Free IIA-CRMA-ADV Practice Test Questions 2026

283 Questions


Last Updated On : 3-Aug-2026


Topic 1: Exam Pool A

While attending a conference, an internal auditor won an all-expense paid trip sponsored by a vendor of the internal auditor's organization.
Which of the following actions are most appropriate for the auditor to take?


A. Consult with an immediate supervisor and notify the organization's audit committee.


B. Consult with an immediate supervisor and review the organization's ethics policy.


C. Give the prize to a friend or family member and notitfy the organization's audit committee.


D. Give the prize to a friend or family member and review the organization's ethics policy.





B.
  Consult with an immediate supervisor and review the organization's ethics policy.

Explanation:

Accepting gifts or prizes from a vendor creates a potential conflict of interest and may impair the auditor's objectivity. The auditor must not accept anything that could be perceived as influencing their professional judgment. The most appropriate first step is to consult with an immediate supervisor to discuss the situation and seek guidance, while simultaneously reviewing the organization's ethics policy to understand any specific rules regarding gifts from vendors. This ensures the auditor acts transparently, seeks proper advice, and complies with both the IIA's Code of Ethics and the organization's internal policies.

Why the other options are incorrect:

A. Consult with supervisor and notify audit committee:
Notifying the audit committee is premature. The issue should first be discussed internally with the supervisor and evaluated against the organization's policy. The audit committee is not involved in routine conflict-of-interest matters unless they are significant or unresolved.

C. Give the prize to a friend/family member and notify audit committee:
This is inappropriate. Transferring the prize to a friend or family member does not eliminate the ethical dilemma; it may be seen as attempting to circumvent the rules. Additionally, the audit committee should not be the first point of contact.

D. Give the prize to a friend/family member and review policy:
Giving the prize away does not resolve the underlying conflict of interest. The auditor must first seek guidance from their supervisor and determine the proper course of action in accordance with the organization's policy.

References:

IIA Code of Ethics – Principle II:
Objectivity: Internal auditors shall not accept anything that may impair or be presumed to impair their professional judgment.

IIA Code of Ethics – Rule of Conduct (Objectivity): Internal auditors shall not accept anything that may impair or be presumed to impair their professional judgment.

While reviewing first quarter sales transactions, an internal auditor discovered that 10 invoices for a new customer had not been posted into the accounts receivable subsidiary ledger. Those 10 invoices were listed in an error report automatically generated by the sales processing system. The system had rejected the invoices because the customer's account number was not found in the customer master file. In this scenario, which of the following controls was lacking?


A. Corrective control.


B. Preventive control.


C. Detective control.


D. Directive control.





B.
  Preventive control.

Explanation:

This question asks about a missing control that allowed a failure to occur. The scenario describes a situation where ten invoices were rejected by the system because the customer's account number was not in the master file. This is a failure of a preventive control.

A preventive control is designed to stop an error or irregularity from occurring in the first place. In this case, the system should have prevented the sales transaction from being entered or processed if the customer account number was invalid. The error report is a detective control because it identifies the error after it occurred, but the lack of a control to prevent the entry of a transaction with an invalid account number is the missing preventive control. A proper preventive control would have required the account number to be validated against the master file at the time of data entry, rejecting the invoice immediately and notifying the user.

Why the other options are incorrect

A. Corrective control:
A corrective control fixes an error after it has been discovered. While the error report allows for correction, the fact that the invoices were posted to the system in the first place means the lack was in prevention, not correction.

C. Detective control:
The error report that listed the rejected invoices is a detective control. It exists, so it was not lacking. The missing control is the one that should have prevented the entry of the invalid invoices initially.

D. Directive control:
A directive control encourages or enforces a desired behavior (e.g., written policies). It is not relevant to a specific system validation failure.

References:

IIA Standard 2130 – Control: Requires internal auditors to evaluate the effectiveness of controls, including the classification of controls as preventive, detective, or corrective.

IIA Practice Guide – "Auditing Information Technology Controls": Defines preventive controls as those designed to prevent errors or irregularities from occurring, such as input validation and master file checks.

According to the Standards, for how long should internal auditors who have previously performed or had management responsibility for an operation wait to become involved in future internal audit activity with that same operation?


