{"description":"Supplier Service Registry & Critical Supplier Assessment as a modular, decision-aware workflow. Each cycle runs on an Audit item created for the cycle (audit_type = vendor_review) — a vendor-review engagement the workflow instance attaches to — while the supplier service register itself lives as Vendor items that are enriched as services onboard, change, or exit, never recreated each cycle. It reconciles the register against the organization's own supplier, procurement, and billing records, maps the systems and data each service touches and its internal relationship owner, classifies critical suppliers, and runs a security and risk assessment before acquisition or engagement, triggering reassessment when services, dependencies, or risk profiles change. Named deliverables: the reconciled supplier service register (the Vendor items), the supplier criticality classifications, the critical-supplier security and risk assessment memo with risk rating (its material third-party exposure recorded as third_party Risk items and its control gaps as finding Issues), the engagement decision, and the scheduled reassessments. In scope: maintaining the supplier service register and performing pre-acquisition and pre-engagement security and risk assessments of critical suppliers. Out of scope: ongoing SLA and contract-performance management, procurement sourcing and negotiation, and enterprise-level risk aggregation. Self-originating — no upstream workflow feeds this cycle; it is opened by a scheduled register review, a new supplier acquisition or engagement, a service onboarding/change/exit event, or a reassessment trigger. It hands off to no named downstream workflow (contract and SLA management being out of scope); an engage decision's conditions are carried forward as finding Issues and in the decision rationale so they remain actionable.","edges":[{"id":"e-map-systems-data-and-relationship-owners-classify-supplier-criticality","source":"map-systems-data-and-relationship-owners","target":"classify-supplier-criticality"},{"id":"e-classify-supplier-criticality-conduct-critical-supplier-risk-assessment","label":"Critical","source":"classify-supplier-criticality","target":"conduct-critical-supplier-risk-assessment","whenValue":"critical"},{"id":"e-classify-supplier-criticality-determine-reassessment-trigger-status","label":"Non-critical","source":"classify-supplier-criticality","target":"determine-reassessment-trigger-status","whenValue":"non_critical"},{"id":"e-conduct-critical-supplier-risk-assessment-decide-critical-supplier-engagement","source":"conduct-critical-supplier-risk-assessment","target":"decide-critical-supplier-engagement"},{"id":"e-decide-critical-supplier-engagement-determine-reassessment-trigger-status","label":"Engage","source":"decide-critical-supplier-engagement","target":"determine-reassessment-trigger-status","whenValue":"engage"},{"id":"e-decide-critical-supplier-engagement-document-non-engagement-and-notify-stakeholders","label":"Do not engage","source":"decide-critical-supplier-engagement","target":"document-non-engagement-and-notify-stakeholders","whenValue":"do_not_engage"},{"id":"e-document-non-engagement-and-notify-stakeholders-determine-reassessment-trigger-status","source":"document-non-engagement-and-notify-stakeholders","target":"determine-reassessment-trigger-status"},{"id":"e-determine-reassessment-trigger-status-schedule-and-log-reassessment","label":"Trigger identified","source":"determine-reassessment-trigger-status","target":"schedule-and-log-reassessment","whenValue":"trigger_identified"},{"id":"e-determine-reassessment-trigger-status-close-and-archive","label":"No trigger","source":"determine-reassessment-trigger-status","target":"close-and-archive","whenValue":"no_trigger"},{"id":"e-schedule-and-log-reassessment-close-and-archive","source":"schedule-and-log-reassessment","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-ASSET-05"],"department":"procurement","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-supplier-service-registry-critical-supplier-assessment","contentDigest":"sha256:bf161dec8217bd83b608ffa897e2f2b7bb5cd7ca553873b4a43fc32b3d54a617","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:bf161dec8217bd83b608ffa897e2f2b7bb5cd7ca553873b4a43fc32b3d54a617","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-supplier-service-registry-critical-supplier-assessment"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"grc-supplier-service-registry-critical-supplier-assessment","source":"coworkcanvas-gallery","standards":["nist-csf-2"],"teams":["procurement"]},"name":"Supplier Service Registry & Critical Supplier Assessment","nodes":[{"data":{"description":"Agent reconciles the supplier service register against procurement and billing records, applies onboarding, change, and exit updates, and maps the systems and data each service touches with a proposed internal relationship owner; human business owners confirm accuracy and accept ownership","instructions":"**Objective** — Reconcile the supplier service register to current reality — applying every onboarding, change, and exit event — and record for each entry the internal systems and data the service touches and its accountable internal relationship owner, so criticality is judged on real exposure and each named owner has accepted accountability.