CIA Part 2 Study Guide — 2026 Edition cover

CIA Part 2 — Internal Audit Engagement · 2026 Edition

CIA Part 2 Study Guide — 2026 Edition

Written to the IIA's CIA Part 2 syllabus (Internal Audit Engagement, effective May 2025): three chapters, 155 original questions with worked explanations, and a 100-question full-length practice exam.

  • 155 original CIA practice questions, each with a worked explanation, in one PDF + EPUB you keep

PDF + EPUB · English · 90 pages · $24.99 one-time

This book is written in English.

Instant download after payment — no account needed, no subscription.

14-day money-back guarantee: not satisfied for any reason? Email support@preppass.org within 14 days of purchase for a full refund. Refund policy

Read a free sample chapter first

Look inside the book

Three real pages, rendered straight from the PDF you download — a reference page, a teaching page, and a worked question, always in that order. Nothing here was redrawn to look better.

  • Quick reference
    Chapter 2 — Information Gathering, Analysis, and Evaluation · PDF page 30

    A page you can turn back to: the numbers, deadlines or terms gathered in one place.

  • How it's taught
    Chapter 1 — Engagement Planning · PDF page 9

    An explanation page: the material taught in prose, in the order the exam tests it.

  • A question, worked
    Chapter 1 — Engagement Planning · PDF page 19

    A practice question with its answer and the reasoning behind it — not just a key.

About the CIA Part 2 exam

CIA candidates preparing for Part 2, which tests engagement planning, fieldwork evidence, and supervision. This independent study guide offers 155 practice questions mapped to the current IIA syllabus with sourced explanations. It is not IIA-approved and includes no online practice.

Certified Internal Auditor (CIA) — Part 2: Internal Audit Engagement — exam facts
Awarding bodyThe Institute of Internal Auditors (IIA)
Questions100
Time limit120 minutes
Passing ruleRaw scores are converted to a 250–750 reporting scale; a score of 600 or higher is required to pass
DeliveryPearson VUE test center or online proctoring (online proctoring not available for some exams and limited to certain regions)
EligibilityMaster's degree or equivalent: 1 year of experience + pass 3 exams; bachelor's degree or equivalent: 2 years + pass 3 exams; active IAP holder: 5 years + pass Parts 2 and 3; no college degree: 5 years + pass 3 exams
RetakesEarliest retake appointment is 60 days from the date the exam was last taken
LanguagesOffered in multiple languages; see the IIA website for current offerings
Content outlineCIA Part 2 syllabus — Part 2: Internal Audit Engagement, V2.09.2024 FINAL — effective May 2025
Domains and weights
  • A. Engagement Planning — 50%
  • B. Information Gathering, Analysis, and Evaluation — 40%
  • C. Engagement Supervision and Communication — 10%

Questions buyers ask

How many questions are on CIA Part 2, and how long is the exam?
The exam has 100 questions with a 120-minute time limit.
What is the passing rule for CIA Part 2?
A score of 600 or higher is required to pass; raw scores are converted to a reporting scale from 250 to 750. The IIA does not publish a percentage correct.
What are the exam domains and their weights?
Engagement Planning is 50%, Information Gathering, Analysis, and Evaluation is 40%, and Engagement Supervision and Communication is 10%.
Which syllabus edition is current, when did it take effect, and what changed?
The current outline is the IIA's Part 2 syllabus, V2.09.2024 FINAL, titled "Part 2 - Internal Audit Engagement," effective May 2025. No cited source for the previous edition's contents was available, so changes from the prior edition are not stated.
Who is eligible to sit CIA Part 2?
Eligibility depends on education: a master's degree needs 1 year of experience and a bachelor's 2 years, each plus all three exams; an active IAP holder needs 5 years plus Parts 2 and 3; no degree needs 5 years plus all three exams.
What are the exam fees, and what happens if I fail?
Fees are not stated in the IIA documents consulted for this book, so check the IIA's current fee schedule. After a failed attempt, the earliest retake appointment is 60 days from the date you last took that exam.
How is this book organized?
Three chapters follow the exam domains, each with a quiz, plus a full 100-question practice exam weighted like the real test, for 155 questions total. The book is priced at $24.99.
Is Part 2 the same as the old "Practice of Internal Auditing"?
The IIA's current syllabus titles Part 2 "Internal Audit Engagement." Older materials may use different names; study the current outline's three domains rather than relying on legacy labels.
Is a study guide enough for the CIA Part 2 — Internal Audit Engagement exam, or do I need a course?
Check eligibility first — per The Institute of Internal Auditors (IIA): master's degree or equivalent: 1 year of experience + pass 3 exams; bachelor's degree or equivalent: 2 years + pass 3 exams; active IAP holder: 5 years + pass Parts 2 and 3; no college degree: 5 years + pass 3 exams. A book does not replace those requirements. For the exam content itself, this 90-page guide teaches the material chapter by chapter with 155 practice questions and explanations inside. A prep course adds live instruction and a set schedule; whether you need one beyond any required education is your call.
Does the CIA Part 2 — Internal Audit Engagement study guide come as a PDF?
Yes — CIA Part 2 Study Guide — 2026 Edition downloads as PDF and EPUB, 90 pages. The download link is emailed the moment payment clears and does not expire.
How much does the CIA Part 2 — Internal Audit Engagement study guide cost?
$24.99, once. There is no subscription and no account to create; the PDF and EPUB files are yours to keep.
Can I read part of the CIA Part 2 — Internal Audit Engagement study guide before buying?
Yes. A full chapter is free to read on this page — not a summary of one, the chapter itself.
Is this the official CIA Part 2 — Internal Audit Engagement study guide?
No. This is an independent study guide and is not affiliated with or endorsed by the exam's awarding body. It is written from The IIA's CIA Part 2 syllabus (V2.09.2024, effective May 2025) and CIA exam references. Always confirm current requirements with the body that issues your licence.

What's included — and what isn't

Included

  • Three chapters following the IIA's CIA Part 2 syllabus (effective May 2025)
  • A quiz closing each chapter, with worked explanations
  • A 100-question full-length practice exam at the published 50/40/10 weights
  • 155 original questions, each explained and cited to its source
  • Taught to the IIA's Global Internal Audit Standards
  • PDF + EPUB you keep

Not included

  • No printed copy is shipped — this is a file you download and can print yourself
  • No video course, instructor, tutoring or online question bank comes with the book — everything is in the file
  • Not your exam registration or the testing centre's fee, which you still pay to the official body

Contents

See 6 sections and the page each one starts on
  1. Chapter 1 — Engagement Planningp. 7
  2. Chapter 2 — Information Gathering, Analysis, and Evaluationp. 24
  3. Chapter 3 — Engagement Supervision and Communicationp. 39
  4. Appendix A — Key termsp. 82
  5. Appendix B — The engagement Standards at a glancep. 85
  6. Appendix C — Exam-day strategyp. 87

Taken from the PDF you download, with the page each one starts on — not typed here.

Read a chapter free, in full

One complete chapter, exactly as it ships in the eBook. Scroll the window to read it right here; no download, no email.

Read chapter 1 here, without leaving the page
FREE SAMPLE — READ IT RIGHT HERE
Chapter 1 · 50% of the exam · ≈9 min read
Engagement Planning
scroll ↓

Half of this exam is planning. That is not an accident: the Standards treat planning as the phase that determines whether everything downstream — evidence, findings, conclusions — is worth anything. Read this chapter the way the exam tests it: every planning task ties to a Standard, and the trap is always a task placed in the wrong phase or assigned to the wrong owner.

A1. Determine engagement objectives and scope

The engagement starts with two documented sentences: what the engagement is trying to achieve (objectives) and what it will and will not cover (scope). The Standard is explicit — internal auditors must establish and document the objectives and scope for each engagement[1]. "Document" is the word candidates gloss over. An objective discussed in a meeting but never written down does not satisfy the Standard.

Objectives are shaped by everything around the activity: regulatory requirements, the organization's strategy and objectives, governance, risk management and control processes, risk appetite and tolerance, internal policies, prior audit reports, the work of other assurance providers, and — decisively — whether the engagement is meant to provide assurance or advisory services. Assurance asks whether something is working; advisory helps management solve or design something. The syllabus names this distinction at the top of planning because it changes the work: for advisory services, a formal documented risk assessment may not be necessary, depending on the agreement with relevant stakeholders[1].

Scope limitations belong in planning too, documented as they are identified — not discovered later and retrofitted. And stakeholder requests need a method for managing and documenting them, because scope changes are normal: objectives and scope shift, and the auditor needs an effective way to address the change, re-document it, and communicate it. Throughout all of this, the auditor communicates effectively with the people who need to know — the Standard requires effective communication throughout the engagement, not just at reporting[1].

The trap: the exam will offer you a scope decision that sounds like fieldwork ("expand testing after a finding") and ask which planning activity it is. Scope changes are managed in planning; testing changes are performed in the work program. Keep the phase straight.

A2. Determine evaluation criteria based on relevant information gathered

Criteria are the "should be" against which the auditor measures the "as is." The Standard requires the auditor to identify the most relevant criteria to evaluate the aspects of the activity under review defined in the engagement objectives and scope[1]. Note the chain: objectives and scope come first; criteria serve them. Criteria chosen before objectives are locked in will measure the wrong thing.

Good criteria are specific, practical, relevant, aligned with the objectives of both the organization and the activity under review, and capable of producing reliable comparisons. The exam tests this as a judgment call: given four candidate criteria, which set actually lets two auditors reach the same comparison? Vague criteria ("best practices") fail the specificity test; criteria disconnected from the activity's objectives fail the relevance test.

The trap: candidates confuse criteria with objectives. Objectives say what the engagement will accomplish; criteria say what good looks like for the activity. A question about "the benchmark used to judge the condition" is asking about criteria — and the Standard that governs it is 13.4.

A3. Plan the engagement to assess key risks and controls

This is the syllabus's longest planning item, and the exam's favorite hunting ground. Planning requires the auditor to develop an understanding of the activity under review to assess the relevant risks[1]. That understanding must cover the strategic objectives of the activity and how they integrate with risk management, business performance measures, and performance management techniques — the auditor plans against what the activity is trying to achieve, not just its procedures.

The item then names the knowledge domains the auditor must recognize when planning: existing and emerging cybersecurity risks, common information security and IT controls, IT general controls, the purpose and benefits of an IT control framework, data privacy principles, and data security policies and practices. Two facts carry the weight here. First, access to physical and logical assets is limited to authorized users, services, and hardware — the access-control baseline[2]. Second, data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information — the data-security baseline[2]. The exam tests whether you can spot a missing IT general control or a data-security gap during planning, not whether you can configure a firewall.

Business continuity and disaster recovery readiness sit in the same item: business resilience, incident management, business impact analysis, and backup and recovery testing. The auditor recognizes these concepts to plan around them — the question is whether recovery capability is in scope and how it will be assessed, not the mechanics of a failover test.

Finance and accounting concepts appear here too: current and fixed assets, short-term and long-term liabilities, capital, and investments. The classification rules are the part to know cold. Assets are listed by how quickly they convert to cash: current assets are "things a company expects to convert to cash within one year," while fixed assets are "those assets used to operate the business but that are not available for sale, such as trucks, office furniture and other property"[3]. Liabilities split the same way: "Current liabilities are obligations a company expects to pay off within the year. Long-term liabilities are obligations due more than one year away"[3]. Working capital is what is left "if a company paid its current liabilities ... from its current assets"[3]. When an engagement touches these balances, a misclassification is a planning risk in its own right: it distorts working capital and every ratio built on it.

Finally, the auditor recognizes key risks and controls for common business processes — asset and inventory management, supply chain, accounts payable, procurement, compliance, third-party processes, CRM and ERP systems, and governance, risk, and compliance systems. The exam tests recognition, not process expertise: which risk belongs to which process, and which control addresses it.

The trap: this item is about recognizing during planning, not testing during fieldwork. If the question asks what the auditor does with a cybersecurity risk at the planning stage, the answer is to reflect it in objectives, scope, criteria, and the work program — not to run a penetration test.

A4. Determine the appropriate approach for an engagement

Traditional auditing runs planning, fieldwork, and reporting in sequence. Agile auditing runs them in sprints — cycles of one to two weeks in which planning, fieldwork, review, and reporting are all done, repeated until the audit is finished[4]. The exam tests the trade: agile gives flexibility and rapid feedback to fast-changing environments; traditional gives structure and predictability. Integrated auditing coordinates with other assurance providers so the same risk is not audited twice; remote auditing changes evidence-gathering methods, not the Standards that govern them.

Project management concepts apply to planning and conducting the engagement: the work program is the project plan, milestones track progress, and resources are the constraint that forces prioritization. When the exam describes a delayed engagement, the planning failure it points to is usually resource or schedule realism, not fieldwork technique.

The trap: agile does not mean less documentation or skipped Standards. The work program must still be developed and documented[1]; agile changes the rhythm, not the requirements.

A5. Complete a detailed risk assessment of each activity under review

The risk assessment turns the understanding from A3 into priorities. It recognizes pervasive financial, operational, IT, cybersecurity, and regulatory risks as they relate to the activity — and emerging risks, whose impact on the organization the auditor must recognize even when the risk is new and poorly measured.

Risks are evaluated and prioritized against criteria the auditor determines — likelihood, impact, velocity, and the organization's risk appetite and tolerance. The assessment must also recognize what changes risk: people, processes, and systems changes; organizational structure and environment (centralized versus decentralized, flat versus traditional, in-person versus remote work); and organizational culture — individual and group behaviors and tone at the top — and its effect on the control environment. A reorganization or a shift to remote work is not background color; it changes the risk assessment, and the exam will ask how.

Topical Requirements enter here as well: the auditor recognizes how to apply them when completing the risk assessment. Topical Requirements "are designed to enhance the consistency and quality of internal audit services related to specific audit subjects," and "internal auditors must conform with the relevant requirements when the scope of an engagement includes one of the identified topics"[1]. Cybersecurity is the first such topic the exam tests[5]. When the topic of the engagement falls under a Topical Requirement, its requirements shape the risk assessment.

The trap: risk assessment is iterative. New information during the engagement updates it — which is why the Standards require the auditor to gather information that is relevant, reliable, and sufficient, and to keep assessing as the picture changes.

A6. Determine engagement procedures and prepare the engagement work program

The work program is the engagement's operating document: the procedures that will achieve the engagement objectives, developed and documented before fieldwork begins[1]. "Develop and document" again — a program in the auditor's head is not a program.

The syllabus splits procedures three ways, and the exam tests the split: procedures to evaluate control design (is the control designed to address the risk?), procedures to test control effectiveness (does it operate as designed?), and procedures to test control efficiency (does it operate without waste?). A walk-through evaluates design; reperformance and sampling test effectiveness; timing and cost analysis test efficiency. Confusing these is the single most tested error in this item.

The auditor also evaluates the adequacy of the work program itself — does it cover the objectives, the risks, and the criteria? — and identifies testing methodologies suited to the engagement's subject matter, whether accounting, finance, IT systems, business operations, or cybersecurity. The methodology follows the subject: financial procedures test valuation and presentation; IT procedures test general and application controls; cybersecurity procedures test against the relevant Topical Requirement.

The trap: the work program is prepared during planning but executed during the engagement. A question about approving changes to procedures mid-engagement is about supervision and change control, not about the initial preparation.

A7. Determine the level of resources and skills needed for the engagement

Planning must identify the types and quantity of resources necessary to achieve the engagement objectives[1] — financial, human, and technological. The exam tests this as a gap analysis: the engagement needs data-analytics skills the team lacks, so the plan brings in a specialist, a guest auditor, or co-sourcing. Resource limitations have implications the auditor must evaluate: reduced scope, extended timelines, or reliance on the work of others — each documented, each communicated.

Data analytics belongs in the resource decision, not just the procedure decision. Analytics allows auditing 100% of data populations rather than a sample, improves assurance quality through data and transactional analysis, and makes the function more predictive with regard to areas of emerging risk[6]. Planning the technological resource — the data, the tools, the access — is what makes that possible. Continuous monitoring, built on data extraction designed during planning, supports both audit planning and execution[6].

The trap: resource decisions are made in planning, but their consequences are managed throughout. If a question describes a mid-engagement resource shortfall, the planning failure was an unrealistic resource assessment — the fix is re-planning, not heroics.

Key numbers & deadlines

FigureValueSource
Domain A weight50% of the exam[7]
Exam length100 questions / 120 minutes[8]
Current syllabusV2.09.2024 FINAL, effective May 2025[7]
Cybersecurity Topical Requirement — exam testing starts2026-August[5]
Agile sprint cycleone to two weeks, covering planning, fieldwork, review, and reporting[4]

Sources cited in this excerpt

  1. Global Internal Audit Standards (published January 9, 2024; effective January 9, 2025). The Institute of Internal Auditors. https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/
  2. NIST Cybersecurity Framework (CSF) 2.0. National Institute of Standards and Technology. https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
  3. SEC — Beginners’ Guide to Financial Statements. U.S. Securities and Exchange Commission. https://www.sec.gov/about/reports-publications/beginners-guide-financial-statements
  4. Agile auditing presentation: sprints, feedback loops, reporting. The Institute of Internal Auditors, Chicago Chapter. http://theiia.org/globalassets/site/chapters/united-states/illinois/chicago/agility-unleashed-reierson-and-farmer.pdf
  5. CIA exam references list, V5.2.2026.07.27, effective May 2025. The Institute of Internal Auditors. https://preprod.theiia.org/globalassets/site/certifications/certified-internal-auditor/cia-exam-references-v4.pdf
  6. Data analytics in internal auditing - capability document. The Institute of Internal Auditors (IIA Quality Services). https://www.theiia.org (IIA quality services PDF)
  7. CIA Part 2 syllabus (Part 2 - Internal Audit Engagement), V2.09.2024 FINAL, effective May 2025. The Institute of Internal Auditors. https://www.theiia.org/globalassets/site/certifications/certifications/cia/cia-part-2-syllabus-cht.pdf
  8. CIA program brochure (exam format overview). The Institute of Internal Auditors. http://www.theiia.org/globalassets/site/certifications/certified-internal-auditor/cia-brochure.pdf
Open the free chapter →

Before you buy

How do I get it?
Pay, and the download appears on this page straight away. The links are also emailed to you. No account is required.
What if it isn't for me?
Email us within 14 days for a full refund, no questions asked.
Is there online practice for this exam too?
No. PrepPass has no online question bank for this exam; the book is self-contained. Its chapter quizzes and full-length practice exam, each question with a worked explanation, are all in the PDF and EPUB.
Can I read it on my phone?
Yes — the EPUB is for phones and e-readers, the PDF is for printing and tabbing. You get both.

Full refund policy

The details

Written to the IIA's CIA Part 2 syllabus (Internal Audit Engagement, effective May 2025): three chapters, 155 original questions with worked explanations, and a 100-question full-length practice exam.

PrepPass team · Verified against The IIA's CIA Part 2 syllabus (V2.09.2024, effective May 2025) and CIA exam references · How we review
  • Format: PDF + EPUB download · 90 pages
  • 155 practice questions in the book, with a full answer key
  • $24.99 one-time — no subscription
  • 14-day money-back guarantee · refund policy
  • Cross-referenced against: The IIA's CIA Part 2 syllabus (V2.09.2024, effective May 2025) and CIA exam references
  • Last updated: September 2026
  • Verified from the official source(The IIA's CIA Part 2 syllabus (V2.09.2024, effective May 2025) and CIA exam references)
  • Instant download, yours for life
Same exam, a fraction of the price
$349–$469→$24.99

A CIA Part 2 review course runs $349–$469. This book teaches the same exam — same rules, verified to current standards — for a one-time $24.99 you keep for life.

What the book gives you

PrepPass has no online question bank for this exam, so the $24.99 book is complete in itself: the material taught in order, a quiz closing each chapter and a full-length practice exam, in a file you own.

  • Systematic teaching — every exam section explained chapter by chapter, start to finish, not just questions
  • Print it & tab it — a paper-ready PDF you can highlight, mark up, and bring to your study table
  • Study anywhere, offline — EPUB on your phone or e-reader; no wifi, no browser tabs
  • Everything in one place — the chapters and the practice questions in one file
  • Yours for life — one-time $24.99, instant download, no subscription

And it's risk-free: 14-day money-back guarantee — not satisfied? Email us for a full refund, no questions asked. See the refund policy.

Get the eBook — $24.99 (PDF + EPUB) ↑

14-day money-back guarantee · full refund, no questions asked.

One-time purchase, lifetime access to the download. The eBook is the full CIA Part 2 — Internal Audit Engagement study guide in PDF and EPUB. Educational summary, not professional or legal advice — always confirm the current rules with the official source. Last updated: September 2026.

Report