- ISO 27001
- Audit
ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence
Updated 8 min read
ISO/IEC 27001:2022 spends five controls on suppliers, and certification auditors treat them as a set: a supplier that appears in one is expected to appear in all of them. The controls are short. What they demand is a process, applied consistently, with records that show it ran.
This guide takes each of Annex A 5.19 to 5.23 in turn: what the control requires, how to implement it in proportion to a small or mid-sized organisation, and the evidence a certification auditor expects to see. It assumes the 2022 edition; the mapping from the 2013 controls is at the end for organisations mid-transition.
The five controls at a glance
| Control | Title | In one line |
|---|---|---|
| 5.19 | Information security in supplier relationships | Have a process for managing the security risks of using suppliers' products and services. |
| 5.20 | Addressing information security within supplier agreements | Put the security requirements in the contract. |
| 5.21 | Managing information security in the ICT supply chain | Extend the process to the suppliers' own suppliers and to the components you buy. |
| 5.22 | Monitoring, review and change management of supplier services | Keep checking, and re-check when something changes. |
| 5.23 | Information security for use of cloud services | Have a process for acquiring, using, managing and exiting cloud services. |
5.19 — Information security in supplier relationships
What it requires. Processes and procedures to manage the information security risks associated with the use of suppliers’ products or services. The implementation guidance expects you to identify and document the types of suppliers that can affect your information security, classify them, define how each type is assessed and selected, set the security requirements for each, and define how incidents and contingencies involving suppliers are handled.
Proportionate implementation. A one-page supplier security policy that names an owner, defines three or four risk tiers by data access and criticality, and states what assessment, agreement terms and review frequency each tier requires. A supplier register that lists every supplier with its tier, owner and review dates. That is the whole control for most organisations; the following four fill in the detail. Vendor risk tiering: how to classify third parties and set a review cadence covers tier criteria that hold up in audit.
Evidence. The policy, approved and dated. The register. The assessment record for each higher-tier supplier: what was reviewed, by whom, the conclusion, and the date.
5.20 — Addressing information security within supplier agreements
What it requires. Relevant information security requirements established and agreed with each supplier, according to the type of relationship. The guidance lists what an agreement should consider: description of the information and access provided; legal and regulatory requirements including data protection; the controls the supplier must implement; incident management and notification; screening of supplier personnel; the right to audit; handling of sub-suppliers; and obligations on termination — return, deletion, transition.
Proportionate implementation. Define a minimum clause set per tier in the policy. For critical suppliers on their own paper, review the agreement against that set at onboarding and log any gap as a condition with a remediation route (an addendum, a data processing agreement, a compensating control on your side). Where personal data is processed, the DPA required by GDPR Article 28 covers much of the list.
Evidence. The minimum clause set. Signed agreements for sampled suppliers, with the clauses locatable. The gap log and what was done about each gap.
5.21 — Managing information security in the ICT supply chain
What it requires. Processes to manage the security risks of the ICT products and services supply chain specifically: the software and hardware you acquire, and the fact that your suppliers have suppliers. The guidance expects you to require suppliers to propagate your requirements down their chain, to know the provenance of critical components, and to be able to identify which of your systems depend on which supplier.
Proportionate implementation. For critical and high-tier suppliers, ask for their sub-processor or sub-supplier list, how they assess those parties, and how much notice you get before a change — three questions in the assessment questionnaire. Require flow-down of security obligations in the agreement. For software components, keep a dependency inventory and a patching process; both are also required elsewhere in Annex A.
Evidence. Questionnaire answers on sub-suppliers for sampled suppliers. Flow-down clauses in agreements. The record of a sub-supplier change being reviewed.
5.22 — Monitoring, review and change management of supplier services
What it requires. Regular monitoring, review, evaluation and change management of supplier security practices and service delivery. The guidance expects service-level monitoring, review of supplier reports and audit results, handling of supplier incidents, and reassessment when the supplier’s service, ownership, sub-suppliers or your own use of the service changes.
Proportionate implementation. A reassessment cadence per tier — annual for critical, less often for the rest — with the next date set when the current review closes. A short list of triggers for an early review: certificate or report expiry, a breach notification, a change of ownership or sub-suppliers, a change in what you share. Supplier reports (SOC 2, ISO certificates, penetration test summaries) reviewed as they renew, with a dated note.
Evidence. Reassessments dated within cadence for sampled suppliers. Review notes on renewed reports. A triggered review, if any occurred in the period, and the decision it produced.
