Showing posts with label GMSiSuccess CIA Part 1 classroom/revision material. Show all posts
Showing posts with label GMSiSuccess CIA Part 1 classroom/revision material. Show all posts

Friday, October 2, 2026

GMSiSuccess CIA Part 1 classroom/revision material



GMSiSuccess CIA Part 1 classroom/revision material

In  the 2025 CIA Part 1 syllabus has four exam domains, but the 2024 Global Internal Audit Standards themselves are organized into five domains and contain 15 principles. These are different things and should not be mixed.

Following notes compiled for Gmsisuccess students: Below is a rewritten, classroom-ready version with exam keywords, traps, corporate case examples, and decision logic.

CIA PART 1 – INTERNAL AUDIT FUNDAMENTALS

2025/2026 Exam-Oriented Revision Notes

With Corporate Case-Based Examples, Keywords & Exam Traps


1. CIA PART 1 – EXAM MAP

The current CIA Part 1 contains:

Domain Weight Approx. questions* Priority
I. Foundations of Internal Auditing 35% ~44 🔴 Very High
II. Ethics & Professionalism 20% ~25 🔴 High
III. Governance, Risk Management & Control 30% ~38 🔴 Very High
IV. Fraud Risks 15% ~19 🟠 High

*Approximation based on the percentage weighting; actual question allocation can vary.

The exam is 125 questions in 150 minutes, giving an average of approximately 72 seconds per question. The IIA confirms these current exam parameters.

OLD → NEW CIA PART 1

Previous syllabus Weight Current syllabus Weight
Foundations 15% Foundations 35%
Independence & Objectivity 15% Ethics & Professionalism 20%
Proficiency & Due Professional Care 18% Ethics & Professionalism included
QAIP 7% Distributed across revised syllabus —
Governance, Risk & Control 35% Governance, Risk & Control 30%
Fraud Risks 10% Fraud Risks 15%

The IIA's revised syllabus confirms this four-domain structure.

⭐ EXAM STRATEGY

Do not think:

"I am studying six old domains."

Think:

2025 CIA Part 1 = 4 domains + 2024 Global Internal Audit Standards + application of professional judgment.


DOMAIN I – FOUNDATIONS OF INTERNAL AUDITING

35% — THE MOST IMPORTANT DOMAIN

Here are *Complete Notes for DOMAIN I – FOUNDATIONS OF INTERNAL AUDITING (35%)* - New Syllabus 2025 - Made for Gmsisuccess Students.

This is the most important domain. If you master this, you clear 44 out of 125 questions.

DOMAIN I - 5 Chapters - 35% Weightage

CHAPTER 1: THE IIA's GLOBAL INTERNAL AUDIT STANDARDS [GIAS] - New 2025

This is the new IPPF. Old IPPF is finished from 9th Jan 2025.

*Hierarchy - Learn in Order:*
1.  *Purpose of Internal Auditing* - New addition in 2025
2.  *Ethics & Professionalism* - Code of Ethics + Core Principles
3.  *Standards* - 5 Domains, 15 Principles, 52 Standards
4.  *Topical Requirements* - Mandatory for specific topics (e.g., Cybersecurity)
5.  *Global Guidance* - Recommended, not mandatory.

> *Exam Trap:* Topical Requirements are MANDATORY if applicable. Global Guidance is only recommended.

*Purpose of Internal Auditing - New Definition:*
"Internal auditing strengthens the organization's ability to create, protect, and sustain value by providing the board and management with independent, risk-based, and objective assurance, advice, insight, and foresight."

*Keywords:* Create, Protect, Sustain Value + Assurance, Advice, Insight, Foresight.

CHAPTER 2: MANDATORY ELEMENTS - 10 Core Principles

These 10 are non-negotiable. Any answer in exam that violates these is WRONG.

1.  Demonstrates Integrity
2.  Demonstrates Competence and Due Professional Care
3.  Is Objective and Free from Undue Influence
4.  Aligns with Strategies, Objectives, Risks of Organization
5.  Is Positioned Appropriately and Adequately Resourced
6.  Demonstrates Quality and Continuous Improvement
7.  Communicates Effectively
8.  Provides Risk-Based Assurance
9.  Is Insightful, Proactive, Future-Focused
10. Provides Organizational Value

*Memory Trick for students:* *I C O A P Q C R I V* - "I COAP QC RIV"

CHAPTER 3: INTERNAL AUDIT MANDATE & CHARTER - Most Tested Topic

*Mandate vs Charter - Don't Confuse:*
- *Mandate = Authority given by Board* to Internal Audit to do its work. It's in laws, regulations, board minutes.
- *Charter = Document that explains* Purpose, Authority, Responsibility, Position, Scope.

*Charter MUST Include 8 Things - Compulsory for Exam:*

1.  Purpose of Internal Audit
2.  Commitment to Standards + Ethics
3.  Authority - Right to access all records, people, property
4.  Organizational Position - Dual Reporting
5.  Scope - Assurance + Consulting + Types of services
6.  Responsibility of CAE and IA Function
7.  QAIP
8.  Requirement for Board Approval

*5 Critical Exam Points on Charter:*

1.  Charter is approved by Board, NOT by CEO or CFO.
2.  Charter must be reviewed periodically - when significant change in organization.
3.  CAE must discuss charter with Board and Senior Management.
4.  If management restricts scope, report to Board.
5.  Without Charter, Internal Audit has NO authority.

> *Example MCQ Logic:*
> Q: Management does not allow auditor to check payroll data. What should auditor do?
> A: Refer to Charter - Charter gives authority to access all data. Report restriction to Board.

CHAPTER 4: TYPES OF SERVICES - ASSURANCE VS CONSULTING

This is asked in 4-5 questions compulsory.
Assurance Services Consulting Services
Auditor decides Nature, Scope, Objective Client + Auditor agree on Nature, Scope together
Auditor gives independent opinion Auditor gives Advice only, No opinion
3 Parties: Auditor, Auditee, User (Board) 2 Parties: Auditor + Client
Examples: Financial Audit, Compliance Audit, Operational Audit Examples: Training, Facilitation, System Design Advice
*Key Rules:*

- For Assurance, Internal Audit must be independent. For Consulting, independence still required but objectivity may be impaired - must disclose.
- If auditor previously did consulting in same area, he can do assurance after 12 months, but must disclose.
- Auditor CANNOT take operational responsibility even in consulting. If he takes, it becomes management function.

