Which of the following is most likely the subject of a periodic report from the chief audit executive to the board?
A. A complete, accurate, and comprehensive account of engagement observations and recommendations.
B. Oversight of the coordination between the internal audit activity and independent outside auditors
C. The internal audit activity's purpose, authority, responsibility, and performance relative to plan.
D. Management's assertions regarding the system of internal controls.
Explanation:
This question tests your knowledge of the CAE's reporting responsibilities to the board, which is governed by Standard 2060 of the IPPF. This standard explicitly outlines the required content of such periodic reports, and the correct option directly mirrors its primary requirements.
✔️ Correct Option: C. The internal audit activity's purpose, authority, responsibility, and performance relative to plan.
IIA Standard 2060 explicitly requires the CAE to report periodically on the internal audit activity's purpose, authority, responsibility, and performance relative to its plan. This report also includes progress against the audit plan, resource requirements, and conformance with the Standards, making it the comprehensive subject of the board report.
❌ Incorrect Option: A. A complete, accurate, and comprehensive account of engagement observations and recommendations.
This level of detail is characteristic of individual engagement reports, not a summary periodic report to the board. While the CAE may report significant issues, the board report provides a higher-level, consolidated summary of the internal audit activity's overall performance and significant risk exposures.
❌ Incorrect Option: B. Oversight of the coordination between the internal audit activity and independent outside auditors.
Although coordinating with external auditors is part of the CAE's role, specific oversight of this coordination is not the central subject of the CAE's periodic report to the board under Standard 2060. The focus is on the internal audit activity itself and its performance against the plan.
❌ Incorrect Option: D. Management's assertions regarding the system of internal controls.
Management's assertions are not the subject of the CAE's periodic report. The CAE reports on the internal audit activity's work, performance, and opinion regarding controls, not on management's self-assessments. This distinction is a key element of the internal audit function's independence.
🔧 Reference:
→ IIA Standard 2060 – Reporting to Senior Management and the Board. This standard confirms that the CAE's periodic report must cover the internal audit activity's purpose, authority, and responsibility, and its performance relative to the plan.
Which of the following situations is most critical for the chief audit executive to report to the board?
A. The chief audit executive disagreed with the business unit manager's initial decision to accept a particular risk Management ultimately agreed to address the risk only after discussing the issue with senior management.
B. The internal audit activity was restructured, which resulted in a significant change in responsibilities among audit managers and supervisors for some audits
C. A staff internal auditor had difficulties completing a portion of the audit because management of the area under review was unwilling to cooperate and provide information timely.
D. The resignation of an internal audit manager during the year caused the chief audit executive to defer a number of audit engagements to the following year.
Explanation:
This question evaluates the chief audit executive’s responsibility to communicate significant matters to the board. Issues that materially affect the internal audit activity’s ability to execute its approved plan, fulfill responsibilities, or provide assurance require escalation because they can influence governance and organizational risk oversight.
🟢 Correct Option: D. The resignation of an internal audit manager during the year caused the chief audit executive to defer a number of audit engagements to the following year
Deferring planned audit engagements due to staffing limitations directly affects execution of the approved audit plan and may leave significant risks unaddressed. The board has oversight responsibility for the effectiveness and adequacy of the internal audit function. Therefore, resource constraints that materially impact audit coverage are critical matters requiring communication by the chief audit executive.
🔴 Incorrect options:
A. The chief audit executive disagreed with the business unit manager's initial decision to accept a particular risk. Management ultimately agreed to address the risk only after discussing the issue with senior management.
The issue was ultimately resolved through management discussion and corrective action was accepted. Since the risk concern was addressed appropriately, it would not normally require escalation as a critical board matter.
B. The internal audit activity was restructured, which resulted in a significant change in responsibilities among audit managers and supervisors for some audits
Changes in internal organization or responsibilities may affect operations, but they do not necessarily represent a significant issue requiring board attention unless audit effectiveness or independence is materially impaired.
C. A staff internal auditor had difficulties completing a portion of the audit because management of the area under review was unwilling to cooperate and provide information timely.
