Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CIA Part 1 2025 Syllabus and Domain Weights

Updated 8 min read
Key takeaway

The 2025 CIA Part 1 syllabus has four domains: Foundations of Internal Auditing 35%, Ethics and Professionalism 20%, Governance, Risk Management and Control 30%, and Fraud Risks 15%.

  • Independence and objectivity remain important, but they are integrated into current domains rather than presented as the old standalone domain.
On this page12 sections
  1. The current four-domain blueprint
  2. Domain I: Foundations of Internal Auditing, 35%
  3. Domain II: Ethics and Professionalism, 20%
  4. Domain III: Governance, Risk Management and Control, 30%
  5. Domain IV: Fraud Risks, 15%
  6. What changed from the prior syllabus
  7. Allocate study time with weights and gaps
  8. Integrated example
  9. How to study the outline
  10. Map learning objectives to observable decisions
  11. How an old question can still be useful
  12. Use weights as a starting point, not a ceiling

The current four-domain blueprint

The current CIA Part 1 syllabus, effective with the 2025 content structure, assigns 35% to Foundations of Internal Auditing, 20% to Ethics and Professionalism, 30% to Governance, Risk Management and Control, and 15% to Fraud Risks. These weights guide preparation priorities. They do not specify an exact question count for a particular sitting, and they do not make the smaller domains optional.

The syllabus is designed around core internal audit knowledge and judgment. Candidates should know not only what a standard or concept means, but how it affects planning, evidence, communication, and the relationship between internal audit and management.

Domain I: Foundations of Internal Auditing, 35%

Foundations is the largest domain. It covers the purpose and mandate of internal auditing, the Global Internal Audit Standards, the internal audit function’s governance and independence, and the nature of assurance and advisory services. Candidates should understand how the charter, board oversight, chief audit executive responsibilities, and organizational position support an effective function.

The domain asks candidates to distinguish internal audit from management, external audit, compliance, and other assurance providers. Internal audit evaluates governance, risk management, and control and offers objective insight. Management remains responsible for operations, risk responses, and controls. An internal auditor may advise but should not assume ownership of the activity being audited.

Function independence is a current Foundations topic. Consider how reporting lines, budget restrictions, scope interference, or access limitations affect the function’s ability to work and communicate. A question about the chief audit executive’s access to the board is different from a question about an individual auditor’s personal financial interest.

Domain II: Ethics and Professionalism, 20%

Ethics and Professionalism addresses the conduct and qualities expected of internal auditors. Candidates should understand integrity, objectivity, competence, due professional care, confidentiality, and professional skepticism as applicable under current IIA standards and ethics materials.

Objectivity belongs here at the individual level. An auditor’s prior responsibility for a process, close relationship with a process owner, financial interest, or personal bias may impair the ability to evaluate evidence fairly. Identify the threat, disclose it through the appropriate channel, and use safeguards such as reassignment or independent review when suitable.

Professionalism also includes recognizing competence limits and obtaining assistance rather than accepting work the auditor cannot perform effectively. Due care means considering the engagement’s purpose, complexity, risk, and evidence; it is not a guarantee that every error or fraud will be detected.

Domain III: Governance, Risk Management and Control, 30%

Governance concerns how the organization is directed, overseen, and held accountable. Risk management identifies and assesses uncertainty in relation to objectives and selects responses. Internal control implements policies, activities, and information that help manage risks. Candidates should understand the connection among these concepts and the role internal audit plays in evaluating them.

A governance weakness may arise when oversight is ineffective or responsibility is unclear. A risk-management weakness may arise when exposures are not identified, assessed, or monitored. A control weakness may involve poor design or failure in operation. A question may provide evidence in all three layers, so determine whether it asks for the root governance issue, the risk, or the control response.

Internal audit can assess whether controls are appropriately designed and operate effectively. It should not take over management’s control ownership. For example, audit can recommend stronger access reviews but should not become the operational approver of user access if that role would impair later assurance.

Domain IV: Fraud Risks, 15%

Fraud Risks covers the auditor’s understanding of fraud exposure, indicators, prevention and detection controls, and appropriate response. Candidates should distinguish intentional deception from error and understand that fraud risk can involve financial reporting, assets, corruption, or other improper benefit.

Auditors maintain awareness of fraud indicators relevant to an engagement, assess whether the organization has responses, and follow the approved escalation and investigation process. They are not presumed to be forensic investigators and cannot guarantee that fraud is absent. Suspected fraud requires sound evidence handling, documentation, consultation, and appropriate communication.

