How to pass IIA Certified Internal Auditor - Part 3: Internal Audit Function (CIA-3)
17 min read4 domains coveredFree practice, no sign-up
The IIA Certified Internal Auditor Part 3, Internal Audit Function, is the final part of the CIA exam. It moves away from the foundations of Part 1 and the single-engagement mechanics of Part 2, and tests whether you can run an internal audit function: set its strategy and resources, build a risk-based plan, keep its quality high, and communicate and monitor engagement results the way the Global Internal Audit Standards expect. Most questions are short scenarios set in a fictional organisation, and they ask for the best action or the correct interpretation, not a definition.
It suits practising internal auditors, audit seniors, and aspiring chief audit executives who already understand how a single engagement is planned and performed and now need to think at the level of the whole function. If you can already explain the difference between the audit universe and the audit plan, or between an internal and an external quality assessment, much of this part will feel natural. If those distinctions are hazy, they are learnable, because the syllabus is defined and the scenarios reward a consistent decision rule rather than memorised trivia.
The exam rewards judgement. Many options describe a legitimate-looking action that skips a required step, confuses two similar roles, or escalates to the wrong party. The skill being tested is choosing the most proactive, evidence-based next action that follows a sound process and preserves the chief audit executive's reporting line to the board. Practise on scenario questions that explain every option, so you learn why a plausible second-best answer is still wrong, not just which letter is correct.
Part 3 tests whether you can run and report on the internal audit function as a chief audit executive would, choosing the correct next action, not reciting a definition.
Difficulty
Advanced
Best for
Practising internal auditors, audit seniors, and aspiring chief audit executives sitting the final part of the IIA CIA exam, and governance or assurance staff who need a working grasp of how the internal audit function is managed.
Prerequisites
The knowledge of CIA Parts 1 and 2 (internal audit foundations and the engagement process) is assumed. Familiarity with the 2024 Global Internal Audit Standards helps.
100
Questions
120 min
Time allowed
600 / 750 (scaled)
Pass mark
$415
Exam cost (USD)
316
Practice questions
How this exam thinks
Three habits separate a pass from a fail on Part 3, and none of them is about knowing more definitions.
First, the exam asks for the single best next action, not a correct statement. The questions are scenarios, and several options will be things an auditor could reasonably do. Only one is the most appropriate step given the situation as written. Read the requirement in the last line first, decide what a sound process demands next, then test each option against that. An action that is defensible in the abstract is still wrong if it skips a required step, such as confirming implementation before closing a finding, or if it reaches the right destination in the wrong sequence.
Second, the exam keeps returning to the chief audit executive's reporting line and independence. When a matter concerns independence, significant risk, or an accepted risk the executive judges unacceptable, the answer preserves the functional reporting line to the board rather than settling the matter with management alone. Escalation has an order: discuss with senior management first, then communicate to the board if it remains unresolved. Make that sequence automatic, because a distractor will offer the right parties in the wrong order or stop one level too low.
Third, the exam expects crisp boundaries between concepts that look alike. The audit universe is not the audit plan; an internal quality assessment is not an external one and needs different qualifications; a recommendation is not a management action plan; residual risk assessment is not risk acceptance communication; following up is not escalating. Most questions turn on one such distinction, so when two options look right, find the boundary the scenario is testing and pick the side that matches what was actually asked.
What each domain tests and how to study it
The CIA-3 blueprint is split across 4 domains. Weights are the official share of the exam; see the official exam guide for the authoritative breakdown.
What you must be able to do. Manage the internal audit function as an operation: set its strategy from stakeholder expectations, resource it, direct and monitor its work, and have the chief audit executive communicate with the board and senior management through the correct reporting lines.
In one sentenceRunning the function day to day: strategy and mission, financial, human, and IT resources, planning and directing the work, and the chief audit executive's communication and reporting relationships with the board and senior management.
Recall check: answer these from memory first
State the chief audit executive's functional and administrative reporting relationships in one line each, and say which matters travel the functional line.
Distinguish the internal audit mission from the vision in one sentence, and say what each is for.
Given a resource limitation that threatens the audit plan, say what the chief audit executive should do and to whom.
What it tests. How the internal audit function is operated and led. It covers planning, organising, directing, and monitoring the function; managing its financial, human, and technology resources; aligning the audit strategy, mission, and vision to stakeholder expectations and organisational objectives; and the chief audit executive's responsibilities for communicating with, and reporting to, the board and senior management, including the functional versus administrative reporting relationship.
How to study it. Anchor everything to the reporting model first, because it recurs across the whole part: the chief audit executive reports functionally to the board and administratively to management, and independence and significant matters travel the functional line. Then learn the resourcing and strategy material as decisions, not labels: what belongs in a mission versus a vision, when a resource limitation must be escalated, and how strategy stays aligned as stakeholder expectations shift. Drill scenarios until you can name the correct party and sequence without hesitating.
Easy to confuse
Functional versus administrative reporting of the chief audit executive. Functional reporting is to the board and covers independence, the charter, the plan, resources, and significant matters; administrative reporting is to senior management and covers day-to-day operations such as budgeting and human resources. When a scenario involves independence or a significant risk, the answer preserves the functional line to the board rather than resolving it with management.
Mission versus vision of the internal audit function. The mission states the function's core purpose and the value it exists to deliver now; the vision describes the aspirational future state it is working toward. The exam plants a vision statement where a mission is asked, and the other way round.
Audit strategy versus the audit plan. The strategy is the multi-year direction that aligns the function to stakeholder expectations and organisational objectives; the plan is the specific set of engagements scheduled to deliver against that strategy. Strategy sets direction, the plan sets the work.
A chief audit executive at Kelmscott Water is building next year's programme of work. She has drawn up a full inventory of every auditable entity, process, and system across the organisation, and separately a list of the specific engagements she intends to resource and schedule over the coming twelve months. A new manager treats these two documents as the same thing. How should the chief audit executive distinguish the audit universe from the annual audit plan?
AThe audit universe is the risk-prioritised set of engagements approved for the year, while the audit plan is the broader catalogue of everything that could be audited.
BThe audit universe and the audit plan are alternative names for the same risk-ranked schedule, differing only in whether the audit committee has formally approved it.
CThe audit universe lists only the engagements requested by management, while the audit plan lists only the engagements requested by the audit committee.
DThe audit universe is the full inventory of auditable areas across the organisation, while the audit plan is the risk-prioritised subset the function will actually resource and perform in the period.check_circle Correct
Distinguish the audit universe as the full population of auditable areas from the annual audit plan as the risk-prioritised subset scheduled for the period. The audit universe defines the complete set of entities and processes that could be audited; the annual plan applies a risk assessment to that population to select and schedule the engagements the function can resource, so the plan is always a subset of the universe.
Why A is wrong: This inverts the two terms; it is tempting because both concepts involve lists, but the universe is the full catalogue and the plan is the selected, scheduled subset.
Why B is wrong: Approval status does not turn one document into the other; the two are genuinely different artefacts, so treating them as synonyms misses the population-versus-selection distinction.
Why C is wrong: Both artefacts are owned and shaped by the internal audit function using a risk assessment, not split by who requested each engagement, so this mischaracterises how both are built.
Why D is correct: Correct: the universe is the complete population of potential engagements, and the plan is the prioritised selection scheduled and resourced for the period, informed by a risk assessment.
What you must be able to do. Build and maintain a risk-based audit plan: identify the sources of potential engagements, assemble and prioritise the plan from the audit universe against risk, keep it dynamic, and coordinate with other assurance providers to rely on their work appropriately.
In one sentenceDeciding what the function will audit: sourcing potential engagements, developing a risk-based and dynamic audit plan from the audit universe, and coordinating with other internal and external assurance providers.
Recall check: answer these from memory first
Distinguish the audit universe from the audit plan in one sentence.
Name four sources the chief audit executive draws on when identifying potential engagements.
State what must be true before internal audit can rely on the work of another assurance provider.
What it tests. How the annual, risk-based audit plan is developed and kept current. It covers the sources of potential engagements, such as the risk assessment, board and management requests, laws and regulations, and emerging trends; developing and prioritising a risk-based plan from the audit universe and keeping it dynamic as risks change; and coordinating with and relying on other assurance providers, including external audit and second-line functions, to avoid duplication and gaps.
