Topic 1 Question #2
An organization is considering the acquisition of a target organization. Senior management asks the internal audit function to advise on the target organization’s information security practices. What type of internal audit service is this?
- A.
System development.
- B.
Process reengineering.
- C.
Due diligence.
- D.
Benchmarking.
Answer: C
This question aligns with the 2025 CIA Part 1 exam domains covering governance, risk management, control, and internal audit service types, specifically advisory services defined in the International Professional Practices Framework (IPPF). The scenario describes internal audit being tasked to assess a target organization’s information security practices to inform senior management’s acquisition decision. The core objective of this assessment is to identify unreported cybersecurity risks, control gaps, or associated liabilities that could impact the financial or operational value of the proposed acquisition, which is a classic use case for pre-transaction due diligence services. This activity is a valid, value-added advisory service consistent with internal audit’s mandate to provide objective, risk-focused insights to support strategic organizational decision-making, a core competency tested in Part 1. Option Analysis:
A. Incorrect. System development refers to the end-to-end process of designing, testing, and implementing new information systems or updates to existing systems, where internal audit may provide assurance on control integration during the SDLC. The scenario does not involve any system creation or modification activity, so this option is irrelevant to the request described.
B. Incorrect. Process reengineering is the radical redesign of existing organizational processes to drive measurable improvements in efficiency, cost, or performance, where internal audit may advise on control alignment during the redesign process. The request in the scenario is to evaluate existing practices at a target entity, not to redesign any internal processes, so this option is not applicable.
C. Correct. Due diligence is defined in IPPF guidance as a specialized pre-transaction advisory service that reviews and assesses all material risk and control domains of a target entity prior to an acquisition, merger, or divestiture to support informed decision-making. The request to evaluate the target’s information security practices as part of acquisition planning fits exactly this service category, making this the correct answer.
D. Incorrect. Benchmarking is the practice of comparing an organization’s practices, processes, or performance metrics against peer entities or industry standards to identify improvement opportunities. While benchmarking may be used as a tool within a due diligence engagement, the overall service type described is focused on pre-transaction risk assessment, not comparative analysis against external benchmarks, so this option is incorrect. Key Concepts:
1. Internal Audit Advisory Services: A core CIA Part 1 concept defined by the IPPF as non-assurance consulting services that add value by improving an organization’s governance, risk management, and control processes, including specialized support for strategic transaction activities like pre-acquisition due diligence.
2. Due Diligence Engagements: Specialized pre-transaction reviews that evaluate material risks, control gaps, compliance status, and operational practices of a target entity to identify potential liabilities or value drivers that impact the feasibility or terms of a proposed corporate transaction.
3. Internal Audit Value Proposition: A foundational Part 1 principle that internal audit delivers value to the organization by providing objective, reliable insights to management and the board on risk and control posture, including support for high-stakes strategic decisions such as mergers and acquisitions. References:
The IIA International Professional Practices Framework (IPPF), The IIA Practice Guide: Internal Audit and Due Diligence