CIA Part 1 Master Guide
CIA Part 1, Internal Audit Fundamentals, has 125 multiple-choice questions in 150 minutes and uses the 2025 syllabus: Foundations of Internal Auditing 35%, Ethics and Professionalism 20%, Governance, Risk Management and Control 30%, and Fraud Risks 15%.
- The passing standard is 600 on a 250-to-750 scaled score.
On this page18 sections
- What CIA Part 1 measures
- The current syllabus and weights
- Exam format and scoring
- The internal auditor’s role
- Independence and objectivity in the current framework
- Ethics and professionalism
- Governance, risk management, and control
- Fraud risks and auditor responsibility
- A practical 12-week preparation sequence
- How to answer scenario questions
- Readiness and study strategy
- Certification and exam planning
- A balanced approach to this exam
- How to study current internal audit standards
- An integrated audit scenario
- How to choose the best answer
- Example: objectivity safeguards
- Keep the credential pathway visible
What CIA Part 1 measures
CIA Part 1 is titled Internal Audit Fundamentals. It assesses the knowledge and judgment used to understand internal auditing, apply professional ethics, reason about governance, risk and control, and respond appropriately to fraud risks. The exam is not simply a vocabulary test. Questions often describe a workplace situation and ask what an internal auditor should do, what a control is designed to accomplish, or which step best aligns with professional standards.
This part is also used for the Internal Audit Practitioner (IAP) credential. Passing CIA Part 1 alone does not earn the full Certified Internal Auditor designation. The CIA certification requires additional program, exam, education, and experience requirements. Candidates should separate the exam result from the credential outcome and confirm which designation they are pursuing.
The current syllabus and weights
The 2025 CIA Part 1 syllabus has four domains: Foundations of Internal Auditing at 35%; Ethics and Professionalism at 20%; Governance, Risk Management and Control at 30%; and Fraud Risks at 15%. Foundations is the largest area, with internal audit purpose, mandate, independence, standards, and assurance and advisory work. Ethics covers the professional conduct expected of internal auditors. Governance, risk, and control asks candidates to understand how those systems relate and how internal audit evaluates them. Fraud Risks examines fraud exposure, red flags, controls, and the auditor’s responsibility.
The 2025 syllabus reorganized material compared with the prior 2019 outline. Independence and objectivity are not a separate standalone domain with its former weight. Function-level independence is integrated into Foundations, while an individual auditor’s objectivity appears within Ethics and Professionalism. The concepts remain important; candidates should study them in their current locations rather than using the retired four-domain outline.
Exam format and scoring
The current CIA Part 1 exam consists of 125 multiple-choice questions and has a 150-minute time limit. The official passing score is 600 on a scaled range of 250 to 750. A scaled result is not a raw percentage. Candidates should not infer that a score of 600 means a certain number or percentage of correct answers, because IIA does not publish a stable raw-score conversion for that purpose.
A candidate should practice questions under time conditions, but a commercial bank percentage is a diagnostic rather than an official score prediction. Track whether you can apply concepts, eliminate tempting distractors, and maintain accuracy across the four domains. If you miss a question, identify whether the problem was knowledge, reading, applying a standard, or distinguishing the auditor’s role from management’s responsibility.
The internal auditor’s role
Internal auditors provide independent and objective assurance and advice designed to add value and improve an organization’s operations. Their work may examine governance, risk management, control, compliance, and process effectiveness. The auditor gathers evidence, evaluates it against criteria, communicates findings, and follows up on agreed actions. Management owns the organization’s risks and controls; internal audit evaluates and provides insight rather than taking over those responsibilities.
That boundary drives many exam questions. If a control is weak, the auditor may explain the risk and recommend options, but the process owner remains responsible for choosing and operating the control. If management asks internal audit to approve a transaction or make an operational decision, the auditor should consider whether that role would impair independence or objectivity. The right response depends on safeguards and governance arrangements, not on a simplistic claim that auditors can never advise.
Independence and objectivity in the current framework
Independence concerns the internal audit function’s ability to fulfill its responsibilities without interference. The board or an appropriate governing body provides oversight of the function, approves the mandate and charter, and supports direct access and reporting arrangements. Organizational placement and restrictions can affect the function’s ability to select scope, perform work, and communicate results.
Objectivity concerns an individual auditor’s impartial attitude and avoidance of conflicts or bias. An auditor may be technically independent at the department level yet personally lack objectivity because of a financial interest, prior responsibility, close relationship, or pressure from a manager. Conversely, an individual may be impartial while the function faces organizational interference. Identify which level the scenario describes and choose a safeguard or escalation that fits.
