Internal audit professionals need to do more than identify risks and control weaknesses. They must plan engagements carefully, gather reliable evidence, evaluate findings objectively, communicate results clearly, and monitor whether agreed actions are implemented. These skills form the foundation of effective internal audit work and are central to the Certified Internal Auditor (CIA) Part 2 examination.
The IIA's revised 2025 CIA syllabus changed Part 2 substantially to align the examination with the Global Internal Audit Standards and current internal audit practices. The revised Part 2 is organized into three domains: Engagement Planning (50%), Information Gathering, Analysis, and Evaluation (40%), and Engagement Supervision and Communication (10%). The exam remains 100 questions with a 120-minute time limit, and the passing score is a scaled 600 out of 750.
Understand the 2025 CIA Part 2 Structure
The revised syllabus is more focused on conducting an actual internal audit engagement than the previous version.
| Domain | Weight |
| Engagement Planning | 50% |
| Information Gathering, Analysis, and Evaluation | 40% |
| Engagement Supervision and Communication | 10% |
Because planning and fieldwork account for 90% of the exam, candidates should spend most of their preparation time developing practical engagement skills. The IIA's current syllabus emphasizes the ability to apply professional judgment rather than simply recall definitions.
This is particularly important for the 2025 syllabus because it was designed to align more closely with current internal auditing practice and the IIA's Global Internal Audit Standards.
Master Engagement Planning
Engagement Planning is the largest Part 2 domain at 50%, so it should be the starting point for your study plan.
The IIA expects candidates to understand how to determine engagement objectives, scope, evaluation criteria, and procedures. Planning should identify the significant risks relevant to the engagement and determine how those risks and related controls will be assessed.
A good engagement begins with a clear understanding of what the audit is intended to accomplish.
For example, suppose an organization is reviewing its procurement process. The internal auditor needs to establish what the engagement will examine, the period covered, relevant controls, the criteria against which performance will be evaluated, and the risks that could prevent the process from achieving its objectives.
The scope should be neither unnecessarily broad nor so narrow that important risks are excluded.
Develop Risk-Based Planning Skills
Risk assessment is central to effective engagement planning.
Candidates should understand how risk and control factors influence the objectives, scope, testing procedures, and resource requirements of an engagement. The IIA's syllabus specifically requires candidates to perform a detailed risk assessment of each audit area and evaluate and prioritize risk and control factors.
Think about risk in terms of potential consequences.
A procurement audit might involve risks such as unauthorized purchasing, conflicts of interest, inaccurate vendor information, duplicate payments, or inadequate segregation of duties.
The auditor then needs to determine which risks are most significant and design procedures capable of addressing them.
This risk-based approach helps ensure that audit resources are directed toward the areas that matter most.
Learn How to Develop an Audit Work Program
Once the auditor establishes objectives, scope, and risks, they need to determine how the engagement will be performed.
The current IIA syllabus includes determining engagement procedures and preparing the engagement work program. It also requires candidates to determine the appropriate staffing and resources needed for the engagement.
An effective work program should connect directly to the engagement's objectives and identified risks.
For example, if an audit objective is to determine whether purchases are properly authorized, the work program might include reviewing approval workflows, selecting transactions for testing, examining supporting documentation, and evaluating exceptions.
The procedures should provide sufficient evidence to support the conclusion.
Understand Evidence and Information Gathering
The second major domain—Information Gathering, Analysis, and Evaluation—represents 40% of the exam.
The IIA expects candidates to gather and examine relevant information through activities such as reviewing previous audit reports and data, conducting walkthroughs, interviewing personnel, and observing processes.
Information gathering should begin with understanding how the process actually works.
A walkthrough can be particularly useful because it allows the auditor to trace a transaction or process from beginning to end. Interviews can provide context, while documentation and system data can provide evidence that supports or challenges what people report.
Do not automatically assume that information provided by management is sufficient audit evidence. The auditor must evaluate whether evidence is relevant, reliable, and sufficient.
Master Sampling Techniques
Sampling is an important practical skill for internal auditors.
The IIA's current Part 2 syllabus includes nonstatistical, judgmental, and discovery sampling, along with statistical analysis techniques.
