Audit-Ready TPRM: Aligning Your Third-Party Risk Program with the IIA’s 2025 Topical Requirement

Amy Zu • June 4, 2025

Big changes ahead: The IIA's new third-party requirement could reshape internal audit


The Institute of Internal Auditors (IIA) has released a public consultation draft of its new topical requirement on third parties1, and it’s poised to become one of the most significant updates to third-party risk management in years.


This topical requirement is planned for issuance by Q3, 2025. Once finalized, this new standard will require mandatory conformance for internal auditors conducting assurance engagements related to vendors, contractors, and other third-party service providers.

Is your organization ready?


This update introduces new expectations, and for many audit teams, it raises critical questions:

  • Can your third-party risk management (TPRM) program demonstrate full lifecycle coverage, from onboarding to offboarding?
  • Are your governance, control, and risk management procedures clearly documented?
  • Will your program withstand the increased scrutiny from audit committees and regulators?

If you’re unsure, now is the time to act.


Start with our Readiness Questionnaire


Quickly evaluate how well your third-party risk program aligns with the IIA’s draft expectations. It’s a fast, practical way to identify gaps before the requirement becomes mandatory.

Download checklist
Audit-Ready TPRM Questionaire

Go deeper with the white paper


Audit-Ready TPRM Program Whitepaper

Audit-Ready: Aligning Your Third-Party Risk (TPRM) Program with the IIA’s 2025 Topical Requirements


This practical resource maps our proven TPRM white paper to the IIA’s proposed requirements for governance, risk, and control, giving you a clear, actionable framework to evaluate, improve, and document your program.


It’s designed for:

  • Internal auditors assessing conformance with the new requirement
  • Risk and compliance leaders building or maturing TPRM programs
  • Executives seeking stronger board visibility into vendor risk


What’s Inside the white paper:

  • A plain-language breakdown of the IIA’s draft expectations
  • A checklist of must-have controls across the third-party lifecycle
  • A crosswalk between the TPRM white paper and IIA assurance areas
  • Guidance on documentation, escalation, and board oversight
  • KPI and reporting strategies to demonstrate program maturity
Download whitepaper

Take the next step


Don't be caught off guard. Prepare now and gain a critical advantage.


Here’s how to get started:

  • Download the readiness checklist – Pinpoint gaps in your TPRM lifecycle and assess audit readiness
  • Get the white paper – Align your program with the IIA’s upcoming assurance requirements
  • Schedule a readiness review – Meet with our team for a personalized consultation

By Allyson Edwards June 8, 2025
Discover how a childhood fascination with fairness and structure led to an unexpected yet deeply fulfilling career in compliance and internal audit. In this personal and insightful post, the author shares their journey from disliking rule-breaking fictional heroes to finding purpose in building systems, solving complex compliance puzzles, and driving continuous improvement in the business world. If you're curious about what makes a career in corporate compliance rewarding, this story offers a fresh, human-centered perspective on a field that’s often misunderstood, but vitally important.
Coworkers meeting
By Dorina Hamzo March 3, 2025
In 2025, organizations face growing risks like cyberattacks and supply chain disruptions. Auditors are critical in identifying risks and ensuring accountability but face pressure to meet deadlines. This blog outlines key strategies for auditors, including writing clear findings, creating effective remediation plans, and building continuous monitoring programs to improve risk management and help organizations thrive in a volatile world.
Healing hands
By Dorina Hamzo February 3, 2025
In response to rising ransomware attacks, HIPAA is introducing critical security updates for healthcare organizations. With 67% targeted in 2024, the new rules mandate HIPAA compliance and include measures such as annual asset inventories, risk analysis, mandatory encryption of ePHI, regular audits, and multi-factor authentication to strengthen data protection and prevent cyber threats.
More posts