{"description":"Subservice Organization & Third-Party Personnel Oversight as a checkpoint graph. Anchor: each run enriches the existing subservice-organization **Vendor** register entry for one provider - the workflow instance and every step document attach to it, and it is never recreated (initial vendor selection and onboarding due diligence are out of scope). In scope: the subservice organizations and third-party suppliers whose services support user-entity control objectives or whose personnel access the organization's systems or data - reconciling and enriching their Vendor register entries, verifying subservice and personnel-security contract terms, reviewing assurance (SOC) reports and mapping complementary user-entity controls (CUECs) to internal Control items, routing exceptions to tracked Issue items, collecting third-party personnel-compliance evidence, monitoring vendor performance, and running the quarterly issue follow-up through to closure. Out of scope: initial vendor selection and onboarding due diligence, and the organization's own internal personnel controls. Upstream: no workflow feeds it - it is built from the existing Vendor register, the prior cycle's archived vendor file, open Issue items, and the internal Control inventory, plus contracts, SOC reports, and performance data uploaded as evidence. Downstream: self-contained - no single workflow consumes its output; the archived, auditor-ready vendor file is the durable evidence record. It runs on the annual per-vendor cycle with quarterly issue follow-up.","edges":[{"id":"e-verify-subservice-contractual-commitments-assess-report-findings-and-route","source":"verify-subservice-contractual-commitments","target":"assess-report-findings-and-route"},{"id":"e-verify-subservice-contractual-commitments-collect-third-party-personnel-compliance-evidence","source":"verify-subservice-contractual-commitments","target":"collect-third-party-personnel-compliance-evidence"},{"id":"e-assess-report-findings-and-route-run-quarterly-issue-follow-up","source":"assess-report-findings-and-route","target":"run-quarterly-issue-follow-up"},{"id":"e-assess-report-findings-and-route-log-and-assign-issue","label":"Exceptions found","source":"assess-report-findings-and-route","target":"log-and-assign-issue","whenValue":"exceptions_escalate"},{"id":"e-assess-report-findings-and-route-run-quarterly-issue-follow-up","label":"No exceptions","source":"assess-report-findings-and-route","target":"run-quarterly-issue-follow-up","whenValue":"no_exceptions_proceed"},{"id":"e-log-and-assign-issue-run-quarterly-issue-follow-up","source":"log-and-assign-issue","target":"run-quarterly-issue-follow-up"},{"id":"e-collect-third-party-personnel-compliance-evidence-run-quarterly-issue-follow-up","source":"collect-third-party-personnel-compliance-evidence","target":"run-quarterly-issue-follow-up"},{"id":"e-run-quarterly-issue-follow-up-escalate-overdue-issues","label":"Overdue - escalate","source":"run-quarterly-issue-follow-up","target":"escalate-overdue-issues","whenValue":"overdue_escalate"},{"id":"e-run-quarterly-issue-follow-up-close-and-archive","label":"On track - close","source":"run-quarterly-issue-follow-up","target":"close-and-archive","whenValue":"on_track_close"},{"id":"e-escalate-overdue-issues-close-and-archive","source":"escalate-overdue-issues","target":"close-and-archive"},{"id":"e-run-quarterly-issue-follow-up-close-and-archive","source":"run-quarterly-issue-follow-up","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-ACCESS-21","UC-HR-05"],"department":"procurement","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-subservice-organization-third-party-personnel-oversight","contentDigest":"sha256:f363048ac9ad6bf8d1664397cb2ca7ee815450822567ec5ffd7c1027bf080c2c","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:f363048ac9ad6bf8d1664397cb2ca7ee815450822567ec5ffd7c1027bf080c2c","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-subservice-organization-third-party-personnel-oversight"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"grc-subservice-organization-third-party-personnel-oversight","source":"coworkcanvas-gallery","standards":["soc1","nist-800-53","iso-27001"],"teams":["procurement","hr"]},"name":"Subservice Organization & Third-Party Personnel Oversight","nodes":[{"data":{"description":"Confirm, from each in-scope subservice organization's executed contract, that the agreement binds the provider both to the security and data-processing commitments matching its mapped control objectives and to personnel-security terms equivalent to those the organization applies to its own staff; log any gap.","instructions":"**Objective**\nConfirm, from each in-scope subservice organization's executed contract, that the agreement binds the provider both to the security and data-processing commitments matching its mapped control objectives and to personnel-security terms equivalent to those the organization applies to its own staff; log any gap.\n\n**Inputs**\nThe subservice-organization / third-party-supplier population as **Vendor items** already in the register (the entries whose services support in-scope control objectives or whose personnel access the organization's systems or data). Each carries `category`, `tier`, `data_classification`, `business_owner`, `risk_owner`, `reassessment_cadence`, `last_assessment_date`, `next_reassessment_date`, `monitoring_status`, and `contract_end_date`.