Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 supplier assessment Annex A 5.19 to 5.23

ISO 27001 Supplier Assessment: Controls 5.19 to 5.23 in 2026

An ISO 27001 supplier assessment is how you show an auditor that the information you share with third parties is protected in proportion to its risk, and in the 2022 edition of the standard, five Annex A controls are devoted to it. Suppliers are among the most common sources of findings, because the evidence sits partly in other companies’ hands and partly in your own records.

This guide walks through controls 5.19 to 5.23, shows how to build a supplier assessment that satisfies them, and lists the evidence certification auditors ask for. It complements our ISO 27001 risk assessment guide, which covers the wider method.

Free gap assessment

Where do you actually stand against ISO 27001?

Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.

Run the free ISO 27001 gap assessment →  or  View premium report sample

The five controls behind an ISO 27001 supplier assessment

The supplier controls sit in the organisational group of Annex A, and each covers a stage of the relationship. Summaries from practitioners describe them as follows.

ControlTitleWhat it asks of you
5.19Information security in supplier relationshipsManage the risks of suppliers’ products and services, to plan how information shared with them is protected
5.20Addressing information security within supplier agreementsPut security terms in written agreements
5.21Managing information security in the ICT supply chainAddress the risks that come with ICT products and services and their own supply chains
5.22Monitoring, review and change management of supplier servicesReview supplier performance and manage changes
5.23Information security for use of cloud servicesSet requirements for acquiring, using and leaving cloud services

You must consider each control when you build your Statement of Applicability, and justify any you exclude. See our Statement of Applicability guide and the overview of the ISO 27001:2022 controls.

Control 5.19: classify suppliers and assess risk

The control requires you to manage the information security risks associated with the use of supplier products and services. A practical approach documents a supplier security policy for a small or mid-sized organisation, or a procedure for managing supplier security risks for a larger one. These documents are recommended rather than mandatory, but an auditor will still expect a consistent process. Commonly used techniques include due diligence questionnaires, a risk assessment before onboarding and a request for independent assurance such as an ISO 27001 certificate or a SOC 2 report.

Free third-party risk assessment

How much risk does this vendor bring?

Tier the vendor, check the evidence, rate the risks from 30 third-party scenarios and choose controls referenced to ISO 27001, NIST CSF 2.0 and DORA. You get a tier, a heat map and the findings an auditor would raise, free.

Start the free vendor risk assessment →  or  View premium report sample

Start with classification, which is the backbone of any ISO 27001 supplier assessment. Group suppliers by the information they can reach and the criticality of their service, for example critical, important and standard. Critical suppliers, such as your cloud host or payment processor, receive full due diligence. Standard suppliers with no access to sensitive information receive a lighter check. Our guide to vendor risk tiering covers scoring and our vendor due diligence checklist lists questions to ask.

Control 5.20: security terms in supplier agreements

The agreement is where your requirements become obligations. Practitioner guidance describes the need for written agreements that set out security rules, and that typically include breach notification duties, audit or assurance rights, and notice of material changes in the supplier’s business. Review agreements regularly. Where a supplier’s standard terms cannot be negotiated, document the gap and the compensating measures you will take. Our service provider oversight guide sets out a clause list that also works for ISO 27001.

Control 5.21: the ICT supply chain

This control extends the reach beyond your direct suppliers. For software, practitioners recommend asking suppliers about their development procedures and requiring notification when updates will stop. For hardware, they point to keeping configuration documentation, looking for tamper evidence and requiring recall notifications. Also consider fourth parties: ask whether a critical supplier depends on another provider whose failure would affect you, and require that supplier to pass your requirements down.

Control 5.22: monitoring and change management

Onboarding is only the start of the ISO 27001 supplier assessment cycle. You must monitor supplier services on an ongoing basis, using tools such as service reports, performance data and audits. Maintain a supplier register that records the review date, the reviewer, the outcome and follow-up actions, and assign a named owner for each critical supplier. React to changes: a supplier that moves its hosting location, changes a subprocessor, is acquired or alters its service may change your risk, so build a trigger that reopens the assessment.