CHAPTER 5: ORGANIZATIONAL INDEPENDENCE - Link to Domain II but asked here

*Dual Reporting Model:*

- *Functional Reporting to Board / Audit Committee - Includes:* Approve Charter, Risk Assessment, Audit Plan, Budget, CAE Appointment/Removal, Results of QAIP. This ensures independence.
- *Administrative Reporting to CEO - Includes:* HR, Leave, Office space, Budget admin, Day-to-day.

> *Exam Trap:* If CAE functionally reports to CFO -> Independence is IMPAIRED. Correct is Board.

*Impairment Handling:*
If independence impaired in fact or appearance -> Must disclose to appropriate parties (Board). Must assess impact.

*Quick Revision Checklist for DOMAIN I - 35%*

For last day revision, remember this flow:

*Purpose -> 10 Core Principles -> Mandate -> Charter (8 contents + Board approval) -> Assurance vs Consulting -> Functional vs Administrative Reporting -> Conformance statement "Conforms with Global Internal Audit Standards"*

*Golden Answers for Domain I:*

1.  Q: Who approves Charter? -> Board.
2.  Q: Difference between Assurance & Consulting? -> Who decides scope + Opinion vs Advice.
3.  Q: Topical Requirements are mandatory or not? -> Mandatory if topic applies.
4.  Q: What gives authority to IA? -> Charter + Mandate.
5.  Q: Can IA do consulting? -> Yes, but must not take management responsibility and must disclose impairment if any.

The IIA's revised syllabus gives Foundations 35%, making it the largest Part 1 domain.

# Domain I – Foundations of Internal Auditing 


**Structure (Global Internal Audit Standards, effective Jan 2025):** 5 Domains, 15 Principles, 52 Standards. Domain I = Purpose of Internal Auditing. Domains II–V = Ethics & Professionalism, Governing the IA Function, Managing the IA Function, Performing IA Services.


## 1. Purpose of Internal Auditing

- Strengthens the organization's ability to create, protect, and sustain value by providing the board and management with independent, risk-based, objective assurance, advice, insight, and foresight.

- Enhances: successful achievement of objectives, governance, risk management and control processes, decision-making and oversight, reputation and credibility, and societal impact.

- Effective only if: the function is independent, auditors are objective, and it operates in line with the Standards.


## 2. Mission and Definition

- **Mission:** enhance and protect organizational value by providing risk-based, objective assurance, advice, and insight.

- **Definition:** an independent, objective assurance and consulting activity designed to add value and improve operations. It helps the organization accomplish its objectives through a systematic, disciplined approach to evaluating and improving governance, risk management, and control.


## 3. Types of Services

- **Assurance:** an objective examination of evidence to give an independent assessment (three parties: process owner, internal auditor, user).

- **Advisory/Consulting:** advice and guidance, with the nature and scope agreed with the client (two parties: requester and auditor). Auditors must not assume management responsibility.

- **Insight and foresight** (new): trends, emerging risks, and forward-looking perspective.


## 4. Principles of Domain I

Principle 1 sets out the purpose. Principles 2–15 are covered in Domains II–V.


## 5. Mandatory Elements of IPPF

- Global Internal Audit Standards (mandatory), Topical Requirements (mandatory), and Global Guidance (recommended).

- Topical Requirements: mandatory minimum criteria for specific risk areas (e.g., cybersecurity, third parties). Conformance is expected when the topic is in scope.

- Each Standard has Requirements (mandatory), Considerations for Implementation (recommended), and Examples of Evidence of Conformance.


## 6. Three Lines Model (IIA 2020)

- **Governing body:** accountable for governance and oversight.

- **1st line (management):** owns and manages risk and controls, delivering products and services.

- **2nd line (management):** provides expertise, support, monitoring, and challenge on risk-related matters (risk, compliance, quality).

- **3rd line (internal audit):** independent, objective assurance and advice on adequacy and effectiveness of governance and risk management. Reports to the governing body.

- **External assurance providers:** external auditors, regulators.

- Key principles: accountability, delegation, independence, alignment, collaboration.


## 7. Value Proposition

- Internal audit adds value by supporting objectives, improving processes, and providing assurance on risk and control.

- Value is shown through stakeholder engagement and performance results.


## 8. Quick Exam Tips

- Know the **definitions** and **Mission** wording.

- Distinguish **assurance vs. consulting** (parties involved, who sets scope).

- Know which Three Lines belongs to which role. Internal audit is **not** responsible for owning risk.

- Remember the structure counts (5 / 15 / 52).

- Expect scenario questions on "what is the purpose/value of IA" and on independence from management.


2. PURPOSE OF INTERNAL AUDITING

Internal auditing exists to strengthen an organization's ability to create, protect and sustain value by providing the board and management with independent, risk-based and objective assurance, advice, insight and foresight.

KEYWORDS

Value creation

Value protection

Risk-based

Objective

Independent

Assurance

Advisory

Insight

Foresight

Corporate example

A large retail company plans to open 500 new stores.

Management believes the major risk is construction cost.

Internal audit performs a broader risk assessment and identifies:

  • vendor fraud
  • lease risks
  • IT access
  • inventory losses
  • regulatory compliance
  • cyber risks
  • cash-handling risks

The internal auditor does not decide whether the company should open the stores.

Instead, IA provides:

Independent assurance + insight into significant risks.

EXAM TRAP

If an answer says:

"Internal audit guarantees that the organization will achieve its objectives."

❌ WRONG.

Internal audit provides reasonable assurance, not a guarantee.


3. THE 2024 IPPF — VERY IMPORTANT

The current 2024 IPPF consists of:

1. Global Internal Audit Standards

Mandatory

2. Topical Requirements

Mandatory when applicable to assurance engagements

3. Global Guidance

Recommended

The IIA explicitly identifies these three components.

MEMORY

S + T = Mandatory

G = Guidance

Standards + Topical Requirements = Mandatory

Global Guidance = Recommended


4. GLOBAL INTERNAL AUDIT STANDARDS

The 2024 Global Internal Audit Standards became effective January 9, 2025.

