Part 1
I. FOUNDATIONS OF INTERNAL AUDITING (15%)
A
Interpret The IIA's Mission of Internal Audit, Definition of Internal
Auditing, and Core Principles for the Professional Practice of Internal Proficient
Auditing, and the purpose, authority, and responsibility of the internal audit
activity
Explain the requirements of an internal audit charter (required components,
B Basic
board approval, communication of the charter, etc.)
Interpret the difference between assurance and consulting services provided
C Proficient
by the internal audit activity
D Demonstrate conformance with the IIA Code of Ethics Proficient
II. INDEPENDENCE AND OBJECTIVITY (15%)
Interpret organizational independence of the internal audit activity
A Basic
(importance of independence, functional reporting, etc.)
Identify whether the internal audit activity has any impairments to its
B Basic
independence
Assess and maintain an individual internal auditor's objectivity, including
C determining whether an individual internal auditor has any impairments to Proficient
his/her objectivity
D Analyze policies that promote objectivity Proficient
III. PROFICIENCY AND DUE PROFESSIONAL CARE
(18%)
Recognize the knowledge, skills, and competencies required (whether
A developed or procured) to fulfill the responsibilities of the internal audit Basic
activity
Demonstrate the knowledge and competencies that an internal auditor needs
to possess to perform his/her individual responsibilities, including technical
B Proficient
skills and soft skills (communication skills, critical thinking,
persuasion/negotiation and collaboration skills, etc.)
C Demonstrate due professional care Proficient
Demonstrate an individual internal auditor's competency through continuing
D Proficient
professional development
IV. QUALITY ASSURANCE AND IMPROVEMENT
PROGRAM (7%)
Describe the required elements of the quality assurance and improvement
A Basic
program (internal assessments, external assessments, etc.)
Describe the requirement of reporting the results of the quality assurance and
B Basic
improvement program to the board or other governing body
Identify appropriate disclosure of conformance vs. nonconformance with The
C Basic
IIA’s International Standards for the Professional Practice of Internal Auditing
V. GOVERNANCE, RISK MANAGEMENT, AND
CONTROL (35%)
A Describe the concept of organizational governance Basic
Recognize the impact of organizational culture on the overall control environment
B Basic
and individual engagement risks and controls
Recognize and interpret the organization's ethics and compliance-related issues,
C Basic
alleged violations, and dispositions
D Describe corporate social responsibility Basic
E Interpret fundamental concepts of risk and the risk management process Proficient
Describe globally accepted risk management frameworks appropriate to the
F Basic
organization (COSO - ERM, ISO 31000, etc.)
G Examine the effectiveness of risk management within processes and functions Proficient
Recognize the appropriateness of the internal audit activity’s role in the
H Basic
organization's risk management process
I Interpret internal control concepts and types of controls Proficient
Apply globally accepted internal control frameworks appropriate to the
J Proficient
organization (COSO, etc.)
K Examine the effectiveness and efficiency of internal controls Proficient
VI. FRAUD RISKS (10%)
Interpret fraud risks and types of frauds and determine whether fraud risks require
A Proficient
special consideration when conducting an engagement
Evaluate the potential for occurrence of fraud (red flags, etc.) and how the
B Proficient
organization detects and manages fraud risks
Recommend controls to prevent and detect fraud and education to improve the
C Proficient
organization's fraud awareness
Recognize techniques and internal audit roles related to forensic auditing
D Basic
(interview, investigation, testing, etc.)
Part 2
I. MANAGING THE INTERNAL AUDIT ACTIVITY (20%)
1. Internal Audit Operations
Describe policies and procedures for the planning, organizing, directing, and
A Basic
monitoring of internal audit operations
Interpret administrative activities (budgeting, resourcing, recruiting, staffing, etc.)
B Basic
of the internal audit activity
2. Establishing a Risk-based Internal Audit Plan
A Identify sources of potential engagements (audit universe, audit cycle requirements, Basic
management requests, regulatory mandates, relevant market and industry trends,
emerging issues, etc.)
