How often should suppliers be monitored?
ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.
ISO/IEC 27036-2:2022 requires the acquirer to define monitoring activities, their frequency, reporting, and corrective-action follow-up in the agreement, while the supplier supports those activities and operates its corrective-action process. Both parties reassess relevant changes and preserve the resulting records. The monitoring plan should state what is checked, who checks it, which evidence is accepted, when review occurs, and what triggers escalation after a .
- Monitor the agreed service and security measures, required reports and assurance, access, incidents, vulnerabilities, updates, findings, corrective actions, subcontractors, and upstream dependencies.
- Set a scheduled review that fits the relationship, then add event triggers for material service, technology, location, ownership, personnel, subcontractor, threat, control, or obligation changes.
- Increase review depth or frequency when evidence expires, performance degrades, findings repeat, corrective actions are late, or the business becomes more dependent on the supplier.
Part 2 requires compliance monitoring and enforcement, change and incident management, corrective-action tracking, risk reassessment, and review of the agreement.
Part 3 guides monitoring of supplier processes and work products, verification, vulnerability response, changes, provenance, and multi-layer dependencies.