{"description":"Runs on the existing system item. Review system and provider dependencies, assess current risk and control evidence, select response actions, and approve the review record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-system-risk-assessment-system-review-closure","source":"system-risk-assessment","target":"system-review-closure"}],"isPublic":true,"itemTypeSlug":"system","metadata":{"capabilities":["system-third-party-risk-review"],"controlVerbs":{"UC-CONFIG-10":"operates","UC-RISK-18":"operates","UC-TPRM-02":"operates","UC-TPRM-04":"operates","UC-TPRM-08":"operates"},"controls":["UC-RISK-18","UC-CONFIG-10","UC-TPRM-02","UC-TPRM-04","UC-TPRM-08"],"department":"risk-management","domains":["grc"],"kind":"system-third-party-risk-review","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:system-third-party-risk-review"}],"canonicalUrl":"https://workflow-library.com/all/?w=grc-system-third-party-risk-review","contentDigest":"sha256:d9186ad1dc8351f49127ab6e35603aab14ffd8eae0f6994ca6e3b52ac74bd3d1","prerequisites":{"anchorItemType":{"slug":"system"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:grc-third-party-vendor-risk-lifecycle"}],"roles":[{"contribution":"expertise","description":"System owner and technical specialist. Assess system and third-party risk.","id":"reviewer-1","nodeIds":["system-risk-assessment"]},{"contribution":"approval","description":"Independent system-risk reviewer. Approve system risk review record.","id":"reviewer-2","nodeIds":["system-review-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:system-third-party-risk-review"}],"releaseId":"sha256:d9186ad1dc8351f49127ab6e35603aab14ffd8eae0f6994ca6e3b52ac74bd3d1","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-system-third-party-risk-review"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"grc-system-third-party-risk-review","source":"coworkcanvas-gallery","standards":["iso-27001","nist-800-53","soc2"],"teams":["risk-management","it","procurement"]},"name":"System & Third-Party Risk Review","nodes":[{"data":{"controls":[],"instructions":"**Objective**\nAssess system and third-party risk. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, architecture and data-flow records, inventory, contracts, service descriptions, business impact analysis, prior assessments, incidents, changes, user populations, and provider documentation.\n2. Use the confirmed scope, risk criteria, due-diligence responses, security and privacy evidence, service performance, incidents, vulnerabilities, continuity tests, contract terms, change history, monitoring, and prior findings.\n\n**Procedure**\n1. Reconcile inventory and ownership, map data types and trust boundaries, identify critical business processes and integrations, distinguish provider and customer responsibilities, identify material fourth parties, and document scope changes.\n2. Evaluate threats and business impacts, inspect control and performance evidence, assess concentration and exit risk, compare contract commitments to practice, analyze incidents and changes, and challenge ratings based only on questionnaires or attestations.\n\nMap data flows, access boundaries and system/provider dependencies explicitly and inspect associated security/control coverage.\n\n**Record in AssureSwarm**\n1. Capture the review period, system and service scope, owners, provider, environments, data classification, users, integrations, critical processes, subservices, locations, changes, exclusions, and information gaps.\n2. Document risk ratings and direction, criteria, evidence, control strengths and gaps, provider and customer responsibilities, concentration and resilience concerns, incidents, uncertainties, and prior-period comparison. Also record risk assessment.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: The review boundary and responsibility model are unambiguous, critical dependencies are represented, and missing information that could affect risk is assigned. The assessment is reproducible, material gaps and uncertainty remain visible, and rating changes or reliance on provider evidence are supported before response selection.","kind":"task","label":"Assess system and third-party risk","requiredApprovals":1},"id":"system-risk-assessment"},{"data":{"controls":["UC-RISK-18","UC-CONFIG-10","UC-TPRM-02","UC-TPRM-04","UC-TPRM-08"],"instructions":"**Objective**\nApprove system risk review record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the completed assessment, open findings, service roadmap, remediation commitments, contract rights, business continuity and exit plans, stakeholder needs, appetite criteria, and proposed monitoring indicators.\n2. Review every stage result, source evidence, ratings, provider and customer responsibilities, response approval, linked issues, monitoring commitments, contract actions, and information gaps.\n\n**Procedure**\n1. Compare continued use, remediation, restriction, replacement, and exception paths; define commitments and evidence; confirm decision authority; set performance and risk triggers; plan escalation and exit readiness; and create linked actions.\n2. Trace material ratings and decisions to evidence, verify commitments and dates, reconcile inventory and linked records, confirm contrary evidence remains visible, and return unsupported or inconsistent analysis for correction.\n\n**Record in AssureSwarm**\n1. Record the decision, rationale, authorized approver, remediation commitments, monitoring indicators and cadence, contract actions, restrictions, contingency or exit steps, linked issues, owners, and due dates. Also record response decision; monitoring plan.\n2. Capture the authorized reviewer, review summary, accepted ratings and response, review effective date, monitoring cadence, provider commitments, linked issues, limitations, owners, and due dates. Also record system risk review summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that the response follows from risk and criticality, decision authority is confirmed, and monitoring and action commitments are measurable. The authorized reviewer accepts the review as a traceable record of work and decisions, related records can be updated consistently, and closure is not represented as assurance.","kind":"task","label":"Approve system risk review record","requiredApprovals":1},"id":"system-review-closure"}],"sourceTemplateId":"workflow-library:grc-system-third-party-risk-review"}
