Few corners of the profession change their labels as often as internal audit certification. A decade ago the IIA offered the CIA plus four specialty credentials: the CGAP for government auditors, the CFSA for financial services auditors, the CCSA for control self-assessment and the CRMA for risk management assurance. Today three of those are closed to new candidates, the CRMA has been rebuilt twice, a leadership qualification has come and gone, an entry-level designation has arrived, and the IIA sells a growing list of certificate programs that are not certifications at all. Meanwhile specialist bodies outside the IIA award credentials of their own for healthcare, government and higher education auditors.
This guide is a map of that alphabet as it stands in September 2026. It sets out the IIA’s current lineup, decodes the acronyms you will meet on résumés and in job postings, explains what happened to the retired credentials and what their holders should do now, separates certifications from certificates, and covers the specialist bodies that serve government, healthcare and university auditors. It ends with a short guide to choosing by sector. Every status and date below comes from the IIA or the body concerned; where we could not confirm something, we say so.
In this guide
- The IIA’s lineup in 2026
- The alphabet, decoded
- What happened to the CGAP, CFSA and CCSA
- If you hold a retired credential
- The Specialty Challenge Exam, and today’s Challenge Exam
- QIAL and the leadership credentials
- Certificates are not certifications
- Specialist bodies beyond the IIA
- For hiring managers: writing postings in the new alphabet
- Choosing by sector
- Questions about specialty and retired credentials
- Related guides
The IIA’s lineup in 2026
The IIA’s certification program is simpler than it has been for twenty years. There are three credentials open to new candidates, arranged as a ladder with a specialist branch, plus a set of certificate programs that sit beside them.
| Credential | Status in September 2026 | What it certifies | How you earn it |
|---|---|---|---|
| Internal Audit Practitioner (IAP) | Open; a permanent certification since July 2025 | Entry-level knowledge of internal audit foundations, ethics, governance, risk, control and fraud | Pass CIA Part 1, which has been the IAP exam since 28 May 2025; the only entry requirement is government-issued identification |
| Certified Internal Auditor (CIA) | Open; the flagship | The whole of internal audit practice under the Global Internal Audit Standards | Pass three parts, or the single Challenge Exam if you hold a qualifying credential; meet the education and experience requirement |
| Certification in Risk Management Assurance (CRMA) | Open; standalone since July 2025 | Assurance and advisory work on risk management and governance | Pass one 120-question exam; meet the education and experience requirement; the CIA is no longer a prerequisite |
| Certificate programs | Open; a growing catalogue | Knowledge of a specific subject, assessed at the end of a course | Complete the course and its assessment; no ongoing certification obligations |
The ladder works like this. The IAP is the first rung: anyone can enter, and passing CIA Part 1 earns the designation. The IAP’s Part 1 carries forward into the CIA, so an IAP holder who goes on needs two more parts and the experience. The CIA is the professional standard, covered in depth in the CIA exam guide and its 2025 syllabus guide. The CRMA is the specialist branch for risk management assurance, assessed in our CRMA guide. Everything else the IIA offers is either a certificate program or a retired credential that existing holders can keep.
Two details of the IAP matter to anyone planning a route. IAPs awarded before 27 May 2025, when the IAP had its own exam, had to apply to the CIA program by 31 May 2026 to use the designation toward the CIA; IAPs awarded after that date keep the benefit for four years from the award. And since 2026 the IAP carries its own CPE requirement of 20 hours a year for practising holders and ten for non-practising holders, which is a reminder that it is now a certification in its own right, not only a stepping stone.
The alphabet, decoded
The acronyms below are the ones internal auditors meet most often on résumés, in job postings and in older articles. The status column is the one that matters: a retired credential on a candidate’s profile is still valid if the holder keeps renewing it, but no one new can earn it.