A. Three months.


B. Six months.


C. One year.


D. Two years.





C.
  One year.

Explanation:

The International Professional Practices Framework (IPPF) explicitly establishes this cooling-off period to protect the internal auditor's objectivity and prevent self-review threats. According to IIA Standard 1130.A1, "Objectivity is presumed to be impaired if an internal auditor provides assurance services for an activity for which the internal auditor had responsibility within the previous year" .

The one-year period is a mandatory minimum requirement designed to ensure sufficient distance between the auditor and their former responsibilities . This safeguard helps maintain the credibility of the audit activity and prevents actual or perceived conflicts of interest that could arise from auditing one's own work. The standard applies specifically to assurance services, where the auditor is evaluating and reporting on an activity they previously managed.

Why the other options are incorrect:

A. Three months and B. Six months are far too short to overcome the self-review threat. The IIA Standards do not recognize these periods; they are insufficient to ensure the auditor's impartiality.

D. Two years exceeds the IIA's minimum requirement. While some organizations may adopt stricter policies, the Standards only mandate a one-year wait .

References:

IIA Standard 1130.A1: "Internal auditors must refrain from assessing specific operations for which they were previously responsible. Objectivity is presumed to be impaired if an internal auditor provides assurance services for an activity for which the internal auditor had responsibility within the previous year" .

Management has asked the chief audit executive (CAE) to provide assurance on the organization's automated control system related to financial data. The current audit staff does not have the expertise needed to conduct this type of engagement. Which of the following would be the best response by the CAE?


A. Accept the assignment and use control self-assessment to complete the project.


B. Do not accept the assignment because the internal audit activity lacks the competency to perform the engagement with due professional care.


C. Accept the assignment and use an external provider with the necessary knowledge and skills to perform the engagement.


D. Accept the assignment if the engagement is included in the current audit plan, but inform senior management that the current audit staff does not have the knowledge and skills required.





C.
  Accept the assignment and use an external provider with the necessary knowledge and skills to perform the engagement.

Explanation:

When the internal audit staff lacks the required expertise for an engagement, the Standards do not require the CAE to decline it. Standard 1210.A1 explicitly states that the CAE "must obtain competent advice and assistance" if the internal auditors lack the necessary knowledge or skills. Engaging an external provider is a recognized, appropriate solution that allows the CAE to accept the assignment while ensuring the work is performed with due professional care. The CAE remains responsible for overseeing the external provider and ensuring the engagement meets the Standards.

Why the other options are incorrect:

A. Use control self-assessment (CSA):
CSA is a management technique, not an audit methodology. It cannot substitute for the technical expertise required to evaluate an automated financial control system. Relying on CSA would not address the competency gap and would compromise assurance reliability.

B. Do not accept the assignment:
This is unnecessarily drastic. The Standards provide a clear avenue to address the gap through external assistance. Refusing the engagement would fail to meet management's needs and ignore the permissive language of Standard 1210.A1.

D. Accept but inform management of the skills gap:
While disclosure is appropriate, this option does not address the core problem. Accepting the engagement without ensuring the work is competently performed—by either internal or external resources—would violate due professional care. The CAE must take action to fill the gap, not merely disclose it.

References:

IIA Standard 1210 – Proficiency: The internal audit activity collectively must possess or obtain the knowledge, skills, and other competencies needed to perform its responsibilities.

IIA Standard 1210.A1: The CAE must obtain competent advice and assistance if the internal auditors lack the knowledge, skills, or other competencies needed to perform all or part of the engagement.

A snow removal company is conducting a scenario planning exercise where participating employees consider the potential impacts of a significant reduction in annua snowfall for the coming winter. Which of the following best describes this type of risk?


A. Residual.


B. Net.


C. Inherent.


D. Accepted.





C.
  Inherent.

Explanation:

The scenario describes a company considering the potential impacts of a significant reduction in annual snowfall before any action is taken to manage or mitigate that risk. This is the definition of inherent risk—the risk that exists in the absence of any management actions or controls to alter its likelihood or impact. Inherent risk represents the raw exposure an organization faces from an event, such as a weather pattern, before any risk response strategies (like diversifying services or investing in snow-making equipment) are applied.

