CIA Part 1 Study Guide — 2026 Edition cover

CIA Part 1 — Internal Audit Fundamentals · 2026 Edition

CIA Part 1 Study Guide — 2026 Edition

Every domain of the CIA Part 1 syllabus (Internal Audit Fundamentals), 222 original questions with worked explanations, and a 125-question full-length practice exam.

  • 222 original practice questions, each with a worked explanation, in one PDF + EPUB you keep

PDF + EPUB · English · 115 pages · $19.99 one-time

This book is written in English.

Instant download after payment — no account needed, no subscription.

14-day money-back guarantee: not satisfied for any reason? Email support@preppass.org within 14 days of purchase for a full refund. Refund policy

Read a free sample chapter first

Look inside the book

Three real pages, rendered straight from the PDF you download — a reference page, a teaching page, and a worked question, always in that order. Nothing here was redrawn to look better.

  • Quick reference
    Chapter 1: Foundations of Internal Auditing I — Purpose, Mandate, and Charter · PDF page 10

    A page you can turn back to: the numbers, deadlines or terms gathered in one place.

  • How it's taught
    Chapter 4: Governance, Risk Management, and Control I — Corporate Governance · PDF page 43

    An explanation page: the material taught in prose, in the order the exam tests it.

  • How it's taught
    Chapter 4: Governance, Risk Management, and Control I — Corporate Governance · PDF page 51

    An explanation page: the material taught in prose, in the order the exam tests it.

About the CIA Part 1 exam

Internal auditors and candidates starting the three-part CIA program, or seeking the IAP through Part 1. This book teaches the four Part 1 syllabus sections, with chapter quizzes and a full practice exam built from IIA-published sources. It is an independent study guide, not affiliated with the IIA, covers Part 1 only, and includes no online practice.

Certified Internal Auditor (CIA) Examination — Part 1: Internal Audit Fundamentals — exam facts
Awarding bodyThe Institute of Internal Auditors (IIA)
Questions125 questions
Time limit150 minutes
Passing ruleRaw score converted to a reporting scale ranging from 250 to 750 points; a score of 600 or higher is required to pass. No penalty for incorrect responses.
FeesCIA application US$120 (member) / US$240 (non-member); CIA Part 1 exam US$310 (member) / US$445 (non-member); all fees non-refundable and non-transferable; outside North America, pricing is verified with the National Institute
DeliveryComputer-based, at a Pearson VUE test center or via online proctoring (online proctoring is not available for some exams and is limited to certain regions)
EligibilityEntry into the CIA program requires meeting the program entry requirements. To certify: master's degree or equivalent + 1 year of internal audit experience; bachelor's degree or equivalent + 2 years; no degree + 5 years; all three exam parts must be passed and experience verified
RetakesEarliest retake appointment is 60 days from the date you last took that exam; a new registration with payment is required; the retake policy does not currently limit the number of attempts during the program eligibility window
LanguagesArabic, Simplified Chinese (mainland China only), Traditional Chinese, English, French, German, Japanese, Korean, Polish, Portuguese, Russian, Spanish, Thai, Turkish; Vietnamese registration effective 28 August 2026. Arabic and Simplified Chinese are currently on the 2019 syllabus
Content outlineCIA Part 1 — Internal Audit Fundamentals syllabus, V2.09.2024 FINAL — effective May 2025
Domains and weights
  • Foundations of Internal Auditing — 35%
  • Ethics and Professionalism — 20%
  • Governance, Risk Management, and Control — 30%
  • Fraud Risks — 15%

