9.3 Topical Requirements & Their Applicability
Key Takeaways
- Topical Requirements are a mandatory component of the 2024 International Professional Practices Framework (IPPF), ranking alongside the Global Internal Audit Standards; Global Guidance remains recommended only.
- Each Topical Requirement sets baseline criteria in three categories — governance, risk management, and control processes — for evaluating a specific risk subject.
- A Topical Requirement becomes applicable when the topic is the subject of a planned assurance engagement, is identified during an active engagement, or is the subject of an unplanned engagement request.
- Topical Requirements are mandatory for assurance services and recommended but not required for advisory services; they never compel the internal audit function to schedule an audit of the topic.
- The Cybersecurity Topical Requirement took effect February 5, 2026, followed by Third-Party (September 15, 2026), Organizational Behavior (December 15, 2026), and Organizational Resilience (April 30, 2027).
9.3 Topical Requirements & Their Applicability
[!IMPORTANT] Why this section exists: The official CIA Part 3 test specifications name Topical Requirements twice — once under Section B (Identify sources of potential engagements) and once under Section C (Describe the required elements of the quality assurance and improvement program). Candidates who studied from pre-2025 material have never encountered the concept, because it did not exist under the 2017 IPPF. It is one of the highest-yield "new content" areas on the exam.
Topical Requirements are mandatory pronouncements issued by The Institute of Internal Auditors (IIA) that establish a consistent baseline for how internal auditors assess a specific risk subject. They exist because the Global Internal Audit Standards (GIAS) deliberately describe how to run an internal audit function without prescribing what good looks like for any particular risk domain. Two internal audit functions could both conform fully with the GIAS and still audit cybersecurity to wildly different depths. Topical Requirements close that gap.
Position Within the 2024 IPPF
The restructured International Professional Practices Framework has a clear authority hierarchy. Confusing the mandatory tier with the recommended tier is a classic distractor.
| IPPF Component | Authority | What It Governs |
|---|---|---|
| Global Internal Audit Standards | Mandatory | How the internal audit function is governed, managed, and performed |
| Topical Requirements | Mandatory | Baseline criteria for assessing a specific risk subject (e.g., cybersecurity) |
| Global Guidance | Recommended only | Implementation aids, practice guides, user guides, model documents |
[!NOTE] Exam trap: A user guide accompanies each Topical Requirement. The requirement is mandatory; the user guide is recommended guidance. Answer options that describe the user guide as binding are incorrect.
Anatomy: Three Requirement Categories
Every Topical Requirement is organized into the same three categories, mirroring the language internal auditors already use when scoping an engagement:
- Governance requirements — whether accountability, oversight, roles, policy approval, and reporting structures for the topic are defined and functioning.
- Risk management requirements — whether the organization identifies, assesses, prioritizes, and treats risks within the topic.
- Control process requirements — whether the specific control activities that mitigate the topic's risks are designed appropriately and operating effectively.
This tripartite structure is worth memorizing: scenario questions frequently ask which category a described procedure belongs to.
Issued Topics and Effective Dates
The IIA is releasing Topical Requirements on a rolling schedule. Each becomes binding on its stated effective date, not on its issue date.
| Topical Requirement | Effective Date |
|---|---|
| Cybersecurity | February 5, 2026 |
| Third-Party | September 15, 2026 |
| Organizational Behavior | December 15, 2026 |
| Organizational Resilience | April 30, 2027 |
Additional topics, including talent management and anti-corruption, have been announced for public consultation and future release. Candidates are not expected to memorize the entire pipeline, but should recognize that Cybersecurity was the first Topical Requirement and that the catalogue is expanding.
The Applicability Test (Section B.1.c)
A Topical Requirement is not triggered simply because the risk exists somewhere in the organization. It becomes applicable when any one of three conditions is met:
- The topic is the subject of a planned assurance engagement in the approved internal audit plan.
- The topic is identified during an active engagement as material to the objectives and scope.
- The topic is the subject of an unplanned engagement request from the board or senior management.
[!IMPORTANT] The single most misunderstood point: A Topical Requirement does not obligate the internal audit function to perform an audit of that topic. The chief audit executive (CAE) retains full discretion over the risk-based plan. What the requirement does mandate is that if the function performs assurance work on the topic, that work must conform to the baseline criteria.
Assurance versus advisory: Conformance is mandatory for assurance services. For advisory services, applying the Topical Requirement is recommended but not required — a frequently tested distinction.
The Documentation Obligation
Applicability is a decision the CAE must be able to evidence. For each engagement, the internal audit function documents:
- Whether the Topical Requirement applies, and on what basis.
- Which individual requirements were addressed within the engagement scope.
- Justification for any requirement excluded, including the rationale and who approved the exclusion.
Silence is not an acceptable audit trail. An engagement file that neither applies nor explains the non-application of an in-force Topical Requirement is a nonconformance in its own right.
Linkage to the Audit Plan and the Audit Universe
Because applicability is driven by what sits in the plan, Topical Requirements reshape planning in three practical ways:
- Scoping depth becomes non-negotiable. Once cybersecurity is on the plan, the engagement cannot be scoped down to a narrow access-review; the baseline governance, risk management, and control criteria must be covered or formally excluded with rationale.
- Resource and competency planning shifts. Meeting the baseline may require specialist skills, co-sourcing, or guest auditors — connecting directly to resource management obligations.
- Audit universe metadata expands. Mature functions tag auditable entities in the universe with the Topical Requirements that would be triggered, so the effort implication is visible at plan-approval time rather than mid-engagement.
Linkage to the QAIP (Section C.1.c)
This is the second blueprint hook and the one candidates most often miss. Conformance with the IPPF means conformance with both the GIAS and any applicable Topical Requirements. Consequently:
- Ongoing monitoring must test whether engagements covering an in-force topic addressed the baseline criteria.
- Periodic internal assessments evaluate conformance with applicable Topical Requirements alongside the Standards.
- External quality assessments under Standard 8.4 evaluate the same, and material failures affect the overall conformance rating.
- Disclosure of nonconformance extends to Topical Requirements — a function that performed cybersecurity assurance without meeting the baseline must disclose that nonconformance, its impact, and the remediation plan.
Exam Trap Recognition
| Distractor Pattern | Why It Is Wrong |
|---|---|
| "The Topical Requirement obligates the CAE to add a cybersecurity audit to the annual plan." | Applicability is triggered by the plan, not the reverse. The CAE's risk-based discretion is preserved. |
| "Topical Requirements are recommended guidance the CAE may adopt voluntarily." | They are mandatory IPPF components for assurance engagements. |
| "Because the engagement was advisory, the function was in nonconformance for not applying the requirement." | Application to advisory services is recommended, not required. |
| "Excluded requirements need not be documented." | Exclusions require documented rationale. |
| "QAIP conformance testing covers only the Global Internal Audit Standards." | The QAIP must also assess conformance with applicable Topical Requirements. |
An organization faces significant cybersecurity risk, but the chief audit executive's risk-based annual plan allocates no engagement to cybersecurity this year because the second line completed a major remediation program and residual risk was reassessed as moderate. What is the effect of the Cybersecurity Topical Requirement?
During an assurance engagement over vendor onboarding, the engagement lead determines that four of the control process requirements in an in-force Topical Requirement are not relevant to the agreed scope and omits them. What must the engagement file contain?
A quality assessor is performing a periodic internal assessment of an internal audit function that completed two cybersecurity assurance engagements after February 5, 2026. Which statement best describes the scope of the conformance evaluation?