The Institute of Internal Auditors study guide

How to pass IIA Certified Internal Auditor - Part 2: Internal Audit Engagement (CIA-2)

15 min read3 domains coveredFree practice, no sign-up

The Certified Internal Auditor Part 2, Internal Audit Engagement, is the middle exam of the IIA's three-part CIA programme. It tests whether you can run an assurance or advisory engagement from planning through fieldwork to communication, and whether you make the judgement calls an internal auditor faces the way the profession expects. It is not a recall test of definitions; most questions are short scenarios that describe a fictional organisation, an audit area, and a situation, then ask for the best action or the correct next step.

It suits internal auditors, external auditors moving in-house, risk and compliance staff, and anyone preparing for the CIA credential after passing Part 1. If you already plan engagements, gather evidence, and write findings in your day job, much of the exam will feel familiar. If your experience is narrow, the gap is closable because the syllabus aligned to the 2024 Global Internal Audit Standards is broad and coherent rather than obscure.

The exam rewards the disciplined next step. Many options describe real audit actions that are premature, skip a required step, overstep internal audit's independence, or solve the wrong problem. The skill being tested is choosing the proactive, evidence-based action that follows a sound engagement process and preserves objectivity, not the action that sounds decisive. Practise on scenario questions that explain every option so you learn why each plausible-but-wrong answer fails.

Part 2 rewards the disciplined next step that preserves independence and follows the engagement process, not the boldest-sounding action.

Difficulty

Intermediate

Best for

Internal auditors, external auditors moving in-house, and risk or compliance staff pursuing the CIA credential, typically after Part 1.

Prerequisites

Familiarity with internal audit basics and the 2024 Global Internal Audit Standards. Part 1 covers the foundation this exam builds on.

100
Questions
120 min
Time allowed
600 / 750 (scaled)
Pass mark
$415
Exam cost (USD)
309
Practice questions

How this exam thinks

Three habits separate a pass from a fail on Part 2, and none of them is about knowing more definitions.

First, the exam asks for the best or next action, not a correct statement. Questions are scenarios, and several options will be legitimate audit actions. Only one fits the situation as written. Read the last line first to find what is actually being asked, then judge each option against the engagement process: has a required step been skipped, is this premature, does it solve the problem the scenario poses. An action that is sound in the abstract is still wrong if the process calls for something else first.

Second, the exam guards internal audit's independence and objectivity relentlessly. The wrong answer is often the one where internal audit designs a control, owns a process, accepts a risk, or makes a management decision. Internal audit assesses and advises; management owns controls and decisions. When an option has the auditor stepping into management's shoes, it is almost always the distractor, even when it looks helpful. The same instinct separates an assurance engagement, where the auditor gives an independent opinion, from an advisory one, where the auditor helps without owning the outcome.

Third, the exam expects precise use of the profession's core distinctions, and plants distractors that blur them. Inherent risk is before controls and residual risk is after. Control design is whether a control would work if it operated, and operating effectiveness is whether it actually did over the period. Evidence must be sufficient, relevant, and reliable, and independent, corroborated, or well-governed sources rank higher. Absolute wording such as always, never, or guarantees usually marks a wrong option, because good audit judgement is conditional, not a blanket rule.

What each domain tests and how to study it

The CIA-2 blueprint is split across 3 domains. Weights are the official share of the exam; see the official exam guide for the authoritative breakdown.

  1. Engagement Planning

    50% of exam

    What you must be able to do. Plan an assurance or advisory engagement end to end: set objectives and scope, assess engagement-level risk, select suitable criteria, and choose the audit approach and resources without crossing into management's role.

    In one sentenceThe largest domain: turning an engagement into a plan, objectives, scope, risk assessment, criteria, resources, and approach, while keeping internal audit independent.

    Recall check: answer these from memory first
    • State the planning sequence from understanding the area to designing procedures, and say why criteria are agreed before procedures are written.
    • Give a one-line distinction between inherent and residual risk, and between control design and operating effectiveness.
    • Name what makes evaluation criteria suitable, and say what the auditor does when management has no formal criteria.
    • Explain when an advisory engagement is appropriate and how the auditor's role differs from an assurance engagement.

