CIA-3 - Internal Audit Operations - Section A.1

Describe methodologies for the planning, organizing, directing, and monitoring of internal audit operations, including managing external providers and balancing assurance and advisory engagements.

Describe how internal audit operations are planned, organised, directed, and monitored, including methods for managing external providers who supplement the function's own resources. Explain how the function balances assurance and advisory engagements against its available capacity, and identify the conditions, such as a changed risk landscape or persistent quality issues, that warrant reviewing and revising internal audit methodologies.

Internal audit operationsExternal service providersAssurance-advisory balance

Practice question for this objective

Free sampleInternal Audit Operationsmedium

A chief audit executive is reviewing how IT resources for the audit function are governed. She separates the analytics platform the team uses to perform engagements from the assurance work the team performs over the organisation's IT controls. A board member conflates the two. Which distinction should the chief audit executive draw?

  • ABoth are the same IT resource, so the audit committee can rely on the analytics platform itself as evidence that the organisation's IT controls are effective.
  • BThe analytics platform is an internally managed resource that supports how engagements are performed, whereas assurance over the organisation's IT controls is audit subject matter the function examines. Correct
  • CThe analytics platform is the audit subject matter, while assurance over IT controls is merely an internal support activity for the function.
  • DNeither relates to managing IT resources, because technology decisions sit entirely with the organisation's IT department and not with the audit function.
The function's own audit technology is a managed resource supporting engagements, distinct from the organisational IT controls the function provides assurance over. Managing IT resources for internal audit means acquiring and maintaining the tools the team uses to work, which is separate from the assurance the team delivers over the enterprise's IT controls. Confusing the tool with the subject matter would let a support asset be mistaken for audit evidence.

Why A is wrong: This is tempting because both involve technology, but the function's own tooling is not evidence about the organisation's controls, so conflating them would misstate assurance.

Why B is correct: Correct: one is a tool the function acquires and maintains to do its work, and the other is the auditee's control environment that the function provides assurance over.

Why C is wrong: This reverses the roles: the platform is the function's support resource and assurance over IT controls is the subject matter, so the labels are swapped.

Why D is wrong: This is plausible because IT departments own enterprise systems, but the function still manages its own audit technology resources, so denying that responsibility is incorrect.

See more CIA-3 practice questions, answers explained.

More in this domain

Back to all Internal Audit Operations objectives, or the CIA-3 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.