Free IIA IIA-CRMA-ADV Practice Questions 2026 - Page 5
Ready for IIA-CRMA-ADV Exam?
This practice test is your final exam before the REAL exam
Dare to Take It?
Practice Questions
Topic 1: Exam Pool A
When internal auditors are preparing workpapers for the testing stage of an engagement,
which of the following guidelines should be observed?
1. Include copies of all client files that were reviewed for the audit.
2. Avoid the use of professional, industry-appropriate jargon and technical terms.
3. Indicate the original sources of all data and information used in the workpapers.
4. Leave blank space for cross-references to be completed during the post-audit process.
A. 1 and 2 only
B. 1 and 4 only
C. 2 and 3 only
D. 3 and 4 only
Explanation:
When preparing workpapers for the testing stage, internal auditors must adhere to the following key guidelines:
Indicate original sources of all data – This is mandatory. Workpapers must clearly document the origin of every piece of information (e.g., system reports, vendor invoices, personnel files) to ensure verifiability, replicability, and traceability of conclusions.
Complete all workpapers during the engagement – Workpapers should be fully prepared, cross-referenced, and reviewed before the engagement concludes. Leaving blank spaces for later completion undermines quality and reviewability.
Avoid excessive documentation – Auditors should include sufficient, relevant evidence, not copies of entire client files. Over-documentation reduces efficiency and obscures key findings.
Use clear, understandable language – While professional jargon is acceptable when defined for the intended reviewer, workpapers should be clear to a knowledgeable reviewer who did not perform the work.
Why Other Options Are Incorrect
Statement 1 (copies of all client files): Incorrect. Workpapers should contain sufficient evidence, not exhaustive copies. Over-documentation is inefficient and unnecessary.
Statement 2 (avoid professional jargon): Incorrect. Technical terms are acceptable when used appropriately and defined for clarity.
Statement 4 (leave blank space for cross-references): Incorrect. Workpapers must be complete, accurate, and self-explanatory at the time of review. Cross-references should be completed during fieldwork, not deferred.
References
IIA Standard 2330 – Recording Information: "Internal auditors must document sufficient, reliable, relevant, and useful information to support the engagement results and conclusions."
IIA Implementation Guide 2330: Workpapers should include the source of information, be complete, accurate, and clear. Cross-references should be made during fieldwork.
Which of the following is the most significant disadvantage of using checklists to evaluate internal controls?
A. They serve as a reminder of what controls should exist in a process.
B. They require yes/no responses to specific questions, not open-ended responses.
C. They do not capture all controls that may exist.
D. They are useful in assessing risk.
Explanation:
The most significant disadvantage of using checklists to evaluate internal controls is that they are inherently incomplete and restrictive. A checklist is a pre-defined list of expected controls based on the auditor's prior knowledge, industry norms, or generic templates. While this provides structure and consistency, it also creates a dangerous cognitive bias: the auditor focuses only on verifying the presence of the listed controls and may fail to identify unique, informal, or undocumented controls that are critical to mitigating specific risks. This can result in a false sense of assurance, as the auditor concludes that controls are adequate based solely on the checklist, while significant risks remain unaddressed because their controls were not included in the tool. Effective control evaluation requires professional judgment, adaptability, and a thorough understanding of the process—qualities that a rigid checklist cannot replace.
Why Other Options Are Incorrect
A. They serve as a reminder of what controls should exist in a process:
This is an advantage, not a disadvantage. Checklists help ensure consistency and completeness in audit planning by reminding the auditor of common or expected control points. Since the question asks for a disadvantage, this option is incorrect.
B. They require yes/no responses, not open-ended responses:
While this is a limitation—reducing the depth of inquiry—it is not the most significant disadvantage. The yes/no format can be mitigated by supplementing the checklist with interviews, walkthroughs, and observations. The far greater risk is the checklist's inability to identify unknown or unexpected controls, which cannot be addressed simply by adding open-ended questions.
D. They are useful in assessing risk:
This is an advantage. Checklists can help identify areas of higher inherent risk or where controls are expected to operate, supporting the risk assessment process. However, they should not be the sole basis for risk evaluation, and their utility in risk assessment does not constitute a disadvantage.