\n- The prior cycle's register state: the prior archived vendor file (documents on the prior workflow instance) and any open **Issue items** carried forward (no `actual_remediation_date`) related to the vendor.\n- The organization's user-entity control objectives and internal control inventory — **Control items** in the Control library (SOC 1-relevant objectives = Control items whose `framework` includes soc1).\n- The cycle trigger for context: the scheduled annual per-vendor review, a subservice organization newly added to the Vendor register, or a quarterly issue-follow-up on a vendor with open items. No upstream workflow feeds this register; it is built from the existing Vendor register and the prior cycle's file.\n\nThe current subservice-organization **Vendor** register entry with each vendor's mapped control objectives — the linked **Control** items from the register-maintenance step.\n- The current, fully executed contract or master services agreement for each in-scope subservice organization and for each supplier whose personnel access the organization's systems or data — uploaded here as PBC/external evidence (the external contract repository is the source of truth; the AssureSwarm copy is evidence).\n- The organization's equivalent-terms standard for personnel security (screening, confidentiality, defined responsibilities, transfer/termination notification) applied to internal personnel — the governing **Policy** item (`policy_type`: standard, `domains`: human_resources_personnel_security), whose document attaches to that item.\n\n**Procedure**\n*Agent retrieval, preparation and filing absorb “Maintain subservice organization register”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Maintain subservice organization register: Produce a current, complete register of the subservice organizations and third-party suppliers relevant to the organization's user-entity control objectives, each an enriched **Vendor** item with an accountable owner and links to the control objective(s) it supports. This cycle enriches the existing Vendor register — it does not create it (onboarding is out of scope).\n\n2. Reconcile the Vendor population against the register: list every in-scope subservice-organization Vendor item and flag any missing an owner or a mapped control objective.\n3. For each Vendor, map the specific user-entity control objective(s) it supports or affects to the corresponding Control items, and mark the entry continuing, newly identified this cycle, or exited.\n4. Update each Vendor entry's business/risk owner, service description, data/system-access classification, reassessment cadence, and contract renewal date; assign an accountable owner to any entry missing one.\n5. Confirm the vendor risk manager of record for this cycle and record the target completion date, distinguishing a full annual review from a quarterly follow-up on existing issues.\n6. Flag for follow-up any subservice organization operating without a current Vendor entry, an owner, or a mapped control objective.\n\n7. Assessment scope for Verify subservice contractual commitments: Confirm, from each in-scope subservice organization's executed contract, that the agreement binds the provider both to the security and data-processing commitments matching its mapped control objectives and to personnel-security terms equivalent to those the organization applies to its own staff; log any gap.\n\nSubservice security & data-processing commitments:\n8. Retrieve the current, fully executed contract or MSA for each in-scope subservice organization.\n9. Extract the security and data-processing clauses — data-protection and confidentiality obligations, security-control requirements, audit / right-to-inspect provisions, breach-notification timelines, and subcontractor flow-down terms — and compare them against the control objectives mapped in the register.\n10. For every control objective the subservice organization supports that lacks a corresponding contractual commitment, log a contract gap with the affected objective and an owner.\nThird-party personnel-security terms (same contracts):\n11. Re-examine each contract for the personnel-security clauses required whenever provider personnel access the organization's systems or data: background-screening requirements, individual confidentiality/non-disclosure agreements, and clearly defined security responsibilities for provider staff.\n12. Confirm the contract obliges the provider to notify the organization of personnel transfers or terminations that affect access, and record the notification channel and timeframe the contract specifies.\n13. Compare the personnel clauses against the organization's equivalent-terms standard; log a personnel-terms gap for any contract silent on screening, confidentiality, defined responsibilities, or transfer/termination notification.\n14. Attach each reviewed contract and clause extract as evidence and link it to the register entry.