| Letters | Full name | Body | Status |
|---|---|---|---|
| IAP | Internal Audit Practitioner | IIA | Open; exam is CIA Part 1 |
| CIA | Certified Internal Auditor | IIA | Open |
| CRMA | Certification in Risk Management Assurance | IIA | Open; CIA no longer required |
| CGAP | Certified Government Auditing Professional | IIA | Retired; closed to new candidates, holders may renew |
| CFSA | Certified Financial Services Auditor | IIA | Retired; closed to new candidates, holders may renew |
| CCSA | Certification in Control Self-Assessment | IIA | Retired; content moved into the CRMA; holders may renew |
| QIAL | Qualification in Internal Audit Leadership | IIA | Withdrawn; not among the IIA’s current certifications |
| CMIIA | Chartered Member of the Chartered IIA | Chartered IIA (UK and Ireland) | Open |
| CHIAP | Certified Healthcare Internal Audit Professional | AHIA | Open |
| CISA | Certified Information Systems Auditor | ISACA | Open |
| CRISC | Certified in Risk and Information Systems Control | ISACA | Open |
| CFE | Certified Fraud Examiner | ACFE | Open; new exam format since June 2026 |
| CGFM | Certified Government Financial Manager | AGA | Open |
| CIGA | Certified Inspector General Auditor | Association of Inspectors General | Open |
For the specialist credentials from other bodies, the guides to the CISA for internal auditors and the CFE for internal auditors cover the two that internal auditors pair with the CIA most often, and the certification roadmap by career stage shows where each fits in a career.
What happened to the CGAP, CFSA and CCSA
In 2018 the IIA announced that it would stop offering its three specialty certifications to new candidates. The CGAP had served government auditors, the CFSA auditors in banking, insurance and securities, and the CCSA practitioners of control self-assessment. The IIA’s transition documents set out what would happen to each: the CCSA’s relevant content would be integrated into the CRMA, on the reasoning that internal control is part of risk management, and the CGAP and CFSA would be repositioned as assessment-based certificate programs combining a curriculum, instruction and an exam. The transition documents did not give a broader rationale, although the direction was clear: one flagship certification, one specialist certification in risk, and certificates for sector knowledge.
| Date | Step |
|---|---|
| 2018 | The IIA announces the retirement of the CGAP, CFSA and CCSA and publishes transition guidance |
| 31 December 2018 | Last date to be certified in a specialty credential to qualify for the CIA Specialty Challenge Exam; new program applications no longer accepted |
| 1 April 2019 | Applications open for the CIA Specialty Challenge Exam |
| 1 July 2019 | Specialty Challenge Exam testing begins in English; other languages from 1 January 2020 |
| 15 December 2020 | Last date to apply for the Specialty Challenge Exam |
| 30 June 2021 | Final date to test in the CGAP, CFSA and CCSA programs, and in the Specialty Challenge Exam |
| 1 April 2021 | The revised CRMA program takes effect; its current syllabus lists control self-assessment among the approaches to assessing risk |
Not everyone agreed. Government auditors in particular objected: the Association of Local Government Auditors wrote to the IIA in November 2018 arguing that the CGAP was well recognized as shorthand for competence in government auditing, that many local governments required or preferred it for audit positions, that it was more relevant to the government environment than the CIA, and that the government audit community had not been consulted. The IIA went ahead. The objection is worth knowing because it explains why some public-sector job postings still mention the CGAP years later, and why government auditors are more likely than most to hold credentials from bodies outside the IIA.
What replaced them, in practice, differs by credential. The CCSA’s subject matter lives on inside the CRMA, whose syllabus lists control self-assessment among the approaches to assessing risk, and the RCSA process guide covers the practice. The CFSA’s sector knowledge is served by the IIA’s financial services certificate courses. For the CGAP, we could not find a current IIA certificate program aimed specifically at government auditing; public-sector auditors today typically pair the CIA with credentials from government bodies, which the specialist bodies section covers.
If you hold a retired credential
The most important fact for holders is the simplest: the IIA’s transition guidance says CGAP, CFSA and CCSA designations continue to be valid as long as holders meet the ongoing requirements. Retirement closed the door to new candidates; it did not revoke anyone’s letters. What holders need to do is keep renewing, decide whether to add a current credential, and describe the one they hold accurately.
