IIA CIA Exam
Certified Internal Auditor Exam (Page 44 )

Updated On: 12-Feb-2026

Which of the following elements is important for an internal auditor to consider when performing a privacy risk assessment of an organization?

I). Areas where personal information is collected, used, stored, and disseminated.
II). Inherent risk.
III). Privacy practices of competitors.
IV). Third-party recipients of information.

  1. III only.
  2. I and II only.
  3. I, II, and IV only.
  4. I, II, III, and IV.

Answer(s): C



The main reason to establish internal controls in an organization is to

  1. Encourage compliance with policies and procedures.
  2. Safeguard the resources of the organization.
  3. Ensure the accuracy, reliability, and timeliness of information.
  4. Provide reasonable assurance on the achievement of objectives.

Answer(s): D



The top three sales representatives for a company consistently include non-allowable charges on their expense reports. Line management is reluctant to deny reimbursement of the charges for fear of losing the sales representatives. This situation has the greatest negative impact on which of the following internal control components?

  1. Monitoring.
  2. Control environment.
  3. Information and communication.
  4. Control activities.

Answer(s): B



According to the International Professional Practices Framework, risk is

I). Defined as the negative effect of events that are expected to occur.
II). Measured in terms of consequences.
III). Measured in terms of likelihood.

  1. I only.
  2. I and II only.
  3. II and III only.
  4. I, II, and III.

Answer(s): C



Which of the following should be incorporated in a risk management policy?

I). Boundaries and limit structures.
II). Requirements for reporting risk.
III). Risk authorities.

  1. I and II only.
  2. I and III only.
  3. II and III only.
  4. I, II, and III.

Answer(s): D






Post your Comments and Discuss IIA CIA exam prep with other Community members:

Join the CIA Discussion