Skip to Content

2019 CIA Exam Syllabus Part 3 – Business Knowledge for Internal Auditing

100 questions | 2.0 Hours (120 minutes)

The CIA exam Part 3 includes four domains focused on business acumen, information security, information technology, and financial management. Part 3 is designed to test candidates’ knowledge, skills, and abilities particularly as they relate to these core business concepts.​

Additional noteworthy elements related to the revised CIA Part Three exam syllabus:

  • The number of topics covered on the Part Three exam has been greatly refocused to the core areas that are most critical for internal auditors.
  • The exam syllabus features a new subdomain on data analytics.
  • The information security portion of the exam has been expanded to include additional topics such as cybersecurity risks and emerging technology practices.
  • The largest domain is “Business Acumen,” which makes up 35% of the exam.
  • A portion of the exam requires candidates to demonstrate a basic comprehension of concepts; another portion requires candidates to demonstrate proficiency in their knowledge, skills, and abilities.

CIA Part 3 Reference List

Most Relevant

  • The IIA’s International Professional Practices Framework
  • Applying the International Professional Practices Framework, by Urton Anderson and Andrew J. Dahle
  • Internal Auditing Assurance and Advisory Services, by Urton Anderson, Michael Head, and Sridhar Ramamoorti
  • Sawyer's Guide for Internal Auditors, by Larry Sawyer
  • Understanding Management, by Richard Daft and Dorothy Marcic
  • Data Analytics: Elevating Internal Audit's Value, by Warren Stippich Jr. and Bradley Preber
  • Data Analysis and Sampling Simplified: A Practical Guide for Internal Auditors, by Donald Dickie
  • Rethinking Data Governance and Data Management, by ISACA
  • Principles of Information Security, by Michael Whitman and Herbert Mattord
  • IT Auditing: Using Controls to Protect Information Assets, by Chris Davis, Mike Schiller, and Kevin Wheeler
  • Internal Audit of the Future: The Impact of Technology and Innovation, by A. Michael Smith
  • Implementing the NIST Cybersecurity Framework, by ISACA
  • Enterprise Risk Management Framework, by COSO
  • Internal Control – Integrated Framework, by COSO
  • “Managing Cyber Risk in a Digital Age,” by COSO
  • Privacy and Data Protection: Internal Audit’s Role in Establishing a Resilient Framework, by IIA Foundation and Crowe
  • Accounting Principles, by Jerry Weygandt, Paul Kimmel, and Donald Kieso

Additional Resources

  • Auditor Essentials: 100 Concepts, Tips, Tools, and Techniques for Success, by Hernan Murdock
  • Ready and Relevant: Prepare to Audit What Matters Most, by Timothy Berichon
  • Project Management Body of Knowledge (PMBOK) Guide, by Project Management Institute
  • Contract and Commercial Management: The Operational Guide, by IACCM
  • Performance Auditing: Measuring Inputs, Outputs, and Outcomes, by Stephen Morgan, Ronell Raaum, and Colleen Waring
  • "Analytics: Good Practices for (smaller) IAFs," by IIA-Netherlands
  • Data Analytics for Beginners: Practical Guide to Master Data Analytics, by TechWorld
  • Auditing Social Media: A Governance and Risk Guide, by J. Mike Jacka and Peter Scott
  • Auditing the Procurement Function by David O'Regan
  • Information Technology Control and Audit, by Sandra Senft, Frederick Gallegos, and Aleksandra Davis
  • Transfer Pricing Guidelines for Multinational Enterprises and Tax Administrations, by OECD
  • Current resources on internal auditing and relevant topics

Access CCMS

Click here