12 real CIA-1 sample questions, each with an explanation of why every option is right or wrong. No account, no card. This is the reasoning the CIA-1 tests: knowing why the tempting answer is wrong, not just spotting the right one.
The real CIA-1 is 125 questions in 150 minutes, pass mark 600 / 750 (scaled). For a domain-by-domain breakdown and a study plan, read the CIA-1 study guide. The full bank has 297 questions.
lock_openFree sampleFoundations of Internal Auditingmedium
Aster Retail's audit committee wants internal audit to provide a high level of confidence that the year-end revenue controls are operating effectively, and it has allocated ample time for extensive testing. Which type of engagement matches this request?
- AA reasonable assurance engagement, which performs more extensive procedures to support a positively expressed conclusion at a high though not absolute level of confidence.check_circle Correct
- BA limited assurance engagement, which performs reduced procedures and conveys a lower level of confidence through a negatively expressed conclusion.
- CAn advisory engagement, because testing controls at the audit committee's request is simply advice provided to the client on demand.
- DA reasonable assurance engagement, which guarantees the revenue controls are free from any deficiency because the testing was so extensive.
Reasonable assurance applies more extensive procedures and a positively worded conclusion to convey a high, though not absolute, level of confidence. Reasonable and limited assurance differ by the depth of work performed and the confidence conveyed. A request for high confidence, backed by time for extensive testing, points to a reasonable assurance engagement with a positively expressed conclusion rather than a reduced-scope limited engagement.
Why A is correct: Reasonable assurance uses deeper procedures to underpin a positively worded conclusion at a high but not absolute level of confidence, which is exactly what the committee has asked for and resourced.
Why B is wrong: Limited assurance is tempting shorthand for any controls review, but its reduced procedures and negative wording give lower confidence than the high assurance requested, so it does not fit.
Why C is wrong: Concluding on whether controls operate effectively for stakeholders is assurance, not advice; labelling it advisory misclassifies the service and is therefore wrong.
Why D is wrong: Reasonable assurance is high but not absolute, so promising a guarantee of no deficiency overstates what the engagement can deliver and makes this option incorrect.
lock_openFree sampleFoundations of Internal Auditingmedium
At Vela Logistics, the chief financial officer asks the chief audit executive to help improve a struggling contract-approval process, and the CAE agrees to run an advisory engagement. To keep internal audit's later ability to provide assurance intact, how should the CAE frame the team's role on this work?
- ATake ownership of redesigning the approval workflow and put the new steps into operation directly, so the fix is delivered to the CFO quickly.
- BDecline the request outright, because giving advice on a process the team may later audit always impairs objectivity beyond repair.
- CPerform the work as an assurance engagement instead, issuing a formal opinion on the redesigned process to the board this quarter.
- DAdvise on options and facilitate management's decision while leaving the design choices and implementation firmly with management.check_circle Correct
In an advisory engagement internal audit gives advice at the client's request without assuming management responsibility for the decisions or their implementation. Advisory services provide advice requested by the client, and the defining safeguard is that internal audit does not take on management responsibility. Keeping design and implementation with management is what protects objectivity so the activity can still provide independent assurance on the same area later.
Why A is wrong: Speed is tempting, but designing and implementing the workflow makes internal audit the process owner and assumes a management responsibility, which impairs objectivity for any later assurance and is wrong.
Why B is wrong: Advisory work is a legitimate internal audit service, so a blanket refusal is unnecessary; the absolute claim that advice always destroys objectivity misstates the standards and is incorrect.
Why C is wrong: Relabelling the work as assurance mischaracterises a request for advice and would opine on a process that is not yet operating, confusing the two service types and making this wrong.
Why D is correct: Advisory services deliver advice at the client's request without internal audit assuming management responsibility, so keeping the decisions and implementation with management preserves the objectivity needed for future assurance.
lock_openFree sampleFoundations of Internal Auditingmedium
During planning at Corvus Bank, an auditor debates whether a proposed piece of work counts as an assurance service or an advisory service. Which feature would most clearly identify the work as assurance?
- AThe work was requested informally by the process owner rather than being scheduled in the approved annual audit plan.
- BThe auditor independently assesses evidence and provides a conclusion for stakeholders beyond the party whose activity is under review.check_circle Correct
- CThe auditor offers recommendations that management remains free to accept or reject entirely as it sees fit.
- DThe scope and objectives of the work are agreed one-to-one with the single client who is receiving the auditor's help.