Questions buyers ask

How many questions are on CIA Part 1, and how long is it?
CIA Part 1 has 125 questions and a 150-minute time limit. Parts 2 and 3 are separate exams of 100 questions and 120 minutes each.
What score do I need to pass CIA Part 1?
You need a scaled score of 600 or higher on a reporting scale of 250 to 750. Your raw score, based on the number of questions answered correctly, is converted to that scale, and there is no penalty for incorrect responses.
What are the CIA Part 1 syllabus sections and their weights?
Foundations of Internal Auditing 35%, Ethics and Professionalism 20%, Governance, Risk Management, and Control 30%, and Fraud Risks 15%.
Which CIA Part 1 syllabus is current, and what changed?
The current Part 1 syllabus is marked Effective May 2025 (V2.09.2024 FINAL). The IIA page notes that Arabic and Simplified Chinese exams are still on the 2019 syllabus; Arabic transitions to the 2025 syllabus on 28 December 2026. The syllabus itself does not publish a summary of changes.
Who is eligible for the CIA?
Candidates must meet the program's entry requirements before registering for any part. To certify, a master's degree or equivalent needs 1 year of internal audit experience, a bachelor's degree 2 years, and no degree 5 years, plus passing all three parts.
How much does CIA Part 1 cost, and can I retake it?
The Part 1 exam costs US$310 for IIA members and US$445 for non-members, plus a CIA application fee of US$120 or US$240. You can retake a failed exam 60 days after your last attempt, with a new paid registration; the policy does not currently limit the number of attempts.
How is this book organized?
Six chapters follow the four Part 1 syllabus sections, each closing with a quiz, followed by a 125-question practice exam weighted like the syllabus. The book contains 222 questions in total, each with a worked explanation, and costs $19.99.
Is CIA Part 1 the same as the IAP exam?
Yes. The IIA states that Part 1 of the CIA exam is the same exam as for the Internal Audit Practitioner (IAP), a stand-alone credential covering the fundamentals. IAP holders still need Parts 2 and 3 and 5 years of experience for the CIA.
Is a study guide enough for the CIA Part 1 — Internal Audit Fundamentals exam, or do I need a course?
Check eligibility first — per The Institute of Internal Auditors (IIA): entry into the CIA program requires meeting the program entry requirements. To certify: master's degree or equivalent + 1 year of internal audit experience; bachelor's degree or equivalent + 2 years; no degree + 5 years; all three exam parts must be passed and experience verified. A book does not replace those requirements. For the exam content itself, this 115-page guide teaches the material chapter by chapter with 222 practice questions and explanations inside. A prep course adds live instruction and a set schedule; whether you need one beyond any required education is your call.
Does the CIA Part 1 — Internal Audit Fundamentals study guide come as a PDF?
Yes — CIA Part 1 Study Guide — 2026 Edition downloads as PDF and EPUB, 115 pages. The download link is emailed the moment payment clears and does not expire.
How much does the CIA Part 1 — Internal Audit Fundamentals study guide cost?
$19.99, once. There is no subscription and no account to create; the PDF and EPUB files are yours to keep.
Can I read part of the CIA Part 1 — Internal Audit Fundamentals study guide before buying?
Yes. A full chapter is free to read on this page — not a summary of one, the chapter itself.
Is this the official CIA Part 1 — Internal Audit Fundamentals study guide?
No. This is an independent study guide and is not affiliated with or endorsed by the exam's awarding body. It is written from IIA's published CIA Part 1 syllabus (Internal Audit Fundamentals) and candidate handbook. Always confirm current requirements with the body that issues your licence.

What's included — and what isn't

Included

  • Every domain of IIA's CIA Part 1 syllabus (Internal Audit Fundamentals)
  • A quiz closing each chapter, with worked explanations
  • A 125-question full-length practice exam at the published weights
  • 222 original questions, each explained and cited to its source
  • Taught to the IIA's Global Internal Audit Standards
  • PDF + EPUB you keep

Not included

  • No printed copy is shipped — this is a file you download and can print yourself
  • No video course, instructor, tutoring or online question bank comes with the book — everything is in the file
  • Not your exam registration or the testing centre's fee, which you still pay to the official body

Contents

See 5 sections and the page each one starts on
  1. Chapter 2: Foundations of Internal Auditing II — Services, Independence, and the Three Linesp. 17
  2. Chapter 3: Ethics and Professionalismp. 28
  3. Chapter 4: Governance, Risk Management, and Control I — Corporate Governancep. 40
  4. Chapter 5: Governance, Risk Management, and Control II — Risk, Controls, and Frameworksp. 52
  5. Chapter 6: Fraud Risksp. 63

Taken from the PDF you download, with the page each one starts on — not typed here.

Read a chapter free, in full

One complete chapter, exactly as it ships in the eBook. Scroll the window to read it right here; no download, no email.

