Free IIA IIA-CRMA-ADV Practice Questions 2026 - Page 8

Timed Practice Test

Ready for IIA-CRMA-ADV Exam?

This practice test is your final exam before the REAL exam
Dare to Take It?




Practice Questions

Topic 1: Exam Pool A

Which of the following would be considered a preventive control?

A. A library control log.

B. A review of exception reports.

C. A password lock on a server.

D. A software scan of financial records for irregularities.

C.   A password lock on a server.

Explanation:

A preventive control is designed to stop an undesirable event from occurring before it happens. A password lock on a server is a classic example—it actively blocks unauthorized individuals from gaining access to the server, thereby preventing potential data breaches, unauthorized modifications, or system misuse. It operates as a gatekeeper, deterring and stopping threats at the point of entry.

Why the other options are incorrect:

A. A library control log:
This is a detective control. It records who has accessed or checked out physical or electronic files, but it does not prevent unauthorized access—it only logs it after the fact for review.

B. A review of exception reports:
This is a detective control. Exception reports highlight deviations from expected patterns (e.g., unusual transactions) after they have occurred, allowing management to investigate and correct them. They do not prevent the deviation.

D. A software scan of financial records for irregularities:
This is a detective control. It scans records after transactions have been processed to identify anomalies, errors, or potential fraud, but it does not prevent them from occurring in the first place.

References:

IIA Standard 2130 – Control: Requires internal auditors to evaluate the effectiveness of controls, including their classification as preventive, detective, or corrective.

IIA Practice Guide – "Auditing Information Technology Controls": Defines preventive controls as those designed to prevent errors, fraud, or unauthorized access from occurring. Password locks are a primary example of a preventive IT control.

Which the following activities should be performed by the internal audit activity to facilitate an effective relationship with the audit committee?
1. Periodically report about the accounting standards followed by the organization.
2. Provide assurance to the audit committee that its charter, activities, and processes are appropriate.
3. Ensure that the role and activities of the internal audit activity are clearly understood and responsive to the needs of the audit committee.
4. Maintain open and effective communications with the audit committee.

A. 1 and 2 only

B. 3 and 4 only

C. 1, 3, and 4 only

D. 2, 3, and 4 only

B.   3 and 4 only

Explanation:

The success of an internal audit activity (IAA) depends heavily on its relationship with the audit committee, which is built on a foundation of clear communication and mutual understanding. Statement 3 is correct because the IAA must ensure its role and activities are clearly understood by the audit committee and are responsive to its needs. This alignment is a core function of the chief audit executive (CAE) in facilitating an effective relationship .

Statement 4 is also correct. Open and effective communication is the cornerstone of this relationship and is explicitly required by IIA standards. The CAE must report periodically to the board and audit committee, which includes information about the audit plan, results of activities, and key risk exposures .

Why the other options are incorrect:

Statement 1 is not a core activity of the IAA to facilitate the relationship.
While internal auditors must evaluate financial information reliability as part of their risk assessments, periodically reporting on the specific accounting standards followed is generally not their responsibility. Their role is to provide assurance on governance, risk management, and control processes, rather than performing the management function of reporting on technical accounting standard compliance .

Statement 2 describes a role that oversteps the IAA's mandate.
The audit committee is responsible for its own charter, activities, and processes. The IAA, under the leadership of the CAE, should provide independent assurance and recommendations on the organization's governance and risk management, but it is not responsible for "providing assurance" to the committee about the appropriateness of its own charter and activities . This would create a conflict of interest and compromise independence.

References:

IIA Standard 1110 – Organizational Independence: This standard establishes the CAE's functional reporting line to the board, which is essential for an effective relationship .

IIA Practice Advisory 1110-1: Clarifies that organizational status and objectivity permit the IAA to render impartial and unbiased judgments

During an internal audit, the internal auditor compares the employee turnover rate in the area being audited with the employee turnover rate in the organization as a whole. This is an example of which of the following analytical auditing procedures?

