Internal Audit Maldives

Independent articles, insights, perspectives, and discussions dedicated to advancing the internal auditing profession in the Maldives.

The Third-Party Topical Requirement Arrives on 15 September. For the Maldives, It May Matter More Than Cybersecurity.

The IIA’s Third-Party Topical Requirement becomes effective on 15 September 2026. That is six weeks away.

Cybersecurity, the first Topical Requirement, has received most of the profession’s attention this year — understandably, since it came first and the risk is universally recognised. But for internal audit functions in the Maldives, the second requirement deserves at least equal weight, and arguably more. Dependence on third parties is not an incidental feature of how organisations operate here. It is close to being the operating model itself.

What the requirement does

The structure will be familiar to anyone who has worked through the cybersecurity requirement. The Third-Party Topical Requirement is a mandatory element of the IIA’s International Professional Practices Framework, and it establishes a baseline for providing assurance services in this specific risk area, covering the design and implementation of third-party governance, risk management, and control processes.

The same architecture applies throughout the series:

If you have already worked out how to handle applicability documentation for cybersecurity, you have already done most of the thinking for this one. The mechanics transfer directly.

Why the local case is stronger

Consider the structure of the Maldivian economy for a moment.

The state-owned enterprise sector, as described in the Privatization and Corporatization Board’s own Annual Report of the SOE Sector, spans electricity, water and sewerage services, financial services, tourism, air and sea transport, telecommunications, and infrastructure development. These are almost entirely service-delivery businesses, and in a small island economy, service delivery at scale is not something any organisation does alone.

The dependency is documented, and it is severe. The World Bank records that the Maldives is almost fully dependent on imported fuel for critical services including electricity generation, water desalination, and inter-island transportation. Fuel imports alone averaged US$63.7 million per month across 2024–25, equivalent to around 10 percent of annual GDP.

The Maldives Development Update published in June 2026 puts it more broadly still: the economy depends almost entirely on goods sourced from abroad, and among the severe downside risks it identifies are strained supply chains, rising costs for essential imports including fuel, food and medicine, and foreign exchange constraints affecting access to critical imports.

Read that as an internal auditor rather than an economist and it describes something specific: concentrated third-party dependency in the delivery of essential services, with limited substitution available. Concentration is exactly what third-party risk frameworks are designed to surface.

The financial sector offers a further reason to take this seriously. The Maldives Monetary Authority’s regulation for banks on the prevention of money laundering and financing of terrorism already requires the board to ensure that subsidiaries, branches, employees, agents, and third parties to whom the bank outsources any of its functions comply with the regulation. The principle that a bank cannot outsource its accountability is therefore already established in local regulation. What the Third-Party Topical Requirement adds is a structured, internationally recognised method for internal audit to test whether that accountability is actually being exercised.

What good coverage looks like

The requirement organises around governance, risk management, and controls, as the others in the series do. Translated into practical audit questions for a Maldivian organisation, that means asking things like:

Governance. Does the board know how many significant third-party relationships the organisation has? Is there an owner for each one? Is third-party risk reported upward, or does it surface only when something fails?

Risk management. Are third parties assessed before engagement and monitored afterwards? Is criticality distinguished from spend, the most expensive contract is rarely the most dangerous one to lose. Does anyone track concentration, including the case where several apparently separate suppliers depend on the same upstream provider or the same shipping route?

Controls. Do contracts include performance obligations, audit rights, and termination provisions? Is performance actually measured against them? Is there an exit plan for critical relationships, and has anyone tested whether it would work?

The exit question is the one I would encourage colleagues here to press hardest. In a market with few alternative suppliers, “we would find another vendor” is an assumption rather than a plan.

Where to start with six weeks left

You are not expected to have a complete third-party assurance programme in place by 15 September. Conformance is about how the work is done when the topic is in scope, not about having already done it.

Three practical steps for the remaining weeks:

Build or refresh the inventory. You cannot audit third-party governance without knowing who the third parties are. In many organisations this list exists in fragments, procurement holds one version, IT another, finance a third. Consolidating it is useful work regardless of what the IIA requires.

Extend your applicability documentation. The engagement planning template you adjusted for cybersecurity needs a second question: does this engagement involve reliance on external parties? Same discipline, same file, minimal additional effort.

Choose one relationship and test it properly. A single well-executed engagement on a genuinely critical supplier will teach you more about your organisation’s third-party maturity than a broad survey, and it gives your audit committee something concrete to react to.

The wider point

Further Topical Requirements follow this one: Organizational Behavior takes effect on 15 December 2026 and Organizational Resilience on 30 April 2027, with an Anti-Corruption requirement due to be issued in the fourth quarter of this year and a Talent Management requirement going to public consultation in October. Anyone treating each as a separate compliance event is going to find the next eighteen months exhausting.

The better framing is that the IIA is progressively supplying internal auditors with defined baselines for the risks that matter most across every economy — and that some of those baselines fit particular economies better than others. For the Maldives, third-party risk is not a borrowed concern. It is a description of how nearly everything here gets done.

Internal audit functions that recognise that, and use the September requirement as the occasion to look properly at their organisation’s dependencies, will be doing work that is valuable well beyond conformance.

Leave a Reply

Your email address will not be published. Required fields are marked *