,

Specialty and Retired Credentials: Making Sense of the IIA’s Changing Alphabet

Few corners of the profession change their labels as often as internal audit certification. A decade ago the IIA offered the CIA plus four specialty credentials: the CGAP for government auditors, the CFSA for financial services auditors, the CCSA for control self-assessment and the CRMA for risk management assurance. Today three of those are closed to new candidates, the CRMA has been rebuilt twice, a leadership qualification has come and gone, an entry-level designation has arrived, and the IIA sells a growing list of certificate programs that are not certifications at all. Meanwhile specialist bodies outside the IIA award credentials of their own for healthcare, government and higher education auditors.

This guide is a map of that alphabet as it stands in September 2026. It sets out the IIA’s current lineup, decodes the acronyms you will meet on résumés and in job postings, explains what happened to the retired credentials and what their holders should do now, separates certifications from certificates, and covers the specialist bodies that serve government, healthcare and university auditors. It ends with a short guide to choosing by sector. Every status and date below comes from the IIA or the body concerned; where we could not confirm something, we say so.

In this guide

The IIA’s lineup in 2026

The IIA’s certification program is simpler than it has been for twenty years. There are three credentials open to new candidates, arranged as a ladder with a specialist branch, plus a set of certificate programs that sit beside them.

CredentialStatus in September 2026What it certifiesHow you earn it
Internal Audit Practitioner (IAP)Open; a permanent certification since July 2025Entry-level knowledge of internal audit foundations, ethics, governance, risk, control and fraudPass CIA Part 1, which has been the IAP exam since 28 May 2025; the only entry requirement is government-issued identification
Certified Internal Auditor (CIA)Open; the flagshipThe whole of internal audit practice under the Global Internal Audit StandardsPass three parts, or the single Challenge Exam if you hold a qualifying credential; meet the education and experience requirement
Certification in Risk Management Assurance (CRMA)Open; standalone since July 2025Assurance and advisory work on risk management and governancePass one 120-question exam; meet the education and experience requirement; the CIA is no longer a prerequisite
Certificate programsOpen; a growing catalogueKnowledge of a specific subject, assessed at the end of a courseComplete the course and its assessment; no ongoing certification obligations

The ladder works like this. The IAP is the first rung: anyone can enter, and passing CIA Part 1 earns the designation. The IAP’s Part 1 carries forward into the CIA, so an IAP holder who goes on needs two more parts and the experience. The CIA is the professional standard, covered in depth in the CIA exam guide and its 2025 syllabus guide. The CRMA is the specialist branch for risk management assurance, assessed in our CRMA guide. Everything else the IIA offers is either a certificate program or a retired credential that existing holders can keep.

Two details of the IAP matter to anyone planning a route. IAPs awarded before 27 May 2025, when the IAP had its own exam, had to apply to the CIA program by 31 May 2026 to use the designation toward the CIA; IAPs awarded after that date keep the benefit for four years from the award. And since 2026 the IAP carries its own CPE requirement of 20 hours a year for practising holders and ten for non-practising holders, which is a reminder that it is now a certification in its own right, not only a stepping stone.

The alphabet, decoded

The acronyms below are the ones internal auditors meet most often on résumés, in job postings and in older articles. The status column is the one that matters: a retired credential on a candidate’s profile is still valid if the holder keeps renewing it, but no one new can earn it.