References
IIA Standard 2130 – Control: Requires internal auditors to evaluate the effectiveness of controls, which demands a comprehensive, risk-based approach that goes beyond ticking boxes. The Standards emphasize professional judgment over mechanistic checklists.
Which of the following conditions is the most likely indicator of fraud?
A. Commissions are paid based on verified increases to sales.
B. Departmental reports are consistently issued in an untimely manner.
C. A manager regularly assumes subordinates' duties.
D. Lower earnings occur during the industry's down cycle.
Explanation:
This question asks for the condition that is the most likely indicator of fraud, which is a classic fraud "red flag." Consistently untimely departmental reports are a significant indicator of fraud for two key reasons. First, delays in reporting can signal manipulation. The perpetrator may be delaying the issuance of reports to buy time to cover up fraudulent transactions or to alter records before they are reviewed . Second, it is a failure of a key detective control. Timely reporting is a fundamental internal control. When a manager is consistently late with reports, it suggests that the control environment is weak or being deliberately circumvented, providing an ideal environment for fraud to occur and go undetected .
Why the other options are incorrect
A. Commissions are paid based on verified increases to sales: This is a normal, legitimate incentive structure. It is only a fraud risk if the verification process is weak or non-existent, not when the increases are verified .
C. A manager regularly assumes subordinates' duties: While it can indicate poor delegation or capacity issues, this is not a classic red flag for fraud. Fraud indicators often involve a manager not allowing others to perform duties (e.g., not taking vacations to conceal their actions) .
D. Lower earnings occur during the industry's down cycle: This is an expected business outcome of external economic conditions and is not an indicator of fraud.
References
IIA Standard 1210.A2 – Proficiency: The internal audit activity must have sufficient knowledge to evaluate the risk of fraud, including recognizing common fraud indicators .
IIA Practice Guide – "Auditing Internal Fraud": Lists red flags of fraud, such as unexplained delays in providing information or reports and a manager who refuses to take vacations .
Which of the following actions indicates a lack of due professional care by an internal auditor performing an audit of a store's cash function?
A. The audit report included a well-supported recommendation for a reduction in staff even though such a reduction might adversely impact morale.
B. The auditor tested samples of transactions to test the cash function's process flows.
C. After determining that the cash function internal controls were strong, the audit report assured senior management that fraud was not present.
D. The auditor discovered an instance of potential fraud and reported it immediately to management, but did not alert authorities outside the organization.
Explanation:
This action indicates a lack of due professional care because internal auditors must recognize that strong internal controls do not guarantee the absence of fraud. Due professional care, as defined in IIA Standard 1220, requires auditors to consider the probability of material misstatements, fraud, or noncompliance, and to exercise caution in making absolute assurances. Providing an unqualified statement that "fraud was not present" is a gross overstep because:
Controls can be overridden by collusion.
Management can circumvent controls.
Sampling (as mentioned in Option B) provides only reasonable assurance, not absolute certainty.
Fraud is inherently difficult to detect, especially if collusive or sophisticated.
By making an absolute assertion, the auditor failed to exercise the professional skepticism and care required, which could mislead senior management and create false confidence.
Why the other options are incorrect
A. Report included a recommendation for staff reduction despite morale impact:
This does not indicate a lack of due care. Recommending cost-saving measures, even if they may affect morale, is a legitimate audit conclusion if well-supported by evidence. Due care requires candor, not avoiding unpopular recommendations.
B. Auditor tested samples to test process flows:
This is an appropriate and standard audit procedure. Sampling is a recognized method for obtaining sufficient, reliable evidence, and does not by itself indicate a lack of care.
D. Reported potential fraud to management but did not alert outside authorities:
This is the correct and required action. The internal auditor’s duty is to report fraud to appropriate internal authorities (typically senior management and the board/audit committee), not to external authorities. Reporting outside the organization without legal obligation would violate confidentiality and may not be within the auditor's authority.
References
IIA Standard 1220 – Due Professional Care:"Internal auditors must apply the care and skill expected of a reasonably prudent and competent internal auditor. Due professional care does not imply infallibility."