| Question | The answer |
|---|---|
| Is my credential still valid? | Yes, while you meet the annual renewal requirements |
| How many CPE hours do I need? | 20 hours a year if practising, 10 if non-practising, including two hours of ethics; retired holders are exempt while retired |
| When do I report? | By 31 December each year, through the IIA’s certification system, CCMS |
| What does renewal cost? | For the CCSA, CFSA or CGAP, $20 a year for IIA members and $120 for non-members, doubling in the grace period; some local institutes pay the member fee on their members’ behalf |
| I also hold the CIA. Do I need separate hours? | No. The IIA’s policy lets hours earned for the specialty credential count toward the CIA’s requirement, so 40 relevant hours satisfy both |
| My status lapsed. Can I reinstate it? | The transition guidance allowed holders in the grace period to reactivate by completing the missing CPE, and inactive holders to reinstate by meeting one period’s CPE and paying a fee; confirm the current terms in CCMS |
| Can I still use the Specialty Challenge Exam to earn the CIA? | No. It closed on 30 June 2021 |
| What is my route to the CIA now? | The three-part exam, or the current Challenge Exam if you hold a qualifying accounting credential, the CISA, or long experience under the pilot pathway |
Whether to add a current credential depends on the one you hold. A CCSA holder whose work is risk-focused has a natural next step in the CRMA, which now examines the CCSA’s subject matter inside a broader risk assurance syllabus and no longer requires the CIA. A CFSA holder in banking or insurance will usually get more from the CIA, which is the credential audit leadership roles in financial services expect, and can add sector depth through the IIA’s financial services certificates. A CGAP holder in government has the widest choice: the CIA for the profession’s standard, the CISA for technology-heavy audit plans, or a credential from a government body such as the AGA or the Association of Inspectors General.
On a CV or profile, describe the credential as it is: “CGAP (Certified Government Auditing Professional), IIA, active” is accurate and needs no apology. Avoid implying that it is still awarded, and if you let it lapse, remove it. The CPE log is the practical risk: a holder of both the CIA and a retired specialty credential should keep one log, labelled by topic, which serves both reports and survives an audit of your CPE; the CIA CPE guide covers what counts.
Three typical holders show how the decision plays out in practice.
- A CGAP holder in a state audit office, twelve years in, no CIA. Keep the CGAP current; it is recognized in the office and costs little beyond the CPE the office’s Yellow Book work already requires, provided the hours meet the IIA’s rules too. Add the CIA through the three-part route, starting with Part 1, because it is recognized in every sector and country rather than only in government, which matters if a move to a city, a university or a regulated company ever appeals; the experience requirement is already met, so the certification follows the last pass.
- A CFSA holder who is a CIA and leads bank audits. Keep both; the same forty hours satisfy both reports. If the audit plan is shifting toward enterprise risk and model risk, the CRMA is a low-cost addition that matches the work; if it is shifting toward fraud and financial crime, the CFE matches better.
- A CCSA holder who facilitates risk workshops in the second line. The CRMA is the natural successor, now available without the CIA, and its syllabus includes the control self-assessment work this holder already does. Keep the CCSA while it costs only the renewal fee, and lead with the CRMA once earned.
The Specialty Challenge Exam, and today’s Challenge Exam
The name causes confusion, because there have been two different challenge exams. The CIA Specialty Challenge Exam was a transition measure for holders of the retired credentials. Candidates had to be certified in the CCSA, CFSA or CGAP by 31 December 2018 and stay actively certified throughout the process. The exam had 150 multiple-choice questions in three hours; the English version cost $895 for members and $1,095 for non-members including learning materials, and other languages $695 and $895. A failed attempt could be retaken after 60 days. Applications closed on 15 December 2020 and testing ended on 30 June 2021. Holders who passed it became CIAs; holders who did not use it now follow the normal routes.
Today’s CIA Challenge Exam is a different program for a different population. It is open to holders of approved accounting credentials from a long list of professional bodies, to active CISAs, and, under a pilot, to professionals with ten or more years of experience in internal audit or related fields. Since June 2026 it has been one unified exam of 150 questions in 180 minutes, with a syllabus aligned to the Global Internal Audit Standards, four testing windows a year, and application and exam fees well above the three-part route’s. A retired specialty credential does not qualify on its own, although a CGAP or CFSA holder with long experience may fit the experience pilot, whose 2026 application window runs to 30 September; check the pathway’s current terms before applying.
