ISO 27001A.5 — Information security in supplier relationships
A.5.19
Information security in supplier relationships
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Manage information security risks associated with the use of suppliers.
Points of focus
- Supplier inventory with criticality
- Due diligence before onboarding
- Security requirements in engagement
- Ongoing monitoring cadence
Implementation notes
Maintain a vendor register linked to A.5.9 assets. Tier by data access and availability impact. Collect SOC 2/ISO reports or questionnaires for high tiers; track issues to closure. Coordinate with privacy DPAs/BAAs when personal data or PHI flows. Feed residual risk into the ISMS risk register.
Audit tip: Walk one critical subprocessor: tier, diligence artifact, contract security clause, last review date.
Evidence auditors typically request:
- Vendor inventory with data/risk tier
- Security questionnaire or SOC report review notes
- Onboarding checklist completion
- Periodic re-review calendar
Common gaps
- Shadow SaaS never inventoried
- One-time questionnaire never refreshed
- Critical subprocessors without owners
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.19 | This control |
| GDPR | Article 28 | Related GDPR articles for personal-data security or processor themes — not a compliance claim. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.19)
Frequently Asked Questions
No. Proportionate diligence — critical data processors need stronger assurance than a marketing pixel vendor.
Annually for critical tiers is common, plus on major incidents or scope changes.
Processor contracts are a legal track; A.5.19 is the ISMS supplier-security process that should align with them.