SCRM Supplier Compliance & Risk Management

Home

ISO/IEC 27001:2022 · Annex A 5.19 – 5.23

Your ISMS does not stop at the firewall. It stops at your supplier.

Five Annex A controls deal exclusively with third parties. They do not ask for a statement of intent. They ask for continuous, evidenced monitoring of your providers – subcontractors and cloud services included.

The 2022 revision sharpened the supply chain considerably. A.5.21 added a dedicated control for the ICT supply chain, A.5.23 one for cloud services. Both point the same way: you own the risks that reach your company through your providers.

For an SME that means the IT provider, the payroll bureau, the data centre and the SaaS tool in marketing are all suppliers in the sense of the standard – each needing a risk assessment, contractual security requirements and a review rhythm.

Who this concerns

  • Companies certified to ISO 27001 or currently seeking certification.
  • Suppliers contractually held to an ISO 27001 level by their customers.
  • IT providers and software vendors who are themselves part of a customer’s supply chain.

The controls in plain words

A.5.19
Information security in supplier relationships: identify and treat risks from using third-party products and services.
A.5.20
Anchor security requirements in agreements – proportionate to risk, not one boilerplate clause for everyone.
A.5.21
Manage risk in the ICT supply chain, including your suppliers’ suppliers.
A.5.22
Monitor and review third-party service delivery and manage changes in a controlled way.
A.5.23
Information security for cloud services: selection, use, administration and exit.

How SCRM covers it

Supplier register with risk class

Every provider with criticality, data category and an accountable owner – the base for A.5.19.

Contract and evidence store

Security annexes, processing agreements and certificates held against the supplier, with expiry dates.

Dependency graph

See who stands behind your supplier – the precondition for answering A.5.21 at all.

Review cycles and incidents

Recurring reviews, recorded incidents and logged changes for A.5.22.

Frequently asked

Is my cloud provider’s own certificate enough?

No. Their certificate is evidence you must obtain, check and file with a validity date. The risk assessment stays with you.

How deep into the sub-supply-chain must we look?

As deep as your risk requires – and you must be able to justify it. A.5.21 does not demand a complete chain, but it does demand a deliberate, documented decision about where you draw the line.

We hold ISO 9001 and ISO 27001. Two systems?

Not needed. Both standards ask about the same suppliers with a different focus. SCRM keeps one supplier record that both views build on.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required