Third-Party Topical Requirement takes effect, CIA testing starts no earlier than March 2027
The IIA's Third-Party Topical Requirement became effective on September 15, 2026, and under The IIA's six-month rule it cannot appear in scored CIA questions before March 15, 2027.
What happened in September
The IIA issued the Third-Party Topical Requirement on September 15, 2025. It became effective on September 15, 2026. Each Topical Requirement becomes effective 12 months after it is issued.
Topical Requirements are a mandatory part of the International Professional Practices Framework and are used together with the Global Internal Audit Standards. Conformance is mandatory for assurance services and recommended for advisory services. A Topical Requirement applies when the topic is the subject of an engagement in the internal audit plan, is identified while performing an engagement, or is the subject of a requested engagement that was not in the original plan.
When it reaches the CIA exam
The IIA's current policy is that scored exam questions on new Topical Requirements will not appear on the CIA exam until at least six months after the effective date. For the Third-Party Topical Requirement, that means not before March 15, 2027. The IIA's CIA exam reference list, version dated August 25, 2026, lists it as a secondary reference with testing starting in March 2027.
The Cybersecurity Topical Requirement became effective on February 5, 2026. Under the same rule it could be tested from August 5, 2026, and the reference list now shows it without a later start date. So for a CIA exam you sit today, cybersecurity is in scope and third party is not yet.
The CIA syllabus did not change. The IIA still points candidates to the 2025 CIA exam syllabus for all three parts.
What the Third-Party Topical Requirement covers
A third party is an external individual, group or entity the organization works with to obtain products or services. The term covers vendors, suppliers, contractors, subcontractors, outsourced service providers, other agencies and consultants. It also reaches fourth and further downstream parties allowed by the contract. It does not cover regulators, agents, trustees or board members, or employees.
Internal auditors consider the third-party life cycle: selecting, contracting, onboarding, monitoring and offboarding. The requirements fall into three groups. Governance covers the approach for deciding whether to contract, policies and procedures, roles and responsibilities, and reporting to stakeholders. Risk management covers standardized processes, risk assessment and prioritization of third parties, risk responses, and escalation when a third party does not respond.
Controls are assessed for third parties prioritized by risk. They include due diligence and a documented business case, approved contracts, a complete list of third-party relationships, onboarding, ongoing monitoring, corrective action protocols, tracking of renewal dates, and a formal offboarding plan. Offboarding includes returning or destroying the organization's sensitive data and revoking the third party's access.
What it means for your study
Third parties are not new to the syllabus. Part 1 asks you to describe third-party and contract compliance audits. Part 2 asks how to apply Topical Requirements when you set objectives and scope, plan an engagement and complete a risk assessment, and it lists third-party processes among common business processes. Part 3 covers the applicability of Topical Requirements in the internal audit plan and in the quality assurance and improvement program.
If you sit before March 15, 2027, you will not get scored questions on the specific requirements of the Third-Party Topical Requirement. If you sit later, read the Topical Requirement itself. It is short, and its governance, risk management and control requirements map directly to what a question can ask.
Also in September: CIA Challenge Exam scoring
From September 1, 2026, CIA Challenge Exam candidates no longer receive an immediate, unofficial score. They receive their official result within three weeks of the exam date. The same change has applied to the three-part CIA exam since April 1, 2026. Under the existing retake policy, candidates wait at least 30 days before retaking an exam part, so the result arrives before a retake is possible.