workflow
Third-Party Risk Program & Vendor Oversight Cycle
A standing quarterly cycle the vendor-management office runs as control owner. The workflow instance is a recurring run attached to the EXISTING Process item "Third-Party / Vendor Risk Management" (process_type: operational, process_owner: Vendor Risk Program Lead, frequency: quarterly), linked to the Control items for the unified controls it operates (UC-TPRM-01/04/05/08) — it enriches that standing program, never recreating it. It consumes no upstream workflow handoff: each run is self-feeding, drawing its criteria and prior state from the program's own standing artifacts — the SCRM plan, third-party risk policy, and program strategy held as Policy items; the criticality-tiered Vendor register (Vendor items); and the prior cycle instance's step documents (the DORA Article 28(3) register of information and the ICT concentration-risk view). In scope: reaffirming or revising the governing Policy items; re-tiering the Vendor register; refreshing the DORA Article 28(3) register of information and the concentration-risk view (a dashboard over the Vendor items); verifying critical-provider exit strategies; executing this cycle's tier-based reassessments and driving findings to tracked third-party Risk items (remediation or risk-committee escalation); confirming external and cloud service provider oversight; and verifying critical suppliers carry live incident-notification coverage. Named deliverables: the refreshed criticality-tiered Vendor register, the updated DORA Article 28(3) register of information, the recomputed ICT concentration-risk view, the exit-readiness summary, this cycle's tracked Risk items, and the archived cycle evidence package on the workflow instance. Terminal at close-and-archive with no downstream handoff — open or escalated vendor risks persist as Risk items in the risk register. Out of scope and handled by separate workflows: the continuous monitor-line vendor lifecycle and the per-engagement due-diligence gate for onboarding a new vendor.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- procurement
- lineOfDefense
- operate
Details
- teams
- procurement
- executive
- domains
- grc
- standards
- nist-800-53
- nist-csf-2
- iso-27001
- cobit-2019
- dora
- sourceTemplateId
- workflow-library:grc-third-party-risk-program-vendor-oversight-cycle
- releaseId
- sha256:a897ce21c38e200ae7741ba040630159a3e639a9f926f61653e2dc07ba3c28f6
- canonicalUrl
- https://workflow-library.com/all/?w=grc-third-party-risk-program-vendor-oversight-cycle
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-TPRM-01
- UC-TPRM-04
- UC-TPRM-08
- UC-TPRM-05
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:a897ce21c38e200ae7741ba040630159a3e639a9f926f61653e2dc07ba3c28f6
Connections
- Third-Party Risk Program & Vendor Oversight Cycle operates UC-TPRM-01 — Operate a third-party security risk management program
- Third-Party Risk Program & Vendor Oversight Cycle operates UC-TPRM-05 — Include suppliers in incident notification and response
- Third-Party Risk Program & Vendor Oversight Cycle operates UC-TPRM-04 — Monitor vendor performance, services, and risk
- Third-Party Risk Program & Vendor Oversight Cycle operates UC-TPRM-08 — Govern security of external and cloud service use