Security Questionnaire Mapper

Subcontractors and subprocessors: the clause the question tests

Who else touches the customer's data on the supplier's behalf, including the providers that host it, and whether the customer is told before that changes.

How the customer usually asks it

example

"Do you use subcontractors to process our data? List them."

Read this question

Anchor clauses

6 frameworks
FrameworkAnchor clause
ISO/IEC 27001:20225.19 Information security in supplier relationships · 5.20 Addressing information security within supplier agreements · 5.21 Managing information security in the ICT supply chain
SOC 2 (Trust Services Criteria)CC9.2 Risk mitigation activities include assessment of vendor and business partner controls
SIG (Shared Assessments)domain T Supply Chain Risk Management
CSA Cloud Controls Matrix v4.0.1DSP-13 Personal Data Sub-processing
PCI DSS v4.0.112.8.1 Third-party service provider inventory
GDPR, Regulation (EU) 2016/679Art. 28 Processor

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The list of subprocessors with what each does, where it processes and what data it reaches, the contract terms that flow down, and the notice route for changes.

The clauses, with what an assessor asks for

ISO 27001 5.19 Information security in supplier relationships

Define and apply processes to manage the security risk suppliers introduce.

Evidence an assessor expects: Supplier risk assessment; Contractual security requirements; Supplier security monitoring; Supplier incident management
Where answers usually fall short: Treating all suppliers as low risk; Missing security clauses in contracts
Source: ISO/IEC 27001:2022
ISO 27001 5.20 Addressing information security within supplier agreements

Establish and agree the relevant security requirements in each supplier contract.

Evidence an assessor expects: Contract security clauses; Supplier risk assessment; Security incident reporting; Performance monitoring reports; Contract termination provisions
Where answers usually fall short: Missing explicit security clauses; No documented risk assessment before onboarding
Source: ISO/IEC 27001:2022
ISO 27001 5.21 Managing information security in the ICT supply chain

Extend security requirements down the ICT products and services supply chain.

Evidence an assessor expects: Supplier security requirements; Contractual security clauses; Supply chain risk assessments; Supplier audit reports; Incident response collaboration
Where answers usually fall short: Treating supplier security as one-off check; Missing contractual security clauses
Source: ISO/IEC 27001:2022
SOC 2 CC9.2 Risk mitigation activities include assessment of vendor and business partner controls

Named, not quoted: the criteria text is not held in full here.

Evidence an assessor expects: The vendor and business partner inventory, with risk tiering based on data access and criticality; Due diligence records performed before engagement, at the depth the tier requires; Contractual commitments covering confidentiality, security requirements, incident notification and the right to assess; Evidence of ongoing monitoring, such as review of assurance reports with complementary user entity control consideration, and follow up on exceptions noted in them; Evidence of termination handling, including return or deletion of data and revocation of access
Where answers usually fall short: Assurance reports collected and filed with no review of the exceptions or of the complementary user entity controls they assume the entity performs; Inventory covering vendors known to procurement, missing services engaged directly by teams
Source: SOC 2 (Trust Services Criteria)
SIG domain T Supply Chain Risk Management

What it asks for, in one line (the standard's own text is not quoted here):

Manage risk across the supply chain including subservice organizations, fourth parties, hardware and software providers, and concentration risk, with appropriate due diligence and continuous monitoring.

Evidence an assessor expects: Supplier inventory with risk tiering; Due diligence questionnaires and reports; Continuous monitoring tool outputs; Concentration risk analysis
Where answers usually fall short: No fourth party visibility; Continuous monitoring not actioned
Source: SIG (Shared Assessments)
CSA CCM DSP-13 Personal Data Sub-processing

What it asks for, in one line (the standard's own text is not quoted here):

Control how personal data is passed to and processed by sub-processors in the service supply chain, in line with applicable law.

Evidence an assessor expects: The sub-processor register with the data each one handles; Contractual terms binding sub-processors to the required protections; Due diligence records before engagement; Evaluation or audit of sub-processor practice
Where answers usually fall short: Sub-processors engaged by delivery teams without the register being updated; Contracts silent on data protection obligations
Source: CSA Cloud Controls Matrix v4.0.1
PCI DSS 12.8.1 Third-party service provider inventory

What it asks for, in one line (the standard's own text is not quoted here):

A list of all third-party service providers (TPSPs) with which account data is shared, or that could affect the security of account data, is maintained, including a description of services provided.

Evidence an assessor expects: TPSP register with contact info and services; Description of data shared or processed per vendor; Internal owner assignment; Annual inventory review records; Onboarding and offboarding workflows
Where answers usually fall short: TPSP register incomplete; No internal owner
Source: PCI DSS v4.0.1
GDPR Art. 28 Processor

Use only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.

Evidence an assessor expects: A processor inventory reconciled against the vendor register or accounts payable, so no processor is missing from it; The Article 28(3) contract for each processor, checked clause by clause against the eight stipulations the Article names; Due diligence evidence gathered before appointment showing sufficient guarantees, distinct from the signed contract; The sub-processor authorisation position for each processor, the current sub-processor list, and evidence changes were notified; Audit or assurance rights exercised in practice, such as a report reviewed with findings tracked, and end of service deletion certificates
Where answers usually fall short: The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice; A processor inventory that misses tools adopted directly by individual teams, which is where undocumented processing usually sits
Source: GDPR, Regulation (EU) 2016/679

Other families in third parties and subprocessors