Although management cooperation issues are important, a difficulty affecting one auditor or one engagement is generally handled operationally unless the restriction materially limits audit scope or becomes widespread.
🔧 Reference:
⇒ IIA – Standard 2060 Reporting to Senior Management and the Board
Confirms that the CAE reports significant issues, resource limitations, and deviations from approved plans.
⇒ IIA – International Professional Practices Framework (IPPF)
Confirms board reporting responsibilities regarding audit activity performance and resource adequacy.
In which of the following situations has an internal audit of obtained physical evidence?
A. An internal auditor made purchases from several of the organization's retail outlets to evaluate customer service
B. An internal auditor interviewed various employees regarding health and safety issues and recorded their answers
C. An internal auditor obtained the current quarterly financial report and computed changes in deb-to-equity ratio
D. An internal auditor received a signed confirmation regarding the terms of a transaction from an independent attorney
Explanation:
The question tests the internal auditor's ability to classify different types of audit evidence (physical, testimonial, analytical, and documentary) based on the specific audit procedures performed.
✅ A. An internal auditor made purchases from several of the organization's retail outlets to evaluate customer service:
Physical evidence is obtained through direct observation, inspection, or participation in an activity. By physically visiting retail outlets, executing transactions, and directly experiencing or observing the service environment, the auditor is gathering firsthand physical and observational evidence regarding operations.
❌ B. An internal auditor interviewed various employees regarding health and safety issues and recorded their answers:
Interviewing personnel and recording their verbal responses yields testimonial evidence. While valuable for understanding employee perceptions or gathering background facts, statements made by individuals do not constitute objective physical or observational evidence.
❌ C. An internal auditor obtained the current quarterly financial report and computed changes in deb-to-equity ratio:
Computing financial ratios and analyzing fluctuations from data tables constitutes analytical evidence. Analytical procedures involve evaluating relationships among financial and non-financial information rather than examining tangible items or direct physical environments.
❌ D. An internal auditor received a signed confirmation regarding the terms of a transaction from an independent attorney:
A signed confirmation letter from an external third party represents documentary evidence. Documentary evidence consists of written or electronic records, agreements, invoices, and certificates used to verify the factual accuracy of financial account assertions.
🔧 Reference:
→ IIA Performance Standard 2330 on Recording Information outlines that internal auditors must identify sufficient, reliable, relevant, and useful information, categorizing it properly into physical, documentary, testimonial, and analytical classifications to support engagement results.
Which of the following methodologies consists of the internal auditor holding individual meetings with different people, asking them the same questions, and aggregating the results?
A. Facilitated workshops.
B. Surveys.
C. Structured interviews.
D. Elicitation.
Explanation:
This question tests the auditor's understanding of different risk and control assessment methodologies. It focuses on distinguishing structured interviews, which use a standardized question set across multiple individual sessions, from group-based or written response techniques.
✅ Correct Option:
C. Structured interviews
Structured interviews involve the auditor meeting individually with different people and asking each of them the same predetermined set of questions. The responses are then aggregated and analyzed for consistency and trends, allowing the auditor to gather comparable insights across multiple perspectives within the organization in a controlled, consistent manner.
❌ Incorrect options:
A. Facilitated workshops
Facilitated workshops involve bringing multiple participants together in a group setting to discuss risks and controls collectively. This differs from structured interviews, which are conducted individually rather than as a group discussion exercise.
B. Surveys
Surveys typically involve distributing written questionnaires to a broad group of respondents who complete them independently. This method lacks the direct, individual meeting format that characterizes structured interviews between the auditor and respondent.
D. Elicitation
Elicitation is a broader term referring to techniques for drawing out information from individuals, but it isn't a specific standardized methodology involving identical questions asked individually and aggregated. It lacks the structured, repeatable format described.
🔧 Reference:
→ IIA Practice Guide - Assessing Organizational Risk — confirms structured interviews as a methodology for gathering consistent, comparable information through individual sessions.
An internal auditor concluded that delays in an ongoing construction project have cost the organization $10 million to date. Which documents should be included in the audit workpapers to provide sufficient evidence to support the conclusion?