Why the other options are incorrect

A. Residual:
Residual risk is the risk that remains after management has implemented controls or mitigation strategies. In this scenario, the company is still in the planning stage and has not yet applied any responses, so the risk being evaluated is not residual.

B. Net:
Net risk is not a standard risk management term used in IIA or COSO frameworks. It is sometimes used colloquially to mean residual risk, but it is not recognized in official guidance.

D. Accepted:
Accepted risk is a response strategy where management consciously chooses to tolerate the risk within the organization's risk appetite, without taking additional action. The scenario describes evaluating the impact of a risk, not deciding to accept it.

References

IIA Standard 2120 – Risk Management: Requires internal audit to evaluate the effectiveness of risk management processes, which includes assessing whether risks are properly identified and categorized (e.g., inherent vs. residual).

ZCOSO Enterprise Risk Management – Integrated Framework (2017): Defines inherent risk as the risk to an entity in the absence of any actions management might take to alter the risk's likelihood or impact.

Which of the following is a requirement for an assurance engagement that may not be for a consulting engagement?


A. The internal audit activity has to ensure team members' objectivity is not impaired.


B. Auditors cannot participate in an assurance engagement of a function for which they previously performed a consulting engagement.


C. The scope and objective of the engagement is agreed upon based on the engagement client's needs.


D. The internal audit activity must ensure management actions have been implemented effectively or risk accepted.





D.
  The internal audit activity must ensure management actions have been implemented effectively or risk accepted.

Explanation:

This question tests the fundamental distinction between assurance and consulting engagements under the IIA’s IPPF. The critical differentiator is accountability for follow-up.

For assurance engagements, the internal audit activity bears a mandatory, non-negotiable responsibility to monitor the disposition of all reported findings. Standard 2500 explicitly requires the Chief Audit Executive (CAE) to establish a follow-up process to confirm that management actions have been effectively implemented or that senior management has formally accepted the risk of not taking action. This is a closed-loop process designed to provide the board and audit committee with confidence that identified control weaknesses or risk exposures are resolved. Without this step, the assurance provided is incomplete.

For consulting engagements, however, the nature and scope are agreed with the client, and the engagement is advisory in nature. While the internal auditor must exercise due professional care, there is no mandatory requirement under the Standards for the CAE to perform formal follow-up on management actions arising from consulting advice. The responsibility to act on recommendations rests primarily with the client, who may accept, modify, or reject the advice without the same level of formal tracking required for assurance findings. This is the key operational distinction.

Why other options are incorrect

A. Objectivity is not impaired.
Incorrect because preserving objectivity is a universal requirement for all engagements (assurance and consulting). Standards 1100 and 1120 mandate objectivity across the entire internal audit activity without exception. Therefore, it cannot be a distinguishing requirement.

B. Cannot assure a function previously consulted.
Incorrect. This reverses the rule. Standard 1130.A1 prohibits assurance work on activities the auditor managed within the prior year. However, Standard 1130.C1 explicitly permits consulting on previously managed areas. The restriction is specific to past management responsibility, not prior consulting work.

C. Scope agreed based on client's needs.
Incorrect. This characteristic defines consulting engagements per the IIA Glossary. For assurance, scope is determined primarily by the auditor's independent professional judgment and risk assessment, not delegated to client preference.

References:

IIA Standard 2500 – Monitoring Progress: Mandates follow-up for assurance engagements.

IIA Standard 1130.A1 & 1130.C1: Distinguishes objectivity rules between assurance and consulting.

Which of the following would not be considered part of preliminary survey of an engagement area?


A. Interviews with individuals affected by the entity.


B. Functional walk through test.


C. Analytical reviews.


D. Sampling scope.





D.
  Sampling scope.

Explanation:

The preliminary survey is the information-gathering and planning phase conducted before detailed fieldwork begins. Its purpose is to gain a sufficient understanding of the activity, identify risks, and establish engagement objectives and scope boundaries. The work here is broad, high-level, and diagnostic—not detailed or substantive.