Identify a risk management framework to assess risks and prioritize audit
B Basic
engagements based on the results of a risk assessment
Interpret the types of assurance engagements (risk and control assessments, audits
of third parties and contract compliance, security and privacy, performance and
C Proficient
quality audits, key performance indicators, operational audits, financial and
regulatory compliance audits)
Interpret the types of consulting engagements (training, system design, system
D development, due diligence, privacy, benchmarking, internal control assessment, Proficient
process mapping, etc.) designed to provide advice and insight
Describe coordination of internal audit efforts with the external auditor, regulatory
E oversight bodies, and other internal assurance functions, and potential reliance on Basic
other assurance providers
3. Communicating and Reporting to Senior Management and the Board
Recognize that the chief audit executive communicates the annual audit plan to
A Basic
senior management and the board and seeks the board's approval
Identify significant risk exposures and control and governance issues for the chief
B Basic
audit executive to report to the board
Recognize that the chief audit executive reports on the overall effectiveness of the
C organization's internal control and risk management processes to senior Basic
management and the board
Recognize internal audit key performance indicators that the chief audit executive
D Basic
communicates to senior management and the board periodically
II. PLANNING THE ENGAGEMENT (20%)
1. Engagement Planning
Determine engagement objectives, evaluation criteria, and the scope of the
A Proficient
engagement
B Plan the engagement to assure identification of key risks and controls Proficient
Complete a detailed risk assessment of each audit area, including evaluating and
C Proficient
prioritizing risk and control factors
D Determine engagement procedures and prepare the engagement work program Proficient
E Determine the level of staff and resources needed for the engagement Proficient
III. PERFORMING THE ENGAGEMENT (40%)
1. Information Gathering
Gather and examine relevant information (review previous audit reports and data,
A conduct walk-throughs and interviews, perform observations, etc.) as part of a Proficient
preliminary survey of the engagement area
Develop checklists and risk-and-control questionnaires as part of a preliminary
B Proficient
survey of the engagement area
Apply appropriate sampling (nonstatistical, judgmental, discovery, etc.) and
C Proficient
statistical analysis techniques
2. Analysis and Evaluation
Use computerized audit tools and techniques (data mining and extraction,
A Proficient
continuous monitoring, automated workpapers, embedded audit modules, etc.)
B Evaluate the relevance, sufficiency, and reliability of potential sources of evidence Proficient
Apply appropriate analytical approaches and process mapping techniques (process
C identification, workflow analysis, process map generation and analysis, spaghetti Proficient
maps, RACI diagrams, etc.)
Determine and apply analytical review techniques (ratio estimation, variance
D analysis, budget vs. actual, trend analysis, other reasonableness tests, benchmarking, Basic
etc.)
Prepare workpapers and documentation of relevant information to support
E Proficient
conclusions and engagement results
Summarize and develop engagement conclusions, including assessment of risks and
F Proficient
controls
3. Engagement Supervision
Identify key activities in supervising engagements (coordinate work assignments,
A Basic
review workpapers, evaluate auditors' performance, etc.)
IV. COMMUNICATING ENGAGEMENT RESULTS AND
MONITORING PROGRESS (20%)
1. Communicating Engagement Results and the Acceptance of Risk
A Arrange preliminary communication with engagement clients Proficient
Demonstrate communication quality (accurate, objective, clear, concise, constructive,
B complete, and timely) and elements (objectives, scope, conclusions, Proficient
recommendations, and action plan)
C Prepare interim reporting on the engagement progress Proficient
D Formulate recommendations to enhance and protect organizational value Proficient
Describe the audit engagement communication and reporting process, including
E holding the exit conference, developing the audit report (draft, review, approve, and Basic
distribute), and obtaining management's response
F Describe the chief audit executive's responsibility for assessing residual risk Basic
Describe the process for communicating risk acceptance (when management has
G Basic
accepted a level of risk that may be unacceptable to the organization)
2. Monitoring Progress
A Assess engagement outcomes, including the management action plan Proficient
Manage monitoring and follow-up of the disposition of audit engagement results
B Proficient
communicated to management and the board
Part 3
I. BUSINESS ACUMEN (35%)
1. Organizational Objectives, Behavior, and Performance
Describe the strategic planning process and key activities (objective setting,
A globalization and competitive considerations, alignment to the organization's mission Basic
and values, etc.)
Examine common performance measures (financial, operational, qualitative vs.
B Proficient
quantitative, productivity, quality, efficiency, effectiveness, etc.)
Explain organizational behavior (individuals in organizations, groups, and how
C organizations behave, etc.) and different performance management techniques (traits, Basic
organizational politics, motivation, job design, rewards, work schedules, etc.)
