Skip to content
arrow_back
search
Annex A 5.20 verified ISO/IEC 27001:2022

Integrating security clauses in supplier agreements

Ensure suppliers meet agreed security requirements relevant to their relationship.

record_voice_over

Plain language

When you deal with suppliers, it's crucial to make sure they protect your information as well as you do. If they don't, sensitive data could leak or be misused, potentially leading to financial or reputational damage. By including clear security requirements in contracts, you ensure everyone knows the rules and responsibilities, reducing the risk of unpleasant surprises.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Relevant information security requirements shall be established and agreed with each supplier based on the type of supplier relationship.
verified ISO/IEC 27001:2022 Annex A 5.20
priority_high

Why it matters

Without defined security clauses, suppliers may mishandle sensitive data, leading to data breaches and loss of trust.

settings

Operational notes

Regularly review supplier contracts for agreed security requirements (e.g. access, incident notice, audit) and update clauses as the relationship or risks change.

Mapping detail

Mapping

Direction

Controls