How to study it. Fix the audit universe versus audit plan boundary before anything else, because most questions here hinge on it: the universe is everything that could be audited, the plan is the risk-prioritised subset scheduled for the period. Learn the plan as dynamic, not annual-and-frozen: new or changed risks trigger an update. For coordination, learn the conditions for relying on another provider's work, so you can tell appropriate reliance from an abdication of the function's own responsibility.
Easy to confuse
Audit universe versus audit plan. The audit universe is the full set of auditable entities, processes, and risks that could be examined; the audit plan is the risk-prioritised selection actually scheduled for the period. A distractor swaps the two, treating the whole universe as the plan or the plan as the universe.
A static annual plan versus a dynamic plan. The plan is risk-based and must be revised when the risk picture changes, not fixed once a year. When a significant new risk emerges mid-year, the answer updates the plan rather than deferring to next year's cycle.
Coordinating with, and relying on, another assurance provider versus duplicating their work. Reliance is appropriate only after assessing the other provider's competence, objectivity, and the quality of their work; without that assessment, relying on them is an abdication and re-performing everything is wasteful duplication. The exam tests whether reliance was earned.
Worked example from the CIA-3 bank
lock_openFree sampleInternal Audit Planmedium
The chief audit executive at Brindle Manufacturing is building next year's audit plan and learns that the external financial auditors already test controls over the revenue cycle each year. She wants to reduce duplicated testing by relying on that work. Before deciding how much to rely on it, what should she evaluate first?
AWhether the audit committee has formally approved the external auditors' engagement letter for the current financial year
BWhether relying on the external auditors' testing will reduce the internal audit function's own budgeted hours for the year
CThe external auditors' competence, objectivity, and the scope and adequacy of the work they performed on those controlscheck_circle Correct
DWhether the external auditors are willing to sign a statement accepting responsibility for the revenue-cycle conclusion
Before relying on another assurance provider's work, evaluate that provider's competence, objectivity, and the relevance and adequacy of the work performed. Reliance is justified only when the internal auditor has judged the other provider's competence and objectivity and confirmed the work's scope covers the objective; efficiency and approvals do not substitute for that judgement, and responsibility for the conclusion stays with internal audit.
Why A is wrong: Tempting because engagement approval is a real governance step, but committee approval of the external audit engagement says nothing about whether that work is competent, objective, or relevant to internal audit's control objective.
Why B is wrong: Tempting because efficiency motivates coordination, but cost saving is a benefit of reliance, not a criterion for it; the decision to rely must rest on the quality and relevance of the other provider's work.
Why C is correct: Correct. Reliance criteria require assessing the other provider's competence and objectivity and confirming that the work's scope, timing, and rigour actually cover the internal audit objective before placing reliance on it.
Why D is wrong: Tempting because shared responsibility sounds prudent, but the internal auditor retains responsibility for conclusions even when leveraging others' work, so seeking a transfer of responsibility misstates how reliance operates.
What you must be able to do. Run the quality assurance and improvement program: distinguish internal from external assessments and their required qualifications, disclose conformance and any nonconformance correctly, and measure and report the function's performance.
In one sentenceKeeping the function credible: the quality assurance and improvement program, internal versus external assessments and who may perform them, disclosing conformance and nonconformance, and performance metrics.
Recall check: answer these from memory first
Distinguish an internal assessment from an external assessment, and state how often the external one is required.
State the two acceptable forms of an external assessment and the qualifications the assessor must hold.
Say when the chief audit executive must disclose nonconformance, to whom, and what the disclosure must include.
What it tests. How the internal audit function assures and improves its own quality. It covers the quality assurance and improvement program, including ongoing monitoring and periodic self-assessment; internal assessments versus external assessments, the required frequency of the external assessment, and the qualifications an external assessor must hold; disclosing conformance with the Global Internal Audit Standards and disclosing any nonconformance and its impact; and key performance indicators and scorecard metrics for measuring and reporting the function's performance.