\n\n**Record in AssureSwarm**\nUpdate each subservice-organization **Vendor** item: `business_owner` / `risk_owner` (accountable owner), `category`, `tier`, `data_classification`, `reassessment_cadence`, `last_assessment_date`, `next_reassessment_date`, `monitoring_status` (enrolled | not_enrolled | exited for lifecycle status), and `contract_end_date` (contract renewal date) (item-update).\n- Link each Vendor item to the user-entity **Control** item(s) it supports (items-link).\n\nUpload each reviewed contract and clause extract as step documents (document-upload) and link each to the subservice-organization **Vendor** register entry (document-link).\n- Capture the clause-verification results and any logged gaps in the native step result, noting the affected control objective and owner for each gap.\n\n**Exit criteria**\nThe register reflects the current subservice-organization landscape relevant to control objectives; no relevant vendor is missing; every Vendor entry has an accountable owner and at least one mapped Control; the cycle scope (vendors, annual vs. quarterly, target date) is recorded. For every in-scope contract: the security/data-processing commitments trace to the mapped control objectives; personnel-security terms are confirmed equivalent to internal standards with explicit transfer/termination notification obligations; every contract gap and personnel-terms gap is logged with an owner; contracts and extracts are linked to the register as evidence.","label":"Verify subservice contractual commitments","performedBy":{"note":"","primitives":["coach-document-upload","coach-form-fill","coach-query-data","coach-item-update","coach-items-link"]}},"id":"verify-subservice-contractual-commitments"},{"data":{"decisionField":"report_findings_outcome","description":"Consolidate the findings from the contract verification and the assurance-report review and decide, as the vendor risk manager, whether the vendor proceeds cleanly or an issue must be logged and escalated. The decision owner is recorded on the form.","formData":{"fields":[{"key":"report_findings_outcome","label":"Assurance report and CUEC findings outcome","options":[{"label":"No exceptions or CUEC gaps - proceed to monitoring","value":"no_exceptions_proceed"},{"label":"Exceptions or CUEC gaps found - log and escalate issue","value":"exceptions_escalate"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective**\nConsolidate the findings from the contract verification and the assurance-report review and decide, as the vendor risk manager, whether the vendor proceeds cleanly or an issue must be logged and escalated. The decision owner is recorded on the form.\n\n**Decision criteria**\nInputs and preparation before selecting the branch:\nThe subservice-organization **Vendor** register entry with mapped control objectives — the linked **Control** items from the register-maintenance step.\n- The subservice organization's most current independent assurance report (SOC 1, SOC 2, or equivalent attestation) covering the relevant service period — uploaded here as PBC/external evidence obtained from the vendor.\n- The organization's internal control inventory — the **Control** library — to map CUECs against.\n\n*Agent retrieval, preparation and filing absorb “Review assurance report and map CUECs”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Review assurance report and map CUECs: Obtain each subservice organization's current assurance (SOC) report, extract the complementary user-entity controls (CUECs) it requires, map each CUEC to the organization's corresponding internal control, and summarize the opinion and mapping in a report-review memo.\n\n2. Obtain the most current assurance report and confirm its scope matches the services the organization actually receives and that the report period covers the relevant service period. If the report is stale or scoped to different services, record it as a coverage gap.\n3. Read the report for the auditor's opinion (unqualified / qualified / adverse / disclaimer), the control objectives or trust-services criteria tested, and any noted deviations or exceptions.\n4. Extract the full list of complementary user-entity controls (CUECs) the report requires the organization to operate.\n5. Map every CUEC to the organization's corresponding internal control; where no corresponding control exists or it is not operating, record an unmapped-CUEC finding.\n6. Compile the report-review memo: opinion, report period and scope, tested objectives/criteria, noted exceptions, and the full CUEC mapping.\n\n7. Assessment scope for Assess report findings and route: Consolidate the findings from the contract verification and the assurance-report review and decide, as the vendor risk manager, whether the vendor proceeds cleanly or an issue must be logged and escalated. The decision owner is recorded on the form.\n\n\n\nConsolidate every finding first: any contract gap or personnel-terms gap from the contract verification, any qualified/adverse opinion or noted exception in the assurance report, and any CUEC mapped to a control that does not exist or is not operating. Classify each finding's severity and whether it affects a control objective the organization relies on.