ISO/IEC 27001:2022 Annex A · Control 5.20
Addressing Information Security Within Supplier Agreements: A Practical Implementation Guide
Translate supplier risk decisions into clear, enforceable contractual obligations.
This control concerns agreeing relevant information security requirements with each supplier based on the relationship and associated risks.
What should the control achieve?
- Contract requirements reflect supplier risk and service.
- Responsibilities are unambiguous.
- The organization can obtain assurance and incident support.
- Security obligations survive relevant changes and termination.
Step-by-step implementation
Start from assessed risk
Translate data, access, criticality, locations and dependencies into requirements.
Use a clause library
Cover baseline themes while allowing tailored schedules for high-risk services.
Allocate responsibilities
Clarify shared controls, customer configurations and subcontractor duties.
Define assurance rights
Specify reports, audit evidence, testing and remediation expectations.
Set incident obligations
Define notification triggers, timelines, cooperation and evidence preservation.
Plan change and exit
Cover material changes, data return, deletion, portability and continuity.
What this could look like in practice
A cloud hosting agreement includes security responsibilities, approved regions, encryption, vulnerability remediation targets, 24-hour incident notification, subcontractor controls, annual assurance and verified deletion at exit.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Security schedule | Requirements are tailored from the supplier risk assessment. | Executed contract |
| Incident clause | Notification, contacts and cooperation are explicit. | Incident schedule |
| Exit clause | Data format, return period and deletion evidence are defined. | Exit provision |
Implementation evidence
- Security clause library
- Risk-to-clause mapping
- Executed agreements
- Responsibility matrix
- Assurance provisions
- Incident clauses
- Subprocessor terms
- Exit requirements
Useful metrics
- High-risk contracts with required clauses
- Clause deviations awaiting approval
- Suppliers missing assurance rights
- Contracts reviewed after material change
Common mistakes
- Using one template without tailoring.
- Accepting vague ‘industry standard’ promises.
- Omitting customer responsibilities.
- No deadline for incident notification.
- No leverage to verify remediation or deletion.
Questions an auditor may ask
- How are clauses selected from risk?
- Show shared responsibilities in an agreement.
- What evidence can you require?
- How are deviations approved?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.