ISO 27001 Annex A 5.19 Information Security in Supplier Relationships Explained

Stuart And Fay High Table

ISO 27001 Information Security in Supplier Relationships

ISO 27001 Annex A 5.19 Information Security In Supplier Relationships is an ISO 27001 control that requires an organisation to mange the information security risks of using supplier products and services.

It is about securing the supply chain.

Suppliers represent one of your biggest risks as you cannot directly manage them or influence them and it is likely you rely on them, they have your data and provide services that you need to be successful.

Key Takeaways

ISO 27001 Annex A 5.19 requires organisations to define and implement processes to manage information security risks associated with the use of supplier products or services. Suppliers often represent your greatest “blind spot”; they hold your data and maintain your systems, yet you cannot directly manage their internal security. This control ensures that you maintain an agreed-upon level of security throughout the Supply Chain, from initial vetting to the termination of the contract.

Purpose

The purpose of ISO 27001 Annex A 5.19 is a preventive control that ensures you maintain an agreed level of information security in supplier relationships.

Definition

The ISO 27001 standard defines ISO 27001 Annex A 5.19 as:

Processes and procedures should be defined and implemented to manage the information security risks associated with the use of supplier’s products or services.

ISO 27001:2022 Annex A 5.19 Information Security In Supplier Relationships

ISO 27001 Annex A 5.19 is a security control that mandates the establishment of processes and procedures to manage risks associated with third-party partners. The primary implementation requirement involves formalising supplier security policies and vetting procedures, ensuring a significant business benefit by protecting sensitive data and maintaining operational uptime.

Requirement

  • Supplier Vetting & Due Diligence: Before signing a contract, you must evaluate a supplier’s security posture. This is typically done through security questionnaires or by verifying their ISO 27001 Certification.
  • Risk-Based Tiering: Not all suppliers are equal. You should categorize suppliers into “Tiers” based on the sensitivity of the data they handle or their criticality to your operations.
  • Contractual Binding: Security requirements must be legally enforceable. This includes “Right to Audit” clauses, data protection terms (GDPR), and incident notification timelines.
  • The Supplier Register: You must maintain a central inventory of all third-party suppliers, their contact details, and their current security status.
  • Access Management: You must define how suppliers access your systems, ensuring they only have the minimum access required (Least Privilege) and that this access is revoked immediately when the project ends.
  • Ongoing Monitoring: Supplier security is not a “one-off” check. You must periodically review critical suppliers to ensure they haven’t allowed their certifications to lapse or their security standards to drift.

Audit Focus

  1. Direct Evidence of Vetting: “Show me the security assessment for your cloud hosting provider or your payroll company. How did you verify they were secure?”
  2. Contractual Review: “Does your contract with your external IT support include a clause about notifying you of a data breach within a specific timeframe?”
  3. Tiering Logic: “Show me your Supplier Tiering Matrix. Why is your stationery supplier categorized differently than your SaaS CRM provider?”

FREE Training Video

Supplier Policy

The standard requires a topic specific policy on supplier relationships – ISO 27001 Supplier Policy Template

Supplier Management Process

You will need a supplier management process that sets out

  • how to identify and document suppliers and supplier types
  • evaluating suppliers according to information process, transmitted or shared
  • reviewing the controls that are in place
  • documenting what suppliers can access, monitor, control and use
  • assessing and managing supplier risks
  • monitoring and ensuring compliance to information security
  • implementing mitigation for non compliance of a supplier
  • the handling of incidents
  • availability, business continuity and disaster recovery
  • managing the transfer of information
  • the process for terminating and ending a supplier / supplier relationship
  • what level of security of people and physical security are expected

Supplier Register

The best way to manage ISO 27001 Suppliers is via the ISO 27001 Supplier Register. You can learn more in the ISO 27001 Supplier Register Beginner’s Guide

Supplier Agreements / Contracts

The number one recommendation is to seek professional legal counsel for the provision of all contracts. The following is guidance but you should always defer to professional legal counsel. Always. You are not a lawyer. We are not a lawyer.

