The Institute of Internal Auditors study guide

How to pass IIA Certified Internal Auditor - Part 1: Essentials of Internal Auditing (CIA-1)

17 min read4 domains coveredFree practice, no sign-up

The IIA Certified Internal Auditor Part 1 (Essentials of Internal Auditing) tests whether you can reason like an internal auditor: whether you understand what makes internal audit independent, objective, and useful, and whether you can pick the correct next action in a governance, risk, control, or fraud situation. It is not a memory test of definitions. Most questions are short scenarios about a fictional organisation, a board, a chief audit executive, and an engagement, and they ask for the best or the next step under the profession's own rules.

It suits people entering or working in internal audit, plus risk, compliance, and controls staff who need the recognised grounding. If you can already explain why organisational independence and individual objectivity are different things, and why internal audit must not own a control it later evaluates, much of the exam will feel natural. If those ideas are new, they are learnable in a few focused weeks because Part 1 is conceptual and principle-driven rather than technical.

The exam rewards judgement against the 2024 Global Internal Audit Standards. Many options describe a legitimate-looking action that quietly impairs independence, blurs the line between assurance and advisory work, takes on a first or second line responsibility, mislabels a control, or picks the wrong risk response. The skill being tested is choosing the most standards-consistent action, so practise on scenario questions that explain why each wrong option is wrong, not just which letter is correct.

CIA Part 1 rewards choosing the most independent, objective, standards-consistent next action in a scenario, not reciting a definition.

Difficulty

Intermediate

Best for

New and aspiring internal auditors, plus risk, compliance, governance, and internal control staff who want the globally recognised internal audit credential.

Prerequisites

None to study, though the CIA designation itself requires education and experience. A little exposure to auditing, risk, or controls helps but is not assumed.

125
Questions
150 min
Time allowed
600 / 750 (scaled)
Pass mark
$395
Exam cost (USD)
297
Practice questions

How this exam thinks

Three habits separate a pass from a fail on Part 1, and none of them is about knowing more definitions.

First, the exam asks for the best or the next action, not a true statement. Several options will be accurate descriptions of internal audit, but only one fits the scenario as written. Read the final sentence of the stem first, decide who holds the responsibility in play (the board, senior management, the chief audit executive, the first line, the second line, or internal audit), then judge each option against that role and the Standards, not against general truth. An option that is correct in the abstract is still wrong if it has internal audit make a management decision or own a control.

Second, the exam keeps returning to independence and objectivity, because that is what protects the value of assurance. Independence is organisational, a reporting-line property of the internal audit function; objectivity is individual, an unbiased mental attitude of the auditor. When a scenario introduces a threat, the standards-consistent answer usually protects one of these: disclose the impairment, adjust the reporting line, reassign the auditor, or add a safeguard, rather than proceed quietly. If an option lets internal audit design, operate, or manage the very thing it will later assure, it is the distractor.

Third, the exam expects precision on the pairs that sloppy candidates blur. Inherent risk is before controls, residual risk is what remains after them. Risk appetite is the broad amount of risk the organisation will accept in pursuit of objectives, risk tolerance is the acceptable variation around a specific objective. A control's design is whether it would work if operating, its operating effectiveness is whether it actually worked over the period. Assurance gives an independent opinion, advisory helps and advises without internal audit taking on management's role. Keep these distinct and a large share of the exam resolves itself; blur them and the plausible second-best answer will catch you.

What each domain tests and how to study it

The CIA-1 blueprint is split across 4 domains. Weights are the official share of the exam; see the official exam guide for the authoritative breakdown.

  1. Foundations of Internal Auditing

    35% of exam

    What you must be able to do. State the purpose, authority, and responsibility of internal audit, apply the mandatory guidance and the 2024 Global Internal Audit Standards, and protect independence and objectivity when a threat appears.

