Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

CIA Part 2 2025 Syllabus

Updated 9 min read
Key takeaway

The 2025 CIA Part 2 syllabus has three domains: Engagement Planning (50%), Information Gathering, Analysis, and Evaluation (40%), and Engagement Supervision and Communication (10%).

  • It replaces the prior four-domain 2019 structure and emphasizes defining the engagement and building evidence-based conclusions.
On this page11 sections
  1. The current blueprint
  2. Domain A: Engagement Planning, 50%
  3. Domain B: Gathering, analysis, and evaluation, 40%
  4. Domain C: Supervision and Communication, 10%
  5. How to translate task statements into study
  6. Worked scenario across domains
  7. Common syllabus mistakes
  8. Preparation checklist
  9. Planning a test that answers the question
  10. Documenting the logic chain
  11. Study distinctions that drive correct answers

The current blueprint

The 2025 CIA Part 2 syllabus is titled Internal Audit Engagement and contains three domains. Engagement Planning carries 50%; Information Gathering, Analysis, and Evaluation carries 40%; Engagement Supervision and Communication carries 10%. It applies to the current Part 2 exam and replaced the prior 2019 four-domain structure.

The change matters for preparation. Older summaries may describe Managing the Internal Audit Activity, Planning the Engagement, Performing the Engagement, and Communicating Engagement Results and Monitoring Progress with different weights. Those old labels and percentages are not the current Part 2 blueprint. Use the current three domains when planning study time and reviewing a question’s subject.

Domain A: Engagement Planning, 50%

Planning begins by determining engagement objectives and scope. Objectives state what the engagement will answer; scope defines boundaries such as processes, locations, systems, transactions, and period. Consider organizational objectives, strategy, regulatory requirements, risk appetite and tolerance, policies, prior findings, other assurance work, and whether the service is assurance or advisory. Select relevant criteria so conclusions have a defensible benchmark.

The auditor develops an understanding of the area through preliminary information gathering: review prior reports and available data, interview people who understand the process, observe operations, and conduct walkthroughs. A walkthrough follows a transaction or event through the process to identify handoffs, systems, decision points, and evidence. It is a way to understand and plan, not proof that controls operated consistently during the period.

Risk assessment identifies and prioritizes the risks relevant to the objective. Assess inherent exposure, the design and operation of controls, and residual risk. Consider magnitude, likelihood, complexity, recent changes, known incidents, process dependencies, and control concentration. A risk-and-control matrix can link objectives, risks, controls, tests, and responsible owners. Avoid treating the matrix as a substitute for judgment; stale or copied risks should be validated against the actual process.

The engagement work program translates the plan into procedures. Determine which tests evaluate control design and which evaluate operating effectiveness; define the population, evidence, time period, selection approach, sample attributes, and documentation. Plan resources to match the work, including staff competence, budget, time, data access, and technology. If required skills are unavailable, seek training, a qualified specialist, or another support arrangement before making a commitment the team cannot meet.

Domain B: Gathering, analysis, and evaluation, 40%

Information gathering includes reviewing relevant documents and data, conducting interviews and walkthroughs, observing activities, developing checklists or risk-and-control questionnaires, and using appropriate sampling. The method should match the question. Interviews can explain how a process is intended to work; observation shows activity at a point in time; records and system logs can establish specific transactions or events. No one source answers every question.

Sampling may be statistical or nonstatistical and may be random, judgmental, discovery-oriented, or otherwise appropriate to the objective. A sample supports an inference only when the population, selection method, test, and evaluation are understood. If the auditor selects only unusual transactions, the selection can identify exceptions but may not estimate a population-wide error rate. Do not present a judgmental selection as if it were a statistically representative sample.

Evidence evaluation asks whether information is relevant, reliable, and sufficient. Relevance means it addresses the objective or assertion. Reliability depends on source, control over creation, independence, and integrity. Sufficiency asks whether the quantity and coverage permit a reasonable conclusion. A signed checklist might show that a review was documented; the underlying records and evidence of review may be needed to establish what was examined and whether exceptions were resolved.

Analysis can use data extraction, mining, continuous monitoring, workflow maps, ratio and variance analysis, trend analysis, benchmarking, and other reasonableness tests. The auditor checks data completeness and definitions before interpreting outputs. A monthly variance may reflect seasonality, a reclassification, or a genuine process issue. Analytical procedures identify relationships and unusual patterns; follow-up evidence determines the cause.

Workpapers document relevant information, procedures performed, evidence, analysis, review, and the reasoning that supports conclusions. A workpaper should let a competent reviewer understand what was tested, what was found, and how the auditor got from evidence to result. Clear documentation records exceptions, limitations, contradictory information, sample basis, and why alternative explanations were accepted or rejected.

Domain C: Supervision and Communication, 10%

Engagement supervision coordinates assignments, reviews workpapers, evaluates whether procedures address objectives, and resolves performance or evidence gaps. Review is not a formality. If the population is incomplete or the workpaper lacks a link between a test and a conclusion, the supervisor should require correction or additional work before relying on it.

Communication covers preliminary coordination with engagement clients, ongoing updates, and reporting results. Clarify objectives, scope, criteria, timing, information needs, and responsibilities. Share significant facts in time for responsible people to respond and address urgent risks. The final communication should present accurate and supported conclusions, significant findings, recommendations or agreed action plans, and relevant management responses.

