IIA-CHAL-QISA Sample Questions

IIA-CHAL-QISA Sample Questions & Answers

Running an internal audit engagement, from planning through performing it, carries the most weight, ahead of the foundations of independence and professional care, and business acumen covering information security and financial management.

Launch the full IIA-CHAL-QISA simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Essentials of Internal Auditing · Governance, Risk Management, and Control

    A continuous auditing script flags that a marketing manager has submitted and approved their own expense report for an amount just below the threshold requiring senior management sign-off. This occurred five times in the last quarter. This situation most directly indicates a potential breakdown in which component of the COSO framework?

    Show answer & explanation

    Correct answer: C

    Control Activities are the policies and procedures that help ensure management directives are carried out. A core principle within Control Activities is the segregation of duties, which is designed to prevent one person from having control over multiple phases of a transaction. The manager submitting and approving their own expense report is a classic violation of segregation of duties, a key type of control activity.

  2. Question 2Beginner

    Practice of Internal Auditing · Communicating Engagement Results

    An audit finding states: 'The change management process for the production database is poorly controlled.' Why does this statement fail to meet the criteria for a well-constructed audit observation?

    Show answer & explanation

    Correct answer: C

    A well-constructed audit observation should contain four key elements: Criteria (what should be), Condition (the current state), Cause (why the condition exists), and Effect (the risk or consequence). The statement 'poorly controlled' is a vague conclusion (condition) without explaining the standard (criteria), the reason for the failure (cause), or the potential impact (effect), making it unactionable and difficult to validate.

  3. Question 3Intermediate

    Essentials of Internal Auditing · Foundations of Internal Auditing

    True or False: The IIA's Code of Ethics requires internal auditors who suspect significant wrongdoing or fraud to report their findings directly to the appropriate external authorities or regulators.

    Show answer & explanation

    Correct answer: B

    The statement is false. The IIA's Code of Ethics, specifically the principle of Confidentiality, requires internal auditors to be prudent in the use and protection of information acquired in the course of their duties. They should not disclose information without appropriate authority unless there is a legal or professional obligation to do so. The primary reporting line for fraud is within the organization, typically to senior management and the board/audit committee, not directly to external authorities unless legally compelled.

  4. Question 4Advanced

    Business Knowledge for Internal Auditing · Strategic Management

    A hospital system is conducting a post-implementation review of its new Electronic Health Record (EHR) system. The internal audit team is tasked with evaluating the project's success. Which of the following is the best example of a strategic performance metric for this audit?

    Show answer & explanation

    Correct answer: C

    A strategic performance metric measures the achievement of the organization's strategic objectives, not just project or operational goals. While budget, schedule, and uptime are important operational metrics, a reduction in patient admission time directly reflects the strategic goals of improving patient care and operational efficiency. It measures the business value and outcomes delivered by the EHR system, which is the core of a strategic assessment.

  5. Question 5Intermediate

    Essentials of Internal Auditing · Independence and Objectivity

    The Chief Audit Executive (CAE) of a multinational corporation reports administratively to the Chief Financial Officer (CFO) and functionally to the audit committee. The CFO has recently been pressuring the CAE to deprioritize an audit of the treasury function, which the CFO oversees, in favor of operational audits with lower risk ratings. This situation presents a significant impairment to:

    Show answer & explanation

    Correct answer: D

    Organizational independence is effectively achieved when the CAE reports functionally to the board. However, pressure from an administrative reporting line (the CFO) to limit the scope of an audit, especially in an area overseen by that executive, is a classic example of an impairment to independence. The CFO is interfering with the risk-based audit plan and attempting to restrict the internal audit activity's unrestricted access and scope.

  6. Question 6Intermediate

    Practice of Internal Auditing · Managing the Internal Audit Activity

    When developing the annual risk-based audit plan for an organization with hundreds of potential auditable entities, the Chief Audit Executive (CAE) has completed a risk assessment and identified far more high-risk areas than can be covered with available resources. What is the CAE's most appropriate next step?

