Does ISO/IEC 27036 prescribe supplier risk tiers?
No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
ISO/IEC 27036-2:2022 requires the acquirer's risk assessment to be commensurate with the criticality of the product or service and requires an acceptable risk level and treatment plan. A tier is an internal way to apply those decisions consistently; it is not an ISO classification or certificate and does not replace the relationship-specific assessment.
- Assess impact: information sensitivity, business and safety effect, legal or customer duties, recovery needs, and consequences of loss, compromise, or failure.
- Assess exposure and dependency: privileged or remote access, hosting or processing, integration, location, subcontractors, concentration, substitutability, provenance, and change rate.
- Use the result to set selection approval, required agreement terms, evidence depth, monitoring, incident escalation, continuity and exit planning, and the authority needed to accept exceptions.
Part 1 explains supplier-relationship risks, inherent and residual risk, relationship types, dependency, and the need for risk-based controls.
Part 2 requires a criticality-commensurate risk assessment, acceptable risk level, risk treatment, management decision, and relationship-specific requirements.