Skip to content
compliancebase
ISO 27001A.5 — Addressing information security within supplier agreements

A.5.20

Addressing information security within supplier agreements

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Address information security in supplier agreements according to the type of relationship.

Points of focus

  • Security clauses appropriate to tier
  • Incident and breach notification terms
  • Data handling and return/deletion
  • Right to review assurance reports

Implementation notes

Maintain a security exhibit for high-tier suppliers covering encryption, access, IR notice, and subcontractors. Coordinate DPAs/BAAs with privacy/legal. Record negotiated exceptions with risk acceptance. On exit, enforce return/deletion obligations and verify when risk warrants. Link to A.5.19 diligence and A.5.22 monitoring.

Audit tip: Show a critical vendor agreement section on security/incident notice and the owner who approved deviations.

Evidence auditors typically request:

  • Contract templates with security schedule
  • Executed MSAs/DPAs for critical vendors
  • Exception log when clauses were negotiated away
  • Legal + security review checklist

Common gaps

  • Click-through ToS only for critical data processors
  • No incident notification timelines
  • Deletion on exit never exercised

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.20This control
GDPRArticle 28Related GDPR articles for personal-data security or processor themes — not a compliance claim.

Primary sources

Frequently Asked Questions

Not always practical. For low-risk tools, evaluate their terms; for high-risk processors, push for acceptable security terms or accept documented risk.

A DPA addresses GDPR processor themes; you may still need security schedules for availability, IR, and assurance report sharing.

Treat maintained SaaS differently from libraries — libraries fall more under secure development and vuln management.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above