Part 3 of the CIA exam is the part that changed the most when the IIA replaced the syllabus in 2025, and most of what is written about it online still describes the exam that no longer exists. The old Part 3, Business Knowledge for Internal Auditing, spent 35 percent of its marks on business acumen, 25 percent on information security, 20 percent on information technology, and 20 percent on financial management. The current Part 3, Internal Audit Function, is a different examination: 25 percent on running internal audit operations, 15 percent on the audit plan, 15 percent on the quality of the function, and 45 percent on communicating engagement results and monitoring what happens afterward. A candidate who prepares from the old outline will study accounting ratios and network security and then sit an exam about exit conferences, risk acceptance, and escalation.
This guide was rewritten in September 2026 from the IIA’s published Part 3 syllabus for the 2025 exam, English testing from 28 May 2025, and it replaces the earlier version of this page that covered the Business Knowledge syllabus. It sets out every domain and topic, maps each one to the Global Internal Audit Standards it examines, explains what changed and why the change matters for how you study, gives a twelve-week plan weighted to the marks, works eight sample questions in the style of the exam, and lists the mistakes that account for most of the failures on a part that passes only 56 percent of sitters. It sits alongside the CIA exam roadmap, the difficulty guide, and the Standards overview.
In this guide
- What changed in 2025: Business Knowledge to Internal Audit Function
- Format, scoring, and the pass rate
- Domain A: Internal Audit Operations (25%)
- Domain B: Internal Audit Plan (15%)
- Domain C: Quality of the Internal Audit Function (15%)
- Domain D: Engagement Results and Monitoring (45%)
- A twelve-week study plan weighted to the marks
- Eight sample questions, worked
- Common mistakes on Part 3
What changed in 2025: Business Knowledge to Internal Audit Function
The 2025 syllabus followed the Global Internal Audit Standards, which took effect in January 2025 and reorganized the profession’s requirements into five domains. The IIA rebuilt all three exam parts around them: Part 1 became Internal Audit Fundamentals, Part 2 became Internal Audit Engagement, and Part 3 became Internal Audit Function, the part that examines whether a candidate could run a function and stand in front of a board with its results. The business acumen, information security, information technology, and financial management content that filled the old Part 3 was reduced to the technology and business awareness a chief audit executive needs, and the space went to the work of managing, planning, assuring the quality of, and reporting from an internal audit function.
| Feature | Old Part 3: Business Knowledge for Internal Auditing (2019 syllabus) | Current Part 3: Internal Audit Function (2025 syllabus) |
|---|---|---|
| Domains and weights | Business Acumen 35%; Information Security 25%; Information Technology 20%; Financial Management 20% | Internal Audit Operations 25%; Internal Audit Plan 15%; Quality of the Internal Audit Function 15%; Engagement Results and Monitoring 45% |
| Underlying framework | The 2017 International Professional Practices Framework | The Global Internal Audit Standards, Domains III, IV, and V in particular, plus the Topical Requirements |
| Perspective tested | A senior auditor’s general business and technology knowledge | The chief audit executive’s: strategy, resources, the plan, quality, stakeholder communication, escalation |
| Accounting and finance | Financial statements, ratios, capital budgeting, transfer pricing, valuation | Budgeting and financial resource management for the function itself; little else |
| Technology | Security frameworks, application controls, system infrastructure, cyber | Technological resources for engagements; emerging technologies as sources of audit universe entries (IoT, AI, blockchain, digital assets, RPA) |
| Reporting and follow-up | Tested in Part 2 | The largest domain of Part 3, 45 percent |
| Questions and time | 100 questions, 120 minutes | 100 questions, 120 minutes; unchanged |
| Scoring | Scaled 250 to 750, pass mark 600 | Unchanged |
| Best preparation | Business and IT review courses | The Standards themselves, read as a CAE would read them |
Two things follow for anyone who started studying under the old outline. First, most of the accounting and technology material can be set aside; the current syllabus mentions budgeting for the function and the technologies that generate audit universe entries, and nothing about ratio analysis, capital budgeting, or network security. Second, the study problem has changed shape. The old Part 3 was a knowledge exam that rewarded breadth; the current one is a judgment exam that rewards knowing what the Standards require the chief audit executive to do, in what order, and with whom. The Domain IV guide and the Domain V guide on this site cover the two Standards domains that supply most of the questions.
