ISO/IEC 27001:2022 Annex A · Control 5.19
Information Security in Supplier Relationships: A Practical Implementation Guide
Manage security risk across the full supplier lifecycle, not only during procurement.
This control establishes processes for identifying and managing information security risks arising from suppliers and their services.
What should the control achieve?
- Suppliers are risk-tiered before engagement.
- Security due diligence matches criticality.
- Owners monitor risk throughout service delivery.
- Exit removes access and protects or returns information.
Step-by-step implementation
Inventory suppliers
Record service, owner, data, access, locations, subcontractors and dependencies.
Risk-tier suppliers
Use impact and exposure to set due-diligence and monitoring depth.
Assess before approval
Review controls, certifications, incidents, resilience and legal context.
Treat identified risk
Require remediation, contract clauses, architecture safeguards or formal acceptance.
Monitor service
Review assurance, incidents, changes and performance on schedule.
Exit securely
Revoke access, return or delete data and preserve required evidence.
What this could look like in practice
A payroll provider is classified critical because it processes employee data. Privacy, Security and HR assess it, contractual safeguards are agreed, annual assurance is reviewed and exit requirements include verified deletion and access revocation.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Onboarding | Tiering determines required assessment and approval. | Supplier assessment |
| Operation | Owner reviews incidents, assurance and changes annually. | Review record |
| Exit | Accounts close and data deletion is certified. | Exit checklist |
Implementation evidence
- Supplier inventory
- Risk-tiering method
- Due-diligence assessments
- Risk decisions
- Security clauses
- Monitoring reviews
- Incident records
- Exit evidence
Useful metrics
- Critical suppliers assessed
- Overdue supplier reviews
- Open high-risk findings
- Exits with complete closure evidence
Common mistakes
- Applying the same questionnaire to every supplier.
- Relying solely on certificates.
- No business owner for supplier risk.
- Ignoring free cloud tools and subcontractors.
- Ending contracts without deleting access.
Questions an auditor may ask
- How are suppliers tiered?
- Show due diligence for a critical supplier.
- How are changes and incidents monitored?
- What happens at exit?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.