GMSiSuccess CIA Part 1 classroom/revision material
In the 2025 CIA Part 1 syllabus has four exam domains, but the 2024 Global Internal Audit Standards themselves are organized into five domains and contain 15 principles. These are different things and should not be mixed.
Following notes compiled for Gmsisuccess students: Below is a rewritten, classroom-ready version with exam keywords, traps, corporate case examples, and decision logic.
CIA PART 1 – INTERNAL AUDIT FUNDAMENTALS
2025/2026 Exam-Oriented Revision Notes
With Corporate Case-Based Examples, Keywords & Exam Traps
1. CIA PART 1 – EXAM MAP
The current CIA Part 1 contains:
| Domain | Weight | Approx. questions* | Priority |
|---|---|---|---|
| I. Foundations of Internal Auditing | 35% | ~44 | 🔴 Very High |
| II. Ethics & Professionalism | 20% | ~25 | 🔴 High |
| III. Governance, Risk Management & Control | 30% | ~38 | 🔴 Very High |
| IV. Fraud Risks | 15% | ~19 | 🟠High |
*Approximation based on the percentage weighting; actual question allocation can vary.
The exam is 125 questions in 150 minutes, giving an average of approximately 72 seconds per question. The IIA confirms these current exam parameters.
OLD → NEW CIA PART 1
| Previous syllabus | Weight | Current syllabus | Weight |
|---|---|---|---|
| Foundations | 15% | Foundations | 35% |
| Independence & Objectivity | 15% | Ethics & Professionalism | 20% |
| Proficiency & Due Professional Care | 18% | Ethics & Professionalism | included |
| QAIP | 7% | Distributed across revised syllabus | — |
| Governance, Risk & Control | 35% | Governance, Risk & Control | 30% |
| Fraud Risks | 10% | Fraud Risks | 15% |
The IIA's revised syllabus confirms this four-domain structure.
⭐ EXAM STRATEGY
Do not think:
"I am studying six old domains."
Think:
2025 CIA Part 1 = 4 domains + 2024 Global Internal Audit Standards + application of professional judgment.
DOMAIN I – FOUNDATIONS OF INTERNAL AUDITING
35% — THE MOST IMPORTANT DOMAIN
The IIA's revised syllabus gives Foundations 35%, making it the largest Part 1 domain.
# Domain I – Foundations of Internal Auditing
**Structure (Global Internal Audit Standards, effective Jan 2025):** 5 Domains, 15 Principles, 52 Standards. Domain I = Purpose of Internal Auditing. Domains II–V = Ethics & Professionalism, Governing the IA Function, Managing the IA Function, Performing IA Services.
## 1. Purpose of Internal Auditing
- Strengthens the organization's ability to create, protect, and sustain value by providing the board and management with independent, risk-based, objective assurance, advice, insight, and foresight.
- Enhances: successful achievement of objectives, governance, risk management and control processes, decision-making and oversight, reputation and credibility, and societal impact.
- Effective only if: the function is independent, auditors are objective, and it operates in line with the Standards.
## 2. Mission and Definition
- **Mission:** enhance and protect organizational value by providing risk-based, objective assurance, advice, and insight.
- **Definition:** an independent, objective assurance and consulting activity designed to add value and improve operations. It helps the organization accomplish its objectives through a systematic, disciplined approach to evaluating and improving governance, risk management, and control.
## 3. Types of Services
- **Assurance:** an objective examination of evidence to give an independent assessment (three parties: process owner, internal auditor, user).
- **Advisory/Consulting:** advice and guidance, with the nature and scope agreed with the client (two parties: requester and auditor). Auditors must not assume management responsibility.
- **Insight and foresight** (new): trends, emerging risks, and forward-looking perspective.
## 4. Principles of Domain I
Principle 1 sets out the purpose. Principles 2–15 are covered in Domains II–V.
## 5. Mandatory Elements of IPPF
- Global Internal Audit Standards (mandatory), Topical Requirements (mandatory), and Global Guidance (recommended).
- Topical Requirements: mandatory minimum criteria for specific risk areas (e.g., cybersecurity, third parties). Conformance is expected when the topic is in scope.
- Each Standard has Requirements (mandatory), Considerations for Implementation (recommended), and Examples of Evidence of Conformance.
## 6. Three Lines Model (IIA 2020)
- **Governing body:** accountable for governance and oversight.
