{
  "packId": "cia",
  "generatedAt": "2026-07-06T13:46:41.087Z",
  "draftWarning": "Production-enabled study pack — update review fields only; do not modify item content in review files without authoring workflow.",
  "dispositionOptions": [
    "accept",
    "revise",
    "reject",
    "needs source verification"
  ],
  "recommendedActions": [
    "approve",
    "revise",
    "reject",
    "hold",
    "retire"
  ],
  "itemCount": 1260,
  "items": [
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q001",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Foundations of Internal Auditing fundamentals",
      "difficulty": "Medium",
      "stem": "When applying foundations of internal auditing principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Foundations of Internal Auditing requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q002",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Foundations of Internal Auditing risk focus",
      "difficulty": "Easy",
      "stem": "In foundations of internal auditing, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q003",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Foundations of Internal Auditing independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing foundations of internal auditing discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q004",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Foundations of Internal Auditing control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to foundations of internal auditing, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q005",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Foundations of Internal Auditing reporting",
      "difficulty": "Medium",
      "stem": "Findings in foundations of internal auditing should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q006",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Foundations of Internal Auditing ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in foundations of internal auditing, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q007",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mission — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying mission within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Mission in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q008",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Value proposition — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on value proposition in Foundations of Internal Auditing. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Value proposition: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q009",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mandatory guidance — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about mandatory guidance in Foundations of Internal Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm mandatory guidance controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q010",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Professional framework — scenario 1",
      "difficulty": "Easy",
      "stem": "During foundations of internal auditing planning, professional framework is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Professional framework in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q011",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mission — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to mission under Foundations of Internal Auditing. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Mission: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q012",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Value proposition — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying value proposition within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm value proposition controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q013",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mandatory guidance — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on mandatory guidance in Foundations of Internal Auditing. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Mandatory guidance in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q014",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Professional framework — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about professional framework in Foundations of Internal Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Professional framework: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q015",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mission — scenario 3",
      "difficulty": "Hard",
      "stem": "During foundations of internal auditing planning, mission is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm mission controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q016",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Value proposition — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to value proposition under Foundations of Internal Auditing. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Value proposition in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q017",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mandatory guidance — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying mandatory guidance within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Mandatory guidance: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q018",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Professional framework — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on professional framework in Foundations of Internal Auditing. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm professional framework controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q019",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mission — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about mission in Foundations of Internal Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Mission in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q020",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Value proposition — scenario 4",
      "difficulty": "Medium",
      "stem": "During foundations of internal auditing planning, value proposition is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Value proposition: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q021",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mandatory guidance — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to mandatory guidance under Foundations of Internal Auditing. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm mandatory guidance controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q022",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Professional framework — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying professional framework within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Professional framework in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q023",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mission — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on mission in Foundations of Internal Auditing. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Mission: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q024",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Value proposition — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about value proposition in Foundations of Internal Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm value proposition controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q025",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mandatory guidance — scenario 5",
      "difficulty": "Easy",
      "stem": "During foundations of internal auditing planning, mandatory guidance is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Mandatory guidance in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q026",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Professional framework — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to professional framework under Foundations of Internal Auditing. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Professional framework: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q027",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mission — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying mission within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm mission controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q028",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Value proposition — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on value proposition in Foundations of Internal Auditing. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Value proposition in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q029",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mandatory guidance — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about mandatory guidance in Foundations of Internal Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Mandatory guidance: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q030",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Professional framework — scenario 6",
      "difficulty": "Hard",
      "stem": "During foundations of internal auditing planning, professional framework is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm professional framework controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q031",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mission — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to mission under Foundations of Internal Auditing. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Mission in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q032",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Value proposition — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying value proposition within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Value proposition: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q033",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mandatory guidance — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on mandatory guidance in Foundations of Internal Auditing. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm mandatory guidance controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q034",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Professional framework — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about professional framework in Foundations of Internal Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Professional framework in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q035",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mission — scenario 8",
      "difficulty": "Medium",
      "stem": "During foundations of internal auditing planning, mission is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Mission: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q036",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Value proposition — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to value proposition under Foundations of Internal Auditing. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm value proposition controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q037",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mandatory guidance — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying mandatory guidance within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Mandatory guidance in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q038",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Professional framework — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on professional framework in Foundations of Internal Auditing. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Professional framework: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q039",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mission — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about mission in Foundations of Internal Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm mission controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q040",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Value proposition — scenario 9",
      "difficulty": "Easy",
      "stem": "During foundations of internal auditing planning, value proposition is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Value proposition in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q041",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mandatory guidance — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to mandatory guidance under Foundations of Internal Auditing. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Mandatory guidance: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q042",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Professional framework — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying professional framework within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm professional framework controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q043",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mission — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on mission in Foundations of Internal Auditing. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Mission in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q044",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Value proposition — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about value proposition in Foundations of Internal Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Value proposition: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q045",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mandatory guidance — scenario 10",
      "difficulty": "Hard",
      "stem": "During foundations of internal auditing planning, mandatory guidance is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm mandatory guidance controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q046",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Professional framework — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to professional framework under Foundations of Internal Auditing. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Professional framework in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q047",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mission — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying mission within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Mission: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q048",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Value proposition — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on value proposition in Foundations of Internal Auditing. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm value proposition controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q049",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mandatory guidance — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about mandatory guidance in Foundations of Internal Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Mandatory guidance in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D1-Q050",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Professional framework — scenario 11",
      "difficulty": "Medium",
      "stem": "During foundations of internal auditing planning, professional framework is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Professional framework: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q001",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Independence and Objectivity fundamentals",
      "difficulty": "Medium",
      "stem": "When applying independence and objectivity principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Independence and Objectivity requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q002",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Independence and Objectivity risk focus",
      "difficulty": "Easy",
      "stem": "In independence and objectivity, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q003",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Independence and Objectivity independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing independence and objectivity discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q004",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Independence and Objectivity control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to independence and objectivity, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q005",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Independence and Objectivity reporting",
      "difficulty": "Medium",
      "stem": "Findings in independence and objectivity should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q006",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Independence and Objectivity ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in independence and objectivity, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q007",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Organizational independence — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying organizational independence within Independence and Objectivity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Organizational independence in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q008",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Individual objectivity — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on individual objectivity in Independence and Objectivity. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Individual objectivity: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q009",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Impairments — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about impairments in Independence and Objectivity is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm impairments controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q010",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Disclosure — scenario 1",
      "difficulty": "Easy",
      "stem": "During independence and objectivity planning, disclosure is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Disclosure in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q011",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Organizational independence — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to organizational independence under Independence and Objectivity. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Organizational independence: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q012",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Individual objectivity — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying individual objectivity within Independence and Objectivity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm individual objectivity controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q013",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Impairments — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on impairments in Independence and Objectivity. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Impairments in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q014",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Disclosure — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about disclosure in Independence and Objectivity is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Disclosure: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q015",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Organizational independence — scenario 3",
      "difficulty": "Hard",
      "stem": "During independence and objectivity planning, organizational independence is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm organizational independence controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q016",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Individual objectivity — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to individual objectivity under Independence and Objectivity. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Individual objectivity in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q017",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Impairments — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying impairments within Independence and Objectivity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Impairments: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q018",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Disclosure — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on disclosure in Independence and Objectivity. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm disclosure controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q019",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Organizational independence — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about organizational independence in Independence and Objectivity is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Organizational independence in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q020",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Individual objectivity — scenario 4",
      "difficulty": "Medium",
      "stem": "During independence and objectivity planning, individual objectivity is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Individual objectivity: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q021",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Impairments — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to impairments under Independence and Objectivity. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm impairments controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q022",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Disclosure — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying disclosure within Independence and Objectivity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Disclosure in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q023",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Organizational independence — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on organizational independence in Independence and Objectivity. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Organizational independence: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q024",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Individual objectivity — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about individual objectivity in Independence and Objectivity is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm individual objectivity controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q025",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Impairments — scenario 5",
      "difficulty": "Easy",
      "stem": "During independence and objectivity planning, impairments is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Impairments in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q026",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Disclosure — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to disclosure under Independence and Objectivity. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Disclosure: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q027",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Organizational independence — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying organizational independence within Independence and Objectivity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm organizational independence controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q028",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Individual objectivity — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on individual objectivity in Independence and Objectivity. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Individual objectivity in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q029",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Impairments — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about impairments in Independence and Objectivity is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Impairments: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q030",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Disclosure — scenario 6",
      "difficulty": "Hard",
      "stem": "During independence and objectivity planning, disclosure is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm disclosure controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q031",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Organizational independence — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to organizational independence under Independence and Objectivity. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Organizational independence in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q032",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Individual objectivity — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying individual objectivity within Independence and Objectivity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Individual objectivity: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q033",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Impairments — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on impairments in Independence and Objectivity. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm impairments controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q034",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Disclosure — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about disclosure in Independence and Objectivity is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Disclosure in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q035",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Organizational independence — scenario 8",
      "difficulty": "Medium",
      "stem": "During independence and objectivity planning, organizational independence is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Organizational independence: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q036",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Individual objectivity — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to individual objectivity under Independence and Objectivity. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm individual objectivity controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q037",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Impairments — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying impairments within Independence and Objectivity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Impairments in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q038",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Disclosure — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on disclosure in Independence and Objectivity. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Disclosure: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q039",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Organizational independence — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about organizational independence in Independence and Objectivity is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm organizational independence controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q040",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Individual objectivity — scenario 9",
      "difficulty": "Easy",
      "stem": "During independence and objectivity planning, individual objectivity is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Individual objectivity in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q041",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Impairments — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to impairments under Independence and Objectivity. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Impairments: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q042",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Disclosure — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying disclosure within Independence and Objectivity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm disclosure controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q043",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Organizational independence — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on organizational independence in Independence and Objectivity. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Organizational independence in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q044",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Individual objectivity — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about individual objectivity in Independence and Objectivity is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Individual objectivity: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q045",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Impairments — scenario 10",
      "difficulty": "Hard",
      "stem": "During independence and objectivity planning, impairments is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm impairments controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q046",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Disclosure — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to disclosure under Independence and Objectivity. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Disclosure in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q047",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Organizational independence — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying organizational independence within Independence and Objectivity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Organizational independence: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q048",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Individual objectivity — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on individual objectivity in Independence and Objectivity. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm individual objectivity controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q049",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Impairments — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about impairments in Independence and Objectivity is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Impairments in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D2-Q050",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Disclosure — scenario 11",
      "difficulty": "Medium",
      "stem": "During independence and objectivity planning, disclosure is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Disclosure: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q001",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Proficiency and Due Professional Care fundamentals",
      "difficulty": "Medium",
      "stem": "When applying proficiency and due professional care principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Proficiency and Due Professional Care requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q002",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Proficiency and Due Professional Care risk focus",
      "difficulty": "Easy",
      "stem": "In proficiency and due professional care, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q003",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Proficiency and Due Professional Care independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing proficiency and due professional care discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q004",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Proficiency and Due Professional Care control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to proficiency and due professional care, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q005",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Proficiency and Due Professional Care reporting",
      "difficulty": "Medium",
      "stem": "Findings in proficiency and due professional care should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q006",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Proficiency and Due Professional Care ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in proficiency and due professional care, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q007",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Competency — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying competency within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Competency in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q008",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Continuing education — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on continuing education in Proficiency and Due Professional Care. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Continuing education: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q009",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Supervision — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about supervision in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm supervision controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q010",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Due care — scenario 1",
      "difficulty": "Easy",
      "stem": "During proficiency and due professional care planning, due care is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Due care in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q011",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Competency — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to competency under Proficiency and Due Professional Care. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Competency: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q012",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Continuing education — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying continuing education within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm continuing education controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q013",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Supervision — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on supervision in Proficiency and Due Professional Care. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Supervision in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q014",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Due care — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about due care in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Due care: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q015",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Competency — scenario 3",
      "difficulty": "Hard",
      "stem": "During proficiency and due professional care planning, competency is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm competency controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q016",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Continuing education — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to continuing education under Proficiency and Due Professional Care. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Continuing education in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q017",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Supervision — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying supervision within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Supervision: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q018",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Due care — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on due care in Proficiency and Due Professional Care. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm due care controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q019",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Competency — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about competency in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Competency in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q020",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Continuing education — scenario 4",
      "difficulty": "Medium",
      "stem": "During proficiency and due professional care planning, continuing education is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Continuing education: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q021",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Supervision — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to supervision under Proficiency and Due Professional Care. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm supervision controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q022",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Due care — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying due care within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Due care in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q023",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Competency — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on competency in Proficiency and Due Professional Care. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Competency: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q024",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Continuing education — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about continuing education in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm continuing education controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q025",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Supervision — scenario 5",
      "difficulty": "Easy",
      "stem": "During proficiency and due professional care planning, supervision is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Supervision in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q026",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Due care — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to due care under Proficiency and Due Professional Care. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Due care: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q027",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Competency — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying competency within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm competency controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q028",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Continuing education — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on continuing education in Proficiency and Due Professional Care. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Continuing education in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q029",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Supervision — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about supervision in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Supervision: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q030",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Due care — scenario 6",
      "difficulty": "Hard",
      "stem": "During proficiency and due professional care planning, due care is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm due care controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q031",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Competency — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to competency under Proficiency and Due Professional Care. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Competency in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q032",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Continuing education — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying continuing education within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Continuing education: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q033",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Supervision — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on supervision in Proficiency and Due Professional Care. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm supervision controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q034",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Due care — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about due care in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Due care in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q035",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Competency — scenario 8",
      "difficulty": "Medium",
      "stem": "During proficiency and due professional care planning, competency is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Competency: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q036",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Continuing education — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to continuing education under Proficiency and Due Professional Care. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm continuing education controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q037",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Supervision — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying supervision within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Supervision in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q038",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Due care — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on due care in Proficiency and Due Professional Care. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Due care: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q039",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Competency — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about competency in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm competency controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q040",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Continuing education — scenario 9",
      "difficulty": "Easy",
      "stem": "During proficiency and due professional care planning, continuing education is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Continuing education in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q041",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Supervision — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to supervision under Proficiency and Due Professional Care. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Supervision: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q042",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Due care — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying due care within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm due care controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q043",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Competency — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on competency in Proficiency and Due Professional Care. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Competency in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q044",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Continuing education — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about continuing education in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Continuing education: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q045",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Supervision — scenario 10",
      "difficulty": "Hard",
      "stem": "During proficiency and due professional care planning, supervision is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm supervision controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q046",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Due care — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to due care under Proficiency and Due Professional Care. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Due care in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q047",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Competency — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying competency within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Competency: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q048",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Continuing education — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on continuing education in Proficiency and Due Professional Care. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm continuing education controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q049",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Supervision — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about supervision in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Supervision in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D3-Q050",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Due care — scenario 11",
      "difficulty": "Medium",
      "stem": "During proficiency and due professional care planning, due care is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Due care: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q001",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Quality Assurance and Improvement Program fundamentals",
      "difficulty": "Medium",
      "stem": "When applying quality assurance and improvement program principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Quality Assurance and Improvement Program requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q002",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Quality Assurance and Improvement Program risk focus",
      "difficulty": "Easy",
      "stem": "In quality assurance and improvement program, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q003",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Quality Assurance and Improvement Program independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing quality assurance and improvement program discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q004",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Quality Assurance and Improvement Program control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to quality assurance and improvement program, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q005",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Quality Assurance and Improvement Program reporting",
      "difficulty": "Medium",
      "stem": "Findings in quality assurance and improvement program should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q006",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Quality Assurance and Improvement Program ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in quality assurance and improvement program, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q007",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Internal assessments — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying internal assessments within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Internal assessments in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q008",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "External assessments — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on external assessments in Quality Assurance and Improvement Program. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to External assessments: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q009",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "QAIP reporting — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about qaip reporting in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm qaip reporting controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q010",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Improvement plans — scenario 1",
      "difficulty": "Easy",
      "stem": "During quality assurance and improvement program planning, improvement plans is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Improvement plans in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q011",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Internal assessments — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to internal assessments under Quality Assurance and Improvement Program. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Internal assessments: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q012",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "External assessments — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying external assessments within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm external assessments controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q013",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "QAIP reporting — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on qaip reporting in Quality Assurance and Improvement Program. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "QAIP reporting in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q014",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Improvement plans — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about improvement plans in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Improvement plans: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q015",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Internal assessments — scenario 3",
      "difficulty": "Hard",
      "stem": "During quality assurance and improvement program planning, internal assessments is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm internal assessments controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q016",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "External assessments — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to external assessments under Quality Assurance and Improvement Program. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "External assessments in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q017",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "QAIP reporting — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying qaip reporting within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to QAIP reporting: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q018",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Improvement plans — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on improvement plans in Quality Assurance and Improvement Program. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm improvement plans controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q019",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Internal assessments — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about internal assessments in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Internal assessments in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q020",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "External assessments — scenario 4",
      "difficulty": "Medium",
      "stem": "During quality assurance and improvement program planning, external assessments is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to External assessments: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q021",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "QAIP reporting — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to qaip reporting under Quality Assurance and Improvement Program. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm qaip reporting controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q022",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Improvement plans — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying improvement plans within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Improvement plans in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q023",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Internal assessments — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on internal assessments in Quality Assurance and Improvement Program. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Internal assessments: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q024",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "External assessments — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about external assessments in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm external assessments controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q025",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "QAIP reporting — scenario 5",
      "difficulty": "Easy",
      "stem": "During quality assurance and improvement program planning, qaip reporting is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "QAIP reporting in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q026",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Improvement plans — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to improvement plans under Quality Assurance and Improvement Program. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Improvement plans: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q027",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Internal assessments — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying internal assessments within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm internal assessments controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q028",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "External assessments — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on external assessments in Quality Assurance and Improvement Program. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "External assessments in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q029",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "QAIP reporting — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about qaip reporting in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to QAIP reporting: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q030",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Improvement plans — scenario 6",
      "difficulty": "Hard",
      "stem": "During quality assurance and improvement program planning, improvement plans is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm improvement plans controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q031",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Internal assessments — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to internal assessments under Quality Assurance and Improvement Program. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Internal assessments in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q032",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "External assessments — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying external assessments within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to External assessments: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q033",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "QAIP reporting — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on qaip reporting in Quality Assurance and Improvement Program. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm qaip reporting controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q034",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Improvement plans — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about improvement plans in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Improvement plans in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q035",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Internal assessments — scenario 8",
      "difficulty": "Medium",
      "stem": "During quality assurance and improvement program planning, internal assessments is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Internal assessments: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q036",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "External assessments — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to external assessments under Quality Assurance and Improvement Program. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm external assessments controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q037",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "QAIP reporting — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying qaip reporting within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "QAIP reporting in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q038",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Improvement plans — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on improvement plans in Quality Assurance and Improvement Program. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Improvement plans: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q039",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Internal assessments — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about internal assessments in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm internal assessments controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q040",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "External assessments — scenario 9",
      "difficulty": "Easy",
      "stem": "During quality assurance and improvement program planning, external assessments is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "External assessments in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q041",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "QAIP reporting — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to qaip reporting under Quality Assurance and Improvement Program. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to QAIP reporting: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q042",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Improvement plans — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying improvement plans within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm improvement plans controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q043",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Internal assessments — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on internal assessments in Quality Assurance and Improvement Program. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Internal assessments in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q044",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "External assessments — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about external assessments in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to External assessments: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q045",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "QAIP reporting — scenario 10",
      "difficulty": "Hard",
      "stem": "During quality assurance and improvement program planning, qaip reporting is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm qaip reporting controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q046",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Improvement plans — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to improvement plans under Quality Assurance and Improvement Program. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Improvement plans in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q047",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Internal assessments — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying internal assessments within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Internal assessments: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q048",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "External assessments — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on external assessments in Quality Assurance and Improvement Program. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm external assessments controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q049",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "QAIP reporting — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about qaip reporting in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "QAIP reporting in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D4-Q050",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Improvement plans — scenario 11",
      "difficulty": "Medium",
      "stem": "During quality assurance and improvement program planning, improvement plans is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Improvement plans: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q001",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Governance, Risk Management, and Control fundamentals",
      "difficulty": "Medium",
      "stem": "When applying governance, risk management, and control principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Governance, Risk Management, and Control requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q002",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Governance, Risk Management, and Control risk focus",
      "difficulty": "Easy",
      "stem": "In governance, risk management, and control, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q003",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Governance, Risk Management, and Control independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing governance, risk management, and control discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q004",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Governance, Risk Management, and Control control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to governance, risk management, and control, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q005",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Governance, Risk Management, and Control reporting",
      "difficulty": "Medium",
      "stem": "Findings in governance, risk management, and control should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q006",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Governance, Risk Management, and Control ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in governance, risk management, and control, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q007",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Three lines model — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying three lines model within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Three lines model in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q008",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Risk appetite — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on risk appetite in Governance, Risk Management, and Control. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Risk appetite: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q009",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Control environment — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about control environment in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm control environment controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q010",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Board oversight — scenario 1",
      "difficulty": "Easy",
      "stem": "During governance, risk management, and control planning, board oversight is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Board oversight in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q011",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Three lines model — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to three lines model under Governance, Risk Management, and Control. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Three lines model: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q012",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Risk appetite — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying risk appetite within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm risk appetite controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q013",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Control environment — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on control environment in Governance, Risk Management, and Control. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Control environment in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q014",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Board oversight — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about board oversight in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Board oversight: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q015",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Three lines model — scenario 3",
      "difficulty": "Hard",
      "stem": "During governance, risk management, and control planning, three lines model is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm three lines model controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q016",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Risk appetite — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to risk appetite under Governance, Risk Management, and Control. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Risk appetite in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q017",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Control environment — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying control environment within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Control environment: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q018",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Board oversight — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on board oversight in Governance, Risk Management, and Control. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm board oversight controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q019",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Three lines model — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about three lines model in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Three lines model in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q020",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Risk appetite — scenario 4",
      "difficulty": "Medium",
      "stem": "During governance, risk management, and control planning, risk appetite is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Risk appetite: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q021",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Control environment — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to control environment under Governance, Risk Management, and Control. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm control environment controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q022",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Board oversight — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying board oversight within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Board oversight in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q023",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Three lines model — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on three lines model in Governance, Risk Management, and Control. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Three lines model: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q024",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Risk appetite — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about risk appetite in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm risk appetite controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q025",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Control environment — scenario 5",
      "difficulty": "Easy",
      "stem": "During governance, risk management, and control planning, control environment is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Control environment in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q026",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Board oversight — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to board oversight under Governance, Risk Management, and Control. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Board oversight: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q027",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Three lines model — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying three lines model within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm three lines model controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q028",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Risk appetite — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on risk appetite in Governance, Risk Management, and Control. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Risk appetite in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q029",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Control environment — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about control environment in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Control environment: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q030",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Board oversight — scenario 6",
      "difficulty": "Hard",
      "stem": "During governance, risk management, and control planning, board oversight is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm board oversight controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q031",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Three lines model — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to three lines model under Governance, Risk Management, and Control. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Three lines model in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q032",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Risk appetite — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying risk appetite within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Risk appetite: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q033",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Control environment — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on control environment in Governance, Risk Management, and Control. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm control environment controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q034",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Board oversight — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about board oversight in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Board oversight in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q035",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Three lines model — scenario 8",
      "difficulty": "Medium",
      "stem": "During governance, risk management, and control planning, three lines model is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Three lines model: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q036",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Risk appetite — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to risk appetite under Governance, Risk Management, and Control. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm risk appetite controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q037",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Control environment — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying control environment within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Control environment in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q038",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Board oversight — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on board oversight in Governance, Risk Management, and Control. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Board oversight: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q039",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Three lines model — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about three lines model in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm three lines model controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q040",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Risk appetite — scenario 9",
      "difficulty": "Easy",
      "stem": "During governance, risk management, and control planning, risk appetite is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Risk appetite in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q041",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Control environment — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to control environment under Governance, Risk Management, and Control. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Control environment: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q042",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Board oversight — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying board oversight within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm board oversight controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q043",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Three lines model — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on three lines model in Governance, Risk Management, and Control. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Three lines model in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q044",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Risk appetite — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about risk appetite in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Risk appetite: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q045",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Control environment — scenario 10",
      "difficulty": "Hard",
      "stem": "During governance, risk management, and control planning, control environment is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm control environment controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q046",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Board oversight — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to board oversight under Governance, Risk Management, and Control. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Board oversight in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q047",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Three lines model — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying three lines model within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Three lines model: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q048",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Risk appetite — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on risk appetite in Governance, Risk Management, and Control. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm risk appetite controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q049",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Control environment — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about control environment in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Control environment in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D5-Q050",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Board oversight — scenario 11",
      "difficulty": "Medium",
      "stem": "During governance, risk management, and control planning, board oversight is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Board oversight: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q001",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud Risks fundamentals",
      "difficulty": "Medium",
      "stem": "When applying fraud risks principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Fraud Risks requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q002",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud Risks risk focus",
      "difficulty": "Easy",
      "stem": "In fraud risks, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q003",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud Risks independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing fraud risks discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q004",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud Risks control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to fraud risks, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q005",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud Risks reporting",
      "difficulty": "Medium",
      "stem": "Findings in fraud risks should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q006",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud Risks ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in fraud risks, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q007",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud indicators — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying fraud indicators within Fraud Risks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Fraud indicators in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q008",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Red flags — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on red flags in Fraud Risks. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Red flags: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q009",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Investigation boundaries — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about investigation boundaries in Fraud Risks is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm investigation boundaries controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q010",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Reporting — scenario 1",
      "difficulty": "Easy",
      "stem": "During fraud risks planning, reporting is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Reporting in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q011",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud indicators — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to fraud indicators under Fraud Risks. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Fraud indicators: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q012",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Red flags — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying red flags within Fraud Risks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm red flags controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q013",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Investigation boundaries — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on investigation boundaries in Fraud Risks. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Investigation boundaries in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q014",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Reporting — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about reporting in Fraud Risks is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q015",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud indicators — scenario 3",
      "difficulty": "Hard",
      "stem": "During fraud risks planning, fraud indicators is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm fraud indicators controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q016",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Red flags — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to red flags under Fraud Risks. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Red flags in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q017",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Investigation boundaries — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying investigation boundaries within Fraud Risks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Investigation boundaries: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q018",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Reporting — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on reporting in Fraud Risks. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm reporting controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q019",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud indicators — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about fraud indicators in Fraud Risks is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Fraud indicators in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q020",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Red flags — scenario 4",
      "difficulty": "Medium",
      "stem": "During fraud risks planning, red flags is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Red flags: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q021",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Investigation boundaries — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to investigation boundaries under Fraud Risks. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm investigation boundaries controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q022",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Reporting — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying reporting within Fraud Risks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Reporting in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q023",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud indicators — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on fraud indicators in Fraud Risks. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Fraud indicators: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q024",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Red flags — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about red flags in Fraud Risks is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm red flags controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q025",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Investigation boundaries — scenario 5",
      "difficulty": "Easy",
      "stem": "During fraud risks planning, investigation boundaries is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Investigation boundaries in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q026",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Reporting — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to reporting under Fraud Risks. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q027",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud indicators — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying fraud indicators within Fraud Risks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm fraud indicators controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q028",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Red flags — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on red flags in Fraud Risks. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Red flags in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q029",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Investigation boundaries — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about investigation boundaries in Fraud Risks is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Investigation boundaries: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q030",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Reporting — scenario 6",
      "difficulty": "Hard",
      "stem": "During fraud risks planning, reporting is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm reporting controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q031",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud indicators — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to fraud indicators under Fraud Risks. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Fraud indicators in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q032",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Red flags — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying red flags within Fraud Risks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Red flags: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q033",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Investigation boundaries — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on investigation boundaries in Fraud Risks. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm investigation boundaries controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q034",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Reporting — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about reporting in Fraud Risks is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Reporting in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q035",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud indicators — scenario 8",
      "difficulty": "Medium",
      "stem": "During fraud risks planning, fraud indicators is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Fraud indicators: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q036",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Red flags — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to red flags under Fraud Risks. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm red flags controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q037",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Investigation boundaries — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying investigation boundaries within Fraud Risks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Investigation boundaries in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q038",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Reporting — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on reporting in Fraud Risks. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q039",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud indicators — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about fraud indicators in Fraud Risks is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm fraud indicators controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q040",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Red flags — scenario 9",
      "difficulty": "Easy",
      "stem": "During fraud risks planning, red flags is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Red flags in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q041",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Investigation boundaries — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to investigation boundaries under Fraud Risks. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Investigation boundaries: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q042",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Reporting — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying reporting within Fraud Risks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm reporting controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q043",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud indicators — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on fraud indicators in Fraud Risks. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Fraud indicators in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q044",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Red flags — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about red flags in Fraud Risks is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Red flags: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q045",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Investigation boundaries — scenario 10",
      "difficulty": "Hard",
      "stem": "During fraud risks planning, investigation boundaries is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm investigation boundaries controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q046",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Reporting — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to reporting under Fraud Risks. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Reporting in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q047",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud indicators — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying fraud indicators within Fraud Risks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Fraud indicators: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q048",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Red flags — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on red flags in Fraud Risks. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm red flags controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q049",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Investigation boundaries — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about investigation boundaries in Fraud Risks is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Investigation boundaries in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D6-Q050",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Reporting — scenario 11",
      "difficulty": "Medium",
      "stem": "During fraud risks planning, reporting is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q001",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Managing the Internal Audit Activity fundamentals",
      "difficulty": "Medium",
      "stem": "When applying managing the internal audit activity principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Managing the Internal Audit Activity requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q002",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Managing the Internal Audit Activity risk focus",
      "difficulty": "Easy",
      "stem": "In managing the internal audit activity, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q003",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Managing the Internal Audit Activity independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing managing the internal audit activity discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q004",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Managing the Internal Audit Activity control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to managing the internal audit activity, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q005",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Managing the Internal Audit Activity reporting",
      "difficulty": "Medium",
      "stem": "Findings in managing the internal audit activity should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q006",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Managing the Internal Audit Activity ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in managing the internal audit activity, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q007",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Charter — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying charter within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Charter in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q008",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Resource planning — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on resource planning in Managing the Internal Audit Activity. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Resource planning: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q009",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Policies — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about policies in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm policies controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q010",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Performance metrics — scenario 1",
      "difficulty": "Easy",
      "stem": "During managing the internal audit activity planning, performance metrics is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Performance metrics in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q011",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Charter — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to charter under Managing the Internal Audit Activity. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Charter: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q012",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Resource planning — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying resource planning within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm resource planning controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q013",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Policies — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on policies in Managing the Internal Audit Activity. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Policies in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q014",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Performance metrics — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about performance metrics in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Performance metrics: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q015",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Charter — scenario 3",
      "difficulty": "Hard",
      "stem": "During managing the internal audit activity planning, charter is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm charter controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q016",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Resource planning — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to resource planning under Managing the Internal Audit Activity. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Resource planning in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q017",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Policies — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying policies within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Policies: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q018",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Performance metrics — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on performance metrics in Managing the Internal Audit Activity. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm performance metrics controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q019",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Charter — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about charter in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Charter in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q020",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Resource planning — scenario 4",
      "difficulty": "Medium",
      "stem": "During managing the internal audit activity planning, resource planning is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Resource planning: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q021",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Policies — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to policies under Managing the Internal Audit Activity. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm policies controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q022",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Performance metrics — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying performance metrics within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Performance metrics in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q023",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Charter — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on charter in Managing the Internal Audit Activity. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Charter: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q024",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Resource planning — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about resource planning in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm resource planning controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q025",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Policies — scenario 5",
      "difficulty": "Easy",
      "stem": "During managing the internal audit activity planning, policies is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Policies in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q026",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Performance metrics — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to performance metrics under Managing the Internal Audit Activity. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Performance metrics: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q027",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Charter — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying charter within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm charter controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q028",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Resource planning — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on resource planning in Managing the Internal Audit Activity. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Resource planning in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q029",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Policies — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about policies in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Policies: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q030",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Performance metrics — scenario 6",
      "difficulty": "Hard",
      "stem": "During managing the internal audit activity planning, performance metrics is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm performance metrics controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q031",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Charter — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to charter under Managing the Internal Audit Activity. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Charter in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q032",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Resource planning — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying resource planning within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Resource planning: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q033",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Policies — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on policies in Managing the Internal Audit Activity. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm policies controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q034",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Performance metrics — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about performance metrics in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Performance metrics in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q035",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Charter — scenario 8",
      "difficulty": "Medium",
      "stem": "During managing the internal audit activity planning, charter is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Charter: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q036",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Resource planning — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to resource planning under Managing the Internal Audit Activity. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm resource planning controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q037",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Policies — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying policies within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Policies in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q038",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Performance metrics — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on performance metrics in Managing the Internal Audit Activity. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Performance metrics: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q039",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Charter — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about charter in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm charter controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q040",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Resource planning — scenario 9",
      "difficulty": "Easy",
      "stem": "During managing the internal audit activity planning, resource planning is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Resource planning in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q041",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Policies — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to policies under Managing the Internal Audit Activity. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Policies: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q042",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Performance metrics — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying performance metrics within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm performance metrics controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q043",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Charter — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on charter in Managing the Internal Audit Activity. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Charter in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q044",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Resource planning — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about resource planning in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Resource planning: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q045",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Policies — scenario 10",
      "difficulty": "Hard",
      "stem": "During managing the internal audit activity planning, policies is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm policies controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q046",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Performance metrics — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to performance metrics under Managing the Internal Audit Activity. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Performance metrics in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q047",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Charter — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying charter within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Charter: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q048",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Resource planning — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on resource planning in Managing the Internal Audit Activity. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm resource planning controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q049",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Policies — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about policies in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Policies in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D7-Q050",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Performance metrics — scenario 11",
      "difficulty": "Medium",
      "stem": "During managing the internal audit activity planning, performance metrics is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Performance metrics: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q001",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Engagement Planning fundamentals",
      "difficulty": "Medium",
      "stem": "When applying engagement planning principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Engagement Planning requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q002",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Engagement Planning risk focus",
      "difficulty": "Easy",
      "stem": "In engagement planning, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q003",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Engagement Planning independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing engagement planning discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q004",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Engagement Planning control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to engagement planning, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q005",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Engagement Planning reporting",
      "difficulty": "Medium",
      "stem": "Findings in engagement planning should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q006",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Engagement Planning ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in engagement planning, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q007",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Risk-based planning — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying risk-based planning within Engagement Planning, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Risk-based planning in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q008",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Scope — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on scope in Engagement Planning. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Scope: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q009",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Objectives — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about objectives in Engagement Planning is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm objectives controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q010",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Work programs — scenario 1",
      "difficulty": "Easy",
      "stem": "During engagement planning planning, work programs is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Work programs in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q011",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Risk-based planning — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to risk-based planning under Engagement Planning. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Risk-based planning: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q012",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Scope — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying scope within Engagement Planning, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm scope controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q013",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Objectives — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on objectives in Engagement Planning. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Objectives in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q014",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Work programs — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about work programs in Engagement Planning is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Work programs: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q015",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Risk-based planning — scenario 3",
      "difficulty": "Hard",
      "stem": "During engagement planning planning, risk-based planning is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm risk-based planning controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q016",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Scope — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to scope under Engagement Planning. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Scope in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q017",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Objectives — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying objectives within Engagement Planning, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Objectives: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q018",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Work programs — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on work programs in Engagement Planning. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm work programs controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q019",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Risk-based planning — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about risk-based planning in Engagement Planning is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Risk-based planning in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q020",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Scope — scenario 4",
      "difficulty": "Medium",
      "stem": "During engagement planning planning, scope is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Scope: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q021",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Objectives — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to objectives under Engagement Planning. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm objectives controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q022",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Work programs — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying work programs within Engagement Planning, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Work programs in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q023",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Risk-based planning — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on risk-based planning in Engagement Planning. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Risk-based planning: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q024",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Scope — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about scope in Engagement Planning is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm scope controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q025",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Objectives — scenario 5",
      "difficulty": "Easy",
      "stem": "During engagement planning planning, objectives is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Objectives in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q026",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Work programs — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to work programs under Engagement Planning. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Work programs: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q027",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Risk-based planning — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying risk-based planning within Engagement Planning, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm risk-based planning controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q028",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Scope — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on scope in Engagement Planning. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Scope in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q029",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Objectives — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about objectives in Engagement Planning is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Objectives: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q030",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Work programs — scenario 6",
      "difficulty": "Hard",
      "stem": "During engagement planning planning, work programs is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm work programs controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q031",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Risk-based planning — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to risk-based planning under Engagement Planning. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Risk-based planning in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q032",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Scope — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying scope within Engagement Planning, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Scope: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q033",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Objectives — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on objectives in Engagement Planning. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm objectives controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q034",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Work programs — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about work programs in Engagement Planning is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Work programs in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q035",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Risk-based planning — scenario 8",
      "difficulty": "Medium",
      "stem": "During engagement planning planning, risk-based planning is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Risk-based planning: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q036",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Scope — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to scope under Engagement Planning. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm scope controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q037",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Objectives — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying objectives within Engagement Planning, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Objectives in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q038",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Work programs — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on work programs in Engagement Planning. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Work programs: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q039",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Risk-based planning — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about risk-based planning in Engagement Planning is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm risk-based planning controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q040",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Scope — scenario 9",
      "difficulty": "Easy",
      "stem": "During engagement planning planning, scope is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Scope in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q041",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Objectives — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to objectives under Engagement Planning. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Objectives: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q042",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Work programs — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying work programs within Engagement Planning, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm work programs controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q043",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Risk-based planning — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on risk-based planning in Engagement Planning. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Risk-based planning in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q044",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Scope — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about scope in Engagement Planning is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Scope: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q045",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Objectives — scenario 10",
      "difficulty": "Hard",
      "stem": "During engagement planning planning, objectives is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm objectives controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q046",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Work programs — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to work programs under Engagement Planning. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Work programs in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q047",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Risk-based planning — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying risk-based planning within Engagement Planning, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Risk-based planning: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q048",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Scope — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on scope in Engagement Planning. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm scope controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q049",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Objectives — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about objectives in Engagement Planning is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Objectives in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D8-Q050",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Work programs — scenario 11",
      "difficulty": "Medium",
      "stem": "During engagement planning planning, work programs is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Work programs: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q001",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Performing the Engagement fundamentals",
      "difficulty": "Medium",
      "stem": "When applying performing the engagement principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Performing the Engagement requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q002",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Performing the Engagement risk focus",
      "difficulty": "Easy",
      "stem": "In performing the engagement, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q003",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Performing the Engagement independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing performing the engagement discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q004",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Performing the Engagement control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to performing the engagement, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q005",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Performing the Engagement reporting",
      "difficulty": "Medium",
      "stem": "Findings in performing the engagement should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q006",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Performing the Engagement ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in performing the engagement, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q007",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Evidence gathering — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying evidence gathering within Performing the Engagement, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Evidence gathering in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q008",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Sampling — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on sampling in Performing the Engagement. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Sampling: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q009",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Analysis — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about analysis in Performing the Engagement is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm analysis controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q010",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Documentation — scenario 1",
      "difficulty": "Easy",
      "stem": "During performing the engagement planning, documentation is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Documentation in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q011",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Evidence gathering — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to evidence gathering under Performing the Engagement. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Evidence gathering: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q012",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Sampling — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying sampling within Performing the Engagement, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm sampling controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q013",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Analysis — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on analysis in Performing the Engagement. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Analysis in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q014",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Documentation — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about documentation in Performing the Engagement is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Documentation: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q015",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Evidence gathering — scenario 3",
      "difficulty": "Hard",
      "stem": "During performing the engagement planning, evidence gathering is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm evidence gathering controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q016",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Sampling — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to sampling under Performing the Engagement. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Sampling in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q017",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Analysis — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying analysis within Performing the Engagement, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Analysis: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q018",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Documentation — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on documentation in Performing the Engagement. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm documentation controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q019",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Evidence gathering — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about evidence gathering in Performing the Engagement is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Evidence gathering in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q020",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Sampling — scenario 4",
      "difficulty": "Medium",
      "stem": "During performing the engagement planning, sampling is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Sampling: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q021",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Analysis — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to analysis under Performing the Engagement. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm analysis controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q022",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Documentation — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying documentation within Performing the Engagement, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Documentation in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q023",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Evidence gathering — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on evidence gathering in Performing the Engagement. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Evidence gathering: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q024",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Sampling — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about sampling in Performing the Engagement is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm sampling controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q025",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Analysis — scenario 5",
      "difficulty": "Easy",
      "stem": "During performing the engagement planning, analysis is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Analysis in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q026",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Documentation — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to documentation under Performing the Engagement. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Documentation: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q027",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Evidence gathering — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying evidence gathering within Performing the Engagement, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm evidence gathering controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q028",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Sampling — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on sampling in Performing the Engagement. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Sampling in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q029",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Analysis — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about analysis in Performing the Engagement is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Analysis: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q030",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Documentation — scenario 6",
      "difficulty": "Hard",
      "stem": "During performing the engagement planning, documentation is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm documentation controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q031",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Evidence gathering — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to evidence gathering under Performing the Engagement. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Evidence gathering in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q032",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Sampling — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying sampling within Performing the Engagement, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Sampling: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q033",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Analysis — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on analysis in Performing the Engagement. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm analysis controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q034",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Documentation — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about documentation in Performing the Engagement is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Documentation in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q035",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Evidence gathering — scenario 8",
      "difficulty": "Medium",
      "stem": "During performing the engagement planning, evidence gathering is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Evidence gathering: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q036",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Sampling — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to sampling under Performing the Engagement. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm sampling controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q037",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Analysis — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying analysis within Performing the Engagement, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Analysis in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q038",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Documentation — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on documentation in Performing the Engagement. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Documentation: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q039",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Evidence gathering — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about evidence gathering in Performing the Engagement is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm evidence gathering controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q040",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Sampling — scenario 9",
      "difficulty": "Easy",
      "stem": "During performing the engagement planning, sampling is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Sampling in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q041",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Analysis — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to analysis under Performing the Engagement. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Analysis: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q042",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Documentation — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying documentation within Performing the Engagement, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm documentation controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q043",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Evidence gathering — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on evidence gathering in Performing the Engagement. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Evidence gathering in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q044",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Sampling — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about sampling in Performing the Engagement is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Sampling: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q045",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Analysis — scenario 10",
      "difficulty": "Hard",
      "stem": "During performing the engagement planning, analysis is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm analysis controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q046",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Documentation — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to documentation under Performing the Engagement. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Documentation in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q047",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Evidence gathering — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying evidence gathering within Performing the Engagement, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Evidence gathering: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q048",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Sampling — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on sampling in Performing the Engagement. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm sampling controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q049",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Analysis — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about analysis in Performing the Engagement is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Analysis in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D9-Q050",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Documentation — scenario 11",
      "difficulty": "Medium",
      "stem": "During performing the engagement planning, documentation is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Documentation: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q001",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Communicating Engagement Results fundamentals",
      "difficulty": "Medium",
      "stem": "When applying communicating engagement results principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Communicating Engagement Results requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q002",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Communicating Engagement Results risk focus",
      "difficulty": "Easy",
      "stem": "In communicating engagement results, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q003",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Communicating Engagement Results independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing communicating engagement results discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q004",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Communicating Engagement Results control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to communicating engagement results, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q005",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Communicating Engagement Results reporting",
      "difficulty": "Medium",
      "stem": "Findings in communicating engagement results should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q006",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Communicating Engagement Results ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in communicating engagement results, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q007",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Reporting — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying reporting within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Reporting in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q008",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Recommendations — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on recommendations in Communicating Engagement Results. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Recommendations: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q009",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Follow-up — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about follow-up in Communicating Engagement Results is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm follow-up controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q010",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Monitoring — scenario 1",
      "difficulty": "Easy",
      "stem": "During communicating engagement results planning, monitoring is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Monitoring in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q011",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Reporting — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to reporting under Communicating Engagement Results. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q012",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Recommendations — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying recommendations within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm recommendations controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q013",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Follow-up — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on follow-up in Communicating Engagement Results. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Follow-up in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q014",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Monitoring — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about monitoring in Communicating Engagement Results is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Monitoring: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q015",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Reporting — scenario 3",
      "difficulty": "Hard",
      "stem": "During communicating engagement results planning, reporting is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm reporting controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q016",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Recommendations — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to recommendations under Communicating Engagement Results. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Recommendations in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q017",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Follow-up — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying follow-up within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Follow-up: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q018",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Monitoring — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on monitoring in Communicating Engagement Results. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm monitoring controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q019",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Reporting — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about reporting in Communicating Engagement Results is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Reporting in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q020",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Recommendations — scenario 4",
      "difficulty": "Medium",
      "stem": "During communicating engagement results planning, recommendations is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Recommendations: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q021",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Follow-up — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to follow-up under Communicating Engagement Results. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm follow-up controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q022",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Monitoring — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying monitoring within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Monitoring in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q023",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Reporting — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on reporting in Communicating Engagement Results. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q024",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Recommendations — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about recommendations in Communicating Engagement Results is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm recommendations controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q025",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Follow-up — scenario 5",
      "difficulty": "Easy",
      "stem": "During communicating engagement results planning, follow-up is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Follow-up in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q026",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Monitoring — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to monitoring under Communicating Engagement Results. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Monitoring: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q027",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Reporting — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying reporting within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm reporting controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q028",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Recommendations — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on recommendations in Communicating Engagement Results. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Recommendations in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q029",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Follow-up — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about follow-up in Communicating Engagement Results is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Follow-up: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q030",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Monitoring — scenario 6",
      "difficulty": "Hard",
      "stem": "During communicating engagement results planning, monitoring is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm monitoring controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q031",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Reporting — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to reporting under Communicating Engagement Results. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Reporting in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q032",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Recommendations — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying recommendations within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Recommendations: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q033",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Follow-up — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on follow-up in Communicating Engagement Results. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm follow-up controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q034",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Monitoring — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about monitoring in Communicating Engagement Results is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Monitoring in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q035",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Reporting — scenario 8",
      "difficulty": "Medium",
      "stem": "During communicating engagement results planning, reporting is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q036",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Recommendations — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to recommendations under Communicating Engagement Results. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm recommendations controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q037",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Follow-up — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying follow-up within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Follow-up in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q038",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Monitoring — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on monitoring in Communicating Engagement Results. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Monitoring: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q039",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Reporting — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about reporting in Communicating Engagement Results is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm reporting controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q040",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Recommendations — scenario 9",
      "difficulty": "Easy",
      "stem": "During communicating engagement results planning, recommendations is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Recommendations in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q041",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Follow-up — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to follow-up under Communicating Engagement Results. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Follow-up: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q042",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Monitoring — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying monitoring within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm monitoring controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q043",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Reporting — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on reporting in Communicating Engagement Results. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Reporting in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q044",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Recommendations — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about recommendations in Communicating Engagement Results is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Recommendations: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q045",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Follow-up — scenario 10",
      "difficulty": "Hard",
