Embedding the IIA Topical Requirement on cyber security
ArticleWhat the IIA topical requirement covers, when it applies, and the practical steps internal audit functions need to take to meet the requirements.

Our quarterly internal audit hot topics provides a thematic view of new and emerging regulatory risks. Get in touch if you would like to discuss any of the topics below.
Internal audit hot topics and evolving priorities continue to shift amid rapid technology change, ongoing geopolitical tensions and macroeconomic uncertainty. As such, effective horizon scanning is essential to help internal auditors manage the operational implications of these emerging risks and opportunities, while maintaining a resilient business environment.
Our quarterly internal audit hot topics reports are here to help you stay on track, respond to change, and support strategic growth. Key considerations include:
Internal audit should ensure these risks are fully embedded across all three lines of defence, supported by a robust control environment.
In addition to the above, financial services firms also need effective regulatory horizon scanning. Internal auditors and audit teams should proactively consider emerging risks across key areas such as:
By addressing these priorities, organisations can move beyond assurance and position internal audit as a strategic function that supports resilience, innovation and sustainable growth.
What the IIA topical requirement covers, when it applies, and the practical steps internal audit functions need to take to meet the requirements.
Assurance mapping gives firms a consolidated view of control activities, helping boards meet Provision 29 requirements in the UK Corporate Governance Code.
Emma Young provides a summary on what organisations need to consider in 2026 to meet provision 29 requirements for the first year reporting.

Risk-based internal audit services that deliver value and impact.