A. Payment and work milestones
B. Pictures from the construction site
C. Initial sprint planning
D. Project internal rate of return
Explanation:
This question addresses the documentation requirements for supporting audit conclusions, specifically regarding construction project delays. To substantiate a $10 million cost conclusion, the auditor needs evidence that directly links the delay to quantifiable financial losses, which is best documented through payment records and work milestone schedules.
✔️ Correct Option: A. Payment and work milestones
This documentation provides the quantitative evidence needed to support a financial conclusion. Payment records show actual costs incurred, while work milestone schedules document the planned versus actual progress, enabling the auditor to quantify delay costs by calculating additional labor, equipment, overhead expenses, and lost productivity directly attributable to the delays .
❌ Incorrect Option: B. Pictures from the construction site
While photographs can document physical conditions and support qualitative observations, they cannot quantify financial losses. Photos show the existence of delays but provide no monetary data to substantiate the $10 million conclusion. The IIA Standards require information to be "sufficient, reliable, relevant, and useful" —visual evidence alone does not meet the quantitative requirement.
❌ Incorrect Option: C. Initial sprint planning
This is a project management artifact unrelated to the specific delay cost calculation. Sprint planning documents establish initial schedules and task breakdowns but do not record actual costs incurred or demonstrate the financial impact of delays, making them insufficient to support a monetary conclusion .
❌ Incorrect Option: D. Project internal rate of return
IRR is a forward-looking investment metric, not a record of historical costs. While IRR may support a business case, it provides no evidential basis for calculating delay-related costs and cannot substantiate the $10 million conclusion because it does not document actual expenditures or schedule performance .
🔧 Reference:
→ IIA Standard 2330 – Documenting Information. This standard requires auditors to document sufficient, reliable, relevant, and useful information to support engagement conclusions and results .
An internal auditor is assessing whether a vendor onboarding procedure is being followed in all business units. The procedure has been centrally designed and depicts activities and validations that must be performed at every step. Which of the following is the most suitable way to compile an internal control questionnaire?
A. Develop statements that are based on the procedure requirements and ask respondents to select yes or no responses
B. Develop open questions that inquire about the appropriateness and efficacy of the procedure
C. Develop closed questions asking managers to describe the onboarding process in detail
D. Develop multiple response questions where a respondent has to identify one correct answer out of four
Explanation:
This question tests understanding of internal control questionnaires (ICQs) and their use in evaluating control compliance. Since the vendor onboarding procedure already contains defined activities and validations, the questionnaire should be structured to verify whether each required control step is consistently followed across business units.
🟢 Correct Option: A. Develop statements that are based on the procedure requirements and ask respondents to select yes or no responses
Internal control questionnaires commonly use structured yes-or-no responses linked directly to established control requirements. This approach allows auditors to efficiently determine whether required procedures are consistently performed and identify exceptions across business units. Using predefined control statements improves standardization, simplifies comparison of responses, and helps detect potential control gaps or noncompliance.
🔴 Incorrect options:
B. Develop open questions that inquire about the appropriateness and efficacy of the procedure
Open questions provide broader opinions and qualitative feedback, but they are less effective for confirming compliance with a predefined procedure because responses may vary significantly and become difficult to compare.
C. Develop closed questions asking managers to describe the onboarding process in detail
Although process descriptions may improve understanding, requiring detailed narrative responses does not efficiently verify whether required control activities are consistently performed.
D. Develop multiple response questions where a respondent has to identify one correct answer out of four
Multiple-choice questions are more appropriate for testing knowledge or training effectiveness. They do not directly determine whether actual control procedures are being followed in practice.
🔧 Reference:
⇒ IIA – International Professional Practices Framework (IPPF) Engagement Planning Guidance
Confirms the use of appropriate techniques for evaluating internal controls.
⇒ IIA – Standard 2240 Engagement Work Program
Confirms that audit procedures should be designed to achieve engagement objectives.
Which of the following is the advantage of using internal control questionnaires (ICQs) as part of a preliminary survey for an engagement?