IIA Standard 1220.A1 – "Internal auditors must consider the probability of significant errors, fraud, or noncompliance."
Why is it important for the chief audit executive to periodically review the audit charter and present the results to senior management and the board?
A. Because management requires the review to measure effectiveness of the internal audit activity.
B. So that the individual objectivity of the internal audit staff can be more clearly established.
C. So that there is assurance of the internal audit staff's proficiency to complete audit activities.
D. Because changes in the organization may impair the internal audit activity's ability to meet its objectives.
Explanation:
The internal audit charter is the foundational document that formally defines the internal audit activity's (IAA) purpose, authority, and responsibility. The IIA Standards require the CAE to periodically review the charter to ensure it remains relevant and adequate as the organization evolves. Organizations undergo constant change—new strategies, acquisitions, regulatory requirements, technological advancements, or shifts in risk appetite. These changes can:
Alter the scope of work the IAA is expected to perform.
Affect the authority or access rights granted to the IAA.
Introduce new risks or governance expectations that are not addressed in the current charter.
If the charter is not updated to reflect these changes, the IAA may lack the mandate or resources to effectively fulfill its responsibilities, potentially compromising its ability to provide independent assurance. Reviewing the charter and presenting results to senior management and the board ensures continued alignment with organizational needs and reaffirms the board's support for the IAA's role.
Why the other options are incorrect:
A. Because management requires the review to measure effectiveness:
Incorrect. The charter does not measure effectiveness; it authorizes the IAA's work. Effectiveness is measured through the Quality Assurance and Improvement Program (QAIP), not the charter review.
B. So that individual objectivity can be more clearly established:
Incorrect. Objectivity is addressed through the Code of Ethics, independence safeguards, and Standards (e.g., 1120, 1130). The charter provides the authority framework, not a mechanism for establishing objectivity.
C. So that there is assurance of the staff's proficiency:
Incorrect. Staff proficiency is assessed through recruitment, training, and performance evaluation—not through a charter review. The charter defines roles broadly, not individual competencies.
References:
IIA Standard 1000 – Purpose, Authority, and Responsibility: "The chief audit executive must periodically review the internal audit charter and present the results to senior management and the board for approval."
After being terminated due to downsizing, an internal auditor finds a different job with an organization in the same industry. Which of the following actions would violate the IIA Code of Ethics?
A. To determine audit priorities in the new job, the auditor uses the audit risk approach that the auditor's previous employer used, without receiving permission to do so.
B. At the new organization, the auditor is asked to develop forms to implement probabilityproportional- to-size sampling. Although unsure of how to perform this type of sampling, the auditor proceeds without asking for assistance.
C. In preparing for an audit at the previous organization, the auditor had conducted a great deal of research on the Internet at home to identify best practices for the management of a treasury function. The auditor has retained much of the research and uses it to conduct an audit of the new employer's treasury function.
D. In the first week at the new organization, the auditor discovers a high fraud risk surrounding the organization's database and suggests that the information technology department implement a new password system to prevent fraudulent actions before they occur.
Explanation:
This action violates the IIA Code of Ethics because it demonstrates a lack of competence and a failure to exercise due professional care. The Code of Ethics requires internal auditors to "perform their work in accordance with the International Standards for the Professional Practice of Internal Auditing" and to "engage only in services for which they have the necessary knowledge, skills, and experience" . By proceeding with a technical task they do not understand, the auditor is knowingly taking on work beyond their proficiency, which could lead to flawed sampling, incorrect conclusions, and a failure to meet the engagement's objectives. A competent auditor would seek guidance, training, or assistance before proceeding. This action also violates Standard 1210 – Proficiency, which requires auditors to possess the knowledge, skills, and competencies needed to perform their responsibilities.
Why the other options are incorrect
A. Using the audit risk approach without permission: Audit methodologies are not proprietary; using a common risk-based approach is acceptable and does not violate the Code of Ethics.
C. Retaining and using research conducted at home: Research on public best practices is not confidential information. Using it in a new job does not violate confidentiality, as it is not proprietary to the previous employer.
