What the IIA’s New Third-Party Topical Requirement Actually Requires
Starting September 15, 2026, internal auditors have a mandatory new standard for testing how organizations manage third-party relationships: the IIA's Third-Party Topical Requirement, part of its International Professional Practices Framework. If you run a supplier risk or third-party risk program, this is the first time your internal audit function has a formal, IIA-issued checklist to test it against. Know what's on it before someone hands it to you.
What the standard actually sets
The requirement lays out 17 requirements across three areas: four on governance, four on risk management, and nine on controls. Conformance is mandatory for internal audit assurance engagements and recommended for advisory work.
One control matters more than the rest for most TPRM teams. It calls for "an accurate, complete, and current listing of all third-party relationships." Not a list assembled once at onboarding. Not whatever procurement happens to track separately from what security tracks separately from what legal tracks. Accurate, complete, and current, all at once.
The document also addresses "verifying the reliability of the information provided," and it extends to downstream parties, such as the subcontractors your third parties rely on.
What it doesn't say
It's worth being precise here, since it's easy to read more into a new standard than it actually states. The IIA's document doesn't mention self-attestation. It doesn't mention AI. And it doesn't prescribe a specific method for verification, only that reliability gets verified. Anyone telling you the standard requires a particular tool or technology is filling in a gap the standard itself leaves open.
It's also worth noting where the standard's own example places that third-party listing: a centralized contract management system, not a dedicated supplier record. The requirement governs how internal audit tests your program. It isn't a mandate on what kind of system should hold the data, and it isn't a new regulation on your company directly.
We cover topics like this every week. Practical supplier management insights for procurement and supply chain teams. Get it in your inbox →
The gap most programs will find
Here's where it gets uncomfortable for a lot of teams. "Accurate, complete, and current" sounds simple until someone has to produce it on request. Most organizations run separate systems for onboarding, procurement, contracts, and security, and each one holds its own version of the third-party list. None of them fully agree with each other, and nobody owns reconciling them.
That's not a hypothetical gap anymore. Starting September 15, it's the exact thing an internal auditor can test for, using an IIA-issued standard instead of their own judgment call.
Closing the gap
This is precisely the kind of fragmentation a Trusted Golden Record is built to close: a single, verified record for each third party instead of separate, disagreeing versions spread across systems that were never built to reconcile with each other. It doesn't satisfy the governance and risk management requirements in the standard on its own, but it removes the specific gap in the inventory control that a lot of programs are about to discover they have.
If you want a structured way to see where your own program's gaps sit before an auditor finds them, that's exactly what TYS's supplier risk checklist is built to surface.
Take the Supplier Risk Checklist →
Primary source: The Institute of Internal Auditors, Third-Party Topical Requirement, effective September 15, 2026.