In this guide you will learn how to implement ISO 27001 Annex A 5.19 Information Security In Supplier Relationships and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 5.19 Information Security In Supplier Relationships is an ISO 27001 control that requires an organisation to mange the information security risks of using supplier products and services.
Table of contents
- Purpose & Definition
- FREE ISO 27001 Annex A 5.19 Training Video
- Implementation Guide
- How to implement ISO 27001 Annex A 5.19
- How to comply
- How to audit ISO 27001 Annex A 5.19
- How to pass the ISO 27001 Annex A 5.19 audit
- What the auditor will check
- Top 3 Mistakes People Make and How to Avoid Them
- ISO 27001 Annex A 5.19 FAQ
- Related ISO 27001 Controls and Further Reading
- ISO 27001 controls and attribute values
Purpose & Definition
The purpose of ISO 27001 Annex A 5.19 is a preventive control that ensures you maintain an agreed level of information security in supplier relationships.
The ISO 27001 standard defines ISO 27001 Annex A 5.19 as:
Processes and procedures should be defined and implemented to manage the information security risks associated with the use of supplier’s products or services.
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 5.19 Training Video
In this free training video you will learn How to implement ISO 27001 Information Security In Supplier Relationships (Annex A 5.19).
Implementation Guide
Supplier Policy
The standard requires a topic specific policy on supplier relationships – ISO 27001 Supplier Policy Template
ISO 27001 Supplier Security Policy Template
The supplier policy sets out your approach to information security of suppliers.

Supplier Management Process
You will need a supplier management process that sets out
- how to identify and document suppliers and supplier types
- evaluating suppliers according to information process, transmitted or shared
- reviewing the controls that are in place
- documenting what suppliers can access, monitor, control and use
- assessing and managing supplier risks
- monitoring and ensuring compliance to information security
- implementing mitigation for non compliance of a supplier
- the handling of incidents
- availability, business continuity and disaster recovery
- managing the transfer of information
- the process for terminating and ending a supplier / supplier relationship
- what level of security of people and physical security are expected
Supplier Register
The best way to manage ISO 27001 Suppliers is via the ISO 27001 Supplier Register. You can learn more in the ISO 27001 Supplier Register Beginner’s Guide
Supplier Register Template
The supplier register is a record of all your suppliers and is used to manage them.

Supplier Agreements / Contracts
The number one recommendation is to seek professional legal counsel for the provision of all contracts. The following is guidance but you should always defer to professional legal counsel. Always. You are not a lawyer. We are not a lawyer.
Our first line of defence and go to is the supplier agreement or supplier contract. At its core it is a legal mechanism that is legally binding and provides the greatest level of overall protection.
- It sets out what is required, what will be done, who will do it, what happens if things go wrong.
- What information is to be provided, accessed and the methods of access.
- Legal, regulatory and contractual requirements. Elements such as intellectual property rights, copyright information, data protection requirements.
- The controls and levels of controls that are required by both parties to the agreement.
- Acceptable and unacceptable use of assets.
- How to grant and remove access
- Penalties, indemnities and remediation for failings to meet the contract.
- Contact information
- Screening requirements for staff were legally enforceable.
- How evidence and assurance of information security will be provided
- Rights to audit
- How to solve problems or conflicts with the contract
- Appropriate back up, business continuity and disaster recovery
- The process for change management
- Physical security as appropriate
- Information transfer processes
- Termination clauses and processes
- Destruction and removal of data processes
- Handover at the end of the contract
Contracts are kept and recorded in the Third Party Supplier Register. They are reviewed at least annually, based on risk and significant change or event.
How to implement ISO 27001 Annex A 5.19
Implementing ISO 27001 Annex A 5.19 requires a structured approach to manage the risks associated with third-party access to organisational assets. By following these steps, you will establish a robust framework for selecting, monitoring, and offboarding suppliers to maintain your security posture throughout the supply chain.
1. Formalise the Supplier Information Security Policy
- Establish a clear policy that defines the security requirements for all third-party relationships: ensuring consistency across the business.
- Identify specific security requirements for different types of suppliers: such as cloud service providers, maintenance contractors, and consultants.
- Distribute the policy to all procurement staff and relevant stakeholders to ensure it is embedded into the vendor selection process.
2. Categorise Suppliers within the Asset Register
- Identify every supplier with access to organisational information or systems: recording them as entities within your central Asset Register.
- Categorise suppliers based on the sensitivity of data handled: ranging from low-risk service providers to high-risk technical partners.
