Skip to content
compliancebase
ISO 27001A.5 — Monitoring, review and change management of supplier services

A.5.22

Monitoring, review and change management of supplier services

ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026

Objective

Monitor, review, and manage changes to supplier services so security posture remains acceptable.

Points of focus

  • Service changes detected or notified
  • Periodic assurance review
  • Change impact on SoA and risk
  • Exit triggers when posture degrades

Implementation notes

Calendar re-reviews by tier. Subscribe to vendor status/security notification channels. When suppliers add regions or AI features that touch customer data, re-run diligence and update DPAs if needed. Feed outcomes into management review. Align with A.5.20 contract rights to obtain fresh assurance reports.

Audit tip: Show last year's review of a critical vendor and one mid-cycle change you evaluated.

Evidence auditors typically request:

  • Annual vendor review records
  • Tickets reacting to supplier security notices
  • Updated diligence after major feature/region change
  • Risk acceptance for overdue reviews

Common gaps

  • SOC reports collected once and never re-read
  • No owner for vendor alert emails
  • Customer-impacting supplier change missed

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.5.22This control
GDPRArticle 28Related GDPR articles for personal-data security or processor themes — not a compliance claim.

Primary sources

Frequently Asked Questions

Proactively request current reports on cadence; escalate or replace if silence blocks risk decisions.

Tooling helps tracking; humans still evaluate report exceptions and residual risk.

Document expedited diligence and time-boxed risk acceptance with a follow-up full review.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: July 2026 · Primary sources linked above