You’ve heard it before: "Just do practice questions." But simply grinding through questions without a strategy is a fast track to frustration, not a pass. The real trap for CIA Part 2 isn't a lack of knowledge, it's failing to understand why an answer is correct and, crucially, why the tempting wrong ones fall short. This part of the exam demands sophisticated judgment, not rote memorization.
To pass CIA Part 2, a strategic approach to practice questions is non-negotiable. It involves active engagement with detailed explanations, understanding the nuances of internal audit practice, and recognizing the examiner's intent. This section of the exam focuses on how internal audit activities are managed, planned, and performed, requiring you to apply the Standards rather than just recall them.
The CIA exam has a <50% pass rate.
VoraPrep's AI finds your weak spots before the exam does — adaptive practice that actually moves your score.
Why Practice Questions Matter: Your 7-Day Performance Sprint Starts Here
The CIA exam's overall pass rate hovers around 40-45%, which tells you one thing: it's tough, and it separates those who truly grasp the material from those who just skim. For Part 2, "Practice of Internal Auditing," the challenge isn't just recalling the IIA Standards; it's applying them to complex scenarios, making judgments, and knowing the implications of various audit decisions. This is where practice questions become your most potent weapon.
Simply reading your study text is passive learning. You might recognize the information, but can you apply it under pressure? High-quality practice questions force you into active learning. They make you retrieve information, analyze situations, and construct arguments for your chosen answer. This active recall strengthens memory pathways far more effectively than re-reading.
More importantly, practice questions are your diagnostic tool. They illuminate your weak areas—not just topics you don't know, but areas where your judgment might be misaligned with the IIA's expectations. Did you consistently miss questions on engagement planning? Or perhaps on communicating results? Pinpointing these gaps allows you to target your review, making your study time exponentially more efficient.
Finally, the CIA exam is a marathon. Part 2, like the others, requires stamina. Working through sets of questions under timed conditions builds your endurance, helping you manage the clock and maintain focus when it counts. It's not just about getting the right answer; it's about getting it right under exam conditions.
10 Free Practice of Internal Auditing Practice Questions (2026)
Ready to dig in? Here are 10 practice questions designed to mirror the difficulty and style of the 2026 CIA Part 2 exam. For each, try to answer it first, then read the detailed explanation, paying close attention to why the correct answer is right and why the distractors are wrong. This is your chance to start thinking like the examiner.
---
Question 1: Managing the Internal Audit ActivityAn internal audit activity recently experienced a significant reduction in its budget, leading to the early retirement of several experienced auditors. The Chief Audit Executive (CAE) is now facing pressure to maintain the same level of audit coverage and quality with a smaller, less experienced team.
Which of the following actions should the CAE prioritize to address this challenge while adhering to the IIA Standards?
- A. Immediately reduce the scope of all planned engagements: While scope reduction might be necessary, an immediate and blanket reduction without a revised risk assessment is reactive and could lead to critical risks being unaddressed. The reduction should be strategic, not arbitrary. This is a tempting but shortsighted solution.
- B. Outsource all high-risk audit areas to a third-party provider: Outsourcing can be a viable strategy (Standard 2030: External Service Provider), but all high-risk areas might be excessive and costly, potentially diluting the internal audit's unique organizational knowledge. It also might not be feasible given the budget reduction.
- C. Reassess the internal audit's risk assessment and audit plan, focusing on critical organizational risks and leveraging technology where possible: This is the most appropriate and strategic response. Standard 2010 requires the CAE to establish a risk-based plan. A significant change in resources necessitates a re-evaluation of this plan to ensure audit resources are focused on the most critical areas. Leveraging technology (e.g., data analytics) can significantly enhance efficiency and coverage with fewer resources, directly addressing the core problem. This demonstrates a proactive, value-driven approach.
- D. Implement a rapid, in-house training program: While staff development is vital (Standard 1210: Proficiency and Due Professional Care), a rapid program cannot instantly replicate the experience of retired auditors and might not be sufficient to maintain quality for complex audits without a concurrent re-prioritization of the audit plan. This is a good long-term step, but not the immediate priority for maintaining coverage and quality given the current constraints.
---
Question 2: Nature of WorkDuring an audit of the accounts payable process, the internal audit team discovered that a significant number of invoices were being paid without proper three-way matching (purchase order, receiving report, and vendor invoice). This control weakness has persisted for several months.
Which of the following is the most appropriate next step for the internal audit team, according to the IIA Standards?
- A. Immediately inform the external auditors: While internal audit findings might be relevant to external auditors, the internal audit team's primary reporting line is to management and the audit committee. Informing external auditors directly before discussing with management is premature and bypasses the proper communication channels. This is a common wrong answer if you confuse internal audit's role with external audit's.
- B. Expand the audit scope to quantify the total monetary impact: Quantifying impact is an important part of documenting findings, but it's not necessarily the most appropriate next step before communicating and recommending. The immediate priority is to document the finding and engage with management. The scope expansion should be part of the deeper analysis to support the recommendation, not a standalone "next step" that delays communication.
- C. Document the findings, discuss them with management, and recommend corrective actions to strengthen the control: This aligns perfectly with Standard 2410: Criteria for Communicating (accuracy, objectivity, clarity, conciseness, constructive, completeness, timeliness) and Standard 2420: Quality of Communications. The internal audit's role is to identify issues, communicate them effectively to the relevant management, and propose solutions. This is the cornerstone of a constructive audit engagement.
- D. Suspend the audit and escalate the issue directly to the audit committee: While the control failure is significant, direct escalation to the audit committee before discussing with management is generally reserved for situations where management is unresponsive, involved in fraud, or when the issue is so egregious it bypasses normal lines of authority (e.g., ethical breaches involving senior leadership). For a control weakness, the normal process involves management first.
---
Question 3: Performing the EngagementAn internal audit team is conducting an engagement to evaluate the effectiveness of the organization's cybersecurity controls. During the testing phase, the team discovers a critical vulnerability in a widely used web application that could allow unauthorized external access to sensitive customer data.
According to the IIA Standards, what is the internal audit team's immediate responsibility upon discovering this critical vulnerability?
- A. Complete all planned testing before reporting: Delaying the report until all testing is complete is a significant risk. The critical nature of a cybersecurity vulnerability means that every hour it remains unaddressed increases the organization's exposure. This is a common mistake for auditors who prioritize process over immediate risk mitigation.
- B. Immediately report the vulnerability to relevant management and recommend urgent remedial action: This is the correct action. Standard 2420 states that communications should be timely. For critical issues, this means immediate, even if preliminary, reporting to allow management to take corrective action before the situation escalates. The internal audit's role is to facilitate risk mitigation.
- C. Attempt to exploit the vulnerability further: While penetration testing can be part of an audit, an internal audit team should only perform such actions if they have the necessary expertise, tools, and prior authorization to do so. Uncontrolled exploitation could cause harm, violate ethical guidelines, or even be illegal. Their immediate responsibility is to report, not to become a threat actor.
- D. Document the finding and include it in the final audit report: This is insufficient. While documentation for the final report is necessary, waiting until the end of the engagement to report a critical vulnerability is a failure of due professional care and could expose the organization to significant harm.
---
Question 4: Communicating Engagement ResultsThe CAE is preparing the annual internal audit activity report for the board and senior management. The report needs to summarize the internal audit's activities, significant findings, and adherence to its charter.
Which of the following elements is most critical to include in this annual report, according to the IIA Standards?
- A. A comprehensive list of all minor control weaknesses: While significant findings should be reported, including all minor weaknesses might clutter the report and obscure the most important issues for the board and senior management. The report should focus on significant risks and findings.
- B. A detailed breakdown of the internal audit activity's budget utilization: While budget information is important for internal audit management, it's not explicitly required by Standard 2060 for the annual report to the board in the same way as conformance with Standards.
- C. An assurance statement regarding the internal audit activity's conformance with the International Standards for the Professional Practice of Internal Auditing (Standards): This is explicitly required by Standard 2060. The CAE must report periodically to senior management and the board on the internal audit activity’s purpose, authority, responsibility, and performance relative to its plan and conformance with the Standards. This ensures the board has confidence in the internal audit function itself.
- D. A projection of staffing needs and training plans: This is relevant for strategic planning and resource management but is not a core, mandatory element for the annual report to the board as specified by Standard 2060.
---
Question 5: Engagement PlanningAn internal audit engagement is being planned for a new e-commerce platform. The platform processes millions of transactions annually and handles sensitive customer payment information. The audit objective is to assess the adequacy of security controls.
