An internal auditor is testing the success of the IT support department in meeting the service levels guaranteed to small, medium and large customers. The customer's size classification is based on its annual expenditures with the organization and the nature and extent of services it receives. Which of the following sampling techniques would be the most suitable to select customers for this test?
A. Interval sampling
B. Cluster sampling
C. Stop-and-go sampling
D. Stratified sampling
Explanation:
This question tests your understanding of sampling techniques used in internal audit engagements, specifically when the population has distinct subgroups. The customer base is already divided into three size categories (small, medium, and large) based on expenditures and services, making stratified sampling the most appropriate method to ensure each category is adequately represented in the test.
✔️ Correct Option: D. Stratified sampling
Stratified sampling divides the population into distinct, non-overlapping subgroups (strata) based on a key characteristic—here, customer size. This ensures that each customer category is proportionally or equally represented, allowing the auditor to draw valid conclusions about service level performance across all groups.
❌ Incorrect Option: A. Interval sampling
Interval sampling selects items at fixed intervals from a population. This method does not account for the natural grouping of customers by size. It could overrepresent or underrepresent certain categories, leading to biased conclusions about service level compliance for specific customer segments.
❌ Incorrect Option: B. Cluster sampling
Cluster sampling divides the population into groups and randomly selects entire clusters for testing. This method is inefficient here because customers are already classified by size, and testing whole clusters would not guarantee balanced representation across all three categories.
❌ Incorrect Option: C. Stop-and-go sampling
Stop-and-go sampling is used for compliance testing when the auditor expects a very low error rate. It allows early termination of testing if no errors are found. This technique is not designed to ensure proportional representation of subgroups and is unsuitable for measuring service levels across distinct customer classifications.
🔧 Reference:
→ IIA Global – Practice Guide: Audit Sampling
This guide explains that stratified sampling is appropriate when the population is divided into subpopulations with different characteristics, ensuring that each stratum is adequately represented.
→ IIA Global – CIA Part 2 Exam Syllabus (Topic on Sampling Methods)
The syllabus includes "sampling methodologies" under engagement procedures, confirming that auditors must know when to apply different sampling approaches based on population characteristics.
The audit plan requires a review of the testing procedures used in pre-production of a large information system prior to its live launch. If the chief audit executive (CAE) is uncertain that the current audit team has all the required knowledge to conduct the engagement, which of the following would be the most appropriate course of action for the CAE to take to preserve independence?
A. Contract with the software vendor to provide an appropriate resource.
B. Ask for a knowledgeable resource from the IT department.
C. Make use of an external service provider.
D. Request audit resources through the external auditor.
Explanation:
This question addresses the chief audit executive's (CAE) responsibility to ensure the internal audit activity has the necessary competence while preserving independence. When the in-house team lacks specific expertise required for an engagement, engaging an external service provider is a standard and appropriate solution that does not compromise the audit function's objectivity, provided proper oversight is maintained .
✔️ Correct Option: C. Make use of an external service provider.
Engaging an independent external service provider to supply the missing technical expertise is a common and effective approach . This option preserves the CAE's independence and objectivity because the external provider reports to the CAE and does not take on a management role, allowing the CAE to maintain strategic oversight and responsibility for the engagement's results .
❌ Incorrect Option: A. Contract with the software vendor to provide an appropriate resource.
Engaging the software vendor itself creates a significant conflict of interest and impairs objectivity. The vendor designed and implemented the system under review, so they cannot provide an independent, unbiased assessment of its own controls. This arrangement would violate fundamental principles of audit independence.
❌ Incorrect Option: B. Ask for a knowledgeable resource from the IT department.
Borrowing a staff member from the IT department directly violates the IIA's Standard 1130, which prohibits internal auditors from assessing operations for which they were previously responsible . This resource would be auditing their own area, creating an unacceptable impairment to objectivity and independence.
❌ Incorrect Option: D. Request audit resources through the external auditor.
While coordination with external auditors is encouraged, relying on them for resources to staff an engagement can create a "managed audit" arrangement. According to the IIA's Standard 2050, the CAE retains full responsibility for internal audit conclusions and opinions, and while the external auditor's work might be considered, using them as direct resources requires careful oversight to ensure the CAE's independence and the engagement's purpose are not compromised .
🔧 Reference:
→ IIA Global – Standard 2070: External Service Provider and Organizational Responsibility for Internal Auditing
This standard clarifies that when an external service provider is used, the organization retains full responsibility for directing, managing, and overseeing the internal audit activity, and the CAE remains accountable for the conclusions and opinions reached.
An engagement work program o of greatest value to audit management when which of the following is true?
A. The work program provides more detailed support for the audit report
B. The work program helps determined the required amount of audit resources
C. The work program helps ensure tie achievement of the engagement objectives
D. The work program assists the auditor n developing and managing audit tests
Explanation:
This question tests understanding of the purpose and value of an engagement work program in internal auditing. A work program acts as a structured plan that guides audit activities, procedures, and testing. Its primary purpose is to ensure audit work remains aligned with objectives and that the engagement effectively addresses identified risks.
🟢 Correct Option: C. The work program helps ensure the achievement of the engagement objectives
An engagement work program provides a systematic framework for conducting audit procedures that directly support the objectives of the engagement. It identifies required tasks, testing procedures, and areas of focus so that auditors perform sufficient work to address risks and reach valid conclusions. This alignment makes the work program most valuable to audit management because it supports successful completion of the engagement purpose.
🔴 Incorrect options:
A. The work program provides more detailed support for the audit report
Although work programs contribute supporting documentation for audit conclusions, their primary purpose is not to provide detailed support for the report. Supporting evidence mainly comes from workpapers and audit findings developed during fieldwork.
B. The work program helps determine the required amount of audit resources
Resource requirements can be estimated during planning activities, but determining staffing needs is not the main value of the work program. Its focus is directing engagement activities rather than primarily allocating resources.
D. The work program assists the auditor in developing and managing audit tests
A work program does help organize audit procedures and testing activities, but this is a supporting function. Its broader and more important purpose is ensuring that engagement objectives are achieved.
🔧 Reference:
⇒ IIA – Standard 2240 Engagement Work Program
Confirms that work programs must achieve engagement objectives.
⇒ IIA – International Professional Practices Framework (IPPF)
Confirms requirements for planning and executing audit engagements.
Which of the following situations would justify the removal of a finding from the final audit report?
A. Management disagrees with the report findings and conclusions in their responses.
B. Management has already satisfactorily completed the recommended corrective action.
C. Management has provided additional information that contradicts the findings.
D. Management believes that the finding is insignificant and unfairly included in the report.
Explanation:
The question assesses the conditions under which an internal audit finding can be validly removed from a final report. It tests the auditor's commitment to objective truth, accuracy, and evidence over administrative disagreements or post-audit remediation.
✅ C. Management has provided additional information that contradicts the findings:
If management provides new, reliable information or documentation that directly refutes the auditor's initial observations, the finding loses its evidentiary support and is no longer valid. Internal audit communications must always be accurate and objective, justifying the immediate removal of any finding proven incorrect by subsequent evidence.
❌ A. Management disagrees with the report findings and conclusions in their responses:
Management's disagreement alone does not invalidate a factually correct and well-supported audit finding. When a difference of opinion exists regarding risk severity or conclusions, the standard professional practice is to include management's formal dissenting response in the final report alongside internal audit’s verified position.
❌ B. Management has already satisfactorily completed the recommended corrective action:
Completing corrective action before the final report is published does not erase the historical fact that the deficiency existed during the review period. The appropriate approach is to keep the finding in the report to document the control environment accurately, while noting that management has already resolved it.
