ISO 27001:2022 – A5.20 Addressing information security within supplier agreements

Introduction to ISO 27001 – A5.20

As stated in Annex A5.19 – Information Security in Supplier Relationships, there is significant cross-over between supplier-related controls. Therefore ISO 27001 – A5.20 should be reviewed alongside:

What does the standard require?

The standard states:

“Relevant information security requirements shall be established and agreed with each supplier based on the type of supplier relationship.” (A5.20 Addressing Information Security within Supplier Agreements)

Why is this required?

As discussed in A5.19, suppliers and other ‘interested parties’ often have elevated access to your systems and information. Without clear agreements, their access and responsibilities can go unchecked, potentially leading to major security incidents — like the Target breach, where lack of a defined agreement with a third-party vendor was a contributing factor.

Well-defined agreements ensure mutual clarity on roles, responsibilities, and expectations — including data protection. For data processors, a Data Processing Agreement (DPA) may also be legally required under data protection laws.

What the auditor is looking for

The auditor will want to see that you have written agreements or contracts in place with key suppliers — especially those who process or access your data. These agreements should include:

  • Clearly defined roles and responsibilities
  • Confidentiality clauses
  • Incident response and escalation procedures
  • Access control requirements and limitations
  • Consequences of non-compliance
  • Termination clauses

In addition, the auditor will expect evidence of regular supplier reviews. These don’t need to be formally documented but should be demonstrable through meeting minutes, action logs, or email correspondence.

What do you need to do?

  • Review your existing supplier agreement templates.
  • Ensure they include the security and compliance elements outlined above.
  • Update outdated templates or seek legal input if necessary — these are legally binding documents.
  • Document your review process in your supplier register, including contract review dates and points of contact.

Q & A

How do we ensure suppliers comply with our agreements?

Firstly, these should be defined (i.e. written down), and agreed prior to the service being provided.  Having regular reviews to ensure everything is on track will reduce the risk of non-compliance. It is far better to have these meetings regularly so that there are no issues, but if there are problems, the agreement should include clear consequences for non-compliance.

 

How often should we review our agreements?

This depends on the kind of agreement in place, but at the very least your supplier agreements should be reviewed annually. Again, this ensures that everyone is clear about what the service is, and how it should be delivered. Any deviation from the agreement can be quickly addressed to ensure everything remains on track. The longer you leave it between reviews, the harder this may become.

 

Difficulty rating

We rate this a 1 out of 5 difficulty rating. This means that it requires little if any technical skill to understand the requirement. You need to conduct a review of your supplier agreements and capture the saliant points (noted above).  These can be added to your Supplier Register with dates for review alongside them.

 

More questions?

Remember that nothing in ISO27001 sits in isolation, so you should review our FAQ to gain answers to other aspects of the standard. Follow the links in this control to see the relationship in other controls, but if you’re still confused about this control, then please get in touch.

 

 We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” which is available on Amazon. 

ISO 27001 – A5.20