Which of the following is the most crucial consideration for the internal audit team when defining the scope of this engagement?
- A. The total number of transactions processed: While transaction volume indicates materiality and risk, it's a quantitative metric. The type of data and regulatory requirements are more direct drivers for defining the scope of security controls. This is a tempting distractor that indicates volume but not the specific regulatory or data sensitivity issues.
- B. The platform's compliance with Payment Card Industry Data Security Standard (PCI DSS) requirements: This is the most crucial consideration. Given the platform handles sensitive customer payment information, PCI DSS compliance is a critical regulatory and industry standard that directly dictates the required security controls. Assessing compliance with such a standard directly addresses the audit objective of "adequacy of security controls" for payment data. This is a non-negotiable aspect of this type of audit.
- C. The availability of internal audit staff with e-commerce and cybersecurity expertise: This is an important resource consideration (Standard 2030: Resource Management), but it defines the feasibility of the audit, not the most crucial element for defining the scope. The scope should first be defined based on risk and objectives, then resources are allocated or acquired.
- D. The previous audit findings related to the organization's legacy e-commerce system: Previous findings can provide valuable context and inform the risk assessment (Standard 2201: Planning Considerations), but a new platform may have different architecture, risks, and controls. Focusing solely on legacy issues might overlook new or different risks inherent in the new system.
---
Question 6: Managing the Internal Audit Activity - Quality AssuranceThe CAE is establishing a Quality Assurance and Improvement Program (QAIP) for the internal audit activity.
According to the IIA Standards, which of the following is a mandatory component of the QAIP?
- A. An external assessment conducted at least once every five years by a qualified, independent reviewer: This is an explicit, mandatory requirement under Standard 1312. External assessments provide an independent evaluation of the internal audit activity's conformance with the Standards and its effectiveness.
- B. A comprehensive annual survey of all auditees: While auditee feedback is valuable and often part of an internal assessment (Standard 1311: Internal Assessments), it is not a mandatory component of the QAIP itself as defined by the Standards.
- C. Regular peer reviews conducted by auditors from other departments: Peer reviews can be part of an internal assessment, but they are not the same as the mandatory external assessment. Auditors from other departments may not possess the independence or specific expertise to conduct a formal peer review of the internal audit function's conformance with the Standards.
- D. Formal certification of all internal auditors: While professional certification like the CIA is highly encouraged and speaks to proficiency (Standard 1210: Proficiency), it is not a mandatory component of the QAIP itself, nor is it explicitly required for all internal auditors by the Standards.
---
Question 7: Applying Audit ProceduresAn internal auditor is reviewing expense reports for potential fraud. The auditor notices a pattern where a specific employee consistently submits expense reports just below the approval threshold requiring a second signature. The amounts are often rounded, and the descriptions are vague.
Which audit procedure would be most effective in investigating this suspicious pattern?
- A. Interview the employee's direct supervisor: While useful for gathering context, interviewing the supervisor first might alert the employee prematurely or give the supervisor an opportunity to cover up. It's better to gather more objective evidence first.
- B. Review a random sample of other employees' expense reports: A random sample might miss similar patterns, especially if they are not widespread. This approach is less targeted and efficient than data analytics for pattern detection.
- C. Perform data analytics on all expense reports to identify other employees with similar patterns and the frequency of submissions just below approval thresholds: This is the most effective procedure. Data analytics can efficiently process large volumes of data to identify precise patterns, such as expenses just below thresholds, rounded amounts, and vague descriptions across all employees. This provides objective evidence, quantifies the potential issue, and identifies if it's an isolated incident or a systemic problem before any direct confrontation. This is a prime example of leveraging technology to enhance audit efficiency and effectiveness.
- D. Immediately confront the employee: Confrontation should only occur after sufficient objective evidence has been gathered and carefully considered. Immediate confrontation without a strong evidentiary basis can be counterproductive, leading to denial, destruction of evidence, or even legal issues.
---
Question 8: Managing the Internal Audit Activity - Independence and ObjectivityThe CAE of a publicly traded company is asked by the CEO to lead a critical project team focused on implementing a new enterprise resource planning (ERP) system. The CEO assures the CAE that this is a temporary assignment, lasting approximately six months, after which the CAE will return to full internal audit duties.
According to the IIA Standards, how should the CAE respond to this request?
- A. Accept the assignment, provided the internal audit activity formally re-evaluates its annual audit plan: Even with a re-evaluation and exclusion, the CAE would have been directly involved in the system's design and implementation. This creates a self-review threat that cannot be fully mitigated, as the CAE would be auditing their own work (or work they oversaw) in the future.
- B. Decline the assignment, as leading the implementation team would impair the internal audit activity's independence and the CAE's objectivity regarding future audits of the ERP system: This is the correct response. Standard 1120 explicitly states that internal auditors must have an impartial, unbiased attitude and avoid conflicts of interest. Performing operational duties, even temporarily, would create a significant self-review threat and impair the CAE's objectivity when the internal audit activity eventually audits the ERP system. The CAE's independence is crucial for the credibility of the internal audit function.
- C. Accept the assignment, but ensure that another senior auditor reports directly to the audit committee: While this attempts to mitigate, it doesn't resolve the fundamental impairment of the CAE's objectivity regarding the ERP system. The CAE is ultimately responsible for the internal audit activity, and their involvement in the ERP implementation would still taint the internal audit's ability to provide truly independent assurance on that system.
- D. Accept the assignment, as it provides valuable operational experience: While operational experience can be beneficial, it cannot come at the cost of independence and objectivity, which are foundational principles of internal auditing. The risk to the internal audit function's credibility outweighs the benefit of temporary operational experience.
---
Question 9: Engagement Planning - Risk Assessment ExampleAn internal audit team is planning an audit of a company's new customer relationship management (CRM) system. The system went live six months ago, integrates with billing and customer service, and stores personally identifiable information (PII).
To develop a risk-based audit plan for this system, which of the following risk factors should the internal auditor quantify or assess with the highest priority?
- A. The number of customer complaints: While customer complaints indicate operational issues and potential control weaknesses, they primarily reflect service quality or minor errors. They are important, but typically less severe than legal/regulatory risks.
- B. The volume of data migrated: Data volume is relevant to the scale of the system and potential impact of a breach, but it doesn't directly quantify the risk itself in terms of consequences. It's an input to risk assessment, not the highest priority risk factor to quantify.
- C. The potential regulatory fines for PII breaches under GDPR or CCPA: This is the highest priority. The system stores PII, making it subject to stringent data privacy regulations like GDPR (General Data Protection Regulation) or CCPA (California Consumer Privacy Act). A breach of PII could lead to significant financial penalties (e.g., up to 4% of global annual revenue for GDPR), reputational damage, and legal action. Quantifying these potential fines directly assesses the most severe consequence of a critical control failure related to PII. This is the "real numbers" aspect of the risk.
- Worked Example: If the company has a global annual revenue of $500 million, a GDPR fine could be up to $20 million (4% of $500M). This immediate, quantifiable impact on the business makes it a critical risk to assess.
- D. The cost incurred by the IT department for system maintenance: Maintenance costs are operational expenses. While cost overruns might indicate inefficiency, they do not represent the same level of strategic, financial, or reputational risk as a major data breach with regulatory fines.
---
Question 10: Monitoring Progress and Follow-UpFollowing an internal audit, management agreed to implement a new access control system to address a significant security vulnerability. The implementation deadline was set for three months from the audit report date. Six months have passed, and the internal audit team has received no update from management.
What is the most appropriate action for the CAE to take in this situation?
- A. Close the audit issue: This is incorrect. The internal audit activity is responsible for following up on audit findings to ensure corrective actions have been effectively implemented (Standard 2500.A1). Closing an issue without confirmation defeats the purpose of the audit and leaves the organization exposed to the identified risk. This is a common wrong answer for auditors who believe their job ends at reporting.
- B. Conduct a full re-audit: A full re-audit might be necessary if the issue remains unresolved for an extended period, but the most appropriate first step is to inquire about the status. A full re-audit is resource-intensive and premature without understanding why the action was delayed.
- C. Contact management to ascertain the status of the corrective action and, if necessary, escalate the issue to senior management or the audit committee: This is the correct action. The CAE must monitor the status of corrective actions. If there's an unexplained delay, the CAE needs to follow up with the responsible management. If management remains unresponsive or the delay poses a significant risk, escalation to senior management and ultimately the audit committee is appropriate to ensure the risk is addressed. This demonstrates due professional care and accountability.
