Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CIA Part 2 Master Guide

Updated 13 min read
Key takeaway

CIA Part 2 tests how candidates plan and perform an internal audit engagement.

  • The 2025 syllabus assigns 50% to Engagement Planning, 40% to Information Gathering, Analysis, and Evaluation, and 10% to Engagement Supervision and Communication.
  • The exam has 100 multiple-choice questions, 120 minutes, and a 600 scaled passing standard.
On this page16 sections
  1. What Part 2 covers
  2. Exam facts and score
  3. A repeatable engagement model
  4. Worked planning example: vendor changes
  5. Evidence and analysis
  6. Evaluate results without overclaiming
  7. Supervision and communication
  8. A focused study strategy
  9. Timing and exam-day method
  10. How Part 2 connects to the other CIA parts
  11. Final readiness check
  12. Assurance versus advisory work
  13. Using other assurance providers
  14. When plans must change
  15. A compact case review method
  16. How to use results to study efficiently

What Part 2 covers

CIA Part 2 is the Internal Audit Engagement exam. It tests the work that turns an audit mandate into a defensible conclusion: define the objective and scope, understand the area and its risks, identify controls, design procedures, obtain reliable evidence, evaluate results, supervise work, and communicate outcomes. It is not simply a test of memorized audit vocabulary. Candidates must select actions that fit the engagement facts and the internal auditor’s role.

The 2025 syllabus is the current blueprint. Its three domains are Engagement Planning at 50%, Information Gathering, Analysis, and Evaluation at 40%, and Engagement Supervision and Communication at 10%. This replaced the 2019 four-domain structure. The major practical implication is that planning receives half the emphasis; candidates should not spend most study time on testing techniques while treating objective, scope, risk assessment, work programs, and resources as preliminary paperwork.

Part 2 is one exam within the CIA certification program. Passing it alone does not award the CIA designation. Candidates must satisfy the other applicable exam parts and program requirements. Part 1 addresses internal audit fundamentals, Part 2 addresses engagement work, and Part 3 addresses internal audit function and organizational topics. The parts connect, but each has a distinct current syllabus.

Exam facts and score

The current Part 2 exam contains 100 multiple-choice questions and allows 120 minutes. That is an average of 72 seconds per item. Most questions require reading a short situation and identifying the strongest audit action, evidence source, or conclusion. Use the average as a pacing guide rather than forcing every item into an identical time box.

The passing standard is 600 on a scaled range of 250 to 750. The scale does not mean 80% correct, and the public standard does not supply a fixed raw-score conversion. A commercial practice percentage cannot be translated into an official scaled result. Use practice performance to identify weak domains, recurring reasoning errors, and timing problems.

The three weights are percentages of exam content, not a promise that a particular sitting contains an exact fixed count from each domain. It is useful to plan study effort roughly around the weights while still covering every topic. A candidate with experience in fieldwork may still need deliberate practice in planning and in the less familiar 2025 task structure.

A repeatable engagement model

Start with the objective. Ask what assurance or advisory question the engagement must answer and which organizational objective or risk makes it important. A vague objective such as “review purchasing” does not tell the auditor what conclusion is needed. A focused objective might ask whether emergency purchases are authorized, supported, and recorded accurately.

Set scope and criteria next. Scope defines the locations, systems, period, transactions, and boundaries examined. Criteria define the expected state: law, contract, policy, control design, approved risk tolerance, or another suitable benchmark. Without criteria, a finding can become an unsupported statement that something “should be better.” If a policy conflicts with a binding requirement, the auditor must identify the right hierarchy and communicate the conflict rather than quietly select a convenient standard.

Assess risk to identify where failure could most affect the objective. Learn the process through prior reports, policy, interviews, walkthroughs, data, and observation. Identify inherent exposure, existing controls, and residual risk. Prioritize areas where likelihood, impact, change, complexity, or known weaknesses justify deeper procedures. Then choose tests capable of producing evidence relevant to the objective.

A work program translates the plan into executable steps: population, sample or selection method, evidence to obtain, control attribute or assertion to test, period, responsible auditor, and documentation expected. It should be detailed enough to guide consistent work but adaptable if new information changes the risk picture. An auditor should not continue an obsolete test simply because it appears in the original program.

Worked planning example: vendor changes

A retailer has experienced several payment diversions after vendor bank details changed. The engagement objective is to assess whether changes are authorized, independently verified, and reflected accurately before payment. The auditor first maps the change process from request through master-file update and payment. Relevant criteria include internal policy, contractual requirements, and the organization’s own approval design.

The risk assessment identifies the bank-detail change as the high-risk point, especially when one employee can enter and approve a change. The audit plan includes a walkthrough, review of access rights, analysis of changes shortly before payment runs, and testing of a sample of changes for independent verification. A complete list of changes is obtained from the system rather than relying only on a manager-selected list.