Format, scoring, and the pass rate
Part 3 is 100 multiple-choice questions in 120 minutes, 72 seconds a question, delivered at Pearson VUE centers year-round, scored on a scale of 250 to 750 with 600 to pass. The IIA’s most recently published cumulative pass rate for Part 3 is 56 percent, the highest of the three parts, which candidates read as reassurance and should read as a warning: it is highest because the people who reach Part 3 have already passed two parts and are, on average, the strongest candidates, not because the material is easy. The failure pattern on Part 3 is specific. Candidates who work in audit answer from their own function’s practice rather than from the Standards, and candidates who have never managed a function or written a board paper have to learn a viewpoint rather than a body of facts. The difficulty guide covers pacing and retake rules; the cost guide has the fees, which for Part 3 are $280 for IIA members and $415 for non-members as of September 2026.
Domain A: Internal Audit Operations (25%)
Domain A is the chief audit executive’s management job: methodologies, resources, strategy, and stakeholder communication. It corresponds to Principles 9 through 11 of the Standards, and the questions test whether you know what the CAE must do, not whether you can describe good management in general. The four topics below are the IIA’s; the right-hand columns are what the questions actually turn on.
| Topic | What the syllabus lists | Where it lives in the Standards | What questions turn on |
|---|---|---|---|
| A1. Planning, organizing, directing, and monitoring methodologies | Managing external providers of internal audit services; monitoring internal audit operations; balancing assurance and advisory engagements; conditions warranting a review of methodologies | Standard 9.3 Methodologies; 9.5 Coordination and Reliance; Domain III on the charter’s scope of services | The CAE owns the methodologies and must review them when the Standards change, the organization changes, or quality assessments find gaps. Co-sourced work is performed under the function’s methodologies and the CAE stays responsible. Advisory work is permitted and must not impair objectivity over the same activity for a year; see the co-sourcing guide |
| A2. Managing financial, human, and IT resources | Budgeting steps; recruiting; roles and responsibilities; training, development, and retention; performance management; technological resources for engagements; job design, rewards, mentoring | Standards 10.1 Financial Resource Management; 10.2 Human Resources Management; 10.3 Technological Resources; 8.2 Resources (the board’s role) | The CAE must develop the budget from the plan, tell the board when resources are insufficient and what the impact is, ensure the collective competence of the function, and seek technology that improves effectiveness; the board, not the CAE, approves resources. Questions favor “communicate the impact of the shortfall to the board” over “cut the plan quietly” |
| A3. Aligning internal audit strategy to stakeholder expectations | Supporting business strategy and risk management; mission and vision statements; resource planning aligned to strategy; conditions warranting strategy review | Standard 9.2 Internal Audit Strategy; 6.1 Internal Audit Mandate; 9.1 Understanding Governance, Risk Management, and Control Processes | The strategy is a plan of action to achieve the mandate, developed by the CAE with input from the board and senior management, with vision, objectives, and initiatives; it is reviewed when the organization’s strategy, risks, or stakeholder expectations change |
| A4. Chief audit executive responsibilities for stakeholder communication | Formal and informal communication; audit plan communication and linkage to strategy; independence concerns and risk exposure reporting; reporting on the effectiveness of risk management and control; communicating quality assessment results, performance metrics, and remediation | Standards 11.1 Building Relationships and Communicating with Stakeholders; 11.3 Communicating Results; 8.1 Board Interaction; 8.3 Quality; 12.2 Performance Measurement | The CAE communicates the plan and significant changes to the board, reports independence impairments, gives the board an overall view of governance, risk management, and control, and reports quality assessment results and performance measures; the sequence is always senior management first, then the board, unless the matter concerns senior management |
A worked illustration helps with A2, which produces the most counterintuitive answers. MidState Beverage’s six-person function, the example that runs through the audit plan guide, built its FY27 plan on 8,000 internal hours plus 140 co-sourced hours, held 12 percent in reserve, and could not cover seven areas of its universe. The exam’s answer to what the CAE does about the seven uncovered areas is not to stretch the team or drop the reserve; it is to present the uncovered areas, the risk they carry, and the resource needed to cover them to senior management and the board, and let the board decide. Candidates who manage real functions know that budgets are negotiated, and the exam does not care; it tests the Standard, which places the resourcing decision and its consequences with the board.
