Accounting · CIA

CIA Part 3: Business Knowledge for Internal Auditing

Business acumen, IT, and financial management concepts tested on CIA Exam Part 3.

41 cards · basic cards · AI-written, checked twice. Edit anything.

Study this set free Get FlashKeepers for iPhone
What is the primary purpose of an organization's strategic plan?
To establish long-term direction, objectives, and resource allocation aligned with organizational mission.
Define working capital in a business context.
Current assets minus current liabilities; funds available for day-to-day operations.
What does IT governance establish?
Framework for IT decision-making, accountability, and alignment with business objectives.
What is a control environment in internal auditing?
The tone at the top; culture and values established by management regarding internal control importance.
Define operational risk.
Risk of loss from inadequate or failed processes, systems, people, or external events.
What is the purpose of segregation of duties in internal controls?
To separate authorization, execution, custody, and recording to prevent error or fraud.
What does Return on Investment (ROI) measure?
Profit generated on capital invested, expressed as a percentage.
Define enterprise risk management (ERM).
Integrated approach to identifying, assessing, and responding to risks across the entire organization.
What is a business process?
Series of activities or tasks performed to achieve a specific business outcome or objective.
What is the role of the audit committee?
Oversee internal audit, external audit, financial reporting, and risk management on behalf of the board.
Define information security.
Protection of information assets from unauthorized access, modification, disclosure, or destruction.
What are the three lines of defense in internal audit?
First: operational management controls. Second: risk management and compliance functions. Third: internal and external audit.
What is accounts receivable?
Amount of money customers owe an organization for goods or services delivered.
Define cybersecurity risk.
Threat of unauthorized digital access, data breach, or system compromise affecting business continuity.
What is the purpose of an internal audit function?
Provide independent, objective assurance and advisory services to improve organizational effectiveness and manage risks.

26 more cards in the app