A red flag should prompt analysis, not a premature accusation. A missing approval could result from a control failure, an emergency exception, or intentional override. Corroborate the facts and consider who needs to know. Management has primary responsibility for prevention and detection; internal audit evaluates governance, risk management, and controls and may investigate when its mandate and competence support that role.

What changed from the prior syllabus

The older 2019 outline presented Independence and Objectivity as a standalone domain. The 2025 syllabus integrates function-level independence in Foundations of Internal Auditing and individual objectivity in Ethics and Professionalism. Candidates should continue to study both concepts, but should not use the old domain weight or describe it as a current separate section.

This distinction matters when using old prep books, question banks, or notes. Map a legacy independence question to the appropriate current domain and verify whether its terminology reflects the 2024 Global Internal Audit Standards, effective January 9, 2025. A prior question may test a still-valid principle but use an outdated framework or category.

Allocate study time with weights and gaps

A candidate with 100 study hours could use the weights as an initial guide: 35 hours Foundations, 20 Ethics, 30 Governance/Risk/Control, and 15 Fraud. This is not a required distribution. If you already know audit planning but struggle with governance frameworks, rebalance while keeping some review for each domain.

Start with a diagnostic and map each miss to a syllabus objective. Review foundational concepts, then solve scenario questions that mix standards and responsibilities. A candidate may know a definition but still select the wrong response because the question asks for the next step, not a theoretical principle.

Integrated example

An internal audit team is asked to review a procurement process. A senior auditor previously managed procurement, the chief audit executive is told to remove supplier concentration from scope, and the team finds an unexplained vendor payment. The facts touch multiple domains: prior operational responsibility may affect individual objectivity; interference with scope may threaten function independence; supplier concentration is a risk-management issue; and the unexplained payment is a potential fraud indicator.

A complete response does not collapse the issues into one label. The team should disclose and address the senior auditor’s impairment, document and escalate scope interference through governance channels, assess the procurement risk, and follow the organization’s evidence and suspected-fraud protocols for the payment. Management still owns procurement controls. This integrated view reflects the current four-domain blueprint.

How to study the outline

Study each domain in three layers: core concept, professional responsibility, and scenario application. For every concept, write one example and one boundary. For instance, internal audit evaluates controls but does not own them; a fraud red flag warrants follow-up but is not proof; individual objectivity and function independence are related but distinct.

Use the 2025 syllabus as your checklist and the Global Internal Audit Standards as the source for current professional concepts. Practice original scenarios and explain why each distractor is weaker. This method builds transferable judgment and prevents overreliance on an outdated domain map.

Map learning objectives to observable decisions

For each syllabus objective, ask what an auditor would actually observe or decide. A standard about independence may require recognizing a restriction on scope and reporting it to the proper governance level. An objectivity objective may require disclosing a prior operational role and arranging an impartial review. A control objective may require testing whether an approval was authorized and evidenced. This approach turns domain labels into practical judgment.

Use paired examples to avoid collapsing concepts. If the chief audit executive cannot communicate a finding to the board because management blocks the report, consider function independence. If an auditor reviews a process the auditor recently managed, consider individual objectivity. Both issues can arise in one engagement, but the remedy must address the specific impairment.

For fraud, map risk indicator, control response, and auditor action separately. A vendor address shared with an employee may be a red flag. A vendor-validation control may be preventive. Internal audit may test that control and preserve evidence of a suspected issue. Management retains responsibility for vendor oversight and corrective action unless a separate mandate assigns investigation work to audit.

How an old question can still be useful

A prior-edition question may test a principle that remains relevant, such as independence, objectivity, or due care. Before using it, identify the concept and map it to the 2025 domain. Do not reuse an old standalone independence percentage or assume that every standard reference matches the 2024 Global Internal Audit Standards. The current structure and effective date matter.

If a legacy item presents the chief audit executive reporting to management with limited board access, map the question to function-level independence in Foundations. If it describes an auditor evaluating a process the auditor previously owned, map it to individual objectivity in Ethics and Professionalism. The underlying distinction remains useful even when the older book’s section label is retired.

Use weights as a starting point, not a ceiling

The 35%, 30%, 20%, and 15% shares are useful for planning, but they are not an instruction to stop studying a domain once its allocated hours are spent. A candidate who is weak in Fraud Risks may need more than 15% of study time to reach a sound level. Continue to maintain stronger Foundations knowledge through mixed practice while repairing the weaker area.