ComplianceJuly 29, 2026

The IIA Topical Requirement for Organizational Resilience: Internal audit’s next challenge

Organizational resilience has moved from a business continuity topic to a board-level risk issue. The past several years has shown how quickly organizations can be disrupted by cyberattacks, geopolitical conflict, supply chain failures, technology outages, workforce instability, regulatory change, and reputational crises. Disruption is no longer an exceptional event. Prepared organizations understand that disruption is part of normal operations.

As with other major risk areas, the IIA has released the Topical Requirement for Organizational Resilience. The requirement provides a consistent baseline for internal auditors when assessing the design and implementation of governance, risk management, and control processes related to organizational resilience. The IIA defines organizational resilience as an organization’s ability to absorb and adapt in a changing environment. In practical terms, that means an organization must be able to continue delivering critical products and services, maintain stakeholder trust, and adapt to survive when conditions shift unexpectedly.

For internal audit, the IIA Topical Requirement for Organizational Resilience should be viewed as an opportunity to evaluate whether the organization can continue delivering its most important services when disruption occurs. Auditors are required to look beyond traditional business continuity plans and ask difficult questions about governance, dependencies, decision-making, recovery capability, crisis response, and accountability.

Organizational resilience is more than business continuity

Many organizations already believe they are resilient because they have business continuity plans, disaster recovery procedures, insurance coverage, and crisis communication templates. These items are important, but they do not automatically create resilience. A plan that has not been tested under realistic conditions may fail when it is needed. A recovery time objective that was never aligned to business impact may create false confidence. A supplier continuity questionnaire may not reveal whether a critical third party can perform during a regional disruption. A crisis management team may exist on paper but lack the authority or information needed to make timely decisions. Even insurance policies can fail when management has not taken sufficient steps to ensure resilience.

The IIA Topical Requirement for Organizational Resilience pushes internal audit to evaluate resilience more holistically. The guide asks whether resilience is governed, risk-assessed, controlled, tested, and whether management is committed to improvement. Resilience is not owned by one department. It cuts across operations, technology, finance, legal, compliance, human resources, procurement, communications, and executive leadership.

Organizational disruption has become more interconnected. For example, a cyberattack can lead to an operational outage. An operational outage can become a customer service issue. A customer service issue can become a regulatory or reputational problem. A third-party failure can affect financial reporting, customer commitments, product delivery, and compliance obligations at the same time.

When resilience fails, it is usually because the organization did not understand its critical dependencies, did not escalate information quickly enough, did not test realistic scenarios, or did not assign clear ownership for decisions that had to be made under pressure.

Governance: Resilience must be owned before the crisis

The first area organizations should focus on is governance. Effective resilience starts with defining who is responsible for setting expectations, approving priorities, monitoring readiness, and responding when disruption occurs. Boards and senior leaders do not need to manage every operational detail, but they do need visibility into the organization’s most critical services, the risks that could disrupt them, and the level of disruption the organization is willing or able to tolerate.

Many organizations will find that resilience governance is fragmented. Business continuity may sit in operations. Disaster recovery may sit in IT. Third-party risk may sit in procurement or compliance. Cyber resilience may sit with the CISO. Crisis communications may sit with legal or public relations. Enterprise risk management may maintain a risk register, but that register may not connect directly to operational recovery capability.

Each function may be doing reasonable work within its own lane, but no one may be looking across the full resilience picture. Internal audit can add value by testing whether governance structures connect these efforts. The IIA Topical Requirement for Organizational Resilience also emphasizes the need for a formal organizational strategy that addresses a unified approach to resilience.

Resilience reporting should be presented in risk terms to help leadership understand where the organization is prepared, where it remains exposed, and where residual risk exceeds appetite. Reporting should connect resilience objectives to critical business activities, known vulnerabilities, unresolved remediation items, testing results, resource needs, and emerging threats. A board does not need every operational detail, but it does need a clear view of whether management’s resilience capability matches the organization’s risk profile.

Internal audit should evaluate whether the board receives enough information to provide effective oversight. A mature organization should be able to explain which services are most critical, which dependencies support those services, how recovery capabilities have been tested, what gaps remain, and what decisions require board or executive attention.

Risk management: Resilience depends on understanding what matters most

Organizational resilience depends on understanding what must be protected, what can fail, and how failure would affect the organization’s objectives. Risk management’s traditional assessments may not go far enough because they often evaluate risks by category rather than by operational dependency.

A resilience-focused assessment should identify critical business services, supporting processes, technology platforms, data flows, facilities, people, suppliers, and regulatory obligations. It is not enough to know that a system is important. The organization must understand what service relies on that system, what upstream and downstream processes are affected, what manual alternatives exist, and how long the business can operate without it.

Internal audit should expect challenges in this area because dependency mapping is difficult. Many organizations do not have a complete view of how processes, systems, data, and third parties connect. Documentation may be outdated. Business owners may understand their own workflows but not the technology or suppliers that support them. IT may understand infrastructure but not the business impact of downtime. Procurement may maintain contracts but not operational recovery details.

