top of page

What TPRM Practitioners Need to Know About the IIA’s New Third-Party Topical Requirement

6 days ago
6 min read
What TPRM Practitioners Need to Know About the IIA’s New Third-Party Topical Requirement

A New Requirement Takes Effect September 15, 2026 

On September 15, 2026, the Institute of Internal Auditors’ (IIA) new Third-Party Topical Requirement goes into effect, establishing a consistent, mandatory framework for internal auditors conducting assurance engagements that involve third party management (TPRM).


For TPRM practitioners, the requirement provides greater clarity into what internal audit may examine and the types of practices, controls, and evidence organizations should be prepared to demonstrate.


The IIA has published two core documents:


Third-Party Topical Requirement – Provides the mandatory baseline of requirements internal auditors must follow when performing assurance engagements on third party management.


Third-Party Topical Requirement User GuideProvides guidance for implementing the requirement, including examples of evidence and controls internal auditors may consider.


Additional information is available on the IIA Third-Party Topical Requirement resource page.


Unlike a regulatory or industry-specific standard, the requirement establishes principles that can be applied across organizations and industries. Many align with existing regulatory guidance and established TPRM practices, while others extend beyond traditional TPRM activities into areas such as sourcing decisions and contract performance monitoring.


Why This Matters: A Professional Perspective 

I’ve worked in third party and vendor risk management for more than 20 years, working with more than 100 organizations across financial services, healthcare, pharmaceuticals, energy, and other highly regulated industries. That experience has given me the opportunity to see TPRM programs at very different stages of maturity, as well as how the audits evaluating those programs have changed over time.


Audits that once focused more narrowly on vendor due diligence and basic controls have expanded to examine how organizations govern third party relationships, manage risk across the lifecycle, and demonstrate that their processes are working as intended.


The IIA’s new Third-Party Topical Requirement reflects much of that evolution. It also brings greater attention to several challenges I’ve encountered across organizations and industries over the years.


With that perspective, here’s what TPRM practitioners should know about the new requirement, along with five areas that I believe deserve particular attention as organizations prepare.


What the Topical Requirement Is 

The Third-Party Topical Requirement is a mandatory component of the IIA’s International Professional Practices Framework.


When internal auditors perform an assurance engagement that addresses third party management, whether as part of a planned engagement or because third party risk becomes relevant during an audit, they are required to use the Topical Requirement as their framework.


Each audit will still reflect the professional judgment, scope, and priorities of the team conducting it, but the requirement provides a consistent foundation from which to work.


What Auditors Will Be Looking For 

The Topical Requirement contains 17 requirements organized into three categories: governance, risk management, and controls. Each category has defined criteria, supported by the User Guide with examples of evidence auditors may consider.


Third Party Governance, 4 Requirements 

Governance focuses on whether the organization has a formalized approach to third party management. This includes documented policies and procedures covering the full lifecycle of the relationship, clearly defined roles and responsibilities, and communication protocols that keep appropriate stakeholders informed.


Third Party Risk Management, 4 Requirements 

Risk management focuses on whether risk practices are standardized and comprehensive throughout the lifecycle. This includes how the organization identifies, assesses, prioritizes, and responds to third party risks, how issues are escalated and managed when they arise, and how risk information flows to leadership and oversight bodies.


Third Party Controls, 9 Requirements 

Controls focus on operational execution throughout the lifecycle, including sourcing, due diligence, contracting, onboarding, monitoring, corrective action protocols, and offboarding.


The requirements also address maintaining a complete, accurate, and current inventory of third party relationships, an area that can present practical challenges when third parties enter an organization through multiple channels.


Five Areas That Deserve a Closer Look 

Based on my experience with TPRM programs across industries and at different stages of maturity, there are five areas I would pay particular attention to when preparing for the new requirement.


