Chapter 16
16Third Parties and Supply Chain Security
“Your security is only as strong as the weakest supplier holding a key to your house.”
No creative organisation works alone: freelancers, printers, sound studios, cloud providers, software libraries and AI tools. Each of these parties touches part of our assets. That is why ISO 27001:2022 devotes five controls (5.19 to 5.23) to security in supplier relationships and cloud services.


Text in this figure
Third · Party · Pre-assessment · Questionnaire · certs · Contracting · Security, privacy clauses · Onboarding · Least privilege · Monitoring · Periodic review · Exit · Revoke access, delete · Figure 21
The Third-Party Security Management Cycle
- Classification: Not every supplier carries the same risk; the printer receiving final files before launch is not the stationery supplier.
- Pre-contract assessment: A short security questionnaire, or a request for ISO 27001 certification or a SOC 2 report for critical suppliers.
- Contract: Confidentiality, data protection, incident reporting, right to audit, and return or deletion of data at the end.
- Monitoring: Periodic review of performance and access, and following news of supplier breaches.
- Exit: Revoke all access, and recover assets or confirm their deletion.
The Software Supply Chain
Every open-source library and every plugin in a design application is a grant of trust. A software bill of materials (SBOM) inventories what goes into each application we build, so the moment a vulnerability is announced in a popular library we know whether we are affected. Software composition analysis (SCA) tools scan this inventory automatically.
Cloud Services
Control 5.23 is new and requires processes for acquiring, using, managing and exiting cloud services. The governing principle is “shared responsibility”: the provider secures the infrastructure, and we secure the configuration, accounts and data. Most cloud incidents are caused by customer misconfiguration, not a breach of the provider.
2026 Update
AI tools are third parties too. Before adopting any tool, ask: is our data used to train the model? Where is it stored? For how long? Is there an enterprise edition with clearer terms? ISO 42001 requires in its Annex A (A.10) the allocation of responsibilities with suppliers and customers for every AI system.
Know your suppliers as you know your employees; both hold your keys.
Lessons Learned
- 1Suppliers are classified by the risk of what they access.
- 2The contract carries confidentiality, reporting, audit and deletion clauses.
- 3An SBOM reveals the impact of library vulnerabilities immediately.
- 4AI tools are suppliers to be assessed before adoption.
Tip: use ← → to move between sections.