How to study it. Make the internal versus external assessment distinction exact, because it is the densest source of traps: know what each covers, how often the external one is required, and that the external assessor must be qualified and independent of the organisation. Learn the two forms an external assessment can take, a full external assessment or a self-assessment with independent external validation. For disclosure, learn who must be told, what is disclosed, and when, and keep performance measurement concrete: which metrics signal function health and where they are reported.
Easy to confuse
Internal assessment versus external assessment. Internal assessments are ongoing monitoring and periodic self-assessment performed within the function; the external assessment is performed at least once every five years by a qualified, independent assessor from outside the organisation. The exam swaps who performs each and how often.
A full external assessment versus a self-assessment with independent validation. Both satisfy the external requirement, but a self-assessment must be validated by a qualified independent external reviewer to count; a self-assessment alone does not. The exam offers an unvalidated self-assessment as a tempting shortcut.
Ongoing monitoring versus periodic self-assessment. Ongoing monitoring is the continuous supervision and review built into day-to-day operations; the periodic self-assessment is a deeper, scheduled internal review of the whole function. Both are internal, but they differ in depth and cadence.
Worked example from the CIA-3 bank
lock_openFree sampleQuality of the Internal Audit Functionhard
The board of a large organisation wants assurance that the internal audit function's external assessment obligation under its quality assurance and improvement program is being met correctly. Which approach satisfies that obligation?
AEither a full external assessment or a self-assessment with independent external validation, conducted at least once every five years by a qualified reviewer from outside the organisation.check_circle Correct
BOnly a full external assessment performed every year by a reviewer who is employed elsewhere within the same organisation but outside the audit team.
CA periodic self-assessment signed off by the chief audit executive alone, provided that the function repeats the exercise at least every three years.
DOngoing monitoring supplemented by a stakeholder survey, provided that senior management approves the scope of the review beforehand.
The external assessment can be a full external assessment or a validated self-assessment, done at least every five years by a qualified independent outside reviewer. The external assessment requirement can be discharged two ways, a full external assessment or a self-assessment with independent external validation, but either must occur at least once every five years and rely on a qualified reviewer independent of the organisation, which is what supplies the objectivity.
Why A is correct: This is correct: the obligation may be met by a full external assessment or by a validated self-assessment, performed at least every five years by a qualified, independent outside reviewer.
Why B is wrong: An annual cadence is stricter than required and a reviewer from inside the same organisation is not independent of it, so this fails the independence expectation.
Why C is wrong: A self-assessment without independent external validation is an internal activity; the chief audit executive's sign-off does not supply the external independence the obligation requires.
Why D is wrong: Ongoing monitoring and surveys are internal in nature and do not deliver an independent external judgement, so management approval of scope does not turn them into an external assessment.
What you must be able to do. Communicate and monitor results at the function level: apply the attributes of effective communication, separate recommendations from management action plans, assess residual risk, escalate an accepted risk correctly, and follow up until action is confirmed.
In one sentenceThe largest domain: communicating engagement results with the required attributes to the right stakeholders, separating recommendations from action plans, assessing residual risk, escalating accepted risk in the correct sequence, and monitoring action plans to closure.
Recall check: answer these from memory first
List the seven attributes of effective engagement communication and give a one-line example of a report breaching one of them.
Distinguish a recommendation from a management action plan, and say who owns each.
State the correct sequence for communicating an accepted risk the chief audit executive judges unacceptable.
What it tests. How engagement results are communicated and monitored across the function. It covers the attributes of effective communication (accurate, objective, clear, concise, constructive, complete, and timely) applied to a scenario; distributing and, where needed, correcting final communications; developing recommendations and distinguishing them from management action plans, including root cause and cost-benefit considerations; the chief audit executive's residual risk assessment; communicating an accepted risk to senior management and the board in the correct sequence; and monitoring management action plans through follow-up until implementation is confirmed.
How to study it. This is the heaviest domain, so spend the most time here. Learn the seven communication attributes well enough to spot which one a flawed report breaches. Fix three boundaries that generate most of the questions: recommendation versus management action plan, residual risk assessment versus risk acceptance communication, and follow-up versus escalation. Learn the risk-acceptance escalation sequence exactly, and treat a finding as open until implementation is confirmed, never on management's assertion alone.