If the population has a spike around a system migration, the auditor may stratify by before/after migration and focus additional testing on changed workflow. If records are incomplete, the limitation itself affects the conclusion and may require alternative evidence or scope communication. The auditor does not infer that a payment is fraudulent solely because the bank details changed; the evidence must establish which control failed and what exposure remains.

Evidence and analysis

Evidence should be relevant to the objective, reliable enough for the conclusion, and sufficient in quantity and coverage. Relevance asks whether information bears on the question. Reliability concerns its source and integrity. Sufficiency concerns whether the evidence supports a reasonable conclusion. A screenshot showing a current approval screen may be relevant to design but insufficient to establish that approvals occurred throughout the year.

Evidence from independent sources can strengthen a conclusion. A system log, bank confirmation, and approved change ticket may corroborate one another. Inquiry alone is weaker when it is the only support for a high-risk control. A walkthrough helps understand the process and identify where evidence can be collected; it is not automatically proof that the control operated consistently.

Analysis can include transaction testing, trend comparisons, ratio or variance analysis, workflow mapping, data extraction, and sampling. Select the technique based on the objective and data quality. A population summary can show unusual patterns, but a trend is a signal to investigate, not proof of cause. If a data extract is incomplete or uses the wrong date field, precise calculations can still produce a misleading result.

Evaluate results without overclaiming

Compare actual conditions with criteria. A finding normally explains the condition, expected criterion, cause when supportable, effect or risk, and a feasible action. Do not label every exception as a major deficiency. Consider the rate, value, nature, repetition, compensating controls, and whether the deviation is isolated or systemic.

Suppose 3 of 25 tested purchase orders lack documented competitive bids. Before concluding that the policy is broadly ineffective, verify the population and selection, investigate whether exceptions were permitted, assess whether evidence exists elsewhere, and determine whether the three share a cause. If policy permits emergency exceptions, test whether each item meets that criterion. The conclusion should match what the evidence establishes.

Recommendations should address the cause and help reduce risk, but management owns the response. Audit may discuss options and agree on an action owner and timeline. It should not design, approve, or operate management’s control in a way that compromises future assurance. A strong recommendation is clear enough to address the gap and flexible enough for management to choose an appropriate implementation.

Supervision and communication

Engagement supervision includes assigning work to people with suitable competence, explaining objectives and methods, reviewing workpapers, resolving questions, and ensuring the evidence supports conclusions. Review should be substantive. A supervisor should be able to trace the reported conclusion back to the objective, procedure, population, evidence, and analysis. A tick mark without a clear review trail does not demonstrate that the work was assessed.

Communication begins before the final report. Discuss objectives, scope, criteria, timing, and access with relevant stakeholders. Share emerging facts promptly when delay could allow loss or harm, while preserving fairness and confidentiality. Validate factual accuracy with the auditee and distinguish disagreement about facts from disagreement about risk or severity. Management’s disagreement does not automatically invalidate a supported finding.

The final communication should be accurate, objective, clear, concise, constructive, complete, and timely. It explains purpose, scope, conclusions, significant findings, and agreed actions or management responses as appropriate. If management accepts risk beyond its authority or the organization’s tolerance, the chief audit executive follows the proper escalation route. Internal audit does not silently assume that a risk has been resolved because a report was issued.

A focused study strategy

Use the 50/40/10 blueprint as a guide. Spend the largest share of study time on planning: objectives, scope, criteria, preliminary survey, risk assessment, work program, procedures, and resource needs. Spend nearly as much time on gathering and evaluating evidence. Review supervision and communication carefully even though they carry 10%, because these topics often determine the correct next step in a scenario.

For each practice item, write down the task being tested, the decisive fact, and why the chosen response is appropriate now. Then explain why each tempting alternative is premature, outside audit’s authority, or unsupported by evidence. If you miss a question, tag the underlying error: misread objective, confused design with operation, weak evidence judgment, sampling overclaim, ignored criteria, or management-ownership confusion.

Use mixed practice after studying individual topics. Real work connects planning to testing and reporting: a risk shapes scope, scope drives procedures, evidence affects conclusions, and findings shape communication. A set organized only by chapter can hide these transitions. Revisit missed scenarios after a delay and solve them without looking at the original rationale.

Timing and exam-day method

With 120 minutes for 100 items, maintain a pace near 72 seconds on average. Read the final question sentence first if that helps orient you, then read the facts for the objective, stage of work, constraint, and requested action. “Best next step” questions often reward sequencing: understand before testing, obtain evidence before concluding, disclose before deciding how an impairment is handled, and communicate significant issues through the proper route.

