| A | B | C | D | E | F | G | H | I | |
|---|---|---|---|---|---|---|---|---|---|
1 | |||||||||
2 | Stage | Task | Owner (replace with actual owner) | Expected output | Tier (see second tab for guidance) | Trigger (change based on your decision) | Evidence to keep (personalize to your situation) | Status | Notes |
3 | 1. Strategy & scope | ||||||||
4 | Define third-party risk appetite and tolerance | CISO / Risk Committee | Approved risk appetite statement for third parties | Program setup | Board or executive approval records | | [Add notes] | ||
5 | Define vendor categories and scope (in/out) | GRC Lead | Documented vendor scope definition | Program setup | TPRM policy version history | | [Add notes] | ||
6 | Map regulatory and compliance requirements | Compliance | List of applicable regulations per vendor type | Program setup | Regulatory mapping document | | [Add notes] | ||
7 | Configure automation rules aligned to risk appetite | GRC / Security Ops | System rules reflecting risk thresholds | Program setup | System configuration logs | | [Add notes] | ||
8 | 2. Tiering & inventory | ||||||||
9 | Centralize all vendors into a single inventory | Procurement / GRC | Complete third-party inventory | New vendor / inventory update | Vendor master list export | | [Add notes] | ||
10 | Define tiering logic (data access, criticality, impact) | Security / GRC | Risk tiering criteria | New vendor / inventory update | Tiering methodology document | | [Add notes] | ||
11 | Automate vendor intake and classification | Procurement | Vendors automatically assigned a tier | New vendor / inventory update | Intake workflow logs | | [Add notes] | ||
12 | Enrich vendor profiles with external data | GRC | Pre-populated vendor risk profiles | New vendor / inventory update | Data enrichment timestamps | | [Add notes] | ||
13 | 3. Due diligence | ||||||||
14 | Trigger tier-based assessments automatically | GRC | Correct questionnaire sent per tier | Assessment / renewal | Assessment assignment logs | | [Add notes] | ||
15 | Collect security documentation (SOC 2, ISO, etc.) | Vendor / GRC | Evidence uploaded and linked to vendor | Assessment / renewal | Uploaded documents + metadata | | [Add notes] | ||
16 | Automate response analysis and gap flagging | Security | Flagged control gaps and risk issues | Assessment / renewal | Automated risk scoring output | | [Add notes] | ||
17 | Approve residual risk or remediation plans | Risk Owner | Formal risk decision recorded | Assessment / renewal | Approval records and comments | | [Add notes] | ||
18 | 4. Incident handling | ||||||||
19 | Enable vendor incident reporting channel | Security Ops | Centralized incident intake | Incident reported | Incident submission logs | | [Add notes] | ||
20 | Automate incident routing and escalation | Security | Correct teams notified by severity | Incident reported | Escalation workflow records | | [Add notes] | ||
21 | Track incident resolution and outcomes | GRC / Security | Incident closed with documented resolution | Incident reported | Incident tickets and timelines | | [Add notes] | ||
22 | Perform post-incident risk reassessment | Risk Owner | Updated vendor risk rating | Incident reported | Risk score change history | | [Add notes] | ||
23 | 5. Monitoring & feedback | ||||||||
24 | Integrate continuous monitoring feeds | Security | Real-time vendor risk signals | Monitoring signal / periodic review | Monitoring feed logs | | [Add notes] | ||
25 | Trigger reassessments based on risk changes | GRC | Automated reassessment events | Monitoring signal / periodic review | Trigger history | | [Add notes] | ||
26 | Review and update tiering logic periodically | GRC / Risk Committee | Refined tiering rules | Monitoring signal / periodic review | Change management records | | [Add notes] | ||
27 | Refresh evidence and certifications automatically | GRC | Up-to-date vendor documentation | Monitoring signal / periodic review | Renewal timestamps and versions | | [Add notes] | ||
28 | |||||||||
29 | |||||||||