🇺🇸 Certified Internal Auditor (CIA) · subject
Certified Internal Auditor (CIA) Performing the Engagement (Part 2) Syllabus
Every chapter and topic of Performing the Engagement (Part 2) examined in Certified Internal Auditor (CIA) — 3 chapters, 11 topics and 22 sub-topics, plus 52 flashcards written against it.
Performing the Engagement (Part 2) syllabus — full chapter and topic list
Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Performing the Engagement (Part 2) in Certified Internal Auditor (CIA), not a summary of it.
-
Engagement Planning
3 topics- Objectives and Scope
- Preliminary engagement risk assessment
- Defining boundaries and exclusions
- Engagement Risk and Control Assessment
- Identifying key risks and controls
- Control criteria
- Engagement Work Program
- Designing procedures and tests
- Resource and time allocation
- Objectives and Scope
-
Conducting the Engagement
4 topics- Gathering Evidence
- Sufficiency, reliability, relevance
- Observation, inquiry, confirmation, inspection
- Analytical and Audit Procedures
- Analytical review and trend analysis
- Statistical and judgmental sampling
- Data Analytics and Technology
- Computer-assisted audit techniques
- Continuous auditing and monitoring
- Documentation and Workpapers
- Workpaper standards and review
- Retention and confidentiality
- Gathering Evidence
-
Findings, Communication, and Follow-Up
4 topics- Developing Findings
- Criteria, condition, cause, effect, recommendation
- Root cause analysis
- Engagement Communications
- Accurate, objective, clear, concise reporting
- Interim and final reports
- Errors, Omissions, and Disclosures
- Correcting and reissuing reports
- Disclosing nonconformance
- Monitoring and Follow-Up
- Tracking management action plans
- Accepting residual risk and escalation
- Developing Findings
Performing the Engagement (Part 2) flashcards for Certified Internal Auditor (CIA)
21 of 52 cards from the Performing the Engagement (Part 2) deck — real questions with worked answers.
What are the two components that define the boundaries of an internal audit engagement?
The objectives (what the engagement aims to accomplish) and the scope (the extent, boundaries, activities, locations, time period, and resources covered).
Per IIA Standards, what must engagement objectives reflect for the activity being reviewed?
They must address the risks, controls, and governance processes associated with the activities under review.
When establishing scope, what must internal auditors consider regarding relevant systems, records, personnel, and property?
The scope must be sufficient to satisfy the engagement objectives, including relevant systems, records, personnel, and physical property (even those under the control of third parties).
What is a scope limitation in an internal audit engagement?
A restriction placed on the engagement that prevents the auditor from accomplishing objectives as planned (e.g., denied access to records, inadequate resources, or time constraints); significant ones must be communicated, usually in writing, to senior management and the board.
What is the difference between engagement objectives and engagement procedures?
Objectives are broad statements of what the engagement intends to achieve; procedures are the specific steps and techniques (tests) performed to gather evidence and meet those objectives.
During an engagement, what is a preliminary (risk) assessment used to determine?
The areas of significant risk that warrant audit attention, helping focus the engagement objectives, scope, and the nature/extent of testing on higher-risk areas.
Define inherent risk in the context of an audit engagement.
The susceptibility of an activity or assertion to a material error or loss before considering the effect of any related controls.
Define residual risk.
The risk that remains after management takes action (implements controls) to reduce the impact and likelihood of an adverse event, including the risk that controls are not effective.
What is the formula relationship between inherent risk, controls, and residual risk?
Residual risk = Inherent risk reduced by the effect of controls (i.e., Inherent risk minus the risk mitigated by controls).
What two dimensions are used to assess and prioritize risks during an engagement?
Likelihood (probability of occurrence) and impact (significance/consequence), often combined in a risk map or heat map.
In a control assessment, what is the difference between control design effectiveness and operating effectiveness?
Design effectiveness asks whether the control, if operating as intended, would prevent or detect the risk; operating effectiveness asks whether the control actually functions as designed over the relevant period.
What are the three main categories of controls by function (timing relative to an event)?
Preventive controls (stop errors before they occur), detective controls (identify errors after they occur), and corrective controls (fix errors and prevent recurrence).
What is a compensating (mitigating) control?
A control that reduces risk when the primary control is absent, weak, or not cost-effective, providing alternative assurance over the same risk.
What is a key control versus a secondary (compensating) control?
A key control is essential and, if it fails, the objective likely will not be met or the failure won't be detected timely; a secondary control reduces residual risk but is not by itself essential to achieving the objective.
What is the purpose of an engagement work program?
It documents the procedures for identifying, analyzing, evaluating, and recording information during the engagement, ensuring objectives are met consistently and providing a basis for supervision and review.
Per IIA Standards, when must engagement work programs be approved, and by whom?
They must be approved by the chief audit executive (or designee) prior to the start of engagement work; adjustments must be approved promptly.
What essential elements should a well-designed engagement work program include?
Engagement objectives, scope, the specific procedures/steps to gather and analyze evidence, the basis for sample selection, and a means to document who performed and reviewed the work.
Why might a work program for a consulting (advisory) engagement differ from one for an assurance engagement?
Consulting work programs vary in form and content based on the nature of the engagement and may be more flexible, whereas assurance work programs are more standardized to support an objective assessment.
What are the four attributes that audit evidence should possess to be reliable and useful?
Evidence should be sufficient, reliable, relevant, and useful (the SRRU criteria).
What does 'sufficient' mean as an attribute of audit evidence?
There is enough factual, adequate, and convincing evidence that a prudent, informed person would reach the same conclusions as the auditor.
What does 'reliable' mean as an attribute of audit evidence?
The evidence is the best attainable information through the use of appropriate engagement techniques; reliability generally increases with auditor-obtained, externally sourced, and corroborated evidence.
Planning Performing the Engagement (Part 2) for Certified Internal Auditor (CIA)
Performing the Engagement (Part 2) is about 17% of the Certified Internal Auditor (CIA) syllabus by topic count — 11 of 66 topics, spread over 3 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 15 hours.
The heaviest chapters are Conducting the Engagement (4 topics), Findings, Communication, and Follow-Up (4 topics), Engagement Planning (3 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.
Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.
Performing the Engagement (Part 2) (Certified Internal Auditor (CIA)) FAQ
What is in the Certified Internal Auditor (CIA) Performing the Engagement (Part 2) syllabus?
Performing the Engagement (Part 2) is split into 3 chapters — Engagement Planning, Conducting the Engagement and Findings, Communication, and Follow-Up, containing 11 topics and 22 sub-topics in total.
How many chapters are there in Performing the Engagement (Part 2) for Certified Internal Auditor (CIA)?
3 chapters. Performing the Engagement (Part 2) accounts for about 17% of the topics in the whole Certified Internal Auditor (CIA) syllabus (11 of 66).
How long should I spend on Performing the Engagement (Part 2) for Certified Internal Auditor (CIA)?
Budget around 15 hours for a first pass through Performing the Engagement (Part 2) — about 45 minutes per topic plus 12 minutes per sub-topic across its 11 topics. Add revision cycles on top.
Are there flashcards for Certified Internal Auditor (CIA) Performing the Engagement (Part 2)?
Yes — a 52-card Performing the Engagement (Part 2) deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.