workflow
Vendor Due Diligence & Contracting Gate
Vendor Due Diligence & Contracting Gate as a modular, decision-aware workflow. Anchor: the vendor's register entry — the Vendor item (slug: vendor). For a net-new engagement the gate creates the Vendor item and populates its tier, data_classification, business_owner, and risk_owner; for a renewal it enriches the existing Vendor item rather than duplicating it (enrich, never recreate). This is the first-line pre-contract gate the vendor-management office runs for every new engagement or renewal - tiering criticality, running proportionate due diligence into the vendor due-diligence report, documenting the risk-acceptance decision and any risk-reducing sourcing conditions, binding the contract to required security, privacy, and regulatory clauses, authorizing the specific information exchange before access begins, and - where personal data is involved - obtaining the signed written privacy commitments and scheduling compliance monitoring and incident-response routing. In scope: pre-contract due diligence, risk acceptance, and contract execution for one vendor engagement, ending with the Vendor item enrolled in monitoring (Vendor.monitoring_status = enrolled). There is no upstream workflow — the engagement trigger (a new prospective vendor or a renewal) is its own entry point. Downstream handoff: the archived gate record exported at close is the handoff package the ongoing third-party risk monitoring / vendor oversight lifecycle picks up to sustain the scheduled compliance checks and incident routing; that linkage is a prose handoff of live controls on the same Vendor item, not a triggered downstream node.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- procurement
- lineOfDefense
- operate
Details
- teams
- procurement
- privacy
- domains
- grc
- standards
- nist-800-53
- soc2
- nist-csf-2
- gdpr
- sourceTemplateId
- workflow-library:grc-vendor-due-diligence-contracting-gate
- releaseId
- sha256:5119b29be115a4aef6f49bee55dd7116b088d3345b47938ce2a9e3dd6fa846dc
- canonicalUrl
- https://workflow-library.com/all/?w=grc-vendor-due-diligence-contracting-gate
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-TPRM-02
- UC-TPRM-03
- UC-DATA-16
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:5119b29be115a4aef6f49bee55dd7116b088d3345b47938ce2a9e3dd6fa846dc
Connections
- Vendor Due Diligence & Contracting Gate operates UC-DATA-16 — Bind third parties handling personal data to privacy commitments
- Vendor Due Diligence & Contracting Gate operates UC-TPRM-02 — Perform risk-based due diligence before engaging vendors
- Vendor Due Diligence & Contracting Gate operates UC-TPRM-03 — Bind vendors to security and privacy terms by contract