Why it matters
Supplier risk isn't a one-time check at signup — vendors change their own security posture over time.
How a self-led small team implements it
An annual check-in with critical vendors (status page history, any breach notices) is proportionate for a small business.
What auditors expect to see
Supplier review log.
Track A.5.22 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS