A. Foundations of Internal Auditing
1. Which of the following BEST describes the primary purpose of internal auditing?
A. To prepare accurate financial statements
B. To provide independent, objective assurance and advisory services designed to add value and improve operations
C. To detect every instance of fraud
D. To guarantee that organizational objectives will be achieved
Answer: B
2. Which of the following is NOT normally an objective of internal auditing?
A. Evaluating governance processes
B. Assessing risk management
C. Improving control processes
D. Guaranteeing that management will never make an error
Answer: D
3. The internal audit activity creates value primarily by:
A. Replacing management's responsibilities
B. Providing assurance and insight regarding governance, risk management, and control
C. Taking responsibility for operational decisions
D. Eliminating all organizational risks
Answer: B
4. Which statement about internal auditors is MOST appropriate?
A. Internal auditors own the organization's risks.
B. Internal auditors are responsible for establishing management controls.
C. Internal auditors evaluate and provide assurance regarding governance, risk management, and controls.
D. Internal auditors must approve every significant management decision.
Answer: C
5. EITHER/OR
The internal audit activity primarily provides:
A. Assurance OR advisory services
B. Assurance and/or advisory services
C. Management services OR accounting services only
D. Audit opinions OR statutory certifications only
Answer: B
6. Which of the following would create the GREATEST threat to internal audit independence?
A. The chief audit executive reports functionally to the audit committee.
B. The internal audit department participates in risk assessment discussions.
C. The chief audit executive is responsible for operating a business process being audited.
D. Internal auditors communicate audit findings to senior management.
Answer: C
7. An internal auditor previously managed the payroll function. The auditor is now assigned to audit payroll. Which is the BEST approach?
A. Accept the assignment without modification.
B. Disclose the potential impairment and consider an appropriate safeguard.
C. Cancel the entire internal audit activity.
D. Allow the auditor to audit payroll because prior experience automatically guarantees objectivity
Answer: B
8. ASSERTION–REASON
Assertion: Internal auditors should maintain objectivity during audit engagements.
Reason: Objectivity requires an unbiased mental attitude that allows auditors to perform engagements without compromising professional judgment.
A. Both Assertion and Reason are true, and Reason correctly explains Assertion.
B. Both are true, but Reason does not explain Assertion.
C. Assertion is true, Reason is false.
D. Assertion is false, Reason is true.
Answer: A
9. Which of the following is the BEST example of an internal audit advisory service?
A. Designing and operating management's controls
B. Making an operational decision for management
C. Advising management on control considerations during implementation of a new system
D. Assuming responsibility for the organization's risk management process
Answer: C
10. NEITHER/NOR
Which of the following should internal auditors normally do?
A. Neither evaluate controls nor communicate deficiencies
B. Evaluate controls and communicate significant deficiencies
C. Assume management's responsibility for controls
D. Guarantee that controls will eliminate all risk
Answer: B
B. Ethics & Professionalism
11. Which principle requires internal auditors to be honest and truthful?
A. CompetencyB. IntegrityC. ConfidentialityD. Objectivity
Answer: B
12. An internal auditor discovers confidential customer information during an engagement. The auditor should:
A. Share it with friends because the information is interesting.
B. Use the information for personal investment decisions.
C. Protect the information and use it only for legitimate professional purposes.
D. Publish it after completing the audit.
Answer: C
13. Which of the following is MOST likely to violate the principle of confidentiality?
A. Reporting relevant information to authorized management
B. Discussing confidential client information with an unauthorized third party
C. Using information necessary to perform an audit
D. Protecting audit documentation
Answer: B
14. An auditor receives an expensive gift from the manager of an audited department. What is the PRIMARY concern?
A. CompetencyB. ObjectivityC. CommunicationD. Audit documentation
Answer: B
15. Which of the following is NOT consistent with professional competence?
A. Applying appropriate knowledge and skills
B. Continuing professional development
C. Performing work without possessing the necessary knowledge
D. Maintaining professional proficiency
Answer: C
16. EXCEPT
Internal auditors should demonstrate professional behavior by doing all of the following EXCEPT:
A. Exercising professional judgment
B. Maintaining confidentiality
C. Acting with integrity
D. Suppressing unfavorable audit findings to protect management
Answer: D
17. ASSERTION–REASON
Assertion: Internal auditors should disclose material facts known to them when withholding such facts could distort reporting.
Reason: Ethical professional conduct requires auditors to communicate information fairly and not knowingly participate in misleading reporting.
A. Both are true, and Reason explains Assertion.B. Both are true, but Reason does not explain Assertion.C. Assertion is true, Reason is false.
D. Both are false.
Answer: A
18. An internal auditor lacks sufficient knowledge to audit a highly specialized cybersecurity system. What should the auditor MOST appropriately do?
A. Perform the engagement regardless of competence.
B. Obtain appropriate assistance or expertise.
C. Ignore cybersecurity risks.
D. Ask management to perform the audit instead.
Answer: B
19. Which situation BEST represents a conflict of interest?
A. An auditor reviews a process in which the auditor has a significant personal financial interest.
B. An auditor communicates findings to the audit committee.
C. An auditor performs a risk assessment.
D. An auditor reviews supporting documentation.
Answer: A
20. EITHER/OR
If an auditor's objectivity is impaired, the auditor should:
A. Ignore the impairment OR conceal it
B. Disclose the impairment and apply appropriate safeguards OR avoid the assignment
C. Continue auditing OR change the audit results
D. Accept management's explanation OR delete the working papers
Answer: B
C. Governance
21. Which of the following BEST describes organizational governance?
A. The system by which an organization is directed, overseen, and held accountableB. The process of recording journal entries
C. The preparation of tax returnsD. The process of approving employee leave
Answer: A
22. Which body normally provides the MOST direct oversight of the chief audit executive?
A. Accounts payable departmentB. Audit committee or equivalent governing bodyC. Sales departmentD. Human resources department
Answer: B
23. Which of the following is NOT normally a responsibility of the board?
A. Providing oversight of risk management
B. Overseeing organizational governance
C. Monitoring senior management's performance
D. Performing every operational control personally
Answer: D
24. CASE-BASED
The board of a company rarely receives information about major cybersecurity risks. Management believes cybersecurity is purely an IT issue.
Internal audit discovers that significant cyber risks could affect the organization's strategic objectives.
What should internal audit MOST appropriately recommend?