    In one sentenceThe core of the profession: the definition and mandate of internal audit, the Standards and Code of Ethics that govern it, and the independence and objectivity that make its assurance worth anything.

    Recall check: answer these from memory first
    • Distinguish organisational independence from individual objectivity in one sentence each, and say which is a reporting-line property.
    • Explain why the chief audit executive reports functionally to the board and administratively to senior management.
    • Name a threat to objectivity and the safeguard that addresses it.
    • State the difference between an assurance service and an advisory service in internal audit.

    What it tests. The nature and mandate of internal auditing: its purpose, authority, and place in the organisation, the internal audit charter, and the mandatory guidance in the 2024 Global Internal Audit Standards. It tests organisational independence and individual objectivity, the reporting relationship of the chief audit executive to the board, threats to independence and objectivity and their safeguards, and the difference between assurance and advisory services.

    How to study it. Fix the independence-versus-objectivity distinction first, because it runs through the whole exam: independence is a function-level, reporting-line property, objectivity is an individual mental attitude. Learn the chief audit executive's dual reporting line to the board and senior management and why it exists. Be able to name a threat (self-review, self-interest, familiarity, bias, undue influence) and the correct safeguard. Drill scenario questions until you can spot the option that quietly has internal audit own or manage what it will later assure.

    Easy to confuse

    • Independence versus objectivity. Independence is organisational, a property of the internal audit function secured through its reporting line to the board; objectivity is individual, an unbiased mental attitude of the auditor. The exam plants a scenario about a reporting relationship and offers an objectivity fix, or vice versa, to see whether you attach the remedy to the right level.
    • Assurance services versus advisory services. Assurance gives an independent opinion on governance, risk, or control based on an objective assessment; advisory is client-requested help and counsel where internal audit advises without assuming management's responsibility. If the scenario has internal audit deciding or owning the outcome, it has crossed from advisory into a management role, which the Standards do not permit.
    • Functional reporting versus administrative reporting for the chief audit executive. Functional reporting to the board protects independence and covers the charter, budget, audit plan, and the appointment or removal of the chief audit executive; administrative reporting to senior management covers day-to-day operations such as facilities and human resources. The exam tests which decisions must sit with the board to keep the function independent.

    Worked example from the CIA-1 bank

    Free sampleFoundations of Internal Auditingmedium

    Aster Retail's audit committee wants internal audit to provide a high level of confidence that the year-end revenue controls are operating effectively, and it has allocated ample time for extensive testing. Which type of engagement matches this request?

    • AA reasonable assurance engagement, which performs more extensive procedures to support a positively expressed conclusion at a high though not absolute level of confidence. Correct
    • BA limited assurance engagement, which performs reduced procedures and conveys a lower level of confidence through a negatively expressed conclusion.
    • CAn advisory engagement, because testing controls at the audit committee's request is simply advice provided to the client on demand.
    • DA reasonable assurance engagement, which guarantees the revenue controls are free from any deficiency because the testing was so extensive.
    Reasonable assurance applies more extensive procedures and a positively worded conclusion to convey a high, though not absolute, level of confidence. Reasonable and limited assurance differ by the depth of work performed and the confidence conveyed. A request for high confidence, backed by time for extensive testing, points to a reasonable assurance engagement with a positively expressed conclusion rather than a reduced-scope limited engagement.

    Why A is correct: Reasonable assurance uses deeper procedures to underpin a positively worded conclusion at a high but not absolute level of confidence, which is exactly what the committee has asked for and resourced.

    Why B is wrong: Limited assurance is tempting shorthand for any controls review, but its reduced procedures and negative wording give lower confidence than the high assurance requested, so it does not fit.

    Why C is wrong: Concluding on whether controls operate effectively for stakeholders is assurance, not advice; labelling it advisory misclassifies the service and is therefore wrong.

    Why D is wrong: Reasonable assurance is high but not absolute, so promising a guarantee of no deficiency overstates what the engagement can deliver and makes this option incorrect.

