workflow

Vendor Risk Assessment and Disposition

Runs on one existing System with vendor=true. Uses the supplier record, contracts, assurance/CUECs, access and continuity evidence to produce a reviewed vendor risk assessment and authorized disposition for the business/risk owner and readiness evidence consumers. Two checkpoints retain expert challenge and the owner’s choice of conditions, treatment and monitoring; executor work is recorded in step results and documents, with no collection forms or runtime branches.

In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)

Record JSON · Open in map · Data retrieval guide

Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.

Attributes

domain
grc
department
procurement
lineOfDefense
monitor

Details

teams
  • procurement
  • risk-management
  • it
domains
  • grc
standards
  • iso-27001
  • nist-800-53
  • soc1
  • soc2
sourceTemplateId
workflow-library:grc-vendor-risk-assessment-disposition
releaseId
sha256:b8c3c926ec5f356c7ccdebf02d8090a1ddbc3f65d98281ffc93ae30e1cfd788c
canonicalUrl
https://evidenceflows.com/workflows/all/?w=grc-vendor-risk-assessment-disposition
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-TPRM-02
    • UC-TPRM-03
    • UC-TPRM-04
    • UC-ACCESS-21
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:b8c3c926ec5f356c7ccdebf02d8090a1ddbc3f65d98281ffc93ae30e1cfd788c

            Connections