A. Reasonableness test.

B. Regression analysis.

C. Benchmarking.

D. Trend analysis.

C.   Benchmarking.

Explanation:

Benchmarking is an analytical procedure that involves comparing an organization's metrics, processes, or performance indicators against those of other entities or against internal standards to identify best practices, areas for improvement, or significant deviations. In this scenario, the internal auditor is comparing the turnover rate of a specific area (e.g., a department or division) against the turnover rate of the entire organization (an internal benchmark). This comparison provides context for evaluating whether the area's turnover is unusually high or low relative to the organizational average, which could indicate underlying issues such as poor management, low morale, or compensation problems.

Why the other options are incorrect:

A. Reasonableness test:
This involves analyzing a relationship between two or more data points to see if they are logically consistent (e.g., comparing total payroll expense to number of employees). It does not involve comparing a specific area's metric to an organizational average.

B. Regression analysis:
This is a statistical technique used to model the relationship between a dependent variable and one or more independent variables. It is not a simple comparison of one metric against another.

D. Trend analysis:
This involves comparing data over time (e.g., turnover rates year-over-year) to identify patterns or changes. The auditor in this scenario is comparing across entities (the area vs. the organization), not across time periods.

References:

IIA Standard 2320 – Analysis and Evaluation: Requires internal auditors to base conclusions and engagement results on appropriate analyses and evaluations. Benchmarking is a recognized analytical technique under this standard.

IIA Practice Guide – "Analytical Procedures": Defines benchmarking as comparing client data to internal or external benchmarks to identify unusual fluctuations or relationships.

Which of the following activities best reflects the scope and status of the internal audit activity as defined in the internal audit policy statement?

A. The internal auditor reviews the physical access to merchandise during an inventory count.

B. The audit manager conducts an internal quality assessment of the internal audit activity’s adherence to the Standards.

C. The audit manager refrains from assigning an auditor who was a former payroll clerk to conduct a payroll audit.

D. The board approves the annual performance evaluation of the chief audit executive.

A.   The internal auditor reviews the physical access to merchandise during an inventory count.

Explanation:

The internal audit charter is a formal document that defines the purpose, authority, and responsibility of the internal audit activity . A key element of this charter is defining the scope of internal audit activities, which is the range of actions the function is authorized to perform . This scope is fundamentally tied to the Definition of Internal Auditing: an independent, objective assurance and consulting activity designed to add value and improve an organization’s operations .

An activity like reviewing physical access to inventory is a core assurance task. It directly supports the internal audit's mission of evaluating and improving the effectiveness of risk management, control, and governance processes . This specific task involves the systematic evaluation of internal controls (inventory security), which is a primary component of the audit scope as defined by the Standards .

Why the other options are incorrect:

B. The audit manager conducts an internal quality assessment of the internal audit activity’s adherence to the Standards.
This is a management and quality assurance activity, not a reflection of the audit function's scope as defined in the charter. It pertains to the Standards (Standard 1300 series) governing the internal audit function itself, rather than the activities it is authorized to perform across the organization.

C. The audit manager refrains from assigning an auditor who was a former payroll clerk to conduct a payroll audit.
This action addresses individual objectivity. Avoiding a conflict of interest is a requirement of the Code of Ethics and the Standards, but it relates to the professional conduct of auditors and safeguarding independence, not to defining the scope of work as per the charter.

D. The board approves the annual performance evaluation of the chief audit executive.
This is a governance and oversight action that supports the independence and accountability of the internal audit function. While it relates to the charter's provisions on the CAE's relationship with the board, it is not itself an activity that reflects the audit scope.

References:

IIA Standard 1000 – Purpose, Authority, and Responsibility: The purpose, authority, and responsibility of the internal audit activity must be formally defined in an internal audit charter .

IIA Implementation Guide 1000: The charter defines the scope of internal audit activities and authorizes access to records, personnel, and physical properties relevant to the performance of engagements .

A manufacturing organization discovers that the waste water released has failed to meet permitted limits.
Which control function will be least effective in correcting the issue?

