CIA-1 - Foundations of Internal Auditing - Section A.8

Recognize the internal audit function's role in the organization's risk management process, including The IIA's Three Lines Model and the safeguards needed when auditors take on first or second line responsibilities.

Explain The IIA's Three Lines Model and where internal audit sits as the third line providing independent assurance, distinct from first-line operational management and second-line risk and compliance functions. Identify first or second line responsibilities that would impair independence if internal audit performed them, and describe the safeguards to apply when auditors do, or appear to, take on such duties.

Three Lines ModelRisk management processIndependence safeguards

Practice question for this objective

Free sampleFoundations of Internal Auditingmedium

At Kestrel Utilities the enterprise risk manager is on extended leave, and the chief executive asks the chief audit executive to temporarily own the corporate risk register, set the risk responses, and report those decisions to the board as management's own position. The chief audit executive wants to keep internal audit able to give independent assurance over risk management later. What should the chief audit executive do first?

  • AAccept ownership of the risk register and the response decisions for the interim period, since the chief executive has personally requested the support and the arrangement is only temporary.
  • BAccept the role but arrange for the external auditor to provide all future assurance over risk management so that internal audit's independence is not a concern.
  • CAccept the role and simply disclose the impairment in every future audit report covering risk management, treating disclosure as a sufficient safeguard.
  • DDecline the management responsibility, explain that owning and deciding risk responses are first and second line roles, and offer instead to advise on the risk process while keeping decisions with management. Correct
Internal audit must not take ownership of risk responses, which are first and second line duties, if it is to retain its independent third line assurance role. Under The IIA's Three Lines Model, management owns and responds to risk while internal audit provides independent assurance. Owning the risk register and deciding responses would make internal audit assess its own work, destroying the independence its assurance depends on.

Why A is wrong: It is tempting because a direct request from the chief executive feels authoritative and the work is short-term, but owning the register and deciding responses are first and second line duties that would leave internal audit assuring its own decisions.

Why B is wrong: This looks prudent because outsourcing the assurance seems to sidestep the conflict, but it wrongly cedes internal audit's mandate and still has internal audit performing a second line function it should not own in the first place.

Why C is wrong: Disclosure is a recognised safeguard when auditors take on operational tasks, but it does not cure ongoing ownership of a core management responsibility, so relying on it alone still breaches the separation of lines.

Why D is correct: Correct: The IIA's Three Lines Model places risk ownership with the first and second lines, so internal audit must not decide responses; advising while decisions stay with management preserves the third line assurance role.

See more CIA-1 practice questions, answers explained.

More in this domain

Back to all Foundations of Internal Auditing objectives, or the CIA-1 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.