Our first line of defence and go to is the supplier agreement or supplier contract. At its core it is a legal mechanism that is legally binding and provides the greatest level of overall protection.

  • It sets out what is required, what will be done, who will do it, what happens if things go wrong.
  • What information is to be provided, accessed and the methods of access.
  • Legal, regulatory and contractual requirements. Elements such as intellectual property rights, copyright information, data protection requirements.
  • The controls and levels of controls that are required by both parties to the agreement.
  • Acceptable and unacceptable use of assets.
  • How to grant and remove access
  • Penalties, indemnities and remediation for failings to meet the contract.
  • Contact information
  • Screening requirements for staff were legally enforceable.
  • How evidence and assurance of information security will be provided
  • Rights to audit
  • How to solve problems or conflicts with the contract
  • Appropriate back up, business continuity and disaster recovery
  • The process for change management
  • Physical security as appropriate
  • Information transfer processes
  • Termination clauses and processes
  • Destruction and removal of data processes
  • Handover at the end of the contract

Contracts are kept and recorded in the Third Party Supplier Register. They are reviewed at least annually, based on risk and significant change or event.

How to implement it

Implementing ISO 27001 Annex A 5.19 requires a structured approach to manage the risks associated with third-party access to organisational assets. By following these steps, you will establish a robust framework for selecting, monitoring, and offboarding suppliers to maintain your security posture throughout the supply chain.

1. Formalise the Supplier Information Security Policy

  • Establish a clear policy that defines the security requirements for all third-party relationships: ensuring consistency across the business.
  • Identify specific security requirements for different types of suppliers: such as cloud service providers, maintenance contractors, and consultants.
  • Distribute the policy to all procurement staff and relevant stakeholders to ensure it is embedded into the vendor selection process.

2. Categorise Suppliers within the Asset Register

  • Identify every supplier with access to organisational information or systems: recording them as entities within your central Asset Register.
  • Categorise suppliers based on the sensitivity of data handled: ranging from low-risk service providers to high-risk technical partners.
  • Assign an internal owner for each supplier relationship to maintain accountability for security compliance.

3. Conduct Risk-Based Security Due Diligence

  • Perform a pre-contract risk assessment for every new supplier: identifying potential vulnerabilities in their operational processes.
  • Utilise security questionnaires to evaluate the supplier’s technical controls: focusing on their adherence to industry standards like ISO 27001 or SOC 2.
  • Document all identified risks and obtain formal sign-off from the Risk Owner before proceeding with the engagement.

4. Incorporate Security Requirements into Formal Agreements

  • Draft legally binding contracts that include specific information security clauses: ensuring the supplier is contractually obligated to protect your data.
  • Define clear Rules of Engagement (ROE) for any technical testing or access: establishing the boundaries of the relationship.
  • Include a “Right to Audit” clause and mandatory incident notification windows to ensure transparency during a security event.

5. Provision Granular Identity and Access Management (IAM) Roles

  • Apply the Principle of Least Privilege (PoLP) by creating specific IAM roles for supplier personnel: restricting access to only the necessary systems.
  • Enforce Multi-Factor Authentication (MFA) for all remote access attempts made by third parties: mitigating the risk of credential theft.
  • Schedule quarterly reviews of supplier access rights to ensure that redundant accounts are identified and removed promptly.

6. Address ICT Supply Chain Security Risks

  • Mandate that primary suppliers flow down security requirements to their own sub-contractors: ensuring security is maintained throughout the tiers of the supply chain.
  • Require evidence of secure development lifecycles (SDLC) for any bespoke software provided by third parties.
  • Verify the provenance of hardware components to protect against the insertion of malicious implants or counterfeit equipment.

7. Establish Standardised Incident Reporting Procedures

  • Define the mandatory reporting timeline for suppliers in the event of a security breach: ensuring your internal team can respond effectively.
  • Integrate supplier contact points into your organisational Incident Response Plan (IRP).
  • Conduct joint “desktop” exercises with critical suppliers to test the effectiveness of communication channels during a crisis.

8. Execute Regular Security Audits and Compliance Reviews

  • Audit critical suppliers annually to verify that they are meeting their contractual security obligations: using a mix of remote assessments and site visits.
  • Review independent audit reports and penetration test summaries provided by the supplier to validate their technical claims.
  • Log all audit findings and track the remediation of non-conformities through a formal Corrective Action Plan.

9. Manage Changes in Supplier Service Delivery

  • Perform a fresh risk assessment whenever a supplier makes significant changes to their service, location, or infrastructure.
  • Evaluate the security implications of supplier mergers or acquisitions: ensuring that the new entity maintains the required security standards.
  • Update contract terms and security requirements dynamically as the scope of the supplier relationship evolves over time.
  • Monitor supplier performance against agreed Service Level Agreements (SLAs) to ensure security controls do not degrade.

10. Revoke Access and Execute Secure Termination

  • Implement a termination checklist to ensure all IAM roles and physical access permissions are revoked immediately upon contract end.
  • Verify the secure return or certified destruction of all organisational information assets held by the supplier.
  • Formalise the transfer of knowledge and responsibilities to ensure that security continuity is maintained during the transition to a new provider.

Supplier Tiering Example

TierDefinitionExampleDue Diligence Required
Tier 1 (Critical)Holds sensitive data (PII) or critical to uptime.AWS, Payroll Provider.ISO 27001 Cert + Deep Audit.
Tier 2 (High)Access to internal systems but no sensitive data.IT Support Agency.Security Questionnaire.
Tier 3 (Low)No access to systems/data.Stationary Supplier.None / Basic Checks.

ISO 27001 Supplier Register Template

The ultimate ISO 27001 Supplier Register Template.

ISO27001 Third Party Supplier Register - ISO 27001 Annex A 5.19 Template

ISO 27001 Supplier Policy Template

The ultimate ISO 27001 Supplier Register Template.

ISO27001 Third Party Supplier Policy - ISO 27001 Annex A 5.19 Template

How to comply

To comply with ISO 27001 Annex A 5.19 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to

How to audit it

Implementing Annex A 5.19 requires a systematic approach to managing third-party risks. This 10-step audit process ensures that security is embedded into the entire supplier lifecycle, from initial selection to contract termination.

1. Formalise the Supplier Security Policy

  • Develop a documented policy defining security requirements for all third-party entities.
  • Ensure the policy addresses data protection, physical security, and personnel screening.
  • Communicate the policy to all relevant internal stakeholders and procurement teams.

2. Categorise Suppliers within the Asset Register

  • Identify every supplier with access to organisational information or systems.
  • Record these entities within the formal Asset Register to ensure full visibility.
  • Assign risk levels based on the sensitivity of the data the supplier processes.

3. Conduct Comprehensive Supplier Risk Assessments

  • Evaluate the security posture of potential suppliers before signing contracts.
  • Use standardised questionnaires to assess technical controls and compliance history.
  • Document identified risks and determine if they fall within the organisational risk appetite.

4. Incorporate Security Requirements into Formal Agreements

  • Define clear security obligations within legally binding contracts and NDAs.
  • Include a “Right to Audit” clause and establish a clear Rules of Engagement (ROE) document.
  • Specify the required uptime, incident notification windows, and data handling procedures.

5. Provision Granular Identity and Access Management (IAM)

  • Apply the Principle of Least Privilege (PoLP) for all supplier accounts.
  • Enforce Multi-Factor Authentication (MFA) for any remote or administrative access.
  • Log and monitor all third-party access attempts to sensitive network segments.

6. Manage Information Security in the ICT Supply Chain

  • Mandate that primary suppliers flow down security requirements to their sub-contractors.
  • Assess the security of hardware and software components provided by third parties.
  • Verify that suppliers follow secure development and manufacturing practices.

7. Establish Incident Management and Reporting Protocols

  • Standardise how suppliers must report security breaches or potential vulnerabilities.
  • Define the escalation path for significant incidents affecting organisational data.
  • Include suppliers in periodic incident response testing and desktop exercises.

8. Execute Regular Security Audits and Compliance Reviews

  • Perform scheduled reviews of supplier performance against contractual security obligations.
  • Conduct technical audits or vulnerability scans where the ROE permits.
  • Request and review independent audit reports, such as SOC 2 or ISO 27001 certificates.

9. Monitor Continuous Service Delivery and Changes

  • Track supplier performance against agreed service levels and security KPIs.
  • Assess the impact of any changes to the supplier’s service, location, or infrastructure.
  • Update risk assessments whenever a significant change occurs in the supplier relationship.
  • Evaluate the impact of supplier organisational changes, such as mergers or acquisitions.

10. Revoke Access and Manage Service Termination

  • Ensure all IAM roles and physical access permissions are revoked immediately upon termination.
  • Verify the secure return or certified destruction of all organisational assets and data.
  • Maintain a checklist to confirm that all post-termination obligations are fulfilled.

How to pass the audit

To pass an audit of ISO 27001 Annex A 5.19 you are going to make sure that you have followed the steps above in how to comply.

You are going to do that by first conducting an internal audit, following the How to Conduct an ISO 27001 Internal Audit Guide.

What the auditor will check

The audit is going to check a number of areas. Lets go through the most common

1. That you have a supplier management process

The auditor is going to check the rules, procedures and supplier management methodology and make sure you followed them. Make sure all suppliers are listed, you have contracts or agreements or terms for each supplier and that you have assurance they are doing the right thing for information security.

2. That you have an ISO 27001 Supplier Register

You will need an ISO 27001 Supplier Register to record and manage your suppliers. Make sure it is up to date and reflects your reality.

3. Documentation

They are going to look at audit trails and all your documentation and see that is classified and labelled. All the documents that you show them, as a minimum if they are confidential should be labelled as such. Is the document up to date. Has it been reviewed in the last 12 months. Does the version control match.

Top 3 Mistakes People Make and How to Avoid Them

The top 3 Mistakes People Make For ISO 27001 Annex A 5.19 are

Make sure that there is a contract, agreement, terms of business or some legal mechanism for engaging with suppliers and you have a copy, it is in date and covers what you are using.

2. You have no assurance they are doing the right thing for information security

Make sure you have done your security assessment and can place your hands on an in date certificate such as an ISO 27001 Certification for assurance they are doing the right thing. It needs to be in date a cover the products and / or services you have acquired and are using form the supplier.

3. Your document and version control is wrong

Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.

Applicability across different business models

Business TypeApplicability & InterpretationExamples of Control
Small Businesses

The “Tiering” Logic. You don’t need a complex procurement team. Compliance means having a list (Register) that separates critical data handlers (e.g., your Accountant) from non-risky vendors (e.g., Office Cleaners).

Supplier Register: A simple Excel sheet listing all vendors, categorized as “Critical” or “Non-Critical.” • Basic Checks: Verifying that your IT support provider uses 2FA before you hire them.

Tech Startups

Onboarding Gates. The focus is on preventing “Shadow IT.” You need a policy that says employees cannot sign up for new SaaS tools without a quick security check.

Vendor Risk Assessment (VRA): Sending a lightweight security questionnaire to new SaaS vendors before signing the contract. • Policy Enforcement: A “Procurement Policy” stating that no company credit card can be used for software without CTO approval.

AI Companies

Data Ethics & Privacy. Supplier selection isn’t just about security; it’s about data rights. You must vet whether a supplier (e.g., a data labelling firm) has adequate privacy controls to handle your training sets.

Due Diligence: Specifically checking if data annotation vendors conduct background checks on their staff. • Ethical Sourcing: Ensuring your “Supplier Policy” mandates that data providers have valid consent for the datasets they sell you.

Standard / LawRelevant Section / RequirementMapping & Compliance Logic
NIST CSF v2.0GV.SC (Supply Chain Risk Management)NIST mandates that supply chain risk is part of the governance strategy. It requires formalised supplier selection and monitoring, mirroring A 5.19.
DORA (EU)Chapter V (ICT Third-Party Risk)The most stringent mapping. DORA requires “Standard Contractual Clauses” and mandatory exit strategies for critical ICT third-party providers.
NIS2 (EU)Article 21 (Supply Chain Security)Requires entities to assess the security of their direct suppliers and the quality of their cybersecurity practices, including secure development.
SOC 2 (Trust Services)CC9.1 & CC9.2 (Vendor Management)Focuses on whether the entity evaluates, selects, and monitors third-party service providers to ensure security commitments are met.
GDPR (EU/UK)Article 28 (Processor Contracts)Mandates that “Data Processing Agreements” (DPAs) are in place, ensuring the supplier provides sufficient guarantees of technical security.
UK Data (Use & Access) Act 2025Part 1 (Security of Data Flows)Evolves GDPR by focusing on “Trusted Data Partners.” A 5.19 is the mechanism used to verify these partners meet the UK’s updated security thresholds.
UK Cyber Security & Resilience BillSection: MSP RegulationExpands the scope of NIS2-style reporting to Managed Service Providers. A 5.19 is the audit control used to verify MSP compliance.
EU AI ActArticle 16 & 28 (Provider Obligations)High-risk AI system providers must ensure their suppliers (data annotators, model hosts) follow strict quality and security protocols.
ISO/IEC 42001:2023Control 8.5 (AI Supply Chain)The AI Management System standard. It directly references A 5.19 for managing the unique risks of “AI as a Service” (AIaaS) vendors.
CIRCIA (USA)72-Hour Reporting RuleWhile focused on the incident, A 5.19 is where you contractually “hook” the supplier into the 72-hour reporting window required by US law.
EU PLD (Product Liability)Cybersecurity Flaw LiabilityExtends strict liability to software. A 5.19 becomes a “liability shield” for companies to ensure suppliers are accountable for flaws.
ECCF (EU Certification)Harmonised Security LabelsFuture state mapping where A 5.19 reviews will require suppliers to present an EU-wide harmonised security label for their products.
HIPAA (USA)§ 164.308(b) (Business Associates)Requires “Business Associate Agreements” (BAAs) to ensure third parties protect PHI (Protected Health Information).
CCPA / CPRA (California)§ 1798.140 (Service Providers)Requires written contracts that prohibit service providers from retaining, using, or disclosing personal information for any other purpose.

FAQ

How do you perform a supplier security risk assessment?

A supplier risk assessment is performed by evaluating a vendor’s security posture against your organisation’s risk appetite using questionnaires or audit reports.
Step 1: Determine the sensitivity of the data the supplier will access.
Step 2: Issue a Security Questionnaire (SAQ) or review SOC 2/ISO 27001 certificates.
Step 3: Identify gaps between vendor controls and your internal requirements.
Step 4: Implement compensatory controls or reject the supplier based on the risk score.

Is a “Right to Audit” clause required for Annex A 5.19?

Yes, while the specific terminology may vary, the organisation must have the legal right to monitor and review supplier security performance.
Allows for periodic onsite or remote security audits.
Mandates that suppliers provide independent audit reports (e.g., SOC 2 Type II).
Ensures the organisation can verify that security controls are functioning as promised.
Typically formalised within the Master Service Agreement (MSA) or a DPA.

ISO 27001 controls and attribute values

Control typeInformation security propertiesCybersecurity conceptsOperational capabilitiesSecurity domains
PreventiveConfidentialityIdentifySupplier relationships securityProtection
AvailabilityGovernance and ecosystem
Integrity

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top