Skip to content
compliancebase
ISO 27001A.5 — Information security in supplier relationships

A.5.19

Information security in supplier relationships

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Manage information security risks associated with the use of suppliers.

Points of focus

  • Supplier inventory with criticality
  • Due diligence before onboarding
  • Security requirements in engagement
  • Ongoing monitoring cadence

Implementation notes

Maintain a vendor register linked to A.5.9 assets. Tier by data access and availability impact. Collect SOC 2/ISO reports or questionnaires for high tiers; track issues to closure. Coordinate with privacy DPAs/BAAs when personal data or PHI flows. Feed residual risk into the ISMS risk register.

Audit tip: Walk one critical subprocessor: tier, diligence artifact, contract security clause, last review date.

Evidence auditors typically request:

  • Vendor inventory with data/risk tier
  • Security questionnaire or SOC report review notes
  • Onboarding checklist completion
  • Periodic re-review calendar

Common gaps

  • Shadow SaaS never inventoried
  • One-time questionnaire never refreshed
  • Critical subprocessors without owners

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.19This control
GDPRArticle 28Related GDPR articles for personal-data security or processor themes — not a compliance claim.

Primary sources

Frequently Asked Questions

No. Proportionate diligence — critical data processors need stronger assurance than a marketing pixel vendor.

Annually for critical tiers is common, plus on major incidents or scope changes.

Processor contracts are a legal track; A.5.19 is the ISMS supplier-security process that should align with them.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above