Friday, December 12, 2025

CIA Part 1Compreh Mocktest Challenging

 


 

CIA PART 1 (2025)

Challenging Essay-Based MCQs

 

1. Independence vs Objectivity (Governance & Ethics)

The Chief Audit Executive (CAE) reports functionally to the audit committee and administratively to the CFO. Due to budget constraints, the CFO requires the internal audit department to review expense reimbursements of senior executives and report findings directly to him before communicating with the audit committee.

Which statement BEST describes the situation?

A. Independence is impaired because the CAE reports administratively to the CFO

B. Objectivity is impaired due to familiarity threat

C. Independence may be impaired due to interference with audit communication

D. There is no impairment as long as findings are eventually reported

Correct Answer: 

 

2. Three Lines Model – Accountability

An organization assigns the risk management department responsibility for designing controls, monitoring their effectiveness, and providing assurance to the board.

Which flaw exists in this structure?

A. Risk management should not design controls

B. Risk management should report administratively to internal audit

C. Second-line functions should not provide independent assurance

D. Board should approve all controls

Correct Answer: 


3. Assurance vs Consulting Engagement

Internal auditors are asked to facilitate a workshop to help management redesign the procurement process and later audit the same process.

What is the MOST appropriate action?

A. Accept both assignments without restriction

B. Decline the consulting engagement

C. Perform consulting but assign a different auditor for assurance

D. Accept assurance engagement first, then consulting

Correct Answer: 

 

4. Risk Assessment – Residual Risk

Management implements controls that reduce inherent risk significantly, but key controls are manual and inconsistently applied.

How should internal audit assess residual risk?

A. Low, because inherent risk was high but mitigated

B. Moderate to high, due to control effectiveness issues

C. Low, because management accepted the risk

D. Insignificant, because controls exist

Correct Answer: 


5. Governance – Board Responsibilities

Which of the following is the PRIMARY governance responsibility of the board?

A. Designing internal controls

B. Managing organizational risk

C. Providing independent oversight

D. Performing internal audits

Correct Answer: 

 

6. Professional Due Care

During an audit, an internal auditor suspects fraud but lacks forensic expertise. Management insists there is no issue.

What should the auditor do FIRST?

A. Ignore the suspicion

B. Perform forensic procedures

C. Report suspicion and recommend specialist involvement

D. Inform external auditors immediately

Correct Answer: 

 

7. Ethical Dilemma – Confidentiality

An internal auditor discovers confidential salary data during an engagement. A department head requests the information informally.

What is the MOST appropriate response?

A. Share data since the manager requested it

B. Share only summarized data

C. Decline and maintain confidentiality

D. Seek permission from HR

Correct Answer: 

 

8. Risk-Based Audit Planning

Which factor should MOST influence the internal audit plan?

A. Management preference

B. Time since last audit

C. Risk severity and likelihood

D. Availability of audit staff

Correct Answer: 

 

9. Quality Assurance and Improvement Program (QAIP)

Which activity BEST demonstrates an effective QAIP?

A. Annual performance appraisal of auditors

B. External assessment every year

C. Ongoing internal reviews and periodic external assessments

D. Audit committee review of reports

Correct Answer: 

 

10. Combined Assurance

Multiple assurance providers independently review the same low-risk area while high-risk areas remain unaudited.

What governance weakness does this indicate?

A. Inadequate segregation of duties

B. Poor coordination of assurance activities

C. Lack of internal controls

D. Ineffective audit committee

Correct Answer: 

 

11. Objectivity Threat

An auditor previously worked as procurement manager six months ago and is assigned to audit procurement.

What threat exists?

A. Advocacy threat

B. Familiarity threat

C. Self-review threat

D. No threat exists

Correct Answer: 

 

12. Management Risk Acceptance

Internal audit identifies a high residual risk. Management formally accepts the risk.

What should the CAE do?

A. Accept management decision without action

B. Escalate the matter to the board

C. Modify audit opinion

D. Re-audit immediately

Correct Answer: 

 

Exam Tip (CIA Part 1 – 2025)

✔ Focus on judgment, not definitions

✔ Look for governance failures, independence threats, risk misalignment

✔ Eliminate options that confuse management responsibility vs audit responsibility

 

Section B….


Below are 50 ultra-tricky, exam-level MCQs , strictly aligned to CIA Part 1 – Essentials of Internal Auditing (New Syllabus 2025).

These are IIA-style, scenario-based, high-confusion questions designed to test judgment, independence, governance, risk, and ethics.

 

CIA PART 1 (2025)

1.

The CAE attends executive meetings but is excluded when strategic risks are discussed.

What is the MOST significant implication?

A. Objectivity impairment

B. Scope limitation

C. Independence impairment

D. Ineffective risk management

Answer: 

 

2.

Which situation MOST threatens internal audit independence?

A. Budget approval by management

B. Administrative reporting to CEO

C. Audit committee approving audit plan

D. Management limiting audit areas

Answer: 

 

3.

A consulting engagement requires recommending control design.

What MUST the auditor ensure?

A. Independence is not required

B. Objectivity is safeguarded

C. Assurance standards apply fully

D. Audit committee approval

Answer: 

 

4.

Which function BEST fits the second line of defense?

A. Internal audit

B. External audit

C. Compliance monitoring

D. Board of directors

Answer: 

 

5.

Residual risk remains high even after controls.

What does this MOST likely indicate?

A. Poor inherent risk assessment

B. Ineffective controls

C. Lack of management oversight

D. Risk appetite not defined

Answer: 

 

6.

Which is NOT a board responsibility?

A. Oversight of risk

B. Setting tone at the top

C. Designing internal controls

D. Ensuring audit independence

Answer: 

 

7.

An auditor accepts a gift of nominal value from auditee.

Which principle is MOST at risk?

A. Integrity

B. Confidentiality

C. Competence

D. Objectivity

Answer: 

 

8.

Which action BEST supports risk-based auditing?

A. Rotating audits annually

B. Auditing all units equally

C. Prioritizing high residual risk areas

D. Auditing only financial risks

Answer: 

 

9.

What is the PRIMARY purpose of QAIP?

A. Auditor appraisal

B. Regulatory compliance

C. Continuous improvement

D. Cost reduction

Answer: 

 

10.

External quality assessment must be performed at least every:

A. 3 years

B. 4 years

C. 5 years

D. 6 years

Answer: 

 

11.

Management accepts a risk beyond risk appetite.

What should the CAE do?

A. Document acceptance

B. Ignore decision

C. Escalate to board

D. Re-assess controls

Answer: 

 

12.

Which engagement provides the HIGHEST level of assurance?

A. Consulting

B. Compliance review

C. Assurance audit

D. Advisory service

Answer: 

 

13.

Which threat arises when auditing a former department?

A. Advocacy

B. Familiarity

C. Self-review

D. Intimidation

Answer: 

 

14.

Which factor LEAST affects audit independence?

A. Scope limitation

B. Reporting line

C. Staff competence

D. Management interference

Answer: 

 

15.

Internal audit reports administratively to CFO.

Which safeguard is MOST important?

A. Budget control

B. Functional reporting to audit committee

C. Management representation

D. Annual planning

Answer: 

 

16.

Which risk remains after controls are applied?

A. Inherent risk

B. Control risk

C. Residual risk

D. Detection risk

Answer: 

 

17.

What BEST defines governance?

A. Daily management

B. Control activities

C. Direction and oversight

D. Risk assessment

Answer: 

 

18.

Which activity compromises objectivity MOST?

A. Providing training

B. Process facilitation

C. Decision-making authority

D. Control evaluation

Answer: 

 

19.

Which is an internal auditor’s responsibility regarding fraud?

A. Investigate all fraud

B. Detect fraud

C. Consider fraud risk

D. Prevent fraud

Answer: 

 

20.

Which is a key element of effective governance?

A. Strong management

B. Ethical culture

C. Detailed procedures

D. Cost control

Answer: 

 

21.

Which is a limitation of internal control?

A. Management override

B. Segregation of duties

C. Authorization

D. Documentation

Answer: 

 

22.

What is the FIRST step in risk-based audit planning?

A. Allocate resources

B. Identify risks

C. Evaluate controls

D. Perform audits

Answer: 

 

23.

Which party owns risk?

A. Internal audit

B. Board

C. Management

D. Compliance

Answer: 

 

24.

Which report relationship BEST ensures independence?

A. Admin: CFO / Func: CEO

B. Admin: CEO / Func: Audit Committee

C. Admin: COO / Func: CFO

D. Admin: Board / Func: Management

Answer: 

 

25.

Which engagement gives advice without assurance?

A. Assurance

B. Consulting

C. External audit

D. Compliance audit

Answer: 

 

26.

Which scenario shows scope limitation?

A. Auditor lacks skill

B. Management denies access

C. Budget reduction

D. Poor planning

Answer: 

 

27.

What ensures objectivity MOST?

A. Rotation

B. Independence

C. Professional judgment

D. Ethics training

Answer: 

 

28.

Which line monitors compliance but does not audit?

A. First

B. Second

C. Third

D. Fourth

Answer: 

 

29.

Which factor MOST influences audit frequency?

A. Last audit date

B. Risk level

C. Auditor availability

D. Management request

Answer: 

 

30.

Which is NOT part of QAIP?

A. Internal assessments

B. External assessments

C. Peer reviews

D. Financial statement audits

Answer: 

 

31.

What is a red flag of weak governance?

A. Clear risk appetite

B. Active audit committee

C. Board dominated by management

D. Independent directors

Answer: 

 

32.

Which BEST supports combined assurance?

A. Multiple audits

B. Independent reviews

C. Coordinated assurance providers

D. Frequent reporting

Answer: 

 

33.

Which engagement risks self-review threat?

A. Training staff

B. Policy drafting

C. Auditing drafted policy

D. Risk assessment

Answer: 

 

34.

Which code principle addresses misuse of information?

A. Integrity

B. Objectivity

C. Confidentiality

D. Competence

Answer: 

 

35.

Which situation requires disclosure of impairment?

A. Consulting engagement

B. Prior employment

C. Time pressure

D. Lack of resources

Answer: 

 

36.

What does “tone at the top” influence MOST?

A. Controls

B. Risk assessment

C. Ethical culture

D. Audit plan

Answer: 

 

37.

Which is NOT an internal audit role?

A. Assurance

B. Consulting

C. Risk ownership

D. Advisory

Answer: 

 

38.

Which risk cannot be eliminated fully?

A. Inherent risk

B. Control risk

C. Residual risk

D. Compliance risk

Answer: 

 

39.

Which best describes assurance?

A. Advice

B. Facilitation

C. Independent evaluation

D. Decision support

Answer: 

 

40.

Which activity MOST supports audit quality?

A. Fast reporting

B. High coverage

C. Professional skepticism

D. Automation

Answer: 

 

41.

What threatens independence MOST?

A. Consulting services

B. Management approval of plan

C. Performance evaluation by management

D. Risk workshops

Answer: 

 

42.

Which risk relates to incorrect processes?

A. Strategic

B. Operational

C. Financial

D. Compliance

Answer: 

 

43.

Which is a governance failure?

A. Risk acceptance

B. Management override

C. Strong audit committee

D. Ethical leadership

Answer: 

 

44.

What is the CAE’s role in ERM?

A. Own risks

B. Manage risks

C. Provide assurance and advice

D. Approve risk responses

Answer: 

 

45.

Which assurance level is highest?

A. Limited

B. Negative

C. Reasonable

D. Moderate

Answer: 

 

46.

Which is an example of management override?

A. Policy violation

B. Unauthorized access

C. Bypassing controls

D. Segregation of duties

Answer: 

 

47.

Which is a safeguard for objectivity?

A. Incentives

B. Audit rotation

C. Management feedback

D. Bonus linkage

Answer: 

 

48.

Which engagement requires most professional judgment?

A. Checklist audit

B. Compliance audit

C. Risk-based audit

D. Inventory count

Answer: 

 

49.

Which area should internal audit avoid owning?

A. Risk assessment

B. Control evaluation

C. Risk mitigation decisions

D. Governance review

Answer: 

 

50.

Which scenario BEST demonstrates effective governance?

A. Strong management controls

B. Independent board oversight

C. Frequent audits

D. Detailed procedures

Answer: 

 

🔑 CIA PART 1 SUCCESS STRATEGY

✔ Choose oversight over execution

✔ Internal audit = assurance + advice, not management

✔ Board = independence, ethics, oversight

✔ Risk drives everything

 

www.gmsisuccess.in

Section C....

Below are logical, exam-oriented MCQ questions with clear reasoning, focused on Internal Control & Control Application, aligned with CIA Part 1 (2025), US CMA, and ACCA-style logic.

These test cause–effect, control purpose, and application, not rote memory.

 

Logical MCQs on Internal Control & Control Application

1.

Which control BEST prevents unauthorized payments?

A. Bank reconciliation

B. Segregation of duties between authorization and payment

C. Monthly expense analysis

D. Internal audit review

Answer: 

 

2.

A company performs bank reconciliation by the same employee who records cash receipts.

Which risk remains MOST significant?

A. Recording errors

B. Unauthorized payments

C. Cash theft concealment

D. Delayed reconciliation

Answer: 

 

3.

Which control is primarily a detective control?

A. Access passwords

B. Approval limits

C. Bank reconciliation

D. System validation checks

Answer: 

 

4.

A purchase order is approved after goods are received.

Which control principle is violated?

A. Authorization

B. Documentation

C. Timeliness

D. Segregation of duties

Answer: 


5.

Which control BEST ensures accuracy of data entry?

A. Physical inventory count

B. Edit checks in IT system

C. Supervisory review

D. Bank confirmation

Answer


6.

Which situation indicates a compensating control?

A. Password protection

B. Segregation of duties

C. Management review due to lack of segregation

D. Automated approval

Answer:

 

7.

Which control MOST reduces risk of duplicate vendor payments?

A. Vendor master file review

B. Three-way matching

C. Segregation of duties

D. Budget monitoring

Answer: 

8.

A company relies heavily on manual controls.

What is the PRIMARY risk?

A. High cost

B. System failure

C. Human error and inconsistency

D. Lack of documentation

Answer: 

9.

Which control activity addresses existence of inventory?

A. Inventory valuation review

B. Physical inventory count

C. Authorization of purchases

D. Inventory turnover analysis

Answer:

10.

Which control is MOST effective in preventing payroll fraud?

A. Payroll register review

B. Segregation of HR and payroll processing

C. Trend analysis of wages

D. External audit

Answer: 

11.

Which internal control component sets the foundation for all others?

A. Risk assessment

B. Control activities

C. Control environment

D. Monitoring

Answer: 

12.

Which control BEST prevents management override?

A. Policies

B. Internal audit

C. Board and audit committee oversight

D. Automated controls

Answer

13.

Which is an example of an IT application control?

A. Firewall

B. Password policy

C. Input validation check

D. Disaster recovery plan

Answer: 

14.

Which control ensures completeness of sales recording?

A. Credit approval

B. Pre-numbered invoices

C. Price authorization

D. Customer confirmation

Answer

15.

Which control is MOST suitable to detect fictitious vendors?

A. Three-way match

B. Periodic vendor master review

C. Bank reconciliation

D. Budget comparison

Answer: 

16.

Which control is preventive rather than detective?

A. Exception reports

B. Physical access restriction

C. Reconciliation

D. Variance analysis

Answer:

17.

Which risk increases when one person handles cash, records transactions, and reconciles bank accounts?

A. Recording delay

B. Fraud concealment

C. System error

D. Budget variance

Answer

18.

Which control activity addresses valuation of receivables?

A. Credit approval

B. Aging analysis and allowance review

C. Pre-numbered invoices

D. Cash receipts segregation

Answer: 

19.

Which monitoring activity provides ongoing assurance?

A. External audit

B. Annual internal audit

C. Continuous management review

D. Fraud investigation

Answer: 

20.

Which statement BEST describes an effective internal control system?

A. Eliminates all risks

B. Prevents all fraud

C. Provides reasonable assurance

D. Guarantees accuracy

Answer: 


🔍 Exam Logic to Remember

✔ Ask: What risk is being addressed?

✔ Prevention > Detection (but both are needed)

✔ Segregation of duties is the strongest control

✔ Internal control ≠ fraud elimination

 

www.gmsisuccess.in


Tuesday, December 9, 2025

Essay based Questions ⁉️ Internal Control system



Scenario-Based Essay Question

(CIA Part 1 – Internal Control System)

Question

Apex Retail Ltd. is a fast-growing company operating multiple stores across different regions. The board has recently observed an increase in inventory shrinkage, delayed financial reporting, and instances of unauthorized discounts offered by store managers.

The organization has basic internal control procedures, such as authorization limits and periodic stock counts. However, controls are inconsistently applied across locations, and management relies heavily on trust and informal supervision rather than documented procedures.

The Chief Audit Executive (CAE) has been asked to evaluate the effectiveness of the internal control system and educate senior management on its limitations and requirements.



Essay Question 1

Question

Based on the Apex Retail Ltd. scenario, identify the key internal control weaknesses and explain the risks arising from those weaknesses.

Answer


Essay Question 2

Question

Explain how management override of controls could occur in the given scenario and why it represents an inherent limitation of internal control.

Answer


Essay Question 3

Question

Discuss how segregation of duties could reduce inventory shrinkage at Apex Retail Ltd., and explain why segregation may still fail.

Answer


Essay Question 4

Question

Evaluate the importance of the control environment in addressing the weaknesses identified in the scenario.

Answer


Essay Question 5

Question

Explain why internal control systems must be continuously monitored and updated, with reference to the Apex Retail scenario.

Answer


Essay Question 6

Question

Describe the role of internal auditing in educating management about the limitations of internal control systems.

Answer


Essay Question 7

Question

Why is it not cost-effective to eliminate all internal control weaknesses at Apex Retail Ltd.?

Answer


CIA Part 1 Exam Tip

For essay questions, always:



Section B....

Required:

  1. Explain the concept and objectives of an internal control system.
  2. Discuss the inherent limitations of internal control.
  3. Explain the prerequisites for an effective internal control system.
  4. State the role of internal auditing in strengthening internal controls.



For your reference...

(CIA Part 1 – High-Scoring Structured Answer)


1. Concept and Objectives of Internal Control System

An internal control system is a process designed and implemented by the board of directors, management, and employees to provide reasonable assurance regarding the achievement of organizational objectives.

According to the COSO Framework, internal control aims to ensure:

In the case of Apex Retail Ltd., weak consistency in control application and lack of formal documentation indicate deficiencies in control design and implementation.


2. Inherent Limitations of Internal Control

Internal controls cannot provide absolute assurance due to the following inherent limitations:

  1. Human Judgment Errors
    Decisions may be flawed due to fatigue, lack of training, or misunderstanding.

  2. Management Override
    Senior management may bypass established controls for personal or operational reasons.

  3. Collusion
    Two or more employees can circumvent controls acting together, particularly in inventory and sales functions.

  4. Cost–Benefit Constraint
    Controls are implemented only when benefits outweigh costs.

  5. Change in Conditions
    Controls may become obsolete due to business expansion, technology changes, or new risks.

In Apex Retail, unauthorized discounts may result from management override or lack of preventive controls.


3. Prerequisites for an Effective Internal Control System

For internal controls to operate effectively, the following prerequisites must exist:

  1. Strong Control Environment

    • Ethical values and integrity
    • Clear organizational structure
    • Competent personnel
  2. Management Commitment (Tone at the Top)
    Management must consistently enforce controls and accountability.

  3. Clearly Defined Policies and Procedures
    Controls must be formally documented and communicated to employees.

  4. Adequate Segregation of Duties
    Authorization, custody, recording, and reconciliation functions should be separated.

  5. Continuous Monitoring and Review
    Controls must be monitored and updated to address emerging risks.

  6. Competent and Trained Employees
    Employees must understand and follow control responsibilities.

Apex Retail’s reliance on informal supervision undermines these prerequisites.


4. Role of Internal Auditing in Strengthening Internal Controls

Internal auditing adds value by:

The CAE plays a critical role in educating management about control limitations and promoting continuous improvement.


Key CIA Exam Keywords to Use

✔ Reasonable assurance
✔ COSO framework
Tone at the top
✔ Management override
✔ Segregation of duties
✔ Control environment
Inherent limitations


www.gmsisuccess.in


Scenerio Based Essay Question.. Activity base costing

 

Below is a US CMA–exam-oriented scenario (essay-type)


Scenario-Based Essay Question

(Activity-Based CostingUS CMA Exam Pattern)

Question:

Omega Manufacturing Inc. produces two products: Product Alpha (high volume, standardized) and Product Beta (low volume, customized). The company currently uses a traditional absorption costing system based on direct labor hours to allocate overhead.

Management has noticed that Product Beta appears highly profitable, while Product Alpha shows low margins, despite Alpha having stronger market demand and Beta facing pricing pressure. The CFO suspects that the overhead allocation method is distorting product costs and decides to evaluate Activity-Based Costing (ABC).

Omega identifies the following major activities and cost drivers:

Activity Cost Driver
Machine setup Number of setups
Quality inspection Number of inspections
Material handling Number of material moves
Machining Machine hours

Product Beta consumes a significantly higher proportion of setups, inspections, and material moves relative to its production volume.

Required:

  1. Explain why traditional costing may distort product costs in this scenario.
  2. Explain how Activity-Based Costing improves cost accuracy.
  3. Discuss managerial decisions that could improve after adopting ABC.
  4. Briefly state limitations of Activity-Based Costing.
  5. What is cost subsidization 
  6. Write 1 difference between Traditional costing and Activity base costing 
  7. Write two examples of methods of costing in Traditional costing system 
  8. Write difference between under costing and over costing, Also mention Product Alpha and Product Beta,which one is overcost and undercoat?
  9. Write 3 examples of Cost activity with suitable Cost Driver 
  10. Write 1 reason, Why Activity base costing is not suitable for one product, small business concern 
***Best wishes 🍀****/

www.gmsisuccess.in



Saturday, December 6, 2025

DOMAIN 1 – FOUNDATIONS OF INTERNAL AUDITING (35%) 50 Scenario-Based, Tricky & Exam-Style MCQs



DOMAIN 1 – FOUNDATIONS OF INTERNAL AUDITING (35%)

50 Scenario-Based, Tricky & Exam-Style MCQs


1. Independence

1. The CAE reports administratively to the COO and functionally to the audit committee. During an audit of operations, the COO pressures the CAE to delay issuing the final report. What is MOST appropriate?
A. Delay the report because operational matters fall under the COO.
B. Inform the audit committee about the pressure.
C. Remove the COO’s comments and issue the report immediately.
D. Escalate to external auditors.
Answer: 


2. Objectivity

2. An internal auditor previously worked in the procurement department two years ago. He is assigned to audit procurement this year. What should he do?
A. Proceed normally.
B. Refuse the assignment due to impairment.
C. Disclose the prior role and accept if CAE approves.
D. Perform only consulting services.
Answer: 


3. Mandatory Guidance

3. Which element of the IPPF is mandatory?
A. Practice Guides
B. Code of Ethics
C. Supplemental Guidance
D. Position Papers
Answer: 


4. Mission of Internal Audit

4. An audit team only reports control weaknesses but does not evaluate organizational value creation. What IPPF element is violated?
A. Core Principles
B. Mission of Internal Audit
C. Implementation Guidance
D. Performance Standards
Answer:


5. Core Principles

5. An audit report is technically accurate but delivered 4 months late, reducing management acceptance. Which Core Principle is violated?
A. Objectivity
B. Standards
C. Timeliness & Quality
D. Adds value & improves operations
Answer: 


6. Governance

6. Who is primarily responsible for establishing governance processes?
A. Internal audit
B. CAE
C. Senior management
D. Board
Answer: 


7. Governance Failures

7. During an audit, the internal auditor notices that whistleblowing cases are not reviewed for months. What should IA do first?
A. Report immediately to regulators.
B. Discuss with management responsible for governance.
C. Inform the board directly.
D. Investigate the cases themselves.
Answer: 


8. Three Lines Model

8. Who owns controls in the Three Lines Model?
A. Internal Audit (Third Line)
B. External Audit
C. Management (First Line)
D. Audit Committee
Answer: 


9. Board Responsibilities

9. The board requests internal audit to approve risk appetite. Is this appropriate?
A. Yes – IA has risk expertise.
B. No – setting risk appetite is management’s role.
C. Yes, if CAE signs only after consulting management.
D. Allowed only if noted in audit charter.
Answer: 


10. Charter Requirements

10. Who must approve the internal audit charter?
A. CAE only
B. CEO and CFO
C. Board
D. External auditors
Answer: 


11. Organizational Independence

11. The CAE’s performance appraisal is conducted solely by the CFO. What risk arises?
A. Fraud
B. Independence impairment
C. Inefficient audit planning
D. Conflict with HR
Answer: 


12. Internal Audit Plan

12. The CAE prepares the annual audit plan but excludes new IT systems because management says they are not risky. What should CAE do?
A. Accept management’s decision
B. Include IT risks based on IA’s own assessment
C. Ask external audit
D. Perform only consulting activities
Answer: 


13. Assurance vs Consulting

13. A department asks internal audit to design controls for a new system. What is allowed?
A. IA can design controls fully.
B. IA cannot give any advice.
C. IA can advise but cannot make decisions.
D. IA must decline completely.
Answer: 


14. Resource Management

14. CAE identifies lack of cybersecurity expertise in the team. What is the BEST action?
A. Cancel cybersecurity audits.
B. Outsource or co-source.
C. Rotate staff internally.
D. Report to HR only.
Answer: 


15. Proficiency

15. An auditor is assigned to audit a financial derivative valuation model but lacks expertise. The auditor should:
A. Learn quickly and continue.
B. Perform the audit anyway.
C. Decline or request expert support.
D. Skip testing complex areas.
Answer: 


16. Due Professional Care

16. During fieldwork, an auditor identifies a red flag of fraud but lacks evidence. What should they do?
A. Report fraud immediately
B. Ignore because evidence is limited
C. Extend testing based on risk
D. Transfer case to HR
Answer: 


17. Fraud Responsibility

17. Internal audit is reviewing an inventory theft case. Who is responsible for detecting fraud?
A. Internal audit
B. Every employee / management
C. External audit
D. Legal department
Answer: 


18. Engagement Objectives

18. Engagement objectives must align MOST with:
A. Audit budget
B. Management preferences
C. Risk assessment
D. Auditor experience
Answer: 


19. Planning

19. An auditor reviews prior audit reports before planning a new audit. Which standard is applied?
A. 1210
B. 2120
C. 2200
D. 2410
Answer: 


20. Risk Management Evaluation

20. IA notes that management identifies risks but does not document mitigation measures. IA should:
A. Document risk appetite
B. Provide assurance on risk processes
C. Create mitigation plans
D. Report only to CEO
Answer: 


21. Internal Control

21. IA observes that management performs controls inconsistently. Which COSO component is weak?
A. Monitoring
B. Control Environment
C. Control Activities
D. Information & Communication
Answer: 


22. Control Environment Weakness

22. Employees fear retaliation for reporting issues. Which is affected?
A. Control activities
B. Governance
C. Ethical culture
D. Risk tolerance
Answer: 


23. CAE Communication

23. The CEO wants to remove a finding from the draft report. CAE should:
A. Remove it
B. Inform audit committee
C. Delay reporting
D. Reduce severity
Answer: 


24. Quality Assurance (QAIP)

24. External quality assessment must be performed:
A. Annually
B. Every 5 years
C. Every 3 years
D. Optional
Answer: 


25. Non-conformance

25. If IA does not fully comply with Standards, what must occur?
A. Stop audits
B. Disclose non-conformance
C. Hire more auditors
D. Reset charter
Answer: 


26. Reporting Results

26. Who approves the final audit report?
A. CAE
B. Board
C. Process owner
D. Audit team
Answer: 


27. Engagement Supervision

27. Supervision ensures:
A. Recommendations are mandatory
B. Work meets objectives
C. Management cannot challenge findings
D. Auditors work independently
Answer: 


28. Document Retention

28. Working papers should support:
A. Auditor opinions
B. CAE job evaluation
C. External audit reliance
D. Risk register
Answer: 


29. Communication Quality

29. An audit report is technically correct but unclear. It violates:
A. Accuracy
B. Objectivity
C. Clarity
D. Finality
Answer: 


30. Follow-Up

30. Follow-up is required for:
A. All findings
B. Only high-risk findings
C. Only management requests
D. Only consulting results
Answer: 


31. Ethical Dilemma

31. An auditor is offered a gift during fieldwork. Best action?
A. Accept if below monetary threshold
B. Decline and disclose
C. Accept and inform CAE
D. Accept privately
Answer: 


32. Disclosing Impairment

32. Auditor’s spouse works in the audited department. What should auditor do first?
A. Decline assignment
B. Continue normally
C. Disclose to CAE
D. Investigate spouse’s work
Answer: 


33. Confidentiality

33. A former employee asks about findings in the audit report. Auditor must:
A. Provide summary
B. Provide report if they were responsible
C. Decline
D. Provide report after approval from management
Answer: 


34. Engagement Scope

34. Scope changes during audit due to new risk. Auditor should:
A. Ignore changes
B. Modify engagement objectives
C. Stop audit
D. Continue with old plan
Answer: 


35. Consulting Engagement

35. IA is asked to facilitate a risk workshop. This is:
A. Prohibited
B. Assurance service
C. Consulting service
D. Governance action
Answer: 


36. Assessing Culture

36. IA notices employees bypass controls due to pressure for deadlines. This indicates:
A. Fraud
B. Poor control environment
C. Good efficiency
D. Appropriate risk appetite
Answer: 


37. Governance Oversight

37. Audit committee asks IA to evaluate board performance. IA should:
A. Decline
B. Outsource
C. Perform assessment carefully
D. Only review documentation
Answer: 


38. Rotation

38. To maintain objectivity, auditor rotation is recommended when:
A. Auditor likes the process
B. Auditor has audited same area for years
C. Budget cuts occur
D. Findings are repetitive
Answer: 


39. Red Flags

39. During AP audit, an auditor finds multiple vendor accounts with similar bank details. Auditor should:
A. Report fraud immediately
B. Gather more evidence
C. Ignore
D. Delete vendors
Answer: 


40. Root Cause Analysis

40. Repeated control failures mostly relate to:
A. Symptoms
B. Root causes
C. Audit report format
D. Ethical standards
Answer: 


41. Workpaper Review

41. Manager reviewing workpapers must check:
A. Grammar
B. Evidence supports conclusions
C. Auditor handwriting
D. Location of files
Answer: 


42. Assurance Engagement

42. Who determines the level of assurance?
A. Auditor
B. CAE
C. Management
D. Audit committee
Answer: 


43. Conflict of Interest

43. An auditor owns shares in a company that is a major supplier. What is required?
A. Sell shares
B. Transfer auditor
C. Disclose & avoid the engagement
D. Ignore because minor issue
Answer: 


44. Continuous Auditing

44. Continuous monitoring is responsibility of:
A. IA
B. Management
C. Board
D. External auditors
Answer: 


45. Continuous Assurance

45. Continuous auditing focuses on:
A. Real-time monitoring
B. Financial statements
C. HR activities only
D. Bypassing controls
Answer: 


46. Consulting Independence

46. After providing consulting, IA must ensure:
A. They do not audit that area
B. They audit after 3 months
C. Consulting does not impair future assurance
D. No recommendations are given
Answer: 


47. Escalation

47. Serious risk not addressed by management must be reported to:
A. CFO
B. Audit committee
C. Process owners
D. HR
Answer: 


48. Fraud Investigation

48. IA is asked to perform fraud investigation. IA should:
A. Decline always
B. Perform investigation if competent
C. Transfer to external audit
D. Outsource completely
Answer: 


49. IT Controls

49. IA finds privileged access granted without approval. This is weakness in:
A. Change management
B. Logical access controls
C. Governance
D. Physical security
Answer: 


50. Alignment with Strategy

50. IA should evaluate whether governance:
A. Focuses on short-term profits
B. Aligns objectives, values, and performance
C. Avoids risks completely
D. Delegates all responsibility to auditors
Answer: 


www.gmsisuccess.in


ANSWERS....

50 Challenging & Scenario-Based MCQs on Domain 1 – Foundations of Internal Auditing (35%), fully aligned with the 2025 Revised CIA Part 1 syllabus.

Each question includes A–D options and correct answers with explanations.


DOMAIN 1 – FOUNDATIONS OF INTERNAL AUDITING (35%)

50 Scenario-Based, Tricky & Exam-Style MCQs


1. Independence

1. The CAE reports administratively to the COO and functionally to the audit committee. During an audit of operations, the COO pressures the CAE to delay issuing the final report. What is MOST appropriate?
A. Delay the report because operational matters fall under the COO.
B. Inform the audit committee about the pressure.
C. Remove the COO’s comments and issue the report immediately.
D. Escalate to external auditors.
Answer: B – Functional reporting ensures independence.


2. Objectivity

2. An internal auditor previously worked in the procurement department two years ago. He is assigned to audit procurement this year. What should he do?
A. Proceed normally.
B. Refuse the assignment due to impairment.
C. Disclose the prior role and accept if CAE approves.
D. Perform only consulting services.
Answer: C – Past involvement (within 1 year) is impairment; after 1 year disclosure is required.


3. Mandatory Guidance

3. Which element of the IPPF is mandatory?
A. Practice Guides
B. Code of Ethics
C. Supplemental Guidance
D. Position Papers
Answer: B


4. Mission of Internal Audit

4. An audit team only reports control weaknesses but does not evaluate organizational value creation. What IPPF element is violated?
A. Core Principles
B. Mission of Internal Audit
C. Implementation Guidance
D. Performance Standards
Answer: B – Mission focuses on value addition.


5. Core Principles

5. An audit report is technically accurate but delivered 4 months late, reducing management acceptance. Which Core Principle is violated?
A. Objectivity
B. Standards
C. Timeliness & Quality
D. Adds value & improves operations
Answer: D


6. Governance

6. Who is primarily responsible for establishing governance processes?
A. Internal audit
B. CAE
C. Senior management
D. Board
Answer: C


7. Governance Failures

7. During an audit, the internal auditor notices that whistleblowing cases are not reviewed for months. What should IA do first?
A. Report immediately to regulators.
B. Discuss with management responsible for governance.
C. Inform the board directly.
D. Investigate the cases themselves.
Answer: B


8. Three Lines Model

8. Who owns controls in the Three Lines Model?
A. Internal Audit (Third Line)
B. External Audit
C. Management (First Line)
D. Audit Committee
Answer: C


9. Board Responsibilities

9. The board requests internal audit to approve risk appetite. Is this appropriate?
A. Yes – IA has risk expertise.
B. No – setting risk appetite is management’s role.
C. Yes, if CAE signs only after consulting management.
D. Allowed only if noted in audit charter.
Answer: B


10. Charter Requirements

10. Who must approve the internal audit charter?
A. CAE only
B. CEO and CFO
C. Board
D. External auditors
Answer: C


11. Organizational Independence

11. The CAE’s performance appraisal is conducted solely by the CFO. What risk arises?
A. Fraud
B. Independence impairment
C. Inefficient audit planning
D. Conflict with HR
Answer: B


12. Internal Audit Plan

12. The CAE prepares the annual audit plan but excludes new IT systems because management says they are not risky. What should CAE do?
A. Accept management’s decision
B. Include IT risks based on IA’s own assessment
C. Ask external audit
D. Perform only consulting activities
Answer: B


13. Assurance vs Consulting

13. A department asks internal audit to design controls for a new system. What is allowed?
A. IA can design controls fully.
B. IA cannot give any advice.
C. IA can advise but cannot make decisions.
D. IA must decline completely.
Answer: C


14. Resource Management

14. CAE identifies lack of cybersecurity expertise in the team. What is the BEST action?
A. Cancel cybersecurity audits.
B. Outsource or co-source.
C. Rotate staff internally.
D. Report to HR only.
Answer: B


15. Proficiency

15. An auditor is assigned to audit a financial derivative valuation model but lacks expertise. The auditor should:
A. Learn quickly and continue.
B. Perform the audit anyway.
C. Decline or request expert support.
D. Skip testing complex areas.
Answer: C


16. Due Professional Care

16. During fieldwork, an auditor identifies a red flag of fraud but lacks evidence. What should they do?
A. Report fraud immediately
B. Ignore because evidence is limited
C. Extend testing based on risk
D. Transfer case to HR
Answer: C


17. Fraud Responsibility

17. Internal audit is reviewing an inventory theft case. Who is responsible for detecting fraud?
A. Internal audit
B. Every employee / management
C. External audit
D. Legal department
Answer: B


18. Engagement Objectives

18. Engagement objectives must align MOST with:
A. Audit budget
B. Management preferences
C. Risk assessment
D. Auditor experience
Answer: C


19. Planning

19. An auditor reviews prior audit reports before planning a new audit. Which standard is applied?
A. 1210
B. 2120
C. 2200
D. 2410
Answer: C – Engagement Planning


20. Risk Management Evaluation

20. IA notes that management identifies risks but does not document mitigation measures. IA should:
A. Document risk appetite
B. Provide assurance on risk processes
C. Create mitigation plans
D. Report only to CEO
Answer: B


