CIA Exam · 15 min read Updated

CIA Practice of Internal Auditing: Risk assessment of the activity under review — Complete Study Guide

Rob Pfleghardt

10-year Price Waterhouse alumnus · Founder of VoraPrep · Former CPA (1987–2024) · with the VoraPrep Editorial Team

CIA Practice of Internal Auditing: Risk assessment of the activity under review — Complete Study Guide

Key Takeaways

  • Engagement plans must be based on a risk assessment that links directly to the organization's strategic objectives and stated risk appetite.
  • The 2024+ Global Internal Audit Standards mandate a risk-based approach to planning every audit engagement, per Domain II, Standard 2.1.
  • Prioritizing risks requires weighing financial impact, likelihood, and qualitative factors like reputational damage against the organization's specific risk thresholds.
  • A common exam trap is to focus on high-likelihood, low-impact risks while ignoring low-likelihood, high-impact risks that could be catastrophic.
  • Weak entity-level controls increase control risk, making it harder for management to mitigate inherent risks and leading to higher residual risk.
  • The "Three Lines Approach" clarifies roles, establishing internal audit as the independent third line providing objective assurance on risk management.

An internal audit team identifies two critical risks. Risk A has a 70% chance of occurring this year, with a potential financial impact of $100,000. Risk B has a 5% chance of occurring but would cause a $5 million loss and trigger regulatory fines. Which risk gets prioritized in the audit plan? If you immediately chose Risk A because of its high likelihood, you've just fallen for the single most common trap on CIA Part 2. The exam doesn't test if you can spot a risk; it tests if you can weigh it against the organization's strategic objectives.

Quick answer

For CIA Part 2, risk assessment of the activity under review is the process of identifying, analyzing, and prioritizing threats to an engagement's objectives. It requires applying professional judgment to align limited audit resources with the organization's most significant risks, based on impact, likelihood, and the board-approved risk appetite.

Key facts

  • Official Body: The Institute of Internal Auditors (IIA).
  • Governing Standards: The 2024+ Global Internal Audit Standards (effective Jan 2025 for 2026 exams).
  • CIA Part 2 Focus: "Practice of Internal Auditing" covers managing the audit function, planning engagements, and reporting.
  • Exam Format: 100% multiple-choice questions (MCQs), often presented as complex scenarios.
  • Pass Rate: Historically, the global pass rate for all CIA parts hovers around 40-45%.
  • Typical Salary: Certified Internal Auditors often earn between $80,000 and $130,000, though this varies significantly with experience, industry, and location.

The U.S. Bureau of Labor Statistics projects employment for accountants and auditors to grow 4 percent from 2022 to 2032, with certified professionals being highly sought after (BLS).

How Does Engagement Risk Assessment Drive an Audit?

Engagement risk assessment is the systematic process internal auditors use to identify, analyze, and prioritize potential risks tied to a specific area being audited. This is the foundation that ensures your limited audit resources are aimed at the most significant threats to the organization, making it a cornerstone of CIA Part 2.

This process doesn't happen in a vacuum. It's a crucial link between the organization's high-level Enterprise Risk Management (ERM) framework and the detailed work program for a single audit. The annual audit plan is derived from the ERM; your engagement plan is derived from the annual plan. The exam will test your ability to make this connection.

Free 5-Min Diagnostic

Studying for CIA CIA2? Benchmark your score in 5 minutes.

Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.

You won't be asked to simply define "risk." You'll be asked to decide which of four plausible risks demands the most urgent attention, given a specific corporate context. A frequent error is failing to connect an activity's risks to the organization's larger strategic goals. A minor inventory control issue might seem trivial, but if that inventory is for a flagship product launch critical to the company's five-year plan, its strategic risk is immense.

The new Global Internal Audit Standards are explicit on this. Domain II (Managing the Internal Audit Function), Standard 2.1: Planning Engagements requires that "The internal audit function plans engagements to determine the objectives, scope, and approach." This planning must be rooted in a preliminary assessment of relevant risks. Neglecting this connection is a guaranteed way to miss points. You can try VoraPrep's free CIA practice questions to see how these scenarios are structured.

Mastering the Core Components of Risk Assessment

To correctly answer exam questions, you need to integrate several key concepts. The examiner expects you to see how these elements work together to form a coherent audit plan.

Inherent Risk, Control Risk, and Residual Risk

This is a fundamental relationship you must master. Candidates often mix them up.
ConceptDefinitionExam Focus
Inherent RiskThe raw, untreated risk associated with an activity, assuming no controls exist.Identifying the natural level of risk in a process (e.g., cash handling is inherently risky).
Control RiskThe risk that a control will fail to prevent or detect a material error or noncompliance.Assessing the effectiveness of management's controls. Weak controls mean high control risk.
Residual RiskThe risk that remains after management has implemented controls. Inherent Risk - Control Effectiveness = Residual Risk.Determining if the remaining risk is acceptable. This is the primary focus of your audit.

Your audit engagement is designed to provide assurance on whether the residual risk is within the organization's risk appetite. If inherent risk is high and controls are weak (high control risk), residual risk will also be high, signaling a priority area for your audit.

Entity-Level Controls (ELCs)

ELCs are the organization-wide controls that create the foundation for all other controls. They include the tone at the top, ethical values, and the board's oversight.

A common mistake is thinking weak ELCs make a process inherently riskier.

The reality is that weak ELCs increase control risk. A poor tone at the top doesn't make cash handling inherently more dangerous; it makes it more likely that the controls designed to protect the cash will be ignored or fail. Your assessment of an activity's risk must factor in the strength of the ELCs that influence the control environment.

The Three Lines Approach

The IIA's Three Lines Approach is a model for structuring roles and responsibilities for risk management.
  1. First Line: Operational management, which owns and manages risks.
  2. Second Line: Risk management and compliance functions that oversee risk.
  3. Third Line: Internal audit, which provides independent and objective assurance.

On the exam, understanding this model helps you identify the proper role of internal audit. We don't own the risks or the controls; we provide assurance on how well the first and second lines are doing their jobs.

Risk Appetite, Tolerance, and Capacity

This is often the key to solving prioritization questions on the exam.
  • Risk Appetite: The amount and type of risk an organization is willing to accept to achieve its objectives. This is a high-level statement from the board.
  • Risk Tolerance: The specific, measurable level of acceptable variation from objectives (e.g., "we can tolerate no more than a 1% error rate in this process").
  • Risk Capacity: The maximum amount of risk an organization can bear without failing.

An organization might have a high appetite for financial risk in its investment portfolio but zero tolerance for safety violations. You must use the stated risk appetite in a scenario to guide your prioritization. Our guide on risk appetite and risk tolerance offers a deeper analysis of this critical area.

Sources of Engagement Information

A robust risk assessment requires triangulation from multiple sources. Relying solely on management interviews is a red flag. Key sources include:
  • Prior internal and external audit reports.
  • Regulatory changes and industry benchmark data.
  • Financial reports, budgets, and key performance indicators (KPIs).
  • Strategic plans and board meeting minutes.
  • Direct observation and process walkthroughs.

Understanding how these sources fit within a recognized framework, such as the COSO ICIF 2013, demonstrates a comprehensive approach to planning.

Worked Example: Prioritizing Risks in Practice

Let's apply these concepts to a realistic exam scenario. Scenario:

Phoenix Manufacturing Co. (PMC) produces specialized industrial parts. The internal audit department is planning its engagement for the upcoming quarter. One potential area for review is the "New Product Development (NPD) Process," which currently accounts for 30% of future revenue projections but has experienced significant delays and cost overruns in 2 of the last 5 projects.

The following risks have been identified:

Risk CategoryLikelihoodFinancial ImpactOther Factors
Market RiskModerate (30%)High ($10M-$20M)Accepted part of business
Project Mgmt RiskHigh (60%)Moderate ($2M-$5M)New software in place (untested)
IP RiskLow (5%)Very High ($50M+)Permanent competitive loss
Regulatory RiskModerate (20%)High ($10M+)Fines + severe reputational damage

PMC's board has stated a strong aversion to reputational damage and legal non-compliance but accepts moderate market-related business risks as part of its innovation strategy.

