# CIA SME Review Packet

> Production-enabled study pack — update review fields only; do not modify item content in review files without authoring workflow.

Generated: 2026-07-06T13:46:41.070Z

Total items: 1260

---

## CIA-D1-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Foundations of Internal Auditing fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying foundations of internal auditing principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Foundations of Internal Auditing requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Foundations of Internal Auditing risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In foundations of internal auditing, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Foundations of Internal Auditing independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing foundations of internal auditing discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Foundations of Internal Auditing control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to foundations of internal auditing, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Foundations of Internal Auditing reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in foundations of internal auditing should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Foundations of Internal Auditing ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in foundations of internal auditing, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mission — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying mission within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Mission in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Value proposition — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on value proposition in Foundations of Internal Auditing. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Value proposition: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mandatory guidance — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about mandatory guidance in Foundations of Internal Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm mandatory guidance controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Professional framework — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During foundations of internal auditing planning, professional framework is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Professional framework in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mission — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to mission under Foundations of Internal Auditing. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Mission: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Value proposition — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying value proposition within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm value proposition controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mandatory guidance — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on mandatory guidance in Foundations of Internal Auditing. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Mandatory guidance in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Professional framework — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about professional framework in Foundations of Internal Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Professional framework: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mission — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During foundations of internal auditing planning, mission is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm mission controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Value proposition — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to value proposition under Foundations of Internal Auditing. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Value proposition in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mandatory guidance — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying mandatory guidance within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Mandatory guidance: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Professional framework — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on professional framework in Foundations of Internal Auditing. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm professional framework controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mission — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about mission in Foundations of Internal Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Mission in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Value proposition — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During foundations of internal auditing planning, value proposition is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Value proposition: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mandatory guidance — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to mandatory guidance under Foundations of Internal Auditing. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm mandatory guidance controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Professional framework — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying professional framework within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Professional framework in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mission — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on mission in Foundations of Internal Auditing. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Mission: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Value proposition — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about value proposition in Foundations of Internal Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm value proposition controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mandatory guidance — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During foundations of internal auditing planning, mandatory guidance is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Mandatory guidance in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Professional framework — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to professional framework under Foundations of Internal Auditing. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Professional framework: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mission — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying mission within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm mission controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Value proposition — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on value proposition in Foundations of Internal Auditing. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Value proposition in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mandatory guidance — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about mandatory guidance in Foundations of Internal Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Mandatory guidance: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Professional framework — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During foundations of internal auditing planning, professional framework is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm professional framework controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mission — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to mission under Foundations of Internal Auditing. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Mission in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Value proposition — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying value proposition within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Value proposition: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mandatory guidance — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on mandatory guidance in Foundations of Internal Auditing. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm mandatory guidance controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Professional framework — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about professional framework in Foundations of Internal Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Professional framework in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mission — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During foundations of internal auditing planning, mission is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Mission: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Value proposition — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to value proposition under Foundations of Internal Auditing. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm value proposition controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mandatory guidance — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying mandatory guidance within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Mandatory guidance in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Professional framework — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on professional framework in Foundations of Internal Auditing. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Professional framework: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mission — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about mission in Foundations of Internal Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm mission controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Value proposition — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During foundations of internal auditing planning, value proposition is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Value proposition in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mandatory guidance — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to mandatory guidance under Foundations of Internal Auditing. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Mandatory guidance: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Professional framework — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying professional framework within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm professional framework controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mission — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on mission in Foundations of Internal Auditing. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Mission in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Value proposition — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about value proposition in Foundations of Internal Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Value proposition: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mandatory guidance — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During foundations of internal auditing planning, mandatory guidance is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm mandatory guidance controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Professional framework — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to professional framework under Foundations of Internal Auditing. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Professional framework in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mission — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying mission within Foundations of Internal Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Mission: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Value proposition — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on value proposition in Foundations of Internal Auditing. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Foundations of Internal Auditing includes transparent documentation and follow-up to confirm value proposition controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mandatory guidance — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about mandatory guidance in Foundations of Internal Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Mandatory guidance in Foundations of Internal Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D1-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Professional framework — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During foundations of internal auditing planning, professional framework is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Professional framework: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Independence and Objectivity fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying independence and objectivity principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Independence and Objectivity requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Independence and Objectivity risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In independence and objectivity, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Independence and Objectivity independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing independence and objectivity discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Independence and Objectivity control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to independence and objectivity, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Independence and Objectivity reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in independence and objectivity should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Independence and Objectivity ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in independence and objectivity, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Organizational independence — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying organizational independence within Independence and Objectivity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Organizational independence in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Individual objectivity — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on individual objectivity in Independence and Objectivity. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Individual objectivity: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Impairments — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about impairments in Independence and Objectivity is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm impairments controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Disclosure — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During independence and objectivity planning, disclosure is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Disclosure in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Organizational independence — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to organizational independence under Independence and Objectivity. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Organizational independence: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Individual objectivity — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying individual objectivity within Independence and Objectivity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm individual objectivity controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Impairments — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on impairments in Independence and Objectivity. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Impairments in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Disclosure — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about disclosure in Independence and Objectivity is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Disclosure: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Organizational independence — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During independence and objectivity planning, organizational independence is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm organizational independence controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Individual objectivity — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to individual objectivity under Independence and Objectivity. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Individual objectivity in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Impairments — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying impairments within Independence and Objectivity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Impairments: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Disclosure — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on disclosure in Independence and Objectivity. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm disclosure controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Organizational independence — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about organizational independence in Independence and Objectivity is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Organizational independence in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Individual objectivity — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During independence and objectivity planning, individual objectivity is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Individual objectivity: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Impairments — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to impairments under Independence and Objectivity. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm impairments controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Disclosure — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying disclosure within Independence and Objectivity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Disclosure in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Organizational independence — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on organizational independence in Independence and Objectivity. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Organizational independence: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Individual objectivity — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about individual objectivity in Independence and Objectivity is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm individual objectivity controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Impairments — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During independence and objectivity planning, impairments is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Impairments in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Disclosure — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to disclosure under Independence and Objectivity. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Disclosure: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Organizational independence — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying organizational independence within Independence and Objectivity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm organizational independence controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Individual objectivity — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on individual objectivity in Independence and Objectivity. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Individual objectivity in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Impairments — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about impairments in Independence and Objectivity is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Impairments: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Disclosure — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During independence and objectivity planning, disclosure is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm disclosure controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Organizational independence — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to organizational independence under Independence and Objectivity. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Organizational independence in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Individual objectivity — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying individual objectivity within Independence and Objectivity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Individual objectivity: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Impairments — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on impairments in Independence and Objectivity. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm impairments controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Disclosure — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about disclosure in Independence and Objectivity is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Disclosure in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Organizational independence — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During independence and objectivity planning, organizational independence is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Organizational independence: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Individual objectivity — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to individual objectivity under Independence and Objectivity. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm individual objectivity controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Impairments — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying impairments within Independence and Objectivity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Impairments in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Disclosure — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on disclosure in Independence and Objectivity. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Disclosure: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Organizational independence — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about organizational independence in Independence and Objectivity is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm organizational independence controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Individual objectivity — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During independence and objectivity planning, individual objectivity is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Individual objectivity in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Impairments — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to impairments under Independence and Objectivity. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Impairments: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Disclosure — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying disclosure within Independence and Objectivity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm disclosure controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Organizational independence — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on organizational independence in Independence and Objectivity. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Organizational independence in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Individual objectivity — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about individual objectivity in Independence and Objectivity is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Individual objectivity: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Impairments — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During independence and objectivity planning, impairments is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm impairments controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Disclosure — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to disclosure under Independence and Objectivity. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Disclosure in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Organizational independence — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying organizational independence within Independence and Objectivity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Organizational independence: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Individual objectivity — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on individual objectivity in Independence and Objectivity. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Independence and Objectivity includes transparent documentation and follow-up to confirm individual objectivity controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Impairments — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about impairments in Independence and Objectivity is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Impairments in Independence and Objectivity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D2-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Disclosure — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During independence and objectivity planning, disclosure is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Disclosure: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Proficiency and Due Professional Care fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying proficiency and due professional care principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Proficiency and Due Professional Care requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Proficiency and Due Professional Care risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In proficiency and due professional care, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Proficiency and Due Professional Care independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing proficiency and due professional care discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Proficiency and Due Professional Care control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to proficiency and due professional care, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Proficiency and Due Professional Care reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in proficiency and due professional care should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Proficiency and Due Professional Care ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in proficiency and due professional care, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Competency — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying competency within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Competency in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Continuing education — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on continuing education in Proficiency and Due Professional Care. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Continuing education: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Supervision — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about supervision in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm supervision controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Due care — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During proficiency and due professional care planning, due care is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Due care in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Competency — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to competency under Proficiency and Due Professional Care. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Competency: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Continuing education — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying continuing education within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm continuing education controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Supervision — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on supervision in Proficiency and Due Professional Care. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Supervision in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Due care — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about due care in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Due care: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Competency — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During proficiency and due professional care planning, competency is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm competency controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Continuing education — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to continuing education under Proficiency and Due Professional Care. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Continuing education in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Supervision — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying supervision within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Supervision: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Due care — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on due care in Proficiency and Due Professional Care. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm due care controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Competency — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about competency in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Competency in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Continuing education — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During proficiency and due professional care planning, continuing education is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Continuing education: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Supervision — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to supervision under Proficiency and Due Professional Care. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm supervision controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Due care — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying due care within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Due care in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Competency — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on competency in Proficiency and Due Professional Care. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Competency: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Continuing education — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about continuing education in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm continuing education controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Supervision — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During proficiency and due professional care planning, supervision is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Supervision in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Due care — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to due care under Proficiency and Due Professional Care. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Due care: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Competency — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying competency within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm competency controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Continuing education — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on continuing education in Proficiency and Due Professional Care. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Continuing education in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Supervision — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about supervision in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Supervision: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Due care — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During proficiency and due professional care planning, due care is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm due care controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Competency — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to competency under Proficiency and Due Professional Care. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Competency in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Continuing education — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying continuing education within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Continuing education: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Supervision — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on supervision in Proficiency and Due Professional Care. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm supervision controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Due care — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about due care in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Due care in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Competency — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During proficiency and due professional care planning, competency is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Competency: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Continuing education — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to continuing education under Proficiency and Due Professional Care. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm continuing education controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Supervision — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying supervision within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Supervision in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Due care — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on due care in Proficiency and Due Professional Care. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Due care: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Competency — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about competency in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm competency controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Continuing education — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During proficiency and due professional care planning, continuing education is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Continuing education in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Supervision — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to supervision under Proficiency and Due Professional Care. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Supervision: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Due care — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying due care within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm due care controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Competency — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on competency in Proficiency and Due Professional Care. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Competency in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Continuing education — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about continuing education in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Continuing education: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Supervision — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During proficiency and due professional care planning, supervision is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm supervision controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Due care — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to due care under Proficiency and Due Professional Care. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Due care in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Competency — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying competency within Proficiency and Due Professional Care, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Competency: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Continuing education — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on continuing education in Proficiency and Due Professional Care. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Proficiency and Due Professional Care includes transparent documentation and follow-up to confirm continuing education controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Supervision — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about supervision in Proficiency and Due Professional Care is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Supervision in Proficiency and Due Professional Care requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D3-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Due care — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During proficiency and due professional care planning, due care is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Due care: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Quality Assurance and Improvement Program fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying quality assurance and improvement program principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Quality Assurance and Improvement Program requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Quality Assurance and Improvement Program risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In quality assurance and improvement program, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Quality Assurance and Improvement Program independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing quality assurance and improvement program discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Quality Assurance and Improvement Program control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to quality assurance and improvement program, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Quality Assurance and Improvement Program reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in quality assurance and improvement program should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Quality Assurance and Improvement Program ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in quality assurance and improvement program, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Internal assessments — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying internal assessments within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Internal assessments in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** External assessments — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on external assessments in Quality Assurance and Improvement Program. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to External assessments: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** QAIP reporting — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about qaip reporting in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm qaip reporting controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Improvement plans — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During quality assurance and improvement program planning, improvement plans is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Improvement plans in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Internal assessments — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to internal assessments under Quality Assurance and Improvement Program. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Internal assessments: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** External assessments — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying external assessments within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm external assessments controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** QAIP reporting — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on qaip reporting in Quality Assurance and Improvement Program. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

QAIP reporting in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Improvement plans — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about improvement plans in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Improvement plans: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Internal assessments — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During quality assurance and improvement program planning, internal assessments is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm internal assessments controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** External assessments — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to external assessments under Quality Assurance and Improvement Program. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

External assessments in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** QAIP reporting — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying qaip reporting within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to QAIP reporting: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Improvement plans — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on improvement plans in Quality Assurance and Improvement Program. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm improvement plans controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Internal assessments — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about internal assessments in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Internal assessments in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** External assessments — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During quality assurance and improvement program planning, external assessments is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to External assessments: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** QAIP reporting — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to qaip reporting under Quality Assurance and Improvement Program. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm qaip reporting controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Improvement plans — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying improvement plans within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Improvement plans in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Internal assessments — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on internal assessments in Quality Assurance and Improvement Program. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Internal assessments: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** External assessments — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about external assessments in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm external assessments controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** QAIP reporting — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During quality assurance and improvement program planning, qaip reporting is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

QAIP reporting in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Improvement plans — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to improvement plans under Quality Assurance and Improvement Program. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Improvement plans: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Internal assessments — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying internal assessments within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm internal assessments controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** External assessments — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on external assessments in Quality Assurance and Improvement Program. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

