ComplianceJuly 22, 2026

The IIA’s Third Party Topical Requirement raises the bar for internal audit

Organizations have always relied on third parties to provide specialized products and services. Historically, those relationships centered on relatively straightforward outsourcing arrangements involving payroll processing, facilities management, or contract labor. The current operating environment is fundamentally different. Organizations increasingly depend on third parties to deliver a broad range of services, including mission-critical technology, cloud infrastructure, cybersecurity services, software development, artificial intelligence capabilities, logistics, customer support, and financial operations. As organizations expand their reliance and dependence on external providers, the associated risks become increasingly interconnected with their strategic, operational, financial, and regulatory objectives.

The Institute of Internal Auditors (IIA) recognized this shift with the release of the IIA Third Party Topical Requirement guidance. Rather than presenting another procurement or contract management checklist, the IIA Topical Requirement third-party framework establishes a mandatory baseline for internal auditors performing assurance engagements involving third-party relationships, much like the expectations set by the requirements for Cybersecurity and Organizational Behavior. The guidance requires auditors to evaluate governance, risk management, and control processes throughout the entire third-party lifecycle while applying professional judgment based on organizational risk.

The requirement, like all of the IIA’s Topical Requirements, represents an important evolution for the profession. Internal auditors have traditionally focused on verifying the existence of contracts, reviewing due diligence documentation, or confirming that service organization reports were obtained. Those activities remain important, but they no longer provide sufficient assurance regarding the effectiveness of an organization's third-party risk management program. Modern organizations require a broader assessment that evaluates whether management has established an effective governance framework capable of identifying, managing, and responding to risks throughout the duration of every significant third-party relationship.

The IIA’s Topical Requirement’s third-party risk definition

One of the most important aspects of the Topical Requirement is the breadth of its definition of a third party. The guidance encompasses vendors, suppliers, contractors, consultants, outsourced service providers, subcontractors, and other external organizations that provide products or services. The IIA Topical Requirement third-party guidance also recognizes that risk frequently extends beyond the organization's direct contractual relationships to downstream subcontractors, often referred to as fourth parties or even fifth parties.

Considering that the total supply chain is particularly important because modern business operations frequently involve layered outsourcing arrangements. A cloud software provider may rely on another organization for infrastructure hosting. A managed security service provider may subcontract specialized monitoring services. A payroll processor may depend upon multiple technology vendors to support payroll calculations, tax reporting, and payment processing. Although these downstream relationships may not be visible to the contracting organization, disruptions within those providers can directly affect business operations.

The Topical Requirement reinforces a principle that internal auditors should consistently communicate to management: outsourcing an activity does not outsource accountability. In other words, you cannot outsource risks related to your operations or controls for managing those risks. Organizations remain responsible for achieving their objectives regardless of whether operational activities are performed internally or by an external service provider. Third-party failures may create operational disruptions, financial losses, regulatory violations, cybersecurity incidents, or reputational damage, all of which ultimately remain the responsibility of the primary organization.

The entire life cycle requires oversight

Many organizations continue to approach third-party risk as a procurement exercise. Due diligence is performed before the contract is signed, required documentation is collected, and responsibility for oversight gradually diminishes until contract renewal. Such an approach fails to recognize that third-party risk changes continuously throughout the relationship.

The IIA Topical Requirement third-party framework organizes the third-party life cycle into five distinct stages: selecting, contracting, onboarding, monitoring, and offboarding. Each stage introduces unique risks requiring appropriate governance, risk management, and control activities.

Selection activities require management to justify why outsourcing represents the appropriate business decision and whether sufficient due diligence has been performed. Contracting establishes legal protections, service expectations, performance metrics, and risk allocation. Onboarding ensures the third party can effectively integrate with organizational processes while satisfying security, compliance, and operational requirements. Monitoring evaluates ongoing performance, identifies emerging risks, and determines whether contractual obligations continue to be satisfied. Offboarding addresses data protection, access removal, asset recovery, transition planning, and business continuity following termination of the relationship.

This lifecycle approach reflects the reality that third-party risk is dynamic rather than static. Financial conditions change, cybersecurity threats evolve, regulatory expectations increase, and organizational priorities shift. Relationships that presented acceptable risk several years earlier may require substantially greater oversight today.

Governance forms the foundation of effective third-party management

Many third-party audits begin with contract reviews or vendor testing. The Topical Requirement begins much earlier in the process by requiring auditors to evaluate governance.

The governance section requires organizations to establish a formal strategy for determining when third parties should be used, documented policies governing the entire third-party life cycle, clearly defined roles and responsibilities, and communication protocols supporting timely reporting of performance, compliance, and risk information to relevant stakeholders.

Governance establishes accountability throughout the organization by defining ownership for selecting vendors, approving contracts, performing risk assessments, monitoring performance, escalating issues, and communicating with executive management and the board. Organizations frequently experience control failures because responsibilities are fragmented across procurement, legal, compliance, information security, finance, and business operations without clear coordination.

Effective governance also requires collaboration across the Three Lines Model. Procurement, legal, information technology, information security, compliance, enterprise risk management, finance, and operational leadership all contribute unique perspectives regarding third-party risk. Internal audit provides independent assurance regarding the effectiveness of those collective governance activities rather than assuming ownership of operational responsibilities.

Risk management must reflect the organization's actual exposure

Cybersecurity has become synonymous with third-party risk management in many organizations. Security questionnaires, penetration testing, and SOC reports often receive considerable attention during vendor onboarding. Although cybersecurity remains critically important, the Topical Requirement recognizes that organizations face a much broader collection of risks arising from third-party relationships.

