A.5.22A.5 Organizational controls

Monitoring, review and change management of supplier services

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.5.22 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Regularly monitor, review and control changes to the security practices and service delivery of suppliers.

How to meet this control

In short: Regularly monitor, review, audit and manage changes to supplier service delivery.

  1. Step 01Schedule annual vendor reviews and re-assess on major scope or ownership changes
  2. Step 02Track supplier performance against agreed service levels and review their service reports
  3. Step 03Review supplier audit reports and SOC 2 or ISO 27001 bridge letters and follow up on noted exceptions
  4. Step 04Manage any supplier security events, incidents or vulnerabilities through your incident process
  5. Step 05Assign a named relationship owner for each significant supplier to act on shortfalls

Tip: Schedule annual vendor reviews; re-assess on major scope changes.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Track supplier service performance against the agreed terms and service levels
  • ›Watch for changes suppliers make, including new technologies, sub-suppliers or relocated facilities
  • ›Review supplier service reports and hold regular progress meetings
  • ›Audit suppliers and sub-suppliers, drawing on independent auditor reports, and follow up on issues
  • ›Review supplier audit trails and records of security events, faults and disruptions
  • ›Respond to and manage any security events, incidents or vulnerabilities tied to the supplier
  • ›Confirm suppliers keep enough service continuity capacity and plans to recover from major failures
  • ›Assign a named person or team to own each supplier relationship and act on service shortfalls

Audit evidence to keep

  • - Annual or periodic supplier review records with outcomes
  • - Supplier service reports and SLA performance tracking
  • - Reviewed supplier audit or attestation reports with follow-up actions
  • - Named supplier relationship owners recorded in the vendor register

Common mistakes

  • - Treating all suppliers as equal risk
  • - Collecting vendor reports but not reviewing exceptions
  • - Forgetting exit, deletion, sub-processor, and change-notice terms

Owner, cadence, and proof

Assign one accountable owner for A.5.22. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all organizational controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.