A. Ignore the issue because cybersecurity belongs only to IT.
B. Ensure significant cybersecurity risks are incorporated into organizational risk oversight and governance.
C. Transfer all cybersecurity responsibilities to internal audit.
D. Eliminate the cybersecurity department.
Answer: B
25. Which governance practice BEST promotes accountability?
A. Clearly defined roles and responsibilities
B. Unlimited management authority
C. No reporting requirements
D. Elimination of independent oversight
Answer: A
26. NEITHER/NOR
Effective governance normally requires:
A. Neither accountability nor transparency
B. Accountability and transparency
C. Elimination of risk assessment
D. Elimination of board oversight
Answer: B
27. Which of the following is the BEST example of effective governance?
A. Management makes decisions without oversight.
B. The board receives reliable information and oversees organizational performance and risk.
C. Internal audit approves operational transactions.
D. Employees determine the organization's risk appetite independently.
Answer: B
D. Risk Management
28. Risk is BEST described as:
A. The certainty that an objective will fail
B. The possibility of an event occurring that could affect achievement of objectives
C. A financial loss only
D. Fraud committed by employees
Answer: B
29. Which of the following BEST describes inherent risk?
A. Risk remaining after controls are applied
B. Risk existing before management takes action to modify it
C. Risk eliminated by internal audit
D. Risk resulting only from fraud
Answer: B
30. Which of the following BEST describes residual risk?
A. Risk before controls are implemented
B. Risk remaining after management's response to risk
C. Risk that can never occur
D. Risk identified only by external auditors
Answer: B
31. A company's risk appetite represents:
A. The amount and type of risk the organization is willing to accept in pursuit of its objectivesB. The amount of fraud management expects
C. The maximum audit feeD. The amount of risk internal audit must eliminate
Answer: A
32. EXCEPT
Management may respond to risk by:
A. Accepting the riskB. Avoiding the riskC. Reducing the riskD. Guaranteeing that the risk will never occur
Answer: D
33. ASSERTION–REASON
Assertion: Internal auditors should consider risk when developing the audit plan.
Reason: Internal audit resources are limited and should generally be directed toward areas with significant risks to organizational objectives.
A. Both are true, and Reason correctly explains Assertion.
B. Both are true, but Reason does not explain Assertion.
C. Assertion is true, Reason is false.
D. Assertion is false, Reason is true.
Answer: A
34. CASE-BASED
A company has identified a major supply-chain risk. Management believes the probability is moderate but the potential financial impact is extremely high.
What should internal audit consider when assessing this risk?
A. Impact only
B. Likelihood only
C. Both likelihood and impact
D. Neither likelihood nor impact
Answer: C
35. Which of the following is the BEST example of risk avoidance?
A. Purchasing insuranceB. Installing additional controls
C. Discontinuing an activity that exposes the organization to unacceptable risk
D. Accepting the risk without action
Answer: C
E. Internal Control
36. The PRIMARY purpose of internal control is to:
A. Guarantee achievement of all objectivesB. Provide reasonable assurance regarding achievement of objectivesC. Eliminate all risks
D. Detect every fraud
Answer: B
37. Which of the following is NOT a typical internal control objective?
A. Effectiveness and efficiency of operations
B. Reliability of reporting
C. Compliance with applicable laws and regulations
D. Guaranteeing zero business risk
Answer: D
38. Which control is MOST likely preventive?
A. Bank reconciliation
B. Exception report
C. Password access restriction
D. Post-audit review
Answer: C
39. Which control is MOST likely detective?
A. Segregation of dutiesB. Authorization before purchase
C. Bank reconciliationD. Password requirement
Answer: C
40. EXCEPT
Which of the following can be considered control activities EXCEPT:
A. AuthorizationB. ReconciliationC. Physical safeguards
D. Elimination of all inherent limitations of control
Answer: D
41. A company requires one employee to prepare payments and another employee to approve them. This is primarily an example of:
A. Segregation of dutiesB. Risk acceptance
C. Risk avoidanceD. Monitoring
Answer: A
42. CASE-BASED
An employee can create a new vendor, approve invoices from that vendor, and authorize payment.
Which control weakness is MOST significant?
A. Excessive monitoring
B. Inadequate segregation of duties
C. Excessive authorization
D. Excessive documentation
Answer: B
43. Which of the following is an example of a corrective control?
A. Password requirementB. Approval before purchase
C. Automated backup restoration after data lossD. Segregation of duties
Answer: C
44. ASSERTION–REASON
Assertion: Internal controls provide reasonable rather than absolute assurance.
Reason: Human judgment, management override, collusion, and cost-benefit considerations can limit control effectiveness.
A. Both are true, and Reason correctly explains Assertion.
B. Both are true, but Reason does not explain Assertion.
C. Assertion is true, Reason is false.
D. Assertion is false, Reason is true.
Answer: A
45. NEITHER/NOR
Which statement is correct regarding internal controls?
A. Neither preventive nor detective controls are necessary.
B. Preventive and detective controls can complement each other.
C. Controls eliminate all risk.
D. Controls eliminate the need for management oversight.
Answer: B
F. Fraud Risks
46. Which of the following is NOT one of the classic elements of the fraud triangle?
A. Pressure/incentiveB. OpportunityC. RationalizationD. Guaranteed detection
Answer: D
47. CASE-BASED
A finance manager is under severe personal financial pressure and believes that manipulating expense reports is justified because "the company owes me anyway."
Which fraud triangle elements are MOST clearly present?
A. Pressure and rationalizationB. Opportunity only
C. Detection and monitoringD. Governance and compliance
Answer: A
48. An employee discovers that no one reviews manual journal entries. The employee realizes that fictitious entries can be recorded without detection.
This situation MOST directly represents:
A. RationalizationB. OpportunityC. PressureD. Risk avoidance
Answer: B
49. EXCEPT
Internal auditors may contribute to fraud risk management by:
A. Assessing fraud risksB. Evaluating controls designed to address fraud risks
C. Increasing awareness of fraud indicatorsD. Assuming complete responsibility for preventing all fraud
Answer: b
50. COMPREHENSIVE CASE-BASED
A rapidly growing company has weak segregation of duties. Senior management rarely reviews unusual transactions. Several employees complain that sales targets are unrealistic. An internal auditor notices that one sales manager frequently records large sales at month-end and reverses them early in the following month.
Which combination BEST represents the situation?
A. Strong governance, low fraud risk, and effective controlsB. Fraud risk indicators involving pressure, opportunity, and potentially inappropriate revenue recognitionC. Only operational risk with no fraud implications
D. Neither governance nor control weaknesses
Answer b
Pl read…High-yield CIA Part 1 areas tested
- Foundations: purpose, role, assurance/advisory, independence, objectivity
- Ethics & Professionalism: integrity, objectivity, confidentiality, competency
- Governance: board, audit committee, accountability, transparency
- Risk Management: inherent risk, residual risk, appetite, response
- Internal Control: preventive, detective, corrective, segregation of duties, reasonable assurance
- Fraud: pressure/incentive, opportunity, rationalization, fraud indicators
CIA Part 1–style MCQs on Ethics & Professionalism….