| Feature | CIA Specialty Challenge Exam | CIA Challenge Exam, 2026 |
|---|---|---|
| Who it served | Holders of the CCSA, CFSA or CGAP certified by 31 December 2018 | Approved accounting credential holders, active CISAs, and experienced professionals under the pilot |
| Questions and time | 150 questions, 3 hours | 150 questions, 180 minutes |
| Status | Closed; testing ended 30 June 2021 | Open; four testing windows a year |
| Retakes | After 60 days, until the program closed | See the Challenge Exam guide for current rules |
| Fees | $895 or $1,095 in English, with materials | Application $150 or $380, exam $845 or $1,245 |
QIAL and the leadership credentials
The Qualification in Internal Audit Leadership was the IIA’s attempt at a credential for chief audit executives and aspiring ones, assessed on leadership rather than technical knowledge. It is not among the IIA’s current certifications, and the Chartered IIA, which offered it in the UK and Ireland, describes it as withdrawn. The IIA still lists renewal fees for existing QIAL holders, $30 a year for members and $120 for non-members, and its renewal policy sets their CPE at 20 hours a year, the same as the specialty credentials. For practical purposes, no one can earn it today.
In the UK and Ireland, the leadership credential that matters is chartered status. The Chartered IIA awards Chartered Membership, the CMIIA, through several routes: a Chartered Leadership Programme of around 400 hours; a Chartered by Experience route for experienced practitioners, with a 2026 deadline of 19 October and a fee of £2,090 plus VAT; and direct entry for some chartered accountants. It also offers a Foundations of Internal Auditing qualification for newer practitioners and apprenticeship routes, including an internal audit technician program and a professional program, with a CIA apprenticeship that the Chartered IIA says is due in early 2027. Outside the UK and Ireland, there is no leadership certification with comparable standing; aspiring chief audit executives build the case through the CIA, a specialist credential where the function needs one, and a record of leading engagements and people, as the career ladder guide describes.
Certificates are not certifications
The distinction is easy to miss and matters on a CV. A certification, such as the CIA or the CRMA, requires an exam, education and experience, a code of ethics and annual CPE, and entitles you to use letters after your name for as long as you keep it current. A certificate program, the model the IIA chose for sector knowledge when it retired the specialty credentials, is a course with an assessment at the end: you learn the content, pass the test and receive a certificate that records the achievement. It carries no ongoing obligations and no post-nominal letters.
The IIA’s catalogue in September 2026 included certificate programs in financial services audit, quality assessment, artificial intelligence for internal audit and for coordinated assurance, COSO fraud risk management, environmental, social and governance topics, auditing the cybersecurity program, data literacy and data analytics. The Financial Services Audit Certificate, for example, carries 20 CPE hours and a 50-question exam; the Quality Assessor certificate program, 16 CPE hours and a 40-question assessment. These are useful for building knowledge and earning CPE, and for showing an interviewer that you have studied a subject, but they are not substitutes for a certification when a role asks for one.
| Feature | Certification (CIA, CRMA, IAP) | Certificate program |
|---|---|---|
| Entry requirements | Education, experience or both, varying by credential | Usually none beyond enrolment |
| Assessment | Proctored exam at a test center | An assessment at the end of the course |
| Ethics | Bound by the IIA’s ethics requirements, with an ethics CPE requirement | No ongoing obligation |
| Ongoing requirements | Annual CPE and renewal by 31 December | None |
| Letters after your name | Yes | No; list it under training or education |
| Best used for | Proving professional competence to employers and boards | Building knowledge in a subject and earning CPE |
Specialist bodies beyond the IIA
Several sectors have their own associations for internal auditors, and some award their own credentials. For auditors in those sectors, these bodies often matter more day to day than any IIA specialty ever did.
Healthcare: AHIA and the CHIAP
The Association of Healthcare Internal Auditors awards the Certified Healthcare Internal Audit Professional. The standard route requires a bachelor’s degree, two years of internal audit experience within the last ten years and two years of healthcare experience within the last five; there are alternative routes for candidates with an associate degree and more experience, or with ten years of combined experience. The exam has 175 multiple-choice questions, of which 150 are scored, in four hours, and it is delivered online with remote proctoring. It costs $495 for AHIA members and $745 for non-members, with a $150 retake fee. Holders report 40 CPE hours every two years, including two of ethics and at least ten in each year. For a healthcare auditor, the CHIAP signals knowledge of billing, coding, clinical and regulatory risk that no general credential covers.
Higher education: ACUA
The Association of College and University Auditors serves internal auditors in universities and colleges. Its value lies in resources rather than a credential: its annual AuditCon conference, held in New Orleans from 27 September to 1 October 2026, a journal, practical Kick Starter audit guides, a risk dictionary for higher education and a peer review program. A university auditor typically holds the CIA and uses ACUA for the sector’s specific risks, from research grants to athletics compliance.
Government: AGA, AIG and ALGA
Government auditors have the richest set of alternatives, partly because of the CGAP’s retirement. The AGA awards the Certified Government Financial Manager, a credential for government financial management that many public-sector auditors hold. The Association of Inspectors General awards certifications for the inspector general community, including the Certified Inspector General Auditor, through its training institutes. The Association of Local Government Auditors serves city and county auditors through peer review, training and its Knighton Awards for audit reports. For government auditors working under the Government Auditing Standards, these bodies’ training also helps meet the Yellow Book’s CPE expectations, which are separate from the IIA’s.
The loss of the CGAP matters less than it once did for one further reason: the Global Internal Audit Standards now address the public sector directly. They include a section on applying the Standards in the public sector, which recognizes that government functions often have mandates set in law, funding decided by legislatures and reporting lines that differ from a corporate board. A public-sector auditor who studies for the CIA therefore meets the public-sector context inside the flagship syllabus’s source material, which was not true when the CGAP was created. The guides to governing the function and the Standards reference map show where those considerations sit.
Technology, fraud and risk
ISACA’s CISA and CRISC, the ACFE’s CFE and the risk management credentials from risk bodies are the other specialist options internal auditors add most often. They are covered in our guides to the CISA, the CFE, the CIA versus the CFE and the CRMA, which includes a comparison with the main risk credentials.
| Body | Sector | What it offers |
|---|---|---|
| Association of Healthcare Internal Auditors (AHIA) | Healthcare | The CHIAP certification, conferences and sector guidance |
| Association of College and University Auditors (ACUA) | Higher education | AuditCon, a journal, Kick Starter guides, a risk dictionary and peer review |
| AGA | Government financial management | The CGFM certification and training |
| Association of Inspectors General (AIG) | Inspectors general | Certifications including the CIGA, through training institutes |
| Association of Local Government Auditors (ALGA) | Local government | Peer review, training and the Knighton Awards |
| ISACA | Technology | The CISA and CRISC certifications |
| ACFE | Fraud | The CFE certification |
| Chartered IIA | UK and Ireland | Chartered membership, Foundations and apprenticeships |
For hiring managers: writing postings in the new alphabet
The retirements create a quiet problem in job postings. Templates written years ago still ask for credentials that no one can now earn, which shrinks the candidate pool to people certified before 2019 and signals to everyone else that the posting has not been reviewed. The fix is to ask for the capability the old credential stood for, name the current credentials that demonstrate it, and accept the retired credential as equivalent for the people who hold it.
| If the posting asks for | The problem | Ask instead for |
|---|---|---|
| CGAP required | Closed to new candidates since 2019 | CIA, CGFM or an AIG certification preferred; active CGAP accepted; public-sector audit experience |
| CFSA required | Closed to new candidates since 2019 | CIA preferred, with CRMA, CFE or CISA as relevant; active CFSA accepted; financial services audit experience |
| CCSA preferred | Closed to new candidates since 2019 | CRMA preferred; active CCSA accepted; experience facilitating control self-assessment |
| CRMA required, with the CIA assumed | Since July 2025 the CRMA no longer implies the CIA | Name both if you need both |
| QIAL preferred | Withdrawn | CIA plus a record of leading a function; CMIIA in the UK and Ireland |
| IIA certificate required | A course, not a certification | List it as preferred training, not a requirement |
Verification deserves the same care. A retired credential is valid only while the holder renews it, so confirm status rather than accepting a CV line at face value: ask the candidate for evidence of current status from the IIA, or verify through the IIA’s certification records. The same applies to the CRMA, where a pre-2021 holder earned a different syllabus from a 2026 holder, which is not a reason to prefer either but is a reason to ask what the candidate has done with it. The interview question bank includes questions that test the capability behind the letters.
Choosing by sector
With the specialty credentials gone, the practical model for most internal auditors is a base plus a specialism: the CIA as the professional standard, and at most one specialist credential chosen for the sector or the kind of work. The table sets out the combinations that fit each sector best, in our view; they are starting points, not rules.
| Sector or role | Base | Specialist addition | Resources beyond credentials |
|---|---|---|---|
| Federal, state or local government | CIA | CGFM for financial roles; an AIG certification for inspector general offices; CISA for technology-heavy plans | ALGA peer review and training; the Yellow Book |
| Banking, insurance, securities | CIA | CRMA for risk assurance, CFE for fraud-exposed roles, CISA for technology | IIA financial services certificates |
| Healthcare | CIA | CHIAP | AHIA conferences and guidance |
| Higher education | CIA | CISA or CFE, depending on the plan | ACUA resources and peer review |
| Technology-heavy functions | CIA or CISA | CRISC for risk roles | ISACA frameworks |
| Investigations and fraud | CIA or CFE | The other of the two | ACFE resources |
| Risk-focused audit leadership | CIA | CRMA | The IIA’s risk guidance |
| UK and Ireland | CIA or Chartered IIA qualifications | CMIIA for leadership | Chartered IIA apprenticeships |
The broader lesson of the retirements is that credentials follow the profession’s own structure. The IIA consolidated around one global standard, the Global Internal Audit Standards, and one flagship certification that examines it, and it moved sector knowledge into courses. Specialist bodies filled the gaps where sector knowledge needed its own credential. A candidate choosing today should start with the base, which for almost every internal auditor is the CIA, and add a specialism only when the work calls for it. The CIA Study Planner and the free CIA practice questions are the fastest way to start on the base.
Questions about specialty and retired credentials
Can I still earn the CGAP, CFSA or CCSA?
No. New applications closed at the end of 2018 and final testing ended on 30 June 2021. Existing holders can keep their designations by renewing each year.
Is a retired credential worth keeping?
Usually, yes, if you already hold the CIA, because the renewal costs you nothing extra in CPE, since the same hours count toward both, and the fee is $20 a year for members. It remains a genuine credential that you earned, and in sectors such as government it still carries recognition. If you do not hold the CIA and the retired credential is your only one, keep it while you work toward a current credential.
Does the IIA still offer any specialty certification?
One: the CRMA, for risk management assurance, which no longer requires the CIA. Sector knowledge is now served by certificate programs rather than certifications.
I passed the old IAP exam. Does it still count toward the CIA?
It depends on when you earned it. IAPs awarded before 27 May 2025 had to apply to the CIA program by 31 May 2026 to use the designation toward the CIA; later IAPs, whose exam is CIA Part 1, keep the benefit for four years from the award. Check your record in CCMS if you are unsure.
What is the difference between the IAP and the CIA?
The IAP certifies entry-level knowledge and requires only CIA Part 1 and identification; the CIA certifies full professional competence and requires all three parts, or the Challenge Exam, plus education and experience. The IAP is a credential in its own right and the first step toward the CIA, since its exam is Part 1.
Should a government auditor take the CIA or a government credential?
For most, the CIA first, because it is the global standard and examines the Global Internal Audit Standards, which apply to public-sector functions that conform with them. Add a government credential when the role calls for it: the CGFM for financial management, an AIG certification in inspector general offices.
Related guides
- The CIA exam, explained — the flagship credential in full.
- The CRMA — the IIA’s remaining specialty certification.
- The CIA Challenge Exam — the shorter route for qualified professionals.
- A certification roadmap by career stage — the base-plus-specialism model over a career.
- The CISA for internal auditors — the technology specialism.
- The CFE for internal auditors — the fraud specialism.
- CIA vs CFE — the generalist and the specialist compared.
- CIA CPE requirements — one log for every credential you hold.
- Internal audit certifications, overview — the wider field.
- The internal audit career ladder — where credentials matter at each level.
Leave a Reply