Foundations of Internal Auditing
35%of exam
Ethics and Professionalism
20%of exam
Governance, Risk Management, and Control
30%of exam
Fraud Risks
15%of exam
Quick Facts
- Exam
- IAP
- Also known as
- CIA Part 1
- Questions
- 125
- Time
- 150 min
- Pass score
- 600/750 scaled
- Level
- Entry
- Delivery
- Pearson VUE only
- Retake wait
- 30 days
Three Lines Model
1st Ops | 2nd Oversight | 3rd Audit
Assurance vs Advisory
Assurance
- Independent opinion delivered
- IA sets the scope
- Forms a conclusion
Advisory
- Advice, no assurance
- Scope agreed together
- No independent conclusion
Opinion vs advice
Assurance vs Advisory Picker
- Need independent opinion→Assurance(IA sets scope)
- Need risk training/advice→Advisory(Scope agreed together)
- Extensive procedures performed→Reasonable assurance(Higher confidence level)
- Narrow procedures performed→Limited assurance(Modest confidence level)
- IA sets the scope→Assurance service
- Stakeholders agree the scope→Advisory service
Purpose & Mandate
- Purpose
- Create, protect, sustain value
- Mandate
- Std 6.1: authority, role
- Charter
- Std 6.2: board-approved doc
- CAE
- Chief Audit Executive
- Board approval
- Final charter authority
- Pre-2024 Mission
- Retired: enhance, protect value
Limited vs Reasonable Assurance
Limited
- Narrower procedures done
- Modest conclusion reached
Reasonable
- Extensive procedures done
- Higher confidence reached
Narrow work vs broad
Independence Threat Picker
- CAE reports functionally to mgmt→Escalate to the board(Reporting-line impairment)
- Auditor reviews own design→Reassign the auditor(Self-review bias)
- Close ties to audited area→Reassign or disclose(Familiarity bias)
- Budget or access restricted→Report to the board(Scope impairment)
Engagement Types
- Assurance
- Independent evaluation, opinion
- Advisory
- Advice, no assurance
- Limited assurance
- Narrower procedures used
- Reasonable assurance
- Extensive procedures used
- Consulting
- Same as advisory
- Foresight
- Anticipates emerging risks
- Assurance scope
- Set by internal audit
- Advisory scope
- Agreed with stakeholders
Functional vs Administrative Reporting
Functional
- CAE reports to the board
- Protects audit independence
Administrative
- CAE reports to management
- Covers budget and HR
Independence vs day-to-day
Independence & Reporting
- Org independence
- Freedom from interference
- Functional reporting
- Std 7.1: CAE to board
- Administrative reporting
- CAE to management, ops
- Impairment
- Threat to objectivity
- Three Lines Model
- 2020 IIA framework
- First line
- Operations, own risk
- Second line
- Risk oversight functions
- Third line
- Internal audit itself
- Perceived impairment
- Appears biased; must disclose
- Board's duty
- Safeguard IA independence
Ethics Five Principles
Integrity | Objectivity | Competency | Care | Confidentiality
Self-Review vs Familiarity Bias
Self-review
- Audits own prior work
- Design conflict of interest
Familiarity
- Close, longstanding relationship
- Reluctant to flag issues
Own work vs closeness
Objectivity Safeguard Picker
- Auditor discloses a conflict→Report to board/CAE(Standard 2.2/2.3)
- Same auditor stays conflicted→Reassign the auditor
- No independent staff available→Outsource the work
- Auditee offers a gift→Decline the gift(Standard 2.2 rule)
Ethics: Five Principles
- Integrity
- Honesty, professional courage
- Objectivity
- Unbiased, no conflicts
- Competency
- Knowledge, skills, experience
- Due professional care
- Reasonably prudent auditor
- Confidentiality
- Protect, use info properly
Objectivity Threats & Safeguards
- Self-review bias
- Auditing own work
- Familiarity bias
- Close relationship bias
- Gifts/favors
- Barred if impairs
- Disclosure
- Report impairment upward
- Reassignment
- Move affected auditor
- Outsourcing
- Independent party performs
COSO IC Components
Environment, Risk, Activities, Info, Monitor
Inherent vs Residual Risk
Inherent
- Exposure before controls
- Raw, unmitigated risk
Residual
- Exposure after controls
- Remaining, mitigated risk
Gap shows mitigation
Control Type Picker
- Stop error before it happens→Preventive control
- Find error after it happens→Detective control
- Fix damage after detection→Corrective control
- Check the control on paper→Design effectiveness
- Check the control in practice→Operating effectiveness