The chief audit executive may need to communicate acceptance of risk when management accepts exposure that exceeds the organization’s tolerance or management’s authority. Engagement auditors should elevate significant concerns through the established process, not settle them privately. Audit does not own the risk response or operate the remediation control.

How to translate task statements into study

Build a study map with three columns: domain, tasks, and a worked decision. For “determine objectives and scope,” write a scenario where a broad request needs boundaries and criteria. For “apply appropriate sampling,” write a population, selection method, and intended inference. For “evaluate evidence,” compare a manager interview with system evidence and identify what each can support.

Practice linked cases. Begin with planning a review, then reveal test results, an exception, a data limitation, and management’s response. At each stage, decide whether to revise the risk assessment, work program, sample, conclusion, or communication. This method reflects that engagement work is iterative: new evidence may change a plan, but a change should be explained and documented.

Use the stated weights to allocate time, not to omit the smaller domain. A candidate who knows testing but not how to set a relevant objective may collect large amounts of irrelevant evidence. A candidate who plans well but cannot evaluate reliability may draw a conclusion from unsupported inquiry. The domains form a chain.

Worked scenario across domains

A hospital wants assurance that user access to a medication system is appropriate. The objective is to determine whether access is authorized, periodically reviewed, and removed when no longer needed. Scope covers selected facilities, relevant user roles, and a defined period. Criteria include approved policy, role assignments, and applicable requirements. The planning phase identifies privileged access, staff transfers, contractors, and emergency accounts as higher-risk categories.

The work program includes a population completeness test against HR and contractor records, a sample of access additions and removals, review of periodic recertifications, and analysis of privileged accounts. The auditor obtains system extracts, validates fields and dates, inspects approvals, and corroborates selected terminations against access logs. If the extract omits a facility, the sample cannot support a conclusion about the whole organization.

A few approvals are missing. The auditor determines whether approvals exist in another approved system, whether access was nevertheless appropriate, and whether the exception recurs in one facility or role. The conclusion describes the control failure and residual risk proportionately. The supervisor reviews the evidence trail. The report communicates the condition, policy criterion, risk, and action management chooses, while internal audit retains responsibility for independent evaluation.

Common syllabus mistakes

The first mistake is using old weights. Always distinguish the 2025 three-domain outline from the former four-domain version. The second is treating all questions as fieldwork. Half the current content concerns planning. The third is confusing obtaining information with evaluating it: more data do not make evidence better if the source is incomplete or irrelevant.

Another mistake is using “sample” as if it guaranteed statistical inference. Selection and objective matter. A targeted selection can identify a known risk but usually cannot justify a precise population error rate. Similarly, a walkthrough can reveal design and process paths but cannot establish an entire year of consistent operation.

Finally, candidates may focus on a defect and ignore the objective. A control can be imperfect without being material to the engagement question. Explain how the fact affects the stated objective, risk, or criterion before determining significance.

Preparation checklist

Memorize the three weights, then test your understanding by teaching the engagement sequence aloud: objective, scope, criteria, risk assessment, procedures and resources, evidence, analysis, conclusion, supervision, communication. For each step, name a common failure and a corrective action.

Use new examples rather than memorizing answers. A good practice set includes incomplete data, competing evidence, a weak criterion, a design gap, an operating exception, a sampling limitation, a specialist need, and a management disagreement. For each, state the strongest next step and why it fits the auditor’s authority and the engagement stage.

Planning a test that answers the question

A procedure is useful only when it connects to an objective and risk. Suppose the objective is to determine whether new employees receive required system access only after approval. A design review can determine whether policy and system workflow require approval. Operating tests can examine additions during the audit period, match them to authorized requests, and verify that the access level aligns with the role. Sampling only active users at year-end may miss unauthorized access that was later removed.

Write the expected result before testing. If the procedure is to inspect a change ticket, specify which attributes matter: requester, approver, role, date, and system record. If an attribute is absent, determine whether it is stored elsewhere or represents a control failure. A well-defined procedure reduces hindsight bias and makes supervisor review more effective.

Documenting the logic chain

A strong workpaper makes the chain visible: objective, risk, criterion, procedure, population or selection, evidence, result, conclusion. If one link is missing, the conclusion may not be supportable. For example, a spreadsheet of exceptions without its source query and date range cannot show that the tested population is complete. A conclusion without a criterion cannot show why the condition is a deviation.

Documentation should capture contradictory evidence and resolution. If a manager states all exceptions were approved but logs show approvals after transactions, explain the conflict and test the chronology. Omitting inconvenient evidence creates a biased file. Clear records also allow a qualified reviewer to understand limitations and distinguish fact from judgment.

Study distinctions that drive correct answers

Separate a risk from a control and a procedure. A risk is an uncertain event that may impede an objective. A control is a response management uses to prevent, detect, or correct the risk. An audit procedure is what the auditor does to evaluate the risk or control. A policy requiring two approvals is a control; inspecting a sample of approvals is an audit procedure.

Also separate condition, cause, effect, and recommendation. The condition is what the auditor found; criteria are what should occur; cause explains why the gap exists when evidence supports it; effect describes actual or potential consequence; recommendation or agreed action addresses the issue. The report need not assert a speculative root cause when the work has not established one.