External assessments in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** QAIP reporting — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about qaip reporting in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to QAIP reporting: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Improvement plans — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During quality assurance and improvement program planning, improvement plans is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm improvement plans controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Internal assessments — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to internal assessments under Quality Assurance and Improvement Program. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Internal assessments in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** External assessments — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying external assessments within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to External assessments: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** QAIP reporting — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on qaip reporting in Quality Assurance and Improvement Program. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm qaip reporting controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Improvement plans — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about improvement plans in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Improvement plans in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Internal assessments — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During quality assurance and improvement program planning, internal assessments is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Internal assessments: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** External assessments — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to external assessments under Quality Assurance and Improvement Program. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm external assessments controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** QAIP reporting — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying qaip reporting within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

QAIP reporting in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Improvement plans — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on improvement plans in Quality Assurance and Improvement Program. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Improvement plans: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Internal assessments — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about internal assessments in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm internal assessments controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** External assessments — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During quality assurance and improvement program planning, external assessments is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

External assessments in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** QAIP reporting — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to qaip reporting under Quality Assurance and Improvement Program. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to QAIP reporting: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Improvement plans — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying improvement plans within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm improvement plans controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Internal assessments — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on internal assessments in Quality Assurance and Improvement Program. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Internal assessments in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** External assessments — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about external assessments in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to External assessments: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** QAIP reporting — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During quality assurance and improvement program planning, qaip reporting is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm qaip reporting controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Improvement plans — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to improvement plans under Quality Assurance and Improvement Program. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Improvement plans in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Internal assessments — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying internal assessments within Quality Assurance and Improvement Program, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Internal assessments: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** External assessments — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on external assessments in Quality Assurance and Improvement Program. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Quality Assurance and Improvement Program includes transparent documentation and follow-up to confirm external assessments controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** QAIP reporting — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about qaip reporting in Quality Assurance and Improvement Program is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

