What is CIA and how does it differ from an external audit qualification?
CIA is the Certified Internal Auditor designation from the Institute of Internal Auditors, and it is the globally recognised credential for internal auditing specifically β a different profession from external audit. External auditors are engaged by shareholders to give an opinion on financial statements; internal auditors are part of the organisation, report functionally to the audit committee, and provide assurance and advice on the whole control environment including operations, compliance, technology and governance, not only the financial statements. The designation is earned through three examination parts: essentials of internal auditing covering the mandatory guidance, independence, risk and the audit engagement; the practice of internal auditing covering managing the internal audit function, planning and performing engagements and communicating results; and business knowledge for internal auditing covering governance, organisational structure, leadership, information technology and financial management. The experience requirement scales with academic qualification, so candidates with a master's degree need less than those with a bachelor's, and a route exists for candidates without a degree who have substantially more experience. The credential is maintained through annual continuing professional education, with a lower requirement for those not practising.
- CIA is the globally recognised internal audit designation, and internal audit is a different profession from external audit.
- Three examination parts cover the standards, the practice of auditing and broader business knowledge.
- The experience requirement scales with academic qualification, with a longer route for candidates without a degree.
- Independence and objectivity are central examinable content, not professional courtesy.
CIA at a glance
| Cost | Application, examination and certification maintenance fees are set by the institute and priced differently for members β see its current fee schedule |
| Duration | Three examination parts taken separately, alongside the required period of internal audit experience |
| Issued by | Institute of Internal Auditors (IIA) |
| Format | Three computer-based examination parts delivered at commercial test centres |
| Expiry | Maintained through annual continuing professional education, with a reduced requirement for non-practising holders |
| Who needs it | Internal auditors, audit managers and chief audit executives across corporate, financial services, government and not-for-profit organisations |
| Experience scaling | The required experience falls as academic qualification rises, with a longer-experience route for candidates without a degree |
| Different profession | Internal audit is distinct from external audit in scope, reporting line and purpose |
Sources: Institute of Internal Auditors β CIA certification Β· IIA β certification maintenance and CPE. Reviewed August 2026 by the GlobalCybers team.
The Three Parts and the Standards Behind Them
Independence is the discipline's foundation
Internal auditors sit inside the organisation they audit, which creates a structural tension the profession's standards exist to manage: functional reporting to the audit committee, administrative reporting elsewhere, and rules on objectivity, scope interference and auditing work you previously performed. The examination treats independence and objectivity as central examinable content rather than as professional courtesy, because it is what separates internal audit from a management consulting function.
What each part covers
Where internal audit certification matters
Internal auditors are counted among accountants and auditors in federal wage statistics, alongside external auditors and accountants generally. The designation is the profession's global standard and matters most for progression: audit manager and chief audit executive roles commonly expect it, and multinational organisations value that it is recognised identically across jurisdictions.
GlobalCybers reimburses certification fees after a successful permanent placement through our network.
What CIA Covers, Independence Through Business Knowledge
Independence
Functional reporting to the audit committee, managing scope interference, and the objectivity rules governing auditing areas you previously worked in.
Risk-Based Planning
Building an audit plan from the organisation's actual risk profile rather than a rotation cycle, and defending it to an audit committee.
Engagement Execution
Objectives and scope, evidence sufficiency, sampling, working paper standards and supervision β the mechanics that make a finding defensible.
Reporting
Writing findings that are accurate, balanced and actionable, agreeing management responses, and escalating when a response is inadequate.
Technology
Application and general controls, cybersecurity risk, data analytics in auditing, and auditing systems the audit function did not build.
Governance
Board and committee structures, ethics programmes, the three lines model and where assurance genuinely comes from in an organisation.
How do you become a Certified Internal Auditor, step by step?
Check how your degree changes the experience requirement
The required period of internal audit experience falls as academic qualification rises, and there is a longer-experience route for candidates without a degree. Establish which applies to you before planning, because it materially changes the timeline.
Take the parts in order and start with essentials
The first part establishes the standards framework that the other two assume. Candidates who start elsewhere find themselves answering practice questions without the mandatory guidance underneath them. It is also the part where experienced auditors discover that local practice diverges from the professional standards.
Prepare business knowledge deliberately
The third part covers technology, financial management, organisational behaviour and leadership, which is a wide sweep outside the daily work of many internal auditors. It is the part most often underestimated, particularly by candidates from a purely financial audit background.
Maintain through annual continuing education
Continuing professional education is reported annually, with a reduced requirement for holders not practising. Institute chapter events, conferences and structured learning typically cover it, and the requirement should be recorded as it is completed rather than reconstructed.
Not Required by Law β Expected by Audit Committees
No general law requires internal auditors to be certified, though regulated sectors such as banking impose expectations about internal audit capability and independence. The practical driver is governance: audit committees and external quality assessments look at whether the function is professionally qualified and conforms to recognised standards, and the designation is the standard evidence. Chief audit executive appointments in large organisations routinely assume it.
CIA, Frequently Asked Questions
Internal audit certified? Functions are recruiting.
Corporate, financial services and public sector audit functions are hiring. Set your sector and let audit committees' recruiters find you.
Join the Network βMore about CIA
Your career research journey
Do your homework, then let the network do the rest.Get the job, then keep rising
FreeSet your intent, matching jobs come to you. No applying.
A roadmap to your next licence tier and higher pay band.
Once placed, we cover all certification, licence & career-guide fees.
Hiring trade workers?
Get a verified shortlist of 3β5 qualified candidates in 48 hours
GlobalCybers verifies active state licenses, trade certifications, Intent and right-to-work status before any candidate reaches your portal. Flat $2,999/mo RPO (Recruitment Process Outsourcing), up to 3 concurrent roles, or a free trial (pay on hire). 90-day written guarantee.