An organization facing financial hardships is planning to reduce its internal audit function size without a reduction in workload. The organization plans to aid internal auditors by providing a generative artificial intelligence application that will process written responses from the activity under review to identify high-risk areas on which the remaining auditors will concentrate. Which of the following would be the most significant concern in this process?
A. Slight variations in answers can result in very different risk assessments
B. Generative artificial intelligence cannot make inferences out of free text responses
C. Replacing auditor judgment with machine judgment is contrary to the Global Internal Audit Standards
D. Poor acceptance of the new system by the activity under review will impact engagement outcomes
Explanation:
This question assesses the most significant risk when integrating generative AI into internal audit processes to compensate for staff reductions. The core issue is maintaining the fundamental principles of the internal audit profession when technology is used to automate critical analysis. While several options present valid concerns, the most severe risk is the fundamental erosion of professional judgment, which is a cornerstone of the Global Internal Audit Standards.
✔️ Correct Option:
C. Replacing auditor judgment with machine judgment is contrary to the Global Internal Audit Standards
This is the most significant concern because the profession's standards are built on the principle of reasonable assurance, which depends on professional judgment and skepticism. The Global Internal Audit Standards emphasize performance, which relies on human interpretation and oversight. The ethical use of AI in internal audit requires that technology enhances, not replaces, human judgment to maintain objectivity. All guidance on AI in internal audit stresses that AI tools should support auditors, not make autonomous decisions, to uphold audit independence and credibility.
❌ Incorrect Options:
A. Slight variations in answers can result in very different risk assessments
While this is a recognized risk of using generative AI, particularly with free-text prompts, it is a technical challenge of implementation. This issue can be managed through careful prompt engineering, verification, and testing of results. It is a significant concern but does not undermine the foundational principles of the audit profession as fundamentally as option C does.
B. Generative artificial intelligence cannot make inferences out of free text responses
This is factually incorrect. Generative AI models are specifically designed to process natural language and identify patterns, which is the exact capability the organization intends to leverage. The inability to process free text is not a limitation of the technology, making this a poor choice.
D. Poor acceptance of the new system by the activity under review will impact engagement outcomes
While stakeholder engagement is vital for audit performance, lack of acceptance is a change management issue that can be addressed through training and communication. This is a practical, manageable challenge and does not pose the same existential risk to the auditor's professional role and the validity of the audit as replacing human judgment.
🔧 Reference:
→ The IIA's Artificial Intelligence Auditing Framework: Provides structured guidance that emphasizes the need for internal auditors to audit AI risks and maintain reasonable assurance, which depends on human judgment, objectivity, and transparency.
An organization invests excess short-term cash in trading securities Which of the following actions should an internal auditor take to test the valuation of those securities
A. Use the equity method to recalculate the investment carrying value
B. Confirm the securities held by the broker.
C. Perform a calculation of premium or discount amortization.
D. Compare the carrying value with current market quotations
Explanation:
This question tests the auditor's knowledge of substantive testing procedures for financial instruments. Specifically, it requires identifying the appropriate audit procedure to verify the valuation of trading securities, which must be reported at fair value under standard accounting frameworks.
✅ Correct Option:
D. Compare the carrying value with current market quotations
Trading securities are short-term investments held for active buying and selling, and accounting standards mandate that they be recorded at fair value on the balance sheet. To test their valuation, the auditor must independently verify their year-end market prices by comparing the recorded carrying value against active, publicly available current market quotations or official exchange listings.
❌ Incorrect options:
A. Use the equity method to recalculate the investment carrying value
The equity method is used only when an investor exerts significant influence over an investee, typically holding between 20% to 50% of the voting stock. Short-term trading securities represent minor, passive investments, making the equity method completely inapplicable for their valuation.
B. Confirm the securities held by the broker.
Sending a confirmation to an external broker is an effective audit procedure, but it primarily tests the assertions of existence and rights/obligations. It proves that the organization actually owns the investments, not that the market valuation recorded in the ledger is accurate.
C. Perform a calculation of premium or discount amortization.
Amortization of premiums or discounts applies strictly to held-to-maturity debt securities, where the investment is held long-term to collect contractual cash flows. Trading securities are focused on short-term capital gains, so amortized cost tracking is not used.
🔧 Reference:
→ The IIA Global Financial Auditing Guidance confirms that substantive testing for the valuation of liquid investment securities requires comparing recorded book values to independent third-party market price feeds.
Which of the following actions should the chief audit executive take when senior management decides to accept risks by choosing to do business with a questionable vendor?
A. Persuade senior management to take appropriate action.
B. Cancel issuing the engagement report due to the assumed risks.
C. Accept senior management’s assumption of the risks.
D. Discuss the issue with the board for them to take appropriate action.
Explanation:
This question tests the chief audit executive’s (CAE) responsibility when management accepts a level of risk that may be unacceptable to the organization. According to IIA guidance, if the CAE believes management has accepted a risk beyond the organization's risk tolerance, the matter should be escalated to the board for resolution.
🟢 Correct Option:
D. Discuss the issue with the board for them to take appropriate action.
When senior management accepts a risk that the CAE believes exceeds the organization’s risk appetite or tolerance, the CAE should elevate the issue to the board. The board provides oversight of risk management and governance activities. Escalation ensures that significant risks receive appropriate review and allows the board to determine whether the accepted risk aligns with organizational objectives.
🔴 Incorrect options:
A. Persuade senior management to take appropriate action.
The CAE may discuss concerns with management, but persuasion alone is not the required action if management still chooses to accept an unacceptable level of risk.
B. Cancel issuing the engagement report due to the assumed risks.
The presence of accepted risk does not justify canceling or withholding an audit report. Significant findings and concerns should still be communicated appropriately.
C. Accept senior management’s assumption of the risks.
The CAE should not automatically accept management’s decision if the risk level appears to exceed organizational tolerance. Significant concerns require escalation when necessary.
🔧 Reference:
⇒ Global Internal Audit Standards – Escalating Risk Acceptance
Confirms that the CAE should discuss risk matters with the board when management accepts unacceptable risks.
⇒ IIA Position Paper – The Three Lines Model
Confirms the board’s oversight role in governance and risk management activities.
Which is the most appropriate evaluation criterion regarding the quality of audit engagement workpapers?
A. Every workpaper should provide reasonable evidence of work conducted.
B. Every workpaper should result in appropriately worded audit findings.
C. Every workpaper should include a conclusion regarding the likelihood of fraud.
D. Every workpaper should be approved by the engagement client.
Explanation:
This question tests the basic quality standard for audit workpapers. Good workpapers should clearly show what work was performed, support the conclusions reached, and allow another reviewer to understand the audit trail. The main criterion is whether the documentation provides sufficient evidence of the procedures performed.
✔️ Correct Option:
A. Every workpaper should provide reasonable evidence of work conducted.
This is the most appropriate criterion because audit workpapers must document the procedures performed and support the observations and conclusions reached. A strong workpaper should show enough detail for a reviewer to understand what was done, when it was done, and what evidence supports the result. That is the core measure of workpaper quality.
❌ Incorrect options:
B. Every workpaper should result in appropriately worded audit findings.
Workpapers support findings, but not every workpaper must produce a finding. Some workpapers simply document background, planning, sampling, or test results without leading to a formal audit issue.
C. Every workpaper should include a conclusion regarding the likelihood of fraud.
Fraud evaluation is important when relevant, but it is not required in every workpaper. Many workpapers cover routine controls or operational testing and do not need a fraud conclusion.
D. Every workpaper should be approved by the engagement client.
Client approval is not the standard for workpaper quality. Workpapers are prepared for the internal audit function and reviewed by audit management, not validated by the client as a rule.
🔧 Reference:
→ The IIA — Global Internal Audit Standards — confirms the official internal audit standards framework.
During the review of an organization's retail fraud deterrence program, an employee mentions that an expensive fraud surveillance information system is rarely used. The internal auditor concludes that additional staff are required to properly utilize the system to its full potential. According to IIA guidance, which criteria for evidence is most lacking to reach this conclusion?
A. Sufficiency.
B. Reliability.
C. Relevancy.
D. Usefulness.
Explanation:
This question tests understanding of the evidence criteria under IIA guidance — sufficiency, reliability, relevancy, and usefulness — and which one is missing when a conclusion is drawn from a single, uncorroborated source. It focuses on identifying gaps in the evidence-gathering process before reaching a conclusion.
✅ Correct Option:
A. Sufficiency
A single employee's comment is not enough evidence to support the conclusion that additional staff are needed. Sufficiency requires enough factual, adequate evidence for a prudent, informed person to reach the same conclusion. Additional corroboration, such as system usage logs, staffing analysis, or discussions with fraud unit supervisors, would be needed to substantiate the claim before it is deemed sufficient.
❌ Incorrect Options:
B. Reliability
The employee's testimony is a legitimate source of testimonial evidence and is not inherently unreliable in this context. The issue is not that the information cannot be trusted, but that there simply isn't enough of it to support the auditor's specific staffing conclusion.
