Free IIA IIA-IAP Practice Questions 2026 - Page 3
Ready for IIA-IAP Exam?
This practice test is your final exam before the REAL exam
Dare to Take It?
Practice Questions
Which of the following would be considered out of scope for a purchasing process audit engagement?
A. Authorization of requisitions
B. Control of goods
C. Matching goods received to requisitions
Explanation:
A purchasing process audit typically covers the end-to-end procure-to-pay cycle, from requisition authorization to vendor payment. However, "control of goods" (physical custody, inventory management, warehouse security) falls under inventory or logistics management, not the purchasing process itself, making it out of scope for a purchasing-specific audit.
Correct Option:
B. Control of goods
Purchasing ends when goods are received and accepted; subsequent physical control, storage, and inventory management belong to warehousing or logistics functions.
Including goods control would expand scope beyond purchasing into areas with different risks (theft, obsolescence, inventory valuation).
A purchasing audit focuses on requisitioning, vendor selection, purchase orders, receiving, invoice matching, and payment.
Overlapping with goods control would dilute audit objectives and require additional expertise.
Incorrect Options:
A. Authorization of requisitions
Requisition authorization is a key purchasing control to prevent unauthorized or unnecessary purchases. It falls directly within purchasing process scope as it initiates the procurement cycle.
C. Matching goods received to requisitions
Matching received goods to requisitions (or purchase orders) is a critical purchasing control ensuring that only ordered and needed items are accepted. This is part of the three-way match and is central to purchasing audits.
Reference:
IIA Standard 2220 – Engagement Scope: "The established scope must be sufficient to achieve the engagement's objectives." IIA Practice Guide: "Auditing the Procurement Function" defines purchasing scope as including requisition, sourcing, purchase order, receiving, and invoice processing. Inventory control (physical custody, stock records) is explicitly excluded from purchasing audit scope unless the engagement is broadened to supply chain management.
Which of the following elements are typically included in an engagement work program?
A. Planning, objectives, and preliminary risk assessments
B. Fieldwork, analytical testing, and resources
C. Opinions and final engagement communications
Explanation:
An engagement work program is a documented plan that outlines the procedures necessary to achieve engagement objectives. It typically includes the planning phase details, specific engagement objectives, and preliminary risk assessments that guide the nature, timing, and extent of testing. This ensures a structured, risk-based approach to fieldwork.
Correct Option:
A. Planning, objectives, and preliminary risk assessments
The work program translates objectives into step-by-step procedures.
Preliminary risk assessments help prioritize areas requiring detailed testing.
Including planning steps (e.g., understanding the activity, identifying key controls) ensures completeness.
Standard 2200 – Engagement Planning requires documentation of objectives, scope, and procedures.
Work programs are finalized during planning before fieldwork begins.
Incorrect Options:
B. Fieldwork, analytical testing, and resources
Fieldwork is the execution phase, not a component of the work program itself. Analytical testing is a type of procedure found within a work program, but "fieldwork" as a phase is too broad. Resources (staff, budget) are documented in the engagement plan, not typically in the work program.
C. Opinions and final engagement communications
Opinions and final communications are outputs or results of the engagement, not elements of the work program. The work program guides evidence collection; opinions are formed after analysis and are reported separately in the engagement communication.
Reference:
IIA Standard 2200 – Engagement Planning requires internal auditors to develop and document a work program. Implementation Guidance for Standard 2200 states: "A work program typically includes the engagement objectives, scope, and detailed procedures for obtaining sufficient, reliable, relevant, and useful information." Practice Advisory 2200-1 lists planning steps, objectives, and risk assessments as essential components of a work program.
During a procurement process consulting engagement, the internal auditors reviewed contracts for the hospital's supply of medicine. Which of the following would the internal auditors most likely recommend to improve the effectiveness of the procurement process?
A. The procurement process should begin with clearly specified needs.
B. The procurement process must be comprehensively documented.
C. Only qualified procurement professionals should manage the procurement process.
Explanation:
Effectiveness in procurement means obtaining the right goods (medicine) at the right time, quality, and cost. The entire process depends on accurately specified needs. Without clear specifications, even well-documented or professionally managed procurement may fail to meet clinical requirements, leading to waste or patient safety risks.
Correct Option:
A. The procurement process should begin with clearly specified needs.
Clearly specified needs (e.g., medicine type, dosage, expiry, storage requirements) ensure suppliers provide appropriate products.
This is a prerequisite for effective sourcing, bidding, and contract management.
Vague or incorrect specifications lead to wrong products, delivery delays, or patient harm.
Standard 2120 – Risk Management requires evaluating controls that ensure objectives are met; needs specification is a key control for effectiveness.
This recommendation addresses root cause of procurement failures.
Incorrect Options:
B. The procurement process must be comprehensively documented.
Documentation supports accountability and audit trail but does not directly improve effectiveness. A process can be well-documented yet procure wrong medicine if needs are unclear. Documentation is an efficiency/compliance control, not an effectiveness driver.
C. Only qualified procurement professionals should manage the procurement process.
Qualified professionals are important for efficiency and compliance, but even experts cannot procure effectively if needs are not specified. Competence without clear requirements still results in ineffective outcomes. This is a supporting, not primary, recommendation.
Reference:
IIA Standard 2120.A1 requires evaluation of risk management processes related to achieving objectives. COSO Framework emphasizes that control activities must be based on clear objectives. IIA Practice Guide: "Auditing the Procurement Function" states that defining requirements (needs specification) is the most critical step for procurement effectiveness. Also see ISO 20400 – Sustainable Procurement, which identifies needs identification as first principle.
Which of the following is the most important initial action for a chief audit executive to perform when establishing a new internal audit activity?
A. Establish an internal audit charter.
B. Establish a code of ethics for the internal audit activity.
C. Approve the internal audit budget.
Explanation:
The internal audit charter is the foundational document that defines the activity's purpose, authority, responsibility, and reporting relationships. Without an approved charter, the CAE has no formal mandate to perform audits, access records, or allocate resources. All other actions depend on the charter's existence.
Correct Option:
A. Establish an internal audit charter.
The charter formally establishes internal audit's position within the organization.
It defines reporting lines (e.g., to the board/audit committee and senior management).
It grants access to records, personnel, and physical properties (Standard 1100).
The charter must be approved by the board and reviewed periodically.
Without a charter, the CAE lacks authority to set budgets, hire staff, or perform engagements.
Standard 1000 – Purpose, Authority, and Responsibility explicitly requires a written charter.
Incorrect Options:
B. Establish a code of ethics for the internal audit activity.
While important, the Code of Ethics is established by the IIA globally, not created by each activity. The CAE must ensure compliance with the IIA Code of Ethics, but this is subsequent to establishing the charter. The charter is the legal/structural foundation.
C. Approve the internal audit budget.
Budget approval requires existing authority granted through the charter. The CAE may develop a budget, but approval comes from the board or audit committee after the charter defines reporting lines. Budget is operational; charter is constitutional.
Reference:
IIA Standard 1000 – Purpose, Authority, and Responsibility: "The purpose, authority, and responsibility of the internal audit activity must be formally defined in an internal audit charter, consistent with the Mission of Internal Audit and the mandatory elements of the IPPF." Implementation Guidance for Standard 1000 states: "Establishing the charter is the most important initial step when forming a new internal audit activity." Standard 1100 requires independence and objectivity defined within the charter.
What is the primary objective for testing controls?
A. To determine whether controls are operating effectively.
B. To understand whether a control is in place.
C. To identify major patterns of errors or irregularities that might exist in final account balances.
Explanation:
Testing controls is performed to obtain evidence that controls are operating effectively—meaning they prevent or detect material misstatements or risks in a timely manner. This involves testing both design (whether control is suitably designed) and operating effectiveness (whether it works as intended over time).
Correct Option:
A. To determine whether controls are operating effectively.
Operating effectiveness means the control works consistently throughout the period.
Testing includes inquiry, observation, inspection, and re-performance.
Effectiveness testing confirms that the control reduces risk to an acceptable level.
Standard 2310 – Identifying Information requires evidence that controls are effective.
This is distinct from understanding control design (walkthroughs) or identifying errors in balances.
Incorrect Options:
B. To understand whether a control is in place.
Understanding whether a control exists (design assessment) is a preliminary step, usually done via walkthroughs during planning. The primary objective of testing is to confirm operating effectiveness, not just existence.
C. To identify major patterns of errors or irregularities that might exist in final account balances.
This describes substantive testing (directly verifying account balances), not control testing. Control testing focuses on the processes that prevent or detect errors, not on finding errors in final balances themselves.
Reference:
IIA Standard 2310 – Identifying Information: "Sufficient, reliable, relevant, and useful information must be obtained to achieve engagement objectives." Implementation Guidance distinguishes between understanding control design (walkthroughs) and testing operating effectiveness (control testing). Also see IIA Practice Guide: "Control Testing and Documentation" – primary objective is effectiveness, not existence or error detection in balances.
In the absence of any action to control or modify the circumstances, the probability of loss arising from circumstances existing in an environment is known as which of the following types of risk?
A. Residual
B. Inherent
C. Control
Explanation:
Inherent risk is the risk that exists in the absence of any management action or controls. It represents the natural exposure to loss based solely on the nature of the activity, transaction, or environment. This is the starting point before considering how controls might mitigate the risk.
Correct Option:
B. Inherent
Inherent risk assumes no controls are applied to modify the outcome.
It is based on factors like complexity, transaction volume, asset liquidity, or external environment.
Auditors assess inherent risk to determine where controls are most needed.
Standard 2010.A1 requires the CAE to consider inherent risks in audit planning.
Contrast with residual risk, which is risk remaining after controls.
Incorrect Options:
A. Residual
Residual risk is the risk that remains after management has implemented controls. The question explicitly says "in the absence of any action to control or modify circumstances," which excludes residual risk because residual risk considers controls already in place.
C. Control
Control risk is the risk that existing controls will fail to prevent or detect material misstatements or losses. This assumes controls exist but may be ineffective. The question describes a scenario with no controls at all, making inherent risk the correct term.
Reference:
IIA Standard 2010.A1 – Planning: "The internal audit activity's plan of engagements must be based on a documented risk assessment, undertaken at least annually... The input of senior management and the board must be considered." Implementation Guidance defines inherent risk as "risk in the absence of any actions to alter its likelihood or impact." Also see COSO ERM Framework, which distinguishes inherent risk (no controls) from residual risk (after controls).
During a travel expense audit engagement, the internal auditor discovered that the accounts payable staff spend a significant amount of time previewing expense reports before the reports are sent to managers for review and approval. The total of all expense reports during a year represents less than 1% of the organization’s total budget. Which of the following best supports the auditor’s recommendation to reduce the level of reviews?
A. The inherent risk of travel expense fraud is low.
B. The cost of the control outweighs the benefit.
C. The duplication of effort in the review process is unnecessary.
Explanation:
The auditor observed that accounts payable staff extensively preview expense reports before manager review. Since travel expenses are only 1% of the total budget, the cost (staff time) of this dual-review control likely exceeds the potential loss from undetected errors or fraud. This supports a risk-based recommendation to reduce redundant reviews.
Correct Option:
B. The cost of the control outweighs the benefit.
Controls should be cost-effective; if implementation cost exceeds potential loss, the control may be inefficient.
Travel expenses represent less than 1% of budget, so maximum potential loss is relatively small.
Dual review (AP preview + manager approval) duplicates effort without proportional benefit.
Standard 2120.A2 requires evaluating whether control costs are reasonable relative to potential risks.
Recommendation to streamline is justified by cost-benefit analysis.
Incorrect Options:
A. The inherent risk of travel expense fraud is low.
Low inherent risk might suggest less need for controls, but it does not directly justify removing an existing control. The auditor's observation focuses on control duplication and cost, not on fraud risk level alone. Inherent risk could still be moderate despite small budget percentage.
C. The duplication of effort in the review process is unnecessary.
Calling the duplication "unnecessary" assumes the fact without analysis. The justification for reducing reviews rests on cost-benefit (value for money), not merely the presence of duplication. Some duplication may be justified for high-risk areas; here, low budget percentage makes it inefficient.
Reference:
IIA Standard 2120.A2: "Internal auditors must evaluate the potential for the occurrence of fraud and how the organization manages fraud risk." Implementation Guidance for Standard 2130 – Control states: "Controls must be cost-effective... The cost of a control should not exceed the benefit derived from it." Also see COSO Internal Control – Control Environment principle on balancing control costs with benefits.
Which sampling technique uses a nonrandom selection process that is expected to be representative of the population as a whole?
A. Judgmental sampling.
B. Haphazard sampling.
C. Attribute sampling.
Explanation:
Judgmental sampling (also called purposive or expert sampling) is a nonrandom selection technique where the auditor uses professional judgment to choose sample items believed to be representative of the population. While not statistically valid, it relies on the auditor's knowledge and experience to select typical or high-risk items.
Correct Option:
A. Judgmental sampling.
Judgmental sampling is nonrandom because the auditor deliberately selects specific items.
The expectation of representativeness comes from the auditor's expertise and understanding of the population.
Common uses include testing controls where randomness is impractical or population is homogeneous.
Results cannot be statistically projected to the entire population.
Standard 2330 – Documenting Information allows judgmental sampling when appropriate.
