15.3 Comparing Existing Conditions to Evaluation Criteria

Key Takeaways

  • GIAS Standard 14.2 requires auditors to compare evaluation criteria (the expected state) with existing conditions (the current state) to develop potential engagement findings.
  • Finding elements are criteria, condition, cause, and effect (CCCE); a gap without all four is incomplete analysis, even if the condition looks dramatic.
  • Criteria are selected and tested in planning (Chapter 3, Standard 13.4) and are not quietly swapped in fieldwork to avoid an unfavorable result.
  • Condition is what is, evidenced: relevant, reliable, and sufficient information—not rumor, not an untested dashboard tile, not a manager's vibe.
  • Cause and effect explain why the gap exists and what it does to objectives; they are developed here and appraised for significance in the next section.
Last updated: August 2026

Criteria Versus Condition Is the Heart of a Finding

Section B6a requires you to analyze existing conditions and compare them to evaluation criteria. Under Standard 14.2, internal auditors analyze relevant, reliable, and sufficient information to develop potential engagement findings. The comparison is simple to say and easy to fail on the exam: criteria are the expected state (what should be); condition is the current state (what is). The gap between them is what you then explain with cause and effect. Those four elements—criteria, condition, cause, effect (CCCE)—are how IIA materials have long structured a finding. CIA Part 2 still tests the structure even though final communication of findings is primarily a Part 3 skill.

If you cannot name the criteria, you do not have a finding. You have an observation that something happened. If you cannot evidence the condition, you do not have a finding. You have a lead. If you skip cause, you will later mis-rank significance and, in Part 3, mis-aim any recommendation. If you skip effect, you cannot tell whether the gap matters to the engagement objectives.

Criteria Are Locked in Planning

Standard 13.4 (Evaluation Criteria) lives in planning, which this guide covered in Chapter 3. By the time you are in B6, the criteria should already be identified, relevant to the objectives, and—where practical—discussed with management of the activity. Typical sources: laws and regulations, contracts, board-approved policies, documented procedures, industry standards the organization adopted, engineered standards, service-level agreements, and performance measures the activity itself uses to run the process.

Fieldwork does not get a silent rewrite. If results look unfavorable, you do not swap in a softer expected state so the activity "passes." If the original criteria turn out to be genuinely inappropriate—wrong policy version, criterion that does not match the objective, a stretch target that was never an operational standard—you document a criteria change with rationale, including who was informed. That is a planning correction, not moving the goalposts. Management's current informal preference ("we usually try to three-way match when we can") is not automatic criteria unless planning accepted it as the expected state.

Weak criteria produce weak findings. "Best practice" with no source, an auditor's undocumented personal preference, last year's actual used as a permanent standard without considering change, or a peer's number that is not comparable—all fail the relevance test from Chapter 3 and will fail B6a when the stem asks what is missing from the finding.

Condition Must Be Evidenced

Condition is the factual current state of the activity, described at the level of precision the objective needs. "Receiving often skips three-way match" is not a condition. It is an allegation. A condition looks like: in a statistically or judgmentally justified sample of 40 invoices over $5,000 paid in Q2, 16 (40 percent) lacked a receiving report in the three-way-match file; the exception rate in Q4 last year on the same test was 12 percent. That sentence can be tied to workpapers, source documents, and a population definition.

Evidence quality is Chapter 12 (Standard 14.1), but B6a will still punish you for promoting rumor. Relevant evidence actually bears on the criteria. Reliable evidence is produced under conditions you can defend (independent source, effective control environment, original documents, corroboration). Sufficient evidence is enough for an informed, competent person to reach the same condition statement. A single dashboard screenshot, an anonymous comment, or one walk-through anecdote can start inquiry. It cannot be the condition on which you hang cause, effect, and significance.

Analytical review from 15.1–15.2 often points at a condition. The unexpected freight gap, the sales-versus-shipments shortfall, the overtime ratio that did not move with volume—those are differences. You still have to evidence what is happening in the process: misposted accounts, unbilled shipments, unapproved overtime, missing receivers. Do not paste the variance chart into the finding and call the chart the condition.

Cause and Effect Complete the Comparison

Once criteria and evidenced condition show a gap, Standard 14.2 expects you to determine potential causes and effects. You do not need the full significance appraisal yet (that is B6b–c in the next section), but you cannot stop at "variance noted."

Cause is why the condition exists. Surface causes ("the clerk skipped the match") are usually not enough; you are looking for the process, system, or governance failure that allowed the skip. Effect is the consequence for the activity's objectives: incorrect payments, inventory overstatement, missed discounts, regulatory exposure, extra freight, delayed customer orders. Effect should be described in operational and, where possible, quantified terms, including whether the effect is already realized or is a reasonably possible exposure.

ElementMeaningNorth Hub three-way-match exampleFail pattern
CriteriaExpected state from planningPolicy and system design require a receiver, PO, and invoice match before payment over $5,000"I prefer three-way match" after seeing results
ConditionEvidenced current state16 of 40 sampled invoices over $5,000 paid with no receiver; rate up from 12 percent to 40 percent"Staff say receiving is sloppy"
CauseWhy the gap existsForce-pay access never recertified after WMS go-live; exception path has no second reviewerStop at "human error"
EffectImpact on objectivesDuplicate and unmatched payments; inventory receipts lag; $X unmatched AP; stockouts from delayed receiving"Looks bad" with no link to objectives

A complete CCCE package is still a potential finding until you appraise significance (15.4). Isolated, compensated, or trivial gaps may not survive that appraisal. That does not mean you skip CCCE. It means you build the four elements so the significance decision is evidence-based.

On the exam, when a stem gives a dramatic anecdote and asks what to do, the answer is usually: identify the planning criteria, gather evidenced condition, then analyze cause and effect. When a stem shows the auditor changing the target because operations complained, the answer is: keep the planning criteria or document a justified change—do not sanitize the expected state. When a stem offers a finding with only a variance chart, name the missing element: usually an evidenced condition, a sourced criterion, or both.

Loading diagram...
CCCE comparison under GIAS 14.2
Test Your Knowledge

In the criteria-condition-cause-effect model, criteria are:

A
B
C
D
Test Your Knowledge

An auditor is told that "receiving often skips three-way match." For finding development, that statement is:

A
B
C
D
Test Your Knowledge

Fieldwork results look unfavorable against the criteria agreed in planning. The auditor should:

A
B
C
D