Assurance services provide an independent assessment and a conclusion for stakeholders, unlike advisory work delivered to and shaped by the client alone. Assurance involves internal audit forming an independent conclusion for the benefit of stakeholders, not merely the party being reviewed. Advisory work, by contrast, delivers advice whose nature and scope are agreed with the client requesting it, which is the boundary the auditor is trying to locate.
Why A is wrong: A request from the process owner points towards advice sought by a client, which is characteristic of advisory work, so this feature does not mark the work as assurance.
Why B is correct: Assurance is an independent assessment that produces a conclusion for stakeholders rather than only the reviewed party, which is precisely the feature that distinguishes it from advisory work.
Why C is wrong: Recommendations the client may take or leave describe the give-and-take of an advisory engagement, so this feature signals advisory rather than assurance and is wrong.
Why D is wrong: Scope negotiated directly with the recipient is a hallmark of advisory services, so this points away from assurance rather than towards it and is therefore incorrect.
lock_openFree sampleGovernance, Risk Management, and Controlmedium
At Meridian Freight, the board has set a stated risk appetite of no unplanned service outages exceeding four hours per quarter. During an assurance engagement, the internal auditor finds that management has formally accepted a residual technology risk whose worst-case outage is estimated at nine hours. What should the internal auditor do next?
- AReport that the accepted residual risk exceeds the board's stated appetite and escalate the matter to senior management and the board as the appropriate risk owners.check_circle Correct
- BDirect the IT manager to change the risk response from accept to reduce so the exposure falls back within the board's stated appetite before the engagement closes.
- CAccept management's decision without comment, because choosing to accept a risk is a legitimate response option that always sits within management's authority to make.
- DRedesign the technology control and implement the additional recovery capacity needed to bring the estimated outage below the four-hour appetite threshold.
Internal audit evaluates whether an accepted residual risk exceeds the board's stated appetite and escalates it rather than owning the response. Risk appetite is the board's stated boundary; an accepted residual risk above that boundary is a governance exception. The auditor's independent role is to evaluate the response against appetite and escalate to the accountable owners, never to select or implement the response itself.
Why A is correct: Evaluating the response against appetite and escalating an exposure that exceeds it to the accountable owners is the independent, standards-consistent action, keeping the decision with management and the board.
Why B is wrong: Selecting and changing the risk response is a first line management decision; directing it would breach the Three Lines Model and impair the auditor's objectivity, so this is wrong despite seeming decisive.
Why C is wrong: Accept is a valid response, which makes this tempting, but the auditor must still evaluate whether the accepted residual risk is consistent with the board's appetite rather than passing silently over a breach.
Why D is wrong: Designing and implementing controls is a management responsibility; taking it on would make the auditor an owner of the very control later assured, so this impairs independence and is wrong.
lock_openFree sampleGovernance, Risk Management, and Controlmedium
Aster Manufacturing distinguishes its risk appetite, the broad level of risk it will pursue, from its risk tolerance, the acceptable variation around specific objectives. An auditor reviews a plant whose scrap-rate objective is 2 percent with a stated tolerance of plus or minus 0.5 percentage points; the current scrap rate is 3.1 percent and management calls it acceptable. How should the auditor interpret this situation?
- AThe scrap rate is within tolerance because a single plant's performance is judged against the organisation's overall appetite rather than the objective-level tolerance band.
- BThe scrap rate of 3.1 percent breaches the stated tolerance band around the objective, so management's claim that it is acceptable warrants a finding and follow-up on the response.check_circle Correct
- CThe scrap rate is acceptable provided management documents a revised objective of 3 percent, which the auditor should draft and recommend to the plant leadership team.
- DThe scrap rate cannot be assessed because tolerance applies only to financial objectives, leaving an operational metric such as scrap outside any measurable boundary.
Risk tolerance is the acceptable variation around a specific objective, and performance outside that band is an exception regardless of overall appetite. Tolerance sets a measurable band around a specific objective, distinct from the organisation-wide appetite. A metric outside the band is an exception even if broad appetite feels comfortable, so the auditor tests performance against the objective-level tolerance, not against appetite.
Why A is wrong: This confuses appetite with tolerance; tolerance is measured against the specific objective, so judging the plant against broad appetite is the wrong yardstick and produces a false pass.
Why B is correct: Tolerance defines acceptable variation around a specific objective; 3.1 percent sits well outside the 1.5 to 2.5 percent band, so treating it as acceptable is inconsistent with the stated tolerance and correctly raises a finding.
Why C is wrong: Resetting the objective to fit performance is a management decision, and drafting it for them blurs the assurance role; the tolerance breach is not resolved by moving the target, so this is wrong.
