Free IIA IIA-CRMA-ADV Practice Questions 2026 - Page 4
Ready for IIA-CRMA-ADV Exam?
This practice test is your final exam before the REAL exam
Dare to Take It?
Practice Questions
Topic 1: Exam Pool A
An internal auditor notes that employees are able to download files from the internet. According to IIA guidance, which of the following strategies would best protect the organization from the risk of copyright infringement and licensing violations resulting from this practice?
A. Apply antivirus and patch management software.
B. Utilize dedicated and encrypted network connections.
C. Install a software inventory management application.
D. Utilize secure socket layer encryption.
Explanation:
A software inventory management application is the most direct and effective strategy for protecting the organization from copyright infringement and licensing violations because it provides the visibility needed to ensure compliance. The risk arises from employees downloading unapproved or unlicensed software, making the organization vulnerable to legal and financial penalties . To manage this risk, the organization must be able to answer two critical questions: what software is installed, and where is it being used? Without tracking installations and comparing them to license entitlements, compliance cannot be verified .
Why the other options are incorrect
A. Apply antivirus and patch management software:
This addresses cybersecurity threats (like malware and system vulnerabilities) rather than the legal and compliance risk of copyright infringement .
B. Utilize dedicated and encrypted network connections:
This focuses on the security and confidentiality of data in transit, which is unrelated to the management of software licenses .
D. Utilize secure socket layer encryption:
This is a security protocol to protect data transmitted over the internet, serving a different purpose from software license compliance .
References
IIA Standard 2120 – Risk Management: The internal audit activity must evaluate the effectiveness and contribute to the improvement of risk management processes, which includes protecting the organization from compliance risks like licensing violations.
IIA Practice Guide – "Auditing the Risk Management Process": This guide highlights the need to evaluate the controls in place to manage and mitigate risks, including the use of tools such as software asset management applications for compliance purposes.
Which of the following controls is not appropriate for sales in a manufacturing organization?
A. Customers' orders are recorded promptly.
B. Goods shipped are matched with valid customer orders.
C. Goods returned are inspected for damage by the receiving department for proper disposition.
D. Sales department approval is required for credit sales transactions.
Explanation:
In a manufacturing organization, the Sales Department is responsible for generating revenue, promoting products, and managing customer relationships. It is an operational function that works directly with customers and has a natural bias toward closing deals and maximizing sales volume. Requiring the Sales Department to approve credit sales transactions creates an incompatible segregation of duties and a fundamental control weakness, because the same department that initiates a transaction (sales) would also be authorizing the extension of credit to the customer.
Why the other options are correct controls
A. Customers' orders are recorded promptly:
This is an appropriate control to ensure that all sales are captured completely and accurately, preventing revenue leakage and ensuring timely recognition of transactions.
B. Goods shipped are matched with valid customer orders:
This is an appropriate control to prevent shipping errors, unauthorized shipments, and fraudulent activities. Matching ensures that only legitimate, approved orders are fulfilled.
C. Goods returned are inspected for damage by the receiving department for proper disposition:
This is an appropriate control to ensure that returned goods are properly evaluated for restocking, disposal, or credit issuance. The receiving department provides an independent assessment separate from the sales function.
References
IIA Standard 2130 – Control: "The internal audit activity must assist the organization in maintaining effective controls by evaluating their effectiveness and efficiency and by promoting continuous improvement."
COSO Internal Control – Integrated Framework (2013): Identifies segregation of duties as a key control activity, specifically separating authorization (credit approval) from transaction initiation (sales) and record-keeping.
A government agency's policy states that board members' travel and hospitality expenses must be audited annually. Which of following people or groups is most appropriate to perform this audit?
A. The government's independent auditor.
B. The external auditors from an accounting firm.
C. The internal audit activity.
D. The agency's chief compliance officer.
Explanation:
This scenario involves auditing the expenses of board members, who hold the highest governance position in the organization. The key principle is that the auditor must be independent of the persons being audited and free from management influence. The internal audit activity is uniquely positioned to fulfill this requirement, as the IIA Standards mandate that the chief audit executive (CAE) report functionally to the board, ensuring the activity has the organizational independence necessary to conduct audits of senior management and board members without interference . An internal audit of board member expenses is a routine, internal assurance engagement, which aligns directly with the primary purpose of the internal audit activity . Independent oversight of executive and board expenses is a recognized practice, as it helps prevent inappropriate expenditures and serves as a key control to reassure the public and ensure that expenses serve the public interest .
Why the other options are incorrect
A. The government's independent auditor:
This typically refers to the legislative auditor or auditor general, who conducts performance or financial audits of government entities as a whole, not routine, policy-mandated internal audits of specific board expenses. This would be an inefficient and disproportionate use of their resources .
B. The external auditors from an accounting firm:
External auditors focus on the annual financial statement audit and are not engaged to perform routine, policy-mandated internal audits. Using them for this purpose would be outside their standard scope and cost-prohibitive.
D. The agency's chief compliance officer:
The chief compliance officer is a management function, often falling within the second line of defense . As a member of management, the compliance officer would not be independent of the board members whose expenses are under review, as the board has oversight authority over management. Auditing the expenses of those who oversee your role presents a significant conflict of interest.
References
IIA Standard 1100 – Independence and Objectivity: "The internal audit activity must be independent, and internal auditors must be objective in performing their work" .
IIA Standard 1110 – Organizational Independence: "The chief audit executive must report to a level within the organization that allows the internal audit activity to fulfill its responsibilities... Organizational independence is effectively achieved when the chief audit executive reports functionally to the board" .
Which of the following decisions made during the testing phase of a compliance audit requires the most judgment by an internal auditor?
A. Which sampling methodology to select for testing.
B. Which fields to examine on each invoice.
C. Whether an individual expenditure is allowable.
D. What level of noncompliance is acceptable.
Explanation:
This question tests the distinction between technical/mechanical decisions and professional judgment in auditing. During the testing phase of a compliance audit, the decision that requires the most professional judgment is determining the level of noncompliance that is acceptable—i.e., the tolerable deviation rate. This decision inherently involves balancing multiple subjective factors:
Materiality: The auditor must assess whether identified deviations are quantitatively or qualitatively material to the overall compliance objective.
Risk Appetite: The auditor must consider management's and the board's tolerance for compliance failures, which is not a fixed number but a contextual judgment.
Root Cause Analysis: The auditor must evaluate whether deviations are isolated errors (acceptable within tolerance) or indicative of systemic control failures (unacceptable even if below a numerical threshold).
Regulatory Context: The auditor must interpret laws and regulations, which often contain ambiguities that require judgment on what constitutes a "material" or "significant" violation.
While the other options involve decisions, they are largely technical, procedural, or referential in nature, requiring less subjective judgment. The auditor can rely on established policies, checklists, and mathematical models for those decisions. In contrast, setting the acceptable level of noncompliance requires synthesizing legal, operational, and governance considerations into a defensible professional conclusion.
Why the other options are incorrect
A. Which sampling methodology to select for testing:
This is a technical decision guided by documented standards, engagement objectives, and statistical principles. The auditor applies established criteria (e.g., expected deviation rate, confidence level) to choose between statistical or non-statistical sampling—it involves methodology, not subjective value judgment.
B. Which fields to examine on each invoice:
This is a procedural decision driven by the audit program, control objectives, and prior risk assessment. The auditor focuses on fields that capture critical compliance data (e.g., amount, vendor, authorization)—this is a routine, checklist-based decision.
C. Whether an individual expenditure is allowable:
While this requires interpretation of policies, it is typically a binary fact-based determination. The auditor compares the expenditure against defined allowable costs—the judgment is limited to applying a rule to a specific fact pattern, not setting the threshold for acceptability.
