unified
UC-TPRM-04 — Monitor vendor performance, services, and risk
Continuously monitor third-party performance, service delivery, and security posture against contractual and risk requirements throughout the relationship. Conduct periodic reassessments and reviews, such as questionnaires, assurance reports, and audits, at a frequency based on criticality, and manage changes to supplier services. Record, prioritize, and track identified vendor risks through response and remediation.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Third-Party / Supply-Chain Risk
- type
- detective
- category
- administrative
Details
- unified_id
- UC-TPRM-04
- title
- Monitor vendor performance, services, and risk
- statement
- Continuously monitor third-party performance, service delivery, and security posture against contractual and risk requirements throughout the relationship. Conduct periodic reassessments and reviews, such as questionnaires, assurance reports, and audits, at a frequency based on criticality, and manage changes to supplier services. Record, prioritize, and track identified vendor risks through response and remediation.
- domain
- Third-Party / Supply-Chain Risk
- control_type
- detective
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- SR-6
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.SC-07
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.SC-09
- coverage
- partial
- delta
- integration of practices across the technology life cycle satisfied by program control
- relationship
- intersects_with
- framework
- iso-27001
- control_id
- A.5.22
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-04 — Monitor vendor performance, services, and risk
- UC-TPRM-04 — Monitor vendor performance, services, and risk mitigates Third-party compliance failure creating vicarious liability
- strength
- related
- rationale
- Questionnaires, assurance-report review, and audits surface vendor compliance drift, reducing vicarious-liability exposure.
- Vendor Risk Assessment and Disposition oversees UC-TPRM-04 — Monitor vendor performance, services, and risk
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-TPRM-04 — Monitor vendor performance, services, and risk
- System and Third-Party Risk Review operates UC-TPRM-04 — Monitor vendor performance, services, and risk
- UC-TPRM-04 — Monitor vendor performance, services, and risk maps_to GV.SC-07 — Cybersecurity Supply Chain Risk Management: The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
- framework
- nist-csf-2
- control_id
- GV.SC-07
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Vendor SOC 1/SOC 2 Report Review & CUEC Mapping oversees UC-TPRM-04 — Monitor vendor performance, services, and risk
- UC-TPRM-04 — Monitor vendor performance, services, and risk maps_to SR-6 — Supplier Assessments and Reviews
- framework
- nist-800-53
- control_id
- SR-6
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-TPRM-04 — Monitor vendor performance, services, and risk mitigates Critical vendor failure, insolvency or concentration
- strength
- related
- rationale
- Periodic reassessment and posture monitoring surface a deteriorating critical vendor early, reducing failure impact.
- Third-Party Vendor Assurance Engagement tests UC-TPRM-04 — Monitor vendor performance, services, and risk
- UC-TPRM-04 — Monitor vendor performance, services, and risk maps_to GV.SC-09 — Cybersecurity Supply Chain Risk Management: Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
- framework
- nist-csf-2
- control_id
- GV.SC-09
- coverage
- partial
- delta
- integration of practices across the technology life cycle satisfied by program control
- relationship
- intersects_with
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Third-Party Risk Program & Vendor Oversight Cycle operates UC-TPRM-04 — Monitor vendor performance, services, and risk
- SOC 2 Reporting and Management Assertion operates UC-TPRM-04 — Monitor vendor performance, services, and risk
- Third-Party ICT Vendor Regulatory Assurance oversees UC-TPRM-04 — Monitor vendor performance, services, and risk
- GCP Physical and Environmental Subservice Reliance oversees UC-TPRM-04 — Monitor vendor performance, services, and risk
- UC-TPRM-04 — Monitor vendor performance, services, and risk mitigates Weak supplier security requirements and monitoring
- strength
- primary
- rationale
- Continuously monitoring third-party service delivery and security posture with periodic reassessment is precisely the monitoring the risk says is absent.
- UC-TPRM-04 — Monitor vendor performance, services, and risk mitigates Vendor/outsourcing service non-performance and disputes
- strength
- primary
- rationale
- Monitoring performance and service delivery against contractual and SLA requirements directly detects and drives remediation of non-performance.
- UC-TPRM-04 — Monitor vendor performance, services, and risk maps_to A.5.22 — Monitoring, review and change management of supplier services
- framework
- iso-27001
- control_id
- A.5.22
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.