Easy to confuse
A recommendation versus a management action plan. A recommendation is internal audit's proposed remedy; a management action plan is management's own committed response, with an owner and a due date. The exam blurs ownership, offering an auditor-written remedy as if it were management's commitment.
Residual risk assessment versus communicating risk acceptance. Residual risk assessment is the auditor's judgement of the risk remaining after controls; communicating risk acceptance is reporting management's decision to accept that risk. Assessing the risk does not decide whether to accept it, and the exam separates the two.
Follow-up versus escalation. Follow-up is the process of confirming that agreed actions were implemented; escalation is raising an unresolved or overdue matter to a higher authority. Following up comes first, and escalation is triggered only when action is not taken, so an answer that escalates before following up moves too fast.
A resolved finding versus an open finding. A finding is closed only when implementation of the agreed action is confirmed by the auditor, not when management asserts it is done. The exam treats a manager's assurance as if it closed the item, which it does not.
Worked example from the CIA-3 bank
lock_openFree sampleEngagement Results and Monitoringmedium
Halden Water Services' internal audit team uncovers, midway through an engagement, evidence that a manager has been circumventing procurement controls and exposing the organisation to continuing loss. The final engagement report is not due for another six weeks. What should the chief audit executive do to keep the communication timely?
AWait until the final report is issued so the matter can be presented with full context and a documented management response.
BCommunicate the matter promptly to senior management and the board so corrective action can be taken ahead of the final report.check_circle Correct
CAdd the matter to the next quarterly summary sent to the finance director for consolidation with the period's other findings.
DHold the finding until fieldwork closes and then compress the report timetable by shortening the management response period.
Timely communication requires issuing interim results when a significant finding needs action before the final engagement report. Timeliness is judged by whether stakeholders receive results soon enough to act on them. When an engagement surfaces a significant matter that is causing ongoing harm, waiting for the scheduled final report defeats the purpose, so an interim communication to management and the board is the sound step.
Why A is wrong: Bundling the matter into the final report feels tidy, but timeliness means communicating significant findings soon enough for action, and a six-week delay lets a known loss continue.
Why B is correct: Timely communication means issuing interim results when a finding is significant enough to warrant action before fieldwork closes, and routing it to management and the board preserves the reporting line and enables a fast response.
Why C is wrong: A quarterly roll-up to a single manager is neither timely nor directed to the right level, and it delays action on an issue that is already causing loss.
Why D is wrong: Squeezing the later timetable still leaves weeks of continuing loss untreated and trades a genuine interim communication for a rushed final one.
A study plan that works
Map the syllabus and set a date
Day 1
Read the official Part 3 exam syllabus and the four sections with their weights, and confirm you are working from the current Internal Audit Function outline, not the retired 2019 Business Knowledge one. Book a provisional exam date now: a fixed date turns open-ended study into a plan.
Lock the function-management model (Internal Audit Operations)
Week 1
Get the reporting model, strategy, and resourcing solid first, because the later sections assume the chief audit executive's reporting lines. Use the recall prompts in this guide: cover the summary, answer from memory, then reveal. Be able to name the correct party and sequence out loud.
Build the plan and secure quality (Internal Audit Plan and Quality)
Weeks 1-2
Master the audit universe versus audit plan boundary and the dynamic, risk-based nature of the plan, then the quality assurance and improvement program with its internal versus external assessment distinction. These two sections are smaller but dense with traps, so drill the confusable pairs.
Go deep on engagement results and monitoring
Weeks 2-3
This section carries the most weight, so spend the bulk of your time here: the seven communication attributes, recommendations versus action plans, residual risk and risk acceptance, and the follow-up and escalation sequence. Use scenario questions, not definitions alone.
Practise on scenarios with every answer explained
Week 3
Move to full practice sets and read the explanation for every question, including the ones you got right. Part 3 tests the single best next action among plausible options, so understanding why a second-best answer is still wrong is where the marks are.
Find and close your weak sections
Week 4
Use your per-section accuracy to drill the areas dragging you down rather than re-reading what you already know. Repeat until every section clears the pass line with margin on unseen questions.
Sit a timed mock and review it
Week 4
Take at least one full timed mock to rehearse pacing and flag-and-return. Treat the score as a per-section readiness signal, then review every missed question before booking or sitting.
