workflow

Vendor Offboarding & Secure Termination

Vendor Offboarding & Secure Termination as a decision-aware workflow triggered on a relationship termination. It runs on the vendor's existing Vendor register item - the offboarding enriches that record, it never creates a duplicate: the run marks the Vendor `monitoring_status: exited` and stamps `contract_end_date`, and where the vendor's risk is registered it links to the existing third-party Risk item (`category: third_party`). In scope: executing one vendor's contractual exit end to end - inventorying the vendor's access, data, and dedicated components; containing access immediately on for-cause exits; transitioning each service to its successor; revoking every credential; verifying data return or destruction; disposing of internal-side components using defined techniques; and retaining the post-relationship evidence. Out of scope: the underlying contract-termination or renewal business decision and any separately-governed affiliate contracts. Initial inputs are the termination trigger and effective date, the vendor's contractual exit provisions (master agreement, data processing addendum, exit plan) - which also carry the data-disposition and evidence-retention clauses consumed downstream - and the existing Vendor register item with its risk tier; there is no upstream workflow. The named deliverable is the retained, audit-standing termination evidence package assembled at compile-termination-evidence-and-retain; the workflow is terminal - close-and-archive exports the run and hands off nothing downstream.

In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)

Record JSON · Open in map · Data retrieval guide

Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.

Attributes

domain
grc
department
procurement
lineOfDefense
operate

Details

teams
  • procurement
  • it
domains
  • grc
standards
  • nist-800-53
  • nist-csf-2
sourceTemplateId
workflow-library:grc-vendor-offboarding-secure-termination
releaseId
sha256:0e0021998364a42f1cde3c12c246bee5c4f006e4c9c3f7215c619cbb4cba2e6b
canonicalUrl
https://evidenceflows.com/workflows/all/?w=grc-vendor-offboarding-secure-termination
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-TPRM-06
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:0e0021998364a42f1cde3c12c246bee5c4f006e4c9c3f7215c619cbb4cba2e6b

            Connections