QAIP reporting in Quality Assurance and Improvement Program requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D4-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Improvement plans — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During quality assurance and improvement program planning, improvement plans is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Improvement plans: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Governance, Risk Management, and Control fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying governance, risk management, and control principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Governance, Risk Management, and Control requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Governance, Risk Management, and Control risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In governance, risk management, and control, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Governance, Risk Management, and Control independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing governance, risk management, and control discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Governance, Risk Management, and Control control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to governance, risk management, and control, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Governance, Risk Management, and Control reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in governance, risk management, and control should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Governance, Risk Management, and Control ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in governance, risk management, and control, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Three lines model — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying three lines model within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Three lines model in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Risk appetite — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on risk appetite in Governance, Risk Management, and Control. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Risk appetite: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Control environment — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about control environment in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm control environment controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Board oversight — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During governance, risk management, and control planning, board oversight is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Board oversight in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Three lines model — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to three lines model under Governance, Risk Management, and Control. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Three lines model: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Risk appetite — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying risk appetite within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm risk appetite controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Control environment — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on control environment in Governance, Risk Management, and Control. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Control environment in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Board oversight — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about board oversight in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Board oversight: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Three lines model — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During governance, risk management, and control planning, three lines model is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm three lines model controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Risk appetite — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to risk appetite under Governance, Risk Management, and Control. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Risk appetite in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Control environment — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying control environment within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Control environment: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Board oversight — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on board oversight in Governance, Risk Management, and Control. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm board oversight controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Three lines model — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about three lines model in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Three lines model in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Risk appetite — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During governance, risk management, and control planning, risk appetite is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Risk appetite: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Control environment — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to control environment under Governance, Risk Management, and Control. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm control environment controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Board oversight — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying board oversight within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Board oversight in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Three lines model — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on three lines model in Governance, Risk Management, and Control. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Three lines model: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Risk appetite — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about risk appetite in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm risk appetite controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Control environment — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During governance, risk management, and control planning, control environment is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Control environment in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Board oversight — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to board oversight under Governance, Risk Management, and Control. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Board oversight: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Three lines model — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying three lines model within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm three lines model controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Risk appetite — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on risk appetite in Governance, Risk Management, and Control. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Risk appetite in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Control environment — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about control environment in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Control environment: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Board oversight — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During governance, risk management, and control planning, board oversight is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm board oversight controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Three lines model — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to three lines model under Governance, Risk Management, and Control. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Three lines model in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Risk appetite — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying risk appetite within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Risk appetite: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Control environment — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on control environment in Governance, Risk Management, and Control. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm control environment controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Board oversight — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about board oversight in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Board oversight in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Three lines model — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During governance, risk management, and control planning, three lines model is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Three lines model: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Risk appetite — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to risk appetite under Governance, Risk Management, and Control. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm risk appetite controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Control environment — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying control environment within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Control environment in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Board oversight — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on board oversight in Governance, Risk Management, and Control. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Board oversight: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Three lines model — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about three lines model in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm three lines model controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Risk appetite — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During governance, risk management, and control planning, risk appetite is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Risk appetite in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Control environment — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to control environment under Governance, Risk Management, and Control. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Control environment: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Board oversight — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying board oversight within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm board oversight controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Three lines model — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on three lines model in Governance, Risk Management, and Control. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Three lines model in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Risk appetite — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about risk appetite in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Risk appetite: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Control environment — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During governance, risk management, and control planning, control environment is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm control environment controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Board oversight — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to board oversight under Governance, Risk Management, and Control. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Board oversight in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Three lines model — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying three lines model within Governance, Risk Management, and Control, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Three lines model: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Risk appetite — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on risk appetite in Governance, Risk Management, and Control. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Governance, Risk Management, and Control includes transparent documentation and follow-up to confirm risk appetite controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Control environment — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about control environment in Governance, Risk Management, and Control is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Control environment in Governance, Risk Management, and Control requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D5-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Board oversight — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During governance, risk management, and control planning, board oversight is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Board oversight: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud Risks fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying fraud risks principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Fraud Risks requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud Risks risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In fraud risks, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud Risks independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing fraud risks discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud Risks control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to fraud risks, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud Risks reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in fraud risks should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud Risks ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in fraud risks, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud indicators — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying fraud indicators within Fraud Risks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Fraud indicators in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Red flags — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on red flags in Fraud Risks. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Red flags: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Investigation boundaries — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about investigation boundaries in Fraud Risks is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm investigation boundaries controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Reporting — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During fraud risks planning, reporting is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Reporting in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud indicators — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to fraud indicators under Fraud Risks. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Fraud indicators: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Red flags — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying red flags within Fraud Risks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm red flags controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Investigation boundaries — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on investigation boundaries in Fraud Risks. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Investigation boundaries in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Reporting — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about reporting in Fraud Risks is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud indicators — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During fraud risks planning, fraud indicators is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm fraud indicators controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Red flags — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to red flags under Fraud Risks. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Red flags in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Investigation boundaries — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying investigation boundaries within Fraud Risks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Investigation boundaries: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Reporting — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on reporting in Fraud Risks. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm reporting controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud indicators — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about fraud indicators in Fraud Risks is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Fraud indicators in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Red flags — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During fraud risks planning, red flags is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Red flags: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Investigation boundaries — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to investigation boundaries under Fraud Risks. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm investigation boundaries controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Reporting — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying reporting within Fraud Risks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Reporting in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud indicators — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on fraud indicators in Fraud Risks. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Fraud indicators: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Red flags — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about red flags in Fraud Risks is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm red flags controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Investigation boundaries — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During fraud risks planning, investigation boundaries is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Investigation boundaries in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Reporting — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to reporting under Fraud Risks. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud indicators — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying fraud indicators within Fraud Risks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm fraud indicators controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Red flags — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on red flags in Fraud Risks. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Red flags in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Investigation boundaries — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about investigation boundaries in Fraud Risks is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Investigation boundaries: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Reporting — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During fraud risks planning, reporting is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm reporting controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud indicators — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to fraud indicators under Fraud Risks. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Fraud indicators in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Red flags — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying red flags within Fraud Risks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Red flags: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Investigation boundaries — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on investigation boundaries in Fraud Risks. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm investigation boundaries controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Reporting — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about reporting in Fraud Risks is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Reporting in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud indicators — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During fraud risks planning, fraud indicators is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Fraud indicators: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Red flags — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to red flags under Fraud Risks. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm red flags controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Investigation boundaries — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying investigation boundaries within Fraud Risks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Investigation boundaries in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Reporting — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on reporting in Fraud Risks. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud indicators — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about fraud indicators in Fraud Risks is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm fraud indicators controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Red flags — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During fraud risks planning, red flags is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Red flags in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Investigation boundaries — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to investigation boundaries under Fraud Risks. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Investigation boundaries: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Reporting — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying reporting within Fraud Risks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm reporting controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud indicators — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on fraud indicators in Fraud Risks. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Fraud indicators in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Red flags — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about red flags in Fraud Risks is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Red flags: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Investigation boundaries — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During fraud risks planning, investigation boundaries is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm investigation boundaries controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Reporting — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to reporting under Fraud Risks. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Reporting in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud indicators — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying fraud indicators within Fraud Risks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Fraud indicators: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Red flags — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on red flags in Fraud Risks. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Fraud Risks includes transparent documentation and follow-up to confirm red flags controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Investigation boundaries — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about investigation boundaries in Fraud Risks is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Investigation boundaries in Fraud Risks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D6-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Reporting — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During fraud risks planning, reporting is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Managing the Internal Audit Activity fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying managing the internal audit activity principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Managing the Internal Audit Activity requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Managing the Internal Audit Activity risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In managing the internal audit activity, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Managing the Internal Audit Activity independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing managing the internal audit activity discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Managing the Internal Audit Activity control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to managing the internal audit activity, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Managing the Internal Audit Activity reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in managing the internal audit activity should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Managing the Internal Audit Activity ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in managing the internal audit activity, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Charter — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying charter within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Charter in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Resource planning — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on resource planning in Managing the Internal Audit Activity. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Resource planning: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Policies — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about policies in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm policies controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Performance metrics — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During managing the internal audit activity planning, performance metrics is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Performance metrics in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Charter — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to charter under Managing the Internal Audit Activity. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Charter: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Resource planning — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying resource planning within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm resource planning controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Policies — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on policies in Managing the Internal Audit Activity. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Policies in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Performance metrics — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about performance metrics in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Performance metrics: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Charter — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During managing the internal audit activity planning, charter is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm charter controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Resource planning — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to resource planning under Managing the Internal Audit Activity. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Resource planning in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Policies — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying policies within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Policies: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Performance metrics — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on performance metrics in Managing the Internal Audit Activity. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm performance metrics controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Charter — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about charter in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Charter in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Resource planning — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During managing the internal audit activity planning, resource planning is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Resource planning: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Policies — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to policies under Managing the Internal Audit Activity. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm policies controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Performance metrics — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying performance metrics within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Performance metrics in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Charter — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on charter in Managing the Internal Audit Activity. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Charter: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Resource planning — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about resource planning in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm resource planning controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Policies — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During managing the internal audit activity planning, policies is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Policies in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Performance metrics — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to performance metrics under Managing the Internal Audit Activity. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Performance metrics: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Charter — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying charter within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm charter controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Resource planning — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on resource planning in Managing the Internal Audit Activity. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Resource planning in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Policies — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about policies in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Policies: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Performance metrics — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During managing the internal audit activity planning, performance metrics is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm performance metrics controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Charter — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to charter under Managing the Internal Audit Activity. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Charter in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Resource planning — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying resource planning within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Resource planning: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Policies — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on policies in Managing the Internal Audit Activity. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm policies controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Performance metrics — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about performance metrics in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Performance metrics in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Charter — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During managing the internal audit activity planning, charter is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Charter: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Resource planning — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to resource planning under Managing the Internal Audit Activity. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm resource planning controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Policies — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying policies within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Policies in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Performance metrics — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on performance metrics in Managing the Internal Audit Activity. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Performance metrics: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Charter — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about charter in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm charter controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Resource planning — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During managing the internal audit activity planning, resource planning is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Resource planning in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Policies — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to policies under Managing the Internal Audit Activity. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Policies: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Performance metrics — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying performance metrics within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm performance metrics controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Charter — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on charter in Managing the Internal Audit Activity. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Charter in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Resource planning — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about resource planning in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Resource planning: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Policies — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During managing the internal audit activity planning, policies is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm policies controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Performance metrics — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to performance metrics under Managing the Internal Audit Activity. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Performance metrics in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Charter — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying charter within Managing the Internal Audit Activity, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Charter: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Resource planning — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on resource planning in Managing the Internal Audit Activity. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Managing the Internal Audit Activity includes transparent documentation and follow-up to confirm resource planning controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Policies — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about policies in Managing the Internal Audit Activity is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Policies in Managing the Internal Audit Activity requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D7-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Performance metrics — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During managing the internal audit activity planning, performance metrics is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Performance metrics: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Engagement Planning fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying engagement planning principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Engagement Planning requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Engagement Planning risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In engagement planning, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Engagement Planning independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing engagement planning discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Engagement Planning control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to engagement planning, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Engagement Planning reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in engagement planning should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Engagement Planning ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in engagement planning, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Risk-based planning — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying risk-based planning within Engagement Planning, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Risk-based planning in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Scope — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on scope in Engagement Planning. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Scope: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Objectives — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about objectives in Engagement Planning is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm objectives controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Work programs — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During engagement planning planning, work programs is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Work programs in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Risk-based planning — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to risk-based planning under Engagement Planning. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Risk-based planning: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Scope — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying scope within Engagement Planning, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm scope controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Objectives — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on objectives in Engagement Planning. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Objectives in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Work programs — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about work programs in Engagement Planning is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Work programs: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Risk-based planning — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During engagement planning planning, risk-based planning is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm risk-based planning controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Scope — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to scope under Engagement Planning. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Scope in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Objectives — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying objectives within Engagement Planning, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Objectives: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Work programs — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on work programs in Engagement Planning. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm work programs controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Risk-based planning — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about risk-based planning in Engagement Planning is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Risk-based planning in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Scope — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During engagement planning planning, scope is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Scope: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Objectives — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to objectives under Engagement Planning. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm objectives controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Work programs — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying work programs within Engagement Planning, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Work programs in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Risk-based planning — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on risk-based planning in Engagement Planning. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Risk-based planning: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Scope — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about scope in Engagement Planning is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm scope controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Objectives — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During engagement planning planning, objectives is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Objectives in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Work programs — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to work programs under Engagement Planning. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Work programs: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Risk-based planning — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying risk-based planning within Engagement Planning, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm risk-based planning controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Scope — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on scope in Engagement Planning. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Scope in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Objectives — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about objectives in Engagement Planning is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Objectives: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Work programs — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During engagement planning planning, work programs is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm work programs controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Risk-based planning — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to risk-based planning under Engagement Planning. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Risk-based planning in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Scope — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying scope within Engagement Planning, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Scope: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Objectives — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on objectives in Engagement Planning. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm objectives controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Work programs — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about work programs in Engagement Planning is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Work programs in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Risk-based planning — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During engagement planning planning, risk-based planning is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Risk-based planning: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Scope — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to scope under Engagement Planning. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm scope controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Objectives — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying objectives within Engagement Planning, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Objectives in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Work programs — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on work programs in Engagement Planning. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Work programs: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Risk-based planning — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about risk-based planning in Engagement Planning is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm risk-based planning controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Scope — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During engagement planning planning, scope is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Scope in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Objectives — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to objectives under Engagement Planning. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Objectives: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Work programs — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying work programs within Engagement Planning, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm work programs controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Risk-based planning — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on risk-based planning in Engagement Planning. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Risk-based planning in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Scope — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about scope in Engagement Planning is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Scope: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Objectives — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During engagement planning planning, objectives is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm objectives controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Work programs — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to work programs under Engagement Planning. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Work programs in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Risk-based planning — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying risk-based planning within Engagement Planning, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Risk-based planning: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Scope — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on scope in Engagement Planning. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Engagement Planning includes transparent documentation and follow-up to confirm scope controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Objectives — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about objectives in Engagement Planning is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Objectives in Engagement Planning requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D8-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Work programs — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During engagement planning planning, work programs is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Work programs: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Performing the Engagement fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying performing the engagement principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Performing the Engagement requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Performing the Engagement risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In performing the engagement, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Performing the Engagement independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing performing the engagement discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Performing the Engagement control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to performing the engagement, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Performing the Engagement reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in performing the engagement should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Performing the Engagement ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in performing the engagement, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Evidence gathering — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying evidence gathering within Performing the Engagement, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Evidence gathering in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Sampling — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on sampling in Performing the Engagement. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Sampling: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Analysis — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about analysis in Performing the Engagement is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm analysis controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Documentation — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During performing the engagement planning, documentation is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Documentation in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Evidence gathering — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to evidence gathering under Performing the Engagement. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Evidence gathering: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Sampling — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying sampling within Performing the Engagement, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm sampling controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Analysis — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on analysis in Performing the Engagement. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Analysis in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Documentation — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about documentation in Performing the Engagement is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Documentation: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Evidence gathering — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During performing the engagement planning, evidence gathering is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm evidence gathering controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Sampling — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to sampling under Performing the Engagement. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Sampling in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Analysis — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying analysis within Performing the Engagement, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Analysis: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Documentation — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on documentation in Performing the Engagement. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm documentation controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Evidence gathering — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about evidence gathering in Performing the Engagement is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Evidence gathering in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Sampling — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During performing the engagement planning, sampling is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Sampling: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Analysis — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to analysis under Performing the Engagement. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm analysis controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Documentation — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying documentation within Performing the Engagement, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Documentation in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Evidence gathering — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on evidence gathering in Performing the Engagement. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Evidence gathering: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Sampling — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about sampling in Performing the Engagement is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm sampling controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Analysis — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During performing the engagement planning, analysis is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Analysis in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Documentation — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to documentation under Performing the Engagement. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Documentation: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Evidence gathering — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying evidence gathering within Performing the Engagement, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm evidence gathering controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Sampling — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on sampling in Performing the Engagement. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Sampling in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Analysis — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about analysis in Performing the Engagement is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Analysis: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Documentation — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During performing the engagement planning, documentation is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm documentation controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Evidence gathering — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to evidence gathering under Performing the Engagement. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Evidence gathering in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Sampling — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying sampling within Performing the Engagement, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Sampling: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Analysis — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on analysis in Performing the Engagement. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm analysis controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Documentation — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about documentation in Performing the Engagement is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Documentation in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Evidence gathering — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During performing the engagement planning, evidence gathering is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Evidence gathering: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Sampling — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to sampling under Performing the Engagement. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm sampling controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Analysis — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying analysis within Performing the Engagement, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Analysis in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Documentation — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on documentation in Performing the Engagement. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Documentation: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Evidence gathering — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about evidence gathering in Performing the Engagement is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm evidence gathering controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Sampling — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During performing the engagement planning, sampling is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Sampling in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Analysis — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to analysis under Performing the Engagement. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Analysis: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Documentation — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying documentation within Performing the Engagement, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm documentation controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Evidence gathering — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on evidence gathering in Performing the Engagement. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Evidence gathering in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Sampling — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about sampling in Performing the Engagement is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Sampling: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Analysis — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During performing the engagement planning, analysis is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm analysis controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Documentation — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to documentation under Performing the Engagement. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Documentation in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Evidence gathering — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying evidence gathering within Performing the Engagement, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Evidence gathering: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Sampling — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on sampling in Performing the Engagement. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Performing the Engagement includes transparent documentation and follow-up to confirm sampling controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Analysis — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about analysis in Performing the Engagement is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Analysis in Performing the Engagement requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D9-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Documentation — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During performing the engagement planning, documentation is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Documentation: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Communicating Engagement Results fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying communicating engagement results principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Communicating Engagement Results requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Communicating Engagement Results risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In communicating engagement results, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Communicating Engagement Results independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing communicating engagement results discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Communicating Engagement Results control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to communicating engagement results, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Communicating Engagement Results reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in communicating engagement results should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Communicating Engagement Results ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in communicating engagement results, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Reporting — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying reporting within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Reporting in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Recommendations — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on recommendations in Communicating Engagement Results. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Recommendations: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Follow-up — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about follow-up in Communicating Engagement Results is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm follow-up controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Monitoring — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During communicating engagement results planning, monitoring is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Monitoring in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Reporting — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to reporting under Communicating Engagement Results. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Recommendations — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying recommendations within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm recommendations controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Follow-up — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on follow-up in Communicating Engagement Results. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Follow-up in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Monitoring — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about monitoring in Communicating Engagement Results is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Monitoring: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Reporting — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During communicating engagement results planning, reporting is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm reporting controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Recommendations — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to recommendations under Communicating Engagement Results. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Recommendations in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Follow-up — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying follow-up within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Follow-up: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Monitoring — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on monitoring in Communicating Engagement Results. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm monitoring controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Reporting — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about reporting in Communicating Engagement Results is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Reporting in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Recommendations — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During communicating engagement results planning, recommendations is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Recommendations: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Follow-up — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to follow-up under Communicating Engagement Results. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm follow-up controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Monitoring — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying monitoring within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Monitoring in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Reporting — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on reporting in Communicating Engagement Results. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Recommendations — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about recommendations in Communicating Engagement Results is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm recommendations controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Follow-up — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During communicating engagement results planning, follow-up is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Follow-up in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Monitoring — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to monitoring under Communicating Engagement Results. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Monitoring: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Reporting — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying reporting within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm reporting controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Recommendations — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on recommendations in Communicating Engagement Results. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Recommendations in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Follow-up — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about follow-up in Communicating Engagement Results is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Follow-up: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Monitoring — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During communicating engagement results planning, monitoring is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm monitoring controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Reporting — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to reporting under Communicating Engagement Results. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Reporting in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Recommendations — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying recommendations within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Recommendations: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Follow-up — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on follow-up in Communicating Engagement Results. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm follow-up controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Monitoring — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about monitoring in Communicating Engagement Results is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Monitoring in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Reporting — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During communicating engagement results planning, reporting is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Recommendations — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to recommendations under Communicating Engagement Results. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm recommendations controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Follow-up — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying follow-up within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Follow-up in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Monitoring — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on monitoring in Communicating Engagement Results. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Monitoring: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Reporting — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about reporting in Communicating Engagement Results is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm reporting controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Recommendations — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During communicating engagement results planning, recommendations is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Recommendations in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Follow-up — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to follow-up under Communicating Engagement Results. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Follow-up: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Monitoring — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying monitoring within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm monitoring controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Reporting — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on reporting in Communicating Engagement Results. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Reporting in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Recommendations — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about recommendations in Communicating Engagement Results is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Recommendations: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Follow-up — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During communicating engagement results planning, follow-up is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm follow-up controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Monitoring — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to monitoring under Communicating Engagement Results. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Monitoring in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Reporting — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying reporting within Communicating Engagement Results, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Reporting: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Recommendations — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on recommendations in Communicating Engagement Results. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Communicating Engagement Results includes transparent documentation and follow-up to confirm recommendations controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Follow-up — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about follow-up in Communicating Engagement Results is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Follow-up in Communicating Engagement Results requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D10-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Monitoring — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During communicating engagement results planning, monitoring is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Monitoring: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Business Acumen fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying business acumen principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Business Acumen requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Business Acumen risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In business acumen, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Business Acumen independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing business acumen discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Business Acumen control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to business acumen, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Business Acumen reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in business acumen should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Business Acumen ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in business acumen, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Industry context — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying industry context within Business Acumen, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Industry context in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Strategy — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on strategy in Business Acumen. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Strategy: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Operations — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about operations in Business Acumen is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Business Acumen includes transparent documentation and follow-up to confirm operations controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Value drivers — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During business acumen planning, value drivers is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Value drivers in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Industry context — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to industry context under Business Acumen. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Industry context: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Strategy — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying strategy within Business Acumen, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Business Acumen includes transparent documentation and follow-up to confirm strategy controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Operations — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on operations in Business Acumen. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Operations in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Value drivers — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about value drivers in Business Acumen is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Value drivers: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Industry context — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During business acumen planning, industry context is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Business Acumen includes transparent documentation and follow-up to confirm industry context controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Strategy — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to strategy under Business Acumen. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Strategy in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Operations — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying operations within Business Acumen, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Operations: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Value drivers — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on value drivers in Business Acumen. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Business Acumen includes transparent documentation and follow-up to confirm value drivers controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Industry context — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about industry context in Business Acumen is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Industry context in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Strategy — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During business acumen planning, strategy is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Strategy: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Operations — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to operations under Business Acumen. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Business Acumen includes transparent documentation and follow-up to confirm operations controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Value drivers — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying value drivers within Business Acumen, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Value drivers in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Industry context — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on industry context in Business Acumen. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Industry context: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Strategy — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about strategy in Business Acumen is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Business Acumen includes transparent documentation and follow-up to confirm strategy controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Operations — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During business acumen planning, operations is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Operations in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Value drivers — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to value drivers under Business Acumen. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Value drivers: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Industry context — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying industry context within Business Acumen, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Business Acumen includes transparent documentation and follow-up to confirm industry context controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Strategy — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on strategy in Business Acumen. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Strategy in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Operations — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about operations in Business Acumen is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Operations: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Value drivers — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During business acumen planning, value drivers is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Business Acumen includes transparent documentation and follow-up to confirm value drivers controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Industry context — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to industry context under Business Acumen. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Industry context in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Strategy — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying strategy within Business Acumen, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Strategy: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Operations — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on operations in Business Acumen. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Business Acumen includes transparent documentation and follow-up to confirm operations controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Value drivers — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about value drivers in Business Acumen is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Value drivers in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Industry context — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During business acumen planning, industry context is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Industry context: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Strategy — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to strategy under Business Acumen. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Business Acumen includes transparent documentation and follow-up to confirm strategy controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Operations — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying operations within Business Acumen, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Operations in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Value drivers — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on value drivers in Business Acumen. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Value drivers: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Industry context — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about industry context in Business Acumen is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Business Acumen includes transparent documentation and follow-up to confirm industry context controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Strategy — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During business acumen planning, strategy is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Strategy in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Operations — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to operations under Business Acumen. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Operations: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Value drivers — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying value drivers within Business Acumen, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Business Acumen includes transparent documentation and follow-up to confirm value drivers controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Industry context — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on industry context in Business Acumen. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Industry context in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Strategy — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about strategy in Business Acumen is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Strategy: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Operations — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During business acumen planning, operations is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Business Acumen includes transparent documentation and follow-up to confirm operations controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Value drivers — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to value drivers under Business Acumen. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Value drivers in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Industry context — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying industry context within Business Acumen, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Industry context: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Strategy — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on strategy in Business Acumen. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Business Acumen includes transparent documentation and follow-up to confirm strategy controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Operations — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about operations in Business Acumen is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Operations in Business Acumen requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D11-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Value drivers — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During business acumen planning, value drivers is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Value drivers: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Information Security fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying information security principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Information Security requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Information Security risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In information security, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Information Security independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing information security discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Information Security control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to information security, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Information Security reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in information security should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Information Security ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in information security, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Access controls — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying access controls within Information Security, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Access controls in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Data protection — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on data protection in Information Security. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Data protection: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Incident response — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about incident response in Information Security is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Security includes transparent documentation and follow-up to confirm incident response controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Security governance — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During information security planning, security governance is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Security governance in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Access controls — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to access controls under Information Security. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Access controls: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Data protection — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying data protection within Information Security, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Security includes transparent documentation and follow-up to confirm data protection controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Incident response — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on incident response in Information Security. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Incident response in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Security governance — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about security governance in Information Security is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Security governance: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Access controls — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During information security planning, access controls is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Security includes transparent documentation and follow-up to confirm access controls controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Data protection — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to data protection under Information Security. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Data protection in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Incident response — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying incident response within Information Security, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Incident response: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Security governance — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on security governance in Information Security. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Security includes transparent documentation and follow-up to confirm security governance controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Access controls — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about access controls in Information Security is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Access controls in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Data protection — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During information security planning, data protection is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Data protection: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Incident response — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to incident response under Information Security. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Security includes transparent documentation and follow-up to confirm incident response controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Security governance — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying security governance within Information Security, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Security governance in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Access controls — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on access controls in Information Security. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Access controls: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Data protection — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about data protection in Information Security is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Security includes transparent documentation and follow-up to confirm data protection controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Incident response — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During information security planning, incident response is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Incident response in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Security governance — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to security governance under Information Security. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Security governance: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Access controls — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying access controls within Information Security, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Security includes transparent documentation and follow-up to confirm access controls controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Data protection — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on data protection in Information Security. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Data protection in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Incident response — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about incident response in Information Security is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Incident response: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Security governance — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During information security planning, security governance is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Security includes transparent documentation and follow-up to confirm security governance controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Access controls — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to access controls under Information Security. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Access controls in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Data protection — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying data protection within Information Security, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Data protection: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Incident response — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on incident response in Information Security. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Security includes transparent documentation and follow-up to confirm incident response controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Security governance — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about security governance in Information Security is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Security governance in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Access controls — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During information security planning, access controls is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Access controls: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Data protection — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to data protection under Information Security. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Security includes transparent documentation and follow-up to confirm data protection controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Incident response — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying incident response within Information Security, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Incident response in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Security governance — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on security governance in Information Security. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Security governance: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Access controls — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about access controls in Information Security is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Security includes transparent documentation and follow-up to confirm access controls controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Data protection — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During information security planning, data protection is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Data protection in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Incident response — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to incident response under Information Security. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Incident response: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Security governance — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying security governance within Information Security, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Security includes transparent documentation and follow-up to confirm security governance controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Access controls — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on access controls in Information Security. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Access controls in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Data protection — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about data protection in Information Security is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Data protection: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Incident response — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During information security planning, incident response is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Security includes transparent documentation and follow-up to confirm incident response controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Security governance — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to security governance under Information Security. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Security governance in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Access controls — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying access controls within Information Security, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Access controls: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Data protection — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on data protection in Information Security. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Security includes transparent documentation and follow-up to confirm data protection controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Incident response — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about incident response in Information Security is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Incident response in Information Security requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D12-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Security governance — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During information security planning, security governance is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Security governance: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Information Technology fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying information technology principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Information Technology requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Information Technology risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In information technology, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Information Technology independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing information technology discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Information Technology control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to information technology, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Information Technology reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in information technology should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Information Technology ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in information technology, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT general controls — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying it general controls within Information Technology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

IT general controls in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Change management — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on change management in Information Technology. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Change management: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** System development — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about system development in Information Technology is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Technology includes transparent documentation and follow-up to confirm system development controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT audit — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During information technology planning, it audit is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

IT audit in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT general controls — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to it general controls under Information Technology. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to IT general controls: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Change management — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying change management within Information Technology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Technology includes transparent documentation and follow-up to confirm change management controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** System development — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on system development in Information Technology. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

System development in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT audit — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about it audit in Information Technology is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to IT audit: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT general controls — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During information technology planning, it general controls is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Technology includes transparent documentation and follow-up to confirm it general controls controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Change management — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to change management under Information Technology. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Change management in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** System development — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying system development within Information Technology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to System development: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT audit — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on it audit in Information Technology. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Technology includes transparent documentation and follow-up to confirm it audit controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT general controls — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about it general controls in Information Technology is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

IT general controls in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Change management — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During information technology planning, change management is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Change management: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** System development — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to system development under Information Technology. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Technology includes transparent documentation and follow-up to confirm system development controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT audit — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying it audit within Information Technology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

IT audit in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT general controls — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on it general controls in Information Technology. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to IT general controls: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Change management — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about change management in Information Technology is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Technology includes transparent documentation and follow-up to confirm change management controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** System development — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During information technology planning, system development is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

System development in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT audit — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to it audit under Information Technology. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to IT audit: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT general controls — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying it general controls within Information Technology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Technology includes transparent documentation and follow-up to confirm it general controls controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Change management — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on change management in Information Technology. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Change management in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** System development — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about system development in Information Technology is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to System development: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT audit — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During information technology planning, it audit is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Technology includes transparent documentation and follow-up to confirm it audit controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT general controls — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to it general controls under Information Technology. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

IT general controls in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Change management — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying change management within Information Technology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Change management: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** System development — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on system development in Information Technology. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Technology includes transparent documentation and follow-up to confirm system development controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT audit — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about it audit in Information Technology is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

IT audit in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT general controls — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During information technology planning, it general controls is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to IT general controls: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Change management — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to change management under Information Technology. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Technology includes transparent documentation and follow-up to confirm change management controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** System development — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying system development within Information Technology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

System development in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT audit — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on it audit in Information Technology. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to IT audit: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT general controls — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about it general controls in Information Technology is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Technology includes transparent documentation and follow-up to confirm it general controls controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Change management — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During information technology planning, change management is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Change management in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** System development — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to system development under Information Technology. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to System development: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT audit — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying it audit within Information Technology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Technology includes transparent documentation and follow-up to confirm it audit controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT general controls — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on it general controls in Information Technology. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

IT general controls in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Change management — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about change management in Information Technology is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Change management: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** System development — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During information technology planning, system development is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Technology includes transparent documentation and follow-up to confirm system development controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT audit — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to it audit under Information Technology. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

IT audit in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT general controls — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying it general controls within Information Technology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to IT general controls: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Change management — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on change management in Information Technology. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Information Technology includes transparent documentation and follow-up to confirm change management controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** System development — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about system development in Information Technology is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

System development in Information Technology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D13-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT audit — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During information technology planning, it audit is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to IT audit: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial Management fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying financial management principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Financial Management requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial Management risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In financial management, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial Management independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing financial management discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial Management control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to financial management, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial Management reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in financial management should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial Management ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in financial management, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial statements — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying financial statements within Financial Management, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Financial statements in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Budgeting — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on budgeting in Financial Management. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Budgeting: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Variance analysis — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about variance analysis in Financial Management is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Financial Management includes transparent documentation and follow-up to confirm variance analysis controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Accounting controls — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During financial management planning, accounting controls is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Accounting controls in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial statements — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to financial statements under Financial Management. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Financial statements: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Budgeting — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying budgeting within Financial Management, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Financial Management includes transparent documentation and follow-up to confirm budgeting controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Variance analysis — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on variance analysis in Financial Management. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Variance analysis in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Accounting controls — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about accounting controls in Financial Management is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Accounting controls: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial statements — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During financial management planning, financial statements is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Financial Management includes transparent documentation and follow-up to confirm financial statements controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Budgeting — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to budgeting under Financial Management. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Budgeting in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Variance analysis — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying variance analysis within Financial Management, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Variance analysis: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Accounting controls — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on accounting controls in Financial Management. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Financial Management includes transparent documentation and follow-up to confirm accounting controls controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial statements — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about financial statements in Financial Management is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Financial statements in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Budgeting — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During financial management planning, budgeting is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Budgeting: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Variance analysis — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to variance analysis under Financial Management. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Financial Management includes transparent documentation and follow-up to confirm variance analysis controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Accounting controls — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying accounting controls within Financial Management, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Accounting controls in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial statements — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on financial statements in Financial Management. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Financial statements: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Budgeting — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about budgeting in Financial Management is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Financial Management includes transparent documentation and follow-up to confirm budgeting controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Variance analysis — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During financial management planning, variance analysis is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Variance analysis in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Accounting controls — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to accounting controls under Financial Management. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Accounting controls: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial statements — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying financial statements within Financial Management, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Financial Management includes transparent documentation and follow-up to confirm financial statements controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Budgeting — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on budgeting in Financial Management. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Budgeting in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Variance analysis — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about variance analysis in Financial Management is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Variance analysis: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Accounting controls — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During financial management planning, accounting controls is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Financial Management includes transparent documentation and follow-up to confirm accounting controls controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial statements — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to financial statements under Financial Management. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Financial statements in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Budgeting — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying budgeting within Financial Management, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Budgeting: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Variance analysis — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on variance analysis in Financial Management. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Financial Management includes transparent documentation and follow-up to confirm variance analysis controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Accounting controls — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about accounting controls in Financial Management is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Accounting controls in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial statements — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During financial management planning, financial statements is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Financial statements: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Budgeting — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to budgeting under Financial Management. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Financial Management includes transparent documentation and follow-up to confirm budgeting controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Variance analysis — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying variance analysis within Financial Management, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Variance analysis in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Accounting controls — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on accounting controls in Financial Management. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Accounting controls: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial statements — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about financial statements in Financial Management is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Financial Management includes transparent documentation and follow-up to confirm financial statements controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Budgeting — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During financial management planning, budgeting is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Budgeting in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Variance analysis — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to variance analysis under Financial Management. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Variance analysis: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Accounting controls — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying accounting controls within Financial Management, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Financial Management includes transparent documentation and follow-up to confirm accounting controls controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial statements — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on financial statements in Financial Management. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Financial statements in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Budgeting — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about budgeting in Financial Management is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Budgeting: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Variance analysis — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During financial management planning, variance analysis is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Financial Management includes transparent documentation and follow-up to confirm variance analysis controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Accounting controls — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to accounting controls under Financial Management. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Accounting controls in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial statements — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying financial statements within Financial Management, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Financial statements: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Budgeting — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on budgeting in Financial Management. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Financial Management includes transparent documentation and follow-up to confirm budgeting controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Variance analysis — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about variance analysis in Financial Management is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Variance analysis in Financial Management requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D14-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Accounting controls — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During financial management planning, accounting controls is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Accounting controls: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Internal Control Frameworks fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying internal control frameworks principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Internal Control Frameworks requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Internal Control Frameworks risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In internal control frameworks, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Internal Control Frameworks independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing internal control frameworks discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Internal Control Frameworks control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to internal control frameworks, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Internal Control Frameworks reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in internal control frameworks should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Internal Control Frameworks ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in internal control frameworks, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** COSO components — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying coso components within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

COSO components in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Control activities — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on control activities in Internal Control Frameworks. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Control activities: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Monitoring — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about monitoring in Internal Control Frameworks is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm monitoring controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Deficiencies — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During internal control frameworks planning, deficiencies is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Deficiencies in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** COSO components — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to coso components under Internal Control Frameworks. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to COSO components: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Control activities — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying control activities within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm control activities controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Monitoring — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on monitoring in Internal Control Frameworks. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Monitoring in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Deficiencies — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about deficiencies in Internal Control Frameworks is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Deficiencies: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** COSO components — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During internal control frameworks planning, coso components is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm coso components controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Control activities — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to control activities under Internal Control Frameworks. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Control activities in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Monitoring — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying monitoring within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Monitoring: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Deficiencies — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on deficiencies in Internal Control Frameworks. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm deficiencies controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** COSO components — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about coso components in Internal Control Frameworks is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

COSO components in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Control activities — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During internal control frameworks planning, control activities is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Control activities: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Monitoring — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to monitoring under Internal Control Frameworks. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm monitoring controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Deficiencies — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying deficiencies within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Deficiencies in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** COSO components — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on coso components in Internal Control Frameworks. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to COSO components: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Control activities — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about control activities in Internal Control Frameworks is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm control activities controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Monitoring — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During internal control frameworks planning, monitoring is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Monitoring in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Deficiencies — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to deficiencies under Internal Control Frameworks. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Deficiencies: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** COSO components — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying coso components within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm coso components controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Control activities — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on control activities in Internal Control Frameworks. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Control activities in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Monitoring — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about monitoring in Internal Control Frameworks is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Monitoring: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Deficiencies — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During internal control frameworks planning, deficiencies is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm deficiencies controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** COSO components — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to coso components under Internal Control Frameworks. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

COSO components in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Control activities — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying control activities within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Control activities: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Monitoring — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on monitoring in Internal Control Frameworks. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm monitoring controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Deficiencies — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about deficiencies in Internal Control Frameworks is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Deficiencies in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** COSO components — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During internal control frameworks planning, coso components is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to COSO components: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Control activities — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to control activities under Internal Control Frameworks. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm control activities controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Monitoring — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying monitoring within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Monitoring in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Deficiencies — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on deficiencies in Internal Control Frameworks. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Deficiencies: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** COSO components — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about coso components in Internal Control Frameworks is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm coso components controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Control activities — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During internal control frameworks planning, control activities is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Control activities in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Monitoring — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to monitoring under Internal Control Frameworks. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Monitoring: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Deficiencies — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying deficiencies within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm deficiencies controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** COSO components — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on coso components in Internal Control Frameworks. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

COSO components in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Control activities — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about control activities in Internal Control Frameworks is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Control activities: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Monitoring — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During internal control frameworks planning, monitoring is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm monitoring controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Deficiencies — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to deficiencies under Internal Control Frameworks. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Deficiencies in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** COSO components — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying coso components within Internal Control Frameworks, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to COSO components: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Control activities — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on control activities in Internal Control Frameworks. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Internal Control Frameworks includes transparent documentation and follow-up to confirm control activities controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Monitoring — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about monitoring in Internal Control Frameworks is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Monitoring in Internal Control Frameworks requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D15-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Deficiencies — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During internal control frameworks planning, deficiencies is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Deficiencies: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data Analytics in Auditing fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying data analytics in auditing principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Data Analytics in Auditing requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data Analytics in Auditing risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In data analytics in auditing, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data Analytics in Auditing independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing data analytics in auditing discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data Analytics in Auditing control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to data analytics in auditing, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data Analytics in Auditing reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in data analytics in auditing should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data Analytics in Auditing ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in data analytics in auditing, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Continuous auditing — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying continuous auditing within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Continuous auditing in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data mining — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on data mining in Data Analytics in Auditing. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Data mining: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Visualization — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about visualization in Data Analytics in Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm visualization controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Anomaly detection — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During data analytics in auditing planning, anomaly detection is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Anomaly detection in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Continuous auditing — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to continuous auditing under Data Analytics in Auditing. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Continuous auditing: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data mining — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying data mining within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm data mining controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Visualization — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on visualization in Data Analytics in Auditing. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Visualization in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Anomaly detection — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about anomaly detection in Data Analytics in Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Anomaly detection: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Continuous auditing — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During data analytics in auditing planning, continuous auditing is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm continuous auditing controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data mining — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to data mining under Data Analytics in Auditing. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Data mining in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Visualization — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying visualization within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Visualization: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Anomaly detection — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on anomaly detection in Data Analytics in Auditing. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm anomaly detection controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Continuous auditing — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about continuous auditing in Data Analytics in Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Continuous auditing in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data mining — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During data analytics in auditing planning, data mining is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Data mining: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Visualization — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to visualization under Data Analytics in Auditing. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm visualization controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Anomaly detection — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying anomaly detection within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Anomaly detection in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Continuous auditing — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on continuous auditing in Data Analytics in Auditing. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Continuous auditing: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data mining — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about data mining in Data Analytics in Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm data mining controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Visualization — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During data analytics in auditing planning, visualization is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Visualization in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Anomaly detection — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to anomaly detection under Data Analytics in Auditing. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Anomaly detection: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Continuous auditing — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying continuous auditing within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm continuous auditing controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data mining — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on data mining in Data Analytics in Auditing. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Data mining in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Visualization — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about visualization in Data Analytics in Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Visualization: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Anomaly detection — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During data analytics in auditing planning, anomaly detection is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm anomaly detection controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Continuous auditing — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to continuous auditing under Data Analytics in Auditing. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Continuous auditing in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data mining — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying data mining within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Data mining: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Visualization — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on visualization in Data Analytics in Auditing. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm visualization controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Anomaly detection — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about anomaly detection in Data Analytics in Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Anomaly detection in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Continuous auditing — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During data analytics in auditing planning, continuous auditing is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Continuous auditing: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data mining — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to data mining under Data Analytics in Auditing. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm data mining controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Visualization — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying visualization within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Visualization in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Anomaly detection — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on anomaly detection in Data Analytics in Auditing. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Anomaly detection: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Continuous auditing — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about continuous auditing in Data Analytics in Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm continuous auditing controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data mining — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During data analytics in auditing planning, data mining is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Data mining in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Visualization — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to visualization under Data Analytics in Auditing. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Visualization: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Anomaly detection — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying anomaly detection within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm anomaly detection controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Continuous auditing — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on continuous auditing in Data Analytics in Auditing. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Continuous auditing in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data mining — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about data mining in Data Analytics in Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Data mining: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Visualization — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During data analytics in auditing planning, visualization is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm visualization controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Anomaly detection — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to anomaly detection under Data Analytics in Auditing. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Anomaly detection in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Continuous auditing — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying continuous auditing within Data Analytics in Auditing, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Continuous auditing: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data mining — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on data mining in Data Analytics in Auditing. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Data Analytics in Auditing includes transparent documentation and follow-up to confirm data mining controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Visualization — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about visualization in Data Analytics in Auditing is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Visualization in Data Analytics in Auditing requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D16-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Anomaly detection — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During data analytics in auditing planning, anomaly detection is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Anomaly detection: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Ethics and Professionalism fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying ethics and professionalism principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Ethics and Professionalism requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Ethics and Professionalism risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In ethics and professionalism, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Ethics and Professionalism independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing ethics and professionalism discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Ethics and Professionalism control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to ethics and professionalism, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Ethics and Professionalism reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in ethics and professionalism should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Ethics and Professionalism ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in ethics and professionalism, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** IIA Code of Ethics — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying iia code of ethics within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

IIA Code of Ethics in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Conflicts of interest — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on conflicts of interest in Ethics and Professionalism. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Conflicts of interest: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Confidentiality — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about confidentiality in Ethics and Professionalism is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm confidentiality controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Integrity — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During ethics and professionalism planning, integrity is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Integrity in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** IIA Code of Ethics — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to iia code of ethics under Ethics and Professionalism. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to IIA Code of Ethics: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Conflicts of interest — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying conflicts of interest within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm conflicts of interest controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Confidentiality — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on confidentiality in Ethics and Professionalism. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Confidentiality in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Integrity — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about integrity in Ethics and Professionalism is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Integrity: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** IIA Code of Ethics — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During ethics and professionalism planning, iia code of ethics is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm iia code of ethics controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Conflicts of interest — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to conflicts of interest under Ethics and Professionalism. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Conflicts of interest in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Confidentiality — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying confidentiality within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Confidentiality: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Integrity — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on integrity in Ethics and Professionalism. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm integrity controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** IIA Code of Ethics — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about iia code of ethics in Ethics and Professionalism is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

IIA Code of Ethics in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Conflicts of interest — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During ethics and professionalism planning, conflicts of interest is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Conflicts of interest: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Confidentiality — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to confidentiality under Ethics and Professionalism. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm confidentiality controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Integrity — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying integrity within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Integrity in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** IIA Code of Ethics — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on iia code of ethics in Ethics and Professionalism. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to IIA Code of Ethics: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Conflicts of interest — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about conflicts of interest in Ethics and Professionalism is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm conflicts of interest controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Confidentiality — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During ethics and professionalism planning, confidentiality is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Confidentiality in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Integrity — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to integrity under Ethics and Professionalism. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Integrity: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** IIA Code of Ethics — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying iia code of ethics within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm iia code of ethics controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Conflicts of interest — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on conflicts of interest in Ethics and Professionalism. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Conflicts of interest in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Confidentiality — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about confidentiality in Ethics and Professionalism is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Confidentiality: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Integrity — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During ethics and professionalism planning, integrity is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm integrity controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** IIA Code of Ethics — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to iia code of ethics under Ethics and Professionalism. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

IIA Code of Ethics in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Conflicts of interest — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying conflicts of interest within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Conflicts of interest: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Confidentiality — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on confidentiality in Ethics and Professionalism. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm confidentiality controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Integrity — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about integrity in Ethics and Professionalism is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Integrity in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** IIA Code of Ethics — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During ethics and professionalism planning, iia code of ethics is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to IIA Code of Ethics: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Conflicts of interest — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to conflicts of interest under Ethics and Professionalism. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm conflicts of interest controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Confidentiality — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying confidentiality within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Confidentiality in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Integrity — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on integrity in Ethics and Professionalism. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Integrity: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** IIA Code of Ethics — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about iia code of ethics in Ethics and Professionalism is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm iia code of ethics controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Conflicts of interest — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During ethics and professionalism planning, conflicts of interest is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Conflicts of interest in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Confidentiality — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to confidentiality under Ethics and Professionalism. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Confidentiality: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Integrity — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying integrity within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm integrity controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** IIA Code of Ethics — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on iia code of ethics in Ethics and Professionalism. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

IIA Code of Ethics in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Conflicts of interest — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about conflicts of interest in Ethics and Professionalism is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Conflicts of interest: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Confidentiality — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During ethics and professionalism planning, confidentiality is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm confidentiality controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Integrity — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to integrity under Ethics and Professionalism. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Integrity in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** IIA Code of Ethics — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying iia code of ethics within Ethics and Professionalism, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to IIA Code of Ethics: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Conflicts of interest — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on conflicts of interest in Ethics and Professionalism. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Ethics and Professionalism includes transparent documentation and follow-up to confirm conflicts of interest controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Confidentiality — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about confidentiality in Ethics and Professionalism is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Confidentiality in Ethics and Professionalism requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D17-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Integrity — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During ethics and professionalism planning, integrity is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Integrity: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory Compliance fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying regulatory compliance principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Regulatory Compliance requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory Compliance risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In regulatory compliance, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory Compliance independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing regulatory compliance discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory Compliance control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to regulatory compliance, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory Compliance reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in regulatory compliance should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory Compliance ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in regulatory compliance, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Legal requirements — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying legal requirements within Regulatory Compliance, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Legal requirements in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Policy compliance — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on policy compliance in Regulatory Compliance. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Policy compliance: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory change — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about regulatory change in Regulatory Compliance is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm regulatory change controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Sanctions risk — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During regulatory compliance planning, sanctions risk is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Sanctions risk in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Legal requirements — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to legal requirements under Regulatory Compliance. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Legal requirements: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Policy compliance — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying policy compliance within Regulatory Compliance, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm policy compliance controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory change — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on regulatory change in Regulatory Compliance. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Regulatory change in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Sanctions risk — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about sanctions risk in Regulatory Compliance is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Sanctions risk: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Legal requirements — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During regulatory compliance planning, legal requirements is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm legal requirements controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Policy compliance — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to policy compliance under Regulatory Compliance. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Policy compliance in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory change — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying regulatory change within Regulatory Compliance, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Regulatory change: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Sanctions risk — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on sanctions risk in Regulatory Compliance. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm sanctions risk controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Legal requirements — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about legal requirements in Regulatory Compliance is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Legal requirements in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Policy compliance — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During regulatory compliance planning, policy compliance is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Policy compliance: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory change — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to regulatory change under Regulatory Compliance. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm regulatory change controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Sanctions risk — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying sanctions risk within Regulatory Compliance, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Sanctions risk in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Legal requirements — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on legal requirements in Regulatory Compliance. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Legal requirements: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Policy compliance — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about policy compliance in Regulatory Compliance is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm policy compliance controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory change — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During regulatory compliance planning, regulatory change is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Regulatory change in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Sanctions risk — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to sanctions risk under Regulatory Compliance. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Sanctions risk: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Legal requirements — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying legal requirements within Regulatory Compliance, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm legal requirements controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Policy compliance — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on policy compliance in Regulatory Compliance. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Policy compliance in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory change — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about regulatory change in Regulatory Compliance is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Regulatory change: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Sanctions risk — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During regulatory compliance planning, sanctions risk is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm sanctions risk controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Legal requirements — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to legal requirements under Regulatory Compliance. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Legal requirements in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Policy compliance — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying policy compliance within Regulatory Compliance, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Policy compliance: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory change — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on regulatory change in Regulatory Compliance. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm regulatory change controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Sanctions risk — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about sanctions risk in Regulatory Compliance is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Sanctions risk in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Legal requirements — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During regulatory compliance planning, legal requirements is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Legal requirements: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Policy compliance — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to policy compliance under Regulatory Compliance. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm policy compliance controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory change — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying regulatory change within Regulatory Compliance, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Regulatory change in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Sanctions risk — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on sanctions risk in Regulatory Compliance. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Sanctions risk: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Legal requirements — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about legal requirements in Regulatory Compliance is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm legal requirements controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Policy compliance — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During regulatory compliance planning, policy compliance is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Policy compliance in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory change — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to regulatory change under Regulatory Compliance. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Regulatory change: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Sanctions risk — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying sanctions risk within Regulatory Compliance, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm sanctions risk controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Legal requirements — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on legal requirements in Regulatory Compliance. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Legal requirements in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Policy compliance — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about policy compliance in Regulatory Compliance is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Policy compliance: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory change — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During regulatory compliance planning, regulatory change is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm regulatory change controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Sanctions risk — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to sanctions risk under Regulatory Compliance. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Sanctions risk in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Legal requirements — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying legal requirements within Regulatory Compliance, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Legal requirements: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Policy compliance — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on policy compliance in Regulatory Compliance. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Regulatory Compliance includes transparent documentation and follow-up to confirm policy compliance controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory change — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about regulatory change in Regulatory Compliance is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Regulatory change in Regulatory Compliance requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D18-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Sanctions risk — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During regulatory compliance planning, sanctions risk is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Sanctions risk: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk Assessment Methodology fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying risk assessment methodology principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Risk Assessment Methodology requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk Assessment Methodology risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In risk assessment methodology, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk Assessment Methodology independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing risk assessment methodology discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk Assessment Methodology control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to risk assessment methodology, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk Assessment Methodology reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in risk assessment methodology should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk Assessment Methodology ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in risk assessment methodology, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Inherent risk — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying inherent risk within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Inherent risk in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Residual risk — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on residual risk in Risk Assessment Methodology. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Residual risk: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk registers — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about risk registers in Risk Assessment Methodology is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm risk registers controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Heat maps — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During risk assessment methodology planning, heat maps is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Heat maps in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Inherent risk — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to inherent risk under Risk Assessment Methodology. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Inherent risk: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Residual risk — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying residual risk within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm residual risk controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk registers — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on risk registers in Risk Assessment Methodology. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Risk registers in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Heat maps — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about heat maps in Risk Assessment Methodology is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Heat maps: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Inherent risk — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During risk assessment methodology planning, inherent risk is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm inherent risk controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Residual risk — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to residual risk under Risk Assessment Methodology. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Residual risk in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk registers — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying risk registers within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Risk registers: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Heat maps — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on heat maps in Risk Assessment Methodology. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm heat maps controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Inherent risk — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about inherent risk in Risk Assessment Methodology is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Inherent risk in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Residual risk — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During risk assessment methodology planning, residual risk is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Residual risk: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk registers — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to risk registers under Risk Assessment Methodology. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm risk registers controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Heat maps — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying heat maps within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Heat maps in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Inherent risk — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on inherent risk in Risk Assessment Methodology. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Inherent risk: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Residual risk — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about residual risk in Risk Assessment Methodology is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm residual risk controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk registers — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During risk assessment methodology planning, risk registers is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Risk registers in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Heat maps — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to heat maps under Risk Assessment Methodology. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Heat maps: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Inherent risk — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying inherent risk within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm inherent risk controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Residual risk — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on residual risk in Risk Assessment Methodology. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Residual risk in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk registers — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about risk registers in Risk Assessment Methodology is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Risk registers: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Heat maps — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During risk assessment methodology planning, heat maps is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm heat maps controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Inherent risk — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to inherent risk under Risk Assessment Methodology. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Inherent risk in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Residual risk — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying residual risk within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Residual risk: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk registers — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on risk registers in Risk Assessment Methodology. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm risk registers controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Heat maps — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about heat maps in Risk Assessment Methodology is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Heat maps in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Inherent risk — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During risk assessment methodology planning, inherent risk is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Inherent risk: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Residual risk — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to residual risk under Risk Assessment Methodology. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm residual risk controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk registers — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying risk registers within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Risk registers in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Heat maps — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on heat maps in Risk Assessment Methodology. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Heat maps: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Inherent risk — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about inherent risk in Risk Assessment Methodology is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm inherent risk controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Residual risk — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During risk assessment methodology planning, residual risk is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Residual risk in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk registers — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to risk registers under Risk Assessment Methodology. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Risk registers: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Heat maps — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying heat maps within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm heat maps controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Inherent risk — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on inherent risk in Risk Assessment Methodology. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Inherent risk in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Residual risk — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about residual risk in Risk Assessment Methodology is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Residual risk: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk registers — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During risk assessment methodology planning, risk registers is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm risk registers controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Heat maps — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to heat maps under Risk Assessment Methodology. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Heat maps in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Inherent risk — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying inherent risk within Risk Assessment Methodology, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Inherent risk: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Residual risk — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on residual risk in Risk Assessment Methodology. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Risk Assessment Methodology includes transparent documentation and follow-up to confirm residual risk controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk registers — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about risk registers in Risk Assessment Methodology is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Risk registers in Risk Assessment Methodology requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D19-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Heat maps — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During risk assessment methodology planning, heat maps is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Heat maps: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Audit Reporting and Follow-Up fundamentals
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying audit reporting and follow-up principles, which action best aligns with the IIA Standards and professional internal auditing practice?