21. Internal Control

21. IA observes that management performs controls inconsistently. Which COSO component is weak?
A. Monitoring
B. Control Environment
C. Control Activities
D. Information & Communication
Answer: C


22. Control Environment Weakness

22. Employees fear retaliation for reporting issues. Which is affected?
A. Control activities
B. Governance
C. Ethical culture
D. Risk tolerance
Answer: C


23. CAE Communication

23. The CEO wants to remove a finding from the draft report. CAE should:
A. Remove it
B. Inform audit committee
C. Delay reporting
D. Reduce severity
Answer: B


24. Quality Assurance (QAIP)

24. External quality assessment must be performed:
A. Annually
B. Every 5 years
C. Every 3 years
D. Optional
Answer: B


25. Non-conformance

25. If IA does not fully comply with Standards, what must occur?
A. Stop audits
B. Disclose non-conformance
C. Hire more auditors
D. Reset charter
Answer: B


26. Reporting Results

26. Who approves the final audit report?
A. CAE
B. Board
C. Process owner
D. Audit team
Answer: A


27. Engagement Supervision

27. Supervision ensures:
A. Recommendations are mandatory
B. Work meets objectives
C. Management cannot challenge findings
D. Auditors work independently
Answer: B


28. Document Retention

28. Working papers should support:
A. Auditor opinions
B. CAE job evaluation
C. External audit reliance
D. Risk register
Answer: A


29. Communication Quality

29. An audit report is technically correct but unclear. It violates:
A. Accuracy
B. Objectivity
C. Clarity
D. Finality
Answer: C


30. Follow-Up

30. Follow-up is required for:
A. All findings
B. Only high-risk findings
C. Only management requests
D. Only consulting results
Answer: A


31. Ethical Dilemma

31. An auditor is offered a gift during fieldwork. Best action?
A. Accept if below monetary threshold
B. Decline and disclose
C. Accept and inform CAE
D. Accept privately
Answer: B


32. Disclosing Impairment

32. Auditor’s spouse works in the audited department. What should auditor do first?
A. Decline assignment
B. Continue normally
C. Disclose to CAE
D. Investigate spouse’s work
Answer: C


33. Confidentiality

33. A former employee asks about findings in the audit report. Auditor must:
A. Provide summary
B. Provide report if they were responsible
C. Decline
D. Provide report after approval from management
Answer: C


34. Engagement Scope

34. Scope changes during audit due to new risk. Auditor should:
A. Ignore changes
B. Modify engagement objectives
C. Stop audit
D. Continue with old plan
Answer: B


35. Consulting Engagement

35. IA is asked to facilitate a risk workshop. This is:
A. Prohibited
B. Assurance service
C. Consulting service
D. Governance action
Answer: C


36. Assessing Culture

36. IA notices employees bypass controls due to pressure for deadlines. This indicates:
A. Fraud
B. Poor control environment
C. Good efficiency
D. Appropriate risk appetite
Answer: B


37. Governance Oversight

37. Audit committee asks IA to evaluate board performance. IA should:
A. Decline
B. Outsource
C. Perform assessment carefully
D. Only review documentation
Answer: C


38. Rotation

38. To maintain objectivity, auditor rotation is recommended when:
A. Auditor likes the process
B. Auditor has audited same area for years
C. Budget cuts occur
D. Findings are repetitive
Answer: B


39. Red Flags

39. During AP audit, an auditor finds multiple vendor accounts with similar bank details. Auditor should:
A. Report fraud immediately
B. Gather more evidence
C. Ignore
D. Delete vendors
Answer: B


40. Root Cause Analysis

40. Repeated control failures mostly relate to:
A. Symptoms
B. Root causes
C. Audit report format
D. Ethical standards
Answer: B


41. Workpaper Review

41. Manager reviewing workpapers must check:
A. Grammar
B. Evidence supports conclusions
C. Auditor handwriting
D. Location of files
Answer: B


42. Assurance Engagement

42. Who determines the level of assurance?
A. Auditor
B. CAE
C. Management
D. Audit committee
Answer: A


43. Conflict of Interest

43. An auditor owns shares in a company that is a major supplier. What is required?
A. Sell shares
B. Transfer auditor
C. Disclose & avoid the engagement
D. Ignore because minor issue
Answer: C


44. Continuous Auditing

44. Continuous monitoring is responsibility of:
A. IA
B. Management
C. Board
D. External auditors
Answer: B


45. Continuous Assurance

45. Continuous auditing focuses on:
A. Real-time monitoring
B. Financial statements
C. HR activities only
D. Bypassing controls
Answer: A


46. Consulting Independence

46. After providing consulting, IA must ensure:
A. They do not audit that area
B. They audit after 3 months
C. Consulting does not impair future assurance
D. No recommendations are given
Answer: C


47. Escalation

47. Serious risk not addressed by management must be reported to:
A. CFO
B. Audit committee
C. Process owners
D. HR
Answer: B


48. Fraud Investigation

48. IA is asked to perform fraud investigation. IA should:
A. Decline always
B. Perform investigation if competent
C. Transfer to external audit
D. Outsource completely
Answer: B


49. IT Controls

49. IA finds privileged access granted without approval. This is weakness in:
A. Change management
B. Logical access controls
C. Governance
D. Physical security
Answer: B


50. Alignment with Strategy

50. IA should evaluate whether governance:
A. Focuses on short-term profits
B. Aligns objectives, values, and performance
C. Avoids risks completely
D. Delegates all responsibility to auditors
Answer: B


www.gmsisuccess.in