Topic 1: Exam Pool A
An internal auditor would like to identify the involvement of various organizational units in handling employee travel reimbursement claims. Which of the following methods would be most effective and efficient in completing this task?
A. Process mapping.
B. Interviewing.
C. Monitoring.
D. Distributing questionnaires.
Explanation:
Process mapping (often in the form of a flowchart) is the most effective and efficient method for identifying the involvement of various organizational units in handling employee travel reimbursement claims. A process map provides a visual, end-to-end depiction of the workflow, clearly showing each step in the process, the sequence of activities, the decision points, and—most importantly—which department or role performs each action (e.g., employee submits claim, supervisor approves, accounts payable verifies, finance disburses payment).
Why the other options are incorrect:
B. Interviewing:
While interviews can identify unit involvement, they are time-consuming, rely on individual recollections that may be incomplete or inconsistent, and must be conducted with multiple people across different units. This is less efficient than reviewing or creating a single process map.
C. Monitoring:
Monitoring (direct observation over time) is resource-intensive and inefficient for identifying unit involvement, as the auditor would need to observe the processing of multiple claims across all units to see who does what. It also captures only what happens during the observation period, which may not reflect the full process.
D. Distributing questionnaires:
Questionnaires are inefficient for this purpose, as they rely on written responses that may be vague, incomplete, or misinterpreted. They also require significant time to design, distribute, collect, and consolidate, and they do not provide a cohesive, visual overview of the entire workflow across units.
References
IIA Standard 2210.A1 – Engagement Objectives: Requires internal auditors to consider the probability of significant errors, fraud, noncompliance, and other exposures. Process mapping is a fundamental preliminary survey technique used to gain an understanding of processes, controls, and responsibilities before developing the engagement program.
Which of the following best describes the assessment of risks?
A. Assess the actions necessary to reduce the likelihood and/or impact of risk to tolerable levels.
B. Assess the likelihood and/or impact of risk on the achievement of organizational objectives.
C. Assess the amount of risk an organization can accept while pursuing its objectives.
D. Assess alternative strategies to reduce or eliminate major risks.
Explanation:
Risk assessment is the fundamental process of identifying and analyzing risks to determine their nature and level. By definition, it involves evaluating two core components: likelihood (the probability that an event will occur) and impact (the potential effect on achieving organizational objectives). This is the essence of the risk assessment phase within the broader risk management process—it answers the question, "How significant is this risk?" before any decisions about treatment are made. Internal auditors rely on this foundational understanding to plan engagements and evaluate the adequacy of risk management processes.
Why the other options are incorrect:
A. Assess the actions necessary to reduce the likelihood and/or impact of risk to tolerable levels: This describes risk treatment or risk response (mitigation), not risk assessment. It occurs after the risks have been assessed to determine what actions are needed.
C. Assess the amount of risk an organization can accept while pursuing its objectives: This describes risk appetite or risk tolerance—the amount of risk the organization is willing to accept. This is a strategic input into the risk assessment process, not the assessment itself.
D. Assess alternative strategies to reduce or eliminate major risks: This also describes risk response—specifically, the evaluation of different mitigation strategies (e.g., avoid, reduce, share, accept). This occurs in the risk treatment phase, not during the assessment phase.
References
IIA Standard 2120 – Risk Management:"The internal audit activity must evaluate the effectiveness and contribute to the improvement of risk management processes." The standard's implementation requires understanding how management assesses risks, which is defined as evaluating likelihood and impact relative to objectives.
An internal audit charter describes the mission and scope of the internal audit activity (IAA), responsibilities of the IAA, accountability of the chief audit executive, independence of the IAA, and standards followed by the IAA. Which of the following also should be included in the charter?
A. The purpose of the IAA.
B. The IAA's right to have unrestricted access to functions, records, personnel, and physical property.
C. A detailed audit plan or program for the year.
D. The job specifications and descriptions of the internal audit staff.
Explanation:
The internal audit charter is a formal, board-approved document that establishes the internal audit activity's (IAA) position, authority, and responsibility. While the question correctly lists the mission, scope, responsibilities, accountability, independence, and standards, it is missing a critical element: the IAA's right of access.
Standard 1000 and its Implementation Guide explicitly require the charter to include the IAA's unrestricted access to records, personnel, and physical properties relevant to the performance of engagements. This provision is not a mere courtesy; it is the enabling authority that allows internal auditors to obtain the information they need without interference. Without this explicit right embedded in the charter, management could legally or administratively block access to critical documents or personnel, rendering the IAA ineffective. Including this access right in the charter ensures that the board, senior management, and all staff are formally notified of this non-negotiable authority.
