CIA Exam · 8 min read 2026 Blueprint Verified

IIA Global Internal Audit Standards on the 2026 CIA Exam: What Changed?

Rob Pfleghardt

10-year Price Waterhouse alumnus · Founder of VoraPrep · Former CPA (1987–2024) · with the VoraPrep Editorial Team

Key Takeaways

  • Effective Implementation Date: January 9, 2025 (all 2026 CIA exams test GIAS exclusively).
  • Structural Architecture: Replaces legacy IPPF with 5 Domains, 15 Principles, and 52 Standards.
  • Governance Elevation: Domain III explicitly codifies the Board's responsibilities for authorizing, resourcing, and overseeing the internal audit function.
  • Ethics Integration: The IIA Code of Ethics is now directly incorporated as Domain II (Ethics and Professionalism).
  • Public Sector & Small Functions: Includes special application considerations for public sector audits and small internal audit departments.
  • CIA Exam Format: Part 1 (125 MCQs, 2.5 hours); Part 2 (100 MCQs, 2.0 hours); Part 3 (100 MCQs, 2.0 hours). Passing standard is 600 on a 250-750 scaled score.
Quick answer

The transition to the Global Internal Audit Standards (GIAS) represents the most significant overhaul to the Certified Internal Auditor (CIA) syllabus in over a decade. All CIA exams administered in 2026 test the new five-domain structure (Purpose, Ethics, Governance, Management, and Performance), replacing the legacy International Professional Practices Framework (IPPF) 2017 standards.

In January 2024, the Institute of Internal Auditors (IIA) published the new Global Internal Audit Standards (GIAS), which officially became effective on January 9, 2025. Following a phased syllabus transition, all three parts of the Certified Internal Auditor (CIA) examination administered worldwide are now based exclusively on the new GIAS framework.

Candidates preparing for the 2026 CIA exam cannot rely on older study materials or 2023 question banks. The new standards do not merely rename terms; they redefine the Chief Audit Executive (CAE) relationship with the Board, restructure mandatory ethical requirements, and alter the technical criteria for engagement planning and reporting.

Below is the definitive, operational breakdown of what changed, how the five domains map to CIA Parts 1, 2, and 3, and how to adapt your study strategy to pass on your first attempt.

Free 5-Min Diagnostic

Studying for CIA ALL? Benchmark your score in 5 minutes.

Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.

Key facts

  • Effective Implementation Date: January 9, 2025 (all 2026 CIA exams test GIAS exclusively).
  • Structural Architecture: Replaces legacy IPPF with 5 Domains, 15 Principles, and 52 Standards.
  • Governance Elevation: Domain III explicitly codifies the Board's responsibilities for authorizing, resourcing, and overseeing the internal audit function.
  • Ethics Integration: The IIA Code of Ethics is now directly incorporated as Domain II (Ethics and Professionalism).
  • Public Sector & Small Functions: Includes special application considerations for public sector audits and small internal audit departments.
  • CIA Exam Format: Part 1 (125 MCQs, 2.5 hours); Part 2 (100 MCQs, 2.0 hours); Part 3 (100 MCQs, 2.0 hours). Passing standard is 600 on a 250-750 scaled score.

The Structural Shift: Old IPPF (2017) vs. New GIAS (2024–2026)

Under the legacy 2017 IPPF, internal audit standards were organized into Attribute Standards (1000 series) and Performance Standards (2000 series), supported by a separate Code of Ethics and Core Principles.

The new Global Internal Audit Standards eliminate this disjointed structure, organizing all mandatory guidance into a unified, sequential hierarchy:

Standard ComponentLegacy IPPF (2017)New Global Internal Audit Standards (GIAS 2026)Exam Weight Shift
Overarching FrameworkAttribute & Performance Standards5 Sequential Domains with 15 Core PrinciplesRestructures all 3 parts
Ethics & ConductSeparate standalone Code of EthicsDomain II: Ethics & Professionalism (5 Principles)Central focus of Part 1
Board Oversight & CharterStandard 1000 (Individual Attribute)Domain III: Governing the Internal Audit FunctionElevated in Part 1 & Part 2
Department ManagementStandard 2000 seriesDomain IV: Managing the Internal Audit FunctionCore syllabus of Part 2
Engagement ExecutionStandard 2200 to 2400 seriesDomain V: Performing Internal Audit ServicesPrimary focus of Part 2
Application GuidanceImplementation Guides (Non-mandatory)Considerations for Implementation (Embedded)Tested as practical judgment

The 5 GIAS Domains and Their Exam Blueprint Impact

Domain I: Purpose of Internal Auditing

Domain I articulates why internal auditing exists: to strengthen the organization's ability to create, protect, and sustain value by providing the board and management with independent, risk-based, and objective assurance, advice, insight, and foresight. On the exam, questions test your ability to distinguish between assurance and advisory engagements.

Domain II: Ethics and Professionalism

Domain II consolidates professional conduct into five distinct principles:
  1. Integrity: Demonstrating honesty and moral courage in challenging audit situations.
  2. Objectivity: Maintaining an unbiased mental attitude and identifying real or perceived conflicts of interest.
  3. Competency: Applying professional knowledge, skills, and continuous professional development (CPE).
  4. Due Professional Care: Applying the diligence and skill expected of a reasonably prudent internal auditor.
  5. Confidentiality: Protecting sensitive organizational data and proprietary records.

Domain III: Governing the Internal Audit Function

Domain III represents the most dramatic conceptual shift on the exam. It bridges internal audit with the Board of Directors and senior management:
  • Principle 6 (Board Mandate): The board authorizes the internal audit mandate through a formal, documented Internal Audit Charter.
  • Principle 7 (Independence): The Chief Audit Executive must report functionally to the board and administratively to executive management.
  • Principle 8 (Board Oversight): The board must approve the internal audit plan, budget, resource allocation, and CAE performance evaluation.

Domain IV: Managing the Internal Audit Function

Domain IV addresses the strategic and operational management of the department, which forms the backbone of CIA Part 2:
  • Strategic planning and annual risk-based audit plan methodology.
  • Human capital management, technical resource allocation, and external co-sourcing.
  • Quality Assurance and Improvement Program (QAIP), including internal ongoing monitoring and mandatory external assessments every five years.

Domain V: Performing Internal Audit Services

Domain V covers end-to-end engagement workflows:
  • Engagement Planning: Setting objectives, defining scope, establishing criteria, and developing the work program.
  • Fieldwork & Evidence: Testing internal controls, evaluating root causes, and applying statistical sampling.
  • Findings & Communication: Documenting condition, criteria, cause, and effect, and formulating actionable recommendations.
  • Monitoring Progress: Tracking management action plans until remediation is verified.

How GIAS Alters Each Part of the 2026 CIA Examination

CIA Part 1: Essentials of Internal Auditing

Part 1 is where the GIAS transition is felt most acutely. Over 45% of Part 1 questions now originate directly from Domains I, II, and III. Candidates must master ethical dilemmas where management pressures an auditor to alter findings, evaluating whether independence or objectivity has been compromised.

CIA Part 2: Practice of Internal Auditing

Part 2 aligns directly with Domains IV and V. Questions emphasize practical execution: evaluating engagement risk assessments, selecting sampling techniques, and drafting clear audit observations. Understanding root-cause analysis is now a heavily tested skill under GIAS Principle 14.

CIA Part 3: Business Knowledge for Internal Auditing

While Part 3 primarily tests external disciplines (Financial Management, Information Security, and Business Acumen), GIAS elevates cybersecurity governance and third-party risk management. Auditors must evaluate organizational resilience and IT controls through the lens of Domain IV risk management standards.

Worked Example: Assessing Functional Reporting and Board Independence

Consider a common scenario tested under GIAS Domain III on CIA Part 1:

Scenario: The Chief Executive Officer (CEO) of Acme Corp informs the Chief Audit Executive (CAE) that due to corporate restructuring, the internal audit budget for the upcoming fiscal year will be reduced by 35%, eliminating planned audits of foreign subsidiaries. The CEO states that because administrative reporting flows through the executive suite, budget decisions are within management's sole discretion. The CAE is instructed not to present the original risk-based audit plan to the Audit Committee.

How to Analyze Under GIAS Standards:

  1. Identify the Core Standard: GIAS Principle 7 (Organizational Independence) and Principle 8 (Board Oversight).
  2. Evaluate Functional vs. Administrative Authority: Under GIAS Standard 7.1 and 8.1, the board is responsible for approving the internal audit budget and resource plan. While executive management handles day-to-day administrative matters (payroll, expense approvals), management cannot unilaterally restrict internal audit resources.
  3. The Required Auditor Action: The CAE must maintain objectivity and integrity (Domain II). Under GIAS Standard 8.3, the CAE is strictly required to inform the board of the budget limitation and explain the operational risks of omitting foreign subsidiary audits. Conforming to the CEO's directive to conceal the budget reduction from the board is an ethical violation.

How to Prepare for the 2026 GIAS-Aligned CIA Exam

  1. Discard Pre-2025 Study Materials: Legacy IPPF questions will mislead you on reporting hierarchies, charter approvals, and quality assurance terminology. Use a platform updated explicitly for GIAS, such as VoraPrep CIA Review.
  2. Focus on Practical Application: The IIA tests application-level and analysis-level Bloom's taxonomy. Memorizing the 15 principles is insufficient; you must be able to apply them to tricky workplace scenarios.
  3. Master Domain III Mechanics: Board governance and charter authority questions are high-frequency targets across Parts 1 and 2. Understand exactly which decisions require board approval versus management consultation.

Frequently asked questions

When did the Global Internal Audit Standards officially take effect on the CIA exam?

The new standards were published in January 2024 and became mandatory worldwide on January 9, 2025. All CIA exam parts administered in 2026 are based 100% on the new Global Internal Audit Standards.

What is the biggest difference between the old IPPF and the new GIAS?

The biggest difference is the structural consolidation into five cohesive domains and the explicit elevation of board governance (Domain III). The new standards clearly delineate the board's fiduciary responsibilities in supporting and protecting internal audit independence.

Does the CIA exam passing score change under the new standards?

No. The passing score remains 600 on a scaled score range of 250 to 750 across all three parts. Raw scores are converted using psychometric equating to ensure uniform difficulty across testing windows.

What is the best sequence to take the CIA exam under GIAS?

The recommended order is Part 1, Part 2, and Part 3. Part 1 establishes the foundational GIAS standards and ethics that are directly tested and applied in Part 2. Part 3 should be completed last as it covers broader business, finance, and IT concepts. Read our CIA Exam Part Order Guide for full details.

What is the most cost-effective way to study for the 2026 CIA exam?

VoraPrep provides a comprehensive, fully GIAS-updated study system with 4,800+ adaptive questions, Prometric mock exam simulation, and a 24/7 AI tutor for just $149/year (or $19/month). Explore our CIA review course under $500 guide to get started.
⚡ Instant Knowledge Check · 1-Click Test Drive
CIA Part 1: Essentials of Internal Auditing

Under the IIA Global Internal Audit Standards (Domain III: Governing the Internal Audit Function), who has the ultimate responsibility for ensuring the organizational independence of the internal audit activity?

✨ Free 5-Min Assessment

Test Your CIA Exam Readiness

Evaluate your mastery of the new Global Internal Audit Standards and benchmark your baseline readiness.

Take Free CIA Quiz →

Official resources and references

RP

About the Author: Rob Pfleghardt

Rob Pfleghardt is the founder of VoraPrep, a comprehensive exam prep platform for the CPA, CMA, EA, CIA, CISA, and CFP exams. A Virginia Tech graduate in Accounting and Finance, Rob began his career at Price Waterhouse, spending a decade in audit and IT consulting. After holding a CPA license for 37 years (1987–2024) and successfully scaling his own enterprise IT consultancy serving the Department of Defense, Rob launched VoraPrep. He now leverages his deep systems architecture background to build the adaptive training technology and curriculum that helps candidates pass their certification exams efficiently.

Connect with Rob on LinkedIn →
Free Diagnostic Assessment

Find your exact CIA weak spots in 10 minutes.

Most candidates fail because they study blindly. Take our free 10-question diagnostic to identify your weakest blueprint topics and receive a custom 12-week study plan PDF generated instantly.

Keep reading

Free 5-min CIA diagnostic + 12-week plan PDF

Start →
CIA 1:1 Prometric Simulator

4,800+ practice questions with instant Socratic feedback