CIA-1 domain - 30% of the exam

Governance, Risk Management, and Control

Governance, Risk Management, and Control is 30% of the IIA Certified Internal Auditor - Part 1: Essentials of Internal Auditing (CIA-1) exam. These are the objectives it covers, each with practice questions, with every answer explained.

Objectives in this domain

Sample question from this domain

Free sampleGovernance, Risk Management, and Controlmedium

At Meridian Freight, the board has set a stated risk appetite of no unplanned service outages exceeding four hours per quarter. During an assurance engagement, the internal auditor finds that management has formally accepted a residual technology risk whose worst-case outage is estimated at nine hours. What should the internal auditor do next?

  • AReport that the accepted residual risk exceeds the board's stated appetite and escalate the matter to senior management and the board as the appropriate risk owners. Correct
  • BDirect the IT manager to change the risk response from accept to reduce so the exposure falls back within the board's stated appetite before the engagement closes.
  • CAccept management's decision without comment, because choosing to accept a risk is a legitimate response option that always sits within management's authority to make.
  • DRedesign the technology control and implement the additional recovery capacity needed to bring the estimated outage below the four-hour appetite threshold.
Internal audit evaluates whether an accepted residual risk exceeds the board's stated appetite and escalates it rather than owning the response. Risk appetite is the board's stated boundary; an accepted residual risk above that boundary is a governance exception. The auditor's independent role is to evaluate the response against appetite and escalate to the accountable owners, never to select or implement the response itself.

Why A is correct: Evaluating the response against appetite and escalating an exposure that exceeds it to the accountable owners is the independent, standards-consistent action, keeping the decision with management and the board.

Why B is wrong: Selecting and changing the risk response is a first line management decision; directing it would breach the Three Lines Model and impair the auditor's objectivity, so this is wrong despite seeming decisive.

Why C is wrong: Accept is a valid response, which makes this tempting, but the auditor must still evaluate whether the accepted residual risk is consistent with the board's appetite rather than passing silently over a breach.

Why D is wrong: Designing and implementing controls is a management responsibility; taking it on would make the auditor an owner of the very control later assured, so this impairs independence and is wrong.

Other domains in this exam

See also the CIA-1 cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.