{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:bf161dec8217bd83b608ffa897e2f2b7bb5cd7ca553873b4a43fc32b3d54a617","slug":"grc-supplier-service-registry-critical-supplier-assessment","url":"/assets/agent_workflow-grc-supplier-service-registry-critical-supplier-assessment-1165e384.001538c3e8afea5c.json"},"kind":"record","record":{"attributes":{"department":"procurement","domain":"grc","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-supplier-service-registry-critical-supplier-assessment","description":"Supplier Service Registry & Critical Supplier Assessment as a modular, decision-aware workflow. Each cycle runs on an Audit item created for the cycle (audit_type = vendor_review) — a vendor-review engagement the workflow instance attaches to — while the supplier service register itself lives as Vendor items that are enriched as services onboard, change, or exit, never recreated each cycle. It reconciles the register against the organization's own supplier, procurement, and billing records, maps the systems and data each service touches and its internal relationship owner, classifies critical suppliers, and runs a security and risk assessment before acquisition or engagement, triggering reassessment when services, dependencies, or risk profiles change. Named deliverables: the reconciled supplier service register (the Vendor items), the supplier criticality classifications, the critical-supplier security and risk assessment memo with risk rating (its material third-party exposure recorded as third_party Risk items and its control gaps as finding Issues), the engagement decision, and the scheduled reassessments. In scope: maintaining the supplier service register and performing pre-acquisition and pre-engagement security and risk assessments of critical suppliers. Out of scope: ongoing SLA and contract-performance management, procurement sourcing and negotiation, and enterprise-level risk aggregation. Self-originating — no upstream workflow feeds this cycle; it is opened by a scheduled register review, a new supplier acquisition or engagement, a service onboarding/change/exit event, or a reassessment trigger. It hands off to no named downstream workflow (contract and SLA management being out of scope); an engage decision's conditions are carried forward as finding Issues and in the decision rationale so they remain actionable.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-supplier-service-registry-critical-supplier-assessment","capabilities":[],"controls":["UC-ASSET-05"],"domains":["grc"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:bf161dec8217bd83b608ffa897e2f2b7bb5cd7ca553873b4a43fc32b3d54a617","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:grc-supplier-service-registry-critical-supplier-assessment","standards":["nist-csf-2"],"teams":["procurement"]},"id":"wf:G26","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG26","slug":"grc-supplier-service-registry-critical-supplier-assessment","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"Supplier Service Registry & Critical Supplier Assessment","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:57622f962958f6be0fc2f989352c6a70d6a164134b44f6ffb370449ad54e188e","properties":{},"sourceDetailPath":"/data/v1/records/wf-g26-08681202.json","sourceId":"wf:G26","targetDetailPath":"/data/v1/records/uc-uc-asset-05-11852f6d.json","targetId":"uc:UC-ASSET-05","type":"operates"}],"schemaVersion":1}
