CIA-1 domain - 15% of the exam

Fraud Risks

Fraud Risks is 15% of the IIA Certified Internal Auditor - Part 1: Essentials of Internal Auditing (CIA-1) exam. These are the objectives it covers, each with practice questions, with every answer explained.

Objectives in this domain

Sample question from this domain

Free sampleFraud Riskshard

At Kelston Manufacturing, internal audit is evaluating how well the organisation manages fraud risk. Management runs a documented annual fraud risk assessment and maintains anti-fraud controls, but the assessment has not been revisited even though the company has entered three overseas markets this year, each carrying different bribery and procurement-fraud exposures. How should the internal auditor characterise this situation?

  • AThe fraud risk management process is adequate, because a documented annual fraud risk assessment and a set of anti-fraud controls are already in place and were completed on schedule this year.
  • BThe fraud risk management process is not adequate, because the fraud risk assessment has not been updated to reflect the new fraud exposures created by the recent market expansion. Correct
  • CThe internal auditor should personally re-perform the fraud risk assessment for the three new markets and hand management the completed assessment so the gap is closed before the engagement ends.
  • DThe internal auditor should conclude that fraud is likely occurring in the new markets, because the exposures there were never assessed and uncontrolled fraud risk almost always results in actual fraud.
A fraud risk management process is adequate only if its assessment is kept current with changing fraud exposure, not merely because an assessment exists. Fraud risk management is evaluated against whether identification, assessment, and response track the organisation's actual exposure. When new markets create fresh fraud risks that the assessment never captures, the responses cannot match the exposure, so the process is inadequate; re-performing the assessment or asserting that fraud is occurring both exceed the auditor's proper role.

Why A is wrong: The presence of an assessment is reassuring, but adequacy depends on whether it reflects current exposure; an assessment that ignores materially changed fraud risks is not adequate simply because it exists.

Why B is correct: Evaluating fraud risk management means checking that identification and assessment keep pace with changing exposure; a static assessment that misses new bribery and procurement risks leaves the response mismatched to the actual exposure.

Why C is wrong: Spotting the gap is correct, but owning and performing the fraud risk assessment is a management responsibility; taking it on would place internal audit in a first line role and impair later assurance over that work.

Why D is wrong: An unassessed exposure is a control weakness, not proof of fraud; concluding that fraud is occurring without evidence oversteps the auditor's role, which is to report the weakness in fraud risk management.

Other domains in this exam

See also the CIA-1 cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.