The public consultation closes on 23 July 2026. This may be the most locally consequential Topical Requirement yet — and everyone from practitioners to our integrity institutions has a window to shape it.
The Institute of Internal Auditors (IIA) has released the draft Anti-Corruption Topical Requirement for public consultation, with the comment window running from 8 June to 23 July 2026. Once finalized, it will become a mandatory element of the International Professional Practices Framework (IPPF), sitting alongside the Global Internal Audit Standards. Any internal audit function performing assurance work that touches anti-corruption, whether planned or discovered mid-engagement, will be required to conform.
For internal auditors in the Maldives, this is not a distant global development. Corruption is a standing national conversation here, woven through public procurement debates, SOE governance reforms, and the daily work of our oversight institutions. A global standard that tells internal auditors how to assess an organization’s defenses against corruption will land directly on Maldivian audit plans, Maldivian audit committees, and Maldivian quality assessments. The question is whether it will land in a form that works for organizations like ours, and the only way to influence that is to comment before 23 July.
What the Draft Actually Requires
Topical Requirements set a minimum baseline for auditing specific risk areas. They do not force a topic onto the audit plan; risk-based planning still decides that. But once anti-corruption is the subject of an assurance engagement, or once corruption-related elements surface during any engagement, the requirements become mandatory, and conformance will be tested in quality assessments.
The draft follows the now-familiar structure of governance, risk management, and control processes, mirroring the Three Lines Model. In summary, internal auditors must assess whether:
Governance — the board and senior management demonstrate genuine commitment to fighting corruption, an anti-corruption program (or, where none exists, core compliance components such as training, reporting, discipline, and monitoring) is in place and overseen by the board, roles and responsibilities are defined, and protocols exist for communicating with stakeholders including timely reporting of allegations.
Risk management — corruption risks are continuously identified, assessed, and managed through standardized processes; risk responses match the ranking and prioritization of risks; and escalation processes ensure accountability when issues arise.
Control processes — policies are tailored and communicated, training is commensurate with role-based risk, whistleblower channels are secured and protected, financial controls (segregation of duties, approval levels, dedicated accounts for gifts, donations, and sponsorships) are operating, third-party due diligence is established, ongoing monitoring and testing occur, and incident response and continuous improvement practices exist.
The draft identifies the corruption schemes auditors should understand: bribery and kickbacks, disguised charitable and political donations, conflicts of interest, facilitation payments, accounting deficiencies, gifts and entertainment, hiring of related parties, sponsored travel, and corrupt sponsorships. It even flags the corrupt use of AI as an emerging risk.
One boundary deserves emphasis, because Maldivian stakeholders blur it constantly: this Topical Requirement covers assurance over anti-corruption programs — not the conduct of corruption investigations. Internal audit’s role is to assess whether the organization’s defenses are designed and operating effectively, and to recognize indicators that may warrant further investigation by those mandated to investigate. Boards and executives who expect internal audit to “catch the corrupt” are asking the wrong function to do the wrong job. The draft states plainly that conformance provides no absolute assurance that all corruption will be detected.
What This Means in the Maldivian Context
Global drafters write for organizations with compliance departments and mature second-line functions — not the organization most Maldivian internal auditors walk into on Sunday morning. Reading the draft against our realities, a few things stand out.
For SOEs and public sector offices, few have a formal anti-corruption program in the sense the draft imagines; the provision for organizations without one, that core compliance components should at least exist, is the one Maldivian auditors will lean on most. Early engagements will surface long lists of foundational gaps, but used well, the requirement becomes a roadmap chief internal auditors can put in front of boards. The User Guide also acknowledges that legislation, government structure, and political environments can restrict engagement scope in the public sector, and requires such limitations to be documented and communicated rather than quietly absorbed.
For audit committees and boards, the requirement cuts both ways: tone at the top and board commitment become part of the audit subject matter itself. Committees should also ask now whether their function has the competence for this work, the draft’s fallback of contracting external specialists assumes a market that barely exists in the Maldives, and the Standards require resource shortfalls to be reported to the board.
For CIA candidates, Topical Requirements are now a permanent feature of the profession, and exam questions follow at least six months after each effective date. Start reading them now, they describe the auditor the profession expects you to become.
A Call to Our Integrity Institutions
Here is the part of this consultation that I believe deserves the most attention in the Maldives, and it is not directed at auditors.
The IIA’s public consultations are open to all stakeholders, not just members of the profession. And the institutions with the deepest insight into how corruption actually manifests in the Maldives are our own integrity and oversight bodies.
The Anti-Corruption Commission of the Maldives (ACC) carries a constitutional mandate that extends well beyond investigation. Under the Anti-Corruption Commission Act (13/2008), its responsibilities include researching corruption prevention, recommending improvements to relevant authorities, and promoting integrity across the operations of the state. Commenting on a global standard that will govern how internal auditors assess anti-corruption programs sits naturally within that prevention mandate. The ACC’s investigators and prevention staff have seen, case by case, how corruption schemes actually operate in Maldivian procurement, hiring, and public administration, knowledge of local typologies that the drafters simply cannot have. Notably, the draft’s own reference list includes the UN Convention against Corruption, to which the Maldives has been a signatory since 2007; contributing to this consultation is a small but concrete way to advance commitments the country has already made.
The Privatization and Corporatization Board (PCB), which monitors and evaluates the state-owned enterprises where much of the country’s corruption risk concentrates, has an equally direct stake. The PCB has pushed SOEs on governance through its Code of Corporate Governance and has engaged with the internal audit community on strengthening audit practices within SOEs. A standard that defines the assurance baseline for anti-corruption in every SOE audit function is, in effect, an extension of the PCB’s own agenda.
If our regulators and oversight bodies review the draft and find it sound, that review itself builds institutional familiarity with a standard their auditees will soon be measured against. If they find gaps, and I suspect a Maldivian reading will find several, particularly around small jurisdictions, high social proximity, thin supplier markets, and resource-constrained audit functions, then the consultation window is the moment to say so.
Comment Before 23 July
The consultation runs until 23 July 2026, through a public comment survey available on the IIA’s website, where the draft Topical Requirement and its accompanying User Guide can also be downloaded. The survey walks respondents through the requirements and invites both structured feedback and open comments.
Read the draft. Form a view. Submit it before 23 July.
Leave a Reply