A.5.19A.5 Organizational controls

Information security in supplier relationships

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.5.19 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Maintain an agreed level of security in relationships with suppliers.

How to meet this control

In short: Define and implement processes to manage security risks from supplier use.

  1. Step 01Maintain a vendor register with a risk rating per supplier based on the data they touch and the access they hold
  2. Step 02Run security due diligence proportionate to risk before onboarding (questionnaire, SOC 2 or ISO 27001 evidence, references)
  3. Step 03Define what each supplier may access, monitor or control and document it
  4. Step 04Monitor supplier compliance with security requirements and manage non-compliance through a defined process
  5. Step 05Plan secure exit on termination including de-provisioning access and returning or destroying data

Tip: Maintain a vendor register with a risk rating per supplier.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Establish and communicate a topic-specific policy on supplier relationships
  • ›Identify and document the types of suppliers that can affect the organisation’s information
  • ›Evaluate and select suppliers based on the sensitivity of information and the adequacy of their controls
  • ›Define what information and infrastructure suppliers can access, monitor or control
  • ›Assess and manage risks from supplier access and from faulty or vulnerable supplier products
  • ›Monitor supplier compliance with security requirements and handle any non-compliance
  • ›Agree how supplier-related incidents and contingencies will be handled, with responsibilities defined on both sides
  • ›Plan how you would keep operating if a supplier failed or stopped supplying, for example by identifying alternative suppliers in advance
  • ›Train staff who interact with suppliers on the relevant rules and procedures
  • ›Plan for secure termination of the relationship, including de-provisioning access and handling data

Audit evidence to keep

  • - Vendor register with risk ratings and the data each supplier accesses
  • - Completed due diligence or security assessments for key suppliers
  • - Records of supplier compliance monitoring and any non-compliance handling
  • - Supplier offboarding records showing access removal and data return

Common mistakes

  • - Treating all suppliers as equal risk
  • - Collecting vendor reports but not reviewing exceptions
  • - Forgetting exit, deletion, sub-processor, and change-notice terms

Owner, cadence, and proof

Assign one accountable owner for A.5.19. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all organizational controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.