CIA Exam · 13 min read Updated

CIA Part 2 Study Guide: Practice of Internal Auditing

Rob Pfleghardt

10-year Price Waterhouse alumnus · Founder of VoraPrep · Former CPA (1987–2024) · with the VoraPrep Editorial Team

CIA Part 2 Study Guide: Practice of Internal Auditing

Key Takeaways

  • Exam name: Certified Internal Auditor (CIA), Part 2: Practice of Internal Auditing
  • Official body: The Institute of Internal Auditors (IIA)
  • Exam format: 100 multiple-choice questions
  • Exam duration: 120 minutes (2 hours)
  • Passing score: 600 on a scale of 250-750
  • Governing standards (2026 exams): The Global Internal Audit Standards™ (GIAS)

You’ve hit CIA Part 2, "Practice of Internal Auditing," and you're staring down the new Global Internal Audit Standards™, trying to cram every requirement. That’s the #1 trap. Candidates think this part is about memorizing the rulebook, only to get paralyzed by a scenario question that doesn't ask what the rule is, but how a professional applies it under pressure. The real challenge isn’t recalling a standard number; it’s knowing what to do when management pushes back on your findings and the evidence feels incomplete.

Quick answer

CIA Part 2 tests your ability to apply the IIA's Global Internal Audit Standards™ (GIAS) throughout an engagement. It covers Managing the Internal Audit Activity (20%), Planning the Engagement (20%), Performing the Engagement (40%), and Communicating Results & Monitoring Progress (20%). Passing requires applying professional judgment in scenarios, not just recalling rules.

Key facts

  • Exam name: Certified Internal Auditor (CIA), Part 2: Practice of Internal Auditing
  • Official body: The Institute of Internal Auditors (IIA)
  • Exam format: 100 multiple-choice questions
  • Exam duration: 120 minutes (2 hours)
  • Passing score: 600 on a scale of 250-750
  • Governing standards (2026 exams): The Global Internal Audit Standards™ (GIAS)
  • Key topics: Engagement planning, fieldwork, communication, risk management, COSO frameworks

CIA Part 2 Syllabus Breakdown: What the Exam Really Tests

Think of Part 1 as the "what" and Part 2 as the "how." This section moves beyond foundational concepts and tests your proficiency in the four key phases of an internal audit engagement. The IIA wants to know if you can think and act like an internal auditor when faced with realistic workplace pressures.

The exam syllabus is weighted across four domains:

Free 5-Min Diagnostic

Studying for CIA CIA2? Benchmark your score in 5 minutes.

Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.

  1. Managing the Internal Audit Activity (20%): This covers the strategic and operational management of the function. It's about the Internal Audit Charter, the Quality Assurance and Improvement Program (QAIP), and how the Chief Audit Executive (CAE) interacts with the board and senior management.
  2. Planning the Engagement (20%): Here, you'll be tested on setting engagement objectives, determining the required scope and resources, and performing a risk assessment to guide the audit plan.
  3. Performing the Engagement (40%): This is the largest domain. It's the "boots on the ground" work of gathering sufficient, reliable, relevant, and useful evidence, applying analytical procedures, creating workpapers, and drawing sound conclusions.
  4. Communicating Engagement Results and Monitoring Progress (20%): This covers drafting audit reports, communicating findings to management, formulating recommendations, and the critical process of following up to ensure management's action plans are implemented.

Your success on Part 2 depends entirely on applying the standards with professional judgment. Ready to see how your judgment stacks up? Test yourself with VoraPrep's adaptive CIA practice questions and get instant feedback with detailed explanations.

The New Global Internal Audit Standards™ (GIAS): Your 2026 Exam Blueprint

This is critical: As of January 9, 2025, the old IPPF (with its Attribute and Performance standards) is replaced by the new Global Internal Audit Standards™ (GIAS). If you are sitting for the exam in 2026, you must use the new GIAS. Studying from outdated materials is a guaranteed way to fail.

Forget the old 1000/2000 series numbering. The new structure is organized into five domains. For Part 2, you need to know how they apply in practice:

GIAS DomainTitleWhat It Really Means for Your Exam
Domain IEthics and ProfessionalismThe bedrock. This elevates the Code of Ethics and covers Due Professional Care. Expect scenario questions testing your integrity and competence under pressure.
Domain IIGoverning the Internal Audit FunctionHow the function is structured for success. This covers the Internal Audit Charter, Independence, and the CAE's relationship with the Board.
Domain IIIManaging the Internal Audit FunctionHow the CAE runs the department. Think strategic planning, resource management, and the all-important Quality Assurance and Improvement Program (QAIP).
Domain IVPerforming Internal Audit ServicesThe "how-to" of an audit. This covers engagement planning, gathering evidence (sufficiency and appropriateness), and documenting work.
Domain VCommunicating and Following UpThe final stages. This includes reporting results, forming conclusions and recommendations, and monitoring management's action plans.

Your focus for Part 2 should be on Domains III, IV, and V, with a strong understanding of Independence (Domain II) and the Code of Ethics (Domain I).

The IIA Code of Ethics: The Foundation of Judgment

The GIAS places the Code of Ethics front and center. It's not just a list to memorize; it's the basis for every judgment call you'll be tested on. You must know the four principles and be able to apply their associated Rules of Conduct in a scenario.

  1. Integrity: Establishes trust and provides the basis for reliance on your judgment.
  2. Objectivity: Requires you to be unbiased in your work, avoiding all conflicts of interest.
  3. Confidentiality: Demands respect for the value and ownership of information you receive.
  4. Competence: Means you only perform services you have the necessary knowledge, skills, and experience for.

An exam question won't ask, "What is objectivity?" It will describe a situation—like being asked to audit a system you helped design—and expect you to identify the specific ethical principle that is impaired.

A Decision Tree for Independence and Objectivity Traps

The terms "independence" and "objectivity" are often confused by candidates, which is a fatal mistake on the exam. The examiners love to test this distinction.

  • Independence is organizational. It belongs to the internal audit function. It’s about the CAE having a direct reporting line to the board and freedom from management interference. (GIAS Domain II)
  • Objectivity is individual. It belongs to the auditor. It's an unbiased mental attitude. (GIAS Domain I & II)

Use this decision tree to navigate scenario questions:

Condition: An auditor is assigned to an engagement. Is there an impairment?
  1. Question 1: Does the issue affect the entire audit department's freedom or reporting structure?
  • YES: This is an independence issue.
  • Example: The CAE reports functionally to the CFO instead of the Audit Committee. This threatens the entire department's ability to audit impartially.
  • Action: The impairment must be disclosed to the board. The audit charter should be corrected to reflect a direct reporting line.
  • NO, the issue is specific to one auditor's relationship with the auditee: Proceed to Question 2.
  1. Question 2: Does the individual auditor have a conflict of interest, bias, or prior responsibility for the area being audited?
  • YES: This is an objectivity issue.
  • Example: The auditor, Jane, was the acting manager of the payroll department for six months last year. She is now assigned to audit payroll.
  • Tempting Wrong Answer: "Jane can perform the audit if she discloses her prior role in the final report."
  • Correct Approach: This is a clear impairment of objectivity. Standard 2.2 requires internal auditors to be objective. The generally accepted "cooling-off" period is one year. Jane should not be assigned to the payroll audit. The CAE must reassign the engagement.

Thinking through scenarios with this structure—organizational vs. individual—will help you cut through the distractors and select the correct answer. The Vory AI tutor, included with a VoraPrep subscription, can walk you through hundreds of these distinctions until they become second nature.

✨ Free 5-Min Assessment

Test Your CIA Exam Readiness

Evaluate your mastery of the new Global Internal Audit Standards and benchmark your baseline readiness.

Take Free CIA Quiz →

The COSO Frameworks: Internal Control vs. ERM

You absolutely must know the difference between the COSO Internal Control framework and the COSO ERM framework. The exam will give you a scenario and ask which framework is more applicable or test your knowledge of their specific components.

