Free IIA CIA Part 1 (Internal Audit Fundamentals) Governance, Risk Management, and Control Practice Questions
Governance, Risk Management, and Control on CIA Part 1 covers governance structures and processes, risk appetite and tolerance, inherent versus residual risk, control classifications (preventive, detective, corrective), and the control environment. 30% of Part 1, and the domain where COSO and Three Lines vocabulary earns its keep.
90 questions33 easy44 medium13 hard2026 syllabus
Sample Questions
Question 1
Easy
According to IIA guidance, which statement best describes residual risk?
🎉
Correct Answer: D
Solution
D is correct. Residual risk is the exposure that persists after management has designed and operated its risk responses, including internal controls. Internal auditors evaluate residual risk when concluding on the adequacy of risk management and control processes, because it is the residual level, not the gross level, that must fall within the board-approved risk appetite. Standard 9.1 requires the internal audit function to understand the organization's governance, risk management, and control processes, which includes distinguishing inherent from residual exposure.
Question 2
Medium
Senior management asks the chief audit executive to develop and operate the organization's new ethics hotline. What is the most appropriate response?
🎉
Correct Answer: B
Solution
B is correct. The internal audit function may provide advisory input on the design of the organization's ethical framework, including a whistleblower hotline, but management retains responsibility for approving, owning, and operating it. Keeping approval and implementation with management preserves objectivity so the function can later provide assurance over the hotline's effectiveness. Standard 2.2 requires safeguards over objectivity, and the guidance on advisory services permits input without assuming management responsibility.
Question 3
Hard
A quality unit reporting to the operations director designs and monitors the controls it evaluates. The chief audit executive plans to rely on its testing. Which conclusion is best supported?
🎉
Correct Answer: D
Solution
D is correct. Under the Three Lines Model, a unit that designs controls and reports through the operations director is performing management activity and is not organizationally independent of the process it evaluates, so its work cannot be treated as equivalent to internal audit assurance. IIA guidance on coordination and reliance requires the chief audit executive to evaluate the competence, objectivity, and methodology of other assurance providers before using their work, and to determine what additional internal audit procedures are needed. Self-monitoring of self-designed controls is a recognized objectivity concern; reliance may remain possible, but only after that assessment and with the scope of reliance adjusted accordingly.
FreeFellow was built by Jeffrey Ting, a credentialed actuary and CFA charterholder who passed thirteen of the hardest exams in finance on the first attempt, and paid four-figure prep fees for every one. The learning itself was always free. The price was a moat.
So he started writing his own questions, then lessons, then mock exams, until it grew into a full prep platform covering 40 finance credentials with more than 44,000 original practice questions. The name says exactly what it is: the question bank is free, and Fellow is what you become once you pass.
01
Cost shouldn't decide who gets in.
The exam is a fair gate. A four-figure prep course is not. FreeFellow takes the second gate down, so the exam is the only one left.
02
Free should mean free.
No trial clock, no email gate, no credit card. The question bank, worked solutions, lessons, and readiness score stay free, and they are enough to pass.
03
Built by someone who sat where you sit.
He paid for the big-name courses, found nothing he respected, and built the prep he wished had existed. Not a marketing team that has never sat an exam.