1. Which principle requires an internal auditor to be honest and transparent in professional activities?
A. ConfidentialityB. ObjectivityC. IntegrityD. Competency
Answer: C. Integrity
2. An internal auditor discovers confidential information about a planned acquisition. What should the auditor do?
A. Share it with colleagues outside the engagement
B. Use it for personal investment purposes
C. Protect the information and use it only for legitimate professional purposes
D. Discuss it publicly after the audit
Answer: C. Protect the information and use it only for legitimate professional purposes
3. Which situation MOST likely impairs an internal auditor's objectivity?
A. Reviewing evidence obtained during an engagement
B. Attending professional training
C. Auditing a department that the auditor previously managed
D. Communicating findings to the audit committee
Answer: C. Auditing a department that the auditor previously managed
4. Which of the following is NOT consistent with professional competence?
A. Maintaining relevant knowledge and skills
B. Performing an engagement without adequate expertise
C. Obtaining assistance when specialized knowledge is required
D. Continuing professional development
Answer: B. Performing an engagement without adequate expertise
Which of the following BEST demonstrates professional competence?
A. Ignoring new professional requirements
B. Performing work without adequate knowledge
C. Maintaining and applying appropriate knowledge and skills
D. Accepting assignments regardless of expertise
Answer: C. Maintaining and applying appropriate knowledge and skills
5. An auditor is offered an expensive gift by the manager of the department being audited. What is the PRIMARY ethical concern?
A. ConfidentialityB. CompetencyC. ObjectivityD. Due professional care
Answer: C. Objectivity
6. ASSERTION–REASON
Assertion: Internal auditors should disclose significant impairments to independence or objectivity.
Reason: Undisclosed impairments may influence users' perception of the reliability and impartiality of audit work.
A. Assertion is false, but Reason is true
B. Both are false
C. Both are true, and Reason correctly explains Assertion
D. Assertion is true, but Reason is false
Answer: C
7. An internal auditor does not possess sufficient expertise to evaluate a highly technical cybersecurity system. What is the MOST appropriate action?
A. Obtain appropriate assistance or expertise
B. Complete the engagement without considering the limitation
C. Ignore the cybersecurity component
D. Transfer responsibility for the entire internal audit function to IT
Answer: A. Obtain appropriate assistance or expertise
8. EXCEPT
Internal auditors should:
A. Exercise professional judgment
B. Protect confidential information
C. Maintain objectivity
D. Deliberately omit unfavorable findings to protect senior management
Answer: D. Deliberately omit unfavorable findings to protect senior management
9. An internal auditor becomes aware of information that, if omitted, would make an audit report misleading. What should the auditor do?
A. Delete the information from the working papers
B. Report only information requested by management
C. Communicate the relevant information appropriately
D. Wait until the next audit cycle
Answer: C. Communicate the relevant information appropriately
10. CASE-BASED
An internal auditor is auditing a purchasing department. The department manager is a close personal friend of the auditor. During the engagement, the manager asks the auditor to ignore several control deficiencies.
What is the BEST course of action?
A. Ignore the deficiencies because the manager is a friend
B. Allow the manager to decide which findings are reported
C. Disclose the potential impairment and take appropriate action to safeguard objectivity
D. Cancel the entire internal audit activity
Answer: C. Disclose the potential impairment and take appropriate action to safeguard objectivity
CIA Part 1–style practice questions focused on fraud risks, fraud risk management, fraud indicators, the fraud triangle, controls, investigations, and the internal auditor's role.
1. Which of the following BEST describes the internal auditor's role regarding fraud?
A. Guarantee that fraud will never occur
B. Assume management's responsibility for fraud prevention
C. Assess fraud risks and evaluate controls designed to address those risks
D. Conduct criminal investigations in every suspected case
Answer: C
2. Which of the following is NOT an element of the traditional fraud triangle?
A. Pressure or incentiveB. OpportunityC. RationalizationD. Competency
Answer: D
3. An employee is experiencing severe financial difficulties and believes that stealing company funds is justified because the company underpays employees. Which fraud triangle elements are MOST evident?
A. Opportunity and detectionB. Governance and control
C. Pressure and rationalizationD. Competency and monitoring
Answer: C
4. An employee discovers that no one reviews cash disbursements. The employee realizes that fictitious payments could be made without detection. This represents:
A. RationalizationB. PressureC. OpportunityD. Fraud concealment
Answer: C
5. Which of the following is the BEST preventive control against employee fraud?
A. Investigation after fraud is discovered
B. Segregation of incompatible duties
C. Review of fraud losses after year-end
D. External reporting of detected fraud
Answer: B
6. Which situation is MOST likely to indicate fraudulent financial reporting?
A. Management consistently exceeds realistic earnings expectations by recording unsupported revenue near year-end
B. The company performs monthly bank reconciliations
C. Employees take annual leave regularly
D. Management strengthens approval procedures
Answer: A
7. EXCEPT
Fraud risk indicators may include all of the following EXCEPT:
A. Unusual transactions
B. Significant unexplained changes in financial results
C. Strong segregation of duties
D. Excessive management pressure to achieve unrealistic targets
Answer: C
8. Which of the following is the BEST example of asset misappropriation?
A. Deliberately overstating revenue
B. Concealing a regulatory violation
C. Stealing inventory for personal use
D. Manipulating accounting estimates
Answer: C
9. CASE-BASED
A purchasing employee creates a fictitious vendor controlled by a relative and approves invoices from that vendor. No independent review of new vendors is performed.
Which combination of fraud risk factors is MOST apparent?
A. Opportunity and conflict of interestB. Rationalization only
C. Pressure onlyD. Risk avoidance and monitoring
Answer: A
10. Which action would MOST effectively reduce the opportunity component of the fraud triangle?
A. Increasing employee bonusesB. Establishing effective segregation of duties and authorization controlsC. Reducing internal audit activities
D. Allowing employees unrestricted system access
Answer: B
11. ASSERTION–REASON
Assertion: Internal auditors should consider fraud risks when planning engagements.
Reason: Fraud can prevent an organization from achieving its objectives and may exploit weaknesses in governance, risk management, and control processes.
