workflow
Third-Party Vendor Assurance Engagement
Runs on the existing Audit item for this engagement (audit_type=vendor_review) — the workflow enriches that already-planned engagement record, it never creates a duplicate — consuming the confirmed scope, criteria, and calendar handed off from Audit Engagement Planning. An IA-led third-party vendor assurance engagement that concludes on the design and operating effectiveness of the organization’s TPRM program — governance, risk tiering, vendor control-environment reliance, monitoring, exclusions, and reporting. Vendors under test are the existing Vendor items, each finding is an Issue item, and the named deliverable is a reperformable engagement workpaper package. In scope: assuring the program (IA evaluates management’s third-party risk management; it does not operate it). Out of scope: operating the vendor lifecycle (onboarding, tier refresh, remediation), which belongs to the second-line Third-Party Vendor Risk Lifecycle workflow; deep single-report SOC work, which can be delegated to the reusable Vendor SOC 1/SOC 2 Report Review & CUEC Mapping workflow; and ICT arrangements caught by regulatory regimes, which route to Third-Party ICT Vendor Regulatory Assurance. Findings and the engagement conclusion exit through Audit Report Drafting, and action plans route to Finding Remediation & Action-Plan Monitoring.
In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)
Record JSON · Open in map · Data retrieval guide
Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.
Attributes
- domain
- audit
- department
- internal-audit
- lineOfDefense
- assure
Details
- teams
- internal-audit
- procurement
- domains
- audit
- standards
- iia-2024
- sourceTemplateId
- workflow-library:audit-third-party-assurance-engagement
- releaseId
- sha256:9c834df785ff76b25f1b84fe61e00d2d5017799e5fdf363171e41eee945a7100
- canonicalUrl
- https://evidenceflows.com/workflows/all/?w=audit-third-party-assurance-engagement
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- assure
- controls
- UC-AUDIT-12
- UC-AUDIT-13
- UC-AUDIT-16
- UC-TPRM-01
- UC-TPRM-02
- UC-TPRM-04
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:9c834df785ff76b25f1b84fe61e00d2d5017799e5fdf363171e41eee945a7100
Connections
- Third-Party Vendor Assurance Engagement tests UC-AUDIT-13 — Gather and analyze evidence to develop engagement findings
- Third-Party Vendor Assurance Engagement tests UC-AUDIT-16 — Communicate final engagement results to stakeholders
- Third-Party Vendor Assurance Engagement tests UC-TPRM-01 — Operate a third-party security risk management program
- Third-Party Vendor Assurance Engagement tests UC-AUDIT-12 — Plan engagements with risk-based objectives, scope, and criteria
- Third-Party Vendor Assurance Engagement tests UC-TPRM-04 — Monitor vendor performance, services, and risk
- Third-Party Vendor Assurance Engagement tests UC-TPRM-02 — Perform risk-based due diligence before engaging vendors