A.5.19Information security in supplier relationships
Identify and manage the security risks that come with using suppliers who handle your information or systems. Your security is only as strong as the partners you rely on.
Mapping at a glance
A.5.19Information security in supplier relationshipsISO/IEC 27001:2022
What an auditor, or Sekit's evidence engine, asks for.
Vendor due diligence and monitoring
How the company assesses a supplier's security before hiring and monitors it during the relationship, including the process when it ends.
From the Sekit evidence catalog
In practice
For most companies this means a short questionnaire sent to any new vendor that will touch company data, kept on file alongside the contract, plus a note on when to check again. Auditors ask for the vendor due diligence and monitoring records and pick a critical supplier, often the cloud host or payroll provider, to check whether the assessment on file is current or years stale. The gap that shows up most is a vendor list with assessments only for the largest suppliers, while smaller tools with real access to company data, an analytics plugin or a scheduling app, were never assessed at all.
Common gaps
Vendor due diligence was completed for major suppliers at onboarding but was never repeated, so assessments on file for long-standing vendors are years out of date.
Smaller tools with real access to company data, such as an analytics or scheduling plugin, were never included in the supplier risk process at all.
The supplier list itself is incomplete because it was built from memory rather than cross-checked against billing or integration records.
Questions your auditor will ask
How do you assess a new supplier's security before signing a contract?
Point to the vendor due diligence and monitoring records showing a documented security check completed and reviewed before the contract was signed.
How often is that assessment repeated during the relationship?
Reference the defined re-assessment cycle and show a critical supplier's most recent review date against that cycle.
How do you know which suppliers have access to company data or systems?
Show the service dependency register naming each supplier with its owner, criticality and what data or systems it touches.
Where regulation demands it
NIS2 art. 5.1 (Supply chain security policy) requires the same risk-based approach to supplier relationships A.5.19 asks organizations to maintain.
ENS op.ext.1 (Contratación y acuerdos de nivel de servicio) sets the equivalent baseline for managing supplier and service agreements.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.