LettersFull nameBodyStatus
IAPInternal Audit PractitionerIIAOpen; exam is CIA Part 1
CIACertified Internal AuditorIIAOpen
CRMACertification in Risk Management AssuranceIIAOpen; CIA no longer required
CGAPCertified Government Auditing ProfessionalIIARetired; closed to new candidates, holders may renew
CFSACertified Financial Services AuditorIIARetired; closed to new candidates, holders may renew
CCSACertification in Control Self-AssessmentIIARetired; content moved into the CRMA; holders may renew
QIALQualification in Internal Audit LeadershipIIAWithdrawn; not among the IIA’s current certifications
CMIIAChartered Member of the Chartered IIAChartered IIA (UK and Ireland)Open
CHIAPCertified Healthcare Internal Audit ProfessionalAHIAOpen
CISACertified Information Systems AuditorISACAOpen
CRISCCertified in Risk and Information Systems ControlISACAOpen
CFECertified Fraud ExaminerACFEOpen; new exam format since June 2026
CGFMCertified Government Financial ManagerAGAOpen
CIGACertified Inspector General AuditorAssociation of Inspectors GeneralOpen

For the specialist credentials from other bodies, the guides to the CISA for internal auditors and the CFE for internal auditors cover the two that internal auditors pair with the CIA most often, and the certification roadmap by career stage shows where each fits in a career.

What happened to the CGAP, CFSA and CCSA

In 2018 the IIA announced that it would stop offering its three specialty certifications to new candidates. The CGAP had served government auditors, the CFSA auditors in banking, insurance and securities, and the CCSA practitioners of control self-assessment. The IIA’s transition documents set out what would happen to each: the CCSA’s relevant content would be integrated into the CRMA, on the reasoning that internal control is part of risk management, and the CGAP and CFSA would be repositioned as assessment-based certificate programs combining a curriculum, instruction and an exam. The transition documents did not give a broader rationale, although the direction was clear: one flagship certification, one specialist certification in risk, and certificates for sector knowledge.

DateStep
2018The IIA announces the retirement of the CGAP, CFSA and CCSA and publishes transition guidance
31 December 2018Last date to be certified in a specialty credential to qualify for the CIA Specialty Challenge Exam; new program applications no longer accepted
1 April 2019Applications open for the CIA Specialty Challenge Exam
1 July 2019Specialty Challenge Exam testing begins in English; other languages from 1 January 2020
15 December 2020Last date to apply for the Specialty Challenge Exam
30 June 2021Final date to test in the CGAP, CFSA and CCSA programs, and in the Specialty Challenge Exam
1 April 2021The revised CRMA program takes effect; its current syllabus lists control self-assessment among the approaches to assessing risk

Not everyone agreed. Government auditors in particular objected: the Association of Local Government Auditors wrote to the IIA in November 2018 arguing that the CGAP was well recognized as shorthand for competence in government auditing, that many local governments required or preferred it for audit positions, that it was more relevant to the government environment than the CIA, and that the government audit community had not been consulted. The IIA went ahead. The objection is worth knowing because it explains why some public-sector job postings still mention the CGAP years later, and why government auditors are more likely than most to hold credentials from bodies outside the IIA.

What replaced them, in practice, differs by credential. The CCSA’s subject matter lives on inside the CRMA, whose syllabus lists control self-assessment among the approaches to assessing risk, and the RCSA process guide covers the practice. The CFSA’s sector knowledge is served by the IIA’s financial services certificate courses. For the CGAP, we could not find a current IIA certificate program aimed specifically at government auditing; public-sector auditors today typically pair the CIA with credentials from government bodies, which the specialist bodies section covers.

If you hold a retired credential

The most important fact for holders is the simplest: the IIA’s transition guidance says CGAP, CFSA and CCSA designations continue to be valid as long as holders meet the ongoing requirements. Retirement closed the door to new candidates; it did not revoke anyone’s letters. What holders need to do is keep renewing, decide whether to add a current credential, and describe the one they hold accurately.