Read chapter 2 here, without leaving the page

We didn't give you the easy intro — the free chapter opens on one of the hardest-working parts of the book, so you can judge the teaching where the exam gets difficult.

FREE SAMPLE — READ IT RIGHT HERE
Chapter 2 · ≈11 min read
Foundations of Internal Auditing II — Services, Independence, and the Three Lines Model
scroll ↓

Chapter 1 established why the function exists. This chapter covers what it does — assurance and advisory services — and the independence architecture that makes its work trustworthy: what impairs independence, who protects it, and where the function sits relative to management's own risk and control responsibilities under the Three Lines Model. Section A devotes five of its eight topics to this ground, and the exam tests it with scenarios that force you to classify a service, spot an impairment, or place an activity in the right line.

2.1 Assurance services vs advisory services

The Standards' glossary draws a bright line:

  • Assurance services are "services through which internal auditors perform objective assessments to provide assurance." The nature and scope are determined by internal audit — the function decides what assurance is needed and how to provide it.[1]
  • Advisory services are "services through which internal auditors provide advice to an organization's stakeholders without providing assurance or taking on management responsibilities. The nature and scope of advisory services are subject to agreement with relevant stakeholders."[1]

Three distinctions fall out of those definitions, and each is testable:

  1. Who determines scope. For assurance, internal audit determines it. For advisory, it is agreed with the stakeholder. A stem describing the CAE negotiating the objectives of a consulting review with the CFO is signaling advisory.
  2. Assurance vs advice. Assurance is an objective assessment against criteria, producing a conclusion. Advisory is advice — facilitation, training, analysis — without an assurance conclusion and without the auditor taking on management's responsibilities.
  3. Limited vs reasonable assurance. Within assurance services, the syllabus requires you to differentiate limited from reasonable assurance. Reasonable assurance is the higher level — a positive conclusion that controls are effective, supported by more extensive evidence. Limited assurance is a negative form of conclusion ("nothing came to our attention"), supported by less extensive procedures. The exam tests this with stems about review-type engagements or interim communications.

Why it matters: classification questions are among the most frequent in Section A. "The CAE facilitates a workshop to help management design its risk register" — advisory. "The function tests whether procurement controls operated effectively during the year" — assurance.

How it is tested: scenarios asking "which type of service is this?" or "which statement about advisory services is true?" The distractors typically claim advisory scope is determined by internal audit alone, or that advisory services provide assurance, or that auditors may assume management responsibilities in an advisory role — all false under the definitions.

The trap: the phrase "consulting services." The Standards note that advisory services are also known as consulting services — same thing, new name. A question using "consulting" is not describing a third category.

2.2 Types of assurance services

The syllabus lists seven types. Learn them as a set, because the exam asks you to recognize which type a described engagement belongs to:

  • Risk and control assessments — evaluating the design and effectiveness of risk management and controls in an area.
  • Third-party and contract compliance audits — auditing vendors, suppliers, or contract terms (royalties, service-level agreements).
  • IT security and privacy audits — assessing information security and data protection controls.
  • Performance and quality audits — economy, efficiency, and effectiveness of operations or programs.
  • Operational, financial, and regulatory compliance audits — the traditional core: do operations work, do the numbers hold up, are laws and regulations followed.
  • Audits of organizational culture — assessing tone at the top, values, and behavioral norms and their effect on control.
  • Audits of the management reporting process — the reliability of internal reporting to the board and management.

Why it matters: the exam presents an engagement description and asks which type it is. The discriminators are the subject matter: a vendor's adherence to contract terms is third-party/contract compliance even if the procedures look like any other audit.

The trap: culture audits. Candidates forget this type exists and misclassify a culture assessment as a "performance audit." If the stem mentions values, tone, survey results, or behavioral norms, think culture.

2.3 Types of advisory services

The syllabus lists seven advisory roles. Note the pattern: in every one, the auditor helps but does not own:

  • Risk and control training — teaching the organization about risk and control.
  • System design and development — advising on controls during design, without owning the design decision.
  • Due diligence services — supporting management's evaluation of a target or transaction.
  • Maintaining data privacy — advising on privacy practices (distinct from auditing privacy controls, which is assurance).
  • Benchmarking — comparing practices against peers or standards.
  • Internal control assessments — advising on control design outside a formal assurance engagement.
  • Process mapping — facilitating management's documentation of its processes.