Candidates should understand why sampling is used and how the selection method influences audit conclusions.
Consider an organization with 50,000 transactions in a year. Reviewing every transaction may be impractical. The auditor can instead select a representative sample based on the engagement objective and risk.
The appropriate sampling method depends on the purpose of the test, the population, the nature of the risk, and the desired level of confidence.
Avoid treating sampling as simply selecting a convenient number of records.
Evaluate Evidence Quality
An internal audit conclusion must be supported by appropriate evidence.
The IIA specifically requires candidates to evaluate the relevance, sufficiency, and reliability of potential evidence.
These concepts should be clearly distinguished.
Relevance concerns whether the evidence supports the audit objective.
Sufficiency concerns whether enough evidence has been obtained to support the conclusion.
Reliability concerns the quality and trustworthiness of the evidence.
For example, independently generated system records may provide stronger evidence than an unsupported verbal statement. However, even system-generated evidence needs to be evaluated in context.
When practicing questions, always ask whether the evidence actually proves the point being tested.
Use Data Analytics and Technology
Modern internal auditing increasingly uses technology to analyze large volumes of information.
The Part 2 syllabus includes computerized audit tools and techniques such as data mining and extraction, continuous monitoring, automated workpapers, and embedded audit modules.
Candidates should understand when data analytics can improve audit effectiveness.
Suppose an organization has thousands of payments. Rather than manually examining every transaction, an auditor could use analytics to identify duplicate payments, unusual amounts, transactions outside normal hours, or other indicators of potential exceptions.
Technology does not replace professional judgment. It helps auditors examine information more efficiently and identify areas requiring deeper investigation.
Study Analytical Review Techniques
Internal auditors use analytical techniques to identify unusual patterns and relationships.
The IIA includes ratio analysis, variance analysis, budget-to-actual comparisons, trend analysis, benchmarking, and reasonableness tests within Part 2.
Learn what each technique can reveal.
A variance analysis may highlight a significant difference between actual and expected results. A trend analysis can reveal whether a metric is consistently moving in one direction. Benchmarking can help compare performance against an appropriate reference point.
The important point is understanding what question each technique can answer.
For example, if travel expenses suddenly increase by 30%, an auditor should investigate the underlying reason rather than automatically treating the increase as a control failure.
Understand Process Mapping
Process mapping can help auditors understand how activities, decisions, controls, and information flow through an organization.
The current CIA-Part2 syllabus references workflow analysis, process maps, spaghetti maps, and RACI diagrams.
A process map can help identify unnecessary steps, bottlenecks, duplicate responsibilities, missing approvals, and control gaps.
A RACI diagram, for example, helps clarify who is Responsible, Accountable, Consulted, and Informed for different activities.
Practice using these techniques to understand how an organization's process actually operates before evaluating whether the controls are effective.
Prepare Strong Audit Workpapers
Workpapers document the audit procedures performed, evidence obtained, analysis conducted, and conclusions reached.
The IIA requires candidates to prepare workpapers and documentation that support engagement conclusions and results.
A good workpaper should allow another qualified auditor to understand what was tested, what evidence was reviewed, what exceptions were identified, and how the conclusion was reached.
Avoid vague documentation.
Instead of writing that "controls were reviewed," specify what control was examined, which sample was tested, what evidence was obtained, and what the test demonstrated.
Good documentation improves quality, supervision, review, and defensibility.
Understand Engagement Supervision
The revised syllabus places Engagement Supervision and Communication at 10%.
Although this domain has the smallest weighting, it should still be studied because supervision affects audit quality.
The IIA's syllabus includes coordinating work assignments, reviewing workpapers, and evaluating auditor performance.
A senior auditor should ensure that assigned work is appropriate for the auditor's experience and that completed work is reviewed adequately.
Supervision should identify incomplete testing, unsupported conclusions, unclear documentation, or deviations from the approved audit program.
Think of supervision as an ongoing quality-control activity rather than something that happens only at the end of an engagement.
Develop Effective Communication Skills
Communication is essential throughout the audit engagement.