Sampling scope (Option D) is not part of the preliminary survey because sampling relates to the execution of detailed testing during fieldwork. Sample selection, size, and methodology are determined after the survey is complete, once the auditor understands the processes, controls, and risk areas sufficiently to design a focused test plan. Deciding on sampling scope prematurely, before understanding the activity, would be inefficient and potentially ineffective. This is a fieldwork activity governed by detailed engagement work programs, not a planning activity.

Why other options are incorrect

A. Interviews:
Incorrect. Speaking with management, staff, and affected individuals is a primary technique during the preliminary survey to gather operational insights, understand perspectives, and identify potential red flags. This is explicitly recognized as an information-gathering method.

B. Functional walkthrough test:
Incorrect. Walkthroughs—tracing a transaction from initiation to completion—are performed during the survey to document and understand process flows and identify where controls exist. This is a standard planning procedure, not detailed substantive testing.

C. Analytical reviews:
Incorrect. Broad, high-level analytical reviews of financial and operational data are conducted during the survey to spot unusual trends, significant variances, or risk indicators. These are not the detailed substantive analytics performed later; they serve to direct audit attention.

References:

IIA Standard 2200 – Engagement Planning: Requires internal auditors to develop and document a plan including objectives, scope, timing, and resource allocation.

IIA Standard 2210.A1:Mandates a preliminary assessment of risks relevant to the activity under review before determining engagement objectives.

As a matter of policy, the chief audit executive routinely rotates internal audit staff assignments and periodically interviews the staff to discuss the potential for conflicts of interest. These actions help fulfill which of the following internal audit mandates?


A. Organizational independence.


B. Professional objectivity.


C. Due professional care.


D. Individual proficiency.





B.
  Professional objectivity.

Explanation:

This question tests the distinction between organizational independence and individual objectivity, a core concept in the IIA's IPPF.

The actions described—rotating staff assignments and interviewing staff about conflicts of interest—are proactive measures to ensure that individual auditors maintain an impartial, unbiased mental attitude. This is the essence of professional objectivity. According to IIA Standard 1120 (Individual Objectivity), internal auditors must have an impartial, unbiased attitude and avoid any conflict of interest. The Implementation Guide for Standard 1120 explicitly states that to manage objectivity, the CAE should organize staff assignments to prevent conflicts, periodically obtain information about potential conflicts, and, when practicable, rotate internal audit staff assignments. These are the exact actions described in the question.

Why other options are incorrect:

A. Organizational independence:
This is an attribute of the internal audit activity as a whole (not individuals). It refers to freedom from conditions that threaten the ability to carry out responsibilities, achieved through functional reporting to the board. Staff rotation and individual conflict interviews do not address organizational independence—they address individual objectivity.

C. Due professional care:
This refers to the diligence and skill expected of internal auditors in performing work (Standard 1220). It concerns how work is performed (planning, supervision, evidence gathering), not preventing personal bias or conflicts of interest.

D. Individual proficiency:
This relates to knowledge, skills, and competencies required to perform services (Standard 1210). Staff rotation for objectivity purposes is unrelated to ensuring auditors possess the necessary technical expertise.

References:

IIA Standard 1120 – Individual Objectivity: Requires impartial, unbiased attitude and avoiding conflicts of interest.

IIA Practice Advisory 1120-1: States CAE should organize staff assignments to prevent conflicts and rotate assignments periodically.

An internal audit activity includes in its audit reports the assertion that its work is performed in conformance with the International Standards for the Professional Practice of Internal Auditing {Standards). A recent external quality assessment concluded that the internal audit activity had substantial deficiencies that impact its overall operations. According to IIA guidance, which of the following is the most appropriate action for issuing future audit reports?


A. Refrain from indicating that the internal audit activity operates in conformance with the Standards until the chief audit executive confirms that the internal audit activity has addressed all areas of nonconformance and the audit committee has been notified.


B. Refrain from indicating that the internal audit activity operates in conformance with the Standards until another external assessment confirms that the significant areas of nonconformance have been addressed.


C. Indicate that the internal audit activity operates in partial conformance with the Standards, as the internal audit activity has a quality assurance and improvement program in place to address deficiencies and has met the requirement for conducting an external assessment.