A. Performing a chemical analysis of the water, prior to discharge, for components specified in the permit.

B. Posting signs that tell employees which substances may be disposed of via sinks and floor drains within the facility.

C. Diluting pollutants by flushing sinks and floor drains daily with large volumes of clean water.

D. Establishing a preventive maintenance program for the pretreatment system.

C.   Diluting pollutants by flushing sinks and floor drains daily with large volumes of clean water.

Explanation:

This scenario involves a violation of environmental regulations regarding wastewater discharge. A corrective action is needed to bring the organization back into compliance.

Option C describes dilution, which is a flawed and ineffective approach to correcting a pollution problem. Diluting pollutants does not remove them; it merely reduces their concentration, which is often illegal and ineffective as a long-term solution. Furthermore, flushing large volumes of clean water would increase the total volume of wastewater, potentially violating the permit's volume limits and burdening the treatment system. This is a temporary, non-sustainable fix that fails to address the root cause of the pollution.

Why the other options are incorrect:

A. Performing a chemical analysis of the water, prior to discharge:
This is an effective detective and corrective control. It allows the organization to identify non-compliant water before it is discharged, enabling corrective action to be taken.

B. Posting signs that tell employees which substances may be disposed of:
This is an effective preventive control. It helps ensure that only permitted substances enter the waste stream in the first place.

D. Establishing a preventive maintenance program for the pretreatment system:
This is an effective preventive control. Regular maintenance ensures the treatment system operates effectively, reducing the risk of non-compliant discharges.

References:

IIA Standard 2130 – Control: Requires internal auditors to evaluate the effectiveness of controls, which includes assessing whether corrective actions address root causes.

IIA Practice Guide – "Auditing Environmental Risk and Compliance": dentifies dilution as a weak control and recommends source reduction and treatment as more effective strategies.

An organization has implemented a new automated payroll system that contains a table of pay rates that are matched to employee job classifications. Which control should an internal auditor suggest in order to ensure that the table is updated correctly, and is used only for valid pay changes?

A. Restrict data-table access from management and line supervisors who have the authority to determine pay rates.

B. Require a supervisor in the department, who has the ability to change the table, to compare the changes to a signed management authorization.

C. Ensure that adequate edit and reasonableness checks are built into the automated system.

D. Require a manager, who is independent of the system and who cannot change the table, to authorize and sign-off on any employee pay changes.

D.   Require a manager, who is independent of the system and who cannot change the table, to authorize and sign-off on any employee pay changes.

Explanation:

This question addresses the need for a control to ensure that the pay rate table is updated correctly (accurate data) and only for valid pay changes (authorized transactions). The most effective control is a segregation of duties between the authorization of pay changes and the ability to update the system table.

Option D provides this safeguard by requiring an independent manager—who does not have the ability to change the table—to authorize and sign-off on any pay changes. This ensures that every change is formally approved by someone with proper authority (not the person making the system update), creating an independent verification layer. This prevents unauthorized, erroneous, or fraudulent updates to the pay rate table.

Why the other options are incorrect::

A. Restrict data-table access from management and line supervisors who have the authority to determine pay rates:
This is incorrect because the people who determine pay rates (management/supervisors) are the ones who initiate pay changes. They need a mechanism to communicate those changes. Restricting their access does not ensure that changes are valid or correctly updated; it merely prevents them from making the updates themselves, which could be an appropriate segregation but does not address authorization and accuracy.

B. Require a supervisor in the department, who has the ability to change the table, to compare changes to a signed management authorization:
This is incorrect because the supervisor who can change the table is the same person performing the comparison. There is no independent verification—the person making the change is also checking their own work, which creates a conflict of interest and does not provide an objective review.

C. Ensure that adequate edit and reasonableness checks are built into the automated system:
This is a system-level processing control that can help detect data entry errors (e.g., pay rate too high), but it does not address the authorization of changes. A system check cannot verify whether a pay change was properly approved by management; it only verifies that the data falls within acceptable parameters.

References:

IIA Standard 2130 – Control:Requires internal auditors to evaluate the effectiveness of controls, including segregation of duties and authorization controls.

Why are preventative controls generally preferred to detective controls?

A. Because preventive controls promote doing the right thing in the first place, and lessen the need for corrective action.

