CIA Part 1 · Governance, Risk Management, and Control · Free Lesson

Interpret the fundamental types of risk

Free IIA CIA Part 1 (Internal Audit Fundamentals) lesson in Governance, Risk Management, and Control. 15 min read, ~2,287 words.

A distribution company's board asks internal audit one question: "How exposed are we?" The honest answer depends on which risk you mean and whether you are counting the controls that already exist.

Risk is the effect of uncertainty on the achievement of objectives. Two features of that definition drive every exam question here. First, risk attaches to an objective, so a "risk" with no objective behind it is just an event. Second, the effect runs both directions: risk includes upside variation, though the CIA exam concentrates on downside exposure.

Strategic, operational, financial, compliance, reputational, and environmental or sustainability risk are classification labels. They exist so the board can assign ownership, so management can aggregate exposure by category, and so internal audit can build a risk-based plan that covers all categories rather than the two it finds easiest to test.

Read the full lesson, free →
Worked examples and practice. Free with a free account, no card.

Common mistakes

Bottom line

Exam shortcut

Work the stem in two passes. First pass: underline the objective that is threatened and ask what failed. That names the type. Second pass: check whether the stem describes controls. If the phrase is "assuming no controls," "before considering," or "absent management action," the number wanted is inherent. If the phrase is "after controls," "remaining," "net," or "currently faces," the number wanted is residual.

The full lesson (about 2,287 words, 15 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.

Learning objectives

Browse all free CIA Part 1 lessons or jump into free CIA Part 1 practice questions.