The IIA’s most recently published pass rates for the Certified Internal Auditor exam are 44 percent for Part 1, 48 percent for Part 2, and 56 percent for Part 3. Read those numbers the way an auditor would read a control failure rate: more than half the people who sit Part 1 fail it, and these are people who paid $310 to be there, most of whom work in the profession and many of whom bought a review course. The exam is not hard because the material is obscure; the Standards are public and the syllabus fits on a few pages. It is hard because it tests judgment under time pressure in a format most candidates have never practiced, because the 2025 syllabus rewards a precise reading of the Global Internal Audit Standards over general audit experience, and because candidates consistently sit before their practice scores say they are ready.
This guide is an honest account of the difficulty and a plan for passing on the first attempt. It gives the pass rates by part with what each number means, a table of the eight ways candidates actually fail and which part each one hits, a comparison with the CPA, CISA, and CFE on the dimensions that matter, a study-hours matrix by experience level, a twelve-week first-attempt plan for each part, an exam-day technique section built around the scaled scoring, a part-by-part account of what is hard under the 2025 syllabus, and a retake protocol for the roughly half who will need one. It was rewritten in September 2026 against the 2025 syllabus and the IIA’s current published pass rates. The eligibility rules are in the site’s CIA exam requirements guide and the full budget in the CIA exam cost guide.
In this guide
- The pass rates by part, and what they mean
- Why candidates fail: eight failure modes
- How the CIA compares with the CPA, CISA, and CFE
- How many hours it takes, by experience level
- The twelve-week first-attempt plan for each part
- Exam-day technique and the scaled score
- Part by part: what is hard under the 2025 syllabus
- The retake protocol
- Common preparation mistakes
The pass rates by part, and what they mean
The IIA’s Professional Certifications Board publishes pass rates periodically rather than on a fixed schedule, and the figures below are the latest set it has released, repeated by the major review providers through 2026. Three things about them are worth knowing before you plan. They are per sitting, not per candidate, so a candidate who passes on the second attempt counts once as a fail and once as a pass. They rise across the parts partly because of selection: everyone who reaches Part 3 has already passed two exams and learned the format. And the Challenge Exam, sat by CPAs and chartered accountants who are by definition experienced test-takers, passes at 47 percent, which is the clearest evidence that the difficulty is in the exam rather than in the candidates.
| Exam | Published pass rate | Format | Domains and weights (2025 syllabus) | Where the difficulty sits |
|---|---|---|---|---|
| Part 1: Internal Audit Fundamentals | 44% | 125 questions, 150 minutes (72 seconds per question) | Foundations of Internal Auditing 35%; Ethics and Professionalism 20%; Governance, Risk Management, and Control 30%; Fraud Risks 15% | The densest Standards content of the three parts; most candidates’ first sitting, with the least exam technique; the Foundations domain alone is more than a third of the marks |
| Part 2: Internal Audit Engagement | 48% | 100 questions, 120 minutes | Engagement Planning 50%; Information Gathering, Analysis, and Evaluation 40%; Engagement Supervision and Communication 10% | Application questions with two defensible answers, where the Standards’ wording decides which is “most appropriate”; experienced auditors are marked down for answering from their own function’s practice |
| Part 3: Internal Audit Function | 56% | 100 questions, 120 minutes | Internal Audit Operations 25%; Internal Audit Plan 15%; Quality of the Internal Audit Function 15%; Engagement Results and Monitoring 45% | Chief audit executive perspective; candidates who have never managed a function or written a committee report have to learn a viewpoint, not just content |
| Challenge Exam (credential holders) | 47% | 150 questions, 180 minutes | All three parts combined | Breadth; one sitting covering the full syllabus |
The pass mark is a scaled score of 600 on a scale of 250 to 750. The IIA does not publish the raw percentage that maps to 600, and it varies slightly by exam form because forms are equated for difficulty, but candidates who consistently score 75 to 80 percent on fresh, timed practice questions from a current-syllabus bank pass at rates far above the published averages, and candidates sitting on 65 percent do not. That gap is the single most useful fact in this guide: the published pass rates describe the population that sits, and the population that sits includes a large group who were told by their own practice scores that they were not ready and went anyway, because the registration window was closing or the date was booked.
