An auditor asks the accounts payable manager how invoices get approved and receives a clean four-step answer. A walk-through of three live invoices finds a fifth step nobody mentioned: a clerk who edits vendor bank details after approval. The map you draw from interviews is the process people believe exists. The map you verify is the one that runs.
A process workflow segment is a bounded slice of a larger process with a defined start event, end event, and owner. Segmenting first keeps the map testable. "Procure to pay" is too large to map usefully; "purchase requisition through purchase order issuance" has a trigger, a terminal output, and one accountable owner.
Divide process workflow segments at handoffs, because handoffs are where control breaks. Every point where the work changes hands, changes systems, or changes department is a candidate boundary and a candidate risk.
Process mapping is the graphical representation of activities, decisions, inputs, outputs, and handoffs in sequence. Standard elements: activity boxes, decision diamonds, directional arrows, and swim lanes that assign each activity to a...
Common mistakes
- Concluding on operating effectiveness from a walk-through. Tracing three invoices confirms design and finds undocumented steps. It does not support a conclusion that the control operated all year across 84,215 payments.
- Treating an anomaly flag as a finding. The 310 flags were candidates; only 22 survived corroboration.
- Normalizing before verifying completeness. Cleaning an extract that is 215 records short yields a precise answer about the wrong population.
Bottom line
- Process workflow segments need a defined start event, end event, and single owner; segment at handoffs.
- Process maps use activity boxes, decision diamonds, arrows, and swim lanes to expose control points, redundancies, and segregation conflicts; they document design, not evidence.
- Walk-throughs trace a few transactions end to end to confirm the map, find undocumented steps, and verify evidence exists; they never establish operating effectiveness.
- RACI rule: exactly one Accountable per activity, multiple Responsible allowed; no A is a gap, two A's is a conflict.
Exam shortcut
Read the verb in the stem, then pick the analysis type. "Why" or "root cause" is diagnostic. "Likely," "forecast," or "risk score" is predictive. "Recommend," "optimize," or "set the threshold" is prescriptive. Anything asking only what the data shows is descriptive, and the trap answer will be a fancier label. Two stem signals to memorize.
The full lesson (about 2,107 words, 14 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 4
Browse all free CIA Part 2 lessons or jump into free CIA Part 2 practice questions.