Free IIA IIA-CRMA-ADV Practice Questions 2026 - Page 9
Ready for IIA-CRMA-ADV Exam?
This practice test is your final exam before the REAL exam
Dare to Take It?
Practice Questions
Topic 1: Exam Pool A
Allegations have been made that an organization's share price has been manipulated.
Which of the following would provide an internal auditor with the most objective evidence in
this case?
A. Major shareholders of the organization.
B. Large customers of the organization.
C. Former members of management.
D. Former financial consultants.
Explanation:
When investigating share price manipulation, an internal auditor needs evidence that is objective, verifiable, and unlikely to be influenced by the parties under scrutiny. The goal is to uncover activities like artificial trading, false information dissemination, or collusion designed to distort the market price .
Large customers are the most objective source because their primary business relationship with the organization is through commercial transactions, not financial engineering. Their transaction records, order histories, and accounts payable/receivable data provide concrete, documentary evidence of real economic activity. If a share price rise is unsupported by actual business performance, customer data will not corroborate it. This aligns with the internal auditor's scope of work, which includes verifying financial transactions and assessing internal controls .
Why the other options are incorrect:
A. Major shareholders: They may have a direct financial interest in the share price and could be actively involved in or benefit from manipulation schemes . Their testimony is potentially self-serving and less reliable.
C. Former members of management: Their statements are subjective and could be influenced by personal grievances, ongoing litigation, or a desire to avoid personal liability for decisions made during their tenure.
D. Former financial consultants: Like former managers, their perspectives may be subjective. They are paid advisors, not independent transactional counterparties, and their account of events can be colored by disputes or the terms of their departure.
The most reliable evidence in such cases comes from objective, third-party transactional data, which is precisely what is obtained from large customers, rather than from the potentially biased statements of insiders or interested parties .
References:
IIA Standard 2310 – Identifying Information: Requires internal auditors to identify sufficient, reliable, relevant, and useful information to achieve engagement objectives.
IIA Standard 2320 – Analysis and Evaluation: Requires internal auditors to base conclusions on appropriate analyses and evaluations.
According to IIA guidance, which of the following individuals would best be considered independent for the purpose of participating in an external assessment of the quality assurance and improvement program for an internal audit activity (IAA)?
A. A former employee knowledgeable of the IAA who resigned three years earlier from the organization.
B. A competent employee of an independent external organization that provides cosourcing services to the IAA.
C. An employee in an affiliated organization who has never worked directly with the IAA.
D. An employee in the parent organization who has not had any previous contact with the IAA.
Explanation:
This question tests the requirement for an independent assessor or assessment team to conduct an external quality assessment of the internal audit activity (IAA), as mandated by the Standards. The key element is independence, meaning the assessor must be free from conflicts of interest and not be under the influence of the organization being reviewed.
For an external assessment, an independent assessor must be "from outside the organization," with no actual, potential, or perceived conflicts of interest. When considering former employees, a critical factor is the length of time they have been independent. The Implementation Guide for Standard 1312 advises that consideration should be given to how long the former employee has been separated from the organization, where "independent" means not having a conflict of interest and not being a part of, or under the control of, the organization. A three-year separation is a sufficient cooling-off period to reasonably conclude that the individual is no longer influenced by the organization and can provide an objective assessment.
Why the other options are incorrect:
B. An employee of an independent external organization that provides cosourcing services to the IAA.
A provider of cosourcing services has a significant, ongoing business relationship with the IAA. This creates a direct conflict of interest and an impairment to objectivity, as they are effectively auditing a client they also serve.
C. An employee in an affiliated organization who has never worked directly with the IAA.
Individuals from a "related organization" (e.g., a parent company or affiliate) are not considered independent for this purpose, even if they have not worked directly with the IAA. The organizational relationship itself creates a potential conflict of interest.
D. An employee in the parent organization who has not had any previous contact with the IAA.
Similar to option C, a person from the parent organization is not independent for an external assessment. The Implementation Guide explicitly states that individuals from a parent organization are not considered independent, regardless of their prior contact.
References:
IIA Standard 1312 – External Assessments: Requires that external assessments be conducted by a qualified, independent assessor or assessment team from outside the organization, with the CAE discussing their independence and any potential conflict of interest with the board.
During an internal audit, an organization's processing department is found to have incidences of both duplicate invoices and notices from customers that purchased goods were not received. The department under review insists that some of these reports are false and that others were isolated oversights due to understaffing. Which of the following tests would best help the internal auditor detect fraudulent activity?
A. Check inventory levels.
B. Search for gaps in check numbers.
C. Compare vendor summaries.
D. Review raw material purchase quantities.
Explanation:
The scenario presents two classic red flags: duplicate invoices (payments made twice for the same goods) and customer complaints about non-receipt of goods (goods billed but not shipped). The department attributes these to false reports and understaffing—both plausible excuses, but also potential cover stories for fraud.
Why the other options are incorrect:
B. Search for gaps in check numbers:
This is a test for missing documents (e.g., checks destroyed or voided to conceal theft). While useful, it does not directly address duplicate invoices or customer non-receipt complaints, which involve fictitious transactions rather than missing payment records.
C. Compare vendor summaries:
This compares total purchases from vendors to identify unusual patterns. It may highlight a concentration of purchases from a suspicious vendor, but it does not directly test whether goods were actually received or whether invoices are legitimate.
D. Review raw material purchase quantities:
This would compare raw material purchases to production output to see if quantities are reasonable. While this can detect inflated purchases, it does not directly test whether goods were actually received or whether sales are fictitious. It is a less direct and less effective test for the fraud indicators described.
References:
IIA Standard 2320 – Analysis and Evaluation: Requires internal auditors to base conclusions on appropriate analyses and evaluations. Physical inventory observation is a recognized analytical and verification procedure under this standard.
IIA Practice Guide – "Auditing Inventory and Warehousing": Recommends observing physical inventory counts and reconciling them to perpetual records as a key procedure to detect fraud, theft, and recording errors.
Which of the following would provide the best evidence of errors in the quantities of items received from suppliers?
A. Suppliers' reports of over shipments.
B. Warehouse receiving logs.
C. Purchase requisitions and purchase orders.
D. Observation and inspection of inventory.
Explanation:
This question asks for the best evidence to identify errors in the quantities of items received from suppliers. The receiving log is the primary document created at the point of receipt, documenting the actual quantities of goods received as they enter the warehouse. It provides a direct, contemporaneous record of what was physically received, making it the most relevant and reliable evidence for identifying quantity discrepancies. When compared to purchase orders (what was ordered) and supplier invoices (what was billed), the receiving log is the critical document for detecting over-shipments, under-shipments, or shipment errors.
Why the other options are incorrect:
A. Suppliers' reports of over shipments:
While a supplier's notification is relevant, it is not the best evidence. It is a self-reported document from the supplier, which may be less reliable or complete, and does not provide an independent verification of what was physically received.
C. Purchase requisitions and purchase orders:
These documents reflect what was ordered, not what was actually received. They are useful for testing authorization and completeness, but they do not provide evidence of actual receipt quantities.
D. Observation and inspection of inventory:
While observing and inspecting inventory is a valid audit procedure, it is more effective for verifying the existence and condition of inventory on hand at a point in time. It is less effective for detecting receiving quantity errors because those errors would have been recorded (or not recorded) in the receiving log at the time of receipt.
References:
IIA Standard 2310 – Identifying Information: Requires internal auditors to identify sufficient, reliable, relevant, and useful information to achieve the engagement's objectives. Warehouse receiving logs are a primary source document that provides direct evidence of receipt quantities.
IIA Practice Guide – "Auditing Inventory and Warehousing": Recommends comparing receiving logs to purchase orders and supplier invoices as a key procedure to detect quantity discrepancies.
While reviewing the workpapers of a new auditor, the auditor in charge discovered that additional audit procedures might be necessary. According to IIA guidance, which of the following would be most relevant for the auditor in charge to consider when making this decision?
A. Resource management.
B. Coordination.
C. Due professional care.
D. Engagement supervision.
Explanation:
The scenario describes a supervisor reviewing a new auditor's workpapers and determining whether additional audit procedures are necessary. This is the essence of engagement supervision, which is defined in Standard 2340 as the process of overseeing an engagement to ensure objectives are achieved, quality is assured, and staff is developed. The decision to expand procedures based on workpaper review is a direct supervisory responsibility. The supervisor must evaluate the sufficiency and reliability of the evidence gathered and, if it is inadequate, direct the auditor to perform additional tests.
Why the other options are incorrect :
A. Resource management: This concerns allocating budget, staff, and time to the overall audit plan. It does not address the judgment on whether a specific engagement's testing is complete based on workpaper review.
B. Coordination: This relates to synchronizing efforts with other auditors or departments to avoid duplication. It does not apply to the supervisor's decision to expand testing within a single engagement.
C. Due professional care: This is the overarching standard requiring diligence and skill. However, the mechanism by which due care is ensured in this instance is engagement supervision. The supervisor exercises due care through supervision.
References:
IIA Standard 2340 – Engagement Supervision: "Engagements must be properly supervised to ensure objectives are achieved, quality is assured, and staff is developed."
IIA Implementation Guide 2340: Supervision includes reviewing workpapers, evaluating the auditor's performance, and deciding whether additional work is needed to support conclusions.
Which of the following techniques would best assist an internal auditor in evaluating the efficiency of a wholesale grocery distributor`s process to fill and package orders for shipping?
A. A Bedford analysis of orders filled to average delivery times.
B. Decision trees rating actual performance against requirements.
C. Queuing theory to assess potential bottlenecks in the process.
D. A program evaluation and review technique chart.
Explanation:
Queuing theory is the most appropriate technique for evaluating the efficiency of a repetitive operational process like order filling and packaging. It is specifically designed to analyze workflow congestion, waiting times, and resource utilization—the core factors that determine whether a process is efficient or bottlenecked . By modeling order arrival rates and service times at each packaging station, queuing theory helps the auditor identify where delays occur and whether staffing or equipment is adequate to meet demand without excessive idle time or backlog . This aligns with IIA guidance that internal auditors should base conclusions on appropriate analyses and evaluations of operational efficiency .
Why the other options are incorrect:
A. Bedford analysis: "Bedford analysis" is not a recognized audit technique. A commonly used digital analysis tool is Benford's Law, which tests the integrity of large data sets by detecting anomalies in number distributions, not process efficiency .
B. Decision trees: These are classification models used to predict outcomes or assess risk based on multiple variables, but they do not analyze process flow, capacity, or congestion .
D. PERT chart: This is a project management tool for scheduling complex, non-repetitive projects with uncertain task durations; it is not designed for evaluating the day-to-day efficiency of a routine warehousing process.
References:
IIA Standard 2320 – Analysis and Evaluation: Requires internal auditors to base conclusions and engagement results on appropriate analyses and evaluations .
IIA Implementation Guide 2320: Recommends analytical procedures such as ratio, trend, and regression analysis to evaluate business processes .
Which of the following is a preventive control?
A. Creating an audit trail.
B. Placing controls on physical access to inventory.
C. Reconciling purchase orders with approvals.
D. Reviewing expense accounts for irregularities.
Explanation:
A preventive control is designed to stop an undesirable event from occurring before it happens. Placing physical access controls on inventory (e.g., locks, keycard entry, security gates) is a classic example—it actively blocks unauthorized individuals from entering the storage area, thereby preventing theft, misplacement, or unauthorized use of inventory. This control acts as a barrier at the point of entry, deterring and stopping the threat before any loss occurs. Preventive controls are generally preferred because they reduce the need for corrective action after the fact.
Why the other options are incorrect:
A. Creating an audit trail: This is a detective control. It records who accessed what and when, but it does not prevent unauthorized access—it only logs it after the fact for review.
C. Reconciling purchase orders with approvals: This is a detective control. Reconciliation identifies mismatches or unauthorized transactions after they have been processed, allowing management to investigate and correct them.
D. Reviewing expense accounts for irregularities: This is a detective control. Reviews of expense accounts identify anomalies or potential fraud after expenses have been incurred and recorded.
References:
IIA Standard 2130 – Control: Requires internal auditors to evaluate the effectiveness of controls, including their classification as preventive, detective, or corrective.
IIA Practice Guide – "Auditing Internal Controls": Defines preventive controls as those that stop problems before they occur, such as physical access restrictions and segregation of duties.
Which of the following is a valid statement about the use of visual observations during an
audit engagement?
1. Visual observations can be used to detect ineffective controls, idle resources, and safety
hazards.
2. Visual observations can be used during both preliminary survey and fieldwork stages of
the audit engagement.
3. Visual observations can provide unsubstantiated facts to management if the internal
auditor believes the information is useful.
4. Visual observations can assist an auditor in determining if a material observation should
be communicated through informal means to the organization’s senior management.
A. 1 and 2 only
B. 1 and 4 only
C. 2 and 3 only
D. 3 and 4 only
Explanation:
Visual observation is a fundamental audit technique that involves physically seeing and inspecting activities, processes, and conditions. It is a powerful tool for gathering direct, firsthand evidence during an audit.
Statement 1 is correct.
Visual observations are highly effective for detecting ineffective controls (e.g., unlocked doors, missing segregation of duties), idle resources (e.g., unused equipment, overstaffed areas), and safety hazards (e.g., blocked fire exits, improper storage of hazardous materials). These are all tangible conditions that can be confirmed through direct observation.
Statement 2 is correct.
Visual observations are used throughout the audit process. During the preliminary survey, they help the auditor gain an initial understanding of the process, identify potential risk areas, and plan the engagement. During fieldwork, they are used to verify that controls are actually operating as described (e.g., observing that inventory counts are performed properly).
Why the other options are incorrect:
Statement 3 is incorrect.
Visual observations provide factual, firsthand evidence—they are not "unsubstantiated facts." If the auditor believes the information is useful, it must be documented and, if material, included in the audit report. Observations are not "unsubstantiated"; they are direct evidence.
Statement 4 is incorrect.
