Verify Compliance with Security Requirements
Regularly ensure service providers are following the security agreements in their contracts.
Plain language
This control is about checking that service providers are doing what they promised in terms of security. It's important because if they slip up, your data and systems could be at risk, leading to data breaches or service disruptions.
Framework
ASD Information Security Manual (ISM)
Control effect
Detective
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
The right to verify compliance with security requirements documented in contractual arrangements with service providers is regularly exercised.
Why it matters
If providers aren't following security agreements, you risk data breaches, financial loss, and damaged reputation.
Operational notes
Regular communication with service providers ensures they remain aware of their security obligations. Keep track of compliance issues and follow-ups.
Implementation tips
- Procurement teams should review contracts with service providers to ensure they include clear security obligations. Make sure these are specific about what security measures the provider must take.
- IT managers should schedule regular compliance checks with each service provider. Use a checklist based on the security terms in the contract and conduct these checks quarterly.
- Assign an employee to be the main point of contact for service providers. This person should keep track of communications and follow up on any security issues identified.
- Security leaders should conduct training sessions for staff involved with contract management. Focus on recognising security needs and how to enforce them through contracts.
- Business managers should review reports from compliance checks. Ensure that any issues are followed up and that providers are held accountable for improving their security posture.
Audit / evidence tips
- Askthe last compliance check report with service providersLook atdetails on what was checked and what issues were foundGoodthe report includes a checklist, findings, and corrective actions with timelines
- Goodeach contract has a dedicated section on security obligations with explicit terms
- Askevidence of communication between the organisation and service providers about security issuesLook atdocumented emails or meeting minutesGooda series of emails or minutes showing issues raised and addressed
- Asktraining records of staff involved in managing provider contractsLook atdetails on date, content, and attendeesGoodrecent training records demonstrating that relevant staff attended and understood contract security requirements
- Look ata clear plan with dates and responsible personsGooda documented plan showing regular intervals and assigned employees for each check
Cross-framework mappings
How ISM-1738 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 5.20 | Annex A 5.20 requires relevant information security requirements to be established and agreed with each supplier based on the relationshi... | |
sync_altPartially overlaps(4)expand_less | ||
| Annex A 5.19 | ISM-1738 mandates regular verification of service provider compliance with contracted security requirements | |
| Annex A 5.21 | ISM-1738 requires regular, ongoing verification of service providers against contractual security requirements | |
| Annex A 5.22 | Annex A 5.22 requires organisations to monitor and evaluate supplier practices and service delivery, including managing change | |
| Annex A 5.36 | Annex A 5.36 requires organisations to regularly review compliance with information security policies, rules and standards | |
handshakeSupports(2)expand_less | ||
| Annex A 8.21 | Annex A 8.21 requires that security requirements for network services are identified and that implemented mechanisms and service levels a... | |
| Annex A 8.30 | Annex A 8.30 requires directing, monitoring and reviewing outsourced system development activities on an ongoing basis | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Procurement and outsourcing
See all Guidelines for procurement and outsourcing controls, or browse the full ASD ISM library.