· Guide · 8 min read

How to Audit an Outsourced Supplier Against ISO 27001

Plan and perform a risk-based ISO 27001 supplier audit with clear criteria, evidence sampling, findings, ownership and proportionate follow-up.


A second-party supplier audit is an audit performed by, or on behalf of, a customer to obtain assurance about a supplier. For ISO 27001 programmes, its purpose is not to award certification. It is to determine whether agreed security requirements and relevant controls are operating for the service you receive.

The strongest supplier audits begin with business risk and the contract. They do not send every provider the same long questionnaire or try to re-audit an entire ISMS. A focused audit follows the data, service dependencies and failure scenarios that matter to the customer.

This guide provides a practical method for scoping, performing and following up an outsourced supplier audit while preserving a workable relationship.

Decide whether an audit is the right assurance method

An audit consumes time for both parties. Start by classifying the supplier using factors such as information sensitivity, privileged access, operational criticality, concentration risk, subcontracting, recovery dependency and regulatory obligations.

Low-risk suppliers may be adequately monitored through service reviews and security attestations. A higher-risk supplier may justify deeper document review, technical testing or an on-site or remote audit. An audit can also be triggered by a material service change, control failure, incident or repeated performance concern.

The UK National Cyber Security Centre recommends a proportionate supply-chain approach and notes that organisations should exercise audit rights or obtain upward security reporting. Its supplier assurance guidance also makes an important practical point: an audit should not be the security team’s first interaction with the supplier.

Establish authority before planning fieldwork

Confirm that the contract permits the planned activity. Audit clauses may define notice periods, frequency, locations, confidentiality, access limitations, use of third parties, cost allocation and treatment of findings. Cloud and multi-tenant providers may restrict direct inspection to protect other customers.

If access is limited, agree acceptable alternatives such as independent assurance reports, certification records, controlled demonstrations, evidence viewed without copying, or a briefing from the supplier’s external auditor. A contractual right does not remove the need to handle evidence lawfully and securely.

Record the audit sponsor, customer audit lead, supplier liaison, process owners and the person authorised to accept residual supplier risk. Procurement should help interpret contractual commitments; security should define risk-based criteria; the service owner should explain how the service is actually used.

Translate supplier risk into audit objectives

Avoid an objective as broad as “verify ISO 27001 compliance.” The supplier may have a certified ISMS whose scope does not cover your service, and your contract may require controls beyond its Statement of Applicability.

A better objective is specific, for example:

Determine whether privileged access to the hosted production service is authorised, reviewed, logged and revoked in accordance with the contract and the customer’s identified risks.

For each objective, identify:

  • the business or information asset at risk;
  • applicable contractual, policy and regulatory criteria;
  • relevant ISO 27001 requirements or selected Annex A controls;
  • the period of operation to examine;
  • locations, systems and subcontractors in scope; and
  • the evidence needed to reach a conclusion.

The Annex A control lookup can help locate related control themes, while the risk register guide explains how to keep audit priorities tied to real risk scenarios.

Request focused pre-audit information

Ask only for information that supports scope and sampling. Useful items may include the service architecture and data flow, responsibility model, relevant policies, asset and administrator populations, recent service changes, incident summaries, recovery test results, subcontractor list, assurance reports and the supplier’s own control metrics.

Treat a certificate as one input. Verify the certified entity, standard edition, issue and expiry dates, certification body and scope statement. A valid certificate may reduce duplicated work, but it does not prove that your contracted service, location or risk is covered.

Before receiving sensitive material, agree a secure transfer method, access restrictions, retention period and disposal approach. Often the auditor can examine records in the supplier’s environment and retain only identifiers or summaries needed to support findings.

Build an audit plan the supplier can execute

Share a plan that states objectives, scope, criteria, dates, time zone, participants, evidence access and meeting schedule. Identify any technical demonstrations early so the supplier can arrange authorised personnel.

Keep the agenda connected to risk. A one-day audit of a managed service might cover:

SessionPurposeLikely participants
Opening and service contextConfirm scope, changes and responsibility boundariesService owner, security lead
Identity and accessTrace joiners, privileged access and review recordsIAM owner, operations
Operations and monitoringExamine logging, alerts, vulnerabilities and changesSOC, platform team
Incident and continuityTest notification, recovery and learningIncident lead, continuity owner
Supplier chainReview material subcontractors and flow-down dutiesProcurement, legal
Findings validationConfirm facts and ownersRelevant process owners

The agenda is guidance, not a claim that every supplier needs all six sessions.

