
374 page slide deck on the CIA Part 1 (new syllabus).
Master CIA part 1 fundamentals and exam strategy, covering timing, structure, and planning for internal audit certification, with language options and exam centers.
Meet Adrian Reisig, a chief internal audit executive who started as an accountant and champions certifications like CIA and CRM, guiding a global career through GRC and Aussig.
Learn CIA exam tips and tricks: space out your study time, plan ahead, and take a practice exam to avoid recycled questions, then focus on proficiency sections and IIA standards.
Explore the purpose and definition of internal audit, embracing independence, objectivity, assurance and consulting services, and how governance, risk management, and internal controls drive value and risk responses.
Define the internal audit charter that establishes independence, reporting lines, scope, and unfettered access for the chief audit executive and auditors to provide risk-based, objective assurance, advice, and insight.
Explore the ippf standards guiding internal audit, including ethics, governance, risk-based planning, and performing audit services across sectors, with cia context for board and management.
This lecture explains independence and objectivity in internal auditing, detailing board-approved internal audit charter, reporting lines, freedom from interference, access to information, and safeguards against threats and conflicts of interest.
Understand organizational independence for the internal audit function, including functional reporting to the board, administrative reporting to management, unrestricted access, annual independence reporting, and avoidance of interference to preserve objectivity.
Assess internal audit's role on a continuum from no role to managing risk and obligation to evaluate, assure, and support risk management including fraud risk, governance, operations, and information systems.
Explore the three lines of defence model from the Institute of Internal Auditors, detailing first-line risk ownership, second-line oversight, and independent third-line assurance by internal audit.
Explore the types of internal audit engagements, from assurance to consulting, and learn how scope, resources, and objectives define and plan each engagement.
Examine external business relationships with suppliers, clients, and partners, and assess risks from noncompliance, IP threats, and conflicts of interest; cover contracts, SLAs, due diligence, and audits.
Assess security audits to safeguard assets and ensure the reliability and integrity of information. Explore data storage risks, mislabeling, data classification, naming conventions, file management, mirroring, and cloud-based backups.
Learn how data protection audits ensure confidential handling of customer, employee, and partner data, guided by GDPR as the standard and explicit consent, purpose limitation, retention, disclosure, and access rights.
Compare external and internal audits by focusing on financial statements versus internal controls, clarifying who provides assurance over risks in financial reporting processes under generally accepted accounting principles.
Understand the internal control environment as the base of the COSO pyramid. Examine management attitude, tone at the top, ethics, reporting lines, and training shaping controls and risk assessment.
Educate the board and senior management on governance and risk management, review laws and standards, and facilitate workshops to identify emerging risks for the internal audit plan.
Develop objectivity in internal auditing by upholding the code of ethics and avoiding conflicts of interest. Disclose all material facts to prevent distorted reporting and maintain independent, accurate work.
Internal auditors must protect confidential information, avoid personal gain, and follow the code of ethics, including using the whistleblowing hotline for reporting illegal activity.
Internal auditors must perform only services they have the knowledge, skills, and experience for, under chief audit executive oversight, and continually improve through professional education to standards.
Coordinate governance actions, risk management, and control to manage risk and keep the organization on track to its objectives, containing risks within risk tolerance at the lowest cost.
Explore how internal control works through an audit report example, from draft to final report, including four-eyes review, client confirmation, and supervisory checks by the audit committee and board.
COSO's control environment forms the foundation of the pyramid. It covers culture, tone at the top, and hiring practices that shape integrity, ethics, and overall risk management.
Examine how controls operate at the entity, process, and transaction levels, and how internal audits assess governance, journal entries, and financial statements to mitigate risks across the organization.
Examine how internal controls promote performance and profitability targets, support organizational goals, and increase likelihood—never guarantee—while aiding resource protection and reliable financial reporting.
Explore control self-assessment as a structured process where managers and teams assess risks, controls, and objectives, with internal audit providing varied involvement from verifier to facilitator.
Explore coso internal control frameworks. Learn how five components and 17 principles shape the control environment, risk assessment, control activities, information and communication, and monitoring at entity and awareness levels.
Explore Cobit 5 as a governance and management framework for enterprise IT, emphasizing value for stakeholders, end-to-end coverage, integrated enablers, and separation of governance from management.