  2. Ethics and Professionalism

    20% of exam

    What you must be able to do. Apply the IIA Code of Ethics and its four principles to a dilemma, exercise due professional care and professional scepticism, and act correctly when confidentiality, competency, or objectivity is under pressure.

    In one sentenceHow an internal auditor is expected to behave: the four Code of Ethics principles, due professional care and professional scepticism, and the right response when a request conflicts with them.

    Recall check: answer these from memory first
    • Name the four principles of the IIA Code of Ethics.
    • Define due professional care and say why it is not a guarantee that nothing was missed.
    • Explain what professional scepticism requires when reviewing evidence management has provided.
    • State the correct action when a client asks you to omit an unfavourable finding.

    What it tests. Professional ethics and conduct: the IIA Code of Ethics and its four principles of integrity, objectivity, confidentiality, and competency, and how they apply to realistic dilemmas. It tests due professional care and professional scepticism, continuing professional development and competency, the correct handling of confidential information, and what an auditor should do when management or a client pressures them to act against the Code.

    How to study it. Memorise the four principles by name and, more importantly, learn to recognise which principle a scenario is straining. Treat due professional care as reasonable care and skill, not perfection or a guarantee, and professional scepticism as a questioning mind that does not assume management is either dishonest or unquestionably honest. Practise dilemmas where the standards-consistent answer is to decline, disclose, or escalate rather than to comply quietly, because that is the shape of most ethics questions.

    Easy to confuse

    • Due professional care versus a guarantee of no error. Due professional care is the competence and diligence a reasonably prudent and skilled internal auditor would apply; it does not promise that every irregularity will be found. The exam offers an absolute-sounding option (the audit guarantees no fraud exists) as the distractor against the measured, care-based answer.
    • Confidentiality versus a duty to disclose. Confidentiality protects information acquired during work, but it does not shield illegal acts or override a legitimate reporting obligation to the board or a regulator. The exam tests whether you know that confidentiality yields when disclosure is required, rather than treating it as absolute silence.
    • Objectivity versus independence in an ethics scenario. In an ethics dilemma the issue is usually individual objectivity, a personal bias or conflict of interest, not the function's organisational independence. Read whether the pressure is on the auditor's mindset or on the function's structure, and apply the matching principle.

    Worked example from the CIA-1 bank

    Free sampleEthics and Professionalismmedium

    Brant Water's internal audit function is scoping an assurance engagement over a new actuarial reserving model. No one on the team has actuarial expertise, and the chief audit executive cannot recruit a qualified actuary before the engagement must begin. What is the most appropriate way to proceed?

    • AProceed with the engagement but narrow the scope to the general controls the team already understands, leaving the actuarial calculations untested this year.
    • BObtain a written confirmation from management that the reserving model is accurate, then rely on that assertion in place of independent testing.
    • CProcure the missing actuarial competency externally, for example through a guest auditor or an external specialist, so the function collectively has the skills the work requires. Correct
    • DPostpone the engagement indefinitely until a suitably qualified actuary can be recruited as a permanent member of the internal audit staff.
    Where the internal audit function lacks a required competency, it may procure that expertise externally rather than proceed under-qualified or drop the work. Competency can be satisfied collectively: when in-house skills fall short, sourcing an external specialist keeps the engagement competent while internal audit retains its independent assurance role, which neither a narrowed scope nor reliance on management can deliver.

    Why A is wrong: Scoping around a competency gap is tempting because it lets the work start on time, but it leaves the very risk the engagement exists to examine unassessed and does not fulfil the mandate.

    Why B is wrong: This looks efficient, but relying on the auditee's own assertion abandons independent assurance and adopts a first-line responsibility, which impairs objectivity.

    Why C is correct: The Global Internal Audit Standards allow competencies to be developed or procured; bringing in a qualified specialist lets the function cover the model competently without impairing its independent role.

    Why D is wrong: Permanent recruitment feels thorough, but the Standards permit procuring competencies, so an open-ended delay is unnecessary and leaves a material risk unaddressed.

  3. Governance, Risk Management, and Control

    30% of exam

    What you must be able to do. Read a governance, risk management, and control situation through the Three Lines Model, classify risks and controls correctly, choose the right risk response, and judge internal audit's proper role in each.

    In one sentenceThe machinery internal audit assesses: governance and the Three Lines Model, the risk management process with appetite and tolerance, and control types and effectiveness, with internal audit as the independent third line.

    Recall check: answer these from memory first
    • State the role of each of the three lines and where internal audit sits.
    • Distinguish inherent risk from residual risk, and risk appetite from risk tolerance.
    • Name the four risk responses and give a one-line example of each.
    • Explain the difference between testing a control's design and testing its operating effectiveness.

    What it tests. Governance, risk management, and control: governance concepts and the IIA Three Lines Model, the risk management process including risk appetite and risk tolerance and the inherent-versus-residual distinction, and the four risk responses of accept, avoid, reduce, and share. It tests control frameworks such as COSO Internal Control, control types (preventive, detective, corrective), the difference between control design and operating effectiveness, and internal audit's role as the third line without owning first or second line responsibilities.

    How to study it. Learn the Three Lines Model as roles, not a diagram: the first line owns and manages risk, the second line provides oversight and expertise such as risk and compliance, and internal audit is the independent third line providing assurance. Drill the precise pairs the exam loves: inherent versus residual risk, appetite versus tolerance, design versus operating effectiveness, and the preventive, detective, and corrective control types. For any scenario, first decide whose responsibility it is, then pick the option that keeps internal audit in an assurance role.

    Easy to confuse

    • Inherent risk versus residual risk. Inherent risk is the exposure before any control is applied; residual risk is what remains after controls operate. The exam tests whether a proposed response or opinion is about the risk gross of controls or net of them, because the correct management action depends on which one the scenario names.
    • Risk appetite versus risk tolerance. Risk appetite is the broad amount and type of risk the organisation is willing to pursue in pursuit of its objectives; risk tolerance is the acceptable variation around a specific objective or measure. Appetite is strategic and organisation-wide, tolerance is narrow and measurable, and the exam swaps them to check the precision.
    • Control design versus operating effectiveness. Design effectiveness asks whether a control, if it operated as intended, would prevent or detect the risk; operating effectiveness asks whether it actually did so consistently over the period. A well-designed control that was not performed still fails on operating effectiveness, which is the distinction the exam probes.
    • The three lines and who may own a control. The first line owns and operates controls and the second line oversees them; internal audit, the third line, provides independent assurance and must not own or manage a control it will assess. An option that has internal audit design or run a control is a Three Lines violation regardless of how helpful it sounds.

    Worked example from the CIA-1 bank

    Free sampleGovernance, Risk Management, and Controlmedium

    At Meridian Freight, the board has set a stated risk appetite of no unplanned service outages exceeding four hours per quarter. During an assurance engagement, the internal auditor finds that management has formally accepted a residual technology risk whose worst-case outage is estimated at nine hours. What should the internal auditor do next?

    • AReport that the accepted residual risk exceeds the board's stated appetite and escalate the matter to senior management and the board as the appropriate risk owners. Correct
    • BDirect the IT manager to change the risk response from accept to reduce so the exposure falls back within the board's stated appetite before the engagement closes.
    • CAccept management's decision without comment, because choosing to accept a risk is a legitimate response option that always sits within management's authority to make.
    • DRedesign the technology control and implement the additional recovery capacity needed to bring the estimated outage below the four-hour appetite threshold.
    Internal audit evaluates whether an accepted residual risk exceeds the board's stated appetite and escalates it rather than owning the response. Risk appetite is the board's stated boundary; an accepted residual risk above that boundary is a governance exception. The auditor's independent role is to evaluate the response against appetite and escalate to the accountable owners, never to select or implement the response itself.