The Standards contain:

5 Domains

15 Principles

52 Standards

The five domains are:

  1. Purpose of Internal Auditing
  2. Ethics & Professionalism
  3. Governing the Internal Audit Function
  4. Managing the Internal Audit Function
  5. Performing Internal Audit Services

⚠️ IMPORTANT CORRECTION TO YOUR ORIGINAL NOTES

Do not teach:

"2024 Standards have five principles."

That is incorrect.

The 2024 Standards have 15 principles.

The five concepts:

  • Integrity
  • Objectivity
  • Competency
  • Due Professional Care
  • Confidentiality

are the first five principles under Domain II: Ethics & Professionalism, not all 15 principles.


5. THE 15 PRINCIPLES — HIGH-VALUE REVISION

Domain I – Purpose

  1. Demonstrate Integrity
  2. Maintain Objectivity
  3. Demonstrate Competency
  4. Exercise Due Professional Care
  5. Maintain Confidentiality

Domain II – Governing the Internal Audit Function

  1. Authorized by the Board
  2. Positioned Independently
  3. Overseen by the Board

Domain III

  1. Plan Strategically
  2. Manage Resources
  3. Communicate Effectively
  4. Enhance Quality

Domain IV

  1. Plan Engagements Effectively
  2. Conduct Engagement Work
  3. Communicate Engagement Results and Monitor Action Plans

These 15 principles are directly reflected in the IIA's current Standards.

MEMORY CHAIN

I-O-C-D-C → A-P-O → P-M-C-Q → P-C-C

For quick recall:

Integrity → Objectivity → Competency → Due Care → Confidentiality

then

Board Authorization → Independence → Board Oversight


6. TOPICAL REQUIREMENTS

Topical Requirements are one of the biggest changes students should understand.

They provide a minimum mandatory baseline for auditing specific risk topics when applicable.

Examples currently issued include:

  • Cybersecurity
  • Third Party

and additional requirements are being introduced over time.

Important distinction

For an assurance engagement, applicable Topical Requirements must be considered and applied.

For advisory services, they are recommended rather than mandatory.

Corporate example

A bank's internal audit plan includes:

Cybersecurity Assurance Review

The auditor cannot simply use personal experience.

The auditor should consider the applicable:

Cybersecurity Topical Requirement + Global Internal Audit Standards + relevant organizational criteria/frameworks.

KEYWORDS

Mandatory

Risk-specific

Assurance

Applicability

Document rationale

Minimum baseline

EXAM TRAP

"Every internal audit engagement must automatically apply every Topical Requirement."

❌ WRONG.

Applicability depends on the topic and engagement.


7. INTERNAL AUDIT CHARTER

The charter establishes the internal audit activity's:

  • purpose
  • mandate
  • authority
  • responsibilities
  • organizational position
  • reporting relationships
  • commitment to applicable Standards

WHO APPROVES?

Board / governing body

Not CFO.

Not CEO alone.

Not CAE alone.

Corporate example

The CAE wants unrestricted access to:

  • ERP records
  • employees
  • contracts
  • Board papers
  • vendors
  • financial information

The charter should provide the authority necessary for the IA function to perform its responsibilities.

KEYWORDS

Board approval

Mandate

Authority

Responsibility

Organizational position

Reporting relationship

Unrestricted access

EXAM TRAP

If management says:

"You cannot access this confidential Board document."

The CAE should consider the authority established through the charter and appropriate escalation—not simply accept management's restriction.


8. ASSURANCE vs CONSULTING

Assurance Consulting
Independent assessment Advisory service
IA evaluates evidence IA advises/facilitates
Provides assurance Provides advice
Scope generally determined within IA's mandate/risk process Scope agreed with client
Auditor maintains objectivity Must avoid assuming management responsibility

Corporate case

A company implements a new ERP.

Management asks IA:

"Please advise us on control risks before implementation."

This can be:

Consulting/advisory.

But if IA:

  • designs the controls
  • selects the configuration
  • approves transactions
  • operates the control

then IA may create a self-review or management-responsibility threat.

GOLDEN RULE

Advise — YES. Manage — NO.


9. MANAGEMENT RESPONSIBILITY vs INTERNAL AUDIT RESPONSIBILITY

MANAGEMENT

Owns

  • risks
  • controls
  • operations
  • decisions
  • remediation

INTERNAL AUDIT

Assesses

  • governance
  • risk management
  • controls
  • effectiveness
  • compliance
  • fraud-risk management

BOARD

Oversees

  • governance
  • risk oversight
  • internal audit
  • major strategic matters

MEMORY

Management OWNS → IA ASSESSES → Board OVERSEES

This is one of the most useful CIA decision rules.


DOMAIN II – ETHICS & PROFESSIONALISM

20%


Here is *DOMAIN II – ETHICS & PROFESSIONALISM (20%)* – Complete Notes for New Syllabus 2025.


This domain is *pure scoring*. 25 Questions out of 125. All are direct theory. If you understand 4 Principles + Independence, you will get 20+ marks easily.


### DOMAIN II – 2 Parts: A) Ethics  B) Professionalism (Independence + Objectivity)

---

#### PART A: ETHICS – Code of Ethics – 4 Principles + Rules

In New GIAS 2025, Ethics is now in *Domain II - Principles 1 to 5*. This is MANDATORY.

*1. INTEGRITY - The Foundation*

- Means: Honest, Courageous, Responsible. Don't do illegal work. Don't be part of fraud.

- Rule: Auditor shall not knowingly be party to illegal activity. Shall respect law.

- *Exam Trap:* If boss says "Hide this fraud finding", Integrity says you MUST NOT hide. Report to Board.


*2. OBJECTIVITY - Most Tested*

- Means: Unbiased mental attitude. No conflict of interest.

- Do NOT accept gifts, favors, money from auditee that impairs judgment.

- Do NOT participate in activity where you have personal interest.

- *3 Threats to Objectivity – MUST MUG UP:*

Threat Meaning Example

**Self-Review Threat** Auditing your own work You designed payroll system, now you audit payroll

**Familiarity Threat** Too friendly with client Auditing same branch for 5 years, become friends

**Social Pressure / Intimidation** Forced by senior CFO says "If you report this, you will be fired"

- *Rule for Objectivity:* If impaired in fact OR appearance, disclose to Board immediately.


*3. CONFIDENTIALITY*

- Do NOT disclose info to third party without authorization.

