PrepPass team · Verified against IIA's published CIA Part 1 syllabus (Internal Audit Fundamentals) and candidate handbook · How we review
FREE SAMPLE · READ ONLINEChapter 2

Foundations of Internal Auditing II — Services, Independence, and the Three Lines Model

This is Chapter 2 of the CIA Part 1 Study Guide — 2026 Edition — one complete chapter, free to read right here; no download, no email. It is the same text as the eBook. When you reach the end, the complete guide is one click away.

We didn't give you the easy intro — this free chapter opens on one of the hardest-working parts of the book, so you can judge the teaching where the exam gets difficult.

Chapter 1 established why the function exists. This chapter covers what it does — assurance and advisory services — and the independence architecture that makes its work trustworthy: what impairs independence, who protects it, and where the function sits relative to management's own risk and control responsibilities under the Three Lines Model. Section A devotes five of its eight topics to this ground, and the exam tests it with scenarios that force you to classify a service, spot an impairment, or place an activity in the right line.

2.1 Assurance services vs advisory services

The Standards' glossary draws a bright line:

  • Assurance services are "services through which internal auditors perform objective assessments to provide assurance." The nature and scope are determined by internal audit — the function decides what assurance is needed and how to provide it.[1]
  • Advisory services are "services through which internal auditors provide advice to an organization's stakeholders without providing assurance or taking on management responsibilities. The nature and scope of advisory services are subject to agreement with relevant stakeholders."[1]

Three distinctions fall out of those definitions, and each is testable:

  1. Who determines scope. For assurance, internal audit determines it. For advisory, it is agreed with the stakeholder. A stem describing the CAE negotiating the objectives of a consulting review with the CFO is signaling advisory.
  2. Assurance vs advice. Assurance is an objective assessment against criteria, producing a conclusion. Advisory is advice — facilitation, training, analysis — without an assurance conclusion and without the auditor taking on management's responsibilities.
  3. Limited vs reasonable assurance. Within assurance services, the syllabus requires you to differentiate limited from reasonable assurance. Reasonable assurance is the higher level — a positive conclusion that controls are effective, supported by more extensive evidence. Limited assurance is a negative form of conclusion ("nothing came to our attention"), supported by less extensive procedures. The exam tests this with stems about review-type engagements or interim communications.

Why it matters: classification questions are among the most frequent in Section A. "The CAE facilitates a workshop to help management design its risk register" — advisory. "The function tests whether procurement controls operated effectively during the year" — assurance.

How it is tested: scenarios asking "which type of service is this?" or "which statement about advisory services is true?" The distractors typically claim advisory scope is determined by internal audit alone, or that advisory services provide assurance, or that auditors may assume management responsibilities in an advisory role — all false under the definitions.

The trap: the phrase "consulting services." The Standards note that advisory services are also known as consulting services — same thing, new name. A question using "consulting" is not describing a third category.

2.2 Types of assurance services

The syllabus lists seven types. Learn them as a set, because the exam asks you to recognize which type a described engagement belongs to:

  • Risk and control assessments — evaluating the design and effectiveness of risk management and controls in an area.
  • Third-party and contract compliance audits — auditing vendors, suppliers, or contract terms (royalties, service-level agreements).
  • IT security and privacy audits — assessing information security and data protection controls.
  • Performance and quality audits — economy, efficiency, and effectiveness of operations or programs.
  • Operational, financial, and regulatory compliance audits — the traditional core: do operations work, do the numbers hold up, are laws and regulations followed.
  • Audits of organizational culture — assessing tone at the top, values, and behavioral norms and their effect on control.
  • Audits of the management reporting process — the reliability of internal reporting to the board and management.

Why it matters: the exam presents an engagement description and asks which type it is. The discriminators are the subject matter: a vendor's adherence to contract terms is third-party/contract compliance even if the procedures look like any other audit.

The trap: culture audits. Candidates forget this type exists and misclassify a culture assessment as a "performance audit." If the stem mentions values, tone, survey results, or behavioral norms, think culture.

