A.5.22Monitoring, review and change management of supplier services
Regularly monitor and review the security of services your suppliers deliver, and manage changes to those services carefully. Supplier performance and risk can drift over time.
Mapping at a glance
A.5.22Monitoring, review and change management of supplier servicesISO/IEC 27001:2022
What an auditor, or Sekit's evidence engine, asks for.
Vendor due diligence and monitoring
How the company assesses a supplier's security before hiring and monitors it during the relationship, including the process when it ends.
From the Sekit evidence catalog
In practice
In practice this control shows up as a recurring calendar entry, quarterly or annual, where someone re-opens the vendor due diligence and monitoring file for each critical supplier and checks whether anything changed: a security incident, a lapsed certification, a change in the service itself. Auditors look for evidence the review took place on schedule, not only that a review process is described in policy, and ask what would trigger an out-of-cycle check, such as a breach notification from the supplier. The common gap is a company that assessed suppliers thoroughly at onboarding but has no working process for noticing when a supplier's posture or service changes years later.
Common gaps
Supplier reviews are described in policy on a set cycle, but the vendor due diligence and monitoring file has no completed review on record for a critical provider, so the cadence isn't demonstrated in practice.
Nobody is watching for breach notifications or security rating drops from key suppliers between scheduled review dates, so a change would only surface at the next annual check.
A critical supplier changed its service terms and sub-processors, but the change was never flagged for security review because notification only goes to procurement.
Questions your auditor will ask
How often do you re-review the security of a critical supplier after onboarding?
Point to the review cadence in the vendor due diligence and monitoring process and the completed record for the most recent cycle.
What would trigger a review outside the normal schedule?
Describe the triggers, such as a supplier breach notification or a significant service change, that prompt an out-of-cycle assessment.
How is a change to a supplier's service, such as a new sub-processor, managed?
Show the change management step that routes supplier-initiated changes to security review before they are accepted as business as usual.
Where regulation demands it
NIS2 art. 5.1 (Supply chain security policy) sets the expectation that suppliers stay managed as an ongoing commitment, which A.5.22 turns into scheduled review and change management.
ENS op.ext.1 (Contratación y acuerdos de nivel de servicio) sets the baseline for managing the supplier contracts and service levels A.5.22 requires reviewing over time.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.