Topical Requirements and Quality Assurance: A CIA Part 3 Guide
Introduction
Under the Institute of Internal Auditors' (IIA) Global Internal Audit Standards (effective January 9, 2025), the quality of an internal audit function depends on two things. It must follow the Standards, and it must apply the Topical Requirements when they are relevant. The Quality Assurance and Improvement Program (QAIP) is how the function shows it has done both. For CIA Part 3, you need to know how these pieces connect: what Topical Requirements are, when they apply, and how quality assessments evaluate conformance with them.
Why It Is Important
1. Consistency on high-risk topics. Some risk areas, such as cybersecurity, are common to most organizations and often poorly audited. Topical Requirements set a minimum baseline, so stakeholders can trust that core aspects were evaluated whoever performed the audit.
2. Credibility of conformance claims. A function may state that it conforms with the Standards only if the QAIP supports that claim. Because Topical Requirements are mandatory, ignoring an applicable one undermines that statement.
3. Board and senior management confidence. Under Principle 8 (Overseen by the Board), the board relies on the chief audit executive (CAE) to report quality results. These results include whether Topical Requirements were properly applied.
4. Continuous improvement. Under Principle 12 (Enhance Quality), quality assurance is more than compliance. It drives better methods, staff competence and audit coverage.
What It Is
The IPPF structure. The International Professional Practices Framework (IPPF) has three components:
• Global Internal Audit Standards (mandatory)
• Topical Requirements (mandatory)
• Global Guidance, such as Practice Guides and GTAGs (recommended, not mandatory)
Topical Requirements. These are mandatory minimum requirements for auditing specific risk areas. Key features:
• The first was the Cybersecurity Topical Requirement, released in 2025 and effective February 5, 2026. Others, such as third-party risk management and organizational behavior, have followed or are in development.
• Each one is organized around three areas: governance, risk management and control processes related to the topic.
• Each comes with a User Guide, which offers practical help but is not mandatory.
• They support the Standards and do not replace them. Auditors still apply the Standards to plan, perform and communicate engagements.
Quality Assurance and Improvement Program (QAIP). The QAIP covers all aspects of the internal audit function. Its main parts are:
• Internal assessments (Standard 12.1). These include ongoing monitoring, such as engagement supervision, review of workpapers, checklists and performance metrics. They also include periodic self-assessments.
• Performance measurement (Standard 12.2). This uses objectives and key performance indicators to track the function's effectiveness.
• Engagement oversight (Standard 12.3). The CAE ensures engagements are supervised and quality is built into the work.
• External quality assessment (EQA) (Standard 8.4). This must happen at least once every five years. It is done either as a full external assessment or as a self-assessment with independent validation. The assessor or team must be qualified and independent, and at least one member must hold an active CIA designation. The board oversees the EQA, including discussing its scope, frequency and assessor selection.
• Board involvement (Standard 8.3). The CAE must communicate quality results, action plans and any nonconformance to the board and senior management.
How It Works
Step 1: Risk assessment and planning. When building the risk-based internal audit plan, the CAE considers whether topics covered by a Topical Requirement are significant to the organization. Topical Requirements do not require the function to audit every topic. They only govern how a topic is audited once it is in scope.
Step 2: Determining applicability. A Topical Requirement applies in three situations:
• The topic is the subject of an assurance engagement in the audit plan.
• The topic is identified as a significant risk during an engagement.
• An engagement on the topic is requested but was not in the original plan.
For advisory engagements, applying Topical Requirements is recommended but not required.
Step 3: Applying the requirement. The engagement work program addresses each required element across governance, risk management and controls. If some elements are judged not applicable, the auditor must document the rationale for excluding them.
Step 4: Documentation. Workpapers must show:
• how applicability was determined
• which requirements were addressed
• why any were excluded
This documentation is the evidence quality reviewers will examine.
Step 5: Quality assessment. Conformance with Topical Requirements is evaluated through the QAIP in two ways:
• Internal assessments, through supervision and periodic reviews.
• External assessments, where assessors check whether applicable Topical Requirements were identified, applied and documented.
Step 6: Reporting and improvement. The CAE reports quality results to the board and senior management. If nonconformance affects the overall scope or operation of the function, its impact must be disclosed, along with corrective action plans. The conformance statement may be used only when it is supported by QAIP results.
Common Misconceptions
• Myth: Topical Requirements force the function to audit cybersecurity every year.
Reality: Coverage is driven by the risk assessment. The requirements apply only when the topic is in scope.
• Myth: Topical Requirements are guidance.
Reality: They are mandatory. The User Guides and Global Guidance are not.
• Myth: Every element must always be tested.
Reality: Elements may be excluded with documented justification.
• Myth: The QAIP is only the five-year external review.
Reality: It also includes ongoing monitoring and periodic self-assessments.
Exam Tips: Answering Questions on Topical Requirements and Quality Assurance
1. Identify the trigger. Ask whether the topic is in scope of an assurance engagement, emerged during one, or was requested. If so, the Topical Requirement applies. If the question describes an advisory engagement, applying it is recommended, not required.
2. Mandatory versus recommended. The Standards and Topical Requirements are mandatory. Practice Guides, GTAGs and User Guides are recommended. Eliminate answers that treat guidance as binding, or Topical Requirements as optional.
3. Documentation is usually the answer. When a scenario describes excluding parts of a requirement, the correct response is almost always to document the rationale. It is not to apply everything regardless, and not to silently skip elements.
4. Memorize the key numbers and roles.
• EQA at least every five years.
• The assessor must be qualified and independent, with at least one active CIA on the team.
• The board oversees the EQA and receives quality results.
• The CAE owns the QAIP.
5. Internal versus external. Ongoing supervision and workpaper review are internal assessments. Self-assessment with independent validation counts as an external assessment. Watch for distractors that confuse the two.
6. The conformance statement. Choose answers stating that conformance may be claimed only when supported by QAIP results. Significant nonconformance must be disclosed to the board and senior management.
7. Risk-based coverage. If an option says Topical Requirements mandate auditing the topic regardless of risk, it is likely wrong.
8. Use the three-area framework. When asked what a Topical Requirement covers, think governance, risk management and control processes.
9. Read for the best answer. CIA questions often have several plausible choices. Prefer the one that reflects professional judgment, documentation, board communication and continuous improvement over purely mechanical compliance.
Summary
Topical Requirements set mandatory minimum expectations for auditing specific high-risk areas once they are in scope. The QAIP, through internal assessments, performance measurement, engagement oversight and external assessments at least every five years, verifies that these requirements and the Standards are followed. For the exam, focus on four things: applicability triggers, documenting exclusions, the mandatory status of Topical Requirements, and the roles of the CAE and the board.