1. Lifecycle-Based Framework 

Across organizations, third party management frequently spans multiple business functions, each with its own policies, processes, systems, and responsibilities. That can make it difficult to create a cohesive view of third party management across the enterprise.


The requirement calls for a formalized, documented approach that spans the full third party lifecycle. Organizations should consider whether activities across functions are sufficiently coordinated and whether policies, procedures, and responsibilities support a consistent enterprise approach.


2. Accurate, Documented Procedures 

Policies and procedures don’t always mature at the same pace. In many programs I’ve worked with, policies benefit from formal approval and regular review cycles, while the procedures supporting them may receive less attention over time.


Procedures should clearly define roles, accountability, and documentation requirements and accurately reflect how the organization operates today. That review is particularly important as processes and technologies change, including the adoption of AI-enabled solutions.


3. Communications and Reporting 

Reporting can remain difficult even for well-established TPRM programs. Often, what appears to be a reporting problem begins further upstream with the quality and consistency of the underlying data.


When third party data is captured by different functions without consistent fields, definitions, ownership, or collection practices, maintaining accurate and complete reporting becomes more difficult. Practitioners should consider both their reporting capabilities and the quality of the data supporting those reports.


4. Risk Domains Beyond Cyber 

Another pattern that has emerged over the years is the significant attention given to cybersecurity within third party risk programs. Regulatory requirements and established information security ownership have helped make cyber a well-defined component of TPRM in many organizations.


The Topical Requirement, however, addresses a much broader set of risks, including strategic, reputational, financial, legal, operational, and geopolitical risks. Organizations should consider whether these additional risk domains have appropriate ownership, assessment processes, and oversight within the broader third party management framework.


5. Accurate Third Party Inventory 

Maintaining an accurate third party inventory continues to be a practical challenge for many organizations. One reason is structural: third parties may enter through procurement, accounts payable, corporate cards, or direct relationships established by individual business units.


When those channels are not connected to a consistent process or system of record, gaps in the inventory can result. Organizations should evaluate whether they have clearly defined ownership, consistent processes for identifying and recording third parties, and a reliable system of record for third party relationships.


What TPRM Practitioners Can Do Now 

The IIA has provided internal auditors with a clear framework to work from. For TPRM practitioners, preparation can focus on three things:


  • Understand what's expected. Read the Topical Requirement and User Guide to understand the policies, practices and evidence auditors will look for. 

  • Evaluate your scope of operations. Focus on things you are responsible for within the third party management lifecycle and be honest about where you stand today. 

  • Coordinate with cross-functional peers. For those things outside your scope but within the Topical Requirement, work with your peers who own those activities to ensure responsibilities are clear, documented, and coordinated. Auditors will want to see a unified approach, not disconnected functions operating independently.


The new requirement does not mean every element of third party management needs to sit within the TPRM function. It does mean organizations should be able to demonstrate how responsibilities and activities work together across the lifecycle.


Starting that review now gives practitioners an opportunity to understand their current state, identify areas that may need attention, and coordinate with the other functions responsible for third party management before the requirement takes effect.

Author Bio

Tom Rogers
Tom Rogers

Founder and CEO of Vendor Centric


Tom Rogers is the Founder and CEO of Vendor Centric, a professional services firm that works exclusively with third-party and vendor management leaders to build, improve, mature and run their programs.  With over 20 years in the field, Tom has worked with over 100 clients across financial services, healthcare, pharma, energy, and other highly regulated

industries. He brings a practical, real-world perspective to helping leaders build operations that don't just hold up under scrutiny but actually deliver value.


Tom and his team built a free self-assessment tool that maps to all 17 standards within the IIA’s Third-Party Topical Requirement. It takes about 15-20 minutes to complete and gives you an interactive gap analysis as soon as you’re done, along with a downloadable report you can share with the colleagues you’ll need to work with to close the gaps. You can access the tool here.


You can connect with Tom on LinkedIn or reach him at trogers@vendorcentric.com.




Comments


bottom of page