Case-based CIA Part 1 MCQs focused on Domain I: Ethics & Professionalism, aligned to the IIA Code of Ethics principles: Integrity, Objectivity, Confidentiality, and Competency
1. Integrity – Management Pressure
An internal auditor discovers that a department manager intentionally excluded several unfavorable transactions from a report. The manager asks the auditor not to mention the issue because it could affect the department's performance evaluation.
What should the internal auditor NOT do?
A. Ignore the omission because management has accepted responsibility
B. Discuss the matter with the appropriate audit supervisor
C. Document the facts and evidence supporting the finding
D. Report the matter through the appropriate escalation process
Answer: A
2. Objectivity – Personal Relationship
An internal auditor is assigned to audit a department headed by her close friend. She believes she can remain impartial.
Which action is MOST appropriate?
A. Accept the assignment without disclosure
B. Ask the friend to sign a conflict-of-interest statement
C. Disclose the relationship to the appropriate audit authority
D. Perform the audit but avoid interviewing the friend
Answer: C
3. Confidentiality – Information Sharing
During an audit, an auditor obtains confidential information concerning a pending acquisition. A colleague from another department asks about the acquisition.
What should the auditor NOT do?
A. Discuss the information informally with the colleague
B. Protect the information from unauthorized disclosure
C. Follow organizational confidentiality requirements
D. Share information only with authorized persons who have a legitimate need
Answer: A
4. Competency – Technical Knowledge
An auditor is assigned an IT security audit but has limited knowledge of cybersecurity.
Which action is LEAST appropriate?
A. Obtain appropriate assistance or supervision
B. Inform the chief audit executive of the limitation
C. Perform the audit independently despite lacking necessary competence
D. Acquire the required knowledge before performing significant audit procedures
Answer: C
5. Integrity – Altering Evidence
A senior manager asks an internal auditor to remove an unfavorable finding from the working papers.
What should the auditor NOT do?
A. Delete the finding merely to satisfy management
B. Retain sufficient evidence supporting the conclusion
C. Discuss the disagreement with the audit supervisor
D. Escalate the matter if inappropriate pressure continues
Answer: A
6. Objectivity – Financial Interest
An internal auditor owns shares in a company that is a major supplier of the organization.
The auditor is assigned to audit procurement.
What is the BEST action?
A. Sell the shares after completing the audit
B. Continue because the investment is small
C. Disclose the potential conflict and seek reassignment if necessary
D. Avoid auditing only the transactions involving that supplie
Answer: C
7. Confidentiality – Former Employee
A former employee asks an internal auditor to provide copies of confidential audit reports that were prepared while the employee worked for the organization.
What should the auditor NOT do?
A. Provide the reports because the employee previously had access
B. Verify whether disclosure is authorized
C. Follow organizational information-security policies
D. Refuse unauthorized disclosure
Answer: A
8. Competency – New Regulation
A new regulation significantly changes the compliance requirements relevant to an audit.
Which action is LEAST appropriate?
A. Update audit procedures based on the new requirements
B. Obtain professional guidance if necessary
C. Continue using outdated procedures without evaluation
D. Develop sufficient knowledge of the new regulation
Answer: C
9. Integrity – Management Representation
Management verbally assures the auditor that all significant liabilities have been disclosed. However, the auditor finds evidence suggesting otherwise.
What should the auditor NOT do?
A. Accept management's verbal statement without further investigation
B. Obtain sufficient appropriate evidence
C. Investigate contradictory information
D. Communicate significant discrepancies appropriately
Answer: A
10. Objectivity – Previous Responsibility
An auditor recently transferred from the purchasing department to internal audit. She is assigned to audit purchasing activities she managed six months earlier.
Which action is MOST appropriate?
A. Audit the area because she knows it well
B. Audit only routine transactions
C. Consider whether her prior responsibility creates an impairment to objectivity
D. Ask purchasing management whether they are comfortable with the assignment
Answer: C
11. Confidentiality – Social Media
An auditor discovers a significant control weakness and posts a vague comment about the organization's poor controls on social media.
Which principle is MOST directly violated?
A. Integrity
B. Objectivity
C. Confidentiality
D. Competency
Answer: C
12. Competency – Specialized Audit
An internal audit team lacks expertise in derivatives valuation.
Management nevertheless expects the team to complete the audit without outside assistance.
What should the team NOT do?
A. Pretend to possess the required expertise
B. Communicate the competency limitation
C. Obtain qualified assistance
D. Adjust the audit scope appropriately
Answer: A
13. Integrity – Undue Influence
A senior executive tells an auditor, "If you report this finding, your promotion may be affected."
What should the auditor NOT do?
A. Suppress the finding because of the threat
B. Maintain professional integrity
C. Document the attempted influence
D. Escalate inappropriate interference
Answer: A
14. Objectivity – Gifts
An auditee offers an expensive gift to an internal auditor immediately before the auditor completes the engagement.
What should the auditor NOT do?