- Do NOT use info for personal gain.

- Continue even after leaving organization.

- *Exception:* Legal requirement, or Board approval.

- *Example:* You find client data during audit. You cannot share on WhatsApp or with next employer. This is violation.


*4. COMPETENCY*

- Do only those audits for which you have knowledge, skill, experience.

- Must continuously improve – CPE hours, training.

- If you don't have skill, take help of expert or decline engagement.

- Must follow Standards.


> *Exam Logic for All 4 Principles:*

> Q asks: What should auditor do?

> Step 1: Is it against Integrity? -> NO

> Step 2: Is Objectivity impaired? -> If yes, Disclose.

> Step 3: Is it confidential? -> Don't disclose.

> Step 4: Do you have competency? -> If no, take expert.


#### PART B: PROFESSIONALISM – Independence & Objectivity


This is the core of Domain II. IIA asks minimum 10 questions from this.


*1. Organizational Independence – 2 Reporting Lines*


- *Functional Reporting to BOARD / Audit Committee (5 Powers):*

    1. Approve Audit Charter

    2. Approve Risk-Based Audit Plan

    3. Approve Budget & Resources

    4. Approve CAE Appointment, Removal, Salary

    5. Receive communication on Results, QAIP, Impairments


- *Administrative Reporting to CEO (4 Day-to-day):*

    HR, Leave, Office, Admin expenses.


> *Golden Rule for Exam:* If CAE reports functionally to CFO or CEO -> Independence is IMPAIRED. Correct answer is always Board.


*2. Individual Objectivity – 12 Months Rule*


- *Rule 1:* Auditor who previously worked in an area cannot audit that area for *12 months*.

- *Rule 2:* Auditor who has personal relationship / financial interest in auditee -> Cannot audit.

- *Rule 3:* Assurance services for function where consulting was done previously -> Can do, but must disclose impairment and must not have taken operational responsibility.


> *Example:* Smit was Payroll Manager till Dec 2024. Can he audit Payroll in June 2025?

> Answer: NO. Must wait till Jan 2026 (12 months cooling period).


*3. Safeguards to Protect Objectivity – 6 Safeguards (Exam asks)*


1.  Job Rotation – Don't audit same area for long time

2.  Supervision & Review by CAE

3.  No gifts policy

4.  No operational duties

5.  Periodic rotation of audit staff

6.  Disclosure of conflict to Board


*4. Impairment – What to do when independence is impaired?*


*Step-by-Step Process:*

1.  Identify impairment (fact or appearance)

2.  Assess impact on audit

3.  Disclose to appropriate party – Board / Audit Committee

4.  If impairment affects specific engagement -> Reassign auditor or disclose in engagement report

5.  If impairment is organization-level -> Board must resolve


> *Never do this:* Never accept impairment silently. Never continue without disclosure. Never hide.

#### DOMAIN II – 15 Must-Know Definitions for Exam

1.  *Independence:* Freedom from conditions that threaten objectivity.

2.  *Objectivity:* Unbiased mental attitude.

3.  *Impairment in Fact:* Actually biased.

4.  *Impairment in Appearance:* Others may think you are biased (even if you are not).

5.  *Conflict of Interest:* Personal interest vs professional duty.


#### Last Night Revision – 10 Sure-Shot MCQs Logic

1.  Gift from client of $50 pen? -> If it impairs objectivity -> Must decline or disclose. IIA says NO gifts that impair.

2.  CAE asked to take CFO role for 2 months? -> Must NOT accept. Taking operational role impairs independence.

3.  Auditor's brother is head of department to be audited? -> Objectivity impaired -> Reassign auditor.

4.  Management restricts scope? -> Report to Board.

5.  Auditor finds fraud? -> Report to Board, not police. Maintain confidentiality.

6.  Can internal auditor do consulting? -> Yes, but must not take management responsibility.

7.  Who is responsible for ethics in organization? -> Board + Management sets tone at top. IA assesses.

8.  Can auditor use confidential info for personal share trading? -> NO, violates Confidentiality + Integrity.

9.  What is required for Competency? -> Continuous Professional Development.

10. Best way to ensure independence? -> Functional reporting to Board.

This domain is easy. Students lose marks because they think practically, not as per Standards. Always choose most ethical, most independent, most board-oriented answer.


10. INTEGRITY

Integrity means being:

  • honest
  • truthful
  • courageous
  • professional

Corporate example

An auditor discovers that a senior executive's expense claim appears fraudulent.

The executive pressures the auditor:

"Don't include this finding. I'll handle it."

The auditor should not suppress the finding merely because the individual is senior.

KEYWORDS

Honesty

Courage

Truthfulness

Professional judgment

Ethical behavior


11. OBJECTIVITY

Objectivity means making professional judgments without allowing:

  • bias
  • conflicts of interest
  • undue influence
  • personal relationships
  • financial interests

to compromise professional judgment.

Common threats

Self-interest

Self-review

Familiarity

Bias

Conflict of interest

Undue influence / intimidation


12. SELF-REVIEW THREAT

Corporate case

An auditor previously helped Accounts Payable design a new vendor approval process.

Six months later the CAE assigns the same auditor to audit that process.

The auditor may have to evaluate decisions that he/she previously helped make.

Risk:

Self-review threat

Better solution:

Assign another auditor or establish appropriate safeguards.

KEYWORD

"I am auditing my own work." = SELF-REVIEW


13. FAMILIARITY THREAT

An auditor has worked with the same department head for many years and becomes excessively trusting.

The auditor stops challenging unusual transactions.

Risk:

Familiarity

Solution:

  • rotation where appropriate
  • independent review
  • supervision
  • disclosure of impairment
  • reassignment when necessary

EXAM TRAP

Do not memorize an absolute rule such as:

"Every auditor must be rotated after exactly 12 months."

The question should be evaluated based on the nature of the impairment, safeguards and applicable organizational policy/Standards.


14. INTIMIDATION / UNDUE INFLUENCE

Corporate case

The CFO tells the CAE:

"If you report this control weakness to the Audit Committee, I will make sure your budget is cut."

This is a serious independence/objectivity issue.

Appropriate response:

Do not change the conclusion simply because of pressure.

Escalate appropriately, particularly through the Board/Audit Committee relationship.

