Certified Internal Auditor Examination (CIA)
Full Professional Practice Examination
1. Which of the following best describes the primary purpose of internal auditing?
A. To prepare financial statements for external stakeholders B. To provide independent assurance and
consulting services designed to add value and improve operations C. To manage daily operational risks
for management D. To replace external auditors in evaluating financial controls
Answer: B. To provide independent assurance and consulting services designed to add value and
improve operations
Rationale: Internal auditing is an independent, objective assurance and consulting activity intended to
add value and improve an organization’s operations. It assists organizations in achieving objectives by
evaluating and improving risk management, control, and governance processes. Internal auditors do
not prepare financial statements or replace management or external auditors. Their role is broader
and focuses on operational effectiveness, compliance, and strategic risk management.
1. Which of the following is the most important characteristic of an internal auditor?
A. Technical accounting expertise B. Independence and objectivity C. Marketing ability D. Supervisory
authority
Answer: B. Independence and objectivity
Rationale: Independence and objectivity are foundational principles of internal auditing. Without
these qualities, auditors cannot provide reliable assurance regarding controls, governance, and risk
management. While technical expertise is important, it is secondary to the auditor’s ability to perform
work free from bias or undue influence.
1. According to the International Professional Practices Framework (IPPF), which of the following is
considered a core principle of internal auditing?
A. Maximizing shareholder wealth B. Maintaining absolute secrecy from management C. Demonstrating
integrity D. Eliminating all organizational risks
Answer: C. Demonstrating integrity
Rationale: Integrity is one of the core principles identified in the IPPF. Internal auditors are expected
to perform work honestly, diligently, and responsibly. Integrity builds trust and provides the basis for
reliance on audit judgment. Internal auditing cannot eliminate all risks, nor is it intended to operate
independently from management communication.
1. Which of the following is the responsibility of management rather than the internal audit
function?
A. Assessing the adequacy of controls B. Recommending process improvements C. Establishing and
maintaining internal controls D. Conducting independent evaluations
1
,Answer: C. Establishing and maintaining internal controls
Rationale: Management is responsible for designing, implementing, and maintaining internal controls.
Internal auditors evaluate whether these controls are adequate and functioning effectively. Although
auditors may recommend improvements, ownership of controls always remains with management.
1. Which type of audit engagement focuses primarily on the efficiency and effectiveness of
operations?
A. Financial audit B. Compliance audit C. Operational audit D. Integrated audit
Answer: C. Operational audit
Rationale: Operational audits evaluate the efficiency, effectiveness, and economy of organizational
activities. These audits go beyond financial reporting and compliance issues to determine whether
resources are being used optimally and whether processes support organizational objectives.
1. Which of the following would most likely impair an internal auditor’s objectivity?
A. Recommending internal control improvements B. Reviewing procedures designed by another
department C. Auditing an activity for which the auditor had operational responsibility during the
previous year D. Discussing findings with management before issuing a report
Answer: C. Auditing an activity for which the auditor had operational responsibility during the
previous year
Rationale: Auditing activities for which the auditor previously had responsibility may impair objectivity
because the auditor could be reviewing work previously performed or supervised. The IIA Standards
recommend safeguards or reassignment in such cases. The other activities are generally acceptable
audit practices.
1. The chief audit executive should report functionally to the:
A. Chief financial officer B. Audit committee or board C. Human resources director D. Chief operating
officer
Answer: B. Audit committee or board
Rationale: Functional reporting to the board or audit committee helps ensure the independence of the
internal audit function. This structure allows auditors to perform work without undue management
influence and supports unbiased reporting of audit results.
1. Which of the following is the best example of a preventive control?
A. Bank reconciliation B. Surprise cash count C. Password authentication system D. Variance analysis
Answer: C. Password authentication system
2
, Rationale: Preventive controls are designed to stop errors or irregularities before they occur. Password
authentication restricts unauthorized access and helps prevent security breaches. Bank reconciliations
and variance analyses are detective controls because they identify problems after occurrence.
1. Which of the following best defines residual risk?
A. Risk before controls are implemented B. Risk transferred through insurance C. Risk remaining after
management implements controls D. Risk caused by external economic factors
Answer: C. Risk remaining after management implements controls
Rationale: Residual risk is the level of risk that remains after management has implemented responses
and controls. Internal auditors assess whether residual risk falls within the organization’s risk appetite
and tolerance levels.
1. Which sampling method gives every item in the population an equal chance of selection?
A. Judgmental sampling B. Block sampling C. Random sampling D. Haphazard sampling
Answer: C. Random sampling
Rationale: Random sampling ensures that every item in the population has an equal probability of
selection. This method reduces bias and supports statistically valid conclusions. Judgmental and
haphazard sampling rely on auditor discretion and are nonstatistical approaches.
1. Which of the following is most closely associated with governance?
A. Safeguarding inventory B. Strategic direction and oversight C. Preparing journal entries D. Processing
payroll transactions
Answer: B. Strategic direction and oversight
Rationale: Governance involves the processes and structures used to direct and oversee organizational
activities. It includes setting strategic objectives, monitoring performance, and ensuring
accountability. Operational activities such as payroll processing are management functions rather
than governance responsibilities.
1. During audit planning, the internal auditor should first:
A. Prepare the final audit report B. Conduct fieldwork testing C. Understand the activity under review D.
Recommend corrective actions
Answer: C. Understand the activity under review
Rationale: Audit planning begins with obtaining sufficient understanding of the area being audited.
This understanding includes objectives, risks, controls, and relevant processes. Effective planning
ensures that audit procedures focus on significant risk areas.