    What it tests. Everything that happens before fieldwork: establishing engagement objectives and scope, performing a preliminary risk assessment of the area, selecting evaluation criteria that are authoritative and relevant, building the work programme, and allocating competent resources. It covers inherent versus residual risk, control design versus operating effectiveness, the assurance versus advisory distinction, and choosing among traditional, agile, integrated, and remote audit approaches for the stated context.

    How to study it. Learn the planning sequence as a chain where each step depends on the one before: understand the area, assess risk, set objectives and scope, agree criteria, then design procedures. Drill the independence boundary until it is automatic, because the most common distractor here has internal audit designing or owning the control it should be assessing. Practise matching the audit approach to the context, and be able to say in one line what makes criteria suitable, authoritative, relevant, reliable, and specific enough to measure against.

    Easy to confuse

    • Inherent risk versus residual risk. Inherent risk is the exposure before any controls are considered; residual risk is what remains after controls operate. The exam plants a distractor that names one when the scenario is describing the other, usually to test whether you assess risk before or after control effectiveness.
    • Control design versus operating effectiveness. Design effectiveness asks whether a control, if it operated as intended, would address the risk; operating effectiveness asks whether it actually did so consistently over the period. A well-designed control that was skipped fails on operation, not design, and the exam tests which conclusion the evidence supports.
    • Assurance versus advisory engagement. In an assurance engagement the auditor forms an independent opinion for a third party; in an advisory engagement the auditor helps management at its request without owning the result. The scope, the deliverable, and the auditor's independence obligations differ, so the exam establishes the engagement type and then tests whether your action fits it.
    • Internal audit designing a control versus assessing it. Assessing whether a control is adequate preserves objectivity; designing, implementing, or owning that control impairs it because the auditor would later be reviewing their own work. The exam's most frequent trap is a helpful-sounding option where internal audit steps into management's role.

    Worked example from the CIA-2 bank

    Free sampleEngagement Planningmedium

    During planning, an audit lead must decide whether an upcoming procurement engagement is assurance or advisory. Which statement correctly distinguishes the two engagement types?

    • AIn an assurance engagement the auditor advises management and management remains free to reject the recommendations offered.
    • BAn assurance engagement involves a three-party relationship and an objective assessment against criteria, while advisory work is directed by the client to add value. Correct
    • CIn an advisory engagement the auditor issues an independent opinion to third parties on the adequacy of the control environment.
    • DBoth engagement types require the auditor to design and then implement the controls that management will later operate.
    Distinguish assurance engagements, which give an objective three-party assessment against criteria, from advisory engagements directed by the client to add value. Assurance depends on a three-party relationship and evaluation against suitable criteria so that reliant users can trust the conclusion, whereas advisory work is shaped with the client and produces no independent opinion for third parties.

    Why A is wrong: This is tempting because advice is common in audit work, but it describes advisory work; assurance involves an independent assessment against criteria, not optional advice.

    Why B is correct: Correct because assurance rests on a process owner, an assessor, and a user, tested against defined criteria, whereas advisory scope and nature are agreed with the client.

    Why C is wrong: This sounds authoritative, but issuing an independent opinion to reliant parties is the hallmark of assurance, not advisory work, which is client-directed counsel.

    Why D is wrong: This is plausible because auditors advise on control gaps, but designing and implementing controls destroys independence; management owns and builds its own controls.

  2. Information Gathering, Analysis, and Evaluation

    40% of exam

    What you must be able to do. Gather sufficient, relevant, and reliable evidence, apply the right analytical technique, and reach conclusions that are supported by the evidence rather than by an isolated exception or an unverified anomaly.

    In one sentenceThe fieldwork domain: collecting and testing evidence, using data analytics and CAATs well, and building findings whose significance the evidence actually supports.

    Recall check: answer these from memory first
    • Rank these by reliability: an external confirmation, a management verbal assertion, and a report from a well-controlled system, and say why.
    • Explain why an anomaly found by data analytics is a trigger to investigate rather than a finding on its own.
    • Distinguish continuous monitoring from continuous auditing in one line, focusing on who owns each.
    • Name the elements of a finding and say what the cause element adds beyond condition and criteria.