KEYWORDS

Pressure

Threat

Undue influence

Escalation

Board


15. GIFTS & CONFLICTS OF INTEREST

Supplier offers an internal auditor an expensive smartphone before a vendor audit.

Question:

Should the auditor accept?

Generally:

No, if acceptance could influence—or reasonably appear to influence—objectivity.

Exam logic

Even if the auditor says:

"I promise it won't affect me."

The issue may still be:

APPEARANCE of impaired objectivity.

KEYWORD

Perception matters.


16. COMPETENCY

The internal audit function must collectively possess or obtain the knowledge, skills and competencies needed.

Important principle

One auditor does not need to be an expert in everything.

The CAE can:

  • train employees
  • recruit specialists
  • use co-sourcing
  • obtain external expertise

Corporate example

IA is auditing an AI-based credit-scoring model.

The audit team lacks sufficient AI/model-risk expertise.

Possible solution:

Engage an appropriately qualified specialist.

EXAM TRAP

Wrong answer:

"Proceed anyway because internal auditors must personally know everything."

Correct approach:

Obtain appropriate competency.


17. DUE PROFESSIONAL CARE

Due professional care means applying the level of care and competence expected from a reasonably prudent and competent internal auditor.

It requires:

  • professional skepticism
  • judgment
  • appropriate evidence
  • consideration of risk
  • materiality
  • significance
  • cost/benefit
  • complexity

VERY IMPORTANT

Due care ≠ perfection

Internal auditors are not expected to guarantee detection of every fraud or error.

Corporate case

An auditor samples 100 transactions from 100,000 transactions.

A fraudulent transaction outside the sample is later discovered.

This does not automatically mean the auditor failed due care.

The question is:

Was the audit procedure appropriately designed and executed based on risk?


18. CONFIDENTIALITY

Internal auditors have access to sensitive information such as:

  • salary data
  • customer information
  • passwords
  • strategic plans
  • acquisition plans
  • confidential investigations

Corporate case

An auditor learns that the company is secretly negotiating to acquire a competitor.

The auditor tells a friend:

"Buy the competitor's shares before the announcement."

This is a serious confidentiality and ethical violation.

KEYWORDS

Need-to-know

Confidential information

Unauthorized disclosure

Data protection


19. ORGANIZATIONAL INDEPENDENCE

Functional reporting

Usually involves the Board/Audit Committee.

Examples:

  • approve charter
  • approve risk-based audit plan
  • approve CAE appointment/removal
  • approve CAE compensation/evaluation as appropriate
  • meet privately with CAE
  • oversee independence

Administrative reporting

Often to CEO or another senior executive.

Examples:

  • payroll
  • office facilities
  • HR administration
  • travel
  • routine budgeting

MEMORY

FUNCTIONAL = Independence

ADMINISTRATIVE = Operations

Corporate case

CAE reports only to CFO.

CFO controls:

  • audit plan
  • audit budget
  • CAE performance evaluation
  • access to Audit Committee

This creates a significant independence concern.


20. QAIP – QUALITY ASSURANCE & IMPROVEMENT

The quality program evaluates whether the internal audit activity:

  • conforms with applicable Standards
  • achieves objectives
  • improves continuously
  • operates effectively

Internal assessment

Includes:

Ongoing monitoring

Periodic self-assessment

External assessment

The external assessment requirement is generally:

At least once every five years

The assessor should be appropriately qualified and independent/objective.

KEYWORD

External assessment = 5 years

EXAM TRAP

Do not confuse:

Ongoing monitoring

with

External assessment.


DOMAIN III – GOVERNANCE, RISK MANAGEMENT & CONTROL

30%


**CIA Part 1 – Domain V: Governance, Risk Management & Control (~35% of the exam)**

**Governance**
- Governance = the structures and processes the board uses to direct, manage, and monitor the organization toward its objectives.
- Board's role: set strategy and tone at the top, oversee management, approve the internal audit charter, and ensure the CAE's independence.
- Ethics and culture: code of conduct, whistleblowing channels, and consistent enforcement. Internal audit assesses them and reports to the board.
- Three Lines Model: 1st line (management/operations owns risk), 2nd line (risk, compliance, and other functions that support and monitor), 3rd line (independent internal audit assurance). The governing body sits above, accountable for oversight.
- Internal audit's role: assess and make recommendations on governance processes (objective setting, accountability, communication of risk and control information).

**Risk management**
- Key terms: inherent risk (before controls), residual risk (after controls), risk appetite (amount accepted to pursue objectives), risk tolerance (acceptable deviation).
- Risk responses: avoid, accept, reduce/mitigate, share/transfer.
- Frameworks: COSO ERM and ISO 31000.
- Management owns risk management. Internal audit gives assurance on its effectiveness.
- Consulting role: internal audit may facilitate, but must not set risk appetite, make risk decisions, impose its own risk responses, or take on management's responsibilities.
- Risk assessment for audit planning: likelihood × impact, linked to organizational objectives.

**Control**
- Control types: preventive, detective, corrective, directive.
- COSO Internal Control Framework: 5 components (control environment, risk assessment, control activities, information & communication, monitoring) and 17 principles.
- Entity-level vs. process-level controls.
- Control environment: integrity, competence, and tone at the top (the foundation for all other components).
- IT controls: general controls (access, change management, operations) vs. application controls (input, processing, output).
- Cost-benefit principle: a control should not cost more than the risk it mitigates.
- Segregation of duties: separate authorization, recording, and custody of assets.

**Exam tips**
- Remember who owns what: management owns risk and control; internal audit evaluates and advises.
- Watch for "consulting vs. assurance" and "independence threat" wording in scenario questions.
- Know the COSO components and their order.



21. GOVERNANCE

Governance determines how an organization:

  • makes decisions
  • sets objectives
  • provides oversight
  • manages accountability
  • promotes ethics
  • monitors performance

Board

Provides oversight.

Management

Executes strategy and manages operations.

Internal Audit

Provides independent assessment and insight.

Corporate case

A listed company repeatedly misses compliance requirements.

The Board asks:

"Is management's compliance governance operating effectively?"

IA can assess:

  • accountability
  • reporting
  • oversight
  • controls
  • risk management
  • ethical culture.

IA should not become the compliance owner merely because it identifies the problem.


22. RISK APPETITE vs RISK TOLERANCE

Risk Appetite

Amount/type of risk the organization is willing to accept in pursuit of objectives.

Risk Tolerance

Acceptable variation around objectives/risk appetite.

Example

A bank says:

"We have moderate appetite for credit risk."

That is:

Risk appetite.

It then establishes:

"Non-performing loans should remain below 3%."

That is closer to a:

Risk tolerance / limit.


23. INHERENT vs RESIDUAL RISK

Inherent risk

Risk before considering controls.

Residual risk

Risk remaining after controls.

Example

Cash theft risk:

Before controls: ₹10 million potential exposure.

Controls:

  • segregation of duties
  • CCTV
  • daily reconciliation
  • surprise cash counts

Risk remaining after controls:

Residual risk

MEMORY

INHERENT = BEFORE

RESIDUAL = AFTER


24. CONTROL TYPES

Preventive

Stops an undesirable event before it happens.

Examples:

  • authorization
  • password controls
  • segregation of duties
  • credit-limit approval

Detective

Identifies an event after it occurs.

Examples:

  • bank reconciliation
  • inventory count
  • exception report
  • audit trail review

Corrective

Fixes or restores after a problem.

Examples:

  • disaster recovery
  • correcting erroneous records
  • restoring backup

MEMORY

Prevent → Detect → Correct


25. AUTOMATED vs MANUAL CONTROLS

Automated control

System performs the control.

Example:

ERP automatically blocks a purchase order above an employee's authorization limit.

Manual control

Human performs the control.

Example:

Finance manager reviews monthly expense report.

IT-dependent manual control

Human reviews information produced by IT.

Example:

Manager reviews an automated exception report.


26. COSO INTERNAL CONTROL FRAMEWORK

Remember:

5 Components + 17 Principles

  1. Control Environment
  2. Risk Assessment
  3. Control Activities
  4. Information & Communication
  5. Monitoring Activities

MEMORY

C-R-C-I-M

Control → Risk → Control Activities → Information → Monitoring


27. CONTROL ENVIRONMENT

The foundation.

Includes:

  • integrity
  • ethical values
  • Board oversight
  • organizational structure
  • authority/responsibility
  • competence
  • accountability

Corporate case

Company has sophisticated software controls.

But the CEO routinely tells employees:

"Ignore the approval process. Just get the deal done."

The technical controls may exist, but the:

Control Environment is weak.

KEYWORD

Tone at the top


28. MANAGEMENT OVERRIDE

This is a very important CIA concept.

Example

Company policy:

Expenses above ₹1 million require two approvals.

CEO instructs Accounts Payable:

"Process this ₹3 million payment without the second approval."

The CEO has:

Overridden the control.

Why dangerous?

Management override can defeat otherwise effective controls.


DOMAIN IV – FRAUD RISKS

15%

Here is *DOMAIN IV – FRAUD RISKS (15%)* – Complete Notes for CIA Part 1 New Syllabus 2025.

This is 15% = 19 Questions. Very scoring because all questions are logical. IIA does NOT expect you to be fraud detective, only to EVALUATE fraud risk.

DOMAIN IV – FRAUD – 6 Chapters Only

CHAPTER 1: WHAT IS FRAUD? – Definition

*Fraud = Any illegal act characterized by deceit, concealment, or violation of trust. Not dependent on violence.*

Fraud is done for personal gain.

*2 Types of Fraud in IIA Syllabus:*
Type Who does it? Example Loss to whom?
**1. Fraud Against Organization** (Asset Misappropriation, Corruption) Employee does fraud AGAINST company Cash theft, fake vendor, bribery Company loses money
**2. Fraud On Behalf of Organization** (Financial Statement Fraud) Management does fraud FOR company to show good result Fake sales, hiding liabilities Investors, Public loses money
> *Exam Trap:* Financial Statement Fraud is mostly done by TOP Management. Asset Misappropriation is done by lower-level employees. This is always asked.

CHAPTER 2: FRAUD TRIANGLE – Most Important Model – 3 Elements MUST

Without these 3, fraud cannot happen. IIA asks 3-4 questions directly from this.

*1. Pressure / Incentive:* Why person does fraud? – Personal financial problem, greed, unrealistic targets from boss, debt.
*2. Opportunity:* How can he do fraud? – Weak controls, no segregation of duties, no supervision, override of controls by management.
*3. Rationalization:* How he justifies? – "Company owes me", "I will return later", "Everyone does it".

*New 2025 – Fraud Diamond – 4th Element:*
*Capability* – Person must have skills, position, knowledge to do fraud.

> *Memory Trick:* *P-O-R-C* = *Pressure, Opportunity, Rationalization, Capability*

*Q: Which element can Internal Audit control best?*
*Answer: OPPORTUNITY.* Auditor cannot control pressure or rationalization, but can improve controls to reduce opportunity.

CHAPTER 3: WHO IS RESPONSIBLE FOR FRAUD? – Very Important

This is the #1 confusion for students.

- *Board / Audit Committee:* Oversight of fraud risk, sets tone at top, ensures ethics hotline exists.
- *Management:* PRIMARY responsibility to PREVENT, DETECT, and DETER fraud. Management designs controls.
- *Internal Audit:* Must have sufficient knowledge to EVALUATE fraud risk. Must ASSESS controls to prevent fraud. Must be ALERT to red flags. But NOT primary responsibility to detect.
- *External Auditor:* Responsible to provide reasonable assurance that financial statements are free from material misstatement due to fraud.

> *Golden Rule for Exam:*
> Q: Who is responsible for fraud prevention? -> MANAGEMENT
> Q: What is IA's responsibility? -> Evaluate risk, Assess controls, Be alert.
> IA NEVER says "We will prevent fraud". IA says "We will evaluate if controls are adequate to prevent fraud".

CHAPTER 4: FRAUD RED FLAGS – 50% Questions come from here

Red Flag = Warning sign that fraud MAY exist. Not proof of fraud.

*A) Behavioral Red Flags – 6 Main:*
1.  Living beyond means – Big car, costly lifestyle on small salary
2.  Financial difficulties – Debt, divorce
3.  Unusually close association with vendor/customer
4.  Wheeler-dealer attitude – Always wants to bypass controls
5.  Refusal to take vacation or rotation – Afraid fraud will be found
6.  Excessive overtime, comes early, leaves late – Hiding something

*B) Organizational Red Flags – Weak Controls:*
1.  No segregation of duties – Same person can create vendor + approve payment + make payment
2.  No mandatory vacation / job rotation
3.  Management override of controls
4.  Lack of whistleblower hotline
5.  No code of ethics
6.  High turnover in finance dept

*C) Transactional Red Flags:*
1.  Missing documents, photocopies instead of originals
2.  Round numbers – Many invoices of exactly $10,000
3.  Weekend transactions
4.  Vendor with only PO Box address
5.  Frequent manual journal entries near year-end
6.  Duplicate payments to same vendor

CHAPTER 5: FRAUD CONTROLS – How to Prevent?

*3 Levels of Controls:*

1.  *Preventive Controls – Best:* Segregation of duties, Authorization, Job rotation, Mandatory vacation, Background checks, Ethics training, Code of conduct.
2.  *Detective Controls:* Reconciliations, Surprise audits, Data analytics, Exception reports, Whistleblower hotline, Independent checks.
3.  *Corrective Controls:* Disciplinary action, Insurance, Recovery, Lessons learned.

*Most Powerful Fraud Deterrents – Must Mug Up:*
1.  Tone at the Top – Management shows ethical behavior
2.  Whistleblower Hotline – Anonymous reporting
3.  Segregation of Duties (SOD)
4.  Surprise Audits

> *SOD Example:* Person who can approve purchase should NOT be person who can make payment.

CHAPTER 6: WHAT SHOULD INTERNAL AUDITOR DO IF FRAUD IS SUSPECTED?

*Step-by-Step Process – IIA Standard:*

*Step 1:* Don't panic, Don't accuse. Maintain professional skepticism.
*Step 2:* Evaluate if red flag is real – Gather more evidence.
*Step 3:* If suspicion remains, communicate to appropriate level:
   - If staff-level fraud -> Report to Management + CAE
   - If management-level fraud -> Report directly to Board / Audit Committee (Bypass management)
*Step 4:* Do NOT conduct full investigation unless Board / Charter gives authority and you have competency. IA may assist investigation, but legal/HR may lead.
*Step 5:* Assess impact on overall control environment.
*Step 6:* Report: Facts only, no opinion that "This is fraud". Say "Indicators of potential fraud noted".
*Step 7:* Follow-up – Ensure controls improved.

*What IA should NOT do:*
- Don't inform police directly without Board approval (breach of confidentiality)
- Don't confront suspect directly
- Don't destroy evidence
- Don't promise confidentiality to whistleblower beyond what policy allows

---

LAST NIGHT REVISION – 15 Sure Questions for Exam

1.  *Fraud Triangle has?* Pressure, Opportunity, Rationalization.
2.  *Who can reduce Opportunity?* Internal Auditor by improving controls.
3.  *Asset misappropriation done by?* Lower employees.
4.  *Financial statement fraud done by?* Senior management.
5.  *Primary responsibility for fraud?* Management.
6.  *IA's responsibility?* Evaluate risk, not prevent fraud.
7.  *Strongest fraud deterrent?* Tone at the top + Hotline.
8.  *If CAE suspects CFO fraud?* Report to Board/Audit Committee, not to CEO.
9.  *Employee never takes vacation?* Red flag for fraud.
10. *Same person creates vendor + pays vendor?* Lack of SOD – Opportunity for fraud.
11. *Can IA investigate fraud?* Only if competent and authorized, otherwise assist.
12. *What is rationalization?* Self-justification.
13. *Fraud risk assessment done by whom?* Management, evaluated by IA.
14. *Should IA have fraud knowledge?* Yes, sufficient to evaluate risk.
15. *If fraud found, what to do with controls?* Assess and recommend improvement.

Memory Trick for Students

*Fraud = P-O-R + B-O-T + S*

*P-O-R = Triangle (Pressure, Opportunity, Rationalization)*
*B-O-T = Who is responsible (Board Oversight, Management owns, IA Tests)*
*S = SOD is best control*

29. FRAUD TRIANGLE

1. PRESSURE / INCENTIVE

Example:

  • debt
  • financial problems
  • unrealistic sales targets
  • bonus pressure

2. OPPORTUNITY

Example:

  • weak segregation
  • poor supervision
  • excessive system access
  • management override

3. RATIONALIZATION

Example:

"The company owes me."

"Everyone does it."

"I'll return the money later."

MEMORY

P + O + R = Fraud Triangle


30. CORPORATE FRAUD CASE

Imagine a sales director has a year-end bonus based on revenue.

He instructs employees to record shipments that have not actually been delivered.

Pressure:

Bonus target

Opportunity:

Weak revenue controls

Rationalization:

"The customer will accept delivery next month anyway."

This creates the classic:

Fraud Triangle


31. FRAUD RESPONSIBILITY

Management's responsibility

Management is primarily responsible for:

  • preventing fraud
  • detecting fraud
  • establishing controls
  • maintaining ethical culture
  • investigating according to organizational processes

Internal Audit

IA evaluates whether fraud risks are appropriately:

  • identified
  • assessed
  • managed
  • controlled

IA may perform investigations when specifically authorized and appropriately competent.

VERY IMPORTANT CORRECTION

Your original statement:

"If fraud is found → Report to Board, not police directly."

is too absolute.

The correct CIA logic is:

Follow the organization's established fraud-investigation/reporting protocol, applicable laws/regulations, and appropriate governance escalation.

Internal audit should not independently decide to call the police unless that is appropriate under the organization's policy, legal requirements, authority and circumstances.


32. FRAUD RED FLAGS

Employee-level

  • unexplained wealth
  • lifestyle beyond apparent income
  • financial difficulties
  • unusual relationships with suppliers
  • refusal to take leave
  • excessive control over one process
  • unusual working hours
  • defensive behavior

Organizational

  • weak segregation of duties
  • missing documentation
  • excessive management override
  • poor vendor due diligence
  • unrealistic targets
  • weak whistleblower mechanisms
  • inadequate supervision

EXAM KEYWORD

Red flag ≠ proof of fraud

A red flag means:

Further investigation/assessment may be necessary.


33. FRAUD SCENARIO – VENDOR COLLUSION

Procurement manager repeatedly awards contracts to one supplier.

