{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:31af594ee8aeb5af01927dcc0e95bf6ea9f05a8d45fd1524d012709768b688e0","slug":"controls-vendor-soc-cuec-review","url":"/assets/agent_workflow-controls-vendor-soc-cuec-review-4c3418a6.2c350c3b2cb62df2.json"},"kind":"record","record":{"attributes":{"department":"procurement","domain":"controls","lineOfDefense":"monitor"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-vendor-soc-cuec-review","description":"Reach a defensible reliance conclusion on a service organization's SOC 1/SOC 2 report. The workflow instance runs on an Audit item (audit_type: vendor_review) created for this vendor's SOC report period — enrich that item, never duplicate it; its native fields carry the report and reliance metadata (external_firm = CPA firm, opinion = service auditor's opinion, period_start/period_end = report coverage, report_date, rating = overall reliance verdict). Consumes the vendor risk handoff package from the Third-Party Vendor Risk Lifecycle workflow — the existing Vendor item, its tier, and the dependent Process items. In scope: report scope and type confirmation, the service auditor's opinion and exception analysis, complementary user entity control (CUEC) mapping, bridge/gap-period coverage, and the documented reliance decision — producing the SOC reliance memo and the reviewer-ready reliance package. Out of scope: the vendor's initial risk tiering and onboarding, and ongoing control monitoring. Hands the completed reliance package to the Continuous Controls Monitoring (ISCM) Cycle (and Third-Party ICT Vendor Regulatory Assurance) workflows.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-vendor-soc-cuec-review","capabilities":[],"controls":["UC-ACCESS-21","UC-TPRM-04"],"domains":["controls"],"lineOfDefense":"monitor","mappingStatus":"mapped","releaseId":"sha256:31af594ee8aeb5af01927dcc0e95bf6ea9f05a8d45fd1524d012709768b688e0","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-vendor-soc-cuec-review","standards":["soc1","soc2"],"teams":["procurement","it"]},"id":"wf:C11","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC11","slug":"controls-vendor-soc-cuec-review","sourceIds":["iso-27001","nist-800-53","nist-csf-2","soc1"],"sourceUrl":null,"title":"Vendor SOC 1/SOC 2 Report Review & CUEC Mapping","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8057572cda7b21587d3ec5893138ab77675283df290c0008f883c11becee8803","properties":{},"sourceDetailPath":"/data/v1/records/wf-c11-f590792c.json","sourceId":"wf:C11","targetDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","targetId":"uc:UC-TPRM-04","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ea36e63f05373b1cc6c2191a77e284fd94ba2350bf917b8770ecedea4803659f","properties":{},"sourceDetailPath":"/data/v1/records/wf-c11-f590792c.json","sourceId":"wf:C11","targetDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","targetId":"uc:UC-ACCESS-21","type":"oversees"}],"schemaVersion":1}
