Skip to Content

Topical Requirements

Depending on the results of the internal audit function’s risk assessment, internal auditors must apply Topical Requirements in conformance with the Global Internal Audit Standards when providing assurance services on the topic. Topical Requirements are recommended but not required for advisory services. Each Topical Requirement becomes effective 12 months after it is issued.

IPPF image

Each Topical Requirement is accompanied by a user guide to help internal audit functions implement the requirements. Both documents are available in multiple languages. The final publication results from the diligent work of the Global Guidance Council and IIA staff to follow a due process that includes public consultation and revision based on the feedback received. To read the details, download Report on the Development and Public Consultation Processes for the Cybersecurity Topical Requirement.