References
IIA Standard 2220 – Engagement Scope: Requires auditors to determine the scope of work "with consideration of the risk management processes, the control environment, and the objectives of the engagement." Setting the acceptable level of deviation (tolerable error) is a critical component of scoping that requires judgment.
According to the IIA guidance, who is responsible for periodically assessing the internal audit activity?
A. The board.
B. The chief audit executive.
C. Senior management.
D. The external auditors.
Explanation:
The IIA Standards require the CAE to develop and maintain a Quality Assurance and Improvement Program (QAIP) that covers all aspects of the internal audit activity . This program includes both internal assessments (ongoing monitoring and periodic self-assessments) and external assessments conducted at least once every five years by a qualified, independent party from outside the organization .
The CAE has the primary responsibility for ensuring these assessments are conducted and for implementing improvements based on their results . While the board receives assurance about the quality of the internal audit function's performance through the QAIP , the responsibility for conducting the assessment rests with the CAE .
Why the other options are incorrect
A. The board: The board receives and reviews the results of the quality assessments to provide oversight, but it is not responsible for performing them. The board's role is governance and oversight .
C. Senior management: Senior management receives the results of the quality assessments as a stakeholder, but the CAE is accountable for developing and executing the QAIP .
D. The external auditors: External auditors are not responsible for assessing the internal audit activity. They may coordinate with internal audit, but the QAIP is a specific requirement for the internal audit function and is managed by the CAE .
References
IIA Standard 1300 – Quality Assurance and Improvement Program: "The chief audit executive must develop and maintain a quality assurance and improvement program that covers all aspects of the internal audit activity" .
According to IIA guidance, which of the following statements regarding the internal audit charter is true?
A. Senior management should approve the charter before it is submitted to the board.
B. The charter should describe the purpose and authority of the internal audit activity, consistent with the Standards.
C. The charter should define the consulting services that the internal audit activity is permitted to perform.
D. The CEO periodically should assess whether the terms of the charter continue to be adequate.
Explanation:
The internal audit charter is a foundational, board-approved document that formally establishes the internal audit activity's role within the organization. According to IIA Standard 1000, the charter must define the activity's purpose, authority, and responsibility in a manner that is consistent with the mandatory elements of the International Professional Practices Framework (IPPF). The charter sets the position of the internal audit activity, authorizes necessary access to records and personnel, and defines its scope.
Why the other options are incorrect
A. Senior management should approve the charter before it is submitted to the board:
Incorrect. While the CAE should discuss the charter with senior management, final approval authority resides with the board (or governing body). The board's final approval is documented in meeting minutes to formally establish the audit activity's authority.
C. The charter should define the consulting services that the internal audit activity is permitted to perform:
Incorrect. The charter must define the nature of consulting services, but this is a required component under Standards 1000.C1, not a complete definition of permitted services. The nature and scope of individual consulting engagements are agreed upon with the client on a case-by-case basis.
D. The CEO periodically should assess whether the terms of the charter continue to be adequate:
Incorrect. Responsibility for periodically reviewing the charter rests with the chief audit executive (CAE), not the CEO. The CAE presents the results of this review to senior management and the board to ensure the charter remains adequate for the activity to meet its objectives.
The results of an internal audit activity's (IAA) quality assurance and improvement program are favorable and an external assessment was completed within the last five years. Which of the following statements may the IAA use to describe its work?
A. "Completed with the advance certification of the External Assessors Association for Auditing Review."
B. "Conforms with the International Standards for the Professional Practice of Internal Auditing."
C. "Certified 100% accuracy, per the International Standards of External Assessment."
D. "Compliant with all domestic and international legal statutes, and certified quality assured for ten years."
Explanation:
The statement that an internal audit activity (IAA) "Conforms with the International Standards for the Professional Practice of Internal Auditing" is the specific and correct terminology defined by IIA guidance . This language is not a marketing claim; it is a formal declaration that is explicitly permitted only under the conditions described in the scenario. According to Standard 1321 – Use of "Conforms with the International Standards for the Professional Practice of Internal Auditing", the IAA may only use this statement if it is supported by the results of its quality assurance and improvement program (QAIP) .
Why the Other Options Are Incorrect
A. "Completed with the advance certification of the External Assessors Association for Auditing Review."
This is incorrect because it references a non-existent organization and a non-standard terminology. The IIA does not have an "External Assessors Association for Auditing Review"; the external assessment is simply performed by a qualified, independent assessor .
C. "Certified 100% accuracy, per the International Standards of External Assessment."
This is incorrect for two reasons. First, the IIA Standards use a rating system such as "Generally Conforms" or "Full Achievement," not "100% accuracy" . Second, "International Standards of External Assessment" is not a recognized standard.
D. "Compliant with all domestic and international legal statutes, and certified quality assured for ten years."
This is incorrect because it misstates both the scope and the timing of the requirement. The QAIP assesses conformance with the IIA Standards, not all legal statutes. Additionally, an external assessment is required at least once every five years, not ten .
References
IIA Standard 1300 – Quality Assurance and Improvement Program: The CAE must develop and maintain a QAIP that covers all aspects of the internal audit activity .
IIA Standard 1312 – External Assessments: External assessments must be conducted at least once every five years by a qualified, independent assessor .
The chief audit executive (CAE) has been asked to manage the regulatory compliance function for the organization's retail store operations. Store operations are included in the annual audit plan. Which of the following strategies best fulfills the requirements of the Standards regarding these audits?
A. The scope of store operations audits should exclude compliance.
B. Store operations audits can be fully executed with appropriate disclosure to the board.
C. Store operations audits should be performed by an external service provider.
D. A store operations compliance audit should be performed by a staff internal auditor under the direction of the CAE.
Explanation:
This scenario presents a clear impairment to organizational independence and individual objectivity (Standard 1130). The CAE has been asked to manage the regulatory compliance function for retail store operations—an operational management responsibility. At the same time, store operations are included in the annual audit plan, meaning the CAE would be responsible for auditing activities they now manage. This is a direct conflict because internal auditors cannot audit their own work.
Why the other options are incorrect :
A. The scope of store operations audits should exclude compliance:
Incorrect. Excluding compliance from the scope does not eliminate the impairment. The CAE still has operational responsibility for a function (compliance) that is directly related to the area being audited (store operations), creating a conflict even if specific compliance processes are excluded.
B. Store operations audits can be fully executed with appropriate disclosure to the board:
Incorrect. Disclosure does not cure the impairment. Standard 1130 requires that impairments be disclosed, but also requires the CAE to address them (i.e., remove the conflict). Merely disclosing allows the impairment to persist, which violates the Standards.
D. A store operations compliance audit should be performed by a staff internal auditor under the direction of the CAE:
Incorrect. The CAE is managing the compliance function, so any audit performed under the CAE's direction would be compromised. The impairment applies to the CAE and, by extension, the internal audit activity they lead. Even if the CAE does not perform the fieldwork, their oversight over the audit creates a conflict.
References
IIA Standard 1130.A1 – Impairments to Independence or Objectivity (Assurance):"Internal auditors must not assume operational responsibility for any activity or process that would impair their objectivity. This includes, but is not limited to, providing assurance services for an activity for which the internal auditor had responsibility within the preceding year."
An internal auditor is reviewing employee travel data to identify opportunities to cut costs while ensuring adequate participation at conferences to support the organization's mission. Which of the following pieces of evidence would be sufficient for completing this task?
A. A log from the last year that includes dates of travel, conference titles, and conference objectives, all of which correspond with employee names and costs per trip.
B. A log that includes titles of conferences that all employees were invited to attend in the last year, along with the dates of those conferences and average costs per traveler.