    Show answer & explanation

    Correct answer: B

    Standard 2010.A2 requires that the risk-based plan must consider the organization’s risk appetite. When resources are insufficient to cover all high-risk areas, the CAE's responsibility is to communicate this resource gap to senior management and the board. This allows them to make an informed decision: either accept the residual risk of the unaudited areas, increase the internal audit budget, or re-evaluate strategic priorities. The CAE provides the information; management and the board make the final decision on risk acceptance.

  7. Question 7Advanced

    Essentials of Internal Auditing · Governance, Risk Management, and Control

    An internal auditor is evaluating the effectiveness of a 'three lines of defense' model of governance. The auditor observes that the second-line risk management function is understaffed and primarily focused on generating reports for regulators, with little proactive engagement with business units. What is the most significant risk created by this weakness?

    Show answer & explanation

    Correct answer: B

    The primary role of the second line of defense (e.g., risk management, compliance) is to provide expertise, frameworks, and oversight to help the first line (operational management) effectively manage risks. If the second line is weak and reactive, the first line loses a critical partner. This often leads to inconsistent risk management practices, unidentified risks, and a failure to embed risk awareness into daily operations, which is the model's primary goal.

  8. Question 8Beginner

    Business Knowledge for Internal Auditing · Business Acumen

    A manufacturing company is concerned about its high inventory holding costs. An internal auditor is tasked with identifying inefficiencies in the supply chain. Which metric should the auditor focus on to best measure the time it takes to convert inventory into revenue?

    The correct metric is the [blank].

    Show answer & explanation

    Correct answer: B

    The Cash Conversion Cycle (CCC) measures the number of days it takes for a company to convert its investments in inventory and other resources into cash flows from sales. It encompasses the entire process from purchasing raw materials to collecting cash from customers, making it the most comprehensive metric for assessing the efficiency of inventory management in relation to revenue generation.

  9. Question 9Intermediate

    Practice of Internal Auditing · Monitoring Progress

    During a follow-up review, management states that the recommendation from a prior audit to segregate duties in the cash disbursement process has been fully implemented. What is the most effective audit procedure to verify management's assertion?

    Show answer & explanation

    Correct answer: C

    The most effective way to verify the implementation of a control is through direct testing. Selecting and examining a sample of transactions provides direct evidence that the new control is not only designed correctly (as documentation might show) but is also operating effectively in practice. Inquiry (memo) and inspection of documents are less persuasive forms of evidence than reperformance or direct testing.

  10. Question 10Advanced

    Business Knowledge for Internal Auditing · IT Governance and Strategy

    Case Study:

    A mid-sized regional bank recently launched a new mobile banking application developed by a third-party vendor. The application allows customers to perform transactions, check balances, and apply for loans. The bank's Chief Audit Executive (CAE) has scheduled an audit of the application's security and data privacy controls, as the bank is subject to strict data protection regulations similar to GDPR.

    The initial review by the IT auditor reveals that the contract with the vendor contains only generic clauses about 'industry-standard security' and lacks a specific right-to-audit clause. The vendor is resistant to providing access to their development environment or source code, citing intellectual property concerns. The bank's IT security team performed a penetration test before launch, which identified several medium-risk vulnerabilities that were verbally accepted by the project manager due to time-to-market pressures.

    Which of the following is the most significant underlying governance failure that the internal auditor should report to the audit committee?

    Show answer & explanation

    Correct answer: C

    While all other options are issues, the root cause and most significant governance failure is the lack of a formal risk acceptance process. A project manager verbally accepting medium-risk security vulnerabilities without a documented analysis and approval from a senior stakeholder with the appropriate authority (e.g., a Chief Risk Officer or business unit head) demonstrates a breakdown in IT governance. This informal process circumvents proper oversight and accountability for managing risks to the bank's data and reputation.

Ready for the real thing?

The full IIA-CHAL-QISA simulator has every exam-style question, timed mode, and instant scoring.