workflow
Third-Party Vendor Assurance Engagement
Runs on the existing Audit item for this engagement (audit_type=vendor_review) — the workflow enriches that already-planned engagement record, it never creates a duplicate — consuming the confirmed scope, criteria, and calendar handed off from Audit Engagement Planning. An IA-led third-party vendor assurance engagement that concludes on the design and operating effectiveness of the organization’s TPRM program — governance, risk tiering, vendor control-environment reliance, monitoring, exclusions, and reporting. Vendors under test are the existing Vendor items, each finding is an Issue item, and the named deliverable is a reperformable engagement workpaper package. In scope: assuring the program (IA evaluates management’s third-party risk management; it does not operate it). Out of scope: operating the vendor lifecycle (onboarding, tier refresh, remediation), which belongs to the second-line Third-Party Vendor Risk Lifecycle workflow; deep single-report SOC work, which can be delegated to the reusable Vendor SOC 1/SOC 2 Report Review & CUEC Mapping workflow; and ICT arrangements caught by regulatory regimes, which route to Third-Party ICT Vendor Regulatory Assurance. Findings and the engagement conclusion exit through Audit Report Drafting, and action plans route to Finding Remediation & Action-Plan Monitoring.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- audit
- department
- internal-audit
- lineOfDefense
- assure
Details
- teams
- internal-audit
- procurement
- domains
- audit
- standards
- iia-2024
- sourceTemplateId
- workflow-library:audit-third-party-assurance-engagement
- releaseId
- sha256:559830dd60ca4ef7406b72e8d19e4c47cc75cede6d875886681f1bf77abddf64
- canonicalUrl
- https://workflow-library.com/all/?w=audit-third-party-assurance-engagement
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- assure
- controls
- UC-AUDIT-12
- UC-AUDIT-13
- UC-AUDIT-16
- UC-TPRM-01
- UC-TPRM-02
- UC-TPRM-04
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:559830dd60ca4ef7406b72e8d19e4c47cc75cede6d875886681f1bf77abddf64
Connections
- Third-Party Vendor Assurance Engagement tests UC-AUDIT-13 — Gather and analyze evidence to develop engagement findings
- Third-Party Vendor Assurance Engagement tests UC-AUDIT-16 — Communicate final engagement results to stakeholders
- Third-Party Vendor Assurance Engagement tests UC-TPRM-01 — Operate a third-party security risk management program
- Third-Party Vendor Assurance Engagement tests UC-AUDIT-12 — Plan engagements with risk-based objectives, scope, and criteria
- Third-Party Vendor Assurance Engagement tests UC-TPRM-04 — Monitor vendor performance, services, and risk
- Third-Party Vendor Assurance Engagement tests UC-TPRM-02 — Perform risk-based due diligence before engaging vendors