1. Which of the following is the strongest segregation of duties?
3
Full Professional Practice Examination
1. Which of the following best describes the primary purpose of internal auditing?
A. To prepare financial statements for external stakeholders B. To provide independent assurance and
consulting services designed to add value and improve operations C. To manage daily operational risks
for management D. To replace external auditors in evaluating financial controls
Answer: B. To provide independent assurance and consulting services designed to add value and
improve operations
Rationale: Internal auditing is an independent, objective assurance and consulting activity intended to
add value and improve an organization’s operations. It assists organizations in achieving objectives by
evaluating and improving risk management, control, and governance processes. Internal auditors do
not prepare financial statements or replace management or external auditors. Their role is broader
and focuses on operational effectiveness, compliance, and strategic risk management.
1. Which of the following is the most important characteristic of an internal auditor?
A. Technical accounting expertise B. Independence and objectivity C. Marketing ability D. Supervisory
authority
Answer: B. Independence and objectivity
Rationale: Independence and objectivity are foundational principles of internal auditing. Without
these qualities, auditors cannot provide reliable assurance regarding controls, governance, and risk
management. While technical expertise is important, it is secondary to the auditor’s ability to perform
work free from bias or undue influence.
1. According to the International Professional Practices Framework (IPPF), which of the following is
considered a core principle of internal auditing?
A. Maximizing shareholder wealth B. Maintaining absolute secrecy from management C. Demonstrating
integrity D. Eliminating all organizational risks
Answer: C. Demonstrating integrity
Rationale: Integrity is one of the core principles identified in the IPPF. Internal auditors are expected
to perform work honestly, diligently, and responsibly. Integrity builds trust and provides the basis for
reliance on audit judgment. Internal auditing cannot eliminate all risks, nor is it intended to operate
independently from management communication.
1. Which of the following is the responsibility of management rather than the internal audit
function?
A. Assessing the adequacy of controls B. Recommending process improvements C. Establishing and
maintaining internal controls D. Conducting independent evaluations
1
,Answer: C. Establishing and maintaining internal controls
Rationale: Management is responsible for designing, implementing, and maintaining internal controls.
Internal auditors evaluate whether these controls are adequate and functioning effectively. Although
auditors may recommend improvements, ownership of controls always remains with management.
1. Which type of audit engagement focuses primarily on the efficiency and effectiveness of
operations?
A. Financial audit B. Compliance audit C. Operational audit D. Integrated audit
Answer: C. Operational audit
Rationale: Operational audits evaluate the efficiency, effectiveness, and economy of organizational
activities. These audits go beyond financial reporting and compliance issues to determine whether
resources are being used optimally and whether processes support organizational objectives.
1. Which of the following would most likely impair an internal auditor’s objectivity?
A. Recommending internal control improvements B. Reviewing procedures designed by another
department C. Auditing an activity for which the auditor had operational responsibility during the
previous year D. Discussing findings with management before issuing a report
Answer: C. Auditing an activity for which the auditor had operational responsibility during the
previous year
Rationale: Auditing activities for which the auditor previously had responsibility may impair objectivity
because the auditor could be reviewing work previously performed or supervised. The IIA Standards
recommend safeguards or reassignment in such cases. The other activities are generally acceptable
audit practices.
1. The chief audit executive should report functionally to the:
A. Chief financial officer B. Audit committee or board C. Human resources director D. Chief operating
officer
Answer: B. Audit committee or board
Rationale: Functional reporting to the board or audit committee helps ensure the independence of the
internal audit function. This structure allows auditors to perform work without undue management
influence and supports unbiased reporting of audit results.
1. Which of the following is the best example of a preventive control?
A. Bank reconciliation B. Surprise cash count C. Password authentication system D. Variance analysis
Answer: C. Password authentication system
2
, Rationale: Preventive controls are designed to stop errors or irregularities before they occur. Password
authentication restricts unauthorized access and helps prevent security breaches. Bank reconciliations
and variance analyses are detective controls because they identify problems after occurrence.
1. Which of the following best defines residual risk?
A. Risk before controls are implemented B. Risk transferred through insurance C. Risk remaining after
management implements controls D. Risk caused by external economic factors
Answer: C. Risk remaining after management implements controls
Rationale: Residual risk is the level of risk that remains after management has implemented responses
and controls. Internal auditors assess whether residual risk falls within the organization’s risk appetite
and tolerance levels.
1. Which sampling method gives every item in the population an equal chance of selection?
A. Judgmental sampling B. Block sampling C. Random sampling D. Haphazard sampling
Answer: C. Random sampling
Rationale: Random sampling ensures that every item in the population has an equal probability of
selection. This method reduces bias and supports statistically valid conclusions. Judgmental and
haphazard sampling rely on auditor discretion and are nonstatistical approaches.
1. Which of the following is most closely associated with governance?
A. Safeguarding inventory B. Strategic direction and oversight C. Preparing journal entries D. Processing
payroll transactions
Answer: B. Strategic direction and oversight
Rationale: Governance involves the processes and structures used to direct and oversee organizational
activities. It includes setting strategic objectives, monitoring performance, and ensuring
accountability. Operational activities such as payroll processing are management functions rather
than governance responsibilities.
1. During audit planning, the internal auditor should first:
A. Prepare the final audit report B. Conduct fieldwork testing C. Understand the activity under review D.
Recommend corrective actions
Answer: C. Understand the activity under review
Rationale: Audit planning begins with obtaining sufficient understanding of the area being audited.
This understanding includes objectives, risks, controls, and relevant processes. Effective planning
ensures that audit procedures focus on significant risk areas.
1. Which of the following is the strongest segregation of duties?
3