3.1 Selecting and Testing Evaluation Criteria

Key Takeaways

  • GIAS Standard 13.4 requires internal auditors to identify the most relevant criteria for the aspects of the activity defined in engagement objectives and scope
  • CIA Part 2 A2 tests five quality checks: criteria must be specific, practical, relevant, aligned with organizational and activity objectives, and able to produce reliable comparisons
  • If management's or the board's criteria are adequate, use them; if they are inadequate, identify appropriate criteria through discussion — do not silently impose a yardstick the activity never agreed to
  • Sources include laws and regulations, internal policies, contracts, industry frameworks management has adopted, management-established performance measures, and GIAS/Topical Requirements when the topic is in assurance scope
  • Vague criteria such as 'timely processing' or 'adequate controls' cannot support a finding; a defensible criterion names a source, an expected state or threshold, and a population
Last updated: August 2026

3.1 Selecting and Testing Evaluation Criteria

Quick Answer: Identify the most relevant criteria for the activity under review, then test whether they are specific, practical, relevant, aligned with the objectives of the organization and the activity, and able to produce reliable comparisons. If management's criteria pass, use them. If they fail, do not invent a private yardstick — identify appropriate criteria through discussion with management and/or the board (GIAS Standard 13.4).

Evaluation criteria are the yardstick you will later hold against conditions. A finding is a documented gap between those two. If the yardstick is vague, unagreed, or misaligned with what the activity is actually supposed to achieve, you cannot support a finding that an informed, competent person would reach. That is why the 2025 CIA Part 2 syllabus tests criteria during engagement planning (Section A2), not only when you compare conditions to criteria in fieldwork (Section B6, covered later).

Why the exam says “most relevant”

The expanded test specifications ask you to identify the most relevant criteria for evaluating the activity under review. “Most relevant” is not “the strictest framework you personally prefer.” It is the set that:

  • Matches the engagement objectives and scope already set in Chapter 2
  • Reflects how the organization and the activity define success
  • Can be applied consistently to evidence you can actually obtain

GIAS Standard 13.4 requires internal auditors to identify those criteria for the aspects of the activity defined in objectives and scope. The Standard's logic is sequential. First ask whether the board and senior management have already established adequate criteria to determine whether the activity has accomplished its objectives and goals. If those criteria are adequate, you must use them. If they are inadequate, you must identify appropriate criteria through discussion with management and/or the board.

That sequence is an exam favorite. Imposing ISO/IEC 27001 maturity level 4 on a 40-person shared-service center that never adopted ISO 27001, never budgeted for it, and is measured on a contractual service-level agreement (SLA) is a planning failure — even if ISO 27001 is a respected framework.

The five CIA quality tests

The 2025 syllabus tells you exactly how to judge a set of criteria. Walk every fact pattern through all five tests before you lock the work program.

TestWhat it means in planningFails when you write…
SpecificA competent person could apply the same rule to the same evidence and reach a comparable conclusion“Invoices should be processed timely.”
PracticalThe activity can reasonably be expected to meet the criterion with its systems, staffing, and mandate, and you can obtain evidence“Same-day payment of every invoice” when the ERP payment run is twice weekly
RelevantThe criterion actually evaluates the objective in scopeUsing a customer net-promoter score to judge accounts-payable duplicate-payment risk
AlignedConsistent with organizational objectives and the activity under reviewHolding AP to a treasury cash-conservation goal that AP's SLA does not include
Reliable comparisonsThe same definition can be used across periods, sites, or samplesThree regions each start the “cycle time” clock on a different event

Memorize the pairing organization + activity. Alignment to the enterprise strategy alone is not enough if the activity's approved mandate, SLA, or policy says something different. Alignment to a local KPI alone is not enough if that KPI contradicts law, a board-approved risk appetite, or a binding contract.

Worked example: AP invoice timeliness

Vague (fails specific and comparable): “Accounts payable should pay vendors on time.”

Relevant, specific, practical, aligned, comparable: “Per Shared-Services SLA §4.2 (effective 1 March 2025), 95% of clean, three-way-matched invoices are paid within 10 business days of the later of receipt date or goods-receipt date, measured from the ERP time stamp, excluding invoices on a valid hold.”

