🇺🇸 Certified Internal Auditor (CIA) · flashcards
Certified Internal Auditor (CIA) Governance, Risk, Control, and Fraud (Part 1) Flashcards
50 question-and-answer cards covering Governance, Risk, Control, and Fraud (Part 1) as it is examined in Certified Internal Auditor (CIA). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.
24 sample cards from the Governance, Risk, Control, and Fraud (Part 1) deck
Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.
What is a key risk indicator (KRI)?
A metric used to provide an early signal of increasing risk exposure in an area, enabling proactive management.
What are the three steps of the risk assessment process?
Risk identification (what could happen), risk analysis (likelihood and impact), and risk evaluation (compare to criteria/appetite to prioritize responses).
What is a risk and control matrix (or risk map/heat map) used for?
A heat map plots risks by likelihood and impact to visualize and prioritize them; a risk and control matrix links each risk to its mitigating controls.
What is the difference between qualitative and quantitative risk analysis?
Qualitative uses descriptive scales (high/medium/low) and judgment; quantitative assigns numeric/monetary values and probabilities (e.g., expected loss, simulations).
According to IIA Standards, what is internal audit's role in organizational risk management?
To evaluate the effectiveness of and contribute to the improvement of risk management processes, providing assurance—not to own or manage risks (which is management's responsibility).
What risk management activities should internal audit NOT undertake to preserve objectivity?
Setting risk appetite, owning/managing risks, making risk responses/decisions for management, or being accountable for risk management. These are management's responsibilities.
What is a risk-based audit plan?
An audit plan that prioritizes and allocates audit resources to the areas with the highest assessed risk to the organization's objectives.
How does the COSO Internal Control–Integrated Framework define internal control?
A process, effected by an entity's board, management, and other personnel, designed to provide reasonable assurance regarding achievement of objectives in operations, reporting, and compliance.
What are the five components of the COSO Internal Control framework?
1) Control environment; 2) Risk assessment; 3) Control activities; 4) Information and communication; 5) Monitoring activities.
How many principles underlie the five components of the 2013 COSO Internal Control framework?
17 principles (distributed across the five components).
What is the control environment component of COSO?
The set of standards, processes, and structures that provide the foundation for internal control—integrity/ethical values, board oversight, structure, competence, and accountability.
Distinguish preventive, detective, and corrective controls with an example of each.
Preventive stops errors/fraud before they occur (e.g., segregation of duties); detective finds them after occurrence (e.g., reconciliations); corrective fixes the problem (e.g., backups/restoration, error correction procedures).
What is the difference between a manual control and an automated (application) control?
A manual control is performed by people (e.g., manual approval); an automated control is performed by IT systems (e.g., system edit checks, automatic calculations).
What are general controls versus application controls in IT?
General controls apply across the IT environment (access security, change management, operations); application controls are specific to individual applications/transactions (input, processing, output controls).
What are entity-level controls versus transaction-level controls?
Entity-level controls operate broadly across the organization (e.g., tone at the top, policies, monitoring); transaction-level controls operate at the process/activity level (e.g., approvals, reconciliations).
What is segregation (separation) of duties and which functions should be separated?
Dividing responsibilities so no single person controls a whole transaction—separating authorization, recording (custody of records), custody of assets, and reconciliation/review.
What does 'reasonable assurance' mean regarding internal control?
Internal control can provide only reasonable—not absolute—assurance of achieving objectives because of inherent limitations like human error, collusion, management override, and cost-benefit constraints.
What are the inherent limitations of internal control?
Human error/judgment lapses, collusion among individuals, management override of controls, and cost-benefit trade-offs that limit control implementation.
What does it mean to evaluate the design effectiveness versus operating effectiveness of a control?
Design effectiveness asks whether the control, if operating as intended, would prevent/detect the risk; operating effectiveness asks whether the control actually functioned as designed over the period.
What is the difference between a control deficiency, a significant deficiency, and a material weakness?
A control deficiency is any flaw in design or operation; a significant deficiency is serious enough to merit attention by those overseeing reporting; a material weakness creates a reasonable possibility that a material misstatement won't be prevented or detected timely.
What three elements make up the 'fraud triangle'?
Pressure/incentive (motive), opportunity (weak controls allowing it), and rationalization (justifying the act). All three typically must be present for fraud to occur.
What are the three major categories of occupational fraud per the ACFE?
Asset misappropriation (theft/misuse of assets), corruption (e.g., bribery, conflicts of interest), and financial statement fraud (intentional misstatement). Asset misappropriation is most common; financial statement fraud is costliest.
What is internal audit's responsibility regarding fraud under the IIA Standards?
To have sufficient knowledge to evaluate the risk of fraud and how the organization manages it, remain alert to fraud indicators (red flags), and evaluate fraud risk—while investigation is typically management's responsibility (internal audit may assist).
What are the four principles of the IIA Code of Ethics and its two main parts?
The four principles are Integrity, Objectivity, Confidentiality, and Competency; the Code consists of (1) Principles and (2) Rules of Conduct that apply them to internal auditors.
What this deck covers
The Governance, Risk, Control, and Fraud (Part 1) deck follows the Certified Internal Auditor (CIA) Governance, Risk, Control, and Fraud (Part 1) syllabus — 4 chapters and 13 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 12.5 cards per chapter.
Answers are written to be recallable, not just readable — averaging about 179 characters, which is long enough to carry the reasoning and short enough to say out loud.
A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.
Governance, Risk, Control, and Fraud (Part 1) flashcards FAQ
How many Governance, Risk, Control, and Fraud (Part 1) flashcards are in this Certified Internal Auditor (CIA) deck?
50 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.
Are these Certified Internal Auditor (CIA) flashcards free?
Yes. The preview here is free to read with no signup, and the full 50-card deck is free inside the Examius app.
What do the Governance, Risk, Control, and Fraud (Part 1) cards cover?
They follow the Certified Internal Auditor (CIA) Governance, Risk, Control, and Fraud (Part 1) syllabus — 4 chapters and 13 topics — so the questions track what is actually examinable.
How should I use these flashcards?
Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.