Why D is wrong: Tolerance applies to operational as well as financial objectives, so the claim that scrap falls outside any boundary is incorrect and would wrongly excuse the exception from evaluation.
lock_openFree sampleGovernance, Risk Management, and Controlmedium
Corvus Insurance runs a risk management cycle of identify, assess, respond, and monitor. During an engagement the auditor notes that the payments team maintains a rich risk register and detailed response plans, but there is no evidence anyone re-checks whether the chosen responses are still working as conditions change. Which weakness in the cycle should the auditor report?
- AThe identification step is deficient, because a register that lists responses cannot also have captured the underlying risks that those responses were designed to address.
- BThe assessment step is deficient, because documented response plans prove that risks were never scored for likelihood and impact before responses were selected.
- CThe monitoring step is deficient, because no one re-evaluates whether the selected responses remain effective as conditions change, leaving the cycle without feedback.check_circle Correct
- DThe response step is deficient, because maintaining plans without acting on them means the organisation has not actually treated any of the identified risks.
The monitoring step of the risk management cycle re-evaluates whether chosen responses remain effective as conditions change. The cycle identify, assess, respond, and monitor is a loop: monitoring feeds back so responses are re-checked as conditions change. A register and response plans satisfy earlier steps, so the missing ongoing re-evaluation is a monitoring failure, not an identification or assessment one.
Why A is wrong: A rich register is evidence that identification occurred, so calling identification deficient misreads the facts; the gap described sits later in the cycle, making this wrong.
Why B is wrong: Selecting proportionate responses normally follows assessment, so documented plans suggest assessment happened; blaming assessment misplaces the gap and is therefore incorrect.
Why C is correct: Monitoring closes the cycle by re-checking that responses stay effective as conditions shift; its absence is exactly what the scenario describes, so reporting the monitoring gap is correct.
Why D is wrong: This is tempting because plans alone change nothing, but the scenario says responses exist and are planned; the missing element is ongoing checking, not the response itself, so this is wrong.
lock_openFree sampleEthics and Professionalismmedium
Brant Water's internal audit function is scoping an assurance engagement over a new actuarial reserving model. No one on the team has actuarial expertise, and the chief audit executive cannot recruit a qualified actuary before the engagement must begin. What is the most appropriate way to proceed?
- AProceed with the engagement but narrow the scope to the general controls the team already understands, leaving the actuarial calculations untested this year.
- BObtain a written confirmation from management that the reserving model is accurate, then rely on that assertion in place of independent testing.
- CProcure the missing actuarial competency externally, for example through a guest auditor or an external specialist, so the function collectively has the skills the work requires.check_circle Correct
- DPostpone the engagement indefinitely until a suitably qualified actuary can be recruited as a permanent member of the internal audit staff.
Where the internal audit function lacks a required competency, it may procure that expertise externally rather than proceed under-qualified or drop the work. Competency can be satisfied collectively: when in-house skills fall short, sourcing an external specialist keeps the engagement competent while internal audit retains its independent assurance role, which neither a narrowed scope nor reliance on management can deliver.
Why A is wrong: Scoping around a competency gap is tempting because it lets the work start on time, but it leaves the very risk the engagement exists to examine unassessed and does not fulfil the mandate.
Why B is wrong: This looks efficient, but relying on the auditee's own assertion abandons independent assurance and adopts a first-line responsibility, which impairs objectivity.
Why C is correct: The Global Internal Audit Standards allow competencies to be developed or procured; bringing in a qualified specialist lets the function cover the model competently without impairing its independent role.
Why D is wrong: Permanent recruitment feels thorough, but the Standards permit procuring competencies, so an open-ended delay is unnecessary and leaves a material risk unaddressed.
lock_openFree sampleEthics and Professionalismmedium
During a closing meeting at Denholm Foods, the auditee disputes a well-evidenced finding and the discussion is turning adversarial. The internal auditor is confident the finding is correct but needs management to accept it and commit to corrective action. Which competency should the auditor draw on most to move the discussion forward?
- ACommunication and negotiation, by listening to the objection, clarifying the evidence calmly, and building agreement on a workable corrective action.check_circle Correct
- BConfidentiality, by declining to share the underlying evidence so the auditee has no basis on which to keep challenging the methodology.
- CTechnical accounting knowledge, by piling on further quantitative detail until the auditee is overwhelmed into agreeing with the conclusion.
- DEscalation authority, by reporting the manager to the board at once for obstructing the engagement and refusing the finding.
