Practical toolGlobalISO/IEC 27036

ISO/IEC 27036 Onboarding and Offboarding Workflow

Approve a supplier only after the risk treatment, selection decision, security terms, transition controls, and operating owners are ready. Close the relationship only after the termination plan is complete.

ISO/IEC 27036-2:2022 supplies the relationship requirements. Use ISO/IEC 27036-3:2023 for hardware, software, and services supply chains and ISO/IEC 27036-4:2016 for cloud-specific guidance. Applicable law and the agreement can add binding duties.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use five controlled stages: create the , select the supplier, approve the agreement and transition, manage the live service, and execute termination. ISO/IEC 27036-2:2022 assigns activities and records to the acquirer and supplier at each stage; it does not treat onboarding as a completed questionnaire.

Section 1

What must be decided before supplier onboarding?

Start with a . The acquirer identifies the product or service, relevant assets and owners, information that may be shared, legal and regulatory constraints, required permissions, security roles, minimum security requirements, and risks created by dependencies on other suppliers. Management records whether the risk assessment and treatment plan allow procurement to begin.

Selection then tests the supplier against criteria derived from that plan. Relevant criteria can include acceptance of security requirements, demonstrated security capability, audit and assurance terms, transition and termination readiness, capacity, financial strength, service location, and transparency about subcontractors. A certificate can support this decision, but its scope must match the product, service, locations, and entities in the proposed relationship.

  • Acquirer: document the risk assessment, treatment plan, acceptable risk decision, , selection criteria, and evaluation result.
  • Supplier: assess the risks of supplying the product or service, identify gaps against the acquirer's requirements, and provide a response that states how those gaps will be handled.
  • Decision branch: do not approve onboarding merely because due diligence was returned. Record a rejection, treatment action, contractual condition, or explicit risk decision when a requirement is not met.
Section 2

What must the agreement and go-live gate contain?

Before go-live, the acquirer and supplier approve an agreement that carries the selected security requirements into operation. ISO/IEC 27036-2:2022 calls for roles and responsibilities, required controls, subcontracting terms, service levels or measures, change and incident procedures, compliance monitoring, corrective-action handling, intellectual-property terms, termination conditions, and a termination plan. Add a transition plan when another party previously operated or manufactured the product or service.

The go-live owner should check that the signed agreement and plans are stored under document control, required personnel understand the security terms, agreed communication methods work, access is limited to approved people and assets, and transition results are recorded. If a control will be completed after go-live, record its owner, deadline, compensating control, and risk approval.

  • Agreement gate: every material requirement has an owner, acceptance test, evidence source, review trigger, and escalation path.
  • Technical gate: identities, privileges, connectivity, logging, asset records, information-transfer methods, and incident contacts match the approved scope.
  • Business gate: transition, continuity, support, training, and termination responsibilities are understood by both parties.
  • Deadline check: use applicable law and the signed agreement, not ISO/IEC 27036 alone, to set notification, retention, deletion, and response times.
Section 3

What happens after the supplier goes live?

Operate the relationship against the approved agreement rather than the original questionnaire. The acquirer and supplier manage agreed changes and incidents, train personnel involved in the relationship, carry out the monitoring plan, and track corrective actions. Keep the current agreement linked to risk assessments, audit reports, transition results, change and incident histories, and the status of each corrective action.

Reassess changes that fall outside the agreed procedure, including changes in ownership, financial strength, service location, security status, continuity capability, or applicable legal, regulatory, and contractual requirements. Decide whether to update controls, accept residual risk, amend the agreement, pause work, or terminate the relationship.

  • Scheduled review: compare measures and evidence with the criteria and reporting frequency stated in the agreement.
  • Event-driven review: reassess after an incident, audit nonconformity, material change, new subcontractor or dependency, or loss of a relied-on assurance.
  • Decision record: state the finding, affected requirement, interim protection, corrective action, due date, accountable party, approval, and closure evidence.
Section 4

How should supplier offboarding be executed and closed?

Start from the latest approved agreement and termination plan. Confirm the reason for termination and assess any security risk behind it. Decide whether the product or service will stop, return to the acquirer, or transfer to another supplier. For sudden termination of a critical supply, invoke the applicable continuity arrangements.

Appoint a termination owner and communicate with affected personnel and third parties. Reconcile the asset inventory; agree which assets and records each party will return, transfer, retain, or destroy; protect transfers; remove the other party's logical and physical access; and obtain evidence for agreed destruction. Retention law, regulatory duties, litigation holds, and surviving confidentiality terms can prevent immediate deletion, so record the authority, owner, protection, and end date for retained material.

  • Closure evidence: communication record, named termination owner, reconciled asset inventory, access-removal report, termination execution report, and any transfer or destruction evidence.
  • Exception branch: keep an item open when access, asset disposition, transfer, destruction, confidentiality, or another surviving obligation is incomplete; assign an owner and due date.
  • Final approval: both parties confirm completion against the termination plan and record any obligation that survives the end of service.
Recommended next step

Put ISO/IEC 27036 Onboarding and Offboarding Workflow into practice

Capture owners, evidence, decisions, and review dates in one workflow record so supplier security controls and escalation points stay auditable over time.

Primary sources

References and citations

iso.org
Referenced sections
  • Clauses 7.3 and 7.5 require an agreed termination plan and specify termination decisions, communications, ownership, asset disposition, access removal, completion agreement, and output records.
iso.org
Referenced sections
  • Part 3 supplies additional life-cycle guidance for transition, maintenance, and disposal in hardware, software, and services supply chains.
iso.org
Referenced sections
  • Part 4 addresses cloud-service acquisition risks but expressly excludes business continuity management, which must be handled through applicable continuity requirements and other guidance.
Related guides

Explore more topics

ISO/IEC 27036 Assurance Evidence FAQ
Collect evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.
ISO/IEC 27036 Cloud Suppliers FAQ
Treat cloud as a supplier relationship with cloud service customer and provider perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.
ISO/IEC 27036 Contract Controls FAQ
Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.
ISO/IEC 27036 Contract Security Clauses Guide
Build ISO/IEC 27036-aligned supplier security clauses from relationship risk, responsibilities, assurance, change, incidents, and exit.
ISO/IEC 27036 Fourth Parties FAQ
Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes multi-layer supply chains; it does not require the same questionnaire or direct audit right for every remote tier.
ISO/IEC 27036 ICT Supply Chain Lifecycle Guide
Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
ISO/IEC 27036 Indirect and Fourth Party Suppliers Guide
Manage indirect supplier dependencies under ISO/IEC 27036 using risk-based visibility, flow-down expectations, monitoring, and contingency planning.
ISO/IEC 27036 Risk Tiers FAQ
No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
ISO/IEC 27036 Supplier Assurance Framework Guide
Design risk-based ISO/IEC 27036 supplier assurance with defined evidence scope, monitoring, findings, and reassessment.
ISO/IEC 27036 Supplier Incidents FAQ
Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.
ISO/IEC 27036 Supplier Monitoring Evidence Workflow
Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.
ISO/IEC 27036 Supplier Monitoring FAQ
ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.
ISO/IEC 27036 Supplier Relationship Types Guide
Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
ISO/IEC 27036 Supplier Security FAQ
Plain-language answers about ISO/IEC 27036 scope, parts, roles, agreements, assurance, monitoring, incidents, indirect suppliers, cloud services, and exit.
ISO/IEC 27036 Termination and Offboarding FAQ
Plan termination before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.
ISO/IEC 27036 Third Party Risk Checklist
Use an ISO/IEC 27036 supplier-risk checklist across scope, assessment, agreement, operation, change, incidents, and termination.
ISO/IEC 27036 vs NIST SP 800-161 Comparison
Compare ISO/IEC 27036 supplier-relationship security with NIST SP 800-161 Rev. 1 cyber supply-chain risk management.
Using the ISO/IEC 27036 Supplier Relationship Series
Understand how to apply the four-part ISO/IEC 27036 series without treating it as a law or standalone certification.