The IIA's revised Part 2 materials emphasize communication with stakeholders and the communication of engagement results. The IIA also identifies attributes such as accuracy, objectivity, clarity, conciseness, constructiveness, completeness, and timeliness as important characteristics of engagement communications.
An audit report should communicate information that stakeholders can understand and act upon.
Avoid overly technical language when a straightforward explanation would be clearer.
For example, instead of describing a control exception only in technical terms, explain the underlying risk, why the issue matters, and what action could reasonably address it.
Understand Findings, Recommendations, and Action Plans
Audit findings should lead to useful organizational improvement.
Candidates should understand how recommendations and management action plans relate to identified issues and root causes. The IIA's current challenge-exam material, reflecting the revised engagement framework, emphasizes determining whether an action plan adequately addresses the root cause of a finding.
This is an important distinction.
Suppose an audit finds repeated late payments because invoices are not routed to the appropriate approver. Simply reminding employees to process invoices faster may not address the underlying problem.
A stronger action plan might address the workflow or approval system responsible for the recurring delay.
Think beyond symptoms and identify the underlying cause.
Learn About Risk Acceptance
Internal auditors may encounter situations where management accepts a level of risk that the auditor considers potentially unacceptable.
The IIA's current Part 2 syllabus includes the chief audit executive's responsibility regarding residual risk and the process for communicating risk acceptance.
Candidates should understand that internal auditors do not simply take ownership of management's risk decisions.
The appropriate response involves communicating the concern through the established governance structure and following the applicable escalation process.
The objective is to ensure that significant risk acceptance decisions receive appropriate visibility.
Use the IIA's Official CIA Materials
The IIA provides a dedicated CIA syllabus, terminology resources, references, and exam-preparation resources. Its current CIA page also provides retired examination questions through official practice examinations, with rationales for correct and incorrect responses.
The IIA states that the CIA exam is a non-disclosed examination, meaning current live exam questions and answers are not published or divulged.
For candidates working toward Part 2, the official 2025 syllabus should be the primary checklist.
At the revision stage, certification preparation for CIA Part 2 2025 can reinforce major concepts and provide additional review opportunities. However, preparation should remain aligned with the IIA's current syllabus and Global Internal Audit Standards.
Practice Complete Audit Engagements
One of the best ways to prepare for Part 2 is to simulate a complete engagement.
Imagine you are auditing an organization's procurement process.
Begin by defining the engagement objective and scope. Identify significant risks and relevant controls. Develop the work program and decide what staffing and resources are required.
Then perform walkthroughs, interviews, document reviews, sampling, and data analysis.
Next, evaluate the evidence, document exceptions, determine root causes, and develop conclusions.
Finally, communicate the results and consider how management's action plan addresses the underlying issues.
This exercise connects nearly every major Part 2 competency.
Create a Focused Study Routine
Because the revised syllabus is weighted heavily toward planning and fieldwork, your study schedule should reflect those percentages.
Spend the largest amount of time on engagement planning, risk assessment, objectives, scope, work programs, sampling, evidence, analysis, workpapers, and conclusions.
Then concentrate on communication, supervision, recommendations, action plans, and risk acceptance.
The IIA's revised CIA examination was specifically designed to align with current internal audit practice and the Global Internal Audit Standards, so candidates should focus on applying concepts using professional judgment.
Practice questions should therefore be followed by an explanation of why an option is appropriate rather than simply recording whether the answer was right or wrong.
Approach CIA Part 2 Like an Internal Auditor
The strongest approach to CIA Part 2 is to think through the complete audit engagement lifecycle.
Start with a clearly defined objective and risk-based scope. Gather relevant information, evaluate evidence, apply appropriate sampling and analytics, document your work, and develop conclusions supported by evidence.
Then communicate results objectively and ensure that agreed actions address the underlying causes of identified issues.
The IIA's current 2025 syllabus places 50% on Engagement Planning and 40% on Information Gathering, Analysis, and Evaluation, making these areas the core of effective preparation.
By combining the current IIA syllabus, Global Internal Audit Standards, official practice resources, realistic audit scenarios, and targeted certification preparation for CIA Part 2 2025, candidates can build the practical judgment and engagement skills needed to approach Part 2 with greater confidence.