A. ICQs provide testimonial evidence.
B. ICQs are efficient.
C. ICQs provide tangible evidence to be quantified.
D. ICQs put observations into perspective.
Explanation:
This question tests your understanding of audit tools and techniques used during the preliminary survey phase of an engagement. Internal Control Questionnaires (ICQs) are a standard tool for gathering information about an organization's control environment quickly and systematically, and their primary advantage in this context is efficiency.
✔️ Correct Option: B. ICQs are efficient.
ICQs allow for efficient gathering of information from a large number of respondents at once, whereas interviews would require a much longer time or many more auditors to administer. They are easy to administer and cost-effective, providing a structured way to identify potential control weaknesses during the preliminary survey stage. This efficiency helps the auditor focus engagement planning on key risk areas.
❌ Incorrect Option: A. ICQs provide testimonial evidence.
This is incorrect. Testimonial evidence is obtained through interviews and inquiries with personnel, not from written questionnaires. ICQs provide documentary evidence in the form of completed forms, but the responses themselves are not considered testimonial evidence in the audit evidence framework.
❌ Incorrect Option: C. ICQs provide tangible evidence to be quantified.
This is incorrect. ICQs typically use yes/no or scaled responses and are designed to identify the existence or absence of controls, not to provide quantifiable, tangible evidence. While responses can be aggregated for analysis, the tool itself does not produce the kind of measurable, physical evidence that would be obtained through inspection or observation.
❌ Incorrect Option: D. ICQs put observations into perspective.
This is incorrect and misstates the purpose of ICQs. While ICQs can help structure the auditor's understanding of a process, "putting observations into perspective" is more characteristic of the overall analytical and judgmental process an auditor performs after gathering evidence, not a specific advantage of the ICQ tool itself.
🔧 Reference:
→ IIA Learning System – Internal Control Questionnaires. This official IIA source confirms that internal control questionnaires are "efficient and easy to administer" and allow for "efficient gathering of information from large numbers of respondents at once" during preliminary surveys and control self-assessments.
Which of the following is the most appropriate reason for a chief audit executive to conduct an external assessment more frequently than five years?
A. Significant changes in the organization's accounting policies or procedures would warrant timely analysis and feedback.
B. More frequent external assessments can serve as an equivalent substitute for internal assessments.
C. The parent organization's internal audit activity agreed to perform biennial reciprocal external assessments to provide greater assurance at a reduced cost.
D. A change in senior management or internal audit leadership may change expectations and commitment to conformance
Explanation:
This question tests the auditor's understanding of the IIA's Quality Assurance and Improvement Program requirements, specifically circumstances warranting more frequent external assessments than the standard five-year cycle. It focuses on factors affecting the internal audit activity's conformance and standing within the organization.
✅ Correct Option:
D. A change in senior management or internal audit leadership may change expectations and commitment to conformance
Leadership transitions can shift organizational priorities, support, and commitment toward internal audit standards conformance. A more frequent external assessment helps verify that the internal audit activity continues meeting required standards despite changes in senior management or audit leadership, ensuring sustained quality and stakeholder confidence in the function's performance.
❌ Incorrect options:
A. Significant changes in the organization's accounting policies or procedures would warrant timely analysis and feedback
Accounting policy changes typically require internal audit's attention through engagement planning and risk assessment updates, not necessarily an accelerated external quality assessment of the internal audit activity itself.
B. More frequent external assessments can serve as an equivalent substitute for internal assessments
External and internal assessments serve complementary, not interchangeable, purposes within the Quality Assurance and Improvement Program. One can't substitute for the other regardless of frequency, as both are required components.
C. The parent organization's internal audit activity agreed to perform biennial reciprocal external assessments to provide greater assurance at a reduced cost
Reciprocal arrangements raise independence and objectivity concerns under IIA standards. Cost reduction through reciprocal agreements isn't an appropriate justification for assessment frequency decisions.
🔧 Reference:
→ IIA Standards - Quality Assurance and Improvement Program — confirms external assessments should occur at least once every five years, with more frequent assessments warranted by factors like leadership changes.
An internal audit report includes a recommendation to remove inappropriate user access to an IT application. Which of the following does the recommendation represent?
