Skip to content
  • ISO 27001
  • Audit

ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence

Updated 8 min read

ISO/IEC 27001:2022 spends five controls on suppliers, and certification auditors treat them as a set: a supplier that appears in one is expected to appear in all of them. The controls are short. What they demand is a process, applied consistently, with records that show it ran.

This guide takes each of Annex A 5.19 to 5.23 in turn: what the control requires, how to implement it in proportion to a small or mid-sized organisation, and the evidence a certification auditor expects to see. It assumes the 2022 edition; the mapping from the 2013 controls is at the end for organisations mid-transition.

The five controls at a glance

ControlTitleIn one line
5.19Information security in supplier relationshipsHave a process for managing the security risks of using suppliers' products and services.
5.20Addressing information security within supplier agreementsPut the security requirements in the contract.
5.21Managing information security in the ICT supply chainExtend the process to the suppliers' own suppliers and to the components you buy.
5.22Monitoring, review and change management of supplier servicesKeep checking, and re-check when something changes.
5.23Information security for use of cloud servicesHave a process for acquiring, using, managing and exiting cloud services.

5.19 — Information security in supplier relationships

What it requires. Processes and procedures to manage the information security risks associated with the use of suppliers’ products or services. The implementation guidance expects you to identify and document the types of suppliers that can affect your information security, classify them, define how each type is assessed and selected, set the security requirements for each, and define how incidents and contingencies involving suppliers are handled.

Proportionate implementation. A one-page supplier security policy that names an owner, defines three or four risk tiers by data access and criticality, and states what assessment, agreement terms and review frequency each tier requires. A supplier register that lists every supplier with its tier, owner and review dates. That is the whole control for most organisations; the following four fill in the detail. Vendor risk tiering: how to classify third parties and set a review cadence covers tier criteria that hold up in audit.

Evidence. The policy, approved and dated. The register. The assessment record for each higher-tier supplier: what was reviewed, by whom, the conclusion, and the date.

5.20 — Addressing information security within supplier agreements

What it requires. Relevant information security requirements established and agreed with each supplier, according to the type of relationship. The guidance lists what an agreement should consider: description of the information and access provided; legal and regulatory requirements including data protection; the controls the supplier must implement; incident management and notification; screening of supplier personnel; the right to audit; handling of sub-suppliers; and obligations on termination — return, deletion, transition.

Proportionate implementation. Define a minimum clause set per tier in the policy. For critical suppliers on their own paper, review the agreement against that set at onboarding and log any gap as a condition with a remediation route (an addendum, a data processing agreement, a compensating control on your side). Where personal data is processed, the DPA required by GDPR Article 28 covers much of the list.

Evidence. The minimum clause set. Signed agreements for sampled suppliers, with the clauses locatable. The gap log and what was done about each gap.

5.21 — Managing information security in the ICT supply chain

What it requires. Processes to manage the security risks of the ICT products and services supply chain specifically: the software and hardware you acquire, and the fact that your suppliers have suppliers. The guidance expects you to require suppliers to propagate your requirements down their chain, to know the provenance of critical components, and to be able to identify which of your systems depend on which supplier.

Proportionate implementation. For critical and high-tier suppliers, ask for their sub-processor or sub-supplier list, how they assess those parties, and how much notice you get before a change — three questions in the assessment questionnaire. Require flow-down of security obligations in the agreement. For software components, keep a dependency inventory and a patching process; both are also required elsewhere in Annex A.

Evidence. Questionnaire answers on sub-suppliers for sampled suppliers. Flow-down clauses in agreements. The record of a sub-supplier change being reviewed.

5.22 — Monitoring, review and change management of supplier services

What it requires. Regular monitoring, review, evaluation and change management of supplier security practices and service delivery. The guidance expects service-level monitoring, review of supplier reports and audit results, handling of supplier incidents, and reassessment when the supplier’s service, ownership, sub-suppliers or your own use of the service changes.