\n\n**Inputs**\n- The trigger that opened this cycle — a scheduled register review, a new supplier acquisition or engagement requiring pre-engagement assessment, a supplier-service onboarding/change/exit event, or a reassessment trigger such as a dependency or risk-profile change. Record the trigger type, its date, and its source.\n- The existing supplier service register — the Vendor items already in the tenant, each carrying category, tier (criticality), data_classification, business_owner, risk_owner, reassessment_cadence, last_assessment_date, next_reassessment_date, monitoring_status, and contract_end_date, or a note that no Vendor items exist yet. This register already exists as an input; enrich it, never recreate it.\n- Active supplier, contract, procurement, and billing records to reconcile against, plus any newly reported engagements, service changes, or terminations since the last cycle; procurement records and contract signatories are also what the accountable business owner is inferred from.\n- Data-flow diagrams, integration/interface inventories, and each supplier's own service description, uploaded as documents on this step or drawn from the CMDB/architecture repository (External system).\n- No upstream workflow feeds this cycle; every input is one of the organization's own operational records.\n\n**Procedure**\n_Items 1–5 are agent-run (folded from the former \"Inventory and update the supplier service register\" step); the human moment is the owners' confirmation and acceptance at item 9._\n1. Confirm and log the trigger, then scope the cycle to the specific supplier-delivered services (and any single acquisition or engagement) it concerns; note explicitly what is out of scope so the inventory does not sprawl.\n2. Compile the full inventory of supplier-delivered services by querying active supplier and procurement records, the current register entries, and any newly reported engagements.\n3. Apply lifecycle events entry by entry: for each service newly onboarded since the last cycle, create a register entry (supplier, service description, effective date); for each service reported materially changed, update the existing entry and note what changed; for each service reported exited or terminated, mark the entry for retirement pending confirmation — do not delete it, so audit history is retained.\n4. Reconcile the compiled inventory against the prior register snapshot and flag any supplier-delivered service that appears active in procurement or billing but is absent from the register — an unmanaged or shadow supplier that must be added.\n5. Assemble a change summary — additions, changes, exits, and reconciliation exceptions — so the reviewer can confirm the delta rather than re-reading the whole register.\n6. For each service, identify and record the internal systems it integrates with or can access — production applications, data stores, identity providers, network zones — citing the integration inventory or interface catalog.\n7. Identify and record the categories and sensitivity of data the service touches (for example PII, financial, regulated PCI/PHI, confidential IP, or public) and its approximate volume, drawing on data-flow diagrams or the service description.\n8. Propose the internal relationship owner for each service — the business function or named individual accountable for the supplier relationship — from procurement records, contract signatories, or the prior register entry.\n9. Route each proposed systems/data mapping and ownership assignment to the relevant business owner for confirmation, so accountability is accepted rather than merely assigned, and have the vendor risk manager confirm on the same pass that the change summary is complete and no active procurement or billing service is missing.\n\n**Record in AssureSwarm**\n- Enrich the supplier service register as Vendor items: a service newly onboarded this cycle -> create its Vendor item (category, business_owner, risk_owner, and, from procurement/billing, contract_end_date); a materially changed service -> update the affected fields on its Vendor item; an exited or terminated service -> set monitoring_status: exited on its Vendor item (retained, never deleted, so audit history survives) (coach-item-create, coach-item-update).\n- Record the trigger type and cycle date on the anchor Audit item created for this cycle (audit_type: vendor_review) — the trigger and its source in Audit.description, the in-scope services in Audit.scope (coach-item-update).\n- Query and cite the supplier, procurement, and billing records used for reconciliation, and add any active-but-unregistered (shadow) supplier surfaced in procurement or billing as a new Vendor item (coach-query-data).\n- Set the confirmed data exposure and relationship owner on each Vendor item — data_classification (the highest sensitivity of data the service touches), business_owner (the accountable relationship owner), and risk_owner (coach-item-update).\n- Capture the systems-and-data mapping (which internal systems each service integrates with or can access) in a systems-mapping document attached to this step, and link it to the Vendor item — there is no native System/Asset item type to link to, so this document plus the Vendor's data_classification is the ground truth (coach-document-upload, coach-items-link).\n\n**Exit criteria** — The register reflects every current supplier-delivered service with onboarding, change, and exit events correctly applied and no active procurement or billing service missing; each named relationship owner has confirmed accountability for their service; and the vendor risk manager confirms the systems and data mapping is accurate and complete for every register entry, before criticality is classified.","label":"Map systems, data, and relationship owners","performedBy":{"primitives":["coach-items-link","coach-item-create","coach-item-update","coach-document-upload","coach-query-data"]}},"id":"map-systems-data-and-relationship-owners"},{"data":{"decisionField":"supplier_criticality","description":"Agent drafts a criticality classification for each in-scope supplier using service impact, data sensitivity, and dependency signals; human vendor risk manager decides whether a full risk assessment is required","formData":{"fields":[{"key":"supplier_criticality","label":"Supplier criticality classification","options":[{"label":"Critical - security and risk assessment required","value":"critical"},{"label":"Non-critical - no assessment required this cycle","value":"non_critical"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Resolve, for each in-scope supplier, whether it is a critical supplier that must undergo a security and risk assessment before acquisition or engagement, or a non-critical supplier that needs no full assessment this cycle. The vendor risk manager owns the call.\n\n**Decision criteria**\n- Select **critical** (`critical`) when the service touches sensitive or high-volume data, integrates with production or identity systems, carries a hard availability dependency or low substitutability, has regulatory or contractual significance, is newly under acquisition or engagement, or has never been assessed — any of these means a security and risk assessment must complete before engagement proceeds.\n- Select **non-critical** (`non_critical`) when the service touches only low-sensitivity data, has limited system access, is readily substitutable, and carries no regulatory weight — its residual risk does not warrant a full assessment this cycle, and it proceeds straight to register recording with a next-review date.\n\nScore each supplier against the organization's documented critical-supplier criteria, cross-reference prior classifications, and flag any status change since the last cycle. The branch not selected can be pruned.\n\n**Record in AssureSwarm**\n- Submit the `supplier_criticality` SELECT (critical / non_critical) for each in-scope supplier.\n- Record the determination rationale and evidence references in the step result and name the decision owner in the step's approver record.\n- Stamp the classification onto each supplier's Vendor item as tier — critical -> tier: critical; non_critical -> tier: low or medium per its residual exposure — so the register itself carries the criticality (coach-item-update).\n- Link the supporting scoring evidence to the supplier's Vendor item (coach-document-link).\n\n**Exit criteria** — The classification form is submitted with a rationale and evidence references for every in-scope supplier, and the branch not taken is prunable.","kind":"decision","label":"Classify supplier criticality","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-item-update"]}},"id":"classify-supplier-criticality"},{"data":{"description":"Agent solicits the supplier's security questionnaire and assurance evidence, assesses it against the systems and data the service touches, and drafts the findings and risk rating; human vendor risk manager judges whether the evidence is current and sufficient to decide the engagement","formData":{"fields":[{"key":"subprocessor_chain","label":"Subprocessors and fourth parties used to deliver this service: for each, the data they can access and the country they operate from","required":false,"type":"textarea"},{"key":"incident_history_24_months","label":"Security breaches, incidents, or regulatory actions affecting this service in the last 24 months, with dates and remediation","required":false,"type":"textarea"},{"key":"breach_notification_commitment","label":"Breach-notification timeframe you can commit to contractually","options":[{"label":"Within 24 hours of becoming aware","value":"within_24_hours"},{"label":"Within 72 hours of becoming aware","value":"within_72_hours"},{"label":"Other (state the timeframe above)","value":"other"}],"required":false,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Produce a supported security and risk assessment — evidence, findings, and a risk rating — for a supplier classified critical, sufficient to decide the engagement.\n\n**Inputs**\n- The supplier's Vendor item with its confirmed systems-and-data mapping (data_classification) and its critical classification (tier: critical), plus the systems-mapping document from the prior step.\n- The critical supplier's security and risk evidence, solicited through this step's form and uploaded as documents on this step: completed security questionnaire responses; current SOC 2 or ISO 27001 attestations or equivalent certifications; financial and reputational risk signals; breach or incident history; and the supplier's subprocessor / fourth-party chain.\n\n**Procedure**\nFirst reconcile the current inventory, contracts, prior responses, reports, certificates and other supplied evidence against the assessment period. Record supported answers and their sources as request context. Send a form only for unresolved facts, and identify exactly which optional questions need an answer; leave known questions unanswered and do not require their re-entry. If the artifacts answer every question, omit the form assignment and assess those artifacts directly. Use a named supplier contact who holds none of this workflow’s preparation, execution, review or approval assignments. The internal executor resolves evidence conflicts and records the assessment in the step result.\n\n1. Compile the evidence set from available artifacts and any requested missing-fact responses, chasing unresolved evidence gaps or expired attestations before assessing. An attestation whose period end predates the engagement is stale — request a bridge letter or the current report.\n2. Assess the evidence against the systems and data the service touches, evaluating access scope, data-sensitivity exposure, availability dependency, and concentration risk (how much the organization would lose if this supplier failed).\n3. Draft the risk rating and findings memo, noting any control gaps, required remediations, and contractual safeguards such as right-to-audit or breach-notification terms — testing the supplier's stated notification commitment against what the organization's own obligations require.\n4. Package the assessment memo with the supporting evidence so a reviewer can trace every rating to its source before an engagement decision is made.\n\n**Record in AssureSwarm**\n- The form on this step, answered by the critical supplier's security contact, captures the supplier’s subprocessor / fourth-party chain, its 24-month incident history and the breach-notification timeframe it will commit to. Use the approved service/access mapping and assigned representative; read assurance type and period from the reports and certificates supplied as documents. It is the supplier's declaration; the assessor's testing and rating go in the step result and the memo.\n- Upload the compiled evidence bundle and the critical-supplier security and risk assessment memo (with its risk rating) as documents on this step, and link the memo to the supplier's Vendor item (coach-document-upload, coach-items-link).\n- Record material third-party exposure the memo identifies as a Risk item — category: third_party, taxonomies: third_party_risk, likelihood, impact, inherent_rating, residual_rating, and risk_owner — linked to the anchor Audit (coach-item-create, coach-items-link).\n- Record each control gap or required remediation as an Issue — issue_type: finding, source: compliance_review, severity, recommendation, issue_owner, identified_date, target_remediation_date — linked to the anchor Audit and the Vendor item (coach-item-create, coach-items-link).\n- Query and cite the source records and prior assessments used (coach-query-data).\n\n**Exit criteria** — Any requested missing-fact response is attributable to the named supplier representative, or the existing evidence answers all required facts; the vendor risk manager confirms the evidence is current and sufficient, that the risk rating and findings are well supported, and that any gaps are clearly flagged, before the engagement is decided.\n\n**Form recipient** — Critical supplier security contact, only when that person holds none of the preparation, execution, review or approval assignments anywhere in this workflow. Request only the unresolved facts listed in the assignment; the optional fields do not require known information to be entered again. If no facts are missing, no form response is required.","label":"Conduct critical supplier security and risk assessment","performedBy":{"primitives":["coach-document-upload","coach-query-data","coach-item-create","coach-items-link"]}},"id":"conduct-critical-supplier-risk-assessment"},{"data":{"decisionField":"critical_supplier_engagement_decision","description":"Agent summarizes the assessment findings into an engagement recommendation; human vendor risk manager or approver decides whether the acquisition or engagement proceeds","formData":{"fields":[{"key":"critical_supplier_engagement_decision","label":"Critical supplier engagement decision","options":[{"label":"Engage - acquisition or engagement may proceed","value":"engage"},{"label":"Do not engage - residual risk unacceptable","value":"do_not_engage"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Decide whether the critical supplier's acquisition or engagement may proceed given the assessed residual risk. The vendor risk manager or the designated approver owns the call.\n\n**Decision criteria**\n- Select **engage** (`engage`) when the residual risk sits within the organization's risk tolerance — either because the assessment surfaced no material gaps, or because the required remediations, contract terms, and monitoring commitments can be attached as conditions and recorded in the rationale.\n- Select **do not engage** (`do_not_engage`) when the residual risk is unacceptable and cannot be brought within tolerance by conditions — for example an unremediated critical control gap on a high-data-sensitivity service, an unacceptable subprocessor chain, or a refusal to accept required safeguards.\n\nCross-check the recommendation against risk tolerance and required contractual safeguards before submitting. The branch not selected can be pruned.\n\n**Record in AssureSwarm**\n- Submit the `critical_supplier_engagement_decision` SELECT (engage / do_not_engage).\n- Record the rationale, any attached conditions, and evidence references in the step result, and name the decision owner in the step's approver record; the conditions themselves stay actionable as the finding Issues raised by the assessment (this workflow names no downstream contracting workflow to consume them).\n- Link the assessment memo that supports the decision (coach-document-link).\n\n**Exit criteria** — The engagement decision form is submitted with a rationale and evidence references, and the branch not taken is prunable.","kind":"decision","label":"Decide critical supplier engagement","performedBy":{"primitives":["coach-form-fill","coach-document-upload"]}},"id":"decide-critical-supplier-engagement"},{"data":{"description":"Agent files the non-engagement rationale and notifies procurement and the relationship owner; human relationship owner confirms the supplier engagement will not proceed","instructions":"**Objective** — Formally record and communicate a do-not-engage outcome so no system access or contractual commitment is initiated or continued with the declined supplier.\n\n**Inputs**\n- The do-not-engage decision, its rationale, and the supporting assessment evidence.\n- The procurement contact and the proposed relationship owner for the declined engagement.\n\n**Procedure**\n1. File the do-not-engage decision, its rationale, and the assessment evidence against the supplier's register entry.\n2. Draft a non-engagement notice for procurement and the proposed relationship owner explaining the risk basis for the decision.\n3. Confirm that no active contract, purchase order, or system access is initiated or continued for the declined engagement — and if any provisional access exists, flag it for immediate revocation.\n4. Log the closure of the acquisition or engagement request with a reference back to the assessment record.\n\n**Record in AssureSwarm**\n- Upload the non-engagement notice (PDF/DOCX) to this step (coach-document-upload).\n- Link the decision and assessment evidence to the supplier's Vendor item, and set that Vendor item monitoring_status: not_enrolled so the register shows it was assessed and not engaged (coach-items-link, coach-item-update).\n- Notify procurement and the proposed relationship owner (coach-notify).\n\n**Exit criteria** — The relationship owner and procurement confirm the engagement will not proceed and that no access or contractual commitment has been made, before the register outcome is recorded.\n\n> **⚡ Audit Artist accelerator:** `/coach-notify` sends the non-engagement notice to procurement and the proposed relationship owner with the risk basis and a link to the assessment record.","label":"Document non-engagement and notify stakeholders","performedBy":{"primitives":["coach-document-upload","coach-items-link","coach-notify","coach-item-update"]}},"id":"document-non-engagement-and-notify-stakeholders"},{"data":{"decisionField":"reassessment_trigger_status","description":"Resolve whether any updated register entry meets a reassessment trigger and must be queued for reassessment, or whether none does this cycle. The vendor risk manager owns the call.","formData":{"fields":[{"key":"reassessment_trigger_status","label":"Reassessment trigger status","options":[{"label":"Trigger identified - reassessment required","value":"trigger_identified"},{"label":"No trigger - no reassessment required","value":"no_trigger"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective**\nResolve whether any updated register entry meets a reassessment trigger and must be queued for reassessment, or whether none does this cycle. The vendor risk manager owns the call.\n\n**Decision criteria**\nInputs and preparation before selecting the branch:\nThe criticality classification for each in-scope supplier.\n- For critical suppliers: the assessment memo plus the engagement decision (engage with any conditions, or the do-not-engage record).\n- The standard review cadence and any conditions imposed by an engagement decision.\n\n*Agent retrieval, preparation and filing absorb “Record assessment and register outcome”; the responsible roles retain their judgments and all independent sign-offs within this checkpoint.*\n\n1. Assessment scope for Record assessment and register outcome: Update every in-scope register entry with its criticality classification, assessment and engagement outcome, linked evidence, and next-review date, so the register stands as audit-ready evidence.\n\n2. For each critical supplier, record its classification, the security and risk assessment result, the engagement decision, and any conditions attached.\n3. For each non-critical supplier, record the classification rationale and the date of the next scheduled review.\n4. Link the supporting evidence — questionnaires, certifications, the assessment memo, and the engagement or non-engagement record — to each register entry so every outcome is traceable to its basis.\n5. Set the next scheduled review date for every updated entry based on the standard cadence or any conditions imposed.\n\n6. Assessment scope for Determine reassessment trigger status: Resolve whether any updated register entry meets a reassessment trigger and must be queued for reassessment, or whether none does this cycle. The vendor risk manager owns the call.\n\n\n\nSelect **trigger identified** (`trigger_identified`) when one or more entries meet a trigger condition: a material change to the service, a change in the systems or data it touches, a change in its dependency or subprocessor chain, or a change in the supplier's risk profile such as a new incident, a ratings downgrade, or a lapsed certification.\n- Select **no trigger** (`no_trigger`) when no register entry meets a reassessment condition this cycle.\n\nCross-reference open onboarding/change/exit items from this cycle and any assessment conditions that carried a monitoring commitment before submitting. The branch not selected can be pruned.\n\n**Record in AssureSwarm**\nUpdate each in-scope Vendor item with its outcome: tier (criticality), monitoring_status (enrolled for an engaged critical supplier; not_enrolled for a non-critical or declined supplier), last_assessment_date (this cycle), next_reassessment_date, and reassessment_cadence from the standard review cadence or any imposed engagement conditions (coach-item-update).\n- Link the supporting evidence — the assessment memo, the third_party Risk and finding Issue items, and the engagement or non-engagement record — to each Vendor item and to the anchor Audit (coach-items-link).\n\nSubmit the `reassessment_trigger_status` SELECT (trigger_identified / no_trigger).\n- Record the rationale, the specific triggers, and evidence references in the step result, and name the decision owner in the step's approver record.\n- Cite the evidence via the register scan (coach-query-data, coach-workflow-scan).\n\n**Exit criteria**\nThe vendor risk manager confirms every in-scope register entry is updated with its outcome, evidence is linked, and the record is complete enough to stand as evidence to auditors, before reassessment triggers are checked. The reassessment-trigger form is submitted with a rationale and evidence references, and the branch not taken is prunable.","kind":"decision","label":"Determine reassessment trigger status","performedBy":{"note":"","primitives":["coach-query-data","coach-workflow-scan","coach-item-create","coach-items-link","coach-item-update"]}},"id":"determine-reassessment-trigger-status"},{"data":{"description":"Agent schedules the reassessment cycle for each flagged supplier and logs the trigger and due date; human relationship owner confirms the schedule","instructions":"**Objective** — Schedule and log a reassessment for each flagged supplier so the next cycle's trigger scan finds it and the relationship owner knows what is due and when.\n\n**Inputs**\n- The list of suppliers flagged with a reassessment trigger, each with its specific trigger and the evidence that raised it.\n- Urgency signals — active incident, certification lapse, or risk-rating downgrade.\n\n**Procedure**\n1. For each flagged supplier, create a scheduled reassessment task naming the specific trigger — service change, dependency change, or risk-profile change — and the evidence that raised it.\n2. Set the reassessment due date from the trigger's urgency, prioritizing suppliers with an active incident, a certification lapse, or a risk-rating downgrade.\n3. Notify the relationship owner and the vendor risk manager of the scheduled reassessment and the evidence it will require.\n4. Log the scheduled reassessments against the register so the next cycle's trigger scan finds them, and surface them on the supplier-risk tracking dashboard.\n\n**Record in AssureSwarm**\n- Create one scheduled-reassessment Audit item per flagged supplier — audit_type: vendor_review, status PLANNED, scope naming the specific trigger and the evidence that raised it, period_start/period_end framing the due window — and set next_reassessment_date on that supplier's Vendor item so the next cycle's trigger scan finds it (coach-item-create, coach-item-update).\n- Build or refresh the supplier-risk tracking dashboard — driven off the PLANNED vendor_review Audit items and the open third_party Risk and finding Issue items — so upcoming reassessments surface (coach-dashboard-create).\n\n**Exit criteria** — The relationship owner confirms the reassessment schedule and due dates are appropriate to the trigger's urgency, before the cycle is closed.","label":"Schedule and log reassessment","performedBy":{"primitives":["coach-item-create","coach-dashboard-create","coach-item-update"]}},"id":"schedule-and-log-reassessment"},{"data":{"description":"Automatically archive the current register and selected assessment/reassessment outcomes under their existing approvals.","instructions":"**Objective** — Archive the complete cycle record to the retention location and formally close the cycle, leaving durable, auditor-ready evidence.\n\n**Inputs**\n- The updated supplier service register, criticality classifications, critical-supplier assessment memos, engagement decisions, non-engagement notices, and scheduled reassessments produced this cycle.\n\n**Procedure**\n1. Assemble the complete cycle record — the updated register, classifications, assessment memos, engagement decisions, non-engagement notices, and scheduled reassessments.\n2. Archive the record to the retention location as evidence, tagged with the cycle date and the applicable retention period, and link it back to the register.\n3. Update linked records — open procurement or contract requests and any dashboards tracking supplier risk — so downstream work references the current outcome.\n4. Communicate the closed-cycle summary, including any scheduled reassessments and their due dates, to the vendor risk manager and affected relationship owners.\n\n**Record in AssureSwarm**\n- Export and archive the full cycle package (the register, classifications, assessment memos, engagement decisions, non-engagement notices, and scheduled reassessments) as a document on this step and to the retention location, tagged with the cycle date and retention period (coach-workflow-export).\n- Stamp the anchor Audit item with the cycle outcome — report_date: the cycle close date, rating from the cycle result — so the workflow instance itself stands as the durable audit trail (coach-item-update).\n- Link the archived package back to the anchor Audit and to the affected Vendor items (coach-document-link).\n\n**Exit criteria** — After the selected trigger or schedule approval, automatically verify the self-contained archive of register, classifications, assessments, decisions and applicable reassessment schedule, then record cycle closure.\n\n> **⚡ Audit Artist accelerator:** `/coach-workflow-export` assembles and exports the full cycle package to the retention location with the cycle date and retention period applied.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-document-upload","coach-item-update"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:grc-supplier-service-registry-critical-supplier-assessment"}
