CIA-3 domain - 15% of the exam

Internal Audit Plan

Internal Audit Plan is 15% of the IIA Certified Internal Auditor - Part 3: Internal Audit Function (CIA-3) exam. These are the objectives it covers, each with practice questions, with every answer explained.

Objectives in this domain

Sample question from this domain

Free sampleInternal Audit Planmedium

The chief audit executive at Brindle Manufacturing is building next year's audit plan and learns that the external financial auditors already test controls over the revenue cycle each year. She wants to reduce duplicated testing by relying on that work. Before deciding how much to rely on it, what should she evaluate first?

  • AWhether the audit committee has formally approved the external auditors' engagement letter for the current financial year
  • BWhether relying on the external auditors' testing will reduce the internal audit function's own budgeted hours for the year
  • CThe external auditors' competence, objectivity, and the scope and adequacy of the work they performed on those controls Correct
  • DWhether the external auditors are willing to sign a statement accepting responsibility for the revenue-cycle conclusion
Before relying on another assurance provider's work, evaluate that provider's competence, objectivity, and the relevance and adequacy of the work performed. Reliance is justified only when the internal auditor has judged the other provider's competence and objectivity and confirmed the work's scope covers the objective; efficiency and approvals do not substitute for that judgement, and responsibility for the conclusion stays with internal audit.

Why A is wrong: Tempting because engagement approval is a real governance step, but committee approval of the external audit engagement says nothing about whether that work is competent, objective, or relevant to internal audit's control objective.

Why B is wrong: Tempting because efficiency motivates coordination, but cost saving is a benefit of reliance, not a criterion for it; the decision to rely must rest on the quality and relevance of the other provider's work.

Why C is correct: Correct. Reliance criteria require assessing the other provider's competence and objectivity and confirming that the work's scope, timing, and rigour actually cover the internal audit objective before placing reliance on it.

Why D is wrong: Tempting because shared responsibility sounds prudent, but the internal auditor retains responsibility for conclusions even when leveraging others' work, so seeking a transfer of responsibility misstates how reliance operates.

Other domains in this exam

See also the CIA-3 cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.