workflow
Vendor Risk Assessment and Disposition
Runs on one existing System with vendor=true. Uses the supplier record, contracts, assurance/CUECs, access and continuity evidence to produce a reviewed vendor risk assessment and authorized disposition for the business/risk owner and readiness evidence consumers. Two checkpoints retain expert challenge and the owner’s choice of conditions, treatment and monitoring; executor work is recorded in step results and documents, with no collection forms or runtime branches.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- procurement
- lineOfDefense
- monitor
Details
- teams
- procurement
- risk-management
- it
- domains
- grc
- standards
- iso-27001
- nist-800-53
- soc1
- soc2
- sourceTemplateId
- workflow-library:grc-vendor-risk-assessment-disposition
- releaseId
- sha256:0e1b87c81c6df3a7731724450a4addf288b73a1af31f910c346d83d2618b16a5
- canonicalUrl
- https://workflow-library.com/all/?w=grc-vendor-risk-assessment-disposition
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-TPRM-02
- UC-TPRM-03
- UC-TPRM-04
- UC-ACCESS-21
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:0e1b87c81c6df3a7731724450a4addf288b73a1af31f910c346d83d2618b16a5
Connections
- Vendor Risk Assessment and Disposition oversees UC-TPRM-04 — Monitor vendor performance, services, and risk
- Vendor Risk Assessment and Disposition oversees UC-TPRM-03 — Bind vendors to security and privacy terms by contract
- Vendor Risk Assessment and Disposition oversees UC-ACCESS-21 — Manage subservice organizations supporting the system
- Vendor Risk Assessment and Disposition oversees UC-TPRM-02 — Perform risk-based due diligence before engaging vendors