Practical toolGlobalISO/IEC 27036

ISO/IEC 27036 Third Party Risk Checklist

Decide whether a supplier relationship is understood, treated, agreed, monitored, and closed with current evidence.

Use Part 2 for supplier and acquirer relationship requirements and Parts 1, 3, and 4 for concepts or guidance. The series is voluntary; assess contracts, law, customer commitments, and certification scopes separately.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this checklist before approval, during operation, after material change, and at exit. A completed questionnaire is not the decision: the and supplier must identify their risks, agree responsibilities and evidence, treat unacceptable exposure, and record who approved any residual risk. Scale the work to the product or service, access, dependence, supply-chain depth, and applicable obligations.

Section 1

What should the initial supplier-risk assessment establish?

ISO/IEC 27036-2:2022 applies to organizations of any type or size and to procurement and supply of products and services, including manufacturing, business-process procurement, software and hardware components, build-operate-transfer arrangements, and cloud services. It is a voluntary international standard unless law, regulation, policy, customer terms, or a contract makes selected requirements binding. The checklist does not replace those separate duties.

The assessment must describe the actual relationship before it scores risk. Identify the legal entities and accountable owners, the product or service, intended use, information and systems involved, access method and privilege, processing and support locations, business criticality, recovery need, planned term, and feasible alternatives.

Assess risks to both parties. ISO/IEC 27036-2 specifically includes business dependence, underlying technology, subcontractors, past performance, contractual arrangements, and the supplier's ability to demonstrate information-security capability. Add product provenance, component and update dependencies, and end-of-support exposure for an ICT supply chain.

  • Relationship owner: verify the scope, purpose, parties, locations, term, business dependence, substitutability, and direct and indirect dependencies; evidence is an approved inventory record.
  • Security and privacy owners: classify the information and access, identify threat and control dependencies, assess inherent and residual risk, and document treatment; evidence is the assessment and treatment plan.
  • Risk owner: approve the remaining risk only after gaps, assumptions, compensating controls, expiry, and reassessment triggers are recorded; evidence is the dated decision.
Section 2

How should due diligence and treatment follow risk and bargaining position?

Choose due-diligence depth from risk, not supplier size or a single tier label. Review the exact entity, service, location, and period covered by certificates, attestations, tests, continuity evidence, and audit reports. Record exclusions, reliance on management statements, stale evidence, and findings that remain open.

If the supplier will not accept a requested control or audit right, do not mark the item complete. Decide whether alternative evidence, a technical restriction, reduced scope, additional monitoring, a different supplier, or explicit residual-risk acceptance makes the relationship acceptable. ISO/IEC 27036-2 recommends that procurement not proceed when identified risk cannot be reduced to the acceptable level; the authorized risk owner must apply the organization's approval rules.

  • Procurement: test supplier acceptance of security requirements, assurance terms, transition duties, termination duties, capacity, location, and subcontractor transparency before selection.
  • Security: verify control design and scope for identity and access, information protection, vulnerability and change management, incident coordination, logging, resilience, and secure disposal as applicable.
  • Legal and contract owners: set the actual notice periods, audit or assurance route, sub-supplier conditions, remediation process, and exit duties in the agreement; ISO/IEC 27036 does not supply statutory deadlines.
Section 3

Which evidence supports approval and ongoing oversight?

Approval evidence should let a later reviewer reconstruct the decision: scoped inventory record, assessment criteria and results, treatment plan, due-diligence evidence, exceptions, legal and regulatory review where applicable, selected supplier rationale, agreement, named approver, and next review trigger.

Operational evidence should show that the agreed controls work for the covered service and period. Use access reviews, service and security measures, vulnerability and patch records, incident records, assurance reports, continuity tests, sub-supplier changes, corrective actions, and risk reassessments as applicable.

Do not accept a document by title alone. Record the provider, covered entity and service, period, locations, method, qualifications, findings, reviewer conclusion, follow-up owner, and due date.

  • Version the assessment, agreement, and assurance record instead of overwriting the basis for an earlier approval.
  • Link each open finding to remediation, a compensating control, risk avoidance or transfer, or a dated residual-risk acceptance.
  • Limit access to supplier-confidential and security-sensitive evidence and apply the handling rules agreed by the parties.
Recommended next step

Put ISO/IEC 27036 Third Party Risk Checklist into practice

Capture owners, evidence, decisions, and review dates in one workflow record so supplier security controls and escalation points stay auditable over time.

Section 4

When should the checklist be rerun or the relationship closed?

Rerun affected checklist items at the planned interval and when a significant business, legal, regulatory, architectural, policy, or contractual change occurs. Also reopen the decision after a serious incident, material control failure, new privileged access, new processing location, ownership change, critical sub-supplier change, major release, missed recovery objective, or change in business dependence.

