The Certified Internal Auditor and the Certified Fraud Examiner answer different questions. The CIA, awarded by the Institute of Internal Auditors, says you know how internal audit should be done: the Global Internal Audit Standards, the engagement from planning to follow-up, and the governance, risk and control territory the function covers. The CFE, awarded by the Association of Certified Fraud Examiners, says you know how fraud is committed, detected, investigated and prevented, including the law and the interview room. One is a generalist’s credential for a profession. The other is a specialist’s credential for a problem every profession meets.
That difference settles most of the choice, and it is why the question is usually framed badly. For most internal auditors it is not “CIA or CFE?” but “which first, and is the second worth it?” This guide compares the two on what they signal, what the exams test and where they overlap, what it takes to qualify, what they cost in money and time, what it takes to keep them and where each moves a career. It then sets out the two-credential path for auditors who work near fraud and a short way to decide. Figures are those the IIA and the ACFE published as of September 2026. For each credential in depth, see the CIA exam guide and the CFE guide for internal auditors.
In this guide
- The short answer
- What each credential says about you
- The two credentials side by side
- What the exams test, and where they overlap
- Qualifying: experience, points and membership
- What each costs in money and time
- Keeping them: CPE, dues and ethics
- Where each moves a career
- The both answer: sequencing two credentials
- Deciding in five questions
- Questions auditors ask about the CIA and the CFE
- Related guides
The short answer
If you intend to build a career in internal audit, and especially if you want to lead a function one day, the CIA comes first. It is the profession’s own designation, its content matches the job, and it is the credential a search for an audit manager or chief audit executive will assume you hold. If your work is, or is about to become, investigations, forensic accounting, an anti-fraud program, compliance investigations or special investigations in insurance or government, the CFE comes first, because it names the specialism and its content is the job. If you are an internal auditor who keeps being handed the allegations, the answer is both, usually in that order: the CIA counts toward CFE eligibility, and with the CIA’s foundations in place the CFE takes weeks of study rather than months.
| Your situation | First credential | Why |
|---|---|---|
| Staff or senior internal auditor who intends to stay in internal audit | CIA | The profession’s designation; the syllabus is the job; expected on the path to management |
| Auditor aiming at audit manager, director or chief audit executive | CIA | Leadership of a function is examined in the CIA, not the CFE; a CFE can follow as a complement |
| Auditor on a fraud-focused team, or the person who gets the hotline cases | CIA, then CFE; or CFE first if the move is imminent | Both are used every week; the CIA adds ten points toward CFE eligibility |
| Investigator, forensic accountant, insurance special investigations, inspector general’s office | CFE | The specialism’s credential; the CIA matters only if you move into audit leadership |
| Compliance professional who runs internal investigations | CFE | Investigation method, evidence and legal constraints are the gaps it fills |
| Audit data analyst building fraud tests | Either; CFE if the fraud work is the career | Scheme knowledge sharpens the tests; the CIA frames them inside the audit plan |
| Graduate in a first audit or investigations job | The one that matches the job you have | Both can be sat before the experience requirement is complete |
What each credential says about you
The CIA is the global designation of the internal audit profession, held, the IIA says, by more than 220,000 people in 170 countries. The 2025 syllabus certifies competence across the whole mandate of the function: the Global Internal Audit Standards, independence and ethics and professionalism, governance, risk and control, fraud risk, engagement planning, evidence and analysis, managing the function, quality, and communicating and monitoring results. To a hiring manager, a CIA says that you know how an audit should be run to the Standards and that you can work anywhere in an audit universe. The IIA’s own promotional material cites a member survey in which 70 percent of chief audit executives said they prefer to hire CIAs; treat that as the IIA’s claim about its own credential, but the practical point stands: the CIA is the one credential built around the internal audit role itself, so it is the one an audit committee or a CAE search can read without translation.
The CFE is the credential of fraud examination, held by roughly 60,000 people, with the ACFE’s membership above 95,000. It certifies three bodies of knowledge: how frauds and financial crimes are committed, how they are investigated and the law that governs the investigation, and how they are prevented and deterred. To a hiring manager, a CFE says that you can recognize a scheme from its traces in the records, run or support an investigation without damaging the evidence or the case, and design controls that make fraud harder. Outside internal audit it is the recognized credential for investigations, forensic accounting, insurance and healthcare special investigation units, financial crime teams and government inspectors general.
Neither credential makes you the other kind of professional. The IIA’s previous Standards drew the line explicitly: internal auditors need enough knowledge to evaluate the risk of fraud and how the organization manages it, not the expertise of a person whose primary job is detecting and investigating fraud. The CIA puts you on the right side of that line for an auditor; it does not make you an investigator. The CFE gives you the investigator’s knowledge; it does not teach you to plan a risk-based audit, manage a function or conform with the Standards. Hiring managers know the difference, which is why a CFE applying for an audit manager role is asked about the CIA, and a CIA applying for an investigations role is asked about the CFE.
The two credentials side by side
The table sets out the facts each body published as of September 2026. The CFE exam moved to a new three-section format in June 2026, so older comparisons that describe four sections are out of date.
| Dimension | CIA (IIA) | CFE (ACFE) |
|---|---|---|
| What it certifies | Internal audit practice to the Global Internal Audit Standards | Fraud examination: schemes and financial crimes, investigation and law, prevention and deterrence |
| Holders | More than 220,000 in 170 countries | Roughly 60,000 |
| Exam structure | Three parts sat separately: Part 1, 125 questions in 150 minutes; Parts 2 and 3, 100 questions in 120 minutes each | Three sections: Fraud Schemes and Financial Crimes, 120 questions in 2.5 hours; Fraud Investigations and Legal Issues, 120 questions in 2.5 hours; Fraud Prevention and Deterrence, 70 questions in 1.5 hours |
| Total testing | 325 questions, 6.5 hours | 310 questions, 6.5 hours |
| Question style | Multiple choice, heavily scenario-based | Multiple choice and true-or-false, closed book |
| Delivery | Pearson VUE test centers only; online proctoring ended in May 2025 | Remote proctoring through Prometric, or a Prometric test center |
| Passing standard | Scaled score of 600 on a 250 to 750 scale | 75 percent on each section |
| Completion window | Three years from application approval; one-time 12-month extension for $275 | 60 days from activation to complete all three sections; application valid two years, with a one-year extension for $150 |
| Retakes | 30 days after the last attempt; up to eight attempts per part | Up to five attempts per section; each retake costs $110, with a 30-day wait before the fourth and fifth |
| To sit | An approved application; degree holders and IAP holders can sit before completing the experience | 40 qualification points and ACFE Associate membership |
| To certify | Experience by education: one year with a master’s, two with a bachelor’s, five with no degree | 50 points, at least two years of fraud-related professional experience and professional recommendations |
| Membership | Optional, except for residents of the UK, Ireland and South Africa | Required to sit and to hold the credential |
| Exam fees | $990 for members, $1,515 for non-members, for the application and three parts | $480, covering processing and a first attempt at each section |
| CPE | 40 hours a year for practising CIAs, including two of ethics | 20 hours a year, including ten related to fraud and two of ethics |
| Annual cost to keep it | Renewal fee of $30 for members, $120 for non-members | ACFE membership dues |
Three rows deserve a second look. The completion window is the biggest structural difference: the CIA lets you pace three parts across three years, while the CFE opens a 60-day window that forces all three sections into two months, so the preparation must be done before you activate. Delivery matters for candidates far from a test center: the CFE can be sat at home under remote proctoring, while the CIA now requires a Pearson VUE center for every part. And the passing standards are not comparable: the CIA’s scaled 600 reflects a standard-setting method that adjusts for the difficulty of each exam form, while the CFE’s 75 percent is a percentage of each section.
What the exams test, and where they overlap
The 2025 CIA syllabus is organized around the internal audit function. Part 1 covers the foundations of internal auditing (35 percent), ethics and professionalism (20 percent), governance, risk management and control (30 percent) and fraud risks (15 percent). Part 2 covers a single engagement: planning (50 percent), information gathering, analysis and evaluation (40 percent), and supervision and communication (10 percent). Part 3 covers running the function: operations (25 percent), the audit plan (15 percent), quality (15 percent) and engagement results and monitoring (45 percent). The CFE’s three sections are organized around fraud itself: how it is committed, how it is investigated, and how it is prevented.
The overlap is real but narrower than most candidates expect. The table maps the main territories.
| Territory | In the CIA | In the CFE |
|---|---|---|
| Fraud schemes and red flags | Part 1 fraud risks domain: fraud concepts and types, the fraud triangle, red flags, controls that prevent and detect fraud | Fraud Schemes and Financial Crimes: the full scheme taxonomy, in depth, with the accounting that reveals each scheme |
| Investigation | One topic: investigation techniques and the internal auditor’s role in an investigation | Fraud Investigations and Legal Issues: planning, evidence handling, digital evidence, interviews, tracing transactions, reporting |
| Law | Not examined | Legal elements of fraud, individual rights, criminal and civil procedure, evidence law; US law first |
| Governance, risk and control | Part 1, 30 percent: governance, culture, risk management, control types and design | Fraud Prevention and Deterrence: governance, control frameworks, fraud risk assessment and management |
| Ethics | Part 1, 20 percent: the Standards’ ethics and professionalism | Ethics for fraud examiners, within the prevention section |
| Evidence and analysis | Part 2, 40 percent: relevance, sufficiency and reliability of evidence, analytics, workpapers | Evidence collection and preservation for use in legal proceedings |
| Planning | Part 2, 50 percent: engagement objectives, scope, criteria, work programs | Planning an investigation, a narrower exercise |
| Reporting | Part 3, 45 percent: communicating results, recommendations, action plans, monitoring | Writing investigation reports and giving testimony |
| Running a function | Part 3: strategy, resources, the risk-based plan, quality assurance | Not examined |
| Financial crime | Not examined in depth | Money laundering, identity theft, cyber-enabled and sector-specific frauds |
For a CIA moving to the CFE, the prevention section will feel familiar, the schemes section partly familiar from process audits and the ACFE fraud tree, and the investigations and legal section almost entirely new. That section is where an auditor’s study time goes, and the CFE guide’s ten-week plan front-loads it for that reason. For a CFE moving to the CIA, the pattern reverses: the fraud domain of Part 1 will be easy, governance and control partly familiar, and Parts 2 and 3 new, because they test how internal audit plans, performs, reports and manages under the Standards. The overlap is worth a few weeks at most in either direction.
The exams also reward different habits. CIA questions are mostly scenarios with several defensible options, and the skill is choosing the best answer under the Standards; candidates who fail usually knew the material and misjudged the scenario. CFE questions are closer to knowledge recall from the ACFE’s Fraud Examiners Manual, with true-or-false items mixed in, and the skill is breadth; candidates who fail usually skimmed a section, most often the legal material. Practise each exam the way it asks: for the CIA, timed scenario sets with the rationale read for every option, which the free CIA question bank is built around; for the CFE, coverage of the whole manual through the ACFE’s prep course.
The difference is easiest to see on a single subject. Take a vendor that turns out to be an employee’s shell company, and look at how each exam would ask about it. The two items below are our own illustrations of the styles, not questions from either exam.
- CIA style. While testing vendor payments, an internal auditor notices that a vendor added three months ago shares a home address with an accounts payable clerk, and that its invoices sit just under the approval threshold. What should the auditor do first? The options might be to interview the clerk, to notify law enforcement, to finish the planned sample and report the matter as a finding, or to inform the chief audit executive so the matter is handled under the organization’s fraud response procedures. The best answer is the last: the question tests the auditor’s role, not the auditor’s courage, and every other option either oversteps that role or understates the risk.
- CFE style. A payment to a fictitious vendor set up by an employee is an example of which kind of scheme: a billing scheme, a skimming scheme, a larceny scheme or a payroll scheme? The answer is a billing scheme, a branch of fraudulent disbursements on the fraud tree. A companion true-or-false item might state that in a skimming scheme the cash is taken before it is recorded in the books, which is true, and is exactly what distinguishes skimming from larceny.
The CIA question needs the Standards and judgment about roles; the CFE questions need the taxonomy cold. An auditor who holds both uses the two together in practice: the taxonomy to recognize the pattern in the data, and the judgment to escalate it correctly. That pairing is why the fraudulent disbursements branch of the fraud tree is among the most useful pages for either exam.
Qualifying: experience, points and membership
The CIA uses a simple experience rule tied to education: a master’s degree and one year of internal audit or equivalent experience, a bachelor’s and two years, or five years with no degree; the Internal Audit Practitioner designation also opens the program. Equivalent experience includes quality assurance, risk management, compliance, external audit and internal control work. Candidates with a degree, or with the IAP, can sit the exams before they complete the experience, and the certification is awarded once the experience is verified, provided it is complete within the three-year program window. The CIA requirements guide covers the edge cases.
The CFE uses a points system with two thresholds. You need 40 points to sit the exam and 50 points, with at least two years of fraud-related professional experience, to be certified. A bachelor’s degree or higher is worth 40 points; each year of university study short of a degree is worth ten, up to 40; each year of fraud-related professional experience is worth five; and each approved professional certification, a list that includes the CIA, the CPA and the CMA, is worth ten. Certifications add points but cannot replace the two years of experience. The ACFE treats accounting and auditing among the fields that count as fraud-related, which is why most internal auditors meet the experience requirement without changing jobs; the ACFE decides each application, and the certification application also asks for professional recommendations.
| Candidate | CFE points | Can sit? | Can certify? |
|---|---|---|---|
| Graduate in a first internal audit job, bachelor’s degree | 40 (degree) | Yes, now | After two years of qualifying experience, which also lifts the total to 50 |
| Senior auditor with a bachelor’s, the CIA and four years in audit | 40 + 10 (CIA) + 20 (four years) = 70 | Yes | Yes, if at least two of the years count as fraud-related |
| Investigator with two years of university and six years in loss prevention | 20 (study) + 30 (experience) = 50 | Yes | Yes |
| Investigator with no university study and seven years in investigations | 35 | Not yet; an eighth year reaches 40 | At ten years, or earlier with an approved certification |
| Career changer with a master’s and no fraud-related experience | 40 | Yes | Not until two years of qualifying experience |
Membership is the other structural difference. The IIA does not require membership to earn or hold the CIA, except for residents of the UK, Ireland and South Africa, although members pay lower fees. The ACFE requires Associate membership to sit the exam and continued membership to hold the credential, so the annual dues are part of the cost of being a CFE for as long as you use the letters.
What each costs in money and time
The fees are published; the study material and the time are where the real difference lies. The table uses the figures the two bodies and the main providers listed as of September 2026.
| Cost item | CIA | CFE |
|---|---|---|
| Application and exams | Application $120 for members, $240 for non-members; Part 1 $310 or $445; Parts 2 and 3 $280 or $415 each; $990 or $1,515 in total | $480, covering processing and a first attempt at each of the three sections |
| Membership | Optional in most countries; lowers the fees | ACFE Associate membership required; annual dues |
| Retake | The part fee again, after 30 days | $110 per section |
| Study material | Review courses from about $500 to $1,600 for three parts; see the review course comparison | The ACFE’s CFE Exam Prep Course, three tiers listed from $899.20 to $1,699.20 for members and $1,124 to $2,124 for non-members |
| Extensions | One-time 12-month program extension, $275; one-time 75-day registration extension, $100 | One-year application extension, $150 |
| Study time | A typical planning range of 250 to 400 hours across the three parts, over six to eighteen months | About ten to twelve weeks for a practising auditor on our CFE plan, with all sections inside 60 days |
All in, a member candidate who passes the CIA first time with a mid-priced review course spends roughly $1,900 to $2,100, plus any membership; the CIA cost guide itemizes the variants. A member candidate who passes the CFE first time with the base prep course spends roughly $1,400 plus annual dues. The CFE is cheaper and much faster to complete; the CIA costs more because it covers more. Most employers that fund one will fund the other under the same policy, and a candidate planning both should ask whether the policy caps reimbursement per year, because sequencing the two across budget years can recover the whole cost.
Time is the cost candidates underestimate. The CIA’s pacing is flexible but long: three exams, each with its own preparation, registration and result, and a 30-day wait if a part must be retaken. The CIA Study Planner turns your exam dates and weekly hours into a day-by-day schedule with the registration and result milestones. The CFE’s pacing is short but rigid: once the 60-day window opens, every section and any retake must fit inside it, which is why the CFE guide advises booking the first section before starting to study.
Keeping them: CPE, dues and ethics
A practising CIA reports 40 hours of continuing professional education a year, including two hours of ethics, with an attestation by 31 December; non-practising CIAs report 20 hours and retired CIAs none. The IIA’s annual renewal fee is $30 for members and $120 for non-members, rising to $60 and $240 for a renewal made in the grace period. The CIA CPE guide covers what counts. A CFE reports 20 hours a year, of which at least ten must relate directly to fraud and at least two to ethics, keeps the ACFE membership current, and remains bound by the ACFE Code of Professional Ethics.
Holding both is lighter than it looks. The same hours can usually be reported to both bodies when they meet each body’s rules, so a practising auditor who holds both needs 40 hours a year, at least ten of them on fraud, with ethics hours that satisfy each body. A single fraud conference, or a fraud-focused training course, covers the CFE’s specific requirement and counts toward the CIA’s forty. The discipline that matters is the log: record each session with its topic and hours, and label the fraud sessions clearly, because an auditor’s general CPE does not satisfy the CFE’s fraud-specific ten, and an audit of your CPE will ask for the evidence.
Where each moves a career
Credentials open doors unevenly. The table maps common roles to the credential that fits the work; it describes fit, not a guarantee of what any employer will ask for.
| Role | Credential that fits | Why |
|---|---|---|
| Staff and senior internal auditor | CIA | The syllabus is the job: the Standards, engagements, evidence, reporting |
| Audit manager, director, chief audit executive | CIA, with a specialist credential as a complement | Running a function, the audit plan and quality are examined only in the CIA |
| Internal auditor in banking, insurance, healthcare, government or retail | CIA, then CFE | Fraud risk is a standing part of the audit universe in these sectors |
| Forensic accountant in an advisory firm | CFE, often alongside an accounting credential | Investigation method, evidence and testimony are the work |
| Corporate or compliance investigator | CFE | Interviews, evidence handling and legal constraints are the daily risks |
| Special investigations unit, inspector general’s office | CFE | The recognized specialist credential for fraud examination |
| Financial crime and anti-money laundering compliance | CFE, or a specialist AML credential such as CAMS | Financial crimes are CFE content; AML programs have their own credentials |
| Audit analytics and continuous monitoring | Either | The CFE sharpens fraud tests; the CIA places them inside the audit plan |
On pay, both bodies publish claims and neither isolates the effect of the credential. The ACFE’s 2024 Compensation Guide reported a 32 percent pay premium for CFEs over their non-certified peers. Self-reported salary data on PayScale showed average base salaries of about $103,000 for CIAs and about $98,000 for CFEs as of May 2026. People who earn credentials also tend to be more experienced and more senior, so none of these figures proves that the letters caused the pay; what they show is that both credentials sit comfortably in professional pay bands. The internal auditor salary guide puts the numbers in context by level and sector.
The stronger career argument is optionality. An internal auditor with a CIA can move up the audit ladder, into risk and compliance, or out to the roles in the exit opportunities guide. Adding a CFE opens investigations and forensic work, and it makes the auditor the natural owner of the fraud risk assessment and the fraud analytics program inside the function. The certification roadmap by career stage places both on the timeline alongside the CISA and the CPA.
The both answer: sequencing two credentials
For an auditor who works near fraud, holding both is common and sensible, and the order matters more than the choice. There are four paths, and the right one depends on where the work is heading.
| Path | Best for | How it runs |
|---|---|---|
| CIA, then CFE | Internal auditors in fraud-exposed sectors, or who own the fraud risk assessment | The CIA over six to eighteen months; then the CFE in ten to twelve weeks, with the CIA adding ten points toward eligibility and Part 1’s fraud domain as a primer |
| CFE, then CIA | Investigators moving into internal audit, or auditors whose role is already investigative | The CFE first for the immediate job; the CIA when audit leadership becomes the goal, checking first whether investigation experience counts toward the CIA’s requirement |
| CFE only | Career investigators and forensic accountants | The CIA adds little unless you will lead an internal audit function |
| CIA only | Auditors whose plans rarely touch fraud beyond the fraud risk assessment | Part 1’s fraud domain and the fraud CPE you choose cover the need; revisit if your role changes |
Three practical rules make the two-credential path smoother. Do not study for both at once: the CIA rewards judgment under the Standards and the CFE rewards breadth of fraud knowledge, and splitting attention costs more than it saves. Start the CFE when you have a clear run of ten to twelve weeks, because the 60-day window does not pause for audit season. And use the overlap on purpose: the fraud risk assessment, the red flags library and the first 48 hours protocol on this site are written for exactly the auditor who holds, or is heading toward, both.
Deciding in five questions
If the tables have not settled it, answer these in order. First, where do you want to be in five years: leading audit work, or leading investigations? Leading audit points to the CIA; leading investigations points to the CFE. Second, what is in your job today? If allegations reach your desk every month, the CFE pays back immediately; if your plan is process and control audits, the CIA does. Third, how much study time can you protect in the next year? Ten to twelve weeks points to the CFE now and the CIA later; six months or more makes the CIA feasible. Fourth, where is your bigger gap: audit method or fraud expertise? A quick diagnostic helps: the CIA question bank’s Part 1 fraud domain and its Part 2 engagement questions will show you in twenty minutes which side is weaker. Fifth, what will your employer fund, and when? Sequence the two to the reimbursement policy, not to a résumé deadline.
Whichever you choose, choose by destination rather than prestige. The CIA vs CISA, CIA vs CPA and CIA vs CFA comparisons make the same point for the other common pairings, and the overview of internal audit certifications lists the wider field.
Questions auditors ask about the CIA and the CFE
Does the CIA count toward the CFE?
Yes. The CIA is on the ACFE’s list of approved professional certifications and adds ten qualification points. It does not replace the requirement for two years of fraud-related professional experience before certification.
Does the CFE count toward the CIA?
No. There is no exemption or credit, and the CFE is not one of the credentials that open the shorter CIA Challenge Exam, which is limited to approved accounting credentials, the CISA and, as a pilot, long professional experience.
Which exam is harder?
They are hard in different ways. The CIA is longer to prepare for and tests judgment in scenarios; the IIA publishes pass rates of 44, 48 and 56 percent for Parts 1, 2 and 3. The CFE is shorter and tests breadth, including law that most auditors have not studied. We could not find a published pass rate for the CFE’s new three-section format, so treat any comparison you read with care. The CIA difficulty guide explains why candidates fail each part.
Can I take either exam from home?
The CFE, yes: the ACFE offers remote proctoring through Prometric as well as test centers. The CIA, no: the IIA ended online proctoring in May 2025, and every part is now sat at a Pearson VUE test center.
Is the CFE worth it if I never run an investigation?
It can be. Auditors who plan fraud risk assessments, design fraud analytics or audit high-risk processes such as procurement and journal entries use scheme knowledge every week. If your work rarely touches fraud beyond the annual assessment, the money and time are better spent on the CIA, or on the CISA if your plan is mostly technology.
Do I need a law or accounting background for the CFE?
No. The points system accepts degrees in any field and several kinds of experience. The legal content is learned as exam content, and the accounting concepts are those needed to see a scheme in the records; the ACFE’s prep course covers both.
Related guides
- The CIA exam, explained — parts, fees, scoring and the study plans.
- The CFE for internal auditors — the exam sections, points and a ten-week plan.
- A certification roadmap by career stage — where each credential fits.
- The CISA for internal auditors — the technology alternative.
- CIA review courses compared — choosing the study material.
- The CIA Study Planner — a day-by-day plan with milestones and a budget.
- How to run a fraud risk assessment — where the two credentials meet.
- The ACFE fraud tree, explained — the scheme taxonomy both exams draw on.
- Internal auditor salary guide — pay by level and sector.
- The internal audit career ladder — the roles each credential supports.
Leave a Reply