- ISO 27001
- Annex A
ISO 27001 Annex A 5.22: Monitoring, review and change management of supplier services
Updated 5 min read
A supplier assessed once and never again is a supplier whose file describes a company that may no longer exist. Annex A 5.22 is the control that keeps the supplier picture current: regular monitoring and review, and re-evaluation when something changes — on their side or yours.
This page covers the requirement, a review cadence that scales, what auditors test and an evidence checklist. For the full supplier control set, read ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence.
What Annex A 5.22 requires
The control, paraphrased: the organisation should regularly monitor, review, evaluate and manage change in supplier information security practices and service delivery. Its full title is Monitoring, review and change management of supplier services. It brings together two 2013 controls, A.15.2.1 (Monitoring and review of supplier services) and A.15.2.2 (Managing changes to supplier services).
The ISO/IEC 27002:2022 guidance, summarised, covers:
- monitoring service performance against the agreement;
- reviewing supplier reports, holding progress reviews where the relationship warrants it, and auditing suppliers or reviewing independent audit reports;
- getting information about supplier security incidents and making sure they are handled;
- reviewing the security of the supplier’s relationships with its own suppliers;
- checking the supplier keeps workable continuity plans for the service;
- assigning responsibility for each supplier relationship to a named person;
- managing changes — to the agreement, and by the supplier, such as new services, technology, locations or subcontractors — and re-evaluating risk accordingly.
A review cadence that scales
| Tier | Scheduled review | What the review covers |
|---|---|---|
| Critical | Every 6–12 months | Updated questionnaire, renewed independent reports, incidents and SLA performance, sub-supplier changes |
| High | Every 12 months | Updated questionnaire or attestation, renewed reports, sub-supplier changes |
| Medium | Every 18 months | Short-form questionnaire, contract and data check |
| Low | Every 24 months | Confirm the service, data and owner have not changed |
Alongside the schedule, define triggers for an early review: a breach or incident at the supplier, an expired certificate or report, a change of ownership, a new sub-processor, a new data category or integration on your side, or a material drop in service quality. The trigger list is short; the discipline is acting on it and writing down what you decided. Vendor risk tiering: how to classify third parties and set a review cadence explains how tiers and cadences fit together.
What certification auditors look for
- Your defined review frequency per tier, and evidence that sampled suppliers were reviewed within it.
- Review notes on renewed SOC 2 reports or ISO certificates, dated.
- At least one triggered review in the period, if a trigger occurred, and its outcome.
- A named owner for each critical supplier relationship.
- How supplier incidents reach you, and what happened with the last one.
The typical finding is an overdue review on a critical supplier, or a review that happened in a meeting and left no record. A register that shows each supplier’s next review date makes the first visible before the auditor sees it.
Evidence checklist for Annex A 5.22
- Review frequency per tier and the list of early-review triggers, in the procedure
- Supplier register with last and next review dates; nothing critical overdue
- Dated reassessment records for sampled suppliers
- Review notes on renewed independent reports (scope, period, exceptions, conclusion)
- SLA or service performance records for critical services
- Supplier incident notifications received and how each was handled
- Records of supplier changes reviewed, with the decision
- Named owner for each critical and high-tier supplier
Related controls
- ISO 27001 Annex A 5.19: Information security in supplier relationships — the process that sets the tiers and review frequency.
- ISO 27001 Annex A 5.20: Addressing information security within supplier agreements — the agreement you are monitoring against.
- ISO 27001 Annex A 5.21: Managing information security in the ICT supply chain — sub-supplier changes in the ICT supply chain.
- ISO 27001 Annex A 5.23: Information security for use of cloud services — monitoring and exit for cloud services.
Supplier incidents also feed 5.24 to 5.28, the incident management controls, and the records here are the same ones a SOC 2 auditor samples; see SOC 2 vendor management: what auditors expect from your third-party programme.
Frequently asked questions
- What is ISO 27001 Annex A 5.22?
- Annex A 5.22, Monitoring, review and change management of supplier services, requires the organisation to regularly monitor, review, evaluate and manage change in supplier information security practices and service delivery. It merged A.15.2.1 and A.15.2.2 of ISO/IEC 27001:2013.
- How often should suppliers be reviewed under ISO 27001?
- The standard does not set a frequency; you do, in proportion to risk, and then you must follow it. A common pattern is every 6 to 12 months for critical suppliers, 12 months for high, 18 for medium and 24 for low, plus an early review when a trigger such as a breach, an expired certificate or a change of sub-processor occurs.
- What counts as a supplier change under 5.22?
- Changes to the agreement, and changes by the supplier: new or different services, new technology or tools, new locations, changes of ownership, and new subcontractors. Changes on your side count too, such as sharing more sensitive data with an existing supplier. Each should prompt a proportionate re-evaluation.
- Is reading a supplier's new SOC 2 report enough for 5.22?
- It is a good part of it, provided you record that you read it: the period, the scope, any exceptions and complementary user entity controls, and your conclusion. Combine it with service-level monitoring and incident tracking for critical suppliers.
Related guides
- ISO 27001
- Audit
ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence
The five supplier controls in the 2022 edition, what each demands, and the records that satisfy them.
11 min read
- ISO 27001
- Annex A
ISO 27001 Annex A 5.19: Information security in supplier relationships
The control that asks for a supplier security process: types of supplier, tiers, requirements, and the records that prove it ran.
5 min read
- ISO 27001
- Annex A
ISO 27001 Annex A 5.20: Addressing information security within supplier agreements
Which security requirements belong in the supplier contract, how to handle vendors on their own paper, and the gap log auditors ask for.
5 min read