Skip to main content
Rehmann
Rehmann
Industries
Resources
About Us

IIA Third-Party Topical Requirement: What Internal Audit Teams Need to Know

September 9, 2026

Contributors: Sam Muehlenbeck, CIA

The Basics 

  • The Institute of Internal Auditors (IIA) has established the Third-Party Topical Requirement, a mandatory baseline for internal audit assurance engagements that involve third parties and its subcontractors.
  • IIA’s Third-Party Topical Requirement framework standardizes how third-party risks are assessed across an organization.
  • Implementation requires auditors to document the applicability of each requirement at the individual engagement level, providing clear justification for any exclusions. 

________________________________________________________________________________ 

What Your Organization Needs to Know 

The IIA’s Third-Party Topical Requirement is a regulatory framework that auditors can use to evaluate third-party risk across internal audit engagements. It is the second in a series of six Topical Requirements, each a mandatory component of the International Professional Practices Framework, which the IIA is issuing for specific high-priority risk areas. 

(The first Topical Requirement, the Cybersecurity Topical Requirement, became effective Feb. 5, 2026. See the Frequently Asked Questions section at the bottom of this article for dates regarding forthcoming frameworks.)

Because the Third-Party Topical Requirement will fundamentally reshape how internal audit functions approach high-priority risks in 2026 and beyond, utilizing it demands thoughtful integration into internal audit engagement level planning. 

Why Did the IIA Create the Third-Party Audit Requirement? 

The IIA introduced the Third-Party Topical Requirement to create a standard baseline internal auditors could use to evaluate governance, risk management, and controls across business relationships with external individuals, groups, or entities.  

By establishing this mandatory framework, the requirement shifts focus from a check of a program’s existence to a deeper evaluation of whether its processes are actually designed and operating effectively. 

What Requirements Are in IIA’s Third-Party Topical Requirement? 

The IIA’s Third-Party Topical Requirement contains 17 specific requirements organized within three core areas:

When and How to Implement: Best Practices for Compliance 

As of Sept. 15, 2026, compliance with the Third-Party Topical Requirement is mandatory for all assurance engagements, and recommended for advisory engagements, when involving external parties that act on behalf of the organization or deliver services, products, and business functions. Third parties include: 

  • Vendors 
  • Suppliers 
  • Sales agents 
  • Insurance brokers 
  • Financial intermediaries 

The requirement also explicitly extends to fourth- and fifth-party engagements, such as those with subcontractors and secondary service providers (e.g. a broker’s software vendor, a supplier’s sub-tier provider). 

Regulators, board members, trustees, and investors are generally excluded from the third-party framework because they represent governance, oversight, ownership, or regulatory authority rather than external operational service providers. They may, however, be evaluated under general internal audit standards or other frameworks. 

Your organization should assess whether the new requirements apply whenever one of the following “triggers” occurs:  

  • Audit Planning: Evaluate any engagement already listed on your annual internal audit plan to see if it carries third-party implications. 
  • Fieldwork Discovery: Apply the requirements if you identify third-party risks while already performing an audit. 
  • Ad Hoc Requests: Review any new, unplanned audit requests to determine if they involve third parties that fall under the topical scope.  
  • Mature third-party risk management programs: If your organization already has a mature third-party risk management program in place, IIA’s Third-Party Topical Requirement Framework provides internal audit with a baseline to validate whether existing practices are complete, consistently applied, and sufficiently documented. Translation: Your program may already address many of the Third-Party Topical Requirement’s concepts, but internal audit must still demonstrate how coverage was considered during the annual planning and individual engagement scoping.  

Why the Third-Party Requirement Matters 

Third-party relationships are embedded in nearly every organization’s operating model. Vendors, outsourced service providers, contractors, consultants, technology platforms, and downstream subcontractors often support critical processes, sensitive data, customer interactions, and regulatory obligations. 

Third-party risk is not limited to procurement or third-party risk management. The IIA specifically identifies a broad range of potential third-party risks, including strategic, reputational, ethical, operational, financial, compliance, cybersecurity, information technology, legal, sustainability, and geopolitical risks. For many organizations, these risks can affect financial reporting, operations, data protection, customer trust, regulatory compliance, and business continuity. For regulated industries, these risks can also intersect with supervisory expectations and contractual obligations. 

The IIA’s Third-Party Requirement gives internal audit teams a common baseline for evaluating these risks. It also creates a documentation expectation: Internal auditors must assess applicability, determine which requirements apply based on risk and scope, and retain the rationale for any exclusions. 