Test implementation and operation

Policies and diagrams show design. Samples and observations show whether processes operated. Use several evidence methods and compare the results:

  • interview the person accountable for the control and a person who performs it;
  • inspect approved procedures and current responsibility records;
  • observe a configuration or workflow in the live administrative interface;
  • sample records across the audit period;
  • trace exceptions through approval and closure; and
  • compare supplier evidence with customer-side tickets, reports or incidents.

For access management, select samples from different populations: new access, changed privileges, terminations, periodic reviews and emergency access. For incident management, include at least one event that crossed a notification threshold if the population contains one. For recovery, inspect objectives, test scope, results, unresolved actions and whether the customer participated where required.

Sampling should be explainable. Record the population, period, selection method, selected items and limitations. Do not imply statistical assurance from a small judgemental sample.

Follow subcontracting and shared responsibilities

A supplier can pass parts of the service to cloud, support or specialist providers, but the customer risk does not disappear. Identify which party performs each material security activity and who provides evidence.

Follow at least one important control through the chain. If the supplier relies on a cloud platform for backups, determine what the platform provides, what the supplier configures and what the customer must do. Then test the supplier’s responsibilities rather than accepting a provider brochure.

ISO/IEC 27036-2:2022 addresses information security across supplier and acquirer relationships, including operation, monitoring, review and improvement. Use it as additional guidance where the relationship warrants the depth; do not treat it as an automatic certification criterion.

Write findings that can be acted on

A defensible finding contains four elements:

  1. Criterion: the contract, policy or audit requirement used.
  2. Condition: what the auditor observed.
  3. Evidence: the records, samples and interviews supporting the condition.
  4. Risk: why the difference matters to the customer or service.

Distinguish a confirmed nonconformity from an observation or an evidence limitation. If the contract does not require a particular solution, avoid presenting personal preference as a breach.

Pass, partial and fail examples

Pass: The supplier produced the agreed privileged-user population, all selected accounts had current approval, quarterly reviews were completed and two removals were traceable to closed records within the contractual timeframe.

Partial: Reviews were performed for the primary platform, but the inherited support console was excluded without documented risk acceptance. The conclusion is limited to the tested platform and the gap is reported against the agreed scope.

Fail: Three terminated administrators retained active access, and the supplier could not show monitoring or approved exceptions. The finding names the criterion and affected samples without claiming that every account failed.

Assign follow-up and residual risk ownership

Agree the factual accuracy of findings before closing, but do not negotiate away supported conclusions. Each action should have a responsible supplier owner, expected outcome, due date and evidence of completion. The customer service owner monitors delivery; security validates control evidence; procurement manages contractual escalation; an authorised risk owner decides whether remaining exposure is accepted.

Closure requires more than a promise. First confirm correction of the sampled issue, then examine the cause and broader population, and finally assess whether the corrective action operated. A new procedure is implementation evidence; several completed cycles may be needed for operating evidence.

Use the risk score calculator to support prioritisation, applying the organisation’s approved method rather than treating the tool result as a final decision.

Common supplier-audit failures

Audits lose value when teams:

  • use a generic question set unrelated to service risk;
  • assume certification covers the contracted service;
  • ignore customer responsibilities in a shared model;
  • request excessive sensitive data without handling rules;
  • test only current settings and not operation over time;
  • surprise the supplier with technical access demands; or
  • close findings after receiving revised words but no operational evidence.

The remedy is a clear line from risk to criterion, evidence, conclusion and action.

A proportionate conclusion

A second-party audit should give decision-makers a defensible answer about a defined supplier risk. It is not a contest to find the most findings, and it is not a replacement for ongoing service monitoring.

Plan from the contract and risk assessment, verify scope boundaries, combine evidence methods, sample operation and give every material finding an owner. That approach produces useful assurance while respecting the practical constraints of outsourced services.

The subject perspective was informed by Advisera’s article on second-party audits of outsourced suppliers, with supplier-assurance claims checked against ISO and NCSC sources.