19.1 2025 vs 2019 Traps and Part 2 vs Part 3 Boundaries

Key Takeaways

  • English CIA Part 2 since 28 May 2025 is Internal Audit Engagement with three sections: Engagement Planning 50%, Information Gathering, Analysis, and Evaluation 40%, and Engagement Supervision and Communication 10%.
  • The retired 2019 Part 2 (Practice of Internal Auditing) used four domains: Managing the Internal Audit Activity 20%, Planning the Engagement 20%, Performing the Engagement 40%, and Communicating Engagement Results and Monitoring Progress 20%.
  • 2019 Domain I plus Domain IV were 40% of the old Part 2; they are not 40% of the live exam. Managing the activity, the annual plan, CAE board KPIs, final-results communication as a large domain, recommendations/action-plan protocol, residual-risk acceptance communication, and follow-up monitoring moved primarily to CIA Part 3 2025 (Section D is about 45% of Part 3).
  • What stayed and expanded in Part 2: engagement objectives, scope, and criteria; planning for cyber, IT, privacy, BCP, finance, process, and system risks; approaches; engagement risk assessment including structure and culture; work program and resources; evidence, analytics, workpapers, and conclusions; supervision; and in-flight communication.
  • Topical Requirements remain mandatory IPPF planning-and-performing constraints on this engagement. They are not a Part 3-only close-out topic and they are not optional Global Guidance when they apply to assurance work.
Last updated: August 2026

Why the 2019 four-domain map fails a 2025 English sitting

Quick Answer: English CIA Part 2 since 28 May 2025 is Internal Audit Engagement, not the retired 2019 title Practice of Internal Auditing. The 2019 exam used four domains: Managing the Internal Audit Activity 20%, Planning the Engagement 20%, Performing the Engagement 40%, and Communicating Engagement Results and Monitoring Progress 20%. The live English map is three sections: Engagement Planning 50%, Information Gathering, Analysis, and Evaluation 40%, and Engagement Supervision and Communication 10%. Managing the activity, the annual plan, CAE board KPIs, and the large final-report / recommendations / residual-risk / follow-up cluster moved to CIA Part 3.

The highest-yield mistake on a 2025 English sitting is to treat 2019 Domain I and Domain IV as if they were still 40% of Part 2. They were 40% of the old Part 2 (20% + 20%). They are not 40% of the exam you will sit. Planning grew from a 20% domain to a 50% section. Performing was restated as information gathering, analysis, and evaluation at 40%—same numeric weight, different job description. Communication shrank from a 20% results-and-monitoring domain to a 10% supervision-and-in-flight-communication section.

If you study in English, you are on Internal Audit Engagement with the 50/40/10 map, testable since 28 May 2025. Other languages do not all flip on that date; use that language's published syllabus. Do not mix a 2025 English study plan with a 2019-language appointment.

The two outlines, side by side

2019 Part 2 domain (Practice of Internal Auditing)2019 weight2025 Part 2 section (Internal Audit Engagement)2025 weightWhat happened
I. Managing the Internal Audit Activity20%Not a Part 2 section0% of Part 2Moved primarily to Part 3 (function / operations management)
II. Planning the Engagement20%A. Engagement Planning50%Stayed and expanded; now half the exam
III. Performing the Engagement40%B. Information Gathering, Analysis, and Evaluation40%Weight held; restated around evidence, analytics, workpapers, conclusions
IV. Communicating Engagement Results and Monitoring Progress20%C. Engagement Supervision and Communication10%Final-report machinery moved to Part 3 Section D (~45% of Part 3); Part 2 keeps in-flight communication plus supervision

"About 50 / 40 / 10" is a study allocation on a 100-item form, not a promise that your sitting is sliced with a knife. Pretest items may be embedded, and you will not be told which items are pretest. It is still the right way to divide remaining hours: half of Part 2 study belongs in planning. Candidates who love fieldwork techniques and starve planning are studying the exam they wish existed.

Content that moved to Part 3 — stop drilling it as Part 2

When a Part 2 stem is still inside one engagement, treat the following as wrong-exam answers even if a 2019 deck filed them under Domain I or Domain IV.

Managing the internal audit activity. Operations of the function, activity-level budgeting, recruiting the department, and CAE-owned methodology as a management topic. Staffing this payroll review this week is a Part 2 resource question. Designing how the activity is organized for the year is not.

The annual or periodic internal audit plan. Audit universe, cycle coverage, and the CAE's risk-based plan for the year. Engagement-level risk assessment stayed in Part 2 Section A. Activity-level annual planning moved.

CAE reporting of KPIs to the board. Function performance measures and board dashboards for the activity. Part 2 may still ask you to evaluate auditors' performance on this engagement (Section C). It does not ask you to design the CAE's board KPI pack.

Final engagement results communication as a large domain. 2019 Domain IV made draft, review, approve, distribute, and the exit conference a 20% pillar of Part 2. In 2025 that close-out package is primarily Part 3 Section D at 45%. Part 2 still talks during reporting—closing meeting, fact confirmation, method and stakeholder choice. It does not own GIAS Standard 15.1 final engagement communication as a major percentage.

Recommendations and action-plan protocol. How management's action plan is obtained, documented, and owned as the results protocol. Part 2 can conclude that a condition exists and that a finding is significant. The later protocol for recommendations and action plans is Part 3.

Residual-risk acceptance communication. When management accepts a level of risk that may be unacceptable to the organization, the CAE's communication of that acceptance is a Part 3 topic. A Part 2 stem that is still in fieldwork is asking for documentation, supervision, and in-engagement escalation—not the residual-risk memo to the board.

Follow-up monitoring. Whether agreed actions were implemented, and how the CAE monitors disposition of results. Principle 15's name includes monitoring action plans. The CIA split that principle: Part 2 keeps the in-engagement slice; Part 3 keeps the monitoring engine.

GIAS Domain V still frames the work: Principle 13 Plan Engagements Effectively, Principle 14 Conduct Engagement Work, Principle 15 Communicate Engagement Results and Monitor Action Plans. Memorizing the Standard's full name is not a license to import Part 3 close-out into every Part 2 communication item.

2019 Part 2 domain weights vs 2025 Part 2 section weights (percentage of that exam)

Content that stayed or expanded in Part 2 — this is the exam

Section A (50%) is planning this engagement, not the year's plan. On a 100-question form that matches the blueprint, that is about 50 items.

  • Objectives, scope, and criteria. What this assignment is trying to conclude, where the boundary sits, what you will evaluate against, including scope limitations, stakeholder requests, and scope changes.
  • Planning for cyber, IT, privacy, BCP, finance, process, and system risks. Cybersecurity, IT general controls, privacy and data security, business continuity and disaster recovery, finance and accounting concepts for the activity under review, and business process and system risks (assets, supply chain, inventory, payables, procurement, compliance, third parties, CRM, ERP, GRC). You are not sitting a CISSP, a controller's exam, or a resilience certification. You are sitting an engagement-planning exam that expects you to pull those risks into objectives, scope, criteria, and the work program when they sit in the activity.
  • Approaches. Agile, traditional, integrated, and remote, plus project-management discipline while planning and conducting the job.
  • Engagement risk assessment, including structure and culture. Pervasive financial, operational, IT, cyber, and regulatory risks; emerging risks and the impact of change; methods to evaluate and prioritize risks and controls; centralized versus decentralized, flat versus traditional, in-person versus remote; tone at the top and group behavior as they affect this engagement.
  • Work program and resources. Adequacy of the work program, testing methodologies for accounting, finance, IT, operations, and cybersecurity, and the implications of financial, human, and technological resource limits.

Section B (40%) is the evidence engine: information sources (interviews, observations, walk-throughs, data analysis, policies, checklists, questionnaires, self-assessments); evidence relevance, sufficiency, and reliability (independence, corroboration, control environment, competent-person standard); technology options for findings (AI, machine learning, RPA, continuous monitoring, dashboards, embedded audit modules) as engagement tools, not as a data-science vanity project; process mapping and analytics (workflow, RACI, structured versus unstructured data, diagnostic, prescriptive, predictive, anomaly, and text analysis); analytical review (ratios, variances, trends, benchmarking) and finding evaluation (criteria versus conditions, root cause, effects, significance); workpapers that are complete, retained, and linked to results; and conclusions that aggregate findings on governance, risk, and control for the engagement.

