Cheat sheet

IIA IAP Cheat Sheet

Quick Facts

Exam
IAP
Also known as
CIA Part 1
Questions
125
Time
150 min
Pass score
600/750 scaled
Level
Entry
Delivery
Pearson VUE only
Retake wait
30 days

Three Lines Model

1st Ops | 2nd Oversight | 3rd Audit

1st = management, own risk2nd = risk oversight roles3rd = internal audit itself

Assurance vs Advisory

Assurance

  • Independent opinion delivered
  • IA sets the scope
  • Forms a conclusion

Advisory

  • Advice, no assurance
  • Scope agreed together
  • No independent conclusion

Opinion vs advice

Assurance vs Advisory Picker

  1. Need independent opinionAssurance(IA sets scope)
  2. Need risk training/adviceAdvisory(Scope agreed together)
  3. Extensive procedures performedReasonable assurance(Higher confidence level)
  4. Narrow procedures performedLimited assurance(Modest confidence level)
  5. IA sets the scopeAssurance service
  6. Stakeholders agree the scopeAdvisory service

Purpose & Mandate

Purpose
Create, protect, sustain value
Mandate
Std 6.1: authority, role
Charter
Std 6.2: board-approved doc
CAE
Chief Audit Executive
Board approval
Final charter authority
Pre-2024 Mission
Retired: enhance, protect value

Limited vs Reasonable Assurance

Limited

  • Narrower procedures done
  • Modest conclusion reached

Reasonable

  • Extensive procedures done
  • Higher confidence reached

Narrow work vs broad

Independence Threat Picker

  1. CAE reports functionally to mgmtEscalate to the board(Reporting-line impairment)
  2. Auditor reviews own designReassign the auditor(Self-review bias)
  3. Close ties to audited areaReassign or disclose(Familiarity bias)
  4. Budget or access restrictedReport to the board(Scope impairment)

Engagement Types

Assurance
Independent evaluation, opinion
Advisory
Advice, no assurance
Limited assurance
Narrower procedures used
Reasonable assurance
Extensive procedures used
Consulting
Same as advisory
Foresight
Anticipates emerging risks
Assurance scope
Set by internal audit
Advisory scope
Agreed with stakeholders

Functional vs Administrative Reporting

Functional

  • CAE reports to the board
  • Protects audit independence

Administrative

  • CAE reports to management
  • Covers budget and HR

Independence vs day-to-day

Independence & Reporting

Org independence
Freedom from interference
Functional reporting
Std 7.1: CAE to board
Administrative reporting
CAE to management, ops
Impairment
Threat to objectivity
Three Lines Model
2020 IIA framework
First line
Operations, own risk
Second line
Risk oversight functions
Third line
Internal audit itself
Perceived impairment
Appears biased; must disclose
Board's duty
Safeguard IA independence

Ethics Five Principles

Integrity | Objectivity | Competency | Care | Confidentiality

I = honesty & courageO = unbiased, no conflictsC = skills & knowledgeCare = prudent judgmentConf = protects information

Self-Review vs Familiarity Bias

Self-review

  • Audits own prior work
  • Design conflict of interest

Familiarity

  • Close, longstanding relationship
  • Reluctant to flag issues

Own work vs closeness

Objectivity Safeguard Picker

  1. Auditor discloses a conflictReport to board/CAE(Standard 2.2/2.3)
  2. Same auditor stays conflictedReassign the auditor
  3. No independent staff availableOutsource the work
  4. Auditee offers a giftDecline the gift(Standard 2.2 rule)

Ethics: Five Principles

Integrity
Honesty, professional courage
Objectivity
Unbiased, no conflicts
Competency
Knowledge, skills, experience
Due professional care
Reasonably prudent auditor
Confidentiality
Protect, use info properly

Objectivity Threats & Safeguards

Self-review bias
Auditing own work
Familiarity bias
Close relationship bias
Gifts/favors
Barred if impairs
Disclosure
Report impairment upward
Reassignment
Move affected auditor
Outsourcing
Independent party performs

COSO IC Components

Environment, Risk, Activities, Info, Monitor

1 = control environment2 = risk assessment3 = control activities4 = info & comm5 = monitoring activities

Inherent vs Residual Risk

Inherent

  • Exposure before controls
  • Raw, unmitigated risk

Residual

  • Exposure after controls
  • Remaining, mitigated risk

Gap shows mitigation

Control Type Picker

  1. Stop error before it happensPreventive control
  2. Find error after it happensDetective control
  3. Fix damage after detectionCorrective control
  4. Check the control on paperDesign effectiveness
  5. Check the control in practiceOperating effectiveness

Governance & Risk Terms

Governance
Board processes, structures
Risk appetite
Broad risk willingness
Risk tolerance
Acceptable variation range
Inherent risk
Risk before controls
Residual risk
Risk after controls
Risk response
Accept, avoid, reduce, share
Risk management cycle
Identify, assess, respond, monitor
Internal control
Process giving reasonable assurance

Risk Response Options

Accept | Avoid | Reduce | Share | Pursue

Accept = keep the riskAvoid = exit the activityReduce = add more controlsShare = transfer to othersPursue = ERM-only response

Appetite vs Tolerance

Risk appetite

  • Broad risk willingness
  • Set at board level

Risk tolerance

  • Variation around one objective
  • Narrower acceptable band

Overall vs specific

Risk Response Picker

  1. Risk exceeds the appetiteAvoid or reduce
  2. Risk is within appetiteAccept the risk
  3. Risk shared externallyShare or transfer(E.g., insurance)
  4. Risk taken for upsidePursue(ERM-only response)

COSO Internal Control 2013

Control environment
Component 1: tone
Risk assessment
Component 2: identify risk
Control activities
Component 3: policies applied
Info & communication
Component 4: relevant info
Monitoring activities
Component 5: ongoing checks
17 principles
Support the 5 components
3 objectives
Ops, reporting, compliance

Design vs Operating Effectiveness

Design

  • Control looks right on paper
  • Addresses the identified risk

Operating

  • Control works in practice
  • Actually functioning as intended

Paper vs practice

COSO ERM 2017 Components

Governance & culture
Component 1
Strategy & objectives
Component 2
Performance
Component 3
Review & revision
Component 4
Info, comm & reporting
Component 5
20 principles
Total ERM principles

COSO IC vs ERM

COSO IC 2013

  • 5 components, 17 principles
  • Controls-focused framework

COSO ERM 2017

  • 5 components, 20 principles
  • Risk-focused framework

Control focus vs risk focus

Control Types

Preventive
Stops event beforehand
Detective
Finds event afterward
Corrective
Fixes event, damage
Design effectiveness
Controls address the risk
Operating effectiveness
Control works as intended
Control deficiency
Design or operating gap
Compensating control
Offsets another weak control

Fraud Triangle

Motivation + Opportunity + Rationalization = Fraud

Motivation: pressure/incentiveOpportunity: weak controlsRationalization: self-justifies act

Fraud Role Picker

  1. Charter assigns lead roleIA leads the probe
  2. Charter assigns support roleIA supports investigators
  3. No fraud role assignedIA can stay uninvolved
  4. Testing a planned areaAssess fraud risk first

Fraud Triangle & Schemes

Motivation
Pressure or incentive
Opportunity
Weak, overridden controls
Rationalization
Self-justification for act
Fraud triangle
3-element model (Cressey)
Financial statement fraud
Misstated financial reports
Occupational fraud
Employee abuses own position
Asset misappropriation
Most common fraud type
Corruption
Bribery, conflicts of interest

Red Flags & Anti-Fraud Controls

Tone at the top
Leadership's ethical example
Segregation of duties
Split custody, recording
Whistleblower hotline
Anonymous tip channel
Reconciliation
Finds unexplained differences
Management override
High-risk red flag
Authority limits
Caps approval authority

Common Traps

Assurance vs Advisory

Assurance forms a conclusion Advisory only gives advice

Mandate vs Charter

Mandate is the authority itself Charter is the written document

Appetite vs Tolerance

Appetite is the broad level Tolerance is the narrow band

Design vs Operating Effectiveness

Design means correct on paper Operating means working in practice

Self-Review vs Familiarity Bias

Self-review audits your own work Familiarity trusts people you know

COSO IC vs COSO ERM

IC has 17 control principles ERM has 20 risk principles

Motivation vs Pressure Wording

IAP syllabus says motivation Cressey/ACFE models say pressure

Last Minute

  1. 1.125 Qs, 150 min, Pearson VUE
  2. 2.Pass score: 600 of 250-750 scale
  3. 3.Weights: 35 / 20 / 30 / 15
  4. 4.IAP exam = CIA Part 1 now
  5. 5.Standards: 5 domains, 15 principles
  6. 6.52 total standards (2024 Standards)
  7. 7.Ethics = Domain II, not separate Code
  8. 8.Fraud triangle: motivation, opportunity, rationalization
  9. 9.COSO IC: 5 components, 17 principles
  10. 10.COSO ERM: 5 components, 20 principles
  11. 11.Retake wait: 30 days, 8 max
  12. 12.No prereqs: any candidate can sit
Same family resources

Explore More IIA Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.