    Why A is correct: Evaluating the response against appetite and escalating an exposure that exceeds it to the accountable owners is the independent, standards-consistent action, keeping the decision with management and the board.

    Why B is wrong: Selecting and changing the risk response is a first line management decision; directing it would breach the Three Lines Model and impair the auditor's objectivity, so this is wrong despite seeming decisive.

    Why C is wrong: Accept is a valid response, which makes this tempting, but the auditor must still evaluate whether the accepted residual risk is consistent with the board's appetite rather than passing silently over a breach.

    Why D is wrong: Designing and implementing controls is a management responsibility; taking it on would make the auditor an owner of the very control later assured, so this impairs independence and is wrong.

  4. Fraud Risks

    15% of exam

    What you must be able to do. Apply the fraud triangle to a scenario, weigh fraud risk in planning, recognise red flags, and place internal audit's role in prevention, detection, and investigation correctly.

    In one sentenceFraud through the internal auditor's lens: the fraud triangle, fraud risk in the audit plan and controls, red-flag indicators, and internal audit's supporting rather than leading role in investigations.

    Recall check: answer these from memory first
    • Name the three legs of the fraud triangle and give a red flag for each.
    • State internal audit's role when fraud is suspected, and what it is not.
    • Distinguish a preventive anti-fraud control from a detective one with an example of each.
    • Explain how fraud risk should influence engagement planning.

    What it tests. Fraud risks and the internal auditor's responsibilities: the fraud triangle of pressure or motivation, opportunity, and rationalisation, types of fraud, and fraud risk factors and red flags. It tests how fraud risk is considered in engagement planning and in the design of anti-fraud controls, the difference between fraud prevention and detection, and internal audit's role, which is typically to assess fraud risk and support an investigation rather than to lead it or guarantee that fraud will be found.

    How to study it. Learn the three legs of the fraud triangle and be able to map a red flag to the leg it signals, because scenarios describe a situation and ask which element is present. Keep internal audit's role calibrated: it evaluates the adequacy of fraud controls and exercises due professional care to be alert to fraud, but it does not normally lead investigations, and it never guarantees detection. Distinguish preventive anti-fraud controls (segregation of duties, authorisation) from detective ones (reconciliations, analytics, hotlines).

    Easy to confuse

    • The three legs of the fraud triangle. Pressure or motivation is the incentive to commit fraud, opportunity is the weak control or access that lets it happen, and rationalisation is the mindset that justifies it. Of the three, opportunity is the one internal audit and controls most directly reduce, and the exam tests whether you can label the leg a scenario describes.
    • Internal audit's role versus leading a fraud investigation. Internal audit assesses fraud risk, evaluates anti-fraud controls, and supports an investigation with its skills, but leading a formal investigation typically belongs to management, legal, or specialist investigators to preserve internal audit's independence and objectivity. An option that has internal audit take charge of the investigation is usually the distractor.
    • Fraud prevention versus fraud detection. Preventive anti-fraud controls stop fraud before it occurs, such as segregation of duties and authorisation limits; detective controls surface it after the fact, such as reconciliations, data analytics, and a whistle-blower hotline. The exam asks which type a proposed control is, and pairs the requirement (stop it happening versus catch it) with the control class.

    Worked example from the CIA-1 bank

    Free sampleFraud Riskshard

    At Kelston Manufacturing, internal audit is evaluating how well the organisation manages fraud risk. Management runs a documented annual fraud risk assessment and maintains anti-fraud controls, but the assessment has not been revisited even though the company has entered three overseas markets this year, each carrying different bribery and procurement-fraud exposures. How should the internal auditor characterise this situation?

