CIA-1 - Fraud Risks - Section D.2

Determine whether fraud risks require special consideration during an engagement, including recognizing fraud risks when planning and assessing processes with significant exposure to fraud.

Determine when an engagement warrants specific attention to fraud by recognising fraud risk factors during planning and identifying processes, such as cash handling, procurement, or payroll, that carry significant exposure. Recognise that considering the potential for fraud is part of due professional care, without requiring the auditor to become a fraud investigator on every engagement.

Fraud risk assessmentEngagement planningFraud exposure

Practice question for this objective

Free sampleFraud Risksmedium

While planning an engagement at Verdon Logistics, an internal auditor argues that because internal audit is not a fraud investigation unit, the engagement plan need not address fraud at all. The chief audit executive reviews this position. Which correction best reflects the auditor's obligation during planning?

  • AThe auditor is correct, because fraud is entirely the remit of the forensic team and has no place in the planning of an engagement.
  • BThe auditor must now personally lead a formal fraud investigation on this engagement in order to satisfy due professional care.
  • CConsidering the potential for fraud is part of due professional care, so the plan should weigh fraud risk even though the auditor need not investigate every engagement. Correct
  • DFraud need only be considered after fieldwork ends, when the engagement results are being reported to the audit committee.
Considering the potential for fraud in planning is required by due professional care, but it does not oblige the auditor to investigate every engagement. Due professional care obliges the auditor to consider the potential for fraud when planning, which sits between two errors: ignoring fraud entirely and treating every engagement as a full fraud investigation.

Why A is wrong: It seems consistent with role boundaries, but it ignores that considering fraud potential is part of due professional care, so fraud cannot be absent from planning.

Why B is wrong: This overstates the duty; due professional care requires considering fraud risk, not leading an investigation on every engagement where fraud is possible.

Why C is correct: Correct: the auditor must consider fraud potential when planning as part of due professional care, while not being obliged to conduct a full fraud investigation on each engagement.

Why D is wrong: Reporting is too late; fraud risk is a planning input, and deferring it to the reporting stage defeats the purpose of considering it at all.

See more CIA-1 practice questions, answers explained.

More in this domain

Back to all Fraud Risks objectives, or the CIA-1 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.