Free IIA-CRMA-ADV Practice Test Questions 2026

283 Questions


Last Updated On : 3-Aug-2026


Topic 1: Exam Pool A

During an internal audit, the internal auditor compares the employee turnover rate in the area being audited with the employee turnover rate in the organization as a whole. This is an example of which of the following analytical auditing procedures?


A. Reasonableness test.


B. Regression analysis.


C. Benchmarking.


D. Trend analysis.





C.
  Benchmarking.

Explanation:

Benchmarking is an analytical procedure that involves comparing an organization's metrics, processes, or performance indicators against those of other entities or against internal standards to identify best practices, areas for improvement, or significant deviations. In this scenario, the internal auditor is comparing the turnover rate of a specific area (e.g., a department or division) against the turnover rate of the entire organization (an internal benchmark). This comparison provides context for evaluating whether the area's turnover is unusually high or low relative to the organizational average, which could indicate underlying issues such as poor management, low morale, or compensation problems.

Why the other options are incorrect:

A. Reasonableness test:
This involves analyzing a relationship between two or more data points to see if they are logically consistent (e.g., comparing total payroll expense to number of employees). It does not involve comparing a specific area's metric to an organizational average.

B. Regression analysis:
This is a statistical technique used to model the relationship between a dependent variable and one or more independent variables. It is not a simple comparison of one metric against another.

D. Trend analysis:
This involves comparing data over time (e.g., turnover rates year-over-year) to identify patterns or changes. The auditor in this scenario is comparing across entities (the area vs. the organization), not across time periods.

References:

IIA Standard 2320 – Analysis and Evaluation: Requires internal auditors to base conclusions and engagement results on appropriate analyses and evaluations. Benchmarking is a recognized analytical technique under this standard.

IIA Practice Guide – "Analytical Procedures": Defines benchmarking as comparing client data to internal or external benchmarks to identify unusual fluctuations or relationships.

Which of the following activities best reflects the scope and status of the internal audit activity as defined in the internal audit policy statement?


A. The internal auditor reviews the physical access to merchandise during an inventory count.


B. The audit manager conducts an internal quality assessment of the internal audit activity’s adherence to the Standards.


C. The audit manager refrains from assigning an auditor who was a former payroll clerk to conduct a payroll audit.


D. The board approves the annual performance evaluation of the chief audit executive.





A.
  The internal auditor reviews the physical access to merchandise during an inventory count.

Explanation:

The internal audit charter is a formal document that defines the purpose, authority, and responsibility of the internal audit activity . A key element of this charter is defining the scope of internal audit activities, which is the range of actions the function is authorized to perform . This scope is fundamentally tied to the Definition of Internal Auditing: an independent, objective assurance and consulting activity designed to add value and improve an organization’s operations .

An activity like reviewing physical access to inventory is a core assurance task. It directly supports the internal audit's mission of evaluating and improving the effectiveness of risk management, control, and governance processes . This specific task involves the systematic evaluation of internal controls (inventory security), which is a primary component of the audit scope as defined by the Standards .

Why the other options are incorrect:

B. The audit manager conducts an internal quality assessment of the internal audit activity’s adherence to the Standards.
This is a management and quality assurance activity, not a reflection of the audit function's scope as defined in the charter. It pertains to the Standards (Standard 1300 series) governing the internal audit function itself, rather than the activities it is authorized to perform across the organization.

C. The audit manager refrains from assigning an auditor who was a former payroll clerk to conduct a payroll audit.
This action addresses individual objectivity. Avoiding a conflict of interest is a requirement of the Code of Ethics and the Standards, but it relates to the professional conduct of auditors and safeguarding independence, not to defining the scope of work as per the charter.

D. The board approves the annual performance evaluation of the chief audit executive.
This is a governance and oversight action that supports the independence and accountability of the internal audit function. While it relates to the charter's provisions on the CAE's relationship with the board, it is not itself an activity that reflects the audit scope.

References:

IIA Standard 1000 – Purpose, Authority, and Responsibility: The purpose, authority, and responsibility of the internal audit activity must be formally defined in an internal audit charter .

