CIA Part 1 Practice Questions: Objectivity and Control Scenarios
Use these original questions to practice CIA Part 1 judgment.
- They are not copied from secure IIA exams.
- Work each scenario before reading the answer, then explain why the strongest distractor fails and which responsibility or evidence distinction controls the decision.
On this page10 sections
- Original scenario practice
- How to use the questions
- A repeatable reasoning method
- Question 1 reasoning: a past operational role
- Question 2 reasoning: advising versus operating
- Question 3 reasoning: control weakness versus fraud
- Question 4 reasoning: function-level independence
- Turn practice into learning
- Why the distractors are tempting
- Build another scenario from your own work
Original scenario practice
An internal auditor is assigned to review a payroll process that the auditor supervised six months ago. The auditor believes they can be fair because the process is now managed by someone else. What is the best response?
- Proceed without disclosure because the auditor no longer supervises payroll.
- Disclose the prior responsibility and have the chief audit executive assess and address the potential objectivity impairment, such as through reassignment or independent review.
- Ask payroll management to approve the auditor’s findings before they are reported.
- Remove payroll from the audit plan permanently.
A business unit asks internal audit to approve all new vendor records for the next quarter because the unit is short-staffed. The audit team is scheduled to review vendor controls next year. What should the chief audit executive do?
- Accept the approval role because the request is temporary.
- Clarify that management owns vendor approval, explain the independence concern, and recommend that management assign an appropriate control owner.
- Approve only high-risk vendors and audit the rest later.
- Cancel the future audit so the team can perform the approvals without conflict.
During an audit, an auditor finds three purchase orders without evidence of approval. The process owner says the approvals occurred verbally but cannot identify who gave them. What is the most appropriate next step?
- Conclude that the purchasing manager committed fraud.
- Document the evidence, determine the scope and risk of the exceptions, seek corroboration, and discuss the control weakness through the engagement process.
- Ignore the exceptions because the purchases were delivered.
- Approve the purchases retroactively on behalf of the process owner.
Senior management instructs the chief audit executive to remove a high-risk procurement project from the audit plan because the project is politically sensitive. The board has approved the audit charter and risk-based plan. What is the strongest response?
- Remove the project without documenting the instruction.
- Document and discuss the restriction with senior management, then communicate unresolved interference to the board or appropriate governing body.
- Ask the procurement manager to decide whether the audit should proceed.
- Proceed secretly without informing management or the board.
How to use the questions
These questions are original practice material written for this guide. They do not reproduce secure IIA exam items or claim to match the live test interface. Work without notes, select an answer, and write a sentence explaining the controlling fact. Then read the rationale and identify why the closest distractor fails.
The scenarios focus on concepts that can be confused: individual objectivity, management control ownership, evidence of a control failure, and function independence. The current 2025 CIA Part 1 syllabus includes these ideas across Foundations, Ethics and Professionalism, Governance/Risk/Control, and Fraud Risks.
A repeatable reasoning method
First identify the actor: an individual auditor, the chief audit executive, management, or the board. Next classify the issue: personal objectivity, function independence, control design or operation, or fraud risk. Then determine what the evidence establishes and choose a proportionate next step. This sequence prevents the candidate from jumping from a concerning fact to a conclusion the evidence does not support.
The best answer often preserves the internal audit role while addressing the risk. Auditors can evaluate and advise; management operates controls and accepts risk. A professional response should be timely, documented, and communicated through the appropriate channel.
Question 1 reasoning: a past operational role
Prior responsibility can affect objectivity even after the employee leaves the role. The relevant question is not whether the auditor personally believes they are fair, but whether the prior role could impair or appear to impair impartial judgment. Disclosure and a safeguard let the chief audit executive respond transparently.
A practice variation: if the auditor only received general training on the payroll system and never made decisions or supervised the process, the impairment analysis may be different. The candidate should use facts about actual responsibility, recency, and influence rather than treating every contact with a process as disqualifying.
Question 2 reasoning: advising versus operating
Internal audit may provide advice on vendor controls, but operating vendor approval creates a management responsibility. If the audit team performs the approval and later evaluates whether approval controls worked, it may be evaluating its own decisions. Management should appoint an appropriate operational owner, while audit can offer nonbinding advice or later provide assurance.
The temporary nature of the request does not remove the risk. A short-term task can still affect evidence, accountability, and future audit independence. The chief audit executive should document the discussion and use safeguards if any advisory work proceeds.
Question 3 reasoning: control weakness versus fraud
The missing evidence means the auditor cannot verify that approvals occurred according to the control design. That is enough to document and assess a control exception. It is not enough to accuse the purchasing manager of fraud. Further tests might examine approval logs, delegation records, purchase thresholds, vendor receipt, and whether similar exceptions appear elsewhere.
A good finding describes condition, criteria, cause, effect, and evidence as appropriate. The auditor should avoid writing that approvals never happened if the evidence only shows that documentation is missing. Precise wording protects credibility and helps management correct the underlying process.
Question 4 reasoning: function-level independence
When management restricts scope, the chief audit executive should not quietly accept a limitation that prevents coverage of a material risk. The issue is organizational interference, not necessarily a personal conflict. The chief audit executive should seek resolution and use the reporting route established by governance arrangements.
The exact sequence depends on the charter and Standards, but the scenario gives a board-approved plan and a direct instruction to omit a sensitive project. Documenting and reporting unresolved scope interference protects the function’s ability to fulfill its mandate. Secretly proceeding creates additional governance and communication risks.
Turn practice into learning
After completing the set, mark each answer as confident, uncertain, or guessed. Review uncertain correct answers as carefully as wrong ones. If you missed Question 1, study the difference between independence and objectivity. If you missed Question 2, review management ownership of controls. If you missed Question 3, practice describing the limits of evidence. If you missed Question 4, review function independence and governance escalation.
Then wait a day and explain the answer logic without looking. If you can recall only the letter, you have not yet learned the concept. Solve new scenarios with changed facts to test whether the principle transfers.
Why the distractors are tempting
These scenarios use plausible distractors because the exam tests judgment, not just recognition. In Question 1, the auditor’s confidence in personal fairness is tempting but does not replace disclosure and independent assessment. In Question 2, taking over approval appears helpful during a staffing shortage, yet it compromises management ownership and may affect future assurance.
In Question 3, delivered goods can make the missing authorization seem harmless. The control objective still matters: evidence of timely approval helps ensure purchases are authorized. A later review might reduce risk but does not prove the original control operated. In Question 4, secrecy or unilateral action seems decisive, but the chief audit executive should use governance channels and document scope interference.
When you review any question, state the fact that defeats the strongest wrong option. If you cannot articulate that distinction, mark the topic for another practice set. This method turns answer explanations into a repeatable decision skill.
Build another scenario from your own work
Choose a process you know, such as access administration, procurement, expense approval, or inventory. Write a fictional control objective, one observed exception, and four possible auditor actions. Make one option too passive, one too aggressive, one that takes over management’s role, and one proportionate response based on evidence. Explain the rationale and then map the concept to the current 2025 syllabus domain.