, ,

CIA vs CFE: Assurance Generalist or Fraud Specialist?

The Certified Internal Auditor and the Certified Fraud Examiner answer different questions. The CIA, awarded by the Institute of Internal Auditors, says you know how internal audit should be done: the Global Internal Audit Standards, the engagement from planning to follow-up, and the governance, risk and control territory the function covers. The CFE, awarded by the Association of Certified Fraud Examiners, says you know how fraud is committed, detected, investigated and prevented, including the law and the interview room. One is a generalist’s credential for a profession. The other is a specialist’s credential for a problem every profession meets.

That difference settles most of the choice, and it is why the question is usually framed badly. For most internal auditors it is not “CIA or CFE?” but “which first, and is the second worth it?” This guide compares the two on what they signal, what the exams test and where they overlap, what it takes to qualify, what they cost in money and time, what it takes to keep them and where each moves a career. It then sets out the two-credential path for auditors who work near fraud and a short way to decide. Figures are those the IIA and the ACFE published as of September 2026. For each credential in depth, see the CIA exam guide and the CFE guide for internal auditors.

In this guide

The short answer

If you intend to build a career in internal audit, and especially if you want to lead a function one day, the CIA comes first. It is the profession’s own designation, its content matches the job, and it is the credential a search for an audit manager or chief audit executive will assume you hold. If your work is, or is about to become, investigations, forensic accounting, an anti-fraud program, compliance investigations or special investigations in insurance or government, the CFE comes first, because it names the specialism and its content is the job. If you are an internal auditor who keeps being handed the allegations, the answer is both, usually in that order: the CIA counts toward CFE eligibility, and with the CIA’s foundations in place the CFE takes weeks of study rather than months.

Your situationFirst credentialWhy
Staff or senior internal auditor who intends to stay in internal auditCIAThe profession’s designation; the syllabus is the job; expected on the path to management
Auditor aiming at audit manager, director or chief audit executiveCIALeadership of a function is examined in the CIA, not the CFE; a CFE can follow as a complement
Auditor on a fraud-focused team, or the person who gets the hotline casesCIA, then CFE; or CFE first if the move is imminentBoth are used every week; the CIA adds ten points toward CFE eligibility
Investigator, forensic accountant, insurance special investigations, inspector general’s officeCFEThe specialism’s credential; the CIA matters only if you move into audit leadership
Compliance professional who runs internal investigationsCFEInvestigation method, evidence and legal constraints are the gaps it fills
Audit data analyst building fraud testsEither; CFE if the fraud work is the careerScheme knowledge sharpens the tests; the CIA frames them inside the audit plan
Graduate in a first audit or investigations jobThe one that matches the job you haveBoth can be sat before the experience requirement is complete

What each credential says about you

The CIA is the global designation of the internal audit profession, held, the IIA says, by more than 220,000 people in 170 countries. The 2025 syllabus certifies competence across the whole mandate of the function: the Global Internal Audit Standards, independence and ethics and professionalism, governance, risk and control, fraud risk, engagement planning, evidence and analysis, managing the function, quality, and communicating and monitoring results. To a hiring manager, a CIA says that you know how an audit should be run to the Standards and that you can work anywhere in an audit universe. The IIA’s own promotional material cites a member survey in which 70 percent of chief audit executives said they prefer to hire CIAs; treat that as the IIA’s claim about its own credential, but the practical point stands: the CIA is the one credential built around the internal audit role itself, so it is the one an audit committee or a CAE search can read without translation.

The CFE is the credential of fraud examination, held by roughly 60,000 people, with the ACFE’s membership above 95,000. It certifies three bodies of knowledge: how frauds and financial crimes are committed, how they are investigated and the law that governs the investigation, and how they are prevented and deterred. To a hiring manager, a CFE says that you can recognize a scheme from its traces in the records, run or support an investigation without damaging the evidence or the case, and design controls that make fraud harder. Outside internal audit it is the recognized credential for investigations, forensic accounting, insurance and healthcare special investigation units, financial crime teams and government inspectors general.

