Back to all 93 controls
Annex A 5.19
Organizational
A.5.19 Information security in supplier relationships
Security is considered in supplier relationships.
What good looks like
Supplier inventory with criticality, security due diligence before onboarding.
Evidence an auditor will ask for
Supplier register, due-diligence questionnaires, risk ratings.
Reviewed & Verified by a Certified ISO/IEC 27001 Lead Implementer
Built for practitioners, by practitioners. Every template, control definition, and audit checklist in this directory is aligned with the latest ISO 27001:2022 standard and structured around real-world certification audit requirements.
Certified Lead Implementer
2022 Standard Aligned
Audit-Ready Materials
Document template for this control
The Supplier Relationship Security Policy template gives you auditor-ready wording that fulfils Annex A 5.19. Preview the full document before you download the editable version.