Section C (10%) is small in weight and expensive in mistakes. Supervision throughout planning and fieldwork: coordinating assignments, reviewing workpapers and conclusions, evaluating auditors' performance. Communication during the engagement: formal and informal methods, escalation, stakeholder selection. "During reporting" on Part 2 means how you talk while results are taking shape. It does not mean drafting the final report's required attributes.

If a stem asks who signs the final report, how residual risk is communicated when management accepts too much risk, or how the CAE tracks whether last year's recommendations closed, you are looking at Part 3 even if a 2019 deck filed it under Domain IV.

Topic2025 Part 2 homeNot a current Part 2 pillar
Engagement objectives, scope, criteriaSection AAnnual audit-universe planning
Cyber / IT / privacy / BCP / finance / process / system risks in this jobSection AManaging the activity's IT methodology as a CAE operations topic
Agile / traditional / integrated / remote approachSection AFunction-wide methodology ownership as Part 3 management
Structure and culture in the engagement risk assessmentSection ABoard KPI pack for the internal audit activity
Work program, testing methods, resource limitsSection AActivity-level recruiting and annual resourcing
Evidence, analytics, workpapers, engagement conclusionsSection BFollow-up tracker of prior-year action plans
Supervision and in-flight communicationSection CStandard 15.1 final communication, residual-risk acceptance, action-plan monitoring

Topical Requirements as planning and performing constraints

Topical Requirements are mandatory IPPF elements, equal in force to the Global Internal Audit Standards when they apply. They did not move to Part 3 as a function-management-only topic. Part 2 tests them as constraints on this engagement's objectives, scope, risk assessment, and procedures. Part 3 may test them in how the function manages methodology. Mixing those is a boundary error.

When cybersecurity—or another issued topic—is the subject of an assurance engagement or a significant component, the applicable Topical Requirement is a minimum baseline for governance, risk management, and control, not optional Global Guidance. You may exclude an individual element that truly does not apply only with documented rationale in the file. You may not drop the whole requirement because the process owner wants an "operational, not IT" label.

Timing you locked in Chapter 2: the Cybersecurity Topical Requirement was issued 5 February 2025 and is effective 5 February 2026; scored CIA items appear at least six months after the effective date (from about August 2026). Chapter 19's job is not to re-teach NIST mappings. It is to stop you from treating Topical Requirements as either Part 3-only or skippable reading while you cram 2019 Domain I.

Scenario: forty percent of the wrong exam

A candidate passed Part 1 in 2024 using a colleague's 2019 Part 2 outline. They treat Domain I (managing the activity) and Domain IV (communicating results and monitoring progress) as 40% of Part 2, because that is what the old weights add to. Study hours go to the annual plan, CAE board KPIs, residual-risk acceptance memos, recommendation protocols, and follow-up trackers. Planning is skimmed because "planning was only 20%."

On the 2025 English form, those hours are largely spent on content that moved. The items that appear ask for engagement objectives, evaluation criteria, cyber/privacy/BCP/finance/process context, structure and culture in the engagement risk assessment, work-program adequacy, evidence quality, analytics, workpapers, supervision, and in-flight communication. Domain I plus Domain IV are not 40% of this exam. Planning is 50%. The colleague's outline was accurate for the exam they sat. It is not accurate for yours.

A quieter trap: treating 2019 Domain III Performing the Engagement (40%) as identical to 2025 Section B (also 40%). The weight matches. The restatement does not. Section B is information gathering, analysis, and evaluation—evidence, analytics, workpapers, conclusions—not a license to import 2019 close-out and monitoring tasks into "performing."

If your remaining calendar is short, cut 2019 activity-management and final-report drills first. Do not cut Section A to make room for report-writing and follow-up. Report-writing and follow-up are the wrong exam.

Official comparison sources:

Loading diagram...
Where 2019 Part 2 domains went on the 2025 CIA
Test Your Knowledge

On the live 2025 English CIA Part 2 syllabus, what is the weight of Engagement Planning?

A
B
C
D
Test Your Knowledge

A candidate studies 2019 Domain I (Managing the Internal Audit Activity, 20%) and Domain IV (Communicating Engagement Results and Monitoring Progress, 20%) as if they were still 40% of CIA Part 2. Which statement matches the 2025 English exam?

A
B
C
D
Test Your Knowledge

Which item is a 2025 CIA Part 2 planning-and-performing constraint rather than a Part 3 close-out task?

A
B
C
D