    What it tests. Performing the engagement: selecting evidence-gathering techniques such as interviews, observation, inspection, and confirmation, and judging evidence against the sufficient, relevant, and reliable standard. It covers computer-assisted audit techniques and the analytics ladder from descriptive to predictive, the difference between continuous monitoring and continuous auditing, and building a finding from criteria, condition, cause, and effect to a root cause and a supported conclusion.

    How to study it. Memorise the evidence hierarchy as a decision tool: evidence from an independent external source, corroborated evidence, and evidence from a well-governed system outrank an unsupported management assertion. Learn that an analytical anomaly is a signal to investigate, not proof of a finding. Get the continuous monitoring versus continuous auditing distinction precise, because it turns on who owns the activity. Practise assembling a finding so that the significance you assign matches the evidence, and so that individually minor issues that aggregate into a real weakness are recognised.

    Easy to confuse

    • Sufficient versus relevant versus reliable evidence. Sufficiency is about quantity, whether there is enough to support the conclusion; relevance is about whether the evidence bears on the objective; reliability is about the trustworthiness of the source. The exam describes a shortfall and asks which of the three it breaches, so keep them separate.
    • Continuous monitoring versus continuous auditing. Continuous monitoring is a management activity that management owns to oversee its own controls; continuous auditing is internal audit's own automated testing that the auditor designs and runs for assurance. The distinction turns on ownership, and blurring it, treating an audit-owned automated test as monitoring, is a keyed error the exam plants.
    • An isolated exception versus a systemic finding. One exception may be an anomaly, while a pattern across the population points to a systemic control weakness. The exam tests whether you extend testing to establish which it is before you report, rather than escalating a single item or dismissing a pattern.
    • Cause versus condition in a finding. The condition is what was found; the cause is why it happened. A recommendation that does not address the cause treats a symptom, so the exam checks that you identify the root cause rather than restating the condition.

    Worked example from the CIA-2 bank

    Free sampleInformation Gathering, Analysis, and Evaluationhard

    An internal auditor gathers a signed contract from the client's legal department, a verbal assurance from the process owner, and a copy of an invoice provided by the vendor being examined. When judging the reliability of this evidence, which principle should the auditor apply first?

    • AEvidence obtained from a source independent of the client is generally more reliable than evidence supplied by an interested party. Correct
    • BVerbal assurances from a process owner are the most reliable because they come directly from the person accountable for the control.
    • CDocumentary evidence is reliable purely because it is written, regardless of who produced or supplied it.
    • DThe most recently dated item is the most reliable because it reflects the current state of the process.
    Recognise that independence of the evidence source is a primary factor determining evidence reliability. Reliability rises with the independence and objectivity of the source, because a party with no interest in the outcome has little incentive to distort what the evidence shows, unlike an internal owner or the audited vendor.

    Why A is correct: Independence of source is a core determinant of reliability; evidence from a party with no stake in the outcome is less likely to be biased or manipulated.

    Why B is wrong: Tempting because the owner is accountable, but oral evidence from an interested internal party is among the least reliable forms and needs corroboration.

    Why C is wrong: Form of evidence matters, but written form alone does not confer reliability when the document originates from an interested source such as the vendor.

    Why D is wrong: Recency can aid relevance, yet it says nothing about source independence or authenticity, so it is the wrong first test of reliability.

  3. Engagement Supervision and Communication

    10% of exam

    What you must be able to do. Supervise the engagement to a quality standard, communicate results with the right message to the right audience at the right time, obtain management action plans, and escalate and follow up appropriately.

    In one sentenceThe closing domain: supervisory review before conclusions are issued, fit-for-audience communication, management action plans, escalation, and follow-up.

    Recall check: answer these from memory first
    • Say what supervisory review must confirm before an engagement conclusion is issued.
    • Explain when a risk warrants interim communication rather than waiting for the final report.
    • State why issuing the final report does not close a finding, and what does.
    • Describe when a matter must escalate beyond the engagement team and to whom.

    What it tests. Supervising and communicating the engagement: the review that must occur before conclusions are issued, the content and quality of interim and final communications, tailoring the message to the audience, and obtaining a management action plan for each finding. It covers escalation when a matter must go beyond the immediate team, the basis for an overall opinion, and closing a finding only after follow-up confirms the action, not merely because the report was issued.

