The Institute of Internal Auditors free practice

Free CIA-3 practice questions

12 real CIA-3 sample questions, each with an explanation of why every option is right or wrong. No account, no card. This is the reasoning the CIA-3 tests: knowing why the tempting answer is wrong, not just spotting the right one.

The real CIA-3 is 100 questions in 120 minutes, pass mark 600 / 750 (scaled). For a domain-by-domain breakdown and a study plan, read the CIA-3 study guide. The full bank has 316 questions.

Engagement Results and Monitoring (45% of the exam)

Free sampleEngagement Results and Monitoringmedium

Halden Water Services' internal audit team uncovers, midway through an engagement, evidence that a manager has been circumventing procurement controls and exposing the organisation to continuing loss. The final engagement report is not due for another six weeks. What should the chief audit executive do to keep the communication timely?

  • AWait until the final report is issued so the matter can be presented with full context and a documented management response.
  • BCommunicate the matter promptly to senior management and the board so corrective action can be taken ahead of the final report. Correct
  • CAdd the matter to the next quarterly summary sent to the finance director for consolidation with the period's other findings.
  • DHold the finding until fieldwork closes and then compress the report timetable by shortening the management response period.
Timely communication requires issuing interim results when a significant finding needs action before the final engagement report. Timeliness is judged by whether stakeholders receive results soon enough to act on them. When an engagement surfaces a significant matter that is causing ongoing harm, waiting for the scheduled final report defeats the purpose, so an interim communication to management and the board is the sound step.

Why A is wrong: Bundling the matter into the final report feels tidy, but timeliness means communicating significant findings soon enough for action, and a six-week delay lets a known loss continue.

Why B is correct: Timely communication means issuing interim results when a finding is significant enough to warrant action before fieldwork closes, and routing it to management and the board preserves the reporting line and enables a fast response.

Why C is wrong: A quarterly roll-up to a single manager is neither timely nor directed to the right level, and it delays action on an issue that is already causing loss.

Why D is wrong: Squeezing the later timetable still leaves weeks of continuing loss untreated and trades a genuine interim communication for a rushed final one.

Free sampleEngagement Results and Monitoringmedium

While reviewing the draft engagement report for Bramwell Foods, the chief audit executive finds that a headline savings figure in a key finding traces back to a workpaper that does not reconcile to the supporting records. The report is scheduled to be issued tomorrow. What should the chief audit executive do to keep the communication accurate?

  • AIssue the report as drafted and attach a note that some figures are provisional and may be revised after publication.
  • BDelete the finding altogether, since a single reconciliation gap casts doubt on the reliability of the whole engagement.
  • CVerify the underlying evidence and correct the figure before the report is issued to management and the board. Correct
  • DEscalate the discrepancy to the audit committee and let it decide whether the disputed figure should remain in the report.
Accurate communication is free from error and faithfully supported by verified evidence before a report is issued. The accuracy attribute requires that communications contain no errors and are supported by the evidence gathered. A figure that does not reconcile is an unresolved error, so the correct response is to verify and correct it before issue rather than publish it with a caveat or discard the finding.

Why A is wrong: A provisional caveat looks pragmatic against a deadline, but publishing a figure known to be unsupported breaches the accuracy attribute rather than curing it.

Why B is wrong: Dropping a supportable finding over one fixable discrepancy overcorrects and sacrifices completeness; the gap should be resolved, not used to discard the issue.

Why C is correct: Accuracy means the communication is free from error and faithful to the evidence, so resolving the reconciliation gap and correcting the figure before issue is the sound next step.

Why D is wrong: Asking the committee to adjudicate a factual reconciliation shifts a preparation task onto governance and still leaves an unverified figure in the draft.

Free sampleEngagement Results and Monitoringmedium

At Corley Transit a senior auditor drafts the engagement findings using wording that assigns personal blame to named departmental staff and lists faults without proposing remedies. The chief audit executive wants the final communication to be constructive. How should the findings be revised?

  • AKeep the blame-focused wording so that management grasps the seriousness and prioritises fixing the control weaknesses.
  • BSoften the report by removing the control weaknesses that reflect poorly on the department's management.
  • CReplace the written findings with a general statement of concern and convey the detail to the department verbally instead.
  • DReframe the findings around root causes and practical recommendations that help the client correct the weaknesses. Correct
Constructive communication focuses on root causes and actionable recommendations that help the client improve. The constructive attribute asks that communications be helpful to the engagement client and the organisation, leading to improvement. Assigning personal blame or listing faults without remedies works against that, so reframing findings around causes and practical fixes is the appropriate revision.