      "stem": "During communicating engagement results planning, follow-up is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm follow-up controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q046",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Monitoring — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to monitoring under Communicating Engagement Results. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Monitoring in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q047",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Reporting — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying reporting within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q048",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Recommendations — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on recommendations in Communicating Engagement Results. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm recommendations controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q049",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Follow-up — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about follow-up in Communicating Engagement Results is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Follow-up in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D10-Q050",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Monitoring — scenario 11",
      "difficulty": "Medium",
      "stem": "During communicating engagement results planning, monitoring is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Monitoring: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q001",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Business Acumen fundamentals",
      "difficulty": "Medium",
      "stem": "When applying business acumen principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Business Acumen requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q002",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Business Acumen risk focus",
      "difficulty": "Easy",
      "stem": "In business acumen, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q003",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Business Acumen independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing business acumen discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q004",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Business Acumen control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to business acumen, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q005",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Business Acumen reporting",
      "difficulty": "Medium",
      "stem": "Findings in business acumen should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q006",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Business Acumen ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in business acumen, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q007",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Industry context — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying industry context within Business Acumen, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Industry context in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q008",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Strategy — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on strategy in Business Acumen. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Strategy: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q009",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Operations — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about operations in Business Acumen is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Business Acumen includes transparent documentation and follow-up to confirm operations controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q010",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Value drivers — scenario 1",
      "difficulty": "Easy",
      "stem": "During business acumen planning, value drivers is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Value drivers in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q011",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Industry context — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to industry context under Business Acumen. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Industry context: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q012",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Strategy — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying strategy within Business Acumen, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Business Acumen includes transparent documentation and follow-up to confirm strategy controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q013",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Operations — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on operations in Business Acumen. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Operations in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q014",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Value drivers — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about value drivers in Business Acumen is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Value drivers: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q015",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Industry context — scenario 3",
      "difficulty": "Hard",
      "stem": "During business acumen planning, industry context is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Business Acumen includes transparent documentation and follow-up to confirm industry context controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q016",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Strategy — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to strategy under Business Acumen. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Strategy in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q017",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Operations — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying operations within Business Acumen, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Operations: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q018",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Value drivers — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on value drivers in Business Acumen. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Business Acumen includes transparent documentation and follow-up to confirm value drivers controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q019",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Industry context — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about industry context in Business Acumen is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Industry context in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q020",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Strategy — scenario 4",
      "difficulty": "Medium",
      "stem": "During business acumen planning, strategy is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Strategy: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q021",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Operations — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to operations under Business Acumen. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Business Acumen includes transparent documentation and follow-up to confirm operations controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q022",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Value drivers — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying value drivers within Business Acumen, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Value drivers in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q023",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Industry context — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on industry context in Business Acumen. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Industry context: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q024",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Strategy — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about strategy in Business Acumen is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Business Acumen includes transparent documentation and follow-up to confirm strategy controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q025",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Operations — scenario 5",
      "difficulty": "Easy",
      "stem": "During business acumen planning, operations is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Operations in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q026",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Value drivers — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to value drivers under Business Acumen. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Value drivers: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q027",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Industry context — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying industry context within Business Acumen, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Business Acumen includes transparent documentation and follow-up to confirm industry context controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q028",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Strategy — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on strategy in Business Acumen. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Strategy in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q029",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Operations — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about operations in Business Acumen is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Operations: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q030",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Value drivers — scenario 6",
      "difficulty": "Hard",
      "stem": "During business acumen planning, value drivers is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Business Acumen includes transparent documentation and follow-up to confirm value drivers controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q031",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Industry context — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to industry context under Business Acumen. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Industry context in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q032",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Strategy — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying strategy within Business Acumen, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Strategy: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q033",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Operations — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on operations in Business Acumen. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Business Acumen includes transparent documentation and follow-up to confirm operations controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q034",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Value drivers — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about value drivers in Business Acumen is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Value drivers in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q035",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Industry context — scenario 8",
      "difficulty": "Medium",
      "stem": "During business acumen planning, industry context is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Industry context: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q036",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Strategy — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to strategy under Business Acumen. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Business Acumen includes transparent documentation and follow-up to confirm strategy controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q037",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Operations — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying operations within Business Acumen, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Operations in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q038",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Value drivers — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on value drivers in Business Acumen. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Value drivers: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q039",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Industry context — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about industry context in Business Acumen is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Business Acumen includes transparent documentation and follow-up to confirm industry context controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q040",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Strategy — scenario 9",
      "difficulty": "Easy",
      "stem": "During business acumen planning, strategy is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Strategy in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q041",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Operations — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to operations under Business Acumen. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Operations: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q042",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Value drivers — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying value drivers within Business Acumen, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Business Acumen includes transparent documentation and follow-up to confirm value drivers controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q043",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Industry context — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on industry context in Business Acumen. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Industry context in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q044",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Strategy — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about strategy in Business Acumen is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Strategy: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q045",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Operations — scenario 10",
      "difficulty": "Hard",
      "stem": "During business acumen planning, operations is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Business Acumen includes transparent documentation and follow-up to confirm operations controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q046",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Value drivers — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to value drivers under Business Acumen. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Value drivers in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q047",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Industry context — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying industry context within Business Acumen, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Industry context: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q048",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Strategy — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on strategy in Business Acumen. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Business Acumen includes transparent documentation and follow-up to confirm strategy controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q049",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Operations — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about operations in Business Acumen is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Operations in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D11-Q050",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Value drivers — scenario 11",
      "difficulty": "Medium",
      "stem": "During business acumen planning, value drivers is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Value drivers: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q001",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Information Security fundamentals",
      "difficulty": "Medium",
      "stem": "When applying information security principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Information Security requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q002",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Information Security risk focus",
      "difficulty": "Easy",
      "stem": "In information security, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q003",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Information Security independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing information security discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q004",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Information Security control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to information security, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q005",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Information Security reporting",
      "difficulty": "Medium",
      "stem": "Findings in information security should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q006",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Information Security ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in information security, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q007",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Access controls — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying access controls within Information Security, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Access controls in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q008",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Data protection — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on data protection in Information Security. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Data protection: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q009",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Incident response — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about incident response in Information Security is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Security includes transparent documentation and follow-up to confirm incident response controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q010",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Security governance — scenario 1",
      "difficulty": "Easy",
      "stem": "During information security planning, security governance is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Security governance in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q011",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Access controls — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to access controls under Information Security. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Access controls: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q012",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Data protection — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying data protection within Information Security, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Security includes transparent documentation and follow-up to confirm data protection controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q013",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Incident response — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on incident response in Information Security. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Incident response in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q014",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Security governance — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about security governance in Information Security is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Security governance: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q015",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Access controls — scenario 3",
      "difficulty": "Hard",
      "stem": "During information security planning, access controls is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Security includes transparent documentation and follow-up to confirm access controls controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q016",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Data protection — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to data protection under Information Security. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Data protection in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q017",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Incident response — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying incident response within Information Security, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Incident response: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q018",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Security governance — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on security governance in Information Security. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Security includes transparent documentation and follow-up to confirm security governance controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q019",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Access controls — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about access controls in Information Security is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Access controls in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q020",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Data protection — scenario 4",
      "difficulty": "Medium",
      "stem": "During information security planning, data protection is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Data protection: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q021",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Incident response — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to incident response under Information Security. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Security includes transparent documentation and follow-up to confirm incident response controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q022",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Security governance — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying security governance within Information Security, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Security governance in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q023",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Access controls — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on access controls in Information Security. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Access controls: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q024",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Data protection — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about data protection in Information Security is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Security includes transparent documentation and follow-up to confirm data protection controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q025",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Incident response — scenario 5",
      "difficulty": "Easy",
      "stem": "During information security planning, incident response is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Incident response in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q026",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Security governance — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to security governance under Information Security. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Security governance: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q027",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Access controls — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying access controls within Information Security, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Security includes transparent documentation and follow-up to confirm access controls controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q028",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Data protection — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on data protection in Information Security. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Data protection in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q029",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Incident response — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about incident response in Information Security is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Incident response: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q030",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Security governance — scenario 6",
      "difficulty": "Hard",
      "stem": "During information security planning, security governance is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Security includes transparent documentation and follow-up to confirm security governance controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q031",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Access controls — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to access controls under Information Security. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Access controls in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q032",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Data protection — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying data protection within Information Security, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Data protection: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q033",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Incident response — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on incident response in Information Security. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Security includes transparent documentation and follow-up to confirm incident response controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q034",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Security governance — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about security governance in Information Security is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Security governance in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q035",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Access controls — scenario 8",
      "difficulty": "Medium",
      "stem": "During information security planning, access controls is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Access controls: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q036",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Data protection — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to data protection under Information Security. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Security includes transparent documentation and follow-up to confirm data protection controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q037",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Incident response — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying incident response within Information Security, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Incident response in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q038",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Security governance — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on security governance in Information Security. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Security governance: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q039",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Access controls — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about access controls in Information Security is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Security includes transparent documentation and follow-up to confirm access controls controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q040",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Data protection — scenario 9",
      "difficulty": "Easy",
      "stem": "During information security planning, data protection is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Data protection in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q041",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Incident response — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to incident response under Information Security. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Incident response: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q042",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Security governance — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying security governance within Information Security, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Security includes transparent documentation and follow-up to confirm security governance controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q043",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Access controls — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on access controls in Information Security. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Access controls in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q044",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Data protection — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about data protection in Information Security is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Data protection: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q045",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Incident response — scenario 10",
      "difficulty": "Hard",
      "stem": "During information security planning, incident response is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Security includes transparent documentation and follow-up to confirm incident response controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q046",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Security governance — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to security governance under Information Security. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Security governance in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q047",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Access controls — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying access controls within Information Security, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Access controls: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q048",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Data protection — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on data protection in Information Security. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Security includes transparent documentation and follow-up to confirm data protection controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q049",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Incident response — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about incident response in Information Security is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Incident response in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D12-Q050",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Security governance — scenario 11",
      "difficulty": "Medium",
      "stem": "During information security planning, security governance is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Security governance: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q001",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Information Technology fundamentals",
      "difficulty": "Medium",
      "stem": "When applying information technology principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Information Technology requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q002",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Information Technology risk focus",
      "difficulty": "Easy",
      "stem": "In information technology, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q003",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Information Technology independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing information technology discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q004",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Information Technology control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to information technology, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q005",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Information Technology reporting",
      "difficulty": "Medium",
      "stem": "Findings in information technology should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q006",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Information Technology ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in information technology, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q007",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT general controls — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying it general controls within Information Technology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "IT general controls in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q008",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Change management — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on change management in Information Technology. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Change management: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q009",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "System development — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about system development in Information Technology is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Technology includes transparent documentation and follow-up to confirm system development controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q010",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT audit — scenario 1",
      "difficulty": "Easy",
      "stem": "During information technology planning, it audit is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "IT audit in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q011",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT general controls — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to it general controls under Information Technology. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to IT general controls: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q012",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Change management — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying change management within Information Technology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Technology includes transparent documentation and follow-up to confirm change management controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q013",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "System development — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on system development in Information Technology. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "System development in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q014",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT audit — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about it audit in Information Technology is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to IT audit: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q015",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT general controls — scenario 3",
      "difficulty": "Hard",
      "stem": "During information technology planning, it general controls is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Technology includes transparent documentation and follow-up to confirm it general controls controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q016",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Change management — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to change management under Information Technology. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Change management in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q017",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "System development — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying system development within Information Technology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to System development: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q018",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT audit — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on it audit in Information Technology. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Technology includes transparent documentation and follow-up to confirm it audit controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q019",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT general controls — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about it general controls in Information Technology is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "IT general controls in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q020",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Change management — scenario 4",
      "difficulty": "Medium",
      "stem": "During information technology planning, change management is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Change management: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q021",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "System development — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to system development under Information Technology. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Technology includes transparent documentation and follow-up to confirm system development controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q022",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT audit — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying it audit within Information Technology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "IT audit in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q023",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT general controls — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on it general controls in Information Technology. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to IT general controls: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q024",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Change management — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about change management in Information Technology is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Technology includes transparent documentation and follow-up to confirm change management controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q025",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "System development — scenario 5",
      "difficulty": "Easy",
      "stem": "During information technology planning, system development is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "System development in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q026",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT audit — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to it audit under Information Technology. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to IT audit: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q027",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT general controls — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying it general controls within Information Technology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Technology includes transparent documentation and follow-up to confirm it general controls controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q028",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Change management — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on change management in Information Technology. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Change management in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q029",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "System development — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about system development in Information Technology is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to System development: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q030",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT audit — scenario 6",
      "difficulty": "Hard",
      "stem": "During information technology planning, it audit is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Technology includes transparent documentation and follow-up to confirm it audit controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q031",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT general controls — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to it general controls under Information Technology. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "IT general controls in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q032",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Change management — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying change management within Information Technology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Change management: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q033",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "System development — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on system development in Information Technology. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Technology includes transparent documentation and follow-up to confirm system development controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q034",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT audit — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about it audit in Information Technology is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "IT audit in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q035",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT general controls — scenario 8",
      "difficulty": "Medium",
      "stem": "During information technology planning, it general controls is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to IT general controls: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q036",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Change management — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to change management under Information Technology. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Technology includes transparent documentation and follow-up to confirm change management controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q037",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "System development — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying system development within Information Technology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "System development in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q038",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT audit — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on it audit in Information Technology. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to IT audit: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q039",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT general controls — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about it general controls in Information Technology is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Technology includes transparent documentation and follow-up to confirm it general controls controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q040",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Change management — scenario 9",
      "difficulty": "Easy",
      "stem": "During information technology planning, change management is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Change management in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q041",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "System development — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to system development under Information Technology. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to System development: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q042",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT audit — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying it audit within Information Technology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Technology includes transparent documentation and follow-up to confirm it audit controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q043",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT general controls — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on it general controls in Information Technology. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "IT general controls in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q044",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Change management — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about change management in Information Technology is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Change management: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q045",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "System development — scenario 10",
      "difficulty": "Hard",
      "stem": "During information technology planning, system development is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Technology includes transparent documentation and follow-up to confirm system development controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q046",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT audit — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to it audit under Information Technology. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "IT audit in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q047",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT general controls — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying it general controls within Information Technology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to IT general controls: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q048",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Change management — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on change management in Information Technology. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Information Technology includes transparent documentation and follow-up to confirm change management controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q049",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "System development — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about system development in Information Technology is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "System development in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D13-Q050",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT audit — scenario 11",
      "difficulty": "Medium",
      "stem": "During information technology planning, it audit is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to IT audit: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q001",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial Management fundamentals",
      "difficulty": "Medium",
      "stem": "When applying financial management principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Financial Management requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q002",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial Management risk focus",
      "difficulty": "Easy",
