CIA-1 - Foundations of Internal Auditing - Section A.5

Describe the types of assurance services performed by the internal audit function, including risk and control, compliance, IT security and privacy, performance, financial, and operational audits.

Describe the common assurance engagement types the function performs, including risk and control assessments, third-party and contract compliance audits, IT security and privacy audits, performance and quality audits, and operational, financial, and regulatory compliance audits. Recognise that these can extend to assurance over organisational culture and the management reporting process.

Risk and control assessmentCompliance auditOperational auditIT audit

Practice question for this objective

Free sampleFoundations of Internal Auditingmedium

The board wants internal audit to provide assurance over whether the organisation's culture supports ethical behaviour and appropriate risk-taking, rather than over any single process or transaction. Which type of assurance engagement does this describe?

  • AA culture assurance engagement, because it assesses whether shared values, behaviours, and attitudes support the organisation's objectives and ethical conduct. Correct
  • BA compliance audit, because it checks whether employees have signed and acknowledged the individual clauses of the published code of conduct.
  • CA reporting assurance engagement, because it tests whether the organisation's external disclosures fairly present its financial position.
  • DAn advisory engagement, because internal audit is being asked to coach management on how to improve the organisation's culture.
Classify assurance over shared values and behaviours as a culture assurance engagement, distinct from compliance or reporting assurance. Culture assurance is defined by its subject: the shared values, behaviours, and attitudes that shape ethical conduct and risk-taking across the organisation. That behavioural focus separates it from checking rule acknowledgements or the fairness of external disclosures.

Why A is correct: Correct: culture assurance evaluates the organisation's shared values and behaviours and how they shape ethical conduct and risk-taking, which is what the board requested.

Why B is wrong: Confirming acknowledgements is conformance work, which makes compliance tempting, but culture assurance looks at shared behaviours and attitudes rather than whether a form was signed.

Why C is wrong: Reporting assurance addresses the fairness of disclosures, a neighbouring assurance type, so it is tempting but wrong because culture is about behaviour rather than reported information.

Why D is wrong: The board is seeking an independent conclusion on culture, which is assurance work, so framing it as requested coaching mistakes an assurance engagement for advisory support.

See more CIA-1 practice questions, answers explained.

More in this domain

Back to all Foundations of Internal Auditing objectives, or the CIA-1 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.