A supplier security assessment is how an ISO 27001-certified organization shows that the risks its suppliers introduce are identified, treated and monitored — and it is the evidence behind four Annex A controls that certification auditors test together: A.5.19 information security in supplier relationships, A.5.20 addressing information security within supplier agreements, A.5.21 managing information security in the ICT supply chain, and A.5.22 monitoring, review and change management of supplier services. Most organizations have the agreements. Far fewer have the assessment that decided what the agreements should say, or the monitoring that checks the supplier still meets them. This guide explains what a supplier security assessment covers under ISO 27001:2022, how to tier suppliers so the effort matches the risk, what to ask and what evidence to accept, and how to keep the assessment alive after onboarding.

What ISO 27001 requires of a supplier security assessment
The standard does not prescribe a questionnaire. It requires, through the four controls, that the organization defines and implements processes to manage supplier risk (A.5.19), establishes security requirements in agreements (A.5.20), manages risk in the ICT supply chain specifically (A.5.21), and regularly monitors, reviews and evaluates supplier performance and changes (A.5.22). Underneath those sits the clause 6.1.2 risk assessment, which is where supplier risks are identified in the first place, and A.5.23 for cloud services, which adds acquisition, use, management and exit requirements for cloud specifically.
A supplier security assessment is the practical instrument that satisfies A.5.19 and produces the inputs to A.5.20 and A.5.22. An auditor will ask for: the list of suppliers with access to information or systems in scope, the risk-based method for deciding how much assessment each gets, the completed assessments for the higher-risk ones, the agreements that carry the requirements the assessment identified, and the records of monitoring and review. Our guide to the ISO 27001 control assessment covers how A.5.19–A.5.22 are scored with the rest of Annex A.
Tier suppliers before assessing them
Assessing every supplier the same way is how supplier security programs die. Tier by the access and impact each supplier has, then scale the assessment to the tier:
| Tier | Criteria | Assessment | Evidence accepted | Review cycle |
|---|---|---|---|---|
| 1 Critical | Processes or hosts in-scope information; privileged or persistent access; single point of failure for an in-scope service | Full assessment: questionnaire, evidence review, interview where warranted | ISO 27001 certificate with scope checked; SOC 2 Type II report read, not just received; penetration test summary; BCP test results | Annual, plus on any significant change |
| 2 Significant | Access to some in-scope information or systems, non-privileged; recoverable if lost | Standard questionnaire with evidence for key answers | Certificate or attestation, policies on request | Every 2 years, plus on change |
| 3 Standard | No access to in-scope information or systems; commodity services | Self-declaration; contract security clauses | Signed terms | On renewal |
The tiering decision is itself evidence for A.5.19 and should be recorded per supplier with the reason. It also settles a common audit question — why supplier X was not assessed — with a documented answer rather than an apology.
What a supplier security assessment asks
The questionnaire should mirror the Annex A themes, because the supplier’s answers are being used to judge whether your controls still hold when the work is theirs. A workable Tier 1 assessment covers:
| Area | What to establish | Annex A anchor |
|---|---|---|
| Governance | Named security owner; policies approved and reviewed; certifications and their scope | A.5.1, A.5.2 |
| People | Screening; confidentiality terms; awareness training; leaver process | A.6.1–A.6.5 |
| Access | How your data is segregated; who can access it; MFA; privileged access control; access reviews | A.5.15–A.5.18, A.8.2, A.8.5 |
| Data handling | Location and jurisdiction; encryption at rest and in transit; retention and deletion on exit; backup | A.5.10, A.5.14, A.8.10, A.8.13, A.8.24 |
| Operations | Vulnerability and patch management; logging and monitoring; change management; configuration baselines | A.8.8, A.8.9, A.8.15, A.8.16, A.8.32 |
| Incidents | Detection; notification to you, with a time commitment; post-incident reporting | A.5.24–A.5.28 |
| Continuity | Recovery objectives for the service; tested plans; ICT readiness | A.5.29, A.5.30 |
| Their suppliers | Sub-processors and fourth parties with access to your data; how they are assessed | A.5.21 |
| Development | Secure development lifecycle where the supplier builds software for you | A.8.25–A.8.29 |
What evidence to accept
Answers are claims; evidence is what the assessment records. Three principles:
- Read the certificate scope. An ISO 27001 certificate covers the scope printed on it. A supplier certified for its head office ISMS while your service runs from an uncertified subsidiary has given you no assurance about your service. Check the certificate number with the certification body.
- Read the SOC 2 report, not the cover letter. A Type II report lists the controls tested, the exceptions found and the complementary user entity controls you are expected to operate. The exceptions and the CUECs are the assessment findings.
- Ask for the artefact, not the policy. “We patch monthly” is evidenced by a patch report, not a patching policy. For Tier 1 suppliers ask for one artefact per critical area, redacted if necessary.
Where the supplier cannot or will not evidence a critical answer, the assessment records a gap, and the gap becomes either a contractual requirement, a compensating control on your side, or an accepted risk signed off under your risk treatment process. Silence is not an option the auditor recognizes.
From assessment to agreement
A.5.20 requires security requirements to be established and agreed with each supplier “according to the type of supplier relationship”. The assessment tells you what they should be. Typical clauses that come out of a Tier 1 assessment: the right to audit or to receive assurance reports; incident notification within a stated period; data location, return and deletion; sub-processor approval; security requirements flowed down to the supplier’s own suppliers; and change notification for anything affecting the service’s security. Our guide to third-party risk assessment covers the contractual side across regimes beyond ISO 27001.
Keeping the supplier security assessment alive
A.5.22 is the control most often found as a nonconformity: the onboarding assessment exists, the annual review does not. Three habits close it:
- Put the review cycle in the register. Next review date per supplier, by tier, with an owner. The register is the evidence; the calendar is what makes it happen.
- Re-assess on change. A new sub-processor, a change of data location, a breach in the news, a certificate that lapses. Each is a trigger recorded in the register.
- Review performance, not only security. A.5.22 asks for service performance against agreed levels as well as security. Service reviews with a security item on the agenda satisfy both and produce minutes.
Frequently asked questions
Which ISO 27001 controls require a supplier security assessment?
A.5.19 supplier relationships, A.5.20 supplier agreements, A.5.21 ICT supply chain and A.5.22 monitoring and review, with A.5.23 adding requirements for cloud services. The assessment is the instrument that implements A.5.19 and feeds the others.
Do we have to assess every supplier?
No. The standard expects a risk-based approach. Tier suppliers by their access to in-scope information and systems, assess the high tiers in depth, and record why the low tiers received a lighter treatment.
Is a supplier’s ISO 27001 certificate enough?
Only for the scope on the certificate. Check that the certified scope covers the service you receive, verify the certificate with the certification body, and still fix your specific requirements in the agreement.
What about SOC 2 reports?
A Type II report is strong evidence if it is read: the exceptions and the complementary user entity controls are findings that belong in your assessment.
How often should suppliers be reassessed?
By tier — commonly annually for critical suppliers, every two years for significant ones, on renewal for the rest — and on any significant change, which A.5.22 explicitly requires.
Where this leaves you
Build the supplier security assessment as a cycle, not a form: tier by risk, assess the high tiers against the Annex A themes with evidence rather than answers, write what the assessment found into the agreement, and review on a calendar and on change. That is the full set of records A.5.19 to A.5.22 ask for, and it is what an auditor opens after the SoA.
References
- ISO/IEC 27001:2022 — Annex A controls A.5.19–A.5.23.
- ISO/IEC 27002:2022 — Implementation guidance for the supplier controls.
More on ISO 27001 assessment
- The supplier security assessment — you are here
- ISO 27001 control assessment: scoring Annex A
- ISO 27001 self-assessment: scoring all 93 controls
- Third-party risk assessment across regimes
- ISO 27001 gap assessment: the four outputs
- ISO 27001 assessment report: the six sections
A control-by-control questionnaire covering A.5.19–A.5.23 with the rest of Annex A, with automatic scoring and summary dashboards, is what the Excel-based ISO 27001 Assessment Tool provides, or start with the free templates.