Internal audit can help by assessing whether resilience risks are periodically identified, assessed, managed, and mapped to strategic objectives. The organization should be able to show how resilience risks are evaluated across operations, technology, supply chain, facilities, human resources, finance, legal, compliance, and other relevant areas. The process should also include clear accountability for monitoring risk levels and escalating issues when risk exceeds tolerance.

Control processes must be operationally credible

The next area is control processes. Resilience controls include the policies, procedures, systems, tests, monitoring activities, and corrective actions that allow the organization to prepare for and respond to disruption. These controls may include business continuity plans, disaster recovery plans, backup processes, incident response procedures, crisis management protocols, emergency communication tools, supplier contingency plans, manual workaround procedures, training programs, and post-incident review processes.

The challenge for internal audit is to evaluate whether these controls are operationally credible. A control should not be considered effective simply because a document exists. Internal audit should assess whether plans are current, approved, accessible, aligned to business impact analyses, and tested. Testing should go beyond tabletop conversations that confirm everyone knows the plan. Mature organizations test decision-making, handoffs, data recovery, alternate processing, communication channels, and third-party dependencies through live simulation. They also track issues identified during exercises and confirm that corrective actions are completed.

View a demo

Technology resilience deserves specific attention

Technology resilience deserves special focus because many organizations have become more dependent on cloud platforms, integrated applications, automation, artificial intelligence, and third-party software. These capabilities create efficiency, but they also increase concentration risk. A failure in one platform can cascade across customer service, financial reporting, logistics, compliance, and management reporting.

Internal audit should evaluate whether recovery strategies reflect current technology architecture, not legacy assumptions. For example, a vendor may claim a 4-hour window for restoring an application, but in reality, they may take several days. Backups, access controls, change management, monitoring, and restoration testing all become part of the resilience conversation. The organization should understand which technology assets are critical to operations and whether those assets can be recovered within timeframes aligned to business needs.

Third-party resilience is now part of organizational resilience

Third-party dependency is one of the most important resilience risks facing many organizations. Critical services often depend on suppliers, outsourced service providers, cloud platforms, logistics partners, consultants, payment processors, data providers, and other external parties. When one of those parties fails, the organization may still be accountable to customers, regulators, investors, and employees.

The IIA Topical Requirement for Organizational Resilience expects organizations to identify critical third-party providers and determine the minimum inventory levels or alternate supplier arrangements needed to sustain essential operations. This will be a challenge for organizations that treat third-party risk primarily as a contracting or onboarding process.

Resilience requires an ongoing operational view. The organization should understand which vendors support critical services, whether those vendors have credible continuity capabilities, what contractual recovery expectations exist, whether alternate suppliers are available, and how quickly the organization could transition if needed. Internal audit should evaluate whether third-party resilience is incorporated into broader resilience planning rather than managed as a separate compliance exercise.

Organizations should prepare before the requirement becomes urgent

Chief audit executives should not wait to begin preparing for the IIA Topical Requirement for Organizational Resilience. Internal audit functions should review the requirement and user guide, compare them to current audit methodology, and determine how resilience considerations will be incorporated into audit planning, engagement scoping, work programs,

The IIA Topical Requirement for Organizational Resilience arrives at the right time. Organizations are operating in an environment where disruption is expected, interconnected, and often fast-moving. Internal audit has an important role to play because resilience is not just about response. It is about governance before the event, risk management before the failure, controls before the crisis, and learning after the disruption.

Preparing for the requirement will take time. Organizations will need to clarify ownership, improve dependency mapping, strengthen scenario analysis, test recovery capabilities, mature third-party resilience oversight, and improve reporting to senior management and the board. Internal audit functions will need to update methodologies, train auditors, and determine when and how the requirement applies across the audit plan.

The organizations that benefit most from the new requirement will be those that use it as a catalyst for better conversations. They will ask what services matter most, what could stop those services from operating, how much disruption the organization can tolerate, and whether current capabilities are strong enough to meet that expectation. They will recognize that resilience is not proven by a plan sitting in a folder. It is proven by the organization’s ability to make decisions, adapt, recover, and continue serving stakeholders when conditions are difficult.

For internal auditors, that is the real opportunity. The IIA Topical Requirement for Organizational Resilience gives the profession a clearer baseline, but the value will come from how auditors apply it. A thoughtful audit will not only confirm whether required elements exist. It will help leaders understand whether the organization is prepared for the disruption it is most likely to face next.

Subscribe below to receive monthly Expert Insights in your inbox

Missing the form below?

To see the form, you will need to change your cookie settings. Click the button below to update your preferences to accept all cookies. For more information, please review our Privacy & Cookie Notice.

For auditors who are challenged to improve audit productivity while delivering strategic insights, TeamMate provides expert solutions, delivered with premium professional services, to auditors around the globe and in every industry.
Back To Top