Getting a defensible finding accepted depends on the auditor's communication, persuasion, and negotiation competencies, not on withholding evidence or premature escalation. A correct finding only creates value when management acts on it; the interpersonal competencies of listening, clarifying, and negotiating are what secure that commitment, whereas confidentiality, data-dumping, and instant escalation each work against acceptance.
Why A is correct: Persuasion, communication, and negotiation are the competencies that turn a defensible finding into an accepted, actioned one while preserving the relationship the auditor still needs.
Why B is wrong: Confidentiality protects sensitive information from outsiders; it has no bearing here, and withholding evidence from the auditee would only weaken the finding and inflame the dispute.
Why C is wrong: More data feels authoritative, but a relationship breakdown is not resolved by volume, and overwhelming the auditee is coercion rather than genuine persuasion.
Why D is wrong: Immediate escalation is tempting when tension rises, but it bypasses negotiation, damages the working relationship, and is premature for a finding still under discussion.
lock_openFree sampleEthics and Professionalismmedium
At Kesteven Group, the chief audit executive is finalising an annual audit plan covering IT, treasury, and health-and-safety engagements. The in-house team is strong on financial controls but thin in those other areas. Under the Global Internal Audit Standards, what is the chief audit executive primarily responsible for ensuring?
- AThat every individual auditor personally holds expertise across IT, treasury, and health and safety before any of those engagements begins.
- BThat engagements outside the team's current strengths are dropped from the plan so only financial-controls work remains in scope.
- CThat external specialists are engaged to lead the entire plan while the in-house team observes and documents the specialists' conclusions.
- DThat the function collectively possesses, or obtains through procurement, the competencies needed to fulfil the responsibilities set out in its mandate.check_circle Correct
The chief audit executive ensures the internal audit function collectively holds or procures the competencies its mandate demands, not that every auditor holds every skill. Competency under the Standards is a function-level test: the chief audit executive must ensure the mix of developed and procured skills covers the mandate, which is why collective competency, not universal individual expertise or a trimmed plan, is the correct responsibility.
Why A is wrong: This overstates the requirement; competency is judged collectively across the function, so demanding full expertise from each auditor is neither realistic nor what the Standards require.
Why B is wrong: Cutting the plan to fit existing skills is tempting, but it lets a competency gap dictate coverage and leaves significant organisational risks unaudited.
Why C is wrong: Procurement is appropriate for gaps, but handing the whole plan to outsiders while the team merely observes wastes in-house strengths and is not what competency requires.
Why D is correct: The chief audit executive is accountable for the function having the skills its mandate requires, met either by in-house capability or by procured specialists, so the whole plan can be delivered competently.
lock_openFree sampleFraud Riskshard
At Kelston Manufacturing, internal audit is evaluating how well the organisation manages fraud risk. Management runs a documented annual fraud risk assessment and maintains anti-fraud controls, but the assessment has not been revisited even though the company has entered three overseas markets this year, each carrying different bribery and procurement-fraud exposures. How should the internal auditor characterise this situation?
- AThe fraud risk management process is adequate, because a documented annual fraud risk assessment and a set of anti-fraud controls are already in place and were completed on schedule this year.
- BThe fraud risk management process is not adequate, because the fraud risk assessment has not been updated to reflect the new fraud exposures created by the recent market expansion.check_circle Correct
- CThe internal auditor should personally re-perform the fraud risk assessment for the three new markets and hand management the completed assessment so the gap is closed before the engagement ends.
- DThe internal auditor should conclude that fraud is likely occurring in the new markets, because the exposures there were never assessed and uncontrolled fraud risk almost always results in actual fraud.
A fraud risk management process is adequate only if its assessment is kept current with changing fraud exposure, not merely because an assessment exists. Fraud risk management is evaluated against whether identification, assessment, and response track the organisation's actual exposure. When new markets create fresh fraud risks that the assessment never captures, the responses cannot match the exposure, so the process is inadequate; re-performing the assessment or asserting that fraud is occurring both exceed the auditor's proper role.
Why A is wrong: The presence of an assessment is reassuring, but adequacy depends on whether it reflects current exposure; an assessment that ignores materially changed fraud risks is not adequate simply because it exists.
Why B is correct: Evaluating fraud risk management means checking that identification and assessment keep pace with changing exposure; a static assessment that misses new bribery and procurement risks leaves the response mismatched to the actual exposure.
Why C is wrong: Spotting the gap is correct, but owning and performing the fraud risk assessment is a management responsibility; taking it on would place internal audit in a first line role and impair later assurance over that work.
