Resource · Template

ISO 27001 Vendor Assessment Template

A structured supplier-risk questionnaire mapped to ISO 27001:2022 Controls 5.19, 5.20, 5.21 and 5.22 — ready to drop into your GRC workflow. Use it to onboard new suppliers, score residual risk and schedule periodic reviews.

How to use this template

  1. Classify the supplier by criticality before you start — that determines depth and review cadence.
  2. Walk each section with the supplier; capture evidence references, not just yes/no answers.
  3. Score each item (Met / Partial / Not met / N/A) and aggregate per section.
  4. Document residual risk, the risk owner and the next review date in your register.

Scoring scheme

RatingMeaningAction
MetControl fully implemented with current evidence.Record and move on.
PartialControl implemented but with documented gaps or stale evidence.Open finding; agree remediation plan.
Not metControl absent or evidence not provided.Escalate; risk-owner sign-off required to proceed.
N/AControl not applicable to the service in scope.Justify in writing.

Assessment checklist

Supplier relationships – governance

Control 5.19

Establish that the supplier relationship is owned, documented and reviewed. ISO 27001:2022 Control 5.19 expects a defined process for managing information-security risks introduced by suppliers.

  • Is the supplier recorded in the vendor inventory with a named internal owner?

    Evidence: Vendor register entry, owner name, business purpose

  • Has the supplier been classified by criticality (e.g. critical / important / standard)?

    Evidence: Classification rationale, data categories processed

  • Is there a signed contract or DPA covering information security and confidentiality obligations?

    Evidence: Executed MSA, DPA, NDA

  • Are right-to-audit, sub-processor and termination clauses present?

    Evidence: Contract clause references

  • Is a review cadence defined proportional to risk (e.g. annual for critical)?

    Evidence: Next review date, reviewer

ICT supply chain security

Control 5.21

For ICT services and products, verify that security requirements flow down to sub-suppliers (Control 5.21).

  • Does the supplier disclose sub-processors and notify changes in advance?

    Evidence: Sub-processor list, change notification policy

  • Are software supply-chain controls in place (SBOM, signed releases, vulnerability disclosure)?

    Evidence: SBOM sample, security.txt, VDP URL

  • Is there a documented secure-development lifecycle (SDLC)?

    Evidence: SDLC policy, code-review evidence

Information security controls

Control A.5 / A.8

Confirm the supplier operates a recognised ISMS and applies baseline technical controls on data you share.

  • Is the supplier ISO 27001 certified, SOC 2 Type II audited or equivalent?

    Evidence: Certificate, audit report, scope statement, expiry

  • Is access to your data restricted via SSO/MFA and least privilege?

    Evidence: Access policy, MFA enforcement

  • Is data encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent)?

    Evidence: Encryption statement, key-management policy

  • Are backup and recovery objectives (RPO/RTO) defined and tested?

    Evidence: BCP/DR test results

  • Is there a documented vulnerability and patch management process?

    Evidence: Patch SLAs, last pentest report

  • Are logs retained centrally and monitored for security events?

    Evidence: SIEM coverage, retention period

Data protection & privacy

Control GDPR / DPA

Where personal data is processed, document lawful basis, location and transfer mechanisms.

  • Are the categories of personal data and processing purposes documented?

    Evidence: ROPA entry, DPA Annex

  • Is the data hosting region defined and acceptable?

    Evidence: Region list, residency statement

  • If data leaves the EEA, are SCCs and a transfer impact assessment in place?

    Evidence: SCC version, TIA document

  • Does the supplier support data subject requests within statutory deadlines?

    Evidence: DSR process description

Incident management & notification

Control 5.20 / 5.24

Control 5.20 requires security obligations within supplier agreements, including incident handling.

  • Is the breach-notification window contractually defined (e.g. ≤72h)?

    Evidence: Contract clause

  • Is a security contact (email / phone) provided and tested annually?

    Evidence: Contact card, last test date

  • Does the supplier participate in joint incident exercises if classified critical?

    Evidence: Exercise minutes

Monitoring, review and exit

Control 5.22

Control 5.22 covers ongoing monitoring, review and managed change of supplier services.

  • Are SLAs and KPIs reported and reviewed at agreed intervals?

    Evidence: Service-review minutes

  • Is a documented exit plan in place (data return / destruction within X days)?

    Evidence: Exit clause, certificate of destruction template

  • Has residual risk been accepted by the risk owner and recorded?

    Evidence: Risk register entry, sign-off

Reviewer sign-off

Risk owner

Name, role, signature, date

Security reviewer

Name, role, signature, date

Residual risk rating

Low / Medium / High / Critical

Next review date

DD / MM / YYYY

FAQ

What is an ISO 27001 vendor assessment template?
A structured questionnaire and checklist used to evaluate a supplier's information-security posture against ISO 27001:2022 controls — primarily 5.19 (supplier relationships), 5.20 (addressing security within agreements), 5.21 (ICT supply chain) and 5.22 (monitoring and review).
Which ISO 27001 controls apply to vendor risk management?
Controls 5.19, 5.20, 5.21 and 5.22 cover the supplier lifecycle from onboarding through ongoing monitoring and exit. Technical baseline expectations are reinforced by Annex A.8 controls (access, cryptography, logging).
How often should vendor assessments be repeated?
Tie the cadence to risk classification: annually for critical suppliers, every 2 years for important ones, and on material change (breach, ownership, scope expansion) regardless of class.
Do I need a separate template for GDPR?
No — extend the ISO 27001 template with a privacy section covering data categories, lawful basis, hosting region and transfer mechanism (SCCs + TIA where applicable). Both audits can then run from a single record.