ISO 27001:2022 supplier controls, in plain terms
The 2022 revision restructured Annex A and sharpened the supplier controls. Five of them, A.5.19 to A.5.23, decide whether your third-party programme survives an audit. Here is what each one actually asks for.
The five controls
- A.5.19
- Information security in supplier relationships. Define and apply processes to manage the risks a supplier introduces. The auditor is looking for a process that exists before the contract, not a form filled in afterwards.
- A.5.20
- Addressing security within supplier agreements. The requirements have to be in the agreement. Not in an email, not assumed. Named contacts, incident obligations, audit rights.
- A.5.21
- Managing security in the ICT supply chain. Extends beyond your direct supplier to the components and services they depend on. This is where subcontractor visibility stops being optional.
- A.5.22
- Monitoring, review and change management of supplier services. The one that catches people. It requires regular monitoring and review, and management of changes. Onboarding due diligence does not satisfy it.
- A.5.23
- Information security for use of cloud services. New in 2022. Acquisition, use, management and exit for cloud specifically, which for most organisations is most of the supplier estate.
What changed in 2022, and why it matters
The 2013 version had supplier controls, but A.5.22's explicit expectation of regular monitoring, combined with the new cloud control, moved the bar. Auditors now ask a question that a document folder cannot answer.
The question that decides A.5.22. "Show me the last three reviews for this supplier." Three dated records, with what was checked and what was found, passes. One questionnaire from onboarding plus an intention to review annually does not.
The common failure
Organisations rarely fail these controls because they do not care about suppliers. They fail because the evidence is the wrong shape:
- A supplier register that lists names and contract values but not criticality, data locations or attestation status.
- Questionnaires on file with no record of anyone having assessed the answers.
- An annual review cadence written in a policy and not evidenced in practice.
- Cloud services procured on a card and never entering the register at all, which fails A.5.23 immediately.
- No exit consideration for services the business could not operate without.
What good evidence looks like
- For A.5.19
- A documented process, and records showing it ran before contracts were signed.
- For A.5.20
- Agreements with the security schedule attached, and a record of which suppliers have it and which are outstanding.
- For A.5.21
- Subcontractor and sub-processor lists per supplier, with a date and a source.
- For A.5.22
- Dated review records at a stated cadence, showing what was checked and what changed. This is the one that benefits most from automation, because the evidence is generated as a by-product of doing the work.
- For A.5.23
- A cloud service inventory with owner, data classification, region and exit position.
Where we fit
Continuous verification produces A.5.22 evidence automatically: every scheduled check is a dated review record with an observation attached. The sample report shows the format, including an honest coverage statement, which auditors tend to prefer to a claim of completeness.
If you are earlier than that, the readiness assessment maps your current state against all of Annex A and gives you a prioritised plan.
Certification audit coming up?
A.5.22 is the supplier control most often raised as a nonconformity. Worth checking your evidence before the auditor does.
Book a call