Proportionate implementation. A reassessment cadence per tier — annual for critical, less often for the rest — with the next date set when the current review closes. A short list of triggers for an early review: certificate or report expiry, a breach notification, a change of ownership or sub-suppliers, a change in what you share. Supplier reports (SOC 2, ISO certificates, penetration test summaries) reviewed as they renew, with a dated note.

Evidence. Reassessments dated within cadence for sampled suppliers. Review notes on renewed reports. A triggered review, if any occurred in the period, and the decision it produced.

5.23 — Information security for use of cloud services

What it requires. This is the control new in 2022. Processes for the acquisition, use, management and exit from cloud services, in line with your security requirements. The guidance covers: defining security requirements for cloud services; selection criteria and scope of use; roles and responsibilities between you and the provider; which controls the provider operates and which you must; how to obtain assurance; how incidents involving the service are handled; and how to exit — including getting your data back in a usable form.

Proportionate implementation. Most SMB suppliers are cloud services, so 5.23 is largely satisfied by the supplier process above applied with three additions: a shared-responsibility note for each critical cloud service (what they secure, what you configure), an assurance source (their SOC 2 or ISO certificate, reviewed), and an exit note (how data is exported, in what format, and how deletion is confirmed). The exit note is the piece most often missing, and auditors have started asking for it.

Evidence. A documented cloud services process — a section in the supplier policy is enough. For sampled cloud services: the shared-responsibility note, the assurance review, and the exit note.

How the certification auditor tests the set

Expect the auditor to select two or three suppliers from the register — at least one critical — and trace each through all five controls: where is it in the register and what tier (5.19); show me the agreement and the security terms (5.20); what do you know about their sub-suppliers (5.21); when was it last reviewed and what triggered any earlier review (5.22); and, if it is a cloud service, show me the responsibility split, the assurance and the exit plan (5.23). A supplier that passes 5.19 and fails 5.22 is still a nonconformity.

Minor nonconformities on supplier controls are common in first certifications and are almost always about records rather than practice: the review happened but nobody wrote it down, the agreement has the clause but nobody checked. The fix is to make the record the output of the work, not a separate task.

Mapping from the 2013 edition

2022 control2013 control(s)
5.19A.15.1.1 Information security policy for supplier relationships
5.20A.15.1.2 Addressing security within supplier agreements
5.21A.15.1.3 Information and communication technology supply chain
5.22A.15.2.1 Monitoring and review; A.15.2.2 Managing changes to supplier services
5.23New in 2022

Where to go next

The assessment records 5.19 and 5.22 depend on come from the process in Vendor due diligence: a practical guide for small and mid-sized businesses. For the questions to send higher-tier suppliers, including the sub-supplier questions 5.21 needs, Vendor risk assessment questionnaire: what to ask, and how to score the answers. For the whole programme sized to a small organisation, Third-party risk management for small businesses: a programme without a GRC team.

Frequently asked questions

Which ISO 27001 controls cover suppliers?
In ISO/IEC 27001:2022, Annex A controls 5.19 (information security in supplier relationships), 5.20 (addressing security within supplier agreements), 5.21 (managing security in the ICT supply chain), 5.22 (monitoring, review and change management of supplier services) and 5.23 (information security for use of cloud services). They replaced controls A.15.1.1–A.15.2.2 of the 2013 edition.
What changed for suppliers between ISO 27001:2013 and 2022?
The 2013 supplier controls were consolidated and one new control was added: 5.23, information security for use of cloud services. It requires a process for acquiring, using, managing and exiting cloud services, which most organisations now have to evidence for the SaaS tools they rely on.
Can I exclude the supplier controls from my Statement of Applicability?
Only with a justification the auditor accepts, and for an organisation that uses any external service that is very hard to make. If you use cloud hosting or SaaS, 5.19–5.23 apply. The proportionate approach is to apply them with a tiered process rather than to argue they are not applicable.
What evidence does an ISO 27001 auditor want for supplier controls?
A supplier security policy, a supplier register with risk classification, assessment records for higher-risk suppliers, agreements containing the security requirements 5.20 lists, records of monitoring and review, and a documented process for cloud services including exit. The auditor will trace a sample of suppliers through all of it.