ISO 27001A.5 — Addressing information security within supplier agreements
A.5.20
Addressing information security within supplier agreements
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Address information security in supplier agreements according to the type of relationship.
Points of focus
- Security clauses appropriate to tier
- Incident and breach notification terms
- Data handling and return/deletion
- Right to review assurance reports
Implementation notes
Maintain a security exhibit for high-tier suppliers covering encryption, access, IR notice, and subcontractors. Coordinate DPAs/BAAs with privacy/legal. Record negotiated exceptions with risk acceptance. On exit, enforce return/deletion obligations and verify when risk warrants. Link to A.5.19 diligence and A.5.22 monitoring.
Audit tip: Show a critical vendor agreement section on security/incident notice and the owner who approved deviations.
Evidence auditors typically request:
- Contract templates with security schedule
- Executed MSAs/DPAs for critical vendors
- Exception log when clauses were negotiated away
- Legal + security review checklist
Common gaps
- Click-through ToS only for critical data processors
- No incident notification timelines
- Deletion on exit never exercised
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.20 | This control |
| GDPR | Article 28 | Related GDPR articles for personal-data security or processor themes — not a compliance claim. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.20)
Frequently Asked Questions
Not always practical. For low-risk tools, evaluate their terms; for high-risk processors, push for acceptable security terms or accept documented risk.
A DPA addresses GDPR processor themes; you may still need security schedules for availability, IR, and assurance report sharing.
Treat maintained SaaS differently from libraries — libraries fall more under secure development and vuln management.