- Assign an internal owner for each supplier relationship to maintain accountability for security compliance.
3. Conduct Risk-Based Security Due Diligence
- Perform a pre-contract risk assessment for every new supplier: identifying potential vulnerabilities in their operational processes.
- Utilise security questionnaires to evaluate the supplier’s technical controls: focusing on their adherence to industry standards like ISO 27001 or SOC 2.
- Document all identified risks and obtain formal sign-off from the Risk Owner before proceeding with the engagement.
4. Incorporate Security Requirements into Formal Agreements
- Draft legally binding contracts that include specific information security clauses: ensuring the supplier is contractually obligated to protect your data.
- Define clear Rules of Engagement (ROE) for any technical testing or access: establishing the boundaries of the relationship.
- Include a “Right to Audit” clause and mandatory incident notification windows to ensure transparency during a security event.
5. Provision Granular Identity and Access Management (IAM) Roles
- Apply the Principle of Least Privilege (PoLP) by creating specific IAM roles for supplier personnel: restricting access to only the necessary systems.
- Enforce Multi-Factor Authentication (MFA) for all remote access attempts made by third parties: mitigating the risk of credential theft.
- Schedule quarterly reviews of supplier access rights to ensure that redundant accounts are identified and removed promptly.
6. Address ICT Supply Chain Security Risks
- Mandate that primary suppliers flow down security requirements to their own sub-contractors: ensuring security is maintained throughout the tiers of the supply chain.
- Require evidence of secure development lifecycles (SDLC) for any bespoke software provided by third parties.
- Verify the provenance of hardware components to protect against the insertion of malicious implants or counterfeit equipment.
7. Establish Standardised Incident Reporting Procedures
- Define the mandatory reporting timeline for suppliers in the event of a security breach: ensuring your internal team can respond effectively.
- Integrate supplier contact points into your organisational Incident Response Plan (IRP).
- Conduct joint “desktop” exercises with critical suppliers to test the effectiveness of communication channels during a crisis.
8. Execute Regular Security Audits and Compliance Reviews
- Audit critical suppliers annually to verify that they are meeting their contractual security obligations: using a mix of remote assessments and site visits.
- Review independent audit reports and penetration test summaries provided by the supplier to validate their technical claims.
- Log all audit findings and track the remediation of non-conformities through a formal Corrective Action Plan.
9. Manage Changes in Supplier Service Delivery
- Perform a fresh risk assessment whenever a supplier makes significant changes to their service, location, or infrastructure.
- Evaluate the security implications of supplier mergers or acquisitions: ensuring that the new entity maintains the required security standards.
- Update contract terms and security requirements dynamically as the scope of the supplier relationship evolves over time.
- Monitor supplier performance against agreed Service Level Agreements (SLAs) to ensure security controls do not degrade.
10. Revoke Access and Execute Secure Termination
- Implement a termination checklist to ensure all IAM roles and physical access permissions are revoked immediately upon contract end.
- Verify the secure return or certified destruction of all organisational information assets held by the supplier.
- Formalise the transfer of knowledge and responsibilities to ensure that security continuity is maintained during the transition to a new provider.
Check Your Work?
You built it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let an ISO 27001 Lead Auditor check your work.

How to comply
To comply with ISO 27001 Annex A 5.19 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to
- Implement a topic specific policy
- Implement an supplier management process
- Implement an ISO 27001 supplier register
How to audit ISO 27001 Annex A 5.19
Implementing Annex A 5.19 requires a systematic approach to managing third-party risks. This 10-step audit process ensures that security is embedded into the entire supplier lifecycle, from initial selection to contract termination.
1. Formalise the Supplier Security Policy
- Develop a documented policy defining security requirements for all third-party entities.
- Ensure the policy addresses data protection, physical security, and personnel screening.
- Communicate the policy to all relevant internal stakeholders and procurement teams.
2. Categorise Suppliers within the Asset Register
- Identify every supplier with access to organisational information or systems.
- Record these entities within the formal Asset Register to ensure full visibility.
- Assign risk levels based on the sensitivity of the data the supplier processes.
3. Conduct Comprehensive Supplier Risk Assessments
- Evaluate the security posture of potential suppliers before signing contracts.
- Use standardised questionnaires to assess technical controls and compliance history.
- Document identified risks and determine if they fall within the organisational risk appetite.
4. Incorporate Security Requirements into Formal Agreements
- Define clear security obligations within legally binding contracts and NDAs.