- D. Extend the deadline for another three months: Unilaterally extending the deadline without communication or understanding the reason for the delay is irresponsible. The internal audit activity's role is to ensure risks are mitigated, not to passively accept delays.
---
How These Questions Were Chosen
These 10 practice questions aren't just random picks; they're strategically crafted to prepare you for the nuances of the CIA Part 2 exam. We design our VoraPrep questions to mirror the actual exam's difficulty and style, focusing on several key areas:
- Mirrors Actual Exam Difficulty: The CIA Part 2 isn't about easy wins. Our questions are designed to make you think critically, often requiring you to weigh multiple plausible options, just like on exam day. They push you beyond simple recall to application and analysis.
- Covers Key Blueprint Areas: We've ensured these questions touch upon the most heavily weighted domains of the Part 2 syllabus: managing the internal audit activity, planning engagements, performing engagements, communicating results, and monitoring progress. This gives you a taste of the breadth of topics you'll encounter.
- Common Mistake Triggers: Each question explanation highlights a "tempting wrong answer" and explains why it's a trap. This is crucial for developing your judgment. Examiners often design distractors based on common misunderstandings or partial knowledge. By identifying these, you learn to spot them on the real exam.
- High-Value Concepts: We focus on concepts that are frequently tested and fundamental to internal audit practice, such as independence, objectivity, risk-based planning, and communication protocols. Mastering these core principles is essential for a passing score.
How to Use Practice Questions Effectively: Your 7-Day Sprint
Simply answering questions isn't enough. To truly benefit, you need a structured approach. Here's a 7-day sprint plan to maximize your learning from practice questions for CIA Part 2:
Day 1: Baseline Assessment & Setup
- Action: Take a set of 10-20 Part 2 practice questions under timed conditions (e.g., 90 seconds per question).
- Goal: Establish a baseline score and experience exam pressure. Don't worry about the score too much; this is diagnostic.
- Tip: Ensure you're in a quiet environment, mimicking exam conditions. Use a scratchpad.
Day 2: Deep Dive - Every Answer Matters
- Action: Review every single question from Day 1, not just the ones you got wrong.
- Goal: Understand the "why." For correct answers, confirm your reasoning aligns with the explanation. For incorrect answers, identify exactly why you chose wrong and why the correct answer is superior. Pay close attention to the tempting wrong answers.
- Tip: Create a short summary note for each question, capturing the key concept or standard it tested. This is active recall.
Day 3: Identify & Track Weaknesses
- Action: Analyze your Day 1 and 2 results. Categorize your incorrect answers by topic (e.g., "Independence," "Engagement Planning," "Monitoring Progress").
- Goal: Pinpoint specific knowledge gaps or areas where your judgment differs from the IIA's. Is there a pattern? (e.g., consistently missing questions about quality assurance).
- Tip: Use a simple spreadsheet. Column 1: Question Topic. Column 2: Your Answer. Column 3: Correct Answer. Column 4: Why I got it wrong (e.g., "misunderstood Standard 1120," "didn't prioritize risk consequence").
Day 4: Targeted Review & Re-engagement
- Action: Revisit your study materials for the specific topics identified on Day 3. Focus on understanding the underlying IIA Standards or best practices. Then, attempt 10-15 new practice questions specifically on those weak topics.
- Goal: Strengthen your understanding of challenging areas.
- Tip: Don't just read. Create flashcards, explain the concept aloud, or teach it to an imaginary student.
Day 5: Spaced Repetition Integration
- Action: Incorporate questions from previous days' weak areas into a new, mixed set of 20 questions. Ensure some questions are from topics you previously mastered to maintain recall.
- Goal: Reinforce learning over time and combat the forgetting curve.
- Tip: Use a spaced repetition system (like Anki or even manual flashcards) for key definitions, standards, and concepts you struggle with.
Day 6: Scenario Application & Judgment
- Action: Focus on scenario-based questions. For each question, practice articulating your thought process before selecting an answer. What are the key facts? What standards apply? What are the potential consequences of each option?
- Goal: Develop your "examiner mindset" – the ability to discern the best course of action under internal audit principles.
- Tip: If possible, discuss a few questions with a study partner. Explaining your reasoning aloud is a powerful learning tool.
Day 7: Full Mini-Mock & Refine Strategy
- Action: Take a longer set of 30-50 questions under strict timed conditions, simulating a mini-exam.
