You’ve hit CIA Part 2, "Practice of Internal Auditing," and you're staring down the new Global Internal Audit Standards™, trying to cram every requirement. That’s the #1 trap. Candidates think this part is about memorizing the rulebook, only to get paralyzed by a scenario question that doesn't ask what the rule is, but how a professional applies it under pressure. The real challenge isn’t recalling a standard number; it’s knowing what to do when management pushes back on your findings and the evidence feels incomplete.
CIA Part 2 tests your ability to apply the IIA's Global Internal Audit Standards™ (GIAS) throughout an engagement. It covers Managing the Internal Audit Activity (20%), Planning the Engagement (20%), Performing the Engagement (40%), and Communicating Results & Monitoring Progress (20%). Passing requires applying professional judgment in scenarios, not just recalling rules.
Key facts
- Exam name: Certified Internal Auditor (CIA), Part 2: Practice of Internal Auditing
- Official body: The Institute of Internal Auditors (IIA)
- Exam format: 100 multiple-choice questions
- Exam duration: 120 minutes (2 hours)
- Passing score: 600 on a scale of 250-750
- Governing standards (2026 exams): The Global Internal Audit Standards™ (GIAS)
- Key topics: Engagement planning, fieldwork, communication, risk management, COSO frameworks
CIA Part 2 Syllabus Breakdown: What the Exam Really Tests
Think of Part 1 as the "what" and Part 2 as the "how." This section moves beyond foundational concepts and tests your proficiency in the four key phases of an internal audit engagement. The IIA wants to know if you can think and act like an internal auditor when faced with realistic workplace pressures.
The exam syllabus is weighted across four domains:
Studying for CIA CIA2? Benchmark your score in 5 minutes.
Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.
- Managing the Internal Audit Activity (20%): This covers the strategic and operational management of the function. It's about the Internal Audit Charter, the Quality Assurance and Improvement Program (QAIP), and how the Chief Audit Executive (CAE) interacts with the board and senior management.
- Planning the Engagement (20%): Here, you'll be tested on setting engagement objectives, determining the required scope and resources, and performing a risk assessment to guide the audit plan.
- Performing the Engagement (40%): This is the largest domain. It's the "boots on the ground" work of gathering sufficient, reliable, relevant, and useful evidence, applying analytical procedures, creating workpapers, and drawing sound conclusions.
- Communicating Engagement Results and Monitoring Progress (20%): This covers drafting audit reports, communicating findings to management, formulating recommendations, and the critical process of following up to ensure management's action plans are implemented.
Your success on Part 2 depends entirely on applying the standards with professional judgment. Ready to see how your judgment stacks up? Test yourself with VoraPrep's adaptive CIA practice questions and get instant feedback with detailed explanations.
The New Global Internal Audit Standards™ (GIAS): Your 2026 Exam Blueprint
This is critical: As of January 9, 2025, the old IPPF (with its Attribute and Performance standards) is replaced by the new Global Internal Audit Standards™ (GIAS). If you are sitting for the exam in 2026, you must use the new GIAS. Studying from outdated materials is a guaranteed way to fail.Forget the old 1000/2000 series numbering. The new structure is organized into five domains. For Part 2, you need to know how they apply in practice:
| GIAS Domain | Title | What It Really Means for Your Exam |
|---|---|---|
| Domain I | Ethics and Professionalism | The bedrock. This elevates the Code of Ethics and covers Due Professional Care. Expect scenario questions testing your integrity and competence under pressure. |
| Domain II | Governing the Internal Audit Function | How the function is structured for success. This covers the Internal Audit Charter, Independence, and the CAE's relationship with the Board. |
| Domain III | Managing the Internal Audit Function | How the CAE runs the department. Think strategic planning, resource management, and the all-important Quality Assurance and Improvement Program (QAIP). |
| Domain IV | Performing Internal Audit Services | The "how-to" of an audit. This covers engagement planning, gathering evidence (sufficiency and appropriateness), and documenting work. |
| Domain V | Communicating and Following Up | The final stages. This includes reporting results, forming conclusions and recommendations, and monitoring management's action plans. |
Your focus for Part 2 should be on Domains III, IV, and V, with a strong understanding of Independence (Domain II) and the Code of Ethics (Domain I).
The IIA Code of Ethics: The Foundation of Judgment
The GIAS places the Code of Ethics front and center. It's not just a list to memorize; it's the basis for every judgment call you'll be tested on. You must know the four principles and be able to apply their associated Rules of Conduct in a scenario.
- Integrity: Establishes trust and provides the basis for reliance on your judgment.
- Objectivity: Requires you to be unbiased in your work, avoiding all conflicts of interest.
- Confidentiality: Demands respect for the value and ownership of information you receive.
- Competence: Means you only perform services you have the necessary knowledge, skills, and experience for.
An exam question won't ask, "What is objectivity?" It will describe a situation—like being asked to audit a system you helped design—and expect you to identify the specific ethical principle that is impaired.
A Decision Tree for Independence and Objectivity Traps
The terms "independence" and "objectivity" are often confused by candidates, which is a fatal mistake on the exam. The examiners love to test this distinction.
- Independence is organizational. It belongs to the internal audit function. It’s about the CAE having a direct reporting line to the board and freedom from management interference. (GIAS Domain II)
- Objectivity is individual. It belongs to the auditor. It's an unbiased mental attitude. (GIAS Domain I & II)
Use this decision tree to navigate scenario questions:
Condition: An auditor is assigned to an engagement. Is there an impairment?- Question 1: Does the issue affect the entire audit department's freedom or reporting structure?
- YES: This is an independence issue.
- Example: The CAE reports functionally to the CFO instead of the Audit Committee. This threatens the entire department's ability to audit impartially.
- Action: The impairment must be disclosed to the board. The audit charter should be corrected to reflect a direct reporting line.
- NO, the issue is specific to one auditor's relationship with the auditee: Proceed to Question 2.
- Question 2: Does the individual auditor have a conflict of interest, bias, or prior responsibility for the area being audited?
- YES: This is an objectivity issue.
- Example: The auditor, Jane, was the acting manager of the payroll department for six months last year. She is now assigned to audit payroll.
- Tempting Wrong Answer: "Jane can perform the audit if she discloses her prior role in the final report."
- Correct Approach: This is a clear impairment of objectivity. Standard 2.2 requires internal auditors to be objective. The generally accepted "cooling-off" period is one year. Jane should not be assigned to the payroll audit. The CAE must reassign the engagement.
Thinking through scenarios with this structure—organizational vs. individual—will help you cut through the distractors and select the correct answer. The Vory AI tutor, included with a VoraPrep subscription, can walk you through hundreds of these distinctions until they become second nature.
Test Your CIA Exam Readiness
Evaluate your mastery of the new Global Internal Audit Standards and benchmark your baseline readiness.
The COSO Frameworks: Internal Control vs. ERM
You absolutely must know the difference between the COSO Internal Control framework and the COSO ERM framework. The exam will give you a scenario and ask which framework is more applicable or test your knowledge of their specific components.
Here’s a quick-reference table to keep them straight:
| Feature | COSO Internal Control – Integrated Framework | COSO Enterprise Risk Management (ERM) |
|---|---|---|
| Primary Goal | To help organizations design and evaluate the effectiveness of internal controls over operations, reporting, and compliance. | To integrate risk management with strategy and performance to create, preserve, and realize value. |
| Scope | More focused on controls at the process and transaction level. | Broader, more strategic scope. Focuses on managing risk across the entire enterprise to achieve strategic objectives. |
| Mnemonic | CRIME | GO PRO |
| Components | Control Environment, Risk Assessment, Control Activities, Information & Communication, Monitoring Activities | Governance & Culture, Objective-Setting & Strategy, Performance, Review & Revision, Ongoing Information, Communication, & Reporting |
| Exam Application | Questions about testing specific controls, identifying control deficiencies, or assessing the control environment. | Questions about setting risk appetite, identifying strategic risks, or evaluating the organization's overall risk culture. |
Don't just memorize the mnemonics. Understand that Internal Control is a component of the broader ERM process. For a deeper analysis, review our complete guide to the COSO internal control framework.
Worked Example: Attribute Sampling for Control Testing
Let’s walk through a classic Part 2 scenario that combines technical skill with professional judgment.
Scenario: You are the lead auditor for an engagement at "Stark Industries." You're testing a key control: "All capital expenditures over $100,000 must be approved by the VP of Finance." There were 2,000 such expenditures during the year. Your team has decided on the following parameters:- Confidence Level: 95% (This means you accept a 5% risk of overreliance—the risk of concluding the control is effective when it's not.)
- Tolerable Deviation Rate (TDR): 6% (You can tolerate up to a 6% failure rate in this control.)
- Expected Population Deviation Rate (EPDR): 2% (Based on last year's audit, you expect about 2% of approvals to be missing.)
- Using a sample size table, your team determines the appropriate sample size is 99.
- After testing the 99 items, you discover 4 expenditures that lack the required VP approval.
- What is your audit conclusion regarding this control?
- SDR = (Number of Deviations / Sample Size)
- SDR = 4 / 99 = 4.04%
This is where many candidates stop and make the wrong call.
Step 2: Determine the Achieved Upper Deviation Rate (UDR) The SDR is just a point estimate from your sample. You must account for sampling risk. The UDR calculates the maximum possible deviation rate in the entire population at your stated 95% confidence level.- Rule: You will be given a table or the UDR value in the exam. You won't calculate it from a formula. The table would look at your sample size (99), your number of deviations (4), and your confidence level (95%).
- For this example, let's assume the statistical table tells you the UDR is 9.5%.
This means you are 95% confident that the true rate of missing approvals in the entire population of 2,000 expenditures is no higher than 9.5%.
Step 3: Draw a Conclusion This is the judgment step. Compare your result to the threshold you set at the beginning.- Compare Achieved UDR to your Tolerable Deviation Rate (TDR):
- Achieved UDR (9.5%) > Tolerable Deviation Rate (6%)
- Conclusion: Since the maximum likely deviation rate (9.5%) exceeds the maximum rate you were willing to accept (6%), you cannot rely on this control. The risk of control failure is unacceptably high. Your audit report must state that this control is not operating effectively.
- Tempting Wrong Answer: "The sample deviation rate of 4.04% is less than the tolerable rate of 6%, so the control is effective."
- Why it's Wrong: This conclusion completely ignores sampling risk. You are not auditing the sample; you are auditing the population. The UDR is your statistically valid projection onto the population. Always base your final conclusion on the comparison between the UDR and the TDR.
The VoraPrep adaptive learning engine has thousands of scenarios like this to build the critical thinking patterns you need for exam day.
Common CIA Part 2 Traps the IIA Sets
Here are the traps the IIA sets to separate passing candidates from the rest.
Trap 1: Misinterpreting the New GIAS Requirements
The new Global Internal Audit Standards™ move away from the old "Must" and "Should" language. Instead, they contain Requirements and Considerations for Implementation. An exam question might present a scenario where an auditor follows a "consideration" but violates a "requirement." You must know the difference: requirements are mandatory.Trap 2: Lacking Professional Skepticism
A key part of due professional care is maintaining professional skepticism—an attitude that includes a questioning mind. If a question states, "The department manager assured the auditor that all controls were functioning as designed," treat that as a red flag. An auditor's conclusion must be based on sufficient, reliable, relevant, and useful evidence—not on management's word alone.Trap 3: Ignoring the Scope of the Engagement
A scenario will provide a lot of detail. Before answering, always confirm the specific objectives and scope of the audit engagement described. An action that is perfectly reasonable for a financial audit (e.g., focusing on dollar amounts) might be inappropriate for an operational audit (e.g., focusing on efficiency) or a compliance audit (e.g., focusing on adherence to regulation).Trap 4: Confusing Risk Appetite and Risk Tolerance
The exam loves to test if you can apply the right term to the right context.- Risk Appetite: The broad amount and type of risk an organization is willing to accept in pursuit of its strategic objectives. It's a high-level statement.
- Risk Tolerance: The acceptable level of variation around specific objectives. It's tactical and operational, often stated in measurable terms (e.g., "we tolerate no more than 1% downtime").