Domain B: Internal Audit Plan (15%)
Domain B covers where engagements come from, how the plan is built and kept current, and how the function coordinates with the other people who provide assurance. Fifteen percent of the marks is roughly fifteen questions, and they are among the most predictable on the exam, because the Standards’ requirements for the plan are specific and the IIA lists the sources of engagements explicitly.
| Topic | What the syllabus lists | Where it lives in the Standards | What questions turn on |
|---|---|---|---|
| B1. Sources of potential engagements | Defining the audit universe and its components; applicability of the Topical Requirements; board and management requests; laws and regulatory mandates; market trends, organizational changes, emerging issues and technologies (IoT, AI, blockchain, digital assets, RPA); rationale for audit cycle requirements | Standard 9.4 Internal Audit Plan; 9.1 Understanding Governance, Risk Management, and Control Processes; the Topical Requirements | The universe is the full set of auditable entities, not last year’s plan; a Topical Requirement applies whenever the function performs assurance over that topic, and the plan must recognize it; management requests are inputs weighed against risk, not orders. The Topical Requirements guide lists what is in force and when |
| B2. Developing risk-based audit plans | Risk assessment methodology and prioritization; alignment with organizational strategy, internal audit strategy, and stakeholder expectations; circumstances that trigger dynamic updates | Standard 9.4 Internal Audit Plan; 9.2 Internal Audit Strategy | The plan is based on a documented risk assessment performed at least annually, considers input from the board and senior management, is approved by the board, and is updated as risks change with significant changes communicated to the board; the CAE can adjust it without waiting for the annual cycle |
| B3. Coordinating with other assurance providers | Identifying internal and external assurance providers; coordination methods and examples; criteria for relying on their work | Standard 9.5 Coordination and Reliance | The CAE coordinates to minimize duplication and gaps, may rely on other providers’ work after assessing their competence, objectivity, and the rigor of their work, and remains responsible for the conclusions the function reports; the criteria are the point of most questions. The internal audit vs. compliance guide works the reliance decision in detail |
The trap in Domain B is the audit cycle. Older practice and many candidates’ own functions rotate every entity through the plan on a fixed cycle, and the exam will offer that as a tempting answer. The Standards’ answer is that the plan is risk-based, that coverage cycles are one input among several, and that a low-risk entity may go unaudited for years if the risk assessment supports it, provided the board understands the coverage it is getting. The risk assessment guide and the risk-based auditing guide describe the mechanics the questions assume.
Domain C: Quality of the Internal Audit Function (15%)
Domain C is the quality assurance and improvement program, the disclosure of nonconformance, and the performance measures a function reports. It is short, it is almost entirely drawn from Principles 8 and 12 of the Standards, and it is where candidates lose easy marks by confusing the internal and external assessment requirements.
| Topic | What the syllabus lists | Where it lives in the Standards | What questions turn on |
|---|---|---|---|
| C1. Quality assurance and improvement program elements | Key components; applicability of the Topical Requirements; purpose; the CAE’s board communication responsibilities; internal versus external assessment elements; qualifications of an acceptable assessor; ongoing monitoring and periodic self-assessment | Standard 8.3 Quality; 8.4 External Quality Assessment; 12.1 Internal Quality Assessment; 12.3 Oversee and Improve Engagement Performance | The program covers all aspects of the function and conformance with the Standards; internal assessment combines ongoing monitoring with periodic self-assessment; an external assessment is required at least once every five years by a qualified, independent assessor or an independently validated self-assessment; the CAE discusses the scope and frequency with the board and communicates results to the board and senior management. The QAIP guide covers the whole program |
| C2. Disclosing nonconformance with the Standards | What must be communicated: the circumstances, the actions taken, the impact, and the rationale; the steps for communicating to senior management and the board | Standards 8.3, 12.1, and 15.1 (the conformance statement in final communications) | Nonconformance that affects the function’s overall scope or operation must be disclosed to the board and senior management with its impact; an engagement report may say it was conducted in conformance with the Standards only when the function’s quality program supports the statement, and any nonconformance affecting the engagement is disclosed in the report |
| C3. Key performance indicators and scorecard metrics | Objectives of KPIs; establishing measures and targets; qualitative and quantitative indicators; performance measures across financial, operational, quality, productivity, efficiency, and effectiveness dimensions | Standard 12.2 Performance Measurement; 8.1 Board Interaction | The CAE develops objectives and measures to evaluate the function’s performance against its mandate, strategy, and plan, communicates results to the board, and uses them to drive improvement; questions test the purpose of a measure and whether it reads on effectiveness rather than activity. The internal audit department guide lists a working set |
Domain D: Engagement Results and Monitoring (45%)
Nearly half the exam is about what happens after the fieldwork: how results are communicated, how disagreements are handled, who receives what, how residual risk is assessed and rated, what the CAE does when management accepts a risk the organization should not, and how action plans are monitored and escalated. This is Principle 11 and Principle 15 territory, with Principle 14’s evaluation of findings underneath it, and it rewards candidates who have written or reviewed real reports. The eight topics are below; the two that produce the most wrong answers, risk acceptance and escalation, are worked in prose afterward.
| Topic | What the syllabus lists | Where it lives in the Standards | What questions turn on |
|---|---|---|---|
| D1. Attributes of effective engagement communication | Defining accurate, objective, clear, concise, constructive, complete, and timely; applying them; effective communication methods | Standard 11.2 Effective Communication | Recognizing which attribute a flawed report fails: an unsupported statement is inaccurate, a one-sided one is not objective, jargon is unclear, a late report is untimely, a report that omits a scope limitation is incomplete |
| D2. Demonstrating effective communication | Key report components (objectives, scope, conclusions, recommendations, action plans); appropriate use of “conducted in accordance with the Global Internal Audit Standards”; documenting scope limitations | Standards 15.1 Final Engagement Communication; 14.5 Engagement Conclusions | The final communication includes objectives, scope, conclusions, findings, recommendations or action plans, and the conformance statement where supported; scope limitations imposed during the engagement are disclosed in the report and, if significant, to the board. The report template shows every required element in place |
| D3. Recommendations, action plans, and collaboration with management | Protocol for disagreements about findings or action plans; purposes of recommendations and action plans, including cost-benefit; assessing whether action plans address root causes | Standards 14.4 Recommendations and Action Plans; 14.2 Analyses and Potential Engagement Findings | Management may develop the action plan, internal audit assesses whether it addresses the root cause; a disagreement is documented in the report with both positions; a recommendation’s cost must be weighed against the risk it reduces. The five Cs guide covers the root-cause element |
| D4. Closing communication and reporting | Exit conference purpose and participants; the CAE’s distribution and stakeholder reporting responsibilities; purposes of communicating to management, senior leadership, the board, risk functions, external auditors, regulators, and the public; reporting findings management has already resolved; correcting significant errors and omissions | Standards 15.1; 11.3 Communicating Results; 11.4 Errors and Omissions | The CAE is responsible for communicating results to the parties who can act on them, decides distribution, and when a final communication contained a significant error or omission must communicate the corrected information to everyone who received the original; findings resolved before the report is issued are still reported, with the resolution noted |
| D5. Assessing residual risk | Methods for assessing control design and effectiveness; purposes of aggregating and prioritizing findings; purposes of rating scales for the overall control assessment | Standards 14.3 Evaluation of Findings; 14.5 Engagement Conclusions | Findings are evaluated for significance using impact and likelihood with the function’s methodology, aggregated to form the engagement conclusion, and rated on a scale the methodology defines and the board understands. The severity ratings guide and deficiency evaluation guide are the practical versions |
| D6. Communicating risk acceptance | Determining when a risk management has accepted may be unacceptable to the organization; the appropriate parties; the correct sequence | Standard 11.5 Communicating the Acceptance of Risks | The sequence is the whole question: discuss with senior management first; if unresolved, communicate to the board; the CAE does not resolve the matter alone and does not go to the board first |
| D7. Monitoring implementation of action plans | Internal audit’s responsibilities for follow-up and tracking; the steps to monitor and confirm implementation | Standard 15.2 Confirming the Implementation of Recommendations or Action Plans | The CAE establishes a process to monitor implementation and confirms action plans were implemented, with the extent of confirmation based on the significance of the finding; management’s assertion is not confirmation. The issue validation guide covers the evidence standard |
| D8. Escalation when action plans are not implemented | Appropriate parties for escalation; correct sequencing | Standards 15.2 and 11.5 | Unimplemented action plans are treated as risk acceptance by management; the CAE escalates to senior management, then, if unresolved, to the board; the board decides whether the acceptance stands |
Risk acceptance, topic D6, is worth working through with a real case because the exam asks it in several disguises. In MidState Beverage’s FY27-01 route cash report, the chief operating officer accepted the residual risk on part of finding five, the 1,130 customers who receive no monthly statement, most of them accounts of the two acquired distributors, arguing that statements would begin when those accounts migrated to the ERP the following year and that a manual statement run in the meantime cost more than it was worth. The chief audit executive judged the accepted risk potentially unacceptable to the organization because unstated customers were exactly how the Dayton diversion had run undetected for five months. The Standard’s sequence, and the exam’s, is that the CAE discusses the matter with senior management, in this case the chief executive, and only if it is not resolved there communicates it to the board. Answers that have the CAE overrule the COO, drop the finding, or write to the audit committee before speaking to the chief executive are all wrong, each for a different reason, and the exam will offer all three.
Escalation, topic D8, is the same principle six months later. If the director of route accounting’s action plan on the reconciliation finding, due 30 June, has not been implemented by the September follow-up, the CAE does not simply re-date it. An unimplemented action plan is management accepting the risk by default, so the CAE confirms the status on evidence, discusses it with the responsible executive and then senior management, and escalates to the board if it is not resolved. The distinction the exam draws is between the two decisions in play: management decides whether to accept a risk, and the board decides whether management’s acceptance is acceptable to the organization. Internal audit’s job is to make sure the second decision is made by the people entitled to make it, with the facts in front of them; the issue log template has the escalation ladder written out.
A twelve-week study plan weighted to the marks
The plan below assumes eight to ten hours a week, about a hundred hours in total, which is the upper end of what prep providers quote for Part 3 and the right amount for a candidate who has not run a function. It allocates weeks in proportion to the marks, with Domain D getting nearly half, and it front-loads the Standards themselves because every question is ultimately a question about what they require. The primary text is the Global Internal Audit Standards, free from the IIA; a question bank is the second text; a review course is optional and most useful for candidates without management experience.
| Week | Focus | Read | Do | Gate to pass before moving on |
|---|---|---|---|---|
| 1 | Orientation and the Standards’ structure | Standards Domains I to III in full; the Part 3 syllabus | One page per Principle in your own words: who must do what | You can name the five domains and the fifteen principles without notes |
| 2 | Domain A: methodologies and strategy | Principle 9: Standards 9.1 to 9.5 | Write the CAE’s responsibilities under each standard as a checklist; 40 questions | 75 percent on Domain A questions |
| 3 | Domain A: resources and stakeholder communication | Principles 10 and 11; Standard 8.2 | Draft a one-page resource shortfall memo to a board; 40 questions | You answer resource questions with “communicate the impact to the board” reflexively |
| 4 | Domain B: the plan | Standards 9.4 and 9.5; the Topical Requirements guide | Build a ten-entity audit universe with risk scores and a plan; 40 questions | 75 percent on Domain B; you can state the reliance criteria from memory |
| 5 | Domain C: quality | Principle 8 and Principle 12; Standard 15.1 on the conformance statement | Table of internal versus external assessment requirements; 40 questions | You can explain when a report may claim conformance and what nonconformance disclosure contains |
| 6 | Domain D: communication attributes and report content | Standards 11.2, 11.3, 15.1; the report examples guide | Grade three real or sample reports against the seven attributes; 50 questions | You identify the failed attribute in a flawed excerpt in under a minute |
| 7 | Domain D: findings, recommendations, action plans, disagreements | Standards 14.2 to 14.5 | Write five findings in the five Cs with a root cause and an action plan; 50 questions | 80 percent on D1 to D3 questions |
| 8 | Domain D: distribution, errors and omissions, residual risk, ratings | Standards 11.3, 11.4, 14.3, 14.5 | Rate a set of findings and an engagement on a scale you define; 50 questions | You can explain aggregation and why a rating scale exists |
| 9 | Domain D: risk acceptance, monitoring, escalation | Standards 11.5 and 15.2 | Write the sequence for risk acceptance and for escalation as two flowcharts; 50 questions | Zero errors on sequencing questions |
| 10 | Full mixed practice | Nothing new | Two timed 100-question sets, 120 minutes each; review every miss to the Standard it tests | Both sets above 80 percent |
| 11 | Weak-domain repair | Only the Standards behind your misses | 100 questions in the weakest domain; rewrite your notes for it | Weakest domain above 75 percent |
| 12 | Final rehearsal | Your notes | One timed set two days before the exam; rest the day before | Above 80 percent with time to spare; then stop |
Two rules make the plan work. The first is to read the Standards before the review course, not after, because course summaries paraphrase requirements in ways that lose the exact verb the question will turn on; “must communicate” and “should consider” are different answers. The second is to answer every practice question as the chief audit executive of a function that follows the Standards perfectly, not as yourself in your own function; the exam is not interested in how it is done where you work. The hardest topics guide covers the question-technique side, and the study schedule guide the habit side.
Eight sample questions, worked
The questions below are written in the exam’s style: a short scenario, four options, one that is most consistent with the Standards. They are original to this guide, not IIA questions, and the point of each is the reasoning in the last column. Notice how often the correct answer is a sequence or a party rather than an action.
| Scenario and question | Options | Answer and why |
|---|---|---|
| 1. The board approves a plan that the CAE has told it covers only 70 percent of high-risk entities because two positions are vacant. Six months later the positions are still vacant. What should the CAE do? | A. Reduce engagement scopes to cover the remaining entities. B. Communicate the impact of the continued shortfall to senior management and the board. C. Defer the uncovered entities to next year without comment. D. Engage a co-source firm using the training budget. | B. Standard 10.1 and Standard 8.2: the CAE communicates the impact of insufficient resources; the board decides. A and D hide the shortfall; C ignores the requirement to keep the board informed. |
| 2. A manufacturing company adopts a new Topical Requirement’s subject area, third-party risk, as a major initiative. The CAE’s plan already includes a vendor management audit next year. What is required? | A. Nothing; the existing engagement is sufficient. B. The engagement must conform to the Topical Requirement when it provides assurance over the topic. C. The Topical Requirement applies only to financial services. D. The CAE must add a separate compliance review. | B. Topical Requirements are mandatory when the function performs assurance over the topic, regardless of industry; conformance is assessed in the engagement, not by adding a separate review. |
| 3. Which statement about the external quality assessment is correct? | A. It is required every three years. B. It may be a self-assessment with independent validation, at least every five years. C. It is optional for functions with a strong internal assessment. D. It must be performed by another internal audit function. | B. Standard 8.4: at least once every five years by a qualified, independent assessor or team, or a self-assessment with independent validation. |
| 4. A draft report is accurate and complete but runs to forty pages and uses undefined acronyms throughout. Which attribute of effective communication is most clearly not met? | A. Objective. B. Constructive. C. Clear. D. Timely. | C. Standard 11.2: clear means easily understood, logical, and free of unnecessary technical language. Concise is also failed, but clarity is the attribute the acronyms defeat. |