2.3 Types of advisory services

The syllabus lists seven advisory roles. Note the pattern: in every one, the auditor helps but does not own:

  • Risk and control training — teaching the organization about risk and control.
  • System design and development — advising on controls during design, without owning the design decision.
  • Due diligence services — supporting management's evaluation of a target or transaction.
  • Maintaining data privacy — advising on privacy practices (distinct from auditing privacy controls, which is assurance).
  • Benchmarking — comparing practices against peers or standards.
  • Internal control assessments — advising on control design outside a formal assurance engagement.
  • Process mapping — facilitating management's documentation of its processes.

Why it matters: the exam tests the boundary. "The auditor designs the new procurement system and approves vendor selections" — that crosses into management responsibility and is impermissible. "The auditor advises the project team on control considerations for the new procurement system" — proper advisory.

The trap: any option where the auditor decides, approves, or operates. Advisory never includes taking on management responsibilities — that phrase from the definition is the exam's favorite discriminator.

2.4 Independence impairments

Independence is "the freedom from conditions that may impair the ability of the internal audit function to carry out internal audit responsibilities in an unbiased manner."[1] The syllabus lists five impairment situations; each maps to a Standards requirement:

  • Inappropriate functional reporting line. The CAE must report functionally to the board. If the CAE reports functionally to the CFO or CEO — the people whose areas get audited — independence is impaired in appearance at minimum.
  • The board's protective responsibility. The board establishes and protects the function's independence.[1] A board that will not approve an adequate charter, budget, or reporting line is failing this duty.
  • The CAE's protective responsibility. The CAE must confirm organizational independence to the board at least annually, communicate impairments and the safeguards used, and discuss with the board and senior management any roles that could impair independence in fact or appearance.[1]
  • Budget limitations. A budget so constrained that the function cannot cover its mandate restricts operations and can impair independence — the function that cannot afford to audit is not independent in any meaningful sense.
  • Scope limitations and restricted access. Denied access to people, records, or areas impairs the function's ability to do unbiased work; the CAE must communicate the limitation and its impact.

Why it matters: impairment questions are scenario-based. "The CAE's bonus is tied to the company's earnings targets" — impairment (personal interest in results). "The audit committee meets the CAE quarterly in executive session" — a safeguard, not an impairment.

How it is tested: "Which situation impairs independence?" with three safeguards and one impairment, or the reverse. Also "what should the CAE do?" — communicate to the board, document safeguards.

The trap: confusing administrative reporting with functional reporting. Administrative reporting to the CEO (for HR, facilities, budgets) is normal. Functional reporting — who approves the plan, who receives results, who hires/fires the CAE — must go to the board. An option describing administrative reporting to senior management as an impairment is the trap; it is not one.

2.5 The Three Lines Model

The IIA's Three Lines Model describes how risk and control responsibilities are distributed:

  • First line: operational management — owns and manages risk directly (provides products/services, maintains controls).
  • Second line: management's support functions — risk management, compliance, control expertise that assists the first line.
  • Third line: internal audit — independent assurance to the board and senior management.

The syllabus requires three things: describe the model, identify first/second-line responsibilities that could impair independence if taken on by internal audit, and describe safeguards.

Why it matters: the exam's favorite move is to hand an internal audit function a first- or second-line job — "the CAE is asked to own the enterprise risk register" or "internal audit will approve all wire transfers above $1 million" — and ask about the effect on independence. Owning risk management or operating controls impairs independence because the function would later audit its own work (self-review).

Safeguards the exam expects: if the CAE temporarily takes on a nonaudit role, assurance over that area must come from an independent third party during the assignment and for 12 months after, and the CAE must plan the transition of the responsibility back to management.[1] Other safeguards: board oversight of the arrangement, time limits, and clear documentation.

The trap: options suggesting the function can permanently hold a management role "as long as the board approves." Board approval does not cure self-review — the safeguard for temporary assignments is third-party assurance plus a transition plan, not a board waiver.

Key numbers

  • CIA Part 1: 125 questions, 150 minutes; Section A (Foundations) is 35%.[2, 3]
  • If the CAE temporarily assumes nonaudit responsibilities, independent third-party assurance is required during the assignment and for the subsequent 12 months.[1]
  • The CAE confirms organizational independence to the board at least annually.[1]

Key takeaways

  • Assurance scope is determined by internal audit; advisory scope is agreed with stakeholders; advisory never includes assurance conclusions or management responsibilities.
  • Limited assurance is a negative conclusion on less evidence; reasonable assurance is a positive conclusion on more extensive evidence.
  • Functional reporting goes to the board; administrative reporting to senior management is normal. Impairments — bad reporting lines, budget strangulation, scope denial — must be communicated to the board with safeguards.
  • Under the Three Lines Model, internal audit is the third line. Taking on first- or second-line responsibilities impairs independence; temporary assignments require third-party assurance plus a transition plan.

Chapter 2 quiz

1. The chief audit executive agrees with the chief financial officer on the objectives and scope of a review of the treasury function's new hedging procedures, then facilitates workshops to help treasury staff design controls. Which type of service is this?

  • A. An advisory service — scope was agreed
  • B. An external audit service, because treasury is involved
  • C. A compliance audit, because hedging is regulated
  • D. An assurance service, because it concerns hedging controls

2. Internal audit tests whether the company's anti-bribery controls operated effectively throughout the year and issues a conclusion on their effectiveness. This is an example of:

  • A. Advisory services
  • B. A management self-assessment
  • C. Reasonable assurance
  • D. Limited assurance

3. Which statement about advisory services is true under the Global Internal Audit Standards?

  • A. Their nature and scope are determined solely by the chief audit executive
  • B. They provide a higher level of assurance than assurance services
  • C. They are consulting services whose scope is agreed with stakeholders
  • D. They permit internal auditors to assume management responsibilities temporarily

4. An engagement letter describes a review that will result in the statement "nothing came to our attention that would indicate the controls were not operating effectively." This describes:

  • A. An advisory service
  • B. Limited assurance
  • C. A fraud investigation
  • D. Reasonable assurance

5. The internal audit function is asked to audit whether a major supplier complied with the pricing terms of a five-year contract. This engagement is best classified as:

  • A. An advisory service
  • B. A contract compliance audit
  • C. An operational audit
  • D. A financial statement audit

6. During a system implementation, the auditor advises the project team on control considerations for the new software but does not approve design decisions. This is:

  • A. Proper advisory work — advice without management responsibility
  • B. An assurance service, because systems are involved
  • C. Impermissible, because auditors may not participate in system projects
  • D. An independence impairment that must be reported to regulators

7. The chief audit executive reports functionally to the chief financial officer and administratively to the audit committee. Which statement is correct?

  • A. Reporting lines do not affect independence as long as the auditors are competent
  • B. The functional reporting line to the CFO impairs independence
  • C. The administrative reporting line to the audit committee impairs independence
  • D. This is the standard arrangement and impairs nothing

8. The audit committee approves the internal audit budget but the CFO, who controls disbursements, repeatedly delays releasing funds for planned engagements. This situation is best described as:

  • A. An advisory service performed by the CFO
  • B. Evidence of effective cost control
  • C. A routine administrative matter with no independence implications
  • D. A budget limitation that can impair independence

9. Which of the following is a safeguard the chief audit executive should employ when independence may be impaired?

  • A. Requesting that senior management approve the impairment in writing
  • B. Concealing the impairment from the board to preserve the function's reputation
  • C. Communicating the impairment and safeguards to the board
  • D. Expanding the audit plan to avoid the affected area

10. The board asks the chief audit executive to take ownership of the enterprise risk management program for two years while a new chief risk officer is recruited. Which combination preserves independence?

  • A. The CAE accepts permanently, since the board requested it
  • B. The CAE declines all nonaudit work under all circumstances
  • C. The CAE accepts and audits the risk management program personally to ensure quality
  • D. Accept temporarily, with third-party assurance and a planned transition back to management

11. Under the IIA's Three Lines Model, which activity belongs to the third line?

  • A. Designing compliance training for new hires
  • B. Operating the company's credit approval controls
  • C. Independent assurance on risk and control to the board
  • D. Maintaining the enterprise risk register

12. An internal auditor performed advisory work helping design a procurement process. Six months later the auditor is assigned to provide assurance on that same process. What is the concern?

