Supplier risk is rarely caused by bad intent—it is caused by unclear expectations. Over my 30 years in governance, risk, and compliance, I have seen far too many organisations rely on informal verbal promises, glossy vendor marketing claims, or generic commercial purchase orders that contain zero security language. When a third-party data breach, system outage, or audit failure occurs, relying on unwritten assumptions leaves your business completely indefensible, legally exposed, and unable to enforce accountability. Annex A 5.20 turns supplier security from vague assumption into explicit, legally binding contractual agreement before access is granted or services begin.
ISO 27001:2022 includes Annex A 5.20 to ensure your organisation explicitly defines, documents, and embeds information security requirements directly into contracts and agreements with suppliers. This control updates former 2013 requirements (15.1.2) and forms the contractual bedrock of your supplier security governance—linking directly with ICT supply chain controls (Annex A 5.21), ongoing supplier monitoring (Annex A 5.22), cloud security (Annex A 5.23), and privacy safeguards (Annex A 5.34).
Quick Summary: What ISO 27001 Annex A 5.20 Requires
At a practical level, Annex A 5.20 is about ensuring that every third-party vendor, SaaS platform, contractor, or managed service provider (MSP) is bound by enforceable security commitments that match the risk they pose to your business. It does not mean forcing a 100-page legal schedule onto a local stationery supplier; it expects risk-proportionate, clear contractual terms. Here is what you need to do in plain English:
- Incorporate Mandatory Security Schedules: Attach explicit Information Security Schedules or Data Processing Agreements (DPAs) to Master Services Agreements (MSAs) and Statements of Work (SOWs).
- Define Permitted Data Use & Access Boundaries: Contractually restrict what information the supplier can access, where it can be stored/processed, and how it must be protected (Annex A 8.3).
- Mandate Rapid Incident Notification SLAs: Require vendors to report confirmed or suspected security incidents within strict, defined timeframes (e.g., 24–48 hours) (Annex A 5.26).
- Govern Subcontractor & Sub-Processor Rules: Require prior written consent or explicit notification before a vendor can delegate services or transfer data to downstream fourth-party subcontractors (Annex A 5.21).
- Secure Right-to-Audit & Assurance Clauses: Reserve contractual rights to review annual SOC 2 Type II reports, ISO 27001 certificates, or conduct independent security assessments (Annex A 5.22).
- Establish Explicit Exit & Data Return/Destruction Obligations: Define binding terms for returning corporate data, revoking access, and receiving formal Certificates of Destruction upon contract termination (Annex A 8.10).
Why Relying on Unwritten Supplier Expectations Is a Critical Hazard
When an organisation grants third-party access to systems or data without explicit contractual security terms, it loses legal leverage and operational control. If a vendor suffers a ransomware outbreak or leaks sensitive records, you cannot force them to cooperate, disclose technical logs, or cover remediation costs if those duties were omitted from the contract.
Ignoring contractual supplier security controls exposes your business to severe hazards:
- Disputed Incident Accountability & Delayed Reporting: A vendor discovering a data breach on Friday but waiting three weeks to inform you because their contract contained no incident notification SLA (Annex A 5.31).
- Uncontrolled Fourth-Party Subcontracting: Vendors silently outsourcing software development or cloud hosting to unvetted offshore sub-processors without your knowledge or approval (Annex A 5.21).
- Inability to Verify Security Posture: Vendors refusing to provide SOC 2 reports, penetration test summaries, or compliance proof because the contract lacks audit rights clauses.
- Residual Post-Termination Data Exposure: Departed vendors retaining legacy customer backups or source code indefinitely because no data return or destruction obligations were specified (Annex A 5.33).
My 8 Step Plan to Implement Annex A 5.20 Fast
You do not need a massive legal retainer to satisfy an ISO 27001 auditor. Here is my pragmatic, 8-step plan to establish an audit-ready supplier agreement framework.
1. Create Standard Security Schedule Templates Tiered by Risk
Co-author standardized Information Security Addendums with your Legal and Procurement leads, tiered by vendor risk (Annex A 8.9):
- High Risk / Critical (Data Processors, Cloud Hosting, MSPs): Full Information Security Schedule + Data Processing Agreement (DPA) + Right to Audit + 24-hr Incident SLA + Strict Subcontractor Controls.
- Medium Risk (Operational SaaS, Software Vendors): Standard Security Schedule + Annual SOC 2 / ISO Certificate Collection + 48-hr Incident SLA + Data Return/Deletion clause.
- Low Risk (Commodity Suppliers, Facilities): Basic Confidentiality / NDA clause + Acceptable Use Policy compliance.
2. Define Explicit Information Handling and Confidentiality Terms
Ensure agreements set strict boundaries around how your organizational assets and data may be handled (Annex A 5.34):
- Prohibit vendors from using, copying, modifying, or selling corporate data for any purpose outside the explicit scope of the contract.
- Mandate encryption baselines: AES-256 for data at rest and TLS 1.3 for data in transit across all vendor-managed platforms (Annex A 8.24).
- Specify geographical data residency boundaries (e.g., “Data must remain hosted within the UK / EU / US”) to comply with statutory privacy laws (Annex A 5.31).
