How should teams manage Fourth Parties under ISO/IEC 27036?
Start with the operational decision: define what Fourth Parties means in your ISO/IEC 27036 scope, who owns it, and what record proves the decision is current.
For supplier work, keep the supplier relationship type, tier, contract control, fourth-party exposure, monitoring cadence, incident notice route, and exit evidence in one record. This keeps the answer useful in audits, customer reviews, incidents, supplier reviews, and management review.
- Name the accountable owner and reviewer for Fourth Parties.
- Record the scope, assumptions, decision, approval date, evidence location, exception status, and next review trigger.
- Escalate when Fourth Parties changes risk acceptance, service commitments, customer promises, regulatory duties, or certification evidence.
Primary ISO listing for supplier relationship security overview and concepts.
Primary ISO listing for supplier and acquirer relationship requirements.