The 2025 syllabus includes both ideas but does not treat them as one old standalone weighted domain. Candidates should learn the distinction, the current Standards’ principles, and how an impairment is disclosed and addressed. A manager’s request to remove an inconvenient finding can threaten the function’s ability to report; auditing a process the auditor recently managed can threaten personal objectivity.
Ethics and professionalism
The Ethics and Professionalism domain asks how an internal auditor behaves when handling information, performing work, communicating, and facing pressure. Competence means applying suitable knowledge and skill, recognizing limits, and obtaining help where needed. Due professional care requires a thoughtful assessment of significance, risk, and evidence; it does not promise that every engagement will find every issue. Confidentiality requires care with information and authorized use, while integrity and professional courage support truthful communication.
A question may present a manager who wants a finding softened, a colleague who shares confidential data casually, or an auditor asked to work outside their competence. Focus on the professional obligation and a proportionate response. Clarify facts, document relevant decisions, consult appropriate policy or supervision, and escalate where necessary. Do not jump to public disclosure or resigning when a normal professional channel can address the concern.
Governance, risk management, and control
Governance provides oversight, direction, accountability, and monitoring. Risk management identifies and assesses uncertainty that could affect objectives, then selects responses and monitors residual exposure. Internal control consists of policies, procedures, activities, and information that help manage risks and achieve objectives. These concepts connect: governance sets expectations, risk management prioritizes threats and opportunities, and controls implement responses.
Internal audit evaluates whether governance, risk management, and control are designed and operating effectively. It does not own the processes it audits. For example, management may own access approvals; internal audit can test whether approvals are timely, authorized, and evidenced. If exceptions appear, audit reports the cause and impact, discusses corrective options, and follows up.
A control is not automatically effective because it exists on paper. A policy may be well written but bypassed in practice. A detective control may identify an error without preventing it, which may still be appropriate if the risk is monitored and corrected. Questions often turn on whether a control is preventive, detective, or corrective, who owns it, and what evidence shows it operated.
Fraud risks and auditor responsibility
Fraud involves intentional deception or concealment for an improper benefit. Fraud risk can include asset misappropriation, corruption, or fraudulent reporting. Internal auditors should understand fraud risks relevant to their work, remain alert to indicators, and evaluate whether controls address identified exposure. They are not automatically responsible for conducting a forensic investigation or guaranteeing that fraud does not exist.
A red flag is a reason to investigate and assess, not proof. Unusual journal entries, override of approvals, unexplained vendor relationships, pressure to meet a target, or missing documentation may warrant corroboration. The auditor should preserve evidence, follow methodology, consult appropriate specialists, and communicate through authorized channels. Avoid accusing a person based on a single anomaly or confronting a suspected subject in a way that could compromise evidence.
Management is primarily responsible for preventing and detecting fraud through governance and control. Internal audit may assess the design and operation of those responses and investigate within its mandate and competence. The proper action depends on the engagement scope, evidence, and escalation protocol.
A practical 12-week preparation sequence
A 12-week plan is a planning model rather than an IIA requirement. Begin with the syllabus and a baseline quiz, then spend time on Foundations, Governance/Risk/Control, Ethics, and Fraud in proportion to their weights and your gaps. Foundations at 35% and Governance/Risk/Control at 30% deserve substantial practice. Maintain ethics and fraud review throughout instead of leaving them to the last week.
In the early weeks, learn terminology and the current standards concepts. In the middle weeks, solve scenario questions and explain why the best response fits the auditor’s role. In the final weeks, use mixed timed sets, review weak objectives, and revisit guessed answers. A candidate studying fewer hours per week can extend the plan; a candidate with current internal audit experience may shorten foundational refresh but should still cover the full syllabus.
How to answer scenario questions
Read the requirement before the scenario details when the item is long. Identify the actor, the responsibility, and the level of the issue: function independence, individual objectivity, management control ownership, governance oversight, or fraud response. Then locate the fact that changes the answer, such as a recent operational role, pressure to alter scope, missing evidence, or a control owner’s responsibility.
Prefer the response that is professional, evidence-based, proportionate, and consistent with the auditor’s role. Distractors may be too passive, too aggressive, or may assume internal audit should operate the process. The best answer often starts with clarification and documentation, then uses the appropriate reporting or escalation route. Do not confuse being objective with refusing to provide any advice.
Readiness and study strategy
Use a domain tracker with the four current weights. For each objective, label your confidence as strong, developing, or weak and attach evidence from practice. A topic is not strong merely because it sounds familiar. Test it with new scenarios and explain your reasoning without notes. A question bank should help you diagnose learning, not become a substitute for understanding the standards.
As a personal readiness check, complete mixed practice under the full 150-minute limit and review wrong and guessed items. Look for consistent application across domains, not just a high score on a familiar topic. If you repeatedly confuse assurance with management responsibility, or independence with objectivity, focus on those distinctions using paired examples.
