1. Purpose
The Supplier Security Review Template provides a structured method for periodically reviewing the information-security performance and security controls of suppliers and third-party service providers.
The review helps determine whether:
- The supplier continues to meet agreed security requirements
- Security controls remain appropriate for the service and risk
- Supplier access remains necessary and authorized
- Information remains appropriately protected
- Security incidents or vulnerabilities have occurred
- Subprocessors or service arrangements have changed
- Business continuity requirements remain satisfied
- Open security findings have been addressed
- Supplier risk has changed
- Contractual security requirements remain appropriate
Core Principle
Review → Verify → Identify Changes → Assess Risk → Address Findings → Approve → Monitor → Improve
2. When to Use
Use this review:
- Periodically based on supplier risk
- For critical and high-risk suppliers
- After a significant security incident
- After a major supplier service change
- When new information or systems are introduced
- When production or privileged access changes
- When new subprocessors are introduced
- When the supplier changes ownership
- When data location changes
- Before major contract renewal
- When significant security concerns arise
The review frequency should be defined using the organization’s risk methodology.
3. Supplier Review Information
| Field | Details |
|---|---|
| Review ID | |
| Supplier ID | |
| Supplier Name | |
| Supplier Type | |
| Service/Product | |
| Business Owner | |
| Supplier Owner | |
| Technical Owner | |
| Supplier Criticality | |
| Current Risk Level | |
| Previous Risk Level | |
| Review Date | |
| Reviewer | |
| Review Period | |
| Contract Expiry/Renewal | |
| Next Review Date | |
| Review Status |
4. Supplier Profile
Supplier
Service Provided
Business Process Supported
Critical Business Dependency
Information Processed
Information Classification
☐ Public
☐ Internal
☐ Confidential
☐ Restricted
5. Review Scope
Define what will be reviewed.
☐ Supplier security governance
☐ Security controls
☐ Access management
☐ Privileged access
☐ Cloud security
☐ Application security
☐ Vulnerability management
☐ Incident management
☐ Data protection
☐ Privacy
☐ Encryption
☐ Logging and monitoring
☐ Business continuity
☐ Subprocessors
☐ Data location
☐ Contractual requirements
☐ Security assurance
☐ Supplier performance
☐ Previous findings
☐ Exit arrangements
Scope Limitations
6. Previous Review
Review the previous supplier assessment.
| Previous Review Item | Result |
|---|---|
| Previous Risk Level | |
| Previous Findings | |
| Open Actions | |
| Security Incidents | |
| Contract Changes | |
| Service Changes | |
| Access Changes | |
| Subprocessor Changes | |
| Previous Exceptions |
7. Supplier Changes Since Last Review
Determine whether material changes occurred.
☐ Service changes
☐ Technology changes
☐ Ownership changes
☐ Management changes
☐ New locations
☐ New data locations
☐ New subprocessors
☐ New integrations
☐ New customer information
☐ New personal data
☐ New production access
☐ New privileged access
☐ Major security incident
☐ Major vulnerability
☐ Contract changes
☐ Business continuity changes
Change Summary
8. Security Governance Review
Assess whether the supplier continues to maintain appropriate security governance.
☐ Information-security policy
☐ Security responsibilities
☐ Security management
☐ Risk-management process
☐ Security awareness
☐ Internal security reviews
☐ Security objectives
☐ Security incident process
☐ Security improvement activities
Review Result
☐ Satisfactory
☐ Partially Satisfactory
☐ Requires Improvement
☐ Not Applicable
Comments
9. Security Certifications and Assurance
Review current assurance.
| Assurance | Status | Scope | Valid Until | Reviewed |
|---|---|---|---|---|
| ISO/IEC 27001 | ||||
| SOC 2 | ||||
| PCI DSS | ||||
| ISO/IEC 27701 | ||||
| Penetration Test | ||||
| Independent Assessment |
Check:
☐ Certification/report remains valid
☐ Scope covers relevant service
☐ Relevant locations are covered
☐ Exceptions reviewed
☐ Significant findings considered
☐ Expiry/renewal tracked
Comments
10. Information Security Control Review
Assess the supplier’s security controls against agreed requirements.
| Control Area | Status | Evidence | Finding |
|---|---|---|---|
| Access Control | |||
| Authentication/MFA | |||
| Privileged Access | |||
| Encryption | |||
| Vulnerability Management | |||
| Logging/Monitoring | |||
| Incident Management | |||
| Backup/Recovery | |||
| Business Continuity | |||
| Physical Security | |||
| Secure Development | |||
| Data Protection |
Status
- Effective
- Partially Effective
- Not Effective
- Not Applicable
- Evidence Not Available
11. Access Review
Verify that supplier access remains appropriate.
Access Questions
☐ Is access still required?
☐ Is the access limited to business need?
☐ Are individual accounts used where practical?
☐ Is MFA enabled?
☐ Are privileged accounts identified?
☐ Is production access still required?
☐ Are temporary accounts expired?
☐ Are inactive accounts removed?
☐ Are former supplier personnel removed?
☐ Is access periodically reviewed?
Access Review Summary
12. Privileged Access Review
Where suppliers have elevated access:
| User | System | Role | Business Need | MFA | Expiry | Review Result |
|---|---|---|---|---|---|---|
Verify:
☐ Business justification
☐ Named account
☐ Least privilege
☐ MFA
☐ Logging
☐ Monitoring where appropriate
☐ Review completed
☐ Access still required
☐ Excess privileges removed
13. Cloud Security Review
Where the supplier provides or manages cloud services:
☐ Cloud accounts identified
☐ Production environments identified
☐ IAM controls reviewed
☐ MFA reviewed
☐ Privileged roles reviewed
☐ Network security reviewed
☐ Encryption reviewed
☐ Logging reviewed
☐ Monitoring reviewed
☐ Backup reviewed
☐ Security configuration reviewed
Findings
14. Application Security Review
For software/SaaS suppliers:
☐ Secure development lifecycle
☐ Code review
☐ Dependency management
☐ Vulnerability scanning
☐ SAST/DAST where appropriate
☐ Security testing
☐ Penetration testing
☐ Security defect management
☐ Release/change controls
☐ Software supply-chain controls
Review Result
15. Vulnerability Management Review
Assess:
☐ Vulnerability identification
☐ Vulnerability scanning
☐ Risk prioritization
☐ Patch management
☐ Remediation tracking
☐ Retesting
☐ Critical vulnerability escalation
☐ Customer notification where contractually required
Significant Vulnerabilities
| Vulnerability | Severity | Affected Service | Remediation | Status |
|---|---|---|---|---|
16. Security Incident Review
Determine whether the supplier experienced security incidents during the review period.
☐ No significant incidents reported
☐ Incident occurred
☐ Information unavailable
☐ Further investigation required
If an incident occurred:
| Field | Details |
|---|---|
| Incident ID | |
| Date | |
| Type | |
| Affected Service | |
| Information Affected | |
| Customer Impact | |
| Root Cause | |
| Corrective Action | |
| Current Status |
Assessment
17. Data Breach Review
If the supplier processes customer or personal data:
☐ Data breach occurred
☐ No breach reported
☐ Breach information unavailable
☐ Further assessment required
Consider:
- Data involved
- Data subjects
- Cause
- Impact
- Notification
- Corrective action
- Regulatory implications
- Customer communication
Review Result
18. Data Protection Review
Verify:
☐ Data classification remains appropriate
☐ Data minimization remains appropriate
☐ Access remains restricted
☐ Retention requirements remain appropriate
☐ Deletion requirements remain defined
☐ Data location remains acceptable
☐ Transfers remain authorized
☐ Encryption remains appropriate
☐ Contractual requirements remain satisfied
19. Subprocessor Review
Determine whether subprocessors have changed.
☐ No changes
☐ New subprocessors
☐ Existing subprocessor removed
☐ Subprocessor service changed
| Subprocessor | Service | Data/Access | Location | Security Review |
|---|---|---|---|---|
Assess whether changes require:
- Risk reassessment
- Contract update
- Privacy review
- Customer notification
- Security review
20. Data Location Review
Verify whether data-processing locations have changed.
| Location | Activity | Information | Change | Assessment |
|---|---|---|---|---|
Consider applicable contractual, privacy, regulatory, and customer requirements.
21. Encryption Review
Assess:
☐ Encryption in transit
☐ Encryption at rest
☐ Key management
☐ Key access
☐ Certificate management
☐ Key rotation
☐ Cryptographic controls
Findings
22. Logging and Monitoring Review
Assess whether relevant security activity remains monitored.
☐ Authentication
☐ Privileged activity
☐ Administrative activity
☐ Security events
☐ Application events
☐ Access events
☐ Incident alerts
☐ Log protection
☐ Log retention
Review Result
23. Business Continuity Review
Assess whether supplier continuity arrangements remain appropriate.
☐ Business Continuity Plan
☐ Disaster Recovery Plan
☐ Backup
☐ Recovery testing
☐ Redundancy
☐ Recovery objectives
☐ Incident escalation
☐ Alternative arrangements
Recovery Requirements
RTO: __________________
RPO: __________________
Review Result
24. Supplier Service Availability
Review supplier performance against agreed requirements.
| Metric | Requirement | Actual | Status |
|---|---|---|---|
| Availability | |||
| Response Time | |||
| Incident Response | |||
| Recovery | |||
| Support |
Service Issues
25. Contractual Security Review
Review whether the current contract remains appropriate.
☐ Security requirements
☐ Confidentiality
☐ Data protection
☐ Incident notification
☐ Breach notification
☐ Subprocessors
☐ Data location
☐ Data retention
☐ Data deletion/return
☐ Business continuity
☐ Security assurance
☐ Audit/assessment provisions where appropriate
☐ Termination
☐ Exit assistance
Contract Changes Required
26. Supplier Security Questionnaire Review
Where a questionnaire was used:
☐ Questionnaire remains current
☐ Responses reviewed
☐ Material changes identified
☐ Evidence reviewed
☐ Exceptions identified
☐ Follow-up completed
Key Changes
27. Supplier Security Findings
Record findings identified during the review.
| Finding ID | Area | Finding | Risk | Recommendation | Owner | Due Date | Status |
|---|---|---|---|---|---|---|---|
28. Corrective Action Tracking
| Action ID | Finding | Corrective Action | Owner | Due Date | Evidence | Status |
|---|---|---|---|---|---|---|
Corrective actions should be verified before closure where appropriate.
29. Risk Reassessment
Compare current risk with the previous assessment.
| Risk | Previous | Current | Change | Treatment |
|---|---|---|---|---|
Risk Factors
Consider:
- New information
- New systems
- New access
- New vulnerabilities
- Incidents
- Service changes
- Subprocessors
- Data-location changes
- Business dependency
- Regulatory changes
- Contract changes
30. Residual Risk
After considering existing controls and corrective actions:
Residual Risk: __________________
Risk Owner: ______________________
Risk Treatment: __________________
Risk Acceptance Required: ☐ Yes ☐ No
If risk acceptance is required, follow the organization’s approved risk-acceptance process.
31. Critical Supplier Assessment
If the supplier is classified as critical:
☐ Criticality remains valid
☐ Business dependency reviewed
☐ Availability requirements reviewed
☐ Recovery requirements reviewed
☐ Concentration risk considered
☐ Alternative arrangements considered
☐ Exit/migration capability reviewed
☐ Enhanced security assurance reviewed
Critical Supplier Comments
32. Supplier Security Performance
Evaluate supplier performance using documented evidence.
| Area | Result | Evidence/Comments |
|---|---|---|
| Security Controls | ||
| Incidents | ||
| Vulnerabilities | ||
| Access Management | ||
| Service Availability | ||
| Business Continuity | ||
| Contract Compliance | ||
| Security Responsiveness | ||
| Corrective Actions |
This section should describe evidence-based observations rather than assigning an arbitrary overall score unless the organization’s approved methodology requires one.
33. Review Conclusion
Review Outcome
☐ Controls remain appropriate
☐ Minor improvements required
☐ Corrective action required
☐ Risk reassessment required
☐ Contract update required
☐ Enhanced monitoring required
☐ Supplier re-approval required
☐ Relationship escalation required
Conclusion
34. Supplier Approval Status
Following the review:
☐ Continue supplier relationship
☐ Continue with conditions
☐ Continue with corrective actions
☐ Enhanced monitoring required
☐ Suspend specific access/service
☐ Further management decision required
☐ Initiate supplier exit
Conditions
35. Management Escalation
Escalate where appropriate due to:
☐ Significant security risk
☐ Major unresolved finding
☐ Significant incident
☐ Critical vulnerability
☐ Contractual non-compliance
☐ Business continuity concern
☐ Excessive supplier dependency
☐ Unacceptable residual risk
Escalated To: ______________________________
Date: _____________________________________
Decision/Action: ____________________________
36. Supplier Review Approval
Business Owner
Name: ______________________
Role: _______________________
Signature/Approval: ______________________
Date: _______________________
Security/ISMS Reviewer
Name: ______________________
Role: _______________________
Approval: ___________________
Date: _______________________
Risk Owner
Name: ______________________
Role: _______________________
Approval: ___________________
Date: _______________________
37. Next Review
Next Review Date: __________________________
Earlier Review Required If:
☐ Security incident
☐ Data breach
☐ Major vulnerability
☐ New production access
☐ New privileged access
☐ New service
☐ New data
☐ New subprocessor
☐ Major contract change
☐ Change in ownership
☐ Major outage
☐ Regulatory change
38. Evidence Repository
Record where supporting evidence is maintained.
| Evidence | Reference/Location |
|---|---|
| Supplier Questionnaire | |
| Security Assessment | |
| Assurance Report | |
| Contract | |
| Risk Assessment | |
| Access Review | |
| Incident Records | |
| Business Continuity Evidence | |
| Findings | |
| Corrective Actions | |
| Approval |
Do not place passwords, API keys, private keys, access tokens, or other actual secrets in the review record.