Governance & Risk Terms
- Governance
- Board processes, structures
- Risk appetite
- Broad risk willingness
- Risk tolerance
- Acceptable variation range
- Inherent risk
- Risk before controls
- Residual risk
- Risk after controls
- Risk response
- Accept, avoid, reduce, share
- Risk management cycle
- Identify, assess, respond, monitor
- Internal control
- Process giving reasonable assurance
Risk Response Options
Accept | Avoid | Reduce | Share | Pursue
Appetite vs Tolerance
Risk appetite
- Broad risk willingness
- Set at board level
Risk tolerance
- Variation around one objective
- Narrower acceptable band
Overall vs specific
Risk Response Picker
- Risk exceeds the appetite→Avoid or reduce
- Risk is within appetite→Accept the risk
- Risk shared externally→Share or transfer(E.g., insurance)
- Risk taken for upside→Pursue(ERM-only response)
COSO Internal Control 2013
- Control environment
- Component 1: tone
- Risk assessment
- Component 2: identify risk
- Control activities
- Component 3: policies applied
- Info & communication
- Component 4: relevant info
- Monitoring activities
- Component 5: ongoing checks
- 17 principles
- Support the 5 components
- 3 objectives
- Ops, reporting, compliance
Design vs Operating Effectiveness
Design
- Control looks right on paper
- Addresses the identified risk
Operating
- Control works in practice
- Actually functioning as intended
Paper vs practice
COSO ERM 2017 Components
- Governance & culture
- Component 1
- Strategy & objectives
- Component 2
- Performance
- Component 3
- Review & revision
- Component 4
- Info, comm & reporting
- Component 5
- 20 principles
- Total ERM principles
COSO IC vs ERM
COSO IC 2013
- 5 components, 17 principles
- Controls-focused framework
COSO ERM 2017
- 5 components, 20 principles
- Risk-focused framework
Control focus vs risk focus
Control Types
- Preventive
- Stops event beforehand
- Detective
- Finds event afterward
- Corrective
- Fixes event, damage
- Design effectiveness
- Controls address the risk
- Operating effectiveness
- Control works as intended
- Control deficiency
- Design or operating gap
- Compensating control
- Offsets another weak control
Fraud Triangle
Motivation + Opportunity + Rationalization = Fraud
Fraud Role Picker
- Charter assigns lead role→IA leads the probe
- Charter assigns support role→IA supports investigators
- No fraud role assigned→IA can stay uninvolved
- Testing a planned area→Assess fraud risk first
Fraud Triangle & Schemes
- Motivation
- Pressure or incentive
- Opportunity
- Weak, overridden controls
- Rationalization
- Self-justification for act
- Fraud triangle
- 3-element model (Cressey)
- Financial statement fraud
- Misstated financial reports
- Occupational fraud
- Employee abuses own position
- Asset misappropriation
- Most common fraud type
- Corruption
- Bribery, conflicts of interest
Red Flags & Anti-Fraud Controls
- Tone at the top
- Leadership's ethical example
- Segregation of duties
- Split custody, recording
- Whistleblower hotline
- Anonymous tip channel
- Reconciliation
- Finds unexplained differences
- Management override
- High-risk red flag
- Authority limits
- Caps approval authority
Common Traps
Assurance vs Advisory
Assurance forms a conclusion ≠ Advisory only gives advice
Mandate vs Charter
Mandate is the authority itself ≠ Charter is the written document
Appetite vs Tolerance
Appetite is the broad level ≠ Tolerance is the narrow band
Design vs Operating Effectiveness
Design means correct on paper ≠ Operating means working in practice
Self-Review vs Familiarity Bias
Self-review audits your own work ≠ Familiarity trusts people you know
COSO IC vs COSO ERM
IC has 17 control principles ≠ ERM has 20 risk principles
Motivation vs Pressure Wording
IAP syllabus says motivation ≠ Cressey/ACFE models say pressure
Last Minute
- 1.125 Qs, 150 min, Pearson VUE
- 2.Pass score: 600 of 250-750 scale
- 3.Weights: 35 / 20 / 30 / 15
- 4.IAP exam = CIA Part 1 now
- 5.Standards: 5 domains, 15 principles
- 6.52 total standards (2024 Standards)
- 7.Ethics = Domain II, not separate Code
- 8.Fraud triangle: motivation, opportunity, rationalization
- 9.COSO IC: 5 components, 17 principles
- 10.COSO ERM: 5 components, 20 principles
- 11.Retake wait: 30 days, 8 max
- 12.No prereqs: any candidate can sit
Explore More IIA Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.