
Executive Summary
For the first time in the history of the profession, internal auditors worldwide are subject to a mandatory, subject-specific standard for how cybersecurity must be assessed. The Institute of Internal Auditors issued the Cybersecurity Topical Requirement in February 2025 as the first Topical Requirement under the Global Internal Audit Standards, and it has been in force since 5 February 2026. Every internal audit function that provides assurance over cybersecurity — in-house, outsourced or co-sourced, in a bank in Kingston or a utility in Port of Spain — must now conform to it, and must be able to demonstrate that conformance in internal and external quality assessments.
This article — the standards deep-dive the previous two articles in this series have pointed toward — explains what the Topical Requirement actually says and, just as importantly, what it does not. It sets out the requirement’s three-domain architecture of governance, risk management and control processes; the precise circumstances in which conformance is mandatory; the flexibility functions retain in choosing frameworks such as NIST CSF or COBIT; and the honest capability question the requirement forces on every Caribbean function. It closes with a practical conformance path a function can complete within a plan year, and a readiness checklist for chief audit executives and audit committees.
What Is the Topical Requirement — and Why Does It Exist?

The 2024 Global Internal Audit Standards introduced a new instrument into the profession’s framework: Topical Requirements — mandatory baselines for assessing specific risk areas that matter to organisations everywhere. Cybersecurity was chosen as the first, which is itself a statement about where the profession believes its credibility is most at stake. The reasoning is straightforward: cyber risk sits at or near the top of every serious risk survey, boards increasingly rely on internal audit for cyber assurance, and yet the depth and quality of that assurance has varied enormously from function to function — from genuine control evaluation in some organisations to a courtesy review of the information-security policy in others.
The Topical Requirement exists to end that variability. It establishes a consistent baseline: a defined set of matters — seventeen requirements across three domains — that an internal audit function must consider when it assesses cybersecurity. It does not turn auditors into penetration testers, and it does not prescribe any particular technology or vendor. What it prescribes is coverage and consistency: any stakeholder reading a cyber assurance conclusion from a conforming function anywhere in the world can now rely on a common floor beneath it. For a region like the Caribbean — where regulators, correspondent banks and international partners increasingly scrutinise the assurance behind local institutions — that portability of credibility is not a burden; it is an asset.
When Does Conformance Actually Apply? Getting the Boundaries Right

Precision matters here, because the requirement is widely misquoted in both directions. Three boundaries define its application. First, conformance is mandatory for assurance engagements: whenever cybersecurity is the subject of an assurance engagement — named in the audit plan, or arising within an engagement’s scope — the function must apply the Topical Requirement to the areas being assessed. Second, for advisory engagements the requirement is recommended rather than mandatory, though a function advising on cyber matters would be unwise to ignore the baseline it will later be assessed against. Third — and this is the nuance most commentary misses — the Topical Requirement does not itself force cybersecurity into the audit plan. No Topical Requirement mandates that its subject be audited.
That third point is not the escape clause it may appear to be. The Global Standards separately require risk-based planning, and it is a rare Caribbean organisation in which an honest risk assessment would leave cybersecurity out of the plan year after year. A function that omits cyber must be able to defend that omission on risk grounds — to its audit committee, and to any external quality assessor — and “we lack the skills” is a capability finding, not a risk justification. In practice, then, the requirement operates as a pincer: risk-based planning pulls cybersecurity into the plan, and the moment it enters, the Topical Requirement governs how it must be assessed. Conformance must also be demonstrable: documentation of how engagements addressed the applicable requirements is what internal and external quality assessments will look for.
| THE PRECISE POSITION
The Topical Requirement does not force cyber into your audit plan — risk-based planning does. But once cybersecurity is the subject of an assurance engagement, conformance is mandatory, and it must be demonstrable in quality assessments. “We audited cyber our own way” is no longer a defensible position. |
What Does the Requirement Actually Cover?