Control 5.23: cloud services

Cloud providers are suppliers, with the difference that their terms are usually not negotiable. Because of that, define your criteria in a cloud policy before selection: what data may go to the cloud, what assurance you require, how you will manage the relationship, and how data is returned or deleted on exit. Assign an owner for each cloud service and record the shared responsibility split. Our note on the BSI C5 report review shows one way to read a provider’s assurance report.

Building the ISO 27001 supplier assessment process

  1. Create the supplier inventory. List every supplier with access to information or that provides ICT services, with an owner for each.
  2. Classify. Score by data sensitivity, access and criticality.
  3. Assess before onboarding. Use a questionnaire and evidence proportionate to the tier.
  4. Contract. Include the security clauses required by your policy.
  5. Onboard with least access. Grant only the access the service needs.
  6. Monitor. Review at a frequency set by tier, and after any change or incident.
  7. Exit. Remove access, retrieve or destroy information and record it.

Evidence auditors expect

Certification auditors will look for a supplier policy or procedure, the register with tiers and review dates, completed questionnaires or risk assessments, copies of certificates or assurance reports with a note of your review, signed agreements with security terms, service reports and records of supplier incidents, and exit records. They will often select a critical supplier and follow it from selection through to the latest review. If you cannot show the trail, the finding is likely to be a nonconformity. See our ISO 27001 nonconformity guide for how findings are handled.

Ownership and reporting for the ISO 27001 supplier assessment

Procurement, security and the business owner of each service all touch suppliers, so agree who does what. Procurement owns the contract and the register entry, security owns the risk assessment and the review, and the business owner owns the relationship and reports issues. Present a short supplier report at management review: the number of suppliers by tier, reviews completed against plan, open findings, incidents involving suppliers and any exits pending. That report is useful evidence for clause 9.3 and shows top management that the ISO 27001 supplier assessment is a living process.

Handling suppliers that will not cooperate

Some suppliers refuse questionnaires or will not share reports. Do not ignore the gap. Record the refusal, assess the risk with the information you do have, consider compensating measures such as limiting the data shared, adding encryption you control or monitoring activity, and get a named manager to accept any residual risk. For a critical supplier, repeated refusal is a reason to plan a replacement. An auditor is usually satisfied by a reasoned decision, and rarely by silence.

A hypothetical example

A software company lists 42 suppliers. It classifies three as critical: its cloud host, its identity provider and a managed security operations vendor. Each receives a full questionnaire, a review of independent assurance reports, contract checks and an annual meeting. Eleven are important, with a shorter questionnaire and biennial review, and the rest are standard, with a contract check only. When the identity provider announces a new hosting region, the owner reopens the assessment, confirms the data location terms and records the result. At the surveillance audit, the auditor samples the identity provider and finds the full trail. The example is illustrative only.

Common findings in an ISO 27001 supplier assessment

  • Incomplete inventory. Departments have signed up to tools that are missing from the register.
  • Everyone treated alike. No tiering, so effort is spread thinly and critical suppliers are under-assessed.
  • Certificates filed, not reviewed. The scope or exceptions were never read.
  • Old contracts. Agreements predate the security policy and lack key clauses.
  • No monitoring evidence. Reviews are promised but not recorded.
  • Exit forgotten. Access remains after a contract ends.

Tools and templates

The records are simple and repeatable: a supplier policy, a register, a questionnaire, a risk scoring sheet, a contract clause checklist, a review form and an exit checklist. The ISO 27001 Assessment Tool helps you assess your position against the standard, including the supplier controls. For an outside summary of the controls, see the URM overview of the supplier controls, and read the controls in your licensed copy of the standard.

ISO 27001 supplier assessment FAQ

Which ISO 27001 controls cover suppliers?

Annex A controls 5.19 to 5.23 in the 2022 edition cover supplier relationships, agreements, the ICT supply chain, monitoring and cloud services.

Do I need to assess every supplier?

You need a risk-based approach. Critical suppliers receive detailed assessment, and low-risk suppliers can be handled with lighter checks, as long as your classification is documented.

Is a supplier’s ISO 27001 certificate enough?

It is useful evidence, but check that its scope covers the service you use and read the Statement of Applicability, then record your conclusion.

How often should suppliers be reviewed?

By tier, commonly annually for critical suppliers, and after any significant change or incident.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.