Free IIA IIA-CRMA-ADV Practice Questions 2026 - Page 7

Timed Practice Test

Ready for IIA-CRMA-ADV Exam?

This practice test is your final exam before the REAL exam
Dare to Take It?




Practice Questions

Topic 1: Exam Pool A

The internal audit supervisor is reviewing the workpapers prepared by the staff. According to the Standards, which of the following statements regarding workpaper supervision is not true?

A. Review notes of questions that arise during the review process must be retained.

B. Dating and initialing each workpaper provides evidence of review.

C. Workpaper review allows for staff training and development.

D. Workpapers may be amended during the review process.

A.   Review notes of questions that arise during the review process must be retained.

Explanation:

The supervisor's review of workpapers is a critical part of engagement supervision, ensuring quality and staff development. Review notes are a tool used during this process, but IIA guidance clarifies that there is no mandatory requirement to retain them. They are used to ask questions and request additional information from the auditor. Once the concerns are resolved, the workpapers are updated, and the review notes can be discarded. The key is that the final workpapers, not the intermediary review notes, are the permanent record of the audit. The fact that a review occurred and issues were resolved must be documented, but the questions themselves do not need to be retained.

Why the other options are incorrect:

B. Dating and initialing each workpaper provides evidence of review.
This is a common and recommended method for documenting that supervision has occurred. While the standard may not require each page to be signed off, documenting the review process with evidence like a reviewer's initials and date is a key practice.

C. Workpaper review allows for staff training and development.
This is a fundamental purpose of supervision as outlined in Standard 2340, which states that engagements must be supervised to ensure "objectives are achieved, quality is assured, and staff is developed".

D. Workpapers may be amended during the review process.
This is a standard part of the review process. The purpose of review notes is to identify areas that need clarification or additional evidence, and the auditor is expected to amend the workpapers accordingly.

References:

IIA Standard 2340 – Engagement Supervision: Engagements must be properly supervised to ensure objectives are achieved, quality is assured, and staff is developed.

IIA Practice Advisory 2340-1 – Engagement Supervision: Review notes may be written by the reviewer and, after being cleared, may be discarded, or they may be retained.

According to IIA guidance, which of the following statements is true?

A. Risks in IT processes are best mitigated by individual controls.

B. The overall focus of the framework is on significant controls in all critical IT applications.

C. IT risks and related controls are operational and best identified using a bottom-up approach.

D. Control process risks are found at multiple layers of the IT environment.

D.   Control process risks are found at multiple layers of the IT environment.

Explanation:

According to the IIA's Guide to the Assessment of IT (GAIT) guidance, IT control process risks do not exist in a single, isolated area. They are pervasive across the entire technology stack and can be found at various layers including application program code, database, operating systems, and network. Therefore, to effectively manage risk, an organization must assess controls across all these layers, recognizing that a weakness in one layer can compromise the entire IT environment.

Why the other options are incorrect:

A. Risks in IT processes are best mitigated by individual controls:
Incorrect. GAIT Principle 4 states that risks are mitigated by the achievement of IT control objectives, not individual controls. It is the cumulative effect of multiple controls working together that achieves the objective and mitigates the risk.

B. The overall focus of the framework is on significant controls in all critical IT applications:
Incorrect. The guidance focuses specifically on IT General Controls (ITGC) that affect financial reporting. The focus is not "all critical IT applications" but on identifying which specific ITGCs are necessary for the continued reliable operation of controls that mitigate risks to financial reporting.

C. IT risks and related controls are operational and best identified using a bottom-up approach:
Incorrect. GAIT Principle 1 states that identifying risks and related controls should be a continuation of a top-down, risk-based approach. This approach starts with business objectives and significant accounts, working down to the IT controls that support them, rather than starting from the technical details and working up.

References:

IIA's GAIT (Guide to the Assessment of IT General Controls Scope Based on Risk) – Core Principles 1, 2, 3, and 4.

IIA Standard 2120 – Risk Management: Requires the internal audit activity to evaluate the effectiveness of risk management processes, which in an IT context necessitates evaluating risks at multiple technology layers.

Which of the following are components of the COSO enterprise risk management framework?
1. Objective setting.
2. External environment.
3. Data collection.
4. Control activities.

A. 1 and 3 only

B. 1 and 4 only

C. 2 and 3 only

D. 2 and 4 only

B.   1 and 4 only

Explanation:

The COSO Enterprise Risk Management (ERM) framework is structured around specific components that define its scope. The 2004 COSO ERM – Integrated Framework outlines eight interrelated components, including Objective Setting and Control Activities. This framework was updated in 2017 and reorganized into five core components, one of which is Strategy and Objective-Setting, while Control Activities remains a key component. Thus, both listed items are established components of the framework.

Why the Other Options Are Incorrect:

2. External environment:
This is an element considered during risk identification and assessment, but it is not a standalone component of the framework. The framework includes "Internal Environment," not "External Environment".

3. Data collection:
While "Information and Communication" is a component, "data collection" itself is not listed as a core component in the official framework structure.

References:

IIA's COSO ERM Framework Overview: Identifies the five components of the updated 2017 framework, which includes "Strategy and Objective-Setting" and "Control Activities".

COSO ERM – Integrated Framework (2004): Lists the eight components, including "Objective Setting" and "Control Activities".

Which of the following scenarios exemplifies a potential internal control weakness?

A. The same employee who receives cash from customers prepares a prelisting of cash receipts.

B. The same employee who records cash receipts in the accounts receivable subsidiary ledger ensures that the ledger automatically updates the information.

C. The same employee who restrictively endorses checks received from customers prepares the bank's check deposit slips.

D. The same employee who makes deposits at the bank prepares the monthly bank reconciliation.

D.   The same employee who makes deposits at the bank prepares the monthly bank reconciliation.

Explanation:

This scenario represents a classic segregation of duties failure. The employee who has custody of assets (making deposits at the bank) also performs the reconciliation function (preparing the monthly bank reconciliation). This is a critical weakness because the employee could steal cash or manipulate deposits and then alter the bank reconciliation to conceal the theft. The person performing the reconciliation should be independent of the custody and recording functions to provide an objective check on the completeness and accuracy of the cash transactions.

Why the other options are incorrect

A. The same employee who receives cash from customers prepares a prelisting of cash receipts:
This is actually an appropriate segregation of duties. The employee is simply documenting the cash received as it comes in, which is part of the same custody function. The risk arises if this same person also records or reconciles the receipts.

B. The same employee who records cash receipts in the accounts receivable subsidiary ledger ensures that the ledger automatically updates the information:
This is a system-level recording function, not a segregation issue. The ledger update is a programmed control, not a manual override by the employee.

C. The same employee who restrictively endorses checks received from customers prepares the bank's check deposit slips:
This is still within the custody function and does not create a control weakness. The endorsement and deposit slip preparation are part of the same asset-handling process.

References

IIA Standard 2130 – Control: Requires internal auditors to evaluate the effectiveness of controls, which includes assessing segregation of duties. COSO Internal Control – Integrated Framework (2013): Identifies segregation of duties as a key control activity to prevent errors and fraud.

An organization's chief audit executive (CAE) determines that the internal audit staff does not have the requisite skills to conduct an audit of the financial derivatives area. Which of the following would be the best course of action for the CAE to follow?

A. Outsource the audit engagement to a qualified external auditing firm without burdening the audit committee with the decision.

B. Determine the requisite knowledge needed, and obtain the proper training for auditors, even if the training will significantly push back the project's timeframe as outlined by the audit committee.

C. Notify the audit committee of the problem, and assign the most competent auditors on staff to perform the audit engagement.

D. Employ the skills of a financial derivatives expert to consult on the project, and supplement the consulting with a local seminar on financial derivatives.

D.   Employ the skills of a financial derivatives expert to consult on the project, and supplement the consulting with a local seminar on financial derivatives.

An internal auditor makes a series of observations when performing an analytical review of division operations. The auditor notes the following things: the current ratio is increasing and the quick ratio is decreasing, sales and current liabilities have remained constant, and the number of day sales in inventory is increasing. Which conclusion should the auditor

A. Cash or accounts receivable has decreased.

B. The gross margin has decreased.

C. The division produced fewer items this year than in prior years.

D. The gross margin has increased.

A.   Cash or accounts receivable has decreased.

Explanation:

The scenario presents three key financial indicators:

Current ratio is increasing.
Quick ratio is decreasing.
Sales and current liabilities are constant.
Days sales in inventory (DSI) is increasing.
The current ratio is calculated as Current Assets / Current Liabilities. Since current liabilities are constant, an increasing current ratio means current assets are increasing.

Why the other options are incorrect:

B. The gross margin has decreased: Gross margin is a profitability measure (sales minus cost of goods sold). The given ratios provide no direct information about gross margin, which would require data on cost of sales.

C. The division produced fewer items this year: Increasing DSI suggests more inventory relative to sales, not fewer production. If production had decreased, DSI would likely decrease (less stock to sell), not increase.

D. The gross margin has increased: Same as B—no information on cost of sales or gross margin is provided. The ratios given are liquidity and activity metrics, not profitability metrics.

References:

IIA Standard 2320 – Analysis and Evaluation: "Internal auditors must base conclusions and engagement results on appropriate analyses and evaluations." Analytical review procedures, including ratio analysis, are recognized techniques under this standard.

IIA Practice Guide – "Analytical Procedures": Recommends the use of ratio analysis (e.g., current ratio, quick ratio, and days sales in inventory) to identify unusual trends and relationships. It emphasizes that auditors must understand the underlying business and financial relationships to draw valid conclusions.

The director of purchasing, a certified internal auditor (CIA), signs a contract to procure a large order from a supplier whose products provide the best price, quality, and performance. A few days after signing the contract, the supplier presents the CIA with $1, 000 as a gift. Which statement regarding acceptance of the money is correct?

A. Accepting the money would be prohibited only if it were non-customary.

B. Accepting the money would violate the IIA Code of Ethics.

C. Because the CIA is not acting as an internal auditor, accepting the money would be governed only by the organization's code of conduct.

D. Because the contract was signed before the money was offered, accepting the money would not violate the IIA Code of Ethics.

B.   Accepting the money would violate the IIA Code of Ethics.

Explanation:

This scenario directly implicates the Integrity and Objectivity principles of the IIA Code of Ethics, which apply to all individuals who hold the CIA certification—regardless of their current role. The gift was offered after a contract was signed, but the Code is not limited to the audit process; it governs all professional conduct.

Accepting the $1,000 gift creates an actual or perceived conflict of interest and a clear impairment to objectivity. The Code's Rule of Conduct under Objectivity states that internal auditors shall not accept anything that may impair or be presumed to impair their professional judgment. The Code's Integrity principle further prohibits accepting gifts that could be perceived as influencing decisions. The fact that the contract was signed prior does not eliminate the ethical violation—the gift still creates an appearance of impropriety and a conflict between personal gain and professional duty. A prudent professional would decline the gift to maintain independence and impartiality.

Why the other options are incorrect:

A. Accepting the money would be prohibited only if it were non-customary:
Incorrect. Even if accepting gifts is customary, the Code prohibits accepting anything that may impair objectivity. The size of the gift ($1,000) is substantial enough to create an appearance of impropriety, regardless of custom.

C. Because the CIA is not acting as an internal auditor, accepting the money would be governed only by the organization's code of conduct:
Incorrect. The IIA Code of Ethics applies to all certified internal auditors, whether they are acting as internal auditors or in other capacities.

D. Because the contract was signed before the money was offered, accepting the money would not violate the IIA Code of Ethics:
Incorrect. Accepting the gift after the contract is signed still creates an appearance of impropriety and violates the Objectivity principle. Professional judgment and impartiality may be perceived as compromised.

References:

IIA Code of Ethics – Principle I: Integrity: Internal auditors shall not accept anything that may impair or be presumed to impair their professional judgment.

IIA Code of Ethics – Principle II: Objectivity: Internal auditors shall not accept anything that may impair or be presumed to impair their professional judgment.

A computer system automatically locks a user's account after three unsuccessful attempts to log on.
Which type of control does this scenario represent?

A. Corrective control.

B. Preventive control.

C. Detective control.

D. Compensating control.

B.   Preventive control.

Explanation:

A control that automatically locks a user's account after three unsuccessful login attempts is a preventive control. Its purpose is to deter, stop, or prevent an undesirable event from occurring—in this case, unauthorized access to the system. By locking the account, the control actively blocks the attacker (or anyone making repeated failed attempts) from continuing to guess passwords, thereby preventing a potential security breach before it happens.

Why the other options are incorrect:

A. Corrective control:
These controls are designed to remediate or fix issues after they have occurred (e.g., restoring data from backup after corruption). Locking an account after attempts is not correcting an error; it is blocking an ongoing threat.

C. Detective control:
These controls identify and report that an event has already occurred (e.g., audit logs, intrusion detection alerts). This control does not detect a breach; it actively prevents one from proceeding.

D. Compensating control:
These are alternative controls used when a primary control is not feasible or fails (e.g., manager override for an unavailable system). Account lockout is a primary security control, not a substitute for another missing control.

References:

IIA Standard 2130 – Control: Requires internal auditors to evaluate the effectiveness of controls, including their classification (preventive, detective, corrective).

IIA Practice Guide – "Auditing Information Technology Controls": Defines preventive controls as those designed to prevent errors, fraud, or unauthorized access from occurring. Account lockout mechanisms are a classic example of a preventive IT control.

Which of the following would not be a red flag for fraud?

A. Several recent, large expenditures to a new vendor have not been documented.

B. A manager has bragged about multiple extravagant vacations taken within the last year, which are excessive relative to the manager's salary.

C. A weak control environment has been accepted by management to encourage creativity.

D. New employees occasionally fail to meet established project deadlines due to staffing shortages.

D.   New employees occasionally fail to meet established project deadlines due to staffing shortages.

Explanation:

This question asks which scenario is not a red flag for fraud. A red flag is an indicator, anomaly, or warning sign that suggests a heightened risk of potential fraud. Option D describes a routine operational issue—new employees missing deadlines due to staffing shortages. This is a common performance management problem, not an indicator of fraudulent activity.

Why the other options are incorrect:

A. Several recent, large expenditures to a new vendor have not been documented:
This is a red flag because undocumented transactions may indicate fraudulent payments or kickback schemes. The lack of proper documentation is a classic warning sign of fraudulent activity.

B. A manager has bragged about multiple extravagant vacations taken within the last year, which are excessive relative to the manager's salary:
This is a red flag because it suggests the manager may be living beyond their means, which is one of the most common behavioral indicators of fraud. It may indicate they are receiving undisclosed income from fraudulent activities.

C. A weak control environment has been accepted by management to encourage creativity:
A weak control environment provides opportunity for fraud, and management's acceptance of it is a known red flag. A poor control environment and management override are major fraud risk factors.

References:

IIA Standard 1210.A2 – Proficiency: The internal audit activity must have sufficient knowledge to evaluate the risk of fraud.

IIA Practice Advisory 1210.A2-1 – Identification of Fraud: Lists behavioral red flags, including lifestyle changes and living beyond means.

According to IIA guidance, which of the following best describes processes and tools typically used in ongoing internal assessments?

A. Benchmarking of the internal audit activity's practices and performance.

B. Report of internal assessment results, response plans, and outcomes.

C. Analysis of performance metrics such as cycle times.

D. Self-assessments and surveys of stakeholder groups.

C.   Analysis of performance metrics such as cycle times.

Explanation:

According to IIA guidance, ongoing internal assessments are a key part of the Quality Assurance and Improvement Program (QAIP) and are primarily achieved through two interrelated activities: ongoing monitoring and periodic self-assessments.

A core component of ongoing monitoring is the analysis of performance metrics. This helps the chief audit executive (CAE) determine whether internal audit processes are delivering quality on an engagement-by-engagement basis. Such metrics often include the analysis of key performance indicators (KPIs) like engagement timeliness, budget-to-actual variance, and audit plan completion rates—all of which can be encompassed by analyzing "cycle times".

Why the other options are incorrect:

A. Benchmarking of the internal audit activity's practices and performance:
Benchmarking is a tool that can be used as part of periodic self-assessments or external assessments to evaluate performance against peers, not a defining tool of ongoing internal assessments.

B. Report of internal assessment results, response plans, and outcomes:
This describes the output or communication of assessment results, not the processes and tools used to perform the ongoing assessment itself.

D. Self-assessments and surveys of stakeholder groups:
These are part of periodic internal assessments. The question asks for processes and tools used in ongoing internal assessments, which rely more on continuous monitoring activities like supervision and KPI analysis, rather than periodic self-evaluations.

References:

IIA Standard 1311 – Internal Assessments: Requires internal assessments to include both ongoing monitoring and periodic self-assessments.

Implementation Guide 1311 – Internal Assessments: Provides detailed guidance on ongoing monitoring mechanisms, including the use of checklists, feedback, and performance measures such as KPIs.

Page 7 out of 29 Pages