QuestionThe answer
Is my credential still valid?Yes, while you meet the annual renewal requirements
How many CPE hours do I need?20 hours a year if practising, 10 if non-practising, including two hours of ethics; retired holders are exempt while retired
When do I report?By 31 December each year, through the IIA’s certification system, CCMS
What does renewal cost?For the CCSA, CFSA or CGAP, $20 a year for IIA members and $120 for non-members, doubling in the grace period; some local institutes pay the member fee on their members’ behalf
I also hold the CIA. Do I need separate hours?No. The IIA’s policy lets hours earned for the specialty credential count toward the CIA’s requirement, so 40 relevant hours satisfy both
My status lapsed. Can I reinstate it?The transition guidance allowed holders in the grace period to reactivate by completing the missing CPE, and inactive holders to reinstate by meeting one period’s CPE and paying a fee; confirm the current terms in CCMS
Can I still use the Specialty Challenge Exam to earn the CIA?No. It closed on 30 June 2021
What is my route to the CIA now?The three-part exam, or the current Challenge Exam if you hold a qualifying accounting credential, the CISA, or long experience under the pilot pathway

Whether to add a current credential depends on the one you hold. A CCSA holder whose work is risk-focused has a natural next step in the CRMA, which now examines the CCSA’s subject matter inside a broader risk assurance syllabus and no longer requires the CIA. A CFSA holder in banking or insurance will usually get more from the CIA, which is the credential audit leadership roles in financial services expect, and can add sector depth through the IIA’s financial services certificates. A CGAP holder in government has the widest choice: the CIA for the profession’s standard, the CISA for technology-heavy audit plans, or a credential from a government body such as the AGA or the Association of Inspectors General.

On a CV or profile, describe the credential as it is: “CGAP (Certified Government Auditing Professional), IIA, active” is accurate and needs no apology. Avoid implying that it is still awarded, and if you let it lapse, remove it. The CPE log is the practical risk: a holder of both the CIA and a retired specialty credential should keep one log, labelled by topic, which serves both reports and survives an audit of your CPE; the CIA CPE guide covers what counts.

Three typical holders show how the decision plays out in practice.

  • A CGAP holder in a state audit office, twelve years in, no CIA. Keep the CGAP current; it is recognized in the office and costs little beyond the CPE the office’s Yellow Book work already requires, provided the hours meet the IIA’s rules too. Add the CIA through the three-part route, starting with Part 1, because it is recognized in every sector and country rather than only in government, which matters if a move to a city, a university or a regulated company ever appeals; the experience requirement is already met, so the certification follows the last pass.
  • A CFSA holder who is a CIA and leads bank audits. Keep both; the same forty hours satisfy both reports. If the audit plan is shifting toward enterprise risk and model risk, the CRMA is a low-cost addition that matches the work; if it is shifting toward fraud and financial crime, the CFE matches better.
  • A CCSA holder who facilitates risk workshops in the second line. The CRMA is the natural successor, now available without the CIA, and its syllabus includes the control self-assessment work this holder already does. Keep the CCSA while it costs only the renewal fee, and lead with the CRMA once earned.

The Specialty Challenge Exam, and today’s Challenge Exam

The name causes confusion, because there have been two different challenge exams. The CIA Specialty Challenge Exam was a transition measure for holders of the retired credentials. Candidates had to be certified in the CCSA, CFSA or CGAP by 31 December 2018 and stay actively certified throughout the process. The exam had 150 multiple-choice questions in three hours; the English version cost $895 for members and $1,095 for non-members including learning materials, and other languages $695 and $895. A failed attempt could be retaken after 60 days. Applications closed on 15 December 2020 and testing ended on 30 June 2021. Holders who passed it became CIAs; holders who did not use it now follow the normal routes.

Today’s CIA Challenge Exam is a different program for a different population. It is open to holders of approved accounting credentials from a long list of professional bodies, to active CISAs, and, under a pilot, to professionals with ten or more years of experience in internal audit or related fields. Since June 2026 it has been one unified exam of 150 questions in 180 minutes, with a syllabus aligned to the Global Internal Audit Standards, four testing windows a year, and application and exam fees well above the three-part route’s. A retired specialty credential does not qualify on its own, although a CGAP or CFSA holder with long experience may fit the experience pilot, whose 2026 application window runs to 30 September; check the pathway’s current terms before applying.

