CIA resources

CIA Part 1: Internal Audit Fundamentals — the complete guide

Everything a candidate needs to know about CIA Part 1, Internal Audit Fundamentals: what the exam tests and in what format, the four official syllabus domains with the IIA's published weights, the concepts you must be able to apply — not just recite — from the Global Internal Audit Standards, two original worked examples, and a study approach that matches effort to weight. All factual claims are maintained against the official IIA sources cited at the end of this page. Certuvo is an independent study resource and is not affiliated with or endorsed by The Institute of Internal Auditors.

STATEMENT — REVIEWEDPROGRESS
Published
Last reviewed
Next review
Reading time
12 min

What Part 1 tests — and why it comes first for most candidates

Part 1, Internal Audit Fundamentals, is the longest of the three CIA exam parts: the IIA's published exam information lists it at 125 multiple-choice questions in 2.5 hours (Parts 2 and 3 each have 100 questions in 2 hours). Like the rest of the CIA exam it is delivered by computer-based testing, and the IIA permits candidates to take the parts in any order.

The name is accurate. Part 1 tests the conceptual foundation of the entire profession: what internal auditing is for, the authority and responsibility of the internal audit function, the ethical principles that govern individual auditors, how governance, risk management and control fit together, and how fraud risk enters that picture. Since the IIA's syllabus update effective May 2025, that foundation is framed by the Global Internal Audit Standards — the framework that replaced the previous International Professional Practices Framework (IPPF) — so current-syllabus fluency in the Standards' structure and vocabulary is non-negotiable.

This is also why most candidates take Part 1 first even though no rule requires it. The distinctions Part 1 drills — assurance versus advisory work, independence versus objectivity, inherent versus residual risk, the roles of the board, management and internal audit — are the working vocabulary of Part 2 (how engagements are managed and performed) and the backdrop to Part 3 (how the internal audit function itself is run). Time invested in genuinely understanding Part 1 concepts, rather than memorising them, is repaid across all three parts.

The four syllabus domains and their official weights

The IIA's exam syllabus divides Part 1 into four domains and publishes the weight of each — the approximate share of exam questions drawn from that domain. The weights below are the IIA's, not ours, and they should drive how you allocate study time.

CIA Part 1 syllabus domains and official weights (IIA exam syllabus)
DomainWeightWhat it covers
Foundations of Internal Auditing35%The purpose, authority and responsibility of internal audit; the Global Internal Audit Standards; assurance and advisory services; independence of the function.
Ethics and Professionalism20%The ethical principles and professional conduct expected of internal auditors, including objectivity and competence.
Governance, Risk Management, and Control30%Governance structures and roles; risk management concepts including risk appetite; control types and control frameworks.
Fraud Risks15%Fraud awareness: red flags, types of fraud, and the basics of fraud risk management and internal audit's role in it.

Two-thirds of the exam sits in just two domains: Foundations (35%) and Governance, Risk Management, and Control (30%). That does not make Ethics and Fraud optional — at 20% and 15% they can still decide a pass — but it tells you where depth matters most.

The concepts you must master, domain by domain

Part 1 rewards candidates who can apply concepts to short scenarios, not recite definitions. Here is what mastery looks like in each domain.

Domain: Foundations of Internal Auditing

  • Purpose, authority and responsibility of internal audit. Be able to explain what internal auditing exists to do — provide independent assurance and advice on governance, risk management and control — and how its mandate is established and documented (notably through the internal audit charter) with the board and senior management.
  • The structure of the Global Internal Audit Standards. Know how the Standards are organised into domains spanning the purpose of internal auditing, ethics and professionalism, governing the function, managing the function, and performing engagements — and where a given requirement or principle would live. You do not need to recite Standards text; you need to navigate their topics confidently.
  • Assurance versus advisory engagements. Assurance work provides an independent assessment for reliance by the board and others; advisory work provides advice and insight, generally at management's request and without the same independent assessment being communicated for others to rely on. Many Part 1 questions turn on spotting which type a scenario describes and which expectations follow.
  • Independence versus objectivity. The distinction that trips up more candidates than any other. Independence is an attribute of the internal audit function — its positioning, typically reporting functionally to the board, that frees it from interference. Objectivity is an attribute of the individual auditor — an unbiased mental attitude. A function can be independent while an individual auditor's objectivity is impaired, and vice versa.

Domain: Ethics and Professionalism

  • The ethical principles. The Global Internal Audit Standards set out principles covering integrity, objectivity, competency, due professional care and confidentiality. Expect scenario questions: a gift from an auditee, a request to suppress a finding, an engagement beyond the auditor's competence — and be ready to name which principle is at stake and what the auditor should do.
  • Professionalism in practice. Maintaining competence through continuing development, exercising due professional care proportionate to the engagement's complexity, and protecting information obtained during audit work.

Domain: Governance, Risk Management, and Control

  • Governance structures and roles. Who does what: the board sets direction and oversees; senior management runs the organisation and owns risks and controls; internal audit provides independent assurance over how well the first two are working. Questions probe whether you can keep these roles separate under pressure.
  • Risk management concepts, including risk appetite. Understand risk appetite (the level of risk an organisation is willing to accept in pursuit of its objectives) and how it differs from related ideas such as risk tolerance; distinguish inherent risk (before controls) from residual risk (after controls); and know the basic risk responses — accept, avoid, reduce, share.
  • Control types and frameworks. Classify controls as preventive, detective or corrective, and as manual or automated, and match a control to the risk it addresses. Be comfortable with the idea of a control framework — widely used models such as the COSO internal control framework — as the structure against which control systems are designed and evaluated.

Domain: Fraud Risks

  • Fraud red flags. Recognise common warning signs — overridden controls, unexplained lifestyle changes, dominant managers who resist oversight, missing documentation, unusual transactions near period end — and understand that red flags warrant attention, not accusations.
  • Fraud risk management basics. The conditions commonly associated with fraud (pressure or incentive, opportunity, and rationalisation), the difference between management's responsibility to prevent and detect fraud and internal audit's responsibility to assess fraud risk and maintain professional scepticism, and how fraud risk is considered when planning engagements.

Where candidates struggle

Four difficulties come up repeatedly with Part 1, and none of them is a lack of raw intelligence — they are predictable features of how the exam is written.

  • Terminology precision. The exam distinguishes between terms that casual usage blurs: charter versus mandate, risk appetite versus risk tolerance, assurance versus advisory, inherent versus residual risk. Answer options are often constructed so that only the precise meaning separates the correct choice from a plausible distractor. Vague familiarity is exactly what the format punishes.
  • The independence-versus-objectivity confusion. Because everyday English treats the words as synonyms, candidates reliably misattribute one to the other. Anchor the distinction structurally: independence belongs to the function and is about positioning and reporting lines; objectivity belongs to the person and is about an unbiased mental attitude. Then practise on scenarios until the reflex is automatic.
  • Judgement-based scenario questions. Many questions describe a situation and ask what the auditor should do, with several answers that are not wrong so much as less right. These reward candidates who reason from principles — who is the assurance for, what threatens objectivity here, whose responsibility is this — rather than pattern-matching to a memorised rule.
  • The breadth of the governance domain. Governance, Risk Management, and Control spans board structures, risk concepts and control frameworks — three textbooks' worth of material behind one 30% domain. Candidates who study it as a single undifferentiated block tend to develop shallow coverage everywhere; treat its three strands as separate study units.

Two worked examples

Both examples below were written by Certuvo to illustrate how Part 1 reasoning works. They are not drawn from, and do not resemble deliberately, any actual exam content.

Example A — Is objectivity impaired?

Original Certuvo example — not from any actual exam.

Nadia joined the internal audit function eight months ago from the operations team, where last year she designed the vendor-onboarding workflow now used across the company. The chief audit executive (CAE) is planning an assurance engagement over procurement, including vendor onboarding, and the scheduler has provisionally assigned Nadia because she knows the process best. Should she perform the engagement?

Walk the reasoning in order:

  1. Classify the question. This is about objectivity — an individual auditor's unbiased attitude — not about the independence of the function, which is unaffected by one assignment decision.
  2. Identify the threat. Nadia would be assessing work she herself designed within the past year. This is a self-review threat: evaluating your own prior work creates a bias toward confirming it was sound, however honest you are. Under the Global Internal Audit Standards' treatment of objectivity and conflicts of interest, providing assurance over an activity for which the auditor recently had responsibility is presumed to impair objectivity — the recency matters, and here it is well within a year.
  3. Note what does not fix it. Her process knowledge is real, but expertise does not cure a self-review threat; if anything it deepens her authorship stake in the process. Good intentions do not cure it either — impairment is assessed on the circumstances, not the auditor's character.
  4. Conclude. Nadia should disclose the conflict to the CAE, and the CAE should assign the vendor-onboarding assurance work to someone else. Nadia can still work on unrelated engagements, and her knowledge could legitimately be used in an advisory capacity or as background input, where no independent assessment of her own work is being communicated for others to rely on.

The exam-craft lesson: the tempting wrong answers in a question like this usually offer a partial safeguard — supervision, disclosure alone, or her expertise — instead of the clean resolution, which is reassignment.

Example B — Assurance or advisory?

Original Certuvo example — not from any actual exam.

Classify each request received by an internal audit function as an assurance engagement or an advisory engagement, then check the discriminators below.

  1. The audit committee asks internal audit to assess whether the controls over payroll are operating effectively and to report a conclusion it can rely on.
  2. The operations director asks internal audit to review the draft control design for a new warehouse system before go-live and suggest improvements.
  3. Management asks internal audit to facilitate a workshop helping department heads identify and rate their own risks, with no evaluation reported.
Example B answers — classification and reasoning (original Certuvo example)
ScenarioClassificationWhy
1 — Payroll controls assessmentAssuranceAn independent assessment with a communicated conclusion, requested by an oversight body intending to rely on it.
2 — Pre-go-live design reviewAdvisoryAdvice and recommendations to the process owner at management's request; no independent conclusion is issued for third-party reliance.
3 — Risk workshop facilitationAdvisoryInternal audit facilitates management's own self-assessment; it evaluates nothing and expresses no conclusion.

The discriminators to internalise: who asked (an oversight body seeking reliance points to assurance; a manager seeking help points to advisory), what is communicated (an independent assessment or conclusion signals assurance; recommendations and facilitation signal advisory), and who relies on it (assurance serves parties beyond the requester; advisory primarily serves the requester). One caution: taking on advisory work over a process can create the same self-review considerations Example A illustrates if the function later audits it — another reason the two examples belong together.

A study approach that matches the syllabus

Part 1 is a foundations exam, so study it foundations-first:

  • Start with the Global Internal Audit Standards themselves. Read for structure before detail: learn the domains of the Standards, what kind of requirement lives where, and the vocabulary they use. Third-party summaries are useful for review, but the exam's terminology is the Standards' terminology, and since the May 2025 syllabus alignment there is no substitute for working from the current framework.
  • Sequence your depth by domain weight. Give Foundations of Internal Auditing (35%) and Governance, Risk Management, and Control (30%) the largest and earliest blocks of study time; cover Ethics and Professionalism (20%) and Fraud Risks (15%) thoroughly but proportionately. Weight-blind study plans overspend on whatever the candidate finds most interesting.
  • Answer questions every day, from week one. Because Part 1 tests application, practice questions are not a final-phase activity — they are how the material is learned. A daily block of questions with careful review of the explanations, including for questions you got right, builds the scenario reflexes the exam demands.
  • Use spaced review. Foundations material is dense with distinctions that fade fast (charter versus mandate, appetite versus tolerance). Short, scheduled re-reviews of earlier domains while you study later ones beat a single cramming pass at the end.
  • Finish with full-length timed mocks. 125 questions in 2.5 hours is a pacing challenge — roughly 72 seconds per question. At least two full simulations under exam timing will teach you your pace, your fatigue curve and which domains wobble under pressure while there is still time to fix them.

To turn this into a dated, week-by-week plan built around your actual available hours, use the free exam study-plan generator.

