workflow

New Vendor Onboarding

Runs automatically on a new System item marked as a vendor (System.vendor is true). Collect the requester's business facts and the vendor's security questionnaire, assess system and third-party risk, and approve the onboarding decision. Deliver the approved system risk review record, set the System item's tier, data classification, monitoring status and last and next assessment dates, and hand open actions to the responsible register owner; the yearly System & Third-Party Risk Review takes over from there.

In catalog since 2026-10-09T17:15:44Z · Last changed 2026-10-09T17:15:44Z (e3174baba434)

Record JSON · Open in map · Data retrieval guide

Catalog revision: e3174baba4349814a5b925938b4124ba43ccab6702e45e83d6cdef7c8898f67b. A connection does not establish full coverage.

Attributes

domain
grc
department
risk-management
lineOfDefense
operate

Details

teams
  • risk-management
  • procurement
  • it
domains
  • grc
standards
  • iso-27001
  • nist-800-53
  • soc2
sourceTemplateId
workflow-library:grc-new-vendor-onboarding
releaseId
sha256:30ac179fd116d09282f0116498473c3c250a9a7c00dc76f5e09b77649ef50b92
canonicalUrl
https://evidenceflows.com/workflows/all/?w=grc-new-vendor-onboarding
capabilities
  • new-vendor-onboarding
mappingStatus
mapped
lineOfDefense
operate
controls
  • UC-RISK-18
  • UC-TPRM-02
  • UC-CONFIG-10
  • UC-TPRM-08
  • UC-TPRM-04
roleIntegrity
activityCount
0
ermPhases
    lineRoles
      serviceModes
        warnings

          Source

          No record-specific source URL is provided.

          Download workflow template · Release: sha256:30ac179fd116d09282f0116498473c3c250a9a7c00dc76f5e09b77649ef50b92

          Connections