Which risk should the internal audit team prioritize for its initial engagement focus within the NPD process?
A. Market Risk
B. Project Management Risk
C. Intellectual Property (IP) Risk
D. Regulatory Compliance Risk
Step-by-step walkthrough showing the reasoning process:
  1. Identify the Core Question: The goal is to prioritize where audit work will add the most value, aligning with PMC's objectives and risk appetite.
  2. Analyze the Data: The table lays out the quantitative and qualitative factors. Note the likelihood, financial impact, and other critical context for each risk.
  3. Apply the Risk Appetite Filter: This is the most important step. PMC has a strong aversion to regulatory and reputational risks. This statement from the board acts as a multiplier on the significance of any risk touching those areas. They are willing to accept market risk, pushing it down the priority list despite its high financial impact.
  4. Evaluate the Top Candidates:
  • Project Management Risk (B): This is highly tempting. It has the highest likelihood (60%) and is a known, recurring problem. Management has a control (new software), but it's untested, making it a valid audit target.
  • Regulatory Compliance Risk (D): This risk has a lower likelihood (20%) than project management risk. However, its impact includes a high financial penalty plus severe reputational damage. This aligns directly with the board's stated strong aversion.
  1. Make the Judgment Call: The examiner is forcing a choice between a frequent, moderately costly operational problem (Project Management) and a less frequent but potentially devastating strategic problem (Regulatory Compliance). Given the explicit risk appetite, the threat of reputational damage and legal trouble outweighs the more probable operational issue. Internal audit's highest value is in helping the organization avoid catastrophic failures.
The tempting wrong answer and why it's wrong: B. Project Management Risk is the classic wrong answer. Candidates are drawn to its high likelihood (60%) and the tangible evidence of past failures. It feels like the most "obvious" problem to fix. But this choice ignores the single most important piece of information in the prompt: the organization's risk appetite. The internal audit function must prioritize based on the risks that matter most to the board and senior management, not just the ones that happen most often.
✓ Correct Answer:

D. Regulatory Compliance Risk

This choice demonstrates a mature understanding of risk assessment, integrating quantitative data with the critical qualitative context of organizational strategy and risk appetite.

✨ Free 5-Min Assessment

Test Your CIA Exam Readiness

Evaluate your mastery of the new Global Internal Audit Standards and benchmark your baseline readiness.

Take Free CIA Quiz →

Practice Questions: Test Your Judgment

VoraPrep's adaptive learning engine includes thousands of questions to sharpen this skill. Here are three examples.

---

Sample Q1: During the planning phase of an audit of a manufacturing plant, the internal auditor identifies a specific risk: a catastrophic equipment failure due to inadequate maintenance, which could halt production for weeks, costing millions, but has a historically very low probability of occurring (e.g., once every 20 years). The plant manager argues that its low likelihood means it should be a low audit priority. Which of the following best describes the internal auditor's primary consideration when evaluating this risk?
A. The plant manager's assessment of low likelihood should be the sole determinant of audit priority.
B. The internal auditor should prioritize based solely on the potential financial impact, regardless of likelihood.
C. The internal auditor must consider the organization's overall risk appetite and tolerance for catastrophic operational disruptions, even if infrequent.
D. The internal auditor should focus only on risks with a high likelihood of occurrence, as they are more likely to manifest during the audit period.
Explanation:

The correct answer is C. Risk prioritization is a function of impact, likelihood, and risk appetite. A low-likelihood, high-impact event (a "black swan") can destroy an organization. The auditor's duty is to evaluate this risk against the organization's willingness to accept such a catastrophic disruption, not just its frequency.

  • A is incorrect because the auditor must remain independent and objective, not simply accept management's assessment.
  • B is incorrect because ignoring likelihood is as flawed as ignoring impact. Both must be considered.
  • D is incorrect as it describes a common but dangerous trap of ignoring potentially fatal, low-probability risks.

---

Sample Q2: An internal audit team discovers that a company's whistleblower hotline is rarely used, and when it is, concerns are often not investigated effectively. This finding primarily indicates a weakness in which of the following?
A. Information and communication processes.
B. Specific process-level controls over journal entries.
C. The organization's risk assessment methodology for fraud.
D. The entity-level control environment, particularly the tone at the top and monitoring activities.
Explanation:

The correct answer is D. A non-functional whistleblower system is a classic sign of a poor entity-level control environment. It reflects a weak "tone at the top" and a failure in "Monitoring Activities" as defined by frameworks like COSO. It's a systemic, cultural problem, not a narrow process issue.

  • A is incorrect because the root cause isn't just a communication breakdown; it's a failure of governance and accountability.
  • B is incorrect because this is a high-level issue that affects the entire organization, not a specific transactional control.
  • C is incorrect because while related to fraud, the most direct and fundamental failure is in the overarching control environment.

---

Sample Q3: When planning an audit of a commercial bank's loan portfolio for 2026, which source would provide the most insightful information regarding emerging risks and potential areas of non-compliance?
A. Reviewing the bank's internal audit reports from 2020-2022.
B. Analyzing recent regulatory advisories, enforcement actions, and industry white papers concerning lending practices.
C. Interviewing the bank's Chief Financial Officer (CFO) about overall financial performance.
D. Examining the bank's general ledger for large or unusual transactions.
Explanation:

The correct answer is B. To identify emerging risks for a future period (2026), you must look at external, forward-looking information. Regulatory advisories and enforcement actions show where the industry is heading and what regulators are focused on now.

