IIA Third-Party Topical Requirement: What Vendor Management and TPRM Leaders Need to Know

The IIA’s Third-Party Topical Requirement takes effect September 15, 2026, and it will change how your vendor and TPRM program gets audited. Internal audit functions performing any assurance engagement that touches third-party risk are required to follow it. That means the organizations that understand what it demands before it goes live will be in a fundamentally different position than those that find out during an audit.

In plain terms: the Third-Party Topical Requirement is a mandatory internal audit standard that sets one consistent baseline for how auditors assess third-party risk, across three domains, governance, risk management, and lifecycle controls. When third-party risk shows up in an assurance engagement, conformance is required, not optional.

What is the IIA Third-Party Topical Requirement?

The Third-Party Topical Requirement is one of a series of mandatory standards that fall under the IIA’s International Professional Practices Framework (IPPF), which was overhauled in 2024. Topical Requirements establish a consistent baseline for how internal auditors must approach specific risk areas. They are not advisory guidance. When a covered topic appears in an assurance engagement, conformance is required.

The Third-Party Topical Requirement is the second issued, following the Cybersecurity Topical Requirement, which became effective in February 2026. It covers three domains:

  • Governance: how your organization makes decisions about third-party relationships, defines accountability, and communicates risk to relevant stakeholders.
  • Risk management: how third-party risks are identified, assessed, prioritized, and managed across a defined set of categories, including operational, cybersecurity, financial, compliance, legal, sustainability, and geopolitical risk.
  • Lifecycle controls: how your organization manages third parties across the full engagement lifecycle: selection, contracting, onboarding, monitoring, and offboarding.

You can access the full requirement and user guide directly on the IIA’s Third-Party Topical Requirement page.

Why Third-Party Risk Is Under Internal Audit’s Microscope

Third-party risk management has been on the radar of regulators, auditors, and risk professionals for years. What’s changing is the environment around it.

  • The overall growth in outsourcing has created vendor ecosystems that are larger, more complex, and harder to govern than they were a decade ago.
  • Supply chain disruptions and geopolitical instability have made third-party dependencies more visible and more consequential.
  • Cybersecurity incidents tied directly to vendor access and third-party relationships have increased in both frequency and impact.
  • AI integration into third-party products and services has introduced a new and largely uncharted risk category, with most organizations having limited visibility into how AI is embedded in the tools and services they rely on every day.
  • Distributed management across business units has created silos, inconsistent oversight, and risk exposure that is difficult to see and harder to manage.

The IIA’s response was to establish a mandatory set of standards defining how internal auditors assess third-party management. In turn, it sets clear expectations and accountability for how third parties are managed and governed across the enterprise.

How the Requirement Fits the IIA’s Bigger Rollout

The Third-Party Topical Requirement isn’t the only set of requirements that procurement, TPRM, and vendor management practitioners need to understand. The IIA is issuing Topical Requirements in rapid succession, and several share a direct thread to third-party management. Here is a breakdown of the ones so far.

Cybersecurity Topical Requirement, effective February 5, 2026. This requirement covers cybersecurity governance, risk management, and controls. For practitioners, the third-party thread runs through all three domains: vendors are explicitly identified as stakeholders in cybersecurity governance, supply chain is included in risk management scope, and organizations are required to ensure vendor-based controls are in place and the appropriate evidence is reviewed.

Organizational Behavior Topical Requirement, effective December 15, 2026. This requirement covers behavioral governance, risk management, and controls. From a third-party management perspective, auditors will be looking at how vendor decisions are made, who has accountability for them, whether conflicts of interest are identified and managed, and whether incentive structures are driving the right behaviors across procurement and supplier relationships.

Organizational Resilience Topical Requirement, expected April 2027. This requirement is still in development. Based on what the IIA has published, it will focus on an organization’s ability to withstand and recover from significant disruptions. For practitioners, third-party dependencies, vendor concentration risk, and supply chain continuity will be central to how programs are assessed.

Taken together, these requirements establish a consistent, mandatory baseline for how third-party management practices will be assessed going forward. The organizations that treat these requirements as an opportunity to build more mature programs will be better positioned than those that treat each effective date as a one-time compliance event.

Start Assessing Where You Stand

The subjectivity that characterized past audits is being replaced by defined expectations that apply across every engagement. For practitioners, that means gaps that informal or siloed programs have been able to avoid are going to surface. That starts with an honest look at where your program stands against what the requirement demands across governance, risk management, and lifecycle controls.

We have seen how this plays out. When a hard cybersecurity compliance deadline landed on Legal & General America, a life insurer we worked with, they did not treat it as a one-time exercise. They stood up a vendor management office in about six months, ran one program across all their vendors, and kept maturing it well past the deadline. The deadline was the forcing function. The program was the point.

Vendor Centric is publishing a series of articles designed to help practitioners understand the requirements and self-assess where their programs stand. Each article breaks down a specific area of the requirement in practical terms so you know what is expected and where to focus.

Subscribe to Vendor Centric and walk away knowing exactly what the requirement demands and what you need to do.

Frequently Asked Questions

When does the IIA Third-Party Topical Requirement take effect?

September 15, 2026. From that date, any internal audit assurance engagement that touches third-party risk has to conform to it.

Who does the Third-Party Topical Requirement apply to?

Directly, it applies to internal audit functions. In practice, it sets the bar your vendor management, procurement, and TPRM program will be assessed against, so those teams have as much reason to understand it as audit does.

What are the three domains it covers?

Governance, risk management, and lifecycle controls. Together they cover how third-party decisions get made, how third-party risk is assessed and prioritized, and how vendors are managed from selection through offboarding.

Is the Topical Requirement mandatory or just guidance?

Mandatory. Topical Requirements are not advisory. When a covered topic appears in an assurance engagement, conformance is required.

How does it relate to the Cybersecurity Topical Requirement?

It is the second Topical Requirement the IIA has issued, after Cybersecurity (effective February 2026). Cybersecurity threads through third-party risk, but this requirement covers the full third-party program across all three domains.

Share This Article

Stay Connected

Subscribe to
Vendor Centric

Level Up Your Game

Build stronger vendor relationships, reduce risk, and improve your bottom line.

More on This Topic