- Include a “Right to Audit” clause and establish a clear Rules of Engagement (ROE) document.
- Specify the required uptime, incident notification windows, and data handling procedures.
5. Provision Granular Identity and Access Management (IAM)
- Apply the Principle of Least Privilege (PoLP) for all supplier accounts.
- Enforce Multi-Factor Authentication (MFA) for any remote or administrative access.
- Log and monitor all third-party access attempts to sensitive network segments.
6. Manage Information Security in the ICT Supply Chain
- Mandate that primary suppliers flow down security requirements to their sub-contractors.
- Assess the security of hardware and software components provided by third parties.
- Verify that suppliers follow secure development and manufacturing practices.
7. Establish Incident Management and Reporting Protocols
- Standardise how suppliers must report security breaches or potential vulnerabilities.
- Define the escalation path for significant incidents affecting organisational data.
- Include suppliers in periodic incident response testing and desktop exercises.
8. Execute Regular Security Audits and Compliance Reviews
- Perform scheduled reviews of supplier performance against contractual security obligations.
- Conduct technical audits or vulnerability scans where the ROE permits.
- Request and review independent audit reports, such as SOC 2 or ISO 27001 certificates.
9. Monitor Continuous Service Delivery and Changes
- Track supplier performance against agreed service levels and security KPIs.
- Assess the impact of any changes to the supplier’s service, location, or infrastructure.
- Update risk assessments whenever a significant change occurs in the supplier relationship.
- Evaluate the impact of supplier organisational changes, such as mergers or acquisitions.
10. Revoke Access and Manage Service Termination
- Ensure all IAM roles and physical access permissions are revoked immediately upon termination.
- Verify the secure return or certified destruction of all organisational assets and data.
- Maintain a checklist to confirm that all post-termination obligations are fulfilled.
How to pass the ISO 27001 Annex A 5.19 audit
To pass an audit of ISO 27001 Annex A 5.19 you are going to make sure that you have followed the steps above in how to comply.

What the auditor will check
The audit is going to check a number of areas. Lets go through the most common
1. That you have a supplier management process
The auditor is going to check the rules, procedures and supplier management methodology and make sure you followed them. Make sure all suppliers are listed, you have contracts or agreements or terms for each supplier and that you have assurance they are doing the right thing for information security.
2. That you have an ISO 27001 Supplier Register
You will need an ISO 27001 Supplier Register to record and manage your suppliers. Make sure it is up to date and reflects your reality.
3. Documentation
They are going to look at audit trails and all your documentation and see that is classified and labelled. All the documents that you show them, as a minimum if they are confidential should be labelled as such. Is the document up to date. Has it been reviewed in the last 12 months. Does the version control match.
Top 3 Mistakes People Make and How to Avoid Them
The top 3 Mistakes People Make For ISO 27001 Annex A 5.19 are
1. You have no contracts or legal terms with a supplier
Make sure that there is a contract, agreement, terms of business or some legal mechanism for engaging with suppliers and you have a copy, it is in date and covers what you are using.
2. You have no assurance they are doing the right thing for information security
Make sure you have done your security assessment and can place your hands on an in date certificate such as an ISO 27001 Certification for assurance they are doing the right thing. It needs to be in date a cover the products and / or services you have acquired and are using form the supplier.
3. Your document and version control is wrong
Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
ISO 27001 Annex A 5.19 FAQ
A supplier risk assessment is performed by evaluating a vendor’s security posture against your organisation’s risk appetite using questionnaires or audit reports.
Step 1: Determine the sensitivity of the data the supplier will access.
Step 2: Issue a Security Questionnaire (SAQ) or review SOC 2/ISO 27001 certificates.
Step 3: Identify gaps between vendor controls and your internal requirements.
Step 4: Implement compensatory controls or reject the supplier based on the risk score.
Yes, while the specific terminology may vary, the organisation must have the legal right to monitor and review supplier security performance.
Allows for periodic onsite or remote security audits.
Mandates that suppliers provide independent audit reports (e.g., SOC 2 Type II).
Ensures the organisation can verify that security controls are functioning as promised.
Typically formalised within the Master Service Agreement (MSA) or a DPA.
Related ISO 27001 Controls and Further Reading
- ISO 27001 Supplier Security Policy Beginner’s Guide
- ISO 27001: The Importance Of Third-Party Supplier Security Management
ISO 27001 controls and attribute values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Confidentiality | Identify | Supplier relationships security | Protection |
| Availability | Governance and ecosystem | |||
| Integrity |
