Sentrix

ISO 27001 guide · Clause 4

4.2 — Needs and expectations of interested parties

ISO 27001:2022 sub-clause 4.2 requires identifying interested parties and their requirements, and, new in 2022, deciding which ones the ISMS will address.

By Sentrix · Published 2026-07-16

Not every stakeholder demand belongs in your ISMS. This requirement is as much about deciding what to leave out as what to include.

In plain language

4.2 requires you to identify who has a stake in your information security — customers, regulators, employees, shareholders, partners — figure out what each of them actually requires of you, and then decide which of those requirements your ISMS will formally take on.

Why this requirement exists

Interested parties rarely agree on priorities. A regulator wants specific controls documented a certain way; a major customer wants a security questionnaire answered on their own terms; investors want risk framed in business language. Without a deliberate process to reconcile these, the ISMS either tries to please everyone at once — becoming unwieldy — or quietly favours whichever stakeholder shouted loudest.

Scenario: a company’s largest customer insists on a specific encryption standard the organization considers excessive for its actual risk level. Without a documented decision on which interested-party requirements the ISMS formally addresses, the team either quietly ignores the customer’s ask (risking the relationship) or implements it inconsistently across the business (creating uneven, hard-to-audit controls). A deliberate 4.2 decision — addressed as a customer-specific control, scoped explicitly — avoids both outcomes.

What the standard expects

The standard expects the organization to determine the interested parties relevant to the ISMS, and the relevant requirements of those interested parties. The 2022 revision added a third, explicit point: the organization must determine which of these requirements will be addressed through the ISMS. That addition matters — it converts a passive listing exercise into an active scoping decision, and it is the direct bridge into how 4.3 draws the ISMS boundary.

In practice

  • Build a simple interested-party register: who they are, what they require, and whether the ISMS formally addresses that requirement or explicitly does not.
  • Include both formal requirements (laws, regulations, contracts) and informal ones (customer expectations, industry norms) rather than only the legally binding ones.
  • Make the “addressed or not” decision explicit and documented — silence on a requirement reads as an oversight, not a deliberate scoping choice.

Evidence the auditor will ask for

  • An interested-party register with requirements and an explicit in/out-of-scope decision for each.
  • Traceability from a specific interested-party requirement to a control or policy that addresses it.

Common pitfalls

  • A list of interested parties with no analysis of what they actually require.
  • No explicit decision on which requirements the ISMS addresses — the 2022 addition most commonly missed.

Related requirements

2013 → 2022 mapping

2022 version2013 versionNature of change
4.2 Interested parties4.2 Same titleReformulated; added a third point requiring an explicit decision on which requirements the ISMS addresses

Sources

Frequently asked questions

Can we decide not to address a valid interested-party requirement?
Yes, as long as that decision is deliberate and documented — the 2022 addition exists precisely to make that choice visible rather than accidental. The interested-party register should state, for each requirement, whether the ISMS formally addresses it or not: silence on a requirement reads as an oversight, not a deliberate scoping choice.
Do employees count as an interested party?
Yes — internal interested parties (employees, management, unions where relevant) are just as valid as external ones like customers or regulators. The register should include both formal requirements (laws, regulations, contracts) and informal ones (customer expectations, industry norms), rather than only the legally binding ones.
What did the 2022 version change in 4.2?
The 2022 revision added a third, explicit point: the organization must determine which of the interested-party requirements will be addressed through the ISMS. That addition converts a passive listing exercise into an active scoping decision, and it is the direct bridge into how 4.3 draws the ISMS boundary. It is also the 2022 addition most commonly missed.

Let's talk about your compliance program.

Last updated: 2026-09-17