dc dotCreds
Reference guide

IIA CIA Course Notes

Study IIA CIA section notes, then jump straight into the guided course or related practice questions without losing your place.

Continue CourseStart PracticePDF downloads available in Pro.
Checking access

Checking Pro access...

Looking for your active Pro access before showing Course Notes. This usually takes just a moment.

Course Notes preview

Unlock Pro for the full per-exam reference guide.

Preview one piece from each section. Pro includes every Course Notes section, summary, key point, common mistake, exam tip, related-question review, and PDF export.

Includes full Course Mode and Course Notes.

Section 1Part 2A. Engagement Planning (50% of Part 2)Preview
More in this section
  • 15 more key points in Pro version
  • 7 more common mistakes in Pro version
  • 3 more exam tips in Pro version
  • 28 more related questions in Pro version

Summary

PART 2A = 50% of Part 2. Engagement planning converts risk into an executable audit. Define objectives and scope from the engagement's purpose and preliminary risk assessment, establish suitable criteria, identify key controls, build a work program that will produce enough evidence, and assign appropriate resources/time while coordinating with stakeholders and other assurance providers.

Key Points

  • OBJECTIVES — State what the engagement is intended to accomplish; tie objectives to identified risks and stakeholder expectations.

Common Mistakes

  • Writing detailed test steps before understanding engagement risks.

Exam Tips

  • Planning order: Purpose → Risks → Objectives → Scope → Criteria/Controls → Work Program → Resources.
Section 2Part 3D. Engagement Results and Monitoring (45% of Part 3)Preview
More in this section
  • 16 more key points in Pro version
  • 7 more common mistakes in Pro version
  • 3 more exam tips in Pro version
  • 25 more related questions in Pro version

Summary

PART 3D = 45% of Part 3. Results must be evidence-based, appropriately approved, communicated to the right audience, and followed through to resolution. Management owns corrective action and may accept risk. If the CAE concludes management has accepted a level of risk beyond the organization's appetite/tolerance, the CAE discusses it with senior management and, if unresolved, communicates it to the board—the CAE does not personally resolve the risk.

Key Points

  • FINAL COMMUNICATION — Should be supported by completed work and include the information needed to understand objectives, scope, results/conclusions, and recommendations/action plans as applicable.

Common Mistakes

  • Assuming the CAE must personally perform every final report review step.

Exam Tips

  • Result cycle: Communicate → Action → Monitor → Verify → Close/Escalate.
Section 3Part 1A. Foundations of Internal Auditing (35% of Part 1)Preview
More in this section
  • 13 more key points in Pro version
  • 6 more common mistakes in Pro version
  • 3 more exam tips in Pro version
  • 24 more related questions in Pro version

Summary

PART 1A = 35% of Part 1. Internal auditing strengthens an organization's ability to create, protect, and sustain value by providing the board and management with independent, risk-based, objective assurance, advice, insight, and foresight. For exam scenarios, separate the internal audit mandate, charter, organizational independence, and the nature of assurance versus advisory work.

Key Points

  • PURPOSE — Internal audit supports achievement of organizational objectives by evaluating and improving governance, risk management, and control.

Common Mistakes

  • Treating the charter and mandate as identical concepts.

Exam Tips

  • When unsure, ask WHO OWNS the decision. Management owns operations and risk; internal audit assesses and advises.
Section 4Part 2B. Information Gathering, Analysis, and Evaluation (40% of Part 2)Preview
More in this section
  • 19 more key points in Pro version
  • 7 more common mistakes in Pro version
  • 3 more exam tips in Pro version
  • 22 more related questions in Pro version

Summary

PART 2B = 40% of Part 2. Fieldwork is about evidence quality and disciplined evaluation. Collect sufficient, reliable, relevant, and useful information; choose testing/sampling/analytics methods that fit the population and risk; compare condition with criteria; distinguish design from operating effectiveness; identify root causes; and document enough work that a knowledgeable reviewer can understand how the conclusion was reached.

Key Points

  • SUFFICIENT — Quantity of evidence is enough to support a reasonable conclusion; more evidence may be needed when risk/uncertainty is high.

Common Mistakes

  • Equating 'more evidence' with 'better evidence.'

Exam Tips

  • Evidence = S-R-R-U: Sufficient, Reliable, Relevant, Useful.
Section 5Part 1C. Governance, Risk Management, and Control (30% of Part 1)Preview
More in this section
  • 17 more key points in Pro version
  • 6 more common mistakes in Pro version
  • 3 more exam tips in Pro version
  • 20 more related questions in Pro version

Summary

PART 1C = 30% of Part 1. Separate governance, risk management, and control. The board is accountable for governance and oversight; management owns objectives, operations, and risk; internal audit provides independent assurance and advice. Control questions frequently distinguish design adequacy from operating effectiveness.

Key Points

  • GOVERNANCE — The governing body/board is ultimately accountable for governance and provides oversight of management.

Common Mistakes

  • Saying internal audit owns risk because it evaluates risk management.

Exam Tips

  • Three Lines: management manages; oversight/support challenges; internal audit assures independently.
Section 6Part 1B. Ethics and Professionalism (20% of Part 1)Preview
More in this section
  • 14 more key points in Pro version
  • 7 more common mistakes in Pro version
  • 3 more exam tips in Pro version
  • 12 more related questions in Pro version

Summary

PART 1B = 20% of Part 1. Ethics and professionalism questions test integrity, objectivity, competency, due professional care, and confidentiality. The best answer protects impartial judgment, discloses impairments, uses competent resources, applies reasonable professional care, and safeguards information without using it for personal benefit.

Key Points

  • INTEGRITY — Do not knowingly participate in illegal, unethical, misleading, or discreditable conduct.

Common Mistakes

  • Assuming objectivity means merely being polite or 'fair.'

Exam Tips

  • Ethics question? Protect integrity, disclose impairments, preserve objectivity, and avoid management ownership.
Section 7Part 3A. Internal Audit Operations (25% of Part 3)Preview
More in this section
  • 15 more key points in Pro version
  • 7 more common mistakes in Pro version
  • 3 more exam tips in Pro version
  • 12 more related questions in Pro version

Summary

PART 3A = 25% of Part 3. The CAE manages the internal audit function as a professional operation: strategy, methodologies, budget, staffing, technology, service providers, talent, and performance. Resources must be sufficient in quantity and appropriate in capability. If constraints threaten fulfillment of the mandate or plan, the impact must be communicated to senior management and the board.

Key Points

  • STRATEGY — The internal audit strategy should support the mandate and align the function with organizational strategy, objectives, and risks.

Common Mistakes

  • Assuming sufficient resources means only headcount.

Exam Tips

  • Resources = enough people/tools AND the right capability.
Section 8Part 1D. Fraud Risks (15% of Part 1)Preview
More in this section
  • 13 more key points in Pro version
  • 6 more common mistakes in Pro version
  • 3 more exam tips in Pro version
  • 9 more related questions in Pro version

Summary

PART 1D = 15% of Part 1. Internal audit evaluates fraud risk and the adequacy of prevention/detection controls, applies professional skepticism to red flags, and follows established escalation/investigation protocols. Internal audit is not automatically the organization's fraud investigator or guarantor that all fraud will be detected.

Key Points

  • FRAUD TRIANGLE — Pressure/incentive, opportunity, and rationalization are classic fraud-risk factors.

Common Mistakes

  • Treating a red flag as conclusive proof.

Exam Tips

  • Red flag = investigate appropriately, not accuse.
Section 9Part 3B. Internal Audit Plan (15% of Part 3)Preview
More in this section
  • 14 more key points in Pro version
  • 7 more common mistakes in Pro version
  • 3 more exam tips in Pro version
  • 6 more related questions in Pro version

Summary

PART 3B = 15% of Part 3. The internal audit plan is risk-based and dynamic. The CAE assesses organizational strategy, objectives, and risks; considers board/senior-management input and other assurance coverage; proposes a plan and resource requirements; and communicates significant interim changes or limitations for appropriate approval.

Key Points

  • RISK-BASED — The plan should be grounded in documented assessment of organizational strategies, objectives, and risks.

Common Mistakes

  • Using last year's plan as the main basis for this year's plan.

Exam Tips

  • Plan = Objectives + Risks + Coverage + Resources.
Section 10Part 3C. Quality of the Internal Audit Function (15% of Part 3)Preview
More in this section
  • 14 more key points in Pro version
  • 7 more common mistakes in Pro version
  • 3 more exam tips in Pro version
  • 6 more related questions in Pro version

Summary

PART 3C = 15% of Part 3. A Quality Assurance and Improvement Program (QAIP) covers the entire internal audit function and evaluates both conformance with the Global Internal Audit Standards and performance toward objectives. It combines ongoing monitoring, periodic self-assessment, and an independent external quality assessment at least once every five years.

Key Points

  • QAIP — Covers all aspects of the internal audit function, not just engagement workpapers.

Common Mistakes

  • Treating QAIP as a once-every-five-years activity.

Exam Tips

  • QAIP = Ongoing + Periodic + External.
Section 11Part 2C. Engagement Supervision and Communication (10% of Part 2)Preview
More in this section
  • 13 more key points in Pro version
  • 6 more common mistakes in Pro version
  • 3 more exam tips in Pro version
  • 3 more related questions in Pro version

Summary

PART 2C = 10% of Part 2. Supervision is continuous quality control over the engagement, not just a final workpaper sign-off. Supervisors guide staff, review evidence and conclusions, resolve issues, and ensure communications remain accurate, objective, clear, concise, constructive, complete, and timely. Management responses should identify accountable owners and realistic action dates.

Key Points

  • SUPERVISION — Begins during planning and continues through fieldwork, communication, and follow-up preparation.

Common Mistakes

  • Waiting until the end of fieldwork to supervise.

Exam Tips

  • Supervise early and continuously.