Skip to content
  • ISO 27001
  • Annex A

ISO 27001 Annex A 5.20: Addressing information security within supplier agreements

Updated 5 min read

Annex A 5.20 is the contract control. A supplier process under 5.19 decides what you need from a supplier; 5.20 makes sure those requirements are actually agreed with the supplier, in writing, in a form you can enforce. It is also the supplier control where the evidence is easiest to sample, so it is tested in almost every certification audit.

Below: what the control requires, which terms to include, what auditors check, an evidence checklist and how to handle suppliers who only sign their own paper. The parent guide, ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence, covers all five supplier controls together.

What Annex A 5.20 requires

The control, paraphrased: relevant information security requirements should be established and agreed with each supplier based on the type of supplier relationship. Its full title is Addressing information security within supplier agreements, and it replaced A.15.1.2 in the 2013 edition. Two words do most of the work: relevant, so the requirements scale with the relationship, and agreed, so a requirement you hold internally but never put to the supplier does not count.

What a supplier agreement should cover

The implementation guidance in ISO/IEC 27002:2022 lists topics to consider. Grouped and summarised:

TopicWhat to agree
Information and accessWhat information is provided or accessed, its classification, and how it may be accessed
Legal requirementsData protection, intellectual property and other legal, regulatory and contractual obligations
ControlsThe security controls each party must operate, including access control, monitoring and reporting
PeopleScreening of supplier personnel, confidentiality, awareness, and how access is granted and removed
IncidentsHow and how quickly the supplier reports security incidents, and cooperation in handling them
Sub-contractingWhether the supplier may subcontract, and the requirement to pass security obligations down
AssuranceIndependent reports or certifications the supplier will provide, and your right to audit
ContinuityBackup, recovery, alternative facilities and change management for the service
TerminationReturn or secure destruction of information, and a managed handover at the end

A proportionate implementation

Write a minimum clause set per tier into your supplier procedure. For critical and high-tier suppliers that might be: security obligations proportionate to the data, confidentiality, incident notification within a fixed number of hours, notice of sub-processor changes, audit or assessment rights (accepting an independent report is fine), service levels, and return and deletion at termination. Medium and low tiers get a shorter core set.

Large SaaS providers will not negotiate. For them, review their standard terms, DPA and security documentation against your clause set, and log every gap as a condition with a resolution: their published DPA covers it, you operate a compensating control, or a named person accepted the risk. That gap log is legitimate evidence for 5.20; pretending the gaps do not exist is not. Where personal data is involved, the DPA required by GDPR Article 28 covers a good part of the list. The contract stage of Vendor onboarding checklist: the checks to finish before the contract is signed shows where this check fits.

What certification auditors look for

  • Your minimum security requirements for supplier agreements, by tier.
  • For a sample of suppliers: the signed agreement, and where each requirement is in it.
  • For suppliers on their own paper: your review of their terms and the gap log.
  • Consistency with 5.19: a critical supplier in the register should have the critical clause set, not the low-tier one.

Evidence checklist for Annex A 5.20

  • Minimum security clause set per supplier tier, in the approved procedure
  • Signed agreements for sampled suppliers, with the security clauses locatable
  • Contract review records showing each agreement was checked against the clause set
  • Gap log: missing or weak terms and the resolution or accepted risk, with approver
  • Data processing agreements for suppliers processing personal data
  • Non-disclosure or confidentiality agreements where the main contract has none (see 6.6)

Also relevant: 5.14 (Information transfer), which expects agreements covering the secure transfer of information with external parties, and 6.6 (Confidentiality or non-disclosure agreements).

Frequently asked questions

What is ISO 27001 Annex A 5.20?
Annex A 5.20, Addressing information security within supplier agreements, requires the organisation to establish relevant information security requirements and agree them with each supplier, based on the type of supplier relationship. It replaced A.15.1.2 of ISO/IEC 27001:2013.
Do I have to rewrite every supplier contract for ISO 27001?
No. The requirements must be relevant to the type of relationship, and many suppliers will never sign your paper. Define a minimum clause set per risk tier, check each higher-tier supplier's agreement against it, and record any gap with how it was handled: an addendum, a DPA, a compensating control on your side, or an accepted risk with a named approver.
Does a GDPR data processing agreement satisfy Annex A 5.20?
Partly. A DPA that meets GDPR Article 28(3) covers confidentiality, security measures, sub-processors, assistance, deletion or return, and audit rights for personal data. 5.20 is wider: it covers all information the supplier handles, not only personal data, and topics such as incident notification timelines, personnel screening and service continuity.
What do auditors check for Annex A 5.20?
They take a sample of suppliers, usually including a critical one, and ask to see the agreement and where the security requirements are in it. They also look for your minimum clause set and for a record of gaps found during contract review and what was done about them.