IIA Implementation Guide 1000: The charter defines the scope of internal audit activities and authorizes access to records, personnel, and physical properties relevant to the performance of engagements .

A manufacturing organization discovers that the waste water released has failed to meet permitted limits.
Which control function will be least effective in correcting the issue?


A. Performing a chemical analysis of the water, prior to discharge, for components specified in the permit.


B. Posting signs that tell employees which substances may be disposed of via sinks and floor drains within the facility.


C. Diluting pollutants by flushing sinks and floor drains daily with large volumes of clean water.


D. Establishing a preventive maintenance program for the pretreatment system.





C.
  Diluting pollutants by flushing sinks and floor drains daily with large volumes of clean water.

Explanation:

This scenario involves a violation of environmental regulations regarding wastewater discharge. A corrective action is needed to bring the organization back into compliance.

Option C describes dilution, which is a flawed and ineffective approach to correcting a pollution problem. Diluting pollutants does not remove them; it merely reduces their concentration, which is often illegal and ineffective as a long-term solution. Furthermore, flushing large volumes of clean water would increase the total volume of wastewater, potentially violating the permit's volume limits and burdening the treatment system. This is a temporary, non-sustainable fix that fails to address the root cause of the pollution.

Why the other options are incorrect:

A. Performing a chemical analysis of the water, prior to discharge:
This is an effective detective and corrective control. It allows the organization to identify non-compliant water before it is discharged, enabling corrective action to be taken.

B. Posting signs that tell employees which substances may be disposed of:
This is an effective preventive control. It helps ensure that only permitted substances enter the waste stream in the first place.

D. Establishing a preventive maintenance program for the pretreatment system:
This is an effective preventive control. Regular maintenance ensures the treatment system operates effectively, reducing the risk of non-compliant discharges.

References:

IIA Standard 2130 – Control: Requires internal auditors to evaluate the effectiveness of controls, which includes assessing whether corrective actions address root causes.

IIA Practice Guide – "Auditing Environmental Risk and Compliance": dentifies dilution as a weak control and recommends source reduction and treatment as more effective strategies.

An organization has implemented a new automated payroll system that contains a table of pay rates that are matched to employee job classifications. Which control should an internal auditor suggest in order to ensure that the table is updated correctly, and is used only for valid pay changes?


A. Restrict data-table access from management and line supervisors who have the authority to determine pay rates.


B. Require a supervisor in the department, who has the ability to change the table, to compare the changes to a signed management authorization.


C. Ensure that adequate edit and reasonableness checks are built into the automated system.


D. Require a manager, who is independent of the system and who cannot change the table, to authorize and sign-off on any employee pay changes.





D.
  Require a manager, who is independent of the system and who cannot change the table, to authorize and sign-off on any employee pay changes.

Explanation:

This question addresses the need for a control to ensure that the pay rate table is updated correctly (accurate data) and only for valid pay changes (authorized transactions). The most effective control is a segregation of duties between the authorization of pay changes and the ability to update the system table.

Option D provides this safeguard by requiring an independent manager—who does not have the ability to change the table—to authorize and sign-off on any pay changes. This ensures that every change is formally approved by someone with proper authority (not the person making the system update), creating an independent verification layer. This prevents unauthorized, erroneous, or fraudulent updates to the pay rate table.

Why the other options are incorrect::

A. Restrict data-table access from management and line supervisors who have the authority to determine pay rates:
This is incorrect because the people who determine pay rates (management/supervisors) are the ones who initiate pay changes. They need a mechanism to communicate those changes. Restricting their access does not ensure that changes are valid or correctly updated; it merely prevents them from making the updates themselves, which could be an appropriate segregation but does not address authorization and accuracy.

B. Require a supervisor in the department, who has the ability to change the table, to compare changes to a signed management authorization:
This is incorrect because the supervisor who can change the table is the same person performing the comparison. There is no independent verification—the person making the change is also checking their own work, which creates a conflict of interest and does not provide an objective review.

C. Ensure that adequate edit and reasonableness checks are built into the automated system:
This is a system-level processing control that can help detect data entry errors (e.g., pay rate too high), but it does not address the authorization of changes. A system check cannot verify whether a pay change was properly approved by management; it only verifies that the data falls within acceptable parameters.

