ISO 27001A.5 — Monitoring, review and change management of supplier services
A.5.22
Monitoring, review and change management of supplier services
ISO 27001 · ISO/IEC 27001:2022 · Last verified July 2026
Objective
Monitor, review, and manage changes to supplier services so security posture remains acceptable.
Points of focus
- Service changes detected or notified
- Periodic assurance review
- Change impact on SoA and risk
- Exit triggers when posture degrades
Implementation notes
Calendar re-reviews by tier. Subscribe to vendor status/security notification channels. When suppliers add regions or AI features that touch customer data, re-run diligence and update DPAs if needed. Feed outcomes into management review. Align with A.5.20 contract rights to obtain fresh assurance reports.
Audit tip: Show last year's review of a critical vendor and one mid-cycle change you evaluated.
Evidence auditors typically request:
- Annual vendor review records
- Tickets reacting to supplier security notices
- Updated diligence after major feature/region change
- Risk acceptance for overdue reviews
Common gaps
- SOC reports collected once and never re-read
- No owner for vendor alert emails
- Customer-impacting supplier change missed
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| ISO 27001 | A.5.22 | This control |
| GDPR | Article 28 | Related GDPR articles for personal-data security or processor themes — not a compliance claim. |
Primary sources
- ISO/IEC 27001:2022 Annex A: ISO/IEC 27001:2022 Annex A (A.5.22)
Frequently Asked Questions
Proactively request current reports on cadence; escalate or replace if silence blocks risk decisions.
Tooling helps tracking; humans still evaluate report exceptions and residual risk.
Document expedited diligence and time-boxed risk acceptance with a follow-up full review.