Know when you're ready
Readiness for Part 3 is a score on scenario questions you have not seen before, not a feeling that the material is familiar. Those are different things, and the gap between them is where people fail. Re-reading the standards builds fluency, and fluency feels like knowledge, so confidence rises while real recall does not. The fix is to test yourself: if you can read a fresh scenario, name the boundary it is testing, and choose the correct next action while explaining why each other option skips a step or escalates wrongly, you know it; if you can only nod along to an explanation, you do not yet.
Be especially wary of confidence built on definitions. Part 3 rarely asks what a term means; it asks what to do next, in what order, and to whom. A candidate who can define the quality assurance and improvement program can still pick an unvalidated self-assessment or escalate an accepted risk to the wrong party. Trust your measured per-section accuracy over your gut, and set the bar at clearing every section comfortably on unseen questions across more than one session, not scraping the pass mark once.
This guide gives you the map. The practice bank is where you find out whether you can navigate it, with an explanation of why the right answer is right and every wrong one is wrong on every question. Readiness scoring tells you when you are there. Not before.
Ready to put this into practice?
Free CIA-3 questions, every answer explained. No sign-up.
Read the last line of the question first. It tells you what is actually being asked, so you can read the scenario looking for the required next action rather than memorising detail.
Choose the single best next action, not merely a defensible one. Several options are often reasonable; the exam wants the one that follows a sound process without skipping a required step.
Protect the reporting line to the board. When a matter concerns independence, a significant risk, or an accepted risk judged unacceptable, the answer travels the functional line to the board, not just to management.
Respect sequence. Follow up before escalating, discuss with senior management before communicating to the board, and confirm implementation before closing a finding.
Watch for absolutes such as always and never. The correct Part 3 answer is usually the most proactive, evidence-based next step, not a blanket rule.
Eliminate two options fast. Most questions have two clearly weaker choices; removing them turns a guess into a coin flip at worst, and often reveals the boundary being tested.
Frequently asked questions
Is CIA Part 3 hard?
It is a professional-level exam that tests judgement about running the internal audit function, not recall of definitions. The difficulty is in choosing the single best next action among plausible options, which is why scenario practice that explains every option matters more than memorising the standards.
How long should I study for CIA Part 3?
Most candidates who have passed Parts 1 and 2 are ready in three to five weeks of focused study, with the bulk of the time on the engagement results and monitoring section, which carries the most weight.
What is the current Part 3 syllabus?
The current outline is Internal Audit Function, with four sections: Internal Audit Operations, Internal Audit Plan, Quality of the Internal Audit Function, and Engagement Results and Monitoring. It replaced the retired 2019 Business Knowledge for Internal Auditing outline and is aligned to the 2024 Global Internal Audit Standards. Do not study the old business-acumen, IT, information-security, or financial-management material for this part.
What is the pass mark for CIA Part 3?
The exam is scored on a scaled range and the published pass mark is in the facts panel above. Scoring is scaled, so your raw percentage and the scaled score are not the same thing; aim to clear every section comfortably in practice rather than scraping a target.
Which section should I focus on?
Engagement Results and Monitoring is the largest section by weight, so it deserves the most time. The Internal Audit Plan and Quality sections are smaller but dense with confusable pairs, so drill those distinctions rather than skimming them.
How is Part 3 different from Parts 1 and 2?
Part 1 covers the foundations of internal auditing and Part 2 covers performing a single engagement. Part 3 is about running and reporting on the whole function: its strategy and resources, the audit plan, its quality program, and how results are communicated and monitored across engagements.
Do I need to memorise Global Internal Audit Standards numbers?
No. The exam tests whether you can apply the principles, such as the required frequency and independence of the external quality assessment or the escalation sequence for an accepted risk, not whether you can cite a clause number. Learn the concepts and the correct actions, not the numbering.
How many practice questions should I do before booking?
Enough that every section clears the pass line with margin on questions you have not seen before, and that a full timed mock feels comfortable on pacing. Quality of review matters more than raw volume: read the explanation on every question, including those you answered correctly.
Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. This guide is original study material based on the public exam blueprint. We never reproduce live exam items. CIA-3 and related marks belong to their respective owners.