Why D is wrong: An unassessed exposure is a control weakness, not proof of fraud; concluding that fraud is occurring without evidence oversteps the auditor's role, which is to report the weakness in fraud risk management.
lock_openFree sampleFraud Riskshard
During a routine accounts-payable assurance engagement at Wrenfield Utilities, the internal auditor notices that a recently added vendor shares a bank account number with a payments clerk and that its invoices are consistently just below the manager approval threshold. Detecting fraud was not the engagement's objective, and management offers a brief explanation that the vendor is a legitimate small supplier. What is the BEST next action for the auditor?
- AAccept management's explanation and close the point, because the engagement objective was payables accuracy rather than fraud, and a small supplier operating below the threshold is not unusual.
- BConclude that the payments clerk has committed fraud, name the clerk in the engagement report, and quantify the suspected loss so the audit committee can act on a definitive finding.
- CDocument the indicators, perform sufficient additional procedures to understand them, and report the red flags to the appropriate party under the organisation's fraud response protocol without concluding that fraud has occurred.check_circle Correct
- DConfront the payments clerk directly to obtain an explanation before telling anyone else, so the auditor can decide privately whether the matter is worth escalating beyond the engagement team.
On finding fraud indicators mid-engagement, the auditor documents them, does enough work to understand them, and reports the red flags to the appropriate party without concluding fraud. Red flags are indicators, not conclusions. Due professional care requires the auditor to notice them, extend procedures enough to understand what they mean, and route them to the party responsible under the fraud response protocol. Accepting the explanation, declaring fraud, or confronting the suspect all depart from that measured, objective reporting role.
Why A is wrong: The explanation is convenient, but a shared bank account and threshold-hugging invoices are recognised fraud indicators; accepting the account without scrutiny abandons the professional scepticism the situation demands.
Why B is wrong: A definitive fraud conclusion feels decisive, but the auditor has red flags rather than proof; naming an individual and asserting fraud presumes guilt and exceeds the auditor's role of reporting indicators.
Why C is correct: The auditor's role is to stay alert to indicators, gather enough evidence to understand them, and report red flags to the right party; this preserves objectivity while ensuring a possible fraud is escalated rather than judged prematurely.
Why D is wrong: Direct confrontation seems efficient, but it can tip off a suspect and destroy evidence; deciding alone whether to escalate usurps the fraud response protocol and the parties designated to handle indicators.
lock_openFree sampleFraud Riskshard
During a payroll assurance engagement at Tenby Logistics, the internal auditor uncovers indicators strongly suggesting that a supervisor has created several ghost employees and is diverting their wages. Uncovering fraud was not the engagement's objective. The chief financial officer, once told informally, instructs the auditor to keep the finding quiet and personally run the full investigation to a disciplinary conclusion. What is the BEST next action for the auditor?
- APromptly report the indicators to the appropriate parties designated in the fraud response protocol, such as the audit committee, and support any resulting investigation rather than leading it or presuming guilt.check_circle Correct
- BContinue the payroll engagement as planned and simply record the ghost-employee indicators as one observation in the final report, which is due to the audit committee in several weeks' time.
- CTake personal charge of the full investigation as the chief financial officer instructed, gather the evidence alone, and decide the appropriate disciplinary outcome for the supervisor.
- DConfront the supervisor with the evidence to obtain an explanation, and if the explanation is unconvincing, escalate the matter to the chief financial officer and close the engagement.
On finding strong fraud indicators, the auditor promptly reports them to the appropriate parties and supports rather than leads any investigation, without presuming guilt. Internal audit's proper role on discovering fraud indicators is to report them to the parties responsible under the fraud response protocol and to coordinate with and support an investigation, not to lead it, decide discipline, or bury it. A manager instructing silence does not override that duty, so prompt escalation beyond that manager is the standards-consistent action.
Why A is correct: The auditor's role is to report red flags to the right party without presuming fraud and to support, not lead, the investigation; escalating beyond a manager seeking silence protects both the response and the auditor's independence.
Why B is wrong: Treating strong fraud indicators as a routine observation dangerously delays escalation; a suspected ongoing fraud needs prompt reporting to the appropriate party, not deferral to a scheduled report.
Why C is wrong: Leading the investigation and deciding discipline looks decisive, but internal audit coordinates and supports investigations rather than owning them; taking charge unilaterally impairs objectivity and later assurance.
Why D is wrong: Early confrontation risks tipping off the suspect and losing evidence, and routing the matter only through the manager who wants it kept quiet fails to reach the parties who should oversee a suspected fraud.
Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CIA-1 and related marks belong to their respective owners.