A. Accept the gift because it was offered voluntarily
B. Follow organizational policies concerning gifts
C. Consider whether acceptance creates an objectivity impairment
D. Report the offer when required
Answer: A
15. Confidentiality – Unauthorized Email
An auditor accidentally receives confidential payroll information belonging to another department.
What should the auditor NOT do?
A. Forward the information to friends for discussion
B. Protect the information
C. Notify the appropriate person if required
D. Delete or secure the information according to policy
Answer: A
16. Competency – Continuing Education
An internal auditor has not updated knowledge of internal auditing standards for several years.
Which action is LEAST appropriate?
A. Participate in continuing professional development
B. Review current professional guidance
C. Continue relying exclusively on outdated knowledge
D. Identify areas requiring professional development
Answer: C
17. Integrity – Audit Conclusion
Evidence indicates that controls are ineffective, but management pressures the auditor to conclude that controls are effective.
What should the auditor NOT do?
A. Change the conclusion merely to avoid conflict
B. Base conclusions on sufficient evidence
C. Discuss contradictory evidence with management
D. Escalate unresolved disagreements appropriately
Answer: A
18. Objectivity – Performance Evaluation
An auditor is auditing a process for which her spouse is the responsible manager.
Which action is MOST appropriate?
A. Proceed because the auditor believes she is objective
B. Ask the spouse to avoid participating
C. Disclose the relationship and assess the potential impairment
D. Perform the audit secretly
Answer: C
19. Confidentiality – Audit Committee
An auditor discovers information that may be relevant to the audit committee.
What should the auditor NOT do?
A. Automatically disclose every confidential detail to all committee members
B. Follow appropriate reporting protocols
C. Share relevant information with authorized recipients
D. Consider the organization's confidentiality requirements
Answer: A
20. Competency – Audit Evidence
An auditor cannot understand a highly technical engineering report that is critical to an audit conclusion.
What should the auditor NOT do?
A. Interpret the technical evidence without sufficient knowledge
B. Seek qualified assistance
C. Obtain appropriate expertise
D. Consider whether additional procedures are required
Answer: A
21. Integrity – Fraud Discovery
An auditor discovers evidence suggesting fraudulent payments by a senior executive.
The executive asks the auditor to "handle the matter quietly."
What should the auditor NOT do?
A. Suppress the evidence
B. Preserve relevant evidence
C. Follow fraud escalation procedures
D. Communicate with appropriate authorized parties
Answer: A
22. Objectivity – Consulting Engagement
An auditor previously designed a control and is now asked to evaluate whether that same control is effective.
What is the primary concern?
A. Confidentiality
B. Competency
C. Objectivity
D. Integrity
Answer: C
23. Confidentiality – Benchmarking
An auditor wants to share detailed internal control weaknesses with another organization for benchmarking.
What should the auditor NOT do?
A. Share confidential details without authorization
B. Obtain appropriate approval
C. Remove identifying information when appropriate
D. Follow confidentiality requirements
Answer: A
24. Competency – Data Analytics
An auditor uses sophisticated analytical software but does not understand the underlying assumptions or limitations.
Which action is LEAST appropriate?
A. Validate the analytical methodology
B. Obtain technical assistance
C. Rely entirely on software output without understanding it
D. Evaluate whether the results are appropriate
Answer: C
25. Integrity – Documentation
An auditor discovers that evidence contradicts the preliminary audit conclusion.
What should the auditor NOT do?
A. Remove contradictory evidence from the working papers
B. Reconsider the conclusion
C. Perform additional procedures if necessary
D. Document the evidence objectively
Answer: A
26. Objectivity – Bonus Incentive
An auditor's annual bonus depends partly on management satisfaction with audit results.
What should the auditor NOT do?
A. Modify findings to improve the bonus outcome
B. Disclose significant threats to objectivity
C. Maintain independence from management influence
D. Follow appropriate conflict-management procedures
Answer: A
27. Confidentiality – Family Member
An auditor's family member works for a competitor and asks whether the organization is planning a major acquisition.
What should the auditor NOT do?
A. Provide information obtained during the audit
B. Refuse to disclose confidential information
C. Explain that professional confidentiality prevents disclosure
D. Protect information from unauthorized use
Answer: A
28. Competency – Language Barrier
An auditor cannot adequately understand documents written in a foreign language that are essential to the engagement.
What should the auditor NOT do?
A. Guess the meaning of important documents
B. Obtain translation assistance
C. Seek qualified personnel to assist
D. Modify procedures when appropriate
Answer: A
29. Integrity – Conflict With Management
Management disagrees with an audit finding but cannot provide evidence to contradict it.
What should the auditor NOT do?
A. Remove the finding solely because management disagrees
B. Consider valid evidence supplied by management
C. Maintain an evidence-based conclusion
D. Escalate unresolved significant matters
Answer: A
30. Objectivity – Rotation
An auditor has audited the same department for many consecutive years and has developed close relationships with management.
Which concern is MOST relevant?
A. Confidentiality
B. Competency
C. Objectivity
D. Data security
Answer: C
31. Confidentiality – Personal Benefit
An auditor discovers confidential information that could be used to make a profitable personal investment.
What should the auditor NOT do?
