The IIA Topical Requirements: What Internal Audit Needs to Know So Far

Executive Summary

The IIA Topical Requirements establish a mandatory minimum baseline for assurance work in significant risk areas.

They complement the Global Internal Audit Standards by translating them into clear, topic-specific expectations.

Four Topical Requirements have been issued so far:

  • Cybersecurity — 17 requirements; effective 5 February 2026

  • Third-party risk — 17 requirements; effective 15 September 2026

  • Organizational behaviour — 15 requirements; effective 15 December 2026

  • Organizational resilience — 20 requirements; effective 30 April 2027

Together, they contain 69 requirements, consistently organised around three questions:

  1. Governance — Who provides direction, ownership and oversight?

  2. Risk management — How is the risk identified, assessed, monitored and escalated?

  3. Controls — What evidence shows that the risk is being managed in practice?

Conformance is mandatory for assurance engagements and recommended for advisory work. Auditors may conclude that some requirements are not applicable or are covered elsewhere, but every requirement must be considered and the rationale documented. Coverage may also be spread across several engagements, provided it remains deliberate, traceable and supported by evidence.

For internal audit functions, this creates a visible quality benchmark. Chief audit executives should assess the impact on the audit universe and plan, map existing methodologies against all 69 requirements, update engagement templates and quality-review processes, confirm access to appropriate expertise, and brief audit committees on implementation.

The central message is simple: professional judgement remains essential, but undocumented judgement is no longer enough.

Understanding the IIA Topical Requirements

Topical Requirements are the IIA’s new mandatory minimum baseline for auditing important risk areas. They do not replace the Global Internal Audit Standards; they translate the Standards into clear expectations for specific topics.

Their purpose is simple: an audit of cybersecurity, third parties, organizational behaviour, or resilience should cover a recognisable minimum set of matters, regardless of the organisation or country.

1. When they apply

A Topical Requirement must be considered when its subject:

  • is included in the internal audit plan;

  • emerges during another assurance engagement; or

  • becomes the subject of an additional, unplanned engagement.

Conformance is:

  • mandatory for assurance engagements;

  • recommended for advisory engagements.

Auditors do not necessarily have to test every requirement in every engagement. However, they must:

  1. assess every requirement for applicability;

  2. retain evidence of that assessment;

  3. document why any requirement was excluded, superseded or covered elsewhere.

Conformance will be examined through engagement supervision and internal and external quality assessments.

This is the crucial point: professional judgement remains, but undocumented judgement is not enough.

2. The common structure

All four requirements follow the same three-part architecture, as by the infographic below:

Three Questions Behind Every Topical Requirement

All four IIA Topical Requirements follow the same structure: governance, risk management and controls.

The governing body provides direction and oversight. The second line identifies, assesses and monitors risk. The first line operates the controls in practice.

Internal Audit stands apart. As the third line, it independently assesses whether all three are working together.

Different topics. One common architecture. One clearer standard for assurance.

Internal audit, as the third line, independently assesses all three.

The four requirements contain 69 individual requirements:

69 Requirements. One Common Structure

How the IIA Topical Requirements divide across governance, risk management and controls.

Click here to download the Excel file containing the full details

The greater number of control requirements reflects the emphasis on observable evidence—not merely policies and intentions.

3. What each requirement covers

Cybersecurity

The cybersecurity requirement asks whether the organisation can protect its systems and information against attack, disruption, unauthorised access and loss.

Its main expectations are:

  • a formal cybersecurity strategy, policies, governance and competent ownership;

  • organisation-wide identification and management of cyber risk;

  • rapid escalation of unacceptable risks;

  • tested incident response and recovery arrangements;

  • protection of confidentiality, integrity and availability;

  • secure asset lifecycle management;

  • configuration, encryption, patching and access controls;

  • network, endpoint, communication and vendor controls;

  • continuous monitoring of threats and vulnerabilities.

In plain English: Is cybersecurity directed properly, are cyber risks understood, and do the technical and human controls actually work?

It became effective on 5 February 2026.

Third-party risk

This requirement covers vendors, suppliers, contractors, consultants, outsourced service providers and relevant downstream subcontractors.

The central principle is that outsourcing work does not outsource accountability.

Its main expectations cover the complete third-party lifecycle:

  1. determining whether a third party is needed;

  2. due diligence and selection;

  3. contracting and approval;

  4. onboarding;

  5. ongoing performance and risk monitoring;

  6. incident management and remediation;

  7. renewal or termination;

  8. secure offboarding, including data return and access revocation.

Third parties—and parties further downstream—must be prioritised according to risk. The organisation should maintain a complete inventory and monitor performance, compliance, financial, operational, cyber, ethical, geopolitical and other relevant exposures.

