Skip to content

Supply-chain vendor due diligence

Practical guidance for ISO 27001: scope, risk, controls, and evidence that matches how your organisation really works. Use the takeaways and FAQ below as a checklist; then deep-link into your registers and change records.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence, without endless document churn.

Run the ISO 27001 readiness scan

What this page covers

Practical guidance for ISO 27001: scope, risk, controls, and evidence that matches how your organisation really works. Use the takeaways and FAQ below as a checklist; then deep-link into your registers and change records.

Practical next steps

Assign owners, set review dates, and collect artefacts that match production reality. Use internal audits to rehearse the story before the external certification audit.

Common pitfalls

Avoid scope drift, ownerless actions, and documentation that does not match live configuration. Prefer short maintained records over one-off project dumps.

Dutch version: read the Dutch page (same topic, different URL).

Key takeaways

  • Link controls to risk treatment and your Statement of Applicability, avoid policy-only boxes.
  • Assign owners, review cadence, and measurable acceptance criteria for every material action.
  • Use sampling and KPIs to show controls work in operations, not only that they were planned.
  • Align incidents and vendor changes with privacy/legal where personal data or chain risk is involved.

Frequently asked questions

What distinguishes due diligence from collecting certificates?
Due diligence uses supplier information to make a reasoned decision about a specific dependency. Check the scope and relevance of assurance documents, then consider unresolved risks, contract terms and operational interfaces. Record the decision and required follow-up. Collecting certificates without checking what they cover can leave critical questions unanswered, especially when the service or its subcontractors change.

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)