The Institute of Internal Auditors

IIA Certified Internal Auditor - Part 1: Essentials of Internal Auditing (CIA-1) practice questions

Foundations, ethics, governance, risk, control, and fraud risk knowledge for Part 1 of the IIA Certified Internal Auditor exam.

New to CIA-1? Read the how to pass IIA Certified Internal Auditor - Part 1: Essentials of Internal Auditing study guide for a domain breakdown, a study plan, and exam-day tips.

Revising? The CIA-1 cheat sheet puts the domain weightings, key facts, and easy-to-confuse traps on one printable page.

Prefer flashcards? See a free sample of the CIA-1 flashcard deck, concept and misconception cards side by side.

125
Questions
150 min
Time allowed
600 / 750 (scaled)
Pass mark
$395
Exam cost (USD)
297
Practice questions

Exam domains and weighting

The CIA-1 blueprint is split across 4 domains. See the official exam guide for the authoritative breakdown.

CIA-1 domains by share of the exam
DomainWeight
Foundations of Internal Auditing35%
Ethics and Professionalism20%
Governance, Risk Management, and Control30%
Fraud Risks15%

Free sample questions

No account needed. Every question explains why every answer is right or wrong, just like the full bank.

Free sampleGovernance, Risk Management, and Controlmedium

At Meridian Freight, the board has set a stated risk appetite of no unplanned service outages exceeding four hours per quarter. During an assurance engagement, the internal auditor finds that management has formally accepted a residual technology risk whose worst-case outage is estimated at nine hours. What should the internal auditor do next?

  • AReport that the accepted residual risk exceeds the board's stated appetite and escalate the matter to senior management and the board as the appropriate risk owners. Correct
  • BDirect the IT manager to change the risk response from accept to reduce so the exposure falls back within the board's stated appetite before the engagement closes.
  • CAccept management's decision without comment, because choosing to accept a risk is a legitimate response option that always sits within management's authority to make.
  • DRedesign the technology control and implement the additional recovery capacity needed to bring the estimated outage below the four-hour appetite threshold.
Internal audit evaluates whether an accepted residual risk exceeds the board's stated appetite and escalates it rather than owning the response. Risk appetite is the board's stated boundary; an accepted residual risk above that boundary is a governance exception. The auditor's independent role is to evaluate the response against appetite and escalate to the accountable owners, never to select or implement the response itself.

Why A is correct: Evaluating the response against appetite and escalating an exposure that exceeds it to the accountable owners is the independent, standards-consistent action, keeping the decision with management and the board.

Why B is wrong: Selecting and changing the risk response is a first line management decision; directing it would breach the Three Lines Model and impair the auditor's objectivity, so this is wrong despite seeming decisive.

Why C is wrong: Accept is a valid response, which makes this tempting, but the auditor must still evaluate whether the accepted residual risk is consistent with the board's appetite rather than passing silently over a breach.

Why D is wrong: Designing and implementing controls is a management responsibility; taking it on would make the auditor an owner of the very control later assured, so this impairs independence and is wrong.

Free sampleFoundations of Internal Auditingmedium

Aster Retail's audit committee wants internal audit to provide a high level of confidence that the year-end revenue controls are operating effectively, and it has allocated ample time for extensive testing. Which type of engagement matches this request?

  • AA reasonable assurance engagement, which performs more extensive procedures to support a positively expressed conclusion at a high though not absolute level of confidence. Correct
  • BA limited assurance engagement, which performs reduced procedures and conveys a lower level of confidence through a negatively expressed conclusion.
  • CAn advisory engagement, because testing controls at the audit committee's request is simply advice provided to the client on demand.
  • DA reasonable assurance engagement, which guarantees the revenue controls are free from any deficiency because the testing was so extensive.
Reasonable assurance applies more extensive procedures and a positively worded conclusion to convey a high, though not absolute, level of confidence. Reasonable and limited assurance differ by the depth of work performed and the confidence conveyed. A request for high confidence, backed by time for extensive testing, points to a reasonable assurance engagement with a positively expressed conclusion rather than a reduced-scope limited engagement.

Why A is correct: Reasonable assurance uses deeper procedures to underpin a positively worded conclusion at a high but not absolute level of confidence, which is exactly what the committee has asked for and resourced.

Why B is wrong: Limited assurance is tempting shorthand for any controls review, but its reduced procedures and negative wording give lower confidence than the high assurance requested, so it does not fit.

Why C is wrong: Concluding on whether controls operate effectively for stakeholders is assurance, not advice; labelling it advisory misclassifies the service and is therefore wrong.

Why D is wrong: Reasonable assurance is high but not absolute, so promising a guarantee of no deficiency overstates what the engagement can deliver and makes this option incorrect.

Free sampleFoundations of Internal Auditingmedium

At Vela Logistics, the chief financial officer asks the chief audit executive to help improve a struggling contract-approval process, and the CAE agrees to run an advisory engagement. To keep internal audit's later ability to provide assurance intact, how should the CAE frame the team's role on this work?

  • ATake ownership of redesigning the approval workflow and put the new steps into operation directly, so the fix is delivered to the CFO quickly.
  • BDecline the request outright, because giving advice on a process the team may later audit always impairs objectivity beyond repair.
  • CPerform the work as an assurance engagement instead, issuing a formal opinion on the redesigned process to the board this quarter.
  • DAdvise on options and facilitate management's decision while leaving the design choices and implementation firmly with management. Correct
In an advisory engagement internal audit gives advice at the client's request without assuming management responsibility for the decisions or their implementation. Advisory services provide advice requested by the client, and the defining safeguard is that internal audit does not take on management responsibility. Keeping design and implementation with management is what protects objectivity so the activity can still provide independent assurance on the same area later.

Why A is wrong: Speed is tempting, but designing and implementing the workflow makes internal audit the process owner and assumes a management responsibility, which impairs objectivity for any later assurance and is wrong.

Why B is wrong: Advisory work is a legitimate internal audit service, so a blanket refusal is unnecessary; the absolute claim that advice always destroys objectivity misstates the standards and is incorrect.

Why C is wrong: Relabelling the work as assurance mischaracterises a request for advice and would opine on a process that is not yet operating, confusing the two service types and making this wrong.

Why D is correct: Advisory services deliver advice at the client's request without internal audit assuming management responsibility, so keeping the decisions and implementation with management preserves the objectivity needed for future assurance.

More free CIA-1 practice questions, every answer explained

Frequently asked questions

How many questions are on the CIA-1 exam?
The IIA Certified Internal Auditor - Part 1: Essentials of Internal Auditing (CIA-1) exam has 125 questions and runs for 150 minutes. The format is multiple choice, closed book.
What score do I need to pass CIA-1?
The pass mark is 600 / 750 (scaled). Examworthy gives you a per-domain readiness score so you can see which domains are holding you back before you book.
How much does the CIA-1 exam cost?
The exam costs 395 USD to sit. Practising on Examworthy is free to start, and every answer is explained, right and wrong.
Is there a CIA-1 practice exam?
Yes. Examworthy's exam mode runs a timed CIA-1 practice exam (mock) paced to match the real exam, scored per domain so you can see exactly where you stand. Timed mocks are free with an account.
How does Examworthy help me prepare for CIA-1?
Every practice question explains why the right answer is right and why each wrong one is wrong, mapped to the official blueprint domains. You learn the reasoning, not just the letter.
Is Examworthy affiliated with The Institute of Internal Auditors?
No. Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Our questions are original, blueprint-aligned practice material; we never reproduce live exam items.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CIA-1 and related marks belong to their respective owners.