A. Both are true, and the Reason correctly explains the Assertion
B. Both are true, but the Reason does not explain the Assertion
C. Assertion is true, but Reason is false
D. Assertion is false, but Reason is true
Answer: A
12. An employee reports suspected fraud through an organization's whistleblower mechanism. What should management MOST appropriately ensure?
A. The employee is immediately dismissed
B. The allegation is ignored unless financial loss is already proven
C. The allegation is appropriately assessed and investigated according to established procedures
D. The suspected employee is immediately declared guilty
Answer: C
13. Which of the following is MOST likely to be a red flag for procurement fraud?
A. Competitive bidding with documented approvals
B. One supplier repeatedly receiving contracts despite significantly higher prices
C. Periodic supplier evaluations
D. Independent review of purchase orders
Answer: B
14. NEITHER/NOR
Which statement about fraud prevention is MOST appropriate?
A. Neither management nor the board has responsibility for fraud risk management
B. Management and the board have important responsibilities for establishing an environment that reduces fraud risk
C. Internal audit should own all fraud prevention controls
D. Fraud can be completely eliminated through internal controls
Answer: B
15. An internal auditor suspects that senior management may be involved in fraud. What is the MOST appropriate initial consideration?
A. Ignore the matter because senior management cannot commit fraud
B. Follow established escalation and investigation procedures and communicate with the appropriate level of governance
C. Confront the suspected executive publicly
D. Delete the audit evidence to avoid conflict
Answer: B
16. Which of the following BEST distinguishes fraud from error?
A. Fraud always involves a financial lossB. Fraud involves intentional deception, whereas an error is generally unintentionalC. Errors are committed only by employeesD. Fraud can occur only in financial reporting
Answer: B
17. CASE-BASED
A sales director knows that annual bonuses depend on achieving a revenue target. Near year-end, the director instructs employees to record sales before the goods are actually delivered, with the intention of reversing the entries next quarter.
What is the PRIMARY fraud concern?
A. Accidental accounting errorB. Fraudulent financial reporting through premature revenue recognitionC. Normal business judgment
D. Physical asset theft
Answer: B
18. Which of the following is the BEST example of management override?
A. An employee follows an established approval procedure
B. A manager bypasses established controls to authorize an inappropriate transaction
C. An auditor tests a control
D. A supervisor reviews a reconciliation
Answer: B
19. EITHER/OR
Effective fraud risk management generally requires:
A. Preventive controls OR detective controls, but never both
B. Fraud risk identification, assessment, response, and monitoring
C. Internal audit ownership OR management ownership, but not both
D. Investigation OR prevention, but not both
Answer: B
20. COMPREHENSIVE CASE-BASED
A company has aggressive sales targets, weak segregation of duties, inadequate review of journal entries, and employees believe that manipulating results is acceptable because "everyone does it."
Which combination BEST describes the fraud risk environment?
A. Pressure, opportunity, and rationalization are all present
B. Only opportunity is present
C. Only rationalization is present
D. There is no significant fraud risk because management has established sales targets
Answer: A
CIA Part 1 — Control Application
10 Case-Based MCQs with Answers
These questions focus on control design, preventive/detective/corrective controls, segregation of duties, authorization, reconciliation, access controls, monitoring, and control deficiencies.
1 A company allows the same employee to create new vendors, enter invoices, and release payments. Management argues that the employee is trustworthy and has worked for the company for 10 years.
What is the GREATEST control concern?
A. Lack of employee training
B. Excessive documentation
C. Inadequate segregation of duties
D. Lack of physical security
Answer: C
Explanation: Combining vendor creation, invoice processing, and payment authorization creates an opportunity for fictitious vendors and fraudulent payments.
2A manufacturing company requires a purchase order to be approved by an authorized manager before a purchase can be made.
This is primarily what type of control?
A. Detective controlB. Corrective control
C. Preventive controlD. Compensating control
Answer: C
Explanation: The control is designed to prevent an unauthorized transaction from occurring.
3A company performs a monthly bank reconciliation. During the reconciliation, the accountant discovers an unauthorized payment that was processed during the month.
The bank reconciliation is primarily a:
A. Preventive controlB. Detective control
C. Corrective controlD. Directive control
Answer: B
Explanation: The reconciliation identifies an error or irregularity after the transaction has occurred.
4A payroll system allows employees to access payroll records using individual usernames and passwords. However, employees who leave the organization continue to have access for several weeks.
Which control weakness is MOST significant?
A. Lack of employee training
B. Inadequate termination access procedures
C. Excessive payroll documentation
D. Lack of physical inventory controls
Answer: B
Explanation: Access should be promptly removed when employees leave. Delayed termination of access increases the risk of unauthorized transactions or data manipulation.
5. Authorization Control
A company requires all expenses above ₹100,000 to be approved by the CFO. An employee divides a ₹300,000 purchase into three separate ₹100,000 invoices to avoid CFO approval.
Which control weakness is MOST evident?
A. Inadequate monitoring of transactions
B. Excessive segregation of duties
C. Lack of physical safeguards
D. Excessive management review
Answer: A
Explanation: Management should monitor transactions for unusual patterns such as transaction splitting designed to circumvent approval limits.
6. CASE — Inventory A warehouse employee is responsible for receiving goods, updating inventory records, and approving inventory adjustments. No independent physical inventory count is performed.
Which recommendation would BEST strengthen internal control?
A. Give the employee additional authority
B. Eliminate inventory records
C. Separate custody, recordkeeping, and adjustment approval responsibilities
D. Allow inventory adjustments without documentation
Answer: C
Explanation: Separating incompatible duties reduces the opportunity for theft and manipulation of inventory records.
7. CASE — Corrective Control
A company has an automated system that detects duplicate vendor payments. When a duplicate payment is identified, the system automatically blocks the payment and generates an exception report for investigation.
The system's response to the detected duplicate payment is BEST classified as:
A. Preventive control only
B. Corrective control
C. Directive control only
D. Compensating control only
Answer: B
Explanation: Once an exception is identified, blocking the payment and initiating corrective action addresses the detected problem.
8The CEO of a company has authority to approve transactions above all normal approval limits. Internal audit discovers that the CEO approved several unusual transactions without supporting documentation.
What is the PRIMARY control concern?
A. Excessive employee training
B. Management override of controls
C. Excessive segregation of duties
D. Lack of inventory valuation
Answer: B
Explanation: Senior management's ability to bypass established controls creates a significant risk of inappropriate or fraudulent transactions.
9A company maintains separate records for accounts receivable and cash receipts. The accounts receivable clerk prepares a monthly reconciliation between customer accounts and cash received. However, the reconciliation is reviewed by another employee only when differences are identified.