    How to study it. Treat supervisory review as a gate: conclusions are not issued until the work supporting them has been reviewed. Learn the communication rules as audience-and-timing decisions, so an urgent risk triggers interim communication rather than waiting for the final report. Fix in your mind that a finding needs a management action plan and that issuing the report does not close it, follow-up does. Know when a matter escalates beyond the engagement lead and to whom, and what evidence supports an overall engagement opinion.

    Easy to confuse

    • Interim versus final communication. Interim communication conveys a significant or urgent matter during the engagement so action is not delayed; the final communication reports the complete results at the end. The exam describes an urgent risk and tests whether you wait for the report or communicate now.
    • Issuing the report versus closing a finding. Issuing the report communicates the result; closing a finding requires follow-up that confirms the agreed action was implemented and effective. Treating report issuance as closure skips follow-up, which the exam keys as wrong.
    • A management action plan versus a recommendation. The auditor recommends; management commits to an action plan with an owner and a date. A finding communicated without obtaining management's action plan is incomplete, and the exam tests whether you secure that commitment rather than reporting the recommendation alone.

    Worked example from the CIA-2 bank

    Free sampleEngagement Supervision and Communicationmedium

    In the context of an internal audit engagement, what does appropriate supervision primarily provide assurance about?

    • AThat the engagement objectives are achieved and the work supports the conclusions reached. Correct
    • BThat every individual finding is separately escalated to the audit committee before the report is issued.
    • CThat the auditors in charge design the operating controls that management will later implement.
    • DThat the fieldwork is completed within the originally budgeted hours regardless of scope changes.
    Understand that engagement supervision gives reasonable assurance that objectives are achieved and evidence supports the conclusions. Supervision is a quality mechanism: through direction, review, and oversight it gives reasonable assurance that engagement objectives are met and that the workpapers adequately support the conclusions and results communicated, rather than serving as a reporting or control-design function.

    Why A is correct: Supervision exists to give reasonable assurance that objectives are met, quality is attained, and evidence supports the conclusions; that is its defining purpose.

    Why B is wrong: Escalation of individual findings is a reporting and communication judgement, not the aim of supervision; treating supervision this way confuses two distinct activities.

    Why C is wrong: Designing operating controls would breach independence and objectivity; supervision never extends internal audit into owning management's controls.

    Why D is wrong: Budget adherence is a management concern that can be part of supervision, but it is not its primary assurance purpose and is subordinate to quality.

A study plan that works

  1. Map the blueprint and set a date

    Day 1

    Read the IIA Part 2 test specification and the three domains with their weights, and note that the syllabus aligns to the 2024 Global Internal Audit Standards. Book a provisional exam date now: a fixed date turns open-ended study into a plan and is the biggest predictor of actually sitting the exam.

  2. Own engagement planning (Domain 1)

    Weeks 1-2

    This is the largest domain at half the exam, so spend the most time here. Lock the planning sequence, the inherent-versus-residual and design-versus-operating distinctions, criteria selection, and the audit approaches. Use the recall prompts in this guide: cover the summary, answer from memory, then reveal.

  3. Drill the independence boundary until it is reflex

    Week 2

    Across every domain the exam plants options where internal audit designs a control, owns a process, accepts a risk, or makes a management decision. Practise spotting and rejecting them fast, because getting this instinct automatic converts a large share of otherwise tricky questions into easy marks.

  4. Work fieldwork and evidence (Domain 2)

    Weeks 2-3

    Cover evidence-gathering techniques, the sufficient-relevant-reliable standard and the reliability hierarchy, data analytics and CAATs, continuous monitoring versus auditing, and finding construction. Use scenario questions, not flashcards alone, so you practise judging significance from evidence.

  5. Close with supervision and communication (Domain 3)

    Week 3

    This is the smallest domain but the questions are usually clear marks once the rules are firm: supervisory review before conclusions, interim versus final communication, management action plans, escalation, and follow-up before closure.

  6. Practise on scenarios with every answer explained

    Week 4

    Move to full practice sets and read the explanation for every question, including the ones you got right. The exam tests judgement between plausible audit actions, so understanding why a distractor is premature, oversteps independence, or skips a step is where the marks are.

