A.5.22 A.5 · Organisational Controls

A.5.22 — Monitoring, review and change management of supplier services

Regularly monitor, review and audit supplier service delivery including changes to ensure agreed levels of IS and service are maintained.

Also written as A5.22, Annex A 5.22, ISO 27001:2022 A.5.22, ISO27001 A.5.22.

What ISO 27001 A.5.22 requires

Monitoring, review and change management of supplier services is one of 37 Organisational Controls in ISO/IEC 27001:2022 Annex A. Regularly monitor, review and audit supplier service delivery including changes to ensure agreed levels of IS and service are maintained. Organisational controls are judged on governance rather than tooling: an auditor wants a named owner, an approval trail, and evidence the control is exercised on a defined cadence rather than written once and filed.

Audit evidence assessors look for

When preparing your Statement of Applicability (SoA) for A.5.22, gather artefacts such as:

  • Supplier performance review meeting minutes
  • Supplier audit or assessment reports
  • Change notification records from suppliers
  • KPI and SLA compliance reports for key suppliers

How A.5.22 maps to SOC 2 and NIST CSF

If you run more than one framework, the same evidence usually satisfies all of them. A.5.22 aligns with:

SOC 2: CC4.1 Ongoing and separate evaluations, CC9.2 Vendor and business partner risk

NIST CSF 2.0: GV.SC-07 Ongoing supplier risk monitoring, GV.SC-09 Supply chain security throughout lifecycle, DE.CM-06 External provider activity monitoring

ISO 27001:2013 mapping

A.5.22 consolidates the following ISO 27001:2013 control(s): A.15.2.1, A.15.2.2. If you are transitioning an existing ISMS, map your prior evidence for these to A.5.22 in your updated SoA.

Map A.5.22 to NIST CSF & SOC 2 →
Crosswalk this control in the Control Mapper & Gap Assessment.
Document the risk →
Record treatment for gaps against A.5.22 in the Risk Register.

Related Annex A controls

A.5.21 Managing information security in the ICT supply chain A.8.30 Outsourced development A.5.35 Independent review of information security A.5.36 Compliance with policies, rules and standards for information security A.8.29 Security testing in development and acceptance A.8.34 Protection of information systems during audit testing

See all 37 Organisational Controls →

Frequently asked questions

Is ISO 27001 A.5.22 mandatory?

Annex A controls are not mandatory in the abstract. Clause 6.1.3 requires you to compare your risk treatment plan against Annex A and justify, in the Statement of Applicability, any control you exclude. If your risk assessment surfaces a risk that A.5.22 addresses, excluding it needs a documented, risk-based rationale that an auditor will test.

How do auditors test ISO 27001 A.5.22?

In two passes. First design: does a documented control exist, is it owned, and does it address the risk? Then operating effectiveness: the auditor samples records from across the audit period to confirm the control actually ran. A Stage 2 audit will typically pull several samples, so evidence that only exists for the month before the audit is a common finding.

How often should A.5.22 be reviewed?

ISO 27001 sets no fixed interval — it requires review at "planned intervals" and after significant change. Annual review is the norm most certification bodies expect, with an out-of-cycle review triggered by incidents, major system changes, restructures, or new regulatory obligations. Record the review date and outcome either way; an undated control is treated as unreviewed.

What does ISO 27001 A.5.22 map to in SOC 2 and NIST CSF?

A.5.22 aligns with SOC 2 CC4.1, CC9.2 and NIST CSF GV.SC-07, GV.SC-09, DE.CM-06. Evidence gathered for one framework will usually satisfy the others, which is the basis for a test-once, satisfy-many control library.

What was A.5.22 in ISO 27001:2013?

A.5.22 consolidates 2 control(s) from the 2013 edition: A.15.2.1, A.15.2.2. When transitioning, re-point the existing evidence rather than rebuilding it — the underlying requirement has not changed materially.