It becomes effective on 15 September 2026.

Organizational behaviour

This requirement makes culture more auditable by focusing on observable behaviour: “the way we do things.”

Instead of asking whether the organisation has a good culture, it asks whether employee behaviour supports organizational objectives.

Its main expectations include:

  • board and management oversight of behavioural risks;

  • clear accountability and behavioural expectations;

  • monitoring the difference between expected and actual behaviour;

  • root-cause analysis of behavioural gaps;

  • safe reporting and whistleblowing arrangements;

  • incentives and consequences aligned with expected behaviour;

  • issue escalation and remediation;

  • effective training and awareness;

  • recruitment and onboarding aligned with behavioural expectations.

This is a significant conceptual development: culture is converted from an abstract idea into observable choices, patterns, incentives and consequences that can be assessed.

It becomes effective on 15 December 2026.

Organizational resilience

Resilience is broader than business continuity or disaster recovery. It concerns whether the organisation can anticipate, absorb, respond to, recover from and adapt to disruption.

The requirement covers sudden events—such as cyberattacks or natural disasters—but also slow-building threats such as skills shortages, technological change, resource scarcity or reputational erosion.

Its main expectations include:

  • a board-approved resilience strategy;

  • clear objectives, resources, reporting and accountability;

  • an incident command and escalation structure;

  • identification and monitoring of resilience risks;

  • scenario analysis and stress testing;

  • tested crisis response and recovery arrangements;

  • critical suppliers and alternative sources;

  • critical data and IT asset inventories;

  • business continuity and disaster recovery plans;

  • workforce, workplace, financial and technological resources;

  • staff training and simulation exercises;

  • post-incident reviews and lessons learned.

In plain English: Can the organisation continue its critical activities when normal conditions no longer exist?

It becomes effective on 30 April 2027.

4. How the documentation package is structured

For each topic, the IIA has produced three complementary documents:

1. The Topical Requirement

This is the short, mandatory document. It contains:

  • the applicability rules;

  • a definition and explanation of the topic;

  • the minimum requirements under governance, risk management and controls.

It tells auditors what must be assessed.

2. The User Guide

This is nonmandatory implementation guidance. It explains:

  • how to determine applicability;

  • how to use risk assessment and professional judgement;

  • possible evidence and audit considerations for each requirement;

  • how to document coverage and exclusions;

  • practical scenarios and audit examples;

  • links to recognised frameworks;

  • an optional documentation or conformance tool.

It helps auditors determine how the requirements might be assessed, without prescribing a single audit programme.

3. The development and consultation report

This provides transparency over how each requirement was created. It describes:

  • topic selection and initial research;

  • task forces and subject-matter experts;

  • review by the Global Guidance Council;

  • public consultation in several languages;

  • surveys, comment letters and stakeholder meetings;

  • grouping feedback into themes;

  • revision and formal approval;

  • assessment of whether a second consultation was necessary.

The four public consultations collectively received 2,018 completed surveys and 2,782 specific comments. The IIA concluded that re-exposure was unnecessary because the revisions responded to feedback without introducing fundamentally new requirements.

5. What this means for internal audit functions

The Common Architecture of the IIA Topical Requirements

One consistent framework for assessing governance, risk management and controls across the Three Lines.

These documents are more than technical guidance. They introduce a visible quality benchmark.

Chief audit executives should therefore:

  • identify which Topical Requirements affect the audit universe and plan;

  • map existing methodologies and work programmes against all 69 requirements;

  • create an applicability assessment for every relevant engagement;

  • record where requirements are covered across multiple audits or by reliable assurance providers;

  • document exclusions clearly;

  • update templates, methodology guidance and quality-review checklists;

  • confirm that teams have the necessary specialist competence;

  • brief audit committees on the requirements and their effective dates.

The audit does not have to sit in one report. Coverage may be spread across several engagements. What matters is that coverage is deliberate, traceable and supported by evidence.

The essence

The structure can be reduced to three questions:

Who oversees the risk?
How is the risk understood and managed?
What controls demonstrate that it is being managed in practice?

The Topical Requirements do not eliminate professional judgement. They establish the minimum territory through which that judgement must travel—and require auditors to leave a clear trail showing how they travelled through it.

I would be delighted to discuss the analysis, hear your comments or suggestions for improvement, and explore how these requirements may support your organisation.

Please feel free to get in touch.

A.C. Coppola

Antonio Carmine Coppola is an international governance, audit, and risk expert with more than 20 years of experience across 20+ countries. Founder of Phronesium, he believes that knowledge is common, judgement is rare, and better decisions begin with better thinking.

Previous
Previous

Six Thinking Hats: A Simpler Way to Think Together

Next
Next

Influence: Why We Say Yes Before We Think