workflow
Vendor Risk Assessment and Disposition
Runs on one existing System with vendor=true. Uses the supplier record, contracts, assurance/CUECs, access and continuity evidence to produce a reviewed vendor risk assessment and authorized disposition for the business/risk owner and readiness evidence consumers. Two checkpoints retain expert challenge and the owner’s choice of conditions, treatment and monitoring; executor work is recorded in step results and documents, with no collection forms or runtime branches.
In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)
Record JSON · Open in map · Data retrieval guide
Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- procurement
- lineOfDefense
- monitor
Details
- teams
- procurement
- risk-management
- it
- domains
- grc
- standards
- iso-27001
- nist-800-53
- soc1
- soc2
- sourceTemplateId
- workflow-library:grc-vendor-risk-assessment-disposition
- releaseId
- sha256:b8c3c926ec5f356c7ccdebf02d8090a1ddbc3f65d98281ffc93ae30e1cfd788c
- canonicalUrl
- https://evidenceflows.com/workflows/all/?w=grc-vendor-risk-assessment-disposition
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-TPRM-02
- UC-TPRM-03
- UC-TPRM-04
- UC-ACCESS-21
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:b8c3c926ec5f356c7ccdebf02d8090a1ddbc3f65d98281ffc93ae30e1cfd788c
Connections
- Vendor Risk Assessment and Disposition oversees UC-TPRM-04 — Monitor vendor performance, services, and risk
- Vendor Risk Assessment and Disposition oversees UC-TPRM-03 — Bind vendors to security and privacy terms by contract
- Vendor Risk Assessment and Disposition oversees UC-ACCESS-21 — Manage subservice organizations supporting the system
- Vendor Risk Assessment and Disposition oversees UC-TPRM-02 — Perform risk-based due diligence before engaging vendors