A. An agreed action adopted by management.
B. A condition-based recommendation as an interim solution to correct a current condition.
C. A cause-based recommendation to prevent inappropriate access being granted again.
D. A management action plan.
Explanation:
This question tests understanding of audit recommendations and the distinction between condition-based and cause-based actions. Condition-based recommendations address an identified issue that currently exists, while cause-based recommendations focus on eliminating the root cause to prevent recurrence.
🟢 Correct Option: B. A condition-based recommendation as an interim solution to correct a current condition
The recommendation to remove inappropriate user access addresses an existing problem that has already been identified. It corrects the current condition by eliminating unauthorized access rights but does not address the underlying reason why the inappropriate access was granted. Therefore, it is considered a condition-based recommendation intended to resolve an immediate issue rather than prevent future occurrences.
🔴 Incorrect options:
A. An agreed action adopted by management
An audit recommendation itself is not automatically an agreed management action. Management must review the recommendation and decide whether to accept, modify, or implement it through a formal action plan.
C. A cause-based recommendation to prevent inappropriate access being granted again
A cause-based recommendation would focus on correcting the underlying reason for the issue, such as weak access approval processes or inadequate segregation of duties. Simply removing access does not prevent the problem from recurring.
D. A management action plan
A management action plan represents management's response describing how and when corrective actions will be implemented. An audit recommendation alone does not constitute a management action plan.
🔧 Reference:
⇒ IIA – Standard 2410 Criteria for Communicating
Confirms that audit communications include observations and recommendations addressing identified conditions.
⇒ IIA – International Professional Practices Framework (IPPF)
Confirms guidance on communicating findings and recommending corrective actions.
An internal auditor wants to examine the intensity of correlation between electricity price and wind speed. Which of the following analytical approaches would be most appropriate for this purpose?
A. A Gantt chart
B. A scatter diagram
C. A RACI chart
D. A SIPOC diagram
Explanation:
The question asks for the best tool to analyze and visualize the strength and direction of a relationship (correlation) between two continuous variables: electricity price and wind speed.
✅ B. A scatter diagram:
A scatter diagram (or scatter plot) is a mathematical tool that plots pairs of numerical data on an $X$ and $Y$ axis to visually demonstrate the relationship or correlation between two variables. By looking at the pattern and tightness of the plotted data points, an auditor can easily determine the intensity and direction (positive, negative, or linear/non-linear) of the correlation.
❌ A. A Gantt chart:
A Gantt chart is a project management tool used to illustrate a project schedule. It displays timelines, start and end dates of activities, and dependencies between tasks over time, which has no application for calculating statistical correlation between data sets.
❌ C. A RACI chart:
A RACI chart (Responsible, Accountable, Consulted, Informed) is a responsibility assignment matrix used in organizational governance. It clarifies roles and responsibilities for business tasks, milestones, or decisions across different organizational positions.
❌ D. A SIPOC diagram:
A SIPOC diagram (Suppliers, Inputs, Process, Outputs, Customers) is a high-level process mapping tool used in Six Sigma and process improvements. It summarizes the inputs and outputs of one or more processes but cannot measure or analyze numeric correlation.
🔧 Reference:
→ IIA Guidance on Data Analytics and Root Cause Analysis Tools highlights scatter diagrams as a fundamental visual analytics tool used by internal auditors to identify and evaluate patterns, dependencies, and statistical correlations between variables during risk assessment or testing phases.
An internal auditor discovered a control weakness that needs to be communicated to management. Which of the following is the best method for first communicating the weakness?
A. Draft report, to be reviewed by management just prior to final report issuance.
B. Preliminary observation document, discussed during the engagement.
C. Final report, after review by audit management.
D. Verbal communication during the engagement, followed by the final report issuance.
Explanation:
This question tests the auditor's understanding of best practices for timely communication of control weaknesses during an audit engagement. It emphasizes the value of addressing issues early, allowing management to respond and clarify before formal reporting stages.
✅ Correct Option:
B. Preliminary observation document, discussed during the engagement
Communicating a preliminary observation document during the engagement allows management to review and discuss the weakness promptly, while details are fresh and context is available. This early dialogue supports accuracy, allows management to provide feedback or corrective action plans, and prevents surprises at later reporting stages.
