Topic 1: Exam Pool A
Which of the following statements best explains why internal auditors map processes?
1. To obtain audit evidence to support auditor's observations.
2. To determine scope and objectives of the audit.
3. To facilitate the identification of ownership and responsibility for key risks.
4. To identify potential efficiency improvements.
A. 1 and 2.
B. 1 and 3.
C. 2 and 4.
D. 3 and 4.
Explanation:
Process mapping (often in the form of flowcharts or narratives) is a foundational diagnostic tool used during the planning and preliminary survey phases of an audit. Its primary purposes are to help the auditor understand the flow of transactions, identify key control points, and pinpoint areas of risk. The two best explanations for why internal auditors map processes are:
To facilitate the identification of ownership and responsibility for key risks (Statement 3): By visually depicting each step in a process, a map clearly shows who performs which action, where handoffs occur, and where decisions are made. This allows the auditor to identify the specific individuals or departments responsible for managing risks at each critical control point, which is essential for evaluating control design and assigning accountability.
To identify potential efficiency improvements (Statement 4): A process map provides a clear, end-to-end view of the workflow. This allows the auditor to spot redundancies, bottlenecks, unnecessary approvals, rework loops, or duplicated efforts that indicate operational inefficiencies—an important aspect of both assurance and consulting engagements.
Why the other options are incorrect:
Statement 1 – To obtain audit evidence to support auditor's observations:
Incorrect. A process map is a documentation tool that helps the auditor understand a process; it is not itself audit evidence. Evidence is obtained through testing (inspection, observation, recalculation, etc.) that confirms whether the mapped process is actually operating as described. The map supports planning and understanding, not direct evidentiary support for conclusions.
Statement 2 – To determine scope and objectives of the audit:
Incorrect. The scope and objectives of an engagement are determined primarily through a risk assessment, not by process mapping. While process mapping may inform the risk assessment by highlighting areas of complexity, the scope and objectives are set based on identified risks, materiality, and management's concerns—not by the map itself.
References:
IIA Standard 2210.A1 – Engagement Objectives: Requires internal auditors to consider the probability of significant errors, fraud, and noncompliance. Process mapping is a recognized technique used during the preliminary survey to gain an understanding of the process and identify control points.
A candidate has applied for an entry level internal audit position. The candidate holds a CISA (Certified Information Systems Auditor) designation, and has six months of audit experience, but limited knowledge of accounting principles and techniques. According to the IIA guidance, which of the following is the most relevant reason for the chief audit executive to consider this candidate?
A. Other internal auditors possess sufficient knowledge of accounting principles and techniques.
B. The candidate's information systems knowledge and real-world experience in internal auditing.
C. Accounting skills can be learned over time with appropriate training.
D. An entry level position does not require expertise in any particular area.
Explanation:
This question addresses the principle of collective proficiency within an internal audit activity. The fundamental requirement for an internal audit activity is to collectively possess the knowledge and skills needed to perform its responsibilities . Standard 1210 specifies that "The internal audit activity collectively must possess or obtain the knowledge, skills, and other competencies needed to perform its responsibilities" .
Why the other options are incorrect:
B. The candidate's information systems knowledge and real-world experience:
While a strong resume point for an entry-level role, this alone is not the most relevant reason. The key decision hinges on whether the specific skill is needed by the team, not its inherent value. Without considering the team's collective gaps, this reason is less strategic .
C. Accounting skills can be learned over time:
This is a passive justification that overlooks the candidate's immediate value and the core IIA guidance on proficiency. It focuses on a future potential, rather than a current strategic fit.
D. An entry level position does not require expertise in any particular area:
This is incorrect. While entry-level roles don't demand mastery, the IIA Competency Framework specifies foundational skills are expected. Candidates must demonstrate a baseline of knowledge, skills, and abilities . The CAE has a responsibility to ensure every position meets the professional requirements for proficiency.
References:
IIA Standard 1210 – Proficiency: "Internal auditors must possess the knowledge, skills, and other competencies needed to perform their individual responsibilities. The internal audit activity collectively must possess or obtain the knowledge, skills, and other competencies needed to perform its responsibilities."
Which of the following is not one of the 10 core competencies identified in the IIA Competency Framework?
A. Governance, risk, and control.
B. Performance management.
C. Business acumen.
D. Internal audit delivery.
Explanation:
The IIA's Competency Framework is structured around four broad knowledge areas: Internal Auditing Competencies, Professional Competencies, Governance and Risk Management Competencies, and Operational Area Competencies. Under these, the framework identifies a set of core competencies that define the knowledge, skills, and abilities required for effective internal auditors at various career levels.
