7.1 Topical Requirements and Pervasive Financial, Operational, IT, Cyber, and Regulatory Risks
Key Takeaways
- An engagement-level risk assessment (GIAS Standard 13.2) ranks risks inside the activity already selected for this engagement; it does not decide which activities appear on the annual audit plan.
- IIA Topical Requirements are mandatory for assurance when the topic is applicable and significant in this engagement, recommended for advisory work, and do not by themselves place the topic on the annual plan.
- The Cybersecurity Topical Requirement was issued 5 February 2025 and became effective 5 February 2026; IIA policy places scored CIA items on a new Topical Requirement no earlier than six months after its effective date.
- A risk is pervasive at engagement level when one failure can distort multiple assertions or subprocesses in the activity under review, such as privileged payroll-master access affecting wage occurrence, FLSA classification, and confidentiality of employee data.
- The 2025 CIA Part 2 syllabus (A5a–b) requires recognition of five pervasive risk types related to the activity under review: financial, operational, IT, cybersecurity, and regulatory.
Engagement-Level Versus Annual-Plan Risk Assessment
An engagement risk assessment is how you decide what can go wrong inside the activity already selected for this engagement, and which of those risks deserve testing. The 2025 CIA Part 2 syllabus tests this as Section A5: complete a detailed risk assessment of each activity under review. That is not the annual, universe-level assessment the chief audit executive (CAE) uses to choose which activities receive an engagement this year. Annual-plan work sits primarily in Global Internal Audit Standards (GIAS) Domain IV and CIA Part 3. On Part 2, the activity—payroll, treasury, procure-to-pay—is already in front of you. Your job is to understand it, identify relevant risks and controls, evaluate significance, and prioritize.
GIAS Standard 13.2, Engagement Risk Assessment, under Principle 13 (Plan Engagements Effectively), requires internal auditors to develop an understanding of the activity under review and assess relevant risks. In practice that means identifying risks to the activity's objectives, identifying the controls management uses to manage those risks, evaluating significance (including error, fraud, and noncompliance exposures), and deciding which risks to pursue. The output is a documented ranking that later shapes objectives, scope, and testing hours. If you catch yourself ranking payroll against treasury to see which one "gets an audit," you have slipped into the annual plan. If you are ranking ghost employees against privileged access inside payroll, you are in the right place.
Applying Topical Requirements in the Engagement Risk Assessment
Topical Requirements are a mandatory element of the International Professional Practices Framework (IPPF), alongside the Global Internal Audit Standards and Global Guidance. They give a minimum baseline of governance, risk management, and control criteria for a named high-risk topic. They are mandatory for assurance when the topic is in the engagement and recommended for advisory work. They do not force the CAE to put that topic on the annual plan, they do not replace professional judgment, and they do not add a second risk-assessment methodology on top of Standard 13.2. They tell you which baseline criteria to consider when you are providing assurance on that topic.
Application at engagement level is mechanical:
- Identify whether a Topical Requirement that is in effect covers risks present in this activity.
- For an assurance engagement, assess each requirement or criterion for applicability and significance to this activity—not to the organization in the abstract.
- Include those that are applicable and significant in the engagement risk assessment, then prioritize them with every other relevant risk (Standard 13.2) and reflect the result in objectives and scope (Standard 13.3, taught in Chapter 2).
- Document inclusion and exclusion decisions. "Conform or explain": if a criterion is not applicable or not significant here, retain the rationale.
- Do not convert a payroll engagement into a full-scope cybersecurity audit merely because a Cybersecurity Topical Requirement exists. Assess how cyber risks relate to payroll, then scale procedures to residual risk.
The first Topical Requirement is Cybersecurity, issued 5 February 2025 and effective 5 February 2026. The Third-Party Topical Requirement was issued 15 September 2025 and is effective 15 September 2026. IIA certification policy does not place scored CIA items on a new Topical Requirement until at least six months after its effective date—so Cybersecurity is in the live window for exams after 5 August 2026, while Third-Party follows the same logic after it becomes effective. Other topics (organizational behavior, organizational resilience, anti-corruption) have been in development; teach the application method, not a memorized inventory that the IIA may still be issuing.
For a payroll engagement, Cybersecurity Topical Requirement criteria typically become applicable to identity and access around the payroll engine, vendor hosting of employee data, and availability of the pay run. You still judge significance. A small in-house payroll with no external host may document that some vendor-hosting criteria are not applicable. That documentation is the application of the Topical Requirement.
What "Pervasive" Means on This Engagement
On CIA Part 2, pervasive describes a risk that can distort multiple assertions, subprocesses, or control objectives inside this activity. It is not a synonym for "enterprise-wide," and it is not the control-environment or culture discussion reserved for Chapter 8. Privileged access to the payroll master file is pervasive because one failure can create ghost employees (financial occurrence), misclassify overtime (regulatory), and expose Social Security numbers (cybersecurity). A single missed garnishment for one employee is localized unless the same design gap would hit the whole population.
The Five Risk Types Tied to the Activity Under Review
The 2025 syllabus asks you to recognize pervasive financial, operational, IT, cybersecurity, and regulatory risks as they relate to the activity under review. Always name the activity. A floating list of "cyber risk" and "interest-rate risk" with no link to payroll or treasury is how candidates miss A5b.
The five types overlap on purpose. A ransomware event is cybersecurity (confidentiality and availability), IT (systems resilience), operational (the pay run does not process), financial (penalties, idle wages, possible ransom), and often regulatory (breach notification, payroll-tax deposit timing). You still classify the primary type so the team can pick the right specialist and procedure, then note the spillover.
| Risk type | Payroll example | Why it is pervasive in payroll | Typical processes or assertions hit |
|---|---|---|---|
| Financial | Ghost employees; overstated regular or overtime pay; unrecorded wage accruals | A master-file or accrual failure misstates expense, cash, and liabilities across the population | Occurrence of wages; completeness of withholdings; cutoff of accruals |
| Operational | Timekeeping that does not match the paid calendar; supervisors skipping overtime policy | The same processing break repeats every cycle for every employee group | Time capture → calculation → exception handling → disbursement |
| IT | Segregation-of-duties conflict between HR master data and payroll approval; weak privileged access to the payroll engine; brittle timeclock interfaces | One access path or interface can corrupt every subsequent pay run until detected | Master data, interfaces, calculation engine, output files |
| Cybersecurity | Ransomware at a hosted payroll vendor; W-2 phishing; exfiltration of employee personally identifiable information | One confidentiality or availability event hits the entire workforce and can stop the run | Confidentiality of data; integrity of bank files; availability of disbursement |
| Regulatory | Fair Labor Standards Act (FLSA) overtime, tax withholding, garnishments, state wage-hour rules | One classification or withholding design gap creates multi-jurisdiction noncompliance | Exempt/nonexempt classification; deposits; information reporting |
Treasury uses the same five types with different facts. Financial: unauthorized wires, window-dressed cash, unrecorded debt. Operational: the daily cash-position process fails or investment cutoff is missed. IT: a bank-file format change, or SWIFT-portal access not removed when staff leave. Cybersecurity: business-email compromise that changes vendor bank details. Regulatory: sanctions screening, anti-money-laundering checks on wires, debt-covenant reporting. If a risk cannot be tied to a treasury process you can walk through, it is not yet an engagement-level risk—it is a note for the annual universe.
Using the Matrix Without Boiling the Ocean
You do not test every cell equally. You use the matrix to see connections. Privileged access (IT) is often the root of financial occurrence issues and cyber confidentiality issues; that is a reason to put access testing early, not a reason to write five separate findings before fieldwork. Topical Requirement criteria, when applicable, drop into the same matrix rather than living in a side binder.
The engagement risk assessment is complete enough for A5a–b when (1) Topical Requirements that are in effect and relevant have been assessed for applicability and significance, (2) the five pervasive types have been considered for this activity, (3) pervasive versus localized risks are distinguished, and (4) the result is a list of risks and related controls ready to be scored and prioritized—the methods in Section 7.3.
An internal auditor is planning a payroll engagement. Which action belongs to the engagement-level risk assessment rather than the annual audit plan?
When must the Cybersecurity Topical Requirement be applied during an engagement risk assessment?
In a treasury engagement, which risk is most clearly pervasive across multiple treasury processes?