❌ Incorrect options:
A. Draft report, to be reviewed by management just prior to final report issuance
Waiting until the draft report stage delays communication significantly, reducing management's opportunity to respond early. This approach increases the risk of unresolved disagreements surfacing late in the process, close to final reporting.
C. Final report, after review by audit management
Communicating only through the final report is far too late, as management has no opportunity for preliminary discussion or clarification. This approach removes the collaborative dialogue needed before formal documentation.
D. Verbal communication during the engagement, followed by the final report issuance
While verbal communication during the engagement is helpful, it lacks the documented, structured format of a preliminary observation document, which provides clearer reference and accountability for both parties involved.
🔧 Reference:
→ IIA Standards - Communicating Results — confirms internal auditors should communicate engagement results, including timely preliminary observations, to support effective resolution.
An internal auditor wants to determine whether employees are complying with the information security policy, which prohibits leaving sensitive information on employee desks overnight. The auditor checked a sample of 90 desks and found eight that contained sensitive information. How should this observation be reported, if the organization tolerates 4 percent noncompliance?
A. The matter does not need to be reported, because the noncompliant findings fall within the acceptable tolerance limit.
B. The deviations are within the acceptable tolerance limit, so the matter only needs to be reported to the information security manager.
C. The incidents of noncompliance fall outside the acceptable tolerance limit and require immediate corrective action, as opposed to reporting.
D. The incidents of noncompliance exceed the tolerance level and should be included in the final engagement report.
Explanation:
This question tests your understanding of how to evaluate and report audit findings against established tolerance levels, which is a key concept in engagement reporting under the IIA Standards. The auditor found a noncompliance rate of approximately 8.9% (8 out of 90 desks), which exceeds the organization's tolerance level of 4%. Findings that exceed acceptable tolerance limits must be reported to the appropriate levels of management, as they represent a significant deviation from policy that requires attention.
✔️ Correct Option: D. The incidents of noncompliance exceed the tolerance level and should be included in the final engagement report.
The observed noncompliance rate of 8.9% (8/90) clearly exceeds the 4% tolerance level. This constitutes a significant finding that must be reported in the final engagement communication. The IIA Standards require that significant observations be included in final reports to ensure management and the board are aware of issues that could impact the organization's risk profile.
❌ Incorrect Option: A. The matter does not need to be reported, because the noncompliant findings fall within the acceptable tolerance limit.
This is incorrect because the noncompliance rate (8.9%) exceeds the 4% tolerance limit, not falls within it. Even if it were within tolerance, the IIA Standards generally require reporting of all significant observations, regardless of tolerance levels.
❌ Incorrect Option: B. The deviations are within the acceptable tolerance limit, so the matter only needs to be reported to the information security manager.
This option contains two errors: the deviations exceed the tolerance limit, and even if they were within tolerance, the IIA Standards require appropriate reporting to ensure management is informed of risks, not limiting communication to a single manager without justification.
❌ Incorrect Option: C. The incidents of noncompliance fall outside the acceptable tolerance limit and require immediate corrective action, as opposed to reporting.
While immediate corrective action may be appropriate, it does not replace the need for formal reporting. The IIA Standards require that significant observations be communicated in final reports; corrective action and reporting are complementary, not mutually exclusive.
🔧 Reference:
→ IIA Standard 2440 – Disseminating Results. This standard requires that the chief audit executive communicates results to the appropriate parties, which includes reporting significant findings in final engagement reports.
→ IIA Practice Guide: Audit Report Writing. This guide emphasizes that findings exceeding acceptable tolerance levels should be included in final reports to ensure management has complete information for decision-making.
| Page 4 out of 60 Pages |
| 123456789101112131415161718 |
| IIA-CIA-Part2 Practice Test Home |
Real-World Scenario Mastery: Our IIA-CIA-Part2 practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before Certified Internal Auditor Part 2 - Internal Audit Engagement exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive IIA-CIA-Part2 practice exam questions pool covering all topics, the real exam feels like just another practice session.