The requirement’s architecture mirrors the way the Global Standards think about any risk area — and, helpfully, the Three Lines Model this series has used throughout. Its seventeen requirements are organised in three domains. Governance, which links naturally to the board and senior management: the function must assess whether the organisation has a current cybersecurity strategy aligned with its objectives, supported by policies that are established and kept up to date, clear roles and responsibilities for cybersecurity, and genuine engagement and oversight from senior management and the board — the very disciplines Article 3 of this series demanded of directors, now examined from the assurance side.
Risk management, which links to the second line: the function must assess whether the organisation’s risk processes identify, analyse, mitigate and monitor cybersecurity threats and their potential effects — an approach that is current, not an assessment performed once and filed. And control processes, which link to the first line: the function must assess whether management has established an effective internal control environment over the operational realities of cyber defence — the territory of access management and privileged accounts, vulnerability identification and patching, security monitoring, data protection and backup, security awareness and training, and incident response readiness. Functions are free to assess these through the framework their organisation already uses: the IIA’s user guide maps the requirements to NIST and COBIT, but no specific framework is mandated — what a function must be able to demonstrate is that its chosen framework covers the applicable requirements. For Caribbean organisations, NIST CSF 2.0 — the anchor this series has used throughout — maps cleanly and is freely available, which matters for resource-constrained functions.
What Conformance Means in Practice for a Function

Four practical consequences follow. Methodology: the function needs work programmes for cyber engagements that trace to the seventeen requirements — not to guarantee every engagement covers everything, but to ensure scoping decisions are deliberate and documented rather than accidental. Documentation: workpapers must show which requirements applied to each engagement and how they were addressed, because that trail is precisely what an external quality assessment will test — and every function faces one at least every five years. Capability: assessing control processes at the depth the requirement contemplates demands technical understanding that most small functions do not hold in-house, which returns us to the build, partner or co-source decision of the previous article — now with a standards deadline attached rather than merely a good idea’s momentum. And committee reporting: audit committees should expect, and chief audit executives should offer, an explicit statement of how the function conforms — the same verification instinct this series has urged boards to apply everywhere else, applied to the assurance function itself.
Why This Lands Harder — and Matters More — in the Caribbean

The requirement is global, but its weight is not evenly distributed. Caribbean internal audit functions are typically small — often two to five people carrying an entire organisation’s assurance plan — and deep cyber skills are scarce and expensive across the region. A mandatory baseline that assumes access to technical assessment capability therefore presses hardest on exactly the functions least resourced to meet it alone. At the same time, the regional stakes are higher than the averages suggest: financial institutions dominate many Caribbean audit universes, regulators are sharpening technology-risk expectations for licensed entities, and credit unions, utilities and government bodies hold precisely the member and citizen data that attackers monetise.
There is also a commercial dimension regional leaders should not miss. Conformance is portable credibility: a Caribbean institution whose internal audit function demonstrably meets the global baseline carries that evidence into conversations with correspondent banks, reinsurers, international customers and rating reviews. In a region working continuously to hold its place in global financial networks, a recognised assurance standard — met and documented — is one of the cheaper forms of trust an institution can buy. The functions that treat February 2026 as the start of the work, rather than a deadline missed quietly, will convert a compliance obligation into a competitive statement.
A Practical Conformance Path: Six Steps Within One Plan Year

- Run a conformance gap assessment. Compare the function’s current cyber audit approach — plan coverage, work programmes, workpapers, skills — against the seventeen requirements, and document the gaps honestly.
- Fix the audit universe first. Ensure the plan reflects the organisation’s real cyber loss scenarios (Article 4’s first step); a conforming methodology applied to the wrong scope still fails the risk test.
- Map your framework. Adopt or confirm the organisation’s framework — NIST CSF 2.0 for most — and document how it covers the applicable requirements, using the IIA’s user guide mapping as the starting point.
- Close the capability gap deliberately. Decide build, partner or co-source; put the arrangement in place before the first conforming engagement, with specialists working under the function’s methodology and quality control.
- Deliver one conforming engagement — and keep the evidence. Run a cyber engagement fully mapped to the requirements, with documentation an external assessor could follow, and use it as the function’s template.
- Report conformance to the audit committee. State plainly how the function meets the requirement, where gaps remain, and the plan to close them — before the committee has to ask.
The Dawgen Global Perspective
Dawgen Global regards the Topical Requirement as the most consequential development for Caribbean internal audit in a decade — not because it demands anything a good function was not already striving toward, but because it converts aspiration into an assessable obligation. The functions that struggle will not be those that lack size; they will be those that delay. Conformance is genuinely achievable within a plan year for even a small function, provided the gap assessment is honest, the framework mapping is documented, and the capability question is answered with arrangements rather than intentions.
Dawgen Global supports functions across that entire path: independent conformance gap assessments against the seventeen requirements, framework mapping and work-programme development anchored to NIST CSF 2.0, co-sourced delivery of conforming cyber engagements with technical validation embedded, and preparation for external quality assessments. The next article in this series turns from standards to the ground truth they exist to reach: the Caribbean’s most persistent technical misunderstanding — why a vulnerability scan is not a penetration test, and why the difference matters to every conclusion built on top of it.
The Conformance Readiness Checklist: Ten Questions