C. Relevancy
The comment about the surveillance system being underused is directly related to the fraud deterrence program under review. Relevancy is not the concern here, since the information logically connects to the engagement objective; the shortfall lies in the quantity of evidence gathered.
D. Usefulness
Usefulness refers to whether evidence helps the organization meet its goals, which is not the limiting factor in this scenario. The comment could be useful if corroborated, but the auditor's conclusion fails primarily because more evidence is needed, not because the information lacks practical value.
🔧 Reference:
→ IIA Standard 2310 – Identifying Information — requires internal auditors to identify sufficient, reliable, relevant, and useful information to achieve engagement objectives.
An internal auditor conducted interviews with several employees, documented the interviews analyzed the summaries, and drew a number of conclusions. What sort of audit evidence has the internal auditor primarily obtained?
A. Documentary evidence
B. Testimonial evidence
C. Analytical evidence
D. Physical evidence
Explanation:
The question tests classification of audit evidence types. Internal auditors gather various forms of evidence to support conclusions during engagements.
✅ Correct Option:
B. Testimonial evidence
Testimonial evidence consists of statements or information obtained through interviews or inquiries. The auditor’s interviews, documentation of responses, summaries, and derived conclusions are primarily based on oral or written statements from employees.
❌ Incorrect options:
A. Documentary evidence
Documentary evidence involves written records, reports, or data files, not information gathered through direct interviews.
C. Analytical evidence
Analytical evidence results from evaluations, comparisons, or calculations of data (e.g., ratios or trends), not from interview summaries.
D. Physical evidence
Physical evidence includes tangible items observed or inspected (e.g., inventory or assets), which was not obtained here.
🔧 Reference:
→ IIA Global Internal Audit Standards – Gathering Information – Classifies testimonial evidence as information from inquiries and interviews.
→ IIA Practice Guide on Engagement Information – Describes types of evidence and their use in forming conclusions.
'Internal policy prohibits employees from entering into contacts with financial obligations
without proper approval.
A project manager signed a change to an important service agreement without obtaining
the proper approval As a result the organization is receiving $5,000 per month less for its
services.’’
Which of the following should be added to the observation?
A. The reason for not following the internal policy
B. A description of what constitutes proper approval
C. The annual impact of the changed agreement on cash flows
D. Details regarding when the change to the agreement was signed
Explanation:
The question asks which information should be added to an audit observation. Observations are structured using the 5C model: Criteria, Condition, Cause, Consequence (Effect), and Corrective Action/Recommendation . The observation currently states the Condition ($5,000 monthly loss) and the Cause (lack of approval). Quantifying the financial impact addresses the Consequence/Effect element, which is considered essential to complete an audit finding and make it persuasive .
✔️ Correct Option:
C. The annual impact of the changed agreement on cash flows.
An observation must include the Effect, which is the risk or exposure caused by the condition . The current observation states a monthly loss of $5,000. Quantifying this as a **$60,000 annual impact** transforms a detail into a compelling consequence that demonstrates materiality and urgency to management, which is essential for persuasive reporting .
❌ Incorrect Options:
A. The reason for not following the internal policy.
This addresses the Cause of the issue. While the Cause is a required element (explaining why the gap exists) , the scenario states "without obtaining approval" but does not imply this reason is unknown. The question is about adding to the observation, and the primary missing element is the quantified impact to strengthen the report .
B. A description of what constitutes proper approval.
This describes the Criteria (what should exist), which is a benchmark against which the condition is evaluated . While necessary for an audit, this is usually set as the basis of the audit (the internal policy) rather than a detail to add to a final observation where the policy has already been cited.
D. Details regarding when the change to the agreement was signed.
This is a contextual detail about the Condition (what happened) . While the date might be recorded in workpapers, it does not help management understand the severity or priority of the issue. Adding the date does not fulfill the requirement to quantify risk or impact as effectively as calculating the annual financial loss .
🔧 Reference:
→ IIA Practice Advisory 2410-1 - Communication Criteria: Confirms that engagement observations must be based on the elements of Criteria, Condition, Cause, and Effect (impact) .
→ IIA Practice Guide - Audit Reports: States observations should include the Effect (risk or exposure) to provide clarity and materiality to the issue. It recommends quantifying the condition where possible .
Which of the following recognized competitive strategies focuses on gaining efficiencies?