\n- Select **No exceptions or CUEC gaps - proceed to monitoring** (`no_exceptions_proceed`) when the contracts, the report opinion, and the CUEC mapping are all clean — no logged gaps, an unqualified opinion with no relied-upon exceptions, and every CUEC mapped to an operating internal control. The cycle proceeds without opening a new issue.\n- Select **Exceptions or CUEC gaps found - log and escalate issue** (`exceptions_escalate`) when any contract gap, personnel-terms gap, report exception or qualification, or unmapped / non-operating CUEC requires tracked remediation.\n\n**Record in AssureSwarm**\nUpload the assurance report and the report-review memo as step documents (document-upload). The report-review memo (DOCX/PDF) is the named deliverable; it carries the auditor's opinion (unqualified | qualified | adverse | disclaimer), report period, scope, exceptions, and the full CUEC mapping (Vendor items have no native opinion field, so the memo is its home).\n- Link each mapped CUEC's corresponding internal **Control** item to the subservice-organization **Vendor** register entry (items-link).\n\nSubmit the `report_findings_outcome` SELECT field with the chosen branch.\n- Record the decision rationale with evidence references (finding summary and contract/report links) in the rationale field and name the decision owner or approver.\n- Query the consolidated findings across the vendor's **Vendor** entry, its linked **Control** items, and the uploaded contract/report step documents, and link that supporting evidence to the decision step (query-data, document-link).\n\n**Exit criteria**\nThe assurance report is confirmed current and in scope; the opinion and any exceptions are recorded in the report-review memo; every CUEC is mapped to an internal Control or flagged as unmapped; the memo is attached. The form is submitted with a branch selected, rationale and evidence references captured, and the owner named; the unused branch is prunable.","kind":"decision","label":"Assess report findings and route","performedBy":{"note":"","primitives":["coach-query-data","coach-document-upload","coach-items-link"]}},"id":"assess-report-findings-and-route"},{"data":{"description":"Automatically record the findings authorized by the exceptions decision and draft the corrective-action requests.","instructions":"**Objective** — Turn each finding routed as an exception into a tracked issue with an owner, severity, and remediation due date, and notify the vendor of the requested corrective action.\n\n**Inputs**\n- The consolidated findings routed as exceptions from the assurance-findings decision (contract gap, personnel-terms gap, assurance-report exception, unmapped CUEC), each with its affected control objective and source evidence.\n- The subservice-organization **Vendor** register entry for the vendor and its linked **Control** items.\n- The quarterly follow-up cadence, used to set remediation due dates.\n\n**Procedure**\n1. Create an Issue item for each routed finding, describing the finding, the affected control objective, and the source-evidence reference.\n2. Assign each Issue an owner (the vendor risk manager or the relevant control owner), a severity, and a remediation due date consistent with the quarterly follow-up cadence.\n3. Draft the vendor notification / remediation request communicating the finding and the requested corrective action or updated evidence.\n4. Link each Issue to the subservice-organization Vendor entry so it appears in the vendor's file.\n\n**Record in AssureSwarm**\n- Create an **Issue** item per finding — `issue_type`: deficiency (contract gap, non-operating CUEC, personnel-terms gap) or observation (lower-severity report note), `source`: compliance_review, `severity`, `issue_owner`, `identified_date`, `target_remediation_date` (item-create).\n- Link each Issue to the subservice-organization **Vendor** register entry and to the affected **Control** item (items-link).\n\n**Exit criteria** — Every routed finding has a corresponding tracked Issue with a named owner, severity, and due date; the vendor notification is drafted; each Issue is linked to the vendor's Vendor register entry and affected Control.","label":"Log and assign issue","performedBy":{"primitives":["coach-item-create","coach-items-link"]},"requiredApprovals":0},"id":"log-and-assign-issue"},{"data":{"description":"Agent sends the personnel-security attestation form to the provider and tests the returned compliance evidence - screening confirmations, signed confidentiality agreements, and the transfer/termination notification log - against the contracted terms; human confirms the evidence matches the contract terms and opens an Issue for each gap","formData":{"fields":[{"key":"personnel_with_access_count","label":"Number of your personnel with access to our systems or data during the period","required":false,"type":"number"},{"key":"background_screening_status","label":"Background screening status for those personnel","options":[{"label":"All screened to the contracted standard before access","value":"all_screened"},{"label":"Screened with exceptions (list below)","value":"exceptions"},{"label":"Not screened to the contracted standard","value":"not_screened"}],"required":false,"type":"select"},{"key":"confidentiality_agreements_status","label":"Signed confidentiality / non-disclosure agreements in place","options":[{"label":"Signed by every person with access","value":"all_signed"},{"label":"Gaps or exceptions (list below)","value":"exceptions"},{"label":"Not in place","value":"not_in_place"}],"required":false,"type":"select"},{"key":"security_responsibilities_communicated","label":"Defined security responsibilities communicated to personnel with access","options":[{"label":"Yes, with documented acknowledgment","value":"yes_documented"},{"label":"Yes, but acknowledgment is not documented","value":"yes_undocumented"},{"label":"No","value":"no"}],"required":false,"type":"select"},{"key":"transfer_termination_log","label":"Personnel transfers and terminations during the period: for each, the effective date, the date our access was revoked, and the date you notified us","required":false,"type":"textarea"},{"key":"exceptions_and_remediation","label":"Any contracted personnel-security requirement not met this period, with the reason and your remediation plan and date","required":false,"type":"textarea"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Collect and test the provider's compliance evidence for the contracted personnel-security requirements — confirming screening, confidentiality, defined responsibilities, and timely transfer/termination notification — and route any non-compliance to the issue tracker.\n\n**Inputs**\n- The personnel-security terms verified in the contract-verification step (screening, confidentiality/NDA, defined responsibilities, and the transfer/termination notification channel and timeframe) — this step tests evidence against those exact terms.\n- The subservice-organization / supplier **Vendor** register entry and the provider's point of contact for evidence requests.\n- The provider's compliance evidence (screening confirmations, signed NDAs, notification logs) — supplied as PBC/external documents alongside the provider’s form response.\n\n**Procedure**\nFirst reconcile the current inventory, contracts, prior responses, reports, certificates and other supplied evidence against the assessment period. Record supported answers and their sources as request context. Send a form only for unresolved facts, and identify exactly which optional questions need an answer; leave known questions unanswered and do not require their re-entry. If the artifacts answer every question, omit the form assignment and assess those artifacts directly. Use a named supplier contact who holds none of this workflow’s preparation, execution, review or approval assignments. The internal executor resolves evidence conflicts and records the assessment in the step result.\n\n1. Collect the provider's compliance evidence for each verified personnel-security requirement: screening-completion confirmations for personnel with access, signed confidentiality/non-disclosure agreements, and documentation that defined security responsibilities were communicated to provider staff.\n2. Pull the log of personnel transfers or terminations the provider notified during the period — the form's transfer/termination log plus your own access records — and confirm each notification arrived within the contracted timeframe.\n3. Compare the collected evidence against the contracted personnel terms; flag any requirement — screening, confidentiality, defined responsibilities, or timely notification — for which evidence is missing, the attestation is qualified, or the provider is non-compliant. A self-reported \"yes\" with no supporting document is a gap, not evidence.\n4. File the compliance evidence to the vendor's file and, for any gap, create a tracked issue with an owner so it is picked up in the quarterly follow-up.\n\n**Record in AssureSwarm**\n- The form on this step, answered by the subservice organization's personnel-security contact, captures the provider's own attestation: the count of personnel with access, the screening and confidentiality-agreement status, whether security responsibilities were communicated, the period's transfer/termination and notification log, and any unmet requirement with its remediation plan. Bind the named assigned representative and native response timestamp to the declaration, and retain supporting evidence as documents. It is the provider's declaration; the step owner's testing of it goes in the step result.\n- Upload the collected personnel-compliance evidence and the transfer/termination notification log as step documents linked to the **Vendor** file (document-upload).\n- Query the evidence-to-terms comparison and, for any gap, create a tracked **Issue** item with the same shape used by the log-and-assign-issue step — `issue_type`: deficiency, `source`: compliance_review, `severity`, `issue_owner`, `identified_date`, `target_remediation_date` — linked to the Vendor entry so the tracker stays single-source and the gap is picked up in the quarterly follow-up (query-data).\n\n**Exit criteria** — Available evidence and any necessary attributable missing-fact declaration cover the period; evidence exists for every contracted personnel-security requirement, or a tracked Issue is opened for each gap; the transfer/termination notification log is confirmed against the contracted timeframe; all evidence is filed to the Vendor file.