ISO 27001:2022 Annex A 5.19 Information Security in Supplier Relationships Explained

In this guide you will learn how to implement ISO 27001 Annex A 5.19 Information Security In Supplier Relationships and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

ISO 27001 Annex A 5.19 Information Security In Supplier Relationships is an ISO 27001 control that requires an organisation to mange the information security risks of using supplier products and services.

Purpose & Definition

The purpose of ISO 27001 Annex A 5.19 is a preventive control that ensures you maintain an agreed level of information security in supplier relationships.

The ISO 27001 standard defines ISO 27001 Annex A 5.19 as:

Processes and procedures should be defined and implemented to manage the information security risks associated with the use of supplier’s products or services.

ISO/IEC 27001:2022 Annex A 5.19 Information Security In Supplier Relationships

FREE ISO 27001 Annex A 5.19 Training Video

In this free training video you will learn How to implement ISO 27001 Information Security In Supplier Relationships (Annex A 5.19).

Implementation Guide

Supplier Policy

The standard requires a topic specific policy on supplier relationships – ISO 27001 Supplier Policy Template

ISO 27001 Supplier Security Policy Template

The supplier policy sets out your approach to information security of suppliers.

ISO 27001 Supplier Security Policy Template - ISO 27001 Annex A 5.19 Information Security in Supplier Relationships Template
ISO 27001 Third Party Supplier Security Policy Template

Supplier Management Process

You will need a supplier management process that sets out

  • how to identify and document suppliers and supplier types
  • evaluating suppliers according to information process, transmitted or shared
  • reviewing the controls that are in place
  • documenting what suppliers can access, monitor, control and use
  • assessing and managing supplier risks
  • monitoring and ensuring compliance to information security
  • implementing mitigation for non compliance of a supplier
  • the handling of incidents
  • availability, business continuity and disaster recovery
  • managing the transfer of information
  • the process for terminating and ending a supplier / supplier relationship
  • what level of security of people and physical security are expected

Supplier Register

The best way to manage ISO 27001 Suppliers is via the ISO 27001 Supplier Register. You can learn more in the ISO 27001 Supplier Register Beginner’s Guide

Supplier Register Template

The supplier register is a record of all your suppliers and is used to manage them.

ISO 27001 Third Party Supplier Register Template - ISO 27001 Annex A 5.19 Information Security in Supplier Relationships Template
ISO 27001 Third Party Supplier Register Template

Supplier Agreements / Contracts

The number one recommendation is to seek professional legal counsel for the provision of all contracts. The following is guidance but you should always defer to professional legal counsel. Always. You are not a lawyer. We are not a lawyer.

Our first line of defence and go to is the supplier agreement or supplier contract. At its core it is a legal mechanism that is legally binding and provides the greatest level of overall protection.

  • It sets out what is required, what will be done, who will do it, what happens if things go wrong.
  • What information is to be provided, accessed and the methods of access.
  • Legal, regulatory and contractual requirements. Elements such as intellectual property rights, copyright information, data protection requirements.
  • The controls and levels of controls that are required by both parties to the agreement.
  • Acceptable and unacceptable use of assets.
  • How to grant and remove access
  • Penalties, indemnities and remediation for failings to meet the contract.
  • Contact information
  • Screening requirements for staff were legally enforceable.
  • How evidence and assurance of information security will be provided
  • Rights to audit
  • How to solve problems or conflicts with the contract
  • Appropriate back up, business continuity and disaster recovery
  • The process for change management
  • Physical security as appropriate
  • Information transfer processes
  • Termination clauses and processes
  • Destruction and removal of data processes
  • Handover at the end of the contract

Contracts are kept and recorded in the Third Party Supplier Register. They are reviewed at least annually, based on risk and significant change or event.

How to implement ISO 27001 Annex A 5.19

Implementing ISO 27001 Annex A 5.19 requires a structured approach to manage the risks associated with third-party access to organisational assets. By following these steps, you will establish a robust framework for selecting, monitoring, and offboarding suppliers to maintain your security posture throughout the supply chain.

1. Formalise the Supplier Information Security Policy

  • Establish a clear policy that defines the security requirements for all third-party relationships: ensuring consistency across the business.
  • Identify specific security requirements for different types of suppliers: such as cloud service providers, maintenance contractors, and consultants.
  • Distribute the policy to all procurement staff and relevant stakeholders to ensure it is embedded into the vendor selection process.

2. Categorise Suppliers within the Asset Register

  • Identify every supplier with access to organisational information or systems: recording them as entities within your central Asset Register.
  • Categorise suppliers based on the sensitivity of data handled: ranging from low-risk service providers to high-risk technical partners.
  • Assign an internal owner for each supplier relationship to maintain accountability for security compliance.

3. Conduct Risk-Based Security Due Diligence

  • Perform a pre-contract risk assessment for every new supplier: identifying potential vulnerabilities in their operational processes.
  • Utilise security questionnaires to evaluate the supplier’s technical controls: focusing on their adherence to industry standards like ISO 27001 or SOC 2.
  • Document all identified risks and obtain formal sign-off from the Risk Owner before proceeding with the engagement.

4. Incorporate Security Requirements into Formal Agreements

  • Draft legally binding contracts that include specific information security clauses: ensuring the supplier is contractually obligated to protect your data.
  • Define clear Rules of Engagement (ROE) for any technical testing or access: establishing the boundaries of the relationship.
  • Include a “Right to Audit” clause and mandatory incident notification windows to ensure transparency during a security event.

5. Provision Granular Identity and Access Management (IAM) Roles

  • Apply the Principle of Least Privilege (PoLP) by creating specific IAM roles for supplier personnel: restricting access to only the necessary systems.
  • Enforce Multi-Factor Authentication (MFA) for all remote access attempts made by third parties: mitigating the risk of credential theft.
  • Schedule quarterly reviews of supplier access rights to ensure that redundant accounts are identified and removed promptly.

6. Address ICT Supply Chain Security Risks

  • Mandate that primary suppliers flow down security requirements to their own sub-contractors: ensuring security is maintained throughout the tiers of the supply chain.
  • Require evidence of secure development lifecycles (SDLC) for any bespoke software provided by third parties.
  • Verify the provenance of hardware components to protect against the insertion of malicious implants or counterfeit equipment.

7. Establish Standardised Incident Reporting Procedures

  • Define the mandatory reporting timeline for suppliers in the event of a security breach: ensuring your internal team can respond effectively.
  • Integrate supplier contact points into your organisational Incident Response Plan (IRP).
  • Conduct joint “desktop” exercises with critical suppliers to test the effectiveness of communication channels during a crisis.

8. Execute Regular Security Audits and Compliance Reviews

  • Audit critical suppliers annually to verify that they are meeting their contractual security obligations: using a mix of remote assessments and site visits.
  • Review independent audit reports and penetration test summaries provided by the supplier to validate their technical claims.
  • Log all audit findings and track the remediation of non-conformities through a formal Corrective Action Plan.

9. Manage Changes in Supplier Service Delivery

  • Perform a fresh risk assessment whenever a supplier makes significant changes to their service, location, or infrastructure.
  • Evaluate the security implications of supplier mergers or acquisitions: ensuring that the new entity maintains the required security standards.
  • Update contract terms and security requirements dynamically as the scope of the supplier relationship evolves over time.
  • Monitor supplier performance against agreed Service Level Agreements (SLAs) to ensure security controls do not degrade.

10. Revoke Access and Execute Secure Termination

  • Implement a termination checklist to ensure all IAM roles and physical access permissions are revoked immediately upon contract end.
  • Verify the secure return or certified destruction of all organisational information assets held by the supplier.
  • Formalise the transfer of knowledge and responsibilities to ensure that security continuity is maintained during the transition to a new provider.

Check Your Work?

You built it yourself. Maybe with AI. But will it pass the audit?

Don’t gamble – let an ISO 27001 Lead Auditor check your work.

Stuart Barker - High Table - ISO27001 Director

How to comply

To comply with ISO 27001 Annex A 5.19 you are going to implement the ‘how’ to the ‘what’ the control is expecting. In short measure you are going to

How to pass the ISO 27001 Annex A 5.19 audit

To pass an audit of ISO 27001 Annex A 5.19 you are going to make sure that you have followed the steps above in how to comply.

ISO 27001 Templates - ISO 27001 Annex A 5.19 Information Security in Supplier Relationships Templates
ISO 27001 Templates

What the auditor will check

The audit is going to check a number of areas. Lets go through the most common

1. That you have a supplier management process

The auditor is going to check the rules, procedures and supplier management methodology and make sure you followed them. Make sure all suppliers are listed, you have contracts or agreements or terms for each supplier and that you have assurance they are doing the right thing for information security.

2. That you have an ISO 27001 Supplier Register

You will need an ISO 27001 Supplier Register to record and manage your suppliers. Make sure it is up to date and reflects your reality.

3. Documentation

They are going to look at audit trails and all your documentation and see that is classified and labelled. All the documents that you show them, as a minimum if they are confidential should be labelled as such. Is the document up to date. Has it been reviewed in the last 12 months. Does the version control match.

Top 3 Mistakes People Make and How to Avoid Them

The top 3 Mistakes People Make For ISO 27001 Annex A 5.19 are

Make sure that there is a contract, agreement, terms of business or some legal mechanism for engaging with suppliers and you have a copy, it is in date and covers what you are using.

2. You have no assurance they are doing the right thing for information security

Make sure you have done your security assessment and can place your hands on an in date certificate such as an ISO 27001 Certification for assurance they are doing the right thing. It needs to be in date a cover the products and / or services you have acquired and are using form the supplier.

3. Your document and version control is wrong

Keeping your document version control up to date, making sure that version numbers match where used, having a review evidenced in the last 12 months, having documents that have no comments in are all good practices.

ISO 27001 Annex A 5.19 FAQ

How do you perform a supplier security risk assessment?

A supplier risk assessment is performed by evaluating a vendor’s security posture against your organisation’s risk appetite using questionnaires or audit reports.
Step 1: Determine the sensitivity of the data the supplier will access.
Step 2: Issue a Security Questionnaire (SAQ) or review SOC 2/ISO 27001 certificates.
Step 3: Identify gaps between vendor controls and your internal requirements.
Step 4: Implement compensatory controls or reject the supplier based on the risk score.

Is a “Right to Audit” clause required for Annex A 5.19?

Yes, while the specific terminology may vary, the organisation must have the legal right to monitor and review supplier security performance.
Allows for periodic onsite or remote security audits.
Mandates that suppliers provide independent audit reports (e.g., SOC 2 Type II).
Ensures the organisation can verify that security controls are functioning as promised.
Typically formalised within the Master Service Agreement (MSA) or a DPA.

ISO 27001 controls and attribute values

Control typeInformation security propertiesCybersecurity conceptsOperational capabilitiesSecurity domains
PreventiveConfidentialityIdentifySupplier relationships securityProtection
AvailabilityGovernance and ecosystem
Integrity

Stuart Barker

I am the ISO 27001 Ninja.

I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.

If you want to pass your audit the first time, book a call.

Shopping Basket
Scroll to Top