3.1 Selecting and Testing Evaluation Criteria
Key Takeaways
- GIAS Standard 13.4 requires internal auditors to identify the most relevant criteria for the aspects of the activity defined in engagement objectives and scope
- CIA Part 2 A2 tests five quality checks: criteria must be specific, practical, relevant, aligned with organizational and activity objectives, and able to produce reliable comparisons
- If management's or the board's criteria are adequate, use them; if they are inadequate, identify appropriate criteria through discussion — do not silently impose a yardstick the activity never agreed to
- Sources include laws and regulations, internal policies, contracts, industry frameworks management has adopted, management-established performance measures, and GIAS/Topical Requirements when the topic is in assurance scope
- Vague criteria such as 'timely processing' or 'adequate controls' cannot support a finding; a defensible criterion names a source, an expected state or threshold, and a population
3.1 Selecting and Testing Evaluation Criteria
Quick Answer: Identify the most relevant criteria for the activity under review, then test whether they are specific, practical, relevant, aligned with the objectives of the organization and the activity, and able to produce reliable comparisons. If management's criteria pass, use them. If they fail, do not invent a private yardstick — identify appropriate criteria through discussion with management and/or the board (GIAS Standard 13.4).
Evaluation criteria are the yardstick you will later hold against conditions. A finding is a documented gap between those two. If the yardstick is vague, unagreed, or misaligned with what the activity is actually supposed to achieve, you cannot support a finding that an informed, competent person would reach. That is why the 2025 CIA Part 2 syllabus tests criteria during engagement planning (Section A2), not only when you compare conditions to criteria in fieldwork (Section B6, covered later).
Why the exam says “most relevant”
The expanded test specifications ask you to identify the most relevant criteria for evaluating the activity under review. “Most relevant” is not “the strictest framework you personally prefer.” It is the set that:
- Matches the engagement objectives and scope already set in Chapter 2
- Reflects how the organization and the activity define success
- Can be applied consistently to evidence you can actually obtain
GIAS Standard 13.4 requires internal auditors to identify those criteria for the aspects of the activity defined in objectives and scope. The Standard's logic is sequential. First ask whether the board and senior management have already established adequate criteria to determine whether the activity has accomplished its objectives and goals. If those criteria are adequate, you must use them. If they are inadequate, you must identify appropriate criteria through discussion with management and/or the board.
That sequence is an exam favorite. Imposing ISO/IEC 27001 maturity level 4 on a 40-person shared-service center that never adopted ISO 27001, never budgeted for it, and is measured on a contractual service-level agreement (SLA) is a planning failure — even if ISO 27001 is a respected framework.
The five CIA quality tests
The 2025 syllabus tells you exactly how to judge a set of criteria. Walk every fact pattern through all five tests before you lock the work program.
| Test | What it means in planning | Fails when you write… |
|---|---|---|
| Specific | A competent person could apply the same rule to the same evidence and reach a comparable conclusion | “Invoices should be processed timely.” |
| Practical | The activity can reasonably be expected to meet the criterion with its systems, staffing, and mandate, and you can obtain evidence | “Same-day payment of every invoice” when the ERP payment run is twice weekly |
| Relevant | The criterion actually evaluates the objective in scope | Using a customer net-promoter score to judge accounts-payable duplicate-payment risk |
| Aligned | Consistent with organizational objectives and the activity under review | Holding AP to a treasury cash-conservation goal that AP's SLA does not include |
| Reliable comparisons | The same definition can be used across periods, sites, or samples | Three regions each start the “cycle time” clock on a different event |
Memorize the pairing organization + activity. Alignment to the enterprise strategy alone is not enough if the activity's approved mandate, SLA, or policy says something different. Alignment to a local KPI alone is not enough if that KPI contradicts law, a board-approved risk appetite, or a binding contract.
Worked example: AP invoice timeliness
Vague (fails specific and comparable): “Accounts payable should pay vendors on time.”
Relevant, specific, practical, aligned, comparable: “Per Shared-Services SLA §4.2 (effective 1 March 2025), 95% of clean, three-way-matched invoices are paid within 10 business days of the later of receipt date or goods-receipt date, measured from the ERP time stamp, excluding invoices on a valid hold.”