A. Use confidential audit information for personal gain
B. Protect the information
C. Avoid unauthorized disclosure or use
D. Follow applicable professional requirements
Answer: A
32. Competency – Insufficient Experience
A newly appointed auditor is asked to lead a complex cybersecurity investigation.
Which action is LEAST appropriate?
A. Obtain appropriate supervisionB. Seek specialized assistanceC. Lead the investigation alone despite insufficient experienceD. Communicate competency limitations
Answer: C
33. Integrity – False Assurance
An executive asks the auditor to issue a statement saying, "No significant control weaknesses exist," even though the audit is incomplete.
What should the auditor NOT do?
A. Provide the assurance statement without sufficient evidence
B. Explain that the engagement is incomplete
C. Communicate only supported conclusions
D. Complete appropriate procedures before reaching a conclusion
Answer: A
34. Objectivity – Audit Assignment
An auditor is assigned to review a project for which he previously approved major expenditures.
What should happen BEFORE accepting the assignment?
A. Ignore the prior involvement
B. Ask the project manager for permission
C. Evaluate the potential impairment to objectivity
D. Assume objectivity because the auditor changed departments
Answer: C
35. Confidentiality – Audit Committee Meeting
During an audit committee meeting, an auditor hears confidential information unrelated to the auditor's engagement.
What should the auditor NOT do?
A. Share the information with coworkers who are curious
B. Protect the information
C. Limit disclosure to authorized purposes
D. Follow confidentiality requirements
Answer: A
36. Competency – Professional Judgment
An auditor encounters an unusual accounting transaction outside her normal experience.
What should the auditor NOT do?
A. Make an unsupported conclusion based on assumptions
B. Research the issue
C. Consult an appropriate subject-matter expert
D. Perform additional procedures where appropriate
Answer: A
37. Integrity – Misleading Presentation
Management asks the auditor to describe a major control deficiency as a "minor improvement opportunity."
What should the auditor NOT do?
A. Use misleading language merely to satisfy management
B. Present the issue accurately
C. Consider the significance of the deficiency
D. Communicate the matter objectively
Answer: A
38. Objectivity – Incentive From Auditee
An auditee offers the auditor a performance bonus if the audit report contains no major findings.
What should the auditor NOT do?
A. Accept the incentive and continue the engagement
B. Report the offer appropriately
C. Consider the threat to objectivity
D. Decline inappropriate incentives
Answer: A
39. Confidentiality – External Request
A regulatory authority requests confidential internal audit records.
What should the auditor NOT do?
A. Automatically provide all records without verifying authority or requirements
B. Determine whether disclosure is legally required or authorized
C. Consult appropriate legal or organizational personnel when necessary
D. Disclose only information permitted or required
Answer: A
40. Competency – Emerging Technology
An organization implements artificial intelligence in its financial reporting process. The auditor has no knowledge of AI-related risks.
Which action is LEAST appropriate?
A. Develop relevant knowledge
B. Obtain specialized assistance
C. Ignore AI-related risks because they are outside traditional auditing
D. Modify audit procedures to address relevant risks
Answer: C
41. Integrity – Pressure to Meet Deadline
An auditor has insufficient evidence but management wants the report issued immediately.
What should the auditor NOT do?
A. Issue the conclusion despite insufficient evidence
B. Communicate the limitation
C. Obtain additional evidence where necessary
D. Discuss the impact on the audit conclusion
Answer: A
42. Objectivity – Personal Bias
An auditor strongly believes that a particular department is poorly managed before beginning the audit.
What should the auditor NOT do?
A. Allow the preconceived belief to determine audit conclusions
B. Evaluate evidence objectively
C. Consider contradictory evidence
D. Maintain professional skepticism
Answer: A
43. Confidentiality – Unauthorized Database Access
An auditor has access to sensitive employee information but does not need it for the current engagement.
What should the auditor NOT do?
A. Browse the information out of curiosity
B. Access information only for authorized purposes
C. Follow access-control requirements
D. Protect sensitive information
Answer: A
44. Competency – Outsourcing
The internal audit team lacks specialized tax expertise needed for an engagement.
Which action is MOST appropriate?
A. Complete the engagement without considering the limitation
B. Ignore the tax-related risks
C. Obtain qualified external expertise when appropriate
D. Exclude all tax issues without communicating the limitation
Answer: C
45. Integrity – Personal Reputation
An auditor discovers a major weakness that could make the auditor's department appear ineffective.
What should the auditor NOT do?
A. Conceal the weakness to protect the reputation of the audit department
B. Report the weakness accurately
C. Maintain professional integrity
D. Base conclusions on evidence
Answer: A
46. Objectivity – Consulting Advice
An internal auditor provides consulting advice on a new control system and is later asked to provide assurance over the same system.
What should the auditor NOT do?
A. Automatically assume there is no objectivity concern
B. Assess the nature of the previous consulting role
C. Consider safeguards against self-review threats
D. Disclose potential impairment when appropriate
Answer: A
47. Confidentiality – Informal Conversation
Two auditors discuss a sensitive investigation in a crowded cafeteria where unauthorized employees can overhear them.
Which principle is primarily at risk?
A. Integrity
B. Objectivity
C. Confidentiality
D. Competency
Answer: C
48. Competency – Reliance on Experience
An experienced auditor believes that formal training is unnecessary because "I've been auditing for 20 years."
Which statement is LEAST appropriate?
A. Experience can replace all continuing professional developmentB. Professional competence should be maintainedC. Auditors should keep their knowledge currentD. Emerging risks may require new skills
Answer: A
49. Integrity & Objectivity – Senior Executive
An auditor discovers that the CEO has bypassed an important control. The CEO argues that the action was necessary for business reasons.
What should the auditor NOT do?
A. Ignore the violation because the CEO is senior managementB. Evaluate whether the bypass was authorized and justifiedC. Document relevant evidenceD. Communicate significant control violations appropriately
Answer: A
50. Integrated Ethics Case – NEITHER Type
An internal auditor receives a confidential document showing a significant compliance violation. The auditor has a personal relationship with the employee responsible for the violation and lacks specialized knowledge needed to evaluate the technical aspects.
Which action is NEITHER appropriate nor consistent with professional ethics?
A. Disclose the personal relationship and obtain appropriate assistanceB. Protect the confidential information and evaluate the evidence objectivelyC. Seek competent assistance while maintaining confidentialityD. Ignore the violation because investigating it could damage the employee's career
Answer d
Pl read….
Exam-Trap Pattern to Remember
Integrity → Tell the truth, don't conceal, manipulate, suppress, or misrepresent.
Objectivity → Avoid conflicts, bias, self-review, gifts, incentives, relationships, and undue influence.
Confidentiality → Don't disclose, misuse, or access information without authorization or legitimate purpose.
Competency → Don't perform work without the necessary knowledge, skills, experience, or appropriate assistance.
Negative-question trigger words:
NOT • LEAST appropriate • EXCEPT • SHOULD NOT • NEITHER • INAPPROPRIATE • WOULD VIOLATE
case-based CIA Part 1 multiple-choice questions focuses on Domain I: Ethics and Professionalism, aligned with the core IIA Code of Ethics principles of Integrity, Objectivity, Confidentiality, and Competency. True to your constraints, most questions utilize negative, tricky, or "LEAST appropriate" / "NOT" / "NEITHER" framing
Question 1
An internal auditor discovers that a minor financial misstatement in a branch report resulted from an honest, unintentional oversight by a close personal friend. The auditor corrects the working papers quietly without reporting the error upward or discussing it with the friend, believing no malicious intent existed. Which IIA Code of Ethics rule regarding Integrity has the auditor LEAST appropriately observed?
- A. The requirement to perform work with diligence and responsibility rather than concealing mistakes.
- B. The rule permitting personal discretion to alter working papers if no loss occurs.
- C. The obligation to make full and proper disclosure expected by the profession when discrepancies are found.
- D. The duty to maintain honesty and transparency in documentation rather than managing outcomes privately.
Question 2
An internal auditor receives a high-end electronic gadget as a token of appreciation from an auditee department manager immediately after completing a complex operational review. The auditor concludes that the gift is modest enough not to sway their professional judgment and keeps it without reporting the receipt. Which statement NOT describing a violation of Objectivity applies here?
- A. Accepting items that may be presumed to impair professional judgment violates the rules of conduct.C. The auditor failed to recognize that even the appearance of a compromised assessment breaches objectivity safeguards.D. The auditor neglected the absolute rule prohibiting acceptance of anything that creates a presumed impairment.
Question 3
An internal auditor is asked by legal counsel to provide working papers containing sensitive proprietary data about a competitor during an active external lawsuit involving the organization. The auditor refuses to provide any information, citing strict adherence to the principle of Confidentiality without checking for legal obligations. Which evaluation of this action is correct?
- A. The auditor acted properly because client data can never be shared under any circumstance.C. The refusal is incorrect because internal auditors are expected to make disclosures when there is a legal or professional obligation to do so.D. The auditor misapplied confidentiality by failing to recognize statutory exceptions overriding general nondisclosure rules.
Question 4
A newly appointed internal auditor is assigned to lead an advanced IT cybersecurity audit despite having zero background, training, or practical experience in network security frameworks. To avoid looking incompetent to management, the auditor completes the review using generic checklist templates found online. Which principle from the IIA Code of Ethics is NEITHER addressed nor fulfilled by this approach?
- A. Competency, because performing work without requisite technical skills violates core professional performance rules.C. Competency, because the auditor failed to apply the specific knowledge and expertise required for the technical engagement.D. Competency, because the auditor engaged in services exceeding their actual knowledge, skills, and experience
Question 5
An internal auditor identifies a major fraudulent scheme perpetrated by the corporate controller. Fearing retaliation from the executive team, the auditor decides NOT to disclose material facts known to them that directly distort the financial statements under review. Which fundamental tenet of Integrity or Objectivity is violated?
- A. The rule requiring internal auditors to disclose all material facts known to them that, if omitted, distort reporting.C. The requirement to exercise honesty and responsibility in reporting actual known wrongdoing.D. The mandate to avoid omissions that compromise truthful communication of audit findings.
Question 6
An internal auditor utilizes confidential data obtained during an operational audit to purchase shares in a publicly traded supplier before the supplier's contract renewal is publicly announced. The auditor rationalizes that the information was gathered legally during routine fieldwork. Which core rule under Confidentiality is breached?
· A. The duty to protect information ownership rather than weaponizing it for self-enrichment C. The restriction against exploiting inside organizational knowledge for outside financial advantage.D. The explicit prohibition against using acquired information for personal gain
ANSWER D
Question 7
An internal auditor is assigned to review a division managed by their sibling. To maintain the appearance of independence, the auditor lets another staff member draft the report while they secretly perform all the substantive analytical testing and sign off on the conclusions. Which statement LEAST supports compliance with Objectivity?
- A. Participation in any activity or relationship that is presumed to impair unbiased assessment remains a direct violation.C. Delegating the signature line does not eliminate the severe impairment caused by auditing a close family member.
- D. The underlying family relationship heavily taints the entire assessment process regardless of minor review workarounds
ANSWER C
Question 8
An internal auditor agrees to omit a significant unfavorable finding from the final audit report after the operating manager threatens to make the auditor's work environment miserable. The auditor documents the omission in a private personal notebook. Which principle is NOT compromised by this behavior?
- A. Confidentiality, because the auditor kept the notes private in a personal notebook.
- C. Integrity, because the auditor yielded to pressure and failed to act with professional courage.
- D. Objectivity, because the assessment was unduly influenced by external intimidation
ANSWER A
Question 9
An internal auditor possesses general financial auditing credentials but is asked to evaluate a highly specialized chemical manufacturing process. Instead of declining or seeking expert assistance, the auditor pretends to understand the chemistry and signs off on plant safety controls. Which statement correctly identifies the primary ethical failure?
- A. The auditor failed the basic competency requirement to undertake only work matching their actual skillset.
- C. The auditor breached competency standards by misrepresenting their ability to evaluate specialized operations.
- D. The auditor violated the competency rule by engaging in services outside their verified knowledge and experience.
ANSWER D
Question 10
An internal auditor finds an isolated instance of expense account padding by a senior executive. The auditor decides to overlook the issue because the amount is below the established materiality threshold and does not affect the audit opinion. Which aspect of Integrity is LEAST violated or upheld properly here?
- A. Performing work with diligence and responsibility when minor discrepancies do not materially alter financial statements.
- C. Observing the spirit of professional diligence where immaterial omissions do not distort overall reporting integrity.
- D. Exercising balanced professional judgment regarding minor housekeeping anomalies versus systemic fraud.
ANSWER A
Question 11
An internal auditor overhears two executives discussing a confidential upcoming merger in the corporate cafeteria. The auditor casually mentions this rumor to a close friend outside the company during dinner, emphasizing that it is unverified. Why is this action a direct breach of Confidentiality?
- A. Internal auditors must be prudent in protecting information acquired in the course of duties regardless of how it was obtained.
- C. Disclosing unverified corporate intel outside official channels violates the stewardship of organization-owned facts.
- D. Careless casual transmission of internal discussions violates basic rules of information safekeeping.
- Correct Answer: A
Question 12
An internal auditor previously worked as the assistant treasurer of the corporate finance division. Exactly ten months after leaving that position, the auditor is assigned to lead an assurance engagement reviewing the treasury's cash management controls. Which evaluation highlights the status of Objectivity?
- A. Objectivity is presumed to be impaired because the auditor is reviewing an activity for which they had operational responsibility within the previous year.
- C. The one-year cooling-off requirement for prior operational responsibilities has been breached.
- D. Individual objectivity cannot be sustained when auditing recent former operational domains.
- Correct Answer: A
Question 13
An internal auditor wants to improve their technical proficiency in data analytics. They accept free commercial software licenses from an active audit software vendor being reviewed by the internal audit department. Which combination of IIA principles is NEITHER protected nor respected by this choice?
- A. Objectivity and Integrity, because vendor gifts compromise the appearance of independence.
- C. Objectivity and Competency, because seeking tools via unethical vendor favors compromises unbiased assessment.
- D. Objectivity and Integrity, because accepting anything from a vendor creates a presumed impairment to professional judgment
- Correct Answer: D
Question 14
An internal auditor discovers that management is intentionally bypassing environmental regulations to save operating costs. The auditor reports the violation to local regulatory authorities because the law explicitly mandates it, despite corporate threats. Which principle supports this disclosure?
- A.* Integrity, which requires observing the law and making disclosures expected by law and the profession.
- C. Integrity, which supersedes organizational loyalty when illegal activities occur.
- D. Objectivity and Integrity combined, upholding public interest disclosures.
- Correct Answer: A
Question 15
An internal auditor shares working papers with an external consultant without executing a formal non-disclosure agreement or securing authorization from the Chief Audit Executive (CAE), assuming the consultant is trustworthy. Which principle is violated?
- A. Confidentiality, by failing to respect ownership and control over data dissemination
- C. Confidentiality, due to disclosing information without appropriate authority
- D. Competency and Confidentiality, through sloppy administrative safeguarding of files.
- Correct Answer: C
Question 16
An internal auditor is asked to review the marketing department where their spouse serves as a high-level director. The auditor immediately discloses the potential impairment in writing to the CAE and declines the assignment before accepting any fieldwork. Which statement NOT representing an ethical breach applies?
- A. The auditor properly identified and disclosed the impairment, upholding objectivity requirements.
- C. Declining the engagement resolved the conflict of interest correctly.
- D. Transparent disclosure and refusal safeguarded functional objectivity.
- Correct Answer: A
Question 17
An internal auditor padding their resume claims certification credentials and advanced university degrees they do not possess to secure promotion within the internal audit activity. Which IIA Code principle is fundamentally shattered?
- A.* Integrity, because deliberate misrepresentation destroys trust and the basis for reliance on judgment.
- C. Competency and Integrity, by falsifying professional qualifications.
- D. Integrity, through engaging in acts discreditable to the profession.
- Correct Answer: A
Question 18
An internal auditor fails to update their knowledge regarding newly revised IIA global auditing standards and continues executing obsolete audit steps that miss mandatory statutory checks. Which principle is LEAST appropriately met?
- A. Competency, by performing work without up-to-date professional framework awareness.
- C. Competency, through neglecting ongoing professional development.
- D. Competency, because the auditor failed to maintain and apply contemporary knowledge required by professional standards
- Correct Answer: D
Question 19
An internal auditor identifies a severe cash handling deficiency. The auditee manager offers a lucrative consulting contract for the auditor's spouse if the finding is softened in the report. The auditor rejects the offer but says nothing about the bribe attempt to the CAE. Which rule of conduct under Objectivity did the auditor break?
- A.* Failing to disclose an attempted inducement that presumes impairment to judgment.
- C. Omitting material facts regarding undue pressure that distorts reporting integrity.
- D. Accepting or failing to report situations attempting to influence professional assessments.
- Correct Answer: A
Question 20
An internal auditor discusses specific audit findings in an elevator within a public hotel where external industry stakeholders are present, talking loudly about control gaps in their primary client company. Which tenet of Confidentiality is breached?
- A.* Being prudent in the use and protection of information acquired during duties.
- C. Respecting the stewardship of internal corporate data in public spaces.
- D. Preventing inadvertent leakage of proprietary operational facts.
- Correct Answer: A
Question 21
An internal auditor is assigned to evaluate a digital asset trading platform but lacks blockchain auditing skills. The CAE pairs this auditor with an external specialist who possesses the exact required competency. Which evaluation applies to the primary auditor's compliance?
- A. Collective competency within the team satisfies professional service requirements.
- C. . The auditor acted ethically by engaging only with appropriate collective competency and supervision.
- D. Partnering with a skilled specialist fulfills the knowledge requirement safely.
- Correct Answer: C
Question 22
An internal auditor discovers that a senior vice president is embezzling funds. The auditor alters audit evidence logs to cover up the VP's involvement because the VP is a major donor to the auditor's favorite charity. Which principle is NOT directly violated here?
- A.* Confidentiality, because charity funding is a public matter.
- C. Integrity, because the auditor knowingly participated in concealing illegal acts.
- D. Objectivity, because the assessment was compromised by personal outside affiliations.
- Correct Answer: A
Question 23
An internal auditor uses corporate proprietary analytical scripts developed on company time to launch a private, competing side-business providing audit analytics to local firms. Which IIA Code principle is violated?
- A. Confidentiality, by converting internal proprietary methods into personal assets.
- C. Integrity, through acts contrary to legitimate organizational objectives.
- D. Integrity and Confidentiality, by using organizational resources and knowledge for unauthorized personal gain
- Correct Answer: D
Question 24
An internal auditor is pressured by an audit committee member to drop a line of inquiry into a subsidiary. The auditor maintains an unbiased mental attitude, completes the testing objectively, and reports the findings accurately despite the pressure. Which principle is exemplarily demonstrated?
- A.* Objectivity, by making a balanced assessment without undue influence from others.
- C. Integrity and Objectivity, through courage to report factual findings under pressure.
- D. Objectivity, by resisting external intimidation in professional judgments.
- Correct Answer: A
Question 25
An internal auditor stores working papers on an unencrypted personal laptop connected to public Wi-Fi without password protection. A data breach occurs, leaking customer records. Which core rule under Confidentiality or Competency is neglected?
- A Failing to apply basic administrative and technical safeguards for data security.
- C. . Being prudent in the protection and custody of information acquired during duties.
- D. Neglecting professional prudence regarding data asset ownership protection.
- Correct Answer: C
Question 26
An internal auditor is assigned to a consulting engagement to design a new inventory control system for a plant they audited two years ago. The auditor has no operational responsibility in that plant. Is objectivity impaired under the IIA framework?
- A.* No, provided the nature of the consulting does not impair objectivity and individual objectivity is managed.
- C. No, because prior assurance on an area does not block future consulting if timed properly.
- D. No, since the prior audit concluded more than a year ago and operational control was never held by the auditor.
- Correct Answer: A
Question 27
An internal auditor intentionally plagiarizes an entire methodology report from an external audit firm and presents it as their own original work to senior management. Which rule under Integrity is violated?
- A.* Engaging in acts that are discreditable to the profession of internal auditing.
- C. Failing to perform work with true professional honesty and diligence.
- D. Violating foundational professional behavioral expectations.
- Correct Answer: A
Question 28
An internal auditor is asked to review payroll records. The auditor notices their own salary was erroneously calculated too high by payroll, but says nothing, pocketing the excess. Which primary ethical principle is compromised?
- A.* Integrity, because the auditor failed to perform work with honesty and responsibility.
- C. Integrity, by knowingly taking advantage of an internal accounting error.
- D. Objectivity and Integrity, through dishonest personal financial enrichment.
- Correct Answer: A
Question 29
An internal auditor speaks at an industry conference and outlines specific operational vulnerabilities of their employer without masking company identifiers or obtaining clearance. Which rule is violated?
- A.* Confidentiality rule against disclosing operational data without appropriate authority.
- C. Confidentiality rule requiring prudence in the external release of proprietary facts.
- D. Integrity and Confidentiality, by damaging organizational interests publicly.
- Correct Answer: A
Question 30
An internal auditor undertakes an engagement requiring statistical sampling expertise. They take a rapid crash course, apply formulas incorrectly, and issue an invalid high-risk conclusion that damages the auditee's reputation. Which principle is LEAST effectively maintained?
- A.* Competency, because the auditor failed to apply adequate skills and knowledge needed for complex analysis.
- C. Competency, by executing advanced tasks without verified mastery.
- D. Competency, through inadequate preparation for specialized evaluation techniques.
- Correct Answer: A
Question 31
An internal auditor discovers that an executive assistant made a minor typographical error in a public corporate filing. The auditor corrects it and alerts the compliance officer transparently. Which IIA principle is upheld?
- A.* Integrity, demonstrating diligence, honesty, and responsibility in compliance tracking.
- C. Integrity, supporting ethical organizational disclosure standards.
- D. Integrity, maintaining baseline professional transparency.
- Correct Answer: A
Question 32
An internal auditor accepts free tickets to a premier sporting event from a software supplier whose system is currently under evaluation by the internal audit team. The auditor does not disclose this to anyone. Which statement NOT identifying an infraction applies?
- A.* The receipt of such entertainment is acceptable if it does not exceed local market pricing values.* (False premise/violates rule) -> Wait, let's make sure answer A is correct if it states the violation: Accepting anything from a vendor impairs professional judgment. Let's re-align text: A. Accepting the tickets violates the rule against accepting things that presume impairment to judgment.
- Correct Answer: A
Question 33
An internal auditor is subpoenaed by a court of law to reveal confidential client data regarding a money-laundering investigation. The auditor complies fully with the court order. Which evaluation applies?
- A.* The auditor acted ethically because legal obligations override general confidentiality rules.
- C. Compliance with a judicial subpoena satisfies professional disclosure exceptions.
- D. The action respects the legal boundary of the confidentiality principle.
- Correct Answer: A
Question 34
An internal auditor notices a colleague struggling with basic software tools and offers to mentor them to build mutual competency within the department. Which principle does this behavior support?
- A.* Competency, by contributing to the continuous development and maintenance of professional skills.
- C. Competency and professional support within the internal audit team.
- D. Competency enhancement across the audit activity.
- Correct Answer: A
Question 35
An internal auditor uses password-protected company databases to look up personal home addresses and contact numbers of former romantic partners out of personal curiosity. Which core IIA rule is breached?
- A.* Confidentiality and Integrity, by misusing access to company data for non-business personal reasons.
- C. Confidentiality, by failing to restrict data use to legitimate professional duties.
- D. Integrity, through discreditable use of organizational database privileges.
- Correct Answer: A
Question 36
An internal auditor has a minor investment in a diversified mutual fund that happens to hold less than 0.1% shares of an auditee corporation. Does this mutual fund holding impair the auditor's objectivity?
- A.* No, because de minimis indirect holdings do not constitute a material conflict or undue influence.
- C. No, immaterial indirect mutual fund exposure does not impair individual objectivity.
- D. No, remote indirect interests do not create a presumed impairment to judgment.
- Correct Answer: A
Question 37
An internal auditor actively falsifies time-tracking sheets to log hours not worked on an engagement. Which core pillar of professional behavior is violated?
- A.* Integrity, because the auditor failed to perform work with honesty and diligence.
- C. Integrity, through deliberate misrepresentation of time and responsibility.
- D. Integrity, committing an act discreditable to the profession.
- Correct Answer: A
Question 38
An internal auditor keeps confidential work documents locked in a secure physical filing cabinet and destroys draft notes using a cross-cut shredder at the engagement's close. Which ethical principle is properly illustrated?
- A.* Confidentiality, through prudent physical protection of acquired information.
- C. Confidentiality, practicing proper document stewardship.
- D. Confidentiality and due professional care in document lifecycle management.
- Correct Answer: A
Question 39
An internal auditor is asked to review a specialized medical device manufacturing protocol. The auditor brings in a qualified medical expert, supervises the testing, and relies on the expert's technical conclusions. Which assessment of competency is correct?
- A.* The auditor satisfied competency rules by ensuring collective expertise covered the engagement needs.
- C. Utilizing verified specialists complies with resource and competency standards.
- D. Proper supervision of technical experts fulfills individual responsibility requirements.
- Correct Answer: A
Question 40
An internal auditor discovers a major compliance failure and agrees to let the auditee bury the finding in exchange for a promotion inside that operating division. The auditor accepts the promotion. Which combination of IIA principles is violated?
- A.* Integrity and Objectivity, through corrupt career trading and compromised reporting.
- C. Integrity and Objectivity, by yielding to self-interest and suppressing material facts.
- D. Integrity, breaching trust and engaging in acts discreditable to the profession.
- Correct Answer: A
Question 41
An internal auditor shares encrypted working papers via secure corporate channels with an authorized regulatory inspector during a mandated audit. Which principle governs this secure transmission?
- A.* Confidentiality, allowing authorized disclosures when professional obligations require.
- C. Confidentiality and Integrity, respecting legal oversight boundaries.
- D. Confidentiality, honoring regulatory information requests properly.
- Correct Answer: A
Question 42
An internal auditor realizes they made a calculation mistake in a published audit report. Instead of hiding it, they immediately issue a formal correction memo to management and the audit committee. Which value is displayed?
- A.* Integrity, demonstrating professional responsibility, honesty, and transparency.
- C. Integrity, correcting disclosures to ensure reporting accuracy.
- D. Integrity, showing the courage to address past technical errors openly.
- Correct Answer: A
Question 43
An internal auditor accepts a secondary evening teaching position at a local public university teaching introductory accounting. Does this outside employment violate IIA objectivity standards?
- A.* No, provided it does not conflict with the legitimate interests or time commitments of the organization.
- C. No, academic teaching of general accounting does not create a conflict of interest.
- D. No, standard educational activities do not impair professional judgment or objectivity.
- Correct Answer: A
Question 44
An internal auditor skips mandatory annual continuing professional education (CPE) hours, claiming they already know enough from past experience. Which IIA Code principle is LEAST fulfilled?
- A.* Competency, because auditors must continuously develop, maintain, and update necessary skills.
- C. Competency, by refusing ongoing professional learning requirements.
- D. Competency, neglecting the obligation to stay current with evolving practices.
- Correct Answer: A
Question 45
An internal auditor finds an isolated petty cash discrepancy of $5. Fearing negative ratings, they spend 40 hours investigating it, ignoring high-risk multi-million dollar contracts. Which aspect of professional practice is mismanaged?
- A.* Diligence and responsibility under integrity/professional care, misallocating professional priorities.
- C. Competency and diligence in risk-prioritized resource allocation.
- D. Responsible professional judgment regarding material risk thresholds.
- Correct Answer: A
Question 46
An internal auditor accesses confidential payroll files of colleagues to gossip about their salary brackets with other staff members during lunch breaks. Which rule of conduct under Confidentiality is violated?
- A.* Violating the prudent use of information and disclosing internal data without authorization.
- C. Using acquired internal facts in a manner detrimental to ethical workplace objectives.
- D. Failing to protect employee information ownership and privacy.
- Correct Answer: A
Question 47
An internal auditor is offered a seat on the board of a non-profit community charity that has no business transactions or relationship with the auditor's corporate employer. Is objectivity compromised?
- A.* No, because participation in unrelated non-profit entities creates no operational conflict of interest.
- C. No, external civic activities without corporate overlap do not impair judgment.
- D. No, there is no presumed conflict with the interests of the employing organization.
- Correct Answer: A
Question 48
An internal auditor signs an attestation report confirming inventory counts were physically verified by them, even though they skipped the warehouse visit and copied numbers from a manager's sheet. Which principle is violated?
- A.* Integrity, because the auditor failed to perform work with honesty and professional diligence.
- C. Integrity and Objectivity, through falsified field verification claims.
- D. Integrity, engaging in discreditable professional reporting behavior.
- Correct Answer: A
Question 49
An internal auditor deletes critical negative audit evidence files from the server before an internal quality peer review to prevent the review team from spotting sloppy fieldwork. Which IIA rule is broken?
- A.* Integrity, because destroying working papers violates diligence, responsibility, and honesty rules.
- C. Integrity, engaging in deliberate concealment of audit shortcomings.
- D. Integrity and Competency, through obstruction of quality assessment standards.
- Correct Answer: A
Question 50
An internal auditor performs a specialized data migration review after undertaking rigorous training, securing proper software tools, and validating their methodology against current standards. Which IIA Code principle is fully satisfied?
- A.* Competency, by applying verified knowledge, skills, and experience to internal audit services.
- C. Competency and due professional care in specialized engagement execution.
- D. Competency, matching skillsets precisely to engagement scope.
- Correct Answer: A