🇺🇸 Certified Internal Auditor (CIA) · subject
Certified Internal Auditor (CIA) Governance, Risk, Control, and Fraud (Part 1) Syllabus
Every chapter and topic of Governance, Risk, Control, and Fraud (Part 1) examined in Certified Internal Auditor (CIA) — 4 chapters, 13 topics and 26 sub-topics, plus 50 flashcards written against it.
Governance, Risk, Control, and Fraud (Part 1) syllabus — full chapter and topic list
Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Governance, Risk, Control, and Fraud (Part 1) in Certified Internal Auditor (CIA), not a summary of it.
-
Organizational Governance
3 topics- Governance Structures and Roles
- Board, audit committee, and management responsibilities
- Internal audit's assurance role in governance
- Ethics and Organizational Culture
- Tone at the top
- Whistleblower and ethics programs
- The Three Lines Model
- Operational management, risk/compliance, internal audit
- Coordination and assurance mapping
- Governance Structures and Roles
-
Risk Management
4 topics- Risk Management Frameworks
- COSO ERM framework
- ISO 31000 principles
- Risk Concepts
- Risk appetite and tolerance
- Inherent vs. residual risk
- Risk Assessment Process
- Identification, analysis, and response
- Risk likelihood and impact rating
- Internal Audit's Role in Risk Management
- Assurance on the risk process
- Safeguards when consulting on risk
- Risk Management Frameworks
-
Internal Control
3 topics- Control Frameworks
- COSO Internal Control–Integrated Framework
- Five components and seventeen principles
- Types and Categories of Controls
- Preventive, detective, and corrective
- Manual vs. automated controls
- Evaluating Control Effectiveness
- Control design vs. operating effectiveness
- Identifying control deficiencies
- Control Frameworks
-
Fraud Risk and Professional Ethics
3 topics- Fraud Concepts
- The fraud triangle
- Asset misappropriation, corruption, financial reporting fraud
- Internal Audit's Role in Fraud
- Fraud risk assessment
- Red flags and detection techniques
- The IIA Code of Ethics
- Integrity, objectivity, confidentiality, competency
- Rules of conduct
- Fraud Concepts
Governance, Risk, Control, and Fraud (Part 1) flashcards for Certified Internal Auditor (CIA)
22 of 50 cards from the Governance, Risk, Control, and Fraud (Part 1) deck — real questions with worked answers.
What is organizational governance as defined by the IIA?
The combination of processes and structures implemented by the board to inform, direct, manage, and monitor the organization's activities toward achieving its objectives.
What are the three primary parties in a typical governance structure and their core roles?
The board (oversight and direction), senior management (execution and day-to-day management), and stakeholders (owners/others with an interest). Internal and external auditors provide assurance.
What is the primary role of the board of directors in governance?
To provide oversight and strategic direction, set risk appetite/tone, hold management accountable, and protect stakeholder interests.
What is the purpose of an audit committee within governance?
A subcommittee of the board that oversees financial reporting, the internal and external audit functions, internal control, and compliance, providing independent oversight of management.
To whom should the chief audit executive (CAE) report functionally and administratively for optimal independence?
Functionally to the board/audit committee, and administratively to senior management (e.g., the CEO).
What is 'tone at the top' and why does it matter to governance?
The ethical climate and example set by the board and senior management; it strongly influences organizational culture, employee behavior, and the effectiveness of controls.
Define organizational culture in the context of governance.
The shared values, attitudes, beliefs, and behaviors that shape how members of an organization act; it underpins ethics and the control environment.
What are the typical components of an effective ethics/compliance program?
A code of conduct, ethics training, a confidential whistleblower/reporting mechanism (hotline), investigation and discipline procedures, and ongoing monitoring.
What is the purpose of a whistleblower hotline?
To provide a confidential, often anonymous channel for employees and stakeholders to report unethical or fraudulent behavior without fear of retaliation.
What is the difference between ethics and compliance?
Ethics concerns doing what is morally right based on values; compliance concerns adhering to laws, regulations, and policies. Ethical behavior may exceed mere legal compliance.
In the Three Lines Model, what does the first line do?
Operational management that owns and manages risks and controls directly—delivering products/services to customers and managing the associated risks day to day.
In the Three Lines Model, what does the second line do?
Management functions that provide expertise, support, monitoring, and challenge on risk-related matters (e.g., risk management, compliance, quality).
In the Three Lines Model, what does the third line do?
Internal audit, which provides independent and objective assurance and advice on the adequacy and effectiveness of governance, risk management, and control.
In the 2020 IIA Three Lines Model, what is the role of the governing body?
Accountability to stakeholders for oversight; it establishes structures and processes, delegates responsibilities, and ensures resources to achieve objectives—engaging both management and internal audit.
How does the 2020 Three Lines Model differ from the older 'Three Lines of Defense' model?
It emphasizes the contribution of each line to achieving objectives (not just defense), shows roles/relationships rather than rigid silos, and explicitly includes the governing body and external assurance providers.
Where do external assurance providers fit relative to the Three Lines Model?
Outside the three lines; they provide additional independent assurance to satisfy stakeholder and regulatory expectations (e.g., external auditors, regulators).
What is enterprise risk management (ERM)?
A structured, organization-wide process to identify, assess, respond to, and monitor risks that could affect achievement of objectives, integrated with strategy and performance.
Name the five components of the COSO ERM (2017) framework.
1) Governance and culture; 2) Strategy and objective-setting; 3) Performance; 4) Review and revision; 5) Information, communication, and reporting.
What are the four risk categories addressed by ISO 31000 / ERM objective-setting (strategic, operational, reporting, compliance)?
Strategic (high-level goals), operations (effective and efficient use of resources), reporting (reliability of reporting), and compliance (adherence to laws and regulations).
What is the core process flow recommended by ISO 31000 for managing risk?
Establish context, then risk assessment (identification, analysis, evaluation), risk treatment, plus ongoing communication/consultation and monitoring/review.
Define inherent risk.
The risk to an entity in the absence of any actions management might take to alter the risk's likelihood or impact (i.e., before controls).
Define residual risk.
The risk that remains after management has taken action (implemented controls/responses) to modify the risk.
See more Governance, Risk, Control, and Fraud (Part 1) flashcards →
Planning Governance, Risk, Control, and Fraud (Part 1) for Certified Internal Auditor (CIA)
Governance, Risk, Control, and Fraud (Part 1) is about 20% of the Certified Internal Auditor (CIA) syllabus by topic count — 13 of 66 topics, spread over 4 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 15 hours.
The heaviest chapters are Risk Management (4 topics), Organizational Governance (3 topics), Internal Control (3 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.
Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.
Governance, Risk, Control, and Fraud (Part 1) (Certified Internal Auditor (CIA)) FAQ
What is in the Certified Internal Auditor (CIA) Governance, Risk, Control, and Fraud (Part 1) syllabus?
Governance, Risk, Control, and Fraud (Part 1) is split into 4 chapters — Organizational Governance, Risk Management, Internal Control and Fraud Risk and Professional Ethics, containing 13 topics and 26 sub-topics in total.
How is Governance, Risk, Control, and Fraud (Part 1) structured in the Certified Internal Auditor (CIA) syllabus?
4 chapters. Governance, Risk, Control, and Fraud (Part 1) accounts for about 20% of the topics in the whole Certified Internal Auditor (CIA) syllabus (13 of 66).
How long should I spend on Governance, Risk, Control, and Fraud (Part 1) for Certified Internal Auditor (CIA)?
Budget around 15 hours for a first pass through Governance, Risk, Control, and Fraud (Part 1) — about 45 minutes per topic plus 12 minutes per sub-topic across its 13 topics. Add revision cycles on top.
Are there flashcards for Certified Internal Auditor (CIA) Governance, Risk, Control, and Fraud (Part 1)?
Yes — a 50-card Governance, Risk, Control, and Fraud (Part 1) deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.