Here’s a quick-reference table to keep them straight:

FeatureCOSO Internal Control – Integrated FrameworkCOSO Enterprise Risk Management (ERM)
Primary GoalTo help organizations design and evaluate the effectiveness of internal controls over operations, reporting, and compliance.To integrate risk management with strategy and performance to create, preserve, and realize value.
ScopeMore focused on controls at the process and transaction level.Broader, more strategic scope. Focuses on managing risk across the entire enterprise to achieve strategic objectives.
MnemonicCRIMEGO PRO
ComponentsControl Environment, Risk Assessment, Control Activities, Information & Communication, Monitoring ActivitiesGovernance & Culture, Objective-Setting & Strategy, Performance, Review & Revision, Ongoing Information, Communication, & Reporting
Exam ApplicationQuestions about testing specific controls, identifying control deficiencies, or assessing the control environment.Questions about setting risk appetite, identifying strategic risks, or evaluating the organization's overall risk culture.

Don't just memorize the mnemonics. Understand that Internal Control is a component of the broader ERM process. For a deeper analysis, review our complete guide to the COSO internal control framework.

Worked Example: Attribute Sampling for Control Testing

Let’s walk through a classic Part 2 scenario that combines technical skill with professional judgment.

Scenario: You are the lead auditor for an engagement at "Stark Industries." You're testing a key control: "All capital expenditures over $100,000 must be approved by the VP of Finance." There were 2,000 such expenditures during the year. Your team has decided on the following parameters:
  • Confidence Level: 95% (This means you accept a 5% risk of overreliance—the risk of concluding the control is effective when it's not.)
  • Tolerable Deviation Rate (TDR): 6% (You can tolerate up to a 6% failure rate in this control.)
  • Expected Population Deviation Rate (EPDR): 2% (Based on last year's audit, you expect about 2% of approvals to be missing.)
The Question:
  1. Using a sample size table, your team determines the appropriate sample size is 99.
  2. After testing the 99 items, you discover 4 expenditures that lack the required VP approval.
  3. What is your audit conclusion regarding this control?
Decision Steps & Calculation: Step 1: Calculate the Sample Deviation Rate (SDR) This is your raw finding. It's the number of errors you found divided by your sample size.
  • SDR = (Number of Deviations / Sample Size)
  • SDR = 4 / 99 = 4.04%

This is where many candidates stop and make the wrong call.

Step 2: Determine the Achieved Upper Deviation Rate (UDR) The SDR is just a point estimate from your sample. You must account for sampling risk. The UDR calculates the maximum possible deviation rate in the entire population at your stated 95% confidence level.
  • Rule: You will be given a table or the UDR value in the exam. You won't calculate it from a formula. The table would look at your sample size (99), your number of deviations (4), and your confidence level (95%).
  • For this example, let's assume the statistical table tells you the UDR is 9.5%.

This means you are 95% confident that the true rate of missing approvals in the entire population of 2,000 expenditures is no higher than 9.5%.

Step 3: Draw a Conclusion This is the judgment step. Compare your result to the threshold you set at the beginning.
  • Compare Achieved UDR to your Tolerable Deviation Rate (TDR):
  • Achieved UDR (9.5%) > Tolerable Deviation Rate (6%)
  • Conclusion: Since the maximum likely deviation rate (9.5%) exceeds the maximum rate you were willing to accept (6%), you cannot rely on this control. The risk of control failure is unacceptably high. Your audit report must state that this control is not operating effectively.
The Common Trap & Why It's Tempting:
  • Tempting Wrong Answer: "The sample deviation rate of 4.04% is less than the tolerable rate of 6%, so the control is effective."
  • Why it's Wrong: This conclusion completely ignores sampling risk. You are not auditing the sample; you are auditing the population. The UDR is your statistically valid projection onto the population. Always base your final conclusion on the comparison between the UDR and the TDR.

The VoraPrep adaptive learning engine has thousands of scenarios like this to build the critical thinking patterns you need for exam day.

Common CIA Part 2 Traps the IIA Sets

Here are the traps the IIA sets to separate passing candidates from the rest.

Trap 1: Misinterpreting the New GIAS Requirements

The new Global Internal Audit Standards™ move away from the old "Must" and "Should" language. Instead, they contain Requirements and Considerations for Implementation. An exam question might present a scenario where an auditor follows a "consideration" but violates a "requirement." You must know the difference: requirements are mandatory.

