workflow
Third-Party Vendor Risk Lifecycle
Operate the third-party vendor risk lifecycle end to end: scope and tier the vendor population, gather and analyze assurance evidence (SOC reports and CUECs, plus C-SCRM controls), embed contractual protections, enroll ongoing monitoring, and reach a governed disposition and approval. The vendor register IS the set of Vendor items — tiered by criticality (tier) and data exposure (data_classification), owned (business_owner, risk_owner), and driven by reassessment_cadence with last/next assessment dates and monitoring_status; each assessment cycle runs as one workflow instance over that register. In scope: vendor and supplier third-party risk assessment, onboarding controls, and periodic reassessment. Out of scope: procurement sourcing and commercial negotiation, and the deeper fieldwork of a Third-Party Vendor Assurance Engagement, to which the approved package is handed off. This workflow is self-initiating and consumes no upstream workflow package.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- procurement
- lineOfDefense
- monitor
Details
- teams
- procurement
- domains
- grc
- standards
- nist-800-53
- soc2
- sourceTemplateId
- workflow-library:grc-third-party-vendor-risk-lifecycle
- releaseId
- sha256:96f9e2a2333ab1b869a093e9ffa77920c2a18e3719304346f9daebe8bc6ce5fa
- canonicalUrl
- https://workflow-library.com/all/?w=grc-third-party-vendor-risk-lifecycle
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-TPRM-01
- UC-TPRM-02
- UC-TPRM-03
- UC-TPRM-04
- UC-ASSET-05
- UC-ACCESS-21
- UC-DATA-16
- UC-HR-05
- UC-LOG-09
- UC-SDLC-10
- UC-TPRM-05
- UC-TPRM-06
- UC-TPRM-07
- UC-TPRM-09
- UC-TPRM-08
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:96f9e2a2333ab1b869a093e9ffa77920c2a18e3719304346f9daebe8bc6ce5fa
Connections
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-04 — Monitor vendor performance, services, and risk
- Third-Party Vendor Risk Lifecycle oversees UC-SDLC-10 — Oversee outsourced development and vet developers
- Third-Party Vendor Risk Lifecycle oversees UC-ASSET-05 — Inventory supplier services and assess critical suppliers
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-09 — Protect supply chain information through OPSEC
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-07 — Verify component authenticity, provenance, and integrity
- Third-Party Vendor Risk Lifecycle oversees UC-LOG-09 — Monitor providers and exchange audit data across organizations
- Third-Party Vendor Risk Lifecycle oversees UC-HR-05 — Hold third-party personnel to equivalent security terms
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-01 — Operate a third-party security risk management program
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-05 — Include suppliers in incident notification and response
- Third-Party Vendor Risk Lifecycle oversees UC-DATA-16 — Bind third parties handling personal data to privacy commitments
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-08 — Govern security of external and cloud service use
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-02 — Perform risk-based due diligence before engaging vendors
- Third-Party Vendor Risk Lifecycle oversees UC-ACCESS-21 — Manage subservice organizations supporting the system
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-06 — Manage secure termination and disposal at relationship end
- Third-Party Vendor Risk Lifecycle oversees UC-TPRM-03 — Bind vendors to security and privacy terms by contract