Common mistakes to avoid

  • Studying pre-2025 IPPF materials. The most consequential mistake on this list. The IIA aligned the syllabus with the Global Internal Audit Standards effective May 2025; older prep resources teach framework structures and terminology the current exam no longer uses. Check the publication basis of every resource you buy or borrow.
  • Memorising definitions without applying them. Being able to recite what objectivity means is worth little if you cannot spot its impairment in a four-line scenario. Every definition you learn should be immediately exercised against practice questions.
  • Treating independence and objectivity as interchangeable. They are tested as distinct concepts — function versus individual — and questions are written to catch candidates who blur them.
  • Underestimating the governance domain's breadth. Governance, Risk Management, and Control is three substantial strands behind one heading. Plan it as three study units, not one.
  • Skimping on Fraud Risks because it is only 15%. Fifteen percent of 125 questions is a meaningful block, and fraud material is comparatively contained — it is some of the most efficient scoring on the paper.
  • Postponing practice questions until the reading is finished. The reading is never finished. Candidates who question-practise from the start consistently report better retention than those who save questions for a final phase.
  • Ignoring pacing until exam day. Untimed practice hides the 72-seconds-per-question reality. Introduce timed blocks early and full timed mocks before you sit.

Frequently asked questions

How many questions is CIA Part 1, and how long is it?

The IIA's published exam information lists Part 1 at 125 multiple-choice questions with 2.5 hours of testing time. It is the longest of the three parts — Parts 2 and 3 each have 100 questions in 2 hours.

Did the Part 1 syllabus change?

Yes. The IIA updated the CIA syllabus effective May 2025 to align it with the Global Internal Audit Standards, which replaced the previous IPPF framework. Make sure every study resource you use was written for the current syllabus.

Which part should I take first?

The IIA allows the parts to be taken in any order. Taking Part 1 first is the most common strategy, and for good reason: its concepts — assurance versus advisory, independence versus objectivity, governance, risk and control — are the working vocabulary of Parts 2 and 3. But it is a choice, not a rule; see the CIA hub for how to plan your sequence.

Do Part 1 topics come up again in Parts 2 and 3?

Conceptually, yes. Part 2 applies the foundations to planning and performing engagements, and Part 3 assumes them when managing the internal audit function and its results. That is why weak Part 1 fundamentals tend to resurface as trouble later — and why time spent genuinely understanding this part pays off three times.

Official sources and references

Factual claims on this page are maintained against the primary sources below, per our editorial standards.

  1. CIA Exam Syllabus — The Institute of Internal Auditors (IIA)
    Supports: The official Part 1 name (Internal Audit Fundamentals), the four domain names and their official weights (Foundations of Internal Auditing 35%; Ethics and Professionalism 20%; Governance, Risk Management, and Control 30%; Fraud Risks 15%) per the Part 1 Expanded Test Specifications (V2.09.2024, effective May 2025), and the alignment with the Global Internal Audit Standards.
  2. CIA Certification — program information — The Institute of Internal Auditors (IIA)
    Supports: The IIA administers the CIA program; Part 1's published format (125 multiple-choice questions, 2.5 hours) per the IIA's exam pages and candidate handbook; testing is computer-based; parts may be taken in any order; eligibility is defined by the IIA's program rules.

Editorial disclosure

This page was produced by the Certuvo Editorial Team and reviewed through the technical, subject-matter and claims stages described in our content review process. Named individual author attribution with verified credentials is added as our contributor verification programme completes. Certuvo sells exam-preparation courses; editorial content is produced separately from commercial decisions under our editorial standards.

Independent provider

Certuvo is an independent provider. It is not affiliated with, endorsed by, or approved by any certification body referenced on this page. Always confirm eligibility rules, fees and exam policies with the relevant certification body.

Content change history

  • — Initial publication (Release 1).
  • — Corrected to the current IIA CIA syllabus (Expanded Test Specifications V2.09.2024, effective May 2025): part renamed Internal Audit Fundamentals in the title, H1 and text; domain weights (35/20/30/15) re-verified against the official syllabus document; exam-format figures re-attributed to the IIA's exam information rather than the syllabus.

Site-wide changes are recorded in the content changelog.

Know exactly where you stand.

Free planning tools built on the official exam blueprints — a week-by-week study plan and an honest, itemised cost estimate. No sign-up, no stored data.