Why it matters: the exam tests the boundary. "The auditor designs the new procurement system and approves vendor selections" — that crosses into management responsibility and is impermissible. "The auditor advises the project team on control considerations for the new procurement system" — proper advisory.

The trap: any option where the auditor decides, approves, or operates. Advisory never includes taking on management responsibilities — that phrase from the definition is the exam's favorite discriminator.

2.4 Independence impairments

Independence is "the freedom from conditions that may impair the ability of the internal audit function to carry out internal audit responsibilities in an unbiased manner."[1] The syllabus lists five impairment situations; each maps to a Standards requirement:

  • Inappropriate functional reporting line. The CAE must report functionally to the board. If the CAE reports functionally to the CFO or CEO — the people whose areas get audited — independence is impaired in appearance at minimum.
  • The board's protective responsibility. The board establishes and protects the function's independence.[1] A board that will not approve an adequate charter, budget, or reporting line is failing this duty.
  • The CAE's protective responsibility. The CAE must confirm organizational independence to the board at least annually, communicate impairments and the safeguards used, and discuss with the board and senior management any roles that could impair independence in fact or appearance.[1]
  • Budget limitations. A budget so constrained that the function cannot cover its mandate restricts operations and can impair independence — the function that cannot afford to audit is not independent in any meaningful sense.
  • Scope limitations and restricted access. Denied access to people, records, or areas impairs the function's ability to do unbiased work; the CAE must communicate the limitation and its impact.

Why it matters: impairment questions are scenario-based. "The CAE's bonus is tied to the company's earnings targets" — impairment (personal interest in results). "The audit committee meets the CAE quarterly in executive session" — a safeguard, not an impairment.

How it is tested: "Which situation impairs independence?" with three safeguards and one impairment, or the reverse. Also "what should the CAE do?" — communicate to the board, document safeguards.

The trap: confusing administrative reporting with functional reporting. Administrative reporting to the CEO (for HR, facilities, budgets) is normal. Functional reporting — who approves the plan, who receives results, who hires/fires the CAE — must go to the board. An option describing administrative reporting to senior management as an impairment is the trap; it is not one.

2.5 The Three Lines Model

The IIA's Three Lines Model describes how risk and control responsibilities are distributed:

  • First line: operational management — owns and manages risk directly (provides products/services, maintains controls).
  • Second line: management's support functions — risk management, compliance, control expertise that assists the first line.
  • Third line: internal audit — independent assurance to the board and senior management.

The syllabus requires three things: describe the model, identify first/second-line responsibilities that could impair independence if taken on by internal audit, and describe safeguards.

Why it matters: the exam's favorite move is to hand an internal audit function a first- or second-line job — "the CAE is asked to own the enterprise risk register" or "internal audit will approve all wire transfers above $1 million" — and ask about the effect on independence. Owning risk management or operating controls impairs independence because the function would later audit its own work (self-review).

Safeguards the exam expects: if the CAE temporarily takes on a nonaudit role, assurance over that area must come from an independent third party during the assignment and for 12 months after, and the CAE must plan the transition of the responsibility back to management.[1] Other safeguards: board oversight of the arrangement, time limits, and clear documentation.

The trap: options suggesting the function can permanently hold a management role "as long as the board approves." Board approval does not cure self-review — the safeguard for temporary assignments is third-party assurance plus a transition plan, not a board waiver.

Key numbers

  • CIA Part 1: 125 questions, 150 minutes; Section A (Foundations) is 35%.[2, 3]
  • If the CAE temporarily assumes nonaudit responsibilities, independent third-party assurance is required during the assignment and for the subsequent 12 months.[1]
  • The CAE confirms organizational independence to the board at least annually.[1]

Key takeaways

  • Assurance scope is determined by internal audit; advisory scope is agreed with stakeholders; advisory never includes assurance conclusions or management responsibilities.
  • Limited assurance is a negative conclusion on less evidence; reasonable assurance is a positive conclusion on more extensive evidence.
  • Functional reporting goes to the board; administrative reporting to senior management is normal. Impairments — bad reporting lines, budget strangulation, scope denial — must be communicated to the board with safeguards.
  • Under the Three Lines Model, internal audit is the third line. Taking on first- or second-line responsibilities impairs independence; temporary assignments require third-party assurance plus a transition plan.