- **1st line (management):** owns and manages risk and controls, delivering products and services.
- **2nd line (management):** provides expertise, support, monitoring, and challenge on risk-related matters (risk, compliance, quality).
- **3rd line (internal audit):** independent, objective assurance and advice on adequacy and effectiveness of governance and risk management. Reports to the governing body.
- **External assurance providers:** external auditors, regulators.
- Key principles: accountability, delegation, independence, alignment, collaboration.
## 7. Value Proposition
- Internal audit adds value by supporting objectives, improving processes, and providing assurance on risk and control.
- Value is shown through stakeholder engagement and performance results.
## 8. Quick Exam Tips
- Know the **definitions** and **Mission** wording.
- Distinguish **assurance vs. consulting** (parties involved, who sets scope).
- Know which Three Lines belongs to which role. Internal audit is **not** responsible for owning risk.
- Remember the structure counts (5 / 15 / 52).
- Expect scenario questions on "what is the purpose/value of IA" and on independence from management.
2. PURPOSE OF INTERNAL AUDITING
Internal auditing exists to strengthen an organization's ability to create, protect and sustain value by providing the board and management with independent, risk-based and objective assurance, advice, insight and foresight.
KEYWORDS
Value creation
Value protection
Risk-based
Objective
Independent
Assurance
Advisory
Insight
Foresight
Corporate example
A large retail company plans to open 500 new stores.
Management believes the major risk is construction cost.
Internal audit performs a broader risk assessment and identifies:
- vendor fraud
- lease risks
- IT access
- inventory losses
- regulatory compliance
- cyber risks
- cash-handling risks
The internal auditor does not decide whether the company should open the stores.
Instead, IA provides:
Independent assurance + insight into significant risks.
EXAM TRAP
If an answer says:
"Internal audit guarantees that the organization will achieve its objectives."
❌ WRONG.
Internal audit provides reasonable assurance, not a guarantee.
3. THE 2024 IPPF — VERY IMPORTANT
The current 2024 IPPF consists of:
1. Global Internal Audit Standards
Mandatory
2. Topical Requirements
Mandatory when applicable to assurance engagements
3. Global Guidance
Recommended
The IIA explicitly identifies these three components.
MEMORY
S + T = Mandatory
G = Guidance
Standards + Topical Requirements = Mandatory
Global Guidance = Recommended
4. GLOBAL INTERNAL AUDIT STANDARDS
The 2024 Global Internal Audit Standards became effective January 9, 2025.
The Standards contain:
5 Domains
15 Principles
52 Standards
The five domains are:
- Purpose of Internal Auditing
- Ethics & Professionalism
- Governing the Internal Audit Function
- Managing the Internal Audit Function
- Performing Internal Audit Services
⚠️ IMPORTANT CORRECTION TO YOUR ORIGINAL NOTES
Do not teach:
"2024 Standards have five principles."
That is incorrect.
The 2024 Standards have 15 principles.
The five concepts:
- Integrity
- Objectivity
- Competency
- Due Professional Care
- Confidentiality
are the first five principles under Domain II: Ethics & Professionalism, not all 15 principles.
5. THE 15 PRINCIPLES — HIGH-VALUE REVISION
Domain I – Purpose
- Demonstrate Integrity
- Maintain Objectivity
- Demonstrate Competency
- Exercise Due Professional Care
- Maintain Confidentiality
Domain II – Governing the Internal Audit Function
- Authorized by the Board
- Positioned Independently
- Overseen by the Board
Domain III
- Plan Strategically
- Manage Resources
- Communicate Effectively
- Enhance Quality
Domain IV
- Plan Engagements Effectively
- Conduct Engagement Work
- Communicate Engagement Results and Monitor Action Plans
These 15 principles are directly reflected in the IIA's current Standards.
MEMORY CHAIN
I-O-C-D-C → A-P-O → P-M-C-Q → P-C-C
For quick recall:
Integrity → Objectivity → Competency → Due Care → Confidentiality
then
Board Authorization → Independence → Board Oversight
6. TOPICAL REQUIREMENTS
Topical Requirements are one of the biggest changes students should understand.
They provide a minimum mandatory baseline for auditing specific risk topics when applicable.
Examples currently issued include:
- Cybersecurity
- Third Party
and additional requirements are being introduced over time.
Important distinction
For an assurance engagement, applicable Topical Requirements must be considered and applied.
