CIA Part 2 · Engagement Planning · Free Lesson

Plan the engagement to assess key risks and controls

Free IIA CIA Part 2 (Internal Audit Engagement) lesson in Engagement Planning. 17 min read, ~2,568 words.

A warehouse engagement that counts inventory but never asks whether the enterprise resource planning system's access controls let a clerk create a vendor is not a risk-based engagement. It is a stock count with a cover page.

Planning identifies what could stop the activity from achieving its objectives, then identifies the controls management relies on to prevent that. Everything below is a source of candidate risks. Your job in planning is to gather them, rank them, and map each significant one to a control you will test.

KEY: Risks are identified against the objectives of the activity under review, never against the audit's own convenience. No objective, no risk. That ordering is the most tested idea in this scope.

A topical requirement is a mandatory element issued by The IIA that prescribes minimum coverage when an assurance engagement addresses a named subject such as cybersecurity or third-party management. Applying topical requirements when planning means running three checks.

Read the full lesson, free →
Worked examples and practice. Free with a free account, no card.

Common mistakes

Bottom line

Exam shortcut

Read the stem for the objective before you read the risk. If no objective appears, the correct answer is usually the option that establishes one. Signal-to-answer mapping worth memorizing. "Backups completed successfully" means the gap is untested recovery, not backup failure. "Collected additional customer fields for possible future use" means data minimization, a privacy principle, not a security control.

The full lesson (about 2,568 words, 17 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.

Learning objectives

Browse all free CIA Part 2 lessons or jump into free CIA Part 2 practice questions.