- Can the function state, in writing, how its cyber audit approach maps to the seventeen requirements?
- Does the audit plan reflect the organisation’s actual cyber loss scenarios — defensibly, on risk grounds?
- Has the function documented which framework it applies — and how that framework covers the applicable requirements?
- Do cyber work programmes trace to the requirement’s three domains: governance, risk management, control processes?
- Could an external quality assessor follow our workpapers from requirement to procedure to conclusion?
- Do we have access — in-house or co-sourced — to the technical capability the control-processes domain demands?
- Where specialists support engagements, do they work under the function’s methodology and quality control?
- Has at least one fully conforming cyber engagement been delivered since February 2026?
- Has the audit committee received an explicit conformance statement — including remaining gaps and the closure plan?
- Is our next external quality assessment scheduled — and would cyber conformance survive it today?
Frequently Asked Questions
Does the Topical Requirement force cybersecurity into our audit plan?
Not directly — no Topical Requirement mandates that its subject be audited. But the Global Standards’ risk-based planning requirement makes a cyber-free plan very difficult to defend for most organisations, and the moment cybersecurity becomes the subject of an assurance engagement, conformance is mandatory. The practical effect is the same: plan for it, and conform when you audit it.
We use ISO 27001 rather than NIST or COBIT. Is that a problem?
No. The IIA mandates no specific framework; its user guide maps NIST and COBIT as examples. A function may apply the framework its organisation uses — including ISO 27001 — provided it can demonstrate that the framework covers the applicable requirements. The demonstration is the obligation, not the brand.
Does the requirement apply to outsourced or co-sourced internal audit work?
Yes. Conformance attaches to the internal audit function’s work, however it is resourced. Specialists and service providers performing cyber assurance under the function’s plan must operate within a conforming methodology — which is why co-sourcing arrangements should be assessed for Topical Requirement alignment before engagements begin.
What actually happens if we do not conform?
Nonconformance is a professional-standards failure that surfaces in internal and external quality assessments, and external assessments are required at least every five years. Beyond the assessment result, the practical exposure is reliance: a board, regulator or counterparty that discovers cyber assurance was performed below the mandatory baseline has every reason to discount it — which defeats the purpose of having an internal audit function at all.
Move From Cybersecurity Assumptions to Independent Cyber Assurance
Dawgen Global combines cyber governance, risk-based internal audit, penetration testing, resilience assessment and remediation validation to help Caribbean organisations determine whether their cybersecurity controls are properly designed and operating effectively. To establish where your function stands against the mandatory baseline, request a confidential Topical Requirement conformance gap assessment.
About Dawgen Global
Dawgen Global is an independent, integrated multidisciplinary professional services firm headquartered at 47 Trinidad Terrace, New Kingston, Jamaica, serving more than 15 territories across the Caribbean. Founded and led by Dr. Dawkins Brown, Executive Chairman, the firm is independent and not affiliated with any international network. It delivers a full suite of professional services under one roof: audit and assurance; tax advisory; IT and digital transformation; risk management; cybersecurity; actuarial and insurance regulatory advisory; HR advisory; mergers and acquisitions; corporate recovery; business advisory and strategy; accounting BPO and virtual CFO services; and legal process outsourcing.
The proposition is simple: big-firm capability without the big-firm price. Dawgen Global’s integrated approach is built for the specific complexities and opportunities of the Caribbean market, helping organizations make sharper, better-informed decisions that drive measurable progress.
To explore a partnership, reach out:
- Website: dawgen.global
- Email: [email protected]
- WhatsApp (Global): +1 555-795-9071
- Caribbean offices: +1 876-665-5926 | +1 876-929-3670 | +1 876-926-5210