  7. Sit a timed mock and close weak domains

    Week 5

    Take at least one full timed mock to rehearse pacing and flag-and-return, then use your per-domain accuracy to drill the areas dragging you down. Repeat until every domain clears the pass line with margin on unseen questions.

Know when you're ready

Readiness for Part 2 is a score on questions you have not seen before, not a feeling that the material is familiar. Those are different things, and the gap between them is where people fail. Re-reading notes builds fluency, and fluency feels like knowledge, so confidence rises while real recall does not. The fix is to test yourself: if you can answer fresh scenario questions and explain why the wrong options are wrong, you know it; if you can only nod along to an explanation, you do not yet.

Be especially wary of confidence built on your day-job habits. Working practice varies between organisations, and the exam rewards the profession's model answer, which sometimes differs from how your team actually operates. Trust your measured per-domain accuracy over your gut, and pay closest attention to the independence and next-step questions, where experienced auditors lose marks by choosing the decisive-sounding action over the process-correct one.

This guide gives you the map. The practice bank is where you find out whether you can navigate it, with an explanation of why the right answer is right and every wrong one is wrong on every question. Readiness scoring tells you when you are there. Set the bar at clearing every domain comfortably on unseen questions across more than one session, not scraping the pass mark once.

Ready to put this into practice?

Free CIA-2 questions, every answer explained. No sign-up.

Practise CIA-2 free

Exam-day tips

  • Read the last line of the question first. It tells you what is actually being asked, so you can read the scenario looking for the required next step rather than memorising detail.
  • Choose the best or next action, not merely a valid one. Several options are often legitimate audit actions; the exam wants the one the engagement process calls for now.
  • Reject any option where internal audit designs, owns, or accepts a control or risk, or makes a management decision. Internal audit assesses and advises; management owns.
  • Watch for absolutes such as always, never, only, and guarantees. Good audit judgement is conditional, so blanket wording usually marks a wrong option.
  • Check whether the scenario is an assurance or an advisory engagement before you answer, because the auditor's role and the correct action differ between them.
  • Flag and move on. Do not lose time on one hard scenario when easier marks are waiting; the timer rewards covering every question first.
  • Treat an analytical anomaly as a prompt to investigate, not a finding. Extend testing to establish whether an exception is isolated or systemic before you conclude.

Frequently asked questions

Is CIA Part 2 hard?

It is an intermediate exam that tests judgement rather than recall. The difficulty is choosing the best next action among plausible audit options while preserving independence, which is why scenario practice that explains every option matters more than memorising definitions.

How long should I study for CIA Part 2?

Most candidates with internal audit experience are ready in four to six weeks of focused study. Less hands-on engagement experience means more time on the planning domain and on evidence and finding construction, which is where the weight sits.

Do I need work experience to pass Part 2?

Practical engagement experience helps because the exam is scenario-based, but it is not strictly required to sit the exam. Candidates without much fieldwork experience should lean harder on scenario practice to build the judgement the exam rewards.

What is the pass mark for CIA Part 2?

The exam is scored on a scaled range and the published pass mark is in the facts panel above. Scoring is scaled, so your raw percentage and the scaled score are not the same thing; aim to clear every domain comfortably in practice rather than scraping a target.

Which domain should I focus on?

Engagement planning is the largest domain at half the exam, so it deserves the most time. Information gathering, analysis, and evaluation is the next largest, and supervision and communication is the smallest but offers clear marks once the rules are firm.

How is Part 2 different from Part 1?

Part 1 covers the essentials of internal auditing, independence, risk, control, and governance at a foundational level. Part 2 puts you inside a single engagement and tests how you plan it, gather and evaluate evidence, and communicate results, which is why it is more scenario-driven.

Does Part 2 follow the new Global Internal Audit Standards?

Yes. The current Part 2 syllabus aligns to the 2024 Global Internal Audit Standards, effective January 2025, which superseded the older standards. Study current material and cite the standards by name and topic rather than by an outdated clause number.

How many practice questions should I do before booking?

Enough that every domain clears the pass line with margin on questions you have not seen before, and that a full timed mock feels comfortable on pacing. Quality of review matters more than raw volume: read the explanation on every question, including the ones you got right.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. This guide is original study material based on the public exam blueprint. We never reproduce live exam items. CIA-2 and related marks belong to their respective owners.