Why the other options are incorrect:
A. The purpose of the IAA:
The question states the charter already describes the "mission" of the IAA. The mission of internal auditing (as defined by the IIA) inherently captures the purpose. While a charter may reference the mission, the purpose is already covered under the stated elements; the right of access is explicitly missing.
C. A detailed audit plan or program for the year:
Incorrect. The annual audit plan is a separate, dynamic document that is approved by the board but is not part of the fixed charter. The charter provides the overarching authority to develop the plan; it does not contain the plan itself, which changes annually.
D. The job specifications and descriptions of the internal audit staff:
Incorrect. Job descriptions are operational HR documents, not governance-level charter content. The charter may define the IAA's resource requirements broadly, but detailed job specifications are maintained separately.
References
IIA Standard 1000 – Purpose, Authority, and Responsibility: "The purpose, authority, and responsibility of the internal audit activity must be formally defined in an internal audit charter, consistent with the Definition of Internal Auditing, the Code of Ethics, and the Standards. The chief audit executive must periodically review the internal audit charter and present the results to senior management and the board for approval."
What type of risk management strategy is being employed when an organization installs two firewalls to provide protection from unauthorized access to the network?
A. Diversifying the risk that network access will not be available to legitimate, authorized users.
B. Accepting the risk that there may be attempts at unauthorized access to the network.
C. Avoiding the risk of having a direct network connection to un-trusted networks.
D. Sharing the risk that either firewall could be compromised by hackers.
Explanation:
Risk management strategies are typically categorized as avoid, reduce (mitigate), share (transfer), or accept. Installing two firewalls in a layered configuration (often referred to as a demilitarized zone or DMZ architecture) is a strategy designed to eliminate the specific risk of having a direct, unprotected connection between the organization's internal network and untrusted external networks (such as the internet).
Why the other options are incorrect:
A. Diversifying the risk that network access will not be available:
This is incorrect. Diversification (spreading risk across multiple assets or channels) applies to financial portfolios or supply chains. Firewalls do not diversify availability risk; they create redundancy for security, not availability.
B. Accepting the risk of unauthorized access attempts:
This is incorrect. Acceptance means consciously tolerating the risk without taking action. Installing firewalls is the opposite of acceptance—it is an active control. The organization is not simply accepting the risk; it is acting to eliminate a specific exposure.
D. Sharing the risk that either firewall could be compromised:
This is incorrect. Risk sharing (or transfer) involves shifting the financial or operational burden to a third party, typically through insurance, outsourcing, or contractual agreements. Installing internal hardware does not transfer any risk to an external party.
References
IIA Standard 2120 – Risk Management: Requires the internal audit activity to evaluate the effectiveness and contribute to the improvement of risk management processes. This includes assessing whether risk responses (avoid, reduce, share, accept) adequately address identified exposures.
A new chief audit executive (CAE) of a large internal audit activity (IAA) is dissatisfied with the current amount and quality of training being provided to the staff and wishes to implement improvements. According to IIA guidance, which of the following actions would best help the CAE reach this objective?
A. Require that all staff obtain a minimum of two relevant audit certifications.
B. Perform a gap analysis of the IAA's existing knowledge, skills and competencies.
C. Engage a consultant to benchmark the IAA's training program against its peers.
D. Assign one experienced manager to better coordinate staff training and development activities.
Explanation:
To effectively improve staff training, the CAE must first establish a baseline of the current state of the team. The most effective initial step is to perform a gap analysis . This aligns directly with IIA guidance, which recommends that the CAE uses a competency assessment tool to systematically identify the discrepancies between the staff's current capabilities and the competencies required to execute the internal audit plan .
Why the other options are incorrect
A. Require that all staff obtain a minimum of two relevant audit certifications:
While encouraging professional certifications supports the enhancement of proficiency , mandating a blanket requirement is an arbitrary action that fails to address the specific, identified skill deficiencies. It is a solution imposed before the actual problem (the skill gaps) has been diagnosed.
C. Engage a consultant to benchmark the IAA's training program against its peers:
While benchmarking can be informative, it should not be the primary first step. It provides external data that may not be relevant to the organization's unique risk profile and audit plan . The CAE's focus must be on internal needs first, as the "appropriateness" of resources is tied to the specific approved plan .
D. Assign one experienced manager to better coordinate staff training and development activities:
This action may improve administration but does not address the core issue of the content and quality of the training. Without knowing what the gaps are (from a gap analysis), a coordinator cannot effectively tailor the training programs to build the necessary competencies .
References
IIA Implementation Guide 1210 – Proficiency: Explicitly recommends that the CAE develops a competency assessment tool or skills assessment "to identify gaps" in the internal audit activity's collective proficiency .
According to IIA guidance, which of the following objectives of an assurance engagement for the organization's risk management process is valid?
A. All risks have been identified and mitigated.
B. Risks have been accurately analyzed and evaluated.
C. All controls are both adequate and efficient.
D. The board is appropriately addressing intolerable risks.
Explanation:
This question asks for a valid assurance objective regarding the organization's risk management process. According to IIA guidance, the core role of internal audit in risk management is to provide objective assurance to the board on the effectiveness of risk management. This involves evaluating the entire risk management process, not fixing it or guaranteeing perfection.
Why the other options are incorrect
A. All risks have been identified and mitigated:
This objective is unrealistic and overreaching. While internal audit evaluates if significant risks are identified, management can never guarantee that all risks are identified or mitigated. Internal audit does not assume management's responsibility for mitigating risks.
C. All controls are both adequate and efficient:
This is too absolute. Standard 2130 requires internal audit to evaluate the adequacy and effectiveness of controls, but "all" controls being "adequate and efficient" is not a valid, achievable assurance objective; it suggests a level of perfection that internal audit does not guarantee.
D. The board is appropriately addressing intolerable risks:
While the board is responsible for oversight, internal audit's assurance is on the risk management processes, not directly on whether the board is addressing risks. This statement confuses the board's governance role with the internal audit's evaluation of the process.
References
IIA Standard 2120 – Risk Management:"The internal audit activity must evaluate the effectiveness and contribute to the improvement of risk management processes". The interpretation clarifies that this includes assessing whether "significant risks are identified and assessed".
Which of the following audit procedures would provide the most relevant information to identify discrepancies between budgeted versus actual raw material consumption in a production facility?
A. Analytical review.
B. Inquiry.
C. Document verification.
D. Observation.
Explanation:
An analytical review is the most relevant procedure for identifying discrepancies between budgeted versus actual raw material consumption. This procedure involves comparing financial and operational data—such as budgeted consumption quantities against actual usage—to detect significant variances, unusual trends, or unexpected relationships that may indicate errors, inefficiencies, or potential fraud. It is specifically designed to analyze aggregated data and pinpoint anomalies that warrant further investigation.
Why the other options are incorrect :
B. Inquiry:
Asking personnel about consumption variances may provide context or explanations, but it relies on subjective responses and cannot independently verify or quantify discrepancies. It is a corroborative procedure, not a primary detection technique.
C. Document verification:
Examining individual source documents (e.g., requisition forms, delivery receipts) provides evidence of specific transactions but is too granular and time-consuming to efficiently identify aggregate budget-to-actual discrepancies across an entire production facility.
D. Observation:
Watching production processes helps understand operations and control activities but provides no quantitative data on budgeted versus actual consumption. It cannot identify variances in material usage.
References
IIA Standard 2320 – Analysis and Evaluation: "Internal auditors must base conclusions and engagement results on appropriate analyses and evaluations." Analytical review is explicitly recognized as a key analysis technique.
Which of the following is not an appropriate activity for internal auditors to perform?
A. Recommend management seek a consulting firm to advise on outsourcing.
B. Highlight matters that require management's attention.
C. Implement solutions for specific organizational problems.
D. Accumulate data, obtain varying views, and report information to senior management.
Explanation:
This question tests the fundamental boundary between internal audit's assurance and consulting roles and management's operational responsibilities. According to the IIA's International Professional Practices Framework (IPPF), internal auditors are expressly prohibited from assuming management's decision-making responsibilities or implementing solutions. Their role is to evaluate, advise, recommend, and report—not to execute or implement.
Why the other options are correct activities (in brief):
A. Recommend management seek a consulting firm to advise on outsourcing:
This is a valid consulting activity. Internal auditors can identify areas where external expertise is needed and make recommendations to management. They are not implementing outsourcing—they are providing advice.
B. Highlight matters that require management's attention: T
his is a core audit responsibility. Standard 2500 requires internal auditors to communicate significant issues to the appropriate levels of management, which helps management take corrective actions.
D. Accumulate data, obtain varying views, and report information to senior management:
This is a fundamental audit activity. Collecting data, gathering perspectives, and reporting findings are essential components of audit fieldwork and communication under the Standards.
References
IIA Standard 1130.C1 – Impairments to Independence or Objectivity (Consulting): "Internal auditors may provide consulting services relating to operations for which they had previous responsibilities only after a period of at least one year."
IIA Standard 2120.C1 – Risk Management (Consulting): "When assisting management in establishing or improving risk management processes, internal auditors must refrain from assuming any management responsibility."
Which of the following statements is true regarding the use of non-statistical sampling in auditing control tests?
A. It considers tolerable deviation rate more effectively than does statistical sampling.
B. Sampling risk will be accurately quantified through non-statistical sampling.
C. Non-statistical sample results must be projected to the population.
D. Lesser evidence is required to support a conclusion than for statistical sampling.
Explanation:
The requirement to project sample results to the population is a fundamental step in audit sampling, applicable to both statistical and non-statistical methods. Once a non-statistical sample has been tested and errors or deviations are identified, the auditor cannot simply stop with the sample findings. The results must be projected or extrapolated to the entire population to estimate the total error or deviation rate . This projection allows the auditor to compare the estimated error in the whole population against the pre-defined tolerable error, forming a conclusion on whether the population is materially misstated or if controls are operating effectively .
Why the other options are incorrect:
A. It considers tolerable deviation rate more effectively than does statistical sampling:
Incorrect. Tolerable deviation rate is a key input for determining sample size in both statistical and non-statistical approaches . Neither method is inherently more effective at "considering" it, though statistical methods do so within a quantifiable confidence framework.
B. Sampling risk will be accurately quantified through non-statistical sampling:
Incorrect. The main limitation of non-statistical sampling is that it does not allow for the calculation of accuracy or the quantification of sampling risk . This is the defining advantage of statistical sampling, which uses probability theory to measure and control this risk .
D. Lesser evidence is required to support a conclusion than for statistical sampling:
Incorrect. The sufficiency of evidence required to support an audit conclusion is determined by the engagement objectives and the acceptable level of risk, not by the choice of sampling method. Both statistical and non-statistical approaches require the auditor to select a sample size sufficient to provide a reasonable basis for conclusions . In fact, some guidance suggests that the use of non-statistical sampling does not imply the use of smaller sample sizes .
References:
Standard on Internal Audit (SIA) 5, Sampling: Requires that the internal auditor evaluate sample results, which includes projecting errors to the population, regardless of whether a statistical or non-statistical approach is used .
What is the primary purpose of a fishbone diagram?
A. To depict the areas of responsibility for departments in an organization.
B. To plan and control complex projects, such as internal audits.
C. To represent the frequencies of adverse conditions in a given process.
D. To identify the possible causes of adverse conditions.
Explanation:
A fishbone diagram (also known as an Ishikawa or cause-and-effect diagram) is a visual brainstorming tool specifically designed to systematically identify, explore, and display the potential root causes of a specific problem, defect, or adverse condition. The diagram visually organizes causes into categories (typically the 6 Ms: Manpower, Methods, Materials, Machines, Measurements, and Mother Nature/Environment), allowing a team to trace an undesirable outcome back to its possible sources. Its primary purpose is investigative and diagnostic—to help auditors and management move beyond symptoms and uncover the underlying factors contributing to a control failure, operational inefficiency, or quality issue.
Why the other options are incorrect:
A. To depict the areas of responsibility for departments in an organization:
This describes an organizational chart, which shows hierarchical structure and reporting lines, not cause-and-effect relationships.
B. To plan and control complex projects, such as internal audits:
This describes a Gantt chart or PERT chart, which are project management tools for scheduling, tracking timelines, and managing resources.
C. To represent the frequencies of adverse conditions in a given process:
This describes a histogram or Pareto chart, which are quantitative tools used to display frequency distributions and prioritize issues based on their occurrence.
References:
IIA Practice Guide – "Auditing Quality Management Systems": Recommends the use of fishbone diagrams during the planning and fieldwork phases to assist in root cause analysis when investigating quality failures or nonconformities.
IIA GTAG – "Auditing IT Governance": References cause-and-effect analysis as a valuable technique for identifying and structuring risk factors and control weaknesses in IT environments.
