ISO27001:2022 – A5.19 Information security in supplier relationships

Introduction to ISO 27001 – A5.19

ISO27001 isn’t just about your internal security — it also requires you to consider the information security risks associated with third parties. This control ensures that you understand the security arrangements of your suppliers and that you manage those relationships proactively.

ISO 27001 – A5.19 is the first in a group of related controls dealing with supplier management. Others include:

What does the standard require?

The standard states:

“Processes and procedures shall be defined and implemented to manage the information security risks associated with the use of suppliers’ products or services.” (A5.19 Information Security in Supplier Relationships)

Why is this required?

Nearly all organisations rely on suppliers — whether that’s physical goods, cloud platforms, or software as a service (SaaS). These suppliers may have access to your systems or sensitive data, introducing potential risks to your information security.

The infamous Target breach (which cost over $200 million) happened because attackers compromised the systems of a refrigeration contractor. This shows how an overlooked vendor can create massive vulnerabilities.

What the auditor is looking for

The auditor will want to see that:

  • You have identified and documented your key suppliers (supplier register)
  • You perform appropriate due diligence before and during supplier engagements
  • You adjust due diligence based on the supplier’s criticality and level of access
  • Contracts and agreements include requirements related to Information Security

It is extremely important to note that the final point above is actually a required in law…. In the EU and UK GDPR there is an expectation that you will select processors (of data) with care to ensure they have appropriate technical and organisational security controls in place.  Therefore this isn’t just good practice… it’s a legal requirement.

What do you need to do?

If you don’t use procurement software, start with a simple Excel spreadsheet that includes:

  • Relationship owner: Who manages the supplier relationship?
  • Contact details: Key communication information
  • Services provided: What do they do for your organisation?
  • Criticality: How important are they to your operations?
  • Access level: What systems or data can they access?
  • Contract details: Contract expiry and location of the agreement

Alongside this register, develop a procedure for supplier onboarding that includes risk assessment and due diligence. You might use a supplier questionnaire, updated annually, to confirm security practices and highlight risks to track on your risk register.

Q & A

Do I need a written policy?

No, but you do need a defined procedure. The standard requires that processes and procedures be established. Document what you currently do — even informally — and improve it as needed.

Where do I start?

Speak with your finance team and request a list of suppliers paid over the last 12 months. Prioritise them by spend or importance. This gives you a realistic starting point to build your supplier register.

Do I need to complete a questionnaire for every supplier?

No. This should be based on risk. Suppliers with no access to systems or data (e.g. office cleaners or fruit delivery) may not need formal review. IT providers, on the other hand, definitely should.

Difficulty rating

We rate this a 1 out of 5. It’s a straightforward administrative control. Start with a simple spreadsheet, gather contracts, and perform annual reviews for key suppliers.

More questions?

ISO27001 controls work together — especially in supplier management. Review FAQs or contact us directly for help with building your supplier register or conducting due diligence.

 We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001”, available on Amazon.

ISO 27001 – A5.19