❌ D. Management believes that the finding is insignificant and unfairly included in the report:
Management's subjective belief regarding the fairness or insignificance of a finding is not a valid reason for removal. The chief audit executive and the audit team retain independent professional judgment to determine which control vulnerabilities pose a material risk and warrant inclusion in final communications.
🔧 Reference:
→ IIA Performance Standard 2410 on Criteria for Communicating confirms that final engagement communications must be accurate, objective, and clear, meaning they must be revised or retracted if the underlying evidence supporting a finding is discredited.
An internal auditor e assessing the design of a control and has identified a potential significant weakness. The auditor shared his concern with management however management does not agree that the weakness is significant. What should the internet auditor do next?
A. Perform additional audit work to better articulate the risk
B. Report the finding that management has accepted a level of risk that is unacceptable.
C. Proceed to testing how effectively the control is opening
D. Because the design weakness has been identified no additional audit work is needed
Explanation:
This question tests the auditor's understanding of proper escalation procedures when there's disagreement with management over a control weakness. It focuses on the principle that auditors must build a well-supported case before reporting significant risk disagreements, rather than jumping to conclusions or halting work prematurely.
✅ Correct Option:
A. Perform additional audit work to better articulate the risk
When management disagrees on the significance of a weakness, the auditor should gather further evidence to strengthen and clarify the risk assessment. This additional work helps build a more defensible, well-supported position, ensuring conclusions are based on sufficient evidence before escalating disagreements or finalizing the audit finding.
❌ Incorrect options:
B. Report the finding that management has accepted a level of risk that is unacceptable
Reporting this conclusion is premature without first strengthening the risk articulation through additional work. Jumping straight to this judgment risks an unsupported or weak finding, undermining the credibility of the audit conclusion and the escalation process.
C. Proceed to testing how effectively the control is operating
Moving to operating effectiveness testing skips resolving the disagreement over design adequacy. Testing an inadequately designed control's operation provides limited value if the design itself remains contested and unresolved between the auditor and management.
D. Because the design weakness has been identified no additional audit work is needed
This assumes the initial assessment is conclusive despite management's disagreement. Stopping audit work here ignores the need to substantiate findings adequately, especially when the significance of the weakness is being challenged by management.
🔧 Reference:
→ IIA Standards - Communicating Results — confirms auditors must gather sufficient, reliable evidence to support conclusions before communicating significant findings, especially when disputed by management.
An internal auditor plans to conduct a walk-through to evaluate the control design of a process. Which of the following techniques is the auditor most likely to use?
A. Observation and inspection.
B. Inquiry and observation.
C. Inspection and reperformance.
D. Inquiry and reperformance.
Explanation:
The question tests the primary techniques used in a walkthrough to evaluate control design. A walkthrough traces a transaction or process from initiation to completion to confirm the auditor’s understanding of how controls are intended to operate.
✅ Correct Option: B. Inquiry and observation.
During a walkthrough, the auditor primarily uses inquiry (asking process owners about steps and controls) and observation (watching the process in action). This combination effectively reveals whether the design includes necessary controls and how they function in practice.
❌ Incorrect options:
A. Observation and inspection.
Observation and inspection are useful but insufficient alone for a full walkthrough, as they do not capture the reasoning or explanations behind process steps.
C. Inspection and reperformance.
Inspection and reperformance are more relevant for testing the operating effectiveness of controls rather than initially evaluating design through a walkthrough.
D. Inquiry and reperformance.
Reperformance (independently executing control procedures) goes beyond design evaluation and is typically used later for substantive testing of operating effectiveness.
🔧 Reference:
→ IIA Global Internal Audit Standards – Performing the Engagement
Walkthroughs rely heavily on inquiry and observation to understand and evaluate control design.
Which of the following internal audit procedures commonly involves sampling?
