Free IIA IIA-CRMA-ADV Practice Questions 2026 - Page 6

Timed Practice Test

Ready for IIA-CRMA-ADV Exam?

This practice test is your final exam before the REAL exam
Dare to Take It?




Practice Questions

Topic 1: Exam Pool A

When an internal auditor applies due professional care to perform an assurance engagement, which of the following must she consider?
1. Findings of the last audit engagement performed.
2. Probability of significant errors, irregularities, or noncompliance.
3. Extent of work needed to achieve engagement objectives.
4. Cost of the engagement versus the potential benefits.

A. 1 and 4 only

B. 2 and 3 only

C. 2, 3, and 4 only

D. 1, 2, 3, and 4

B.   2 and 3 only

Explanation:

According to IIA Standard 1220 (Due Professional Care), when performing an assurance engagement, an internal auditor must consider specific elements related to the engagement's objectives and the inherent risks of the activity being audited. These mandatory considerations are derived directly from Standard 1220.A1 .

Consideration 2 (Probability of significant errors, irregularities, or noncompliance) is a required element. The auditor must be alert to the possibility of fraud, intentional wrongdoing, and significant errors .

Consideration 3 (Extent of work needed to achieve engagement objectives) is also a required consideration. The auditor must determine the necessary scope and depth of procedures to meet the engagement's goals .

The following are not direct requirements of due professional care for an assurance engagement:

Consideration 1 (Findings of the last audit engagement performed) is a factor in audit planning and continuity, but it is not a specific element the auditor must consider under Standard 1220 for exercising due professional care. The Standard's requirements are focused on the current engagement's scope and risks.

Consideration 4 (Cost of the engagement versus the potential benefits) is a consideration for consulting engagements (Standard 1220.C1), not for assurance engagements . While cost-benefit is a valid management principle, the Standards specifically enumerate it for consulting services, not assurance.

References

IIA Standard 1220 – Due Professional Care: This standard requires internal auditors to apply the care and skill of a reasonably prudent and competent auditor. Standard 1220.A1 specifies the elements an auditor must consider, including the extent of work needed to achieve the engagement's objectives, the relative complexity/materiality of matters, the adequacy and effectiveness of GRC processes, and the probability of significant errors, fraud, or noncompliance .

During an account receivables audit, an internal auditor found a significant number of input errors resulting in a $500, 000 balance understatement. Which of the following is the most important question the internal auditor should ask to develop an appropriate recommendation for this finding?

A. Who?

B. How?

C. Why?

D. When?

C.   Why?

Explanation:

This question tests the auditor's ability to formulate recommendations based on audit findings. The most important question to ask when developing a recommendation is "Why?"—specifically, why did the control fail?

Audit recommendations are designed to correct the root cause of a problem. The finding ($500,000 understatement due to input errors) is a symptom, not the cause. To develop an appropriate, actionable, and lasting recommendation, the auditor must understand the underlying reasons for the errors. Asking "Why?" helps the auditor determine:

Was it a lack of training?
Was it a system design flaw?
Was it a missing validation control?
Was it a failure to follow procedures?

Without understanding the root cause, the auditor might recommend a superficial fix (e.g., "re-train staff") that does not address the real issue (e.g., a system that accepts invalid data). Effective recommendations must address the root cause to prevent recurrence.

Why the other options are incorrect

A. Who? Asking "Who?" focuses on the individual(s) responsible for the errors.
While accountability may be relevant, it does not help the auditor develop a systemic, preventive recommendation. Blaming individuals is not the purpose of audit findings; the goal is to fix the process.

B. How? Asking "How?" focuses on the mechanics of the error (how it occurred).
While useful for understanding the sequence of events, it does not get to the underlying reason why the control failed, which is necessary for a sustainable recommendation.

D. When? Asking "When?" focuses on the timing of the errors.
This is relevant for quantifying the impact or determining the period of exposure, but it does not provide insight into the root cause needed to develop a recommendation.

References

IIA Standard 2410 – Criteria for Communicating: Requires that communications include, where appropriate, recommendations for improvement. The standard emphasizes that recommendations should be based on the findings and root causes.

Which of the following is not a role of the internal audit activity in facilitating risk identification and evaluation?

A. Evaluating risk management processes.

B. Recommending accountability for risk management.

C. Providing assurance that risks are evaluated correctly.

D. Supporting managers to identify ways to mitigate risks.

C.   Providing assurance that risks are evaluated correctly.

Explanation:

This question asks which action is not a role of internal audit in facilitating risk identification and evaluation. Facilitation is a consulting/supportive activity where internal audit assists management in improving risk processes without assuming management responsibility (Standard 2120.C1) .