    • AThe fraud risk management process is adequate, because a documented annual fraud risk assessment and a set of anti-fraud controls are already in place and were completed on schedule this year.
    • BThe fraud risk management process is not adequate, because the fraud risk assessment has not been updated to reflect the new fraud exposures created by the recent market expansion. Correct
    • CThe internal auditor should personally re-perform the fraud risk assessment for the three new markets and hand management the completed assessment so the gap is closed before the engagement ends.
    • DThe internal auditor should conclude that fraud is likely occurring in the new markets, because the exposures there were never assessed and uncontrolled fraud risk almost always results in actual fraud.
    A fraud risk management process is adequate only if its assessment is kept current with changing fraud exposure, not merely because an assessment exists. Fraud risk management is evaluated against whether identification, assessment, and response track the organisation's actual exposure. When new markets create fresh fraud risks that the assessment never captures, the responses cannot match the exposure, so the process is inadequate; re-performing the assessment or asserting that fraud is occurring both exceed the auditor's proper role.

    Why A is wrong: The presence of an assessment is reassuring, but adequacy depends on whether it reflects current exposure; an assessment that ignores materially changed fraud risks is not adequate simply because it exists.

    Why B is correct: Evaluating fraud risk management means checking that identification and assessment keep pace with changing exposure; a static assessment that misses new bribery and procurement risks leaves the response mismatched to the actual exposure.

    Why C is wrong: Spotting the gap is correct, but owning and performing the fraud risk assessment is a management responsibility; taking it on would place internal audit in a first line role and impair later assurance over that work.

    Why D is wrong: An unassessed exposure is a control weakness, not proof of fraud; concluding that fraud is occurring without evidence oversteps the auditor's role, which is to report the weakness in fraud risk management.

A study plan that works

  1. Map the outline and book a date

    Day 1

    Read the official Part 1 exam outline and its four sections with their weights. Book a provisional exam date now: a fixed date turns open-ended study into a plan and is the single biggest predictor of actually sitting the exam.

  2. Lock the foundations and independence (Section A)

    Week 1

    This is the largest section and the base for everything else. Get the mandate of internal audit, the 2024 Global Internal Audit Standards, and the independence-versus-objectivity distinction solid before moving on. Use the recall prompts in this guide: cover the summary, answer from memory, then reveal.

  3. Work through governance, risk, and control (Section C)

    Weeks 1-2

    The second-largest section and the densest on precise pairs. Drill the Three Lines Model roles, inherent versus residual risk, appetite versus tolerance, control types, and design versus operating effectiveness with scenario questions rather than flashcards alone.

  4. Cover ethics and professionalism (Section B)

    Week 2

    Learn the four Code of Ethics principles by name and practise dilemmas where the right answer is to decline, disclose, or escalate. Anchor due professional care and professional scepticism as reasonable care and a questioning mind, not perfection.

  5. Study fraud risks (Section D)

    Week 3

    The smallest section but a reliable source of marks. Learn the fraud triangle, map red flags to its legs, keep internal audit's supporting role calibrated, and separate preventive from detective anti-fraud controls.

  6. Practise on scenarios with every answer explained

    Week 3-4

    Move to full practice sets and read the explanation for every question, including the ones you got right. Part 1 tests judgement between plausible options, so understanding why a distractor impairs independence or crosses a role line is where the marks are.

  7. Find weak sections, then sit a timed mock

    Week 4

    Use your per-section accuracy to drill the sections dragging you down rather than re-reading what you know. Then take at least one full timed mock to rehearse pacing and flag-and-return, and review every missed question before booking or sitting.

Know when you're ready

Readiness for Part 1 is a score on questions you have not seen before, not a feeling that the material is familiar. Those are different things, and the gap between them is where people fail. Re-reading the Standards builds fluency, and fluency feels like knowledge, so confidence rises while real recall does not. The fix is to test yourself: if you can answer a fresh scenario and explain why the wrong options impair independence, blur assurance and advisory, or mislabel a risk or control, you know it; if you can only nod along to the explanation, you do not yet.

