workflow
Third-Party ICT Vendor Regulatory Assurance
Third-Party ICT Vendor Regulatory Assurance as a decision-aware workflow. Each cycle runs on its own Audit engagement item (audit_type = vendor_review) created at kickoff, with Audit.scope set to the in-scope legal entities, regimes, and vendor population; every workpaper, decision form, and gap attaches to that instance. In scope: ICT third-party service providers — including intra-group ICT providers — assessed against DORA, NIS2, and US interagency/FFIEC third-party expectations; out of scope: non-ICT vendors, which stay with the general vendor lifecycle. It consumes the arrangement-level inventory, tiering, and due-diligence handoff package from Third-Party Vendor Risk Lifecycle (whose provider records are the Vendor items); refers vendor SOC 1/SOC 2 reports carrying real reliance to the Vendor SOC 1/SOC 2 Report Review & CUEC Mapping workflow and folds back its reliance conclusions; and produces a provision-cited, severity-rated gap register (Issue items linked to the anchor Audit and the affected Control/Vendor records) plus a qualified final assurance package. It hands the validated obligation statuses to the Regulatory Compliance Attestation Cycle, exchanging handoff packages with related workflows instead of duplicating repeated work.
In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)
Record JSON · Open in map · Data retrieval guide
Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.
Attributes
- domain
- reg
- department
- procurement
- lineOfDefense
- monitor
Details
- teams
- procurement
- compliance-legal
- domains
- reg
- standards
- dora
- nis2
- sourceTemplateId
- workflow-library:reg-third-party-ict-vendor-assurance
- releaseId
- sha256:7ebf5a00d8246ecbb3e4bba98349c0ae72060aa93fea86ba99f58f605046a527
- canonicalUrl
- https://evidenceflows.com/workflows/all/?w=reg-third-party-ict-vendor-assurance
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-TPRM-01
- UC-TPRM-04
- UC-ASSET-05
- UC-LOG-09
- UC-TPRM-05
- UC-TPRM-06
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:7ebf5a00d8246ecbb3e4bba98349c0ae72060aa93fea86ba99f58f605046a527
Connections
- Third-Party ICT Vendor Regulatory Assurance oversees UC-TPRM-01 — Operate a third-party security risk management program
- Third-Party ICT Vendor Regulatory Assurance oversees UC-ASSET-05 — Inventory supplier services and assess critical suppliers
- Third-Party ICT Vendor Regulatory Assurance oversees UC-LOG-09 — Monitor providers and exchange audit data across organizations
- Third-Party ICT Vendor Regulatory Assurance oversees UC-TPRM-06 — Manage secure termination and disposal at relationship end
- Third-Party ICT Vendor Regulatory Assurance oversees UC-TPRM-05 — Include suppliers in incident notification and response
- Third-Party ICT Vendor Regulatory Assurance oversees UC-TPRM-04 — Monitor vendor performance, services, and risk