FeatureCIA Specialty Challenge ExamCIA Challenge Exam, 2026
Who it servedHolders of the CCSA, CFSA or CGAP certified by 31 December 2018Approved accounting credential holders, active CISAs, and experienced professionals under the pilot
Questions and time150 questions, 3 hours150 questions, 180 minutes
StatusClosed; testing ended 30 June 2021Open; four testing windows a year
RetakesAfter 60 days, until the program closedSee the Challenge Exam guide for current rules
Fees$895 or $1,095 in English, with materialsApplication $150 or $380, exam $845 or $1,245

QIAL and the leadership credentials

The Qualification in Internal Audit Leadership was the IIA’s attempt at a credential for chief audit executives and aspiring ones, assessed on leadership rather than technical knowledge. It is not among the IIA’s current certifications, and the Chartered IIA, which offered it in the UK and Ireland, describes it as withdrawn. The IIA still lists renewal fees for existing QIAL holders, $30 a year for members and $120 for non-members, and its renewal policy sets their CPE at 20 hours a year, the same as the specialty credentials. For practical purposes, no one can earn it today.

In the UK and Ireland, the leadership credential that matters is chartered status. The Chartered IIA awards Chartered Membership, the CMIIA, through several routes: a Chartered Leadership Programme of around 400 hours; a Chartered by Experience route for experienced practitioners, with a 2026 deadline of 19 October and a fee of £2,090 plus VAT; and direct entry for some chartered accountants. It also offers a Foundations of Internal Auditing qualification for newer practitioners and apprenticeship routes, including an internal audit technician program and a professional program, with a CIA apprenticeship that the Chartered IIA says is due in early 2027. Outside the UK and Ireland, there is no leadership certification with comparable standing; aspiring chief audit executives build the case through the CIA, a specialist credential where the function needs one, and a record of leading engagements and people, as the career ladder guide describes.

Certificates are not certifications

The distinction is easy to miss and matters on a CV. A certification, such as the CIA or the CRMA, requires an exam, education and experience, a code of ethics and annual CPE, and entitles you to use letters after your name for as long as you keep it current. A certificate program, the model the IIA chose for sector knowledge when it retired the specialty credentials, is a course with an assessment at the end: you learn the content, pass the test and receive a certificate that records the achievement. It carries no ongoing obligations and no post-nominal letters.

The IIA’s catalogue in September 2026 included certificate programs in financial services audit, quality assessment, artificial intelligence for internal audit and for coordinated assurance, COSO fraud risk management, environmental, social and governance topics, auditing the cybersecurity program, data literacy and data analytics. The Financial Services Audit Certificate, for example, carries 20 CPE hours and a 50-question exam; the Quality Assessor certificate program, 16 CPE hours and a 40-question assessment. These are useful for building knowledge and earning CPE, and for showing an interviewer that you have studied a subject, but they are not substitutes for a certification when a role asks for one.

FeatureCertification (CIA, CRMA, IAP)Certificate program
Entry requirementsEducation, experience or both, varying by credentialUsually none beyond enrolment
AssessmentProctored exam at a test centerAn assessment at the end of the course
EthicsBound by the IIA’s ethics requirements, with an ethics CPE requirementNo ongoing obligation
Ongoing requirementsAnnual CPE and renewal by 31 DecemberNone
Letters after your nameYesNo; list it under training or education
Best used forProving professional competence to employers and boardsBuilding knowledge in a subject and earning CPE

Specialist bodies beyond the IIA

Several sectors have their own associations for internal auditors, and some award their own credentials. For auditors in those sectors, these bodies often matter more day to day than any IIA specialty ever did.

Healthcare: AHIA and the CHIAP

The Association of Healthcare Internal Auditors awards the Certified Healthcare Internal Audit Professional. The standard route requires a bachelor’s degree, two years of internal audit experience within the last ten years and two years of healthcare experience within the last five; there are alternative routes for candidates with an associate degree and more experience, or with ten years of combined experience. The exam has 175 multiple-choice questions, of which 150 are scored, in four hours, and it is delivered online with remote proctoring. It costs $495 for AHIA members and $745 for non-members, with a $150 retake fee. Holders report 40 CPE hours every two years, including two of ethics and at least ten in each year. For a healthcare auditor, the CHIAP signals knowledge of billing, coding, clinical and regulatory risk that no general credential covers.

Higher education: ACUA

The Association of College and University Auditors serves internal auditors in universities and colleges. Its value lies in resources rather than a credential: its annual AuditCon conference, held in New Orleans from 27 September to 1 October 2026, a journal, practical Kick Starter audit guides, a risk dictionary for higher education and a peer review program. A university auditor typically holds the CIA and uses ACUA for the sector’s specific risks, from research grants to athletics compliance.

Government: AGA, AIG and ALGA

Government auditors have the richest set of alternatives, partly because of the CGAP’s retirement. The AGA awards the Certified Government Financial Manager, a credential for government financial management that many public-sector auditors hold. The Association of Inspectors General awards certifications for the inspector general community, including the Certified Inspector General Auditor, through its training institutes. The Association of Local Government Auditors serves city and county auditors through peer review, training and its Knighton Awards for audit reports. For government auditors working under the Government Auditing Standards, these bodies’ training also helps meet the Yellow Book’s CPE expectations, which are separate from the IIA’s.

The loss of the CGAP matters less than it once did for one further reason: the Global Internal Audit Standards now address the public sector directly. They include a section on applying the Standards in the public sector, which recognizes that government functions often have mandates set in law, funding decided by legislatures and reporting lines that differ from a corporate board. A public-sector auditor who studies for the CIA therefore meets the public-sector context inside the flagship syllabus’s source material, which was not true when the CGAP was created. The guides to governing the function and the Standards reference map show where those considerations sit.

Technology, fraud and risk

ISACA’s CISA and CRISC, the ACFE’s CFE and the risk management credentials from risk bodies are the other specialist options internal auditors add most often. They are covered in our guides to the CISA, the CFE, the CIA versus the CFE and the CRMA, which includes a comparison with the main risk credentials.

BodySectorWhat it offers
Association of Healthcare Internal Auditors (AHIA)HealthcareThe CHIAP certification, conferences and sector guidance
Association of College and University Auditors (ACUA)Higher educationAuditCon, a journal, Kick Starter guides, a risk dictionary and peer review
AGAGovernment financial managementThe CGFM certification and training
Association of Inspectors General (AIG)Inspectors generalCertifications including the CIGA, through training institutes
Association of Local Government Auditors (ALGA)Local governmentPeer review, training and the Knighton Awards
ISACATechnologyThe CISA and CRISC certifications
ACFEFraudThe CFE certification
Chartered IIAUK and IrelandChartered membership, Foundations and apprenticeships

For hiring managers: writing postings in the new alphabet

The retirements create a quiet problem in job postings. Templates written years ago still ask for credentials that no one can now earn, which shrinks the candidate pool to people certified before 2019 and signals to everyone else that the posting has not been reviewed. The fix is to ask for the capability the old credential stood for, name the current credentials that demonstrate it, and accept the retired credential as equivalent for the people who hold it.

If the posting asks forThe problemAsk instead for
CGAP requiredClosed to new candidates since 2019CIA, CGFM or an AIG certification preferred; active CGAP accepted; public-sector audit experience
CFSA requiredClosed to new candidates since 2019CIA preferred, with CRMA, CFE or CISA as relevant; active CFSA accepted; financial services audit experience
CCSA preferredClosed to new candidates since 2019CRMA preferred; active CCSA accepted; experience facilitating control self-assessment
CRMA required, with the CIA assumedSince July 2025 the CRMA no longer implies the CIAName both if you need both
QIAL preferredWithdrawnCIA plus a record of leading a function; CMIIA in the UK and Ireland
IIA certificate requiredA course, not a certificationList it as preferred training, not a requirement

Verification deserves the same care. A retired credential is valid only while the holder renews it, so confirm status rather than accepting a CV line at face value: ask the candidate for evidence of current status from the IIA, or verify through the IIA’s certification records. The same applies to the CRMA, where a pre-2021 holder earned a different syllabus from a 2026 holder, which is not a reason to prefer either but is a reason to ask what the candidate has done with it. The interview question bank includes questions that test the capability behind the letters.

Choosing by sector

With the specialty credentials gone, the practical model for most internal auditors is a base plus a specialism: the CIA as the professional standard, and at most one specialist credential chosen for the sector or the kind of work. The table sets out the combinations that fit each sector best, in our view; they are starting points, not rules.

Sector or roleBaseSpecialist additionResources beyond credentials
Federal, state or local governmentCIACGFM for financial roles; an AIG certification for inspector general offices; CISA for technology-heavy plansALGA peer review and training; the Yellow Book
Banking, insurance, securitiesCIACRMA for risk assurance, CFE for fraud-exposed roles, CISA for technologyIIA financial services certificates
HealthcareCIACHIAPAHIA conferences and guidance
Higher educationCIACISA or CFE, depending on the planACUA resources and peer review
Technology-heavy functionsCIA or CISACRISC for risk rolesISACA frameworks
Investigations and fraudCIA or CFEThe other of the twoACFE resources
Risk-focused audit leadershipCIACRMAThe IIA’s risk guidance
UK and IrelandCIA or Chartered IIA qualificationsCMIIA for leadershipChartered IIA apprenticeships

The broader lesson of the retirements is that credentials follow the profession’s own structure. The IIA consolidated around one global standard, the Global Internal Audit Standards, and one flagship certification that examines it, and it moved sector knowledge into courses. Specialist bodies filled the gaps where sector knowledge needed its own credential. A candidate choosing today should start with the base, which for almost every internal auditor is the CIA, and add a specialism only when the work calls for it. The CIA Study Planner and the free CIA practice questions are the fastest way to start on the base.

Questions about specialty and retired credentials

Can I still earn the CGAP, CFSA or CCSA?

No. New applications closed at the end of 2018 and final testing ended on 30 June 2021. Existing holders can keep their designations by renewing each year.

Is a retired credential worth keeping?

Usually, yes, if you already hold the CIA, because the renewal costs you nothing extra in CPE, since the same hours count toward both, and the fee is $20 a year for members. It remains a genuine credential that you earned, and in sectors such as government it still carries recognition. If you do not hold the CIA and the retired credential is your only one, keep it while you work toward a current credential.

Does the IIA still offer any specialty certification?

One: the CRMA, for risk management assurance, which no longer requires the CIA. Sector knowledge is now served by certificate programs rather than certifications.

I passed the old IAP exam. Does it still count toward the CIA?

It depends on when you earned it. IAPs awarded before 27 May 2025 had to apply to the CIA program by 31 May 2026 to use the designation toward the CIA; later IAPs, whose exam is CIA Part 1, keep the benefit for four years from the award. Check your record in CCMS if you are unsure.

What is the difference between the IAP and the CIA?

The IAP certifies entry-level knowledge and requires only CIA Part 1 and identification; the CIA certifies full professional competence and requires all three parts, or the Challenge Exam, plus education and experience. The IAP is a credential in its own right and the first step toward the CIA, since its exam is Part 1.

Should a government auditor take the CIA or a government credential?

For most, the CIA first, because it is the global standard and examines the Global Internal Audit Standards, which apply to public-sector functions that conform with them. Add a government credential when the role calls for it: the CGFM for financial management, an AIG certification in inspector general offices.

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading