workflow

Third-Party Risk Program & Vendor Oversight Cycle

A standing quarterly cycle the vendor-management office runs as control owner. The workflow instance is a recurring run attached to the EXISTING Process item "Third-Party / Vendor Risk Management" (process_type: operational, process_owner: Vendor Risk Program Lead, frequency: quarterly), linked to the Control items for the unified controls it operates (UC-TPRM-01/04/05/08) — it enriches that standing program, never recreating it. It consumes no upstream workflow handoff: each run is self-feeding, drawing its criteria and prior state from the program's own standing artifacts — the SCRM plan, third-party risk policy, and program strategy held as Policy items; the criticality-tiered Vendor register (Vendor items); and the prior cycle instance's step documents (the DORA Article 28(3) register of information and the ICT concentration-risk view). In scope: reaffirming or revising the governing Policy items; re-tiering the Vendor register; refreshing the DORA Article 28(3) register of information and the concentration-risk view (a dashboard over the Vendor items); verifying critical-provider exit strategies; executing this cycle's tier-based reassessments and driving findings to tracked third-party Risk items (remediation or risk-committee escalation); confirming external and cloud service provider oversight; and verifying critical suppliers carry live incident-notification coverage. Named deliverables: the refreshed criticality-tiered Vendor register, the updated DORA Article 28(3) register of information, the recomputed ICT concentration-risk view, the exit-readiness summary, this cycle's tracked Risk items, and the archived cycle evidence package on the workflow instance. Terminal at close-and-archive with no downstream handoff — open or escalated vendor risks persist as Risk items in the risk register. Out of scope and handled by separate workflows: the continuous monitor-line vendor lifecycle and the per-engagement due-diligence gate for onboarding a new vendor.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
grc
department
procurement
lineOfDefense
operate

Details

teams
  • procurement
  • executive
domains
  • grc
standards
  • nist-800-53
  • nist-csf-2
  • iso-27001
  • cobit-2019
  • dora
sourceTemplateId
workflow-library:grc-third-party-risk-program-vendor-oversight-cycle
releaseId
sha256:a897ce21c38e200ae7741ba040630159a3e639a9f926f61653e2dc07ba3c28f6
canonicalUrl
https://workflow-library.com/all/?w=grc-third-party-risk-program-vendor-oversight-cycle
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-TPRM-01
    • UC-TPRM-04
    • UC-TPRM-08
    • UC-TPRM-05
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:a897ce21c38e200ae7741ba040630159a3e639a9f926f61653e2dc07ba3c28f6

            Connections