  • A. Self-review of work the auditor helped create
  • B. The auditor lacks competence in procurement
  • C. There is no concern; advisory work improves audit quality
  • D. Advisory services are prohibited by the Standards

13. Management asks internal audit to approve all journal entries above $500,000 before posting. If the function agrees, what is the effect?

  • A. None, because the threshold is high
  • B. The function gains valuable experience that improves future audits
  • C. The function converts the approval into an advisory service
  • D. The function takes on a management responsibility, impairing independence

14. A survey of employee perceptions of "tone at the top," ethical values, and willingness to raise concerns is conducted by internal audit, with findings reported to the board. This engagement is best classified as:

  • A. A culture audit
  • B. An advisory benchmarking exercise
  • C. A fraud investigation
  • D. A financial compliance audit

15. Which of the following statements about the Three Lines Model is true?

  • A. The second line provides independent assurance to the board
  • B. Internal audit, as the third line, may permanently own second-line compliance functions if the board approves
  • C. The three lines eliminate the need for an internal audit charter
  • D. The model places operational management in the first line, owning and managing risk directly

16. The CAE learns that senior management has restricted the function's access to the whistleblower hotline database. What should the CAE do first?

  • A. Accept the restriction and audit around it
  • B. Communicate the scope limitation and its impact to the board
  • C. Report senior management to the external auditor
  • D. Disclose the restriction in the next engagement workpapers only

Sources cited in this excerpt

  1. Global Internal Audit Standards. The Institute of Internal Auditors, issued 2024-01-09, effective 2025-01-09. https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/
  2. Certified Internal Auditor (CIA) brochure. The Institute of Internal Auditors, current edition served 2026-09-22. http://www.theiia.org/globalassets/site/certifications/certified-internal-auditor/cia-brochure.pdf
  3. Certified Internal Auditor (CIA) Examination — Part 1 - Internal Audit Fundamentals (syllabus). The Institute of Internal Auditors, Inc., Effective May 2025 (V2.09.2024 FINAL). https://www.theiia.org/globalassets/site/certifications/certifications/cia/cia-part-1-syllabus-cht.pdf
You've read the free chapter

Get the complete guide

That was Chapter 2 of 6 — one complete chapter, exactly as it ships. The other chapters go just as deep on every section of the exam, plus practice questions with answer explanations — as a clean PDF and EPUB you keep forever.

Same exam, a fraction of the price
$349–$469→$19.99

A CIA Part 1 review course runs $349–$469. This book teaches the same exam — at the depth you just read — for a one-time $19.99 you keep for life.

  • Every domain of IIA's CIA Part 1 syllabus (Internal Audit Fundamentals)
  • A quiz closing each chapter, with worked explanations
  • A 125-question full-length practice exam at the published weights
  • 222 original questions, each explained and cited to its source
  • Taught to the IIA's Global Internal Audit Standards
  • PDF + EPUB you keep

Own the complete book — PDF + EPUB

The practice questions and timed mock stay free. The book is the studying half:

  • Taught chapter by chapter — every exam section explained in order, not just questions
  • Print it & tab it — a paper reference you can highlight and mark up
  • Works offline — PDF for print, EPUB for your phone or e-reader
  • Everything in one file — every chapter together, searchable and printable

This book is written in English.

$19.99one-time · lifetime download · no subscription

14-day money-back guarantee — not satisfied? Email us for a full refund, no questions asked. Refund policy

A free sample chapter is on this site — try before you buy. One payment unlocks the complete book as a PDF + EPUB you keep.

One-time $19.99 · PDF + EPUB · yours forever · see everything inside.

Free sample — one complete chapter of the CIA Part 1 — Internal Audit Fundamentals study guide. Educational summary, not professional or legal advice — always confirm the current rules with the official source. Last updated: August 2026.

Report