CIA Part 3 2025 Syllabus and Domain Weights
The current 2025 CIA Part 3 syllabus assigns 25% to Internal Audit Operations, 15% to the Internal Audit Plan, 15% to Quality of the Internal Audit Function, and 45% to Engagement Results and Monitoring.
- It replaces the former business, IT, information security, and finance domain structure.
On this page14 sections
- The current four-domain outline
- A. Internal Audit Operations, 25%
- B. Internal Audit Plan, 15%
- C. Quality of the Internal Audit Function, 15%
- D. Engagement Results and Monitoring, 45%
- How to read the syllabus as connected work
- Study emphasis by task
- Worked syllabus case
- Common outline errors
- Use weights to structure preparation
- What changed from the prior syllabus
- Quality and standards assertions
- Monitoring actions is part of results
- Apply the format in practice
The current four-domain outline
The 2025 CIA Part 3 syllabus is Internal Audit Function. Its domains are Internal Audit Operations (25%), Internal Audit Plan (15%), Quality of the Internal Audit Function (15%), and Engagement Results and Monitoring (45%).
The 2019 syllabus had four different domains: Business Acumen, Information Security, Information Technology, and Financial Management. Those labels and weights are no longer the current Part 3 blueprint. Current exams place relevant business, technology, security, and finance knowledge in the context of internal audit work and function management.
Part 3 has 100 multiple-choice questions, 120 minutes, and a 600 scaled passing standard. The four weights represent relative content emphasis, not a guaranteed item count by domain on an individual sitting.
A. Internal Audit Operations, 25%
This domain includes methodologies for planning, organizing, directing, and monitoring the activity; managing external providers; balancing assurance and advisory work; and determining when methods should be reviewed or revised. It also tests management of financial, human, and IT resources.
Budgeting links the audit strategy and plan to available resources. The function considers skill needs, staffing, recruitment, training, retention, performance, technology, and workload. Leaders may use financial and operational measures, but should assess quality, effectiveness, and value as well as productivity.
Example: the function’s methodology requires a manual review of every high-risk vendor, but the volume has doubled and results show delays. The chief audit executive examines whether the method remains effective, evaluates alternatives such as data analytics or risk-based selection, pilots an approach, and updates policy with controls for quality. The answer is not to abandon the test without assessing the risk.
B. Internal Audit Plan, 15%
The audit plan is based on a documented risk assessment and should align with organizational and internal audit strategies. The function considers the risk universe, board and senior-management input, emerging events, prior coverage, assurance providers, resources, and changes in objectives or operations.
A plan should be dynamic. A major acquisition, cyber incident, new law, product launch, or control failure may change priorities. The chief audit executive assesses the effect and communicates significant changes or resource constraints to the appropriate governing body.
Coordination with other assurance providers can help identify coverage gaps and avoid unnecessary duplication. The function evaluates provider independence, competence, scope, methods, evidence, and reporting before relying on work. Document the basis and any additional audit procedures needed.
C. Quality of the Internal Audit Function, 15%
The quality assurance and improvement program (QAIP) evaluates conformance with the Global Internal Audit Standards and progress toward function objectives. It includes ongoing monitoring, periodic internal assessments, and an external quality assessment at least once every five years by a qualified independent assessor or assessment team.
Ongoing quality work can include engagement supervision, file reviews, policy compliance, stakeholder feedback, and performance analysis. Periodic assessments examine broader policies and practices. External assessment offers independent evaluation. Findings should lead to improvement actions with ownership and follow-up.
A quality assertion must be supported. If the function has significant nonconformance, the chief audit executive follows requirements for communicating it and addressing impact. A completed checklist does not by itself prove effective quality; the function must use results to improve.
D. Engagement Results and Monitoring, 45%
The largest domain covers effective results communication and monitoring. Communication should be accurate, objective, clear, concise, constructive, complete, and timely. It includes engagement objectives, scope, conclusions, significant findings, recommendations or agreed action plans, and relevant responses.
Findings compare actual conditions with applicable criteria and explain cause and effect when supported. Management owns corrective actions and may select a suitable alternative to audit’s recommendation. The function assesses whether the response addresses the risk and assigns responsibility and timing.
Monitoring verifies implementation through evidence. A status marked “complete” in a tracker does not demonstrate that a control works. Follow-up may inspect configuration, test transactions, review documentation, or wait for enough operating history. Significant risk acceptance should be escalated when outside authority or tolerance.
How to read the syllabus as connected work
These domains form a management cycle. Operations provide methodologies and resources; the risk-based plan chooses priority engagements; quality checks whether the activity works as intended; engagement results and monitoring communicate what was found and whether management acted. A weakness in one domain can undermine the others.
For example, a plan may include extensive technology assurance, but operations have no qualified staff. The function may use co-sourcing, training, or a change to timing and coverage. Quality monitoring then tests whether specialist work was supervised effectively. Results communicate any residual gap to governance, and follow-up checks action.
Study emphasis by task
For Operations, work cases involving budgets, staffing, external providers, methodology change, and performance measures. For the Plan domain, practice risk assessment, prioritization, emerging risk, and coordination. For Quality, learn QAIP components, assessment cadence, reporting, and remediation. For Results and Monitoring, practice findings, communication attributes, management responses, risk acceptance, and closure evidence.
Do not neglect the 15% domains because they seem smaller. They often provide the governance context needed to answer a results question. Likewise, do not study report writing without understanding how the plan and quality program generated reliable work.
Worked syllabus case
An internal audit function reports 100% plan completion, but a board committee asks why a new regulatory risk was not covered. The operations measure is activity completion; it does not establish that the plan stayed risk-relevant. The chief audit executive should explain the risk assessment and plan-update process, assess whether the emerging issue requires coverage, and disclose any resource or governance constraint.
The function may revise the plan and defer lower-priority work, with appropriate communication. QAIP monitoring can later assess whether processes identify significant changes promptly. A complete report should state what was assessed and what remains outside scope, and follow-up should verify management action if a finding is issued.
Common outline errors
Do not use the former four-domain chart. Do not assume that a 45% results domain means only report formatting; it includes monitoring, management action, risk acceptance, and communication. Do not treat quality as an external inspection only; the QAIP includes ongoing and internal work as well as external assessment.
Do not measure operations only by budget or number of reports. Measures should be interpreted together and tied to strategy and quality. Do not call a plan risk-based solely because it lists risks; the prioritization and refresh method should be documented and responsive to change.
Use weights to structure preparation
Spend substantial study time on results and monitoring because that domain carries 45%, but reserve time for operations, plan, and quality. Use mixed scenarios in which all four domains interact.
For each question, identify whether it concerns managing the function, prioritizing work, evaluating quality, or communicating and following results. Then identify the actor and the relevant standard or governance relationship. This task map is more useful than memorizing a list without application.
What changed from the prior syllabus
The 2019 Part 3 outline organized content around business acumen, information security, information technology, and financial management. The 2025 outline instead focuses on function management, the audit plan, quality, and results and monitoring. Candidates should not simply delete technical context: technology, security, finance, and business knowledge still matter when the function plans and performs assurance.
For example, a cloud access review is no longer prepared as a standalone information-security domain topic. The candidate considers whether the function has the skills and methodology to include the risk in the plan, how provider work can be used, whether engagement quality is adequate, and how findings and corrective actions are communicated.
Quality and standards assertions
A quality program gives the chief audit executive evidence about conformance and improvement. It includes continuous monitoring, periodic internal assessments, and external assessment at least every five years. Assessment results may reveal a narrow engagement issue or a broader pattern in methodology, supervision, or resources.
If a function cannot support a claim of conformance, it should not state that its work complied with the Standards. The chief audit executive communicates significant nonconformance and its impact to the board and senior management as required, takes corrective action, and follows up. The syllabus tests the logic of this responsibility, not merely the name QAIP.
Monitoring actions is part of results
An audit report is not the end of the function’s responsibility to track results. The function establishes a monitoring method, obtains evidence of management action, evaluates whether the action addresses the finding, and reports significant overdue or inadequate responses.
Closure requires more than a due date marked complete. If management installs an automated control, audit may inspect configuration and test transactions after sufficient operation. If only a policy was revised, the underlying implementation and staff behavior may still need verification. The depth of follow-up should be proportionate to risk.
Apply the format in practice
Use a crosswalk when studying older materials. Keep enduring concepts such as budgeting, information security, financial processes, and technology risks, but map each to the 2025 task it supports. For example, cybersecurity may influence the risk-based plan, resource requirements, engagement methodology, quality review, and results communication.
A candidate who studies only old chapter headings may know useful concepts but miss how the current exam asks them to be applied. Anchor each study session in a current syllabus domain and a decision the function must make.
A risk-based crosswalk keeps preparation current and helps candidates see why the knowledge is part of an audit-function decision.
Use new scenarios.
Review each domain through application, not recall alone.
Keep facts current.
Use daily review.