ISO 27001 Monitoring, Review and Change Management of Supplier Services
ISO 27001 Annex A 5.22 Monitor, review and change management of supplier services is an ISO 27001 control that requires an organisation to maintain an agreed level of service and information security in line with legal agreements.
It is about ensuring the confidentiality, integrity and availability of your suppliers, their products and their services through monitoring and review.
Table of contents
- ISO 27001 Monitoring, Review and Change Management of Supplier Services
- Key Takeaways
- Purpose
- Definition
- Explanation
- Requirement
- Audit Focus
- FREE Training Video
- Implementation Guide
- How to implement ISO 27001 Annex A 5.22
- Monitoring Metrics Matrix
- ISO 27001 Supplier Register Template
- ISO 27001 Supplier Policy Template
- How to comply
- How to Audit ISO 27001 Annex A 5.22
- How to pass the audit
- What the auditor will check
- Top 3 Mistakes People Make and How to Avoid Them
- Applicability across different business models
- Applicable Laws and Related Standards
- FAQ
- Related ISO 27001 Controls and Further Reading
- ISO 27001 controls and attribute values
Key Takeaways
ISO 27001 Annex A 5.22 requires organisations to regularly monitor, review, and evaluate supplier service delivery. This control ensures that the information security practices agreed upon in your contracts (Annex A 5.20) are actually being followed in reality. In a modern “SaaS-first” business, suppliers are your biggest risk; this “preventive” control ensures that you maintain oversight of their performance, respond to their security incidents, and manage any changes they make to their services without compromising your own security posture.
Purpose
The purpose of ISO 27001 Annex A 5.22 is a preventive control that ensures you maintain an agreed level of information security and service delivery in line with supplier agreements.
Definition
The ISO 27001 standard defines ISO 27001 Annex A 5.22 as:
The organisation should regularly monitor, review, evaluate and manage change in supplier information security practices and service delivery.
ISO 27001:2022 Annex A 5.22 Monitor, review and change management of supplier services
Explanation
ISO 27001 Annex A 5.22 Monitor, Review and Change Management of Supplier Services is a security control that mandates the continuous oversight of third-party performance to ensure compliance with contractual security requirements, ultimately protecting the organisation from supply chain vulnerabilities and service delivery failures through systematic governance and review.
Requirement
- Continuous Performance Monitoring: You must track supplier performance against agreed service levels (SLAs). This is typically done through monthly or quarterly service reports and dashboards.
- Regular Security Reviews: Critical suppliers should be evaluated at least annually. This involves verifying they still hold valid certifications (like ISO 27001 or SOC 2) and haven’t experienced major security regressions.
- Supplier Change Management: You must monitor and respond to changes made by the supplier, such as updates to their software, changes in their sub-processors, or shifts in their data hosting locations.
- Incident & Problem Management: Organizations must have a structured way to respond when a supplier has a security breach or a service outage, ensuring that the impact on your business is minimized.
- Audit Rights Execution: If your contract includes a “Right to Audit,” you should periodically exercise it, either through a direct audit or by reviewing the supplier’s third-party assurance reports.
- Centralized Supplier Register: All monitoring activities and review outcomes should be recorded in an up-to-date Supplier Register.
Audit Focus
- Evidence of Review: “Show me the minutes from your last quarterly review meeting with your critical hosting provider. What security issues were discussed?”
- Assurance Verification: “Show me the current ISO 27001 certificate for your payroll provider. When does it expire, and who is responsible for checking it?”
- Change Impact: “When your CRM provider moved their data storage from the US to the EU, how did you assess the impact on your data privacy compliance?”
FREE Training Video
Implementation Guide
As with all the clauses that relate to supplier management we are looking to assign the responsibility to a person or a team with the skills and resources to be able to track that requirements are being met and where not, they are being addressed.
In basic terms it is about making sure that the terms and conditions in legal agreements that relate to information security are being met. It is about managing issues, problems and incidents as the occur and if changes are needed to suppliers that those changes do not adversely impact the business.
You are going to:
- Those service performance levels are going to be monitored, most likely via reports or metrics or dashboards.
- Check and respond to changes made by suppliers such as updates, changes to process, changes to controls
- Where supplier services change to monitor and respond to those
- Keep your eye on the terms and conditions of the agreements and that they are followed
- Ensure those pesky suppliers are evaluated and maintain adequate security
It isn’t really that hard although you can over complicate it very easily. Have agreements in place, make sure they are followed, check them and respond when things go wrong.
We are not teaching people how to do supplier management or change it. What is here is common sense.
How to implement ISO 27001 Annex A 5.22
Implementing a robust monitoring and review process for supplier services ensures that security standards remain high throughout the lifecycle of the partnership. Use the following ten steps to establish governance, manage changes, and maintain compliance with ISO 27001 Annex A 5.22.
1. Establish a Supplier Monitoring Framework
- Define the scope of monitoring based on the supplier’s risk classification in your Asset Register.
- Identify specific security requirements, such as encryption standards or data residency, that must be tracked.
- Document the frequency of reviews, ensuring high-risk vendors receive more frequent oversight.
2. Appoint Qualified Service Owners
- Assign a dedicated Service Owner to each supplier to act as the primary point of contact for performance and security.
- Ensure the Service Owner has the technical authority to review audit logs and performance dashboards.
- Formalise accountability by including supplier oversight in the Service Owner’s job description.
3. Formalise Performance Metrics and SLAs
- Integrate specific security KPIs into Service Level Agreements (SLAs) to make security performance a contractual obligation.
- Include metrics for incident response times, system uptime, and vulnerability patching cycles.
- Ensure these metrics are measurable and reportable through automated dashboards where possible.
4. Schedule Periodic Performance Reviews
- Conduct monthly or quarterly meetings with suppliers to review service delivery against agreed targets.
- Document meeting minutes and track any identified “Non-Conformities” through to resolution.
- Review supplier reports, such as SOC2 Type II or ISO 27001 certificates, to verify ongoing compliance.
5. Execute Independent Supplier Audits
- Exercise your “Right to Audit” (ROE) as defined in the contract to conduct on-site or remote security assessments.
- Focus audits on technical controls, such as IAM roles, MFA implementation, and physical data centre security.
- Use a standardised checklist to ensure consistency across different supplier audits.
6. Implement Supplier Incident Management
- Establish a clear communication channel for the supplier to report security breaches or service failures.
- Define the “Rules of Engagement” (ROE) for joint incident response involving third-party systems.
- Log all supplier-related incidents in your central incident management system for trend analysis.
7. Authorise Service Changes via Formal Governance
- Subject any significant changes in supplier service delivery to a formal Change Management process.
- Evaluate the security impact of changes, such as new sub-processors or transitions to different cloud regions.
- Require formal sign-off from the CISO or Risk Owner before a change is implemented in production.
8. Audit Technical Access and IAM Roles
- Review the list of supplier personnel who have administrative or “Privileged” access to your organisational assets.
- Verify that MFA is enforced for all third-party remote access connections.
- Ensure that access is revoked immediately upon the termination of a supplier’s staff member or the contract itself.
9. Update the Supplier Risk Register
- Re-evaluate the risk profile of each supplier at least annually or following a significant security incident.
- Capture changes in the threat landscape, such as new geopolitical risks or supply chain vulnerabilities.
- Report high-level supplier risks to the management board during the annual ISO 27001 Management Review.
10. Maintain Validated Exit Strategies
- Develop a transition plan to ensure that services can be moved or brought in-house without a security vacuum.
- Define the process for the secure return or destruction of organisational data at the end of the contract.
- Test the exit strategy periodically to ensure the organisation remains resilient to supplier failure.
Monitoring Metrics Matrix
| Metric | Description | Frequency | Good Score |
| Uptime (SLA) | Is the service available? | Monthly | > 99.9% |
| Incident Response | How fast do they reply to tickets? | Quarterly | < 4 Hours |
| Security Audits | Do they have a valid ISO 27001 cert? | Annually | Valid / Pass |
| Data Breaches | Have they reported any leaks? | Ad-hoc | 0 |
ISO 27001 Supplier Register Template
The ultimate ISO 27001 Supplier Register Template.

ISO 27001 Supplier Policy Template
The ultimate ISO 27001 Supplier Register Template.

How to comply
To comply with ISO 27001 Annex A 5.22 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to
- Implement a topic specific policy
- Implement a supplier management process
- Include in your supplier management process supplier acquisition and supplier transfer
- Implement an ISO 27001 supplier register
- Have agreements with all suppliers that cover information security requirements
- Have information security assurances for critical suppliers as a minimum and ideally all relevant suppliers
- Monitor those suppliers
- Respond to adverse incidents in a structured way
How to Audit ISO 27001 Annex A 5.22
Auditing the monitoring, review, and change management of supplier services is a critical component of ISO 27001 compliance. As a Lead Auditor, I look for objective evidence that your organisation is proactively governing third-party relationships rather than simply assuming security is being maintained. Follow these ten steps to conduct a thorough technical audit of Annex A 5.22.
1. Inspect the Supplier Asset Register
- Verify that all third-party service providers are documented within a central Asset Register or Supplier Inventory.
- Confirm that each entry includes a risk classification based on the criticality of the data processed.
- Ensure that an owner is assigned to manage the ongoing security relationship for every high-risk supplier.
2. Scrutinise Service Level Agreements (SLAs)
- Review contractual agreements to ensure they contain specific security performance metrics and right-to-audit clauses.
- Identify defined Key Performance Indicators (KPIs) related to system availability, incident response times, and vulnerability remediation.
- Check for clear definitions regarding the notification periods for security breaches or significant service changes.
3. Validate Performance Monitoring Records
- Examine evidence of periodic service reviews, such as meeting minutes or performance dashboards.
- Verify that the organisation tracks supplier performance against the agreed security KPIs.
- Confirm that any identified service shortfalls or security non-conformities have been logged and tracked through to resolution.
4. Audit Independent Assurance Reports
- Inspect copies of independent audit evidence, such as SOC2 Type II reports, ISO 27001 certificates, or penetration test summaries.
- Validate that the scope of these third-party audits covers the specific services provided to your organisation.
- Check that the organisation has reviewed these reports and assessed any noted “exceptions” for their impact on internal security.
5. Review Service Change Management Logs
- Audit the change management process for instances where supplier services have been modified or updated.
- Verify that a formal risk assessment was conducted prior to the implementation of significant service changes.
- Ensure that changes to sub-processors or data storage locations were authorised by the relevant Information Security Officer.
6. Verify Technical Rules of Engagement (ROE)
- Examine Rules of Engagement (ROE) documents for technical audits or vulnerability scans conducted on supplier systems.
- Confirm that the ROE defines the boundaries of testing, communication protocols, and the handling of sensitive findings.
- Check for evidence that these protocols were followed during the most recent technical assessment.
7. Audit Privileged Access and IAM Roles
- Inspect the Identity and Access Management (IAM) roles assigned to supplier personnel within your infrastructure.
- Verify that the principle of least privilege is applied and that administrative access is restricted to authorised tasks.
- Confirm that a formal review of supplier access rights is conducted at least quarterly to revoke unnecessary permissions.
8. Scrutinise Supplier Incident Logs
- Cross-reference the organisational incident log with notifications received from suppliers regarding security events.
- Validate that incidents involving third-party services were managed according to the internal incident response plan.
- Review Root Cause Analysis (RCA) reports provided by suppliers following major service disruptions or security breaches.
9. Confirm Multi-Factor Authentication (MFA) Compliance
- Audit technical logs to ensure that Multi-Factor Authentication (MFA) is enforced for all remote supplier access.
- Verify that authentication methods meet the organisation’s security standards, such as the use of hardware tokens or authenticator apps.
- Check for evidence of “shadow” or unmanaged accounts used by suppliers that bypass standard MFA protocols.
10. Evaluate Exit Strategy Documentation
- Inspect the documented exit strategies and transition plans for critical suppliers.
- Verify that there are clear procedures for the secure return or certified destruction of organisational data upon contract termination.
- Confirm that the Asset Register is updated to reflect the revocation of all physical and logical access once a service is decommissioned.
How to pass the audit
To pass an audit of ISO 27001 Annex A 5.22 Monitor, review and change management of supplier services you are going to make sure that you have followed the steps above in how to comply.
What the auditor will check
The audit is going to check a number of areas. Lets go through the most common
1. That you have a supplier agreements in place
The auditor is going to check that you have agreements in place with suppliers that cover the information security requirements. It will check that those agreements are in date and cover the products and / or services acquired.
2. That you have an ISO 27001 Supplier Register
You will need an ISO 27001 Supplier Register to record and manage your suppliers. Make sure it is up to date and reflects your reality.
3. Documentation
They are going to look at audit trails and all your documentation and see that is classified and labelled. All the documents that you show them, as a minimum if they are confidential should be labelled as such. Is the document up to date. Has it been reviewed in the last 12 months. Does the version control match.
Top 3 Mistakes People Make and How to Avoid Them
The top 3 Mistakes People Make For ISO 27001 Annex A 5.22 are
1. You have do not monitor suppliers
Make sure that there are reviews and monitors in place. Perhaps meetings. Perhaps reports. Perhaps dashboards. Be sure to be able to evidence that you review and monitor those suppliers. You will have processes for adverse advents so do not be surprised if you are asked to evidence an adverse event, problem or issue and that you followed your process.
2. You have no assurance they are doing the right thing for information security
Make sure you have done your security assessment and can place your hands on an in date certificate such as an ISO 27001 Certification for assurance they are doing the right thing. It needs to be in date a cover the products and / or services you have acquired and are using form the supplier.
3. Your document and version control is wrong
Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.
Applicability across different business models
| Business Type | Applicability & Interpretation | Examples of Control |
|---|---|---|
| Small Businesses |
Service Availability & Notifications. You cannot force big vendors (Google, Xero) to change, but you must monitor their performance. Compliance focuses on tracking uptime and reviewing “Terms of Service” updates. |
• Status Dashboards: Checking the “Microsoft 365 Health Status” page during outages rather than just waiting. • Policy Updates: Reviewing email notifications regarding “Privacy Policy Updates” from critical SaaS tools to ensure data locations haven’t changed. |
| Tech Startups |
API & Sub-processor Changes. Critical focus on “breaking changes” from infrastructure providers (AWS, Stripe). You must monitor if a vendor changes their sub-processors, which impacts your compliance posture. |
• Automated Alerts: Subscribing to AWS/Heroku “Health Events” via PagerDuty or Slack. • Annual Assurance: Downloading and reviewing the latest SOC 2 Type II report from your hosting provider every 12 months to verify their security controls match your requirements. |
| AI Companies |
Model & Data Policy Integrity. Monitoring suppliers is existential. If an LLM provider changes their “Data Retention Policy” (e.g., switching from zero-retention to training on inputs), you may immediately violate client contracts. |
• ToS Scanning: Using automated tools or legal review to flag changes in API provider terms regarding “Model Training” rights. • Performance Drift: Monitoring inference API uptime and latency to ensure they meet the SLAs you have promised to your own customers. |
Applicable Laws and Related Standards
| Standard / Law | Regulatory Requirement and Control Relationship |
|---|---|
| UK Data (Use and Access) Act 2025 | The evolution of UK GDPR. Annex A 5.22 provides the ‘Appropriate Technical and Organisational Measures’ (TOMs) required to monitor third-party processors. It ensures that reduced administrative burdens do not lead to a drop in supplier security thresholds. |
| DORA (Digital Operational Resilience Act) | Annex A 5.22 is the primary mechanism for the ‘Management of ICT Third-Party Risk’ pillar. It satisfies the requirement for financial entities to continuously monitor the performance of critical third-party service providers. |
| NIS2 / UK Cyber Security & Resilience Bill | These laws mandate supply chain security and reporting for Managed Service Providers (MSPs). 5.22 ensures you have the monitoring hooks in place to detect and report supplier incidents within the required legal windows. |
| NIST Cybersecurity Framework (CSF) 2.0 | Maps directly to the ‘Govern’ (GV.SC) and ‘Monitor’ (ID.SC) functions. 5.22 provides the operational review process to validate that supplier performance aligns with the NIST Supply Chain Risk Management (SCRM) strategy. |
| SOC2 (Trust Services Criteria) | Relates to the CC9.0 ‘Risk Management’ and ‘Common Criteria’ for monitoring. Annex A 5.22 activities provide the audit trail (meeting minutes, audit logs) that SOC2 auditors require to verify vendor management effectiveness. |
| EU AI Act / ISO 42001 (AI SMS) | For organisations using AI suppliers, 5.22 is used to monitor the data quality, bias controls, and drift of third-party AI models. It ensures the ‘Human Oversight’ requirement of the AI Act is met through service reviews. |
| CIRCIA (USA) | The 72-hour reporting mandate for critical infrastructure requires the incident communication channels established in 5.22 to be functional and tested, ensuring supplier-side breaches are reported to CISA on time. |
| EU Product Liability Directive (PLD) Update | As liability extends to software providers for flaws, 5.22 serves as your ‘due diligence’ record. It proves you actively monitored for vulnerabilities and demanded patches from your software suppliers. |
| ECCF (European Cybersecurity Certification Framework) | Annex A 5.22 is the process used to verify that a supplier’s EU-wide security labels (e.g., EUCS for Cloud) remain valid and that any changes to their service do not invalidate their certification. |
| HIPAA (Health Insurance Portability and Accountability Act) | Applies to ‘Business Associate Agreements’ (BAAs). 5.22 provides the periodic audit of health data access by suppliers to ensure ongoing compliance with the HIPAA Security Rule. |
| CCPA / CPRA (California Data Laws) | Relates to the monitoring of ‘Service Providers’ and ‘Contractors’. 5.22 ensures that suppliers are not selling personal data and are adhering to the restricted data processing instructions provided by the business. |
FAQ
High-risk suppliers must be reviewed at least annually, though critical cloud or managed service providers (MSPs) often require quarterly reviews to satisfy NIS2 and DORA requirements. Low-risk vendors may be reviewed every 2 to 3 years. The frequency should be documented in your Supplier Risk Register and based on the criticality of the data being processed.
Auditors require objective evidence of oversight, specifically:
Signed minutes from service review meetings and performance dashboards.
Updated Supplier Risk Registers reflecting recent audit findings or security incidents.
Formal change requests for significant service modifications, such as shifts in data residency or sub-processor changes.
Independent assurance reports like SOC2 Type II or ISO 27001 certificates.
Annex A 5.22 provides the operational framework for the ‘Management of ICT Third-Party Risk’ required by DORA and the supply chain security mandates in NIS2. Implementing this control ensures you have the monitoring hooks and reporting channels necessary to meet the 72-hour incident notification windows required by the UK Cyber Security and Resilience Bill.
Change management in 5.22 ensures that any modification to a supplier’s service, such as a platform upgrade or a new data processing location, is risk-assessed before implementation. Failure to manage these changes can lead to ‘compliance drift,’ where a previously secure service no longer meets your organisational security standards or legal obligations like the UK Data (Use and Access) Act 2025.
Related ISO 27001 Controls and Further Reading
ISO 27001 Supplier Security Policy Beginner’s Guide
ISO 27001 controls and attribute values
| Control type | Information security properties | Cybersecurity concepts | Operational capabilities | Security domains |
|---|---|---|---|---|
| Preventive | Confidentiality | Identify | Supplier relationships security | Protection |
| Integrity | Governance and ecosystem | |||
| Availability | Defence | |||
| Information security assurance |