One Likely Challenge & its Recommended Solution

Understanding the requirements may not be the most difficult part of implementation; applying them consistently at both the annual audit planning level and the engagement level will. 

As such, organizations should consider significant third-party relationships during the annual risk assessment and audit planning process. Once an engagement is selected, internal audit should then determine which individual requirements apply based on the engagement objective, scope, and risk assessment. 

For Example

Consider, for example, an engagement to assess data storage that initially appears unrelated to third-party risk. If internal auditors learn that a third party provides cloud services and identify cybersecurity risks related to that third party, the IIA states that auditors must review both the Cybersecurity Topical Requirement and Third-Party Topical Requirement to determine which requirements apply. While the scope of the engagement may ultimately focus on third-party controls over the services being audited, auditors must nevertheless document their rationale for excluding any requirements of the Third-Party or Cybersecurity Topical Requirements. 

How Internal Audit Teams Can Comply with the Topical Requirement 

A practical approach to compliance starts with the annual risk assessment and internal audit plan, then continues through engagement-level planning and scoping. For each planned internal audit engagement, your organization must ask the following: Does this process engage a third party to help achieve one or more objectives? 

If so, document your assessment and rationale for whether each requirement applies and document the rationale for excluding any requirements.  

Your Takeaways 

  • The IIA Third-Party Topical Requirement is effective Sept 15, 2026, and is mandatory for those that adhere to the IIA Standards.  
  • For IIA functions that do not fully conform to the IIA Standards, the Third-Party Topical Requirement is still strongly recommended as a leading practice.  
  • The requirement establishes a minimum baseline for evaluating third-party governance, risk management, and control processes. 
  • Third-party risk should be assessed across the full life cycle: selecting, contracting, onboarding, monitoring, and offboarding. 
  • Internal audit teams should prioritize third parties based on risk, including downstream subcontractors where relevant. 
  • Applicability and exclusion decisions should be documented and retained in the audit plan or engagement work papers. 
  • Organizations with mature third-party risk management programs can use the requirement to validate existing practices and identify potential gaps in board reporting, risk ranking, monitoring, documentation, and offboarding. 
  • Additional topical requirements are coming, so ensure your internal audit function is aware of the effective dates and requirements.  

Need Help Navigating the Requirement? 

Rehmann’s Risk Advisory team can help organizations translate the IIA’s Third-Party Topical Requirement into a practical, scalable internal audit approach. Whether your organization needs support with gap assessments, audit methodology updates, engagement scoping, documentation templates, or internal audit execution, we can help you evaluate third-party risk with clarity and confidence. Learn more or reach out here. 

Frequently Asked Questions 

Q: Does every vendor relationship now require a full third party risk assessment?
A: No. The requirement applies based on the engagement scope and risk assessment. Internal auditors should identify third-party involvement, determine which requirements are relevant, and document the rationale for any exclusions. 

Q: Is the requirement limited to direct vendors?
A: No. The requirement can extend to subcontracted or downstream vendors when those relationships are allowed by the primary third-party contract or agreement and are relevant based on risk. 

Q: What is the biggest implementation challenge?
A: The biggest challenge is often applying the requirement consistently across annual planning, engagement scoping and documentation. Internal audit teams should avoid treating the requirement as a generic checklist and instead use risk assessment, professional judgment, and clear documentation to support scope decisions. 

Q: How should organizations get started?
A: Start with the annual risk assessment by identifying significant third-party relationships that support critical processes, sensitive data, regulatory obligations, or material business objectives. Then update engagement-level planning procedures so audit teams consistently assess applicability and document their rationale. 

Q: What should internal audit leaders do before the requirement becomes effective?
A: Internal audit leaders should review their audit universe, risk assessment process, third-party coverage history, and engagement planning templates to determine whether the requirement is built into both annual planning and engagement-level documentation. 

Q: What other regulatory changes are expected from the IIA in the near future?   

A. The Cybersecurity Topical Requirement, which became effective Feb. 5, 2026, was the first in the IIA’s series of new frameworks designed to reshape internal audit approaches. Additional requirements include Organizational Behavior (effective Dec. 15, 2026) and Organizational Resilience (effective April 30, 2027)There are no effective dates yet issued for the upcoming Talent Management Topical Requirement or Anti-Corruption Topical Requirement, though the IIA states that the latter will be issued in the fourth quarter of 2026. 

Note: This article is provided for informational purposes. For more, see The Institute of Internal Auditors’ explanation of the Third-Party Topical Requirement and its related user guide. 

Continue the discovery: