In this guide you will learn how to implement ISO 27001 Annex A 5.22 Monitor, review and change management of supplier services and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
ISO 27001 Annex A 5.22 is an ISO 27001 control that requires an organisation to maintain an agreed level of service and information security in line with legal agreements.
Table of contents
- Purpose & Definition
- FREE ISO 27001 Annex A 5.22 Training Video
- Implementation Guide
- How to implement ISO 27001 Annex A 5.22
- How to comply
- How to Audit ISO 27001 Annex A 5.22
- ISO 27001 Templates
- How to pass the audit
- What the auditor will check
- Top 3 Mistakes People Make and How to Avoid Them
- ISO 27001 Annex A 5.22 FAQ
- Related ISO 27001 Controls and Further Reading
- ISO 27001 controls and attribute values
Purpose & Definition
The purpose of ISO 27001 Annex A 5.22 is a preventive control that ensures you maintain an agreed level of information security and service delivery in line with supplier agreements.
The ISO 27001 standard defines ISO 27001 Annex A 5.22 as:
The organisation should regularly monitor, review, evaluate and manage change in supplier information security practices and service delivery.
ISO 27001:2022 Annex A 5.22 Monitor, review and change management of supplier services
White Label
ISO 27001 for Consultants
Custom-brandable ISO 27001 documentation for consultants. Easily rebrand, reduce project time, and deliver professional, high-value security systems. Focus on delivery, not drafting.
FREE ISO 27001 Annex A 5.22 Training Video
In this free training video you will learn How to implement ISO 27001 Change Management of Supplier Services (Annex A 5.22) and Pass Your Audit.
Implementation Guide
As with all the clauses that relate to supplier management we are looking to assign the responsibility to a person or a team with the skills and resources to be able to track that requirements are being met and where not, they are being addressed.
In basic terms it is about making sure that the terms and conditions in legal agreements that relate to information security are being met. It is about managing issues, problems and incidents as the occur and if changes are needed to suppliers that those changes do not adversely impact the business.
You are going to:
- Those service performance levels are going to be monitored, most likely via reports or metrics or dashboards.
- Check and respond to changes made by suppliers such as updates, changes to process, changes to controls
- Where supplier services change to monitor and respond to those
- Keep your eye on the terms and conditions of the agreements and that they are followed
- Ensure those pesky suppliers are evaluated and maintain adequate security
It isn’t really that hard although you can over complicate it very easily. Have agreements in place, make sure they are followed, check them and respond when things go wrong.
We are not teaching people how to do supplier management or change it. What is here is common sense.
Supplier Security Policy Template
The ISO 27001 Supplier Service Monitoring & Change Management Policy Template sets out your approach to information security and management of suppliers.

Supplier Register Template
The supplier register is a record of all your suppliers and is used to manage them.

How to implement ISO 27001 Annex A 5.22
Implementing a robust monitoring and review process for supplier services ensures that security standards remain high throughout the lifecycle of the partnership. Use the following ten steps to establish governance, manage changes, and maintain compliance with ISO 27001 Annex A 5.22.
1. Establish a Supplier Monitoring Framework
- Define the scope of monitoring based on the supplier’s risk classification in your Asset Register.
- Identify specific security requirements, such as encryption standards or data residency, that must be tracked.
- Document the frequency of reviews, ensuring high-risk vendors receive more frequent oversight.
2. Appoint Qualified Service Owners
- Assign a dedicated Service Owner to each supplier to act as the primary point of contact for performance and security.
- Ensure the Service Owner has the technical authority to review audit logs and performance dashboards.
- Formalise accountability by including supplier oversight in the Service Owner’s job description.
3. Formalise Performance Metrics and SLAs
- Integrate specific security KPIs into Service Level Agreements (SLAs) to make security performance a contractual obligation.
- Include metrics for incident response times, system uptime, and vulnerability patching cycles.
- Ensure these metrics are measurable and reportable through automated dashboards where possible.
4. Schedule Periodic Performance Reviews
- Conduct monthly or quarterly meetings with suppliers to review service delivery against agreed targets.
- Document meeting minutes and track any identified “Non-Conformities” through to resolution.
- Review supplier reports, such as SOC2 Type II or ISO 27001 certificates, to verify ongoing compliance.
5. Execute Independent Supplier Audits
- Exercise your “Right to Audit” (ROE) as defined in the contract to conduct on-site or remote security assessments.
- Focus audits on technical controls, such as IAM roles, MFA implementation, and physical data centre security.
- Use a standardised checklist to ensure consistency across different supplier audits.
6. Implement Supplier Incident Management
- Establish a clear communication channel for the supplier to report security breaches or service failures.
- Define the “Rules of Engagement” (ROE) for joint incident response involving third-party systems.
- Log all supplier-related incidents in your central incident management system for trend analysis.
7. Authorise Service Changes via Formal Governance
- Subject any significant changes in supplier service delivery to a formal Change Management process.
- Evaluate the security impact of changes, such as new sub-processors or transitions to different cloud regions.
- Require formal sign-off from the CISO or Risk Owner before a change is implemented in production.
8. Audit Technical Access and IAM Roles
- Review the list of supplier personnel who have administrative or “Privileged” access to your organisational assets.
- Verify that MFA is enforced for all third-party remote access connections.
- Ensure that access is revoked immediately upon the termination of a supplier’s staff member or the contract itself.
9. Update the Supplier Risk Register
- Re-evaluate the risk profile of each supplier at least annually or following a significant security incident.
- Capture changes in the threat landscape, such as new geopolitical risks or supply chain vulnerabilities.
- Report high-level supplier risks to the management board during the annual ISO 27001 Management Review.
10. Maintain Validated Exit Strategies
- Develop a transition plan to ensure that services can be moved or brought in-house without a security vacuum.
- Define the process for the secure return or destruction of organisational data at the end of the contract.
- Test the exit strategy periodically to ensure the organisation remains resilient to supplier failure.
Check Your Work?
You built it yourself. Maybe with AI. But will it pass the audit?
Don’t gamble – let an ISO 27001 Lead Auditor check your work.

How to comply
To comply with ISO 27001 Annex A 5.22 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to
- Implement a topic specific policy
- Implement a supplier management process
- Include in your supplier management process supplier acquisition and supplier transfer
- Implement an ISO 27001 supplier register
- Have agreements with all suppliers that cover information security requirements
- Have information security assurances for critical suppliers as a minimum and ideally all relevant suppliers
- Monitor those suppliers
- Respond to adverse incidents in a structured way
How to Audit ISO 27001 Annex A 5.22
Auditing the monitoring, review, and change management of supplier services is a critical component of ISO 27001 compliance. As a Lead Auditor, I look for objective evidence that your organisation is proactively governing third-party relationships rather than simply assuming security is being maintained. Follow these ten steps to conduct a thorough technical audit of Annex A 5.22.
1. Inspect the Supplier Asset Register
- Verify that all third-party service providers are documented within a central Asset Register or Supplier Inventory.
- Confirm that each entry includes a risk classification based on the criticality of the data processed.
- Ensure that an owner is assigned to manage the ongoing security relationship for every high-risk supplier.
2. Scrutinise Service Level Agreements (SLAs)
- Review contractual agreements to ensure they contain specific security performance metrics and right-to-audit clauses.
- Identify defined Key Performance Indicators (KPIs) related to system availability, incident response times, and vulnerability remediation.
- Check for clear definitions regarding the notification periods for security breaches or significant service changes.
3. Validate Performance Monitoring Records
- Examine evidence of periodic service reviews, such as meeting minutes or performance dashboards.
- Verify that the organisation tracks supplier performance against the agreed security KPIs.
- Confirm that any identified service shortfalls or security non-conformities have been logged and tracked through to resolution.
4. Audit Independent Assurance Reports
- Inspect copies of independent audit evidence, such as SOC2 Type II reports, ISO 27001 certificates, or penetration test summaries.
- Validate that the scope of these third-party audits covers the specific services provided to your organisation.
- Check that the organisation has reviewed these reports and assessed any noted “exceptions” for their impact on internal security.
5. Review Service Change Management Logs
- Audit the change management process for instances where supplier services have been modified or updated.
- Verify that a formal risk assessment was conducted prior to the implementation of significant service changes.
- Ensure that changes to sub-processors or data storage locations were authorised by the relevant Information Security Officer.
6. Verify Technical Rules of Engagement (ROE)
- Examine Rules of Engagement (ROE) documents for technical audits or vulnerability scans conducted on supplier systems.
- Confirm that the ROE defines the boundaries of testing, communication protocols, and the handling of sensitive findings.
- Check for evidence that these protocols were followed during the most recent technical assessment.
7. Audit Privileged Access and IAM Roles
- Inspect the Identity and Access Management (IAM) roles assigned to supplier personnel within your infrastructure.
- Verify that the principle of least privilege is applied and that administrative access is restricted to authorised tasks.
- Confirm that a formal review of supplier access rights is conducted at least quarterly to revoke unnecessary permissions.
8. Scrutinise Supplier Incident Logs
- Cross-reference the organisational incident log with notifications received from suppliers regarding security events.
- Validate that incidents involving third-party services were managed according to the internal incident response plan.
- Review Root Cause Analysis (RCA) reports provided by suppliers following major service disruptions or security breaches.
9. Confirm Multi-Factor Authentication (MFA) Compliance
- Audit technical logs to ensure that Multi-Factor Authentication (MFA) is enforced for all remote supplier access.
- Verify that authentication methods meet the organisation’s security standards, such as the use of hardware tokens or authenticator apps.
- Check for evidence of “shadow” or unmanaged accounts used by suppliers that bypass standard MFA protocols.
10. Evaluate Exit Strategy Documentation
- Inspect the documented exit strategies and transition plans for critical suppliers.
- Verify that there are clear procedures for the secure return or certified destruction of organisational data upon contract termination.
- Confirm that the Asset Register is updated to reflect the revocation of all physical and logical access once a service is decommissioned.
ISO 27001 Templates

How to pass the audit
To pass an audit of ISO 27001 Annex A 5.22 Monitor, review and change management of supplier services you are going to make sure that you have followed the steps above in how to comply.
What the auditor will check
The audit is going to check a number of areas. Lets go through the most common
1. That you have a supplier agreements in place
The auditor is going to check that you have agreements in place with suppliers that cover the information security requirements. It will check that those agreements are in date and cover the products and / or services acquired.
2. That you have an ISO 27001 Supplier Register
You will need an ISO 27001 Supplier Register to record and manage your suppliers. Make sure it is up to date and reflects your reality.
3. Documentation
They are going to look at audit trails and all your documentation and see that is classified and labelled. All the documents that you show them, as a minimum if they are confidential should be labelled as such. Is the document up to date. Has it been reviewed in the last 12 months. Does the version control match.
Top 3 Mistakes People Make and How to Avoid Them
The top 3 Mistakes People Make For ISO 27001 Annex A 5.22 are
1. You have do not monitor suppliers
Make sure that there are reviews and monitors in place. Perhaps meetings. Perhaps reports. Perhaps dashboards. Be sure to be able to evidence that you review and monitor those suppliers. You will have processes for adverse advents so do not be surprised if you are asked to evidence an adverse event, problem or issue and that you followed your process.
2. You have no assurance they are doing the right thing for information security
Make sure you have done your security assessment and can place your hands on an in date certificate such as an ISO 27001 Certification for assurance they are doing the right thing. It needs to be in date a cover the products and / or services you have acquired and are using form the supplier.
3. Your document and version control is wrong
Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
ISO 27001 Annex A 5.22 FAQ
High-risk suppliers must be reviewed at least annually, though critical cloud or managed service providers (MSPs) often require quarterly reviews to satisfy NIS2 and DORA requirements. Low-risk vendors may be reviewed every 2 to 3 years. The frequency should be documented in your Supplier Risk Register and based on the criticality of the data being processed.
Auditors require objective evidence of oversight, specifically:
Signed minutes from service review meetings and performance dashboards.
Updated Supplier Risk Registers reflecting recent audit findings or security incidents.
Formal change requests for significant service modifications, such as shifts in data residency or sub-processor changes.
Independent assurance reports like SOC2 Type II or ISO 27001 certificates.
Annex A 5.22 provides the operational framework for the ‘Management of ICT Third-Party Risk’ required by DORA and the supply chain security mandates in NIS2. Implementing this control ensures you have the monitoring hooks and reporting channels necessary to meet the 72-hour incident notification windows required by the UK Cyber Security and Resilience Bill.
Change management in 5.22 ensures that any modification to a supplier’s service, such as a platform upgrade or a new data processing location, is risk-assessed before implementation. Failure to manage these changes can lead to ‘compliance drift,’ where a previously secure service no longer meets your organisational security standards or legal obligations like the UK Data (Use and Access) Act 2025.
Related ISO 27001 Controls and Further Reading
ISO 27001 Supplier Security Policy Beginner’s Guide
ISO 27001 controls and attribute values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Confidentiality | Identify | Supplier relationships security | Protection |
| Integrity | Governance and ecosystem | |||
| Availability | Defence | |||
| Information security assurance |
