- ISO 27001
- Annex A
ISO 27001 Annex A 5.20: Addressing information security within supplier agreements
Updated 5 min read
Annex A 5.20 is the contract control. A supplier process under 5.19 decides what you need from a supplier; 5.20 makes sure those requirements are actually agreed with the supplier, in writing, in a form you can enforce. It is also the supplier control where the evidence is easiest to sample, so it is tested in almost every certification audit.
Below: what the control requires, which terms to include, what auditors check, an evidence checklist and how to handle suppliers who only sign their own paper. The parent guide, ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence, covers all five supplier controls together.
What Annex A 5.20 requires
The control, paraphrased: relevant information security requirements should be established and agreed with each supplier based on the type of supplier relationship. Its full title is Addressing information security within supplier agreements, and it replaced A.15.1.2 in the 2013 edition. Two words do most of the work: relevant, so the requirements scale with the relationship, and agreed, so a requirement you hold internally but never put to the supplier does not count.
What a supplier agreement should cover
The implementation guidance in ISO/IEC 27002:2022 lists topics to consider. Grouped and summarised:
| Topic | What to agree |
|---|---|
| Information and access | What information is provided or accessed, its classification, and how it may be accessed |
| Legal requirements | Data protection, intellectual property and other legal, regulatory and contractual obligations |
| Controls | The security controls each party must operate, including access control, monitoring and reporting |
| People | Screening of supplier personnel, confidentiality, awareness, and how access is granted and removed |
| Incidents | How and how quickly the supplier reports security incidents, and cooperation in handling them |
| Sub-contracting | Whether the supplier may subcontract, and the requirement to pass security obligations down |
| Assurance | Independent reports or certifications the supplier will provide, and your right to audit |
| Continuity | Backup, recovery, alternative facilities and change management for the service |
| Termination | Return or secure destruction of information, and a managed handover at the end |
A proportionate implementation
Write a minimum clause set per tier into your supplier procedure. For critical and high-tier suppliers that might be: security obligations proportionate to the data, confidentiality, incident notification within a fixed number of hours, notice of sub-processor changes, audit or assessment rights (accepting an independent report is fine), service levels, and return and deletion at termination. Medium and low tiers get a shorter core set.
Large SaaS providers will not negotiate. For them, review their standard terms, DPA and security documentation against your clause set, and log every gap as a condition with a resolution: their published DPA covers it, you operate a compensating control, or a named person accepted the risk. That gap log is legitimate evidence for 5.20; pretending the gaps do not exist is not. Where personal data is involved, the DPA required by GDPR Article 28 covers a good part of the list. The contract stage of Vendor onboarding checklist: the checks to finish before the contract is signed shows where this check fits.
What certification auditors look for
- Your minimum security requirements for supplier agreements, by tier.
- For a sample of suppliers: the signed agreement, and where each requirement is in it.
- For suppliers on their own paper: your review of their terms and the gap log.
- Consistency with 5.19: a critical supplier in the register should have the critical clause set, not the low-tier one.
Evidence checklist for Annex A 5.20
- Minimum security clause set per supplier tier, in the approved procedure
- Signed agreements for sampled suppliers, with the security clauses locatable
- Contract review records showing each agreement was checked against the clause set
- Gap log: missing or weak terms and the resolution or accepted risk, with approver
- Data processing agreements for suppliers processing personal data
- Non-disclosure or confidentiality agreements where the main contract has none (see 6.6)
Related controls
- ISO 27001 Annex A 5.19: Information security in supplier relationships — the supplier process that decides what each agreement needs.
- ISO 27001 Annex A 5.21: Managing information security in the ICT supply chain — flowing requirements down the ICT supply chain.
- ISO 27001 Annex A 5.22: Monitoring, review and change management of supplier services — checking the supplier keeps to what was agreed.
- ISO 27001 Annex A 5.23: Information security for use of cloud services — the additional terms that matter for cloud services.
Also relevant: 5.14 (Information transfer), which expects agreements covering the secure transfer of information with external parties, and 6.6 (Confidentiality or non-disclosure agreements).
Frequently asked questions
- What is ISO 27001 Annex A 5.20?
- Annex A 5.20, Addressing information security within supplier agreements, requires the organisation to establish relevant information security requirements and agree them with each supplier, based on the type of supplier relationship. It replaced A.15.1.2 of ISO/IEC 27001:2013.
- Do I have to rewrite every supplier contract for ISO 27001?
- No. The requirements must be relevant to the type of relationship, and many suppliers will never sign your paper. Define a minimum clause set per risk tier, check each higher-tier supplier's agreement against it, and record any gap with how it was handled: an addendum, a DPA, a compensating control on your side, or an accepted risk with a named approver.
- Does a GDPR data processing agreement satisfy Annex A 5.20?
- Partly. A DPA that meets GDPR Article 28(3) covers confidentiality, security measures, sub-processors, assistance, deletion or return, and audit rights for personal data. 5.20 is wider: it covers all information the supplier handles, not only personal data, and topics such as incident notification timelines, personnel screening and service continuity.
- What do auditors check for Annex A 5.20?
- They take a sample of suppliers, usually including a critical one, and ask to see the agreement and where the security requirements are in it. They also look for your minimum clause set and for a record of gaps found during contract review and what was done about them.
Related guides
- ISO 27001
- Audit
ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence
The five supplier controls in the 2022 edition, what each demands, and the records that satisfy them.
11 min read
- ISO 27001
- Annex A
ISO 27001 Annex A 5.19: Information security in supplier relationships
The control that asks for a supplier security process: types of supplier, tiers, requirements, and the records that prove it ran.
5 min read
- ISO 27001
- Annex A
ISO 27001 Annex A 5.21: Managing information security in the ICT supply chain
Your suppliers have suppliers. What 5.21 expects you to know about them, and how to evidence it without auditing the whole chain.
5 min read