What supplier assurance evidence should we collect?
Collect assurance evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.
ISO/IEC 27036-2:2022 sets requirements for acquirers and suppliers across the relationship lifecycle. It identifies several forms of assurance, including performance reports, attestations, self-assessments, independent assessments, audits, tested continuity plans, and ISO/IEC 27001 certification. Part 3:2023 adds hardware, software, and service supply-chain guidance. The acquirer must decide what evidence is credible and sufficient for the selected supplier and requirement.
- Start with the requirement and decision: identify the control or risk being tested, the acceptance criteria, the reviewer, and what happens if the evidence is missing or weak.
- Check the evidence boundary: supplier legal entity, named product or service, sites, systems, control period, exclusions, qualifications, subcontractors, and upstream components.
- Test the result: inspect findings and corrective actions, compare claims with the agreement and other evidence, and record any residual risk or follow-up.
Part 2 requires risk-based supplier selection and agreement management and identifies several possible assurance methods rather than one mandatory evidence package.
Part 3 guides acquirers to seek credible evidence, verify supplier claims, and assess what attestations or certifications mean for the intended use.