Be especially careful with the precise pairs. Inherent versus residual risk, appetite versus tolerance, and design versus operating effectiveness feel obvious when you read them and slip under exam pressure, so test them cold rather than trusting recognition. Judge your readiness by measured per-section accuracy across more than one session, and set the bar at clearing every section comfortably on unseen questions, not scraping the pass mark once.

This guide gives you the map. The practice bank is where you find out whether you can navigate it, with an explanation of why the right answer is right and every wrong one is wrong on every question. Readiness scoring tells you when you are there. Not before.

Ready to put this into practice?

Free CIA-1 questions, every answer explained. No sign-up.

Practise CIA-1 free

Exam-day tips

  • Read the last line of the question first. It tells you what is actually being asked, so you can read the scenario looking for the best next action rather than memorising detail.
  • Decide who holds the responsibility before you choose. Fix whether the board, senior management, the chief audit executive, the first line, the second line, or internal audit owns the issue, then pick the option consistent with that role.
  • Choose the most standards-consistent action, not merely a defensible one. Several options are often reasonable; the exam wants the one that best protects independence, objectivity, and the Standards.
  • Distrust any option that has internal audit own, design, or manage a control or make a management decision. That is a Three Lines violation and is almost always the distractor.
  • Watch for absolutes such as always, never, guarantees, and eliminates all risk. Internal audit gives reasonable, not absolute, assurance, so an option promising certainty is usually wrong.
  • Keep the precise pairs straight under pressure: inherent versus residual, appetite versus tolerance, design versus operating effectiveness, assurance versus advisory. Naming the right one resolves a large share of questions.
  • Flag and move on. Do not lose time on one hard item when easier marks are waiting; cover every question first, then return to the flagged ones.

Frequently asked questions

Is CIA Part 1 hard?

It is conceptual rather than technical, so the difficulty is in judgement, not calculation. Most questions are scenarios where several options look reasonable and one best protects independence, objectivity, and the Standards, which is why scenario practice that explains every option matters more than memorising definitions.

How long should I study for CIA Part 1?

Most candidates with some exposure to auditing, risk, or controls are ready in three to five weeks of focused study. Less background means more time on the foundations and the governance, risk, and control sections, which carry the most weight.

What is the difference between independence and objectivity?

Independence is organisational: a property of the internal audit function, secured through the chief audit executive's reporting line to the board. Objectivity is individual: an unbiased mental attitude of the auditor. Part 1 repeatedly tests whether you attach the right remedy to the right level, so keep them distinct.

Which sections should I focus on?

The foundations section and the governance, risk, and control section together make up the majority of the exam, so they deserve the most time. Ethics and professionalism and fraud risks are smaller but reliable sources of marks once the concepts are clear.

Does Part 1 use the 2024 Global Internal Audit Standards or the older numbering?

Part 1 is keyed to the 2024 Global Internal Audit Standards and the current four-section outline. The retired 2017 IPPF International Standards numbering and the older 2019 six-domain outline are out of scope, so study current guidance and ignore old Standard numbers.

What is internal audit's role in fraud?

Internal audit assesses fraud risk, evaluates the adequacy of anti-fraud controls, and stays alert to fraud through due professional care and professional scepticism. It normally supports rather than leads a formal investigation, and it never guarantees that all fraud will be detected.

What is the pass mark for CIA Part 1?

The exam is reported on a scaled score and the published pass mark is in the facts panel above. Because scoring is scaled, your raw percentage and the reported score are not the same thing, so aim to clear every section comfortably in practice rather than targeting a bare pass.

Is the CIA worth it?

The Certified Internal Auditor is the globally recognised designation for the profession, and Part 1 establishes the essentials that Parts 2 and 3 build on. It is a strong credential for anyone building a career in internal audit, risk, or controls.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. This guide is original study material based on the public exam blueprint. We never reproduce live exam items. CIA-1 and related marks belong to their respective owners.