, an internal auditor discovers that a valuable employee in the research department has been patenting new developments in the employee's name that are unrelated to the basic business of the organization.
The organization does not have a policy addressing this specific issue, but does have a general policy that all important new discoveries by employees are the property of the organization.
Division management views the employee's actions as extra incentive to retain the employee.
A decision to include the employee's action in the engagement final communication would be:
1. A violation of the IIA Code of Ethics.
2. A violation of the reporting requirements in the Standards.
3. Justified and necessary, according to the IIA Code of Ethics and Standards.

A. 1 only

B. 2 only

C. 3 only

D. 1 and 2 only

C.   3 only

Explanation:

This scenario involves a conflict between division management's desire to retain a valuable employee and the organization's stated policy that all important discoveries by employees are the property of the organization. The employee is patenting developments in their own name, which is a direct violation of organizational policy, regardless of management's view that it provides extra incentive.

Including this finding in the engagement final communication is both justified and necessary under the IIA Code of Ethics and Standards for the following reasons:

Standard 2400 – Communicating Results: Internal auditors must communicate the results of engagements, which include significant findings and recommendations. A material violation of organizational policy—such as an employee claiming ownership of intellectual property that belongs to the organization—constitutes a significant finding that must be reported.

Standard 2410 – Criteria for Communicating: Communications must include the engagement's objectives, scope, and results. Results include findings, conclusions, and recommendations. Omitting a significant violation of policy would render the communication incomplete and misleading.

Code of Ethics – Integrity: The Code requires internal auditors to "perform their work with honesty, diligence, and responsibility" and to "observe the law and make disclosures expected by the law and the profession." Concealing a known policy violation, even if management condones it, would compromise integrity.

Code of Ethics – Objectivity: Internal auditors must make a balanced assessment and not be unduly influenced by management's preferences. Division management's rationale (employee retention) does not override the requirement to report a material noncompliance with organizational policy.

Why the other options are incorrect:

Statement 1 – A violation of the Code of Ethics: Incorrect. Reporting a material policy violation is required by the Code of Ethics (Integrity and Objectivity), not a violation. Concealing it would be a violation.

Statement 2 – A violation of reporting requirements in the Standards: Incorrect. The Standards explicitly require communication of significant findings (Standard 2400). Omitting this finding would violate the Standards, while including it satisfies them.

Statements 1 and 2: Since both individual statements are false, any combination containing them (A, B, or D) is incorrect.

References:

IIA Standard 2400 – Communicating Results: "Internal auditors must communicate the results of engagements."

IIA Standard 2410 – Criteria for Communicating: "Communications must include the engagement’s objectives, scope, and results."

Page 3 out of 29 Pages