D. Recommending a new password system: This is a consulting activity that does not assume management responsibility, making it appropriate. Internal auditors may recommend controls without implementing them.
References
IIA Code of Ethics – Principle I: Integrity: Internal auditors shall perform their work with honesty, diligence, and responsibility.
IIA Code of Ethics – Principle III: Competency: Internal auditors shall engage only in services for which they have the necessary knowledge, skills, and experience.
An internal auditor is conducting an engagement in the accounts payable department,
which includes expressing an opinion at the micro level. According to IIA guidance, which
of the following statements is true regarding micro-level opinions?
1. They are most effective when using a combination of current and prior engagement
findings to draw conclusions.
2. They typically are based on defined procedures such as those found in an accounts
payable reconciliation process.
3. They are discrete and not normally shared with senior management or the board.
4. They can rely on evidence taken from the work of other assurance activities across the
organization.
A. 1 and 2.
B. 1 and 3.
C. 2 and 3.
D. 3 and 4.
Explanation:
A micro-level opinion is an audit opinion on an individual business process, activity, or business unit, such as the accounts payable department in the question. According to IIA guidance, micro-level opinions are typically based on defined, specific procedures and criteria—like those found in an accounts payable reconciliation process—which provide the benchmark for the auditor's assessment. Furthermore, they are most effective when the auditor considers both current and prior engagement findings to draw informed conclusions. Micro-level opinions, while discrete to a specific process, are not necessarily limited in their audience; they can be a critical component of an overall opinion for an entire function or organization.
Why the other options are incorrect
Statement 3:
"They are discrete and not normally shared with senior management or the board." This is incorrect. While micro-level opinions are specific to an individual engagement, their results are important for governance and oversight. As such, they are frequently shared with senior management and the board, either individually or as part of the basis for an overall macro-level opinion.
Statement 4:
"They can rely on evidence taken from the work of other assurance activities across the organization." This is incorrect, particularly for a micro-level opinion. While other assurance providers' work can inform a macro-level opinion, a micro-level opinion typically requires primary, first-hand evidence obtained directly from the engagement's specific scope (the accounts payable department) to support its conclusion.
References
IIA Practice Guide - Formulating and Expressing Internal Audit Opinions defines macro and micro opinions, noting that a micro opinion relates to an individual business process or activity.
IIA Standard 2410.A1 clarifies that engagement-level opinions (micro) require consideration of the engagement results and their significance.
According to IIA guidance, which of the following is the best example of a system application control?
A. A physical security control over a data center.
B. A system development life cycle control.
C. A program change management control.
D. An input control over data integrity.
Explanation:
This question distinguishes between application controls and general IT controls (GITCs). According to IIA guidance, an application control is specifically related to the functioning of a particular application system to support a business process . These controls ensure that data is processed completely, accurately, and in an authorized manner .
Input controls are a primary example of application controls. They are designed to check the integrity of data as it is entered into a business application, verifying that it is accurate, complete, and authorized . This falls squarely within the definition and purpose of application-specific controls.
Why the other options are incorrect
A. A physical security control over a data center
– This is a general IT control, as it provides pervasive protection over the IT environment, not a specific application's processing.
B. A system development life cycle control
– This is a general IT control, managing how applications are created and changed, which is not specific to the operation of a single application's data processing.
C. A program change management control
– This is a general IT control, focusing on the process for authorizing and implementing changes to applications, rather than the controls within the application itself. It is a foundational control that supports the operation of application controls .
References
IIA GTAG (Global Technology Audit Guide) – Auditing Application Controls: Defines application controls as those specific to an application that ensure complete and accurate processing of data, from input through output .
IIA Standard 2130 – Control: Requires auditors to evaluate the effectiveness of controls, which includes distinguishing between application and general controls to assess risk accurately.
According to IIA guidance, which of the following statements is false regarding continuing professional education for the internal audit activity (IAA)?