C. A log of conferences titles, dates of travel for each employee, and a detailed summary of conference objectives and how they relate to the organization's mission needs.
D. A log of employee travel requests, which include the title of each conference, the conference objectives, anticipated dates of travel, and estimated costs.
Explanation:
This question asks for the most sufficient evidence to support a dual objective: identifying cost-cutting opportunities while ensuring adequate participation at conferences to support the organization's mission. To achieve this, the auditor needs a complete, reliable dataset that allows for both quantitative analysis (costs) and qualitative evaluation (mission alignment).
Why the other options are insufficient
B. A log of conference titles that all employees were invited to attend, with dates and average costs: This is insufficient because it only records invitations (not actual attendance or costs) and uses averages (not actual trip costs). It cannot identify real spending patterns or confirm that participation actually occurred.
C. A log of conference titles, dates of travel for each employee, and a detailed summary of conference objectives and mission relevance: This lacks cost data entirely, making it impossible to identify cost-cutting opportunities. Without financial information, the auditor cannot complete the cost side of the objective.
D. A log of employee travel requests with conference titles, objectives, anticipated dates, and estimated costs: This is insufficient because it relies on anticipated and estimated data (requests), not actual travel and expenditure data. Auditors must use actual transactional evidence to form conclusions, not planned or budgeted figures.
References
IIA Standard 2310 – Identifying Information: "Internal auditors must identify sufficient, reliable, relevant, and useful information to achieve the engagement's objectives."
IIA Standard 2320 – Analysis and Evaluation: "Internal auditors must base conclusions and engagement results on appropriate analyses and evaluations."
The chief audit executive (CAE) of a mid-sized pharmaceutical organization has operational responsibility for the regulatory compliance function. The auditcommittee requests an assessment of regulatory compliance. According to IIA guidance, which of the following is the CAE's best course of action?
A. Have a proficient internal audit staff member perform the assessment and disclose the impairment in the audit report and to the board.
B. Have a regulatory compliance staff member perform a self-assessment, to be reviewed by a proficient internal auditor.
C. Have a proficient internal audit staff member perform the audit and report the results of the assessment directly to senior management and the board.
D. Contract with a third-party entity or external auditor to complete the assessment and report the results to senior management and the board.
Explanation:
The CAE in this scenario has operational responsibility for the regulatory compliance function but is being asked to assess it. This creates a clear impairment to the internal audit activity's independence and objectivity, as the CAE would be auditing their own work. The IIA Standards explicitly state that "assurance engagements for functions over which the chief audit executive has responsibility must be overseen by a party outside the internal audit activity" . Engaging a third-party entity or external auditor is the most effective way to fulfill this requirement while preserving the integrity of the audit process, as it removes the conflict entirely and allows for an independent assessment, which is critical for providing credible assurance to the board .
Why the other options are incorrect
A. Have a proficient internal audit staff member perform the assessment and disclose the impairment: This is insufficient. Disclosure does not negate the requirement for oversight by a party outside the internal audit activity. Using internal staff does not remove the impairment; the work would still be under the CAE's responsibility and thus compromised .
B. Have a regulatory compliance staff member perform a self-assessment: This is not an independent assessment. Relying on a self-assessment by compliance staff is a management function, not an objective assurance activity, and does not meet the Standards' requirements for an independent review .
C. Have a proficient internal audit staff member perform the audit and report results directly: This still constitutes the CAE auditing their own work. The requirement for external oversight of the engagement remains unmet, regardless of reporting lines .
References
IIA Standard 1130.A2: "Assurance engagements for functions over which the chief audit executive has responsibility must be overseen by a party outside the internal audit activity" .
IIA Practice Advisory 1130.A1-1:Persons transferred to internal audit should not be assigned to audit activities they previously performed until at least one year has elapsed, as such assignments are presumed to impair objectivity .
| Page 4 out of 29 Pages |