, ,

CIA Part 3 (Internal Audit Function): 2025 Syllabus Guide

Part 3 of the CIA exam is the part that changed the most when the IIA replaced the syllabus in 2025, and most of what is written about it online still describes the exam that no longer exists. The old Part 3, Business Knowledge for Internal Auditing, spent 35 percent of its marks on business acumen, 25 percent on information security, 20 percent on information technology, and 20 percent on financial management. The current Part 3, Internal Audit Function, is a different examination: 25 percent on running internal audit operations, 15 percent on the audit plan, 15 percent on the quality of the function, and 45 percent on communicating engagement results and monitoring what happens afterward. A candidate who prepares from the old outline will study accounting ratios and network security and then sit an exam about exit conferences, risk acceptance, and escalation.

This guide was rewritten in September 2026 from the IIA’s published Part 3 syllabus for the 2025 exam, English testing from 28 May 2025, and it replaces the earlier version of this page that covered the Business Knowledge syllabus. It sets out every domain and topic, maps each one to the Global Internal Audit Standards it examines, explains what changed and why the change matters for how you study, gives a twelve-week plan weighted to the marks, works eight sample questions in the style of the exam, and lists the mistakes that account for most of the failures on a part that passes only 56 percent of sitters. It sits alongside the CIA exam roadmap, the difficulty guide, and the Standards overview.

In this guide

What changed in 2025: Business Knowledge to Internal Audit Function

The 2025 syllabus followed the Global Internal Audit Standards, which took effect in January 2025 and reorganized the profession’s requirements into five domains. The IIA rebuilt all three exam parts around them: Part 1 became Internal Audit Fundamentals, Part 2 became Internal Audit Engagement, and Part 3 became Internal Audit Function, the part that examines whether a candidate could run a function and stand in front of a board with its results. The business acumen, information security, information technology, and financial management content that filled the old Part 3 was reduced to the technology and business awareness a chief audit executive needs, and the space went to the work of managing, planning, assuring the quality of, and reporting from an internal audit function.

FeatureOld Part 3: Business Knowledge for Internal Auditing (2019 syllabus)Current Part 3: Internal Audit Function (2025 syllabus)
Domains and weightsBusiness Acumen 35%; Information Security 25%; Information Technology 20%; Financial Management 20%Internal Audit Operations 25%; Internal Audit Plan 15%; Quality of the Internal Audit Function 15%; Engagement Results and Monitoring 45%
Underlying frameworkThe 2017 International Professional Practices FrameworkThe Global Internal Audit Standards, Domains III, IV, and V in particular, plus the Topical Requirements
Perspective testedA senior auditor’s general business and technology knowledgeThe chief audit executive’s: strategy, resources, the plan, quality, stakeholder communication, escalation
Accounting and financeFinancial statements, ratios, capital budgeting, transfer pricing, valuationBudgeting and financial resource management for the function itself; little else
TechnologySecurity frameworks, application controls, system infrastructure, cyberTechnological resources for engagements; emerging technologies as sources of audit universe entries (IoT, AI, blockchain, digital assets, RPA)
Reporting and follow-upTested in Part 2The largest domain of Part 3, 45 percent
Questions and time100 questions, 120 minutes100 questions, 120 minutes; unchanged
ScoringScaled 250 to 750, pass mark 600Unchanged
Best preparationBusiness and IT review coursesThe Standards themselves, read as a CAE would read them

Two things follow for anyone who started studying under the old outline. First, most of the accounting and technology material can be set aside; the current syllabus mentions budgeting for the function and the technologies that generate audit universe entries, and nothing about ratio analysis, capital budgeting, or network security. Second, the study problem has changed shape. The old Part 3 was a knowledge exam that rewarded breadth; the current one is a judgment exam that rewards knowing what the Standards require the chief audit executive to do, in what order, and with whom. The Domain IV guide and the Domain V guide on this site cover the two Standards domains that supply most of the questions.

Format, scoring, and the pass rate

Part 3 is 100 multiple-choice questions in 120 minutes, 72 seconds a question, delivered at Pearson VUE centers year-round, scored on a scale of 250 to 750 with 600 to pass. The IIA’s most recently published cumulative pass rate for Part 3 is 56 percent, the highest of the three parts, which candidates read as reassurance and should read as a warning: it is highest because the people who reach Part 3 have already passed two parts and are, on average, the strongest candidates, not because the material is easy. The failure pattern on Part 3 is specific. Candidates who work in audit answer from their own function’s practice rather than from the Standards, and candidates who have never managed a function or written a board paper have to learn a viewpoint rather than a body of facts. The difficulty guide covers pacing and retake rules; the cost guide has the fees, which for Part 3 are $280 for IIA members and $415 for non-members as of September 2026.

Domain A: Internal Audit Operations (25%)

Domain A is the chief audit executive’s management job: methodologies, resources, strategy, and stakeholder communication. It corresponds to Principles 9 through 11 of the Standards, and the questions test whether you know what the CAE must do, not whether you can describe good management in general. The four topics below are the IIA’s; the right-hand columns are what the questions actually turn on.

TopicWhat the syllabus listsWhere it lives in the StandardsWhat questions turn on
A1. Planning, organizing, directing, and monitoring methodologiesManaging external providers of internal audit services; monitoring internal audit operations; balancing assurance and advisory engagements; conditions warranting a review of methodologiesStandard 9.3 Methodologies; 9.5 Coordination and Reliance; Domain III on the charter’s scope of servicesThe CAE owns the methodologies and must review them when the Standards change, the organization changes, or quality assessments find gaps. Co-sourced work is performed under the function’s methodologies and the CAE stays responsible. Advisory work is permitted and must not impair objectivity over the same activity for a year; see the co-sourcing guide
A2. Managing financial, human, and IT resourcesBudgeting steps; recruiting; roles and responsibilities; training, development, and retention; performance management; technological resources for engagements; job design, rewards, mentoringStandards 10.1 Financial Resource Management; 10.2 Human Resources Management; 10.3 Technological Resources; 8.2 Resources (the board’s role)The CAE must develop the budget from the plan, tell the board when resources are insufficient and what the impact is, ensure the collective competence of the function, and seek technology that improves effectiveness; the board, not the CAE, approves resources. Questions favor “communicate the impact of the shortfall to the board” over “cut the plan quietly”
A3. Aligning internal audit strategy to stakeholder expectationsSupporting business strategy and risk management; mission and vision statements; resource planning aligned to strategy; conditions warranting strategy reviewStandard 9.2 Internal Audit Strategy; 6.1 Internal Audit Mandate; 9.1 Understanding Governance, Risk Management, and Control ProcessesThe strategy is a plan of action to achieve the mandate, developed by the CAE with input from the board and senior management, with vision, objectives, and initiatives; it is reviewed when the organization’s strategy, risks, or stakeholder expectations change
A4. Chief audit executive responsibilities for stakeholder communicationFormal and informal communication; audit plan communication and linkage to strategy; independence concerns and risk exposure reporting; reporting on the effectiveness of risk management and control; communicating quality assessment results, performance metrics, and remediationStandards 11.1 Building Relationships and Communicating with Stakeholders; 11.3 Communicating Results; 8.1 Board Interaction; 8.3 Quality; 12.2 Performance MeasurementThe CAE communicates the plan and significant changes to the board, reports independence impairments, gives the board an overall view of governance, risk management, and control, and reports quality assessment results and performance measures; the sequence is always senior management first, then the board, unless the matter concerns senior management

A worked illustration helps with A2, which produces the most counterintuitive answers. MidState Beverage’s six-person function, the example that runs through the audit plan guide, built its FY27 plan on 8,000 internal hours plus 140 co-sourced hours, held 12 percent in reserve, and could not cover seven areas of its universe. The exam’s answer to what the CAE does about the seven uncovered areas is not to stretch the team or drop the reserve; it is to present the uncovered areas, the risk they carry, and the resource needed to cover them to senior management and the board, and let the board decide. Candidates who manage real functions know that budgets are negotiated, and the exam does not care; it tests the Standard, which places the resourcing decision and its consequences with the board.

Domain B: Internal Audit Plan (15%)

Domain B covers where engagements come from, how the plan is built and kept current, and how the function coordinates with the other people who provide assurance. Fifteen percent of the marks is roughly fifteen questions, and they are among the most predictable on the exam, because the Standards’ requirements for the plan are specific and the IIA lists the sources of engagements explicitly.

TopicWhat the syllabus listsWhere it lives in the StandardsWhat questions turn on
B1. Sources of potential engagementsDefining the audit universe and its components; applicability of the Topical Requirements; board and management requests; laws and regulatory mandates; market trends, organizational changes, emerging issues and technologies (IoT, AI, blockchain, digital assets, RPA); rationale for audit cycle requirementsStandard 9.4 Internal Audit Plan; 9.1 Understanding Governance, Risk Management, and Control Processes; the Topical RequirementsThe universe is the full set of auditable entities, not last year’s plan; a Topical Requirement applies whenever the function performs assurance over that topic, and the plan must recognize it; management requests are inputs weighed against risk, not orders. The Topical Requirements guide lists what is in force and when
B2. Developing risk-based audit plansRisk assessment methodology and prioritization; alignment with organizational strategy, internal audit strategy, and stakeholder expectations; circumstances that trigger dynamic updatesStandard 9.4 Internal Audit Plan; 9.2 Internal Audit StrategyThe plan is based on a documented risk assessment performed at least annually, considers input from the board and senior management, is approved by the board, and is updated as risks change with significant changes communicated to the board; the CAE can adjust it without waiting for the annual cycle
B3. Coordinating with other assurance providersIdentifying internal and external assurance providers; coordination methods and examples; criteria for relying on their workStandard 9.5 Coordination and RelianceThe CAE coordinates to minimize duplication and gaps, may rely on other providers’ work after assessing their competence, objectivity, and the rigor of their work, and remains responsible for the conclusions the function reports; the criteria are the point of most questions. The internal audit vs. compliance guide works the reliance decision in detail

The trap in Domain B is the audit cycle. Older practice and many candidates’ own functions rotate every entity through the plan on a fixed cycle, and the exam will offer that as a tempting answer. The Standards’ answer is that the plan is risk-based, that coverage cycles are one input among several, and that a low-risk entity may go unaudited for years if the risk assessment supports it, provided the board understands the coverage it is getting. The risk assessment guide and the risk-based auditing guide describe the mechanics the questions assume.

Domain C: Quality of the Internal Audit Function (15%)

Domain C is the quality assurance and improvement program, the disclosure of nonconformance, and the performance measures a function reports. It is short, it is almost entirely drawn from Principles 8 and 12 of the Standards, and it is where candidates lose easy marks by confusing the internal and external assessment requirements.

TopicWhat the syllabus listsWhere it lives in the StandardsWhat questions turn on
C1. Quality assurance and improvement program elementsKey components; applicability of the Topical Requirements; purpose; the CAE’s board communication responsibilities; internal versus external assessment elements; qualifications of an acceptable assessor; ongoing monitoring and periodic self-assessmentStandard 8.3 Quality; 8.4 External Quality Assessment; 12.1 Internal Quality Assessment; 12.3 Oversee and Improve Engagement PerformanceThe program covers all aspects of the function and conformance with the Standards; internal assessment combines ongoing monitoring with periodic self-assessment; an external assessment is required at least once every five years by a qualified, independent assessor or an independently validated self-assessment; the CAE discusses the scope and frequency with the board and communicates results to the board and senior management. The QAIP guide covers the whole program
C2. Disclosing nonconformance with the StandardsWhat must be communicated: the circumstances, the actions taken, the impact, and the rationale; the steps for communicating to senior management and the boardStandards 8.3, 12.1, and 15.1 (the conformance statement in final communications)Nonconformance that affects the function’s overall scope or operation must be disclosed to the board and senior management with its impact; an engagement report may say it was conducted in conformance with the Standards only when the function’s quality program supports the statement, and any nonconformance affecting the engagement is disclosed in the report
C3. Key performance indicators and scorecard metricsObjectives of KPIs; establishing measures and targets; qualitative and quantitative indicators; performance measures across financial, operational, quality, productivity, efficiency, and effectiveness dimensionsStandard 12.2 Performance Measurement; 8.1 Board InteractionThe CAE develops objectives and measures to evaluate the function’s performance against its mandate, strategy, and plan, communicates results to the board, and uses them to drive improvement; questions test the purpose of a measure and whether it reads on effectiveness rather than activity. The internal audit department guide lists a working set

Domain D: Engagement Results and Monitoring (45%)

Nearly half the exam is about what happens after the fieldwork: how results are communicated, how disagreements are handled, who receives what, how residual risk is assessed and rated, what the CAE does when management accepts a risk the organization should not, and how action plans are monitored and escalated. This is Principle 11 and Principle 15 territory, with Principle 14’s evaluation of findings underneath it, and it rewards candidates who have written or reviewed real reports. The eight topics are below; the two that produce the most wrong answers, risk acceptance and escalation, are worked in prose afterward.

TopicWhat the syllabus listsWhere it lives in the StandardsWhat questions turn on
D1. Attributes of effective engagement communicationDefining accurate, objective, clear, concise, constructive, complete, and timely; applying them; effective communication methodsStandard 11.2 Effective CommunicationRecognizing which attribute a flawed report fails: an unsupported statement is inaccurate, a one-sided one is not objective, jargon is unclear, a late report is untimely, a report that omits a scope limitation is incomplete
D2. Demonstrating effective communicationKey report components (objectives, scope, conclusions, recommendations, action plans); appropriate use of “conducted in accordance with the Global Internal Audit Standards”; documenting scope limitationsStandards 15.1 Final Engagement Communication; 14.5 Engagement ConclusionsThe final communication includes objectives, scope, conclusions, findings, recommendations or action plans, and the conformance statement where supported; scope limitations imposed during the engagement are disclosed in the report and, if significant, to the board. The report template shows every required element in place
D3. Recommendations, action plans, and collaboration with managementProtocol for disagreements about findings or action plans; purposes of recommendations and action plans, including cost-benefit; assessing whether action plans address root causesStandards 14.4 Recommendations and Action Plans; 14.2 Analyses and Potential Engagement FindingsManagement may develop the action plan, internal audit assesses whether it addresses the root cause; a disagreement is documented in the report with both positions; a recommendation’s cost must be weighed against the risk it reduces. The five Cs guide covers the root-cause element
D4. Closing communication and reportingExit conference purpose and participants; the CAE’s distribution and stakeholder reporting responsibilities; purposes of communicating to management, senior leadership, the board, risk functions, external auditors, regulators, and the public; reporting findings management has already resolved; correcting significant errors and omissionsStandards 15.1; 11.3 Communicating Results; 11.4 Errors and OmissionsThe CAE is responsible for communicating results to the parties who can act on them, decides distribution, and when a final communication contained a significant error or omission must communicate the corrected information to everyone who received the original; findings resolved before the report is issued are still reported, with the resolution noted
D5. Assessing residual riskMethods for assessing control design and effectiveness; purposes of aggregating and prioritizing findings; purposes of rating scales for the overall control assessmentStandards 14.3 Evaluation of Findings; 14.5 Engagement ConclusionsFindings are evaluated for significance using impact and likelihood with the function’s methodology, aggregated to form the engagement conclusion, and rated on a scale the methodology defines and the board understands. The severity ratings guide and deficiency evaluation guide are the practical versions
D6. Communicating risk acceptanceDetermining when a risk management has accepted may be unacceptable to the organization; the appropriate parties; the correct sequenceStandard 11.5 Communicating the Acceptance of RisksThe sequence is the whole question: discuss with senior management first; if unresolved, communicate to the board; the CAE does not resolve the matter alone and does not go to the board first
D7. Monitoring implementation of action plansInternal audit’s responsibilities for follow-up and tracking; the steps to monitor and confirm implementationStandard 15.2 Confirming the Implementation of Recommendations or Action PlansThe CAE establishes a process to monitor implementation and confirms action plans were implemented, with the extent of confirmation based on the significance of the finding; management’s assertion is not confirmation. The issue validation guide covers the evidence standard
D8. Escalation when action plans are not implementedAppropriate parties for escalation; correct sequencingStandards 15.2 and 11.5Unimplemented action plans are treated as risk acceptance by management; the CAE escalates to senior management, then, if unresolved, to the board; the board decides whether the acceptance stands

Risk acceptance, topic D6, is worth working through with a real case because the exam asks it in several disguises. In MidState Beverage’s FY27-01 route cash report, the chief operating officer accepted the residual risk on part of finding five, the 1,130 customers who receive no monthly statement, most of them accounts of the two acquired distributors, arguing that statements would begin when those accounts migrated to the ERP the following year and that a manual statement run in the meantime cost more than it was worth. The chief audit executive judged the accepted risk potentially unacceptable to the organization because unstated customers were exactly how the Dayton diversion had run undetected for five months. The Standard’s sequence, and the exam’s, is that the CAE discusses the matter with senior management, in this case the chief executive, and only if it is not resolved there communicates it to the board. Answers that have the CAE overrule the COO, drop the finding, or write to the audit committee before speaking to the chief executive are all wrong, each for a different reason, and the exam will offer all three.

Escalation, topic D8, is the same principle six months later. If the director of route accounting’s action plan on the reconciliation finding, due 30 June, has not been implemented by the September follow-up, the CAE does not simply re-date it. An unimplemented action plan is management accepting the risk by default, so the CAE confirms the status on evidence, discusses it with the responsible executive and then senior management, and escalates to the board if it is not resolved. The distinction the exam draws is between the two decisions in play: management decides whether to accept a risk, and the board decides whether management’s acceptance is acceptable to the organization. Internal audit’s job is to make sure the second decision is made by the people entitled to make it, with the facts in front of them; the issue log template has the escalation ladder written out.

A twelve-week study plan weighted to the marks

The plan below assumes eight to ten hours a week, about a hundred hours in total, which is the upper end of what prep providers quote for Part 3 and the right amount for a candidate who has not run a function. It allocates weeks in proportion to the marks, with Domain D getting nearly half, and it front-loads the Standards themselves because every question is ultimately a question about what they require. The primary text is the Global Internal Audit Standards, free from the IIA; a question bank is the second text; a review course is optional and most useful for candidates without management experience.

WeekFocusReadDoGate to pass before moving on
1Orientation and the Standards’ structureStandards Domains I to III in full; the Part 3 syllabusOne page per Principle in your own words: who must do whatYou can name the five domains and the fifteen principles without notes
2Domain A: methodologies and strategyPrinciple 9: Standards 9.1 to 9.5Write the CAE’s responsibilities under each standard as a checklist; 40 questions75 percent on Domain A questions
3Domain A: resources and stakeholder communicationPrinciples 10 and 11; Standard 8.2Draft a one-page resource shortfall memo to a board; 40 questionsYou answer resource questions with “communicate the impact to the board” reflexively
4Domain B: the planStandards 9.4 and 9.5; the Topical Requirements guideBuild a ten-entity audit universe with risk scores and a plan; 40 questions75 percent on Domain B; you can state the reliance criteria from memory
5Domain C: qualityPrinciple 8 and Principle 12; Standard 15.1 on the conformance statementTable of internal versus external assessment requirements; 40 questionsYou can explain when a report may claim conformance and what nonconformance disclosure contains
6Domain D: communication attributes and report contentStandards 11.2, 11.3, 15.1; the report examples guideGrade three real or sample reports against the seven attributes; 50 questionsYou identify the failed attribute in a flawed excerpt in under a minute
7Domain D: findings, recommendations, action plans, disagreementsStandards 14.2 to 14.5Write five findings in the five Cs with a root cause and an action plan; 50 questions80 percent on D1 to D3 questions
8Domain D: distribution, errors and omissions, residual risk, ratingsStandards 11.3, 11.4, 14.3, 14.5Rate a set of findings and an engagement on a scale you define; 50 questionsYou can explain aggregation and why a rating scale exists
9Domain D: risk acceptance, monitoring, escalationStandards 11.5 and 15.2Write the sequence for risk acceptance and for escalation as two flowcharts; 50 questionsZero errors on sequencing questions
10Full mixed practiceNothing newTwo timed 100-question sets, 120 minutes each; review every miss to the Standard it testsBoth sets above 80 percent
11Weak-domain repairOnly the Standards behind your misses100 questions in the weakest domain; rewrite your notes for itWeakest domain above 75 percent
12Final rehearsalYour notesOne timed set two days before the exam; rest the day beforeAbove 80 percent with time to spare; then stop

Two rules make the plan work. The first is to read the Standards before the review course, not after, because course summaries paraphrase requirements in ways that lose the exact verb the question will turn on; “must communicate” and “should consider” are different answers. The second is to answer every practice question as the chief audit executive of a function that follows the Standards perfectly, not as yourself in your own function; the exam is not interested in how it is done where you work. The hardest topics guide covers the question-technique side, and the study schedule guide the habit side.

Eight sample questions, worked

The questions below are written in the exam’s style: a short scenario, four options, one that is most consistent with the Standards. They are original to this guide, not IIA questions, and the point of each is the reasoning in the last column. Notice how often the correct answer is a sequence or a party rather than an action.

Scenario and questionOptionsAnswer and why
1. The board approves a plan that the CAE has told it covers only 70 percent of high-risk entities because two positions are vacant. Six months later the positions are still vacant. What should the CAE do?A. Reduce engagement scopes to cover the remaining entities. B. Communicate the impact of the continued shortfall to senior management and the board. C. Defer the uncovered entities to next year without comment. D. Engage a co-source firm using the training budget.B. Standard 10.1 and Standard 8.2: the CAE communicates the impact of insufficient resources; the board decides. A and D hide the shortfall; C ignores the requirement to keep the board informed.
2. A manufacturing company adopts a new Topical Requirement’s subject area, third-party risk, as a major initiative. The CAE’s plan already includes a vendor management audit next year. What is required?A. Nothing; the existing engagement is sufficient. B. The engagement must conform to the Topical Requirement when it provides assurance over the topic. C. The Topical Requirement applies only to financial services. D. The CAE must add a separate compliance review.B. Topical Requirements are mandatory when the function performs assurance over the topic, regardless of industry; conformance is assessed in the engagement, not by adding a separate review.
3. Which statement about the external quality assessment is correct?A. It is required every three years. B. It may be a self-assessment with independent validation, at least every five years. C. It is optional for functions with a strong internal assessment. D. It must be performed by another internal audit function.B. Standard 8.4: at least once every five years by a qualified, independent assessor or team, or a self-assessment with independent validation.
4. A draft report is accurate and complete but runs to forty pages and uses undefined acronyms throughout. Which attribute of effective communication is most clearly not met?A. Objective. B. Constructive. C. Clear. D. Timely.C. Standard 11.2: clear means easily understood, logical, and free of unnecessary technical language. Concise is also failed, but clarity is the attribute the acronyms defeat.
5. After a report is issued, the audit team discovers a sample was drawn from an incomplete population and one finding is overstated. What must the CAE do?A. Correct the workpapers and note it in the next follow-up. B. Communicate the corrected information to all parties who received the original report. C. Issue a correction only if management requests one. D. Withdraw the report and re-perform the engagement.B. Standard 11.4: a significant error or omission in a final communication requires corrected information to everyone who received the original.
6. Management declines to implement an action plan for a high-rated finding, stating it accepts the risk. The CAE believes the accepted risk may be unacceptable to the organization. What is the correct first step?A. Report the matter to the board at its next meeting. B. Discuss the matter with senior management. C. Re-rate the finding to reflect management’s view. D. Document the acceptance and close the finding.B. Standard 11.5: discuss with senior management first; if unresolved, communicate to the board. A skips the sequence; C and D abandon the CAE’s judgment.
7. An action plan due in June is reported by its owner as complete in September. What should internal audit do before closing the finding?A. Close it on the owner’s confirmation. B. Confirm implementation with evidence, to an extent based on the finding’s significance. C. Re-perform the entire engagement. D. Escalate to the board.B. Standard 15.2: the CAE confirms implementation; the extent of the confirmation reflects significance. Assertion is not confirmation, and escalation is for unimplemented plans.
8. The CAE wants to state in a report that the engagement was conducted in conformance with the Standards. What must be true?A. The engagement had no scope limitations. B. The function’s quality assurance and improvement program supports the statement. C. The external quality assessment occurred within the last year. D. The board approved the statement.B. Standard 15.1 with Standards 8.3 and 12.1: the statement is appropriate only when supported by the results of the quality program; nonconformance affecting the engagement must be disclosed.

Common mistakes on Part 3

MistakeWhat it looks likeWhy it costs marksFix
Studying the old syllabusWeeks spent on ratios, capital budgeting, and network security from a pre-2025 courseThose domains are gone; the marks are in operations, planning, quality, and reportingCheck the syllabus date on every resource; anything describing Business Knowledge for Internal Auditing is obsolete
Answering from your own functionChoosing the answer that matches how your CAE does itThe exam scores the Standards’ answer, and functions deviate from the Standards constantlyAnswer as the CAE of a perfectly conforming function; when in doubt, choose the option that communicates to the board
Skipping the sequenceGoing straight to the board on risk acceptance or escalationStandards 11.5 and 15.2 specify senior management first, then the boardMemorize the two sequences as flowcharts; expect a question on each
Confusing the assessmentsThree years for the external assessment; internal assessment only when problems ariseExternal at least every five years; internal is ongoing monitoring plus periodic self-assessmentOne table, learned cold
Treating assertion as confirmationClosing findings on management’s wordStandard 15.2 requires confirmation proportionate to significanceAny option that closes on assertion is wrong
Reading the attributes looselyCalling a long report “not concise” when the question describes undefined jargonEach attribute has a definition and the question targets oneLearn the seven definitions verbatim from Standard 11.2
Under-weighting Domain DEqual study time across four domainsDomain D is 45 percent of the marksWeeks 6 to 9 of the plan above, and half of all practice questions
Pacing collapseTwenty questions left with ten minutes to go72 seconds a question leaves no slack for deliberation on every itemQuestion 50 by minute 55; flag and move on; return with what remains

Part 3 is the part of the CIA that most resembles the job the credential is named for. Pass it by learning what a chief audit executive must do under the Standards, in what order, and to whom, and the exam becomes a series of questions you have already answered at your desk. Review date for this guide: September 2026, against the IIA’s published Part 3 syllabus for the 2025 exam.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading