PrepPass team · Verified against The IIA's CIA Part 2 syllabus (V2.09.2024, effective May 2025) and CIA exam references · How we review
FREE SAMPLE · READ ONLINEChapter 1 · 50% of the exam

Engagement Planning

This is Chapter 1 of the CIA Part 2 Study Guide — 2026 Edition — one complete chapter, free to read right here; no download, no email. It is the same text as the eBook. When you reach the end, the complete guide is one click away.

Half of this exam is planning. That is not an accident: the Standards treat planning as the phase that determines whether everything downstream — evidence, findings, conclusions — is worth anything. Read this chapter the way the exam tests it: every planning task ties to a Standard, and the trap is always a task placed in the wrong phase or assigned to the wrong owner.

A1. Determine engagement objectives and scope

The engagement starts with two documented sentences: what the engagement is trying to achieve (objectives) and what it will and will not cover (scope). The Standard is explicit — internal auditors must establish and document the objectives and scope for each engagement[1]. "Document" is the word candidates gloss over. An objective discussed in a meeting but never written down does not satisfy the Standard.

Objectives are shaped by everything around the activity: regulatory requirements, the organization's strategy and objectives, governance, risk management and control processes, risk appetite and tolerance, internal policies, prior audit reports, the work of other assurance providers, and — decisively — whether the engagement is meant to provide assurance or advisory services. Assurance asks whether something is working; advisory helps management solve or design something. The syllabus names this distinction at the top of planning because it changes the work: for advisory services, a formal documented risk assessment may not be necessary, depending on the agreement with relevant stakeholders[1].

Scope limitations belong in planning too, documented as they are identified — not discovered later and retrofitted. And stakeholder requests need a method for managing and documenting them, because scope changes are normal: objectives and scope shift, and the auditor needs an effective way to address the change, re-document it, and communicate it. Throughout all of this, the auditor communicates effectively with the people who need to know — the Standard requires effective communication throughout the engagement, not just at reporting[1].

The trap: the exam will offer you a scope decision that sounds like fieldwork ("expand testing after a finding") and ask which planning activity it is. Scope changes are managed in planning; testing changes are performed in the work program. Keep the phase straight.

A2. Determine evaluation criteria based on relevant information gathered

Criteria are the "should be" against which the auditor measures the "as is." The Standard requires the auditor to identify the most relevant criteria to evaluate the aspects of the activity under review defined in the engagement objectives and scope[1]. Note the chain: objectives and scope come first; criteria serve them. Criteria chosen before objectives are locked in will measure the wrong thing.

Good criteria are specific, practical, relevant, aligned with the objectives of both the organization and the activity under review, and capable of producing reliable comparisons. The exam tests this as a judgment call: given four candidate criteria, which set actually lets two auditors reach the same comparison? Vague criteria ("best practices") fail the specificity test; criteria disconnected from the activity's objectives fail the relevance test.

The trap: candidates confuse criteria with objectives. Objectives say what the engagement will accomplish; criteria say what good looks like for the activity. A question about "the benchmark used to judge the condition" is asking about criteria — and the Standard that governs it is 13.4.

A3. Plan the engagement to assess key risks and controls

This is the syllabus's longest planning item, and the exam's favorite hunting ground. Planning requires the auditor to develop an understanding of the activity under review to assess the relevant risks[1]. That understanding must cover the strategic objectives of the activity and how they integrate with risk management, business performance measures, and performance management techniques — the auditor plans against what the activity is trying to achieve, not just its procedures.

The item then names the knowledge domains the auditor must recognize when planning: existing and emerging cybersecurity risks, common information security and IT controls, IT general controls, the purpose and benefits of an IT control framework, data privacy principles, and data security policies and practices. Two facts carry the weight here. First, access to physical and logical assets is limited to authorized users, services, and hardware — the access-control baseline[2]. Second, data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information — the data-security baseline[2]. The exam tests whether you can spot a missing IT general control or a data-security gap during planning, not whether you can configure a firewall.

Business continuity and disaster recovery readiness sit in the same item: business resilience, incident management, business impact analysis, and backup and recovery testing. The auditor recognizes these concepts to plan around them — the question is whether recovery capability is in scope and how it will be assessed, not the mechanics of a failover test.

Finance and accounting concepts appear here too: current and fixed assets, short-term and long-term liabilities, capital, and investments. The classification rules are the part to know cold. Assets are listed by how quickly they convert to cash: current assets are "things a company expects to convert to cash within one year," while fixed assets are "those assets used to operate the business but that are not available for sale, such as trucks, office furniture and other property"[3]. Liabilities split the same way: "Current liabilities are obligations a company expects to pay off within the year. Long-term liabilities are obligations due more than one year away"[3]. Working capital is what is left "if a company paid its current liabilities ... from its current assets"[3]. When an engagement touches these balances, a misclassification is a planning risk in its own right: it distorts working capital and every ratio built on it.

Finally, the auditor recognizes key risks and controls for common business processes — asset and inventory management, supply chain, accounts payable, procurement, compliance, third-party processes, CRM and ERP systems, and governance, risk, and compliance systems. The exam tests recognition, not process expertise: which risk belongs to which process, and which control addresses it.

The trap: this item is about recognizing during planning, not testing during fieldwork. If the question asks what the auditor does with a cybersecurity risk at the planning stage, the answer is to reflect it in objectives, scope, criteria, and the work program — not to run a penetration test.

A4. Determine the appropriate approach for an engagement

Traditional auditing runs planning, fieldwork, and reporting in sequence. Agile auditing runs them in sprints — cycles of one to two weeks in which planning, fieldwork, review, and reporting are all done, repeated until the audit is finished[4]. The exam tests the trade: agile gives flexibility and rapid feedback to fast-changing environments; traditional gives structure and predictability. Integrated auditing coordinates with other assurance providers so the same risk is not audited twice; remote auditing changes evidence-gathering methods, not the Standards that govern them.

Project management concepts apply to planning and conducting the engagement: the work program is the project plan, milestones track progress, and resources are the constraint that forces prioritization. When the exam describes a delayed engagement, the planning failure it points to is usually resource or schedule realism, not fieldwork technique.

The trap: agile does not mean less documentation or skipped Standards. The work program must still be developed and documented[1]; agile changes the rhythm, not the requirements.

A5. Complete a detailed risk assessment of each activity under review

The risk assessment turns the understanding from A3 into priorities. It recognizes pervasive financial, operational, IT, cybersecurity, and regulatory risks as they relate to the activity — and emerging risks, whose impact on the organization the auditor must recognize even when the risk is new and poorly measured.

Risks are evaluated and prioritized against criteria the auditor determines — likelihood, impact, velocity, and the organization's risk appetite and tolerance. The assessment must also recognize what changes risk: people, processes, and systems changes; organizational structure and environment (centralized versus decentralized, flat versus traditional, in-person versus remote work); and organizational culture — individual and group behaviors and tone at the top — and its effect on the control environment. A reorganization or a shift to remote work is not background color; it changes the risk assessment, and the exam will ask how.

Topical Requirements enter here as well: the auditor recognizes how to apply them when completing the risk assessment. Topical Requirements "are designed to enhance the consistency and quality of internal audit services related to specific audit subjects," and "internal auditors must conform with the relevant requirements when the scope of an engagement includes one of the identified topics"[1]. Cybersecurity is the first such topic the exam tests[5]. When the topic of the engagement falls under a Topical Requirement, its requirements shape the risk assessment.

The trap: risk assessment is iterative. New information during the engagement updates it — which is why the Standards require the auditor to gather information that is relevant, reliable, and sufficient, and to keep assessing as the picture changes.

A6. Determine engagement procedures and prepare the engagement work program

The work program is the engagement's operating document: the procedures that will achieve the engagement objectives, developed and documented before fieldwork begins[1]. "Develop and document" again — a program in the auditor's head is not a program.

The syllabus splits procedures three ways, and the exam tests the split: procedures to evaluate control design (is the control designed to address the risk?), procedures to test control effectiveness (does it operate as designed?), and procedures to test control efficiency (does it operate without waste?). A walk-through evaluates design; reperformance and sampling test effectiveness; timing and cost analysis test efficiency. Confusing these is the single most tested error in this item.

The auditor also evaluates the adequacy of the work program itself — does it cover the objectives, the risks, and the criteria? — and identifies testing methodologies suited to the engagement's subject matter, whether accounting, finance, IT systems, business operations, or cybersecurity. The methodology follows the subject: financial procedures test valuation and presentation; IT procedures test general and application controls; cybersecurity procedures test against the relevant Topical Requirement.

The trap: the work program is prepared during planning but executed during the engagement. A question about approving changes to procedures mid-engagement is about supervision and change control, not about the initial preparation.

A7. Determine the level of resources and skills needed for the engagement

Planning must identify the types and quantity of resources necessary to achieve the engagement objectives[1] — financial, human, and technological. The exam tests this as a gap analysis: the engagement needs data-analytics skills the team lacks, so the plan brings in a specialist, a guest auditor, or co-sourcing. Resource limitations have implications the auditor must evaluate: reduced scope, extended timelines, or reliance on the work of others — each documented, each communicated.

Data analytics belongs in the resource decision, not just the procedure decision. Analytics allows auditing 100% of data populations rather than a sample, improves assurance quality through data and transactional analysis, and makes the function more predictive with regard to areas of emerging risk[6]. Planning the technological resource — the data, the tools, the access — is what makes that possible. Continuous monitoring, built on data extraction designed during planning, supports both audit planning and execution[6].

The trap: resource decisions are made in planning, but their consequences are managed throughout. If a question describes a mid-engagement resource shortfall, the planning failure was an unrealistic resource assessment — the fix is re-planning, not heroics.

Key numbers & deadlines

FigureValueSource
Domain A weight50% of the exam[7]
Exam length100 questions / 120 minutes[8]
Current syllabusV2.09.2024 FINAL, effective May 2025[7]
Cybersecurity Topical Requirement — exam testing starts2026-August[5]
Agile sprint cycleone to two weeks, covering planning, fieldwork, review, and reporting[4]

Sources cited in this excerpt

  1. Global Internal Audit Standards (published January 9, 2024; effective January 9, 2025). The Institute of Internal Auditors. https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/
  2. NIST Cybersecurity Framework (CSF) 2.0. National Institute of Standards and Technology. https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
  3. SEC — Beginners’ Guide to Financial Statements. U.S. Securities and Exchange Commission. https://www.sec.gov/about/reports-publications/beginners-guide-financial-statements
  4. Agile auditing presentation: sprints, feedback loops, reporting. The Institute of Internal Auditors, Chicago Chapter. http://theiia.org/globalassets/site/chapters/united-states/illinois/chicago/agility-unleashed-reierson-and-farmer.pdf
  5. CIA exam references list, V5.2.2026.07.27, effective May 2025. The Institute of Internal Auditors. https://preprod.theiia.org/globalassets/site/certifications/certified-internal-auditor/cia-exam-references-v4.pdf
  6. Data analytics in internal auditing - capability document. The Institute of Internal Auditors (IIA Quality Services). https://www.theiia.org (IIA quality services PDF)
  7. CIA Part 2 syllabus (Part 2 - Internal Audit Engagement), V2.09.2024 FINAL, effective May 2025. The Institute of Internal Auditors. https://www.theiia.org/globalassets/site/certifications/certifications/cia/cia-part-2-syllabus-cht.pdf
  8. CIA program brochure (exam format overview). The Institute of Internal Auditors. http://www.theiia.org/globalassets/site/certifications/certified-internal-auditor/cia-brochure.pdf
You've read the free chapter

Get the complete guide

That was Chapter 1 — one complete chapter, exactly as it ships. The full eBook carries the same depth through every section of the exam, plus practice questions with answer explanations — as a clean PDF and EPUB you keep forever.

Same exam, a fraction of the price
$349–$469→$24.99

A CIA Part 2 review course runs $349–$469. This book teaches the same exam — at the depth you just read — for a one-time $24.99 you keep for life.

  • Three chapters following the IIA's CIA Part 2 syllabus (effective May 2025)
  • A quiz closing each chapter, with worked explanations
  • A 100-question full-length practice exam at the published 50/40/10 weights
  • 155 original questions, each explained and cited to its source
  • Taught to the IIA's Global Internal Audit Standards
  • PDF + EPUB you keep

Own the complete book — PDF + EPUB

The practice questions and timed mock stay free. The book is the studying half:

  • Taught chapter by chapter — every exam section explained in order, not just questions
  • Print it & tab it — a paper reference you can highlight and mark up
  • Works offline — PDF for print, EPUB for your phone or e-reader
  • Everything in one file — every chapter together, searchable and printable

This book is written in English.

$24.99one-time · lifetime download · no subscription

14-day money-back guarantee — not satisfied? Email us for a full refund, no questions asked. Refund policy

A free sample chapter is on this site — try before you buy. One payment unlocks the complete book as a PDF + EPUB you keep.

One-time $24.99 · PDF + EPUB · yours forever · see everything inside.

Free sample — one complete chapter of the CIA Part 2 — Internal Audit Engagement study guide. Educational summary, not professional or legal advice — always confirm the current rules with the official source. Last updated: August 2026.

Report