A. Confirmation and financial statement analysis
B. Reperformance and inspection
C. Vouching and tracing
D. Trend analysis and benchmarking
Explanation:
This question tests your understanding of audit procedures and when sampling is typically applied. Vouching and tracing are both substantive procedures that involve selecting a subset of transactions or documents to verify their accuracy, validity, or completeness, making sampling an inherent and necessary part of these techniques.
✔️ Correct Option: C. Vouching and tracing
Vouching involves taking a sample of recorded transactions and obtaining source documents to verify they actually occurred (existence assertion). Tracing involves taking a sample of source documents and ensuring transactions have been properly recorded in journals and ledgers (completeness assertion). Both require sampling when populations are large.
❌ Incorrect Option: A. Confirmation and financial statement analysis
Confirmation involves sending requests to third parties to verify account balances—this may or may not involve sampling depending on population size. Financial statement analysis is an analytical procedure that does not typically use sampling; it reviews entire financial data sets for trends and relationships.
❌ Incorrect Option: B. Reperformance and inspection
Reperformance involves independently re-executing a control or calculation to verify accuracy, typically done on individual high-risk items. Inspection involves examining documents and records—while it can involve sampling, neither procedure inherently requires it as a defining characteristic.
❌ Incorrect Option: D. Trend analysis and benchmarking
Both are analytical procedures that compare data across periods or against industry standards to identify unusual patterns. These procedures do not involve sampling because they typically analyze entire data sets rather than selecting a subset of transactions.
🔧 Reference:
→ IIA Global – Standards and Guidance on Audit Evidence
The IIA framework confirms that sampling is used when testing entire populations is impractical, particularly for procedures like vouching and tracing that examine individual transactions.
Which of the following reasonably represents best practices regarding what should be the level of internal audit resource investment in monitoring and following up on engagement outcomes?
A. Limited resources should be employed since the actual engagement is already completed and the onus of corrective actions rests with management
B. No resources should be exclusively deployed for that at all rather it should be planned as part of future engagements in the same area
C. Resources should only be provided towards this if doing so does not result in depletion of resources for new engagements planned in the current period
D. Resources should be allocated to this without conditions as long as doing so meets the expectations of management and the judgment of the chief audit executive.
Explanation:
This question tests understanding of internal audit follow-up responsibilities after engagement completion. Monitoring and follow-up are important parts of the audit process because they help determine whether management has effectively implemented corrective actions and whether identified risks have been properly addressed.
🟢 Correct Option: D. Resources should be allocated to this without conditions as long as doing so meets the expectations of management and the judgment of the chief audit executive
The chief audit executive is responsible for establishing an effective follow-up process and determining the level of resources required. Appropriate resources should be assigned based on management expectations, risk significance, and professional judgment. Follow-up activities help ensure agreed corrective actions are implemented and that unresolved risks receive appropriate attention rather than being overlooked after the engagement concludes.
🔴 Incorrect options:
A. Limited resources should be employed since the actual engagement is already completed and the onus of corrective actions rests with management
Although management is responsible for implementing corrective actions, internal audit maintains responsibility for monitoring outcomes. Restricting resources simply because fieldwork ended may reduce the effectiveness of the audit process and leave significant issues unresolved.
B. No resources should be exclusively deployed for that at all rather it should be planned as part of future engagements in the same area
Waiting for future engagements may delay verification of corrective actions and leave important risks unaddressed. Follow-up activities should occur according to organizational needs rather than only during future audit work.
C. Resources should only be provided towards this if doing so does not result in depletion of resources for new engagements planned in the current period
This approach improperly places new engagements above follow-up responsibilities. Resource allocation should depend on risk and audit priorities, not solely on preserving capacity for planned future engagements.
🔧 Reference:
⇒ IIA – Standard 2500 Monitoring Progress
Confirms that the chief audit executive must establish a process to monitor engagement outcomes and corrective actions.
⇒ IIA – International Professional Practices Framework (IPPF)
Confirms responsibilities related to monitoring and follow-up activities.
