
The Institute of Internal Auditors' (IIA)'s first mandatory Thematic Requirement came into force in February 2026, with a focus on cybersecurity. In this article, Felipe Duarte, James Durrant, and Charley Wright explain what the requirement covers, how it applies, and what practical steps internal audit functions need to take to meet the new requirements.
Cybersecurity Thematic Requirement
The Cybersecurity Thematic Requirement is part of a wide-ranging reformulation of the International Professional Practices Framework (IPPF) and is the first to become mandatory. Together with the Global Internal Audit Standards, the thematic requirements establish a minimum basis for how specific high-risk areas should be assessed by internal audit functions.
Other thematic requirements are already in place, including third-party risk management (from September 2026), organizational behavior (from December 2026), and other topics throughout 2027.
These formalized expectations reflect the role of cybersecurity as a top concern for boards and audit committees, especially after a series of high-profile cyber incidents in the UK.
For example, the attacks suffered by British retailers in early 2025 resulted in empty shelves, unavailability of online sales, and disruptions that lasted for months. Subsequently, an attack on the automotive sector was considered the cyber incident with the greatest financial impact ever recorded in the UK, disrupting production and causing effects throughout the supply chain.
In both cases, third-party relationships appear to have been exploited as an entry point for attacks, in line with Verizon's finding that 30% of security breaches recorded in 2024 involved third parties, double the rate seen the previous year.
How will this requirement be enforced?
The Thematic Requirement applies in three situations:
- When cybersecurity is the subject of an internal audit or planned assurance engagement;
- When cybersecurity risks arise during an audit that originally did not focus on cybersecurity.
- When a cybersecurity assessment is requested outside of the original audit plan (for example, when the internal audit team is asked to review controls after a specific incident).
The breadth of this applicability is an important aspect of the new requirements. Internal auditors cannot treat the requirement as something relevant only to specific cybersecurity or technology audits, as it can become applicable to any internal audit that involves cybersecurity-related risks.
The professional judgment of the auditors should guide which parts of the thematic requirements are relevant to each engagement. Given the breadth of the requirements, not all requirements will apply to all audits. It is important to note that, whenever any requirement is excluded, a documented justification explaining this decision must be maintained.
"AI should be seen as a strategic topic that requires risk management, supervision, responsibility, and clear definition of roles and controls. More than implementing new technological solutions, it is essential to ensure that their use occurs in a safe, ethical and transparent way", says Felipe Duarte, IT Risk partner at Grant Thornton.
For most organizations, especially those with more extensive internal audit plans, compliance with thematic requirements can be demonstrated through several in-depth audits. The IIA makes it clear that there is no requirement for a single comprehensive cybersecurity review that can cover the full extent of the requirements. The IIA User Guide includes an optional documentation tool to help teams record these decisions and demonstrate how they are ensuring requirements are covered.
What the requirement covers
All Thematic Requirements are structured around three pillars, which align with the IIA standards as follows:
- Governance: Assessments should cover cybersecurity strategy, reports submitted to the board of directors, cybersecurity policies, related roles and responsibilities, as well as the engagement of the organization's senior leadership with emerging cybersecurity threats.Risk management: In this regard, audit coverage should include the identification of cybersecurity risks and the corresponding mitigation measures, the assessment of cyber risk management activities, risk escalation processes, and the testing of incident response capabilities.
- Controls: This is the most technical and detailed part of the thematic requirement, and probably the most familiar to auditors specializing in cybersecurity. It covers seven major areas related to cybersecurity. These areas include:
- Assessment of systems for confidentiality, integrity and availability;
- Cybersecurity talent management;
- Monitoring and reporting of threats and vulnerabilities;
- IT asset lifecycle management.
The final three parts of the controls pillar cover a wide range of technical areas, including encryption, patching management, access management, monitoring, DevSecOps, network security, and endpoint communications security. These final sections condense a potentially enormous amount of highly technical audit work into fairly comprehensive requirements.
It is important to note that the requirement is only intended to establish a minimum baseline for cybersecurity audits. For organizations that consider their cyber risk to be high, internal auditors are expected to go beyond the standards and assess areas that are not explicitly covered in the requirement.
AI Governance: Innovation with Safety
As the adoption of AI accelerates, so do the challenges related to security, data privacy, regulatory compliance, and cyber risks. The practical experience of organizations demonstrates that the benefits of AI are enhanced when accompanied by a robust governance structure, based on recognized frameworks and good market practices.