### Choices

- A) Apply systematic, disciplined approaches with documented evidence and appropriate supervision
- B) Rely on undocumented assumptions without verification
- C) Skip independence considerations when under time pressure
- D) Withhold significant findings from senior management

**Correct answer:** A

### Explanation

Audit Reporting and Follow-Up requires systematic evidence gathering, professional skepticism, and transparent communication per IIA Standards concepts.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Audit Reporting and Follow-Up risk focus
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

In audit reporting and follow-up, internal auditors should prioritize:

### Choices

- A) Areas of significant risk to organizational objectives and governance effectiveness
- B) Only areas requested by operational managers
- C) Random samples without risk assessment
- D) Low-risk areas to maximize audit hours

**Correct answer:** A

### Explanation

Risk-based internal auditing focuses resources on areas that matter most to governance, risk management, and control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Audit Reporting and Follow-Up independence
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An auditor assessing audit reporting and follow-up discovers a potential impairment to objectivity. The appropriate response is:

### Choices

- A) Disclose the impairment to appropriate parties and refrain from the affected work if objectivity cannot be maintained
- B) Proceed without disclosure to avoid delays
- C) Accept gifts that could influence judgment
- D) Implement controls the auditor previously designed without safeguards

**Correct answer:** A

### Explanation

Independence and objectivity require disclosure of impairments and safeguards before continuing affected audit work.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Audit Reporting and Follow-Up control evaluation
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When evaluating controls related to audit reporting and follow-up, auditors should:

### Choices

- A) Assess design effectiveness and test operating effectiveness with sufficient appropriate evidence
- B) Accept management assertions without testing
- C) Report only on design without considering operations
- D) Limit work to inquiry alone

**Correct answer:** A

### Explanation

Control assurance requires both design assessment and testing of operating effectiveness with sufficient evidence.

**References:** coso-framework: COSO Internal Control Framework (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Audit Reporting and Follow-Up reporting
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Findings in audit reporting and follow-up should be communicated:

### Choices

- A) Timely, accurately, and objectively with clear criteria, condition, cause, and effect
- B) Only verbally without documentation
- C) After all other audits complete regardless of urgency
- D) With subjective opinions unsupported by evidence

**Correct answer:** A

### Explanation

Effective audit reporting includes criteria, condition, cause, effect, and recommendations supported by evidence.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Audit Reporting and Follow-Up ethics
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When conflicts arise in audit reporting and follow-up, internal auditors must:

### Choices

- A) Act with integrity, objectivity, confidentiality, and competency per the IIA Code of Ethics
- B) Disclose confidential information to unauthorized parties
- C) Accept payments that influence audit conclusions
- D) Misrepresent findings to protect management

**Correct answer:** A

### Explanation

The IIA Code of Ethics requires integrity, objectivity, confidentiality, and competency in all professional activities.

**References:** iia-code-ethics: IIA Code of Ethics (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Rating scales — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying rating scales within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Rating scales in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Management responses — scenario 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on management responses in Audit Reporting and Follow-Up. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Management responses: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Action tracking — scenario 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about action tracking in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm action tracking controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Closure criteria — scenario 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During audit reporting and follow-up planning, closure criteria is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Closure criteria in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Rating scales — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to rating scales under Audit Reporting and Follow-Up. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Rating scales: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Management responses — scenario 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying management responses within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm management responses controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Action tracking — scenario 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on action tracking in Audit Reporting and Follow-Up. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Action tracking in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q014

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Closure criteria — scenario 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about closure criteria in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Closure criteria: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q015

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Rating scales — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During audit reporting and follow-up planning, rating scales is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm rating scales controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q016

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Management responses — scenario 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to management responses under Audit Reporting and Follow-Up. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Management responses in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q017

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Action tracking — scenario 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying action tracking within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Action tracking: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q018

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Closure criteria — scenario 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on closure criteria in Audit Reporting and Follow-Up. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm closure criteria controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q019

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Rating scales — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about rating scales in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Rating scales in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q020

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Management responses — scenario 4
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During audit reporting and follow-up planning, management responses is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Management responses: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q021

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Action tracking — scenario 4
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to action tracking under Audit Reporting and Follow-Up. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm action tracking controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q022

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Closure criteria — scenario 4
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying closure criteria within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Closure criteria in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q023

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Rating scales — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on rating scales in Audit Reporting and Follow-Up. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Rating scales: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q024

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Management responses — scenario 5
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about management responses in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm management responses controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q025

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Action tracking — scenario 5
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During audit reporting and follow-up planning, action tracking is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Action tracking in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q026

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Closure criteria — scenario 5
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to closure criteria under Audit Reporting and Follow-Up. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Closure criteria: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q027

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Rating scales — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying rating scales within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm rating scales controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q028

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Management responses — scenario 6
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on management responses in Audit Reporting and Follow-Up. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Management responses in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q029

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Action tracking — scenario 6
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about action tracking in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Action tracking: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q030

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Closure criteria — scenario 6
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During audit reporting and follow-up planning, closure criteria is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm closure criteria controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q031

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Rating scales — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to rating scales under Audit Reporting and Follow-Up. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Rating scales in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q032

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Management responses — scenario 7
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying management responses within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Management responses: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q033

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Action tracking — scenario 7
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on action tracking in Audit Reporting and Follow-Up. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm action tracking controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q034

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Closure criteria — scenario 7
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about closure criteria in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Closure criteria in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q035

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Rating scales — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During audit reporting and follow-up planning, rating scales is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Rating scales: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q036

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Management responses — scenario 8
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

An audit finding relates to management responses under Audit Reporting and Follow-Up. Corrective action should:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm management responses controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q037

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Action tracking — scenario 8
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

When applying action tracking within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Action tracking in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q038

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Closure criteria — scenario 8
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

A facility review focuses on closure criteria in Audit Reporting and Follow-Up. The most defensible next step is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Closure criteria: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q039

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Rating scales — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Which statement about rating scales in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm rating scales controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q040

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Management responses — scenario 9
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

During audit reporting and follow-up planning, management responses is evaluated. The priority action is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Management responses in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q041

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Action tracking — scenario 9
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

An audit finding relates to action tracking under Audit Reporting and Follow-Up. Corrective action should:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Action tracking: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q042

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Closure criteria — scenario 9
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

When applying closure criteria within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm closure criteria controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q043

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Rating scales — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

A facility review focuses on rating scales in Audit Reporting and Follow-Up. The most defensible next step is:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Rating scales in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q044

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Management responses — scenario 10
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Which statement about management responses in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Management responses: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q045

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Action tracking — scenario 10
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

During audit reporting and follow-up planning, action tracking is evaluated. The priority action is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm action tracking controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q046

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Closure criteria — scenario 10
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

An audit finding relates to closure criteria under Audit Reporting and Follow-Up. Corrective action should:

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Closure criteria in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q047

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Rating scales — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

When applying rating scales within Audit Reporting and Follow-Up, which approach best aligns with professional practice and public guidance?

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Rating scales: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q048

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Management responses — scenario 11
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

A facility review focuses on management responses in Audit Reporting and Follow-Up. The most defensible next step is:

### Choices

- A) Document assumptions, communicate findings, and schedule follow-up verification
- B) Close the issue without root-cause analysis
- C) Withhold results from affected workers
- D) Use proprietary prep content without citation

**Correct answer:** A

### Explanation

Professional practice in Audit Reporting and Follow-Up includes transparent documentation and follow-up to confirm management responses controls remain effective.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q049

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Action tracking — scenario 11
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Which statement about action tracking in Audit Reporting and Follow-Up is supported by standard occupational health and safety practice?

### Choices

- A) Use documented, reference-backed methods and verify control effectiveness
- B) Rely on undocumented assumptions without follow-up
- C) Skip worker communication and training
- D) Discard sampling or inspection records

**Correct answer:** A

### Explanation

Action tracking in Audit Reporting and Follow-Up requires traceable data, appropriate public methods, and verification that controls perform as intended.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-D20-Q050

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Closure criteria — scenario 11
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

During audit reporting and follow-up planning, closure criteria is evaluated. The priority action is:

### Choices

- A) Prioritize elimination or engineering controls before administrative measures and PPE
- B) Use PPE alone without assessing source controls
- C) Defer all action until an injury occurs
- D) Ignore applicable regulatory minimums

