The transition to the Global Internal Audit Standards (GIAS) represents the most significant overhaul to the Certified Internal Auditor (CIA) syllabus in over a decade. All CIA exams administered in 2026 test the new five-domain structure (Purpose, Ethics, Governance, Management, and Performance), replacing the legacy International Professional Practices Framework (IPPF) 2017 standards.
In January 2024, the Institute of Internal Auditors (IIA) published the new Global Internal Audit Standards (GIAS), which officially became effective on January 9, 2025. Following a phased syllabus transition, all three parts of the Certified Internal Auditor (CIA) examination administered worldwide are now based exclusively on the new GIAS framework.
Candidates preparing for the 2026 CIA exam cannot rely on older study materials or 2023 question banks. The new standards do not merely rename terms; they redefine the Chief Audit Executive (CAE) relationship with the Board, restructure mandatory ethical requirements, and alter the technical criteria for engagement planning and reporting.
Below is the definitive, operational breakdown of what changed, how the five domains map to CIA Parts 1, 2, and 3, and how to adapt your study strategy to pass on your first attempt.
Studying for CIA ALL? Benchmark your score in 5 minutes.
Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.
Key facts
- Effective Implementation Date: January 9, 2025 (all 2026 CIA exams test GIAS exclusively).
- Structural Architecture: Replaces legacy IPPF with 5 Domains, 15 Principles, and 52 Standards.
- Governance Elevation: Domain III explicitly codifies the Board's responsibilities for authorizing, resourcing, and overseeing the internal audit function.
- Ethics Integration: The IIA Code of Ethics is now directly incorporated as Domain II (Ethics and Professionalism).
- Public Sector & Small Functions: Includes special application considerations for public sector audits and small internal audit departments.
- CIA Exam Format: Part 1 (125 MCQs, 2.5 hours); Part 2 (100 MCQs, 2.0 hours); Part 3 (100 MCQs, 2.0 hours). Passing standard is 600 on a 250-750 scaled score.
The Structural Shift: Old IPPF (2017) vs. New GIAS (2024–2026)
Under the legacy 2017 IPPF, internal audit standards were organized into Attribute Standards (1000 series) and Performance Standards (2000 series), supported by a separate Code of Ethics and Core Principles.
The new Global Internal Audit Standards eliminate this disjointed structure, organizing all mandatory guidance into a unified, sequential hierarchy:
| Standard Component | Legacy IPPF (2017) | New Global Internal Audit Standards (GIAS 2026) | Exam Weight Shift |
|---|---|---|---|
| Overarching Framework | Attribute & Performance Standards | 5 Sequential Domains with 15 Core Principles | Restructures all 3 parts |
| Ethics & Conduct | Separate standalone Code of Ethics | Domain II: Ethics & Professionalism (5 Principles) | Central focus of Part 1 |
| Board Oversight & Charter | Standard 1000 (Individual Attribute) | Domain III: Governing the Internal Audit Function | Elevated in Part 1 & Part 2 |
| Department Management | Standard 2000 series | Domain IV: Managing the Internal Audit Function | Core syllabus of Part 2 |
| Engagement Execution | Standard 2200 to 2400 series | Domain V: Performing Internal Audit Services | Primary focus of Part 2 |
| Application Guidance | Implementation Guides (Non-mandatory) | Considerations for Implementation (Embedded) | Tested as practical judgment |
The 5 GIAS Domains and Their Exam Blueprint Impact
Domain I: Purpose of Internal Auditing
Domain I articulates why internal auditing exists: to strengthen the organization's ability to create, protect, and sustain value by providing the board and management with independent, risk-based, and objective assurance, advice, insight, and foresight. On the exam, questions test your ability to distinguish between assurance and advisory engagements.Domain II: Ethics and Professionalism
Domain II consolidates professional conduct into five distinct principles:- Integrity: Demonstrating honesty and moral courage in challenging audit situations.
- Objectivity: Maintaining an unbiased mental attitude and identifying real or perceived conflicts of interest.
- Competency: Applying professional knowledge, skills, and continuous professional development (CPE).
- Due Professional Care: Applying the diligence and skill expected of a reasonably prudent internal auditor.
- Confidentiality: Protecting sensitive organizational data and proprietary records.
Domain III: Governing the Internal Audit Function
Domain III represents the most dramatic conceptual shift on the exam. It bridges internal audit with the Board of Directors and senior management:- Principle 6 (Board Mandate): The board authorizes the internal audit mandate through a formal, documented Internal Audit Charter.
- Principle 7 (Independence): The Chief Audit Executive must report functionally to the board and administratively to executive management.
- Principle 8 (Board Oversight): The board must approve the internal audit plan, budget, resource allocation, and CAE performance evaluation.
Domain IV: Managing the Internal Audit Function
Domain IV addresses the strategic and operational management of the department, which forms the backbone of CIA Part 2:- Strategic planning and annual risk-based audit plan methodology.
- Human capital management, technical resource allocation, and external co-sourcing.
- Quality Assurance and Improvement Program (QAIP), including internal ongoing monitoring and mandatory external assessments every five years.
Domain V: Performing Internal Audit Services
Domain V covers end-to-end engagement workflows:- Engagement Planning: Setting objectives, defining scope, establishing criteria, and developing the work program.
- Fieldwork & Evidence: Testing internal controls, evaluating root causes, and applying statistical sampling.
- Findings & Communication: Documenting condition, criteria, cause, and effect, and formulating actionable recommendations.
- Monitoring Progress: Tracking management action plans until remediation is verified.
How GIAS Alters Each Part of the 2026 CIA Examination
CIA Part 1: Essentials of Internal Auditing
Part 1 is where the GIAS transition is felt most acutely. Over 45% of Part 1 questions now originate directly from Domains I, II, and III. Candidates must master ethical dilemmas where management pressures an auditor to alter findings, evaluating whether independence or objectivity has been compromised.CIA Part 2: Practice of Internal Auditing
Part 2 aligns directly with Domains IV and V. Questions emphasize practical execution: evaluating engagement risk assessments, selecting sampling techniques, and drafting clear audit observations. Understanding root-cause analysis is now a heavily tested skill under GIAS Principle 14.CIA Part 3: Business Knowledge for Internal Auditing
While Part 3 primarily tests external disciplines (Financial Management, Information Security, and Business Acumen), GIAS elevates cybersecurity governance and third-party risk management. Auditors must evaluate organizational resilience and IT controls through the lens of Domain IV risk management standards.Worked Example: Assessing Functional Reporting and Board Independence
Consider a common scenario tested under GIAS Domain III on CIA Part 1:
Scenario: The Chief Executive Officer (CEO) of Acme Corp informs the Chief Audit Executive (CAE) that due to corporate restructuring, the internal audit budget for the upcoming fiscal year will be reduced by 35%, eliminating planned audits of foreign subsidiaries. The CEO states that because administrative reporting flows through the executive suite, budget decisions are within management's sole discretion. The CAE is instructed not to present the original risk-based audit plan to the Audit Committee.How to Analyze Under GIAS Standards:
- Identify the Core Standard: GIAS Principle 7 (Organizational Independence) and Principle 8 (Board Oversight).
- Evaluate Functional vs. Administrative Authority: Under GIAS Standard 7.1 and 8.1, the board is responsible for approving the internal audit budget and resource plan. While executive management handles day-to-day administrative matters (payroll, expense approvals), management cannot unilaterally restrict internal audit resources.
- The Required Auditor Action: The CAE must maintain objectivity and integrity (Domain II). Under GIAS Standard 8.3, the CAE is strictly required to inform the board of the budget limitation and explain the operational risks of omitting foreign subsidiary audits. Conforming to the CEO's directive to conceal the budget reduction from the board is an ethical violation.
How to Prepare for the 2026 GIAS-Aligned CIA Exam
- Discard Pre-2025 Study Materials: Legacy IPPF questions will mislead you on reporting hierarchies, charter approvals, and quality assurance terminology. Use a platform updated explicitly for GIAS, such as VoraPrep CIA Review.
- Focus on Practical Application: The IIA tests application-level and analysis-level Bloom's taxonomy. Memorizing the 15 principles is insufficient; you must be able to apply them to tricky workplace scenarios.
- Master Domain III Mechanics: Board governance and charter authority questions are high-frequency targets across Parts 1 and 2. Understand exactly which decisions require board approval versus management consultation.