What is the BEST improvement?
A. Eliminate the reconciliation
B. Require independent review of every reconciliation
C. Allow the same clerk to approve differences
D. Reduce the frequency of reconciliations
Answer: B
Explanation: Independent review provides an important control over errors, omissions, and potential manipulation.
10. Comprehensive Case
A company implements a new ERP system. Employees can enter and approve their own transactions. Passwords are shared between employees, terminated employees' accounts are not promptly disabled, and management does not review system-generated exception reports.
Which combination represents the MOST significant control weaknesses?
A. Weak access controls, inadequate segregation of duties, and ineffective monitoring
B. Strong authorization, strong access controls, and effective monitoring
C. Excessive preventive controls and excessive documentation
D. Only inadequate employee training
Answer: A
Explanation: The case contains three major weaknesses:
Pl read… Shared passwords → weak access/security controls
Employees approving their own transactions → inadequate segregation of duties
No review of exception reports → ineffective monitoring
Terminated users retaining access → inadequate user-access management
MCQs — COSO & COBIT Governance Principles
COSO Internal Control Framework
1. Which COSO component establishes the foundation for all other components of internal control?
A. Risk assessmentB. Control activities
C. Control environmentD. Monitoring activities
Answer: C — Control environment
2. Which of the following is NOT one of the five COSO Internal Control components?
A. Risk assessmentB. Control activities
C. Governance and cultureD. Information and communication
Answer: C — Governance and culture
Governance and Culture is a component of COSO ERM, not the COSO Internal Control Framework.
3. Under COSO, management's identification and analysis of fraud risks falls primarily under:
A. Control environmentB. Risk assessment
C. Control activitiesD. Monitoring
Answer: B — Risk assessment
4. Which COSO principle addresses the board's responsibility to exercise oversight?
A. Principle 1B. Principle 2C. Principle 4D. Principle 5
Answer: B — Principle 2
5. Management establishes appropriate structures, reporting lines, and authorities. This relates to which COSO principle?
A. Principle 2B. Principle 3C. Principle 4D. Principle 6
Answer: B — Principle 3
6. An organization provides extensive training to ensure employees possess the skills necessary for their responsibilities. Which COSO principle is most directly addressed?
A. Demonstrates commitment to competence
B. Enforces accountability
C. Exercises oversight responsibility
D. Identifies and analyzes risk
Answer: A — Demonstrates commitment to competence
7. Which principle requires the organization to hold individuals accountable for their internal control responsibilities?
A. Principle 2B. Principle 3C. Principle 4D. Principle 5
Answer: D — Principle 5
8. Which of the following is associated with COSO Principle 6?
A. Identifying fraud riskB. Specifying suitable objectives
C. Selecting control activitiesD. Communicating externally
Answer: B — Specifying suitable objectives
9. A company identifies risks that could prevent it from achieving its objectives and evaluates their significance. This represents:
A. Principle 6B. Principle 7C. Principle 10D. Principle 13
Answer: B — Principle 7
10. Which COSO principle specifically addresses fraud risk?
A. Principle 5B. Principle 7C. Principle 8D. Principle 11
Answer: C — Principle 8
11. A new regulatory requirement significantly changes the organization's operating environment. Which COSO principle is most relevant?
A. Identifies and analyzes significant changeB. Uses relevant information
C. Deploys through policiesD. Enforces accountability
Answer: A — Principle 9
12. Which principle deals specifically with selecting and developing control activities?
A. Principle 8B. Principle 9C. Principle 10D. Principle 12
Answer: C — Principle 10
13. General controls over technology are specifically addressed by which COSO principle?
A. Principle 9B. Principle 10C. Principle 11D. Principle 13
Answer: C — Principle 11
14. Policies and procedures are used to communicate management's expectations regarding control activities. This primarily represents:
A. Principle 10B. Principle 11C. Principle 12D. Principle 14
Answer: C — Principle 12
15. Which COSO principle requires the organization to obtain and use relevant, quality information?
A. Principle 12B. Principle 13C. Principle 14D. Principle 15
Answer: B — Principle 13
16. Communication of important internal control information throughout the organization relates primarily to:
A. Principle 13B. Principle 14C. Principle 15D. Principle 16
Answer: B — Principle 14
17. Communication with external parties regarding relevant internal control matters is primarily addressed by:
A. Principle 12B. Principle 13C. Principle 14D. Principle 15
Answer: D — Principle 15
18. Which activity is most closely associated with COSO monitoring activities?
A. Establishing organizational objectives
B. Performing ongoing and separate evaluations
C. Establishing reporting lines
D. Identifying fraud risks
Answer: B — Performing ongoing and separate evaluations
19. A manager periodically evaluates whether internal controls continue to operate effectively. This is an example of:
A. Risk identificationB. Monitoring
C. Control environmentD. Control design
Answer: B — Monitoring
20. A control deficiency is identified and communicated to those responsible for corrective action. Which COSO principle is most relevant?
A. Principle 15B. Principle 16C. Principle 17D. Principle 10
Answer: C — Principle 17
COSO — Application & Exam Traps
21. Which statement BEST describes COSO Internal Control?
A. It guarantees elimination of fraud.
B. It provides reasonable assurance regarding achievement of objectives.
C. It transfers management's control responsibilities to internal audit.
D. It focuses exclusively on financial reporting.
Answer: B — It provides reasonable assurance regarding achievement of objectives.
COSO emphasizes internal control as supporting achievement of objectives in operations, reporting, and compliance—not merely financial reporting.
22. Which of the following is NOT an objective category of COSO Internal Control?
A. OperationsB. ReportingC. ComplianceD. Investment return maximization
Answer: D — Investment return maximization
23. Which statement about COSO principles is MOST accurate?
A. Each principle applies only to public companies.
B. The principles are unrelated to the five components.
C. The principles support the five components of internal control.
D. The principles replace management's judgment regarding controls.
Answer: C — The principles support the five components of internal control.
24. Which situation BEST illustrates a control environment weakness?
A. Bank reconciliations are not performed monthly.
B. Senior management ignores established ethical standards.
C. An invoice lacks a purchase order.
D. A password expires after 90 days.
Answer: B — Senior management ignores established ethical standards.
25. Which situation BEST illustrates a risk assessment activity?
A. Separating authorization from custody
B. Reviewing employee performance
C. Evaluating the likelihood and impact of a cyberattack
D. Reconciling the bank account
Answer: C — Evaluating the likelihood and impact of a cyberattack
26. Which situation BEST represents a control activity rather than a risk assessment activity?
A. Identifying a new supply-chain riskB. Evaluating fraud exposure
C. Requiring two approvals for large paymentsD. Assessing the impact of inflation
Answer: C — Requiring two approvals for large payments
27. An organization has excellent policies but employees do not understand how to perform their control responsibilities. Which COSO component is MOST directly affected?
