Skip to main content
Category: Supplier and Third-Party

Information Security in Supplier Relationships

Also known as: Supplier Relationships (Annex A control), Supplier Management, Third-Party Information Security
Simply put

Information security in supplier relationships is the practice of managing the security risks that arise when an organisation shares information with, or relies on products and services from, third-party suppliers. It typically involves setting expectations for how suppliers protect that information and putting formal, written agreements in place to hold them to those expectations. The goal is to ensure that information handled by or accessible to suppliers stays appropriately protected.

Formal definition

Within ISO/IEC 27001:2022, information security in supplier relationships is addressed as an Annex A organisational control (referenced in the 2022 revision as A.5.19, and covered under the A.15 grouping in the 2013 version) requiring an organisation to identify and manage the information security risks associated with the use of supplier products and services. In most implementations this involves defining information security requirements for supplier access to and handling of information, documenting these in formal agreements, and applying them proportionately based on risk assessment. As an Annex A reference control, its selection and applicability are determined through the Statement of Applicability rather than being uniformly mandated, and the depth of supplier controls typically varies with the sensitivity of information involved and the nature of the supplier relationship. Related guidance beyond ISO/IEC 27001 itself is provided in the ISO/IEC 27036 series, which addresses cybersecurity and supplier relationships in greater detail.

Why it matters

Modern organisations rarely operate in isolation. They share information with, and depend on products and services from, a range of third-party suppliers, and each of those relationships can create a pathway for information security risk. When a supplier can access, store, or process an organisation's information, weaknesses in the supplier's own controls can undermine the protections the organisation has put in place internally. Managing information security in supplier relationships is how an organisation extends its expectations for protecting information beyond its own boundaries to the parties it relies on.

Because supplier concerns cover a broad range of scenarios, spanning hardware, software, and service relationships, the risks are not uniform. A supplier handling highly sensitive information warrants closer scrutiny than one with limited or no access to protected data. This is why the practice emphasises assessing risk and applying controls proportionately, rather than treating every supplier the same. Formal, written agreements are central to this: they document what security requirements a supplier agrees to and provide a basis for holding the supplier accountable.

It is worth noting the boundaries of this control. Managing supplier relationships reduces and structures third-party risk, but it does not eliminate the possibility of a supplier-related incident, and its effectiveness depends on how requirements are defined, agreed, and monitored over the life of the relationship. As an Annex A reference control, its applicability is determined through the Statement of Applicability, so the depth of implementation typically varies with the sensitivity of the information involved and the nature of each supplier relationship.

Who it's relevant to

Compliance and GRC managers
Those responsible for an ISMS need to decide whether this control is applicable within their Statement of Applicability and, where it is, ensure that supplier information security requirements are defined, documented in formal agreements, and applied proportionately to the risk each supplier presents.
Procurement and vendor management teams
Teams that onboard and manage suppliers are typically involved in embedding information security requirements into written agreements and in ensuring suppliers agree to and document those requirements before being granted access to information.
ISO 27001 auditors and certification bodies
Auditors assessing an ISMS against ISO/IEC 27001:2022 evaluate how the organisation identifies supplier-related information security risks and whether formal agreements and proportionate controls are in place for suppliers within the defined scope. Note that certification covers only the defined scope of the ISMS.
Security engineers and risk assessors
Those performing risk assessments help determine the sensitivity of information a supplier may access and the corresponding depth of controls, informing which requirements are appropriate for each supplier relationship. The ISO/IEC 27036 series can provide additional guidance where more detail is needed.

Inside Information Security in Supplier Relationships

Supplier Risk Assessment
The process of evaluating the security risks associated with engaging a supplier that has access to, processes, or stores organizational information or information systems. In ISO 27001, this activity is informed by the organization's risk assessment and drives which supplier-related controls are selected via the Statement of Applicability.
Contractual Security Requirements
Agreements with suppliers that define the information security obligations relevant to the relationship. The specific requirements depend on scope and the nature of the access granted, and are typically documented so that expectations are enforceable and auditable.
Supply Chain Considerations
Attention to security risks that extend beyond the direct supplier to sub-suppliers and the broader information and communication technology supply chain, depending on how the scope of the relationship is defined.
Monitoring and Review of Supplier Services
Ongoing oversight of supplier performance against agreed security requirements, including review of any changes to supplier services. What is monitored and how frequently typically varies with the assessed risk and scope of the arrangement.
Relationship to Framework Requirements
In ISO/IEC 27001, supplier relationship controls appear as reference controls in Annex A and are selected through the Statement of Applicability rather than being universally mandatory. In a SOC 2 examination, vendor and third-party management is typically evaluated as part of the Security (Common Criteria) category, subject to the scope set for the engagement.

Common questions

Answers to the questions practitioners most commonly ask about Information Security in Supplier Relationships.

