A chief audit executive presents a 14-engagement plan to the audit committee. A director asks why three of them are labeled "assurance" and one is labeled "advisory," and whether the vendor review is really an audit at all. The exam tests exactly that vocabulary.
An assurance service is an objective examination of evidence that produces an independent assessment of governance, risk management, or control processes. Three parties are always present: the process owner, the internal auditor, and the user of the conclusion (usually the board). Internal audit picks the objectives and scope in consultation with the board, not with the client.
Advisory work has two parties and the client sets the scope. Everything below is assurance, which means internal audit determines what to test and issues a conclusion whether or not management likes it.
KEY: Assurance is defined by the three-party structure and internal audit's control over objectives, not by the subject matter. The same vendor contract can be reviewed as an assurance engagement or as advisory work; who sets the scope decides the label.
Common mistakes
- Calling any dollar-recovery engagement a financial audit. Recovering $4,860 from a vendor is contract compliance; the criteria were rate schedules, not accounting policy.
- Treating internal audit's financial work as the external audit. Internal audit evaluates reliability of records and the controls behind them for management and the board. It never issues the external opinion on the financial statements.
- Assuming a security report covers privacy. A vendor report scoped to security says nothing about consent, retention limits, or use limitation.
Bottom line
- Assurance structure: three parties, and internal audit sets the objectives and scope; advisory has two parties with the client setting scope.
- Risk and control assessments: test design effectiveness first, then operating effectiveness; a well-run badly designed control still fails.
- Third-party work: contract compliance on rates, service levels, and clauses, plus due diligence, fourth-party exposure, and reliance on vendor control reports; access depends on a right-to-audit clause.
- IT security: general IT controls (access, change, backup, operations) and application controls (edits, calculations, interfaces).
Exam shortcut
Classify by criteria, not by subject. Ask one question of every stem: what did the auditor measure the activity against? Statute or regulator equals regulatory compliance. Contract terms equals third-party. Access rights, patching, or change tickets equals IT security. Consent or retention equals privacy. Management efficiency targets equals operational. Program goals or funding terms equals performance. Product specification equals quality. Ledger and reconciliation equals financial.
The full lesson (about 2,445 words, 16 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 5
Browse all free CIA Part 1 lessons or jump into free CIA Part 1 practice questions.