A. Continuing professional education can be obtained through IAA involvement in research projects.
B. Employers are responsible for ensuring that the continuing professional education needs of the IAA are met.
C. Completion of self-study courses fulfills IAA continuing professional education requirements.
D. Specialized education that meets unique organizational needs cannot qualify as IAA professional development.
Explanation:
The core concept behind Continuing Professional Education (CPE) is to maintain and enhance the knowledge, skills, and competencies required for internal auditors to perform their work effectively . The IIA's Standards explicitly state that internal auditors must enhance their knowledge, skills, and other competencies through continuing professional development . Therefore, any specialized education that meets the unique needs of the organization and contributes to an auditor's competence is, by its very nature, a legitimate and valuable form of professional development. Its relevance to the organization's specific context is an asset, not a disqualifier .
Why the other options are incorrect
A. Continuing professional education can be obtained through IAA involvement in research projects. This is a true statement. The IIA explicitly lists "conducting research projects" and "volunteering with professional organizations" as valid professional development opportunities .
B. Employers are responsible for ensuring that the continuing professional education needs of the IAA are met. This is true. While individual auditors are responsible for their own certification renewal, the organization (employer) is responsible for ensuring the internal audit activity collectively has the necessary competencies. This often involves providing resources and support for professional development .
C. Completion of self-study courses fulfills IAA continuing professional education requirements. This is a true statement. The IIA recognizes a wide range of activities, including "self-study programs," as qualifying for CPE credits .
References
IIA Standard 1230 – Continuing Professional Development: "Internal auditors must enhance their knowledge, skills, and other competencies through continuing professional development."
IIA Implementation Guide 1230: Clarifies that opportunities for professional development include participating in conferences, seminars, research projects, and self-study programs, as well as other internal and external training .
An accounts receivable clerk receives cash payments, posts the payments to customer accounts, and prepares the daily cash deposit. The clerk has been stealing some cash and manipulating the customer payments to hide the theft. This fraud could be detected with which of the following controls?
A. Monthly bank reconciliations are performed by the clerk on a timely basis.
B. Total cash deposits for the month are reconciled to the cash receipts journal.
C. Names, amounts, and dates on remittance advices are reconciled with the names, amounts, and dates recorded in the cash receipts journal.
D. Total cash deposits are compared with the bank reconciliation.
Explanation:
This question addresses a classic segregation of duties and record-keeping failure, where the same clerk handles cash receipts, posts to customer accounts, and prepares deposits. Without proper controls, the clerk can steal cash and conceal the theft by:
Not recording the payment at all (lapping – applying a later payment to an earlier customer's account).
Recording a lower amount than received.
Falsifying customer account information.
The control described in option C is a detailed reconciliation of remittance advices (the customer's remittance slip showing what was paid) against the cash receipts journal (the record of what was posted). This control would detect discrepancies because:
The remittance advice is a third-party source document (from the customer), providing independent evidence of what payment was intended.
The cash receipts journal records what the clerk actually posted.
Any difference between the two—such as a missing posting, an altered amount, or a misapplied payment—would be flagged during reconciliation.
This control directly addresses the manipulation of customer payments, which is the method used to hide the theft.
Why the other options are incorrect:
A. Monthly bank reconciliations are performed by the clerk on a timely basis:
This is a weak or ineffective control because the same clerk who handles cash also performs the reconciliation, defeating the purpose. The clerk could manipulate both records.
B. Total cash deposits for the month are reconciled to the cash receipts journal:
This is a high-level, aggregated reconciliation that compares total deposits to total recorded receipts. It would not detect the theft if the clerk simply steals a portion of the cash and adjusts the total deposit accordingly—the totals might still agree.
D. Total cash deposits are compared with the bank reconciliation:
This is also an aggregate comparison. It would not detect manipulations of individual customer accounts, as the totals could balance while individual postings are incorrect.
References
IIA Standard 2130 – Control: Requires internal auditors to evaluate the effectiveness of controls, including the segregation of duties and reconciliation procedures.
IIA Practice Guide – "Auditing Accounts Payable and Accounts Receivable": Recommends reconciling remittance advices with cash receipts journal entries as a key control to prevent and detect lapping and skimming schemes.
| Page 5 out of 29 Pages |