Unreasonable and unagreed (fails practical and aligned): “All invoices paid within 24 hours of scan,” when the SLA is 10 days, the payment run is twice weekly, and management never accepted a 24-hour target.
The first version cannot support a finding. The second can. The third would support a finding that management would fairly reject as using criteria the activity never agreed to and that are not reasonable.
Sources of criteria
Part 2 expects you to know where relevant criteria come from, then pick the source that fits the objective — not the source that makes the largest finding.
| Source | Typical content | When it is usually most relevant |
|---|---|---|
| Laws and regulations | Tax withholding, statutory prompt-pay rules, licensing conditions, privacy statutes | The objective is compliance; a statute outranks an internal KPI |
| Internal policies and procedures | Delegation of authority, three-way match, vendor-master segregation of duties | The objective is conformance with a rule the organization already adopted |
| Contracts | Customer or vendor SLAs, shared-service agreements, loan covenants | The activity is measured on a signed performance obligation |
| Industry frameworks | COSO Internal Control — Integrated Framework, NIST CSF 2.0, ISO/IEC 27001, COBIT 2019 | Management has adopted the framework, or law or a regulator expects it |
| Management-established performance measures | KPIs, key risk indicators, OKRs, balanced-scorecard cells, incentive metrics | The objective is economy, efficiency, or goal achievement |
| GIAS and Topical Requirements | Mandatory IPPF baseline for a named risk topic | The topic (for example, cybersecurity) is in assurance scope |
Industry frameworks are a frequent trap. They are excellent candidate criteria. They become the criteria when they are the organization's chosen standard, a regulatory expectation, or the agreed substitute after you demonstrated that management's criteria were inadequate. They are not a spare yardstick you pull from a Global Technology Audit Guide because you like it.
Topical Requirements are not the same as recommended Global Guidance. When a published Topical Requirement's topic is in assurance scope, that Topical Requirement supplies a minimum baseline of relevant criteria. You still apply Standard 13.4: document which requirements apply, and document a rationale for any exclusion. You do not skip the baseline because a vendor checklist is shorter. Applying Topical Requirements in the rest of planning — evidence, specialists, and fit to already-set objectives — is the next section.
Two planning traps the exam writes for
Trap 1 — Criteria the activity never agreed to and that are not reasonable. You read a “leading practice” of four-hour vendor-query response and write a finding against a help desk whose published operating-level agreement is two business days. The condition (response took three days) may be true. The criterion was never the activity's, and it is not reasonable given staffing. Standard 13.4's remedy is discussion, not surprise.
Trap 2 — Vague criteria that cannot support a finding. “The control environment should be adequate.” “Cybersecurity should be mature.” “The process should be efficient.” None of these is specific, practical, or comparable. If you cannot state the criterion in a sentence that names a source, a threshold or expected state, and a population, you cannot later compare conditions to it.
How planning locks criteria in
Once a set survives the five tests:
- Name the source and version — policy ID and date, SLA clause, statute citation, or Topical Requirement requirement identifier.
- Confirm the activity can produce evidence against that definition (an ERP field, a log, a board pack).
- Communicate the criteria while planning (GIAS Principle 13, including Standard 13.1 Engagement Communication) so management can challenge a misread SLA now, not after fieldwork.
- Carry the same wording into the work program. Changing the yardstick mid-engagement is a criteria-and-scope problem, not a “we found something else” convenience.
If management refuses adequate criteria after discussion, document the disagreement and the criteria you will use, and escalate through the engagement communication path. Do not silently audit against a private standard.
Criteria selection is complete when a reviewer can pick up the work program, read one paragraph, and know exactly what “success” and “deficiency” will mean for this activity.
An internal auditor is planning an assurance engagement of a shared-service accounts-payable function. Management's signed SLA requires 95% of clean invoices to be paid within 10 business days. A team member wants to evaluate AP against a "leading practice" of payment within 24 hours that the function never adopted. What should the auditor do first?
Which set of evaluation criteria is most likely to support a defensible finding?
Management has not established measurable criteria for vendor-master data quality, which is in the engagement's scope. According to GIAS Standard 13.4, the internal auditor should: