workflow
Third-Party Vendor Risk Lifecycle
Operate the third-party vendor risk lifecycle end to end: scope and tier the vendor population, gather and analyze assurance evidence (SOC reports and CUECs, plus C-SCRM controls), embed contractual protections, enroll ongoing monitoring, and reach a governed disposition and approval. The vendor register IS the set of Vendor items — tiered by criticality (tier) and data exposure (data_classification), owned (business_owner, risk_owner), and driven by reassessment_cadence with last/next assessment dates and monitoring_status; each assessment cycle runs as one workflow instance over that register. In scope: vendor and supplier third-party risk assessment, onboarding controls, and periodic reassessment. Out of scope: procurement sourcing and commercial negotiation, and the deeper fieldwork of a Third-Party Vendor Assurance Engagement, to which the approved package is handed off. This workflow is self-initiating and consumes no upstream workflow package.
Record JSON · Open in map · Data retrieval guide
Catalog revision: f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- procurement
- lineOfDefense
- monitor
Details
- teams
- procurement
- domains
- grc
- standards
- nist-800-53
- soc2
- sourceTemplateId
- workflow-library:grc-third-party-vendor-risk-lifecycle
- releaseId
- sha256:5457eacda138711f0ab9d59a3651b95f34dcbcbe4146459fcd44beb83164716a
- canonicalUrl
- https://assureswarm.com/workflows/all/?w=grc-third-party-vendor-risk-lifecycle
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-TPRM-01
- UC-TPRM-02
- UC-TPRM-03
- UC-TPRM-04
- UC-ASSET-05
- UC-ACCESS-21
- UC-DATA-16
- UC-HR-05
- UC-LOG-09
- UC-SDLC-10
- UC-TPRM-05
- UC-TPRM-06
- UC-TPRM-07
- UC-TPRM-09
- UC-TPRM-08
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:5457eacda138711f0ab9d59a3651b95f34dcbcbe4146459fcd44beb83164716a
Connections
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-04 — Monitor vendor performance, services, and risk
- Third-Party Vendor Risk Lifecycle oversees UC-SDLC-10 — Oversee outsourced development and vet developers
- Third-Party Vendor Risk Lifecycle oversees UC-ASSET-05 — Inventory supplier services and assess critical suppliers
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-09 — Protect supply chain information through OPSEC
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-07 — Verify component authenticity, provenance, and integrity
- Third-Party Vendor Risk Lifecycle oversees UC-LOG-09 — Monitor providers and exchange audit data across organizations
- Third-Party Vendor Risk Lifecycle oversees UC-HR-05 — Hold third-party personnel to equivalent security terms
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-01 — Operate a third-party security risk management program
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-05 — Include suppliers in incident notification and response
- Third-Party Vendor Risk Lifecycle oversees UC-DATA-16 — Bind third parties handling personal data to privacy commitments
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-08 — Govern security of external and cloud service use
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-02 — Perform risk-based due diligence before engaging vendors
- Third-Party Vendor Risk Lifecycle oversees UC-ACCESS-21 — Manage subservice organizations supporting the system
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-06 — Manage secure termination and disposal at relationship end
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-03 — Bind vendors to security and privacy terms by contract