**Correct answer:** A

### Explanation

The hierarchy of controls applies to Closure criteria: reduce exposure at the source before relying on administrative measures or PPE alone.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D1-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mission definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Foundations of Internal Auditing requires that mission must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Foundations of Internal Auditing integrates mission with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D1-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mission — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Foundations of Internal Auditing, mission is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Mission in Foundations of Internal Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D1-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Value proposition — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing value proposition within Foundations of Internal Auditing, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective value proposition starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D1-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mandatory guidance — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for mandatory guidance in Foundations of Internal Auditing is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Foundations of Internal Auditing.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D1-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Professional framework — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Foundations of Internal Auditing, professional framework is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Professional framework in Foundations of Internal Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D1-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mission — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing mission within Foundations of Internal Auditing, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective mission starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D1-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Value proposition — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for value proposition in Foundations of Internal Auditing is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Foundations of Internal Auditing.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D1-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mandatory guidance — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Foundations of Internal Auditing, mandatory guidance is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Mandatory guidance in Foundations of Internal Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D1-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Professional framework — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing professional framework within Foundations of Internal Auditing, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective professional framework starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D1-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mission — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for mission in Foundations of Internal Auditing is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Foundations of Internal Auditing.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D1-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Value proposition — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Foundations of Internal Auditing, value proposition is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Value proposition in Foundations of Internal Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D1-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Mandatory guidance — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing mandatory guidance within Foundations of Internal Auditing, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective mandatory guidance starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D1-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** foundations-internal-auditing
- **Topic:** Professional framework — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for professional framework in Foundations of Internal Auditing is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Foundations of Internal Auditing.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D2-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Organizational independence definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Independence and Objectivity requires that organizational independence must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Independence and Objectivity integrates organizational independence with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D2-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Organizational independence — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Independence and Objectivity, organizational independence is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Organizational independence in Independence and Objectivity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D2-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Individual objectivity — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing individual objectivity within Independence and Objectivity, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective individual objectivity starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D2-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Impairments — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for impairments in Independence and Objectivity is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Independence and Objectivity.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D2-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Disclosure — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Independence and Objectivity, disclosure is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Disclosure in Independence and Objectivity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D2-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Organizational independence — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing organizational independence within Independence and Objectivity, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective organizational independence starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D2-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Individual objectivity — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for individual objectivity in Independence and Objectivity is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Independence and Objectivity.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D2-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Impairments — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Independence and Objectivity, impairments is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Impairments in Independence and Objectivity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D2-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Disclosure — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing disclosure within Independence and Objectivity, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective disclosure starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D2-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Organizational independence — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for organizational independence in Independence and Objectivity is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Independence and Objectivity.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D2-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Individual objectivity — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Independence and Objectivity, individual objectivity is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Individual objectivity in Independence and Objectivity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D2-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Impairments — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing impairments within Independence and Objectivity, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective impairments starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D2-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** independence-objectivity
- **Topic:** Disclosure — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for disclosure in Independence and Objectivity is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Independence and Objectivity.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D3-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Competency definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Proficiency and Due Professional Care requires that competency must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Proficiency and Due Professional Care integrates competency with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D3-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Competency — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Proficiency and Due Professional Care, competency is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Competency in Proficiency and Due Professional Care requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D3-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Continuing education — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing continuing education within Proficiency and Due Professional Care, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective continuing education starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D3-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Supervision — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for supervision in Proficiency and Due Professional Care is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Proficiency and Due Professional Care.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D3-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Due care — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Proficiency and Due Professional Care, due care is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Due care in Proficiency and Due Professional Care requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D3-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Competency — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing competency within Proficiency and Due Professional Care, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective competency starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D3-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Continuing education — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for continuing education in Proficiency and Due Professional Care is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Proficiency and Due Professional Care.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D3-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Supervision — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Proficiency and Due Professional Care, supervision is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Supervision in Proficiency and Due Professional Care requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D3-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Due care — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing due care within Proficiency and Due Professional Care, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective due care starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D3-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Competency — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for competency in Proficiency and Due Professional Care is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Proficiency and Due Professional Care.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D3-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Continuing education — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Proficiency and Due Professional Care, continuing education is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Continuing education in Proficiency and Due Professional Care requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D3-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Supervision — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing supervision within Proficiency and Due Professional Care, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective supervision starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D3-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** proficiency-due-care
- **Topic:** Due care — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for due care in Proficiency and Due Professional Care is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Proficiency and Due Professional Care.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D4-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Internal assessments definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Quality Assurance and Improvement Program requires that internal assessments must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Quality Assurance and Improvement Program integrates internal assessments with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D4-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Internal assessments — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Quality Assurance and Improvement Program, internal assessments is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Internal assessments in Quality Assurance and Improvement Program requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D4-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** External assessments — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing external assessments within Quality Assurance and Improvement Program, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective external assessments starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D4-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** QAIP reporting — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for qaip reporting in Quality Assurance and Improvement Program is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Quality Assurance and Improvement Program.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D4-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Improvement plans — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Quality Assurance and Improvement Program, improvement plans is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Improvement plans in Quality Assurance and Improvement Program requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D4-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Internal assessments — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing internal assessments within Quality Assurance and Improvement Program, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective internal assessments starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D4-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** External assessments — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for external assessments in Quality Assurance and Improvement Program is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Quality Assurance and Improvement Program.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D4-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** QAIP reporting — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Quality Assurance and Improvement Program, qaip reporting is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

QAIP reporting in Quality Assurance and Improvement Program requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D4-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Improvement plans — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing improvement plans within Quality Assurance and Improvement Program, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective improvement plans starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D4-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Internal assessments — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for internal assessments in Quality Assurance and Improvement Program is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Quality Assurance and Improvement Program.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D4-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** External assessments — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Quality Assurance and Improvement Program, external assessments is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

External assessments in Quality Assurance and Improvement Program requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D4-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** QAIP reporting — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing qaip reporting within Quality Assurance and Improvement Program, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective qaip reporting starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D4-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** quality-assurance-improvement
- **Topic:** Improvement plans — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for improvement plans in Quality Assurance and Improvement Program is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Quality Assurance and Improvement Program.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D5-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Three lines model definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Governance, Risk Management, and Control requires that three lines model must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Governance, Risk Management, and Control integrates three lines model with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D5-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Three lines model — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Governance, Risk Management, and Control, three lines model is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Three lines model in Governance, Risk Management, and Control requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D5-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Risk appetite — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing risk appetite within Governance, Risk Management, and Control, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective risk appetite starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D5-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Control environment — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for control environment in Governance, Risk Management, and Control is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Governance, Risk Management, and Control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D5-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Board oversight — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Governance, Risk Management, and Control, board oversight is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Board oversight in Governance, Risk Management, and Control requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D5-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Three lines model — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing three lines model within Governance, Risk Management, and Control, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective three lines model starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D5-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Risk appetite — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for risk appetite in Governance, Risk Management, and Control is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Governance, Risk Management, and Control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D5-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Control environment — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Governance, Risk Management, and Control, control environment is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Control environment in Governance, Risk Management, and Control requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D5-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Board oversight — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing board oversight within Governance, Risk Management, and Control, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective board oversight starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D5-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Three lines model — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for three lines model in Governance, Risk Management, and Control is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Governance, Risk Management, and Control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D5-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Risk appetite — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Governance, Risk Management, and Control, risk appetite is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Risk appetite in Governance, Risk Management, and Control requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D5-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Control environment — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing control environment within Governance, Risk Management, and Control, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective control environment starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D5-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** governance-risk-control
- **Topic:** Board oversight — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for board oversight in Governance, Risk Management, and Control is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Governance, Risk Management, and Control.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D6-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud indicators definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Fraud Risks requires that fraud indicators must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Fraud Risks integrates fraud indicators with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D6-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud indicators — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Fraud Risks, fraud indicators is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Fraud indicators in Fraud Risks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D6-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Red flags — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing red flags within Fraud Risks, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective red flags starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D6-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Investigation boundaries — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for investigation boundaries in Fraud Risks is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Fraud Risks.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D6-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Reporting — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Fraud Risks, reporting is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Reporting in Fraud Risks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D6-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud indicators — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing fraud indicators within Fraud Risks, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective fraud indicators starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D6-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Red flags — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for red flags in Fraud Risks is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Fraud Risks.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D6-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Investigation boundaries — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Fraud Risks, investigation boundaries is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Investigation boundaries in Fraud Risks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D6-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Reporting — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing reporting within Fraud Risks, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective reporting starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D6-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Fraud indicators — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for fraud indicators in Fraud Risks is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Fraud Risks.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D6-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Red flags — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Fraud Risks, red flags is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Red flags in Fraud Risks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D6-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Investigation boundaries — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing investigation boundaries within Fraud Risks, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective investigation boundaries starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D6-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** fraud-risks
- **Topic:** Reporting — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for reporting in Fraud Risks is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Fraud Risks.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D7-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Charter definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Managing the Internal Audit Activity requires that charter must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Managing the Internal Audit Activity integrates charter with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D7-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Charter — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Managing the Internal Audit Activity, charter is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Charter in Managing the Internal Audit Activity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D7-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Resource planning — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing resource planning within Managing the Internal Audit Activity, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective resource planning starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D7-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Policies — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for policies in Managing the Internal Audit Activity is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Managing the Internal Audit Activity.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D7-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Performance metrics — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Managing the Internal Audit Activity, performance metrics is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Performance metrics in Managing the Internal Audit Activity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D7-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Charter — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing charter within Managing the Internal Audit Activity, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective charter starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D7-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Resource planning — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for resource planning in Managing the Internal Audit Activity is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Managing the Internal Audit Activity.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D7-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Policies — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Managing the Internal Audit Activity, policies is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Policies in Managing the Internal Audit Activity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D7-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Performance metrics — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing performance metrics within Managing the Internal Audit Activity, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective performance metrics starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D7-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Charter — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for charter in Managing the Internal Audit Activity is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Managing the Internal Audit Activity.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D7-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Resource planning — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Managing the Internal Audit Activity, resource planning is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Resource planning in Managing the Internal Audit Activity requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D7-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Policies — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing policies within Managing the Internal Audit Activity, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective policies starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D7-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** managing-audit-activity
- **Topic:** Performance metrics — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for performance metrics in Managing the Internal Audit Activity is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Managing the Internal Audit Activity.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D8-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Risk-based planning definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Engagement Planning requires that risk-based planning must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Engagement Planning integrates risk-based planning with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D8-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Risk-based planning — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Engagement Planning, risk-based planning is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Risk-based planning in Engagement Planning requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D8-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Scope — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing scope within Engagement Planning, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective scope starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D8-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Objectives — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for objectives in Engagement Planning is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Engagement Planning.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D8-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Work programs — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Engagement Planning, work programs is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Work programs in Engagement Planning requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D8-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Risk-based planning — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing risk-based planning within Engagement Planning, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective risk-based planning starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D8-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Scope — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for scope in Engagement Planning is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Engagement Planning.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D8-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Objectives — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Engagement Planning, objectives is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Objectives in Engagement Planning requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D8-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Work programs — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing work programs within Engagement Planning, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective work programs starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D8-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Risk-based planning — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for risk-based planning in Engagement Planning is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Engagement Planning.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D8-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Scope — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Engagement Planning, scope is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Scope in Engagement Planning requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D8-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Objectives — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing objectives within Engagement Planning, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective objectives starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D8-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-planning
- **Topic:** Work programs — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for work programs in Engagement Planning is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Engagement Planning.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D9-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Evidence gathering definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Performing the Engagement requires that evidence gathering must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Performing the Engagement integrates evidence gathering with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D9-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Evidence gathering — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Performing the Engagement, evidence gathering is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Evidence gathering in Performing the Engagement requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D9-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Sampling — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing sampling within Performing the Engagement, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective sampling starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D9-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Analysis — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for analysis in Performing the Engagement is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Performing the Engagement.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D9-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Documentation — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Performing the Engagement, documentation is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Documentation in Performing the Engagement requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D9-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Evidence gathering — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing evidence gathering within Performing the Engagement, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective evidence gathering starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D9-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Sampling — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for sampling in Performing the Engagement is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Performing the Engagement.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D9-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Analysis — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Performing the Engagement, analysis is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Analysis in Performing the Engagement requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D9-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Documentation — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing documentation within Performing the Engagement, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective documentation starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D9-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Evidence gathering — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for evidence gathering in Performing the Engagement is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Performing the Engagement.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D9-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Sampling — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Performing the Engagement, sampling is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Sampling in Performing the Engagement requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D9-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Analysis — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing analysis within Performing the Engagement, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective analysis starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D9-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-performance
- **Topic:** Documentation — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for documentation in Performing the Engagement is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Performing the Engagement.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D10-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Reporting definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Communicating Engagement Results requires that reporting must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Communicating Engagement Results integrates reporting with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D10-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Reporting — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Communicating Engagement Results, reporting is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Reporting in Communicating Engagement Results requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D10-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Recommendations — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing recommendations within Communicating Engagement Results, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective recommendations starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D10-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Follow-up — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for follow-up in Communicating Engagement Results is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Communicating Engagement Results.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D10-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Monitoring — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Communicating Engagement Results, monitoring is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Monitoring in Communicating Engagement Results requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D10-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Reporting — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing reporting within Communicating Engagement Results, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective reporting starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D10-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Recommendations — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for recommendations in Communicating Engagement Results is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Communicating Engagement Results.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D10-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Follow-up — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Communicating Engagement Results, follow-up is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Follow-up in Communicating Engagement Results requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D10-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Monitoring — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing monitoring within Communicating Engagement Results, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective monitoring starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D10-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Reporting — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for reporting in Communicating Engagement Results is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Communicating Engagement Results.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D10-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Recommendations — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Communicating Engagement Results, recommendations is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Recommendations in Communicating Engagement Results requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D10-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Follow-up — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing follow-up within Communicating Engagement Results, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective follow-up starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D10-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** engagement-communication
- **Topic:** Monitoring — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for monitoring in Communicating Engagement Results is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Communicating Engagement Results.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D11-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Industry context definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Business Acumen requires that industry context must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Business Acumen integrates industry context with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D11-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Industry context — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Business Acumen, industry context is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Industry context in Business Acumen requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D11-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Strategy — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing strategy within Business Acumen, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective strategy starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D11-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Operations — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for operations in Business Acumen is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Business Acumen.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D11-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Value drivers — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Business Acumen, value drivers is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Value drivers in Business Acumen requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D11-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Industry context — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing industry context within Business Acumen, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective industry context starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D11-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Strategy — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for strategy in Business Acumen is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Business Acumen.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D11-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Operations — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Business Acumen, operations is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Operations in Business Acumen requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D11-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Value drivers — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing value drivers within Business Acumen, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective value drivers starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D11-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Industry context — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for industry context in Business Acumen is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Business Acumen.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D11-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Strategy — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Business Acumen, strategy is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Strategy in Business Acumen requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D11-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Operations — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing operations within Business Acumen, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective operations starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D11-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** business-acumen
- **Topic:** Value drivers — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for value drivers in Business Acumen is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Business Acumen.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D12-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Access controls definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Information Security requires that access controls must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Information Security integrates access controls with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D12-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Access controls — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Information Security, access controls is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Access controls in Information Security requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D12-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Data protection — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing data protection within Information Security, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective data protection starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D12-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Incident response — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for incident response in Information Security is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Information Security.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D12-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Security governance — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Information Security, security governance is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Security governance in Information Security requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D12-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Access controls — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing access controls within Information Security, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective access controls starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D12-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Data protection — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for data protection in Information Security is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Information Security.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D12-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Incident response — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Information Security, incident response is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Incident response in Information Security requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D12-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Security governance — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing security governance within Information Security, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective security governance starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D12-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Access controls — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for access controls in Information Security is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Information Security.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D12-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Data protection — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Information Security, data protection is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Data protection in Information Security requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D12-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Incident response — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing incident response within Information Security, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective incident response starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D12-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** information-security
- **Topic:** Security governance — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for security governance in Information Security is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Information Security.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D13-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT general controls definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Information Technology requires that it general controls must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Information Technology integrates it general controls with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D13-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT general controls — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Information Technology, it general controls is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

IT general controls in Information Technology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D13-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Change management — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing change management within Information Technology, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective change management starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D13-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** System development — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for system development in Information Technology is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Information Technology.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D13-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT audit — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Information Technology, it audit is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

IT audit in Information Technology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D13-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT general controls — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing it general controls within Information Technology, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective it general controls starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D13-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Change management — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for change management in Information Technology is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Information Technology.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D13-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** System development — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Information Technology, system development is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

System development in Information Technology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D13-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT audit — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing it audit within Information Technology, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective it audit starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D13-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT general controls — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for it general controls in Information Technology is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Information Technology.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D13-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** Change management — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Information Technology, change management is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Change management in Information Technology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D13-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** System development — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing system development within Information Technology, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective system development starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D13-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** information-technology
- **Topic:** IT audit — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for it audit in Information Technology is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Information Technology.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D14-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial statements definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Financial Management requires that financial statements must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Financial Management integrates financial statements with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D14-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial statements — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Financial Management, financial statements is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Financial statements in Financial Management requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D14-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Budgeting — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing budgeting within Financial Management, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective budgeting starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D14-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Variance analysis — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for variance analysis in Financial Management is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Financial Management.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D14-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Accounting controls — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Financial Management, accounting controls is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Accounting controls in Financial Management requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D14-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial statements — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing financial statements within Financial Management, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective financial statements starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D14-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Budgeting — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for budgeting in Financial Management is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Financial Management.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D14-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Variance analysis — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Financial Management, variance analysis is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Variance analysis in Financial Management requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D14-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Accounting controls — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing accounting controls within Financial Management, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective accounting controls starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D14-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Financial statements — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for financial statements in Financial Management is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Financial Management.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D14-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Budgeting — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Financial Management, budgeting is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Budgeting in Financial Management requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D14-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Variance analysis — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing variance analysis within Financial Management, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective variance analysis starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D14-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** financial-management
- **Topic:** Accounting controls — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for accounting controls in Financial Management is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Financial Management.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D15-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** COSO components definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Internal Control Frameworks requires that coso components must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Internal Control Frameworks integrates coso components with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D15-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** COSO components — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Internal Control Frameworks, coso components is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

COSO components in Internal Control Frameworks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D15-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Control activities — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing control activities within Internal Control Frameworks, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective control activities starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D15-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Monitoring — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for monitoring in Internal Control Frameworks is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Internal Control Frameworks.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D15-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Deficiencies — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Internal Control Frameworks, deficiencies is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Deficiencies in Internal Control Frameworks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D15-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** COSO components — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing coso components within Internal Control Frameworks, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective coso components starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D15-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Control activities — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for control activities in Internal Control Frameworks is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Internal Control Frameworks.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D15-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Monitoring — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Internal Control Frameworks, monitoring is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Monitoring in Internal Control Frameworks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D15-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Deficiencies — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing deficiencies within Internal Control Frameworks, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective deficiencies starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D15-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** COSO components — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for coso components in Internal Control Frameworks is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Internal Control Frameworks.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D15-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Control activities — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Internal Control Frameworks, control activities is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Control activities in Internal Control Frameworks requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D15-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Monitoring — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing monitoring within Internal Control Frameworks, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective monitoring starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D15-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** internal-control-frameworks
- **Topic:** Deficiencies — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for deficiencies in Internal Control Frameworks is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Internal Control Frameworks.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D16-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Continuous auditing definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Data Analytics in Auditing requires that continuous auditing must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Data Analytics in Auditing integrates continuous auditing with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D16-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Continuous auditing — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Data Analytics in Auditing, continuous auditing is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Continuous auditing in Data Analytics in Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D16-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data mining — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing data mining within Data Analytics in Auditing, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective data mining starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D16-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Visualization — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for visualization in Data Analytics in Auditing is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Data Analytics in Auditing.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D16-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Anomaly detection — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Data Analytics in Auditing, anomaly detection is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Anomaly detection in Data Analytics in Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D16-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Continuous auditing — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing continuous auditing within Data Analytics in Auditing, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective continuous auditing starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D16-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data mining — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for data mining in Data Analytics in Auditing is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Data Analytics in Auditing.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D16-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Visualization — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Data Analytics in Auditing, visualization is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Visualization in Data Analytics in Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D16-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Anomaly detection — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing anomaly detection within Data Analytics in Auditing, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective anomaly detection starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D16-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Continuous auditing — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for continuous auditing in Data Analytics in Auditing is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Data Analytics in Auditing.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D16-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Data mining — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Data Analytics in Auditing, data mining is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Data mining in Data Analytics in Auditing requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D16-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Visualization — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing visualization within Data Analytics in Auditing, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective visualization starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D16-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** data-analytics-auditing
- **Topic:** Anomaly detection — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for anomaly detection in Data Analytics in Auditing is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Data Analytics in Auditing.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D17-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** IIA Code of Ethics definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Ethics and Professionalism requires that iia code of ethics must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Ethics and Professionalism integrates iia code of ethics with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D17-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** IIA Code of Ethics — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Ethics and Professionalism, iia code of ethics is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

IIA Code of Ethics in Ethics and Professionalism requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D17-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Conflicts of interest — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing conflicts of interest within Ethics and Professionalism, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective conflicts of interest starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D17-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Confidentiality — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for confidentiality in Ethics and Professionalism is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Ethics and Professionalism.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D17-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Integrity — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Ethics and Professionalism, integrity is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Integrity in Ethics and Professionalism requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D17-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** IIA Code of Ethics — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing iia code of ethics within Ethics and Professionalism, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective iia code of ethics starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D17-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Conflicts of interest — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for conflicts of interest in Ethics and Professionalism is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Ethics and Professionalism.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D17-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Confidentiality — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Ethics and Professionalism, confidentiality is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Confidentiality in Ethics and Professionalism requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D17-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Integrity — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing integrity within Ethics and Professionalism, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective integrity starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D17-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** IIA Code of Ethics — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for iia code of ethics in Ethics and Professionalism is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Ethics and Professionalism.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D17-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Conflicts of interest — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Ethics and Professionalism, conflicts of interest is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Conflicts of interest in Ethics and Professionalism requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D17-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Confidentiality — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing confidentiality within Ethics and Professionalism, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective confidentiality starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D17-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** ethics-professionalism
- **Topic:** Integrity — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for integrity in Ethics and Professionalism is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Ethics and Professionalism.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D18-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Legal requirements definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Regulatory Compliance requires that legal requirements must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Regulatory Compliance integrates legal requirements with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D18-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Legal requirements — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Regulatory Compliance, legal requirements is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Legal requirements in Regulatory Compliance requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D18-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Policy compliance — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing policy compliance within Regulatory Compliance, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective policy compliance starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D18-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory change — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for regulatory change in Regulatory Compliance is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Regulatory Compliance.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D18-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Sanctions risk — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Regulatory Compliance, sanctions risk is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Sanctions risk in Regulatory Compliance requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D18-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Legal requirements — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing legal requirements within Regulatory Compliance, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective legal requirements starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D18-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Policy compliance — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for policy compliance in Regulatory Compliance is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Regulatory Compliance.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D18-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory change — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Regulatory Compliance, regulatory change is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Regulatory change in Regulatory Compliance requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D18-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Sanctions risk — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing sanctions risk within Regulatory Compliance, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective sanctions risk starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D18-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Legal requirements — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for legal requirements in Regulatory Compliance is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Regulatory Compliance.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D18-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Policy compliance — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Regulatory Compliance, policy compliance is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Policy compliance in Regulatory Compliance requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D18-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Regulatory change — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing regulatory change within Regulatory Compliance, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective regulatory change starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D18-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** regulatory-compliance
- **Topic:** Sanctions risk — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for sanctions risk in Regulatory Compliance is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Regulatory Compliance.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D19-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Inherent risk definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Risk Assessment Methodology requires that inherent risk must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Risk Assessment Methodology integrates inherent risk with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D19-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Inherent risk — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Risk Assessment Methodology, inherent risk is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Inherent risk in Risk Assessment Methodology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D19-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Residual risk — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing residual risk within Risk Assessment Methodology, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective residual risk starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D19-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk registers — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for risk registers in Risk Assessment Methodology is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Risk Assessment Methodology.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D19-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Heat maps — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Risk Assessment Methodology, heat maps is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Heat maps in Risk Assessment Methodology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D19-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Inherent risk — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing inherent risk within Risk Assessment Methodology, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective inherent risk starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D19-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Residual risk — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for residual risk in Risk Assessment Methodology is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Risk Assessment Methodology.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D19-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk registers — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Risk Assessment Methodology, risk registers is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Risk registers in Risk Assessment Methodology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D19-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Heat maps — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing heat maps within Risk Assessment Methodology, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective heat maps starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D19-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Inherent risk — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for inherent risk in Risk Assessment Methodology is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Risk Assessment Methodology.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D19-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Residual risk — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Risk Assessment Methodology, residual risk is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Residual risk in Risk Assessment Methodology requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D19-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Risk registers — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing risk registers within Risk Assessment Methodology, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective risk registers starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D19-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** risk-assessment-methodology
- **Topic:** Heat maps — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for heat maps in Risk Assessment Methodology is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Risk Assessment Methodology.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D20-Q001

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Rating scales definition
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: Audit Reporting and Follow-Up requires that rating scales must be ____.

### Choices

- A) supported by sufficient appropriate audit evidence
- B) based solely on management representations
- C) optional when schedules are tight
- D) excluded from the audit charter

**Correct answer:** A

### Explanation

Audit Reporting and Follow-Up integrates rating scales with professional standards and evidence requirements.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D20-Q002

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Rating scales — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Audit Reporting and Follow-Up, rating scales is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Rating scales in Audit Reporting and Follow-Up requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D20-Q003

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Management responses — fill-blank 1
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing management responses within Audit Reporting and Follow-Up, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective management responses starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D20-Q004

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Action tracking — fill-blank 1
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for action tracking in Audit Reporting and Follow-Up is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Audit Reporting and Follow-Up.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D20-Q005

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Closure criteria — fill-blank 1
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Audit Reporting and Follow-Up, closure criteria is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Closure criteria in Audit Reporting and Follow-Up requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D20-Q006

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Rating scales — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing rating scales within Audit Reporting and Follow-Up, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective rating scales starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D20-Q007

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Management responses — fill-blank 2
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for management responses in Audit Reporting and Follow-Up is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Audit Reporting and Follow-Up.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D20-Q008

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Action tracking — fill-blank 2
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Audit Reporting and Follow-Up, action tracking is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Action tracking in Audit Reporting and Follow-Up requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D20-Q009

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Closure criteria — fill-blank 2
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing closure criteria within Audit Reporting and Follow-Up, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective closure criteria starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D20-Q010

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Rating scales — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for rating scales in Audit Reporting and Follow-Up is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Audit Reporting and Follow-Up.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D20-Q011

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Management responses — fill-blank 3
- **Difficulty:** Medium
- **Review status:** accepted

### Stem

Fill in the blank: In Audit Reporting and Follow-Up, management responses is best supported by ____.

### Choices

- A) documented plans aligned with stakeholder needs
- B) undocumented verbal agreements only
- C) skipping change control
- D) ignoring governance requirements

**Correct answer:** A

### Explanation

Management responses in Audit Reporting and Follow-Up requires traceable planning, stakeholder alignment, and governance consistent with public project management practice.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D20-Q012

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Action tracking — fill-blank 3
- **Difficulty:** Hard
- **Review status:** accepted

### Stem

Fill in the blank: When executing action tracking within Audit Reporting and Follow-Up, the team should first ____.

### Choices

- A) confirm scope baseline and acceptance criteria
- B) begin work without a baseline
- C) defer stakeholder engagement
- D) skip risk identification

**Correct answer:** A

### Explanation

Effective action tracking starts with a validated baseline and clear acceptance criteria before execution.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

## CIA-FB-D20-Q013

- **Pack:** cia
- **Type:** question
- **Domain:** audit-reporting-followup
- **Topic:** Closure criteria — fill-blank 3
- **Difficulty:** Easy
- **Review status:** accepted

### Stem

Fill in the blank: A key performance indicator for closure criteria in Audit Reporting and Follow-Up is ____.

### Choices

- A) variance against planned targets with trend analysis
- B) activity counts without outcomes
- C) unverified self-reported status
- D) metrics unrelated to objectives

**Correct answer:** A

### Explanation

Outcome-oriented metrics with variance analysis support data-driven decisions in Audit Reporting and Follow-Up.

**References:** iia-standards: IIA International Standards for the Professional Practice of Internal Auditing (concept level)

### SME review

- **Reviewer name:** 
- **Reviewer role:** 
- **Comments:** 
- **Recommended action:** (approve | revise | reject | hold | retire)
- **Source adequacy:** 
- **Technical accuracy:** 
- **Clarity:** 
- **Disposition:** (accept | revise | reject | needs source verification)

---

