nerdexam
IIA

IIA-CIA-PART1 · Question #166

According to IIA guidance, a new internal auditor is expected to possess which of the following competencies?

The correct answer is D. Knowledge of forensic accounting. According to the IIA's Global Internal Audit Competency Framework, knowledge of forensic accounting is identified as an expected baseline competency even for new internal auditors, because fraud awareness and detection are core to the internal audit function from day one - not…

Question

According to IIA guidance, a new internal auditor is expected to possess which of the following competencies?

Options

  • ATechnical industry-specific expertise.
  • BExpertise in cybersecurity, an area of increasing risk.
  • CKnowledge of IT risks and controls.
  • DKnowledge of forensic accounting.

How the community answered

(39 responses)
  • A
    3% (1)
  • B
    5% (2)
  • C
    13% (5)
  • D
    79% (31)

Explanation

According to the IIA's Global Internal Audit Competency Framework, knowledge of forensic accounting is identified as an expected baseline competency even for new internal auditors, because fraud awareness and detection are core to the internal audit function from day one - not just an advanced specialization.

Why the distractors are wrong:

  • A (Technical industry-specific expertise) is an experience-driven competency that develops over time; the IIA does not expect new auditors to arrive with deep industry technical knowledge.
  • B (Cybersecurity expertise) sets the bar too high - awareness of cybersecurity risks is expected, but expertise is a specialized, advanced proficiency level, not an entry-level requirement.
  • C (Knowledge of IT risks and controls) may seem plausible given the IIA's emphasis on technology, but IT risk knowledge at a meaningful depth is categorized as an intermediate or specialist competency, not a new-auditor baseline.

Memory tip: Think of it this way - fraud is the oldest audit concern in the book. The IIA bakes forensic accounting knowledge into the foundation of the auditor competency pyramid. Cybersecurity and industry expertise sit higher up the pyramid because they require experience to develop.

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART1 Practice