Supplier relationships – governance
Control 5.19Establish that the supplier relationship is owned, documented and reviewed. ISO 27001:2022 Control 5.19 expects a defined process for managing information-security risks introduced by suppliers.
Is the supplier recorded in the vendor inventory with a named internal owner?
Evidence: Vendor register entry, owner name, business purpose
Has the supplier been classified by criticality (e.g. critical / important / standard)?
Evidence: Classification rationale, data categories processed
Is there a signed contract or DPA covering information security and confidentiality obligations?
Evidence: Executed MSA, DPA, NDA
Are right-to-audit, sub-processor and termination clauses present?
Evidence: Contract clause references
Is a review cadence defined proportional to risk (e.g. annual for critical)?
Evidence: Next review date, reviewer