Option C, "Providing assurance that risks are evaluated correctly," is the correct choice because it describes a core assurance role—the third line's responsibility to provide independent, objective conclusions on the effectiveness of risk management (Standard 2120.A1) . This is fundamentally different from facilitation. Assurance involves forming an independent opinion and reporting it to the board; facilitation involves coaching, advising, and supporting management in their own risk activities.

Why the other options are incorrect:

A. Evaluating risk management processes:
This is a legitimate internal audit role under Standard 2120, covering both assurance and consulting activities. It can be part of facilitating improvements in the process.

B. Recommending accountability for risk management:
This is a valid advisory/consulting activity. Internal audit can recommend improvements to roles and responsibilities without assuming management accountability.

D. Supporting managers to identify ways to mitigate risks:
This is a classic consulting/facilitation activity, explicitly permitted under the Standards, provided internal audit does not assume management responsibility for making risk decisions.

References

IIA Standard 2120 – Risk Management: Requires internal audit to evaluate the effectiveness of risk management processes (assurance) and contribute to their improvement (consulting).

IIA Standard 2120.A1: The internal audit activity must evaluate risk exposures relating to the organization's governance, operations, and information systems regarding the reliability and integrity of financial and operational information.

A chief audit executive (CAE) of an international charity reports functionally to the audit committee of the board of directors and administratively to the charity's chief financial officer (CFO).
Which of the following would impair the internal audit function's independence?

A. The CFO determines the scope of internal audit work in the accounting department.

B. The CFO manages the accounting of the budget for the internal audit function.

C. The CFO administers the annual evaluation process for the internal auditors.

D. The CFO provides feedback on the CAE's audit reports.

A.   The CFO determines the scope of internal audit work in the accounting department.

Explanation:

This question addresses the distinction between functional reporting (to the board/audit committee) and administrative reporting (to management). The CAE's functional reporting to the audit committee is the primary safeguard for organizational independence, as it ensures the internal audit activity (IAA) is free from management interference in determining its scope of work and reporting findings.

However, this independence is immediately impaired when management (the CFO) determines the scope of internal audit work, even if only for a specific department (accounting). Standard 1110 requires that the CAE report to a level that allows the IAA to fulfill its responsibilities, which includes having the authority to determine the scope of work without management interference. When management dictates what will be audited, it undermines the IAA's ability to make independent, risk-based decisions about where to focus its assurance efforts. This is a direct violation of the principle that the IAA must determine its own priorities based on risk assessment—not management's preferences.

Why the other options are incorrect:

B. The CFO manages the accounting of the budget for the IAA:
This is a normal administrative function that does not impair independence. Managing the budget (i.e., accounting for expenditures) is operational, not decision-making over audit priorities.

C. The CFO administers the annual evaluation process for the internal auditors:
This is also an administrative task. While the CFO may coordinate logistics, the functional evaluation of the CAE's performance—and by extension the IAA's effectiveness—is ultimately the responsibility of the audit committee, not the CFO.

D. The CFO provides feedback on the CAE's audit reports:
Providing feedback is not the same as approving, altering, or directing the content of reports. Management may offer comments or perspectives, but the CAE retains the authority to issue final reports and report directly to the audit committee without management censorship.

References

IIA Standard 1100 – Independence and Objectivity: "The internal audit activity must be independent, and internal auditors must be objective in performing their work."

IIA Standard 1110 – Organizational Independence: "The chief audit executive must report to a level within the organization that allows the internal audit activity to fulfill its responsibilities." The interpretation clarifies that functional reporting to the board includes the authority to determine the scope of internal audit work.

An internal auditor for a large retail chain suspects that a store manager has been stealing money from cash sales by listing the sales as accounts receivable and then writing off the accounts as bad debts. Which of the following irregularities is the most likely cause of the auditor's suspicion?

A. A much higher bad debt expense as a percentage of sales than that of previous years.

B. A much higher bad debt expense as a percentage of sales than that of other stores.

C. A much higher percentage of past-due accounts receivable than that of other stores.

D. A much higher percentage of past-due accounts receivable than that of previous years.

A.   A much higher bad debt expense as a percentage of sales than that of previous years.

Explanation:

The suspected scheme involves lapping or fraudulent write-offs. The store manager is allegedly recording cash sales as accounts receivable (instead of cash) to steal the cash, and then later writing off those fabricated receivables as bad debts to conceal the theft.

Why the other options are incorrect

B. Comparing to other stores:
While a variance from other stores is a useful indicator, it is less direct than comparing to the same store's own historical performance. Differences in local economic conditions, customer demographics, or management styles between stores could explain some variation, making this a less definitive red flag for the specific scheme.

