The Cybersecurity Topical Requirement, incorporated into the International Professional Practices Framework for Internal Auditing, has been mandatory since 5 February 2026 for functions that declare conformance with the Global Internal Audit Standards. Many departments were already auditing information security controls, but this requirement formalizes a minimum scope that must be covered explicitly. This article explains what the requirement demands and how to plan its review.
What the Cybersecurity Topical Requirement is and why it is mandatory
Topical Requirements are IIA Global documents that complement the Global Internal Audit Standards with specific demands around a particular risk area. Cybersecurity was one of the first to be published, given the relevance and urgency of this risk across virtually all sectors.
Origin and effective date
The requirement was developed as part of the framework update process that accompanied the publication of the Global Internal Audit Standards in 2024, with an adaptation period that ended on 5 February 2026. From that date, certified functions must be able to demonstrate they apply it in their methodology.
Who it applies to within the International Professional Practices Framework
The requirement applies to every Internal Audit function that declares conformance with the Global Internal Audit Standards, regardless of sector. It does not replace a technical cybersecurity audit performed by information security specialists, but defines the level of assurance Internal Audit must provide over the governance and management of cyber risk.
What this requirement actually demands from Internal Audit
Evaluation of cybersecurity governance
Internal Audit must assess whether a clear governance structure exists over cybersecurity: who bears executive responsibility, how it is reported to the Board, and whether a cybersecurity strategy has been formally approved and reviewed on a defined schedule.
Evaluation of cybersecurity risk management
The requirement demands verifying that the organization identifies, assesses, and addresses cyber risks systematically, not just reactively after an incident. This includes reviewing whether the cybersecurity risk map is updated with adequate frequency and whether it is aligned with the risk appetite defined by the Board.
Evaluation of operational controls
Beyond governance and strategy, Internal Audit must obtain evidence of the effectiveness of specific controls: access management, incident response, backups and continuity plans, among others. This is where collaboration with technical specialists is often sought when the audit team lacks that internal competency.
How to plan the audit of the Cybersecurity Topical Requirement
Step 1: map the reference frameworks already adopted
Identify whether the organization already follows a framework such as NIST, ISO 27001, or a sector-specific scheme. The Topical Requirement does not impose a specific technical framework, so the audit must evaluate conformance against whichever framework the organization itself has chosen to adopt.
Step 2: maturity assessment against the chosen framework
Before detailed fieldwork, perform a maturity assessment to identify the areas of greatest gap relative to the reference framework. This allows the engagement scope to be prioritized toward the highest-risk controls, rather than reviewing the entire control catalog at the same depth.
Step 3: fieldwork on critical controls
Concentrate detailed testing on controls protecting the most critical assets: systems supporting essential processes, personal data, or financial information. Privileged access management and incident response plans are typically priority control points in this type of review.
Step 4: communicating to the Audit Committee
Cybersecurity findings must be communicated in language the Audit Committee can evaluate in terms of business risk, avoiding excessive technical detail that makes it harder for them to prioritize resources effectively.
Common mistakes when auditing this requirement
- Limiting the review to a point-in-time penetration test. The Topical Requirement also demands evaluating governance and risk management, not just the technical robustness of systems at a specific moment.
- Not verifying how frequently the risk map is updated. An outdated cybersecurity risk map can create a false sense of control over threats that have already changed.
- Delegating the entire audit to technical specialists without Internal Audit involvement in the governance assessment. The requirement demands an integrated perspective that combines both dimensions.
- Not reviewing coverage of third parties with access to critical systems. A significant proportion of cybersecurity incidents originate from vendors with remote access to the organization's infrastructure.
Key control point: if the organization's last cybersecurity maturity assessment is more than twelve months old, it is likely the risk map no longer reflects relevant threats that have emerged in that period.
An audit management and GRC platform allows keeping the cybersecurity risk map current, linking each evaluated control to its evidence, and generating alerts when a scheduled review approaches its due date, without relying on scattered manual tracking across different spreadsheets.
Cybersecurity Topical Requirement checklist
- Is there a formally approved cybersecurity strategy that is reviewed on a defined schedule?
- Is the cybersecurity risk map updated with a defined and documented frequency?
- Has a maturity assessment been performed against the reference framework adopted by the organization?
- Does the audit plan include testing of access management, incident response, and continuity?
- Is the cybersecurity risk associated with third parties accessing critical systems evaluated?
- Are findings communicated to the Audit Committee in business risk terms, not just technical ones?
Conclusion
The Cybersecurity Topical Requirement does not ask Internal Audit to become a technical security team, but it does require a structured evaluation of governance, risk management, and operational controls against whichever reference framework the organization has adopted. Meeting this requirement in a sustained way, with up-to-date and traceable evidence, is what distinguishes a function ready for the next External Quality Assessment from one that merely declares conformance on paper.