For advisory services, they are recommended rather than mandatory.
Corporate example
A bank's internal audit plan includes:
Cybersecurity Assurance Review
The auditor cannot simply use personal experience.
The auditor should consider the applicable:
Cybersecurity Topical Requirement + Global Internal Audit Standards + relevant organizational criteria/frameworks.
KEYWORDS
Mandatory
Risk-specific
Assurance
Applicability
Document rationale
Minimum baseline
EXAM TRAP
"Every internal audit engagement must automatically apply every Topical Requirement."
❌ WRONG.
Applicability depends on the topic and engagement.
7. INTERNAL AUDIT CHARTER
The charter establishes the internal audit activity's:
- purpose
- mandate
- authority
- responsibilities
- organizational position
- reporting relationships
- commitment to applicable Standards
WHO APPROVES?
Board / governing body
Not CFO.
Not CEO alone.
Not CAE alone.
Corporate example
The CAE wants unrestricted access to:
- ERP records
- employees
- contracts
- Board papers
- vendors
- financial information
The charter should provide the authority necessary for the IA function to perform its responsibilities.
KEYWORDS
Board approval
Mandate
Authority
Responsibility
Organizational position
Reporting relationship
Unrestricted access
EXAM TRAP
If management says:
"You cannot access this confidential Board document."
The CAE should consider the authority established through the charter and appropriate escalation—not simply accept management's restriction.
8. ASSURANCE vs CONSULTING
| Assurance | Consulting |
|---|---|
| Independent assessment | Advisory service |
| IA evaluates evidence | IA advises/facilitates |
| Provides assurance | Provides advice |
| Scope generally determined within IA's mandate/risk process | Scope agreed with client |
| Auditor maintains objectivity | Must avoid assuming management responsibility |
Corporate case
A company implements a new ERP.
Management asks IA:
"Please advise us on control risks before implementation."
This can be:
Consulting/advisory.
But if IA:
- designs the controls
- selects the configuration
- approves transactions
- operates the control
then IA may create a self-review or management-responsibility threat.
GOLDEN RULE
Advise — YES. Manage — NO.
9. MANAGEMENT RESPONSIBILITY vs INTERNAL AUDIT RESPONSIBILITY
MANAGEMENT
Owns
- risks
- controls
- operations
- decisions
- remediation
INTERNAL AUDIT
Assesses
- governance
- risk management
- controls
- effectiveness
- compliance
- fraud-risk management
BOARD
Oversees
- governance
- risk oversight
- internal audit
- major strategic matters
MEMORY
Management OWNS → IA ASSESSES → Board OVERSEES
This is one of the most useful CIA decision rules.
DOMAIN II – ETHICS & PROFESSIONALISM
20%
Here is *DOMAIN II – ETHICS & PROFESSIONALISM (20%)* – Complete Notes for New Syllabus 2025.
This domain is *pure scoring*. 25 Questions out of 125. All are direct theory. If you understand 4 Principles + Independence, you will get 20+ marks easily.
### DOMAIN II – 2 Parts: A) Ethics B) Professionalism (Independence + Objectivity)
---
#### PART A: ETHICS – Code of Ethics – 4 Principles + Rules
In New GIAS 2025, Ethics is now in *Domain II - Principles 1 to 5*. This is MANDATORY.
*1. INTEGRITY - The Foundation*
- Means: Honest, Courageous, Responsible. Don't do illegal work. Don't be part of fraud.
- Rule: Auditor shall not knowingly be party to illegal activity. Shall respect law.
- *Exam Trap:* If boss says "Hide this fraud finding", Integrity says you MUST NOT hide. Report to Board.
*2. OBJECTIVITY - Most Tested*
- Means: Unbiased mental attitude. No conflict of interest.
- Do NOT accept gifts, favors, money from auditee that impairs judgment.
- Do NOT participate in activity where you have personal interest.
- *3 Threats to Objectivity – MUST MUG UP:*
Threat Meaning Example
**Self-Review Threat** Auditing your own work You designed payroll system, now you audit payroll
**Familiarity Threat** Too friendly with client Auditing same branch for 5 years, become friends
**Social Pressure / Intimidation** Forced by senior CFO says "If you report this, you will be fired"
- *Rule for Objectivity:* If impaired in fact OR appearance, disclose to Board immediately.
*3. CONFIDENTIALITY*
- Do NOT disclose info to third party without authorization.
- Do NOT use info for personal gain.
- Continue even after leaving organization.
- *Exception:* Legal requirement, or Board approval.
- *Example:* You find client data during audit. You cannot share on WhatsApp or with next employer. This is violation.
*4. COMPETENCY*
- Do only those audits for which you have knowledge, skill, experience.
- Must continuously improve – CPE hours, training.
- If you don't have skill, take help of expert or decline engagement.
- Must follow Standards.
> *Exam Logic for All 4 Principles:*
> Q asks: What should auditor do?
> Step 1: Is it against Integrity? -> NO
> Step 2: Is Objectivity impaired? -> If yes, Disclose.
> Step 3: Is it confidential? -> Don't disclose.
> Step 4: Do you have competency? -> If no, take expert.
#### PART B: PROFESSIONALISM – Independence & Objectivity
This is the core of Domain II. IIA asks minimum 10 questions from this.
*1. Organizational Independence – 2 Reporting Lines*
- *Functional Reporting to BOARD / Audit Committee (5 Powers):*
1. Approve Audit Charter
2. Approve Risk-Based Audit Plan
3. Approve Budget & Resources
4. Approve CAE Appointment, Removal, Salary
5. Receive communication on Results, QAIP, Impairments
- *Administrative Reporting to CEO (4 Day-to-day):*
HR, Leave, Office, Admin expenses.
> *Golden Rule for Exam:* If CAE reports functionally to CFO or CEO -> Independence is IMPAIRED. Correct answer is always Board.
*2. Individual Objectivity – 12 Months Rule*
- *Rule 1:* Auditor who previously worked in an area cannot audit that area for *12 months*.
- *Rule 2:* Auditor who has personal relationship / financial interest in auditee -> Cannot audit.
- *Rule 3:* Assurance services for function where consulting was done previously -> Can do, but must disclose impairment and must not have taken operational responsibility.
> *Example:* Smit was Payroll Manager till Dec 2024. Can he audit Payroll in June 2025?
> Answer: NO. Must wait till Jan 2026 (12 months cooling period).
*3. Safeguards to Protect Objectivity – 6 Safeguards (Exam asks)*
1. Job Rotation – Don't audit same area for long time
2. Supervision & Review by CAE
3. No gifts policy
4. No operational duties
5. Periodic rotation of audit staff
6. Disclosure of conflict to Board
*4. Impairment – What to do when independence is impaired?*
*Step-by-Step Process:*
1. Identify impairment (fact or appearance)
2. Assess impact on audit
3. Disclose to appropriate party – Board / Audit Committee
4. If impairment affects specific engagement -> Reassign auditor or disclose in engagement report
5. If impairment is organization-level -> Board must resolve
> *Never do this:* Never accept impairment silently. Never continue without disclosure. Never hide.
#### DOMAIN II – 15 Must-Know Definitions for Exam
1. *Independence:* Freedom from conditions that threaten objectivity.
2. *Objectivity:* Unbiased mental attitude.
3. *Impairment in Fact:* Actually biased.
4. *Impairment in Appearance:* Others may think you are biased (even if you are not).
5. *Conflict of Interest:* Personal interest vs professional duty.
#### Last Night Revision – 10 Sure-Shot MCQs Logic
1. Gift from client of $50 pen? -> If it impairs objectivity -> Must decline or disclose. IIA says NO gifts that impair.
2. CAE asked to take CFO role for 2 months? -> Must NOT accept. Taking operational role impairs independence.
3. Auditor's brother is head of department to be audited? -> Objectivity impaired -> Reassign auditor.
4. Management restricts scope? -> Report to Board.
5. Auditor finds fraud? -> Report to Board, not police. Maintain confidentiality.
6. Can internal auditor do consulting? -> Yes, but must not take management responsibility.
7. Who is responsible for ethics in organization? -> Board + Management sets tone at top. IA assesses.
8. Can auditor use confidential info for personal share trading? -> NO, violates Confidentiality + Integrity.
9. What is required for Competency? -> Continuous Professional Development.
10. Best way to ensure independence? -> Functional reporting to Board.
This domain is easy. Students lose marks because they think practically, not as per Standards. Always choose most ethical, most independent, most board-oriented answer.
10. INTEGRITY
Integrity means being:
- honest
- truthful
- courageous
- professional
Corporate example
An auditor discovers that a senior executive's expense claim appears fraudulent.
The executive pressures the auditor:
"Don't include this finding. I'll handle it."
The auditor should not suppress the finding merely because the individual is senior.
KEYWORDS
Honesty
Courage
Truthfulness
Professional judgment
Ethical behavior
11. OBJECTIVITY
Objectivity means making professional judgments without allowing:
- bias
- conflicts of interest
- undue influence
- personal relationships
- financial interests
to compromise professional judgment.
Common threats
Self-interest
Self-review
Familiarity
Bias
Conflict of interest
Undue influence / intimidation
12. SELF-REVIEW THREAT
Corporate case
An auditor previously helped Accounts Payable design a new vendor approval process.
Six months later the CAE assigns the same auditor to audit that process.
The auditor may have to evaluate decisions that he/she previously helped make.
Risk:
Self-review threat
Better solution:
Assign another auditor or establish appropriate safeguards.
KEYWORD
"I am auditing my own work." = SELF-REVIEW
13. FAMILIARITY THREAT
An auditor has worked with the same department head for many years and becomes excessively trusting.
The auditor stops challenging unusual transactions.
Risk:
Familiarity
Solution:
- rotation where appropriate
- independent review
- supervision
- disclosure of impairment
- reassignment when necessary
EXAM TRAP
Do not memorize an absolute rule such as:
"Every auditor must be rotated after exactly 12 months."
The question should be evaluated based on the nature of the impairment, safeguards and applicable organizational policy/Standards.
14. INTIMIDATION / UNDUE INFLUENCE
Corporate case
The CFO tells the CAE:
"If you report this control weakness to the Audit Committee, I will make sure your budget is cut."
This is a serious independence/objectivity issue.
Appropriate response:
Do not change the conclusion simply because of pressure.
Escalate appropriately, particularly through the Board/Audit Committee relationship.
KEYWORDS
Pressure
Threat
Undue influence
Escalation
Board
15. GIFTS & CONFLICTS OF INTEREST
Supplier offers an internal auditor an expensive smartphone before a vendor audit.
Question:
Should the auditor accept?
Generally:
No, if acceptance could influence—or reasonably appear to influence—objectivity.
Exam logic
Even if the auditor says:
"I promise it won't affect me."
The issue may still be:
APPEARANCE of impaired objectivity.
KEYWORD
Perception matters.
16. COMPETENCY
The internal audit function must collectively possess or obtain the knowledge, skills and competencies needed.
Important principle
One auditor does not need to be an expert in everything.
The CAE can:
- train employees
- recruit specialists
- use co-sourcing
- obtain external expertise
Corporate example
IA is auditing an AI-based credit-scoring model.
The audit team lacks sufficient AI/model-risk expertise.
Possible solution:
Engage an appropriately qualified specialist.
EXAM TRAP
Wrong answer:
"Proceed anyway because internal auditors must personally know everything."
Correct approach:
Obtain appropriate competency.
17. DUE PROFESSIONAL CARE
Due professional care means applying the level of care and competence expected from a reasonably prudent and competent internal auditor.
It requires:
- professional skepticism
- judgment
- appropriate evidence
- consideration of risk
- materiality
- significance
- cost/benefit
- complexity
VERY IMPORTANT
Due care ≠ perfection
Internal auditors are not expected to guarantee detection of every fraud or error.
Corporate case
An auditor samples 100 transactions from 100,000 transactions.
A fraudulent transaction outside the sample is later discovered.
This does not automatically mean the auditor failed due care.
The question is:
Was the audit procedure appropriately designed and executed based on risk?
18. CONFIDENTIALITY
Internal auditors have access to sensitive information such as:
- salary data
- customer information
- passwords
- strategic plans
- acquisition plans
- confidential investigations
Corporate case
An auditor learns that the company is secretly negotiating to acquire a competitor.
The auditor tells a friend:
"Buy the competitor's shares before the announcement."
This is a serious confidentiality and ethical violation.
KEYWORDS
Need-to-know
Confidential information
Unauthorized disclosure
Data protection
19. ORGANIZATIONAL INDEPENDENCE
Functional reporting
Usually involves the Board/Audit Committee.
Examples:
- approve charter
- approve risk-based audit plan
- approve CAE appointment/removal
- approve CAE compensation/evaluation as appropriate
- meet privately with CAE
- oversee independence
Administrative reporting
Often to CEO or another senior executive.
Examples:
- payroll
- office facilities
- HR administration
- travel
- routine budgeting
MEMORY
FUNCTIONAL = Independence
ADMINISTRATIVE = Operations
Corporate case
CAE reports only to CFO.
CFO controls:
- audit plan
- audit budget
- CAE performance evaluation
- access to Audit Committee
This creates a significant independence concern.
20. QAIP – QUALITY ASSURANCE & IMPROVEMENT
The quality program evaluates whether the internal audit activity:
- conforms with applicable Standards
- achieves objectives
- improves continuously
- operates effectively
Internal assessment
Includes:
Ongoing monitoring
Periodic self-assessment
External assessment
The external assessment requirement is generally:
At least once every five years
The assessor should be appropriately qualified and independent/objective.
KEYWORD
External assessment = 5 years
EXAM TRAP
Do not confuse:
Ongoing monitoring
with
External assessment.
DOMAIN III – GOVERNANCE, RISK MANAGEMENT & CONTROL
30%
21. GOVERNANCE
Governance determines how an organization:
- makes decisions
- sets objectives
- provides oversight
- manages accountability
- promotes ethics
- monitors performance
Board
Provides oversight.
Management
Executes strategy and manages operations.
Internal Audit
Provides independent assessment and insight.
Corporate case
A listed company repeatedly misses compliance requirements.
The Board asks:
"Is management's compliance governance operating effectively?"
IA can assess:
- accountability
- reporting
- oversight
- controls
- risk management
- ethical culture.
IA should not become the compliance owner merely because it identifies the problem.
22. RISK APPETITE vs RISK TOLERANCE
Risk Appetite
Amount/type of risk the organization is willing to accept in pursuit of objectives.
Risk Tolerance
Acceptable variation around objectives/risk appetite.
Example
A bank says:
"We have moderate appetite for credit risk."
That is:
Risk appetite.
It then establishes:
"Non-performing loans should remain below 3%."
That is closer to a:
Risk tolerance / limit.
23. INHERENT vs RESIDUAL RISK
Inherent risk
Risk before considering controls.
Residual risk
Risk remaining after controls.
Example
Cash theft risk:
Before controls: ₹10 million potential exposure.
Controls:
- segregation of duties
- CCTV
- daily reconciliation
- surprise cash counts
Risk remaining after controls:
Residual risk
MEMORY
INHERENT = BEFORE
RESIDUAL = AFTER
24. CONTROL TYPES
Preventive
Stops an undesirable event before it happens.
Examples:
- authorization
- password controls
- segregation of duties
- credit-limit approval
Detective
Identifies an event after it occurs.
Examples:
- bank reconciliation
- inventory count
- exception report
- audit trail review
Corrective
Fixes or restores after a problem.
Examples:
- disaster recovery
- correcting erroneous records
- restoring backup
MEMORY
Prevent → Detect → Correct
25. AUTOMATED vs MANUAL CONTROLS
Automated control
System performs the control.
Example:
ERP automatically blocks a purchase order above an employee's authorization limit.
Manual control
Human performs the control.
Example:
Finance manager reviews monthly expense report.
IT-dependent manual control
Human reviews information produced by IT.
Example:
Manager reviews an automated exception report.
26. COSO INTERNAL CONTROL FRAMEWORK
Remember:
5 Components + 17 Principles
- Control Environment
- Risk Assessment
- Control Activities
- Information & Communication
- Monitoring Activities
MEMORY
C-R-C-I-M
Control → Risk → Control Activities → Information → Monitoring
27. CONTROL ENVIRONMENT
The foundation.
Includes:
- integrity
- ethical values
- Board oversight
- organizational structure
- authority/responsibility
- competence
- accountability
Corporate case
Company has sophisticated software controls.
But the CEO routinely tells employees:
"Ignore the approval process. Just get the deal done."
The technical controls may exist, but the:
Control Environment is weak.
KEYWORD
Tone at the top
28. MANAGEMENT OVERRIDE
This is a very important CIA concept.
Example
Company policy:
Expenses above ₹1 million require two approvals.
CEO instructs Accounts Payable:
"Process this ₹3 million payment without the second approval."
The CEO has:
Overridden the control.
Why dangerous?
Management override can defeat otherwise effective controls.
