The thing that changes on September 15 is not that internal audit starts paying attention to third-party management. Audit has been looking at third-party risk for years. What changes is that the judgment behind that scrutiny stops being subjective. For the first time, there is a fixed, mandatory baseline for how your program gets measured.
In my first article in this series, I covered what the requirement is and where it came from. This one is about what it means for you specifically. Because while the requirement raises the bar on what’s expected from your program, it also hands you the opportunity you’ve been waiting for. Here is why.
There are finally defined standards behind your internal audit
For years, an auditor formed a view of your program based largely on their own experience and judgment, with no common standard to anchor it. Two auditors could look at the same program and reach different conclusions about whether it was sound, and both could defend the call. What was missing was a shared baseline.
The Third-Party Topical Requirement is that baseline. Every program is now measured against the same defined expectations, which makes the results far more comparable across engagements, business units, and audit cycles. Judgment still plays a role, as it always will in an audit. But the judgment now works from defined standards across governance, risk management, and lifecycle controls, rather than from whatever each auditor brings to the table.
What your third-party management program will be measured against
The third-party topical requirement is organized into three categories: governance, risk management, and lifecycle controls. Each one sets out specific expectations for how your program should operate, and together they cover the full arc of what auditors expect.
- Governance is about how your organization makes decisions on third-party relationships. Whether there is a documented strategy for how you engage third parties, whether roles and accountability are clearly defined, and whether risk gets communicated to the people who need to see it, including senior leadership and the board.
- Risk management is about how third-party risks get identified, assessed, and prioritized across a defined set of risk domains, including operational, financial, cybersecurity, compliance, legal, and geopolitical risk. The expectation is that risk drives how you allocate effort.
- Lifecycle controls cover how you manage a third party across the full relationship: selection, contracting, onboarding, monitoring, and offboarding. This is the operational core, and it is where the requirement expects your controls to hold up from the first day of a relationship through the last.
The smartest leaders recognize these requirements as best practice worth evolving toward. You’ll find the same principles running through the regulatory landscape and the major standards bodies, because they are what good looks like no matter who is doing the measuring. And together, they hand you leverage. Here’s what I mean.
The leverage you now have that you didn’t before
Leaders in procurement, TPRM and vendor management already know where their program is thin. The gaps are rarely a surprise. What has been hard is getting leadership to prioritize the fix and put real resources behind it.
Since internal audit reports functionally to the board through an audit committee, findings reach the top of the organization directly. That’s a new kind of visibility, and leverage, with the people that give you the backing and resources you’ve been needing.
You are no longer making the case on your own. Internal audit is making it for you.
Turning the new requirement into leverage
Expectations are higher now, and that is exactly what makes this a prime opportunity. The same requirement raising the bar is the one giving you the backing to meet it.
Here is what you can do to take advantage:
- Self-assess your program against the 17 standards within the three categories, governance, risk management, and controls, to see where you actually stand.
- Engage internal audit early where you can, so you understand how they plan to approach the requirement and how they intend to apply it.
- Build a plan from what you find and take it to leadership as the business case for the support and funding you need to close the gaps.
Work through those steps, and September 15 stops being a deadline you are bracing for. It becomes the reason your program finally gets the investment it has needed all along.
Start building your case by seeing where you stand.
Take our 10-minute self-assessment and walk away with a custom analysis of where your program stands, available immediately.