{"description":"Runs on one existing System with vendor=true. Uses the supplier record, contracts, assurance/CUECs, access and continuity evidence to produce a reviewed vendor risk assessment and authorized disposition for the business/risk owner and readiness evidence consumers. Two checkpoints retain expert challenge and the owner’s choice of conditions, treatment and monitoring; executor work is recorded in step results and documents, with no collection forms or runtime branches.","edges":[{"id":"e-assess-vendor-risk-decide-vendor-disposition","source":"assess-vendor-risk","target":"decide-vendor-disposition"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-TPRM-02","UC-TPRM-03","UC-TPRM-04","UC-ACCESS-21"],"department":"procurement","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-vendor-risk-assessment-disposition","contentDigest":"sha256:0e1b87c81c6df3a7731724450a4addf288b73a1af31f910c346d83d2618b16a5","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:0e1b87c81c6df3a7731724450a4addf288b73a1af31f910c346d83d2618b16a5","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-vendor-risk-assessment-disposition"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"grc-vendor-risk-assessment-disposition","source":"coworkcanvas-gallery","standards":["iso-27001","nist-800-53","soc1","soc2"],"teams":["procurement","risk-management","it"]},"name":"Vendor Risk Assessment and Disposition","nodes":[{"data":{"instructions":"**Objective**\nProduce a vendor risk assessment that an authorized business/risk owner can use to decide whether and under what conditions to rely on the supplier.\n\n**Inputs**\nThe existing parent System with vendor=true; available service and data-flow records; executed agreements and security/privacy terms; assurance reports and bridge material; prior reviews, Issues and exceptions; access configuration; continuity/recovery plans and actual test evidence where available; and the native Risks and Controls linked to this step. Use the current tenant schema and actual records. The CISO/security reviewer is the expected human expert; Resolve the current qualified role holder for each run; this template assigns no individual.\n\n**Procedure**\n1. Verify the parent is the intended supplier and service. Reconcile its actual engagement state as prospective, active, inactive/terminated or unresolved. Record the review reason and actual assessment date, accountable business/risk roles, scope, data handled, personnel/service access, subprocessors, criticality, shared dependencies and any unconfirmed facts. Enrich the existing System; do not create a duplicate supplier.\n2. Compile and assess the evidence as one package. Check executed contracts, DPA/security terms, confidentiality, breach notification, access/audit rights and termination commitments. Distinguish signed, unsigned, expired, unavailable and absent documents. Apply personnel-security checks where supplier staff access company systems or information; do not infer missing terms from an unavailable contract.\n3. Review the available assurance report's issuer, type, period, opinion, exceptions, scope and subservice treatment. Evaluate bridge coverage and complementary user entity controls against the service actually used, with evidence of the company's relevant implementation. Where no report exists, document the alternative posture evidence and limits. A report title, certification logo or public policy is not the underlying assurance report.\n4. Evaluate actual access and integration credentials, least privilege and segregation; identify production/data boundaries and material fourth-party dependencies. Review approved continuity and recovery plans, contractual commitments, substitutability and exit feasibility. Separate documented RTO/RPO from measured results and prepared plans from executed tests. Do not claim tests, remediation, contracts or reviews occurred without evidence.\n5. Read each linked Risk and Control and state the part applicable to this supplier, or a reason it does not apply. Use the current rating method to assess identified exposure and uncertainty, and distinguish existing recorded ratings from proposed changes. Evaluate initial due diligence for prospective suppliers; flag missing historical due diligence for active suppliers. Links indicate relevant records, not control operation, complete coverage or a treatment decision.\n6. Bring the consolidated findings to the CISO/security reviewer. Ask them to challenge material assumptions, report relevance, concentration and access exposure; consider credible alternative explanations, mitigations or service arrangements. Record their actual contribution and changes to the assessment. Keep an independent reviewer for conclusions about controls or work that the reviewer operates. Do not manufacture a challenge or sign-off.\n7. Record the remaining gaps and practical options with their tradeoffs. Use existing sources first. If missing facts need a non-executing respondent, identify who can supply them and prepare the request; use existing authorization or obtain it before sending. This template has no collection forms. Put proposed findings and follow-up into the assessment so the disposition owner can choose conditions, request more work or defer reliance.\n\n**Record in AssureSwarm**\nWrite a Markdown string to this step's result field using the current supported change and review path. Include Scope and evidence dates; Evidence examined and limitations; Contract and assurance findings; Access, continuity and exit analysis; Risk/control applicability; Human challenge and response; and Recommendation with gaps and options. Cite source record/document IDs, actual activity dates and report sections. Attach source contracts, assurance material and supporting files as documents on this step, subject to access rights. Use the configured document attachment location; do not assume a document field exists on the supplier record. Link existing findings to the vendor and relevant Risk/Control records through supported relationships; propose new Issues where needed. Preserve evidence provenance and label proposed item changes. Human review uses native review/approval records, never a typed assertion in the result.\n\n**Exit criteria**\nThe substantive reviewer has evaluated the assessment package and documented their contribution through the appropriate review records. The package identifies applicable records, evidence limits, unresolved gaps and feasible options. A qualified assessment may proceed to a disposition that defers or declines reliance; incomplete evidence does not justify a clean conclusion. Only this reviewed package feeds the disposition checkpoint.","kind":"task","label":"Assess vendor risk"},"id":"assess-vendor-risk"},{"data":{"instructions":"**Objective**\nRecord the authorized vendor disposition and the conditions, treatment and monitoring decisions that govern the service relationship.\n\n**Inputs**\nThe reviewed assessment and source documents from Assess vendor risk; its applicable Risk/Control records, gaps and options; actual business/service needs; existing contracts and commitments; and the organization's current authority, risk-acceptance and review rules. The human contributor is the authorized business/risk decision maker, resolved for the run. The template assigns no person or approval authority.\n\n**Procedure**\n1. Confirm that the assessment package and required expert review are available and that the proposed decision maker has authority for the service, commitments and residual risk. Use an independent authorized approver where the assessor would otherwise approve their own work. If authority or critical facts are missing, record the limitation and obtain the required contribution before an approval or risk acceptance.\n2. Present the practical choices with evidence and tradeoffs: proceed or continue, proceed subject to conditions, defer pending evidence/remediation, decline the proposed engagement, restrict use, or terminate/close when appropriate to the actual lifecycle. This is an authorized business decision recorded in the result and native approval records, not a runtime decision branch or form. Do not infer that an inactive supplier is approved for reuse or that a prospective supplier has been engaged.\n3. Give the decision maker the meaningful choice of mitigations, service arrangements and concentration/exit safeguards. Discuss cost, service value, exposure, uncertainty and operational consequences. Record the option they actually choose and the rationale they provide. Their decision may require further assessment; unresolved matters remain open rather than becoming implied acceptance.\n4. For each accepted finding, agree the corrective action, responsible person/role, actual agreed target date, review evidence and escalation conditions. Preserve distinctions between an assessment recommendation, a management acceptance and a completed action. Risk acceptances or waivers use the current supported Issue representation and granting authority/expiry fields; propose related Risk treatment changes separately through the supported approval path. Never manufacture dates, owners or closed Issues.\n5. Agree proportionate monitoring and reassessment: which assurance, security, availability or service changes to observe, who will act, the actual next review date/cadence, escalation triggers and any contract/exit milestone. Monitor critical dependence and substantiated changes in supplier posture. A monitoring plan is not monitoring already performed.\n6. Record the authorized disposition and obtain the applicable native approval. Then file the reviewed decision with its assessment references, maintain accepted follow-up in the existing records and pass it to the responsible operational owners as part of this checkpoint. Do not add a separate bookkeeping step. Template approval, a draft result or a link does not authorize purchasing, vendor outreach, access changes or termination; perform those only within the actual recorded authority and through their applicable workflows.\n\n**Record in AssureSwarm**\nWrite a Markdown string to this step's result field through the current supported change and review path. Include Decision and authority basis; Options considered and the owner's choice; Conditions and residual uncertainty; Agreed actions; Monitoring/reassessment and exit provisions; and References to the assessment, supporting documents and native approval. Attach supporting decision material to this step. Use native approval records for sign-off. Propose only evidenced, authorized updates to the existing System fields, where the configured schema supports them: vendor, category, tier, data_classification, business_owner, risk_owner, reassessment_cadence, last_assessment_date, next_reassessment_date, monitoring_status and contract_end_date. Reuse current field options. Change last_assessment_date only after the substantive assessment and review occurred; scheduling or template approval is insufficient. Keep contract documents on workflow steps. Maintain relevant Risk, Control and Issue relationships without treating association as evidence of operation.\n\n**Exit criteria**\nThe authorized decision and any required independent approval are recorded natively, with the actual chosen conditions and monitoring/follow-up responsibilities. Accepted changes follow the supported record approval path. A defer, decline, restriction or termination disposition is a valid recorded outcome where supported; it does not certify missing evidence or completed downstream work. No unresolved evidence gap is silently converted into approval, and no follow-up is marked complete without its own evidence.","kind":"task","label":"Decide vendor disposition"},"id":"decide-vendor-disposition"}],"sourceTemplateId":"workflow-library:grc-vendor-risk-assessment-disposition"}
