Audit-Ready TPRM: Aligning Your Third-Party Risk Program with the IIA’s 2025 Topical Requirement

Amy Zu • June 4, 2025

Big changes ahead: The IIA's new third-party requirement could reshape internal audit


The Institute of Internal Auditors (IIA) has released a public consultation draft of its new topical requirement on third parties1, and it’s poised to become one of the most significant updates to third-party risk management in years.


This topical requirement is planned for issuance by Q3, 2025. Once finalized, this new standard will require mandatory conformance for internal auditors conducting assurance engagements related to vendors, contractors, and other third-party service providers.

Is your organization ready?


This update introduces new expectations, and for many audit teams, it raises critical questions:

  • Can your third-party risk management (TPRM) program demonstrate full lifecycle coverage, from onboarding to offboarding?
  • Are your governance, control, and risk management procedures clearly documented?
  • Will your program withstand the increased scrutiny from audit committees and regulators?

If you’re unsure, now is the time to act.


Start with our Readiness Questionnaire


Quickly evaluate how well your third-party risk program aligns with the IIA’s draft expectations. It’s a fast, practical way to identify gaps before the requirement becomes mandatory.

Download checklist
Audit-Ready TPRM Questionaire

Go deeper with the white paper


Audit-Ready Third-Party Risk Management (TPRM) Program

Audit-Ready: Aligning Your Third-Party Risk (TPRM) Program with the IIA’s 2025 Topical Requirements


This practical resource maps our proven TPRM white paper to the IIA’s proposed requirements for governance, risk, and control, giving you a clear, actionable framework to evaluate, improve, and document your program.


It’s designed for:

  • Internal auditors assessing conformance with the new requirement
  • Risk and compliance leaders building or maturing TPRM programs
  • Executives seeking stronger board visibility into vendor risk


What’s Inside the white paper:

  • A plain-language breakdown of the IIA’s draft expectations
  • A checklist of must-have controls across the third-party lifecycle
  • A crosswalk between the TPRM white paper and IIA assurance areas
  • Guidance on documentation, escalation, and board oversight
  • KPI and reporting strategies to demonstrate program maturity
Download whitepaper

Take the next step


Don't be caught off guard. Prepare now and gain a critical advantage.


Here’s how to get started:

  • Download the readiness checklist – Pinpoint gaps in your TPRM lifecycle and assess audit readiness
  • Get the white paper – Align your program with the IIA’s upcoming assurance requirements
  • Schedule a readiness review – Meet with our team for a personalized consultation

Abstract stack of translucent glass-like panels in black and lime green on a white background
By Kristel Jose (Guest Writer) August 3, 2026
Learn how to build a scalable Internal Controls Over Financial Reporting (ICFR) framework. Align people, processes, and technology for SOX readiness.
AI robot performing on stage about to be pulled off with a stage hook.
By Allyson Edwards (Senior Consultant) July 17, 2026
Discover how to adapt existing risk frameworks to AI. Learn the four practical controls every organization needs to protect data and ensure compliance.
AI robot standing beside a small dog in a cage labeled wolf.
By Allyson Edwards (Senior Consultant) June 16, 2026
Explore common AI failures like hallucinations, hidden bias, and missing context. Learn how audit and compliance teams can govern risks and build AI controls.
More posts