You discover:

  • same supplier wins 90% of contracts
  • competing bids look unusually similar
  • supplier employee and procurement manager frequently meet socially
  • prices are consistently above market

Do not immediately conclude:

"Fraud has been proven."

Instead:

Identify indicators → assess risk → obtain evidence → follow investigation/reporting procedures.


34. INTERNAL AUDITOR'S MINDSET

This is the most important concept I would add to your notes.

CIA questions frequently reward the auditor who thinks:

RISK → OBJECTIVITY → EVIDENCE → PROFESSIONAL JUDGMENT → GOVERNANCE

When presented with a scenario, ask:

Question 1

Who owns the responsibility?

Management? Board? IA?

Question 2

Is IA independent?

Question 3

Is there an objectivity impairment?

Question 4

What evidence is required?

Question 5

What is the risk?

Question 6

What is the most appropriate next step?


35. MASTER CORPORATE CASE

Scenario

A multinational company discovers that a senior procurement executive has approved ₹50 crore of purchases from a related vendor.

The CAE is asked to investigate.

The auditor discovers:

  • no competitive bidding
  • vendor relationship not disclosed
  • manager has financial ties to vendor
  • approval controls were bypassed
  • CFO says: "Don't escalate this; we need the supplier."

CIA ANALYSIS

Risk: High

Potential fraud: Yes

Conflict of interest: Yes

Management override: Yes

Control weakness: Yes

Objectivity pressure: Yes

What should IA NOT do?

❌ Ignore the matter

❌ Change findings because CFO requested it

❌ Assume guilt without evidence

❌ Become operational procurement manager

What should IA do?

✅ Maintain objectivity

✅ Gather sufficient appropriate evidence

✅ Follow investigation/reporting protocols

✅ Escalate appropriately

✅ Communicate significant findings

✅ Recommend improvements without assuming management responsibility


36. CIA EXAM KEYWORDS

When you see these words, slow down.

Keyword Think
BEST Most appropriate professional judgment
FIRST Immediate/initial action
MOST likely Highest probability
EXCEPT Find the wrong option
NOT Reverse the question
PRIMARY responsibility Who owns it?
INDEPENDENCE Board/Audit Committee
OBJECTIVITY Individual judgment
SELF-REVIEW Auditor's own previous work
FAMILIARITY Excessive trust
INTIMIDATION Pressure/threat
MANAGEMENT OVERRIDE Management bypasses control
INHERENT RISK Before controls
RESIDUAL RISK After controls
PREVENTIVE Before event
DETECTIVE Find event
CORRECTIVE Fix
RISK APPETITE Willingness to accept risk
RISK TOLERANCE Acceptable variation/limit
REASONABLE ASSURANCE Not absolute assurance
DUE CARE Prudent competent auditor
CONFIDENTIALITY Protect information
TOPICAL REQUIREMENT Mandatory when applicable to assurance
BOARD Oversight
MANAGEMENT Ownership
IA Independent assessment

37. 15 SECOND DECISION TREE

When stuck between two CIA answers:

STEP 1

Does the answer preserve independence?

↓

STEP 2

Does it preserve objectivity?

↓

STEP 3

Does it keep management responsible for management decisions?

↓

STEP 4

Does it use sufficient appropriate evidence?

↓

STEP 5

Does it follow the Standards/policies?

↓

STEP 6

Does it escalate appropriately?

↓

STEP 7

Choose the answer that represents:

Professional judgment + risk-based thinking + independence + evidence + governance.


38. 15 GOLDEN RULES FOR CIA PART 1

  1. Management owns risk; IA assesses risk.
  2. Management owns controls; IA evaluates controls.
  3. Board provides oversight.
  4. Functional reporting protects independence.
  5. Administrative reporting supports day-to-day administration.
  6. IA may advise; IA should not assume management responsibility.
  7. Self-review = auditing your own work.
  8. Familiarity = excessive trust/bias.
  9. Intimidation = pressure or undue influence.
  10. Inherent risk = before controls.
  11. Residual risk = after controls.
  12. Preventive = before; Detective = after; Corrective = fix.
  13. Fraud prevention/detection is primarily management's responsibility.
  14. Due professional care does not mean perfection or guaranteed fraud detection.
  15. When uncertain, choose the answer that best preserves independence, objectivity, evidence-based judgment and management accountability.

39. FINAL CIA PART 1 MASTER MAP

DOMAIN I — FOUNDATIONS — 35%

Purpose

→ Value

→ IPPF

→ Global Standards

→ Topical Requirements

→ Charter

→ Assurance vs Consulting

→ Board/CAE responsibilities

→ Internal audit mandate


DOMAIN II — ETHICS & PROFESSIONALISM — 20%

Integrity

→ Objectivity

→ Competency

→ Due Professional Care

→ Confidentiality

→ Independence

→ Conflicts

→ Impairments

→ QA/quality concepts


DOMAIN III — GOVERNANCE/RISK/CONTROL — 30%

Governance

→ Board

→ Management

→ Risk appetite

→ Risk tolerance

→ Inherent risk

→ Residual risk

→ Risk management

→ COSO

→ Control environment

→ Preventive/detective/corrective

→ Control effectiveness


DOMAIN IV — FRAUD — 15%

Fraud Triangle

→ Pressure

→ Opportunity

→ Rationalization

→ Red flags

→ Fraud risk assessment

→ Fraud controls

→ Management responsibility

→ IA role

→ Investigation/reporting


⭐ ONE-LINE MEMORY FORMULA

CIA = INDEPENDENT + OBJECTIVE + RISK-BASED + EVIDENCE-BASED + ETHICAL + VALUE-FOCUSED

That is the internal auditor's mindset I would repeatedly reinforce with students.

Important source note for study material

"The old six-domain syllabus is useful for historical mapping and understanding legacy study material, but candidates preparing for the current exam should prioritize the revised four-domain CIA Part 1 syllabus and the 2024 Global Internal Audit Standards."

Also, I would not teach the 2017 IPPF as if its separate components are current requirements. The IIA says the 2024 Standards incorporated the former mandatory elements of the 2017 IPPF, while Global Guidance remains recommended.

Official references: · ·

This version is much safer to use as GMSiSuccess CIA Part 1 classroom/revision material, because it separates the current exam's four domains from the 2024 Standards' five domains/15 principles, while retaining the old syllabus only as a mapping tool.