Do not overanalyze a familiar term when the question supplies a specific fact pattern. Eliminate choices that make management’s decision for it, promise certainty beyond the evidence, or skip an essential step. If two choices remain, choose the one that directly advances the objective with appropriate evidence and authority. Move on when further thought is unlikely to improve the answer, then use remaining time for flagged items if the exam interface allows review.

A wrong practice answer is valuable if it reveals a repeatable habit. For example, a candidate may always select “expand the sample” when one exception appears. That can be right, but only after validating the population, understanding the exception, and considering risk and sampling design. Train yourself to read the facts before applying a memorized response.

How Part 2 connects to the other CIA parts

Part 1 concepts appear in engagement scenarios. Objectivity affects who can perform work; independence affects whether the internal audit function can set scope and communicate. Governance, risk, control, and fraud concepts inform planning and evidence evaluation. Apply those ideas without turning Part 2 into a second Part 1 review.

Part 3 topics such as technology, cybersecurity, business processes, and organizational risk can arise as engagement context. The test is not asking every candidate to be a specialist in every industry. It expects the auditor to recognize relevant risks, plan work competently, use specialists or other assurance providers when appropriate, and avoid claims that exceed the evidence or expertise available.

Final readiness check

You are approaching readiness when you can move from a broad request to a clear objective, define boundaries and criteria, identify the most material risks and controls, select procedures that address those risks, evaluate evidence quality, and write a proportionate conclusion. You should also know when a scope limitation, skill gap, management disagreement, or significant risk requires escalation.

Do not measure readiness only by memorized definitions or a single practice score. Can you explain why the evidence is sufficient? Can you distinguish a control design gap from an operating lapse? Can you show how the sample supports or limits the conclusion? Can you state the recommendation without taking management ownership? Those are the behaviors the Part 2 blueprint asks candidates to apply.

Assurance versus advisory work

The engagement purpose affects objectives, scope, evidence, and communication. An assurance engagement gives an independent assessment against criteria. An advisory engagement helps a client improve a process, but management retains decisions and responsibility. A planning question may test whether the auditor has made that distinction before writing procedures.

Suppose operations asks audit to facilitate a workshop about reducing order delays. That can be advisory if internal audit helps identify risks and options while management chooses and owns changes. If audit selects a vendor, configures the workflow, and approves exceptions, it has crossed into management responsibility. A later assurance review may then raise an objectivity concern. Define the role at the outset and document boundaries.

Using other assurance providers

Coordination can reduce duplicated testing and leave important risks uncovered less often. Before relying on another provider, evaluate its independence or objectivity, competence, scope, methods, evidence quality, and reporting. A provider’s name or reputation alone does not prove the work is suitable for the engagement objective.

For example, an external security team may have tested vulnerability scanning but not user-access termination. Internal audit can use the work for the former question if its methods and evidence are adequate, then design separate procedures for termination controls. Document which work is relied upon, how reliance was assessed, what gaps remain, and how the combined coverage supports the audit conclusion.

When plans must change

Engagement plans are based on information available at the time. New facts can make an original procedure unnecessary or reveal a risk that deserves more work. A sound change is tied to the objective and documented with the reason, revised procedure, and effect on scope, schedule, or resources. A change made only to avoid an inconvenient finding is not a defensible risk response.

Imagine an audit of supplier onboarding discovers the business uses a separate urgent-payment route outside the system being tested. The team should understand the route, determine whether it falls within the objective and scope, assess its risk, and revise the work program if needed. If the change materially expands scope or affects timing, discuss it with the engagement client and obtain the appropriate approval rather than silently altering the assignment.

A compact case review method

When reviewing a practice case, create a four-line note: objective; decisive risk or fact; evidence needed; action supported now. For a question about a suspected duplicate reimbursement, the objective might be compliance with expense policy, the decisive fact may be duplicate amounts from one employee, evidence could include receipts and payment records, and the next action could be validate duplicates and test authorization.

Then ask what the evidence cannot establish. Duplicate amounts can result from a correction or split reimbursement, so they do not alone prove intentional fraud. This last step prevents overclaiming and helps identify the appropriate escalation if evidence raises a credible concern. Apply the method across objective selection, sampling, analysis, conclusions, and communication.

How to use results to study efficiently

Maintain a short error log rather than rewriting every explanation. Record the domain, missed judgment, and a corrective rule. “I selected a sample from a management-prepared list without verifying completeness” is more actionable than “review sampling.” “I concluded the control failed from missing documentation without asking whether evidence was stored elsewhere” identifies a specific evidence habit to change.

Revisit the log weekly and solve new examples of each error. Use mixed practice after focused study to strengthen transitions between planning and performance. If repeated misses cluster in planning, devote a study block to objectives, scope, criteria, risk, procedures, and resources. If misses cluster in evaluation, practice evidence reliability, alternative explanations, sample limitations, and conclusion wording.