39. Audit Trail
A completed supplier review should allow an auditor to trace:
Supplier Register
→ Supplier Risk Assessment
→ Previous Review
→ Current Security Evidence
→ Access Review
→ Security Findings
→ Corrective Actions
→ Risk Reassessment
→ Management Decision
→ Supplier Approval
→ Next Review
40. AWS SaaS Startup Example
A SaaS startup uses AWS as a critical supplier.
Review
Supplier: AWS
Service: Production cloud infrastructure
Criticality: Critical
Information: Customer information
Review Areas
- AWS account structure
- IAM/Identity Center
- MFA
- Privileged access
- Production roles
- CloudTrail
- CloudWatch
- Encryption/KMS
- S3 access
- RDS security
- Backup
- Recovery
- Security monitoring
- Service availability
- Supplier assurance
- Relevant incidents
Example Finding
A former administrator retained an unnecessary elevated role.
Corrective Action
Remove unnecessary permission, verify effective permissions, update access records, and retain evidence of remediation.
Audit Trail
Supplier → Critical Dependency → Security Review → Access Finding → Remediation → Verification → Risk Review → Approval
41. Startup-Friendly Supplier Review
A startup does not need to perform the same depth of review for every supplier.
Low-Risk Supplier
Review:
- Service
- Business need
- Information
- Basic security requirements
- Contract
- Incidents
- Material changes
Medium-Risk Supplier
Add:
- Security questionnaire
- Access review
- Security assurance
- Vulnerability management
- Incident management
- Backup/continuity
- Data location
High/Critical Supplier
Add enhanced review of:
- Privileged access
- Production access
- Cloud security
- Application security
- Security testing
- Subprocessors
- Data protection
- Business continuity
- Independent assurance
- Contractual security controls
- Exit/migration capability
42. Common Mistakes
Avoid:
- Treating the supplier review as a formality.
- Copying the previous review without checking for changes.
- Reviewing only certifications.
- Ignoring actual supplier access.
- Ignoring privileged access.
- Ignoring security incidents.
- Ignoring vulnerabilities.
- Ignoring subprocessors.
- Ignoring data-location changes.
- Ignoring business continuity.
- Failing to track open findings.
- Closing findings without verification.
- Failing to reassess risk.
- Failing to update the Supplier Register.
- Treating supplier approval as permanent.
43. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Supplier Register | Master supplier inventory |
| Critical Supplier Register | Critical supplier identification |
| Supplier Security Management Policy | Supplier governance |
| Supplier Risk Assessment | Supplier risk analysis |
| Supplier Security Questionnaire | Supplier-provided information |
| Third-Party Due Diligence Checklist | Initial supplier assessment |
| Supplier Security Assessment | Detailed control assessment |
| Supplier Security Agreement | Contractual requirements |
| Supplier Access Review | Review of supplier access |
| Third-Party Access Procedure | Access lifecycle |
| Supplier Offboarding | Secure supplier exit |
| Risk Register | Significant supplier risks |
| Incident Management | Supplier security incidents |
| Business Continuity Plan | Supplier dependency and recovery |
44. ISO 27001 Connection
Supplier security reviews support the organization’s risk-based management of supplier relationships and related areas such as:
- Supplier relationships
- Supplier agreements
- ICT supply-chain security
- Monitoring and review of supplier services
- Access control
- Information transfer
- Incident management
- Business continuity
- Information-security risk management
The Supplier Security Review Template is not itself a universally mandatory ISO 27001 document. The organization should determine the appropriate review activities, frequency, evidence, and records based on supplier risk, business requirements, contractual obligations, and applicable legal/regulatory requirements.
The applicable ISO 27001 controls should be determined through the organization’s risk assessment and Statement of Applicability.
45. Quick Audit Checklist
☐ Supplier identified
☐ Review scope defined
☐ Previous review considered
☐ Supplier changes assessed
☐ Security controls reviewed
☐ Security assurance reviewed
☐ Access reviewed
☐ Privileged access reviewed
☐ Information protection reviewed
☐ Vulnerabilities reviewed
☐ Incidents reviewed
☐ Business continuity reviewed
☐ Subprocessors reviewed
☐ Data locations reviewed
☐ Contract reviewed
☐ Findings documented
☐ Corrective actions assigned
☐ Risk reassessed
☐ Residual risk considered
☐ Approval obtained
☐ Supplier Register updated
☐ Next review date established
46. Final Principle
A supplier security review should answer one practical question: “Does this supplier still provide the required service while maintaining security controls appropriate to the information, access, dependency, and risk involved?”
The review should therefore connect:
Supplier → Service → Information → Access → Security Controls → Changes → Findings → Risk → Corrective Action → Verification → Approval → Ongoing Monitoring
