Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 5.19

Information Security in Supplier Relationships: A Practical Implementation Guide

Manage security risk across the full supplier lifecycle, not only during procurement.

This control establishes processes for identifying and managing information security risks arising from suppliers and their services.

Practical interpretation: A questionnaire before contract signature is insufficient. Supplier criticality, access, data, dependencies, monitoring, change and exit all require ownership.

What should the control achieve?

  • Suppliers are risk-tiered before engagement.
  • Security due diligence matches criticality.
  • Owners monitor risk throughout service delivery.
  • Exit removes access and protects or returns information.

Step-by-step implementation

1

Inventory suppliers

Record service, owner, data, access, locations, subcontractors and dependencies.

2

Risk-tier suppliers

Use impact and exposure to set due-diligence and monitoring depth.

3

Assess before approval

Review controls, certifications, incidents, resilience and legal context.

4

Treat identified risk

Require remediation, contract clauses, architecture safeguards or formal acceptance.

5

Monitor service

Review assurance, incidents, changes and performance on schedule.

6

Exit securely

Revoke access, return or delete data and preserve required evidence.

What this could look like in practice

A payroll provider is classified critical because it processes employee data. Privacy, Security and HR assess it, contractual safeguards are agreed, annual assurance is reviewed and exit requirements include verified deletion and access revocation.

ActivityPractical implementationEvidence
OnboardingTiering determines required assessment and approval.Supplier assessment
OperationOwner reviews incidents, assurance and changes annually.Review record
ExitAccounts close and data deletion is certified.Exit checklist

Implementation evidence

  • Supplier inventory
  • Risk-tiering method
  • Due-diligence assessments
  • Risk decisions
  • Security clauses
  • Monitoring reviews
  • Incident records
  • Exit evidence

Useful metrics

  • Critical suppliers assessed
  • Overdue supplier reviews
  • Open high-risk findings
  • Exits with complete closure evidence

Common mistakes

  • Applying the same questionnaire to every supplier.
  • Relying solely on certificates.
  • No business owner for supplier risk.
  • Ignoring free cloud tools and subcontractors.
  • Ending contracts without deleting access.

Questions an auditor may ask

  • How are suppliers tiered?
  • Show due diligence for a critical supplier.
  • How are changes and incidents monitored?
  • What happens at exit?
Implementation test: Select a critical supplier and trace risk from selection through contract, operation, incidents, review and exit planning.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.