Applying IIA Topical Requirements in Audit Planning: A Complete CIA Part 3 Guide
Overview
Topical Requirements are a mandatory part of the IIA's International Professional Practices Framework (IPPF). They sit alongside the Global Internal Audit Standards (effective January 9, 2025). They set a minimum baseline for how internal auditors assess specific high-risk topics, such as cybersecurity. For CIA Part 3, you must understand when these requirements are triggered, how they affect the risk-based internal audit plan and engagement planning, and how conformance is documented and evaluated.
1. Why It Is Important
- Consistency: Topical Requirements ensure that whenever internal audit covers a recognized high-risk topic, it covers the same core areas with the same rigor across organizations.
- Credibility with stakeholders: Boards and regulators can rely on a known minimum scope. For example, a cybersecurity audit will address governance, risk management and controls, not just technical settings.
- Mandatory conformance: Topical Requirements are mandatory, like the Standards. Nonconformance can affect the internal audit function's ability to state that it conforms with the Standards. It can also be identified in internal and external quality assessments.
- Better planning: They force the chief audit executive (CAE) to think deliberately about how emerging and pervasive risks are reflected in the audit universe and the plan.
- Exam relevance: Part 3 tests the CAE's management of the internal audit function, including building the risk-based plan (Standard 9.4) and engagement planning (Domain V, Standards 13.1-13.6). Questions increasingly ask how new IPPF elements change these activities.
2. What It Is
A Topical Requirement is a set of mandatory requirements for assessing a specific risk area. Each one typically contains:
- The Requirement: the minimum elements that must be evaluated, usually organized around governance, risk management and control processes.
- A User Guide: implementation guidance on applying the requirement.
- Examples of evidence of conformance: what documentation demonstrates that the requirement was applied.
The first Topical Requirement issued was Cybersecurity, released in February 2025 and effective February 5, 2026. Other topics, such as third-party management and organizational behavior, have been identified for future development.
Key characteristics:
- They establish a baseline, not a ceiling. Auditors may go further based on risk.
- They do not require the topic to be audited every year. The organization's risk assessment determines whether the topic is in the plan.
- They work with the Standards. Professional judgment, risk assessment and documentation requirements all still apply.
3. How It Works
a) When Topical Requirements apply
1. Assurance engagements: conformance is required when the topic is in the scope of an assurance engagement included in the internal audit plan.
2. Topic identified during an engagement: conformance is required when the topic is identified during an engagement that did not originally include it, for example cyber risks discovered during an operational audit.
3. Engagements requested outside the plan: conformance is required when the topic is in the scope of an assurance engagement added to or requested outside the original plan.
4. Advisory engagements: application is recommended or encouraged, but not mandatory.
b) At the internal audit plan level (Standard 9.4)
- The CAE performs the risk assessment of the audit universe. Topics covered by Topical Requirements should be considered explicitly in that assessment.
- If the risk assessment indicates the topic warrants coverage, the engagement is added to the plan. Its scope must then address the Topical Requirement.
- The CAE must make sure resources (Standard 10.2) include the competencies needed, for example IT or cybersecurity specialists. Options include training, co-sourcing or outsourcing.
- The CAE communicates the plan and resource needs to the board and senior management. This includes how high-risk topics are covered or why they are not.
c) At the engagement planning level (Standards 13.1-13.6)
- During the engagement risk assessment, map the scope to each element of the Topical Requirement (governance, risk management, controls).
- Set objectives and scope so that all applicable requirements are covered.
- Excluded requirements: if any requirement is excluded from scope, document the rationale. A partial-scope audit, such as one covering only incident response, is an example.
- Design the work program so evidence is gathered for each requirement.
d) Multiple engagements and coverage
A topic may be covered through several engagements across the plan cycle, for example cyber governance in one audit and access controls in another. The CAE should be able to show, in aggregate, how the requirements were addressed.
e) Documentation and quality assurance
- Workpapers should show that each applicable requirement was assessed, or that its exclusion was justified.
- The Quality Assurance and Improvement Program (QAIP, Standard 8.3/8.4) and external quality assessments evaluate conformance with Topical Requirements.
- Nonconformance must be considered when the function reports on conformance with the Standards.
f) Example: Cybersecurity Topical Requirement
- Governance: cybersecurity strategy and objectives, policies, roles and responsibilities, board oversight, and resources and competencies.
- Risk management: identification and assessment of cyber risks, risk ownership, response, escalation and monitoring, and third-party cyber risk.
- Control processes: design and effectiveness of controls such as access management, configuration, monitoring, incident response and recovery, and continuous improvement.
4. Common Misconceptions
- Wrong: "Topical Requirements mean we must audit cybersecurity every year." Right: the risk-based plan decides coverage. The requirements apply when the topic is in scope.
- Wrong: "They are optional guidance." Right: they are mandatory for assurance engagements in scope. The User Guide is the supporting guidance.
- Wrong: "They replace professional judgment." Right: judgment is still used to tailor scope, and any exclusions must be justified.
- Wrong: "Advisory engagements must fully conform." Right: conformance is recommended, not required.
Exam Tips: Answering Questions on Applying IIA Topical Requirements in Audit Planning
1. Identify the engagement type first. If it is assurance with the topic in scope, conformance is mandatory. If it is advisory, conformance is recommended. Many questions turn on this distinction.
2. Risk drives the plan. If an option says the CAE must include the topic in every annual plan regardless of risk, it is usually wrong. Choose the answer linking coverage to the risk assessment.
3. Look for documentation of exclusions. When a scenario describes a narrowed scope, the best answer usually involves documenting the rationale for excluded requirements.
4. Remember "topic discovered mid-engagement." If the topic emerges during fieldwork, the requirements apply to that coverage. The auditor should adjust scope or plan follow-up coverage, and communicate as needed.
5. Think about competencies. If the team lacks expertise, the CAE's responsibility is to obtain it through training, specialists or co-sourcing. Skipping the requirements is not an acceptable response.
6. Link to quality assurance. Questions about how conformance is verified point to the QAIP, internal assessments and external quality assessments.
7. Use the three-part structure. If asked what a cybersecurity engagement must address, choose the answer that spans governance, risk management and control processes, not just technical controls.
7. Distinguish mandatory from guidance. The Standards and Topical Requirements are mandatory. The Global Guidance and the Topical Requirement User Guides are recommended.
9. Choose the "best" answer. CIA questions often have several plausible options. Prefer the one that is risk-based, documented, communicated to the board and senior management, and consistent with the Standards.
10. Watch the dates. The Cybersecurity Topical Requirement became effective February 5, 2026, and the Standards became effective January 9, 2025. Questions may test whether a requirement was in force.
Quick Recap
Topical Requirements set mandatory minimum coverage for specific high-risk topics. They are triggered when the topic is within the scope of an assurance engagement. The CAE considers them during the risk-based plan (Standard 9.4), resourcing and engagement planning. Auditors map scope to the requirements and document any exclusions. Conformance is evaluated through the QAIP.