unified
UC-TPRM-02 — Perform risk-based due diligence before engaging vendors
Before entering a formal relationship, perform security due diligence on prospective vendors and business partners proportionate to their criticality, evaluating security posture, financial and operational risk, and supply-chain exposure, and document the acceptance decision. Use acquisition strategies, sourcing methods, and selection criteria designed to reduce supply-chain risk before contract award.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Third-Party / Supply-Chain Risk
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-TPRM-02
- title
- Perform risk-based due diligence before engaging vendors
- statement
- Before entering a formal relationship, perform security due diligence on prospective vendors and business partners proportionate to their criticality, evaluating security posture, financial and operational risk, and supply-chain exposure, and document the acceptance decision. Use acquisition strategies, sourcing methods, and selection criteria designed to reduce supply-chain risk before contract award.
- domain
- Third-Party / Supply-Chain Risk
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- SR-5
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.SC-06
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC9.2
- coverage
- partial
- delta
- ongoing monitoring, termination handling, and contractual security/confidentiality commitments satisfied by companion vendor-management and vendor-contract controls
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- System and Third-Party Risk Review operates UC-TPRM-02 — Perform risk-based due diligence before engaging vendors
- UC-TPRM-02 — Perform risk-based due diligence before engaging vendors mitigates Third-party compliance failure creating vicarious liability
- strength
- related
- rationale
- Due diligence on operational risk and supply-chain exposure screens compliance-risky vendors, reducing downstream vicarious-liability exposure.
- UC-TPRM-02 — Perform risk-based due diligence before engaging vendors mitigates Supply-chain disruption of critical inputs
- strength
- related
- rationale
- Acquisition strategies and supply-chain-exposure evaluation before award identify single-source and disruption-prone dependencies early.
- UC-TPRM-02 — Perform risk-based due diligence before engaging vendors maps_to SR-5 — Acquisition Strategies, Tools, and Methods
- framework
- nist-800-53
- control_id
- SR-5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-02 — Perform risk-based due diligence before engaging vendors mitigates Malicious supply-chain injection of tampered hardware/software
- strength
- primary
- rationale
- Acquisition strategies, sourcing methods, and selection criteria designed to reduce supply-chain risk before award defend against false-front and compromised suppliers.
- UC-TPRM-02 — Perform risk-based due diligence before engaging vendors mitigates Critical vendor failure, insolvency or concentration
- strength
- primary
- rationale
- Evaluating financial and operational risk before engagement screens for insolvency and viability risk, directly reducing critical-vendor-failure likelihood.
- Vendor Due Diligence & Contracting Gate operates UC-TPRM-02 — Perform risk-based due diligence before engaging vendors
- UC-TPRM-02 — Perform risk-based due diligence before engaging vendors maps_to GV.SC-06 — Cybersecurity Supply Chain Risk Management: Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
- framework
- nist-csf-2
- control_id
- GV.SC-06
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-02 — Perform risk-based due diligence before engaging vendors mitigates Weak supplier security requirements and monitoring
- strength
- related
- rationale
- Pre-engagement security-posture due diligence screens weaker suppliers at selection but does not itself impose contractual security requirements or ongoing monitoring, so it contributes to rather than operating the oversight defense.
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-02 — Perform risk-based due diligence before engaging vendors
- UC-TPRM-02 — Perform risk-based due diligence before engaging vendors maps_to CC9.2 — The entity assesses and manages risks associated with vendors and business partners.
- framework
- soc2
- control_id
- CC9.2
- coverage
- partial
- delta
- ongoing monitoring, termination handling, and contractual security/confidentiality commitments satisfied by companion vendor-management and vendor-contract controls
- relationship
- intersects_with
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-02 — Perform risk-based due diligence before engaging vendors mitigates AI supply-chain compromise and provider concentration
- strength
- related
- rationale
- Evaluating supply-chain exposure and provider concentration before engaging AI providers reduces concentration and compromise exposure.
- Vendor Risk Assessment and Disposition oversees UC-TPRM-02 — Perform risk-based due diligence before engaging vendors
- UC-TPRM-02 — Perform risk-based due diligence before engaging vendors mitigates Vendor/outsourcing service non-performance and disputes
- strength
- related
- rationale
- Assessing operational risk before engagement screens out likely non-performers, indirectly reducing later service-delivery failures.
- Third-Party Vendor Assurance Engagement tests UC-TPRM-02 — Perform risk-based due diligence before engaging vendors
- SOC 2 Trust Services Readiness tests UC-TPRM-02 — Perform risk-based due diligence before engaging vendors