workflow

Third-Party Vendor Risk Lifecycle

Operate the third-party vendor risk lifecycle end to end: scope and tier the vendor population, gather and analyze assurance evidence (SOC reports and CUECs, plus C-SCRM controls), embed contractual protections, enroll ongoing monitoring, and reach a governed disposition and approval. The vendor register IS the set of Vendor items — tiered by criticality (tier) and data exposure (data_classification), owned (business_owner, risk_owner), and driven by reassessment_cadence with last/next assessment dates and monitoring_status; each assessment cycle runs as one workflow instance over that register. In scope: vendor and supplier third-party risk assessment, onboarding controls, and periodic reassessment. Out of scope: procurement sourcing and commercial negotiation, and the deeper fieldwork of a Third-Party Vendor Assurance Engagement, to which the approved package is handed off. This workflow is self-initiating and consumes no upstream workflow package.

In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)

Record JSON · Open in map · Data retrieval guide

Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.

Attributes

domain
grc
department
procurement
lineOfDefense
monitor

Details

teams
  • procurement
domains
  • grc
standards
  • nist-800-53
  • soc2
sourceTemplateId
workflow-library:grc-third-party-vendor-risk-lifecycle
releaseId
sha256:3afe56b3a8220cf85dcb2688f278c355e9d925466db9eaf1dfff6d4847ce45c3
canonicalUrl
https://evidenceflows.com/workflows/all/?w=grc-third-party-vendor-risk-lifecycle
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-TPRM-01
    • UC-TPRM-02
    • UC-TPRM-03
    • UC-TPRM-04
    • UC-ASSET-05
    • UC-ACCESS-21
    • UC-DATA-16
    • UC-HR-05
    • UC-LOG-09
    • UC-SDLC-10
    • UC-TPRM-05
    • UC-TPRM-06
    • UC-TPRM-07
    • UC-TPRM-09
    • UC-TPRM-08
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:3afe56b3a8220cf85dcb2688f278c355e9d925466db9eaf1dfff6d4847ce45c3

            Connections