WGU D560 — Internal Auditing I OA (Objective Assessment) 2026 Update | 59 Questions | 100 pts
WGU D560 INTERNAL AUDITING I
(OA) OBJECTIVE ASSESSMENT | 59 QUESTIONS AND ANSWERS | 2026 UPDATE | WITH
COMPLETE SOLUTIONS
Western Governors University • Internal Auditing I (D560)
Aligned with 2026 | 2027 academic standards • IIA Standards (GIAS), COSO, Audit Lifecycle
Questions 59 multiple-choice (4 sections) Time (suggested) 120 minutes
Points 100 (~1.69 pts per question) Passing ≥ 70 (Competent)
Cognitive Mix 30% recall · 50% application · 20% analysis Format 75% scenario / 25% direct
Examination Instructions
This Objective Assessment mirrors the structure, rigor, and scenario-based application style of the actual WGU
D560 Internal Auditing I OA. Each question presents four options (A–D) with exactly one correct answer.
Rationales include step-by-step applications of the IIA Standards (including the new Global Internal Audit
Standards, effective January 2025), the COSO Internal Control-Integrated Framework, audit-evidence
procedures, sampling methods, and reporting/follow-up requirements—and explicitly identify the common
conceptual errors that produce each distractor. Section 4 integrates 2026|2027 modern contexts: GIAS
implementation, AI-driven risk assessment, continuous auditing, ESG assurance, and modern IT audit
frameworks (COBIT, NIST CSF).
Section 1: Foundations of Internal Auditing, IIA Standards (IPPF), & Ethics
(Q1–Q15)
Definition and purpose of internal auditing; authority via the audit charter; the new Global Internal Audit Standards
(GIAS); the IIA Code of Ethics (Integrity, Objectivity, Confidentiality, Competency); independence and objectivity;
assurance vs. consulting services; due professional care; fraud responsibility.
Q1. Internal auditing is best defined as a(n):
A. Independent, objective assurance and consulting activity designed to add value and improve an
organization's operations [CORRECT]
B. External examination of financial statements to express an audit opinion
C. Activity focused solely on detecting fraud
D. Function that reports exclusively to the external auditor
Correct Answer: A — Independent, objective assurance and consulting activity designed to add value
and improve an organization's operations
Rationale: Per the IIA, internal auditing is an independent, objective assurance and consulting activity that adds
value and improves operations. B describes external financial-statement auditing; C overstates fraud as the sole
purpose; D misstates the reporting line—internal audit reports to the board/senior management.
Q2. Which of the following is a primary purpose of the internal audit function?
A. To evaluate and improve the effectiveness of governance, risk, and control processes [CORRECT]
B. To prepare the organization's financial statements
C. To certify compliance with tax laws
D. To select external auditors
Western Governors University • Confidential OA Study Tool Page 1
,WGU D560 — Internal Auditing I OA (Objective Assessment) 2026 Update | 59 Questions | 100 pts
Correct Answer: A — To evaluate and improve the effectiveness of governance, risk, and control
processes
Rationale: Internal audit's purpose is to evaluate and improve governance, risk management, and control
processes. B is management's responsibility; C is a tax/compliance function; D is the audit committee's role.
Q3. Under the new Global Internal Audit Standards (GIAS, effective January 2025), which of the following is a
Domain?
A. Domain I: Purpose of Internal Auditing
B. Domain I: Internal Audit Profession [CORRECT]
C. Domain I: Foundational Requirements
D. Domain I: Independence and Objectivity
Correct Answer: B — Domain I: Internal Audit Profession
Rationale: GIAS organizes 15 Standards into 5 Domains: (I) Internal Audit Profession, (II) Ethics and Professionalism,
(III) Internal Auditing Profession Practice, (IV) Managing the Internal Audit Function, (V) Performing Internal Audit
Engagements. Domain I: Internal Audit Profession is correct. The others conflate a Domain with a Standard or
Requirement.
Q4. Internal auditing's authority is derived primarily from:
A. The audit charter approved by the board [CORRECT]
B. The external auditor's work
C. The CEO's discretion
D. Federal regulation
Correct Answer: A — The audit charter approved by the board
Rationale: Internal audit's authority comes from the audit charter, approved by the board (or equivalent oversight
body). B/C/D are incorrect—authority is established governance-wide, not delegated case-by-case or by regulators.
Q5. Which IIA Code of Ethics principle is most directly violated when an internal auditor accepts a significant
gift from an audit client?
A. Integrity
B. Objectivity [CORRECT]
C. Confidentiality
D. Competency
Correct Answer: B — Objectivity
Rationale: Accepting a significant gift creates a self-interest threat impairing Objectivity (the principle that auditors
render impartial, unbiased judgments). Integrity concerns honesty/truth; Confidentiality concerns information protection;
Competency concerns skills/knowledge.
Q6. An internal auditor discloses confidential audit findings to a friend outside the organization. Which ethical
principle is violated?
A. Confidentiality [CORRECT]
B. Objectivity
C. Integrity
D. Competency
Correct Answer: A — Confidentiality
Rationale: Sharing confidential information without authorization violates Confidentiality. Objectivity concerns bias;
Integrity concerns truthfulness; Competency concerns skill.
Q7. The IIA Code of Ethics principle of Integrity requires auditors to:
Western Governors University • Confidential OA Study Tool Page 2
, WGU D560 — Internal Auditing I OA (Objective Assessment) 2026 Update | 59 Questions | 100 pts
A. Perform work with honesty, diligence, and responsibility, observing the law and making disclosures
expected thereof [CORRECT]
B. Disclose all material matters known to them that, if not disclosed, may distort the reporting of activities
under review
C. Apply knowledge, skills, and experience needed
D. Be prudent in protecting information
Correct Answer: A — Perform work with honesty, diligence, and responsibility, observing the law and
making disclosures expected thereof
Rationale: Integrity requires honesty, diligence, and lawful responsible behavior. B describes a sub-rule of Integrity
(disclosure of material facts) but A is the broader principle statement. C is Competency; D is Confidentiality.
Q8. Which of the following is an assurance service rather than a consulting service?
A. Performance audit of the procurement function [CORRECT]
B. Training staff on risk management
C. Facilitating a risk-assessment workshop
D. Advising on control design for a new system
Correct Answer: A — Performance audit of the procurement function
Rationale: A performance audit evaluates the function against criteria and provides assurance. B, C, and D are
consulting/advisory activities (training, facilitation, advisory) that do not provide an assurance opinion.
Q9. Which organizational relationship best supports internal audit independence?
A. Functional reporting to the board/audit committee and administrative reporting to senior management
[CORRECT]
B. Functional and administrative reporting both to the CFO
C. Reporting only to the external auditor
D. Reporting to the general counsel
Correct Answer: A — Functional reporting to the board/audit committee and administrative reporting to
senior management
Rationale: Functional reporting to the board/audit committee (approves charter, budget, appointment, salary) plus
administrative reporting to senior management (day-to-day logistics) best supports independence. B impairs
independence (CFO oversees an area being audited); C/D are misaligned reporting lines.
Q10. Which of the following best describes the concept of 'due professional care' in internal auditing?
A. Competence and diligence expected of a reasonably prudent and competent internal auditor
[CORRECT]
B. Guaranteeing that all fraud will be detected
C. Following the external auditor's procedures
D. Performing only those procedures requested by management
Correct Answer: A — Competence and diligence expected of a reasonably prudent and competent
internal auditor
Rationale: Due professional care = competence + diligence expected of a reasonably prudent internal auditor in
similar circumstances. B is impossible (fraud is not guaranteed); C/D mischaracterize the concept.
Q11. The internal audit function's responsibility regarding fraud is to:
A. Have sufficient knowledge to identify fraud indicators and evaluate indicators when encountered
[CORRECT]
B. Investigate all frauds on behalf of management
C. Guarantee fraud prevention
Western Governors University • Confidential OA Study Tool Page 3
WGU D560 INTERNAL AUDITING I
(OA) OBJECTIVE ASSESSMENT | 59 QUESTIONS AND ANSWERS | 2026 UPDATE | WITH
COMPLETE SOLUTIONS
Western Governors University • Internal Auditing I (D560)
Aligned with 2026 | 2027 academic standards • IIA Standards (GIAS), COSO, Audit Lifecycle
Questions 59 multiple-choice (4 sections) Time (suggested) 120 minutes
Points 100 (~1.69 pts per question) Passing ≥ 70 (Competent)
Cognitive Mix 30% recall · 50% application · 20% analysis Format 75% scenario / 25% direct
Examination Instructions
This Objective Assessment mirrors the structure, rigor, and scenario-based application style of the actual WGU
D560 Internal Auditing I OA. Each question presents four options (A–D) with exactly one correct answer.
Rationales include step-by-step applications of the IIA Standards (including the new Global Internal Audit
Standards, effective January 2025), the COSO Internal Control-Integrated Framework, audit-evidence
procedures, sampling methods, and reporting/follow-up requirements—and explicitly identify the common
conceptual errors that produce each distractor. Section 4 integrates 2026|2027 modern contexts: GIAS
implementation, AI-driven risk assessment, continuous auditing, ESG assurance, and modern IT audit
frameworks (COBIT, NIST CSF).
Section 1: Foundations of Internal Auditing, IIA Standards (IPPF), & Ethics
(Q1–Q15)
Definition and purpose of internal auditing; authority via the audit charter; the new Global Internal Audit Standards
(GIAS); the IIA Code of Ethics (Integrity, Objectivity, Confidentiality, Competency); independence and objectivity;
assurance vs. consulting services; due professional care; fraud responsibility.
Q1. Internal auditing is best defined as a(n):
A. Independent, objective assurance and consulting activity designed to add value and improve an
organization's operations [CORRECT]
B. External examination of financial statements to express an audit opinion
C. Activity focused solely on detecting fraud
D. Function that reports exclusively to the external auditor
Correct Answer: A — Independent, objective assurance and consulting activity designed to add value
and improve an organization's operations
Rationale: Per the IIA, internal auditing is an independent, objective assurance and consulting activity that adds
value and improves operations. B describes external financial-statement auditing; C overstates fraud as the sole
purpose; D misstates the reporting line—internal audit reports to the board/senior management.
Q2. Which of the following is a primary purpose of the internal audit function?
A. To evaluate and improve the effectiveness of governance, risk, and control processes [CORRECT]
B. To prepare the organization's financial statements
C. To certify compliance with tax laws
D. To select external auditors
Western Governors University • Confidential OA Study Tool Page 1
,WGU D560 — Internal Auditing I OA (Objective Assessment) 2026 Update | 59 Questions | 100 pts
Correct Answer: A — To evaluate and improve the effectiveness of governance, risk, and control
processes
Rationale: Internal audit's purpose is to evaluate and improve governance, risk management, and control
processes. B is management's responsibility; C is a tax/compliance function; D is the audit committee's role.
Q3. Under the new Global Internal Audit Standards (GIAS, effective January 2025), which of the following is a
Domain?
A. Domain I: Purpose of Internal Auditing
B. Domain I: Internal Audit Profession [CORRECT]
C. Domain I: Foundational Requirements
D. Domain I: Independence and Objectivity
Correct Answer: B — Domain I: Internal Audit Profession
Rationale: GIAS organizes 15 Standards into 5 Domains: (I) Internal Audit Profession, (II) Ethics and Professionalism,
(III) Internal Auditing Profession Practice, (IV) Managing the Internal Audit Function, (V) Performing Internal Audit
Engagements. Domain I: Internal Audit Profession is correct. The others conflate a Domain with a Standard or
Requirement.
Q4. Internal auditing's authority is derived primarily from:
A. The audit charter approved by the board [CORRECT]
B. The external auditor's work
C. The CEO's discretion
D. Federal regulation
Correct Answer: A — The audit charter approved by the board
Rationale: Internal audit's authority comes from the audit charter, approved by the board (or equivalent oversight
body). B/C/D are incorrect—authority is established governance-wide, not delegated case-by-case or by regulators.
Q5. Which IIA Code of Ethics principle is most directly violated when an internal auditor accepts a significant
gift from an audit client?
A. Integrity
B. Objectivity [CORRECT]
C. Confidentiality
D. Competency
Correct Answer: B — Objectivity
Rationale: Accepting a significant gift creates a self-interest threat impairing Objectivity (the principle that auditors
render impartial, unbiased judgments). Integrity concerns honesty/truth; Confidentiality concerns information protection;
Competency concerns skills/knowledge.
Q6. An internal auditor discloses confidential audit findings to a friend outside the organization. Which ethical
principle is violated?
A. Confidentiality [CORRECT]
B. Objectivity
C. Integrity
D. Competency
Correct Answer: A — Confidentiality
Rationale: Sharing confidential information without authorization violates Confidentiality. Objectivity concerns bias;
Integrity concerns truthfulness; Competency concerns skill.
Q7. The IIA Code of Ethics principle of Integrity requires auditors to:
Western Governors University • Confidential OA Study Tool Page 2
, WGU D560 — Internal Auditing I OA (Objective Assessment) 2026 Update | 59 Questions | 100 pts
A. Perform work with honesty, diligence, and responsibility, observing the law and making disclosures
expected thereof [CORRECT]
B. Disclose all material matters known to them that, if not disclosed, may distort the reporting of activities
under review
C. Apply knowledge, skills, and experience needed
D. Be prudent in protecting information
Correct Answer: A — Perform work with honesty, diligence, and responsibility, observing the law and
making disclosures expected thereof
Rationale: Integrity requires honesty, diligence, and lawful responsible behavior. B describes a sub-rule of Integrity
(disclosure of material facts) but A is the broader principle statement. C is Competency; D is Confidentiality.
Q8. Which of the following is an assurance service rather than a consulting service?
A. Performance audit of the procurement function [CORRECT]
B. Training staff on risk management
C. Facilitating a risk-assessment workshop
D. Advising on control design for a new system
Correct Answer: A — Performance audit of the procurement function
Rationale: A performance audit evaluates the function against criteria and provides assurance. B, C, and D are
consulting/advisory activities (training, facilitation, advisory) that do not provide an assurance opinion.
Q9. Which organizational relationship best supports internal audit independence?
A. Functional reporting to the board/audit committee and administrative reporting to senior management
[CORRECT]
B. Functional and administrative reporting both to the CFO
C. Reporting only to the external auditor
D. Reporting to the general counsel
Correct Answer: A — Functional reporting to the board/audit committee and administrative reporting to
senior management
Rationale: Functional reporting to the board/audit committee (approves charter, budget, appointment, salary) plus
administrative reporting to senior management (day-to-day logistics) best supports independence. B impairs
independence (CFO oversees an area being audited); C/D are misaligned reporting lines.
Q10. Which of the following best describes the concept of 'due professional care' in internal auditing?
A. Competence and diligence expected of a reasonably prudent and competent internal auditor
[CORRECT]
B. Guaranteeing that all fraud will be detected
C. Following the external auditor's procedures
D. Performing only those procedures requested by management
Correct Answer: A — Competence and diligence expected of a reasonably prudent and competent
internal auditor
Rationale: Due professional care = competence + diligence expected of a reasonably prudent internal auditor in
similar circumstances. B is impossible (fraud is not guaranteed); C/D mischaracterize the concept.
Q11. The internal audit function's responsibility regarding fraud is to:
A. Have sufficient knowledge to identify fraud indicators and evaluate indicators when encountered
[CORRECT]
B. Investigate all frauds on behalf of management
C. Guarantee fraud prevention
Western Governors University • Confidential OA Study Tool Page 3