workflow

Supplier Service Registry & Critical Supplier Assessment

Supplier Service Registry & Critical Supplier Assessment as a modular, decision-aware workflow. Each cycle runs on an Audit item created for the cycle (audit_type = vendor_review) — a vendor-review engagement the workflow instance attaches to — while the supplier service register itself lives as Vendor items that are enriched as services onboard, change, or exit, never recreated each cycle. It reconciles the register against the organization's own supplier, procurement, and billing records, maps the systems and data each service touches and its internal relationship owner, classifies critical suppliers, and runs a security and risk assessment before acquisition or engagement, triggering reassessment when services, dependencies, or risk profiles change. Named deliverables: the reconciled supplier service register (the Vendor items), the supplier criticality classifications, the critical-supplier security and risk assessment memo with risk rating (its material third-party exposure recorded as third_party Risk items and its control gaps as finding Issues), the engagement decision, and the scheduled reassessments. In scope: maintaining the supplier service register and performing pre-acquisition and pre-engagement security and risk assessments of critical suppliers. Out of scope: ongoing SLA and contract-performance management, procurement sourcing and negotiation, and enterprise-level risk aggregation. Self-originating — no upstream workflow feeds this cycle; it is opened by a scheduled register review, a new supplier acquisition or engagement, a service onboarding/change/exit event, or a reassessment trigger. It hands off to no named downstream workflow (contract and SLA management being out of scope); an engage decision's conditions are carried forward as finding Issues and in the decision rationale so they remain actionable.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
grc
department
procurement
lineOfDefense
operate

Details

teams
  • procurement
domains
  • grc
standards
  • nist-csf-2
sourceTemplateId
workflow-library:grc-supplier-service-registry-critical-supplier-assessment
releaseId
sha256:bf161dec8217bd83b608ffa897e2f2b7bb5cd7ca553873b4a43fc32b3d54a617
canonicalUrl
https://workflow-library.com/all/?w=grc-supplier-service-registry-critical-supplier-assessment
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-ASSET-05
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:bf161dec8217bd83b608ffa897e2f2b7bb5cd7ca553873b4a43fc32b3d54a617

            Connections