Certification and exam planning
Candidates may need to meet education, experience, character, and program requirements in addition to passing exams, depending on the CIA pathway and applicable candidate category. Part 1 alone is not the full CIA designation. Review the current official pathway that applies to your education and work background before assuming that one qualification route covers another.
The exam plan should reflect the credential you want. If your immediate goal is Internal Audit Practitioner, Part 1 may be the relevant exam. If you are pursuing the CIA, plan for all parts and the certification requirements. In either case, keep registration, testing authorization, and appointment scheduling distinct, and use the current IIA process for deadlines and fees.
A balanced approach to this exam
A strong candidate combines technical knowledge with professional restraint. Know the purpose of internal audit, understand the governance relationship, distinguish management’s role from assurance, apply ethical principles, and respond carefully to possible fraud. Many items reward disciplined judgment rather than a dramatic action.
The 2025 syllabus is the foundation for your preparation. Use its domain weights to allocate time, the Global Internal Audit Standards to understand current professional expectations, and original scenario practice to make the ideas operational. The result is preparation that transfers beyond memorizing a prior syllabus or a list of answer patterns.
How to study current internal audit standards
Read the 2024 Global Internal Audit Standards with the exam’s 2025 syllabus beside you. The syllabus determines the tested Part 1 domains, while the Standards explain the profession’s current principles and requirements. Do not assume every detail of a legacy prep book remains current. Check whether it describes the 2019 syllabus, older Standards, or a retired independence domain. Preserve valid concepts, but map them to the present structure.
As you study, build a comparison chart for independence and objectivity. For independence, record who oversees the function, what reporting access is needed, and how interference with scope or resources is handled. For objectivity, record how a personal relationship, prior responsibility, bias, or financial interest can affect one auditor’s judgment. Add one example of a safeguard for each. This contrast prevents confusing an organizational condition with an individual impairment.
For governance, risk, and control, use a three-column model: governance provides direction and oversight; risk management identifies and responds to uncertainty; controls carry out or monitor a response. When a question describes an ineffective approval, ask whether the underlying problem is unclear oversight, poor risk assessment, weak control design, or failure to operate a sound control. The correct answer often depends on that distinction.
Fraud study should connect indicators with action. Learn common risk factors and control concepts, but do not memorize a red-flag list as proof of fraud. A missing document, unusual payment, or management override calls for corroboration, documentation, and the appropriate escalation process. Understand the audit team’s mandate and competence; the exam does not make every internal auditor a forensic investigator.
An integrated audit scenario
A company has experienced repeated emergency payments to new vendors. Internal audit is assigned to review procurement. The engagement team finds that vendor records are created by one employee, approvals are sometimes missing, and senior management has asked the chief audit executive not to examine a politically sensitive supplier. Each fact points to a different audit issue. The new-vendor pattern creates fraud and control risk; separation of vendor setup and payment approval is a control-design issue; the request to omit a supplier may interfere with the function’s scope.
The auditor should gather and corroborate evidence, determine the risk and control implications, and follow the engagement and suspected-fraud protocols. The chief audit executive should address scope interference through the appropriate governance channel. Management remains responsible for procurement controls and vendor decisions. Internal audit should neither accuse a named employee based only on an indicator nor quietly omit a material risk because a manager requests it. This scenario integrates Foundations, Ethics, Governance/Risk/Control, and Fraud Risks.
How to choose the best answer
Many candidates know the principle but miss the sequence. If the scenario is incomplete, first obtain facts and clarify responsibility. If a conflict or impairment is already clear, disclose and address it rather than waiting for harm. If evidence indicates possible fraud, preserve it and use approved reporting channels rather than conducting an improvised confrontation. The exam’s “best” action is usually the sound next step, not every action that may eventually be needed.
Review the exact verbs in the question. “Primary responsibility” often distinguishes management from internal audit. “Most appropriate next step” asks for sequence. “Best evidence” asks for support, not an opinion. “Most likely impact” asks for inference limited to the facts. A careful read prevents answering a broader question than the one presented.
Example: objectivity safeguards
An auditor is assigned to review a payroll system that the auditor helped select and configure during the prior year. The auditor may know the system well, but prior involvement creates a potential objectivity impairment. The chief audit executive should assess the circumstances and disclose the issue as required, then assign an independent reviewer or reassign the work where appropriate. Expertise does not erase a conflict; disclosure and safeguards protect the credibility of the conclusion.
Keep the credential pathway visible
Before booking a later CIA part, confirm how your Part 1 pass fits the pathway and its validity rules. Maintaining a simple record of exam dates, education documents, experience, and application status avoids treating the first pass as the end of certification.