Examworthyexamworthy.com

IIA Certified Internal Auditor - Part 2: Internal Audit Engagement cheat sheet

The Institute of Internal Auditors

Exam version 2025Reviewed 2026-07-22

Free to share. Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors; CIA-2 and related marks belong to their respective owners.

At a glance

100
Questions
120 min
Time allowed
600 / 750 (scaled)
Pass mark
$415
Cost (USD)

Format: Multiple choice, closed book

Domain weight map

Heaviest first - spend your time here
Engagement Planning50% · 147 Q
Information Gathering, Analysis, and Evaluation40% · 129 Q
Engagement Supervision and Communication10% · 33 Q

How this exam thinks

Part 2 rewards the disciplined next step that preserves independence and follows the engagement process, not the boldest-sounding action.

Spot the trap

Tempting wrong answers, and why they fail

Tempting but wrong

In an assurance engagement the auditor advises management, and management stays free to reject the recommendations offered.

Why it fails

This is tempting because advice is common in audit work, but it describes advisory work; assurance involves an independent assessment against criteria, not optional advice.

Engagement Planning

Tempting but wrong

A verbal assurance from the process owner is the most reliable evidence because it comes directly from the person accountable for the control. Why is this wrong?

Why it fails

Tempting because the owner is accountable, but oral evidence from an interested internal party is among the least reliable forms and needs corroboration.

Information Gathering, Analysis, and Evaluation

Tempting but wrong

Does supervision give assurance that the auditors in charge design the operating controls management will later implement?

Why it fails

No. Designing operating controls would breach independence and objectivity; supervision never extends internal audit into owning management's controls.

Engagement Supervision and Communication

Tempting but wrong

Both assurance and advisory engagements require the auditor to design and then implement the controls management will later operate.

Why it fails

This is plausible because auditors advise on control gaps, but designing and implementing controls destroys independence; management owns and builds its own controls.

Engagement Planning

Tempting but wrong

Cross-checking several independent sources that agree is really about sufficiency, meaning gathering a large enough quantity of evidence. Why is this wrong?

Why it fails

Sufficiency concerns quantity and is tempting here, but the point of cross-checking independent sources is agreement across them, not sheer volume.

Information Gathering, Analysis, and Evaluation

Tempting but wrong

Should the level of supervision be set by a fixed organisation-wide ratio of one reviewer for every staff auditor?

Why it fails

No. A rigid fixed ratio ignores that supervision must flex with competence and complexity; a single mandated ratio cannot fit engagements of differing risk.

Engagement Supervision and Communication

Tempting but wrong

Missing vendor records are a residual risk, since they represent exposure that remains after controls have been applied to payments.

Why it fails

This borrows a real term, but residual risk describes leftover exposure after controls, not a restriction on the auditor's access to evidence.

Engagement Planning

Tempting but wrong

Calling evidence sufficient refers to its reliability, driven by the independence and competence of its source. Why is this wrong?

Why it fails

Reliability is a quality dimension often paired with sufficiency, yet it addresses trustworthiness of the source rather than the amount held.

Information Gathering, Analysis, and Evaluation

Key terms

Engagement objectivesTopical RequirementsScope limitationEvaluation criteriaIT general controlsBusiness continuityBusiness process riskData privacyAgile auditingIntegrated auditingProject managementRisk assessmentEmerging riskOrganizational cultureControl design testingControl effectiveness testing

Exam-day rules

  • Read the last line of the question first. It tells you what is actually being asked, so you can read the scenario looking for the required next step rather than memorising detail.
  • Choose the best or next action, not merely a valid one. Several options are often legitimate audit actions; the exam wants the one the engagement process calls for now.
  • Reject any option where internal audit designs, owns, or accepts a control or risk, or makes a management decision. Internal audit assesses and advises; management owns.
  • Watch for absolutes such as always, never, only, and guarantees. Good audit judgement is conditional, so blanket wording usually marks a wrong option.
  • Check whether the scenario is an assurance or an advisory engagement before you answer, because the auditor's role and the correct action differ between them.

Revision schedule

  1. Day 1
    Map the blueprint and set a date
  2. Weeks 1-2
    Own engagement planning (Domain 1)
  3. Week 2
    Drill the independence boundary until it is reflex
  4. Weeks 2-3
    Work fieldwork and evidence (Domain 2)
  5. Week 3
    Close with supervision and communication (Domain 3)

Practise CIA-2 free

Every question explains why the right answer is right and why each wrong one is rationale. No sign-up.

661 audited flashcards in this deck.

Practise CIA-2 free
Examworthy - IIA Certified Internal Auditor - Part 2: Internal Audit Engagement (CIA-2) cheat sheet. Free to share.examworthy.com