workflow

Third-Party ICT Vendor Regulatory Assurance

Third-Party ICT Vendor Regulatory Assurance as a decision-aware workflow. Each cycle runs on its own Audit engagement item (audit_type = vendor_review) created at kickoff, with Audit.scope set to the in-scope legal entities, regimes, and vendor population; every workpaper, decision form, and gap attaches to that instance. In scope: ICT third-party service providers — including intra-group ICT providers — assessed against DORA, NIS2, and US interagency/FFIEC third-party expectations; out of scope: non-ICT vendors, which stay with the general vendor lifecycle. It consumes the arrangement-level inventory, tiering, and due-diligence handoff package from Third-Party Vendor Risk Lifecycle (whose provider records are the Vendor items); refers vendor SOC 1/SOC 2 reports carrying real reliance to the Vendor SOC 1/SOC 2 Report Review & CUEC Mapping workflow and folds back its reliance conclusions; and produces a provision-cited, severity-rated gap register (Issue items linked to the anchor Audit and the affected Control/Vendor records) plus a qualified final assurance package. It hands the validated obligation statuses to the Regulatory Compliance Attestation Cycle, exchanging handoff packages with related workflows instead of duplicating repeated work.

In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)

Record JSON · Open in map · Data retrieval guide

Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.

Attributes

domain
reg
department
procurement
lineOfDefense
monitor

Details

teams
  • procurement
  • compliance-legal
domains
  • reg
standards
  • dora
  • nis2
sourceTemplateId
workflow-library:reg-third-party-ict-vendor-assurance
releaseId
sha256:7ebf5a00d8246ecbb3e4bba98349c0ae72060aa93fea86ba99f58f605046a527
canonicalUrl
https://evidenceflows.com/workflows/all/?w=reg-third-party-ict-vendor-assurance
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-TPRM-01
    • UC-TPRM-04
    • UC-ASSET-05
    • UC-LOG-09
    • UC-TPRM-05
    • UC-TPRM-06
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:7ebf5a00d8246ecbb3e4bba98349c0ae72060aa93fea86ba99f58f605046a527

            Connections