Why candidates fail: eight failure modes
Having watched colleagues and staff through the exam for a decade, the failures sort into a small number of patterns, and almost none of them are about intelligence or effort. The table names each one, the symptom you can observe in yourself before exam day, the part it most often hits, and the correction.
| Failure mode | Symptom before the exam | Hits hardest on | Fix |
|---|---|---|---|
| Answering from your own shop’s practice | Missed questions where your answer was “what we do” and the key was “what the Standards say” | Part 2 | Read the relevant Standard for every practice question you miss; the exam tests the IIA’s model, not your function’s |
| Studying the old syllabus | Materials organized around Business Knowledge for Internal Auditing, Information Security, or Financial Management | Part 3 | Discard anything pre-May 2025; Part 3 is now about operating the function and reporting results |
| Sitting on practice scores below 75 percent | Registration window or booked date driving the decision, not readiness | Part 1 | Book eight to ten weeks out and move the date, at $75, if two consecutive mock exams are under 75 percent |
| Reading, not practicing | Hours logged on textbook chapters and videos; fewer than 1,000 questions attempted | All parts | Flip the ratio: two-thirds of study time on timed questions with explanations, one-third on reading the gaps they expose |
| Running out of time | Mock exams finished with unanswered questions; over three minutes on hard items | Part 1 (125 questions) | Fixed pacing checkpoints; flag and move on after 90 seconds; there is no penalty for a guessed answer |
| Misreading the stem | Missing “least”, “not”, “except”, “most likely”, “best”; choosing a true statement that does not answer the question | Parts 1 and 2 | Underline the qualifier mentally before reading the options; ask “what is this question testing” before “which answer is true” |
| Ignoring ethics and fraud | Treating the 20 percent Ethics and 15 percent Fraud domains as common sense | Part 1 | Learn the Code of Ethics principles and the fraud indicators as tested material; 35 percent of Part 1 is there |
| The long gap | Six months or more between parts; re-learning the format each time | Parts 2 and 3 | Sit the parts eight to twelve weeks apart while technique is fresh |
The first row is the one experienced auditors underestimate, and it explains why ten-year veterans fail Part 2 while second-year staff pass it. The exam is written to the IIA’s model of an engagement, in which the auditor documents the engagement risk assessment before the work program, sizes the sample to the control’s frequency, and communicates preliminary results before the final report. A senior auditor whose function does those things in a different order, or skips one, will select a defensible real-world answer that is the wrong exam answer. The correction is not to study harder; it is to study the Standards as the exam’s rulebook, which the site’s Global Internal Audit Standards guide and its domain deep-dives are built for.
How the CIA compares with the CPA, CISA, and CFE
Candidates who hold or are weighing another credential want to know whether the CIA is harder. The honest answer is that it is narrower and shorter than the CPA, comparable in per-sitting pass rate, and harder than its reputation because the questions are judgment-based rather than computational. The table compares the four credentials on the dimensions that affect difficulty; where a body does not publish pass rates the table says so rather than repeating a provider’s estimate.
| Dimension | CIA | CPA (US) | CISA | CFE |
|---|---|---|---|---|
| Exams | 3 parts, 325 questions, 6.5 hours total | 4 sections (3 core, 1 discipline), 16 hours total, multiple choice plus task-based simulations | 1 exam, 150 questions, 4 hours | 4 sections of 100 questions, each 2 hours |
| Published pass rates | 44% / 48% / 56% by part; Challenge Exam 47% | Published quarterly by the AICPA; in recent years roughly 40 percent to over 70 percent depending on the section | Not published by ISACA | Not published by the ACFE |
| Question style | Judgment and application against the Standards; little computation | Heavy computation and technical accounting, tax, and audit rules; simulations | Application of IS audit and control concepts; “best” answer format similar to the CIA | Recall and application across fraud schemes, law, investigation, and prevention |
| Typical total study hours | 300 to 450 | 350 to 500 | 100 to 200 | 100 to 200 |
| Experience requirement | 12 to 60 months depending on education, may be earned after the exams | Set by state board, commonly one to two years under a CPA | Five years of IS audit, control, or security experience, with waivers | Two years of fraud-related experience plus a points system |
| Renewal | 40 CPE hours a year, 2 of ethics | Set by state board, commonly 40 hours a year or 120 per three years | 120 hours per three years, minimum 20 a year | 20 hours a year, 2 of ethics |
| Program window | 3 years, one 12-month extension | Rolling 30 months from the first passed section under the current model in most states | Certification application within 5 years of passing | No fixed window on the exam itself |
For a CPA, the CIA’s Part 1 will feel familiar in structure and unfamiliar in content, because the Standards are not the auditing standards you learned; most CPAs find Part 2 the hardest because it tests the internal audit engagement model rather than the financial statement audit. For a CISA, the CIA’s question style is a near match and the difficulty is the volume of Standards material in Part 1. Both groups should check the Challenge Exam first, since a single 150-question exam replaces the three parts for qualifying credential holders; the site’s CIA versus CPA and CIA versus CISA guides go deeper on each pairing.