Why A is wrong: Strong language can seem to convey urgency, but a constructive communication addresses causes and solutions rather than naming individuals, which tends to provoke defensiveness instead of improvement.

Why B is wrong: Deleting valid weaknesses to spare feelings sacrifices completeness and accuracy; being constructive is about framing, not about suppressing real findings.

Why C is wrong: Downgrading documented findings to a vague note and a verbal chat weakens the record and does not make the communication constructive.

Why D is correct: A constructive communication is helpful and forward-looking, focusing on the causes of issues and actionable recommendations so the client can improve, which is what reframing achieves.

Internal Audit Operations (25% of the exam)

Free sampleInternal Audit Operationsmedium

A chief audit executive at Kelmscott Water is building next year's programme of work. She has drawn up a full inventory of every auditable entity, process, and system across the organisation, and separately a list of the specific engagements she intends to resource and schedule over the coming twelve months. A new manager treats these two documents as the same thing. How should the chief audit executive distinguish the audit universe from the annual audit plan?

  • AThe audit universe is the risk-prioritised set of engagements approved for the year, while the audit plan is the broader catalogue of everything that could be audited.
  • BThe audit universe and the audit plan are alternative names for the same risk-ranked schedule, differing only in whether the audit committee has formally approved it.
  • CThe audit universe lists only the engagements requested by management, while the audit plan lists only the engagements requested by the audit committee.
  • DThe audit universe is the full inventory of auditable areas across the organisation, while the audit plan is the risk-prioritised subset the function will actually resource and perform in the period. Correct
Distinguish the audit universe as the full population of auditable areas from the annual audit plan as the risk-prioritised subset scheduled for the period. The audit universe defines the complete set of entities and processes that could be audited; the annual plan applies a risk assessment to that population to select and schedule the engagements the function can resource, so the plan is always a subset of the universe.

Why A is wrong: This inverts the two terms; it is tempting because both concepts involve lists, but the universe is the full catalogue and the plan is the selected, scheduled subset.

Why B is wrong: Approval status does not turn one document into the other; the two are genuinely different artefacts, so treating them as synonyms misses the population-versus-selection distinction.

Why C is wrong: Both artefacts are owned and shaped by the internal audit function using a risk assessment, not split by who requested each engagement, so this mischaracterises how both are built.

Why D is correct: Correct: the universe is the complete population of potential engagements, and the plan is the prioritised selection scheduled and resourced for the period, informed by a risk assessment.

Free sampleInternal Audit Operationsmedium

The board of Tarnbrook Logistics receives a quarterly performance pack from internal audit. One figure tracks the percentage of the approved plan completed against schedule. A separate figure tracks a leading measure of the organisation's exposure, such as the number of overdue high-risk remediation actions, which the function watches because a rising value signals emerging risk before it crystallises. A director asks how to label each figure correctly. Which characterisation fits?

  • APlan completion against schedule is a key performance indicator, while overdue high-risk remediation actions is a key risk indicator that gives an early signal of emerging exposure. Correct
  • BPlan completion against schedule is a key risk indicator, while overdue high-risk remediation actions is a key performance indicator of the function's throughput.
  • CBoth figures are key performance indicators because both are expressed as measurable numbers reported to the board each quarter.
  • DBoth figures are key risk indicators because internal audit reports them to help the board oversee organisational risk.
Distinguish a key performance indicator, which measures the function's delivery, from a key risk indicator, which gives an early warning of emerging exposure. A KPI gauges progress against the function's own objectives, such as plan completion, whereas a KRI is a leading metric selected because its movement precedes and signals a change in risk exposure, so the two answer different management questions.

Why A is correct: Correct: a KPI measures how well the function is performing against its objectives, and a KRI is a forward-looking metric whose movement warns that risk exposure is building.

Why B is wrong: This swaps the labels; it is tempting because both are numeric measures, but completion measures the function's own performance while overdue actions is a forward-looking risk signal.

Why C is wrong: Being numeric and board-reported does not make a measure a KPI; the overdue-actions figure signals emerging exposure rather than the function's performance, so it functions as a KRI.

Why D is wrong: Reporting a figure to support risk oversight does not make it a KRI; plan completion measures the function's own delivery, which is a performance indicator.