Chapter 2 quiz

1. The chief audit executive agrees with the chief financial officer on the objectives and scope of a review of the treasury function's new hedging procedures, then facilitates workshops to help treasury staff design controls. Which type of service is this?

  • A. An advisory service — scope was agreed
  • B. An external audit service, because treasury is involved
  • C. A compliance audit, because hedging is regulated
  • D. An assurance service, because it concerns hedging controls

2. Internal audit tests whether the company's anti-bribery controls operated effectively throughout the year and issues a conclusion on their effectiveness. This is an example of:

  • A. Advisory services
  • B. A management self-assessment
  • C. Reasonable assurance
  • D. Limited assurance

3. Which statement about advisory services is true under the Global Internal Audit Standards?

  • A. Their nature and scope are determined solely by the chief audit executive
  • B. They provide a higher level of assurance than assurance services
  • C. They are consulting services whose scope is agreed with stakeholders
  • D. They permit internal auditors to assume management responsibilities temporarily

4. An engagement letter describes a review that will result in the statement "nothing came to our attention that would indicate the controls were not operating effectively." This describes:

  • A. An advisory service
  • B. Limited assurance
  • C. A fraud investigation
  • D. Reasonable assurance

5. The internal audit function is asked to audit whether a major supplier complied with the pricing terms of a five-year contract. This engagement is best classified as:

  • A. An advisory service
  • B. A contract compliance audit
  • C. An operational audit
  • D. A financial statement audit

6. During a system implementation, the auditor advises the project team on control considerations for the new software but does not approve design decisions. This is:

  • A. Proper advisory work — advice without management responsibility
  • B. An assurance service, because systems are involved
  • C. Impermissible, because auditors may not participate in system projects
  • D. An independence impairment that must be reported to regulators

7. The chief audit executive reports functionally to the chief financial officer and administratively to the audit committee. Which statement is correct?

  • A. Reporting lines do not affect independence as long as the auditors are competent
  • B. The functional reporting line to the CFO impairs independence
  • C. The administrative reporting line to the audit committee impairs independence
  • D. This is the standard arrangement and impairs nothing

8. The audit committee approves the internal audit budget but the CFO, who controls disbursements, repeatedly delays releasing funds for planned engagements. This situation is best described as:

  • A. An advisory service performed by the CFO
  • B. Evidence of effective cost control
  • C. A routine administrative matter with no independence implications
  • D. A budget limitation that can impair independence

9. Which of the following is a safeguard the chief audit executive should employ when independence may be impaired?

  • A. Requesting that senior management approve the impairment in writing
  • B. Concealing the impairment from the board to preserve the function's reputation
  • C. Communicating the impairment and safeguards to the board
  • D. Expanding the audit plan to avoid the affected area

10. The board asks the chief audit executive to take ownership of the enterprise risk management program for two years while a new chief risk officer is recruited. Which combination preserves independence?

  • A. The CAE accepts permanently, since the board requested it
  • B. The CAE declines all nonaudit work under all circumstances
  • C. The CAE accepts and audits the risk management program personally to ensure quality
  • D. Accept temporarily, with third-party assurance and a planned transition back to management

11. Under the IIA's Three Lines Model, which activity belongs to the third line?

  • A. Designing compliance training for new hires
  • B. Operating the company's credit approval controls
  • C. Independent assurance on risk and control to the board
  • D. Maintaining the enterprise risk register

12. An internal auditor performed advisory work helping design a procurement process. Six months later the auditor is assigned to provide assurance on that same process. What is the concern?

  • A. Self-review of work the auditor helped create
  • B. The auditor lacks competence in procurement
  • C. There is no concern; advisory work improves audit quality
  • D. Advisory services are prohibited by the Standards

13. Management asks internal audit to approve all journal entries above $500,000 before posting. If the function agrees, what is the effect?