References:

IIA Standard 2130 – Control:Requires internal auditors to evaluate the effectiveness of controls, including segregation of duties and authorization controls.

Why are preventative controls generally preferred to detective controls?


A. Because preventive controls promote doing the right thing in the first place, and lessen the need for corrective action.


B. Because preventive controls are more sensitive and identify more exceptions than detective controls.


C. Because preventive controls include output procedures, which cover the full range of possible reviews, reconciliations and analysis.


D. Because preventive controls identify exceptions after-the-fact, allowing them to be used after the entire review is complete and therefore finding exceptions that detective controls may have missed.





A.
  Because preventive controls promote doing the right thing in the first place, and lessen the need for corrective action.

Explanation:

Preventive controls are generally preferred over detective controls because they are designed to stop errors or irregularities from occurring in the first place. By preventing a problem from happening, the organization avoids the cost, time, and effort required to detect and correct the issue after it has occurred. In contrast, detective controls only identify problems after they have happened, which means some damage (financial, operational, or reputational) may have already occurred and corrective action is still needed.

Why the other options are incorrect:

B. Because preventive controls are more sensitive and identify more exceptions than detective controls:
This is incorrect. Preventive controls do not identify exceptions; they prevent them. Detective controls are the ones that identify exceptions after they occur.

C. Because preventive controls include output procedures, which cover the full range of possible reviews, reconciliations and analysis:
This is incorrect. Output procedures, reviews, reconciliations, and analysis are characteristic of detective controls, not preventive controls.

D. Because preventive controls identify exceptions after-the-fact, allowing them to be used after the entire review is complete and therefore finding exceptions that detective controls may have missed:
This is incorrect. It inaccurately describes preventive controls as detective controls. Preventive controls act before an event occurs.

References:

IIA Standard 2130 – Control: Requires internal auditors to evaluate the effectiveness of controls, which includes assessing whether controls are preventive, detective, or corrective. Preventive controls are considered more effective because they stop issues before they arise.

COSO Internal Control – Integrated Framework (2013): Identifies preventive controls as those that stop problems before they occur, thereby reducing the need for corrective action and improving efficiency.

An internal auditor finds during an engagement that payment for the organization's general insurance policy is two months overdue. The issue is informally mentioned tothe finance department which immediately submits the invoice for payment. The auditor decides to exclude this finding from the final audit report as the oversight was immediately corrected and there were no consequences because of this late payment. Which of the following rules of conduct as described in the IIA Code of Ethics, did the auditor fail to uphold?


A. Confidentiality.


B. Objectivity.


C. Integrity.


D. Competency.





B.
  Objectivity.

Explanation:

The auditor discovered a material issue—a payment that was two months overdue on a critical policy (general insurance). This finding is significant because:

It represents a control failure (failure to pay on time).
It exposes the organization to potential risk (policy may have lapsed or coverage been interrupted, even if no loss occurred yet).
It indicates a process breakdown that could recur.

The auditor's decision to exclude this finding from the final audit report—simply because it was corrected informally—violates the Integrity principle of the IIA Code of Ethics. The Code requires internal auditors to "perform their work with honesty, diligence, and responsibility" and to "make disclosures of all material facts known to them that, if not disclosed, may distort the reporting of activities under review."

Why the other options are incorrect:

A. Confidentiality:
This principle concerns the unauthorized disclosure of information. The auditor did not disclose confidential information inappropriately; they withheld information from the report, which is the opposite of a confidentiality breach.

B. Objectivity:
While objectivity requires impartiality and freedom from bias, the primary violation here is not bias but dishonesty/incompleteness in reporting. The auditor’s action was not driven by a conflict of interest but by a failure to report material facts.

D. Competency:
Competency relates to possessing the necessary knowledge and skills to perform the audit. The auditor had the skill to identify the issue; the failure was in reporting it, not in understanding it.

References:

IIA Code of Ethics – Principle I:Integrity: Internal auditors shall perform their work with honesty, diligence, and responsibility.

IIA Code of Ethics – Rule of Conduct (Integrity):Internal auditors shall make disclosures of all material facts known to them that, if not disclosed, may distort the reporting of activities under review.

The audit committee is concerned that the small size of the internal audit activity (IAA) makes it impractical to achieve full conformance with the Standards. To address this concern, which of the following actions is most appropriate for the CAE to take?


A. The CAE should agree with the audit committee and implement only those standards appropriate to the size of the IAA.


B. The CAE should request the audit committee to review the Standards to identify specifically which are creating the greatest concern.


C. The CAE should seek sufficient funding to increase audit resources to meet the minimum requirements of the Standards.


D. The CAE should explain that conformance with the Standards is essential and not dependent upon the size of the IAA.





D.
  The CAE should explain that conformance with the Standards is essential and not dependent upon the size of the IAA.

Explanation:

The IIA Standards are designed to be scalable and applicable to all internal audit activities, regardless of size. The size of the internal audit activity (IAA) does not determine the requirement for conformance; rather, how the IAA achieves conformance may differ based on its resources and structure.

The CAE has a fundamental responsibility to ensure that the IAA conforms to the Standards, as mandated by Standard 1300 and supported by the Code of Ethics. Conformance is an absolute requirement for the IAA to fulfill its mission and provide credible assurance. Therefore, the most appropriate action is for the CAE to communicate this principle to the audit committee, clarifying that while the methods of implementation may be tailored to the IAA's size, the requirement to conform is non-negotiable.

Why the other options are incorrect:

A. The CAE should agree with the audit committee and implement only those standards appropriate to the size of the IAA:
Incorrect. The CAE cannot selectively adopt only "appropriate" standards. The Standards apply in their entirety, though implementation can be scaled.

B. The CAE should request the audit committee to review the Standards to identify specifically which are creating the greatest concern:
Incorrect. This shifts the CAE's responsibility to the audit committee. The CAE is accountable for understanding and implementing the Standards, not the audit committee.

C. The CAE should seek sufficient funding to increase audit resources to meet the minimum requirements of the Standards:
Incorrect. While sufficient resources are important, conformance with the Standards is not solely about having more staff. The IAA can conform with fewer staff by using external resources, prioritizing engagements, or implementing scaled procedures. Funding alone does not guarantee conformance.

References:

IIA Standard 1300 – Quality Assurance and Improvement Program: "The chief audit executive must develop and maintain a quality assurance and improvement program that covers all aspects of the internal audit activity." This applies to all IAAs regardless of size.

Which of the following risk management activities is most appropriate for an internal auditor to undertake?


A. Impose risk management processes.


B. Coordinate risk management activities.


C. Implement risk responses on management's behalf.


D. Review the management of key risks.





D.
  Review the management of key risks.

Explanation:

This question addresses the fundamental boundary between management's responsibility for risk and internal audit's role in providing assurance. According to the IIA's Three Lines of Defense model and related guidance, internal audit's core role concerning risk management is to provide independent, objective assurance to the board and management . This assurance role is explicitly defined in the Standards, which require the internal audit activity to evaluate the effectiveness of risk management processes and review how key risks are managed .

Reviewing management of key risks involves examining whether significant risks have been properly identified, assessed, and controlled, and whether the associated risk responses align with the organization's risk appetite . This is an objective evaluation activity, which preserves the auditor's independence and objectivity as the third line of defense .

Why the other options are incorrect:

A. Impose risk management processes:
This is a management responsibility, not an audit activity. IIA guidance explicitly states that imposing risk management processes is a role internal audit "should not undertake" as it would involve taking on management's accountability .

B. Coordinate risk management activities:
While this can be a legitimate consulting role with proper safeguards, it is not the most appropriate activity for internal audit's core role. If carried out, it must be treated as a consulting engagement to protect objectivity . Reviewing key risks remains the primary assurance function.

C. Implement risk responses on management's behalf:
This is strictly prohibited. Internal auditors must never assume management responsibility by actually managing risks or implementing responses, as this would create a severe self-review threat and compromise objectivity .

References:

IIA Standard 2120 – Risk Management: The internal audit activity must evaluate the effectiveness and contribute to the improvement of risk management processes .

IIA Position Paper – The Role of Internal Auditing in ERM (2009): Lists "reviewing the management of key risks" as a legitimate assurance role, while "implementing risk responses on behalf of management" is explicitly a role internal audit should not undertake .

Allegations have been made that an organization's share price has been manipulated.
Which of the following would provide an internal auditor with the most objective evidence in this case?


A. Major shareholders of the organization.


B. Large customers of the organization.


C. Former members of management.


D. Former financial consultants.





B.
  Large customers of the organization.

Explanation:

When investigating share price manipulation, an internal auditor needs evidence that is objective, verifiable, and unlikely to be influenced by the parties under scrutiny. The goal is to uncover activities like artificial trading, false information dissemination, or collusion designed to distort the market price .

Large customers are the most objective source because their primary business relationship with the organization is through commercial transactions, not financial engineering. Their transaction records, order histories, and accounts payable/receivable data provide concrete, documentary evidence of real economic activity. If a share price rise is unsupported by actual business performance, customer data will not corroborate it. This aligns with the internal auditor's scope of work, which includes verifying financial transactions and assessing internal controls .

Why the other options are incorrect:

A. Major shareholders: They may have a direct financial interest in the share price and could be actively involved in or benefit from manipulation schemes . Their testimony is potentially self-serving and less reliable.

C. Former members of management: Their statements are subjective and could be influenced by personal grievances, ongoing litigation, or a desire to avoid personal liability for decisions made during their tenure.

D. Former financial consultants: Like former managers, their perspectives may be subjective. They are paid advisors, not independent transactional counterparties, and their account of events can be colored by disputes or the terms of their departure.

The most reliable evidence in such cases comes from objective, third-party transactional data, which is precisely what is obtained from large customers, rather than from the potentially biased statements of insiders or interested parties .

References:

IIA Standard 2310 – Identifying Information: Requires internal auditors to identify sufficient, reliable, relevant, and useful information to achieve engagement objectives.

IIA Standard 2320 – Analysis and Evaluation: Requires internal auditors to base conclusions on appropriate analyses and evaluations.

According to IIA guidance, which of the following individuals would best be considered independent for the purpose of participating in an external assessment of the quality assurance and improvement program for an internal audit activity (IAA)?


A. A former employee knowledgeable of the IAA who resigned three years earlier from the organization.


B. A competent employee of an independent external organization that provides cosourcing services to the IAA.


C. An employee in an affiliated organization who has never worked directly with the IAA.


D. An employee in the parent organization who has not had any previous contact with the IAA.





A.
  A former employee knowledgeable of the IAA who resigned three years earlier from the organization.

Explanation:

This question tests the requirement for an independent assessor or assessment team to conduct an external quality assessment of the internal audit activity (IAA), as mandated by the Standards. The key element is independence, meaning the assessor must be free from conflicts of interest and not be under the influence of the organization being reviewed.

For an external assessment, an independent assessor must be "from outside the organization," with no actual, potential, or perceived conflicts of interest. When considering former employees, a critical factor is the length of time they have been independent. The Implementation Guide for Standard 1312 advises that consideration should be given to how long the former employee has been separated from the organization, where "independent" means not having a conflict of interest and not being a part of, or under the control of, the organization. A three-year separation is a sufficient cooling-off period to reasonably conclude that the individual is no longer influenced by the organization and can provide an objective assessment.

Why the other options are incorrect:

B. An employee of an independent external organization that provides cosourcing services to the IAA.
A provider of cosourcing services has a significant, ongoing business relationship with the IAA. This creates a direct conflict of interest and an impairment to objectivity, as they are effectively auditing a client they also serve.

C. An employee in an affiliated organization who has never worked directly with the IAA.
Individuals from a "related organization" (e.g., a parent company or affiliate) are not considered independent for this purpose, even if they have not worked directly with the IAA. The organizational relationship itself creates a potential conflict of interest.

D. An employee in the parent organization who has not had any previous contact with the IAA.
Similar to option C, a person from the parent organization is not independent for an external assessment. The Implementation Guide explicitly states that individuals from a parent organization are not considered independent, regardless of their prior contact.

References:

IIA Standard 1312 – External Assessments: Requires that external assessments be conducted by a qualified, independent assessor or assessment team from outside the organization, with the CAE discussing their independence and any potential conflict of interest with the board.

During an internal audit, an organization's processing department is found to have incidences of both duplicate invoices and notices from customers that purchased goods were not received. The department under review insists that some of these reports are false and that others were isolated oversights due to understaffing. Which of the following tests would best help the internal auditor detect fraudulent activity?


A. Check inventory levels.


B. Search for gaps in check numbers.


C. Compare vendor summaries.


D. Review raw material purchase quantities.





A.
  Check inventory levels.

Explanation:

The scenario presents two classic red flags: duplicate invoices (payments made twice for the same goods) and customer complaints about non-receipt of goods (goods billed but not shipped). The department attributes these to false reports and understaffing—both plausible excuses, but also potential cover stories for fraud.

Why the other options are incorrect:

B. Search for gaps in check numbers:
This is a test for missing documents (e.g., checks destroyed or voided to conceal theft). While useful, it does not directly address duplicate invoices or customer non-receipt complaints, which involve fictitious transactions rather than missing payment records.

C. Compare vendor summaries:
This compares total purchases from vendors to identify unusual patterns. It may highlight a concentration of purchases from a suspicious vendor, but it does not directly test whether goods were actually received or whether invoices are legitimate.

D. Review raw material purchase quantities:
This would compare raw material purchases to production output to see if quantities are reasonable. While this can detect inflated purchases, it does not directly test whether goods were actually received or whether sales are fictitious. It is a less direct and less effective test for the fraud indicators described.

References:

IIA Standard 2320 – Analysis and Evaluation: Requires internal auditors to base conclusions on appropriate analyses and evaluations. Physical inventory observation is a recognized analytical and verification procedure under this standard.

IIA Practice Guide – "Auditing Inventory and Warehousing": Recommends observing physical inventory counts and reconciling them to perpetual records as a key procedure to detect fraud, theft, and recording errors.

Which of the following would provide the best evidence of errors in the quantities of items received from suppliers?


A. Suppliers' reports of over shipments.


B. Warehouse receiving logs.


C. Purchase requisitions and purchase orders.


D. Observation and inspection of inventory.





B.
  Warehouse receiving logs.

Explanation:

This question asks for the best evidence to identify errors in the quantities of items received from suppliers. The receiving log is the primary document created at the point of receipt, documenting the actual quantities of goods received as they enter the warehouse. It provides a direct, contemporaneous record of what was physically received, making it the most relevant and reliable evidence for identifying quantity discrepancies. When compared to purchase orders (what was ordered) and supplier invoices (what was billed), the receiving log is the critical document for detecting over-shipments, under-shipments, or shipment errors.

Why the other options are incorrect:

A. Suppliers' reports of over shipments:
While a supplier's notification is relevant, it is not the best evidence. It is a self-reported document from the supplier, which may be less reliable or complete, and does not provide an independent verification of what was physically received.

C. Purchase requisitions and purchase orders:
These documents reflect what was ordered, not what was actually received. They are useful for testing authorization and completeness, but they do not provide evidence of actual receipt quantities.

D. Observation and inspection of inventory:
While observing and inspecting inventory is a valid audit procedure, it is more effective for verifying the existence and condition of inventory on hand at a point in time. It is less effective for detecting receiving quantity errors because those errors would have been recorded (or not recorded) in the receiving log at the time of receipt.

References:

IIA Standard 2310 – Identifying Information: Requires internal auditors to identify sufficient, reliable, relevant, and useful information to achieve the engagement's objectives. Warehouse receiving logs are a primary source document that provides direct evidence of receipt quantities.

IIA Practice Guide – "Auditing Inventory and Warehousing": Recommends comparing receiving logs to purchase orders and supplier invoices as a key procedure to detect quantity discrepancies.


Page 7 out of 24 Pages
PreviousNext
345678910
IIA-CRMA-ADV Practice Test Home

What Makes Our Certification in Risk Management Assurance Practice Test So Effective?

Real-World Scenario Mastery: Our IIA-CRMA-ADV practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.

Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before Certification in Risk Management Assurance exam day arrives.

Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive IIA-CRMA-ADV practice exam questions pool covering all topics, the real exam feels like just another practice session.