How many hours it takes, by experience level
Review providers quote study hours that suit their sales model, so treat any single figure with suspicion. The matrix below is built from what candidates who passed first time actually report, and it varies by part and by background more than by intelligence. Hours mean focused hours: timed questions, reading the Standards, reviewing explanations. Background listening to lectures while commuting is worth roughly a third of its clock time.
| Candidate background | Part 1 | Part 2 | Part 3 | Total | Why |
|---|---|---|---|---|---|
| Internal auditor, 3 or more years, works under the Standards daily | 70 to 90 | 60 to 80 | 80 to 110 | 210 to 280 | Content is familiar; the work is unlearning local practice and learning the CAE perspective for Part 3 |
| Internal auditor, under 2 years | 100 to 130 | 90 to 120 | 110 to 140 | 300 to 390 | Standards knowledge is partial; Part 3’s function-management content is mostly new |
| External auditor or CPA moving across | 90 to 120 | 110 to 140 | 100 to 130 | 300 to 390 | Strong technique and control knowledge; the internal audit engagement model in Part 2 is the hurdle |
| Compliance, risk, or controls professional | 110 to 140 | 110 to 140 | 110 to 140 | 330 to 420 | Adjacent vocabulary but a different framework; all three parts need building from the Standards up |
| Student or career changer with no audit exposure | 130 to 160 | 130 to 160 | 130 to 160 | 390 to 480 | Everything is new; the engagement and function material has nothing in experience to attach to, so worked examples matter more |
Two adjustments to the matrix. Add 20 percent if you are studying in a second language, because the exam’s qualifiers (“most likely”, “least appropriate”, “primary”) are where translation costs marks. And subtract nothing for having “read the Standards at work”: candidates who believe they know the Standards because they cite them in workpapers routinely score lowest on the Foundations domain at the first mock, because working knowledge and tested knowledge are different things. The site’s study timeline guide turns these hours into a calendar for someone working full time.
The twelve-week first-attempt plan for each part
Twelve weeks per part at eight to ten hours a week gives 100 to 120 hours, which covers the middle rows of the matrix above. The plan front-loads the reading into the first three weeks and spends the remaining nine on questions, because retention of the Standards comes from being asked about them, not from reading them twice. The gates in weeks 8 and 11 are the point of the plan: they are the moments at which you decide, on evidence, whether to keep the date.
| Week | Work | Target | Gate |
|---|---|---|---|
| 1 to 3 | Read the review text for the part once, domain by domain, and the underlying Standards for each domain; 30 untimed questions per domain to learn the question style | All domains read; roughly 200 questions attempted | None; this is orientation |
| 4 to 5 | Timed question sets of 40, one domain at a time; every missed question traced to the Standard or concept and written in a one-line error log | 60 to 65 percent on first-pass domain sets | None |
| 6 to 7 | Mixed-domain timed sets of 60; error log reviewed weekly; re-read only the sections the log names | 70 percent on mixed sets | Register the part now if not already registered; book a date for week 12 |
| 8 | First full mock exam under exam conditions (full length, no notes, timed) | 72 percent or better | Below 68 percent: move the date four weeks and repeat weeks 6 and 7 |
| 9 to 10 | Two mixed sets a week plus targeted work on the two weakest domains from the mock; the Standards read once more, in full, for Part 1 | 75 percent on mixed sets | None |
| 11 | Second full mock, different question bank if possible | 75 to 80 percent | Below 72 percent: move the date at $75; two mocks under target is a fail signal, not bad luck |
| 12 | Light review of the error log and the Code of Ethics; no new material after Wednesday; rest the day before | — | Sit |
For Part 3, add a week to the front for candidates who have never worked at manager level, spent on reading the Standards’ Domain IV (managing the internal audit function) and a real audit committee pack; the site’s GIAS Domain IV guide and internal audit report examples are built for exactly that gap. The study schedule guide has a printable week-by-week version of this plan.