- Goal: Assess overall progress, identify any remaining persistent weak spots, and refine your exam-taking strategy (e.g., pacing, skipping difficult questions).
- Tip: Treat this as a real exam. No distractions. Afterward, perform a concise review of only the questions you got wrong, noting why you missed them.
---
Quick Reference: Effective Practice Question Checklist| Step | Description | Status |
|---|---|---|
| Timed Practice | Simulate exam conditions to build stamina and pacing. | |
| Detailed Review | Analyze every answer (right and wrong) for underlying principles. | |
| Identify Weaknesses | Categorize mistakes by topic and type of error (knowledge vs. judgment). | |
| Targeted Study | Revisit study materials specifically for identified weak areas. | |
| Spaced Repetition | Re-attempt past incorrect questions at intervals to reinforce learning. | |
| Explain Reasoning | Articulate why each answer is correct/incorrect, not just memorizing. | |
| Don't Overlook "Easy" | Review correct answers to confirm your reasoning aligns with expert explanations. |
---
Get 2,000+ More Practice of Internal Auditing Questions
These 10 questions are just a glimpse. To truly master CIA Part 2 and pass with confidence, you'll need a comprehensive question bank that goes far beyond a sample set. VoraPrep offers an extensive library of over 2,000 practice questions specifically designed for the CIA exam, covering all three parts.
Our adaptive learning engine intelligently targets your weak areas, serving you questions that will challenge you most and maximize your study efficiency. No more wasting time on concepts you already know. Plus, every single question comes with a detailed, AI-written explanation that not only tells you the right answer but also why it's right and why the common distractors are wrong – exactly the "judgment-first" approach you need. And if you ever get stuck, our AI tutor, Vory, is available 24/7 to provide instant clarification.
Don't leave your CIA Part 2 pass to chance. A robust question bank is the single most important tool for success. You can get started for just $19/month or $149/year, with a 7-day free trial to experience the difference.
Related Resources
- CIA Practice of Internal Auditing Cheat Sheet (2026): Key Formulas, Rules, and Mnemonics — cia cia2 cheat sheet
- Free CIA Essentials of Internal Auditing Practice Questions (2026)
- Free CIA Business Knowledge for Internal Auditing Practice Questions (2026)
- Complete CIA Essentials of Internal Auditing Study Guide 2026 — cia cia1 study guide
- Complete CIA Business Knowledge for Internal Auditing Study Guide 2026 — cia cia3 study guide
- Best CIA Review Courses in 2026: Honest Comparison (Including Free Options) — Compare the best CIA review courses for 2026 — honest breakdowns of price, question banks, and pass
- CIA Essentials of Internal Auditing Cheat Sheet (2026): Key Formulas, Rules, and Mnemonics — cia cia1 cheat sheet
Frequently asked questions
Q: How many hours should I study for CIA Part 2? A: Most successful candidates dedicate between 100-150 hours specifically for CIA Part 2. This includes time for reviewing material, practicing questions, and taking mock exams. The total study time for all three parts of the CIA exam typically ranges from 300-500 hours. Q: Is CIA Part 2 harder than Part 1? A: Part 2 is often considered more challenging than Part 1 because it moves beyond foundational concepts to require application of the IIA Standards and sophisticated judgment in practical internal audit scenarios. It demands a deeper understanding of how internal audit functions in the real world, rather than just what internal audit is. Q: What topics are heavily tested on CIA Part 2? A: CIA Part 2 focuses on the "Practice of Internal Auditing." Heavily tested areas include managing the internal audit activity (e.g., independence, objectivity, QAIP), planning engagements (e.g., risk assessment, scope definition), performing engagements (e.g., audit procedures, evidence), communicating engagement results, and monitoring progress/follow-up. Understanding the IIA Standards is crucial for all these topics. Q: Can I pass CIA Part 2 using only free practice questions? A: While free practice questions are excellent for initial assessment and targeted review, relying solely on them is risky given the exam's difficulty and depth. A comprehensive review course with a large, high-quality question bank (like VoraPrep's 2,000+ questions) and adaptive learning technology significantly increases your chances of passing.Official resources and references
- The Institute of Internal Auditors (IIA) Certifications: Official information on the CIA program, exam content, and candidate handbook.
- U.S. Bureau of Labor Statistics - Accountants and Auditors: Information on salaries and job outlook for related professions, including internal auditors.