A. Focus
B. Cost leadership.
C. Innovation
D. Differentiation
Explanation:
This question tests the understanding of Michael Porter's generic competitive strategies. It requires identifying which strategic approach relies primarily on maximizing operational efficiencies and minimizing production expenses to achieve a competitive advantage in the marketplace.
✅ Correct Option:
B. Cost leadership.
The cost leadership strategy focuses on becoming the lowest-cost producer within an industry. To achieve this, an organization must aggressively pursue operational efficiencies, exploit economies of scale, minimize overhead expenses, and eliminate waste across its entire supply chain, allowing it to maintain profitability while offering highly competitive, low prices to consumers.
❌ Incorrect options:
A. Focus
A focus strategy concentrates entirely on serving a narrow, specialized market niche or specific demographic segment. While a company using this approach can choose to pursue either a cost focus or a differentiation focus within that small niche, the strategy itself is defined by its targeted scope rather than an organization-wide drive for efficiency.
C. Innovation
An innovation strategy focuses on creating completely new products, cutting-edge technologies, or pioneering business models to lead the market. This approach requires heavy investments in research and development and a high tolerance for experimentation, which prioritizes speed-to-market and creativity over driving down day-to-day operational efficiencies.
D. Differentiation
A differentiation strategy aims to create unique products or services that customers perceive as distinct, premium, and superior to competitors' offerings. Because this approach relies heavily on brand building, high-quality materials, and exceptional customer service, companies often incur higher operational costs rather than focusing on strict internal efficiencies.
🔧 Reference:
→ The IIA Business Acumen Guidance confirms that a cost leadership strategy relies fundamentally on maximizing internal process efficiencies and cost controls to maintain a competitive market position.
Which of the following is not a primary purpose for conducting a walk-through during the initial stages of an assurance engagement?
A. To help develop process maps.
B. To determine segregation of duties.
C. To identify residual risks.
D. To test the adequacy of controls.
Explanation:
This question tests the purpose of a walk-through during the early planning phase of an assurance engagement. A walk-through helps auditors understand how a process operates, identify key activities, and recognize possible risks and control points. It is mainly a process-understanding activity rather than detailed control testing.
🟢 Correct Option:
D. To test the adequacy of controls.
A walk-through is not primarily designed to determine whether controls are adequate or effective. Its purpose is to help auditors understand process flow, identify control points, and gain knowledge of operations before detailed testing begins. Actual control adequacy testing normally occurs later through substantive procedures and control testing activities during fieldwork.
🔴 Incorrect options:
A. To help develop process maps.
Walk-throughs assist auditors in understanding how transactions and activities move through a process. This understanding helps create process maps and document workflows accurately.
B. To determine segregation of duties.
Walk-throughs can help identify whether responsibilities are separated appropriately among employees. Auditors may recognize incompatible duties and potential control weaknesses.
C. To identify residual risks.
Walk-throughs help auditors understand processes and recognize areas where risks may remain after existing controls are applied. This information supports engagement planning and risk assessment.
🔧 Reference:
⇒ IIA Standards – Planning and Performing Internal Audit Engagements
Confirms that auditors obtain an understanding of processes and risks during engagement planning.
⇒ IIA Practice Guide – Engagement Planning
Confirms that walk-through activities support process understanding and risk identification.
According to IIA guidance, which of the following strategies would add the least value to the achievement of the internal audit activity's (IAA's) objectives?
A. Align organizational activities to internal audit activities and measure according to the approved IAA performance measures.
B. Establish a periodic review of monitoring and reporting processes to help ensure relevant IAA reporting.
C. Use the results of IAA engagement and advisory reporting to guide current and future internal audit activities.
D. Establish a format and frequency for IAA reporting that is appropriate and aligns with the organization's governance structure.
Explanation:
This question tests which strategy contributes the least to achieving the internal audit activity’s objectives. The most useful strategies are those that improve reporting quality, guide future audit work, and align communication with governance needs. Linking organizational activities to internal audit measures is less directly useful because it is broader and less focused on audit activity performance.
✔️ Correct Option:
A. Align organizational activities to internal audit activities and measure according to the approved IAA performance measures.
This adds the least value because it is too broad and does not directly improve the internal audit activity’s own objectives. Internal audit strategies should focus on reporting, monitoring, communication, and using audit results to guide future work. Measuring organizational activities against internal audit measures does not clearly strengthen the internal audit function itself.
❌ Incorrect options:
B. Establish a periodic review of monitoring and reporting processes to help ensure relevant IAA reporting.
This supports the internal audit activity because it helps maintain timely, relevant, and useful reporting. Regular review of reporting processes directly improves how the IAA communicates results and tracks progress.
C. Use the results of IAA engagement and advisory reporting to guide current and future internal audit activities.
This is valuable because audit results should inform future planning and focus areas. Using engagement and advisory outcomes helps the internal audit activity stay risk-based and responsive to stakeholder needs.
D. Establish a format and frequency for IAA reporting that is appropriate and aligns with the organization's governance structure.
This is important because reporting should match the governance structure and stakeholder expectations. Clear reporting format and timing improve communication and support oversight.
🔧 Reference:
→ The IIA —
Performance Standards
— confirms that internal audit adds value through strategy, objectives, risk focus, and useful reporting.
→ The IIA —
Developing the Internal Audit Strategy
— supports aligning internal audit strategy with reporting, stakeholder needs, and future activities.
Besides a chief audit executive's professional experience what determines the frequency and approach to assessing residual risk?
A. The frequency of executing the internal audit engagements
B. The frequency of changes in the organization environment
C. The expectations set by the board and senior management
D. The expectations set by operating management and senior management
Explanation:
This question tests understanding of what shapes the CAE's approach to assessing residual risk beyond personal professional judgment. It focuses on the governance relationship between internal audit and its key oversight stakeholders in shaping risk assessment practices.
✅ Correct Option:
C. The expectations set by the board and senior management
The board and senior management set the tone for risk appetite, reporting expectations, and the depth of assurance required across the organization. Their expectations directly influence how often and how thoroughly the CAE assesses residual risk, since internal audit's risk assessment approach must align with governance priorities and the level of oversight these stakeholders expect from the internal audit function.
❌ Incorrect Options:
A. The frequency of executing the internal audit engagements
Engagement frequency is an outcome of the risk assessment process, not a driver of it. The internal audit plan is built based on residual risk ratings, so this option reverses the actual relationship between risk assessment and audit scheduling.
B. The frequency of changes in the organization environment
While organizational change can prompt a reassessment of risk, this factor is more about triggering updates rather than shaping the overall frequency and approach. It is a contributing input rather than the primary driver referenced in IIA guidance on residual risk assessment.
D. The expectations set by operating management and senior management
Operating management is responsible for managing risk at the process level, not setting the oversight expectations that shape internal audit's assessment approach. This governance responsibility belongs to the board and senior management, not operating management.
🔧 Reference:
→ IIA Practice Guide: Developing a Risk-based Internal Audit Plan — confirms that the CAE communicates with senior management and the board to align expectations, which shapes how internal audit prioritizes and assesses residual risk.
A chief audit executive (CAE) reviews the supervision of an internal audit engagement Which of the following would most likely assure the CAE that the engagement had adequate supervision?
A. The engagement supervisor has an open door pokey for audit team members to discuss concerns
B. The supervisor reviews weekly progress reports from the audit team members
C. The supervisor reviews and initials internal audit workpapers for the engagement
D. The supervisor meets periodically with management in the reviewed area to get feedback during the engagement.
Explanation:
The question evaluates indicators of effective engagement supervision per IIA Standards. Supervision ensures work quality, adherence to standards, and achievement of objectives.
✅ Correct Option:
C. The supervisor reviews and initials internal audit workpapers for the engagement
Reviewing and initialing workpapers is a primary supervisory activity. It provides direct evidence that the supervisor evaluated the sufficiency of evidence, appropriateness of conclusions, and compliance with engagement standards.
❌ Incorrect options:
A. The engagement supervisor has an open door pokey for audit team members to discuss concerns
An open-door policy supports communication but does not demonstrate active supervision of work quality or documentation.
B. The supervisor reviews weekly progress reports from the audit team members
Progress reports are helpful for monitoring but are indirect and do not verify the detailed quality of audit evidence and conclusions.
D. The supervisor meets periodically with management in the reviewed area to get feedback during the engagement.
Management feedback is valuable for engagement outcomes but is not a core element of supervising the internal audit team’s work.
🔧 Reference:
→ IIA Global Internal Audit Standards – Engagement Supervision – Requires supervisors to review workpapers to ensure quality and support conclusions.
→ IIA Practice Guide on Engagement Supervision – Emphasizes workpaper review as key evidence of adequate supervision.
| Page 7 out of 60 Pages |
| 123456789101112131415161718 |
| IIA-CIA-Part2 Practice Test Home |
Real-World Scenario Mastery: Our IIA-CIA-Part2 practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before Certified Internal Auditor Part 2 - Internal Audit Engagement exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive IIA-CIA-Part2 practice exam questions pool covering all topics, the real exam feels like just another practice session.