Which of the following best describes the four components of a balanced scorecard?
A. Customers, innovation, growth, and internal processes.
B. Business objectives, critical success factors, innovation, and growth.
C. Customers, support, critical success factors, and learning.
D. Financial measures, learning and growth, customers, and internal processes.
Explanation:
This question tests the auditor's knowledge of the balanced scorecard framework, a strategic performance management tool. It requires identifying the four standard perspectives that organizations use to measure performance beyond traditional financial metrics alone.
✅ Correct Option:
D. Financial measures, learning and growth, customers, and internal processes
The balanced scorecard framework, developed by Kaplan and Norton, organizes organizational performance into four perspectives: financial, customer, internal business processes, and learning and growth. This structure ensures organizations track both financial outcomes and the underlying drivers of long-term success, including innovation, employee development, and operational efficiency.
❌ Incorrect options:
A. Customers, innovation, growth, and internal processes
This option omits the financial perspective, which is a core component of the balanced scorecard framework. It also incorrectly separates innovation from growth rather than combining them as "learning and growth," misrepresenting the standard model structure.
B. Business objectives, critical success factors, innovation, and growth
These terms don't represent the four standard balanced scorecard perspectives. Business objectives and critical success factors are planning concepts used within scorecard development, not the framework's core measurement categories themselves.
C. Customers, support, critical success factors, and learning
This combination misrepresents the framework, as "support" and "critical success factors" aren't recognized balanced scorecard perspectives. It also omits the financial and internal process components essential to the standard model.
🔧 Reference:
→ IIA Internal Audit and Performance Management — confirms the balanced scorecard's four perspectives used to evaluate organizational performance comprehensively.
While planning for an accounts payable audit an internal auditor performs an entity level controls analysis. Which of the following statements is true regarding me approach used by the auditor?
A. It enables the auditor to identify the inherent risks to the effective operation of accounts payable process controls.
B. It enables the auditor to understand the framework of the activities and associated accounts payable subprocesses
C. it enables the auditor to understand the accounts payable process and its flow, including key steps and systems.
D. It enables the auditor to categorize the population of transactions within the accounts payable process
Explanation:
This question evaluates your understanding of the difference between entity-level and process-level controls in an audit context. Entity-level controls are broad, top-down controls that apply to the entire organization, such as governance, ethical culture, and oversight structures. Analyzing them helps the auditor understand the overall framework within which specific activities like accounts payable operate.
✔️ Correct Option: B. It enables the auditor to understand the framework of the activities and associated accounts payable subprocesses.
Entity-level controls provide the foundational governance and control environment that influences all other controls. Understanding this broad framework allows the auditor to see how these high-level controls impact and shape the design and effectiveness of the subprocesses within the accounts payable process.
❌ Incorrect Option: A. It enables the auditor to identify the inherent risks to the effective operation of accounts payable process controls.
Identifying inherent risks for a specific process, like accounts payable, is a function of a process-level risk assessment, not an entity-level controls analysis. Entity-level analysis does not directly identify these specific transaction-level risks.
❌ Incorrect Option: C. It enables the auditor to understand the accounts payable process and its flow, including key steps and systems.
Understanding the specific flow, key steps, and systems of the accounts payable process is the objective of documenting the process-level controls, not analyzing entity-level controls. This option describes mapping the workflow of the activity itself.
❌ Incorrect Option: D. It enables the auditor to categorize the population of transactions within the accounts payable process.
Categorizing transaction populations is part of sampling or data analytics at the activity level. This is not a purpose or function of performing an analysis of high-level, enterprise-wide controls.
🔧 Reference:
→ IIA Standard 2100 – Nature of Work
This standard emphasizes that the internal audit activity must evaluate and contribute to the improvement of governance, risk management, and control processes using a systematic and disciplined approach. Understanding entity-level controls is the first step in this evaluation.
Which of the following attribute sampling methods would be most appropriate to use to measure the total misstatement posted to an accounts payable ledger?
A. Stop-or-go sampling
B. Probability to proportional size sampling
C. Classical variable sampling
D. Discovery sampling
Explanation:
The question tests knowledge of sampling methods for estimating the total (projected) monetary misstatement in an account balance, such as accounts payable.
✅ Correct Option: C. Classical variable sampling
Classical variable sampling (e.g., mean-per-unit or difference estimation) is designed to estimate the total dollar amount of misstatement in a population. It is the most appropriate method when the objective is to measure the overall monetary impact posted to the ledger.
❌ Incorrect options:
A. Stop-or-go sampling
Stop-or-go (sequential) sampling is an attribute sampling technique used to determine if the error rate is below a tolerable level. It is not suitable for estimating total monetary misstatement.
B. Probability proportional to size sampling
PPS (monetary unit sampling) is effective for detecting overstatements and projecting misstatements but is a variables sampling method focused on dollar amounts rather than pure attribute sampling.
D. Discovery sampling
Discovery sampling is used to find at least one instance of a rare event (e.g., fraud). It does not measure or project the total misstatement amount.
🔧 Reference:
→ IIA Global Internal Audit Standards & Sampling Guidance
Classical variable sampling is recommended for estimating total monetary misstatements in account balances.
An internal auditor has been assigned to facilitate a risk and control self-assessment for the finance group. Which of the following is the most appropriate role that she should assume when facilitating the workshop?
A. Express an opinion on the participants' inputs and conclusions as the assessment progresses.
B. Provide appropriate techniques and guidelines on how the exercise should be undertaken.
C. Evaluate and report on all issues that may be uncovered during the exercise.
D. Screen and vet participants so that the most appropriate candidates are selected to participate in the exercise.
Explanation:
This question tests understanding of the internal auditor’s role in a Risk and Control Self-Assessment (RCSA). When facilitating an RCSA workshop, the auditor acts as a neutral facilitator who supports the process without influencing outcomes. The objective is to help participants identify and assess risks and controls independently.
🟢 Correct Option: B. Provide appropriate techniques and guidelines on how the exercise should be undertaken
During a risk and control self-assessment workshop, the auditor's role is to guide the process by providing structure, techniques, and facilitation support. The auditor helps participants understand methods for identifying risks, evaluating controls, and documenting outcomes. Maintaining neutrality is essential because participants should develop their own conclusions without influence from the auditor.
🔴 Incorrect options:
A. Express an opinion on the participants' inputs and conclusions as the assessment progresses
Providing opinions during the exercise can influence participants and compromise the auditor's objectivity. The facilitator should avoid directing conclusions and instead support independent discussion and assessment.
C. Evaluate and report on all issues that may be uncovered during the exercise
The purpose of facilitation is to guide the self-assessment process, not perform an independent audit evaluation. Issues identified may later become subjects for audit consideration, but evaluating all findings is not the facilitator's primary role.
D. Screen and vet participants so that the most appropriate candidates are selected to participate in the exercise
Participant selection is generally a management responsibility. The auditor may provide suggestions if needed, but selecting or screening participants is not the main role of a workshop facilitator.
🔧 Reference:
⇒ IIA – Control Self-Assessment (CSA) Guidance
Confirms that internal auditors facilitating CSA activities should maintain neutrality and guide the process.
⇒ IIA – International Professional Practices Framework (IPPF)
Confirms objectivity and advisory responsibilities of internal auditors.
| Page 2 out of 60 Pages |
| 123456789101112131415161718 |
| IIA-CIA-Part2 Practice Test Home |
Real-World Scenario Mastery: Our IIA-CIA-Part2 practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before Certified Internal Auditor Part 2 - Internal Audit Engagement exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive IIA-CIA-Part2 practice exam questions pool covering all topics, the real exam feels like just another practice session.