B. Because preventive controls are more sensitive and identify more exceptions than detective controls.

C. Because preventive controls include output procedures, which cover the full range of possible reviews, reconciliations and analysis.

D. Because preventive controls identify exceptions after-the-fact, allowing them to be used after the entire review is complete and therefore finding exceptions that detective controls may have missed.

A.   Because preventive controls promote doing the right thing in the first place, and lessen the need for corrective action.

Explanation:

Preventive controls are generally preferred over detective controls because they are designed to stop errors or irregularities from occurring in the first place. By preventing a problem from happening, the organization avoids the cost, time, and effort required to detect and correct the issue after it has occurred. In contrast, detective controls only identify problems after they have happened, which means some damage (financial, operational, or reputational) may have already occurred and corrective action is still needed.

Why the other options are incorrect:

B. Because preventive controls are more sensitive and identify more exceptions than detective controls:
This is incorrect. Preventive controls do not identify exceptions; they prevent them. Detective controls are the ones that identify exceptions after they occur.

C. Because preventive controls include output procedures, which cover the full range of possible reviews, reconciliations and analysis:
This is incorrect. Output procedures, reviews, reconciliations, and analysis are characteristic of detective controls, not preventive controls.

D. Because preventive controls identify exceptions after-the-fact, allowing them to be used after the entire review is complete and therefore finding exceptions that detective controls may have missed:
This is incorrect. It inaccurately describes preventive controls as detective controls. Preventive controls act before an event occurs.

References:

IIA Standard 2130 – Control: Requires internal auditors to evaluate the effectiveness of controls, which includes assessing whether controls are preventive, detective, or corrective. Preventive controls are considered more effective because they stop issues before they arise.

COSO Internal Control – Integrated Framework (2013): Identifies preventive controls as those that stop problems before they occur, thereby reducing the need for corrective action and improving efficiency.

An internal auditor finds during an engagement that payment for the organization's general insurance policy is two months overdue. The issue is informally mentioned tothe finance department which immediately submits the invoice for payment. The auditor decides to exclude this finding from the final audit report as the oversight was immediately corrected and there were no consequences because of this late payment. Which of the following rules of conduct as described in the IIA Code of Ethics, did the auditor fail to uphold?

A. Confidentiality.

B. Objectivity.

C. Integrity.

D. Competency.

B.   Objectivity.

Explanation:

The auditor discovered a material issue—a payment that was two months overdue on a critical policy (general insurance). This finding is significant because:

It represents a control failure (failure to pay on time).
It exposes the organization to potential risk (policy may have lapsed or coverage been interrupted, even if no loss occurred yet).
It indicates a process breakdown that could recur.

The auditor's decision to exclude this finding from the final audit report—simply because it was corrected informally—violates the Integrity principle of the IIA Code of Ethics. The Code requires internal auditors to "perform their work with honesty, diligence, and responsibility" and to "make disclosures of all material facts known to them that, if not disclosed, may distort the reporting of activities under review."

Why the other options are incorrect:

A. Confidentiality:
This principle concerns the unauthorized disclosure of information. The auditor did not disclose confidential information inappropriately; they withheld information from the report, which is the opposite of a confidentiality breach.

B. Objectivity:
While objectivity requires impartiality and freedom from bias, the primary violation here is not bias but dishonesty/incompleteness in reporting. The auditor’s action was not driven by a conflict of interest but by a failure to report material facts.

D. Competency:
Competency relates to possessing the necessary knowledge and skills to perform the audit. The auditor had the skill to identify the issue; the failure was in reporting it, not in understanding it.

References:

IIA Code of Ethics – Principle I:Integrity: Internal auditors shall perform their work with honesty, diligence, and responsibility.

IIA Code of Ethics – Rule of Conduct (Integrity):Internal auditors shall make disclosures of all material facts known to them that, if not disclosed, may distort the reporting of activities under review.

The audit committee is concerned that the small size of the internal audit activity (IAA) makes it impractical to achieve full conformance with the Standards. To address this concern, which of the following actions is most appropriate for the CAE to take?

