THIRD PARTYCURRENT
International information-security standard

ISO/IEC 27036-1:2021

Part 1 establishes the concepts and framing for information and communication technology supplier relationships, including risks that arise when organizations acquire products and services or participate in supply chains.

What the authority establishes

Part 1 establishes the concepts and framing for information and communication technology supplier relationships, including risks that arise when organizations acquire products and services or participate in supply chains.

The standard provides durable language for separating customer and supplier responsibilities, understanding relationship context, and structuring information-security expectations across the supplier lifecycle. Its 2026 systematic review makes version tracking relevant without implying the current edition has already changed.

The record is written for operational interpretation, not legal advice. Applicability depends on entity type, jurisdiction, relationship, service, data, criticality, contractual commitments, and later authority guidance.

Who should read it

The primary audiences named in this review are information-security and cybersecurity leaders, procurement and supplier-management teams, third-party risk and supply-chain risk leaders, technology suppliers and service providers, assurance and audit teams. Those roles may divide responsibility differently, but the operating record should still show scope, accountable ownership, evidence, review, exceptions, and the final decision.

Third-party lifecycle implications

Governance And Relationship Definition

Teams should determine what this authority expects at the governance and relationship definition stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Risk Assessment

Teams should determine what this authority expects at the risk assessment stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Supplier Selection

Teams should determine what this authority expects at the supplier selection stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Agreements

Teams should determine what this authority expects at the agreements stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Monitoring

Teams should determine what this authority expects at the monitoring stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Change Management

Teams should determine what this authority expects at the change management stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Termination

Teams should determine what this authority expects at the termination stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Capabilities that may support the work

These links identify relevant operating capabilities; they do not state that any product creates compliance.

Intake And Inventory

establishing an accountable record of relationships, products, owners, and critical services. Buyers should test the workflow against their own scope and evidence requirements.

Inherent Risk Tiering

using relationship context to determine proportional diligence and review. Buyers should test the workflow against their own scope and evidence requirements.

Due Diligence And Assessments

collecting and reviewing evidence before and during a relationship. Buyers should test the workflow against their own scope and evidence requirements.

Evidence Collection

preserving source material, responses, and reviewer context. Buyers should test the workflow against their own scope and evidence requirements.

Continuous Monitoring

bringing material external and internal change into an owned response workflow. Buyers should test the workflow against their own scope and evidence requirements.

Issue Remediation

assigning findings, deadlines, exceptions, and closure evidence. Buyers should test the workflow against their own scope and evidence requirements.

Fourth-Party Visibility

identifying and explaining important downstream dependencies. Buyers should test the workflow against their own scope and evidence requirements.

Regulatory Mapping

connecting program records to obligations and examination needs. Buyers should test the workflow against their own scope and evidence requirements.

Reporting

turning program activity into operator, executive, and board-ready information. Buyers should test the workflow against their own scope and evidence requirements.

Offboarding

closing access, data, evidence, and residual obligations when a relationship ends. Buyers should test the workflow against their own scope and evidence requirements.

What software cannot decide

Software can structure records, route work, preserve evidence, surface change, and support reporting. It cannot determine legal applicability, set risk appetite, negotiate accountable contract terms, validate every external claim, accept residual risk, or make management responsible for an outcome. Those remain organizational decisions.

Related market changes

ISO/IEC 27036-1 enters systematic review

Programs and vendors need version-aware standards records that distinguish a review milestone from a changed requirement.