2.1 Topical Requirements in Objectives and Scope

Key Takeaways

  • IIA Topical Requirements are mandatory IPPF elements, alongside the Global Internal Audit Standards; Global Guidance and user guides are recommended, not optional substitutes for a Topical Requirement
  • When a topic is the subject of an assurance engagement or a significant component of one, the applicable Topical Requirement is a minimum baseline that constrains engagement objectives and scope
  • The Cybersecurity Topical Requirement was issued 5 February 2025 and is effective 5 February 2026; CIA scored items appear at least six months after the effective date, so cybersecurity is tested as a planning-and-performing constraint, not as a standalone IT exam
  • Individual Topical Requirement elements may be excluded only with documented rationale retained in the engagement file; treating the whole requirement as skippable guidance is a nonconformance trap
Last updated: August 2026

2.1 Topical Requirements in Objectives and Scope

Quick Answer: IIA Topical Requirements are mandatory International Professional Practices Framework (IPPF) elements, equal in force to the Global Internal Audit Standards. When you set engagement objectives and scope, an applicable Topical Requirement (cybersecurity is the working example) is a minimum baseline you must cover, not optional reading. The CIA scores new Topical Requirements at least six months after the effective date, not the issue date. Part 2 tests them as planning and performing constraints, not as a standalone IT exam.

CIA Part 2 Section A is Engagement Planning (50%). The first numbered objective is Determine engagement objectives and scope. The first official may-include bullet is: recognize how to apply Topical Requirements when determining objectives and scope. That is a Domain V / Principle 13 skill (plan engagements effectively), anchored in Standard 13.3, Engagement Objectives and Scope. It is not a Part 3 “manage the function” item and it is not Chapter 3’s later work on selecting evaluation criteria.

Where Topical Requirements sit in the IPPF

The 2024 IPPF has two mandatory components and one recommended component. Mixing those categories is the first exam trap.

IPPF componentForceWhat it does for this engagement
Global Internal Audit StandardsMandatoryPrinciples and requirements for planning, performing, and communicating; Standard 13.3 requires documented objectives and a scope sufficient to achieve them
Topical RequirementsMandatory (when applicable)Minimum baseline for assessing design and implementation of governance, risk management, and control processes in a named risk area
Global Guidance (practice guides, GTAGs, user guides)RecommendedHelps you implement; does not replace a Topical Requirement

Topical Requirements exist because the Standards are principles-based. They tell you to plan the engagement, assess risk, and set objectives, but they do not list the minimum governance, risk-management, and control attributes for a pervasive topic such as cybersecurity. A Topical Requirement fills that gap.

User guides that map the Cybersecurity Topical Requirement to NIST Cybersecurity Framework 2.0, COBIT 2019, or NIST SP 800-53 are supplemental. You may use a mapped framework if you can demonstrate it covers the applicable requirements. Citing NIST does not waive the Topical Requirement, and “we follow ISO 27001” is not a free pass unless the file shows coverage of the applicable baseline.

How a Topical Requirement constrains objectives and scope

When a risk assessment leads to a topic being (1) the subject of an assurance engagement on the internal audit plan, or (2) identified while performing an engagement, the Topical Requirement applies. IIA has also been clear that the Cybersecurity Topical Requirement applies to cybersecurity engagements and engagements that have a cybersecurity component. A payroll, ERP, or third-party review that depends on privileged access, data-loss controls, or identity management is not “exempt” because the engagement letter says “operational,” not “IT.”

What that means when you write objectives and scope:

Objectives must be capable of supporting a conclusion on the relevant baseline. For cybersecurity, that baseline is governance, risk management, and control processes—not a menu from which you pick the easy slice. An objective that tests only technical firewall rules while ignoring board oversight, role clarity, and risk-appetite alignment does not meet the requirement. You are not writing a CISSP lab; you are writing an internal audit objective that can still conclude on those three process layers.

Scope must be wide enough to evidence those baseline elements. Scope is the boundary (activities, locations, systems, period, populations) within which you will gather evidence. If the objective claims “cybersecurity governance and control processes over the payroll file,” excluding identity-and-access management because the CISO is busy is a scope limitation, not a professional courtesy. You may exclude an individual requirement that truly does not apply—for example, a control attribute that exists only for a technology the organization does not use—but you must document the rationale and retain it. Evidence that each requirement was assessed for applicability is itself a conformance task. Quality assessments after the effective date review that documentation against Standards 13.2 and 13.3 (the Quality Assessment Manual’s D5 and D6 templates).

Advisory work is different. Topical Requirements are recommended but not required for advisory services. If you apply them on an advisory engagement, document that choice. If you skip them, do not label the work “assurance.” The exam loves a stem in which a stakeholder “agrees” to drop cyber governance from an assurance payroll review; agreement does not convert a mandatory baseline into guidance.

The process-owner trap is treating Topical Requirements as Global Guidance you can “consider.” They are not. For applicable assurance work they constrain what must be covered. A manager who wants a “light IT general-controls look” cannot bargain the function out of a mandatory baseline. If the remaining work still cannot cover the applicable elements, you have a scope limitation (Chapter 2.3)—you document, communicate, and decide whether a conclusion is still supportable. You do not silently rewrite the objective to match the manager’s comfort.

Timing: issued, effective, and CIA-testable

IIA Topical Requirements become effective 12 months after issuance. Early adoption is encouraged. Quality assessments conducted after the effective date assess conformance with effective Topical Requirements.

The Cybersecurity Topical Requirement was issued 5 February 2025 and becomes effective 5 February 2026. It is the first issued Topical Requirement and the one Part 2 candidates must be ready to apply in an objectives-and-scope vignette.

CIA scoring policy, stated by IIA: scored exam questions on new Topical Requirements will not appear until at least six months after the Topical Requirement’s effective date. For cybersecurity, scored items are expected from about August 2026, not from February 2025. Confusing issue date with effective date, or assuming the CIA tests a pronouncement the day it is published, is a designed distractor. The same cadence applies to later topics: Third-Party (effective 15 September 2026), Organizational Behavior (effective 15 December 2026), and Organizational Resilience (effective 30 April 2027). You are not required to memorize every future date. You are required to know the policy (mandatory IPPF element; 12-month effectiveness; CIA lag of at least six months after effective date) and to apply cybersecurity when a scenario makes cyber the subject or a component.

What Part 2 will and will not test

IIA has been explicit: topical requirements are tested in Parts 2 and 3 in the context of planning and performing engagements (Part 2) and managing the internal audit function (Part 3). This is not a standalone IT exam. Expect items that ask whether an objective is complete given the cybersecurity Topical Requirement, whether a scope exclusion was documented, or whether an auditor wrongly treated the requirement as optional. Do not expect SIEM configuration, CVE trivia, or NIST control-ID memorization.

Keep the Part 2 / Part 3 boundary clean. Annual plan construction, CAE board reporting on the quality program, and residual-risk acceptance protocol live primarily in Part 3. This chapter is about this engagement’s objectives and scope. Chapter 3 returns to Topical Requirements when planning the engagement more broadly (risks, criteria, activity context). Chapter 7 returns to them in the engagement risk assessment. Here, the only job is: if a Topical Requirement applies, your objectives and scope must reflect its mandatory baseline.

Loading diagram...
Applying a Topical Requirement when setting objectives and scope
Cybersecurity Topical Requirement: months after 5 February 2025 issuance
Test Your Knowledge

When determining engagement objectives and scope, how should an internal auditor treat an applicable IIA Topical Requirement?

A
B
C
D
Test Your Knowledge

The Cybersecurity Topical Requirement was issued on 5 February 2025. Under IIA CIA policy, when will scored exam questions on that Topical Requirement appear?

A
B
C
D
Test Your Knowledge

An assurance engagement is labeled “payroll operations.” Planning identifies that privileged access to the payroll file and identity-management controls are significant to the activity. The payroll director asks internal audit to omit cybersecurity so the review “stays operational.” What is the most appropriate response when setting objectives and scope?

A
B
C
D