IIA Topical Requirements are mandatory minimum baselines for auditing specific risk subjects, and they sit in the same mandatory tier of the International Professional Practices Framework as the Global Internal Audit Standards. Four have been issued. Two are already in force, having taken effect in February and September 2026, and two more arrive in December 2026 and April 2027. Each comes with a documentation duty that applies item by item.
This guide sets out the four requirements, their effective dates and item counts, when they apply, what you must record, and how to build them into your audit plan.
What this guide covers
- What IIA Topical Requirements are
- The four IIA Topical Requirements issued so far
- When IIA Topical Requirements apply: the three triggers
- Assurance vs advisory under IIA Topical Requirements
- The IIA Topical Requirements applicability record
- Folding IIA Topical Requirements into the risk-based plan
- What is coming next for IIA Topical Requirements
- Frequently asked questions

What IIA Topical Requirements are
A Topical Requirement is a short, structured list of things internal auditors must assess when they audit a particular topic. Each one is organised into three components: governance, risk management and controls. Each item carries an identifier such as CYB-G-A or TP-C-D, which makes them easy to trace through a work program and a testing workbook.
They do not replace the Standards. The IIA Topical Requirements have to be applied in conformance with the Global Internal Audit Standards, which remain the authoritative basis for how engagements are planned, performed and reported. Think of a Topical Requirement as the minimum scope for a topic, and the Standards as the rules for how you do the work.
A baseline is a floor, not a ceiling. Where your risk profile, a regulator or another framework asks for more depth, you go further. The IIA’s application guidance is explicit that a stricter external obligation should drive the scope.
The four IIA Topical Requirements issued so far
Each of the IIA Topical Requirements takes effect 12 months after issue, which gives functions a year to prepare. The dates below are the effective dates.
| Topical Requirement | Effective date | Items | Split (G / R / C) | What it covers |
|---|---|---|---|---|
| Cybersecurity | 5 February 2026 | 17 | 4 / 6 / 7 | Cyber strategy, policies and roles, risk management and incident response, and technical controls |
| Third-Party | 15 September 2026 | 17 | 4 / 4 / 9 | Sourcing decisions, due diligence, contracting, monitoring and exit across the third-party life cycle |
| Organizational Behavior | 15 December 2026 | 15 | 4 / 4 / 7 | Roles, accountability for behavioural expectations, and how behaviour aligns with objectives |
| Organizational Resilience | 30 April 2027 | 20 | 6 / 4 / 10 | Resilience strategy, board reporting, and critical operational, technological and financial processes |
That is 69 items in total. The Organizational Behavior requirement was issued on 15 December 2025 and the Organizational Resilience requirement on 30 April 2026, each one year before its effective date.
The Third-Party requirement has a defined scope worth knowing. It covers vendors, suppliers, contractors, subcontractors, outsourced service providers, consultants and other agencies, including fourth parties and further down the chain. It excludes regulators, agents, trustees and board members, and employees. Our post on the third party topical requirement goes through its 17 items.
When IIA Topical Requirements apply: the three triggers
IIA Topical Requirements become applicable in three situations:
- The topic is in the plan. An engagement on cybersecurity, third parties, behaviour or resilience appears in the approved internal audit plan.
- The topic surfaces during fieldwork. You are auditing something else and the topic emerges as a significant risk within that engagement.
- Someone asks for it. The board or management requests an engagement on the topic that was never part of the original plan.
The second trigger is the one you cannot schedule. A procurement audit that turns up a material outsourcing risk, or an operations review that finds a resilience gap, can bring a requirement into play mid-engagement. The application guidance links this to significance: the topic applies when the risk sits above the threshold your organisation has set through its risk appetite. It also allows a partial application where the risk relates to only one component, for example controls rather than governance.
Assurance vs advisory under IIA Topical Requirements
Conformance is mandatory for assurance services and recommended for advisory services. That distinction matters for how you label engagements in the plan.
There is a legitimate use for the advisory route. Where a topic is high risk but the organisation’s governance and controls around it are immature, a full assurance engagement may have little to test. The application guidance accepts that a requirement can then serve as a framework within an advisory engagement to map gaps and build awareness. It does not let the function stay quiet, though: the exposure still has to go to the board, so leadership understands what is not yet covered.
What the advisory route cannot be is a way around the documentation. If the engagement is in substance assurance, calling it advisory does not change which rules apply, and a quality assessor will read the scope and conclusions rather than the label.
The IIA Topical Requirements applicability record
This record is easy to overlook, and it is not optional. For every item in an applicable Topical Requirement, you must document that it was assessed for applicability and keep that evidence. Where an item is excluded, the rationale must be documented and retained too. Conformance with the IIA Topical Requirements is evaluated during quality assessments, so this record is what an assessor will ask to see.
In practice, a workable record has one row per item and these columns:
- Item identifier (for example TP-R-B) and a short paraphrase of what it asks.
- Which trigger made the requirement applicable, and the engagement or plan reference.
- Applicable, partly applicable or excluded.
- Rationale for any exclusion, tied to the risk rating, the engagement scope, or reliance on another assurance provider.
- Where the item is tested (engagement, work program step, year).
- Reviewer sign-off.
The decision can be recorded at plan level, where a topic is covered by one engagement or spread across several, or at engagement level, where it was triggered during planning or fieldwork. If coverage is spread across engagements or years, the documentation has to show how and when each part is addressed.
Folding IIA Topical Requirements into the risk-based plan
Standard 9.4 already requires a documented risk assessment, informed by the board and senior management and performed at least annually. The IIA Topical Requirements plug into that process rather than running beside it. Our guide to the risk based internal audit plan covers the wider method; the topical steps are these:
- Tag the audit universe. Mark every auditable unit where cybersecurity, third-party, behavioural or resilience risk is material, and reference the relevant requirement against it.
- Score against your threshold. Assess inherent impact and likelihood and compare the result to the risk appetite set with board and senior management input. Above the line, the requirement is in scope.
- Choose the coverage model. A standalone topical audit, or the items distributed across several engagements over more than one cycle.
- Record applicability at plan level. Start the item-by-item record when the plan is approved, then complete it at engagement level.
- Check resources honestly. A shortage of time, staff or expertise does not remove the duty to assess the risk. Under Standard 8.2, the CAE tells the board about the shortfall and how it will be addressed, whether through training, recruitment, co-sourcing or a rescoped engagement the board has agreed to.
- Map to other frameworks. If another provider has already audited cybersecurity against NIST guidance or ISO/IEC 27001, you can rely on that work, but document the reliance and judge whether the evidence is sufficient.
Applying two of the IIA Topical Requirements to one engagement is a judgment call, not a default. The guidance gives the example of a third party that provides cybersecurity services, where both the Cybersecurity and Third-Party requirements may fit.
What is coming next for IIA Topical Requirements
As of October 2026, the IIA’s Topical Requirements page lists an Anti-Corruption requirement as to be issued in Q4 2026 and a Talent Management requirement going to public consultation in January 2027. Given the 12-month rule, Anti-Corruption would become effective one year after whatever its issue date turns out to be. Neither has a published item list yet, so there is nothing to build to; add them to the plan watch list and revisit when the texts appear.
Frequently asked questions
Are IIA Topical Requirements mandatory?
Yes, for assurance engagements where one of the three triggers applies. For advisory engagements they are recommended rather than mandatory.
Do we have to audit every topic every year?
No. A requirement applies when the topic is in scope through one of the triggers, and whether it reaches the plan depends on your risk assessment. If a topic is high risk and you are not covering it, Standard 9.4 expects you to explain that to the board.
Can we exclude individual requirement items?
Yes, where an item does not fit the risk or the engagement scope. Every item still has to be assessed, and each exclusion needs a written, retained rationale.
Where can I read the IIA Topical Requirements?
The IIA publishes them, with user guides, free on its Topical Requirements page. The cybersecurity topical requirement was the first to take effect and is the natural place to start.
Our Internal Audit Toolkit provides 87 editable templates built on the Global Internal Audit Standards and every one of the 69 items in the four issued IIA Topical Requirements. For this topic, the Topical Requirements Applicability and Exclusions Assessment gives you the item-by-item record, and each requirement has its own audit program and testing workbook: the Cybersecurity, Third-Party, Organizational Behavior and Organizational Resilience Audit Programs and Requirement Testing Workbooks, plus a Culture and Behavior Survey for the behaviour work. It is $99.