ISO27001:2022 – A5.22 Monitoring, review and change management of supplier services
Introduction to ISO 27001 – A5.22
As with the other supplier-related controls (A5.19 to A5.23), ISO 27001 – A5.22 highlights just how vital supplier management is in ISO27001. Perhaps none more so than this — because ongoing monitoring, regular reviews, and structured change management are what ensure suppliers continue to meet your needs over time.
What does ISO 27001 – A5.22 require?
The standard states:
“The organisation shall regularly monitor, review, evaluate and manage change in supplier information security practices and service delivery.” (A5.22)
This control consists of three important components:
- Supplier monitoring – Ongoing tracking of performance and compliance
- Supplier review – Periodic meetings and evaluations against SLAs
- Change management – Adjustments or transitions in services or suppliers
Why is this required?
Monitoring and reviewing suppliers allows you to identify risks proactively. Without it, you won’t know if service levels are being met, or if a supplier is introducing vulnerabilities into your environment. This practice also enables relationship management and cost-efficiency improvements over time.
For example:
- You might discover cost savings by switching from monthly to annual software licences.
- Reviewing multiple suppliers may uncover overlaps in services — helping you consolidate for efficiency.
In the case of a breach, regular reviews improve transparency and trust. Your response to incidents — and potential supplier changes — should be governed by this control.
What the auditor is looking for
The auditor won’t expect a written policy or procedure, but will look for evidence that monitoring and reviews take place, and that changes to suppliers are managed in a structured way.
Evidence may include:
- Logs of monitoring activities (e.g. network access by suppliers)
- Minutes of meetings with suppliers
- Annual questionnaires completed by suppliers
- Change management records showing supplier transitions
- Updated agreements following review outcomes
What do you need to do?
Start by reviewing which of your suppliers are critical. Then:
- Request annual security or performance questionnaires
- Hold review meetings with key suppliers — quarterly for ICT providers
- Document decisions or changes from these meetings
- Update contracts or agreements as needed
- Track supplier changes with minimal disruption and maximum transparency
Q & A
How often should we review or monitor suppliers?
It depends on the supplier’s criticality. At minimum, request annual security questionnaires. For high-risk services like ICT or cloud, conduct quarterly reviews aligned with your SLAs and risk appetite.
Do we need to change suppliers if they have a breach?
No, not necessarily. But you must investigate the incident thoroughly and evaluate:
- How the breach occurred
- How and when it was detected
- When you were informed
- The supplier’s response and mitigation steps
Based on this, determine whether trust and service can continue or whether a managed change is required.
Difficulty rating
We rate this control a 1 out of 5. It’s largely administrative, though it requires a structured approach to discussions, documentation, and supplier communications. As always, ICT suppliers may bring some technical complexity to the conversation.
More questions?
ISO27001 controls don’t exist in silos. Review related supplier controls (A5.19 to A5.23), or our FAQ for broader guidance. Need help building a review schedule or risk-based supplier approach? Feel free to reach out.
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001”, available on Amazon.
