Monitoring, review and change management of supplier services
Purpose
Regularly monitor, review and control changes to the security practices and service delivery of suppliers.
How to meet this control
In short: Regularly monitor, review, audit and manage changes to supplier service delivery.
- Step 01Schedule annual vendor reviews and re-assess on major scope or ownership changes
- Step 02Track supplier performance against agreed service levels and review their service reports
- Step 03Review supplier audit reports and SOC 2 or ISO 27001 bridge letters and follow up on noted exceptions
- Step 04Manage any supplier security events, incidents or vulnerabilities through your incident process
- Step 05Assign a named relationship owner for each significant supplier to act on shortfalls
Tip: Schedule annual vendor reviews; re-assess on major scope changes.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Track supplier service performance against the agreed terms and service levels
- ›Watch for changes suppliers make, including new technologies, sub-suppliers or relocated facilities
- ›Review supplier service reports and hold regular progress meetings
- ›Audit suppliers and sub-suppliers, drawing on independent auditor reports, and follow up on issues
- ›Review supplier audit trails and records of security events, faults and disruptions
- ›Respond to and manage any security events, incidents or vulnerabilities tied to the supplier
- ›Confirm suppliers keep enough service continuity capacity and plans to recover from major failures
- ›Assign a named person or team to own each supplier relationship and act on service shortfalls
Audit evidence to keep
- - Annual or periodic supplier review records with outcomes
- - Supplier service reports and SLA performance tracking
- - Reviewed supplier audit or attestation reports with follow-up actions
- - Named supplier relationship owners recorded in the vendor register
Common mistakes
- - Treating all suppliers as equal risk
- - Collecting vendor reports but not reviewing exceptions
- - Forgetting exit, deletion, sub-processor, and change-notice terms
Owner, cadence, and proof
Assign one accountable owner for A.5.22. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.