FAQGlobalISO/IEC 27036

ISO/IEC 27036 FAQ Fourth Parties

How should we manage suppliers used by our supplier?

Part 2 contains supplier and acquirer relationship requirements; the other parts provide concepts or guidance. Apply the relevant part proportionately and verify contractual, legal, and customer duties separately.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes a multi-layer ; it does not require the same questionnaire or direct audit right for every remote tier.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

How should we manage suppliers used by our supplier?

Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes a multi-layer ; it does not require the same questionnaire or direct audit right for every remote tier.

ISO/IEC 27036 uses supply-chain and subcontractor language rather than defining "fourth party." On this page, fourth party means a supplier, component source, service, or other dependency used behind the direct supplier. The direct supplier remains the practical route for setting upstream requirements unless another agreement gives the acquirer direct rights. A subcontractor is not automatically high risk, and a non-contractual component or open-source dependency can still be consequential.

  • Identify upstream dependencies that receive privileged access or sensitive information, supply critical components, create concentration, are hard to replace, or have unclear provenance.
  • Set permission or notification rules for subcontracting and require the direct supplier to pass relevant security, confidentiality, incident, evidence, audit, and disposal requirements upstream.
  • Define which upstream changes or incidents require notice, what evidence the direct supplier must obtain, and who tracks corrective actions.
Citations
ISO/IEC 27036-1:2021 standard page

Part 1 defines a supply chain as successive supplier relationships and explains why an acquirer often has limited control beyond its direct supplier.

ISO/IEC 27036-2:2022 standard page

Part 2 requires subcontractor transparency criteria, including use and change notices, assurance, audit, confidentiality, and other parties exposed to acquirer information.

ISO/IEC 27036-3:2023 standard page

Part 3 addresses physically dispersed and multi-layer hardware, software, and services supply chains and recursive requirements for upstream suppliers.

Question 2

How far into the supply chain should review go?

Go as far as the relationship risk and available influence justify. Start with the function and exposure, not a fixed number of tiers. A remote supplier can deserve attention when it controls a critical component, processes sensitive information, has privileged access, is a single source, or creates a shared dependency across several direct suppliers.

For lower-impact dependencies, evidence that the direct supplier operates an effective upstream risk process may be enough. For a critical dependency, ask for the identity or category, function, location, change and incident duties, assurance evidence, alternatives, and recovery or substitution plan. If identity cannot be disclosed, record the visibility limit and assess whether other evidence or controls are sufficient.

  • Map the dependency to the product or service and to the information, access, component, or business function it affects.
  • Record the direct supplier's responsibility for selection, monitoring, incident escalation, remediation, and replacement.
  • Reassess after a material upstream change, incident, vulnerability, acquisition, location change, loss of support, or concentration increase.
Citations
ISO/IEC 27036-1:2021 standard page

Part 1 explains that supply-chain risk and visibility depend on the acquirer's position and that control generally decreases beyond the direct supplier.

ISO/IEC 27036-2:2022 standard page

Part 2 supports risk-proportionate selection criteria, subcontractor transparency, assurance, change management, incident handling, and corrective action.

ISO/IEC 27036-3:2023 standard page

Part 3 guides visibility, traceability, credible evidence, upstream requirements, vulnerability response, monitoring, and component or service substitution.

Recommended next step

Put ISO/IEC 27036 FAQ: Fourth Parties into practice

Capture owners, evidence, decisions, and review dates in one workflow record so supplier security controls and escalation points stay auditable over time.

Question 3

What if visibility is limited?

Limited visibility leaves the dependency's security unproven. Record what is unknown, why it matters, which direct-supplier evidence was reviewed, and which controls reduce the exposure. Options can include segmentation, least privilege, data minimization, verified updates, inventory and provenance records, diverse supply, substitution, monitoring, or explicit residual-risk acceptance.

Do not promise direct audit rights over an upstream supplier unless an agreement grants them. ISO/IEC 27036 supports proportionate visibility and recursive requirements; it does not create contractual privity or a universal right to inspect every tier.

  • Escalate an unresolved critical dependency to the person authorized to require remediation, change the architecture, approve the residual risk, or choose another supplier.
  • Keep the dependency map, evidence, limitations, decision, owner, and next review trigger with the direct relationship record.
  • Verify any legal, regulatory, or customer flow-down duty separately from ISO/IEC 27036.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 provides requirements for risk treatment, subcontractor criteria, assurance, monitoring, change, incident, and corrective-action records.

Primary sources

References and citations

iso.org
Referenced sections
  • Part 2 provides requirements for risk treatment, subcontractor criteria, assurance, monitoring, change, incident, and corrective-action records.
iso.org
Referenced sections
  • Part 3 provides guidance on multi-layer supply-chain visibility, traceability, recursive requirements, monitoring, and risk treatment.
Related guides

Explore more topics

ISO/IEC 27036 Assurance Evidence FAQ
Collect evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.
ISO/IEC 27036 Cloud Suppliers FAQ
Treat cloud as a supplier relationship with cloud service customer and provider perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.
ISO/IEC 27036 Contract Controls FAQ
Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.
ISO/IEC 27036 Contract Security Clauses Guide
Build ISO/IEC 27036-aligned supplier security clauses from relationship risk, responsibilities, assurance, change, incidents, and exit.
ISO/IEC 27036 ICT Supply Chain Lifecycle Guide
Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
ISO/IEC 27036 Indirect and Fourth Party Suppliers Guide
Manage indirect supplier dependencies under ISO/IEC 27036 using risk-based visibility, flow-down expectations, monitoring, and contingency planning.
ISO/IEC 27036 Onboarding and Offboarding Workflow
Run ISO/IEC 27036 supplier onboarding and offboarding with approval gates, evidence, access control, continuity, and verified closure.
ISO/IEC 27036 Risk Tiers FAQ
No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
ISO/IEC 27036 Supplier Assurance Framework Guide
Design risk-based ISO/IEC 27036 supplier assurance with defined evidence scope, monitoring, findings, and reassessment.
ISO/IEC 27036 Supplier Incidents FAQ
Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.
ISO/IEC 27036 Supplier Monitoring Evidence Workflow
Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.
ISO/IEC 27036 Supplier Monitoring FAQ
ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.
ISO/IEC 27036 Supplier Relationship Types Guide
Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
ISO/IEC 27036 Supplier Security FAQ
Plain-language answers about ISO/IEC 27036 scope, parts, roles, agreements, assurance, monitoring, incidents, indirect suppliers, cloud services, and exit.
ISO/IEC 27036 Termination and Offboarding FAQ
Plan termination before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.
ISO/IEC 27036 Third Party Risk Checklist
Use an ISO/IEC 27036 supplier-risk checklist across scope, assessment, agreement, operation, change, incidents, and termination.
ISO/IEC 27036 vs NIST SP 800-161 Comparison
Compare ISO/IEC 27036 supplier-relationship security with NIST SP 800-161 Rev. 1 cyber supply-chain risk management.
Using the ISO/IEC 27036 Supplier Relationship Series
Understand how to apply the four-part ISO/IEC 27036 series without treating it as a law or standalone certification.