Potential Effects of Deviations from Criteria
In CIA Part 2, potential effects of deviations from criteria refer to the 'effect' element of an engagement finding. Internal auditors build findings from attributes often summarized as the 5 Cs: criteria (what should be), condition (what is), cause (why the gap exists), effect (the risk or exposur… In CIA Part 2, potential effects of deviations from criteria refer to the 'effect' element of an engagement finding. Internal auditors build findings from attributes often summarized as the 5 Cs: criteria (what should be), condition (what is), cause (why the gap exists), effect (the risk or exposure resulting from the gap), and corrective action or recommendation. The effect answers the question 'So what?' and explains why management should care about the deviation. When auditors compare the condition to established criteria, such as policies, laws, contracts, budgets, industry standards, or best practices, any gap must be evaluated for its actual or potential consequences. Effects may be quantitative, such as financial losses, overpayments, fines, lost revenue, or excess costs. They may also be qualitative, such as reputational damage, regulatory sanctions, inefficient operations, poor decision-making from unreliable information, weakened control environments, employee safety concerns, or failure to achieve strategic objectives. Auditors should distinguish between actual effects, which have already occurred, and potential effects, which could occur if the deviation continues. Potential effects are assessed using likelihood and impact, consistent with the organization's risk management framework and risk appetite. This assessment helps determine the significance of the finding, which drives its priority rating, the urgency of management action, and whether it should be escalated to senior management or the board. Under the Global Internal Audit Standards, auditors must evaluate the significance of findings and support conclusions with relevant, reliable, and sufficient evidence. Stating effects clearly and persuasively, ideally quantified where possible, increases management's willingness to accept recommendations and allocate resources. Auditors must also avoid exaggerating effects or presenting speculation as fact. Effects should be logically linked to the condition and cause, realistic, and reasonable. A well-articulated effect connects operational deviations to business objectives, enabling stakeholders to understand the true risk exposure and make informed decisions about corrective actions.
Potential Effects of Deviations from Criteria (CIA Part 2: Information Gathering, Analysis and Evaluation)
Introduction
In the CIA Part 2 syllabus (Practice of Internal Auditing), the domain on engagement information covers how internal auditors identify, analyze, evaluate and document information. One key skill is assessing the potential effects of deviations from criteria. When an auditor finds that a condition (what is) differs from the criteria (what should be), the next question is: So what? What does this mean for the organization? That question is answered by the effect (also called impact, consequence or risk) element of an observation.
Why It Is Important
1. It turns observations into value. A deviation without a stated effect is just a technical note. Management acts when it understands the business consequence, such as financial loss, regulatory penalties, reputational damage, operational inefficiency or failure to reach objectives.
2. It drives significance and prioritization. Under the IIA Global Internal Audit Standards (2024), Standard 14.3 (Evaluation of Findings) requires internal auditors to evaluate the significance of each finding. They do this by considering the likelihood and impact of the risk, then prioritizing findings and recommendations. The effect is central to rating findings (for example high, medium or low).
3. It supports persuasive communication. Standard 15.1 (Final Engagement Communication) requires findings to be clear, accurate, concise, objective and complete. Stating the effect shows management why corrective action is worth the cost.
4. It links assurance to risk and objectives. Effects show how control failures threaten organizational objectives. This is the basis of risk-based auditing.
5. It shapes recommendations and escalation. Effects determine how urgent the remediation is. They also determine whether an issue must be escalated to senior management or the board, including where management may have accepted a risk beyond the organization's risk appetite (Standard 14.5 and the related guidance on risk acceptance).
What It Is
A finding (observation) is traditionally built from these elements, often remembered as the 5 Cs:
- Criteria: the standard, policy, regulation, contract, budget, KPI, best practice or management expectation (what should be).
- Condition: the factual evidence of what actually exists (what is).
- Cause: the root reason for the gap between condition and criteria (why it happened).
- Consequence / Effect: the actual or potential risk or exposure that results from the deviation (so what).
- Corrective action / Recommendation: what should be done. Some models also include management's action plan.
The effect is the risk or exposure the organization and others face because the condition differs from the criteria. Effects may be:
- Actual (realized): loss already incurred, such as $250,000 in duplicate payments already made.
- Potential (unrealized): exposure that could occur, such as the risk that unauthorized vendors could be paid.
- Quantitative: measurable in money, time, volume, error rates or percentages.
- Qualitative: reputational harm, loss of customer trust, legal exposure, safety risks, employee morale or strategic misalignment.
Common categories of effects
- Financial: losses, fraud, misstatement, wasted resources, lost revenue.
- Compliance: fines, penalties, sanctions, license revocation, litigation.
- Operational: inefficiency, delays, rework, service disruption, poor quality.
- Reputational: negative publicity, loss of stakeholder confidence.
- Strategic: failure to achieve objectives or goals.
- Information and reporting: unreliable data, poor decisions.
- Safeguarding assets: theft, misuse, data breaches.
- Health, safety and environment: injuries, environmental damage.
How It Works: The Process
Step 1: Confirm the criteria. Make sure the criteria are appropriate, authoritative and agreed with management where possible. If no criteria exist, the auditor works with management to set suitable criteria (Standard 13.4, Evaluation Criteria).
Step 2: Establish the condition with sufficient evidence. The deviation must be supported by relevant, reliable and sufficient information.
Step 3: Identify the cause. Root cause analysis (5 Whys, fishbone diagrams) separates symptoms from underlying problems. The cause helps predict whether the effect is isolated or systemic.
Step 4: Assess the potential effect. Ask:
- Which objective is threatened?
- What is the worst realistic outcome, and how likely is it?
- Is the deviation isolated or pervasive? Has it recurred?
- Can the effect be quantified? Can sample errors be projected to the population?
- Who is affected: the organization, customers, regulators, employees or the public?
- Are there compensating controls that reduce the exposure?
- Is there a fraud indicator?
Step 5: Evaluate significance. Combine impact (magnitude) and likelihood. Also consider:
- Materiality (quantitative and qualitative).
- Pervasiveness.
- Velocity, meaning how fast the effect could occur.
- Persistence or duration.
- Risk appetite and tolerance.
Small amounts can still be significant. Examples include fraud by senior management, regulatory breaches, or a control weakness that could allow large losses.
Step 6: Communicate and recommend. State the effect clearly and objectively, without exaggeration. Link the recommendation to the cause, not just the symptom. Escalate according to significance.
Worked Example
- Criteria: Company policy requires two approvals for vendor master file changes.
- Condition: In a sample of 40 vendor changes, 12 (30%) had only one approval.
- Cause: The ERP system does not enforce dual approval, and staff were unaware of the policy after a reorganization.
- Effect: Unauthorized or fictitious vendors could be created, or bank details altered, exposing the company to fraudulent payments. Annual vendor payments total $80 million, so the exposure is significant. One altered bank account was also found, with a $45,000 payment already at risk (an actual effect).
- Recommendation: Configure a system-enforced dual approval workflow, retrain staff, and review all vendor changes made in the past 12 months.
Common Pitfalls
- Confusing effect with cause. For example, 'staff were not trained' is a cause, not an effect.
- Confusing effect with condition. Restating the deviation is not an effect.
- Overstating effects without evidence, or understating qualitative effects.
- Ignoring compensating controls.
- Failing to project sample results to assess pervasiveness.
Exam Tips: Answering Questions on Potential Effects of Deviations from Criteria
1. Learn the 5 Cs cold. Many questions give a statement and ask which attribute it represents. 'What should be' is criteria, 'what is' is condition, 'why' is cause, and 'so what / risk / exposure / impact' is effect.
2. Look for keywords. Effect statements use words like could result in, exposes the organization to, may lead to, resulted in losses of, risk of. Cause statements use words like because, due to, lack of training, no system control.
3. Choose the most significant, business-relevant effect. When several answers seem plausible, pick the one tied to organizational objectives and the greatest risk, not a minor procedural point.
4. Remember that effect drives significance and priority. If asked what determines how a finding is rated or whether it is escalated, the answer usually involves the effect (impact and likelihood), not the cause.
5. Know that effects can be potential, not just actual. An auditor does not need a realized loss to report a finding. Exposure is enough.
6. Remember qualitative effects matter. Questions may test whether a small-dollar deviation is significant because of fraud, regulatory or reputational implications. The answer is often yes.
7. Consider compensating controls and pervasiveness. If a scenario mentions a compensating control, the potential effect may be reduced. If errors are widespread, the effect is larger.
8. Match recommendations to the cause, and justify them with the effect. A recommendation fixes the cause. The effect explains why the fix is worth doing.
9. Watch for the 'most important reason' trap. A question may ask why auditors include the effect in a finding. The best answer is usually that it persuades management to take corrective action by showing the risk or consequence.
10. Use elimination. Remove options that restate the condition, describe the criteria, or give a cause. What remains is usually the effect.
11. Think about the audience. Board-level communications focus on the most significant effects and their link to strategy and risk appetite.
12. Stay objective. Correct answers avoid emotional or exaggerated language. Effects must be supported by evidence and reasonable judgment.
Quick Practice Question
An internal auditor found that 15% of inventory counts were not reconciled to the general ledger as required by policy. Which statement best describes the effect?
A. Policy requires monthly reconciliation of counts to the ledger.
B. Warehouse staff lacked time due to staffing shortages.
C. Inventory may be misstated in the financial statements, and theft may go undetected.
D. 15% of counts were not reconciled.
Answer: C. A is criteria, B is cause, and D is condition.
Summary
The potential effect of a deviation from criteria answers the 'so what' of an audit finding. It quantifies or describes the actual or potential exposure and connects control gaps to organizational objectives. It also determines the significance, priority and escalation of findings, and motivates management to act. For the exam, be able to tell effect apart from criteria, condition and cause. Evaluate impact and likelihood, recognize qualitative significance, and always pick the most relevant, evidence-based business consequence.
Unlock Premium Access
Certified Internal Auditor Part 2
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2980 Superior-grade Certified Internal Auditor Part 2 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 2: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!