CIA Part 1 · Governance, Risk Management, and Control · Free Lesson

Describe risk management within organizational processes and functions

Free IIA CIA Part 1 (Internal Audit Fundamentals) lesson in Governance, Risk Management, and Control. 14 min read, ~2,085 words.

A manufacturer keeps a risk register with 180 entries, all rated "medium," last updated 14 months ago. The process exists. The exam question is whether it works.

Internal audit evaluates risk management. It does not own it. Management owns risk and operates the process; the board oversees it; internal audit provides assurance on whether the process is designed well and running as designed. Getting that split right answers a large share of exam items on this objective.

Two distinct evaluations sit inside this work:

KEY: Design and effectiveness fail independently. A well-designed framework nobody executes fails on effectiveness. A diligently executed process that never considers strategic risk fails on design. Read the stem for which one is broken.

Design evaluation asks whether the architecture can work. You test the architecture against a small set of questions.

Read the full lesson, free →
Worked examples and practice. Free with a free account, no card.

Common mistakes

Bottom line

Exam shortcut

Sort the stem into design or effectiveness before reading the answers. Words like "missing category," "no appetite statement," "no owner assigned," or "no reporting route" mean design. Words like "not updated," "ratings unsupported," "plan never executed," or "loss occurred but was never on the register" mean effectiveness.

The full lesson (about 2,085 words, 14 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.

Learning objectives

Browse all free CIA Part 1 lessons or jump into free CIA Part 1 practice questions.