
IIA – The Certified Internal Auditor (CIA)
Course Description:
The Certified Internal Auditor
IIA’s Certification in Internal Auditing qualification (Certified Internal Auditor) accelerates your success as a credible and proficient internal auditor. Internal audit certification is the optimum way to communicate knowledge, skills, and competencies to effectively carry out professional responsibilities for any internal audit, anywhere in the world. The qualification adds value to Organization’s governance, Risk management and Internal controls.
As a matter of fact, earning a professional internal audit credential is a critical step to being distinguished from your peers and will:
- Enhance credibility and respect.
- Sharpen skills and proficiencies.
- Increase advancement and earning potential.
- Demonstrate understanding and commitment.
Visit The Institute of Internal Auditors (IIA) to learn more about Global Institute
Who should study for The Certified Internal Auditor?
Who should study for CIA?
CIA designation is a valuable accomplishment and a professional advantage for auditors at all stages of their careers. This certification program aimed to;
- Chief audit executives
- Audit managers
- Audit staff
- Risk management staff
- Students enrolled in an accounting or other business or financial degree program.
Eligibility to become a CIA
The following criteria needs to be fulfilled at the time of online registration for the examinations.
| Education Level | Years of Work Experience Required |
| Master’s Degree (or equivalent) | 12 months – internal auditing experience or its equivalent at the time of certification. |
| Bachelor’s Degree (or equivalent) | 24 months – internal auditing experience or its equivalent at the time of certification. |
| Associate’s Degree, three A-Level Certificates, grade C or higher (or equivalent) |
60 months – internal auditing experience or its equivalent at the time of joining the programme . |
Work Experience
Candidates may apply to the certification program and sit for exams prior to obtaining the required work experience. However, candidates will not be certified until unless the experience requirement is met within the program eligibility period. Experience for the CIA’s certification program is based on the entry method (refer to the program requirements table above).
- Internal Audit
- Quality Assurance
- Risk Management
- Audit/Assessment/Disciplines
- Compliance
- External Audit
- Internal Control
How is the qualification structured?
The complete CIS educational programme comprises of three examination parts. After completing the examinations the candidates can apply for Certified Internal Auditor Membership.
Membership in The IIA means premier access to the standards-setting and guidance-producing body of the profession. Plus, exclusive industry-specific content, networking opportunities, and savings on world-class training are even more ways we connect over 200,000 members worldwide.
The CIA exam was updated in 2019 and is now available in 12 languages, with additional languages to be released throughout 2020 and into 2021.
How is the examinations structured?
Communication, registration and examination procedure with the institute is a complete online process.
- The examinations are conducted online.
- CIA Part 1 is a 2.5-hour examination with 125 MCQ’s.
- CIA Part 2 and part 3 are each 2.0 hours long with 100 MCQ’s to answer.
- Pass mark of 80%.
- Average pass rate X%
- Mock examinations before the Final exam.
Simply send us your details, we will get back to you with more information.
The complete qualification programme is structured, in 03 staged programmes which students should have to follow and complete each to qualify for the next.
Or just call us, our programme coordinators will guide you through!
. Foundations of Internal Auditing (35%)
- Understand the purpose, benefits, and effectiveness of internal auditing per Global Standards.
- Explain the internal audit mandate and roles of the board & CAE.
- Know the required components of the internal audit charter.
- Differentiate between assurance vs advisory services.
- Describe types of assurance services: risk, compliance, IT audits, performance, etc.
- Describe types of advisory services: risk training, system design, benchmarking, etc.
- Identify situations of impaired independence and responsibilities of the CAE and board.
- Understand the Three Lines Model and the IA function’s role in risk management.
1. Ethics and Professionalism (20%)
- Demonstrate integrity, legal behavior, and courage in ethical dilemmas.
- Assess objectivity impairments (e.g., bias, conflicts of interest).
- Apply policies to mitigate impairments (reassignment, disclosure, outsourcing).
