Skip to main content
Category: Supplier and Third-Party

Monitoring and Review of Supplier Services

Also known as: Monitoring, Review and Change Management of Supplier Services, ISO 27001 Annex A 5.22, Annex A.15.2.1 (2013 revision)
Simply put

This is the practice of regularly keeping an eye on the services and products your suppliers provide to make sure they continue to protect your information properly. It involves monitoring, reviewing, and auditing supplier performance over time, and managing any changes to the services they deliver. The goal is to ensure suppliers maintain the confidentiality, integrity, and availability of the information they handle on your behalf.

Formal definition

An ISO/IEC 27001 organisational control addressing the ongoing oversight of supplier information security practices and service delivery. In the 2022 revision this control appears as Annex A 5.22, 'Monitoring, Review and Change Management of Supplier Services'; in the 2013 revision comparable requirements sat within the A.15 Supplier Relationships domain. The control typically requires organisations to consistently monitor, review, assess, and audit supplier service delivery against agreed requirements, and to manage changes to supplier services, products, and their associated information security arrangements. As an Annex A reference control, its applicability and implementation are determined through the organisation's risk assessment and documented in the Statement of Applicability, rather than being mandated in fixed form. Note that Annex A controls are distinct from the SOC 2 Trust Services Criteria; the certifiable ISMS requirements reside in clauses 4 through 10 of the standard.

Why it matters

Suppliers and third-party service providers often handle, process, or store information on an organisation's behalf, which means their security posture directly affects the confidentiality, integrity, and availability of that information. A supplier's controls that were adequate at the point of onboarding can drift over time as the supplier changes its services, subcontracts work, alters its own architecture, or experiences degradation in its practices. Without ongoing monitoring and review, an organisation can lose visibility into these changes and inherit risk it never consciously accepted.

Regular monitoring, review, and auditing of supplier service delivery gives an organisation the evidence it needs to confirm that suppliers continue to meet agreed information security requirements rather than assuming they do. It also creates a structured way to manage changes to supplier services and products, so that modifications to what a supplier delivers are assessed for their information security implications before they take effect. This helps ensure that security expectations remain aligned with what the supplier actually provides on an ongoing basis.

It is important to recognise the boundaries of this control. As an ISO/IEC 27001 Annex A reference control, its applicability and depth of implementation are determined through the organisation's risk assessment and documented in the Statement of Applicability, so the intensity of monitoring typically varies with the criticality of each supplier. Effective monitoring reduces the likelihood of undetected supplier-side weaknesses, but it does not eliminate supplier risk entirely, nor does it guarantee freedom from incidents originating in the supply chain.

Who it's relevant to

GRC and Compliance Managers
Those responsible for the ISMS use this control to define and evidence how supplier oversight is performed, to justify its applicability in the Statement of Applicability, and to align monitoring intensity with the organisation's risk assessment. They typically own the cadence of supplier reviews and the documentation that supports them during certification audits.
Vendor and Third-Party Risk Teams
Teams managing supplier relationships apply this control to keep continuing visibility into how suppliers protect information over time, to review service delivery against agreed requirements, and to assess the security implications of changes suppliers make to their services or products.
Internal and Certification Auditors
Auditors assessing an ISMS against ISO/IEC 27001 examine whether supplier services are monitored, reviewed, and audited on a regular basis where the control has been deemed applicable, and whether change management for supplier services operates as described. They evaluate the evidence supporting these activities within the defined scope of the ISMS.
Security and Operations Engineers
Engineers who rely on supplier-delivered services and products contribute to and consume the outputs of monitoring, helping to identify when supplier-side changes could affect the confidentiality, integrity, or availability of the information the organisation depends on.

Inside Monitoring and Review of Supplier Services

Supplier Service Delivery Monitoring
The ongoing practice of tracking whether a supplier is delivering services in line with agreed terms, including service levels, security commitments, and contractual obligations. In most engagements this involves reviewing reports, performance data, and evidence provided by the supplier.
Regular Review Cadence
A defined frequency for reviewing supplier performance and security posture. The cadence typically depends on the criticality of the service and the risk it presents, rather than following a single fixed interval for all suppliers.
Assurance Evidence Assessment
Evaluation of assurance artifacts a supplier may provide, such as a SOC 2 report covering the supplier's controls over a defined period, or evidence relating to an ISO/IEC 27001 certificate covering the supplier's defined ISMS scope. Reviewers should confirm the scope, criteria, and period covered rather than assuming blanket coverage.
Change Management for Supplier Services
Processes to identify and evaluate changes to supplier services, technologies, or subcontracting arrangements that could affect risk, and to reassess controls where scope or exposure changes.
Handling of Identified Deficiencies
Mechanisms for raising, tracking, and remediating issues found during monitoring or review, including escalation paths and, depending on the contract, remedies or corrective action expectations.
Framework Alignment
In ISO/IEC 27001, supplier monitoring relates to Annex A reference controls selected through the Statement of Applicability and informed by risk assessment. In a SOC 2 examination, relevant activities are assessed against the applicable Trust Services Criteria, with Security (the Common Criteria) required and other categories included based on scope.

Common questions

Answers to the questions practitioners most commonly ask about Monitoring and Review of Supplier Services.

Does monitoring supplier services mean a supplier's SOC 2 report certifies my organization's compliance?
No. A supplier's SOC 2 report is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard; it is not a certification, and it attests only to the controls and the period the report covers. Reviewing a supplier's SOC 2 report as part of your monitoring activities does not certify your own organization, nor does it guarantee the supplier is free from breaches outside the covered scope and period. You remain responsible for evaluating whether the supplier's controls are relevant to your own scope and for addressing any complementary user entity controls the report identifies.
Is monitoring supplier services the same requirement under SOC 2 and ISO 27001, so that meeting one satisfies the other?
Not automatically. Under ISO/IEC 27001, supplier-related activities are addressed through the ISMS requirements in clauses 4 through 10 and through reference controls in Annex A that are selected via the Statement of Applicability and informed by risk assessment. Under SOC 2, supplier and vendor considerations are evaluated against the applicable Trust Services Criteria, with Security (the Common Criteria) always in scope. Mapping between the two frameworks is possible but partial, so satisfying supplier monitoring expectations in one does not automatically satisfy the other. Depending on scope, you may need to demonstrate the activity separately to each auditor or certification body.
How often should supplier services typically be reviewed?
The frequency generally depends on the risk the supplier presents, the criticality of the service, and your own scoping and risk assessment decisions rather than a single fixed interval. In most engagements, higher-risk or more critical suppliers are reviewed more frequently, while lower-risk relationships may be reviewed on a longer cycle. Neither framework typically prescribes a universal cadence, so document the rationale for the frequency you choose so it can be evidenced to an auditor or certification body.
What evidence typically demonstrates that supplier monitoring is operating?
Evidence commonly includes records of supplier performance reviews, review of any attestation reports the supplier provides (such as a SOC 2 report), tracking of service levels, records of issues raised and remediated, and documentation of any complementary user entity controls you have implemented. For a SOC 2 Type II examination, which assesses operating effectiveness over a defined review period, you would typically retain evidence that the review activity occurred consistently across that period rather than only at a single point in time.
How should the review handle suppliers that do not provide a SOC 2 report or ISO 27001 certificate?
Where a supplier provides no independent attestation or certification, monitoring typically relies on alternative assurance methods proportionate to the assessed risk, such as questionnaires, contractual security commitments, direct performance monitoring, or other agreed reporting. The appropriate approach depends on the supplier's risk profile and your own scope. Document the basis for accepting the alternative evidence so the decision can be explained during an audit or certification assessment.
How does supplier monitoring relate to the boundaries of my own scope?
Supplier monitoring covers the services within your defined scope and does not extend assurance beyond it. An ISO 27001 certificate covers only the defined scope of the ISMS, and a SOC 2 report attests only to the controls and period covered, so a supplier relationship outside those boundaries would not be represented. When defining monitoring activities, confirm which supplier services fall inside your scope and ensure any dependencies relevant to the applicable criteria or ISMS requirements are addressed accordingly.

Common misconceptions

Obtaining a supplier's SOC 2 report or ISO 27001 certificate once is sufficient and no ongoing monitoring is needed.
A SOC 2 report attests only to the controls and period it covers and does not guarantee freedom from future issues, and an ISO 27001 certificate covers only the defined scope of the supplier's ISMS. Because these artifacts have limited coverage and time boundaries, ongoing monitoring and periodic review remain necessary.
A supplier holding one framework's outcome means it satisfies the other, so review under both is unnecessary.
SOC 2 is an attestation examination performed by a licensed CPA firm resulting in a report, while ISO/IEC 27001 is a certification issued by an accredited certification body. Mapping between them is possible but partial, and satisfying one does not automatically satisfy the other, so reviewers should evaluate each against the relevant scope and criteria.
All suppliers should be monitored and reviewed at the same fixed frequency.
In most programs the review cadence and depth vary based on the criticality and risk of the service. Applying a single universal interval can over-invest in low-risk relationships and under-monitor high-risk ones.

Best practices

Maintain an inventory of suppliers with their service criticality and risk rating, and set monitoring cadence and depth accordingly rather than applying one universal interval.
When reviewing supplier assurance artifacts, confirm the scope, applicable criteria, and period covered, for example the categories included in a SOC 2 report or the ISMS scope stated on an ISO 27001 certificate, rather than assuming blanket coverage.
Define contractual service levels and security commitments up front and review supplier-provided evidence and performance data against them at the agreed cadence.
Establish a documented process to identify and reassess risk when supplier services, technologies, or subcontracting arrangements change.
Track identified deficiencies through to remediation with clear escalation paths, and record the outcomes to support future audits or examinations.
Align monitoring activities with the relevant framework requirements, for ISO/IEC 27001, tie them to Annex A controls selected in the Statement of Applicability and informed by risk assessment; for SOC 2, to the applicable Trust Services Criteria in scope.