Trap 2: Lacking Professional Skepticism

A key part of due professional care is maintaining professional skepticism—an attitude that includes a questioning mind. If a question states, "The department manager assured the auditor that all controls were functioning as designed," treat that as a red flag. An auditor's conclusion must be based on sufficient, reliable, relevant, and useful evidence—not on management's word alone.

Trap 3: Ignoring the Scope of the Engagement

A scenario will provide a lot of detail. Before answering, always confirm the specific objectives and scope of the audit engagement described. An action that is perfectly reasonable for a financial audit (e.g., focusing on dollar amounts) might be inappropriate for an operational audit (e.g., focusing on efficiency) or a compliance audit (e.g., focusing on adherence to regulation).

Trap 4: Confusing Risk Appetite and Risk Tolerance

The exam loves to test if you can apply the right term to the right context.
  • Risk Appetite: The broad amount and type of risk an organization is willing to accept in pursuit of its strategic objectives. It's a high-level statement.
  • Risk Tolerance: The acceptable level of variation around specific objectives. It's tactical and operational, often stated in measurable terms (e.g., "we tolerate no more than 1% downtime").

Frequently asked questions

How does CIA Part 2 difficulty compare to Part 1?

Many candidates find Part 2 more practical and less theoretical than Part 1. While Part 1 focuses heavily on memorizing the IPPF standards and foundational concepts, Part 2 requires you to apply those standards to the entire audit engagement lifecycle. If you have hands-on audit experience, the scenarios in Part 2 may feel more intuitive, but the judgment required can be challenging.

How many hours should I study for CIA Part 2?

The general guidance is to budget 100-120 hours of focused study for Part 2. This can fluctuate based on your day-to-day audit experience and how recently you passed Part 1. A common strategy is studying 8-10 hours per week, which translates to a 12-15 week study period for most working professionals.

What is the pass rate for CIA Part 2?

The IIA does not publish official pass rates for individual exam parts, but the overall pass rate for all three parts of the CIA exam hovers around 40-45%. Part 2's pass rate is believed to be consistent with this average. Success hinges on your ability to apply concepts in scenario-based questions, not just recall definitions.

What are the most challenging topics in CIA Part 2?

Candidates often struggle most with Domain II, "Planning the Engagement," because it requires nuanced judgment in risk assessment and scoping. Questions on developing a risk-based plan and determining engagement objectives can be tricky. Additionally, Domain IV, "Communicating Engagement Results and Monitoring Progress," trips people up with its specific requirements for formal reporting and follow-up procedures.
⚡ Instant Knowledge Check · 1-Click Test Drive
CIA Part 1: Essentials of Internal Auditing

Under the IIA Global Internal Audit Standards (Domain III: Governing the Internal Audit Function), who has the ultimate responsibility for ensuring the organizational independence of the internal audit activity?

Official resources and references

  • The Institute of Internal Auditors (IIA) Certifications: The official source for all CIA exam information, including policies and syllabi.
  • IIA Global Internal Audit Standards™: Access the official text of the new standards that govern the practice of internal auditing.
  • COSO Frameworks Overview: Official guidance from the Committee of Sponsoring Organizations of the Treadway Commission.
  • U.S. Bureau of Labor Statistics – Accountants and Auditors: Provides salary and career outlook data for the auditing profession.
RP

About the Author: Rob Pfleghardt

Rob Pfleghardt is the founder of VoraPrep, a comprehensive exam prep platform for the CPA, CMA, EA, CIA, CISA, and CFP exams. A Virginia Tech graduate in Accounting and Finance, Rob began his career at Price Waterhouse, spending a decade in audit and IT consulting. After holding a CPA license for 37 years (1987–2024) and successfully scaling his own enterprise IT consultancy serving the Department of Defense, Rob launched VoraPrep. He now leverages his deep systems architecture background to build the adaptive training technology and curriculum that helps candidates pass their certification exams efficiently.

Connect with Rob on LinkedIn →
Free Diagnostic Assessment

Find your exact CIA weak spots in 10 minutes.

Most candidates fail because they study blindly. Take our free 10-question diagnostic to identify your weakest blueprint topics and receive a custom 12-week study plan PDF generated instantly.

Keep reading

Free 5-min CIA diagnostic + 12-week plan PDF

Start →
CIA 1:1 Prometric Simulator

4,800+ practice questions with instant Socratic feedback