DOMAIN IV – FRAUD RISKS
15%
29. FRAUD TRIANGLE
1. PRESSURE / INCENTIVE
Example:
- debt
- financial problems
- unrealistic sales targets
- bonus pressure
2. OPPORTUNITY
Example:
- weak segregation
- poor supervision
- excessive system access
- management override
3. RATIONALIZATION
Example:
"The company owes me."
"Everyone does it."
"I'll return the money later."
MEMORY
P + O + R = Fraud Triangle
30. CORPORATE FRAUD CASE
Imagine a sales director has a year-end bonus based on revenue.
He instructs employees to record shipments that have not actually been delivered.
Pressure:
Bonus target
Opportunity:
Weak revenue controls
Rationalization:
"The customer will accept delivery next month anyway."
This creates the classic:
Fraud Triangle
31. FRAUD RESPONSIBILITY
Management's responsibility
Management is primarily responsible for:
- preventing fraud
- detecting fraud
- establishing controls
- maintaining ethical culture
- investigating according to organizational processes
Internal Audit
IA evaluates whether fraud risks are appropriately:
- identified
- assessed
- managed
- controlled
IA may perform investigations when specifically authorized and appropriately competent.
VERY IMPORTANT CORRECTION
Your original statement:
"If fraud is found → Report to Board, not police directly."
is too absolute.
The correct CIA logic is:
Follow the organization's established fraud-investigation/reporting protocol, applicable laws/regulations, and appropriate governance escalation.
Internal audit should not independently decide to call the police unless that is appropriate under the organization's policy, legal requirements, authority and circumstances.
32. FRAUD RED FLAGS
Employee-level
- unexplained wealth
- lifestyle beyond apparent income
- financial difficulties
- unusual relationships with suppliers
- refusal to take leave
- excessive control over one process
- unusual working hours
- defensive behavior
Organizational
- weak segregation of duties
- missing documentation
- excessive management override
- poor vendor due diligence
- unrealistic targets
- weak whistleblower mechanisms
- inadequate supervision
EXAM KEYWORD
Red flag ≠ proof of fraud
A red flag means:
Further investigation/assessment may be necessary.
33. FRAUD SCENARIO – VENDOR COLLUSION
Procurement manager repeatedly awards contracts to one supplier.
You discover:
- same supplier wins 90% of contracts
- competing bids look unusually similar
- supplier employee and procurement manager frequently meet socially
- prices are consistently above market
Do not immediately conclude:
"Fraud has been proven."
Instead:
Identify indicators → assess risk → obtain evidence → follow investigation/reporting procedures.
34. INTERNAL AUDITOR'S MINDSET
This is the most important concept I would add to your notes.
CIA questions frequently reward the auditor who thinks:
RISK → OBJECTIVITY → EVIDENCE → PROFESSIONAL JUDGMENT → GOVERNANCE
When presented with a scenario, ask:
Question 1
Who owns the responsibility?
Management? Board? IA?
Question 2
Is IA independent?
Question 3
Is there an objectivity impairment?
Question 4
What evidence is required?
Question 5
What is the risk?
Question 6
What is the most appropriate next step?
35. MASTER CORPORATE CASE
Scenario
A multinational company discovers that a senior procurement executive has approved ₹50 crore of purchases from a related vendor.
The CAE is asked to investigate.
The auditor discovers:
- no competitive bidding
- vendor relationship not disclosed
- manager has financial ties to vendor
- approval controls were bypassed
- CFO says: "Don't escalate this; we need the supplier."
CIA ANALYSIS
Risk: High
Potential fraud: Yes
Conflict of interest: Yes
Management override: Yes
Control weakness: Yes
Objectivity pressure: Yes
What should IA NOT do?
❌ Ignore the matter
❌ Change findings because CFO requested it
❌ Assume guilt without evidence
❌ Become operational procurement manager
What should IA do?
✅ Maintain objectivity
✅ Gather sufficient appropriate evidence
✅ Follow investigation/reporting protocols
✅ Escalate appropriately
✅ Communicate significant findings
✅ Recommend improvements without assuming management responsibility
36. CIA EXAM KEYWORDS
When you see these words, slow down.
| Keyword | Think |
|---|---|
| BEST | Most appropriate professional judgment |
| FIRST | Immediate/initial action |
| MOST likely | Highest probability |
| EXCEPT | Find the wrong option |
| NOT | Reverse the question |
| PRIMARY responsibility | Who owns it? |
| INDEPENDENCE | Board/Audit Committee |
| OBJECTIVITY | Individual judgment |
| SELF-REVIEW | Auditor's own previous work |
| FAMILIARITY | Excessive trust |
| INTIMIDATION | Pressure/threat |
| MANAGEMENT OVERRIDE | Management bypasses control |
| INHERENT RISK | Before controls |
| RESIDUAL RISK | After controls |
| PREVENTIVE | Before event |
| DETECTIVE | Find event |
| CORRECTIVE | Fix |
| RISK APPETITE | Willingness to accept risk |
| RISK TOLERANCE | Acceptable variation/limit |
| REASONABLE ASSURANCE | Not absolute assurance |
| DUE CARE | Prudent competent auditor |
| CONFIDENTIALITY | Protect information |
| TOPICAL REQUIREMENT | Mandatory when applicable to assurance |
| BOARD | Oversight |
| MANAGEMENT | Ownership |
| IA | Independent assessment |
37. 15 SECOND DECISION TREE
When stuck between two CIA answers:
STEP 1
Does the answer preserve independence?
↓
STEP 2
Does it preserve objectivity?
↓
STEP 3
Does it keep management responsible for management decisions?
↓
STEP 4
Does it use sufficient appropriate evidence?
↓
STEP 5
Does it follow the Standards/policies?
↓
STEP 6
Does it escalate appropriately?
↓
STEP 7
Choose the answer that represents:
Professional judgment + risk-based thinking + independence + evidence + governance.
38. 15 GOLDEN RULES FOR CIA PART 1
- Management owns risk; IA assesses risk.
- Management owns controls; IA evaluates controls.
- Board provides oversight.
- Functional reporting protects independence.
- Administrative reporting supports day-to-day administration.
- IA may advise; IA should not assume management responsibility.
- Self-review = auditing your own work.
- Familiarity = excessive trust/bias.
- Intimidation = pressure or undue influence.
- Inherent risk = before controls.
- Residual risk = after controls.
- Preventive = before; Detective = after; Corrective = fix.
- Fraud prevention/detection is primarily management's responsibility.
- Due professional care does not mean perfection or guaranteed fraud detection.
- When uncertain, choose the answer that best preserves independence, objectivity, evidence-based judgment and management accountability.
39. FINAL CIA PART 1 MASTER MAP
DOMAIN I — FOUNDATIONS — 35%
Purpose
→ Value
→ IPPF
→ Global Standards
→ Topical Requirements
→ Charter
→ Assurance vs Consulting
→ Board/CAE responsibilities
→ Internal audit mandate
DOMAIN II — ETHICS & PROFESSIONALISM — 20%
Integrity
→ Objectivity
→ Competency
→ Due Professional Care
→ Confidentiality
→ Independence
→ Conflicts
→ Impairments
→ QA/quality concepts
DOMAIN III — GOVERNANCE/RISK/CONTROL — 30%
Governance
→ Board
→ Management
→ Risk appetite
→ Risk tolerance
→ Inherent risk
→ Residual risk
→ Risk management
→ COSO
→ Control environment
→ Preventive/detective/corrective
→ Control effectiveness
DOMAIN IV — FRAUD — 15%
Fraud Triangle
→ Pressure
→ Opportunity
→ Rationalization
→ Red flags
→ Fraud risk assessment
→ Fraud controls
→ Management responsibility
→ IA role
→ Investigation/reporting
⭐ ONE-LINE MEMORY FORMULA
CIA = INDEPENDENT + OBJECTIVE + RISK-BASED + EVIDENCE-BASED + ETHICAL + VALUE-FOCUSED
That is the internal auditor's mindset I would repeatedly reinforce with students.
Important source note for study material
"The old six-domain syllabus is useful for historical mapping and understanding legacy study material, but candidates preparing for the current exam should prioritize the revised four-domain CIA Part 1 syllabus and the 2024 Global Internal Audit Standards."
Also, I would not teach the 2017 IPPF as if its separate components are current requirements. The IIA says the 2024 Standards incorporated the former mandatory elements of the 2017 IPPF, while Global Guidance remains recommended.
Official references: · ·
This version is much safer to use as GMSiSuccess CIA Part 1 classroom/revision material, because it separates the current exam's four domains from the 2024 Standards' five domains/15 principles, while retaining the old syllabus only as a mapping tool.