  • A. None, because the threshold is high
  • B. The function gains valuable experience that improves future audits
  • C. The function converts the approval into an advisory service
  • D. The function takes on a management responsibility, impairing independence

14. A survey of employee perceptions of "tone at the top," ethical values, and willingness to raise concerns is conducted by internal audit, with findings reported to the board. This engagement is best classified as:

  • A. A culture audit
  • B. An advisory benchmarking exercise
  • C. A fraud investigation
  • D. A financial compliance audit

15. Which of the following statements about the Three Lines Model is true?

  • A. The second line provides independent assurance to the board
  • B. Internal audit, as the third line, may permanently own second-line compliance functions if the board approves
  • C. The three lines eliminate the need for an internal audit charter
  • D. The model places operational management in the first line, owning and managing risk directly

16. The CAE learns that senior management has restricted the function's access to the whistleblower hotline database. What should the CAE do first?

  • A. Accept the restriction and audit around it
  • B. Communicate the scope limitation and its impact to the board
  • C. Report senior management to the external auditor
  • D. Disclose the restriction in the next engagement workpapers only

Sources cited in this excerpt

  1. Global Internal Audit Standards. The Institute of Internal Auditors, issued 2024-01-09, effective 2025-01-09. https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/
  2. Certified Internal Auditor (CIA) brochure. The Institute of Internal Auditors, current edition served 2026-09-22. http://www.theiia.org/globalassets/site/certifications/certified-internal-auditor/cia-brochure.pdf
  3. Certified Internal Auditor (CIA) Examination — Part 1 - Internal Audit Fundamentals (syllabus). The Institute of Internal Auditors, Inc., Effective May 2025 (V2.09.2024 FINAL). https://www.theiia.org/globalassets/site/certifications/certifications/cia/cia-part-1-syllabus-cht.pdf
Open the free chapter →

Before you buy

How do I get it?
Pay, and the download appears on this page straight away. The links are also emailed to you. No account is required.
What if it isn't for me?
Email us within 14 days for a full refund, no questions asked.
Is there online practice for this exam too?
No. PrepPass has no online question bank for this exam; the book is self-contained. Its chapter quizzes and full-length practice exam, each question with a worked explanation, are all in the PDF and EPUB.
Can I read it on my phone?
Yes — the EPUB is for phones and e-readers, the PDF is for printing and tabbing. You get both.

Full refund policy

The details

Every domain of the CIA Part 1 syllabus (Internal Audit Fundamentals), 222 original questions with worked explanations, and a 125-question full-length practice exam.

PrepPass team · Verified against IIA's published CIA Part 1 syllabus (Internal Audit Fundamentals) and candidate handbook · How we review
  • Format: PDF + EPUB download · 115 pages
  • 222 practice questions in the book, with a full answer key
  • $19.99 one-time — no subscription
  • 14-day money-back guarantee · refund policy
  • Cross-referenced against: IIA's published CIA Part 1 syllabus (Internal Audit Fundamentals) and candidate handbook
  • Last updated: September 2026
  • Verified from the official source(IIA's published CIA Part 1 syllabus (Internal Audit Fundamentals) and candidate handbook)
  • Instant download, yours for life
Same exam, a fraction of the price
$349–$469→$19.99

A CIA Part 1 review course runs $349–$469. This book teaches the same exam — same rules, verified to current standards — for a one-time $19.99 you keep for life.

What the book gives you

PrepPass has no online question bank for this exam, so the $19.99 book is complete in itself: the material taught in order, a quiz closing each chapter and a full-length practice exam, in a file you own.

  • Systematic teaching — every exam section explained chapter by chapter, start to finish, not just questions
  • Print it & tab it — a paper-ready PDF you can highlight, mark up, and bring to your study table
  • Study anywhere, offline — EPUB on your phone or e-reader; no wifi, no browser tabs
  • Everything in one place — the chapters and the practice questions in one file
  • Yours for life — one-time $19.99, instant download, no subscription

And it's risk-free: 14-day money-back guarantee — not satisfied? Email us for a full refund, no questions asked. See the refund policy.

Get the eBook — $19.99 (PDF + EPUB) ↑

14-day money-back guarantee · full refund, no questions asked.

One-time purchase, lifetime access to the download. The eBook is the full CIA Part 1 — Internal Audit Fundamentals study guide in PDF and EPUB. Educational summary, not professional or legal advice — always confirm the current rules with the official source. Last updated: September 2026.

Report