FAQGlobalISO/IEC 27036

ISO/IEC 27036 FAQ Supplier Monitoring

How often should suppliers be monitored?

Part 2 contains supplier and acquirer relationship requirements; the other parts provide concepts or guidance. Apply the relevant part proportionately and verify contractual, legal, and customer duties separately.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

How often should suppliers be monitored?

ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.

ISO/IEC 27036-2:2022 requires the acquirer to define monitoring activities, their frequency, reporting, and corrective-action follow-up in the agreement, while the supplier supports those activities and operates its corrective-action process. Both parties reassess relevant changes and preserve the resulting records. The monitoring plan should state what is checked, who checks it, which evidence is accepted, when review occurs, and what triggers escalation after a .

  • Monitor the agreed service and security measures, required reports and assurance, access, incidents, vulnerabilities, updates, findings, corrective actions, subcontractors, and upstream dependencies.
  • Set a scheduled review that fits the relationship, then add event triggers for material service, technology, location, ownership, personnel, subcontractor, threat, control, or obligation changes.
  • Increase review depth or frequency when evidence expires, performance degrades, findings repeat, corrective actions are late, or the business becomes more dependent on the supplier.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 requires compliance monitoring and enforcement, change and incident management, corrective-action tracking, risk reassessment, and review of the agreement.

ISO/IEC 27036-3:2023 standard page

Part 3 guides monitoring of supplier processes and work products, verification, vulnerability response, changes, provenance, and multi-layer dependencies.

Question 2

What should a monitoring review decide?

A review should decide whether the supplier and acquirer are meeting the agreement, whether the evidence covers the actual product or service and review period, whether risk has changed, and whether any finding needs correction, a control change, an agreement update, formal acceptance, or termination planning.

Do not equate receipt with review. Record the requirement tested, evidence and period, reviewer, result, limitation, finding severity, corrective-action owner and due date, approval, and next scheduled or event-driven review.

  • Compare current results with prior findings, service levels, incident history, risk assumptions, and the approved relationship scope.
  • Verify closure evidence for corrective actions instead of closing them from a supplier status statement alone.
  • Escalate persistent or material through the agreement's enforcement and risk-acceptance process.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 identifies audit and risk reports, incident and change histories, corrective-action status, and approved agreement updates as relationship-management outputs.

ISO/IEC 27036-3:2023 standard page

Part 3 supports verification of supplier claims, monitoring of processes and work products, testing, maintenance records, vulnerability response, and component visibility.

Question 3

Which events should trigger an early review?

Trigger an early review after an incident, material vulnerability, missed service or security measure, expired or qualified assurance, major corrective-action delay, service or architecture change, new data use, access expansion, location change, merger or financial distress, new or changed subcontractor, end-of-support notice, regulatory change, or failed recovery or exit test.

The trigger should route to a named owner who can assess scope and risk, request evidence, update controls or terms, approve a time-bound exception, or begin replacement or termination. A calendar date alone does not handle fast-changing relationships.

  • Do not impose the same questionnaire and cadence on every supplier without regard to product or service risk.
  • Do not assume a current corporate certificate covers the exact service, location, period, controls, or upstream dependency in use.
  • State any mandatory monitoring or reporting interval from law, regulation, or contract separately from ISO/IEC 27036.
Citations
ISO/IEC 27036-2:2022 standard page

Part 2 ties monitoring to agreement compliance, risk, changes, incidents, corrective actions, and termination rather than one universal calendar interval.

ISO/IEC 27036-3:2023 standard page

Part 3 supports event-driven review of vulnerabilities, updates, business health, provenance, components, supplier processes, and supply-chain changes.

Primary sources

References and citations

iso.org
Referenced sections
  • Part 2 ties monitoring to agreement compliance, risk, changes, incidents, corrective actions, and termination rather than one universal calendar interval.
iso.org
Referenced sections
  • Part 3 supports event-driven review of vulnerabilities, updates, business health, provenance, components, supplier processes, and supply-chain changes.
Related guides

Explore more topics

ISO/IEC 27036 Assurance Evidence FAQ
Collect evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.
ISO/IEC 27036 Cloud Suppliers FAQ
Treat cloud as a supplier relationship with cloud service customer and provider perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.
ISO/IEC 27036 Contract Controls FAQ
Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.
ISO/IEC 27036 Contract Security Clauses Guide
Build ISO/IEC 27036-aligned supplier security clauses from relationship risk, responsibilities, assurance, change, incidents, and exit.
ISO/IEC 27036 Fourth Parties FAQ
Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes multi-layer supply chains; it does not require the same questionnaire or direct audit right for every remote tier.
ISO/IEC 27036 ICT Supply Chain Lifecycle Guide
Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
ISO/IEC 27036 Indirect and Fourth Party Suppliers Guide
Manage indirect supplier dependencies under ISO/IEC 27036 using risk-based visibility, flow-down expectations, monitoring, and contingency planning.
ISO/IEC 27036 Onboarding and Offboarding Workflow
Run ISO/IEC 27036 supplier onboarding and offboarding with approval gates, evidence, access control, continuity, and verified closure.
ISO/IEC 27036 Risk Tiers FAQ
No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
ISO/IEC 27036 Supplier Assurance Framework Guide
Design risk-based ISO/IEC 27036 supplier assurance with defined evidence scope, monitoring, findings, and reassessment.
ISO/IEC 27036 Supplier Incidents FAQ
Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.
ISO/IEC 27036 Supplier Monitoring Evidence Workflow
Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.
ISO/IEC 27036 Supplier Relationship Types Guide
Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
ISO/IEC 27036 Supplier Security FAQ
Plain-language answers about ISO/IEC 27036 scope, parts, roles, agreements, assurance, monitoring, incidents, indirect suppliers, cloud services, and exit.
ISO/IEC 27036 Termination and Offboarding FAQ
Plan termination before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.
ISO/IEC 27036 Third Party Risk Checklist
Use an ISO/IEC 27036 supplier-risk checklist across scope, assessment, agreement, operation, change, incidents, and termination.
ISO/IEC 27036 vs NIST SP 800-161 Comparison
Compare ISO/IEC 27036 supplier-relationship security with NIST SP 800-161 Rev. 1 cyber supply-chain risk management.
Using the ISO/IEC 27036 Supplier Relationship Series
Understand how to apply the four-part ISO/IEC 27036 series without treating it as a law or standalone certification.