Explore the audit risk model by defining inherent risk, control risk, and detection risk, and understand residual risk through practical examples from external and internal auditing.
Explore how the board defines risk appetite as the level of risk it will accept and how acceptable risk tolerates that risk, consciously or unconsciously, without further controls.
Identify objectives and risk events, assess likelihood and impact, and determine inherent and residual risk; apply risk responses such as hedging and map risks visually.
Show how inherent and residual risks shift from high to medium or low as controls mitigate likelihood and impact. Explain acceptance of unmitigated risk and the resulting risk response.
Explore the enterprise risk management model based on the coso cube, expanding risk assessment into event identification, evaluation, and responses, with emphasis on objective setting, control activities, communication, and monitoring.
Assess how risk management maturity benchmarks organizational implementation using the capability maturity model integration, from informal to optimized processes with KPIs, risk inventories, and strategic, emerging risks.
Define emerging risks as those not yet understood or revealed, and illustrate with examples like democracy under pressure, supply chain disruption, and cyber threats.
Evaluate internal audit's role in risk management by assessing its effectiveness, incorporating consulting knowledge into risk management assurance engagements, and evaluating fraud risk across governance, operations, and information systems.
Internal audit conducts organization-wide risk assessment by identifying, measuring, and prioritizing risks, using risk source and root cause analysis to gauge impact, probability, and likelihood.
Management uses risk controls to convert acceptable risk within the risk appetite, and joint ventures share risk to transform unacceptable risk into acceptable.
Internal audit can rely on ISO 31000–based risk maturity models and the CMI maturity model, using stages from initial to defined as a roadmap for risk management.
Explore psychological biases for assessing risk, including the Dunning–Kruger effect and prospect theory, and discuss how biases hinder precise, granular risk management for internal auditors.
Explore the enterprise risk management model, from the board setting risk appetite to management implementing controls. The risk officer coordinates practices across the organization, with internal audit reviewing their work.
Apply assurance mapping to visualize three lines of defense across risks, controls, and risk owners. Assess inherent and residual risk levels and audit coverage, including IT security risks and governance.
Explore four levels of organizational culture—artifacts, written norms (code of ethics), values, and core assumptions—and how internal auditors influence culture through artifacts and norms.
Internal audit evaluates the design, implementation, and effectiveness of ethics-related objectives and programs, including governance, board oversight, policies, training, and whistleblowing channels to foster an ethical culture.
fraud consists of illegal acts defined by deceit, concealment, and violation of trust to obtain property, money, or services, including forging documents to avoid paying or gain an advantage.
Discover how internal auditors identify, assess, and address fraud risks, integrate fraud indicators into the audit plan, and decide when to perform extra tests or pursue investigations.
The fraud triangle explains how opportunity, motive, and rationalization drive fraud; weak controls and unverified payments create opportunity, while financial pressure and entitlement fuel motive and rationalization.
Classify fraud red flags into motive, rationalization, and opportunity, and examine examples like weak internal controls, questionable management philosophy, low morale, and lack of background verification.
Define fraud and fraud risk as the probability that fraud will occur and the impact when it occurs, expressed as likelihood times impact.
Contrast interviews and interrogations in fraud cases, explaining distinct goals, settings, and questioning approaches used by internal auditors versus specialized fraud investigators.
Identify facts, protect the innocent, stop losses, and recover assets through fraud investigation; gather and protect evidence, interview witnesses, uncover motives, and assess controls for future prevention.
forensic auditors gather admissible evidence and test fraud narratives, often requiring legal background or certifications, while internal auditors identify fraud indicators, red flags, and weak controls.
Internal audit provides independent assurance and consulting to add value and improve operations by supporting organizational objectives, managing risks, strengthening governance, and ensuring effective controls.
Explore how internal auditors assess governance, risk management, and effective controls, shaping the control environment through ethics, culture, and continuous improvement across projects such as construction sites.
Enhance governance through independent internal auditing that communicates risk and control information to the board, coordinates internal and external assurance, and adds value with risk-based advice.
Explore the core principles of internal auditing, including integrity, competence, objectivity, independence, and risk alignment, supported by the code of ethics and the internal audit charter.
Explore the International Professional Practices Framework from the Institute of Internal Auditors, detailing the mission, mandatory guidance, core principles, standards, and code of ethics for CIA exam.
Explore the Institute of Internal Auditors standards, including attribute and performance standards, and how governance, risk management, and internal controls guide internal audit activities.
Examine organizational independence and its effect on objectivity in the internal audit activity, including reporting lines, threats, and how independence supports adherence to standards and ethics.
Discover the ideal independence-focused reporting structure: shareholders to a board with independent non-executive members and an audit committee, with internal audit reporting to the board.
Control the scope and performance of internal audit work without interference from management. Ensure management has no say in reporting results.
Explore administrative reporting and the dotted line relationship with senior management to support operations, including payroll processing and internal communications via published policies, with clear limits on budgets.
Explore organizational independence by examining reporting structures, the role of the audit committee, and how chief executives can safeguard objectivity and ethics through proper charter changes and board-level communication.
The internal audit charter establishes independence, reporting lines, scope, and accountability, aligning with IIA standards and confirming the chief audit executive's duties, unfettered access, and annual board-approved oversight.
Explore internal audit staffing by aligning resources with a risk-based plan, ensuring sufficient, appropriate, and effectively used expertise, whether in-house, outsourced, subcontracted, or seconded, while upholding ethics.
Perform due professional care by conducting formal risk assessments to identify all significant risks, document findings, discuss with leadership, and deliver auditable results in internal audits.
Explore the CIA part one code of ethics, emphasizing integrity, objectivity, confidentiality, and competency, with guidance on honesty, diligence, responsibility, observing the law, and disclosures for conflict of interest.
Internal auditors protect confidentiality and prudently handle information, avoiding personal gain or illegal actions. They guide colleagues toward whistleblowing channels and explain that standards do not guarantee anonymity.
Uphold objectivity by maintaining an unbiased mental attitude and independence. Disclose all material facts, avoid conflicts of interest, and seek independent review to prevent distorted reporting.
Welcome to this exam preparation course for the Certified Internal Auditor (CIA), a certification from the Institute of Internal Auditors (IIA). It follows the latest syllabus from the IIA.
This teaches the new syllabus of the CIA and includes a 374 page slide deck given to download in the course.
This course aims to decrease the time you need to prepare for the exam. It includes instructor support for your questions.
I have taught internal audit courses in person to thousands of internal auditors and other interested professionals. The course covers all areas in which you need to be proficient.
This course has helped many people improve their chances at the CIA, from global Chief Audit Executives to interested students: this course is suited for anyone with an interest in internal audit.
It will help you understand the role that internal audit functions play in an organization and the principles and standards of the profession. It will help you know how to apply key concepts such as independence and objectivity. You will learn how to keep in good standing by knowing how to follow the code of ethics and how to show due professional care and proficiency.
If you manage an internal audit team or want to be ready for when you do, it will help you know whether your reporting lines are appropriate and how to improve your department through quality assurance. You will learn about the essential areas of governance, risk management and internal controls where auditors put much of their work effort. Finally, you will better know how to react if you suspect fraud within your organization.
Most importantly, it aims to help you ‘think’ like an internal auditor, which I find is essential for scoring highly on the exam as well as being a great internal auditor.
The course covers:
CIA Part 1 Introduction and Exam Strategy
Introduction to the CIA certification, overview of the content of CIA Part 1 and exam strategies.
Section A. Foundations of Internal Auditing
Understand the purpose of an internal audit function, what internal audit does and the principles, framework and standards of the profession.
Proficiently understand the critical notion of independence and be able to identify if an audit function has organizational independence.
Section B. Ethics and Professionalism
Know which areas internal auditors need to be proficient (and which they don’t). Learn how to show or identify due professional care.
Know how to always act ethically as an internal auditor.
Section C. Governance, Risk Management, and Control
Gain an understanding of internal audit’s role in governance, risk management and internal controls.
Learn about different frameworks for assessing these areas.
Recognize how this affects the staffing of internal audit functions.
Section D. Fraud Risks
Learn how to identify fraud risks and what to do if fraud is suspected. See how internal audit can change an organization’s culture.