workflow

Vendor Due Diligence & Contracting Gate

Vendor Due Diligence & Contracting Gate as a modular, decision-aware workflow. Anchor: the vendor's register entry — the Vendor item (slug: vendor). For a net-new engagement the gate creates the Vendor item and populates its tier, data_classification, business_owner, and risk_owner; for a renewal it enriches the existing Vendor item rather than duplicating it (enrich, never recreate). This is the first-line pre-contract gate the vendor-management office runs for every new engagement or renewal - tiering criticality, running proportionate due diligence into the vendor due-diligence report, documenting the risk-acceptance decision and any risk-reducing sourcing conditions, binding the contract to required security, privacy, and regulatory clauses, authorizing the specific information exchange before access begins, and - where personal data is involved - obtaining the signed written privacy commitments and scheduling compliance monitoring and incident-response routing. In scope: pre-contract due diligence, risk acceptance, and contract execution for one vendor engagement, ending with the Vendor item enrolled in monitoring (Vendor.monitoring_status = enrolled). There is no upstream workflow — the engagement trigger (a new prospective vendor or a renewal) is its own entry point. Downstream handoff: the archived gate record exported at close is the handoff package the ongoing third-party risk monitoring / vendor oversight lifecycle picks up to sustain the scheduled compliance checks and incident routing; that linkage is a prose handoff of live controls on the same Vendor item, not a triggered downstream node.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
grc
department
procurement
lineOfDefense
operate

Details

teams
  • procurement
  • privacy
domains
  • grc
standards
  • nist-800-53
  • soc2
  • nist-csf-2
  • gdpr
sourceTemplateId
workflow-library:grc-vendor-due-diligence-contracting-gate
releaseId
sha256:5119b29be115a4aef6f49bee55dd7116b088d3345b47938ce2a9e3dd6fa846dc
canonicalUrl
https://workflow-library.com/all/?w=grc-vendor-due-diligence-contracting-gate
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-TPRM-02
    • UC-TPRM-03
    • UC-DATA-16
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:5119b29be115a4aef6f49bee55dd7116b088d3345b47938ce2a9e3dd6fa846dc

            Connections