Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

third party topical requirement — Third Party Topical Requirement: The 2026 Audit Guide

Third Party Topical Requirement: The 2026 Audit Guide

The third party topical requirement took effect on 15 September 2026, and from that date any assurance engagement that touches a supplier, outsourcer or contractor relationship has a defined minimum scope. It has 17 items: four on governance, four on risk management and nine on controls, and between them they follow a third party from the decision to use one through to the exit.

This guide covers who counts as a third party for these purposes, how far down the supply chain it reaches, how the 17 items map to the life cycle, how to choose which parties to test, and how to document the items you exclude.

What this guide covers

third party topical requirement explained
The Third-Party Topical Requirement across the third-party life cycle.

What the third party topical requirement covers

Like the other Topical Requirements, the third party topical requirement is used together with the Global Internal Audit Standards, not as a separate rulebook. Assurance engagements must conform to it; for advisory work it is recommended. Conformance is evaluated during quality assessments.

The underlying idea is simple and worth stating to management at the opening meeting: the organisation that signs the contract keeps accountability for the risks to its objectives, even when a third party does the work. Outsourcing moves activity, not responsibility. The IIA’s text lists the categories of risk this creates, including strategic, reputational, ethical, operational, financial, compliance, cybersecurity, IT, legal, sustainability and geopolitical risk.

Who the third party topical requirement covers and excludes

The IIA’s user guide defines the term broadly. Suppliers and vendors, contractors and their subcontractors, consultants, outsourced service providers and other agencies are all in. It also expressly reaches the subcontractors of those parties, often called fourth, fifth or Nth parties, where the primary contract allows them.

The exclusions matter as much as the inclusions. The requirement itself is not aimed at regulators, agents, trustees or board members, or employees. The user guide adds brokers, investors, public services, members of the public and intragroup service providers to that list. Auditors are also given room to adapt the scope to the organisation’s own definition of a third party, which varies by sector, so write the definition you used into the engagement plan.

Downstream and fourth parties

The third party topical requirement applies to subcontracted relationships the third party’s contract permits, and expects those further-downstream parties to be prioritised by risk like any other. In practice that means testing whether the organisation knows who its critical suppliers rely on, whether contracts require notice or approval of material subcontracting, and whether the risk ranking takes concentration in shared downstream providers into account.

Mapping the third party topical requirement to the life cycle

The IIA divides the relationship into five stages — selecting, contracting, onboarding, monitoring and offboarding. The items are grouped by governance, risk and control rather than by stage, so the table below is our own allocation. Several governance and risk items run across every stage.

Life-cycle stage Items Evidence to request
Across the whole life cycle G-B policies, G-C roles and competence, R-A standard risk process, R-B risk ranking Third-party policy and procedures with review dates; RACI; competence records; risk methodology; current tiering of all parties
Selecting G-A decision to outsource, C-A due diligence and business case Make-or-buy criteria; approved business cases; due diligence files for a sample of new parties
Contracting C-B contracting under policy, C-C review, signature, storage and contract owner Approval trail with legal and compliance sign-off; signed contracts; named contract managers
Onboarding C-D complete inventory, C-E documented onboarding Central contract or supplier register; onboarding checklists completed for the sample
Monitoring G-D stakeholder reporting, R-C risk responses, R-D issue escalation, C-F performance monitoring, C-G corrective action and incidents, C-H renewals Performance reports and scorecards; escalation logs; incident and root-cause reviews; renewal calendar
Offboarding C-I exit plan Exit plans for prioritised parties; evidence of data return or destruction and access removal

The governance and risk items in plain terms

The governance and risk items of the third party topical requirement test the frame around individual contracts. Is there an agreed, periodically reviewed basis for deciding to use an outside provider at all, including whether the needed resources exist? Are policies aligned with regulation and kept current? Is it clear who selects, directs, manages and monitors each party, and are those people competent?

Do the board and other stakeholders get timely reports on the performance, risks and legal compliance of the parties that matter most? On the risk side, is the process standardised and wide enough to cover the risk categories above; are parties ranked, including downstream ones; are responses proportionate to the ranking; and is there an escalation route that ends, if needed, in remediation or termination?

The nine control items in plain terms

The control section holds nine of the 17 items, so it carries more of the third party topical requirement testing than governance and risk management combined.

In our own words, it asks whether there is proper due diligence before selection with a justified business case; whether contracting follows policy with the right functions involved; whether final agreements are reviewed by legal and compliance, signed by authorised people, stored securely and given a named owner.

It also asks whether there is a complete, current list of every relationship; whether onboarding is documented; whether performance against the contract is monitored, including checking the reliability of what the supplier reports; whether failures trigger corrective action, incident escalation and root-cause review; whether expiry and renewal dates are tracked; and whether exit is planned, covering termination, replacement, the organisation’s data held by the supplier, and access to systems and premises.

Risk-based selection under the third party topical requirement

An organisation with hundreds of suppliers cannot have every one tested in every engagement, and the third party topical requirement does not ask for that. It asks auditors to prioritise third and downstream parties based on risk, apply the items the risk assessment indicates, and document what was excluded.

Free third-party risk assessment

How much risk does this vendor bring?

Tier the vendor, check the evidence, rate the risks from 30 third-party scenarios and choose controls referenced to ISO 27001, NIST CSF 2.0 and DORA. You get a tier, a heat map and the findings an auditor would raise, free.

Start the free vendor risk assessment →  or  View premium report sample

A defensible approach has three steps:

  1. Test the organisation’s own ranking first. Item R-B expects management to rank third parties by risk. If that ranking is missing or unreliable, it is a finding in itself, and any sample drawn from it is suspect.
  2. Take the top tier for full life-cycle testing. Critical and high-risk parties are where most items will be applicable.
  3. Add a small sample from lower tiers. This checks that the tiering is working and catches critical services misclassified as low risk.

Exclusions under the third party topical requirement need a written reason. The user guide’s examples include an organisation that relies little on outside providers for its mission-critical services, or a long-standing relationship whose financial impact is small. Record the reason per item, not as a blanket statement, so a quality assessor can follow it.

When the third party topical requirement is triggered

The same three triggers apply as for every Topical Requirement: the topic is an engagement in the plan, it emerges during another engagement, or someone asks for an engagement outside the plan. The second trigger needs the most attention, because it arises after the scope is already set. The user guide’s example is a data storage audit that finds the data is hosted by a cloud provider; at that point both this requirement and the cybersecurity topical requirement need an applicability review.

Plan for this rather than react to it. When you build the risk-based internal audit plan, flag every auditable area with a material outsourced component so the applicability assessment is done at planning, not halfway through fieldwork. Our overview of the IIA topical requirements sets the four issued requirements side by side.

Gaps to look for against the third party topical requirement

These are the questions worth asking early in a third party topical requirement engagement, because each one points to evidence that has to exist before the engagement can conclude:

  • Is there one inventory of third-party relationships, or several partial ones held by procurement, IT and individual departments?
  • Does the risk ranking reach downstream parties, or stop at the contract signatory?
  • Does every live contract have a named owner, and do the owners know they are the owner?
  • Do the prioritised parties have exit plans, and do they address the organisation’s data?
  • When a supplier fails, is there a root-cause review, or just a credit note?

Read the IIA’s own text on the Third-Party Topical Requirement page before finalising your work program; the summaries here are paraphrased.

Frequently asked questions

When did the third party topical requirement become effective?

On 15 September 2026. Each Topical Requirement takes effect 12 months after the IIA issues it.

Are employees and board members third parties?

No. The requirement is not aimed at internal relationships such as employees, or at regulators, agents, and trustees or board members. The user guide also excludes intragroup service providers, brokers and investors.

Do we have to test fourth parties?

Where the third party’s contract allows subcontracting, those downstream parties are in scope and should be prioritised by risk. You test whether management identifies and ranks them, then select based on that ranking.

Does the third party topical requirement replace our TPRM framework?

No. It defines what internal audit must assess. Management still needs its own third-party risk management framework, and the requirement is the yardstick audit uses to evaluate it. If you are building that management framework, our TPRM Toolkit covers that side.

Our Internal Audit Toolkit provides 87 editable templates built on the 2024 Standards and every item of the four issued Topical Requirements. For the third party topical requirement, it includes the Third-Party Audit Program and the Third-Party Requirement Testing Workbook, both covering all 17 items, the Topical Requirements Applicability and Exclusions Assessment for documenting rationale, the Sampling Methodology and Sample Selection Workbook for risk-based selection of parties, and the Information Request List to collect the evidence above. It is $99, in Word and Excel.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.