The guidance identifies strategic, reputational, ethical, operational, financial, compliance, cybersecurity, information technology, legal, sustainability, and geopolitical risks as considerations within an effective third-party risk management program.

Adopting this broader perspective encourages internal auditors to evaluate whether management has developed comprehensive risk assessment methodologies rather than narrowly focusing on information security. Financial instability within a critical supplier may create greater operational risk than a technical vulnerability. Regulatory enforcement actions involving a service provider may create compliance challenges. Political instability affecting a manufacturing region may threaten supply chain continuity. Ethical misconduct by an outsourced provider may significantly damage organizational reputation.

Comprehensive third-party risk management requires organizations to evaluate the full range of risks that could affect achievement of strategic objectives rather than concentrating exclusively on technology-related concerns.

View a demo

Risk-based prioritization is key to sustainability

Another significant strength of the Topical Requirement is its emphasis on risk-based prioritization. Organizations frequently struggle with determining the appropriate level of oversight for diverse third-party populations. Some organizations apply identical review procedures to every vendor regardless of criticality. Others rely primarily upon contract value as the determining factor for oversight. Neither approach adequately reflects organizational risk, and taking on too much work can undermine the risk management program.

The IIA encourages organizations to prioritize third parties based upon factors such as operational criticality, financial materiality, relationship complexity, duration, subcontracting arrangements, and the importance of the services provided. Risk assessments should evaluate both inherent and residual risk while supporting ongoing monitoring and reassessment throughout the relationship.

This expectation allows organizations to allocate oversight resources where they generate the greatest value. Critical cloud providers, managed security service providers, payment processors, enterprise resource planning vendors, and artificial intelligence providers frequently warrant substantially greater oversight than organizations providing routine administrative services. Internal auditors should evaluate whether management's prioritization methodology appropriately reflects actual business risk rather than relying upon arbitrary thresholds or historical practices.

Control activities extend well beyond contracting

The controls section of the Topical Requirement provides perhaps the most practical guidance for internal auditors. Rather than limiting evaluation to procurement documentation, the requirement establishes expectations across the full lifecycle of third-party management.

Organizations should maintain comprehensive due diligence processes supporting vendor selection, formal contracting procedures involving appropriate stakeholders, secure contract management, centralized inventories of third-party relationships, structured onboarding activities, ongoing performance monitoring, corrective action protocols, renewal management, and formal offboarding procedures.

The accompanying User Guide expands upon these expectations by discussing important control considerations including right-to-audit clauses, service level agreements, cybersecurity requirements, business continuity expectations, ethics provisions, downstream subcontracting, change management requirements, artificial intelligence usage, data protection obligations, and independent assurance reports such as SOC examinations.

These examples are valuable because they reflect the control weaknesses commonly identified during internal audits. Organizations often devote substantial effort to vendor selection while missing out on ongoing monitoring, contract administration, or termination planning. Internal auditors should evaluate whether management maintains effective oversight throughout the relationship rather than concentrating efforts solely during procurement.

Artificial intelligence further elevates third-party risk

Artificial intelligence introduces another important dimension to third-party governance. Most organizations are adopting externally developed AI platforms rather than building proprietary models. Consequently, AI governance increasingly depends upon effective third-party governance.

Finance departments use external AI platforms to analyze financial information. Human resources teams use AI to support recruiting activities. Customer service departments implement AI-enabled chatbots. Internal audit functions increasingly incorporate generative AI into audit planning, testing, and reporting.

Each of these relationships creates new considerations involving data privacy, intellectual property, cybersecurity, regulatory compliance, model governance, and operational resilience. The previously referenced User Guide specifically encourages organizations to consider artificial intelligence usage within contracting and ongoing monitoring activities, demonstrating the IIA's recognition that emerging technologies are becoming inseparable from third-party risk management.

Internal auditors should evaluate program effectiveness rather than documentation

Perhaps the greatest value of the Third-Party Topical Requirement lies in its underlying philosophy. Internal auditors should avoid approaching these engagements as documentation exercises designed merely to verify the existence of contracts, questionnaires, or approval signatures.

More meaningful assurance is achieved by evaluating whether governance structures function effectively, whether risk management processes adapt to changing conditions, and whether controls continue operating throughout the lifecycle of significant third-party relationships.

Questions regarding organizational resilience frequently provide greater insight than traditional control testing alone. Does management maintain visibility into critical downstream providers? Can the organization identify concentration risk across multiple vendors? Have exit strategies been established for mission-critical service providers? Are performance issues identified early enough to allow corrective action before significant operational disruption occurs?

Final thoughts

The IIA's Third-Party Topical Requirement reflects the reality that organizations increasingly depend upon external organizations to achieve their strategic objectives. Third-party relationships now influence operational performance, cybersecurity, financial reporting, regulatory compliance, business continuity, and organizational reputation. Internal audit must therefore evaluate these relationships with the same rigor applied to internal operations.

The requirement establishes a practical and comprehensive framework for evaluating governance, risk management, and control processes throughout the complete third-party lifecycle while preserving the professional judgment necessary to tailor engagements according to organizational risk.

Internal audit functions that embrace this broader perspective will provide significantly greater value than those limiting their work to procurement documentation or contract reviews. Effective third-party assurance requires evaluating whether management has established an integrated governance framework capable of identifying, prioritizing, monitoring, and responding to evolving risks across an increasingly complex network of external relationships.

Subscribe below to receive monthly Expert Insights in your inbox

Missing the form below?

To see the form, you will need to change your cookie settings. Click the button below to update your preferences to accept all cookies. For more information, please review our Privacy & Cookie Notice.

For auditors who are challenged to improve audit productivity while delivering strategic insights, TeamMate provides expert solutions, delivered with premium professional services, to auditors around the globe and in every industry.
Back To Top