SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.5.22Monitoring, review and change management of supplier services

Regularly monitor and review the security of services your suppliers deliver, and manage changes to those services carefully. Supplier performance and risk can drift over time.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0026Third-party risk management · ProcesssupportsVerifying contractual obligations at signing and renewal is a checkpoint that feeds A.5.22's ongoing review of whether suppliers still meet what was agreed.RCF-0027Third-party risk management · TechnicalsupportsLogging and reviewing what third-party accounts do gives A.5.22's monitoring requirement something concrete to review, beyond trusting that access is used as intended.RCF-0047Service inventory · ProcessenablesA current service dependency register is what A.5.22's review process checks against; without it there is no reliable list of what to monitor.RCF-0048Service inventory · TechnicalsupportsMonitoring tooling that watches uptime, certificate and domain expiry and provider status feeds supports A.5.22's ongoing visibility over supplier services, though it does not by itself perform the security review or change management the control requires.RCF-0296Supply chain continuity · ProcesssupportsReviewing critical supplier continuity risk on a schedule is the periodic-review half of A.5.22, applied to whether a supplier can still deliver.RCF-0297Supply chain continuity · TechnicalsupportsMonitoring the operational status of critical suppliers so outages surface before customers report them supports A.5.22's review requirement on the narrower axis of availability, not the full security review the control requires.RCF-0317Vendor due diligence · ProcesssupportsRepeating the supplier security assessment on a defined cycle during the relationship is A.5.22's review requirement applied to security posture rather than availability.RCF-0318Vendor due diligence · TechnicalsupportsVendor risk feeds and shared assessment portals make A.5.22's periodic supplier reviews practical to run consistently instead of an occasional manual exercise.RCF-0320Contractual security clauses · ProcesssupportsTracking whether suppliers meet their contractual obligations and acting on non-compliance is A.5.22's review requirement checked against the agreement itself.RCF-0321Contractual security clauses · TechnicalsupportsSurfacing renewal and compliance deadlines automatically is the technical trigger that makes A.5.22's supplier reviews happen on time rather than being missed.RCF-0322Ongoing monitoring · PolicysupportsCommitting in policy to monitor key suppliers' security posture for the whole relationship supports A.5.22's review requirement, but the commitment alone does not perform the review or change management the control also names.RCF-0323Ongoing monitoring · ProcesssupportsRunning periodic supplier reviews and watching breach signals for critical providers supports A.5.22's monitoring and review requirement, while the change management half of the control sits with RCF-0353.RCF-0324Ongoing monitoring · TechnicalenablesAutomated services that continuously score supplier security posture and alert on a rating drop are an input that enables A.5.22's ongoing review, feeding it signals rather than performing the review itself.RCF-0326Offboarding vendors · ProcesssupportsExecuting the vendor exit checklist for every ended relationship is the change management A.5.22 requires when a supplier relationship itself changes to termination.RCF-0332Shared responsibility model · ProcesssupportsMaking the customer-side cloud duties part of routine operations is how A.5.22's review requirement applies to the specific split of responsibility in cloud services.RCF-0353SaaS security configuration · ProcesssupportsRe-checking SaaS security settings whenever a vendor changes them or the company changes plans is A.5.22's change management requirement applied to supplier-driven configuration changes.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

ISO/IEC 42001:2023 — Annex A counterparts

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Vendor due diligence and monitoring
How the company assesses a supplier's security before hiring and monitors it during the relationship, including the process when it ends.
From the Sekit evidence catalog

In practice

In practice this control shows up as a recurring calendar entry, quarterly or annual, where someone re-opens the vendor due diligence and monitoring file for each critical supplier and checks whether anything changed: a security incident, a lapsed certification, a change in the service itself. Auditors look for evidence the review took place on schedule, not only that a review process is described in policy, and ask what would trigger an out-of-cycle check, such as a breach notification from the supplier. The common gap is a company that assessed suppliers thoroughly at onboarding but has no working process for noticing when a supplier's posture or service changes years later.

Common gaps

Supplier reviews are described in policy on a set cycle, but the vendor due diligence and monitoring file has no completed review on record for a critical provider, so the cadence isn't demonstrated in practice.
Nobody is watching for breach notifications or security rating drops from key suppliers between scheduled review dates, so a change would only surface at the next annual check.
A critical supplier changed its service terms and sub-processors, but the change was never flagged for security review because notification only goes to procurement.

Questions your auditor will ask

How often do you re-review the security of a critical supplier after onboarding?
Point to the review cadence in the vendor due diligence and monitoring process and the completed record for the most recent cycle.
What would trigger a review outside the normal schedule?
Describe the triggers, such as a supplier breach notification or a significant service change, that prompt an out-of-cycle assessment.
How is a change to a supplier's service, such as a new sub-processor, managed?
Show the change management step that routes supplier-initiated changes to security review before they are accepted as business as usual.

Where regulation demands it

NIS2 art. 5.1 (Supply chain security policy) sets the expectation that suppliers stay managed as an ongoing commitment, which A.5.22 turns into scheduled review and change management.
ENS op.ext.1 (Contratación y acuerdos de nivel de servicio) sets the baseline for managing the supplier contracts and service levels A.5.22 requires reviewing over time.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.5.22?”
Also via MCP, free with account