workflow

Third-Party Risk Program & Vendor Oversight Cycle

A standing quarterly cycle the vendor-management office runs as control owner. The workflow instance is a recurring run attached to the EXISTING Process item "Third-Party / Vendor Risk Management" (process_type: operational, process_owner: Vendor Risk Program Lead, frequency: quarterly), linked to the Control items for the unified controls it operates (UC-TPRM-01/04/05/08) — it enriches that standing program, never recreating it. It consumes no upstream workflow handoff: each run is self-feeding, drawing its criteria and prior state from the program's own standing artifacts — the SCRM plan, third-party risk policy, and program strategy held as Policy items; the criticality-tiered Vendor register (Vendor items); and the prior cycle instance's step documents (the DORA Article 28(3) register of information and the ICT concentration-risk view). In scope: reaffirming or revising the governing Policy items; re-tiering the Vendor register; refreshing the DORA Article 28(3) register of information and the concentration-risk view (a dashboard over the Vendor items); verifying critical-provider exit strategies; executing this cycle's tier-based reassessments and driving findings to tracked third-party Risk items (remediation or risk-committee escalation); confirming external and cloud service provider oversight; and verifying critical suppliers carry live incident-notification coverage. Named deliverables: the refreshed criticality-tiered Vendor register, the updated DORA Article 28(3) register of information, the recomputed ICT concentration-risk view, the exit-readiness summary, this cycle's tracked Risk items, and the archived cycle evidence package on the workflow instance. Terminal at close-and-archive with no downstream handoff — open or escalated vendor risks persist as Risk items in the risk register. Out of scope and handled by separate workflows: the continuous monitor-line vendor lifecycle and the per-engagement due-diligence gate for onboarding a new vendor.

Record JSON · Open in map · Data retrieval guide

Catalog revision: f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e. A connection does not establish full coverage.

Attributes

domain
grc
department
procurement
lineOfDefense
operate

Details

teams
  • procurement
  • executive
domains
  • grc
standards
  • nist-800-53
  • nist-csf-2
  • iso-27001
  • cobit-2019
  • dora
sourceTemplateId
workflow-library:grc-third-party-risk-program-vendor-oversight-cycle
releaseId
sha256:26e43a6ee25e45eec0f30b74fe52e47eb9ee397d2fa5064268a026a9dc9f0eb1
canonicalUrl
https://assureswarm.com/workflows/all/?w=grc-third-party-risk-program-vendor-oversight-cycle
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-TPRM-01
    • UC-TPRM-04
    • UC-TPRM-08
    • UC-TPRM-05
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:26e43a6ee25e45eec0f30b74fe52e47eb9ee397d2fa5064268a026a9dc9f0eb1

            Connections