Free sampleInternal Audit Operationsmedium

During an engagement at Ravensworth Foods, internal audit finds that a residual risk on the cash-handling process exceeds the level the organisation is prepared to bear, and management has decided in writing not to remediate it. The engagement lead needs to place two ideas correctly: the auditors' evaluation that the remaining exposure is above tolerance, and management's formal choice to live with it. How should these be distinguished?

  • ABoth the auditors' evaluation and management's written decision are forms of risk acceptance, differing only in who signs the documentation.
  • BThe auditors' judgement that residual risk exceeds tolerance is a residual risk assessment, and management's written decision to accept it is a risk acceptance that the chief audit executive may need to escalate if the level is unacceptable. Correct
  • CThe auditors' evaluation is a risk acceptance, while management's written decision is the residual risk assessment that feeds the audit opinion.
  • DNeither is an internal audit responsibility, because both residual risk assessment and risk acceptance are performed solely by the board's risk committee.
Separate residual risk assessment, an audit evaluation of remaining exposure, from risk acceptance, a management decision the chief audit executive may escalate. Internal audit assesses whether residual risk sits above tolerance, but the choice to accept that exposure belongs to management; when the CAE judges the accepted level unacceptable, the matter is escalated to senior management and the board rather than resolved by audit.

Why A is wrong: The auditors assess exposure but do not accept risk on the organisation's behalf; collapsing both into acceptance ignores that only management can choose to bear the risk.

Why B is correct: Correct: assessing residual exposure against tolerance is audit work, whereas accepting that exposure is a management decision, which the CAE escalates to the board when the accepted level seems unacceptable.

Why C is wrong: This reverses the roles; assessment is the auditors' analytical task and acceptance is management's decision, so labelling them the other way round misstates each party's responsibility.

Why D is wrong: Internal audit does assess residual risk during engagements, and the CAE has a defined escalation duty, so treating both as purely board activities removes audit's genuine role.

Internal Audit Plan (15% of the exam)

Free sampleInternal Audit Planmedium

The chief audit executive at Brindle Manufacturing is building next year's audit plan and learns that the external financial auditors already test controls over the revenue cycle each year. She wants to reduce duplicated testing by relying on that work. Before deciding how much to rely on it, what should she evaluate first?

  • AWhether the audit committee has formally approved the external auditors' engagement letter for the current financial year
  • BWhether relying on the external auditors' testing will reduce the internal audit function's own budgeted hours for the year
  • CThe external auditors' competence, objectivity, and the scope and adequacy of the work they performed on those controls Correct
  • DWhether the external auditors are willing to sign a statement accepting responsibility for the revenue-cycle conclusion
Before relying on another assurance provider's work, evaluate that provider's competence, objectivity, and the relevance and adequacy of the work performed. Reliance is justified only when the internal auditor has judged the other provider's competence and objectivity and confirmed the work's scope covers the objective; efficiency and approvals do not substitute for that judgement, and responsibility for the conclusion stays with internal audit.

Why A is wrong: Tempting because engagement approval is a real governance step, but committee approval of the external audit engagement says nothing about whether that work is competent, objective, or relevant to internal audit's control objective.

Why B is wrong: Tempting because efficiency motivates coordination, but cost saving is a benefit of reliance, not a criterion for it; the decision to rely must rest on the quality and relevance of the other provider's work.

Why C is correct: Correct. Reliance criteria require assessing the other provider's competence and objectivity and confirming that the work's scope, timing, and rigour actually cover the internal audit objective before placing reliance on it.

Why D is wrong: Tempting because shared responsibility sounds prudent, but the internal auditor retains responsibility for conclusions even when leveraging others' work, so seeking a transfer of responsibility misstates how reliance operates.

Free sampleInternal Audit Planmedium

At Calvert Utilities the chief audit executive maintains an assurance map and notices that internal audit, the enterprise risk function, and an external compliance reviewer all plan to test the same third-party vendor controls next quarter. The audit committee wants better coordinated assurance. What is the most appropriate next step?

  • ARemove the vendor controls from the internal audit plan entirely, since two other providers already intend to cover them
  • BAsk the enterprise risk function and the external reviewer to submit their working papers to internal audit for approval before they begin
  • CEscalate the overlap to the external financial auditors and let them decide which provider should test the vendor controls
  • DCoordinate timing and scope with the other providers so the combined effort covers the risk without unnecessary overlap, then rely where the work is adequate Correct
Coordinated assurance aligns the scope and timing of multiple providers to cover risks efficiently while internal audit judges where to rely on their work. An assurance map exists to surface overlaps and gaps so providers can be coordinated; the correct response aligns scope and timing and then leverages adequate work, rather than blindly dropping coverage or seizing authority over peers.

