Regulated Customer Contract Checker
Regimes · ISO 27001

ISO/IEC 27001:2022, your own certification

Reaches every recognised agreement when the certification is yours: A.5.31 (hold the legal and contractual requirements as a current register), A.5.19 to A.5.21 read from the customer's side (the security terms a certified customer puts in its supplier contracts), A.5.23 on cloud services, A.5.24 on incident readiness behind a promised clock, A.5.34 where personal data is named, and A.6.6 on confidentiality agreements.

On the register, tick "ISO/IEC 27001:2022 (yours)" (every regime is ticked by default) and these rows attach where the customer's sector and country reach it. Source framework: ISO/IEC 27001:2022.

What it expects, term by term

contract registerA.5.31On every recognised agreement
security scheduleA.5.19 · A.5.20 · A.5.21On an ICT service arrangement
cloud servicesA.5.23On a subscription, licence or SaaS agreement
breach clockA.5.24Where the row names personal data, or on an ICT service arrangement
personal dataA.5.34Where the row names personal data
confidentialityA.6.6On a confidentiality agreement

The clauses, quoted

8

Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.

ISO 27001 A.5.19 Information security in supplier relationships

Define and apply processes to manage the security risk suppliers introduce.

Evidence an auditor accepts: Supplier risk assessment; Contractual security requirements; Supplier security monitoring
Where it usually falls short: Treating all suppliers as low risk
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.20 Addressing information security within supplier agreements

Establish and agree the relevant security requirements in each supplier contract.

Evidence an auditor accepts: Contract security clauses; Supplier risk assessment; Security incident reporting
Where it usually falls short: missing explicit security clauses
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.21 Managing information security in the ICT supply chain

Extend security requirements down the ICT products and services supply chain.

Evidence an auditor accepts: Supplier security requirements; Contractual security clauses; Supply chain risk assessments
Where it usually falls short: Treating supplier security as one-off check
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.23 Information security for use of cloud services

Govern acquisition, use, management and exit of cloud services against your security requirements.

Evidence an auditor accepts: Cloud service selection; Cloud contract management; Cloud security monitoring
Where it usually falls short: Relying solely on provider's security assurances
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.24 Information security incident management planning and preparation

Define incident roles, processes and readiness before an incident happens.

Evidence an auditor accepts: Incident response plan; Role assignment matrix; Training and awareness records
Where it usually falls short: roles are defined but not formally assigned or approved
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.31 Legal, statutory, regulatory and contractual requirements

Identify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.

Evidence an auditor accepts: Legal register; Contractual obligations; Regulatory filing records
Where it usually falls short: outdated legal register
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.34 Privacy and protection of personal identifiable information (PII)

Identify and meet privacy and PII-protection requirements from law, regulation and contract.

Evidence an auditor accepts: Privacy policy; Data inventory; Processing agreements
Where it usually falls short: Missing documented consent for all data subjects
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.6.6 Confidentiality or non-disclosure agreements

Identify, document, review and sign NDAs that reflect the organization's protection needs.

Evidence an auditor accepts: Nda policy; Nda templates; Signed nda registry
Where it usually falls short: NDAs not refreshed when data classification changes
ISO/IEC 27001:2022 in The Art of Service standards library

See what it expects of your list

Paste the list of customer agreements and every row this regime reaches carries these terms, ticked or open. Eight agreements free, no account.

Check my contract list