Illinois Certified Internal Auditor Exam | Latest Verified
Questions and Detailed Answers
OVERVIEW DESCRIPTION:
Part 1: Essentials of Internal Auditing
Covers the IPPF mandatory guidance, independence and objectivity, due professional care,
QAIP, governance, risk, control frameworks (COSO), and fraud risks. Emphasizes the
ethical and theoretical foundation required for assurance and consulting activities.
Part 2: Practice of Internal Auditing
Focuses on managing and executing engagements, including planning, risk assessment,
fieldwork, evidence gathering, supervision, communication, and follow-up. Highlights
practical skills for delivering value and coordinating with stakeholders.
Part 3: Business Knowledge for Internal Auditing
Addresses financial management, information security, IT governance (COBIT), and
organizational acumen. Emphasizes understanding the business context, technology risks,
and strategic frameworks to evaluate operations effectively.
PART 1: ESSENTIALS OF INTERNAL AUDITING
QUESTION 1
According to the International Professional Practices Framework (IPPF), which of the
following is considered mandatory guidance?
A) Implementation Guides
B) Practice Guides
C) The Core Principles
D) The Code of Ethics
CORRECT ANSWER: D
,2|Page
EXPERT RATIONALE: Mandatory guidance consists of the Core Principles, the
Definition of Internal Auditing, the Code of Ethics, and the Standards. Implementation
and Practice Guides are strongly recommended but not mandatory.
QUESTION 2
Which of the following best describes the primary role of the audit committee in relation
to the internal audit function?
A) To directly approve all audit work papers.
B) To oversee the internal audit function's activities and independence.
C) To perform internal audit procedures during an outsourcing arrangement.
D) To manage the day-to-day operations of the audit department.
CORRECT ANSWER: B
EXPERT RATIONALE: The audit committee provides oversight of the internal audit
function, including reviewing the charter, approving the audit plan, and ensuring the
chief audit executive has direct access to the board, thereby safeguarding
independence.
QUESTION 3
An internal auditor discovers a significant error during an engagement that was not
included in the original audit scope. What is the most appropriate initial action?
A) Ignore the error as it is outside the scope.
B) Immediately expand the audit scope to cover the error.
C) Communicate the finding to the appropriate level of management.
D) Document the error only in the final report if it remains unresolved.
CORRECT ANSWER: C
,3|Page
EXPERT RATIONALE: The Standards require auditors to communicate significant issues
or risks identified during an engagement, even if outside the original scope, to the
appropriate level of management to ensure timely awareness and action.
QUESTION 4
Which of the following threats to objectivity is most directly associated with an internal
auditor who previously served as the financial controller for the department being
audited?
A) Self-review threat
B) Familiarity threat
C) Undue influence threat
D) Economic interest threat
CORRECT ANSWER: A
EXPERT RATIONALE: A self-review threat occurs when an auditor evaluates work that
they previously performed or were responsible for. Having served as the financial
controller creates a situation where the auditor would be reviewing their own prior
decisions.
QUESTION 5
According to the IPPF, which of the following is a key element of a quality assurance and
improvement program (QAIP)?
A) Mandatory annual peer review by an external party.
B) Internal assessments, including ongoing monitoring and periodic self-assessments.
C) Exemption from review for engagements deemed "confidential."
D) A requirement that all audit reports be approved by the external auditors.
CORRECT ANSWER: B
, 4|Page
EXPERT RATIONALE: Standard 1300 requires a QAIP that includes both internal
assessments (ongoing monitoring and periodic self-assessments) and external
assessments, typically conducted at least once every five years.
QUESTION 6
What is the primary objective of control activities within a governance framework?
A) To ensure that policies and procedures are carried out as prescribed.
B) To define the organization's strategic objectives.
C) To set the tone at the top for ethical conduct.
D) To provide a mechanism for external financial reporting.
CORRECT ANSWER: A
EXPERT RATIONALE: Control activities are the actions established through policies and
procedures that help ensure management's directives to mitigate risks are carried out
effectively.
QUESTION 7
An internal auditor is evaluating the organization's fraud risk management program.
Which component is essential for a robust program?
A) A dedicated team of external investigators on retainer.
B) An assessment of fraud risk and the establishment of preventive controls.
C) A policy requiring immediate termination of any employee suspected of fraud.
D) A requirement that all fraud reports be made to the external auditors first.
CORRECT ANSWER: B
EXPERT RATIONALE: A robust fraud risk management program should include a fraud
risk assessment, preventive controls (like segregation of duties), detective controls (like
reconciliation), and a reporting mechanism (whistleblower hotline).