At renewal, confirm that the scope, risk, evidence, pricing assumptions, control responsibilities, and exit plan still match the service. At termination, execute the transition plan, remove access, recover assets, return or dispose of information subject to retention duties, preserve required records, and document any obligation that survives.

  • Assign each periodic and event-driven trigger to a named relationship or risk owner.
  • Test high-impact continuity, replacement, data export, and access-removal assumptions before an incident or exit.
  • Close the relationship record only after exit evidence and remaining legal, retention, remediation, or confidentiality obligations are documented.
Primary sources

References and citations

Related guides

Explore more topics

ISO/IEC 27036 Assurance Evidence FAQ
Collect evidence that answers a defined relationship-risk or agreement question and matches the product or service, period, location, controls, and dependencies in scope. A certificate, audit report, questionnaire, or attestation is an input, not automatic proof.
ISO/IEC 27036 Cloud Suppliers FAQ
Treat cloud as a supplier relationship with cloud service customer and provider perspectives. Apply Part 2 relationship requirements and Part 4 cloud guidance, then document how responsibility changes with the service and deployment model, configuration, data, interfaces, and nested cloud services.
ISO/IEC 27036 Contract Controls FAQ
Include controls selected from the relationship risk treatment and responsibilities, not a generic clause library. The agreement should make scope, performance, evidence, communication, exceptions, change, incident coordination, continuity, and exit reviewable by both parties.
ISO/IEC 27036 Contract Security Clauses Guide
Build ISO/IEC 27036-aligned supplier security clauses from relationship risk, responsibilities, assurance, change, incidents, and exit.
ISO/IEC 27036 Fourth Parties FAQ
Use the direct supplier relationship to obtain proportionate visibility and assurance over upstream dependencies that can materially affect security or delivery. ISO/IEC 27036 describes multi-layer supply chains; it does not require the same questionnaire or direct audit right for every remote tier.
ISO/IEC 27036 ICT Supply Chain Lifecycle Guide
Apply ISO/IEC 27036 across ICT supply-chain planning, acquisition, delivery, operation, change, and disposal.
ISO/IEC 27036 Indirect and Fourth Party Suppliers Guide
Manage indirect supplier dependencies under ISO/IEC 27036 using risk-based visibility, flow-down expectations, monitoring, and contingency planning.
ISO/IEC 27036 Onboarding and Offboarding Workflow
Run ISO/IEC 27036 supplier onboarding and offboarding with approval gates, evidence, access control, continuity, and verified closure.
ISO/IEC 27036 Risk Tiers FAQ
No fixed low, medium, or high tier model is prescribed by ISO/IEC 27036. Organizations can use tiers to scale due diligence, agreement terms, assurance, monitoring, approvals, and exit planning, but the criteria and decisions must reflect their own context and risk appetite.
ISO/IEC 27036 Supplier Assurance Framework Guide
Design risk-based ISO/IEC 27036 supplier assurance with defined evidence scope, monitoring, findings, and reassessment.
ISO/IEC 27036 Supplier Incidents FAQ
Agree incident contacts, triggers, information sharing, investigation support, evidence preservation, containment and recovery coordination, corrective action, and review before an incident occurs. ISO/IEC 27036 does not set one universal notification deadline; applicable law, regulation, policy, or contract supplies mandatory timing.
ISO/IEC 27036 Supplier Monitoring Evidence Workflow
Build ISO/IEC 27036 supplier monitoring that turns agreed measures, assurance, incidents, changes, and findings into decisions.
ISO/IEC 27036 Supplier Monitoring FAQ
ISO/IEC 27036 does not prescribe one universal monitoring interval. Set scheduled and event-driven reviews according to risk, agreement terms, service criticality, evidence availability, and the speed at which the relationship can change.
ISO/IEC 27036 Supplier Relationship Types Guide
Classify ISO/IEC 27036 relationships by product, service, ICT supply chain, and cloud context to select proportionate controls.
ISO/IEC 27036 Supplier Security FAQ
Plain-language answers about ISO/IEC 27036 scope, parts, roles, agreements, assurance, monitoring, incidents, indirect suppliers, cloud services, and exit.
ISO/IEC 27036 Termination and Offboarding FAQ
Plan termination before the relationship starts. Coordinate continuity and transition, revoke physical and logical access, rotate shared secrets, disable integrations, recover assets, return or delete information subject to retention duties, preserve required records, and verify surviving obligations.
ISO/IEC 27036 vs NIST SP 800-161 Comparison
Compare ISO/IEC 27036 supplier-relationship security with NIST SP 800-161 Rev. 1 cyber supply-chain risk management.
Using the ISO/IEC 27036 Supplier Relationship Series
Understand how to apply the four-part ISO/IEC 27036 series without treating it as a law or standalone certification.