// COMPLIANCE FRAMEWORK

ISO 27001 VENDOR RISK

International Standard for Information Security Management Systems

ISO 27001 requires managing information security risks from suppliers. Annex A.15 mandates structured vendor risk assessment and monitoring.

See Plans → Explore QFX →
// REQUIREMENTS

WHAT ISO 27001 REQUIRES FOR THIRD-PARTY RISK

01

A.15.1.1: Information security policy for supplier relationships

02

A.15.1.2: Security requirements agreed with each supplier

03

A.15.1.3: ICT supply chain risks addressed specifically

04

A.15.2.1: Supplier service delivery monitored and audited

// VERISQ SOLUTION

HOW VERISQ AI SATISFIES ISO 27001

🛡️

Supplier Monitoring

Continuous scoring satisfies A.15.2.1 monitoring requirements.

📋

Supplier Assessments

QFX questionnaires aligned to Annex A controls.

📊

Evidence Generation

Certificates of Diligence for A.15.1 compliance.

🔔

Incident Awareness

Breach monitoring supports A.16 Incident Management.

// INDUSTRIES

ISO 27001 COMPLIANCE BY INDUSTRY

ISO 27001 compliance is critical for organizations in these sectors.

Technology Financial Services Healthcare

DON'T BE A LARRY. TRY LIVETHREAT FREE.

Assess your first vendors free — no credit card, no contract, no gym membership required.

Try 5 Vendors for Free →