Which of the following scenarios would represent the greatest threat to the authority of the internal audit activity (IAA)?
A. A change was implemented requiring the IAA to report administratively to the organization's chief legal counsel rather than the board.
B. Responsibility for risk management processes were removed from the IAA and placed under a newly created chief risk officer.
C. The IAA was denied access to expenditure and budget requirement reports because the reports were considered to be financial administrative matters.
D. An internal auditor was informed by the chief financial officer that client survey results would be unfavorable unless the auditor changed a finding in the report.
Explanation:
This question asks for the scenario that represents the greatest threat to the authority of the internal audit activity (IAA). Authority is fundamentally rooted in the IAA's right of access as defined in the internal audit charter (Standard 1000). Denial of access to any records, personnel, or physical properties—regardless of the reason—directly undermines the IAA's ability to perform its work and fulfill its mandate.
Why the other options are incorrect :
A. Reporting administratively to chief legal counsel:
This is a threat to organizational independence (Standard 1110), not authority. While problematic, the CAE would still retain audit authority per the charter; independence is impaired but can be disclosed and addressed.
B. Risk management responsibilities removed:
This is a threat to scope and role clarity (Standard 2120). It reduces the IAA's involvement in risk management but does not deny its fundamental authority to access information or perform audits in other areas.
D. CFO asking auditor to change a finding:
This is a threat to individual objectivity (Standard 1120) and professional integrity. It is a serious ethical breach, but the auditor can resist, and the CAE can protect the auditor. It does not prevent the IAA from accessing information or exercising its authority.
References:
IIA Standard 1000 – Purpose, Authority, and Responsibility: Requires the charter to define the IAA's purpose, authority, and responsibility, including the right of access.
IIA Standard 1130 – Impairments to Independence or Objectivity: Requires disclosure of impairments, but denial of access is a direct violation of the charter-granted authority.
Which of the following actions does not violate the IIA Code of Ethics or Standards?
A. An internal auditor performing an audit on an operation that they managed less than a year ago.
B. An internal auditor performing an audit on procedures that they were responsible for creating.
C. An internal auditor disclosing details of an audit report to colleagues from a different organization.
D. An internal auditor disclosing confidential information in response to a lawsuit.
Explanation:
The IIA Code of Ethics strictly mandates that internal auditors must protect the confidentiality of information they acquire in their work and must not disclose confidential information without appropriate authority (which typically means board or audit committee approval) unless there is a legal or professional obligation to do so.
Disclosing confidential information in response to a lawsuit—specifically, when compelled by a valid court order, subpoena, or other legal process—falls under this explicit exception. While the auditor should still exercise caution and ideally seek legal counsel to limit disclosure to only what is legally required, this action does not violate the Code of Ethics or the Standards because it satisfies a legal obligation. It is the only option where the disclosure is mandated by external authority rather than being voluntary or unauthorized.
Why the other options are incorrect:
A. An internal auditor performing an audit on an operation that they managed less than a year ago:
This violates Standard 1130.C1 (Impairments to Independence or Objectivity for Consulting Services), which requires a one-year cooling-off period before providing consulting services for an area previously managed, and Standard 1130.A1 (Assurance) for assurance work, which mandates at least one year before assuming responsibility for an area previously audited.
B. An internal auditor performing an audit on procedures that they were responsible for creating:
This is a clear violation of Standard 1120 (Individual Objectivity) and the Code of Ethics Rule of Conduct for Objectivity. Auditors cannot audit their own work, as this creates an actual conflict of interest and impairs impartiality.
C. An internal auditor disclosing details of an audit report to colleagues from a different organization:
This violates the Confidentiality principle of the IIA Code of Ethics. Internal auditors must not disclose information without appropriate authority (such as board or audit committee approval). Sharing details with external colleagues without authorization is a breach, regardless of intent.
References:
IIA Code of Ethics – Principle IV: Confidentiality: "Internal auditors respect the value and ownership of information they receive and do not disclose information without appropriate authority unless there is a legal or professional obligation to do so."
| Page 2 out of 24 Pages |
| 12345678 |
| IIA-CRMA-ADV Practice Test Home |
Real-World Scenario Mastery: Our IIA-CRMA-ADV practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before Certification in Risk Management Assurance exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive IIA-CRMA-ADV practice exam questions pool covering all topics, the real exam feels like just another practice session.