Why A is wrong: Tempting because avoiding duplication is the goal, but dropping the area outright before assessing whether the others' work is reliable and sufficient could leave a coverage gap the internal auditor is accountable for.

Why B is wrong: Tempting because reviewing others' evidence supports reliance, but demanding approval authority over peer assurance providers oversteps internal audit's role and does not resolve the overlap in planning.

Why C is wrong: Tempting because external auditors are an assurance provider, but they are not positioned to allocate other functions' work; coordinating assurance is the chief audit executive's responsibility, not something to hand off.

Why D is correct: Correct. Coordinated assurance means aligning scope and timing across providers to cover the risk efficiently while the internal auditor decides where others' work is reliable enough to leverage.

Free sampleInternal Audit Planmedium

The chief audit executive at Delmore Health reviewed the work of the organisation's second-line compliance monitoring team and found their testing of patient-data controls competent and well documented, but the team reports directly to the head of the business unit whose controls were tested. How should this affect the decision to rely on that work?

  • AWeigh the objectivity threat from the reporting line and reduce reliance accordingly, performing additional internal audit testing where the threat is greatest Correct
  • BRely on the work in full, because the documentation quality already demonstrates the competence needed for reliance
  • CReject the work outright, because any assurance produced inside the second line of defence cannot be relied upon by internal audit
  • DRely on the work provided the head of the business unit confirms in writing that the monitoring team acted independently
Reliance on another provider's work requires both competence and objectivity; a threat to objectivity should reduce reliance and trigger additional internal audit testing. Competence and objectivity are separate criteria that both must hold; when a provider's reporting line threatens objectivity, the internal auditor scales reliance down and fills the gap with its own procedures rather than accepting or rejecting the work wholesale.

Why A is correct: Correct. Objectivity is a required reliance criterion alongside competence; a reporting line into the tested area is a threat that should lower reliance and prompt supplementary internal audit procedures rather than an all-or-nothing decision.

Why B is wrong: Tempting because competence is genuine and evidenced, but reliance requires both competence and objectivity; strong documentation does not offset a reporting line that threatens the reviewers' independence from the area tested.

Why C is wrong: Tempting because second-line objectivity is limited, but a blanket refusal misstates the criteria; internal audit can still leverage such work after weighing the objectivity threat and adjusting how much reliance it places.

Why D is wrong: Tempting because written confirmation feels like due diligence, but assurance from the very manager whose controls were tested does not resolve the structural objectivity threat and may compound it.

Quality of the Internal Audit Function (15% of the exam)

Free sampleQuality of the Internal Audit Functionhard

The board of a large organisation wants assurance that the internal audit function's external assessment obligation under its quality assurance and improvement program is being met correctly. Which approach satisfies that obligation?

  • AEither a full external assessment or a self-assessment with independent external validation, conducted at least once every five years by a qualified reviewer from outside the organisation. Correct
  • BOnly a full external assessment performed every year by a reviewer who is employed elsewhere within the same organisation but outside the audit team.
  • CA periodic self-assessment signed off by the chief audit executive alone, provided that the function repeats the exercise at least every three years.
  • DOngoing monitoring supplemented by a stakeholder survey, provided that senior management approves the scope of the review beforehand.
The external assessment can be a full external assessment or a validated self-assessment, done at least every five years by a qualified independent outside reviewer. The external assessment requirement can be discharged two ways, a full external assessment or a self-assessment with independent external validation, but either must occur at least once every five years and rely on a qualified reviewer independent of the organisation, which is what supplies the objectivity.

Why A is correct: This is correct: the obligation may be met by a full external assessment or by a validated self-assessment, performed at least every five years by a qualified, independent outside reviewer.

Why B is wrong: An annual cadence is stricter than required and a reviewer from inside the same organisation is not independent of it, so this fails the independence expectation.

Why C is wrong: A self-assessment without independent external validation is an internal activity; the chief audit executive's sign-off does not supply the external independence the obligation requires.

Why D is wrong: Ongoing monitoring and surveys are internal in nature and do not deliver an independent external judgement, so management approval of scope does not turn them into an external assessment.

Free sampleQuality of the Internal Audit Functionhard

Before commissioning an external assessment, an audit committee wants to confirm that the proposed assessor is suitable. Which set of qualifications should the external assessor or assessment team possess?

  • ACurrent membership of the organisation's audit committee together with prior employment within the internal audit function that is being reviewed.
  • BCompetence in the professional practice of internal auditing and in the external assessment process, together with independence from the organisation being reviewed. Correct
  • CA recognised accounting qualification and at least ten years of experience auditing external financial statements for listed companies.
  • DCertification as an information systems auditor along with delegated authority to approve the internal audit plan for the coming year.
An external assessor must be competent in internal audit practice and the assessment process and independent of the organisation reviewed. Credibility of an external assessment rests on two pillars: the assessor must have genuine competence in the professional practice of internal auditing and in conducting the assessment, and must be independent of the organisation so no conflict of interest colours the conclusion.

Why A is wrong: These affiliations create exactly the conflicts an external assessment is meant to avoid; a committee member or former staffer is not independent of the function.

Why B is correct: This is correct: an external assessor must be both competent in internal auditing and the assessment process and independent of the organisation, so the review is expert and objective.

Why C is wrong: Financial statement audit expertise is plausible but off target; the assessment concerns the practice of internal auditing, not external financial reporting credentials.

Why D is wrong: A single technical certification is too narrow, and approving the audit plan would compromise independence rather than support an objective external review.

Free sampleQuality of the Internal Audit Functionhard

At Calderwood Mutual the chief audit executive has a periodic self-assessment scheduled once each year and wants to add a routine that continuously tracks engagement supervision, conformance issues, and stakeholder feedback as engagements close. A senior auditor argues this new routine simply duplicates the annual self-assessment. How should the chief audit executive characterise the new routine?

  • AAs a replacement for the annual periodic self-assessment, since continuous tracking captures the same information more frequently and makes the yearly review redundant.
  • BAs a substitute for the external quality assessment, because measuring conformance in real time removes the need for an outside assessor.
  • CAs ongoing monitoring that runs continuously as part of day-to-day supervision and complements, rather than duplicates, the periodic self-assessment. Correct
  • DAs an informal management courtesy with no role in the quality assurance and improvement program, useful only if time permits after mandatory reviews.
Ongoing monitoring is continuous and embedded in supervision, complementing rather than replacing periodic self-assessment within the quality programme. The quality assurance and improvement program combines continuous ongoing monitoring with periodic self-assessments and external assessments. Ongoing monitoring is woven into everyday supervision and review of engagements, giving real-time signals, while periodic self-assessment steps back for a broader review; each covers ground the other does not.

Why A is wrong: It is tempting to fold one into the other, but ongoing monitoring and periodic self-assessment are distinct components of the programme, and continuous tracking is not designed to replace the broader periodic review.

Why B is wrong: Internal monitoring, however frequent, can never substitute for an independent external assessment; the two answer different questions and one cannot stand in for the other.

Why C is correct: Ongoing monitoring is the continuous, embedded component built into routine supervision and review, and it works alongside the periodic self-assessment rather than repeating it, so the two are complementary.

Why D is wrong: Ongoing monitoring is a required element of the programme, not an optional extra, so treating it as a discretionary courtesy understates its role.

Want the full bank?

316 CIA-3 questions, every one with an explanation of why every option is right or wrong. No sign-up to start.

Practise CIA-3 free

Frequently asked questions

Are these CIA-3 practice questions free?

Yes. Every CIA-3 question on this page is free to read with no sign-up, and each one explains why the right answer is right and why every other option is wrong. The full bank of 316 questions is on Examworthy.

Do the questions explain why the wrong answers are wrong?

Yes, and that is the point. Each option, correct or not, has its own rationale, so you learn to rule out the tempting wrong answer, not just recognise the right one. That is the reasoning the CIA-3 tests.

Are these real CIA-3 exam questions?

No. These are original, blueprint-aligned practice questions written to the public The Institute of Internal Auditors content outline. We never reproduce live exam items. They mirror the format and difficulty of the real exam.

How many questions are on the real CIA-3?

The CIA-3 is 100 questions in 120 minutes, with a pass mark of 600 / 750 (scaled). For the full domain-by-domain breakdown and a study plan, read the study guide.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CIA-3 and related marks belong to their respective owners.