Incorrect Options:
B. Haphazard sampling.
Haphazard sampling attempts to be random without a structured method (e.g., picking items without bias). It is still nonstatistical but does not rely on deliberate judgment for representativeness. The technique itself does not ensure representativeness; bias may occur.
C. Attribute sampling.
Attribute sampling is a statistical sampling method used to estimate the rate of occurrence (e.g., deviation rate) in a population. It requires random selection and allows mathematical projection. It is not a nonrandom technique, so it does not match the question's description.
Reference:
IIA Standard 2330 – Documenting Information: "Internal auditors must document sufficient, reliable, relevant, and useful information to support engagement results." Practice Advisory 2330-1 discusses sampling methods. Also see IIA Practice Guide: "Audit Sampling" – Judgmental sampling is nonstatistical, relies on auditor expertise, and expects representativeness without randomness. Contrast with haphazard (no deliberate judgment pattern) and attribute (statistical) sampling.
Which of the following statements best describes quality audit workpapers?
A. They should be relevant and interesting.
B. They should be electronic and indexed.
C. They should be understandable and complete.
Explanation:
Quality audit workpapers must support engagement conclusions and be useful for review by other auditors or supervisors. The two primary characteristics are understandability (clear logic, labeling, and organization) and completeness (all necessary evidence, cross-references, and documentation). Without these, workpapers fail to demonstrate due professional care.
Correct Option:
C. They should be understandable and complete.
Understandable means another qualified auditor can follow the work without additional explanation.
Complete means all procedures performed, evidence obtained, and conclusions reached are documented.
Standard 2330 – Documenting Information requires workpapers to support engagement results.
Incomplete or confusing workpapers impair review quality and audit defense.
These characteristics align with the IIA's requirements for sufficient and reliable information.
Incorrect Options:
A. They should be relevant and interesting.
While relevance is important (workpapers must relate to engagement objectives), "interesting" is not a quality criterion for audit documentation. Workpapers are professional records, not narrative publications. Interesting content is irrelevant to audit quality.
B. They should be electronic and indexed.
Electronic format and indexing are methods of organizing workpapers but are not universal quality descriptors. Many quality workpapers are paper-based. Indexing supports organization but does not itself define quality; understandability and completeness are fundamental regardless of medium.
Reference:
IIA Standard 2330 – Documenting Information: "Internal auditors must document sufficient, reliable, relevant, and useful information to support engagement results." Implementation Guidance specifies that workpapers should be "complete, accurate, concise, and clearly understandable." Also see Practice Advisory 2330-1: "Workpapers should be organized and contain adequate information for a reviewer to understand the nature, timing, extent, and results of procedures."
Operational management has asked the internal auditor for recommendations regarding an ineffective process. According to IIA guidance, which of the following would be the auditor's most appropriate response?
A. Refrain from providing recommendations to preserve audit independence.
B. Agree to offer recommendations based on observations and conclusions.
C. Explain that only management should recommend and implement the corrective action.
Explanation:
IIA guidance explicitly permits internal auditors to provide recommendations as part of consulting or even assurance engagements. Recommendations based on observations and conclusions add value and help management improve processes. Refusing to offer recommendations when asked would not serve the organization's best interests.
Correct Option:
B. Agree to offer recommendations based on observations and conclusions.
Standard 2240.A1 requires engagement work programs to include procedures for developing recommendations when appropriate.
Recommendations are constructive and help management address root causes.
Providing recommendations does not impair independence as long as the auditor does not assume management responsibility for implementing them.
Standard 1130 allows consulting services that do not create self-review threats.
Refusing would violate the IIA's mission to provide advice and insight.
Incorrect Options:
A. Refrain from providing recommendations to preserve audit independence.
This misinterprets independence. Independence refers to freedom from conditions that threaten objectivity. Providing recommendations (without implementing them) is a standard consulting activity and does not impair independence if properly managed.
C. Explain that only management should recommend and implement the corrective action.
Management implements corrective action, but internal auditors routinely recommend actions. Telling management that only they should recommend denies the value of audit insights and contradicts IIA guidance that encourages recommendations.
Reference:
IIA Standard 2240.A1: "Engagement work programs must include procedures for identifying, analyzing, evaluating, and documenting sufficient information to achieve the engagement's objectives." Implementation Guidance for Standard 2240 states that recommendations are part of engagement communications. IIA Code of Ethics – Principle of Confidentiality does not restrict recommendations. Standard 1130 allows consulting without assuming management responsibility. IPPF Mission includes "providing insight and advice."
| Page 3 out of 10 Pages |