Performance management (B), however, is not a core competency category within the IIA Competency Framework. While performance management—such as evaluating staff, providing feedback, and managing team performance—is an important managerial tool, the framework treats it as a mechanism for applying competencies rather than as a distinct competency itself. In fact, the updated 2025 framework explicitly states that it can be used to support individual performance management and professional development planning, but it does not list performance management as one of the core knowledge areas.
Why the other options are incorrect:
A. Governance, risk, and control: Incorrect because this is a foundational competency area in the framework, essential for evaluating organizational governance, risk management, and internal control systems.
C. Business acumen: Incorrect because this is a recognized competency, requiring auditors to understand business models, industry dynamics, and operational processes to provide relevant assurance and advice.
D. Internal audit delivery: Incorrect because this is a core competency covering the entire audit lifecycle—from planning and fieldwork to communication and follow-up.
References:
IIA's Global Internal Audit Competency Framework (Original): Defines four main competency areas: Internal Auditing Competencies, Professional Competencies, Governance and Risk Management Competencies, and Operational Area Competencies. Specific subcategories include Governance, Risk, and Control; Business Acumen; and Internal Audit Delivery.
An internal audit activity (IAA) provided assurance services for an activity it was
responsible for during the preceding year.
As a result, which IIA Code of Ethics principle is presumed to be impaired?
A. Competence.
B. Flexibility.
C. Objectivity.
D. Independence.
Explanation:
The IIA Code of Ethics and the Standards explicitly prohibit internal auditors from auditing an activity or operation for which they had previous responsibility within the last year. This is because they would be placed in a position of evaluating their own work or decisions, which creates an actual or perceived conflict of interest. The principle directly impaired in this scenario is Objectivity—the unbiased mental attitude and avoidance of conflicts that allows auditors to perform engagements impartially.
Why the other options are incorrect:
A. Competence:
This principle requires auditors to possess the knowledge and skills to perform their duties. There is no indication the auditor lacked competence; the issue is the impartiality of their judgment, not their ability.
B. Flexibility:
This is not a principle of the IIA Code of Ethics. The Code has four principles: Integrity, Objectivity, Confidentiality, and Competency.
D. Independence:
Independence (organizational status) refers to the IAA's freedom from interference in determining scope and reporting findings. This scenario concerns an individual auditor's personal bias arising from prior operational responsibilities—this is an impairment to objectivity, not organizational independence. However, note that Standard 1130 treats this as an impairment that must be disclosed, but the underlying principle violated is objectivity.
References:
IIA Code of Ethics – Principle II: Objectivity: "Internal auditors exhibit the highest level of professional objectivity in gathering, evaluating, and communicating information about the activity or process being examined. Internal auditors make a balanced assessment of all the relevant circumstances and are not unduly influenced by their own interests or by others in forming judgments."
Which type of objectives can best be described as broad goals that promote the effective and efficient use of resources?
A. Strategic objectives.
B. Operational objectives.
C. Reporting objectives.
D. Compliance objectives.
Explanation:
Operational objectives are specifically concerned with the effective and efficient use of resources. They relate to the accomplishment of an entity's basic mission and goals, ensuring that resources (such as people, materials, technology, and capital) are utilized optimally to achieve performance targets. This includes goals related to profitability, productivity, quality, and safeguarding assets—all of which directly address resource efficiency.
In contrast, strategic objectives are high-level goals aligned with the organization's mission and vision; reporting objectives focus on the reliability, timeliness, and transparency of internal and external reporting; and compliance objectives ensure adherence to laws, regulations, and policies. Only operational objectives directly encompass the broad goal of resource effectiveness and efficiency.
Why the other options are incorrect:
A. Strategic objectives: These are high-level, long-term goals that relate to the organization's overall mission, vision, and stakeholder expectations. They do not specifically address resource efficiency; rather, they set the direction for the entire entity.
C. Reporting objectives:These relate to the reliability, timeliness, and transparency of financial and non-financial reporting. They do not concern resource utilization.
D. Compliance objectives: These concern adherence to applicable laws, regulations, and internal policies. While non-compliance can waste resources, the objectives themselves are not defined by resource efficiency.
References:
COSO Internal Control – Integrated Framework (2013): Defines three categories of objectives: Operations, Reporting, and Compliance. Operations objectives are specifically described as pertaining to "the effective and efficient use of the entity's resources."
During the course of an audit, an internal auditor discovers that a valuable employee in the
research department has been patenting new developments in the employee's name that
are unrelated to the basic business of the organization.
The organization does not have a policy addressing this specific issue, but does have a
general policy that all important new discoveries by employees are the property of the
organization.
Division management views the employee's actions as extra incentive to retain the
employee.
A decision to include the employee's action in the engagement final communication would
be:
1. A violation of the IIA Code of Ethics.
2. A violation of the reporting requirements in the Standards.
3. Justified and necessary, according to the IIA Code of Ethics and Standards.
A. 1 only
B. 2 only
C. 3 only
D. 1 and 2 only
Explanation:
This scenario involves a conflict between division management's desire to retain a valuable employee and the organization's stated policy that all important discoveries by employees are the property of the organization. The employee is patenting developments in their own name, which is a direct violation of organizational policy, regardless of management's view that it provides extra incentive.
Including this finding in the engagement final communication is both justified and necessary under the IIA Code of Ethics and Standards for the following reasons:
Standard 2400 – Communicating Results: Internal auditors must communicate the results of engagements, which include significant findings and recommendations. A material violation of organizational policy—such as an employee claiming ownership of intellectual property that belongs to the organization—constitutes a significant finding that must be reported.
Standard 2410 – Criteria for Communicating: Communications must include the engagement's objectives, scope, and results. Results include findings, conclusions, and recommendations. Omitting a significant violation of policy would render the communication incomplete and misleading.
Code of Ethics – Integrity: The Code requires internal auditors to "perform their work with honesty, diligence, and responsibility" and to "observe the law and make disclosures expected by the law and the profession." Concealing a known policy violation, even if management condones it, would compromise integrity.
Code of Ethics – Objectivity: Internal auditors must make a balanced assessment and not be unduly influenced by management's preferences. Division management's rationale (employee retention) does not override the requirement to report a material noncompliance with organizational policy.
Why the other options are incorrect:
Statement 1 – A violation of the Code of Ethics: Incorrect. Reporting a material policy violation is required by the Code of Ethics (Integrity and Objectivity), not a violation. Concealing it would be a violation.
Statement 2 – A violation of reporting requirements in the Standards: Incorrect. The Standards explicitly require communication of significant findings (Standard 2400). Omitting this finding would violate the Standards, while including it satisfies them.
Statements 1 and 2: Since both individual statements are false, any combination containing them (A, B, or D) is incorrect.
References:
IIA Standard 2400 – Communicating Results: "Internal auditors must communicate the results of engagements."
IIA Standard 2410 – Criteria for Communicating: "Communications must include the engagement’s objectives, scope, and results."
An internal auditor notes that employees are able to download files from the internet. According to IIA guidance, which of the following strategies would best protect the organization from the risk of copyright infringement and licensing violations resulting from this practice?
A. Apply antivirus and patch management software.
B. Utilize dedicated and encrypted network connections.
C. Install a software inventory management application.
D. Utilize secure socket layer encryption.
Explanation:
A software inventory management application is the most direct and effective strategy for protecting the organization from copyright infringement and licensing violations because it provides the visibility needed to ensure compliance. The risk arises from employees downloading unapproved or unlicensed software, making the organization vulnerable to legal and financial penalties . To manage this risk, the organization must be able to answer two critical questions: what software is installed, and where is it being used? Without tracking installations and comparing them to license entitlements, compliance cannot be verified .
Why the other options are incorrect
A. Apply antivirus and patch management software:
This addresses cybersecurity threats (like malware and system vulnerabilities) rather than the legal and compliance risk of copyright infringement .
B. Utilize dedicated and encrypted network connections:
This focuses on the security and confidentiality of data in transit, which is unrelated to the management of software licenses .
D. Utilize secure socket layer encryption:
This is a security protocol to protect data transmitted over the internet, serving a different purpose from software license compliance .
References
IIA Standard 2120 – Risk Management: The internal audit activity must evaluate the effectiveness and contribute to the improvement of risk management processes, which includes protecting the organization from compliance risks like licensing violations.
IIA Practice Guide – "Auditing the Risk Management Process": This guide highlights the need to evaluate the controls in place to manage and mitigate risks, including the use of tools such as software asset management applications for compliance purposes.
Which of the following controls is not appropriate for sales in a manufacturing organization?
A. Customers' orders are recorded promptly.
B. Goods shipped are matched with valid customer orders.
C. Goods returned are inspected for damage by the receiving department for proper disposition.
D. Sales department approval is required for credit sales transactions.
Explanation:
In a manufacturing organization, the Sales Department is responsible for generating revenue, promoting products, and managing customer relationships. It is an operational function that works directly with customers and has a natural bias toward closing deals and maximizing sales volume. Requiring the Sales Department to approve credit sales transactions creates an incompatible segregation of duties and a fundamental control weakness, because the same department that initiates a transaction (sales) would also be authorizing the extension of credit to the customer.
Why the other options are correct controls
A. Customers' orders are recorded promptly:
This is an appropriate control to ensure that all sales are captured completely and accurately, preventing revenue leakage and ensuring timely recognition of transactions.
B. Goods shipped are matched with valid customer orders:
This is an appropriate control to prevent shipping errors, unauthorized shipments, and fraudulent activities. Matching ensures that only legitimate, approved orders are fulfilled.
C. Goods returned are inspected for damage by the receiving department for proper disposition:
This is an appropriate control to ensure that returned goods are properly evaluated for restocking, disposal, or credit issuance. The receiving department provides an independent assessment separate from the sales function.
References
IIA Standard 2130 – Control: "The internal audit activity must assist the organization in maintaining effective controls by evaluating their effectiveness and efficiency and by promoting continuous improvement."
COSO Internal Control – Integrated Framework (2013): Identifies segregation of duties as a key control activity, specifically separating authorization (credit approval) from transaction initiation (sales) and record-keeping.
A government agency's policy states that board members' travel and hospitality expenses must be audited annually. Which of following people or groups is most appropriate to perform this audit?
A. The government's independent auditor.
B. The external auditors from an accounting firm.
C. The internal audit activity.
D. The agency's chief compliance officer.
Explanation:
This scenario involves auditing the expenses of board members, who hold the highest governance position in the organization. The key principle is that the auditor must be independent of the persons being audited and free from management influence. The internal audit activity is uniquely positioned to fulfill this requirement, as the IIA Standards mandate that the chief audit executive (CAE) report functionally to the board, ensuring the activity has the organizational independence necessary to conduct audits of senior management and board members without interference . An internal audit of board member expenses is a routine, internal assurance engagement, which aligns directly with the primary purpose of the internal audit activity . Independent oversight of executive and board expenses is a recognized practice, as it helps prevent inappropriate expenditures and serves as a key control to reassure the public and ensure that expenses serve the public interest .
Why the other options are incorrect
A. The government's independent auditor:
This typically refers to the legislative auditor or auditor general, who conducts performance or financial audits of government entities as a whole, not routine, policy-mandated internal audits of specific board expenses. This would be an inefficient and disproportionate use of their resources .
B. The external auditors from an accounting firm:
External auditors focus on the annual financial statement audit and are not engaged to perform routine, policy-mandated internal audits. Using them for this purpose would be outside their standard scope and cost-prohibitive.
D. The agency's chief compliance officer:
The chief compliance officer is a management function, often falling within the second line of defense . As a member of management, the compliance officer would not be independent of the board members whose expenses are under review, as the board has oversight authority over management. Auditing the expenses of those who oversee your role presents a significant conflict of interest.
References
IIA Standard 1100 – Independence and Objectivity: "The internal audit activity must be independent, and internal auditors must be objective in performing their work" .
IIA Standard 1110 – Organizational Independence: "The chief audit executive must report to a level within the organization that allows the internal audit activity to fulfill its responsibilities... Organizational independence is effectively achieved when the chief audit executive reports functionally to the board" .
Which of the following decisions made during the testing phase of a compliance audit requires the most judgment by an internal auditor?
A. Which sampling methodology to select for testing.
B. Which fields to examine on each invoice.
C. Whether an individual expenditure is allowable.
D. What level of noncompliance is acceptable.
Explanation:
This question tests the distinction between technical/mechanical decisions and professional judgment in auditing. During the testing phase of a compliance audit, the decision that requires the most professional judgment is determining the level of noncompliance that is acceptable—i.e., the tolerable deviation rate. This decision inherently involves balancing multiple subjective factors:
Materiality: The auditor must assess whether identified deviations are quantitatively or qualitatively material to the overall compliance objective.
Risk Appetite: The auditor must consider management's and the board's tolerance for compliance failures, which is not a fixed number but a contextual judgment.
Root Cause Analysis: The auditor must evaluate whether deviations are isolated errors (acceptable within tolerance) or indicative of systemic control failures (unacceptable even if below a numerical threshold).
Regulatory Context: The auditor must interpret laws and regulations, which often contain ambiguities that require judgment on what constitutes a "material" or "significant" violation.
While the other options involve decisions, they are largely technical, procedural, or referential in nature, requiring less subjective judgment. The auditor can rely on established policies, checklists, and mathematical models for those decisions. In contrast, setting the acceptable level of noncompliance requires synthesizing legal, operational, and governance considerations into a defensible professional conclusion.
Why the other options are incorrect
A. Which sampling methodology to select for testing:
This is a technical decision guided by documented standards, engagement objectives, and statistical principles. The auditor applies established criteria (e.g., expected deviation rate, confidence level) to choose between statistical or non-statistical sampling—it involves methodology, not subjective value judgment.
B. Which fields to examine on each invoice:
This is a procedural decision driven by the audit program, control objectives, and prior risk assessment. The auditor focuses on fields that capture critical compliance data (e.g., amount, vendor, authorization)—this is a routine, checklist-based decision.
C. Whether an individual expenditure is allowable:
While this requires interpretation of policies, it is typically a binary fact-based determination. The auditor compares the expenditure against defined allowable costs—the judgment is limited to applying a rule to a specific fact pattern, not setting the threshold for acceptability.
References
IIA Standard 2220 – Engagement Scope: Requires auditors to determine the scope of work "with consideration of the risk management processes, the control environment, and the objectives of the engagement." Setting the acceptable level of deviation (tolerable error) is a critical component of scoping that requires judgment.
According to the IIA guidance, who is responsible for periodically assessing the internal audit activity?
A. The board.
B. The chief audit executive.
C. Senior management.
D. The external auditors.
Explanation:
The IIA Standards require the CAE to develop and maintain a Quality Assurance and Improvement Program (QAIP) that covers all aspects of the internal audit activity . This program includes both internal assessments (ongoing monitoring and periodic self-assessments) and external assessments conducted at least once every five years by a qualified, independent party from outside the organization .
The CAE has the primary responsibility for ensuring these assessments are conducted and for implementing improvements based on their results . While the board receives assurance about the quality of the internal audit function's performance through the QAIP , the responsibility for conducting the assessment rests with the CAE .
Why the other options are incorrect
A. The board: The board receives and reviews the results of the quality assessments to provide oversight, but it is not responsible for performing them. The board's role is governance and oversight .
C. Senior management: Senior management receives the results of the quality assessments as a stakeholder, but the CAE is accountable for developing and executing the QAIP .
D. The external auditors: External auditors are not responsible for assessing the internal audit activity. They may coordinate with internal audit, but the QAIP is a specific requirement for the internal audit function and is managed by the CAE .
References
IIA Standard 1300 – Quality Assurance and Improvement Program: "The chief audit executive must develop and maintain a quality assurance and improvement program that covers all aspects of the internal audit activity" .
According to IIA guidance, which of the following statements regarding the internal audit charter is true?
A. Senior management should approve the charter before it is submitted to the board.
B. The charter should describe the purpose and authority of the internal audit activity, consistent with the Standards.
C. The charter should define the consulting services that the internal audit activity is permitted to perform.
D. The CEO periodically should assess whether the terms of the charter continue to be adequate.
Explanation:
The internal audit charter is a foundational, board-approved document that formally establishes the internal audit activity's role within the organization. According to IIA Standard 1000, the charter must define the activity's purpose, authority, and responsibility in a manner that is consistent with the mandatory elements of the International Professional Practices Framework (IPPF). The charter sets the position of the internal audit activity, authorizes necessary access to records and personnel, and defines its scope.
Why the other options are incorrect
A. Senior management should approve the charter before it is submitted to the board:
Incorrect. While the CAE should discuss the charter with senior management, final approval authority resides with the board (or governing body). The board's final approval is documented in meeting minutes to formally establish the audit activity's authority.
C. The charter should define the consulting services that the internal audit activity is permitted to perform:
Incorrect. The charter must define the nature of consulting services, but this is a required component under Standards 1000.C1, not a complete definition of permitted services. The nature and scope of individual consulting engagements are agreed upon with the client on a case-by-case basis.
D. The CEO periodically should assess whether the terms of the charter continue to be adequate:
Incorrect. Responsibility for periodically reviewing the charter rests with the chief audit executive (CAE), not the CEO. The CAE presents the results of this review to senior management and the board to ensure the charter remains adequate for the activity to meet its objectives.
| Page 3 out of 24 Pages |
| 12345678 |
| IIA-CRMA-ADV Practice Test Home |
Real-World Scenario Mastery: Our IIA-CRMA-ADV practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before Certification in Risk Management Assurance exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive IIA-CRMA-ADV practice exam questions pool covering all topics, the real exam feels like just another practice session.