8 real CIA-1 flashcards, sampled from all 4 domains the exam tests, heaviest first. Each concept card is paired with the misconception card built from the tempting wrong answer - the trap most decks skip. No account, no card.
The full deck has 843 flashcards, and a free account opens 40 of them across every domain. For a domain-by-domain breakdown and a study plan, read the CIA-1 study guide.
schoolConceptFoundations of Internal Auditing
In an advisory engagement requested by management, how does internal audit protect its ability to give assurance on the same area later?
arrow_downward
It advises on options and facilitates the decision but leaves the design choices and implementation firmly with management. Not assuming management responsibility is the defining safeguard that keeps objectivity intact, so the activity can still provide independent assurance on that area afterwards.
errorMisconceptionFoundations of Internal Auditing
In an advisory engagement, is it fine for internal audit to redesign the workflow and put the new steps into operation so the fix lands quickly?
arrow_downward
Speed is tempting, but designing and implementing the workflow makes internal audit the process owner and assumes a management responsibility. That impairs objectivity for any later assurance, so it is wrong.
schoolConceptGovernance, Risk Management, and Control
An accepted residual risk exceeds the board's stated risk appetite. What is internal audit's role in responding to it?
arrow_downward
Risk appetite is the board's stated boundary, so an accepted residual risk above it is a governance exception. Internal audit's independent role is to evaluate the response against appetite and escalate the exception to senior management and the board as the accountable owners, never to select or implement the response itself.
errorMisconceptionGovernance, Risk Management, and Control
If an accepted residual risk breaches appetite, the auditor should just direct the IT manager to change the response from accept to reduce.
arrow_downward
Selecting and changing the risk response is a first line management decision. Directing it would breach the Three Lines Model and impair the auditor's objectivity, so it is wrong despite seeming decisive.
schoolConceptEthics and Professionalism
The internal audit team lacks a required competency and cannot recruit the specialist in time. How can it still run a competent engagement?
arrow_downward
Competency can be satisfied collectively. When in-house skills fall short, the function may procure the expertise externally, for example through a guest auditor or specialist, keeping the engagement competent while internal audit retains its independent assurance role.
errorMisconceptionEthics and Professionalism
If the team lacks the expertise, is it fine to narrow the scope to controls the team already understands and leave the specialist area untested?
arrow_downward
Tempting because it lets the work start on time, but scoping around a competency gap leaves the very risk the engagement exists to examine unassessed and does not fulfil the mandate. Procuring the missing skill is the proper response.
schoolConceptFraud Risks
What makes a fraud risk management process adequate: the existence of an annual assessment, or something more?
arrow_downward
Adequacy turns on whether identification, assessment and response track the organisation's actual exposure. When new markets create fresh fraud risks the assessment never captured, the responses cannot match the exposure, so the process is inadequate even though a documented assessment exists.
errorMisconceptionFraud Risks
A documented annual fraud risk assessment and anti-fraud controls, completed on schedule, mean the fraud risk management process is adequate. Right?
arrow_downward
The presence of an assessment is reassuring, but adequacy depends on whether it reflects current exposure. An assessment that ignores materially changed fraud risks, such as new bribery and procurement exposures from overseas expansion, is not adequate simply because it exists.
Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. All flashcards are original, drawn from our own blueprint-aligned practice questions. We never reproduce live exam items. CIA-1 and related marks belong to their respective owners.