- ISO 27001
- Annex A
ISO 27001 Annex A 5.19: Information security in supplier relationships
Updated 5 min read
Annex A 5.19 is where ISO/IEC 27001:2022 starts on suppliers. It is a short control with a broad reach: it asks for a defined, working process for managing the information security risks that come with using other organisations’ products and services. The four supplier controls that follow it — 5.20 to 5.23 — fill in parts of that process, so a weak 5.19 tends to show up as nonconformities across the set.
This page covers what the control requires, what a certification auditor looks for, an evidence checklist, and how to run it in proportion to a small or mid-sized organisation. For all five supplier controls side by side, read the parent guide, ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence.
What Annex A 5.19 requires
The control text, paraphrased: processes and procedures should be defined and implemented to manage the information security risks associated with the use of the supplier’s products or services. Its title is Information security in supplier relationships, and it replaced A.15.1.1 (Information security policy for supplier relationships) in the 2013 edition.
The implementation guidance in ISO/IEC 27002:2022 fills that out. In summary, it expects the organisation to:
- identify and document the types of supplier that can affect its information security — IT and cloud services, logistics, utilities, financial services, ICT infrastructure components and so on;
- decide how suppliers are evaluated and selected according to the sensitivity of the information, products and services involved;
- evaluate and manage the risks each type of supplier brings;
- define the security requirements each type must meet, and monitor compliance with them, including what happens when a supplier falls short;
- plan for incidents and contingencies involving suppliers, including resilience and recovery where a supplier’s service is critical;
- make sure staff who deal with suppliers know the rules, and manage information and assets securely at the end of a relationship.
A proportionate implementation
For most organisations under a few hundred people, 5.19 is satisfied by three things that work together.
- A supplier security procedure, a page or two: the owner, the supplier types in scope, three or four risk tiers defined by data access and criticality, and for each tier the assessment, contract terms and review frequency it requires. Vendor risk management policy template: ten sections you can copy and adapt has text you can adapt.
- A supplier register listing every supplier with its tier, internal owner, the data it handles, the last review and the next. This is the population an auditor samples from, so it has to be complete. Vendor risk tiering: how to classify third parties and set a review cadence covers tier criteria that hold up.
- Assessment records for higher-tier suppliers: what was reviewed, the evidence obtained, the conclusion, who decided and when. The process in How to vet a vendor: a ten-step vendor vetting checklist produces exactly these.
What certification auditors look for
An auditor tests 5.19 by asking for the process and then checking that it ran. Expect these questions:
- Show me how you decide which suppliers matter for information security.
- Show me the supplier register. Is it complete? (They may compare it with accounts payable or your SaaS sign-in logs.)
- Pick a critical supplier: what tier is it, why, and where is its assessment record?
- What happens when a supplier fails to meet a requirement?
- Who owns supplier risk, and how do staff who buy services know the rules?
The common minor nonconformities are a register missing suppliers that obviously belong in it, and assessments that happened but left no record. Both are fixed by making the record the output of the work rather than a separate task.
Evidence checklist for Annex A 5.19
- Supplier security procedure or policy, approved and dated, with a named owner
- Definition of supplier types in scope and risk tiers with criteria
- Complete supplier register: tier, owner, data handled, last and next review
- Assessment records for critical and high-tier suppliers, dated with a conclusion
- A record of how a non-compliant supplier was handled (condition, exception or exit)
- Supplier-related entries in your risk register or risk treatment plan
- Evidence that staff who engage suppliers were told the procedure
Related controls
- ISO 27001 Annex A 5.20: Addressing information security within supplier agreements — the security requirements in each supplier agreement.
- ISO 27001 Annex A 5.21: Managing information security in the ICT supply chain — extending the process to the ICT supply chain.
- ISO 27001 Annex A 5.22: Monitoring, review and change management of supplier services — monitoring suppliers and managing changes.
- ISO 27001 Annex A 5.23: Information security for use of cloud services — the cloud services process.
Two other controls often come up beside them: 5.31 (Legal, statutory, regulatory and contractual requirements), because supplier contracts are among the contractual requirements you must identify; and 8.30 (Outsourced development), where the supplier writes software for you.
Frequently asked questions
- What is ISO 27001 Annex A 5.19?
- Annex A 5.19, Information security in supplier relationships, is the ISO/IEC 27001:2022 control that requires processes and procedures to manage the information security risks of using suppliers' products or services. It replaced A.15.1.1 of the 2013 edition and is the starting point for the other supplier controls, 5.20 to 5.23.
- Does Annex A 5.19 require a supplier security policy?
- The control asks for processes and procedures, not a document with a particular name. In practice a short supplier security policy or procedure is the simplest way to show the process exists: who owns it, how suppliers are classified, what each class must go through, and how often it is repeated.
- Which suppliers are in scope for 5.19?
- Any supplier whose products or services can affect the confidentiality, integrity or availability of information in your ISMS scope: cloud and SaaS providers, IT and managed service providers, outsourced developers, and also less obvious ones such as logistics, cleaning or utilities where they have physical access or your operations depend on them. Classify them; do not assess them all the same way.
- What is the difference between 5.19 and 5.20?
- 5.19 is the overall process for managing supplier risk. 5.20 is one part of it: getting the agreed security requirements into the agreement with each supplier. An auditor usually tests them together by tracing a sample of suppliers from the register to their contracts.
Related guides
- ISO 27001
- Audit
ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence
The five supplier controls in the 2022 edition, what each demands, and the records that satisfy them.
11 min read
- ISO 27001
- Annex A
ISO 27001 Annex A 5.20: Addressing information security within supplier agreements
Which security requirements belong in the supplier contract, how to handle vendors on their own paper, and the gap log auditors ask for.
5 min read
- ISO 27001
- Annex A
ISO 27001 Annex A 5.21: Managing information security in the ICT supply chain
Your suppliers have suppliers. What 5.21 expects you to know about them, and how to evidence it without auditing the whole chain.
5 min read