Describe management’s effectiveness to lead, mentor, guide people, build
D Basic
organizational commitment, and demonstrate entrepreneurial ability
2. Organizational Structure and Business Processes
Appraise the risk and control implications of different organizational configuration
A Basic
structures (centralized vs. decentralized, flat structure vs. traditional, etc.)
Examine the risk and control implications of common business processes (human
B resources, procurement, product development, sales, marketing, logistics, management Proficient
of outsourced processes, etc.)
Identify project management techniques (project plan and scope,
C Basic
time/team/resources/cost management, change management, etc.)
Recognize the various forms and elements of contracts (formality, consideration,
D Basic
unilateral, bilateral, etc.)
3. Data Analytics
Describe data analytics, data types, data governance, and the value of using data
A Basic
analytics in internal auditing
Explain the data analytics process (define questions, obtain relevant data,
B Basic
clean/normalize data, analyze data, communicate results)
Recognize the application of data analytics methods in internal auditing (anomaly
C Basic
detection, diagnostic analysis, predictive analysis, network analysis, text analysis, etc.)
II. INFORMATION SECURITY (25%)
1. Information Security
A Differentiate types of common physical security controls (cards, keys, biometrics, etc.) Basic
Differentiate the various forms of user authentication and authorization controls
B (password, two-level authentication, biometrics, digital signatures, etc.) and identify Basic
potential risks
Explain the purpose and use of various information security controls (encryption,
C Basic
firewalls, antivirus, etc.)
Recognize data privacy laws and their potential impact on data security policies and
D Basic
practices
Recognize emerging technology practices and their impact on security (bring your own
E Basic
device [BYOD], smart devices, internet of things [IoT], etc.)
Recognize existing and emerging cybersecurity risks (hacking, piracy, tampering,
F Basic
ransomware attacks, phishing attacks, etc.)
G Describe cybersecurity and information security-related policies Basic
III. INFORMATION TECHNOLOGY (20%)
1. Application and System Software
Recognize core activities in the systems development lifecycle and delivery
A (requirements definition, design, developing, testing, debugging, deployment, Basic
maintenance, etc.) and the importance of change controls throughout the process
Explain basic database terms (data, database, record, object, field, schema, etc.) and
B internet terms (HTML, HTTP, URL, domain name, browser, click-through, electronic Basic
data interchange [EDI], cookies, etc.)
Identify key characteristics of software systems (customer relationship management
C [CRM] systems; enterprise resource planning [ERP] systems; and governance, risk, Basic
and compliance [GRC] systems; etc.)
2. IT Infrastructure and IT Control Frameworks
Explain basic IT infrastructure and network concepts (server, mainframe, client-server
A Basic
configuration, gateways, routers, LAN, WAN, VPN, etc.) and identify potential risks
Define the operational roles of a network administrator, database administrator, and
B Basic
help desk
Recognize the purpose and applications of IT control frameworks (COBIT, ISO
C Basic
27000, ITIL, etc.) and basic IT controls
3. Disaster Recovery
A Explain disaster recovery planning site concepts (hot, warm, cold, etc.) Basic
B Explain the purpose of systems and data backup Basic
C Explain the purpose of systems and data recovery procedures Basic
IV. FINANCIAL MANAGEMENT (20%)
1. Financial Accounting and Finance
Identify concepts and underlying principles of financial accounting (types of financial
A statements and terminologies such as bonds, leases, pensions, intangible assets, research Basic
and development, etc.)
Recognize advanced and emerging financial accounting concepts (consolidation,
B Basic
investments, fair value, partnerships, foreign currency transactions, etc.)
Interpret financial analysis (horizontal and vertical analysis and ratios related to activity,
C Proficient
profitability, liquidity, leverage, etc.)
Describe revenue cycle, current asset management activities and accounting, and supply
D Basic
chain management (including inventory valuation and accounts payable)
E Describe capital budgeting, capital structure, basic taxation, and transfer pricing Basic
2. Managerial Accounting
Explain general concepts of managerial accounting (cost-volume-profit analysis,
A Basic
budgeting, expense allocation, cost- benefit analysis, etc.)
B Differentiate costing systems (absorption, variable, fixed, activity-based, standard, etc.) Basic
Distinguish various costs (relevant and irrelevant costs, incremental costs, etc.) and their
C Basic
use in decision making