\n\n**Form recipient** — Subservice organization personnel-security contact, only when that person holds none of the preparation, execution, review or approval assignments anywhere in this workflow. Request only the unresolved facts listed in the assignment; the optional fields do not require known information to be entered again. If no facts are missing, no form response is required.","label":"Collect third-party personnel compliance evidence","performedBy":{"primitives":["coach-document-upload","coach-query-data"]}},"id":"collect-third-party-personnel-compliance-evidence"},{"data":{"decisionField":"quarterly_followup_outcome","description":"At the quarterly checkpoint, review the remediation status of every open issue for the vendor and decide whether the cycle can close or overdue/stalled issues must be escalated to management. Owned by the vendor risk manager.","formData":{"fields":[{"key":"quarterly_followup_outcome","label":"Quarterly follow-up outcome","options":[{"label":"All open issues resolved or on track - close cycle","value":"on_track_close"},{"label":"Overdue issues found - escalate to management","value":"overdue_escalate"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective**\nAt the quarterly checkpoint, review the remediation status of every open issue for the vendor and decide whether the cycle can close or overdue/stalled issues must be escalated to management. Owned by the vendor risk manager.\n\n**Decision criteria**\nInputs and preparation before selecting the branch:\nThe CUEC mapping and report-review memo (from the assurance-report review): the internal **Control** items whose operating status must be confirmed against what the report assumes.\n- The subservice organization's performance data for the period — SLA adherence, incident/complaint history — uploaded here as a PBC/external step document from the SLA/incident tooling.\n- The vendor's open **Issue** items (prior-cycle issues with resolution status) and its **Vendor** register entry, contract-verification, and report-review status.\n\n*Agent retrieval, preparation and filing absorb “Monitor vendor performance”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Monitor vendor performance: Compile the subservice organization's performance monitoring — SLA adherence, incident history, and the operating status of every internal control mapped to a CUEC — into the vendor performance dashboard, flagging any trend or CUEC operating gap.\n\n2. Compile the vendor's performance data for the period: SLA adherence, incident or complaint history, and prior-cycle issues and their resolution status.\n3. Cross-check the operating status of each internal control mapped to a CUEC, confirming the complementary user-entity control is actually implemented and functioning as the assurance report assumes; record any CUEC whose internal control is not operating.\n4. Compile the monitoring summary into the vendor's performance dashboard alongside the current register, contract-verification, and report-review status.\n5. Flag any performance trend or CUEC operating gap that warrants closer review before the next annual cycle.\n\n6. Assessment scope for Run quarterly issue follow-up: At the quarterly checkpoint, review the remediation status of every open issue for the vendor and decide whether the cycle can close or overdue/stalled issues must be escalated to management. Owned by the vendor risk manager.\n\n\n\nPull every open issue tied to the vendor from the tracker — contract gaps, personnel-terms gaps, assurance-report exceptions, unmapped CUECs, and personnel-compliance gaps — regardless of which cycle first logged it, and check each issue's remediation status and evidence of progress against its due date and the quarterly cadence.\n- Select **All open issues resolved or on track - close cycle** (`on_track_close`) when every open issue is resolved (with completed-remediation confirmation) or is progressing on schedule against its due date. The cycle proceeds to close and archive.\n- Select **Overdue issues found - escalate to management** (`overdue_escalate`) when any issue is past its due date or shows no progress since the prior quarterly check.\n\n**Record in AssureSwarm**\nUpload the period SLA/incident source data as a step document on the **Vendor** file (document-upload).\n- Query the vendor's **Issue** items and the operating status of its linked **Control** items (query-data).\n- Build or refresh the vendor performance dashboard over the vendor's Issue items and CUEC-linked Control items, surfacing SLA, incident, and CUEC operating status (dashboard-create).\n\nSubmit the `quarterly_followup_outcome` SELECT field with the chosen branch.\n- Record the rationale with evidence references (per-issue status and progress evidence) and name the decision owner.\n- Query every open **Issue** item related to the vendor's **Vendor** entry and scan the workflow for issue status (query-data, workflow-scan). On resolution, each Issue's `actual_remediation_date` and `verified_date` are set and it is closed.