Material observations (significant findings) must be communicated through formal channels—typically in the final audit report to senior management and the board (Standard 2400). They should not be communicated informally, as this undermines the audit process and may compromise objectivity and completeness of reporting.
References:
IIA Standard 2320 – Analysis and Evaluation: Requires internal auditors to base conclusions on appropriate analyses and evaluations. Observation is a recognized technique for gathering evidence.
IIA Practice Advisory 2320-1 – Analysis and Evaluation: Notes that observation is a valid procedure for collecting information during both the preliminary survey and fieldwork phases.
A staff auditor, nearly finished with an audit engagement, discovers that the director of marketing has a gambling habit. The gambling issue is not directly related to the existing engagement, and there is pressure to complete the current engagement. The auditor notes the problem and forwards the information to the chief audit executive, but performs no further follow-up. Which of the following statements is true about the auditor's actions?
A. They are in violation of the IIA Code of Ethics because the auditor withheld meaningful information.
B. They are in violation of the Standards because the auditor did not properly follow up on a red flag that might indicate the existence of fraud.
C. They are in violation of neither the IIA Code of Ethics nor the Standards.
D. They are not in violation of the Standards but are in violation of the IIA Code of Ethics.
Explanation:
The internal auditor's actions are appropriate and align with the IIA's guidance. In this situation, the auditor identified a potential red flag that was outside the scope of the current engagement. The correct protocol is to note the concern, report it to the appropriate level of management, and allow the chief audit executive (CAE) to determine the necessary further actions .
This approach is supported by the IIA Code of Ethics, specifically the Objectivity rule, which does not require the auditor to investigate issues outside their audit's scope, but does require them to disclose all material facts known to them .
This action is also consistent with the Standards concerning proficiency and due professional care. Internal auditors are expected to have sufficient knowledge to identify indicators of fraud, but they are not expected to have the expertise of a person whose primary responsibility is detecting and investigating fraud . The auditor's reporting to the CAE ensures the issue is escalated and can be properly managed.
Why other options are incorrect:
A & D. In violation of the Code of Ethics:
The Code does not mandate the auditor investigate a personally-identified red flag outside the engagement's scope. The auditor acted with integrity by identifying the issue and reporting it, rather than ignoring it or withholding the information. Therefore, this is not a violation.
B. In violation of the Standards:
The Standards do not require an auditor to follow up on a red flag that is unrelated to the current engagement. The auditor's responsibility is to report the concern to the appropriate authority, and they fulfilled this duty by informing the CAE.
References:
IIA Code of Ethics – Principle II: Objectivity: Internal auditors exhibit the highest level of professional objectivity and make a balanced assessment of all the relevant circumstances. Rule 2.3 requires them to "disclose all material facts known to them that, if not disclosed, may distort the reporting of activities under review" .
If an engagement client disputes that a specific action or process is within the scope of the internal audit activity, what would be the most appropriate way for the internal audit activity (IAA) to respond?
A. Terminate the audit engagement in full because an operational audit will not be productive without the client's cooperation.
B. Terminate only the specific action or process with which the client disagrees and work to determine a substitute function that will not impede further IAA or the client-audit relationship.
C. Refer the client to the IAA's charter and the approved yearly audit plan, which includes the areas designated for audit in the current time period.
D. Seek the approval of senior management or the board in mediation, allowing an overseer to clarify the scope of the audit engagement for the client.
Explanation:
The internal audit charter is the foundational document that establishes the internal audit activity’s (IAA) purpose, authority, and responsibility. It defines the scope of its activities and authorizes access to records, personnel, and physical properties relevant to the performance of engagements. The approved annual audit plan, which is based on the charter, specifically identifies the areas designated for audit.
When a client disputes the scope, the most appropriate and effective response is to refer them to these formal, board-approved documents. This affirms the IAA's mandate and authority without escalating the dispute unnecessarily. It is a clear, professional, and objective response grounded in the organization's governance framework.
Why the other options are incorrect:
A. Terminate the audit engagement in full:
This is an overreaction and a failure to fulfill the IAA's mandate. Lack of cooperation does not justify abandoning the engagement.
B. Terminate only the specific action or process:
This is also inappropriate. The IAA has a defined scope based on risk assessment and board approval. Substituting functions would undermine the audit objectives and compromise the integrity of the plan.
D. Seek the approval of senior management or the board:
This is premature and escalates a matter that can be resolved by referring to the charter and audit plan. The board has already approved these documents, so seeking their approval again is unnecessary.
References
IIA Standard 1000 – Purpose, Authority, and Responsibility: The purpose, authority, and responsibility of the internal audit activity must be formally defined in an internal audit charter, consistent with the Definition of Internal Auditing, the Code of Ethics, and the Standards.
IIA Implementation Guide 1000: The charter establishes the IAA's scope and authorizes access to records, personnel, and physical properties.
| Page 9 out of 29 Pages |