      "stem": "In financial management, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q003",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial Management independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing financial management discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q004",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial Management control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to financial management, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q005",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial Management reporting",
      "difficulty": "Medium",
      "stem": "Findings in financial management should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q006",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial Management ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in financial management, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q007",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial statements — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying financial statements within Financial Management, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Financial statements in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q008",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Budgeting — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on budgeting in Financial Management. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Budgeting: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q009",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Variance analysis — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about variance analysis in Financial Management is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Financial Management includes transparent documentation and follow-up to confirm variance analysis controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q010",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Accounting controls — scenario 1",
      "difficulty": "Easy",
      "stem": "During financial management planning, accounting controls is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Accounting controls in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q011",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial statements — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to financial statements under Financial Management. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Financial statements: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q012",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Budgeting — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying budgeting within Financial Management, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Financial Management includes transparent documentation and follow-up to confirm budgeting controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q013",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Variance analysis — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on variance analysis in Financial Management. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Variance analysis in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q014",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Accounting controls — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about accounting controls in Financial Management is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Accounting controls: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q015",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial statements — scenario 3",
      "difficulty": "Hard",
      "stem": "During financial management planning, financial statements is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Financial Management includes transparent documentation and follow-up to confirm financial statements controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q016",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Budgeting — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to budgeting under Financial Management. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Budgeting in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q017",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Variance analysis — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying variance analysis within Financial Management, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Variance analysis: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q018",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Accounting controls — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on accounting controls in Financial Management. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Financial Management includes transparent documentation and follow-up to confirm accounting controls controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q019",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial statements — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about financial statements in Financial Management is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Financial statements in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q020",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Budgeting — scenario 4",
      "difficulty": "Medium",
      "stem": "During financial management planning, budgeting is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Budgeting: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q021",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Variance analysis — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to variance analysis under Financial Management. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Financial Management includes transparent documentation and follow-up to confirm variance analysis controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q022",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Accounting controls — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying accounting controls within Financial Management, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Accounting controls in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q023",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial statements — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on financial statements in Financial Management. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Financial statements: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q024",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Budgeting — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about budgeting in Financial Management is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Financial Management includes transparent documentation and follow-up to confirm budgeting controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q025",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Variance analysis — scenario 5",
      "difficulty": "Easy",
      "stem": "During financial management planning, variance analysis is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Variance analysis in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q026",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Accounting controls — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to accounting controls under Financial Management. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Accounting controls: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q027",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial statements — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying financial statements within Financial Management, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Financial Management includes transparent documentation and follow-up to confirm financial statements controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q028",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Budgeting — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on budgeting in Financial Management. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Budgeting in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q029",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Variance analysis — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about variance analysis in Financial Management is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Variance analysis: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q030",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Accounting controls — scenario 6",
      "difficulty": "Hard",
      "stem": "During financial management planning, accounting controls is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Financial Management includes transparent documentation and follow-up to confirm accounting controls controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q031",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial statements — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to financial statements under Financial Management. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Financial statements in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q032",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Budgeting — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying budgeting within Financial Management, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Budgeting: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q033",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Variance analysis — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on variance analysis in Financial Management. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Financial Management includes transparent documentation and follow-up to confirm variance analysis controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q034",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Accounting controls — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about accounting controls in Financial Management is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Accounting controls in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q035",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial statements — scenario 8",
      "difficulty": "Medium",
      "stem": "During financial management planning, financial statements is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Financial statements: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q036",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Budgeting — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to budgeting under Financial Management. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Financial Management includes transparent documentation and follow-up to confirm budgeting controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q037",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Variance analysis — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying variance analysis within Financial Management, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Variance analysis in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q038",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Accounting controls — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on accounting controls in Financial Management. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Accounting controls: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q039",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial statements — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about financial statements in Financial Management is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Financial Management includes transparent documentation and follow-up to confirm financial statements controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q040",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Budgeting — scenario 9",
      "difficulty": "Easy",
      "stem": "During financial management planning, budgeting is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Budgeting in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q041",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Variance analysis — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to variance analysis under Financial Management. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Variance analysis: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q042",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Accounting controls — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying accounting controls within Financial Management, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Financial Management includes transparent documentation and follow-up to confirm accounting controls controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q043",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial statements — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on financial statements in Financial Management. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Financial statements in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q044",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Budgeting — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about budgeting in Financial Management is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Budgeting: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q045",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Variance analysis — scenario 10",
      "difficulty": "Hard",
      "stem": "During financial management planning, variance analysis is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Financial Management includes transparent documentation and follow-up to confirm variance analysis controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q046",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Accounting controls — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to accounting controls under Financial Management. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Accounting controls in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q047",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial statements — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying financial statements within Financial Management, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Financial statements: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q048",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Budgeting — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on budgeting in Financial Management. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Financial Management includes transparent documentation and follow-up to confirm budgeting controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q049",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Variance analysis — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about variance analysis in Financial Management is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Variance analysis in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D14-Q050",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Accounting controls — scenario 11",
      "difficulty": "Medium",
      "stem": "During financial management planning, accounting controls is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Accounting controls: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q001",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Internal Control Frameworks fundamentals",
      "difficulty": "Medium",
      "stem": "When applying internal control frameworks principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Internal Control Frameworks requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q002",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Internal Control Frameworks risk focus",
      "difficulty": "Easy",
      "stem": "In internal control frameworks, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q003",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Internal Control Frameworks independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing internal control frameworks discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q004",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Internal Control Frameworks control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to internal control frameworks, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q005",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Internal Control Frameworks reporting",
      "difficulty": "Medium",
      "stem": "Findings in internal control frameworks should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q006",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Internal Control Frameworks ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in internal control frameworks, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q007",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "COSO components — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying coso components within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "COSO components in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q008",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Control activities — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on control activities in Internal Control Frameworks. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Control activities: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q009",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Monitoring — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about monitoring in Internal Control Frameworks is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm monitoring controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q010",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Deficiencies — scenario 1",
      "difficulty": "Easy",
      "stem": "During internal control frameworks planning, deficiencies is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Deficiencies in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q011",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "COSO components — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to coso components under Internal Control Frameworks. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to COSO components: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q012",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Control activities — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying control activities within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm control activities controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q013",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Monitoring — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on monitoring in Internal Control Frameworks. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Monitoring in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q014",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Deficiencies — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about deficiencies in Internal Control Frameworks is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Deficiencies: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q015",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "COSO components — scenario 3",
      "difficulty": "Hard",
      "stem": "During internal control frameworks planning, coso components is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm coso components controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q016",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Control activities — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to control activities under Internal Control Frameworks. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Control activities in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q017",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Monitoring — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying monitoring within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Monitoring: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q018",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Deficiencies — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on deficiencies in Internal Control Frameworks. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm deficiencies controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q019",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "COSO components — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about coso components in Internal Control Frameworks is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "COSO components in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q020",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Control activities — scenario 4",
      "difficulty": "Medium",
      "stem": "During internal control frameworks planning, control activities is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Control activities: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q021",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Monitoring — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to monitoring under Internal Control Frameworks. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm monitoring controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q022",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Deficiencies — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying deficiencies within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Deficiencies in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q023",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "COSO components — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on coso components in Internal Control Frameworks. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to COSO components: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q024",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Control activities — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about control activities in Internal Control Frameworks is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm control activities controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q025",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Monitoring — scenario 5",
      "difficulty": "Easy",
      "stem": "During internal control frameworks planning, monitoring is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Monitoring in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q026",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Deficiencies — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to deficiencies under Internal Control Frameworks. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Deficiencies: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q027",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "COSO components — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying coso components within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm coso components controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q028",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Control activities — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on control activities in Internal Control Frameworks. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Control activities in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q029",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Monitoring — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about monitoring in Internal Control Frameworks is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Monitoring: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q030",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Deficiencies — scenario 6",
      "difficulty": "Hard",
      "stem": "During internal control frameworks planning, deficiencies is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm deficiencies controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q031",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "COSO components — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to coso components under Internal Control Frameworks. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "COSO components in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q032",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Control activities — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying control activities within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Control activities: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q033",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Monitoring — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on monitoring in Internal Control Frameworks. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm monitoring controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q034",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Deficiencies — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about deficiencies in Internal Control Frameworks is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Deficiencies in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q035",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "COSO components — scenario 8",
      "difficulty": "Medium",
      "stem": "During internal control frameworks planning, coso components is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to COSO components: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q036",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Control activities — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to control activities under Internal Control Frameworks. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm control activities controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q037",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Monitoring — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying monitoring within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Monitoring in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q038",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Deficiencies — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on deficiencies in Internal Control Frameworks. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Deficiencies: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q039",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "COSO components — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about coso components in Internal Control Frameworks is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm coso components controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q040",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Control activities — scenario 9",
      "difficulty": "Easy",
      "stem": "During internal control frameworks planning, control activities is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Control activities in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q041",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Monitoring — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to monitoring under Internal Control Frameworks. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Monitoring: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q042",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Deficiencies — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying deficiencies within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm deficiencies controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q043",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "COSO components — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on coso components in Internal Control Frameworks. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "COSO components in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q044",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Control activities — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about control activities in Internal Control Frameworks is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Control activities: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q045",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Monitoring — scenario 10",
      "difficulty": "Hard",
      "stem": "During internal control frameworks planning, monitoring is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm monitoring controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q046",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Deficiencies — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to deficiencies under Internal Control Frameworks. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Deficiencies in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q047",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "COSO components — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying coso components within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to COSO components: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q048",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Control activities — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on control activities in Internal Control Frameworks. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm control activities controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q049",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Monitoring — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about monitoring in Internal Control Frameworks is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Monitoring in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D15-Q050",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Deficiencies — scenario 11",
      "difficulty": "Medium",
      "stem": "During internal control frameworks planning, deficiencies is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Deficiencies: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q001",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data Analytics in Auditing fundamentals",
      "difficulty": "Medium",
      "stem": "When applying data analytics in auditing principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Data Analytics in Auditing requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q002",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data Analytics in Auditing risk focus",
      "difficulty": "Easy",
      "stem": "In data analytics in auditing, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q003",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data Analytics in Auditing independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing data analytics in auditing discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q004",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data Analytics in Auditing control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to data analytics in auditing, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q005",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data Analytics in Auditing reporting",
      "difficulty": "Medium",
      "stem": "Findings in data analytics in auditing should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q006",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data Analytics in Auditing ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in data analytics in auditing, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q007",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Continuous auditing — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying continuous auditing within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Continuous auditing in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q008",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data mining — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on data mining in Data Analytics in Auditing. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Data mining: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q009",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Visualization — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about visualization in Data Analytics in Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm visualization controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q010",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Anomaly detection — scenario 1",
      "difficulty": "Easy",
      "stem": "During data analytics in auditing planning, anomaly detection is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Anomaly detection in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q011",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Continuous auditing — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to continuous auditing under Data Analytics in Auditing. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Continuous auditing: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q012",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data mining — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying data mining within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm data mining controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q013",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Visualization — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on visualization in Data Analytics in Auditing. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Visualization in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q014",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Anomaly detection — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about anomaly detection in Data Analytics in Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Anomaly detection: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q015",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Continuous auditing — scenario 3",
      "difficulty": "Hard",
      "stem": "During data analytics in auditing planning, continuous auditing is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm continuous auditing controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q016",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data mining — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to data mining under Data Analytics in Auditing. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Data mining in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q017",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Visualization — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying visualization within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Visualization: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q018",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Anomaly detection — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on anomaly detection in Data Analytics in Auditing. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm anomaly detection controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q019",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Continuous auditing — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about continuous auditing in Data Analytics in Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Continuous auditing in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q020",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data mining — scenario 4",
      "difficulty": "Medium",
      "stem": "During data analytics in auditing planning, data mining is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Data mining: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q021",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Visualization — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to visualization under Data Analytics in Auditing. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm visualization controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q022",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Anomaly detection — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying anomaly detection within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Anomaly detection in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q023",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Continuous auditing — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on continuous auditing in Data Analytics in Auditing. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Continuous auditing: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q024",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data mining — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about data mining in Data Analytics in Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm data mining controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q025",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Visualization — scenario 5",
      "difficulty": "Easy",
      "stem": "During data analytics in auditing planning, visualization is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Visualization in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q026",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Anomaly detection — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to anomaly detection under Data Analytics in Auditing. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Anomaly detection: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q027",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Continuous auditing — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying continuous auditing within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm continuous auditing controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q028",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data mining — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on data mining in Data Analytics in Auditing. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Data mining in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q029",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Visualization — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about visualization in Data Analytics in Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Visualization: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q030",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Anomaly detection — scenario 6",
      "difficulty": "Hard",
      "stem": "During data analytics in auditing planning, anomaly detection is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm anomaly detection controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q031",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Continuous auditing — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to continuous auditing under Data Analytics in Auditing. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Continuous auditing in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q032",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data mining — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying data mining within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Data mining: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q033",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Visualization — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on visualization in Data Analytics in Auditing. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm visualization controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q034",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Anomaly detection — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about anomaly detection in Data Analytics in Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Anomaly detection in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q035",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Continuous auditing — scenario 8",
      "difficulty": "Medium",
      "stem": "During data analytics in auditing planning, continuous auditing is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Continuous auditing: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q036",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data mining — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to data mining under Data Analytics in Auditing. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm data mining controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q037",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Visualization — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying visualization within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Visualization in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q038",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Anomaly detection — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on anomaly detection in Data Analytics in Auditing. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Anomaly detection: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q039",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Continuous auditing — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about continuous auditing in Data Analytics in Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm continuous auditing controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q040",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data mining — scenario 9",
      "difficulty": "Easy",
      "stem": "During data analytics in auditing planning, data mining is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Data mining in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q041",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Visualization — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to visualization under Data Analytics in Auditing. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Visualization: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q042",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Anomaly detection — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying anomaly detection within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm anomaly detection controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q043",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Continuous auditing — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on continuous auditing in Data Analytics in Auditing. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Continuous auditing in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q044",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data mining — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about data mining in Data Analytics in Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Data mining: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q045",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Visualization — scenario 10",
      "difficulty": "Hard",
      "stem": "During data analytics in auditing planning, visualization is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm visualization controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q046",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Anomaly detection — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to anomaly detection under Data Analytics in Auditing. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Anomaly detection in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q047",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Continuous auditing — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying continuous auditing within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Continuous auditing: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q048",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data mining — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on data mining in Data Analytics in Auditing. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm data mining controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q049",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Visualization — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about visualization in Data Analytics in Auditing is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Visualization in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D16-Q050",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Anomaly detection — scenario 11",
      "difficulty": "Medium",
      "stem": "During data analytics in auditing planning, anomaly detection is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Anomaly detection: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q001",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Ethics and Professionalism fundamentals",
      "difficulty": "Medium",
      "stem": "When applying ethics and professionalism principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Ethics and Professionalism requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q002",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Ethics and Professionalism risk focus",
      "difficulty": "Easy",
      "stem": "In ethics and professionalism, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q003",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Ethics and Professionalism independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing ethics and professionalism discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q004",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Ethics and Professionalism control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to ethics and professionalism, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q005",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Ethics and Professionalism reporting",
      "difficulty": "Medium",
      "stem": "Findings in ethics and professionalism should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q006",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Ethics and Professionalism ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in ethics and professionalism, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q007",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "IIA Code of Ethics — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying iia code of ethics within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "IIA Code of Ethics in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q008",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Conflicts of interest — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on conflicts of interest in Ethics and Professionalism. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Conflicts of interest: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q009",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Confidentiality — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about confidentiality in Ethics and Professionalism is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm confidentiality controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q010",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Integrity — scenario 1",
      "difficulty": "Easy",
      "stem": "During ethics and professionalism planning, integrity is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Integrity in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q011",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "IIA Code of Ethics — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to iia code of ethics under Ethics and Professionalism. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to IIA Code of Ethics: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q012",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Conflicts of interest — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying conflicts of interest within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm conflicts of interest controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q013",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Confidentiality — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on confidentiality in Ethics and Professionalism. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Confidentiality in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q014",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Integrity — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about integrity in Ethics and Professionalism is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Integrity: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q015",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "IIA Code of Ethics — scenario 3",
      "difficulty": "Hard",
      "stem": "During ethics and professionalism planning, iia code of ethics is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm iia code of ethics controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q016",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Conflicts of interest — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to conflicts of interest under Ethics and Professionalism. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Conflicts of interest in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q017",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Confidentiality — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying confidentiality within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Confidentiality: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q018",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Integrity — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on integrity in Ethics and Professionalism. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm integrity controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q019",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "IIA Code of Ethics — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about iia code of ethics in Ethics and Professionalism is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "IIA Code of Ethics in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q020",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Conflicts of interest — scenario 4",
      "difficulty": "Medium",
      "stem": "During ethics and professionalism planning, conflicts of interest is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Conflicts of interest: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q021",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Confidentiality — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to confidentiality under Ethics and Professionalism. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm confidentiality controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q022",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Integrity — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying integrity within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Integrity in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q023",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "IIA Code of Ethics — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on iia code of ethics in Ethics and Professionalism. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to IIA Code of Ethics: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q024",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Conflicts of interest — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about conflicts of interest in Ethics and Professionalism is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm conflicts of interest controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q025",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Confidentiality — scenario 5",
      "difficulty": "Easy",
      "stem": "During ethics and professionalism planning, confidentiality is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Confidentiality in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q026",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Integrity — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to integrity under Ethics and Professionalism. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Integrity: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q027",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "IIA Code of Ethics — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying iia code of ethics within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm iia code of ethics controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q028",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Conflicts of interest — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on conflicts of interest in Ethics and Professionalism. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Conflicts of interest in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q029",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Confidentiality — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about confidentiality in Ethics and Professionalism is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Confidentiality: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q030",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Integrity — scenario 6",
      "difficulty": "Hard",
      "stem": "During ethics and professionalism planning, integrity is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm integrity controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q031",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "IIA Code of Ethics — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to iia code of ethics under Ethics and Professionalism. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "IIA Code of Ethics in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q032",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Conflicts of interest — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying conflicts of interest within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Conflicts of interest: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q033",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Confidentiality — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on confidentiality in Ethics and Professionalism. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm confidentiality controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q034",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Integrity — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about integrity in Ethics and Professionalism is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Integrity in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q035",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "IIA Code of Ethics — scenario 8",
      "difficulty": "Medium",
      "stem": "During ethics and professionalism planning, iia code of ethics is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to IIA Code of Ethics: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q036",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Conflicts of interest — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to conflicts of interest under Ethics and Professionalism. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm conflicts of interest controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q037",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Confidentiality — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying confidentiality within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Confidentiality in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q038",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Integrity — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on integrity in Ethics and Professionalism. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Integrity: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q039",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "IIA Code of Ethics — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about iia code of ethics in Ethics and Professionalism is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm iia code of ethics controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q040",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Conflicts of interest — scenario 9",
      "difficulty": "Easy",
      "stem": "During ethics and professionalism planning, conflicts of interest is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Conflicts of interest in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q041",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Confidentiality — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to confidentiality under Ethics and Professionalism. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Confidentiality: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q042",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Integrity — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying integrity within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm integrity controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q043",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "IIA Code of Ethics — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on iia code of ethics in Ethics and Professionalism. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "IIA Code of Ethics in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q044",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Conflicts of interest — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about conflicts of interest in Ethics and Professionalism is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Conflicts of interest: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q045",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Confidentiality — scenario 10",
      "difficulty": "Hard",
      "stem": "During ethics and professionalism planning, confidentiality is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm confidentiality controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q046",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Integrity — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to integrity under Ethics and Professionalism. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Integrity in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q047",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "IIA Code of Ethics — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying iia code of ethics within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to IIA Code of Ethics: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q048",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Conflicts of interest — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on conflicts of interest in Ethics and Professionalism. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm conflicts of interest controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q049",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Confidentiality — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about confidentiality in Ethics and Professionalism is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Confidentiality in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D17-Q050",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Integrity — scenario 11",
      "difficulty": "Medium",
      "stem": "During ethics and professionalism planning, integrity is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Integrity: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q001",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory Compliance fundamentals",
      "difficulty": "Medium",
      "stem": "When applying regulatory compliance principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Regulatory Compliance requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q002",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory Compliance risk focus",
      "difficulty": "Easy",
      "stem": "In regulatory compliance, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q003",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory Compliance independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing regulatory compliance discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q004",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory Compliance control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to regulatory compliance, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q005",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory Compliance reporting",
      "difficulty": "Medium",
      "stem": "Findings in regulatory compliance should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q006",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory Compliance ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in regulatory compliance, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q007",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Legal requirements — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying legal requirements within Regulatory Compliance, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Legal requirements in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q008",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Policy compliance — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on policy compliance in Regulatory Compliance. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Policy compliance: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q009",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory change — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about regulatory change in Regulatory Compliance is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm regulatory change controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q010",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Sanctions risk — scenario 1",
      "difficulty": "Easy",
      "stem": "During regulatory compliance planning, sanctions risk is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Sanctions risk in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q011",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Legal requirements — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to legal requirements under Regulatory Compliance. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Legal requirements: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q012",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Policy compliance — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying policy compliance within Regulatory Compliance, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm policy compliance controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q013",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory change — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on regulatory change in Regulatory Compliance. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Regulatory change in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q014",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Sanctions risk — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about sanctions risk in Regulatory Compliance is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Sanctions risk: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q015",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Legal requirements — scenario 3",
      "difficulty": "Hard",
      "stem": "During regulatory compliance planning, legal requirements is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm legal requirements controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q016",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Policy compliance — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to policy compliance under Regulatory Compliance. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Policy compliance in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q017",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory change — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying regulatory change within Regulatory Compliance, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Regulatory change: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q018",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Sanctions risk — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on sanctions risk in Regulatory Compliance. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm sanctions risk controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q019",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Legal requirements — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about legal requirements in Regulatory Compliance is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Legal requirements in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q020",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Policy compliance — scenario 4",
      "difficulty": "Medium",
      "stem": "During regulatory compliance planning, policy compliance is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Policy compliance: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q021",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory change — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to regulatory change under Regulatory Compliance. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm regulatory change controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q022",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Sanctions risk — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying sanctions risk within Regulatory Compliance, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Sanctions risk in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q023",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Legal requirements — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on legal requirements in Regulatory Compliance. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Legal requirements: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q024",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Policy compliance — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about policy compliance in Regulatory Compliance is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm policy compliance controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q025",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory change — scenario 5",
      "difficulty": "Easy",
      "stem": "During regulatory compliance planning, regulatory change is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Regulatory change in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q026",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Sanctions risk — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to sanctions risk under Regulatory Compliance. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Sanctions risk: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q027",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Legal requirements — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying legal requirements within Regulatory Compliance, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm legal requirements controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q028",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Policy compliance — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on policy compliance in Regulatory Compliance. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Policy compliance in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q029",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory change — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about regulatory change in Regulatory Compliance is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Regulatory change: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q030",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Sanctions risk — scenario 6",
      "difficulty": "Hard",
      "stem": "During regulatory compliance planning, sanctions risk is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm sanctions risk controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q031",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Legal requirements — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to legal requirements under Regulatory Compliance. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Legal requirements in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q032",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Policy compliance — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying policy compliance within Regulatory Compliance, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Policy compliance: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q033",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory change — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on regulatory change in Regulatory Compliance. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm regulatory change controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q034",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Sanctions risk — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about sanctions risk in Regulatory Compliance is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Sanctions risk in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q035",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Legal requirements — scenario 8",
      "difficulty": "Medium",
      "stem": "During regulatory compliance planning, legal requirements is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Legal requirements: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q036",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Policy compliance — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to policy compliance under Regulatory Compliance. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm policy compliance controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q037",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory change — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying regulatory change within Regulatory Compliance, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Regulatory change in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q038",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Sanctions risk — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on sanctions risk in Regulatory Compliance. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Sanctions risk: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q039",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Legal requirements — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about legal requirements in Regulatory Compliance is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm legal requirements controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q040",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Policy compliance — scenario 9",
      "difficulty": "Easy",
      "stem": "During regulatory compliance planning, policy compliance is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Policy compliance in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q041",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory change — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to regulatory change under Regulatory Compliance. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Regulatory change: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q042",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Sanctions risk — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying sanctions risk within Regulatory Compliance, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm sanctions risk controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q043",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Legal requirements — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on legal requirements in Regulatory Compliance. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Legal requirements in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q044",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Policy compliance — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about policy compliance in Regulatory Compliance is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Policy compliance: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q045",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory change — scenario 10",
      "difficulty": "Hard",
      "stem": "During regulatory compliance planning, regulatory change is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm regulatory change controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q046",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Sanctions risk — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to sanctions risk under Regulatory Compliance. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Sanctions risk in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q047",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Legal requirements — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying legal requirements within Regulatory Compliance, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Legal requirements: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q048",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Policy compliance — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on policy compliance in Regulatory Compliance. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm policy compliance controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q049",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory change — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about regulatory change in Regulatory Compliance is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Regulatory change in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D18-Q050",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Sanctions risk — scenario 11",
      "difficulty": "Medium",
      "stem": "During regulatory compliance planning, sanctions risk is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Sanctions risk: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q001",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk Assessment Methodology fundamentals",
      "difficulty": "Medium",
      "stem": "When applying risk assessment methodology principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Risk Assessment Methodology requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q002",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk Assessment Methodology risk focus",
      "difficulty": "Easy",
      "stem": "In risk assessment methodology, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q003",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk Assessment Methodology independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing risk assessment methodology discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q004",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk Assessment Methodology control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to risk assessment methodology, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q005",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk Assessment Methodology reporting",
      "difficulty": "Medium",
      "stem": "Findings in risk assessment methodology should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q006",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk Assessment Methodology ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in risk assessment methodology, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q007",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Inherent risk — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying inherent risk within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Inherent risk in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q008",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Residual risk — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on residual risk in Risk Assessment Methodology. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Residual risk: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q009",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk registers — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about risk registers in Risk Assessment Methodology is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm risk registers controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q010",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Heat maps — scenario 1",
      "difficulty": "Easy",
      "stem": "During risk assessment methodology planning, heat maps is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Heat maps in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q011",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Inherent risk — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to inherent risk under Risk Assessment Methodology. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Inherent risk: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q012",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Residual risk — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying residual risk within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm residual risk controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q013",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk registers — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on risk registers in Risk Assessment Methodology. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Risk registers in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q014",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Heat maps — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about heat maps in Risk Assessment Methodology is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Heat maps: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q015",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Inherent risk — scenario 3",
      "difficulty": "Hard",
      "stem": "During risk assessment methodology planning, inherent risk is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm inherent risk controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q016",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Residual risk — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to residual risk under Risk Assessment Methodology. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Residual risk in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q017",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk registers — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying risk registers within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Risk registers: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q018",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Heat maps — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on heat maps in Risk Assessment Methodology. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm heat maps controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q019",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Inherent risk — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about inherent risk in Risk Assessment Methodology is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Inherent risk in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q020",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Residual risk — scenario 4",
      "difficulty": "Medium",
      "stem": "During risk assessment methodology planning, residual risk is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Residual risk: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q021",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk registers — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to risk registers under Risk Assessment Methodology. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm risk registers controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q022",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Heat maps — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying heat maps within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Heat maps in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q023",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Inherent risk — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on inherent risk in Risk Assessment Methodology. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Inherent risk: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q024",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Residual risk — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about residual risk in Risk Assessment Methodology is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm residual risk controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q025",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk registers — scenario 5",
      "difficulty": "Easy",
      "stem": "During risk assessment methodology planning, risk registers is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Risk registers in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q026",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Heat maps — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to heat maps under Risk Assessment Methodology. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Heat maps: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q027",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Inherent risk — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying inherent risk within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm inherent risk controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q028",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Residual risk — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on residual risk in Risk Assessment Methodology. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Residual risk in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q029",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk registers — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about risk registers in Risk Assessment Methodology is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Risk registers: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q030",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Heat maps — scenario 6",
      "difficulty": "Hard",
      "stem": "During risk assessment methodology planning, heat maps is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm heat maps controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q031",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Inherent risk — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to inherent risk under Risk Assessment Methodology. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Inherent risk in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q032",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Residual risk — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying residual risk within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Residual risk: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q033",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk registers — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on risk registers in Risk Assessment Methodology. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm risk registers controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q034",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Heat maps — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about heat maps in Risk Assessment Methodology is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Heat maps in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q035",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Inherent risk — scenario 8",
      "difficulty": "Medium",
      "stem": "During risk assessment methodology planning, inherent risk is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Inherent risk: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q036",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Residual risk — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to residual risk under Risk Assessment Methodology. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm residual risk controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q037",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk registers — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying risk registers within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Risk registers in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q038",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Heat maps — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on heat maps in Risk Assessment Methodology. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Heat maps: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q039",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Inherent risk — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about inherent risk in Risk Assessment Methodology is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm inherent risk controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q040",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Residual risk — scenario 9",
      "difficulty": "Easy",
      "stem": "During risk assessment methodology planning, residual risk is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Residual risk in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q041",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk registers — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to risk registers under Risk Assessment Methodology. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Risk registers: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q042",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Heat maps — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying heat maps within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm heat maps controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q043",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Inherent risk — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on inherent risk in Risk Assessment Methodology. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Inherent risk in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q044",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Residual risk — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about residual risk in Risk Assessment Methodology is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Residual risk: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q045",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk registers — scenario 10",
      "difficulty": "Hard",
      "stem": "During risk assessment methodology planning, risk registers is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm risk registers controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q046",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Heat maps — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to heat maps under Risk Assessment Methodology. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Heat maps in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q047",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Inherent risk — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying inherent risk within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Inherent risk: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q048",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Residual risk — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on residual risk in Risk Assessment Methodology. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm residual risk controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q049",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk registers — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about risk registers in Risk Assessment Methodology is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Risk registers in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D19-Q050",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Heat maps — scenario 11",
      "difficulty": "Medium",
      "stem": "During risk assessment methodology planning, heat maps is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Heat maps: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q001",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Audit Reporting and Follow-Up fundamentals",
      "difficulty": "Medium",
      "stem": "When applying audit reporting and follow-up principles, which action best aligns with the IIA Standards and professional internal auditing practice?",
      "choiceA": "Apply systematic, disciplined approaches with documented evidence and appropriate supervision",
      "choiceB": "Rely on undocumented assumptions without verification",
      "choiceC": "Skip independence considerations when under time pressure",
      "choiceD": "Withhold significant findings from senior management",
      "correctAnswer": "A",
      "explanation": "Audit Reporting and Follow-Up requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q002",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Audit Reporting and Follow-Up risk focus",
      "difficulty": "Easy",
      "stem": "In audit reporting and follow-up, internal auditors should prioritize:",
      "choiceA": "Areas of significant risk to organizational objectives and governance effectiveness",
      "choiceB": "Only areas requested by operational managers",
      "choiceC": "Random samples without risk assessment",
      "choiceD": "Low-risk areas to maximize audit hours",
      "correctAnswer": "A",
      "explanation": "Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q003",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Audit Reporting and Follow-Up independence",
      "difficulty": "Medium",
      "stem": "An auditor assessing audit reporting and follow-up discovers a potential impairment to objectivity. The appropriate response is:",
      "choiceA": "Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained",
      "choiceB": "Proceed without disclosure to avoid delays",
      "choiceC": "Accept gifts that could influence judgment",
      "choiceD": "Implement controls the auditor previously designed without safeguards",
      "correctAnswer": "A",
      "explanation": "Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q004",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Audit Reporting and Follow-Up control evaluation",
      "difficulty": "Hard",
      "stem": "When evaluating controls related to audit reporting and follow-up, auditors should:",
      "choiceA": "Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence",
      "choiceB": "Accept management assertions without testing",
      "choiceC": "Report only on design without considering operations",
      "choiceD": "Limit work to inquiry alone",
      "correctAnswer": "A",
      "explanation": "Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.",
      "reference": "coso-framework: COSO Internal Control Framework (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q005",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Audit Reporting and Follow-Up reporting",
      "difficulty": "Medium",
      "stem": "Findings in audit reporting and follow-up should be communicated:",
      "choiceA": "Timely, accurately, and objectively with clear criteria, condition, cause, and effect",
      "choiceB": "Only verbally without documentation",
      "choiceC": "After all other audits complete regardless of urgency",
      "choiceD": "With subjective opinions unsupported by evidence",
      "correctAnswer": "A",
      "explanation": "Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q006",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Audit Reporting and Follow-Up ethics",
      "difficulty": "Easy",
      "stem": "When conflicts arise in audit reporting and follow-up, internal auditors must:",
      "choiceA": "Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics",
      "choiceB": "Disclose confidential information to unauthorized parties",
      "choiceC": "Accept payments that influence audit conclusions",
      "choiceD": "Misrepresent findings to protect management",
      "correctAnswer": "A",
      "explanation": "The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.",
      "reference": "iia-code-ethics: IIA Code of Ethics (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q007",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Rating scales — scenario 1",
      "difficulty": "Easy",
      "stem": "When applying rating scales within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Rating scales in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q008",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Management responses — scenario 1",
      "difficulty": "Medium",
      "stem": "A facility review focuses on management responses in Audit Reporting and Follow-Up. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Management responses: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q009",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Action tracking — scenario 1",
      "difficulty": "Hard",
      "stem": "Which statement about action tracking in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm action tracking controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q010",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Closure criteria — scenario 1",
      "difficulty": "Easy",
      "stem": "During audit reporting and follow-up planning, closure criteria is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Closure criteria in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q011",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Rating scales — scenario 2",
      "difficulty": "Medium",
      "stem": "An audit finding relates to rating scales under Audit Reporting and Follow-Up. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Rating scales: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q012",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Management responses — scenario 2",
      "difficulty": "Hard",
      "stem": "When applying management responses within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm management responses controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q013",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Action tracking — scenario 2",
      "difficulty": "Easy",
      "stem": "A facility review focuses on action tracking in Audit Reporting and Follow-Up. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Action tracking in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q014",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Closure criteria — scenario 2",
      "difficulty": "Medium",
      "stem": "Which statement about closure criteria in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Closure criteria: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q015",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Rating scales — scenario 3",
      "difficulty": "Hard",
      "stem": "During audit reporting and follow-up planning, rating scales is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm rating scales controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q016",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Management responses — scenario 3",
      "difficulty": "Easy",
      "stem": "An audit finding relates to management responses under Audit Reporting and Follow-Up. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Management responses in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q017",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Action tracking — scenario 3",
      "difficulty": "Medium",
      "stem": "When applying action tracking within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Action tracking: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q018",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Closure criteria — scenario 3",
      "difficulty": "Hard",
      "stem": "A facility review focuses on closure criteria in Audit Reporting and Follow-Up. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm closure criteria controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q019",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Rating scales — scenario 4",
      "difficulty": "Easy",
      "stem": "Which statement about rating scales in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Rating scales in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q020",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Management responses — scenario 4",
      "difficulty": "Medium",
      "stem": "During audit reporting and follow-up planning, management responses is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Management responses: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q021",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Action tracking — scenario 4",
      "difficulty": "Hard",
      "stem": "An audit finding relates to action tracking under Audit Reporting and Follow-Up. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm action tracking controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q022",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Closure criteria — scenario 4",
      "difficulty": "Easy",
      "stem": "When applying closure criteria within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Closure criteria in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q023",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Rating scales — scenario 5",
      "difficulty": "Medium",
      "stem": "A facility review focuses on rating scales in Audit Reporting and Follow-Up. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Rating scales: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q024",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Management responses — scenario 5",
      "difficulty": "Hard",
      "stem": "Which statement about management responses in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm management responses controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q025",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Action tracking — scenario 5",
      "difficulty": "Easy",
      "stem": "During audit reporting and follow-up planning, action tracking is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Action tracking in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q026",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Closure criteria — scenario 5",
      "difficulty": "Medium",
      "stem": "An audit finding relates to closure criteria under Audit Reporting and Follow-Up. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Closure criteria: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q027",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Rating scales — scenario 6",
      "difficulty": "Hard",
      "stem": "When applying rating scales within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm rating scales controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q028",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Management responses — scenario 6",
      "difficulty": "Easy",
      "stem": "A facility review focuses on management responses in Audit Reporting and Follow-Up. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Management responses in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q029",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Action tracking — scenario 6",
      "difficulty": "Medium",
      "stem": "Which statement about action tracking in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Action tracking: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q030",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Closure criteria — scenario 6",
      "difficulty": "Hard",
      "stem": "During audit reporting and follow-up planning, closure criteria is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm closure criteria controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q031",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Rating scales — scenario 7",
      "difficulty": "Easy",
      "stem": "An audit finding relates to rating scales under Audit Reporting and Follow-Up. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Rating scales in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q032",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Management responses — scenario 7",
      "difficulty": "Medium",
      "stem": "When applying management responses within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Management responses: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q033",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Action tracking — scenario 7",
      "difficulty": "Hard",
      "stem": "A facility review focuses on action tracking in Audit Reporting and Follow-Up. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm action tracking controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q034",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Closure criteria — scenario 7",
      "difficulty": "Easy",
      "stem": "Which statement about closure criteria in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Closure criteria in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q035",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Rating scales — scenario 8",
      "difficulty": "Medium",
      "stem": "During audit reporting and follow-up planning, rating scales is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Rating scales: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q036",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Management responses — scenario 8",
      "difficulty": "Hard",
      "stem": "An audit finding relates to management responses under Audit Reporting and Follow-Up. Corrective action should:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm management responses controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q037",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Action tracking — scenario 8",
      "difficulty": "Easy",
      "stem": "When applying action tracking within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Action tracking in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q038",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Closure criteria — scenario 8",
      "difficulty": "Medium",
      "stem": "A facility review focuses on closure criteria in Audit Reporting and Follow-Up. The most defensible next step is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Closure criteria: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q039",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Rating scales — scenario 9",
      "difficulty": "Hard",
      "stem": "Which statement about rating scales in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm rating scales controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q040",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Management responses — scenario 9",
      "difficulty": "Easy",
      "stem": "During audit reporting and follow-up planning, management responses is evaluated. The priority action is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Management responses in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q041",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Action tracking — scenario 9",
      "difficulty": "Medium",
      "stem": "An audit finding relates to action tracking under Audit Reporting and Follow-Up. Corrective action should:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Action tracking: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q042",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Closure criteria — scenario 9",
      "difficulty": "Hard",
      "stem": "When applying closure criteria within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm closure criteria controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q043",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Rating scales — scenario 10",
      "difficulty": "Easy",
      "stem": "A facility review focuses on rating scales in Audit Reporting and Follow-Up. The most defensible next step is:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Rating scales in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q044",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Management responses — scenario 10",
      "difficulty": "Medium",
      "stem": "Which statement about management responses in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Management responses: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q045",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Action tracking — scenario 10",
      "difficulty": "Hard",
      "stem": "During audit reporting and follow-up planning, action tracking is evaluated. The priority action is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm action tracking controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q046",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Closure criteria — scenario 10",
      "difficulty": "Easy",
      "stem": "An audit finding relates to closure criteria under Audit Reporting and Follow-Up. Corrective action should:",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Closure criteria in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q047",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Rating scales — scenario 11",
      "difficulty": "Medium",
      "stem": "When applying rating scales within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Rating scales: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q048",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Management responses — scenario 11",
      "difficulty": "Hard",
      "stem": "A facility review focuses on management responses in Audit Reporting and Follow-Up. The most defensible next step is:",
      "choiceA": "Document assumptions, communicate findings, and schedule follow-up verification",
      "choiceB": "Close the issue without root-cause analysis",
      "choiceC": "Withhold results from affected workers",
      "choiceD": "Use proprietary prep content without citation",
      "correctAnswer": "A",
      "explanation": "Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm management responses controls remain effective.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q049",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Action tracking — scenario 11",
      "difficulty": "Easy",
      "stem": "Which statement about action tracking in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?",
      "choiceA": "Use documented, reference-backed methods and verify control effectiveness",
      "choiceB": "Rely on undocumented assumptions without follow-up",
      "choiceC": "Skip worker communication and training",
      "choiceD": "Discard sampling or inspection records",
      "correctAnswer": "A",
      "explanation": "Action tracking in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-D20-Q050",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Closure criteria — scenario 11",
      "difficulty": "Medium",
      "stem": "During audit reporting and follow-up planning, closure criteria is evaluated. The priority action is:",
      "choiceA": "Prioritize elimination or engineering controls before administrative measures and PPE",
      "choiceB": "Use PPE alone without assessing source controls",
      "choiceC": "Defer all action until an injury occurs",
      "choiceD": "Ignore applicable regulatory minimums",
      "correctAnswer": "A",
      "explanation": "The hierarchy of controls applies to Closure criteria: reduce exposure at the source before relying on administrative measures or PPE alone.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D1-Q001",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mission definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Foundations of Internal Auditing requires that mission must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Foundations of Internal Auditing integrates mission with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D1-Q002",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mission — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Foundations of Internal Auditing, mission is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Mission in Foundations of Internal Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D1-Q003",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Value proposition — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing value proposition within Foundations of Internal Auditing, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective value proposition starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D1-Q004",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mandatory guidance — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for mandatory guidance in Foundations of Internal Auditing is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Foundations of Internal Auditing.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D1-Q005",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Professional framework — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Foundations of Internal Auditing, professional framework is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Professional framework in Foundations of Internal Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D1-Q006",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mission — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing mission within Foundations of Internal Auditing, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective mission starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D1-Q007",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Value proposition — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for value proposition in Foundations of Internal Auditing is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Foundations of Internal Auditing.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D1-Q008",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mandatory guidance — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Foundations of Internal Auditing, mandatory guidance is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Mandatory guidance in Foundations of Internal Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D1-Q009",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Professional framework — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing professional framework within Foundations of Internal Auditing, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective professional framework starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D1-Q010",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mission — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for mission in Foundations of Internal Auditing is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Foundations of Internal Auditing.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D1-Q011",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Value proposition — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Foundations of Internal Auditing, value proposition is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Value proposition in Foundations of Internal Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D1-Q012",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Mandatory guidance — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing mandatory guidance within Foundations of Internal Auditing, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective mandatory guidance starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D1-Q013",
      "itemType": "question",
      "domain": "foundations-internal-auditing",
      "topic": "Professional framework — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for professional framework in Foundations of Internal Auditing is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Foundations of Internal Auditing.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D2-Q001",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Organizational independence definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Independence and Objectivity requires that organizational independence must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Independence and Objectivity integrates organizational independence with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D2-Q002",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Organizational independence — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Independence and Objectivity, organizational independence is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Organizational independence in Independence and Objectivity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D2-Q003",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Individual objectivity — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing individual objectivity within Independence and Objectivity, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective individual objectivity starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D2-Q004",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Impairments — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for impairments in Independence and Objectivity is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Independence and Objectivity.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D2-Q005",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Disclosure — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Independence and Objectivity, disclosure is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Disclosure in Independence and Objectivity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D2-Q006",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Organizational independence — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing organizational independence within Independence and Objectivity, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective organizational independence starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D2-Q007",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Individual objectivity — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for individual objectivity in Independence and Objectivity is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Independence and Objectivity.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D2-Q008",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Impairments — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Independence and Objectivity, impairments is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Impairments in Independence and Objectivity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D2-Q009",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Disclosure — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing disclosure within Independence and Objectivity, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective disclosure starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D2-Q010",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Organizational independence — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for organizational independence in Independence and Objectivity is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Independence and Objectivity.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D2-Q011",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Individual objectivity — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Independence and Objectivity, individual objectivity is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Individual objectivity in Independence and Objectivity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D2-Q012",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Impairments — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing impairments within Independence and Objectivity, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective impairments starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D2-Q013",
      "itemType": "question",
      "domain": "independence-objectivity",
      "topic": "Disclosure — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for disclosure in Independence and Objectivity is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Independence and Objectivity.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D3-Q001",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Competency definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Proficiency and Due Professional Care requires that competency must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Proficiency and Due Professional Care integrates competency with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D3-Q002",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Competency — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Proficiency and Due Professional Care, competency is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Competency in Proficiency and Due Professional Care requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D3-Q003",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Continuing education — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing continuing education within Proficiency and Due Professional Care, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective continuing education starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D3-Q004",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Supervision — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for supervision in Proficiency and Due Professional Care is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Proficiency and Due Professional Care.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D3-Q005",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Due care — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Proficiency and Due Professional Care, due care is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Due care in Proficiency and Due Professional Care requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D3-Q006",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Competency — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing competency within Proficiency and Due Professional Care, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective competency starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D3-Q007",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Continuing education — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for continuing education in Proficiency and Due Professional Care is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Proficiency and Due Professional Care.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D3-Q008",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Supervision — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Proficiency and Due Professional Care, supervision is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Supervision in Proficiency and Due Professional Care requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D3-Q009",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Due care — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing due care within Proficiency and Due Professional Care, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective due care starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D3-Q010",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Competency — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for competency in Proficiency and Due Professional Care is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Proficiency and Due Professional Care.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D3-Q011",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Continuing education — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Proficiency and Due Professional Care, continuing education is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Continuing education in Proficiency and Due Professional Care requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D3-Q012",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Supervision — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing supervision within Proficiency and Due Professional Care, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective supervision starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D3-Q013",
      "itemType": "question",
      "domain": "proficiency-due-care",
      "topic": "Due care — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for due care in Proficiency and Due Professional Care is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Proficiency and Due Professional Care.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D4-Q001",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Internal assessments definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Quality Assurance and Improvement Program requires that internal assessments must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Quality Assurance and Improvement Program integrates internal assessments with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D4-Q002",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Internal assessments — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Quality Assurance and Improvement Program, internal assessments is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Internal assessments in Quality Assurance and Improvement Program requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D4-Q003",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "External assessments — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing external assessments within Quality Assurance and Improvement Program, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective external assessments starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D4-Q004",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "QAIP reporting — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for qaip reporting in Quality Assurance and Improvement Program is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Quality Assurance and Improvement Program.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D4-Q005",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Improvement plans — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Quality Assurance and Improvement Program, improvement plans is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Improvement plans in Quality Assurance and Improvement Program requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D4-Q006",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Internal assessments — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing internal assessments within Quality Assurance and Improvement Program, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective internal assessments starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D4-Q007",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "External assessments — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for external assessments in Quality Assurance and Improvement Program is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Quality Assurance and Improvement Program.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D4-Q008",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "QAIP reporting — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Quality Assurance and Improvement Program, qaip reporting is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "QAIP reporting in Quality Assurance and Improvement Program requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D4-Q009",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Improvement plans — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing improvement plans within Quality Assurance and Improvement Program, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective improvement plans starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D4-Q010",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Internal assessments — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for internal assessments in Quality Assurance and Improvement Program is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Quality Assurance and Improvement Program.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D4-Q011",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "External assessments — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Quality Assurance and Improvement Program, external assessments is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "External assessments in Quality Assurance and Improvement Program requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D4-Q012",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "QAIP reporting — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing qaip reporting within Quality Assurance and Improvement Program, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective qaip reporting starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D4-Q013",
      "itemType": "question",
      "domain": "quality-assurance-improvement",
      "topic": "Improvement plans — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for improvement plans in Quality Assurance and Improvement Program is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Quality Assurance and Improvement Program.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D5-Q001",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Three lines model definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Governance, Risk Management, and Control requires that three lines model must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Governance, Risk Management, and Control integrates three lines model with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D5-Q002",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Three lines model — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Governance, Risk Management, and Control, three lines model is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Three lines model in Governance, Risk Management, and Control requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D5-Q003",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Risk appetite — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing risk appetite within Governance, Risk Management, and Control, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective risk appetite starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D5-Q004",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Control environment — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for control environment in Governance, Risk Management, and Control is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Governance, Risk Management, and Control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D5-Q005",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Board oversight — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Governance, Risk Management, and Control, board oversight is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Board oversight in Governance, Risk Management, and Control requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D5-Q006",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Three lines model — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing three lines model within Governance, Risk Management, and Control, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective three lines model starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D5-Q007",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Risk appetite — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for risk appetite in Governance, Risk Management, and Control is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Governance, Risk Management, and Control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D5-Q008",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Control environment — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Governance, Risk Management, and Control, control environment is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Control environment in Governance, Risk Management, and Control requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D5-Q009",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Board oversight — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing board oversight within Governance, Risk Management, and Control, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective board oversight starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D5-Q010",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Three lines model — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for three lines model in Governance, Risk Management, and Control is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Governance, Risk Management, and Control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D5-Q011",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Risk appetite — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Governance, Risk Management, and Control, risk appetite is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Risk appetite in Governance, Risk Management, and Control requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D5-Q012",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Control environment — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing control environment within Governance, Risk Management, and Control, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective control environment starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D5-Q013",
      "itemType": "question",
      "domain": "governance-risk-control",
      "topic": "Board oversight — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for board oversight in Governance, Risk Management, and Control is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Governance, Risk Management, and Control.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D6-Q001",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud indicators definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Fraud Risks requires that fraud indicators must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Fraud Risks integrates fraud indicators with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D6-Q002",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud indicators — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Fraud Risks, fraud indicators is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Fraud indicators in Fraud Risks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D6-Q003",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Red flags — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing red flags within Fraud Risks, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective red flags starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D6-Q004",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Investigation boundaries — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for investigation boundaries in Fraud Risks is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Fraud Risks.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D6-Q005",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Reporting — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Fraud Risks, reporting is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Reporting in Fraud Risks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D6-Q006",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud indicators — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing fraud indicators within Fraud Risks, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective fraud indicators starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D6-Q007",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Red flags — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for red flags in Fraud Risks is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Fraud Risks.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D6-Q008",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Investigation boundaries — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Fraud Risks, investigation boundaries is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Investigation boundaries in Fraud Risks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D6-Q009",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Reporting — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing reporting within Fraud Risks, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective reporting starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D6-Q010",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Fraud indicators — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for fraud indicators in Fraud Risks is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Fraud Risks.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D6-Q011",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Red flags — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Fraud Risks, red flags is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Red flags in Fraud Risks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D6-Q012",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Investigation boundaries — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing investigation boundaries within Fraud Risks, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective investigation boundaries starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D6-Q013",
      "itemType": "question",
      "domain": "fraud-risks",
      "topic": "Reporting — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for reporting in Fraud Risks is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Fraud Risks.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D7-Q001",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Charter definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Managing the Internal Audit Activity requires that charter must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Managing the Internal Audit Activity integrates charter with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D7-Q002",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Charter — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Managing the Internal Audit Activity, charter is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Charter in Managing the Internal Audit Activity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D7-Q003",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Resource planning — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing resource planning within Managing the Internal Audit Activity, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective resource planning starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D7-Q004",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Policies — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for policies in Managing the Internal Audit Activity is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Managing the Internal Audit Activity.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D7-Q005",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Performance metrics — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Managing the Internal Audit Activity, performance metrics is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Performance metrics in Managing the Internal Audit Activity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D7-Q006",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Charter — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing charter within Managing the Internal Audit Activity, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective charter starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D7-Q007",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Resource planning — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for resource planning in Managing the Internal Audit Activity is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Managing the Internal Audit Activity.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D7-Q008",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Policies — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Managing the Internal Audit Activity, policies is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Policies in Managing the Internal Audit Activity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D7-Q009",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Performance metrics — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing performance metrics within Managing the Internal Audit Activity, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective performance metrics starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D7-Q010",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Charter — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for charter in Managing the Internal Audit Activity is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Managing the Internal Audit Activity.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D7-Q011",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Resource planning — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Managing the Internal Audit Activity, resource planning is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Resource planning in Managing the Internal Audit Activity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D7-Q012",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Policies — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing policies within Managing the Internal Audit Activity, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective policies starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D7-Q013",
      "itemType": "question",
      "domain": "managing-audit-activity",
      "topic": "Performance metrics — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for performance metrics in Managing the Internal Audit Activity is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Managing the Internal Audit Activity.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D8-Q001",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Risk-based planning definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Engagement Planning requires that risk-based planning must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Engagement Planning integrates risk-based planning with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D8-Q002",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Risk-based planning — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Engagement Planning, risk-based planning is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Risk-based planning in Engagement Planning requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D8-Q003",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Scope — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing scope within Engagement Planning, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective scope starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D8-Q004",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Objectives — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for objectives in Engagement Planning is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Engagement Planning.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D8-Q005",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Work programs — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Engagement Planning, work programs is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Work programs in Engagement Planning requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D8-Q006",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Risk-based planning — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing risk-based planning within Engagement Planning, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective risk-based planning starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D8-Q007",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Scope — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for scope in Engagement Planning is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Engagement Planning.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D8-Q008",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Objectives — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Engagement Planning, objectives is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Objectives in Engagement Planning requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D8-Q009",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Work programs — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing work programs within Engagement Planning, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective work programs starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D8-Q010",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Risk-based planning — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for risk-based planning in Engagement Planning is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Engagement Planning.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D8-Q011",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Scope — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Engagement Planning, scope is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Scope in Engagement Planning requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D8-Q012",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Objectives — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing objectives within Engagement Planning, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective objectives starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D8-Q013",
      "itemType": "question",
      "domain": "engagement-planning",
      "topic": "Work programs — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for work programs in Engagement Planning is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Engagement Planning.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D9-Q001",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Evidence gathering definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Performing the Engagement requires that evidence gathering must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Performing the Engagement integrates evidence gathering with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D9-Q002",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Evidence gathering — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Performing the Engagement, evidence gathering is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Evidence gathering in Performing the Engagement requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D9-Q003",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Sampling — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing sampling within Performing the Engagement, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective sampling starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D9-Q004",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Analysis — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for analysis in Performing the Engagement is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Performing the Engagement.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D9-Q005",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Documentation — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Performing the Engagement, documentation is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Documentation in Performing the Engagement requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D9-Q006",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Evidence gathering — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing evidence gathering within Performing the Engagement, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective evidence gathering starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D9-Q007",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Sampling — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for sampling in Performing the Engagement is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Performing the Engagement.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D9-Q008",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Analysis — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Performing the Engagement, analysis is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Analysis in Performing the Engagement requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D9-Q009",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Documentation — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing documentation within Performing the Engagement, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective documentation starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D9-Q010",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Evidence gathering — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for evidence gathering in Performing the Engagement is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Performing the Engagement.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D9-Q011",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Sampling — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Performing the Engagement, sampling is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Sampling in Performing the Engagement requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D9-Q012",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Analysis — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing analysis within Performing the Engagement, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective analysis starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D9-Q013",
      "itemType": "question",
      "domain": "engagement-performance",
      "topic": "Documentation — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for documentation in Performing the Engagement is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Performing the Engagement.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D10-Q001",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Reporting definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Communicating Engagement Results requires that reporting must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Communicating Engagement Results integrates reporting with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D10-Q002",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Reporting — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Communicating Engagement Results, reporting is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Reporting in Communicating Engagement Results requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D10-Q003",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Recommendations — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing recommendations within Communicating Engagement Results, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective recommendations starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D10-Q004",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Follow-up — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for follow-up in Communicating Engagement Results is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Communicating Engagement Results.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D10-Q005",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Monitoring — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Communicating Engagement Results, monitoring is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Monitoring in Communicating Engagement Results requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D10-Q006",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Reporting — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing reporting within Communicating Engagement Results, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective reporting starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D10-Q007",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Recommendations — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for recommendations in Communicating Engagement Results is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Communicating Engagement Results.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D10-Q008",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Follow-up — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Communicating Engagement Results, follow-up is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Follow-up in Communicating Engagement Results requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D10-Q009",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Monitoring — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing monitoring within Communicating Engagement Results, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective monitoring starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D10-Q010",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Reporting — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for reporting in Communicating Engagement Results is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Communicating Engagement Results.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D10-Q011",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Recommendations — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Communicating Engagement Results, recommendations is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Recommendations in Communicating Engagement Results requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D10-Q012",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Follow-up — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing follow-up within Communicating Engagement Results, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective follow-up starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D10-Q013",
      "itemType": "question",
      "domain": "engagement-communication",
      "topic": "Monitoring — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for monitoring in Communicating Engagement Results is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Communicating Engagement Results.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D11-Q001",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Industry context definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Business Acumen requires that industry context must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Business Acumen integrates industry context with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D11-Q002",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Industry context — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Business Acumen, industry context is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Industry context in Business Acumen requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D11-Q003",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Strategy — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing strategy within Business Acumen, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective strategy starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D11-Q004",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Operations — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for operations in Business Acumen is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Business Acumen.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D11-Q005",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Value drivers — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Business Acumen, value drivers is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Value drivers in Business Acumen requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D11-Q006",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Industry context — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing industry context within Business Acumen, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective industry context starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D11-Q007",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Strategy — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for strategy in Business Acumen is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Business Acumen.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D11-Q008",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Operations — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Business Acumen, operations is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Operations in Business Acumen requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D11-Q009",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Value drivers — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing value drivers within Business Acumen, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective value drivers starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D11-Q010",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Industry context — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for industry context in Business Acumen is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Business Acumen.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D11-Q011",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Strategy — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Business Acumen, strategy is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Strategy in Business Acumen requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D11-Q012",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Operations — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing operations within Business Acumen, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective operations starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D11-Q013",
      "itemType": "question",
      "domain": "business-acumen",
      "topic": "Value drivers — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for value drivers in Business Acumen is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Business Acumen.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D12-Q001",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Access controls definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Information Security requires that access controls must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Information Security integrates access controls with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D12-Q002",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Access controls — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Information Security, access controls is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Access controls in Information Security requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D12-Q003",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Data protection — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing data protection within Information Security, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective data protection starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D12-Q004",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Incident response — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for incident response in Information Security is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Information Security.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D12-Q005",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Security governance — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Information Security, security governance is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Security governance in Information Security requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D12-Q006",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Access controls — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing access controls within Information Security, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective access controls starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D12-Q007",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Data protection — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for data protection in Information Security is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Information Security.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D12-Q008",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Incident response — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Information Security, incident response is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Incident response in Information Security requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D12-Q009",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Security governance — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing security governance within Information Security, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective security governance starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D12-Q010",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Access controls — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for access controls in Information Security is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Information Security.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D12-Q011",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Data protection — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Information Security, data protection is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Data protection in Information Security requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D12-Q012",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Incident response — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing incident response within Information Security, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective incident response starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D12-Q013",
      "itemType": "question",
      "domain": "information-security",
      "topic": "Security governance — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for security governance in Information Security is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Information Security.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D13-Q001",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT general controls definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Information Technology requires that it general controls must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Information Technology integrates it general controls with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D13-Q002",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT general controls — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Information Technology, it general controls is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "IT general controls in Information Technology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D13-Q003",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Change management — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing change management within Information Technology, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective change management starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D13-Q004",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "System development — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for system development in Information Technology is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Information Technology.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D13-Q005",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT audit — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Information Technology, it audit is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "IT audit in Information Technology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D13-Q006",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT general controls — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing it general controls within Information Technology, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective it general controls starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D13-Q007",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Change management — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for change management in Information Technology is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Information Technology.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D13-Q008",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "System development — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Information Technology, system development is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "System development in Information Technology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D13-Q009",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT audit — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing it audit within Information Technology, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective it audit starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D13-Q010",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT general controls — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for it general controls in Information Technology is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Information Technology.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D13-Q011",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "Change management — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Information Technology, change management is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Change management in Information Technology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D13-Q012",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "System development — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing system development within Information Technology, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective system development starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D13-Q013",
      "itemType": "question",
      "domain": "information-technology",
      "topic": "IT audit — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for it audit in Information Technology is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Information Technology.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D14-Q001",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial statements definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Financial Management requires that financial statements must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Financial Management integrates financial statements with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D14-Q002",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial statements — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Financial Management, financial statements is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Financial statements in Financial Management requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D14-Q003",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Budgeting — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing budgeting within Financial Management, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective budgeting starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D14-Q004",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Variance analysis — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for variance analysis in Financial Management is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Financial Management.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D14-Q005",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Accounting controls — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Financial Management, accounting controls is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Accounting controls in Financial Management requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D14-Q006",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial statements — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing financial statements within Financial Management, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective financial statements starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D14-Q007",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Budgeting — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for budgeting in Financial Management is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Financial Management.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D14-Q008",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Variance analysis — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Financial Management, variance analysis is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Variance analysis in Financial Management requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D14-Q009",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Accounting controls — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing accounting controls within Financial Management, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective accounting controls starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D14-Q010",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Financial statements — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for financial statements in Financial Management is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Financial Management.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D14-Q011",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Budgeting — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Financial Management, budgeting is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Budgeting in Financial Management requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D14-Q012",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Variance analysis — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing variance analysis within Financial Management, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective variance analysis starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D14-Q013",
      "itemType": "question",
      "domain": "financial-management",
      "topic": "Accounting controls — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for accounting controls in Financial Management is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Financial Management.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D15-Q001",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "COSO components definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Internal Control Frameworks requires that coso components must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Internal Control Frameworks integrates coso components with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D15-Q002",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "COSO components — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Internal Control Frameworks, coso components is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "COSO components in Internal Control Frameworks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D15-Q003",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Control activities — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing control activities within Internal Control Frameworks, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective control activities starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D15-Q004",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Monitoring — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for monitoring in Internal Control Frameworks is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Internal Control Frameworks.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D15-Q005",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Deficiencies — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Internal Control Frameworks, deficiencies is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Deficiencies in Internal Control Frameworks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D15-Q006",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "COSO components — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing coso components within Internal Control Frameworks, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective coso components starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D15-Q007",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Control activities — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for control activities in Internal Control Frameworks is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Internal Control Frameworks.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D15-Q008",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Monitoring — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Internal Control Frameworks, monitoring is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Monitoring in Internal Control Frameworks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D15-Q009",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Deficiencies — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing deficiencies within Internal Control Frameworks, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective deficiencies starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D15-Q010",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "COSO components — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for coso components in Internal Control Frameworks is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Internal Control Frameworks.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D15-Q011",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Control activities — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Internal Control Frameworks, control activities is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Control activities in Internal Control Frameworks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D15-Q012",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Monitoring — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing monitoring within Internal Control Frameworks, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective monitoring starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D15-Q013",
      "itemType": "question",
      "domain": "internal-control-frameworks",
      "topic": "Deficiencies — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for deficiencies in Internal Control Frameworks is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Internal Control Frameworks.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D16-Q001",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Continuous auditing definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Data Analytics in Auditing requires that continuous auditing must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Data Analytics in Auditing integrates continuous auditing with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D16-Q002",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Continuous auditing — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Data Analytics in Auditing, continuous auditing is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Continuous auditing in Data Analytics in Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D16-Q003",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data mining — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing data mining within Data Analytics in Auditing, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective data mining starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D16-Q004",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Visualization — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for visualization in Data Analytics in Auditing is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Data Analytics in Auditing.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D16-Q005",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Anomaly detection — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Data Analytics in Auditing, anomaly detection is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Anomaly detection in Data Analytics in Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D16-Q006",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Continuous auditing — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing continuous auditing within Data Analytics in Auditing, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective continuous auditing starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D16-Q007",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data mining — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for data mining in Data Analytics in Auditing is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Data Analytics in Auditing.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D16-Q008",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Visualization — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Data Analytics in Auditing, visualization is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Visualization in Data Analytics in Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D16-Q009",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Anomaly detection — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing anomaly detection within Data Analytics in Auditing, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective anomaly detection starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D16-Q010",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Continuous auditing — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for continuous auditing in Data Analytics in Auditing is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Data Analytics in Auditing.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D16-Q011",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Data mining — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Data Analytics in Auditing, data mining is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Data mining in Data Analytics in Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D16-Q012",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Visualization — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing visualization within Data Analytics in Auditing, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective visualization starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D16-Q013",
      "itemType": "question",
      "domain": "data-analytics-auditing",
      "topic": "Anomaly detection — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for anomaly detection in Data Analytics in Auditing is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Data Analytics in Auditing.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D17-Q001",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "IIA Code of Ethics definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Ethics and Professionalism requires that iia code of ethics must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Ethics and Professionalism integrates iia code of ethics with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D17-Q002",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "IIA Code of Ethics — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Ethics and Professionalism, iia code of ethics is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "IIA Code of Ethics in Ethics and Professionalism requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D17-Q003",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Conflicts of interest — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing conflicts of interest within Ethics and Professionalism, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective conflicts of interest starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D17-Q004",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Confidentiality — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for confidentiality in Ethics and Professionalism is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Ethics and Professionalism.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D17-Q005",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Integrity — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Ethics and Professionalism, integrity is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Integrity in Ethics and Professionalism requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D17-Q006",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "IIA Code of Ethics — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing iia code of ethics within Ethics and Professionalism, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective iia code of ethics starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D17-Q007",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Conflicts of interest — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for conflicts of interest in Ethics and Professionalism is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Ethics and Professionalism.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D17-Q008",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Confidentiality — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Ethics and Professionalism, confidentiality is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Confidentiality in Ethics and Professionalism requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D17-Q009",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Integrity — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing integrity within Ethics and Professionalism, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective integrity starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D17-Q010",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "IIA Code of Ethics — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for iia code of ethics in Ethics and Professionalism is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Ethics and Professionalism.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D17-Q011",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Conflicts of interest — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Ethics and Professionalism, conflicts of interest is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Conflicts of interest in Ethics and Professionalism requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D17-Q012",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Confidentiality — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing confidentiality within Ethics and Professionalism, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective confidentiality starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D17-Q013",
      "itemType": "question",
      "domain": "ethics-professionalism",
      "topic": "Integrity — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for integrity in Ethics and Professionalism is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Ethics and Professionalism.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D18-Q001",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Legal requirements definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Regulatory Compliance requires that legal requirements must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Regulatory Compliance integrates legal requirements with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D18-Q002",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Legal requirements — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Regulatory Compliance, legal requirements is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Legal requirements in Regulatory Compliance requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D18-Q003",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Policy compliance — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing policy compliance within Regulatory Compliance, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective policy compliance starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D18-Q004",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory change — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for regulatory change in Regulatory Compliance is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Regulatory Compliance.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D18-Q005",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Sanctions risk — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Regulatory Compliance, sanctions risk is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Sanctions risk in Regulatory Compliance requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D18-Q006",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Legal requirements — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing legal requirements within Regulatory Compliance, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective legal requirements starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D18-Q007",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Policy compliance — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for policy compliance in Regulatory Compliance is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Regulatory Compliance.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D18-Q008",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory change — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Regulatory Compliance, regulatory change is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Regulatory change in Regulatory Compliance requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D18-Q009",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Sanctions risk — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing sanctions risk within Regulatory Compliance, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective sanctions risk starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D18-Q010",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Legal requirements — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for legal requirements in Regulatory Compliance is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Regulatory Compliance.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D18-Q011",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Policy compliance — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Regulatory Compliance, policy compliance is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Policy compliance in Regulatory Compliance requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D18-Q012",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Regulatory change — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing regulatory change within Regulatory Compliance, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective regulatory change starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D18-Q013",
      "itemType": "question",
      "domain": "regulatory-compliance",
      "topic": "Sanctions risk — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for sanctions risk in Regulatory Compliance is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Regulatory Compliance.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D19-Q001",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Inherent risk definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Risk Assessment Methodology requires that inherent risk must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Risk Assessment Methodology integrates inherent risk with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D19-Q002",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Inherent risk — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Risk Assessment Methodology, inherent risk is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Inherent risk in Risk Assessment Methodology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D19-Q003",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Residual risk — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing residual risk within Risk Assessment Methodology, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective residual risk starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D19-Q004",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk registers — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for risk registers in Risk Assessment Methodology is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Risk Assessment Methodology.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D19-Q005",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Heat maps — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Risk Assessment Methodology, heat maps is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Heat maps in Risk Assessment Methodology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D19-Q006",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Inherent risk — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing inherent risk within Risk Assessment Methodology, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective inherent risk starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D19-Q007",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Residual risk — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for residual risk in Risk Assessment Methodology is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Risk Assessment Methodology.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D19-Q008",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk registers — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Risk Assessment Methodology, risk registers is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Risk registers in Risk Assessment Methodology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D19-Q009",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Heat maps — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing heat maps within Risk Assessment Methodology, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective heat maps starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D19-Q010",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Inherent risk — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for inherent risk in Risk Assessment Methodology is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Risk Assessment Methodology.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D19-Q011",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Residual risk — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Risk Assessment Methodology, residual risk is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Residual risk in Risk Assessment Methodology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D19-Q012",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Risk registers — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing risk registers within Risk Assessment Methodology, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective risk registers starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D19-Q013",
      "itemType": "question",
      "domain": "risk-assessment-methodology",
      "topic": "Heat maps — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for heat maps in Risk Assessment Methodology is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Risk Assessment Methodology.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D20-Q001",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Rating scales definition",
      "difficulty": "Easy",
      "stem": "Fill in the blank: Audit Reporting and Follow-Up requires that rating scales must be ____.",
      "choiceA": "supported by sufficient appropriate audit evidence",
      "choiceB": "based solely on management representations",
      "choiceC": "optional when schedules are tight",
      "choiceD": "excluded from the audit charter",
      "correctAnswer": "A",
      "explanation": "Audit Reporting and Follow-Up integrates rating scales with professional standards and evidence requirements.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D20-Q002",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Rating scales — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Audit Reporting and Follow-Up, rating scales is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Rating scales in Audit Reporting and Follow-Up requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D20-Q003",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Management responses — fill-blank 1",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing management responses within Audit Reporting and Follow-Up, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective management responses starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D20-Q004",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Action tracking — fill-blank 1",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for action tracking in Audit Reporting and Follow-Up is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Audit Reporting and Follow-Up.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D20-Q005",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Closure criteria — fill-blank 1",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Audit Reporting and Follow-Up, closure criteria is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Closure criteria in Audit Reporting and Follow-Up requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D20-Q006",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Rating scales — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing rating scales within Audit Reporting and Follow-Up, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective rating scales starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D20-Q007",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Management responses — fill-blank 2",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for management responses in Audit Reporting and Follow-Up is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Audit Reporting and Follow-Up.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D20-Q008",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Action tracking — fill-blank 2",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Audit Reporting and Follow-Up, action tracking is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Action tracking in Audit Reporting and Follow-Up requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D20-Q009",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Closure criteria — fill-blank 2",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing closure criteria within Audit Reporting and Follow-Up, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective closure criteria starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D20-Q010",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Rating scales — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for rating scales in Audit Reporting and Follow-Up is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Audit Reporting and Follow-Up.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D20-Q011",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Management responses — fill-blank 3",
      "difficulty": "Medium",
      "stem": "Fill in the blank: In Audit Reporting and Follow-Up, management responses is best supported by ____.",
      "choiceA": "documented plans aligned with stakeholder needs",
      "choiceB": "undocumented verbal agreements only",
      "choiceC": "skipping change control",
      "choiceD": "ignoring governance requirements",
      "correctAnswer": "A",
      "explanation": "Management responses in Audit Reporting and Follow-Up requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D20-Q012",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Action tracking — fill-blank 3",
      "difficulty": "Hard",
      "stem": "Fill in the blank: When executing action tracking within Audit Reporting and Follow-Up, the team should first ____.",
      "choiceA": "confirm scope baseline and acceptance criteria",
      "choiceB": "begin work without a baseline",
      "choiceC": "defer stakeholder engagement",
      "choiceD": "skip risk identification",
      "correctAnswer": "A",
      "explanation": "Effective action tracking starts with a validated baseline and clear acceptance criteria before execution.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    },
    {
      "packId": "cia",
      "itemId": "CIA-FB-D20-Q013",
      "itemType": "question",
      "domain": "audit-reporting-followup",
      "topic": "Closure criteria — fill-blank 3",
      "difficulty": "Easy",
      "stem": "Fill in the blank: A key performance indicator for closure criteria in Audit Reporting and Follow-Up is ____.",
      "choiceA": "variance against planned targets with trend analysis",
      "choiceB": "activity counts without outcomes",
      "choiceC": "unverified self-reported status",
      "choiceD": "metrics unrelated to objectives",
      "correctAnswer": "A",
      "explanation": "Outcome-oriented metrics with variance analysis support data-driven decisions in Audit Reporting and Follow-Up.",
      "reference": "iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)",
      "reviewStatus": "accepted",
      "reviewerName": "",
      "reviewerRole": "",
      "reviewComments": "",
      "recommendedAction": "",
      "sourceAdequacy": "",
      "technicalAccuracy": "",
      "clarity": "",
      "disposition": ""
    }
  ]
}
