The IIA Global has published a new Topical Requirement on Organizational Resilience, which is now definitively incorporated into the International Professional Practices Framework for Internal Auditing, alongside the Global Internal Audit Standards and the other Topical Requirements already in force. Unlike traditional business continuity, this requirement demands evaluating the organization's genuine capacity to anticipate, withstand, and adapt to disruptions of any nature. This article explains what the requirement covers and how to plan its audit.
What the Organizational Resilience Topical Requirement is
Organizational resilience is the capacity of an organization to anticipate, prepare for, respond to, and adapt to incremental change and sudden disruptions in order to survive and prosper. The new Topical Requirement translates this definition into a set of concrete demands that Internal Audit must be able to evaluate and communicate to the Audit Committee.
Origin within the International Professional Practices Framework
This requirement joins the set of Topical Requirements that IIA Global has been publishing since the Global Internal Audit Standards took effect, including the Cybersecurity Topical Requirement already in force. Its publication responds to the increase in interconnected global risks, in which geopolitics, climate, and technological disruption coexist as factors that can affect any organization's continuity simultaneously.
Difference between organizational resilience and business continuity
Business continuity traditionally focuses on recovering critical processes after a specific incident, such as a technology failure or natural disaster. Organizational resilience is a broader concept that includes business continuity as one of its components, but also requires evaluating the organization's cultural, financial, and strategic capacity for adaptation in the face of disruptions for which no predefined recovery plan necessarily exists.
What the requirement demands from Internal Audit
Evaluating the anticipation capacity
Internal Audit must assess whether the organization has formal mechanisms for identifying emerging threats before they materialize: geopolitical risk monitoring, scenario analysis, and periodic review of critical dependencies, both internal and third-party.
Evaluating the response capacity
The requirement demands verifying that tested (not merely documented) response plans exist for the most relevant disruption scenarios identified by the organization. This includes reviewing who has authority to activate those plans and how quickly they can do so in practice.
Evaluating the adaptation and learning capacity
Beyond the immediate response, Internal Audit must assess whether the organization incorporates lessons learned after each real or simulated disruption, and whether those lessons translate into effective changes in processes, not just reports that are filed away without subsequent follow-up.
How to plan the organizational resilience audit
Step 1: identify the relevant disruption scenarios
Work together with the risk management area to build a map of plausible scenarios for the organization: from technology failures to supply chain disruptions, geopolitical events, or reputational crises. This map must be prioritized by likelihood and impact, not by data availability.
Step 2: review interdependencies between critical processes
A process may appear resilient in isolation but depend on a single vendor, a specific system, or a small team of individuals. Identifying these interdependencies is key to detecting single points of failure that are not always obvious in a surface-level analysis.
Step 3: evaluate exercises and simulations conducted
Request evidence of drills or crisis exercises conducted in recent periods: which scenarios were tested, what deficiencies were identified, and what corrective actions were implemented following those results. A response plan that has never been tested carries a much lower reliability than it appears to have on paper.
Step 4: communicate the actual level of preparedness to the Committee
Resilience reporting must avoid the false sense of security conveyed by a well-written but never-tested plan. Communicate to the Audit Committee the level of preparedness verified through evidence, clearly distinguishing it from preparedness that has only been declared by the responsible areas.
Common mistakes when auditing organizational resilience
- Confusing resilience with business continuity. Limiting the audit to reviewing a continuity plan leaves out the strategic and cultural adaptation dimension that the new requirement demands.
- Validating plans that have never been tested in practice. A documented and approved plan is not equivalent to a plan tested through real exercises.
- Not reviewing interdependencies with critical third parties. Many disruptions originate in a vendor or external partner, not in an internal process.
- Treating resilience as a one-off project rather than a continuous capability. The requirement expects evidence of continuous improvement, not a single isolated exercise.
Key control point: if the organization cannot show evidence of at least one drill or crisis exercise in the last period, it is unlikely to be able to demonstrate a real response capability in the event of a genuine disruption.
An audit management and GRC platform allows centralizing the disruption scenario map, linking each scenario to its response plan, recording evidence of exercises conducted, and tracking corrective actions, maintaining full traceability for the Audit Committee.
Organizational Resilience Topical Requirement checklist
- Is there a disruption scenario map prioritized by likelihood and impact?
- Have critical interdependencies with third parties and between internal processes been identified?
- Do response plans have evidence of exercises or drills conducted?
- Is there a formal process for incorporating lessons learned after each real or simulated disruption?
- Does reporting to the Committee distinguish between verified preparedness and preparedness that is only declared?
- Is the resilience assessment reviewed on a continuous basis or only at set intervals?
Conclusion
The Organizational Resilience Topical Requirement raises the bar beyond traditional business continuity, requiring Internal Audit to evaluate whether the organization can genuinely anticipate, withstand, and adapt to disruptions of very different natures. Meeting it in a robust way requires verifiable evidence of exercises, mapped interdependencies, and continuous learning, not just well-written plans that have never been put to the test.