3.2 Applying Topical Requirements When Planning

Key Takeaways

  • Topical Requirements are a mandatory IPPF component for assurance when the topic is in scope; Global Guidance (GTAGs, Global Practice Guides, user guides) is recommended, not mandatory
  • The Cybersecurity Topical Requirement was issued 5 February 2025 and became effective 5 February 2026; it is a minimum baseline across governance, risk management, and control processes — not a substitute for NIST or a CISSP body of knowledge
  • Applicability triggers: the topic is the subject of an engagement in the internal audit plan, is identified while performing an engagement, or is the subject of an engagement request not on the original plan
  • Planning implications are the required risk/control considerations, the evidence you will need, the specialists you may need, and how the baseline fits objectives and scope already set
  • Evidence that each requirement was assessed for applicability must be retained; exclusions need a documented rationale; conformance is evaluated in quality assessments and the CAE remains responsible if specialist work is outsourced
Last updated: August 2026

3.2 Applying Topical Requirements When Planning

Quick Answer: When a published Topical Requirement's topic is in assurance scope, you must apply it in conformance with the Global Internal Audit Standards. Planning is where you translate that mandate into required risk and control considerations, the evidence the work program will collect, the specialists you may need, and a documented decision about which requirements apply to objectives already set. Global Guidance is recommended. Topical Requirements are not.

Chapter 2 covered Topical Requirements when setting objectives and scope. This section is CIA Part 2 A3a: recognize how to apply them when planning the engagement — staffing, procedures, evidence, and the fit to objectives that already exist. Do not rebuild the annual internal audit plan here; that is CIA Part 3 / GIAS Domain IV. Stay inside one engagement.

Mandatory versus recommended in the 2024 IPPF

The International Professional Practices Framework has three layers. Mixing them up is a high-yield exam error.

IPPF componentStatusWhat it does in engagement planning
Global Internal Audit StandardsMandatoryHow you plan, gather evidence, conclude, and communicate
Topical RequirementsMandatory for assurance when the topic is in scope; recommended for advisory servicesA minimum baseline of relevant criteria for governance, risk management, and control processes on that topic
Global Guidance (GTAGs, Global Practice Guides, Topical Requirement user guides)RecommendedHow-to help, examples, and mappings to frameworks such as NIST CSF 2.0 or COBIT 2019

Topical Requirements “provide a minimum baseline and relevant criteria for a consistent, comprehensive approach” to assessing design and implementation of governance, risk management, and control processes in particular risk areas. They are not intended to cover every aspect you might consider. The organization's risk profile may require more. They are also not a requirement to adopt NIST, COBIT, or ISO; if management already uses those frameworks, you reconcile your intended testing to the Topical Requirement so the baseline is covered.

Each Topical Requirement becomes effective 12 months after issuance. Early adoption is encouraged. Quality assessments conducted after the effective date evaluate conformance, including whether engagement files show the applicability assessment.

As of 2026, issued topics include Cybersecurity (effective 5 February 2026), Third-Party (effective 15 September 2026), Organizational Behavior (effective 15 December 2026), and Organizational Resilience (effective 30 April 2027). The IIA's CIA policy is that scored exam questions on a new Topical Requirement do not appear until at least six months after that requirement's effective date. For Cybersecurity, that window opened about 5 August 2026. The 2025 Part 2 syllabus has tested how to apply Topical Requirements in planning since 28 May 2025, so treat the method as always in play and treat Cybersecurity as the working example the IIA actually published first.

When the requirement applies — three triggers

The Cybersecurity Topical Requirement (and the same pattern on later topics) is applicable when the topic is one of the following:

  • A. The subject of an engagement in the internal audit plan
  • B. Identified while performing an engagement
  • C. The subject of an engagement request not on the original internal audit plan

Evidence that each requirement in the Topical Requirement was assessed for applicability must be documented and retained. Not every individual requirement applies in every engagement. If you exclude requirements, a rationale must be documented and retained. Rotational coverage across more than one engagement can be a valid rationale; “we ran out of hours” without a risk basis is not.

Conformance is mandatory for assurance and recommended for advisory. Relabeling an assurance engagement as “advisory” after you find a cyber issue, solely to dodge the baseline, is not a planning technique — it is a quality-assessment finding waiting to happen.

Cybersecurity as the planning example — not a CISSP chapter

The Cybersecurity Topical Requirement uses NIST's short definition of cybersecurity (protect or defend the use of cyberspace from cyberattacks) and treats cybersecurity as a subset of information security (confidentiality, integrity, and availability). For Part 2 planning you need the three-pillar baseline, not a catalog of controls.

Governance (planning questions). Is there a formal cybersecurity strategy and objectives, updated and reviewed by the board, including resources and budget? Are policies and procedures established and updated? Are roles and responsibilities defined, with a process to assess knowledge, skills, and abilities? Are relevant stakeholders — senior management, operations, risk, HR, legal, compliance, vendors — engaged on vulnerabilities and emerging threats?

Risk management (planning questions). Do enterprise risk processes identify, analyze, mitigate, and monitor cyber threats against strategic objectives? Is cyber risk management cross-functional, not only an IT silo? Is an individual or team accountable for monitoring and reporting, including resources and emerging threats? Is there a process to escalate risk that reaches an unacceptable level, considering financial and nonfinancial impact? Is awareness training in place, with management review of gaps and remediation? Is incident response and recovery defined (detection, containment, recovery, post-incident analysis) and periodically tested?

Control processes (planning questions). Are internal and vendor-based controls in place to protect confidentiality, integrity, and availability, and periodically evaluated? Is there a talent process for technical competency? Is there continuous monitoring of threats and improvement opportunities? Is cybersecurity built into the IT-asset life cycle (selection, use, maintenance, decommissioning)? Are strengthening processes such as configuration, encryption, patching, and user-access management in place? Network and endpoint controls exist in the requirement (segmentation, firewalls, VPN/ZTNA, IDS/IPS, email and file-sharing). For this exam, that list tells you what you may need a specialist to test, not how to configure a firewall. Chapter 4 covers cybersecurity, IT general controls, privacy, and data security as planning knowledge in more operational depth.

The companion user guide maps the baseline to NIST CSF 2.0, NIST SP 800-53, and COBIT 2019. Mapping is recommended help. It does not replace documenting applicability.

Four planning implications you must be able to apply

1. Required risk and control considerations. Once the topic is in scope, the three pillars become default risk/control questions for the work program. You do not invent a parallel private framework. You also do not copy every control-process letter into an accounts-payable test of a web purchase-order portal. Professional judgment (GIAS 13.2, 13.3, 13.4, 13.6) decides which requirements are applicable to this engagement's objectives.

2. Evidence you will need. Planning fails if you discover in week three that board cyber reporting, the last tabletop of the incident-response plan, or vendor SOC reports are not obtainable in the fieldwork window. Typical evidence to schedule up front includes: the cyber strategy and last board or committee pack; policy set and last-review date; CISO (or equivalent) charter, reporting line, and competency assessments; risk-register entries and appetite/tolerance statements; incident-response plan and last test results; vendor SOC reports and contract security clauses; and extracts that will support later testing of access, patching, or encryption if those control-process requirements stay in scope.

3. Specialists you may need. If the internal audit function lacks the knowledge to perform the in-scope work, obtain it — co-source or outsource — under competency and human-resources standards. Outsourcing does not transfer conformance responsibility; the chief audit executive remains responsible for the Topical Requirement. If resources are still insufficient, that limitation must be recognized in planning (and, under GIAS, raised as a resource issue). For a portal-only slice of AP, you may need a short specialist review of authentication and data-in-transit protections rather than a full red-team.

4. Interaction with engagement objectives already set. Objectives and scope decide whether the topic is in. Planning decides which requirements you will cover, what evidence you will collect, and who will do the work. You do not rewrite a three-way-match objective into “audit the enterprise cyber program” merely because a Topical Requirement exists. You also do not ignore a web portal that sits inside an AP walk-through. The IIA's own user-guide example is exactly that: AP was not scoped as a cyber engagement; the walk-through showed web-based purchase-order submission; Standard 13.2 then required a fresh look at the Cybersecurity Topical Requirement; governance or full risk-management pillars might be excluded with a documented rationale if they are not relevant to the portal risk.

In practice

You are planning AP. Objectives are accuracy, timeliness, and vendor-master integrity. Scope originally excluded “IT security.” The walk-through shows vendors upload invoices to an internet-facing portal. Planning response: assess the Cybersecurity Topical Requirement for applicability; keep AP objectives; add the portal-related control-process and risk-management requirements that protect invoice integrity and vendor identity; exclude enterprise cyber-strategy testing with a written rationale; request a specialist for portal authentication if the team cannot evaluate it; schedule evidence (SOC report for the portal vendor, access listings, incident logs for the portal). That is A3a. It is not an invitation to write a CISSP study guide inside an AP file.

Loading diagram...
Topical Requirements in Engagement Planning
Test Your Knowledge

When must internal auditors apply a published Topical Requirement?

A
B
C
D
Test Your Knowledge

An accounts-payable engagement's objectives do not mention cybersecurity. During a walk-through, auditors learn purchase orders are submitted through a public web portal. What is the correct planning response under the Cybersecurity Topical Requirement?

A
B
C
D
Test Your Knowledge

Which statement correctly distinguishes Topical Requirements from Global Guidance when planning an engagement?

A
B
C
D