A. The CAE should agree with the audit committee and implement only those standards appropriate to the size of the IAA.

B. The CAE should request the audit committee to review the Standards to identify specifically which are creating the greatest concern.

C. The CAE should seek sufficient funding to increase audit resources to meet the minimum requirements of the Standards.

D. The CAE should explain that conformance with the Standards is essential and not dependent upon the size of the IAA.

D.   The CAE should explain that conformance with the Standards is essential and not dependent upon the size of the IAA.

Explanation:

The IIA Standards are designed to be scalable and applicable to all internal audit activities, regardless of size. The size of the internal audit activity (IAA) does not determine the requirement for conformance; rather, how the IAA achieves conformance may differ based on its resources and structure.

The CAE has a fundamental responsibility to ensure that the IAA conforms to the Standards, as mandated by Standard 1300 and supported by the Code of Ethics. Conformance is an absolute requirement for the IAA to fulfill its mission and provide credible assurance. Therefore, the most appropriate action is for the CAE to communicate this principle to the audit committee, clarifying that while the methods of implementation may be tailored to the IAA's size, the requirement to conform is non-negotiable.

Why the other options are incorrect:

A. The CAE should agree with the audit committee and implement only those standards appropriate to the size of the IAA:
Incorrect. The CAE cannot selectively adopt only "appropriate" standards. The Standards apply in their entirety, though implementation can be scaled.

B. The CAE should request the audit committee to review the Standards to identify specifically which are creating the greatest concern:
Incorrect. This shifts the CAE's responsibility to the audit committee. The CAE is accountable for understanding and implementing the Standards, not the audit committee.

C. The CAE should seek sufficient funding to increase audit resources to meet the minimum requirements of the Standards:
Incorrect. While sufficient resources are important, conformance with the Standards is not solely about having more staff. The IAA can conform with fewer staff by using external resources, prioritizing engagements, or implementing scaled procedures. Funding alone does not guarantee conformance.

References:

IIA Standard 1300 – Quality Assurance and Improvement Program: "The chief audit executive must develop and maintain a quality assurance and improvement program that covers all aspects of the internal audit activity." This applies to all IAAs regardless of size.

Which of the following risk management activities is most appropriate for an internal auditor to undertake?

A. Impose risk management processes.

B. Coordinate risk management activities.

C. Implement risk responses on management's behalf.

D. Review the management of key risks.

D.   Review the management of key risks.

Explanation:

This question addresses the fundamental boundary between management's responsibility for risk and internal audit's role in providing assurance. According to the IIA's Three Lines of Defense model and related guidance, internal audit's core role concerning risk management is to provide independent, objective assurance to the board and management . This assurance role is explicitly defined in the Standards, which require the internal audit activity to evaluate the effectiveness of risk management processes and review how key risks are managed .

Reviewing management of key risks involves examining whether significant risks have been properly identified, assessed, and controlled, and whether the associated risk responses align with the organization's risk appetite . This is an objective evaluation activity, which preserves the auditor's independence and objectivity as the third line of defense .

Why the other options are incorrect:

A. Impose risk management processes:
This is a management responsibility, not an audit activity. IIA guidance explicitly states that imposing risk management processes is a role internal audit "should not undertake" as it would involve taking on management's accountability .

B. Coordinate risk management activities:
While this can be a legitimate consulting role with proper safeguards, it is not the most appropriate activity for internal audit's core role. If carried out, it must be treated as a consulting engagement to protect objectivity . Reviewing key risks remains the primary assurance function.

C. Implement risk responses on management's behalf:
This is strictly prohibited. Internal auditors must never assume management responsibility by actually managing risks or implementing responses, as this would create a severe self-review threat and compromise objectivity .

References:

IIA Standard 2120 – Risk Management: The internal audit activity must evaluate the effectiveness and contribute to the improvement of risk management processes .

IIA Position Paper – The Role of Internal Auditing in ERM (2009): Lists "reviewing the management of key risks" as a legitimate assurance role, while "implementing risk responses on behalf of management" is explicitly a role internal audit should not undertake .

Page 8 out of 29 Pages