Does ISO 27001 mandate a single, prescribed set of supplier security controls that every organization must implement?
No. Supplier relationship controls appear in Annex A as reference controls, which are selected through the Statement of Applicability and informed by the organization's risk assessment. The certifiable requirements themselves live in clauses 4 through 10. This means the specific supplier controls an organization adopts, and the depth to which they are applied, depend on scope and identified risk rather than a fixed mandate. Which controls apply, and how they are implemented, typically varies from one ISMS to another.
If a supplier provides a SOC 2 report, does that certify the supplier as compliant with ISO 27001 supplier requirements?
No. A SOC 2 report is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard; it is not a certification and does not, by itself, satisfy ISO 27001 requirements. The two frameworks can be partially mapped, but satisfying one does not automatically satisfy the other. A supplier's SOC 2 report attests only to the controls and period it covers and does not extend to the ISMS scope defined for an ISO 27001 certificate. Reviewing such a report can inform supplier assurance, but the outcomes should not be treated as equivalent.
How should we handle security requirements when onboarding a new supplier?
In most engagements, organizations establish agreed security requirements before or during onboarding, often documented in contracts or supplementary agreements. The specific requirements typically reflect the risk the supplier introduces to information within the defined scope, so a supplier handling sensitive data usually warrants more stringent requirements than one with limited access. The applicable expectations depend on scope, risk assessment outcomes, and any relevant criteria selected, so requirements are commonly tailored per relationship rather than applied uniformly.
What evidence can we use to demonstrate supplier oversight during an audit or examination?
Depending on scope and the auditor or certification body, evidence commonly includes contracts or agreements setting out security requirements, records of supplier assessments or due diligence, and documentation of ongoing monitoring activities. For a SOC 2 Type II examination, evidence supporting operating effectiveness over the defined review period is typically expected, whereas a Type I addresses suitability of design at a point in time. The precise evidence relied upon varies with the controls in scope and the assessing party's expectations.
How do we address supplier security within a supply chain that includes subcontractors or fourth parties?
Organizations often extend requirements to sub-suppliers by addressing them in contractual terms with the primary supplier, so that flow-down expectations apply through the chain. The extent of visibility into subcontractors typically depends on the risk involved and what can be practically obtained. Because assurance from a supplier's own reports or certifications covers only their defined scope, gaps may exist beyond that boundary, and these limitations are commonly documented and considered during risk assessment rather than assumed to be covered.
How often should we reassess suppliers after the relationship is established?
The reassessment cadence typically depends on the supplier's risk profile, the sensitivity of the information involved, and any changes in the service or environment. In most programs, higher-risk suppliers are reviewed more frequently than lower-risk ones, and reviews may also be triggered by events such as significant changes, incidents, or renewal cycles. Because the appropriate frequency varies with scope and risk rather than being fixed by the standard, organizations generally define and document their own monitoring schedule.

Common misconceptions

A SOC 2 report or ISO 27001 certificate from a supplier means the organization no longer needs to manage that supplier's security risk.
A supplier's SOC 2 report attests only to the controls and period covered and does not guarantee freedom from breaches, and an ISO 27001 certificate covers only the defined scope of that supplier's ISMS. Neither removes the engaging organization's own responsibility to assess and monitor the relationship within its own scope.
The supplier relationship controls are mandatory in exactly the same form under both SOC 2 and ISO 27001.
The frameworks handle this differently. In ISO/IEC 27001, supplier-related controls are Annex A reference controls selected via the Statement of Applicability and informed by risk assessment, not automatically required. In SOC 2, third-party management is assessed against the Trust Services Criteria (typically the Security/Common Criteria) as scoped for the engagement. Mapping between the two is possible but partial, and satisfying one does not automatically satisfy the other.
Assessing the direct supplier at onboarding is sufficient to address supply chain risk.
Depending on scope, risks can extend to sub-suppliers and the wider supply chain, and supplier services can change over time. In most engagements, ongoing monitoring and review are expected rather than a one-time point-of-onboarding assessment.

Best practices

Base supplier security requirements on a documented risk assessment so that the depth of due diligence is proportionate to the access and data involved, rather than applying a single approach to every supplier.
Document security obligations in supplier agreements and, where relevant to your ISO 27001 scope, reflect the selected supplier controls in the Statement of Applicability.
Establish ongoing monitoring and periodic review of supplier performance against agreed requirements, and reassess when supplier services change materially.
When relying on a supplier's SOC 2 report, confirm the type (Type I addresses suitability of design at a point in time; Type II addresses design and operating effectiveness over a defined review period) and check that the covered controls, criteria, and period align with your needs.
When relying on a supplier's ISO 27001 certificate, verify that the defined ISMS scope actually covers the services you consume, since the certificate applies only to that scope.
Extend supplier oversight to relevant sub-suppliers and the broader supply chain where scope and assessed risk warrant it, rather than limiting review to direct suppliers.