3. Contractualize Strict Incident Management SLAs
Vendor incident response expectations must be established in the contract before a crisis strikes (Annex A 5.26):
- Mandate explicit notification timeframes: require the vendor to notify your CISO/SecOps team in writing within 24 to 48 hours of detecting a confirmed or suspected security incident.
- Obligate the supplier to provide prompt technical updates, root cause analysis (RCA) reports, and full cooperation during forensic investigations (Annex A 5.28).
- Include designated 24/7 emergency contact details (names, roles, direct phone numbers, and monitoring inboxes) for both parties.
4. Enforce Downstream Subcontractor Flow-Down Clauses
Prevent hidden supply chain vulnerabilities by controlling fourth-party sub-processors (Annex A 5.21):
- Require the primary supplier to obtain written approval or provide at least 30 days’ advance notice before engaging new subcontractors that will handle corporate data.
- Mandate that suppliers contractually “flow down” equivalent security, privacy, and confidentiality obligations to all downstream subcontractors.
- Hold the primary vendor fully liable for all security omissions, breaches, or failures caused by their sub-processors.
5. Embed Audit Rights and Assurance Expectations
Ensure your organisation retains the right to verify vendor security posture throughout the relationship (Annex A 5.22):
- Include clauses reserving the right to conduct annual security reviews, review independent SOC 2 Type II / ISO 27001 audit reports, or issue annual security questionnaires.
- Reserve the right to perform (or engage a third party to perform) technical vulnerability scans or on-site audits for critical/high-risk suppliers under agreed notice periods.
- Require suppliers to remediate critical or high-risk audit findings within agreed timeframes (e.g., 30 days) at their own expense.
6. Establish Clear Security Rules for Change Management
Prevent unannounced supplier operational shifts from breaking your security controls (Annex A 8.32):
- Require vendors to provide advance written notice (e.g., 30–60 days) prior to executing major architectural changes, infrastructure migrations, or software version upgrades that could affect security posture or service availability.
- Ensure contracts grant your organisation the right to review and re-assess risk when a supplier undergoes major organizational changes (such as M&A or platform restructuring).
7. Plan for Contract Termination, Exit, and Data Disposal
Obligations must explicitly cover the end of the relationship lifecycle (Annex A 8.10):
- Mandate that upon contract termination, the supplier must promptly return all corporate data, code, and documentation in an agreed open format (e.g., CSV, JSON) (Annex A 5.23).
- Require the vendor to permanently delete or crypto-shred all residual copies, backups, and archives across their primary and secondary environments within 30 days.
- Require the execution and delivery of an auditable, signed Certificate of Destruction confirming complete data sanitization.
8. Enforce Procurement & Renewal Contract Gates
Ensure no vendor relationship begins—or renews—without signed security agreements in place:
- Configure procurement ticketing systems to block vendor purchase order creation or invoice payments until the Security Schedule and DPA are fully executed.
- Require Procurement and Legal leads to review existing vendor security agreements prior to contract renewal or expansion (Annex A 5.22).
- Store all signed contracts, DPAs, and security addendums in a centralized, access-controlled contract management portal for easy audit retrieval.
Common Implementation Pitfalls and How to Fix Them
When preparing clients for ISO 27001 audits, I frequently spot the same contractual agreement mistakes. Here are the main traps and how to solve them:
- Problem: Relying on Generic Off-the-Shelf Commercial Purchase Orders Lacking Security Clauses
Ninja Solution: Mandate the inclusion of a standard Information Security Addendum as a mandatory appendix to all commercial contracts. - Problem: Accepting Vendor Master Terms That Explicitly Disclaim All Incident Notification Liabilities
Ninja Solution: Establish non-negotiable procurement “red lines” requiring strict breach notification SLAs and legal indemnities for data protection failures. - Problem: Overloading Low-Risk Local Suppliers with Complex 50-Page Enterprise Security Schedules
Ninja Solution: Implement a tiered contract framework; reserve comprehensive security schedules strictly for Tier 1 high-risk/critical vendors. - Problem: Forgetting to Include Data Deletion and Certificate of Destruction Clauses Upon Termination
Ninja Solution: Incorporate standard exit, data return, and crypto-shredding requirements into your master contract template.
The ISO 27001 Ninja Bottom Line
ISO 27001 Annex A 5.20 is about turning verbal promises and marketing claims into explicit, legally binding, and enforceable security expectations. Contracts do not create technical security on their own, but they define the legally defensible boundaries within which every third-party relationship must operate.
By creating risk-tiered security schedules, defining information handling boundaries, mandating 24-to-48-hour incident notification SLAs, governing subcontractor flow-down rules, embedding audit rights, managing change notifications, detailing exit data destruction workflows, and enforcing strict procurement contract gates, you eliminate third-party ambiguity, protect your organization from vendor-side liability, and satisfy your ISO 27001 auditor with complete confidence.
Pro Tip for Small Businesses: When dealing with large hyperscale cloud vendors (like AWS, Microsoft, or Google) where custom contract negotiation is impossible, satisfy Annex A 5.20 by documenting your formal review and acceptance of their standard Online Service Terms, Data Processing Addendums (DPAs), and Shared Responsibility Models inside your vendor management file.
