“"Excellent question quality and easy to follow. It helped me improve my confidence."”
David
Internal Auditor
The FSAC final assessment isn't a standalone knowledge test you can walk into cold — it's the capstone of an 11-module on-demand learning path. You only sit for it after working through every module and clearing each module's embedded quiz at 80% or better. The exam itself is 50 multiple-choice questions, delivered through the IIA's own learning platform rather than a Pearson VUE or PSI testing center. The IIA estimates 75–90 minutes to finish, but the session doesn't force you out early — it stays open for up to 150 minutes before auto-closing.
Two things surprise candidates who've taken other IIA exams like the CIA. First, this exam is open-resource: you're allowed to reference your course materials while answering. Second, that openness doesn't make it easy — because you can look things up, the questions lean toward interpretation and application rather than terms you could just recall from memory. Expect scoring on completion, with an immediate pass/fail result and a printable certificate if you clear it. The American Institute of Certified Planners (AICP) also offers professional certification for urban and regional planners.
You also get room to fail forward: the platform allows up to three attempts at the final exam before a retake fee kicks in, and module quizzes can be retaken as many times as needed to hit the 80% threshold. That safety net changes how you should prepare — less "cram until perfect," more "build real understanding, use the retakes as feedback." Looking for additional exam preparation? Try our free ACSM CEP practice test
Unlike a weighted-domain exam, the FSAC's content is organized as 11 self-paced modules that can be completed in any order. Each feeds into the final 50-question exam without a published per-module question count, so treat this as a coverage map rather than a scoring formula.
Module | Focus Area |
|---|---|
Foundations of Internal Auditing in Financial Services Firms | Core audit concepts applied to banking, insurance, and securities |
Liquidity Risk Management | Funding risk, liquidity coverage, and stress indicators |
Auditing Capital Adequacy & Stress Testing for Banks | Capital planning and regulatory stress-test review |
Auditing Credit Risk | Loan portfolio quality, underwriting controls, credit concentration |
Auditing Model Risk Management | Model validation, governance, and use-testing |
The Role of Internal Audit in Insurance Organizations | Insurance-specific audit scope and reserving oversight |
Auditing Market Risk | Trading book exposure, VaR-based controls |
Auditing Culture and Conduct | Behavioral risk indicators and conduct-risk auditing |
Assessing Cybersecurity Risk: Roles of the Three Lines Model | Cyber governance mapped to the Three Lines Model |
Assessing Fraud Risks | Fraud triangle application in financial services settings |
Auditing Third-Party Risk | Vendor and outsourcing oversight |
Because the final exam draws from all 11 modules without publishing individual weightings, no single module is "worth skimming." A weak module still contributes wrong answers on the final 50 questions.
Model risk management trips up more candidates than any other module, mainly because most internal auditors haven't personally validated a model — they audit around one. Questions in this area test whether you understand governance and use-testing concepts, not just definitions, so passive reading of the module rarely sticks.
The Three Lines Model applied specifically to cybersecurity is the second underestimated area. Auditors who know the Three Lines Model in the abstract often stumble when asked to place a specific cyber control — say, a SOC monitoring function — into the correct line. The module isn't testing whether you know the model; it's testing whether you can apply it to an unfamiliar scenario.
Culture and conduct auditing is the third blind spot, and it's a newer addition to internal audit's toolkit generally. Candidates coming from a traditional financial-controls background sometimes treat this module as soft or subjective, then find the exam expects a structured, evidence-based approach to what looks like a judgment call.
Because the real FSAC exam is open-resource, practicing under closed-book conditions first — no notes, no module material in front of you — builds the recall speed you'll need even when you're technically allowed to look things up. If you have to search your notes for every question, you'll burn through the 150-minute window fast.
Once you've built that baseline, shift to scenario-heavy practice sets. The exam favors situational questions — "an auditor discovers X during a review of Y" — over direct definition recall, so practicing with straight terminology quizzes alone will leave a gap. Work through explanations for every question you get wrong, not just the ones you got right by guessing; the FSAC's application-based style means understanding why an answer is correct matters more than memorizing that it is.
Treating the 11 modules as sequential reading rather than material to be tested on trips up a lot of candidates — since modules can be completed in any order, some people front-load the easier ones and rush the harder ones (commonly model risk and cybersecurity) right before the deadline.
Skipping the open-resource advantage is another one. Some candidates study as if the exam is closed-book, over-memorizing details they could have simply referenced, and running out of time as a result because they never practiced navigating their own notes quickly.
Underpracticing insurance-specific content is a third pattern, especially among candidates whose day-to-day work is banking-heavy. The insurance module covers material — reserving oversight, insurance-specific audit scope — that has no banking equivalent, so there's no "transfer knowledge" to lean on practice test.If you're preparing for another certification, try our Certified Professional Contract Manager (CPCM)
New to financial services auditing: Budget four to six weeks. Work through modules in the order listed above rather than jumping around — the foundations module sets vocabulary you'll need for the risk-specific modules that follow. Take the embedded quizzes seriously; a sub-80% score on any of them is an early warning sign for the final exam.
Experienced internal auditor, new to financial services: Two to three weeks is usually enough. You already understand audit methodology, so your gap is domain-specific: credit risk, market risk, liquidity, and model risk terminology. Spend disproportionate time on cybersecurity's Three Lines Model application and culture/conduct auditing, since those don't map cleanly from general audit experience.
Retaking the final exam: One to two weeks, focused entirely on your weak modules rather than a full review. Since you get three attempts before a retake fee applies, use your first attempt's result (even if unsuccessful) as diagnostic information about which modules need another pass.
Last updated on Oct, 7 2026