Examworthyexamworthy.com

IIA Certified Internal Auditor - Part 1: Essentials of Internal Auditing cheat sheet

The Institute of Internal Auditors

Exam version 2025Reviewed 2026-07-22

Free to share. Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors; CIA-1 and related marks belong to their respective owners.

At a glance

125
Questions
150 min
Time allowed
600 / 750 (scaled)
Pass mark
$395
Cost (USD)

Format: Multiple choice, closed book

Domain weight map

Heaviest first - spend your time here
Foundations of Internal Auditing35% · 106 Q
Governance, Risk Management, and Control30% · 88 Q
Ethics and Professionalism20% · 58 Q
Fraud Risks15% · 45 Q

How this exam thinks

CIA Part 1 rewards choosing the most independent, objective, standards-consistent next action in a scenario, not reciting a definition.

Spot the trap

Tempting wrong answers, and why they fail

Tempting but wrong

In an advisory engagement, is it fine for internal audit to redesign the workflow and put the new steps into operation so the fix lands quickly?

Why it fails

Speed is tempting, but designing and implementing the workflow makes internal audit the process owner and assumes a management responsibility. That impairs objectivity for any later assurance, so it is wrong.

Foundations of Internal Auditing

Tempting but wrong

If an accepted residual risk breaches appetite, the auditor should just direct the IT manager to change the response from accept to reduce.

Why it fails

Selecting and changing the risk response is a first line management decision. Directing it would breach the Three Lines Model and impair the auditor's objectivity, so it is wrong despite seeming decisive.

Governance, Risk Management, and Control

Tempting but wrong

If the team lacks the expertise, is it fine to narrow the scope to controls the team already understands and leave the specialist area untested?

Why it fails

Tempting because it lets the work start on time, but scoping around a competency gap leaves the very risk the engagement exists to examine unassessed and does not fulfil the mandate. Procuring the missing skill is the proper response.

Ethics and Professionalism

Tempting but wrong

A documented annual fraud risk assessment and anti-fraud controls, completed on schedule, mean the fraud risk management process is adequate. Right?

Why it fails

The presence of an assessment is reassuring, but adequacy depends on whether it reflects current exposure. An assessment that ignores materially changed fraud risks, such as new bribery and procurement exposures from overseas expansion, is not adequate simply because it exists.

Fraud Risks

Tempting but wrong

Should internal audit decline advisory work outright because advising on a process it may later audit always destroys objectivity?

Why it fails

Advisory work is a legitimate internal audit service, so a blanket refusal is unnecessary. The absolute claim that advice always destroys objectivity misstates the standards; objectivity is preserved by not assuming management responsibility.

Foundations of Internal Auditing

Tempting but wrong

Because accepting a risk is a legitimate response option within management's authority, the auditor can pass over it without comment.

Why it fails

Accept is a valid response, which makes this tempting, but the auditor must still evaluate whether the accepted residual risk is consistent with the board's appetite rather than passing silently over a breach.

Governance, Risk Management, and Control

Tempting but wrong

Could the auditor just obtain written confirmation from management that the model is accurate and rely on that instead of testing?

Why it fails

It looks efficient, but relying on the auditee's own assertion abandons independent assurance and adopts a first-line responsibility, which impairs objectivity.

Ethics and Professionalism

Tempting but wrong

On spotting that the assessment missed the new markets, should the auditor personally re-perform the fraud risk assessment and hand management the completed version?

Why it fails

Spotting the gap is correct, but owning and performing the fraud risk assessment is a management responsibility. Taking it on would place internal audit in a first line role and impair later assurance over that work.

Fraud Risks

Key terms

Global Internal Audit StandardsPurpose of Internal AuditingInternational Professional Practices FrameworkInternal audit mandateChief audit executiveBoard oversightInternal audit charterBoard approvalAssurance servicesAdvisory servicesReasonable assuranceLimited assuranceRisk and control assessmentCompliance auditOperational auditIT audit

Exam-day rules

  • Read the last line of the question first. It tells you what is actually being asked, so you can read the scenario looking for the best next action rather than memorising detail.
  • Decide who holds the responsibility before you choose. Fix whether the board, senior management, the chief audit executive, the first line, the second line, or internal audit owns the issue, then pick the option consistent with that role.
  • Choose the most standards-consistent action, not merely a defensible one. Several options are often reasonable; the exam wants the one that best protects independence, objectivity, and the Standards.
  • Distrust any option that has internal audit own, design, or manage a control or make a management decision. That is a Three Lines violation and is almost always the distractor.
  • Watch for absolutes such as always, never, guarantees, and eliminates all risk. Internal audit gives reasonable, not absolute, assurance, so an option promising certainty is usually wrong.

Revision schedule

  1. Day 1
    Map the outline and book a date
  2. Week 1
    Lock the foundations and independence (Section A)
  3. Weeks 1-2
    Work through governance, risk, and control (Section C)
  4. Week 2
    Cover ethics and professionalism (Section B)
  5. Week 3
    Study fraud risks (Section D)

Practise CIA-1 free

Every question explains why the right answer is right and why each wrong one is rationale. No sign-up.

843 audited flashcards in this deck.

Practise CIA-1 free
Examworthy - IIA Certified Internal Auditor - Part 1: Essentials of Internal Auditing (CIA-1) cheat sheet. Free to share.examworthy.com