It is undeniable that Artificial Intelligence has significant potential to improve services, optimize internal activities, increase project efficiency, expand analytical capacity, and generate even more value for customers and organizations. While expanding the possibilities for innovation, technology also brings new challenges related to risk management, compliance, and information security.
In Duarte's experience, the consistent investment in the development and internal adoption of AI solutions, supported by structured governance, robust controls, and frameworks recognized by the market, has demonstrated in practice the benefits and challenges of this technology. "This accumulated experience strengthens our ability to support organizations at different levels of maturity in building governance models that drive innovation without compromising security and compliance," comments the expert.
In fact, the current debate no longer revolves around the adoption or not of Artificial Intelligence. Taking risks is part of the process, as long as they are properly managed. The real challenge lies in ensuring that this adoption occurs with proper accountability, security, and governance, allowing us to capture the benefits of innovation without exposing organizations to unnecessary risks or without proper management and control.
Common mistakes to avoid
Implementing IIA requirements can strengthen the organization's cybersecurity posture and provide senior management with greater security regarding existing controls. However, there are some key pitfalls that should be avoided to ensure that this work adds value across the company.
Treat cybersecurity as a compliance exercise
The IIA's guidance on thematic requirements specifically mentions the importance of avoiding treating cybersecurity as a periodic exercise of simple item checks. However, there is a real risk that internal audit teams will interpret the extensive and detailed requirements in this way. Cybersecurity is an ongoing and ever-evolving area of risk, and the IIA expects internal audit functions to continue to evolve their approaches to keep up with this scenario as well.
Not keeping up with evolving cyber risks
As anyone who has experienced real cybersecurity incidents knows, handling threats and responding to those incidents happen at a rapid pace, and information can quickly become obsolete. The broader cyber landscape also evolves almost daily, with the continued emergence of new threats and attack vectors. Audit functions will need to keep pace in their interaction with cybersecurity teams, ensuring that audit work is carried out at the appropriate time and addresses the risks actually present to the business.
Not considering the role of third parties and cloud providers
When significant dependencies on third parties or cloud services exist, vendor controls should be explicitly included in the scope of audits, not excluded. The IIA guidance makes specific reference to the review of Service Organization Controls (SOC) reports provided by third parties. In addition, the upcoming Thematic Requirement on third-party risk management will further increase the focus on managing these risks.
What do audit roles need to do?
For internal audit teams to meet the Cybersecurity Thematic Requirement, efforts will need to be focused on four key areas:
- Audit
planning Cybersecurity needs to be incorporated into the annual audit planning process, with the coverage of the Cybersecurity Thematic Requirement mapped between the different works foreseen in the internal audit plan. Where elements of the thematic requirements are addressed through a number of audit engagements throughout the year, this approach should be clearly documented to demonstrate that coverage has been adequately achieved. - Audit methodology
Existing audit testing programs may need to be updated to address, in a structured way, the three pillars of the Cybersecurity Thematic Requirement. Teams that already use recognized cybersecurity frameworks, such as NIST CSF 2.0, COBIT 2019, or NIST 800-53, will benefit from mapping the IIA Thematic Requirement to these widely adopted frameworks. - Audit training
trainingIt is certainly not necessary for all auditors to become cybersecurity experts. However, it will take an appropriate level of technical expertise to formulate the right questions and identify relevant cyber risks in all audit engagements. When the internal audit function lacks the technical skills necessary to perform more detailed assessments, the IIA recommends outsourcing the work or hiring external experts. - Audit documentation
Decisions related to the inclusion, and, perhaps even more importantly, the exclusion, of parts of the Cybersecurity Thematic Requirements must be supported by documented justifications. Quality assessors and regulators will expect evidence that decisions on coverage have been made deliberately and duly justified, and not simply by default or omission.
Conclusion
The introduction of the Thematic Requirements, starting with cybersecurity, represents a shift in the way the IIA defines organizations' obligations in relation to internal audit. Assurance on the most relevant risks for the business will no longer depend exclusively on the judgment of each team and will be increasingly guided by these mandatory standards.
When evaluating the Thematic Requirements, some internal audit functions may conclude that they already meet or even exceed the established requirements, especially those that are more mature and that conduct regular cybersecurity risk assessments.
In these cases, additional actions may not be necessary. For other organizations, however, the adoption of these requirements will represent a significant evolution in the breadth and depth of coverage of cyber risks.