| 5. After a report is issued, the audit team discovers a sample was drawn from an incomplete population and one finding is overstated. What must the CAE do? | A. Correct the workpapers and note it in the next follow-up. B. Communicate the corrected information to all parties who received the original report. C. Issue a correction only if management requests one. D. Withdraw the report and re-perform the engagement. | B. Standard 11.4: a significant error or omission in a final communication requires corrected information to everyone who received the original. |
| 6. Management declines to implement an action plan for a high-rated finding, stating it accepts the risk. The CAE believes the accepted risk may be unacceptable to the organization. What is the correct first step? | A. Report the matter to the board at its next meeting. B. Discuss the matter with senior management. C. Re-rate the finding to reflect management’s view. D. Document the acceptance and close the finding. | B. Standard 11.5: discuss with senior management first; if unresolved, communicate to the board. A skips the sequence; C and D abandon the CAE’s judgment. |
| 7. An action plan due in June is reported by its owner as complete in September. What should internal audit do before closing the finding? | A. Close it on the owner’s confirmation. B. Confirm implementation with evidence, to an extent based on the finding’s significance. C. Re-perform the entire engagement. D. Escalate to the board. | B. Standard 15.2: the CAE confirms implementation; the extent of the confirmation reflects significance. Assertion is not confirmation, and escalation is for unimplemented plans. |
| 8. The CAE wants to state in a report that the engagement was conducted in conformance with the Standards. What must be true? | A. The engagement had no scope limitations. B. The function’s quality assurance and improvement program supports the statement. C. The external quality assessment occurred within the last year. D. The board approved the statement. | B. Standard 15.1 with Standards 8.3 and 12.1: the statement is appropriate only when supported by the results of the quality program; nonconformance affecting the engagement must be disclosed. |
Common mistakes on Part 3
| Mistake | What it looks like | Why it costs marks | Fix |
|---|---|---|---|
| Studying the old syllabus | Weeks spent on ratios, capital budgeting, and network security from a pre-2025 course | Those domains are gone; the marks are in operations, planning, quality, and reporting | Check the syllabus date on every resource; anything describing Business Knowledge for Internal Auditing is obsolete |
| Answering from your own function | Choosing the answer that matches how your CAE does it | The exam scores the Standards’ answer, and functions deviate from the Standards constantly | Answer as the CAE of a perfectly conforming function; when in doubt, choose the option that communicates to the board |
| Skipping the sequence | Going straight to the board on risk acceptance or escalation | Standards 11.5 and 15.2 specify senior management first, then the board | Memorize the two sequences as flowcharts; expect a question on each |
| Confusing the assessments | Three years for the external assessment; internal assessment only when problems arise | External at least every five years; internal is ongoing monitoring plus periodic self-assessment | One table, learned cold |
| Treating assertion as confirmation | Closing findings on management’s word | Standard 15.2 requires confirmation proportionate to significance | Any option that closes on assertion is wrong |
| Reading the attributes loosely | Calling a long report “not concise” when the question describes undefined jargon | Each attribute has a definition and the question targets one | Learn the seven definitions verbatim from Standard 11.2 |
| Under-weighting Domain D | Equal study time across four domains | Domain D is 45 percent of the marks | Weeks 6 to 9 of the plan above, and half of all practice questions |
| Pacing collapse | Twenty questions left with ten minutes to go | 72 seconds a question leaves no slack for deliberation on every item | Question 50 by minute 55; flag and move on; return with what remains |
Part 3 is the part of the CIA that most resembles the job the credential is named for. Pass it by learning what a chief audit executive must do under the Standards, in what order, and to whom, and the exam becomes a series of questions you have already answered at your desk. Review date for this guide: September 2026, against the IIA’s published Part 3 syllabus for the 2025 exam.
Related guides
- The ultimate guide to passing the CIA exam
- How hard is the CIA exam
- CIA exam requirements
- CIA exam cost breakdown
- The hardest CIA exam topics
- CIA vs. CPA
- Global Internal Audit Standards overview
- GIAS Domain III: governing the function
- GIAS Domain IV: managing the function
- GIAS Domain V: performing engagements
- The IIA Topical Requirements
- QAIP and the external quality assessment
- Inside the internal audit department
- Start here
- The CIA exam, explained — requirements, the three parts and their 2025 weightings, every fee, scoring, twelve-week study plans and a directory of every CIA guide on this site
- Free CIA practice questions — an interactive 156-question bank across all three parts with a rationale for every option, in study and exam modes
Leave a Reply