C & D. Higher percentage of past-due accounts receivable:
These indicators point to issues with collectibility or the aging of real receivables (e.g., a weakening credit policy or economic downturn). They do not directly indicate the fraudulent write-off of fake receivables. In the suspected scheme, the receivables are written off, so they would not appear as past-due; they are removed from the aging schedule entirely.

References

IIA Standard 2320 – Analysis and Evaluation:Internal auditors must base conclusions on appropriate analyses, including analytical review procedures such as comparing current financial data to prior periods .

IIA Practice Guide – "Analytical Procedures": Recommends trend analysis as a key technique to identify unusual fluctuations, especially for detecting fraud. Comparing a store's current-year bad debt percentage to its own historical percentages is a classic trend analysis.

Which of the following would most likely be considered a red flag for fraud?

A. An organization lacks a whistleblower hotline for reporting suspicious activity.

B. A senior manager has been delegating the authority to sign-off on small dollar amount purchases to a subordinate.

C. An employee in charge of payroll disbursements has rotated these duties with several colleagues.

D. An employee with significant personal debt is in charge of handling large wire transfers for the organization.

D.   An employee with significant personal debt is in charge of handling large wire transfers for the organization.

Explanation:

This scenario combines two classic fraud risk factors from the Fraud Triangle—pressure/incentive (significant personal debt) and opportunity (handling large wire transfers). When an individual experiencing severe financial strain is also in a position of trust with direct access to significant organizational assets, it creates a high-risk environment where the motivation to commit fraud and the means to execute it coexist. This is widely recognized as a red flag for potential fraudulent activity.

Why the other options are incorrect:

A. Lacks a whistleblower hotline:
While the absence of a whistleblower hotline is a control deficiency, it is not a direct "red flag" of fraud in the same way as a specific combination of personal pressure and access to assets is. It represents a weakness in detection but does not indicate that fraud is occurring.

B. Delegating sign-off authority for small purchases:
Delegating low-value approvals is a normal management practice and does not create a significant risk, as the dollar amounts are small. It is not a fraud indicator.

C. Rotating payroll duties with colleagues:
Rotation of duties is a control activity and a strength, not a red flag. It reduces the risk of fraud by preventing any single individual from having unchecked control over a process.

D. An employee with significant personal debt is in charge of handling large wire transfers:
This is the correct answer, as it combines pressure (debt) and opportunity (access to large transfers), which are major predictors of fraud.

References:

IIA Practice Advisory 1210.A2-1 – Identification of Fraud: Lists red flags such as an employee living beyond their means, excessive personal debt, and a reluctance to take vacations.

IIA Practice Guide – "Auditing Internal Fraud": Describes the Fraud Triangle (Pressure, Opportunity, Rationalization) and identifies combining personal financial pressure with access to assets as a key red flag.

Which of the following is an example of a transaction-level control?

A. Human resource policies.

B. Tone at the top.

C. Reconciliations of primary accounts.

D. Inventory counts.

C.   Reconciliations of primary accounts.

Explanation:

Internal controls are often categorized by their scope and application. Transaction-level controls are specific controls that operate at the level of individual transactions or day-to-day business processes. Their purpose is to ensure that individual transactions are authorized, complete, accurate, and valid.

A reconciliation of primary accounts (e.g., bank reconciliations, subledger-to-general ledger reconciliations) is a classic transaction-level control. It verifies the accuracy and completeness of transactions by comparing internal records against external or independent sources, ensuring that all recorded transactions are properly posted and accounted for.

Why the other options are incorrect:

A. Human resource policies:
These are entity-level controls, as they establish broad standards of conduct and operation that affect the entire organization, not individual transactions.

B. Tone at the top:
This is a foundational component of the control environment, an entity-level control. It sets the overall cultural and ethical framework for the organization.

D. Inventory counts:
While a physical inventory count is a control over inventory transactions, the policy of performing inventory counts is typically categorized as an entity-level control due to its pervasive nature across the organization. The performance of a specific count for a specific transaction can be considered a transaction-level control, but in the context of this question, it is treated as a broader, periodic control. However, note that inventory counts are generally classified as monitoring or review controls rather than transaction-level controls like reconciliations.

References:

IIA Standard 2130 – Control:Requires internal auditors to evaluate the effectiveness of controls, which includes distinguishing between entity-level and transaction-level controls.

COSO Internal Control – Integrated Framework (2013): Distinguishes between entity-level controls (which address the overall control environment and pervasive risks) and transaction-level controls (which address specific, routine processes such as reconciliations, approvals, and verifications).

Which of the following is the most effective strategy to manage the risk of foreign exchange losses due to sales to foreign customers?

A. Hire a risk consultant.

B. Implement a hedging strategy.

C. Maintain a large foreign currency balance.

D. Insist that customers only pay in a stable currency.

B.   Implement a hedging strategy.

Explanation:

Foreign exchange (FX) risk arises from the potential for losses due to unfavorable movements in currency exchange rates. This directly impacts the value of receivables from foreign customers. A hedging strategy is the most recognized and effective financial technique to manage this risk. It involves using financial instruments, such as forward contracts, futures, or options, to lock in an exchange rate for a future transaction. This effectively neutralizes the uncertainty of currency fluctuations, providing a predictable cash flow and protecting the organization's profit margins.

Why the other options are incorrect

A. Hire a risk consultant:
While a consultant may provide valuable advice, they do not manage the risk directly. The risk remains unmanaged unless the organization itself implements specific financial controls or instruments. This is an advisory action, not a primary risk management strategy.

C. Maintain a large foreign currency balance:
This is a speculative approach, not a control. Holding large balances exposes the organization to additional FX risk as the value of that currency fluctuates. It does not mitigate risk; it concentrates it.

D. Insist that customers only pay in a stable currency:
This is not a realistic or feasible strategy for most organizations. It would likely alienate customers and harm competitive positioning. Even a "stable" currency carries FX risk relative to the organization's domestic currency, and this approach does not provide a structural control.

References

IIA Standard 2120 – Risk Management:The internal audit activity must evaluate the effectiveness and contribute to the improvement of risk management processes. This includes assessing the appropriateness of strategies, such as hedging, used to manage financial risks.

Which of the following actions should an internal auditor take to exercise due professional care?
1. Consider the probability of significant noncompliance in each audit engagement.
2. Weigh the cost of assurance against the benefits.
3. Perform assurance procedures with sufficient care to ensure that all risks are identified.

A. 1 and 2 only

B. 1 and 3 only

C. 2 and 3 only

D. 1, 2, and 3

A.   1 and 2 only

Explanation:

Due professional care, as defined by IIA Standard 1220, requires internal auditors to apply the care and skill expected of a reasonably prudent and competent auditor. This includes specific considerations, but it does not guarantee infallibility or the absolute identification of all risks.

Statement 1 is correct.
Standard 1220.A1 explicitly requires internal auditors to consider the probability of significant errors, fraud, or noncompliance in each engagement. This is a mandatory element of exercising due professional care.

Statement 2 is correct.
Weighing the cost of assurance against the potential benefits is a required consideration. However, note that Standard 1220.C1 specifically applies this to consulting engagements (not assurance engagements). But in the broader context of exercising professional care, it is still a valid consideration for an auditor when planning the extent of work.

Statement 3 is incorrect.
Due professional care does not imply that the auditor must identify all risks. Standard 1220 explicitly states that "due professional care does not imply infallibility." Auditors provide reasonable assurance, not absolute certainty. Expecting to identify all risks is unrealistic and contrary to the Standards.

References

IIA Standard 1220 – Due Professional Care: "Internal auditors must apply the care and skill expected of a reasonably prudent and competent internal auditor. Due professional care does not imply infallibility."

When conducting an interview, an internal auditor is most likely to ask open-ended questions in order to:

A. Obtain specific answers and maximize efficiency.

B. Gather factual data on several different topics.

C. Determine agreement or disagreement with a stated viewpoint.

D. Obtain information based on the person's own perspective.

D.   Obtain information based on the person's own perspective.

Explanation:

Open-ended questions are designed to elicit narrative, descriptive responses rather than simple "yes/no" or one-word answers. They typically begin with words like "how," "why," "describe," or "tell me about." The primary purpose of using open-ended questions in an audit interview is to encourage the interviewee to speak freely and provide information from their own perspective, including their understanding of processes, observations, concerns, and rationale. This allows the auditor to gather rich, contextual information that may not be captured by closed questions and can reveal insights into control awareness, potential weaknesses, or cultural factors that are critical to the audit.

Why the other options are incorrect:

A. Obtain specific answers and maximize efficiency:
This describes closed-ended or direct questions (e.g., "Did you approve this invoice?"). While efficient, they do not encourage elaboration or perspective.

B. Gather factual data on several different topics:
This is typically achieved through review of documents, data analytics, or structured questionnaires, not through open-ended interview questions, which are better suited for exploring context rather than collecting multiple discrete facts.

C. Determine agreement or disagreement with a stated viewpoint:
This is the purpose of leading or closed-ended questions, which are used to confirm or refute specific statements, not to explore the interviewee's own perspective.

References:

IIA Practice Guide – "Interviewing in Internal Audit": Recommends the use of open-ended questions to encourage dialogue, build rapport, and gather information on the interviewee's understanding and perspective.

IIA Standard 2310 – Identifying Information: Requires auditors to identify sufficient, reliable, relevant, and useful information. Open-ended interviews help obtain qualitative information that complements documentary evidence.

Page 6 out of 29 Pages