Exam-day technique and the scaled score
Part 1 gives 72 seconds a question and Parts 2 and 3 give 72 as well (100 questions in 120 minutes), and there is no penalty for a wrong answer, so an unanswered question is the only guaranteed loss. Set pacing checkpoints before you start: for Part 1, question 45 by minute 50 and question 90 by minute 100, which leaves 50 minutes for the last 35 questions and the flagged items; for Parts 2 and 3, question 55 by minute 60. Any question that has not resolved after 90 seconds gets a best guess, a flag, and your attention only if time remains at the end. Read the last line of the stem first, because that is where the qualifier lives: “most likely”, “best”, “primary”, “least”, “not”, “except”. Then decide what the question is testing before reading the options, because the wrong options are written as true statements that answer a different question. Between two plausible answers, prefer the one that follows the Standards’ sequence (assess, plan, perform, communicate, monitor) and the one that involves the chief audit executive or the board where escalation is at issue; the exam’s model auditor escalates earlier than most real ones do.
The scaled score means your result is not the percentage you got right. Forms are equated so that 600 represents the same standard across versions, which is why candidates comparing notes on “how many I got wrong” learn nothing. What you receive at the test center is a preliminary pass or fail; the official score report follows in CCMS and, for a fail, shows performance by domain in bands, which is the input the retake protocol below runs on. Candidates who arrive rested with a pacing plan and a qualifier habit convert roughly five to eight percentage points of knowledge into marks that anxious, unpaced candidates leave on the table, and at the 600 boundary that is the difference between the two outcomes for a large share of sitters.
Part by part: what is hard under the 2025 syllabus
Part 1: Internal Audit Fundamentals (44 percent pass rate)
Part 1 is where the 2025 syllabus concentrated the Standards. The Foundations domain, 35 percent of the paper, covers the purpose of internal auditing, the structure of the Global Internal Audit Standards and their domains, the mandate and charter, independence and organizational positioning, and the relationship with the board; questions ask which Standard governs a situation and what the required action is. Ethics and Professionalism, 20 percent, tests the four principles of the Code and the Standards that implement them (integrity, objectivity, competency, due professional care, confidentiality) through scenarios in which an auditor’s objectivity is impaired or a gift, a prior role, or a personal relationship creates a conflict. Governance, Risk Management, and Control, 30 percent, is the conceptual core: the three lines model, COSO’s components and principles, risk appetite, and control types. Fraud Risks, 15 percent, tests indicators, the fraud triangle, and the auditor’s responsibilities, which are to assess fraud risk and design procedures, not to investigate. The difficulty is volume and precision together; 125 questions leave no time to reason from first principles, so the Standards have to be known, not derived. The site’s COSO 17 principles and fraud red flags guides map two of the four domains.
Part 2: Internal Audit Engagement (48 percent pass rate)
Part 2 is an engagement from planning to communication, weighted heavily toward the front: Engagement Planning is half the paper and covers the engagement risk assessment, objectives and scope, criteria, resourcing, and the work program. Information Gathering, Analysis, and Evaluation, 40 percent, is fieldwork: evidence sufficiency and reliability, sampling, analytics, workpaper standards, and the evaluation of findings. Supervision and Communication is 10 percent. The questions are application questions with two defensible options, and the discriminator is almost always the Standards’ preferred sequence or wording: the engagement risk assessment before the work program, the sample sized to the control frequency, preliminary results communicated before the final report. Experienced auditors fail Part 2 by answering as their function would act; the fix is to treat the site’s fieldwork guides, audit evidence, sample sizes, and the work program, as descriptions of the model the exam tests.
Part 3: Internal Audit Function (56 percent pass rate)
Part 3 was rebuilt in 2025 from a business-knowledge paper into a function-management paper, and its highest pass rate reflects a self-selected, experienced population rather than easy content. Engagement Results and Monitoring, 45 percent, covers final communications, ratings and opinions, management’s action plans, follow-up and validation, and reporting to the board. Internal Audit Operations, 25 percent, covers staffing, budgeting, technology, methodologies, and performance measurement of the function. The Internal Audit Plan, 15 percent, covers the risk-based plan and its approval, and Quality of the Internal Audit Function, 15 percent, covers the quality assurance and improvement program, internal and external assessments, and conformance reporting. The difficulty for a staff or senior auditor is perspective: the questions are written from the chief audit executive’s chair, and candidates who have never built a plan, defended a budget, or written a committee report have to learn how those decisions are made. The site’s internal audit plan template, finding severity ratings, and issue validation guides cover the three largest topics in the paper as practitioners actually do them.
The retake protocol
Roughly half of first sittings fail, so a retake is the base case rather than a disaster, and the candidates who pass on the second attempt are the ones who treat the score report as data. The IIA requires a 30-day wait before re-sitting the same part and charges the full part fee again ($280 to $310 for members), so the protocol below is built to a six-to-eight-week cycle. Do not book the retake on day 31; book it when the gate says so.
| Step | What to do | Why |
|---|---|---|
| 1. Read the domain bands on the score report | Identify the one or two domains rated lowest; those are where the marks went | A fail at 570 with one weak domain is a targeted problem; a fail at 480 with all domains weak means the whole plan was short |
| 2. Diagnose the failure mode, not the content | Go back to the eight failure modes: timing, stem misreading, answering from practice, old materials | Re-reading the same textbook fixes none of them |
| 3. Rebuild the error log from a fresh question bank | 300 to 500 new questions, timed, with every miss traced to a Standard | Repeating a bank you have seen inflates practice scores and hides the gap |
| 4. Re-run the gates | Two full mocks at 75 percent or better, one week apart, before booking | The first attempt was probably booked on hope; the second is booked on evidence |
| 5. Sit inside eight weeks | Book once the second mock clears the gate | Knowledge decays and the registration window is 180 days; a retake left six months loses the technique that was working |
A candidate who fails the same part twice should change something structural: the review provider, the study format (questions instead of video, or a live class instead of self-study), or the part order, since sitting Part 2 next and returning to Part 1 with more technique is a legitimate move. Three fails on one part almost always trace to a failure mode in the table above that has not been named, and it is worth having a CIA who knows you look at the error log; the site’s common CIA exam mistakes guide is the checklist for that conversation.
Common preparation mistakes
| Failure | What it looks like | Why it matters | Fix |
|---|---|---|---|
| Booking the date first and studying to it | A test date chosen from the calendar in week one | The date, not readiness, decides when you sit; it is how the 44 percent happens | Book in week 6 or 7, after the first gate, and move it at $75 if the mocks say so |
| Passive study | Dozens of hours of lectures, hundreds of pages read, few questions answered under time | The exam is a timed judgment test; reading trains recognition, not retrieval | Two-thirds of hours on timed questions with explanations |
| One question bank, memorized | Practice scores of 85 percent on questions seen three times | A false readiness signal; the real exam is fresh | Rotate banks; judge readiness only on unseen questions |
| Skipping the Standards themselves | Studying a provider’s summary of the Standards without reading the source | Part 1 questions turn on exact wording and the required versus recommended distinction | Read the Standards in full once for Part 1; keep them open during practice review |
| Studying the old Part 3 | Time spent on information security, IT, and financial management content | Those domains left the syllabus in May 2025 | Confirm every resource states the 2025 syllabus |
| Treating ethics and fraud as filler | No dedicated study for 35 percent of Part 1 | The largest avoidable loss of marks in the whole exam | Learn the Code, the impairment scenarios, and the fraud indicators as tested material |
| Long gaps between parts | Six to twelve months between sittings | Technique decays; each part is approached as a first exam again | Eight to twelve weeks apart; register the next part the week after passing |
| No pacing plan | Twenty questions unanswered when time is called | Unanswered questions are the only guaranteed loss on an exam with no guessing penalty | Checkpoints written on the whiteboard at the start; 90-second flag rule |
| Ignoring the score report after a fail | Re-sitting on day 31 with the same materials | The same failure mode produces the same result | The retake protocol above |
| Studying alone in a vacuum | No contact with anyone who has passed under the current syllabus | Failure modes are easier to see from outside | An IIA chapter study group or a certified colleague to review the error log |
The pass rates are what they are because most sitters make two or three of these mistakes at once, and the exam punishes each one at the margin where 600 sits. A candidate who books on evidence, practices under time, studies the current syllabus from the Standards themselves, and sits the parts close together is not a 44 percent candidate; the population that does those four things passes at rates that would make the credential look easy, and it is not easy. It is a well-designed test of a specific body of knowledge, applied under pressure, and it rewards the preparation that a good auditor would apply to any engagement: know the criteria, test against them, and do not sign off on hope. The site’s hardest CIA exam topics guide lists the content areas where the marks are most often lost, and 50 free practice questions gives a first look at the question style.
Related guides
- CIA exam requirements — eligibility, documents, and the three-year window
- CIA exam cost in 2026 — fees, prep prices, and the cost of a retake
- The CIA exam roadmap — the end-to-end study plan
- How long does it take to prepare? — the hours matrix as a calendar
- CIA exam study schedule — the twelve-week plan, week by week
- Common CIA exam mistakes — the checklist for a retake review
- The hardest CIA exam topics — where marks are lost by content area
- Global Internal Audit Standards — the rulebook Part 1 tests
- GIAS Domain IV: managing the function — the perspective Part 3 requires
- CIA vs. CPA — difficulty and payoff compared
- All Guides — the full index
Leave a Reply