Neither credential makes you the other kind of professional. The IIA’s previous Standards drew the line explicitly: internal auditors need enough knowledge to evaluate the risk of fraud and how the organization manages it, not the expertise of a person whose primary job is detecting and investigating fraud. The CIA puts you on the right side of that line for an auditor; it does not make you an investigator. The CFE gives you the investigator’s knowledge; it does not teach you to plan a risk-based audit, manage a function or conform with the Standards. Hiring managers know the difference, which is why a CFE applying for an audit manager role is asked about the CIA, and a CIA applying for an investigations role is asked about the CFE.

The two credentials side by side

The table sets out the facts each body published as of September 2026. The CFE exam moved to a new three-section format in June 2026, so older comparisons that describe four sections are out of date.

DimensionCIA (IIA)CFE (ACFE)
What it certifiesInternal audit practice to the Global Internal Audit StandardsFraud examination: schemes and financial crimes, investigation and law, prevention and deterrence
HoldersMore than 220,000 in 170 countriesRoughly 60,000
Exam structureThree parts sat separately: Part 1, 125 questions in 150 minutes; Parts 2 and 3, 100 questions in 120 minutes eachThree sections: Fraud Schemes and Financial Crimes, 120 questions in 2.5 hours; Fraud Investigations and Legal Issues, 120 questions in 2.5 hours; Fraud Prevention and Deterrence, 70 questions in 1.5 hours
Total testing325 questions, 6.5 hours310 questions, 6.5 hours
Question styleMultiple choice, heavily scenario-basedMultiple choice and true-or-false, closed book
DeliveryPearson VUE test centers only; online proctoring ended in May 2025Remote proctoring through Prometric, or a Prometric test center
Passing standardScaled score of 600 on a 250 to 750 scale75 percent on each section
Completion windowThree years from application approval; one-time 12-month extension for $27560 days from activation to complete all three sections; application valid two years, with a one-year extension for $150
Retakes30 days after the last attempt; up to eight attempts per partUp to five attempts per section; each retake costs $110, with a 30-day wait before the fourth and fifth
To sitAn approved application; degree holders and IAP holders can sit before completing the experience40 qualification points and ACFE Associate membership
To certifyExperience by education: one year with a master’s, two with a bachelor’s, five with no degree50 points, at least two years of fraud-related professional experience and professional recommendations
MembershipOptional, except for residents of the UK, Ireland and South AfricaRequired to sit and to hold the credential
Exam fees$990 for members, $1,515 for non-members, for the application and three parts$480, covering processing and a first attempt at each section
CPE40 hours a year for practising CIAs, including two of ethics20 hours a year, including ten related to fraud and two of ethics
Annual cost to keep itRenewal fee of $30 for members, $120 for non-membersACFE membership dues

Three rows deserve a second look. The completion window is the biggest structural difference: the CIA lets you pace three parts across three years, while the CFE opens a 60-day window that forces all three sections into two months, so the preparation must be done before you activate. Delivery matters for candidates far from a test center: the CFE can be sat at home under remote proctoring, while the CIA now requires a Pearson VUE center for every part. And the passing standards are not comparable: the CIA’s scaled 600 reflects a standard-setting method that adjusts for the difficulty of each exam form, while the CFE’s 75 percent is a percentage of each section.

What the exams test, and where they overlap

The 2025 CIA syllabus is organized around the internal audit function. Part 1 covers the foundations of internal auditing (35 percent), ethics and professionalism (20 percent), governance, risk management and control (30 percent) and fraud risks (15 percent). Part 2 covers a single engagement: planning (50 percent), information gathering, analysis and evaluation (40 percent), and supervision and communication (10 percent). Part 3 covers running the function: operations (25 percent), the audit plan (15 percent), quality (15 percent) and engagement results and monitoring (45 percent). The CFE’s three sections are organized around fraud itself: how it is committed, how it is investigated, and how it is prevented.

The overlap is real but narrower than most candidates expect. The table maps the main territories.

TerritoryIn the CIAIn the CFE
Fraud schemes and red flagsPart 1 fraud risks domain: fraud concepts and types, the fraud triangle, red flags, controls that prevent and detect fraudFraud Schemes and Financial Crimes: the full scheme taxonomy, in depth, with the accounting that reveals each scheme
InvestigationOne topic: investigation techniques and the internal auditor’s role in an investigationFraud Investigations and Legal Issues: planning, evidence handling, digital evidence, interviews, tracing transactions, reporting
LawNot examinedLegal elements of fraud, individual rights, criminal and civil procedure, evidence law; US law first
Governance, risk and controlPart 1, 30 percent: governance, culture, risk management, control types and designFraud Prevention and Deterrence: governance, control frameworks, fraud risk assessment and management
EthicsPart 1, 20 percent: the Standards’ ethics and professionalismEthics for fraud examiners, within the prevention section
Evidence and analysisPart 2, 40 percent: relevance, sufficiency and reliability of evidence, analytics, workpapersEvidence collection and preservation for use in legal proceedings
PlanningPart 2, 50 percent: engagement objectives, scope, criteria, work programsPlanning an investigation, a narrower exercise
ReportingPart 3, 45 percent: communicating results, recommendations, action plans, monitoringWriting investigation reports and giving testimony
Running a functionPart 3: strategy, resources, the risk-based plan, quality assuranceNot examined
Financial crimeNot examined in depthMoney laundering, identity theft, cyber-enabled and sector-specific frauds

For a CIA moving to the CFE, the prevention section will feel familiar, the schemes section partly familiar from process audits and the ACFE fraud tree, and the investigations and legal section almost entirely new. That section is where an auditor’s study time goes, and the CFE guide’s ten-week plan front-loads it for that reason. For a CFE moving to the CIA, the pattern reverses: the fraud domain of Part 1 will be easy, governance and control partly familiar, and Parts 2 and 3 new, because they test how internal audit plans, performs, reports and manages under the Standards. The overlap is worth a few weeks at most in either direction.

The exams also reward different habits. CIA questions are mostly scenarios with several defensible options, and the skill is choosing the best answer under the Standards; candidates who fail usually knew the material and misjudged the scenario. CFE questions are closer to knowledge recall from the ACFE’s Fraud Examiners Manual, with true-or-false items mixed in, and the skill is breadth; candidates who fail usually skimmed a section, most often the legal material. Practise each exam the way it asks: for the CIA, timed scenario sets with the rationale read for every option, which the free CIA question bank is built around; for the CFE, coverage of the whole manual through the ACFE’s prep course.

The difference is easiest to see on a single subject. Take a vendor that turns out to be an employee’s shell company, and look at how each exam would ask about it. The two items below are our own illustrations of the styles, not questions from either exam.

  • CIA style. While testing vendor payments, an internal auditor notices that a vendor added three months ago shares a home address with an accounts payable clerk, and that its invoices sit just under the approval threshold. What should the auditor do first? The options might be to interview the clerk, to notify law enforcement, to finish the planned sample and report the matter as a finding, or to inform the chief audit executive so the matter is handled under the organization’s fraud response procedures. The best answer is the last: the question tests the auditor’s role, not the auditor’s courage, and every other option either oversteps that role or understates the risk.
  • CFE style. A payment to a fictitious vendor set up by an employee is an example of which kind of scheme: a billing scheme, a skimming scheme, a larceny scheme or a payroll scheme? The answer is a billing scheme, a branch of fraudulent disbursements on the fraud tree. A companion true-or-false item might state that in a skimming scheme the cash is taken before it is recorded in the books, which is true, and is exactly what distinguishes skimming from larceny.

The CIA question needs the Standards and judgment about roles; the CFE questions need the taxonomy cold. An auditor who holds both uses the two together in practice: the taxonomy to recognize the pattern in the data, and the judgment to escalate it correctly. That pairing is why the fraudulent disbursements branch of the fraud tree is among the most useful pages for either exam.

Qualifying: experience, points and membership

The CIA uses a simple experience rule tied to education: a master’s degree and one year of internal audit or equivalent experience, a bachelor’s and two years, or five years with no degree; the Internal Audit Practitioner designation also opens the program. Equivalent experience includes quality assurance, risk management, compliance, external audit and internal control work. Candidates with a degree, or with the IAP, can sit the exams before they complete the experience, and the certification is awarded once the experience is verified, provided it is complete within the three-year program window. The CIA requirements guide covers the edge cases.

The CFE uses a points system with two thresholds. You need 40 points to sit the exam and 50 points, with at least two years of fraud-related professional experience, to be certified. A bachelor’s degree or higher is worth 40 points; each year of university study short of a degree is worth ten, up to 40; each year of fraud-related professional experience is worth five; and each approved professional certification, a list that includes the CIA, the CPA and the CMA, is worth ten. Certifications add points but cannot replace the two years of experience. The ACFE treats accounting and auditing among the fields that count as fraud-related, which is why most internal auditors meet the experience requirement without changing jobs; the ACFE decides each application, and the certification application also asks for professional recommendations.

CandidateCFE pointsCan sit?Can certify?
Graduate in a first internal audit job, bachelor’s degree40 (degree)Yes, nowAfter two years of qualifying experience, which also lifts the total to 50
Senior auditor with a bachelor’s, the CIA and four years in audit40 + 10 (CIA) + 20 (four years) = 70YesYes, if at least two of the years count as fraud-related
Investigator with two years of university and six years in loss prevention20 (study) + 30 (experience) = 50YesYes
Investigator with no university study and seven years in investigations35Not yet; an eighth year reaches 40At ten years, or earlier with an approved certification
Career changer with a master’s and no fraud-related experience40YesNot until two years of qualifying experience

Membership is the other structural difference. The IIA does not require membership to earn or hold the CIA, except for residents of the UK, Ireland and South Africa, although members pay lower fees. The ACFE requires Associate membership to sit the exam and continued membership to hold the credential, so the annual dues are part of the cost of being a CFE for as long as you use the letters.

What each costs in money and time

The fees are published; the study material and the time are where the real difference lies. The table uses the figures the two bodies and the main providers listed as of September 2026.

Cost itemCIACFE
Application and examsApplication $120 for members, $240 for non-members; Part 1 $310 or $445; Parts 2 and 3 $280 or $415 each; $990 or $1,515 in total$480, covering processing and a first attempt at each of the three sections
MembershipOptional in most countries; lowers the feesACFE Associate membership required; annual dues
RetakeThe part fee again, after 30 days$110 per section
Study materialReview courses from about $500 to $1,600 for three parts; see the review course comparisonThe ACFE’s CFE Exam Prep Course, three tiers listed from $899.20 to $1,699.20 for members and $1,124 to $2,124 for non-members
ExtensionsOne-time 12-month program extension, $275; one-time 75-day registration extension, $100One-year application extension, $150
Study timeA typical planning range of 250 to 400 hours across the three parts, over six to eighteen monthsAbout ten to twelve weeks for a practising auditor on our CFE plan, with all sections inside 60 days

All in, a member candidate who passes the CIA first time with a mid-priced review course spends roughly $1,900 to $2,100, plus any membership; the CIA cost guide itemizes the variants. A member candidate who passes the CFE first time with the base prep course spends roughly $1,400 plus annual dues. The CFE is cheaper and much faster to complete; the CIA costs more because it covers more. Most employers that fund one will fund the other under the same policy, and a candidate planning both should ask whether the policy caps reimbursement per year, because sequencing the two across budget years can recover the whole cost.

Time is the cost candidates underestimate. The CIA’s pacing is flexible but long: three exams, each with its own preparation, registration and result, and a 30-day wait if a part must be retaken. The CIA Study Planner turns your exam dates and weekly hours into a day-by-day schedule with the registration and result milestones. The CFE’s pacing is short but rigid: once the 60-day window opens, every section and any retake must fit inside it, which is why the CFE guide advises booking the first section before starting to study.

Keeping them: CPE, dues and ethics

A practising CIA reports 40 hours of continuing professional education a year, including two hours of ethics, with an attestation by 31 December; non-practising CIAs report 20 hours and retired CIAs none. The IIA’s annual renewal fee is $30 for members and $120 for non-members, rising to $60 and $240 for a renewal made in the grace period. The CIA CPE guide covers what counts. A CFE reports 20 hours a year, of which at least ten must relate directly to fraud and at least two to ethics, keeps the ACFE membership current, and remains bound by the ACFE Code of Professional Ethics.

Holding both is lighter than it looks. The same hours can usually be reported to both bodies when they meet each body’s rules, so a practising auditor who holds both needs 40 hours a year, at least ten of them on fraud, with ethics hours that satisfy each body. A single fraud conference, or a fraud-focused training course, covers the CFE’s specific requirement and counts toward the CIA’s forty. The discipline that matters is the log: record each session with its topic and hours, and label the fraud sessions clearly, because an auditor’s general CPE does not satisfy the CFE’s fraud-specific ten, and an audit of your CPE will ask for the evidence.

Where each moves a career

Credentials open doors unevenly. The table maps common roles to the credential that fits the work; it describes fit, not a guarantee of what any employer will ask for.

RoleCredential that fitsWhy
Staff and senior internal auditorCIAThe syllabus is the job: the Standards, engagements, evidence, reporting
Audit manager, director, chief audit executiveCIA, with a specialist credential as a complementRunning a function, the audit plan and quality are examined only in the CIA
Internal auditor in banking, insurance, healthcare, government or retailCIA, then CFEFraud risk is a standing part of the audit universe in these sectors
Forensic accountant in an advisory firmCFE, often alongside an accounting credentialInvestigation method, evidence and testimony are the work
Corporate or compliance investigatorCFEInterviews, evidence handling and legal constraints are the daily risks
Special investigations unit, inspector general’s officeCFEThe recognized specialist credential for fraud examination
Financial crime and anti-money laundering complianceCFE, or a specialist AML credential such as CAMSFinancial crimes are CFE content; AML programs have their own credentials
Audit analytics and continuous monitoringEitherThe CFE sharpens fraud tests; the CIA places them inside the audit plan

On pay, both bodies publish claims and neither isolates the effect of the credential. The ACFE’s 2024 Compensation Guide reported a 32 percent pay premium for CFEs over their non-certified peers. Self-reported salary data on PayScale showed average base salaries of about $103,000 for CIAs and about $98,000 for CFEs as of May 2026. People who earn credentials also tend to be more experienced and more senior, so none of these figures proves that the letters caused the pay; what they show is that both credentials sit comfortably in professional pay bands. The internal auditor salary guide puts the numbers in context by level and sector.

The stronger career argument is optionality. An internal auditor with a CIA can move up the audit ladder, into risk and compliance, or out to the roles in the exit opportunities guide. Adding a CFE opens investigations and forensic work, and it makes the auditor the natural owner of the fraud risk assessment and the fraud analytics program inside the function. The certification roadmap by career stage places both on the timeline alongside the CISA and the CPA.

The both answer: sequencing two credentials

For an auditor who works near fraud, holding both is common and sensible, and the order matters more than the choice. There are four paths, and the right one depends on where the work is heading.

PathBest forHow it runs
CIA, then CFEInternal auditors in fraud-exposed sectors, or who own the fraud risk assessmentThe CIA over six to eighteen months; then the CFE in ten to twelve weeks, with the CIA adding ten points toward eligibility and Part 1’s fraud domain as a primer
CFE, then CIAInvestigators moving into internal audit, or auditors whose role is already investigativeThe CFE first for the immediate job; the CIA when audit leadership becomes the goal, checking first whether investigation experience counts toward the CIA’s requirement
CFE onlyCareer investigators and forensic accountantsThe CIA adds little unless you will lead an internal audit function
CIA onlyAuditors whose plans rarely touch fraud beyond the fraud risk assessmentPart 1’s fraud domain and the fraud CPE you choose cover the need; revisit if your role changes

Three practical rules make the two-credential path smoother. Do not study for both at once: the CIA rewards judgment under the Standards and the CFE rewards breadth of fraud knowledge, and splitting attention costs more than it saves. Start the CFE when you have a clear run of ten to twelve weeks, because the 60-day window does not pause for audit season. And use the overlap on purpose: the fraud risk assessment, the red flags library and the first 48 hours protocol on this site are written for exactly the auditor who holds, or is heading toward, both.

Deciding in five questions

If the tables have not settled it, answer these in order. First, where do you want to be in five years: leading audit work, or leading investigations? Leading audit points to the CIA; leading investigations points to the CFE. Second, what is in your job today? If allegations reach your desk every month, the CFE pays back immediately; if your plan is process and control audits, the CIA does. Third, how much study time can you protect in the next year? Ten to twelve weeks points to the CFE now and the CIA later; six months or more makes the CIA feasible. Fourth, where is your bigger gap: audit method or fraud expertise? A quick diagnostic helps: the CIA question bank’s Part 1 fraud domain and its Part 2 engagement questions will show you in twenty minutes which side is weaker. Fifth, what will your employer fund, and when? Sequence the two to the reimbursement policy, not to a résumé deadline.

Whichever you choose, choose by destination rather than prestige. The CIA vs CISA, CIA vs CPA and CIA vs CFA comparisons make the same point for the other common pairings, and the overview of internal audit certifications lists the wider field.

Questions auditors ask about the CIA and the CFE

Does the CIA count toward the CFE?

Yes. The CIA is on the ACFE’s list of approved professional certifications and adds ten qualification points. It does not replace the requirement for two years of fraud-related professional experience before certification.

Does the CFE count toward the CIA?

No. There is no exemption or credit, and the CFE is not one of the credentials that open the shorter CIA Challenge Exam, which is limited to approved accounting credentials, the CISA and, as a pilot, long professional experience.

Which exam is harder?

They are hard in different ways. The CIA is longer to prepare for and tests judgment in scenarios; the IIA publishes pass rates of 44, 48 and 56 percent for Parts 1, 2 and 3. The CFE is shorter and tests breadth, including law that most auditors have not studied. We could not find a published pass rate for the CFE’s new three-section format, so treat any comparison you read with care. The CIA difficulty guide explains why candidates fail each part.

Can I take either exam from home?

The CFE, yes: the ACFE offers remote proctoring through Prometric as well as test centers. The CIA, no: the IIA ended online proctoring in May 2025, and every part is now sat at a Pearson VUE test center.

Is the CFE worth it if I never run an investigation?

It can be. Auditors who plan fraud risk assessments, design fraud analytics or audit high-risk processes such as procurement and journal entries use scheme knowledge every week. If your work rarely touches fraud beyond the annual assessment, the money and time are better spent on the CIA, or on the CISA if your plan is mostly technology.

Do I need a law or accounting background for the CFE?

No. The points system accepts degrees in any field and several kinds of experience. The legal content is learned as exam content, and the accounting concepts are those needed to see a scheme in the records; the ACFE’s prep course covers both.

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading