IIA Certified Internal Auditor - Part 1: Essentials of Internal Auditing cheat sheet
The Institute of Internal Auditors
Free to share. Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors; CIA-1 and related marks belong to their respective owners.
At a glance
Format: Multiple choice, closed book
Domain weight map
Heaviest first - spend your time hereHow this exam thinks
CIA Part 1 rewards choosing the most independent, objective, standards-consistent next action in a scenario, not reciting a definition.
Spot the trap
Tempting wrong answers, and why they failTempting but wrong
In an advisory engagement, is it fine for internal audit to redesign the workflow and put the new steps into operation so the fix lands quickly?
Why it fails
Speed is tempting, but designing and implementing the workflow makes internal audit the process owner and assumes a management responsibility. That impairs objectivity for any later assurance, so it is wrong.
Foundations of Internal Auditing
Tempting but wrong
If an accepted residual risk breaches appetite, the auditor should just direct the IT manager to change the response from accept to reduce.
Why it fails
Selecting and changing the risk response is a first line management decision. Directing it would breach the Three Lines Model and impair the auditor's objectivity, so it is wrong despite seeming decisive.
Governance, Risk Management, and Control
Tempting but wrong
If the team lacks the expertise, is it fine to narrow the scope to controls the team already understands and leave the specialist area untested?
Why it fails
Tempting because it lets the work start on time, but scoping around a competency gap leaves the very risk the engagement exists to examine unassessed and does not fulfil the mandate. Procuring the missing skill is the proper response.
Ethics and Professionalism
Tempting but wrong
A documented annual fraud risk assessment and anti-fraud controls, completed on schedule, mean the fraud risk management process is adequate. Right?
Why it fails
The presence of an assessment is reassuring, but adequacy depends on whether it reflects current exposure. An assessment that ignores materially changed fraud risks, such as new bribery and procurement exposures from overseas expansion, is not adequate simply because it exists.
Fraud Risks
Tempting but wrong
Should internal audit decline advisory work outright because advising on a process it may later audit always destroys objectivity?
Why it fails
Advisory work is a legitimate internal audit service, so a blanket refusal is unnecessary. The absolute claim that advice always destroys objectivity misstates the standards; objectivity is preserved by not assuming management responsibility.
Foundations of Internal Auditing
Tempting but wrong
Because accepting a risk is a legitimate response option within management's authority, the auditor can pass over it without comment.
Why it fails
Accept is a valid response, which makes this tempting, but the auditor must still evaluate whether the accepted residual risk is consistent with the board's appetite rather than passing silently over a breach.
Governance, Risk Management, and Control
Tempting but wrong
Could the auditor just obtain written confirmation from management that the model is accurate and rely on that instead of testing?
Why it fails
It looks efficient, but relying on the auditee's own assertion abandons independent assurance and adopts a first-line responsibility, which impairs objectivity.
Ethics and Professionalism
Tempting but wrong
On spotting that the assessment missed the new markets, should the auditor personally re-perform the fraud risk assessment and hand management the completed version?
Why it fails
Spotting the gap is correct, but owning and performing the fraud risk assessment is a management responsibility. Taking it on would place internal audit in a first line role and impair later assurance over that work.
Fraud Risks
Key terms
Exam-day rules
- Read the last line of the question first. It tells you what is actually being asked, so you can read the scenario looking for the best next action rather than memorising detail.
- Decide who holds the responsibility before you choose. Fix whether the board, senior management, the chief audit executive, the first line, the second line, or internal audit owns the issue, then pick the option consistent with that role.
- Choose the most standards-consistent action, not merely a defensible one. Several options are often reasonable; the exam wants the one that best protects independence, objectivity, and the Standards.
- Distrust any option that has internal audit own, design, or manage a control or make a management decision. That is a Three Lines violation and is almost always the distractor.
- Watch for absolutes such as always, never, guarantees, and eliminates all risk. Internal audit gives reasonable, not absolute, assurance, so an option promising certainty is usually wrong.
Revision schedule
- Day 1Map the outline and book a date
- Week 1Lock the foundations and independence (Section A)
- Weeks 1-2Work through governance, risk, and control (Section C)
- Week 2Cover ethics and professionalism (Section B)
- Week 3Study fraud risks (Section D)