\n\n**Exit criteria**\nSLA adherence, incident history, and CUEC operating status are compiled into the vendor performance dashboard; every CUEC's internal Control is confirmed operating or flagged; performance trends warranting closer monitoring are noted. The form is submitted with a branch selected, per-issue status recorded with evidence references, and the owner named; the unused branch is prunable.","kind":"decision","label":"Run quarterly issue follow-up","performedBy":{"note":"","primitives":["coach-query-data","coach-workflow-scan","coach-document-upload","coach-dashboard-create"]}},"id":"run-quarterly-issue-follow-up"},{"data":{"description":"Agent escalates every overdue or stalled issue to management with an updated remediation plan; human confirms the escalation is received and owned","instructions":"**Objective** — Escalate every overdue or stalled issue to the accountable manager with a revised remediation plan and obtain acknowledged ownership before the cycle closes.\n\n**Inputs**\n- The set of overdue/stalled issues identified at the quarterly follow-up decision, each with its original finding, elapsed time against due date, prior remediation attempts, and affected control objective / vendor relationship.\n- The accountable manager for each issue and, where the issue is severe, the owner of the vendor-relationship decision.\n\n**Procedure**\n1. Compile the escalation package for every overdue or stalled issue: the original finding, elapsed time against the due date, prior remediation attempts, and the affected control objective or vendor relationship.\n2. Draft the management escalation memo requesting a revised remediation plan and, where the issue is severe enough, a decision on continuing the vendor relationship.\n3. Route the escalation to the accountable manager and record acknowledgment of ownership.\n4. Update each escalated issue's tracker entry with the new due date and owner agreed in the escalation.\n\n**Record in AssureSwarm**\n- Upload the management escalation memo (DOCX/PDF) as a step document on the **Vendor** file, recording the manager's acknowledgment of ownership (document-upload).\n- Update each escalated **Issue** item: revised `target_remediation_date`, reassigned `issue_owner`, and the escalation outcome in `management_response` (item-update).\n- Link each escalated Issue to the escalation memo and to the affected **Vendor** / **Control** (items-link).\n\n**Exit criteria** — Every overdue issue is escalated in a management escalation memo, a manager has acknowledged ownership, and each escalated Issue carries a revised `target_remediation_date` and `issue_owner` in the tracker.","label":"Escalate overdue issues","performedBy":{"primitives":["coach-item-create","coach-document-upload","coach-item-update","coach-items-link"]}},"id":"escalate-overdue-issues"},{"data":{"description":"Automatically archive the vendor file and set future review dates under the selected quarterly or management disposition.","instructions":"**Objective** — Assemble the complete vendor file for the cycle and archive it as durable, auditor-ready evidence, then set the next annual and quarterly review dates and communicate the outcome.\n\n**Inputs**\n- The report-review memo and CUEC mapping (from the assurance-report review).\n- The subservice and personnel contract-clause verification (from contract verification).\n- The third-party personnel-compliance evidence (from evidence collection).\n- The vendor performance dashboard (from performance monitoring).\n- The current issue tracker including any escalation (from the quarterly follow-up and, where taken, the escalation step).\n\n**Procedure**\n1. Assemble the complete vendor file for this cycle: the report-review memo, the CUEC mapping, the subservice and personnel contract-clause verification, the third-party personnel-compliance evidence, the vendor performance dashboard, and the current state of the issue tracker including any escalation.\n2. Archive the vendor file to the retention location with the vendor name, cycle date, and applicable retention period, and link it to the subservice-organization register entry.\n3. Update the register with the next annual review date and the next quarterly follow-up date.\n4. Communicate the cycle's outcome and next review dates to the vendor risk manager and any control owners relying on the vendor's CUECs.\n\n**Record in AssureSwarm**\n- Export and assemble the archived vendor file for the cycle as a workflow-export bundle; the closed **Workflow instance** is itself the durable audit trail (workflow-export).\n- Link the archived file to the subservice-organization **Vendor** register entry and set the vendor's next review dates — `last_assessment_date` (this cycle) and `next_reassessment_date` (next annual review) (document-link); the next quarterly follow-up date is captured in the export summary (Vendor has one reassessment-cadence date, not a separate quarterly field).\n\n**Exit criteria** — The archived vendor file is self-contained and durable enough to serve as auditor evidence without oral explanation — register status, contract verification, report review, CUEC mapping, personnel compliance, performance monitoring, and issue tracker; the next annual and quarterly review dates are set; the cycle is automatically recorded closed under its quarterly or management disposition.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-item-update","coach-document-upload"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:grc-subservice-organization-third-party-personnel-oversight"}