A. Information and communicationB. Risk assessment
C. Control activitiesD. Monitoring
Answer: A — Information and communication
28. Internal audit discovers that a control operates effectively but no longer addresses a newly emerging risk. Which COSO area deserves the MOST attention?
A. Control environmentB. Risk assessment
C. Segregation of dutiesD. External communication
Answer: B — Risk assessment
COSO ERM
29. Which of the following is a COSO ERM component under the 2017 framework?
A. Control activitiesB. Risk assessment
C. PerformanceD. Monitoring activities
Answer: C — Performance
COSO ERM 2017 contains five components: Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; Information, Communication, and Reporting.
30. Risk appetite is most closely associated with which COSO ERM component?
A. Strategy and Objective-Setting
B. Review and Revision
C. Information and Communication
D. Monitoring Activities
Answer: A — Strategy and Objective-Setting
31. Which COSO ERM concept represents the amount and type of risk an organization is willing to accept in pursuit of its objectives?
A. Risk capacityB. Risk appetiteC. Residual riskD. Control deficiency
Answer: B — Risk appetite
32. An organization evaluates whether its strategy remains appropriate after a major change in market conditions. Which COSO ERM component is MOST relevant?
A. Governance and CultureB. Review and Revision
C. PerformanceD. Information, Communication, and Reporting
Answer: B — Review and Revision
COBIT Governance Principles
33. Which of the following is NOT one of the five COBIT 2019 governance system principles?
A. Meeting stakeholder needsB. Covering the enterprise end-to-end
C. Separating governance from managementD. Maximizing shareholder wealth
Answer: D — Maximizing shareholder wealth
The five COBIT governance system principles are meeting stakeholder needs, covering the enterprise end-to-end, applying a single integrated framework, enabling a holistic approach, and separating governance from management.
34. The primary purpose of COBIT is MOST closely related to:
A. Managing only financial statementsB. Governance and management of enterprise information and technologyC. Replacing the external audit function
D. Eliminating all IT risks
Answer: B — Governance and management of enterprise information and technology
35. Which COBIT principle emphasizes that governance should consider all relevant stakeholders and their needs?
A. Applying a single integrated framework
B. Meeting stakeholder needs
C. Enabling a holistic approach
D. Separating governance from management
Answer: B — Meeting stakeholder needs
36. A company evaluates its IT governance from the perspective of the entire enterprise rather than only the IT department. Which COBIT principle is MOST relevant?
A. Covering the enterprise end-to-end
B. Meeting stakeholder needs
C. Applying a single integrated framework
D. Separating governance from management
Answer: A — Covering the enterprise end-to-end
37. An organization integrates COBIT with other applicable standards and frameworks rather than creating isolated governance structures. Which principle applies?
A. Meeting stakeholder needs
B. Applying a single integrated framework
C. Enabling a holistic approach
D. Separating governance from management
Answer: B — Applying a single integrated framework
38. COBIT's holistic approach recognizes that effective governance depends on:
A. Technology aloneB. Policies aloneC. Multiple interconnected components
D. Internal audit alone
Answer: C — Multiple interconnected components
39. Which COBIT principle emphasizes the distinction between governance responsibilities and management responsibilities?
A. Meeting stakeholder needs
B. Covering the enterprise end-to-end
C. Separating governance from management
D. Applying a single integrated framework
Answer: C — Separating governance from management
40. Under COBIT, governance is primarily concerned with:
A. Evaluating, directing, and monitoring
B. Performing every operational IT activity
C. Preparing journal entries
D. Hiring all IT employees
Answer: A — Evaluating, directing, and monitoring
Integrated COSO–COBIT Questions
41. Which framework is generally more specifically focused on enterprise governance and management of information and technology?
A. COSO Internal ControlB. COBITC. COSO ERM onlyD. Basel framework
Answer: B — COBIT
42. Which framework would generally be MOST useful for evaluating whether an organization's overall internal control system is appropriately designed across operations, reporting, and compliance?
A. COSO Internal ControlB. COBIT onlyC. ITIL
D. PMBOK
Answer: A — COSO Internal Control
43. An internal auditor is evaluating IT governance, technology processes, and alignment of IT objectives with enterprise objectives. Which framework would provide particularly relevant guidance?
A. COBITB. COSO Internal Control only
C. GAAPD. IFRS
Answer: A — COBIT
44. Which statement BEST describes the relationship between COSO and COBIT?
A. COBIT completely replaces COSO.
B. COSO completely replaces COBIT.
C. They can be complementary frameworks.
D. They address exactly the same objectives and processes.
Answer: C — They can be complementary frameworks.
COSO and COBIT can be used together because COSO provides a broader internal-control perspective while COBIT provides detailed governance and management guidance for information and technology.
45. A company uses COSO to assess enterprise internal control and COBIT to strengthen IT governance. This approach is:
A. Inconsistent because only one framework may be usedB. Appropriate because frameworks can complement each otherC. Appropriate only for external auditorsD. Prohibited under COSO
Answer: B — Appropriate because frameworks can complement each other
Tricky CIA-Style Questions
46. Which statement is TRUE regarding COSO internal control?
A. A strong control environment eliminates the need for monitoring.B. Effective controls provide absolute assurance.C. Internal control is a process involving people and actions.D. Internal audit owns the organization's internal control system.
Answer: C — Internal control is a process involving people and actions.
47. An organization has all five COSO components documented, but employees do not actually perform the required controls. Which conclusion is MOST appropriate?
A. Internal control is automatically effective because all five components exist on paper.
B. Documentation alone is insufficient; controls must be present and functioning.
C. The organization has no risk.
D. Internal audit should take over management's control responsibilities.
Answer: B — Documentation alone is insufficient; controls must be present and functioning.
COSO's effectiveness concept requires the relevant components and principles to be present and functioning, operating together as an integrated system.
48. Which of the following represents the BEST distinction between governance and management in COBIT?
A. Governance performs daily operations; management monitors the board.
B. Governance evaluates, directs, and monitors; management plans, builds, runs, and monitors operational activities.
C. Governance and management have identical responsibilities.
D. Governance is performed only by the internal audit function
Answer: B — Governance evaluates, directs, and monitors; management handles management/operational activities.
49. A board establishes the organization's desired level of risk, while management develops processes to operate within that level. Which concept is BEST illustrated?
A. Governance and management distinction
B. Segregation of duties only
C. Detective control
D. Corrective control
Answer: A — Governance and management distinction
50. Which combination is MOST appropriate for an internal auditor assessing enterprise internal control and IT governance?
A. COSO for internal control and COBIT for IT governance
B. COBIT for financial accounting and GAAP for IT governance
C. GAAP for internal control and COSO for programming standards
D. IFRS for cybersecurity and COBIT for financial statement presentation
Answer: A — COSO for internal control and COBIT for IT governance
Quick CIA Part 1 Memory Map
Framework | Remember |
COSO Internal Control | 5 components + 17 principles |
Control Environment | Principles 1–5 |
Risk Assessment | Principles 6–9 |
Control Activities | Principles 10–12 |
Information & Communication | Principles 13–15 |
Monitoring | Principles 16–17 |
COSO ERM | 5 components + 20 principles |
COBIT Governance | 5 governance system principles |
COBIT Principle 1 | Meeting stakeholder needs |
COBIT Principle 2 | Covering enterprise end-to-end |
COBIT Principle 3 | Single integrated framework |
COBIT Principle 4 | Holistic approach |
COBIT Principle 5 | Separate governance from management |
These distinctions are especially useful for CIA Part 1 questions that use “MOST appropriate,” “BEST,” “EXCEPT,” “NOT,” and scenario-based wording.
short, exam-focused list of the 17 COSO Internal Control Principles, grouped under the 5 components.
COSO — 17 Principles in Short
1. Control Environment — Principles 1–5
1. Integrity & Ethical Values — Demonstrate commitment to integrity and ethics.
2. Board Oversight — Board exercises oversight responsibility.
3. Structure, Authority & Responsibility — Establish appropriate organizational structure.
4. Competence — Demonstrate commitment to competent personnel.
5. Accountability — Enforce accountability for internal control responsibilities.
2. Risk Assessment — Principles 6–9
6. Suitable Objectives — Specify suitable objectives.
7. Identify & Analyze Risks — Identify and analyze risks.
8. Fraud Risk — Assess fraud risks.
9. Significant Change — Identify and assess significant changes.
3. Control Activities — Principles 10–12
10. Select & Develop Controls — Select and develop control activities.
11. Technology Controls — Select and develop general controls over technology.
12. Policies & Procedures — Deploy controls through policies and procedures.
4. Information & Communication — Principles 13–15
13. Relevant Information — Obtain/use relevant, quality information.
14. Internal Communication — Communicate internally.
15. External Communication — Communicate externally.
5. Monitoring Activities — Principles 16–17
16. Ongoing/Separate Evaluations — Perform evaluations to determine whether controls are functioning.
17. Communicate Deficiencies — Communicate control deficiencies to responsible parties.
🧠Easy Memory Formula
CE → RA → CA → IC → MA
1–5: Ethics → Board → Structure → Competence → Accountability
6–9: Objectives → Risks → Fraud → Change
10–12: Controls → Technology → Policies
13–15: Information → Internal → External
16–17: Evaluate → Deficiencies
This is the COSO Internal Control Framework, not the COSO ERM framework.
exam-focused explanation of all 17 COSO Internal Control Principles with simple practical examples, useful for CIA Part 1 preparation.
COSO 17 Principles with Examples
1. Demonstrates Commitment to Integrity and Ethical Values
Meaning: Management and the board establish and demonstrate ethical behavior.
Example:
The CEO follows the company's code of conduct and takes disciplinary action against a senior employee who commits fraud, even though the employee is a top performer.
CIA clue: Ethics, integrity, code of conduct, "tone at the top."
2. Exercises Oversight Responsibility
Meaning: The board or audit committee independently oversees internal control.
Example:
The audit committee regularly reviews internal audit reports, significant control deficiencies, and management's corrective actions.
CIA clue: Board, audit committee, oversight.
3. Establishes Structure, Authority, and Responsibility
Meaning: The organization establishes appropriate reporting lines, authority, and responsibilities.
Example:
The CFO is responsible for financial reporting, while the controller manages accounting operations and reports to the CFO.
CIA clue: Organization chart, reporting lines, authority, responsibility.
4. Demonstrates Commitment to Competence
Meaning: The organization recruits, develops, and retains employees with the required knowledge and skills.
Example:
Employees responsible for cybersecurity are required to maintain appropriate professional certifications and receive regular technical training.
CIA clue: Skills, qualifications, training, competency.
5. Enforces Accountability
Meaning: Individuals are held accountable for performing their internal control responsibilities.
Example:
A purchasing manager's performance evaluation includes compliance with procurement approval procedures.
CIA clue: Performance evaluation, responsibility, accountability.
Risk Assessment — Principles 6–9
6. Specifies Suitable Objectives
Meaning: Management establishes clear objectives that allow risks to be identified and assessed.
Example:
A company establishes an objective to maintain 99.9% system availability for its online banking platform.
CIA clue: Objectives must be clear and measurable.
7. Identifies and Analyzes Risk
Meaning: The organization identifies risks that could prevent achievement of its objectives and evaluates their significance.
Example:
A company identifies a potential supplier failure as a risk to its production objective and evaluates its likelihood and potential impact.
CIA clue: Identify → analyze → likelihood/impact.
8. Assesses Fraud Risk
Meaning: The organization considers the possibility of fraud when assessing risks.
Example:
Management identifies the risk that an employee could create a fictitious vendor and make payments to the vendor.
CIA clue: Fraud schemes, incentives, opportunities, management override.
9. Identifies and Analyzes Significant Change
Meaning: The organization assesses changes that could significantly affect internal control.
Example:
After acquiring another company, management reassesses its controls because employees, systems, processes, and reporting structures have changed.
CIA clue: Acquisition, new technology, new regulations, restructuring, new business model.
Control Activities — Principles 10–12
10. Selects and Develops Control Activities
Meaning: Management selects appropriate controls to mitigate identified risks.
Example:
To reduce unauthorized payments, the company requires invoices to be approved before payment.
CIA clue: Authorization, approval, reconciliation, verification, segregation of duties.
11. Selects and Develops General Controls Over Technology
Meaning: The organization establishes general IT controls supporting the proper functioning of technology.
Example:
Only authorized IT administrators can modify the company's financial application, and all system changes require approval and testing.
CIA clue: Access controls, change management, backup, system security.
12. Deploys Through Policies and Procedures
Meaning: Control activities are implemented through policies that specify what should be done and procedures that explain how it should be done.
Example:
The company has a policy requiring monthly bank reconciliations and a procedure explaining who prepares, reviews, and approves the reconciliation.
CIA clue: Policy = what; procedure = how.
Information & Communication — Principles 13–15
13. Uses Relevant, Quality Information
Meaning: The organization obtains and uses reliable information needed to support internal control.
Example:
Management uses accurate, timely inventory reports to identify slow-moving and obsolete inventory.
CIA clue: Relevant + quality + timely + accurate information.
14. Communicates Internally
Meaning: Important control information is communicated throughout the organization.
Example:
Management informs employees about a new cybersecurity policy through training, email, and the company's internal portal.
CIA clue: Communication from management → employees and across departments.
15. Communicates Externally
Meaning: Relevant information is communicated to external parties when necessary.
Example:
The company communicates significant control deficiencies to its external auditor or regulatory authority when appropriate.
CIA clue: Customers, suppliers, regulators, external auditors, shareholders.
Monitoring Activities — Principles 16–17
16. Conducts Ongoing and/or Separate Evaluations
Meaning: The organization evaluates whether internal controls are present, functioning, and effective.
Example:
Internal audit periodically tests whether employees are following the company's procurement approval controls.
CIA clue: Ongoing monitoring + separate evaluations.
17. Evaluates and Communicates Deficiencies
Meaning: Control deficiencies are identified, evaluated, and communicated to those responsible for corrective action.
Example:
Internal audit discovers that purchase orders are frequently approved after purchases are made. The deficiency is reported to management, which develops a corrective action plan.
CIA clue: Deficiency → communicate → corrective action.
🔥 CIA Exam Memory Table
Principle | Short Keyword | Easy Example |
1 | Ethics | CEO follows code of conduct |
2 | Oversight | Audit committee reviews controls |
3 | Structure | Clear reporting lines |
4 | Competence | Employee training/certification |
5 | Accountability | Employee evaluated for control performance |
6 | Objectives | 99.9% system availability target |
7 | Risk | Supplier failure risk |
8 | Fraud | Fictitious vendor |
9 | Change | Acquisition/restructuring |
10 | Control Activities | Payment approval |
11 | Technology | IT access/change controls |
12 | Policies | Purchasing policy & procedure |
13 | Information | Accurate inventory report |
14 | Internal Communication | Cybersecurity training |
15 | External Communication | Regulatory reporting |
16 | Evaluation | Internal audit testing |
17 | Deficiencies | Report weakness & corrective action |
🧠Super-fast sequence for CIA Part 1
1–5: ETHICS → BOARD → STRUCTURE → COMPETENCE → ACCOUNTABILITY
6–9: OBJECTIVES → RISK → FRAUD → CHANGE
10–12: CONTROL → TECHNOLOGY → POLICY
13–15: INFORMATION → INTERNAL → EXTERNAL
16–17: EVALUATE → DEFICIENCY
One important CIA exam distinction:
Principle 7 = risks generally
Principle 8 = fraud risks specifically
Principle 9 = significant changes
That distinction is frequently useful in scenario-based questions.
5 COBIT 2019 Governance System Principles with simple examples, especially useful for CIA Part 1 exam preparation.
COBIT 5 Governance Principles — With Examples
Important: If you mean COBIT 5 specifically, its five principles are different in wording from COBIT 2019. The list below is for COBIT 5.
1. Meeting Stakeholder Needs
Meaning:
The governance system should create value for stakeholders by balancing benefits, risk, and resources.
Example:
A bank's customers want secure and fast mobile banking. Management invests in cybersecurity and system availability while considering the cost and acceptable level of risk.
CIA exam clue:
Stakeholder needs → Benefits + Risk + Resources
2. Covering the Enterprise End-to-End
Meaning:
COBIT governance applies to the entire enterprise, not just the IT department.
It covers:
- IT and business processes
- Internal and external stakeholders
- Information and technology across the organization
Example:
A company's cybersecurity program covers not only the IT department but also HR, finance, procurement, operations, employees, suppliers, and third-party service providers.
CIA exam clue:
Enterprise-wide, not IT-only.
3. Applying a Single Integrated Framework
Meaning:
COBIT provides a framework that can integrate and align with other standards, frameworks, and regulations.
Example:
A company uses COBIT for IT governance while also using COSO for internal control and ISO 27001 for information security.
Rather than creating completely separate governance systems, the organization aligns them.
CIA exam clue:
COBIT + COSO + ISO + other frameworks → integrated approach.
4. Enabling a Holistic Approach
Meaning:
Effective governance requires consideration of multiple interconnected components, rather than focusing on technology alone.
COBIT 5 refers to seven enablers, including:
1. Principles, policies and frameworks
2. Processes
3. Organizational structures
4. Information
5. Services, infrastructure and applications
6. People, skills and competencies
7. Culture, ethics and behavior
Example:
A company implements a new ERP system. Successful governance requires not only the software but also trained employees, appropriate processes, organizational responsibilities, policies, accurate data, and an appropriate control culture.
CIA exam clue:
People + Process + Technology + Information + Culture + Structure + Policies
5. Separating Governance From Management
Meaning:
Governance and management have different responsibilities.
Governance:
Evaluates stakeholder needs, conditions, and options; directs through prioritization and decision-making; and monitors performance and compliance.
Management:
Plans, builds, runs, and monitors activities in accordance with the direction established by governance.
Example:
Board:
"We require customer data protection and want cybersecurity risk maintained within our approved risk appetite."
Management:
"We will implement access controls, encryption, employee training, monitoring, and incident-response procedures."
CIA exam clue:
Governance = Evaluate → Direct → Monitor
Management = Plan → Build → Run → Monitor
🧠Easy Memory Formula
S-E-I-H-G
S — Stakeholder Needs
E — Enterprise End-to-End
I — Integrated Framework
H — Holistic Approach
G — Governance ≠ Management
Quick Revision Table
COBIT 5 Principle | Remember | Example |
1 | Stakeholder Needs | Balance benefits, risk & resources |
2 | Enterprise End-to-End | IT governance across entire organization |
3 | Integrated Framework | COBIT + COSO + ISO |
4 | Holistic Approach | People + process + technology |
5 | Governance ≠ Management | Board directs; management executes |
⚠️ CIA Exam Trap: COBIT 5 vs COBIT 2019
The first four principles are the same, but the fifth principle is worded differently:
- COBIT 5: Separating Governance From Management
- COBIT 2019: Separating Governance From Management — still retained as a governance-system principle.
So for CIA questions, always check whether the question specifically asks about COBIT 5 or COBIT 2019.
www.gmsisuccess.in