{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:559830dd60ca4ef7406b72e8d19e4c47cc75cede6d875886681f1bf77abddf64","slug":"audit-third-party-assurance-engagement","url":"/assets/agent_workflow-audit-third-party-assurance-engagement-267e60d4.5abdc27c37d9d73d.json"},"kind":"record","record":{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-third-party-assurance-engagement","description":"Runs on the existing Audit item for this engagement (audit_type=vendor_review) — the workflow enriches that already-planned engagement record, it never creates a duplicate — consuming the confirmed scope, criteria, and calendar handed off from Audit Engagement Planning. An IA-led third-party vendor assurance engagement that concludes on the design and operating effectiveness of the organization’s TPRM program — governance, risk tiering, vendor control-environment reliance, monitoring, exclusions, and reporting. Vendors under test are the existing Vendor items, each finding is an Issue item, and the named deliverable is a reperformable engagement workpaper package. In scope: assuring the program (IA evaluates management’s third-party risk management; it does not operate it). Out of scope: operating the vendor lifecycle (onboarding, tier refresh, remediation), which belongs to the second-line Third-Party Vendor Risk Lifecycle workflow; deep single-report SOC work, which can be delegated to the reusable Vendor SOC 1/SOC 2 Report Review & CUEC Mapping workflow; and ICT arrangements caught by regulatory regimes, which route to Third-Party ICT Vendor Regulatory Assurance. Findings and the engagement conclusion exit through Audit Report Drafting, and action plans route to Finding Remediation & Action-Plan Monitoring.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-third-party-assurance-engagement","capabilities":[],"controls":["UC-AUDIT-12","UC-AUDIT-13","UC-AUDIT-16","UC-TPRM-01","UC-TPRM-02","UC-TPRM-04"],"domains":["audit"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:559830dd60ca4ef7406b72e8d19e4c47cc75cede6d875886681f1bf77abddf64","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:audit-third-party-assurance-engagement","standards":["iia-2024"],"teams":["internal-audit","procurement"]},"id":"wf:A7","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AA7","slug":"audit-third-party-assurance-engagement","sourceIds":["cobit-2019","dora","iia-2024","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2"],"sourceUrl":null,"title":"Third-Party Vendor Assurance Engagement","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:192ed8d4bcdc5010575c85d55b8aa3fbfb15bc3ebbfc6f506e33e14b528173bc","properties":{},"sourceDetailPath":"/data/v1/records/wf-a7-454c1d0e.json","sourceId":"wf:A7","targetDetailPath":"/data/v1/records/uc-uc-audit-13-3dae730e.json","targetId":"uc:UC-AUDIT-13","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2e6ac5bf52f7b685f24e06cdf26d62d103f7555165b63f7ea393a6a0196d8b8e","properties":{},"sourceDetailPath":"/data/v1/records/wf-a7-454c1d0e.json","sourceId":"wf:A7","targetDetailPath":"/data/v1/records/uc-uc-audit-16-03aa1161.json","targetId":"uc:UC-AUDIT-16","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4563542ddc82224ac1112c258485ce77febeec9fa9f0a8eaf3a33969254150ee","properties":{},"sourceDetailPath":"/data/v1/records/wf-a7-454c1d0e.json","sourceId":"wf:A7","targetDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","targetId":"uc:UC-TPRM-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9b06aec14f3cb7b175a37f7c4aa87205e27b8238cf0ba2f24bd98605771558ba","properties":{},"sourceDetailPath":"/data/v1/records/wf-a7-454c1d0e.json","sourceId":"wf:A7","targetDetailPath":"/data/v1/records/uc-uc-audit-12-657c1271.json","targetId":"uc:UC-AUDIT-12","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a49a486d083153ad59e40694fb7939ea084461d9da86e629e8a95c447f699dcb","properties":{},"sourceDetailPath":"/data/v1/records/wf-a7-454c1d0e.json","sourceId":"wf:A7","targetDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","targetId":"uc:UC-TPRM-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e6b5d6eea9b41b87c3a68139f1374bffc0bc3898a20d7045bf35190642f2e6ab","properties":{},"sourceDetailPath":"/data/v1/records/wf-a7-454c1d0e.json","sourceId":"wf:A7","targetDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","targetId":"uc:UC-TPRM-02","type":"tests"}],"schemaVersion":1}