D. Update and reissue previous audit reports, removing the assertion that the internal audit activity operates in conformance with the Standards, and distribute them to all parties who received the original reports.





A.
  Refrain from indicating that the internal audit activity operates in conformance with the Standards until the chief audit executive confirms that the internal audit activity has addressed all areas of nonconformance and the audit committee has been notified.

Explanation

According to IIA Standard 1321, an internal audit activity may state it "Conforms with the International Standards for the Professional Practice of Internal Auditing" only if supported by the results of the Quality Assurance and Improvement Program (QAIP). A recent external quality assessment has concluded there are "substantial deficiencies that impact overall operations." This constitutes a finding of "Does Not Conform" or significant "Partially Conforms," which means the results of the QAIP no longer support the conformance statement.

The CAE must first address the areas of nonconformance through corrective action. Once the CAE confirms remediation is complete, the conformance statement can be reinstated. Importantly, Standard 1322 requires the CAE to disclose any nonconformance that impacts the overall scope or operation to senior management and the board, which has been satisfied in this scenario. Option A correctly reflects this dual requirement: remediate deficiencies and notify the audit committee.

Why other options are incorrect:

B. Another external assessment confirms remediation.
Incorrect. While external assessment validates conformance, the CAE has the authority and responsibility to confirm corrective actions are implemented and effective through ongoing monitoring and internal follow-up. Waiting another five-year cycle for a new external assessment is impractical and not required by the Standards.

C. Indicate partial conformance.
Incorrect. The term "partial conformance" is a rating used internally in assessment reports. It cannot be used as a qualification in external audit reports to stakeholders. The report either states full conformance or omits the statement entirely.

D. Update and reissue previous reports.
Incorrect. The requirement applies to future audit reports, not retroactive reports. Reissuing past reports would create unnecessary confusion and is operationally impractical. The disclosure of nonconformance is made to senior management and the board, not by amending historical documents.

References:

IIA Standard 1321 – Use of "Conforms with the Standards"
IIA Standard 1322 – Disclosure of Nonconformance

According to the HA Code of Ethics, which of the following statements best describes the principle of competency?


A. Internal auditors shall perform their work with honesty, diligence, and responsibility.


B. Internal auditors shall perform their work in accordance with the Standards.


C. Internal auditors shall perform their work in accordance with the law and make disclosures expected by the law.


D. Internal auditors shall be prudent in the use of information acquired while performing their work.





B.
  Internal auditors shall perform their work in accordance with the Standards.

Explanation:

The IIA Code of Ethics comprises four principles: Integrity, Objectivity, Confidentiality, and Competency. Each principle is supported by specific Rules of Conduct that provide enforceable behavioral expectations.

The principle of Competency is defined as applying the knowledge, skills, and experience needed for internal audit services. However, the most direct and enforceable articulation of this principle is found in Rule of Conduct 4.2, which states: "Internal auditors shall perform internal audit services in accordance with the International Standards for the Professional Practice of Internal Auditing." Performing work in conformity with the Standards ensures that auditors apply due professional care, appropriate methodologies, and technical proficiency—all core elements of competency. This is the definitive behavioral requirement that operationalizes the competency principle.


Why other options are incorrect:


A. Honesty, diligence, and responsibility:
This describes the principle of Integrity, not Competency. Integrity is the foundation of trust and requires auditors to be honest and responsible in their work.

C. Law and disclosures expected by law: This also relates to Integrity. The Rules of Conduct require integrity in observing the law and making proper disclosures—this is about ethical conduct, not technical competence.

D. Prudent use of information: This directly describes the principle of Confidentiality. It addresses protecting information acquired during duties, not the knowledge or skill required to perform audit work.

References:

IIA Code of Ethics – Principle of Competency: States internal auditors shall apply knowledge, skills, and experience.

IIA Code of Ethics – Rule of Conduct 4.2: Explicitly requires performing work in accordance with the Standards.

Faced with a complex, highly technical construction audit engagement, the chief audit executive (CAE) considered complementing the current internal audit resources by engaging the services of a civil engineer.
Which of the following should the CAE consider in determining whether the engineer possesses the necessary skills to perform the engagement?
1. Professional certification, license, or other recognition of the engineer's competence in the relevant discipline.
2. Experience of the engineer in the type of work being considered.
3. Compensation or other incentives that the engineer may receive.
4. The extent of other ongoing services that the engineer may be performing for the organization.


A. 1 and 4 only


B. 2 and 3 only


C. 3 and 4 only


D. 1, 2, and 4 only





D.
  1, 2, and 4 only

Explanation:

When engaging an external civil engineer for a technical construction audit, the CAE must assess both competence (skills) and objectivity (impartiality).

Item 1 (Certification/license) – YES:This validates formal technical knowledge and minimum competency standards in civil engineering. It directly answers whether the engineer has the foundational skills required.

Item 2 (Experience) – YES: Credentials alone are insufficient. Relevant hands-on experience with similar construction projects ensures the engineer can apply theoretical knowledge to the specific audit context. This is a critical skill indicator.

Item 4 (Other ongoing services) – YES: While not a skill measure, this is a mandatory due diligence factor. If the engineer is concurrently performing design, project management, or consulting work for the organization, their objectivity is impaired (self-review threat). The CAE must consider this to determine if the engineer can impartially apply their skills.

Item 3 (Compensation/incentives) – NO: The amount or structure of compensation is a budgeting/contractual matter, not a determinant of technical skills. Only contingent compensation (e.g., bonus tied to audit outcomes) threatens objectivity, but the question specifically asks about determining "necessary skills," making this item irrelevant to the core inquiry.

Why Other Options Are Incorrect

A (1 and 4 only): Omits Item 2 (experience), which is essential for assessing practical, applied skills—not just theoretical knowledge.

B (2 and 3 only): Omits Item 1 (certification) and Item 4 (objectivity check), while wrongly including Item 3 (compensation has no bearing on skills).

C (3 and 4 only): Omits both core skill indicators (Items 1 and 2) and incorrectly includes compensation.

References

IIA Standard 1210 – Proficiency: "The CAE must obtain competent advice and assistance if the internal audit staff lacks the knowledge, skills, or other competencies needed." (Mandates evaluating certifications and experience – Items 1 & 2).

According to IIA guidance, the results of a formal quality assessment should be reported to which of the following groups?


A. The audit committee and senior management.


B. The audit committee and the external auditors.


C. Senior management and management of the audited area.


D. Senior management and the external auditors.





A.
  The audit committee and senior management.

Explanation:

According to the IIA's International Standards for the Professional Practice of Internal Auditing, specifically Standard 1320 – Reporting on the Quality Assurance and Improvement Program, the chief audit executive (CAE) must communicate the results of the quality assurance and improvement program to both senior management and the board (which, in practice, is usually the audit committee).

The communication must include the scope and frequency of internal and external assessments, the qualifications and independence of the assessors, the conclusions reached, and any corrective action plans. This requirement ensures full transparency regarding the internal audit activity's conformance with the Standards and its overall quality. Furthermore, internal assessments must be communicated at least annually.

Why Other Options Are Incorrect

B (Audit committee and external auditors):
While the audit committee is a primary recipient, the Standards explicitly require reporting to senior management as well. External auditors are not a mandatory reporting party for these results, though they may receive them indirectly if they rely on internal audit's work.

C (Senior management and management of the audited area):
This omits the audit committee, which is a critical governance body that must be informed about the internal audit activity's quality and conformance. Management of the audited area is not a required recipient for the overall QAIP results.

D (Senior management and external auditors):
This option incorrectly includes external auditors and excludes the audit committee, which is a mandatory reporting group under the Standards.

References:

IIA Standard 1320 – Reporting on the Quality Assurance and Improvement Program: The CAE must communicate the results of the quality assurance and improvement program to senior management and the board.


Page 9 out of 24 Pages
PreviousNext
56789101112
IIA-CRMA-ADV Practice Test Home

What Makes Our Certification in Risk Management Assurance Practice Test So Effective?

Real-World Scenario Mastery: Our IIA-CRMA-ADV practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.

Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before Certification in Risk Management Assurance exam day arrives.

Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive IIA-CRMA-ADV practice exam questions pool covering all topics, the real exam feels like just another practice session.