- Use essential skills and competencies: communication, critical thinking, persuasion, etc.
- Show due professional care: assess risks, benefits, and professional skepticism.
- Maintain confidentiality and handle information appropriately during engagements.
2. C. Governance, Risk Management, and Control (30%)
- Describe organizational governance roles and frameworks.
- Understand organizational culture and its effect on risks and controls.
- Recognize ethical and compliance issues within the organization.
- Interpret types of risks: strategic, operational, financial, etc.
- Understand the risk management process and risk response strategies.
- Evaluate risk frameworks and effectiveness of risk management systems.
- Understand internal control types (preventive, detective, corrective).
- Assess design, effectiveness, and efficiency of controls.
3. Fraud Risks (15%)
- Understand fraud triangle: motivation, opportunity, rationalization.
- Identify when fraud risks need special attention during audits.
- Evaluate an organization’s fraud detection and response capabilities.
- Know controls to prevent/detect fraud (e.g., segregation of duties, hotlines).
- Understand the auditor’s role in investigations, and relevant techniques
Thursday
October 08, 2026
1. Engagement Planning (50%)
- Define objectives and scope using Topical Requirements, strategy, and stakeholder needs.
- Select evaluation criteria aligned with audit objectives and reliable benchmarks.
- Plan engagements to assess key risks and controls in finance, IT, cybersecurity, procurement, CRM, etc.
- Choose suitable engagement approaches (agile, integrated, traditional, remote).
- Conduct risk assessments covering people, process, systems, structure, and culture.
- Develop detailed work programs and choose procedures for testing design, effectiveness, and efficiency.
- Assess required financial, human, and technology resources and manage resource limitations.
2. Information Gathering, Analysis & Evaluation (40%)
- Gather evidence using interviews, walkthroughs, documents, data, and tech tools.
- Evaluate relevance, sufficiency, and reliability of evidence.
- Use data analytics (diagnostic, predictive, anomaly detection, text analysis) and process mapping.
- Apply analytical review techniques like ratio/trend analysis and benchmarking.
- Identify findings through criteria comparison, root cause analysis, and materiality judgments.
- Prepare workpapers that fully support conclusions and meet documentation standards.
- Develop clear, risk-aligned engagement conclusions using professional judgment.
3. Engagement Supervision & Communication (10%)
- Supervise audits: plan tasks, review workpapers, evaluate performance.
- Maintain effective communication with stakeholders during all phases.
- Know when to escalate findings or concerns.
Friday
Qualified professionals can earn the CIA through the One-Part Challenge Exam
1. Internal Audit Operations (25%)
- Plan, organize, and monitor internal audit activities using modern methodologies.
- Manage financial, human, and IT resources and performance development.
- Align audit strategy with stakeholder expectations and business priorities.
- Understand the CAE’s responsibilities for communicating with the board on audit plans, results, and remediation.
2. Internal Audit Plan (15%)
- Build a dynamic risk-based audit plan using:
- Audit universe, board input, laws, industry trends, and emerging technologies (AI, blockchain, IoT, RPA).
- Coordinate with other assurance providers and evaluate reliance on their work.
3. Quality of the Internal Audit Function (15%)
- Apply the Quality Assurance and Improvement Program (QAIP):
- Internal/external assessments, ongoing monitoring, remediation, and communication of results.
- Disclose nonconformance with IIA Standards appropriately.
- Use KPIs and scorecards to monitor audit performance (qualitative & quantitative).
4. Engagement Results & Monitoring (45%)
- Communicate results effectively: accurate, complete, timely, and constructive reports.
- Develop recommendations and action plans collaboratively with management.
- Conduct exit meetings and distribute final reports to appropriate stakeholders.
- Assess residual risk and communicate risk acceptance where needed.
- Monitor and follow up on action plans, escalating unresolved items.
Friday
The Challenge Exam allows you to obtain the CIA designation after successfully passing a one-part examination. Designed exclusively for experienced professionals or those who hold an eligible credential, it evaluates the practical application of internal audit knowledge at an advanced level.
Section A: Internal Audit Professionalism and Quality (20%)
-
Explain the internal audit mandate and responsibilities of the board and chief audit executive
-
Identify situations where the independence of the internal audit function may be impaired
-
Recognize the internal audit function’s role in the organization’s risk management process
-
Assess whether an individual internal auditor has any impairments to objectivity
-
Maintain confidentiality and use information appropriately during engagements
-
Describe the required elements of the quality assurance and improvement program
-
Identify appropriate disclosure of nonconformance with The IIA’s Global Internal Audit Standards
-
Recognize practical methods for establishing internal audit key performance indicators or scorecard metrics that the chief audit executive communicates to senior management and the board
Section B: Internal Audit Operations and Audit Plan (15%)
-
Describe methodologies for the planning, organizing, directing, and monitoring of internal audit operations
-
Describe key activities for managing financial, human, and IT resources within the internal audit function
-
Describe the key elements required to align internal audit strategy to stakeholder expectations
-
Recognize the chief audit executive’s responsibilities for building relationships and communicating with senior management and the board about various matters
-
Identify sources of potential engagements
-
Describe the processes to develop a risk-based audit plan
-
Recognize the importance for internal auditors to coordinate with other assurance providers and leverage their work
Section C: Engagement Planning (20%)
-
Determine engagement objectives and scope
-
Determine evaluation criteria based on relevant information gathered
-
Plan the engagement to assess key risks and controls
-
Determine the appropriate approach for an engagement
-
Complete a detailed risk assessment of each activity under review
-
Determine engagement procedures and prepare the engagement work program
-
Determine the level of resources and skills needed for the engagement
Section D: Engagement Performance (25%)
-
Identify sources of information to support engagement objectives and procedures
-
Evaluate the relevance, sufficiency, and reliability of evidence gathered to support engagement objectives
-
Evaluate technology options that internal auditors may use to develop and support engagement findings and conclusions
-
Apply appropriate analytical approaches and process mapping techniques
-
Apply analytical review techniques
-
Determine whether there is a difference between evaluation criteria and existing conditions and evaluate the significance of each finding
-
Prepare workpapers, including relevant information to support conclusions and engagement results
-
Summarize and develop engagement conclusions
-
Apply appropriate supervision throughout the engagement
-
Apply appropriate communication with stakeholders throughout the engagement
Section E: Engagement Results and Monitoring (20%)
-
Recognize attributes of effective engagement results communication
-
Demonstrate effective communication of engagement results
-
Determine whether to develop recommendations, request action plans from management, or collaborate with management to agree on actions
-
Describe the engagement closing communication and reporting process
-
Describe the chief audit executive’s responsibility for assessing residual risk for the engagement
-
Describe the process for communicating risk acceptance (when management has accepted a level of risk that may be unacceptable to the organization)
-
Describe the process for monitoring and confirming the implementation of management action plans
-
Describe the escalation process if management has not adequately implemented an action plan
Friday
More information on Certified Internal Auditor
The only globally accepted designation for internal auditors
Why study Certified Internal Auditor?
Auditors who hold the CIA designation perform internal audit engagements with diligence and confidence. Ultimately, becoming certified will:
- Prove your willingness to invest in your own development.
- Demonstrate your commitment to your profession.
- Improve your internal audit skills and knowledge.
- Build confidence in your knowledge of the profession.
Key features:
- The Professional Certification Board (PCB) has approved work experience and education exemptions for Association of Chartered Certified Accountants (ACCA) qualified members
- An education exemption for U.S. Certified Public Accountant (CPA) active license holders pursuing the CIA certification.
- IIA members receive discounts on CIA review materials and courses and have access to the latest exam preparation resources, networking opportunities, and current CIA news and information.