  • A is incorrect because old audit reports are historical and unlikely to capture new or emerging threats.
  • C is incorrect because a CFO interview provides a high-level financial view, not the specific, granular detail on emerging lending compliance risks.
  • D is incorrect because examining the general ledger is a detailed testing procedure for fieldwork, not a planning activity for identifying future risks.

--- Ready to see how you'd perform on dozens more risk assessment scenarios? You can practice more questions like these in VoraPrep and get instant feedback from our Vory AI tutor.

How to Study This Topic Effectively

Your study plan must focus on application, not just memorization.

Weekly Drill: Risk Prioritization Matrix Each week, take two practice scenarios. Draw a simple 2x2 matrix with "Likelihood" on one axis and "Impact" on the other. Plot the risks from the scenario on the matrix. Then, write one sentence justifying why you would prioritize one over the others, explicitly mentioning risk appetite. This drill takes 10 minutes and builds critical judgment skills. Exam Day Strategy: When you get a risk assessment scenario, slow down. Use your digital scratchpad to list the key facts:
  1. What is the company's main objective?
  2. What is its stated risk appetite?
  3. For each risk, what is the impact (financial and other)?
  4. What is the likelihood?

The answer is found by connecting these four points. Allocate a full 2 minutes for these complex questions.

How This Connects to Other Part 2 Topics: Your risk assessment directly determines the Engagement Objectives and Scope. The identified risks drive your Audit Procedures and Work Programs. The severity of the risk dictates Resource Allocation. Finally, your Audit Report will communicate findings in the context of how well management is mitigating these key risks. Understanding these links is crucial for questions that touch on topics like finance and business process risks.

Frequently asked questions

How many questions on engagement risk assessment are on the CIA exam? The IIA does not publish the exact number of questions per sub-topic. However, since risk-based planning is a core competency in Part 2, you should expect 5-10 complex scenario questions where risk assessment is the central skill being tested. What is the best way to study risk assessment for the CIA exam? The most effective method is active problem-solving through high-quality practice questions. For every question, force yourself to articulate why the correct answer is best and, more importantly, why the distractors are tempting but flawed. This builds the judgment the exam demands. Is risk assessment of the activity under review tested with simulations? The CIA exam consists entirely of multiple-choice questions (MCQs). There are no task-based simulations (TBS) or written components. However, the lengthy and detailed scenario questions are designed to function like mini-case studies, testing your analytical skills in a practical context. How should I approach risk assessment questions on exam day? First, identify the organization's stated risk appetite and strategic objectives within the prompt. This is your filter. Then, evaluate each risk option based on both its impact (financial and qualitative) and likelihood, always prioritizing alignment with the company's risk appetite. How much time should I dedicate to studying this CIA Part 2 topic? Given its importance for the "Practice of Internal Auditing," plan to spend 15-20 hours focused specifically on risk assessment principles and working through practice scenarios. An adaptive learning platform like VoraPrep can help focus this time on areas where you need the most improvement.

---

Ready to Pass Your CIA Exam? Don't gamble on exam day. VoraPrep's platform is built to develop your judgment with 4,800+ practice questions, detailed explanations, an adaptive learning engine, and a 24/7 AI tutor named Vory. Our plans are flexible and affordable.

Visit voraprep.com to get started and see why hundreds of candidates pass with us.

Start Your Free 14-Day Trial at voraprep.com →
⚡ Instant Knowledge Check · 1-Click Test Drive
CIA Part 1: Essentials of Internal Auditing

Under the IIA Global Internal Audit Standards (Domain III: Governing the Internal Audit Function), who has the ultimate responsibility for ensuring the organizational independence of the internal audit activity?

Official resources and references

RP

About the Author: Rob Pfleghardt

Rob Pfleghardt is the founder of VoraPrep, a comprehensive exam prep platform for the CPA, CMA, EA, CIA, CISA, and CFP exams. A Virginia Tech graduate in Accounting and Finance, Rob began his career at Price Waterhouse, spending a decade in audit and IT consulting. After holding a CPA license for 37 years (1987–2024) and successfully scaling his own enterprise IT consultancy serving the Department of Defense, Rob launched VoraPrep. He now leverages his deep systems architecture background to build the adaptive training technology and curriculum that helps candidates pass their certification exams efficiently.

Connect with Rob on LinkedIn →
Free Diagnostic Assessment

Find your exact CIA weak spots in 10 minutes.

Most candidates fail because they study blindly. Take our free 10-question diagnostic to identify your weakest blueprint topics and receive a custom 12-week study plan PDF generated instantly.

Keep reading

Free 5-min CIA diagnostic + 12-week plan PDF

Start →
CIA 1:1 Prometric Simulator

4,800+ practice questions with instant Socratic feedback