Unreasonable and unagreed (fails practical and aligned): “All invoices paid within 24 hours of scan,” when the SLA is 10 days, the payment run is twice weekly, and management never accepted a 24-hour target.

The first version cannot support a finding. The second can. The third would support a finding that management would fairly reject as using criteria the activity never agreed to and that are not reasonable.

Sources of criteria

Part 2 expects you to know where relevant criteria come from, then pick the source that fits the objective — not the source that makes the largest finding.

SourceTypical contentWhen it is usually most relevant
Laws and regulationsTax withholding, statutory prompt-pay rules, licensing conditions, privacy statutesThe objective is compliance; a statute outranks an internal KPI
Internal policies and proceduresDelegation of authority, three-way match, vendor-master segregation of dutiesThe objective is conformance with a rule the organization already adopted
ContractsCustomer or vendor SLAs, shared-service agreements, loan covenantsThe activity is measured on a signed performance obligation
Industry frameworksCOSO Internal Control — Integrated Framework, NIST CSF 2.0, ISO/IEC 27001, COBIT 2019Management has adopted the framework, or law or a regulator expects it
Management-established performance measuresKPIs, key risk indicators, OKRs, balanced-scorecard cells, incentive metricsThe objective is economy, efficiency, or goal achievement
GIAS and Topical RequirementsMandatory IPPF baseline for a named risk topicThe topic (for example, cybersecurity) is in assurance scope

Industry frameworks are a frequent trap. They are excellent candidate criteria. They become the criteria when they are the organization's chosen standard, a regulatory expectation, or the agreed substitute after you demonstrated that management's criteria were inadequate. They are not a spare yardstick you pull from a Global Technology Audit Guide because you like it.

Topical Requirements are not the same as recommended Global Guidance. When a published Topical Requirement's topic is in assurance scope, that Topical Requirement supplies a minimum baseline of relevant criteria. You still apply Standard 13.4: document which requirements apply, and document a rationale for any exclusion. You do not skip the baseline because a vendor checklist is shorter. Applying Topical Requirements in the rest of planning — evidence, specialists, and fit to already-set objectives — is the next section.

Two planning traps the exam writes for

Trap 1 — Criteria the activity never agreed to and that are not reasonable. You read a “leading practice” of four-hour vendor-query response and write a finding against a help desk whose published operating-level agreement is two business days. The condition (response took three days) may be true. The criterion was never the activity's, and it is not reasonable given staffing. Standard 13.4's remedy is discussion, not surprise.

Trap 2 — Vague criteria that cannot support a finding. “The control environment should be adequate.” “Cybersecurity should be mature.” “The process should be efficient.” None of these is specific, practical, or comparable. If you cannot state the criterion in a sentence that names a source, a threshold or expected state, and a population, you cannot later compare conditions to it.

How planning locks criteria in

Once a set survives the five tests:

  1. Name the source and version — policy ID and date, SLA clause, statute citation, or Topical Requirement requirement identifier.
  2. Confirm the activity can produce evidence against that definition (an ERP field, a log, a board pack).
  3. Communicate the criteria while planning (GIAS Principle 13, including Standard 13.1 Engagement Communication) so management can challenge a misread SLA now, not after fieldwork.
  4. Carry the same wording into the work program. Changing the yardstick mid-engagement is a criteria-and-scope problem, not a “we found something else” convenience.

If management refuses adequate criteria after discussion, document the disagreement and the criteria you will use, and escalate through the engagement communication path. Do not silently audit against a private standard.

Criteria selection is complete when a reviewer can pick up the work program, read one paragraph, and know exactly what “success” and “deficiency” will mean for this activity.

Loading diagram...
Selecting and Testing Evaluation Criteria (GIAS 13.4)
Test Your Knowledge

An internal auditor is planning an assurance engagement of a shared-service accounts-payable function. Management's signed SLA requires 95% of clean invoices to be paid within 10 business days. A team member wants to evaluate AP against a "leading practice" of payment within 24 hours that the function never adopted. What should the auditor do first?

A
B
C
D
Test Your Knowledge

Which set of evaluation criteria is most likely to support a defensible finding?

A
B
C
D
Test Your Knowledge

Management has not established measurable criteria for vendor-master data quality, which is in the engagement's scope. According to GIAS Standard 13.4, the internal auditor should:

A
B
C
D