5.23 — Information security for use of cloud services
What it requires. This is the control new in 2022. Processes for the acquisition, use, management and exit from cloud services, in line with your security requirements. The guidance covers: defining security requirements for cloud services; selection criteria and scope of use; roles and responsibilities between you and the provider; which controls the provider operates and which you must; how to obtain assurance; how incidents involving the service are handled; and how to exit — including getting your data back in a usable form.
Proportionate implementation. Most SMB suppliers are cloud services, so 5.23 is largely satisfied by the supplier process above applied with three additions: a shared-responsibility note for each critical cloud service (what they secure, what you configure), an assurance source (their SOC 2 or ISO certificate, reviewed), and an exit note (how data is exported, in what format, and how deletion is confirmed). The exit note is the piece most often missing, and auditors have started asking for it.
Evidence. A documented cloud services process — a section in the supplier policy is enough. For sampled cloud services: the shared-responsibility note, the assurance review, and the exit note.
How the certification auditor tests the set
Expect the auditor to select two or three suppliers from the register — at least one critical — and trace each through all five controls: where is it in the register and what tier (5.19); show me the agreement and the security terms (5.20); what do you know about their sub-suppliers (5.21); when was it last reviewed and what triggered any earlier review (5.22); and, if it is a cloud service, show me the responsibility split, the assurance and the exit plan (5.23). A supplier that passes 5.19 and fails 5.22 is still a nonconformity.
Minor nonconformities on supplier controls are common in first certifications and are almost always about records rather than practice: the review happened but nobody wrote it down, the agreement has the clause but nobody checked. The fix is to make the record the output of the work, not a separate task.
Mapping from the 2013 edition
| 2022 control | 2013 control(s) |
|---|---|
| 5.19 | A.15.1.1 Information security policy for supplier relationships |
| 5.20 | A.15.1.2 Addressing security within supplier agreements |
| 5.21 | A.15.1.3 Information and communication technology supply chain |
| 5.22 | A.15.2.1 Monitoring and review; A.15.2.2 Managing changes to supplier services |
| 5.23 | New in 2022 |
Where to go next
The assessment records 5.19 and 5.22 depend on come from the process in Vendor due diligence: a practical guide for small and mid-sized businesses. For the questions to send higher-tier suppliers, including the sub-supplier questions 5.21 needs, Vendor risk assessment questionnaire: what to ask, and how to score the answers. For the whole programme sized to a small organisation, Third-party risk management for small businesses: a programme without a GRC team.
Frequently asked questions
- Which ISO 27001 controls cover suppliers?
- In ISO/IEC 27001:2022, Annex A controls 5.19 (information security in supplier relationships), 5.20 (addressing security within supplier agreements), 5.21 (managing security in the ICT supply chain), 5.22 (monitoring, review and change management of supplier services) and 5.23 (information security for use of cloud services). They replaced controls A.15.1.1–A.15.2.2 of the 2013 edition.
- What changed for suppliers between ISO 27001:2013 and 2022?
- The 2013 supplier controls were consolidated and one new control was added: 5.23, information security for use of cloud services. It requires a process for acquiring, using, managing and exiting cloud services, which most organisations now have to evidence for the SaaS tools they rely on.
- Can I exclude the supplier controls from my Statement of Applicability?
- Only with a justification the auditor accepts, and for an organisation that uses any external service that is very hard to make. If you use cloud hosting or SaaS, 5.19–5.23 apply. The proportionate approach is to apply them with a tiered process rather than to argue they are not applicable.
- What evidence does an ISO 27001 auditor want for supplier controls?
- A supplier security policy, a supplier register with risk classification, assessment records for higher-risk suppliers, agreements containing the security requirements 5.20 lists, records of monitoring and review, and a documented process for cloud services including exit. The auditor will trace a sample of suppliers through all of it.
Related guides
- SOC 2
- Audit
SOC 2 vendor management: what auditors expect from your third-party programme
CC9.2, subservice organisations, and the vendor evidence an auditor will sample. Prepare it before the fieldwork window.
7 min read
- Fundamentals
- Checklist
Vendor due diligence: a practical guide for small and mid-sized businesses
The end-to-end process — scoping, questionnaires, evidence, scoring, review cadence — sized for a team of one.
9 min read
- Questionnaires
- Scoring
Vendor risk assessment questionnaire: what to ask, and how to score the answers
The questions that matter by risk tier, mapped to the controls auditors recognise, with a scoring method you can explain.
8 min read